Thanks for the link, Chris. I finally got HijackThis running. I thought
TrojanHunter cleared everything up, but I upgraded to Ad-aware SE from
vers.
6, and it found another 115 problems! Then, while going to your link, the
124787.exe problem popped up again. Anyway, here's my log, and thanks
again.
Logfile of HijackThis v1.98.2
Scan saved at 12:50:12 AM, on 10/13/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINNT\System32\CTHELPER.EXE
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\ABIT\ABIT uGuru\uGuru.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
E:\Tclock229B\TClock.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINNT\system32\CTsvcCDA.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\wdfmgr.exe
C:\WINNT\system32\ZONELABS\vsmon.exe
C:\Program Files\Crazy Browser\Crazy Browser.exe
E:\WebDL\hijackthis\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant =
C:\WINNT\_s.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant =
C:\WINNT\_s.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) =
C:\WINNT\_s.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) =
C:\WINNT\_s.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
C:\WINNT\_h.html
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
C:\WINNT\_h.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://www.maine.rr.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {7E1085A1-2C34-73B4-491E-102D04E21E28} -
C:\WINNT\Tniebhaj.dll
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} -
C:\WINNT\System32\mscb.dll (file missing)
O2 - BHO: (no name) - {ED43DCA8-E45D-2AA2-C95C-168AEB0EDED2} -
C:\WINNT\Tniebhaj.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Search - {1F7B105E-1FA1-666D-B548-4FB5CB236CDC} -
C:\WINNT\Tniebhaj.dll
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround
Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program
Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINNT\UpdReg.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ABIT uGuru] C:\Program Files\ABIT\ABIT uGuru\uGuru.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone
Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter
4.0\THGuard.exe"
O4 - HKCU\..\Run: [winltmpv] c:\winnt\system32\winln.exe
O4 - HKCU\..\Run: [RemoteCenter] C:\Program
Files\Creative\MediaSource\RemoteControl\RcMan.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"
/background
O4 - Startup: TClock.lnk = E:\Tclock229B\TClock.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program
Files\Stardock\ObjectDock\ObjectDock.exe
O9 - Extra button: Corel Network monitor worker -
{280EAB85-B650-4766-AAA2-BA03D65B2E47} - (no file)
O9 - Extra 'Tools' menuitem: Corel Network monitor worker -
{280EAB85-B650-4766-AAA2-BA03D65B2E47} - (no file)
O9 - Extra button: Your PC is infected with Spyware - click here to fix
your
PC - {FB74C951-ACA1-4e33-A94C-A9261EB2CCB7} -
https://www.spydeleter.com/order2.php?KBID=1062 (file missing)
O9 - Extra button: Corel Network monitor worker -
{280EAB85-B650-4766-AAA2-BA03D65B2E47} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Corel Network monitor worker -
{280EAB85-B650-4766-AAA2-BA03D65B2E47} - (no file) (HKCU)
O12 - Plugin for .pdf: C:\Program Files\Internet
Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O16 - DPF: ppctlcab -
http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://public.windupdates.com/get_f...13b668fec7d7:270d2288487988400edd713985bb0eab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13}
(PPSDKActiveXScanner.MainScreen) -
http://69.44.122.156/scanner/axscanner.cab
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} -
http://download.overpro.com/WildApp.cab
O18 - Protocol: start - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} -
%SystemRoot%\System32\mshtml.dll (file missing)
Gary
--
Tweaks & Reviews
www.slottweak.com
Chris said: