Help with spybots (Hijackthis log)

Omatic810Omatic810 Gainesville, FL
edited March 2004 in Science & Tech
I've got a spybot somewhere on my computer that gives me popups every time i start internet explorer, and in 15 minute increments after that. I've used the Spybot S&D scan, and it found a lot of bots, but it didnt fix the problem. Here is the Hijackthis log the program compiled. Thx for the help!

Logfile of HijackThis v1.97.7
Scan saved at 9:15:26 PM, on 3/26/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\kdx\KHost.exe
C:\WINDOWS\SYSTEM32\USRshutA.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Winamp\Winampa.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\PROGRA~1\Keyboard\Ikeymain.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\program files\steam\steam.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\WScript.exe
C:\Program Files\SiSoftware\SiSoftware Sandra Professional 2004.SP1 (Win32 x86)\sandra.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SYSTEM32\notepad.exe
C:\PROGRA~1\Netscape\Netscape\Netscp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\I]some dude's name[/I\Desktop\HijackThis.exe

N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\(your name here)\Application Data\Mozilla\Profiles\default\auvorh25.slt\prefs.js)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [KenKeybd] C:\PROGRA~1\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Search.vbs
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab

Comments

  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited March 2004
    I went through your list and didn't see anything I could spot as malicious. (Lots of unnecessary stuff, but not really a problem).

    Try disabling the "Messenger" service. (Not Windows or MSM.)

    If that doesn't do it I'll look at your list again. :wave:
  • Straight_ManStraight_Man Geeky, in my own way Naples, FL Icrontian
    edited March 2004
    The ATI thing is valid:

    http://www.liutilities.com/products/wintaskspro/processlibrary/ati2evxx/

    inetadpt.dll should be pulled (the O10 entries, ALL FOUR):

    http://www.kephyr.com/spywarescanner/library/targetsoft.inetadpt/index.phtml

    I would get the LATEST Google toolbar, the old one has some tracking functions (which Google DOES use for client-reported rankings mostly and whihc does not report who YOU are to google) that the new one will let you opt out of.

    Unless you use something that needs LDAP, you can get rid of Search.vbs, but some older office suites (and you have one) use LDAP locally for some things. See link below for process info:

    http://www.tburke.net/info/suptools/topics/search.htm

    DS3.cab is Gator Adware, Gator can break without it, I woudl grab teh latest free GetRight or use FTP Voyager instead of Gator.

    Um, err, Media Player 2??? Link:

    http://www.liutilities.com/products/wintaskspro/dlllibrary/msdxm/

    Before we go any further, what version of Windows is running??? It LOOKs like you have an older Windows that has not been security patched, if you can do that, please DO. OR, some older apps that do not need to be around....

    But, most of the things that are MAJOR, I listed here.

    One other thing, the Netscape thing is ok, but I would pull the part about [the name that is now edited out] out of future posts here unless you want your name or a relative's real name advertised. This forum is a public read forum.

    You have MULTIPLE bots and trackers running. I would run SpyBotS&D and AdAware 6.0 also, both updated to latest defs. You might also want to run RegCleaner or Windows Doctor if you have Norton SystemWorks and not just Norton AntiVirus running, looks like some old software entries got left on box.

    John D.-- wishing you the best of luck with this one. Thanks for posting that HijackThis log, it caused me to learn some things while looking stuff up. I like knowing the underside of Windows very well, also Linux and BSD.

    John D.
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited March 2004
    Kill the following:

    O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O4 - Global Startup: Search.vbs
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited March 2004
    ...prof reminds himself that there are two sections to each HJ log... :banghead:
  • Omatic810Omatic810 Gainesville, FL
    edited March 2004
    It worked it WORKED!
    Take THAT, gator.com!! *i HATE gator*

    I realized I had put *somebody's* name up in the log, but I was to lazy to take it down. I also can't upgrade my WinXP because. That's right- because.

    Thanks all, not only did I get my prob fixed, but I know a little more about this.
    I'll be shipping out karma to those who helped.
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited March 2004
    Now, just to be sure, run AdAware... Download the latest definitions first.

    Read the article for links and more info :)
  • DexterDexter Vancouver, BC Canada
    edited March 2004
    Make sure this one is gone:

    O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe

    It belongs to Kontiki, a Browser Helper Object (BHP) spyware program.

    http://www.pestpatrol.com/PestInfo/k/kontiki.asp

    Dexter...
  • LeonardoLeonardo Wake up and smell the glaciers Eagle River, Alaska Icrontian
    edited March 2004
    Moderator Edit: I removed the person's name that was in the log.
  • KwitkoKwitko Sheriff of Banning (Retired) By the thing near the stuff Icrontian
    edited March 2004
    I'd free up some more resources by dumping these as well:
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab (This is spyware. It uses a variant of the VX2 Transponder, a nasty little gremlin. Fortunately, it's detected by Ad-Aware.)

    I noticed you have ATI *and* nVidia programs installed. What kind of video card are you using?
  • Straight_ManStraight_Man Geeky, in my own way Naples, FL Icrontian
    edited March 2004
    Leonardo wrote:
    Moderator Edit: I removed the person's name that was in the log.

    Thanks, I thought that someone might be nice and do that. Thanks for killing it in my post also.

    Note for users who submit logs:

    If you want to pull any personal info from your log, you can do one of two things. Either edit it out after you paste it, in the forum posting editor, or have HijackThis save the log, then edit in Wordpad, then cut (or copy) and paste from Wordpad into the posting editor. You do not have to save the edited file in Wordpad yourself if you do not need it for reference. You can also copy and paste logs from HijackThis into Wordpad if you want.

    Cut: CTRL-X
    Copy: CTRL-C
    Paste: CTRL-V
    (hold down Control (CTRL) key while tapping letter after - and then release BOTh keys-- do NOT type the - key, CTRL-- might do something for one of your applications.)

    Some of our best users started as folks who did not know the DOS cut, copy, and paste keystrokes still worked fine in XP-- for that matter, they work in ALL Windows versions. I use them a LOT.

    John D.
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited March 2004
    Also get rid of this:

    N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\(your name here)\Application Data\Mozilla\Profiles\default\auvorh25.slt\prefs.js)

    But like I said, definitely run an updated adaware scan....
  • Straight_ManStraight_Man Geeky, in my own way Naples, FL Icrontian
    edited March 2004
    Yup, though the free Gator Remover download link on the Gator info link (which actually goes to a SpyHunter trial, AFAIK) I gave will kill Gator and the tagon adware that comes with it also, it has a Gator Remover in it.
  • shwaipshwaip bluffin' with my muffin Icrontian
    edited March 2004
    If you want to use global hotkeys in winamp, I believe you need to have winampa.exe enabled.
  • LeonardoLeonardo Wake up and smell the glaciers Eagle River, Alaska Icrontian
    edited March 2004
    BTW, the "Immunize" function in both Ad-aware and SpywareBlaster work very well. Prevention is even better than cure.
Sign In or Register to comment.