Deucehearts Posted September 6, 2005 Report Share Posted September 6, 2005 (edited) My friends computer is really slow. I tried running Adaware, Spybot and several online scans without any success at all. Everytime I tried running a scan the computer would freeze up and have to be restarted. I was only on the computer for 30 min and pop ups where all over the place. So here is the Hijack log. Help me if you can thanks.Logfile of HijackThis v1.99.1Scan saved at 8:36:01 PM, on 9/5/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeC:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Norton AntiVirus\navapsvc.exeC:\Program Files\Norton AntiVirus\IWP\NPFMntor.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exec:\windows\system32\ibfeqdx.exeC:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exeC:\WINDOWS\system32\NORMANANTIVIRUS.EXEC:\documents and settings\molly\local settings\temp\q4BhRv8.exeC:\windows\system32\p6oM.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\WINDOWS\system32\RUNDLL32.exeC:\windows\system32\ebEyB.exeC:\windows\system32\15BRJLsg.exeC:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exeC:\Program Files\AutoUpdate\AutoUpdate.exeC:\WINDOWS\system32\igmger.exeC:\WINDOWS\system32\r?gsvr32.exeC:\WINDOWS\system32\iearsa16.exeC:\PROGRA~1\AIM\aim.exeC:\WINDOWS\SYSTEM32\ebEyB.exeC:\Program Files\rdso\eetu.exeC:\WINDOWS\system32\QtrgRbne.exeC:\WINDOWS\system32\LnaqyU35.exeC:\Program Files\Aprps\CxtPls.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\LimeWire\LimeWire.exeC:\WINDOWS\system32\cdmweb\iexxathnrd.exeC:\PROGRA~1\MOZILL~1\FIREFOX.EXEC:\Program Files\Messenger\msmsgs.exeC:\Hijackthis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uwlax.edu/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.comR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://pollserver.interpolls.com/cache/hbo...musicmatch.htmlR3 - Default URLSearchHook is missingF2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exeO2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dllO2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\Aprps\plg0\cxtpls.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dllO2 - BHO: (no name) - {63BC0E56-AFAC-E056-BE0E-ED55058EE7A4} - C:\WINDOWS\system32\nnq.dll (file missing)O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\system32\nvms.dllO2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dllO2 - BHO: (no name) - {EF717B91-C20B-BD84-2050-CE09F61122C0} - C:\WINDOWS\system32\entopksa.dllO2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\system32\msbe.dllO2 - BHO: (no name) - {FCCCEE28-7B98-4690-8C5A-083FB8E1E0C8} - C:\WINDOWS\system32\cdmweb\iexxathnrd.dllO2 - BHO: (no name) - {FEE418EA-BC48-FEB0-0E01-F88408AF71A1} - C:\WINDOWS\system32\vdyraudm.dll (file missing)O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exeO4 - HKLM\..\Run: [Norman Antivirus] NORMANANTIVIRUS.EXEO4 - HKLM\..\Run: [q4BhRv8] C:\documents and settings\molly\local settings\temp\q4BhRv8.exeO4 - HKLM\..\Run: [p6oM] C:\windows\system32\p6oM.exeO4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\system32\Cyf0o.exeO4 - HKLM\..\Run: [Wvzp.exe] C:\windows\system32\Wvzp.exeO4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exeO4 - HKLM\..\Run: [EbatesMoeMoneyMaker0] "C:\Program Files\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe"O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMainO4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -uO4 - HKLM\..\Run: [ebEyB.exe] c:\windows\system32\ebEyB.exeO4 - HKLM\..\Run: [15BRJLsg] C:\windows\system32\15BRJLsg.exeO4 - HKLM\..\Run: [WeirdOnTheWeb] "C:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exe"O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exeO4 - HKLM\..\Run: [cqmshny] c:\windows\system32\tyzwef.exeO4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"O4 - HKLM\..\Run: [wssi3nV] igmger.exeO4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exeO4 - HKLM\..\Run: [hghxmtk] c:\windows\system32\ibfeqdx.exe rO4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exeO4 - HKCU\..\Run: [uzmrz] C:\WINDOWS\system32\r?gsvr32.exeO4 - HKCU\..\Run: [hB3sRhZ8T] iearsa16.exeO4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [Aida] C:\Program Files\rdso\eetu.exeO4 - HKCU\..\RunOnce: [Norman Antivirus] NORMANANTIVIRUS.EXEO8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htmO8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.htmlO8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.htmlO8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.htmlO8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.htmlO8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.htmlO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dllO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exeO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)O12 - Plugin for .au: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dllO12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dllO12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dllO12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tri...Transporter.cab?O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildApp.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dllO20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dllO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeO23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeO23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exeO23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exeO23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exeO23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exeO23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeO23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exeO23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exeO23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeO23 - Service: BullGuard XComm (XCOMM) - Unknown owner - C:\WINDOWS\SYSTEM32\xcommsvr.exe (file missing) Edited September 6, 2005 by Deucehearts Quote Link to post Share on other sites
Naming is hard Posted September 6, 2005 Report Share Posted September 6, 2005 0-o shouldn't this be Here Quote Link to post Share on other sites
Deucehearts Posted September 6, 2005 Author Report Share Posted September 6, 2005 can I move this or delete it sorry i posted in wrong section. Quote Link to post Share on other sites
blim Posted September 6, 2005 Report Share Posted September 6, 2005 Deuce, figuring out exactly where to post a question is the hardest part of posting! Don't be sorry, someone will always re-direct you or a Mod will move it for better exposure. My posts have been moved a lot and I haven't gotten yelled at yet (laughed at, lots of times, but not because I posted in the wrong place!)Liz Quote Link to post Share on other sites
Parrotgeek7 Posted September 8, 2005 Report Share Posted September 8, 2005 Normanantivirus, wierdontheweb and cashback/rebates are all spyware programs.disable system restore, boot into safe mode and run add/remove programs an uninstall those 3. Then run your spyware and antivirus again, in safe mode.You can re-enable system restore when you boot back into regular mode and don't see those 3 programs in your HJT log.(I'm not reccomending using HJT to remove them, try uninstalling them first and Google those three apps, there are removal instructions available for them) Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.