Dan

Members
  • Content Count

    742
  • Joined

  • Last visited

Posts posted by Dan

  1. Logfile of HijackThis v1.98.2

    Scan saved at 8:54:34 PM, on 10/26/04

    Platform: Windows 98 SE (Win9x 4.10.2222A)

    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:

    C:\WINDOWS\SYSTEM\KERNEL32.DLL

    C:\WINDOWS\SYSTEM\MSGSRV32.EXE

    C:\WINDOWS\SYSTEM\SPOOL32.EXE

    C:\WINDOWS\SYSTEM\MPREXE.EXE

    C:\WINDOWS\SYSTEM\MSTASK.EXE

    C:\WINDOWS\SYSTEM\mmtask.tsk

    C:\WINDOWS\EXPLORER.EXE

    C:\WINDOWS\SYSTEM\SYSTRAY.EXE

    C:\WINDOWS\SYSTEM\3DLDEMON.EXE

    C:\WINDOWS\SYSTEM\INTERNAT.EXE

    C:\WINDOWS\TASKMON.EXE

    C:\WINDOWS\LOADQM.EXE

    C:\WINDOWS\RunDLL.exe

    C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE

    C:\WINDOWS\SYSTEM\WMIEXE.EXE

    C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE

    C:\WINDOWS\SYSTEM\RNAAPP.EXE

    C:\WINDOWS\SYSTEM\TAPISRV.EXE

    C:\PROGRAM FILES\ICECHAT5\ICECHAT5.EXE

    C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE

    C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://av.yahoo.com/bin/search?p=%s

    O2 - BHO: Yahoo! Companion BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLL

    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLL

    O4 - HKLM\..\Run: [systemTray] SysTray.Exe

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\Run: [scanRegistry] C:\WINDOWS\scanregw.exe /autorun

    O4 - HKLM\..\Run: [3DLabsHelperDemon] 3dldemon.exe nowakeup

    O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG.EXE -off

    O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp

    O4 - HKLM\..\Run: [internat.exe] internat.exe

    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme

    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe

    O4 - HKLM\..\Run: [LoadQM] loadqm.exe

    O4 - HKLM\..\RunServices: [schedulingAgent] mstask.exe

    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme

    O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY

    O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE

    O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm

    O8 - Extra context menu item: &Highlight - C:\WINDOWS\WEB\highlight.htm

    O8 - Extra context menu item: &Web Search - C:\WINDOWS\WEB\selsearch.htm

    O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm

    O8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htm

    O8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htm

    O8 - Extra context menu item: I&mages List - C:\WINDOWS\Web\imglist.htm

    O8 - Extra context menu item: Download with IDM - C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IEExt.htm

    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE

    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL

    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\NETSCAPE\COMMUNICATOR\PROGRAM\AIM\AIM.EXE

    O9 - Extra button: Flash Movie Extractor Scout LITE - {41A53920-24E8-11D9-9927-00C04F6BEFBB} - C:\PROGRAM FILES\FLASH MOVIE EXTRACTOR SCOUT LITE\flashextract.exe

    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (HKCU)

    O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = ldc.upenn.edu

    O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 128.91.2.13,128.91.254.1,128.91.254.4

  2. Hey everyone; I was wondering if anyone would be interested in making a banner for my site. It should have about the same requirements as B's one. It should blend in with my sites colors too..... And if you can't make a banner, you can just make an icon too.

    Thanks,

    Danny

    BTW: my site is www.freewebs.com/dknoppix

  3. finally got it to work again

    Logfile of HijackThis v1.98.2

    Scan saved at 1:26:50 PM, on 10/14/04

    Platform: Windows 98 SE (Win9x 4.10.2222A)

    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:

    C:\WINDOWS\SYSTEM\KERNEL32.DLL

    C:\WINDOWS\SYSTEM\MSGSRV32.EXE

    C:\WINDOWS\SYSTEM\MPREXE.EXE

    C:\WINDOWS\SYSTEM\MSTASK.EXE

    C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE

    C:\WINDOWS\SYSTEM\mmtask.tsk

    C:\WINDOWS\EXPLORER.EXE

    C:\WINDOWS\SYSTEM\SYSTRAY.EXE

    C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE

    C:\WINDOWS\SYSTEM\3DLDEMON.EXE

    C:\WINDOWS\SYSTEM\INTERNAT.EXE

    C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE

    C:\WINDOWS\TASKMON.EXE

    C:\WINDOWS\LOADQM.EXE

    C:\WINDOWS\RunDLL.exe

    C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE

    C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE

    C:\WINDOWS\SYSTEM\WMIEXE.EXE

    C:\WINDOWS\SYSTEM\RNAAPP.EXE

    C:\WINDOWS\SYSTEM\TAPISRV.EXE

    C:\PROGRAM FILES\ICECHAT5\ICECHAT5.EXE

    C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://av.yahoo.com/bin/search?p=%s

    O2 - BHO: Yahoo! Companion BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLL

    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLL

    O4 - HKLM\..\Run: [systemTray] SysTray.Exe

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\Run: [scanRegistry] C:\WINDOWS\scanregw.exe /autorun

    O4 - HKLM\..\Run: [3DLabsHelperDemon] 3dldemon.exe nowakeup

    O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG.EXE -off

    O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp

    O4 - HKLM\..\Run: [internat.exe] internat.exe

    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme

    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP

    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe

    O4 - HKLM\..\Run: [LoadQM] loadqm.exe

    O4 - HKLM\..\RunServices: [schedulingAgent] mstask.exe

    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme

    O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe

    O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY

    O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE

    O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm

    O8 - Extra context menu item: &Highlight - C:\WINDOWS\WEB\highlight.htm

    O8 - Extra context menu item: &Web Search - C:\WINDOWS\WEB\selsearch.htm

    O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm

    O8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htm

    O8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htm

    O8 - Extra context menu item: I&mages List - C:\WINDOWS\Web\imglist.htm

    O8 - Extra context menu item: Download with IDM - C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IEExt.htm

    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE

    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL

    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\NETSCAPE\COMMUNICATOR\PROGRAM\AIM\AIM.EXE

    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (HKCU)

    O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = ldc.upenn.edu

    O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 128.91.2.13,128.91.254.1,128.91.254.4

  4. yes i checked my BIOS and it said: Diskette Drive 0 seak falure.......

    i think that means it's broken... and i have moved it to get to the usb connector in the back.....and i have opened it to try to put in an old HD in... my pc is crap!! and it runs on scsi but works fine...i dont think ill get a cleaner anytime soon because my mom wont pay for it....

    tell me what you think,

    danny

  5. NOW I"M MAD!!!!!!!!! My internet is now f***ing with me now.... first after i took out some spyware, it works, then i have to call my mom and it logs in, but wont allow me to access the site!!! Did i mention I'M SO FRICKIN' MAD!!! Can someone please tell me whats going on?? I'm on dial up 56k. i downloaded CWS shredder, HJT and spybot when i had the chance....

    PLEASE HELP!!!

    DANNY

  6. Hey Everyone.... Here is my HJT log, and I was just infected w/ some spyware and was wondering if there is still something left:

    Logfile of HijackThis v1.98.2

    Scan saved at 2:07:42 PM, on 10/11/04

    Platform: Windows 98 SE (Win9x 4.10.2222A)

    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:

    C:\WINDOWS\SYSTEM\KERNEL32.DLL

    C:\WINDOWS\SYSTEM\MSGSRV32.EXE

    C:\WINDOWS\SYSTEM\MPREXE.EXE

    C:\WINDOWS\SYSTEM\MSTASK.EXE

    C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE

    C:\WINDOWS\SYSTEM\mmtask.tsk

    C:\WINDOWS\EXPLORER.EXE

    C:\WINDOWS\SYSTEM\SYSTRAY.EXE

    C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE

    C:\WINDOWS\SYSTEM\3DLDEMON.EXE

    C:\WINDOWS\SYSTEM\INTERNAT.EXE

    C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE

    C:\WINDOWS\TASKMON.EXE

    C:\WINDOWS\LOADQM.EXE

    C:\WINDOWS\RunDLL.exe

    C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE

    C:\WINDOWS\SYSTEM\WMIEXE.EXE

    C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://av.yahoo.com/bin/search?p=%s

    O2 - BHO: Yahoo! Companion BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLL

    O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\PROGRAM FILES\WEBHANCER\PROGRAMS\WHIEHLPR.DLL (file missing)

    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLL

    O4 - HKLM\..\Run: [systemTray] SysTray.Exe

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\Run: [scanRegistry] C:\WINDOWS\scanregw.exe /autorun

    O4 - HKLM\..\Run: [3DLabsHelperDemon] 3dldemon.exe nowakeup

    O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG.EXE -off

    O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp

    O4 - HKLM\..\Run: [internat.exe] internat.exe

    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme

    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP

    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe

    O4 - HKLM\..\Run: [LoadQM] loadqm.exe

    O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"

    O4 - HKLM\..\Run: [webHancer Agent] "C:\Program Files\webHancer\Programs\whAgent.exe"

    O4 - HKLM\..\RunServices: [schedulingAgent] mstask.exe

    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme

    O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe

    O4 - HKLM\..\RunServices: [KPF4] C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe

    O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY

    O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE

    O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm

    O8 - Extra context menu item: &Highlight - C:\WINDOWS\WEB\highlight.htm

    O8 - Extra context menu item: &Web Search - C:\WINDOWS\WEB\selsearch.htm

    O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm

    O8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htm

    O8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htm

    O8 - Extra context menu item: I&mages List - C:\WINDOWS\Web\imglist.htm

    O8 - Extra context menu item: Download with IDM - C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IEExt.htm

    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE

    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL

    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\NETSCAPE\COMMUNICATOR\PROGRAM\AIM\AIM.EXE

    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (HKCU)

    O10 - Hijacked Internet access by WebHancer

    O10 - Hijacked Internet access by WebHancer

    O10 - Hijacked Internet access by WebHancer

    O10 - Hijacked Internet access by WebHancer

    O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing

    O16 - DPF: {AFDBB6D0-6B96-419C-8BC6-FF0B99368C0B} - http://www.totalvelocity.com/MemoryMeterbb.cab

    O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = ldc.upenn.edu

    O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 128.91.2.13,128.91.254.1,128.91.254.4