Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: HiJackThis problem  (Read 35703 times)

0 Members and 1 Guest are viewing this topic.

franke

    Topic Starter


    Intermediate

    Re: HiJackThis problem
    « Reply #30 on: March 06, 2008, 09:09:06 AM »
    evil
    I'll try again


    [recovering space - attachment deleted by admin]
    Frank

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: HiJackThis problem
    « Reply #31 on: March 06, 2008, 09:36:39 AM »
    Just post the uninstall list directly into the reply box. I can't open those.

    franke

      Topic Starter


      Intermediate

      Re: HiJackThis problem
      « Reply #32 on: March 06, 2008, 09:53:09 AM »
      evilfantasy
      Can't do that.I tried,and was toldthat it was too big;so I shrunk it in esnips.
      sorry
      frank
      Frank

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: HiJackThis problem
      « Reply #33 on: March 06, 2008, 09:57:03 AM »
      I can't seem to open esnips either.

      Please go to www.savefile.com and upload it there. You don't have to sign up, just click Upload My File. Then post the link to it back here.



      franke

        Topic Starter


        Intermediate

        Re: HiJackThis problem
        « Reply #34 on: March 07, 2008, 04:53:10 AM »
        evilfantasy

        [recovering space - attachment deleted by admin]
        Frank

        franke

          Topic Starter


          Intermediate

          Re: HiJackThis problem
          « Reply #35 on: March 07, 2008, 05:07:56 AM »
          Evilfantasy
          Could you just advise me about the programs that I now have clur=ttered on my computer?
          thanks
          Frank
          Frank

          evilfantasy

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: HiJackThis problem
          « Reply #36 on: March 07, 2008, 11:01:45 AM »
          Uninstall or delete REg Clean,  Registry Booster, aawsepersonal, advisor belarc, Firefox Setup 1,5, ieg6setup, psa30se_en_us.

          Also delete any logs that may have been created by the scans we did.

          franke

            Topic Starter


            Intermediate

            Re: HiJackThis problem
            « Reply #37 on: March 07, 2008, 12:30:43 PM »
            Trend Micro HijackThis v2.0.2
            Scan saved at 3:40:21 PM, on 3/1/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16608)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\Explorer.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
            C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
            C:\Program Files\Common Files\AOL\1102907915\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe
            C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
            C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
            C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
            C:\Program Files\Spyware Doctor\pctsAuxs.exe
            C:\Program Files\eSnips\ClientGW.exe
            C:\Program Files\Common Files\AOL\1102907915\ee\services\safetyCore\ver210_5_4_1\AOLSP
            Frank

            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: HiJackThis problem
            « Reply #38 on: March 07, 2008, 12:35:13 PM »
            Thats the first part of the log, use multiple posts to get the whole log posted.

            franke

              Topic Starter


              Intermediate

              Re: HiJackThis problem
              « Reply #39 on: March 07, 2008, 12:43:27 PM »
              Files\Common Files\AOL\1102907915\ee\services\safetyCore\ver210_5_4_1\AOLSP Scheduler.exe
              C:\Program Files\mcafee.com\antivirus\oasclnt.exe
              C:\Program Files\Logitech\MouseWare\system\em_exec.exe
              C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
              C:\Program Files\Common Files\AOL\Loader\aolload.exe
              C:\Program Files\Spyware Doctor\pctsTray.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\PROGRA~1\AIM\aim.exe
              C:\Program Files\Digital Line Detect\DLG.exe
              C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
              C:\Program Files\Common Files\AOL\1102907915\ee\SSCEvtHdlr.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Common Files\AOL\Loader\aolload.exe
              C:\WINDOWS\system32\wdfmgr.exe
              C:\WINDOWS\wanmpsvc.exe
              C:\Program Files\Canon\CAL\CALMAIN.exe
              C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
              C:\WINDOWS\system32\hpoipm07.exe
              C:\WINDOWS\System32\alg.exe
              C:\Program Files\Spyware Doctor\pctsSvc.exe
              C:\Program Files\AOL Companion\companion.exe
              C:\Program Files\America Online 9.0b\waol.exe
              C:\Program Files\America Online 9.0b\shellmon.exe
              C:\Program Files\Common Files\Aol\aoltpspd.exe
              C:\Program Files\Common Files\AOL\1102907915\EE\aolsoftware.exe
              C:\Program Files\Common Files\AOL\1102907915\EE\aolsoftware.exe
              Frank

              franke

                Topic Starter


                Intermediate

                Re: HiJackThis problem
                « Reply #40 on: March 07, 2008, 12:47:10 PM »
                C:\WINDOWS\system32\NOTEPAD.EXE

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.officialsearchlist.org/email-link/msn_hotmail.htm
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
                R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
                R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                F2 - REG:system.ini: Shell=Explorer.exe
                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
                O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
                O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
                O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
                O3 - Toolbar: eSnips - {ED1184DA-E57E-4480-99D0-A16809037F54} - C:\Program Files\eSnips\SnipBar.dll
                O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll

                O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
                O4 - HKLM\..\Run: [Logitech Utility]
                Frank

                franke

                  Topic Starter


                  Intermediate

                  Re: HiJackThis problem
                  « Reply #41 on: March 07, 2008, 12:49:37 PM »
                  un: [Logitech Utility] Logi_MwX.Exe
                  O4 - HKLM\..\Run: [eSnips] "C:\Program Files\eSnips\ClientGW.exe"
                  O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1102907915\ee\services\safetyCore\ver210_5_4_1\AOLSP Scheduler.exe
                  O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1102907915\ee\SSCRun.exe
                  O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
                  O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
                  O4 - HKLM\..\Run: [MPFEXE] "C:\Program Files\mcafee.com\personal firewall\MPFTray.exe"
                  O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                  O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
                  O4 - HKUS\S-1-5-18\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b (User 'Default user')
                  O4 - Startup: VersionTrackerPro.lnk = ?
                  O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0b\aoltray.exe
                  O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
                  O4 - Global Startup: Digital Line Detect.lnk = ?
                  O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
                  O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
                  O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
                  O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
                  O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
                  O8 - Extra context menu
                  Frank

                  franke

                    Topic Starter


                    Intermediate

                    Re: HiJackThis problem
                    « Reply #42 on: March 07, 2008, 12:50:38 PM »
                    text menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
                    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
                    O8 - Extra context menu item: Snip to my eSnips account - C:\Program Files\eSnips\res\SnipIt.htm
                    O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
                    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O16 - DPF: {00000000-7777-0704-0B53-2C8830E9FAEC} - http://gn.one2bill.de/soft/axload.cab
                    O16 - DPF: {0F9B4CA4-A30F-480A-841D-69B45C50A8F8} (SekureL0gin.SekureKontrol) - http://secure2.comned.com/signuptemplates/AktiveSekurity.cab
                    O16 - DPF: {10000273-8230-4DD4-BE4F-6889D1E74167} - http://download.abetterinternet.com/download/cabs/TURB8106/turbo.cab?id=9478387
                    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                    O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
                    O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} - http://aolcc.aol.com/computercheckup/qdiagcc.cab
                    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
                    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/142f788135cc9313e600/netzip/RdxIE601.cab
                    O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-0b7bc258219bec79.spaces.live.com/PhotoUpload/MsnPUpld.cab
                    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                    O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
                    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{050B8AE2-ABDD-4D1C-908F-C178249252A3}: NameServer = 205.188.146.145
                    O17 - HKLM\System\CS1\Services\Tcpip\..\{050B8AE2-ABDD-4D1C-908F-C178249252A3}: NameServer = 205.188.146.145
                    O23 - Service: AOL Conn
                    Frank

                    franke

                      Topic Starter


                      Intermediate

                      Re: HiJackThis problem
                      « Reply #43 on: March 07, 2008, 12:53:34 PM »
                      Evil
                      there ar 6 posts with this file;they are NOT in order.
                      FrankService: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
                      O23 - Service: AOL Antivirus Update Service (aolavupd) - AOL LLC - C:\Program Files\Common Files\AOL\1102907915\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe
                      O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                      O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
                      O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
                      O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
                      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
                      O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
                      O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                      O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                      O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
                      O24 - Desktop Component 0: (no name) - http://members.members-here.com/matex/ce_mellcybert/1/750/mellcybert004.jpg
                      O24 - Desktop Component 1: (no name) - http://members.members-here.com/matex/ce_mellcybert/1/thumbs/mellcybert004.jpg
                      O24 - Desktop Component 2: (no name) - http://www.accuratereloading.com/953l.jpg

                      --
                      End of file - 11819 bytes
                      Frank

                      franke

                        Topic Starter


                        Intermediate

                        Re: HiJackThis problem
                        « Reply #44 on: March 07, 2008, 01:09:39 PM »
                        evilfantasy
                        I found this "disinstall list"Personal
                        Adobe Download Manager 2.2 (Remove Only)
                        Adobe Flash Player 9 ActiveX
                        Adobe Reader 7.0.9
                        Adobe® Photoshop® Album Starter Edition 3.0
                        AOL Instant Messenger
                        AOL Toolbar 5.0
                        AOL Uninstaller (Choose which Products to Remove)
                        BCM V.92 56K Modem
                        Belarc Advisor 7.2
                        CA Pest Patrol Realtime Protection
                        Canon Camera Access Library
                        Canon Camera Support Core Library
                        Canon Camera Window DC_DV 5 for ZoomBrowser EX
                        Canon Camera Window DC_DV 6 for ZoomBrowser EX
                        Canon Camera Window DSLR 5 for ZoomBrowser EX
                        Canon Camera Window MC 6 for ZoomBrowser EX
                        Canon iP6220D
                        Canon iP6220D Memory Card Utility
                        Canon MovieEdit Task for ZoomBrowser EX
                        Canon PhotoRecord
                        Canon RAW Image Task for ZoomBrowser EX
                        Canon Utilities Easy-PhotoPrint
                        Canon Utilities PhotoStitch 3.1
                        Canon ZoomBrowser EX (E)
                        Chessmaster 8000
                        Classic PhoneTools
                        Dell Digital Jukebox Driver
                        Dell Modem-On-Hold
                        Dell Solution Center
                        Frank