Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Help with hijackthis  (Read 4720 times)

0 Members and 1 Guest are viewing this topic.

Mandy

    Topic Starter


    Rookie
    Help with hijackthis
    « on: June 14, 2005, 03:14:56 PM »
    I ran hijackthis and I can't get rid of some of these files that I think are viruses. After I "fix" them they come back either with different name or same name. How do I permently get rid of them? I am using AVG Antivirus which comes back no virus found. I also ran Yahoo Anti-Spy and removed all items. I want to get rid of whatever it is cause I keep getting an error message Windows Explorer has encountered problem and needs to close.

    dl65

    • R.I.P.


    • Prodigy

      Thanked: 18
      Re: Help with hijackthis
      « Reply #1 on: June 14, 2005, 03:46:32 PM »
      Mandy....Sound like a trojan.....( partcularly if it comes back with a differant name )
      Usully hijackthis is very good at removing trojans .......Are you sure you didnt miss removing all the bad entries ?

      Run your hijack again and post it here ......

      Cheers

      dl65  ::)
      If you don't know the answer, it isn't a dumb question.

      Mandy

        Topic Starter


        Rookie
        Re: Help with hijackthis
        « Reply #2 on: June 14, 2005, 03:50:24 PM »
        Logfile of HijackThis v1.99.1
        Scan saved at 4:01:46 PM, on 6/14/2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\LEXBCES.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\LEXPPS.EXE
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
        C:\WINDOWS\System32\LXSUPMON.EXE
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
        C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
        C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
        C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\MSN Apps\Updater\01.03.0000.1005\en-us\msnappau.exe
        C:\WINDOWS\system32\wuauclt.exe
        c:\windows\system32\sttfrrm.exe
        C:\Documents and Settings\Amanda\My Documents\hijackthis\HijackThis.exe


        Mandy

          Topic Starter


          Rookie
          Re: Help with hijackthis
          « Reply #3 on: June 14, 2005, 03:51:36 PM »
          O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
          O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
          O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
          O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
          O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
          O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
          O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
          O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
          O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
          O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
          O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
          O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
          O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
          O4 - HKLM\..\Run: [ncdvzgr] c:\windows\system32\sttfrrm.exe

          Mandy

            Topic Starter


            Rookie
            Re: Help with hijackthis
            « Reply #4 on: June 14, 2005, 03:52:07 PM »
            O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
            O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
            O8 - Extra context menu item: Add to AD Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm
            O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
            O8 - Extra context menu item: Block All Images from the Same Server - C:\Program Files\Avant Browser\AddAllToADBlackList.htm
            O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
            O8 - Extra context menu item: Highlight - C:\Program Files\Avant Browser\Highlight.htm
            O8 - Extra context menu item: Open All Links in This Page... - C:\Program Files\Avant Browser\OpenAllLinks.htm
            O8 - Extra context menu item: Search - C:\Program Files\Avant Browser\Search.htm
            O8 - Extra context menu item: Search &Dictionary - C:\Program files\Lexico\Toolbar\dictionary.htm
            O8 - Extra context menu item: Search &Thesaurus - C:\Program files\Lexico\Toolbar\thesaurus.htm
            O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
            O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
            O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
            O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
            O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan.cab
            O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
            O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/CDT/ie/bridge-c282.cab
            O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} (MsneDiag Class) - http://entimg.msn.com/client/msnediag2918.cab
            O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
            O16 - DPF: {A48D0309-8DA3-41AA-98E4-89194D471890} (Pulse V5 ActiveX Control) - http://www.pulse3d.com/players/english/5.2/win/PulsePlayer5.2AxWin.cab
            O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
            O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
            O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
            O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax2918.cab
            O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
            O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
            O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE


            dl65

            • R.I.P.


            • Prodigy

              Thanked: 18
              Re: Help with hijackthis
              « Reply #5 on: June 14, 2005, 04:03:52 PM »
              Mandy ......First turn off your system restore ........
              Then delete cookies , temp internet files and history ....


              Then ...... Mark for removal ......

              O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/CDT/ie/bridge-c282.cab

              These are not necessary ...I would remove them ...

              O4 - HKLM\..\Run: [TkBellExe] \"C:\Program Files\Common Files\Real\Update_OB\realsched.exe\" -osboot

              O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN


              Give this a try and let us know ......

              dl65  ::)




              « Last Edit: June 14, 2005, 04:04:10 PM by dl65 »
              If you don't know the answer, it isn't a dumb question.

              Amanda Martinez

              • Guest
              Re: Help with hijackthis
              « Reply #6 on: June 14, 2005, 06:26:08 PM »
              It didn't work. I'm wondering aren't some of these items a virus? And how do I delete them?

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\LEXBCES.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\LEXPPS.EXE
              C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
              C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\Explorer.EXE

              Also what is this c:\windows\system32\covdwp.exe

              Amanda Martinez

              • Guest
              Re: Help with hijackthis
              « Reply #7 on: June 14, 2005, 06:39:20 PM »
              Everytime I delete a different one comes back in the list.
              Now says O4 - HKLM\..\Run: [rvvpwuq] c:\windows\system32\kplvzp.exe

              dl65

              • R.I.P.


              • Prodigy

                Thanked: 18
                Re: Help with hijackthis
                « Reply #8 on: June 14, 2005, 11:17:55 PM »
                 Mandy..... Lets try this and see what it finds
                http://www.softpedia.com/get/Antivirus/Ewido-Security-Suite.shtml    

                This is a 14 day trial ......... Give it a try ...its very good at finding and removing trojans .

                BTW ...what happened ...your pc was running ok after the last go round ...what did you download ?


                let us know the result ,

                dl65  ::)
                « Last Edit: June 14, 2005, 11:18:55 PM by dl65 »
                If you don't know the answer, it isn't a dumb question.

                Mandy

                  Topic Starter


                  Rookie
                  Re: Help with hijackthis
                  « Reply #9 on: June 16, 2005, 07:46:57 PM »
                  Well I think I solved the problem.  I ran my computer in safe mode and then ran my antivirus and it found 7 viruses in my yahoo parogram! For some reason the antivirus didn't catch it in normal mode cause I ran it several time and it came back clean. Anyways, since doing that earlier I haven't had the problems. So far so good! Thanks for you help.

                  Raptor

                  • Guest
                  Re: Help with hijackthis
                  « Reply #10 on: June 17, 2005, 06:31:08 AM »
                  You may wish to look into the following programs as well:

                  AVG Free
                  -- Anti virus scanner
                  Adaware SE Personal
                  -- Anti spyware scanner
                  Microsoft Antispyware
                  -- Anti spyware scanner. Windows XP Home and Professional only.
                  Spybot Search & Destroy
                  -- Anti spyware scanner
                  ZoneAlarm Free
                  -- Free firewall - more user friendly
                  Sygate Personal
                  -- Free firewall - more configuration options