domingus Posted October 27, 2004 Report Share Posted October 27, 2004 Chappy or anyone, Here's my HiJackThis log. I don't know what to fix.Thanks for the helpLogfile of HijackThis v1.98.2Scan saved at 8:05:05 PM, on 10/26/2004Platform: Windows XP (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 (6.00.2600.0000)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\LEXBCES.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\LEXPPS.EXEC:\Compaq\eakdrv\STARTDRV.exeC:\WINDOWS\System32\pctspk.exeC:\Compaq\eakdrv\EAKDRV.exeC:\WINDOWS\System32\taskswitch.exeC:\Program Files\RAM Idle\RAMIdle.exeC:\Program Files\BroadJump\Client Foundation\CFD.exeC:\Program Files\Support.com\bin\tgcmd.exeC:\Compaq\eakdrv\EAUSBKBD.EXEC:\Program Files\Yahoo!\browser\ybrwicon.exeC:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exeC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exeC:\Program Files\BillP Studios\WinPatrol\winpatrol.exeC:\PROGRA~1\Yahoo!\browser\ycommon.exeC:\Program Files\Zone Labs\ZoneAlarm\zlclient.exeC:\WINDOWS\System32\ctfmon.exeC:\Program Files\GetRight\getright.exeC:\Program Files\SBC\Connection Manager\CManager.exeC:\Program Files\SpywareGuard\sgmain.exeC:\Program Files\Webshots\WebshotsTray.exeC:\Program Files\SpywareGuard\sgbhp.exeC:\PROGRA~1\BROADJ~1\CORREC~1\CCD.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\ZoneLabs\vsmon.exeC:\WINDOWS\System32\Fast.exeC:\Program Files\HiJackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jsonline.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dslR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dslR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AT&T WorldNet ServiceR3 - Default URLSearchHook is missingO2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [CPQEASYACC] C:\Compaq\eakdrv\STARTDRV.exeO4 - HKLM\..\Run: [PCTVOICE] pctspk.exeO4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exeO4 - HKLM\..\Run: [FastUser] C:\WINDOWS\System32\fast.exeO4 - HKLM\..\Run: [RAM Idle] C:\Program Files\RAM Idle\RAMIdle.exeO4 - HKLM\..\Run: [bJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exeO4 - HKLM\..\Run: [tgcmdprovidersbc] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor /deaf /nosystrayO4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exeO4 - HKLM\..\Run: [iPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exeO4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeO4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exeO4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exeO4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exeO4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exeO4 - Startup: Connection Manager.lnk = C:\Program Files\SBC\Connection Manager\CManager.exeO4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exeO4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exeO4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htmO8 - Extra context menu item: Download with GetRight - C:\PROGRA~1\GetRight\GRdownload.htmO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O8 - Extra context menu item: Open with GetRight Browser - C:\PROGRA~1\GetRight\GRbrowse.htmO8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htmO8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htmO9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dllO9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dllO9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dllO9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dllO9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{06B05BAC-58F8-490D-A4A1-342AAFDC79D6}: NameServer = 65.43.19.26 206.141.192.60O17 - HKLM\System\CS1\Services\Tcpip\..\{06B05BAC-58F8-490D-A4A1-342AAFDC79D6}: NameServer = 65.43.19.26 206.141.192.60 Link to post Share on other sites
Racktracker Posted October 27, 2004 Report Share Posted October 27, 2004 Not really much in the way of problems in your log. Run another hijackthis scan. Place a check next to the following entries, then close all other windows and click the fix button.R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR3 - Default URLSearchHook is missing Link to post Share on other sites
thesidekickcat Posted October 27, 2004 Report Share Posted October 27, 2004 I am not sure if this is any help or not.I scanned with Spybot just after getting off the internet last night and came up clean. Today I logged on and then came over here, found a notice from someone that Spybot had an update, so I got it, did another scan, and it came up with this:"Error during check!: Cabrotor (Datei C:\WINNT\win.ini kann nicht geöffnet werden. The process cannot access the file because it is being used by another process) ()Congratulations!: No immediate threats were found. ()"So it appears to be an error of some kind. It still comes up with same thing on additional scans. I don't know if that is any help or not. I would like to hear if anyone else is getting the same thing.I am sorry if this is the wrong place to put this but thought it might be pertinent.P.S. My Norton scans come up clean. So could this just be a Spybot S+D error or false positive?God bless everyone. Link to post Share on other sites
domingus Posted October 27, 2004 Author Report Share Posted October 27, 2004 Hi RackTracker,I'm not home now, so I'll do this when I get there.I'm curious as to why Yahoo is in need of fixes. Oh well.Thanks. Link to post Share on other sites
domingus Posted October 27, 2004 Author Report Share Posted October 27, 2004 I am not sure if this is any help or not.I scanned with Spybot just after getting off the internet last night and came up clean. Today I logged on and then came over here, found a notice from someone that Spybot had an update, so I got it, did another scan, and it came up with this:"Error during check!: Cabrotor (Datei C:\WINNT\win.ini kann nicht geöffnet werden. The process cannot access the file because it is being used by another process) ()Congratulations!: No immediate threats were found. ()"So it appears to be an error of some kind. It still comes up with same thing on additional scans. I don't know if that is any help or not. I would like to hear if anyone else is getting the same thing.I am sorry if this is the wrong place to put this but thought it might be pertinent.God bless everyone. Wow - I'm glad to know that it's just not happening to me.I wonder if they goofed up again in their update.Thanks thesidekickcat.Take care Link to post Share on other sites
domingus Posted October 27, 2004 Author Report Share Posted October 27, 2004 Hi thesidekickcat,Just wanted you to know that todays update took care of the Cabrotor error message. After the update today, I ran the scan and it was all clear.It appears yesterday's update was an "ooops".Take care. Link to post Share on other sites
thesidekickcat Posted October 27, 2004 Report Share Posted October 27, 2004 Thanks for letting me know it was Spybot S and D's error. Whew!!! And I am sorry for butting in on your HJT log thread (yes I do know better ), but it just felt like something should would have shown up in your log if this threat had been for real. So I was adding my little bit in case there was another reason for this thing. I did another scan after today's Norton antivirus update and came up clean again, as well as updated Spybot and scanned again. Clean!!! Whew!!! Sure a big relief to find it wasn't something invading our computers. My Norton warns me every now and then, even as recently as night before last, that a trojan is attempting entry and it is being blocked. And that is with a dial up connection!!!! Seriously I think my blood pressure would be lower if I wasn't always trying so hard to stay safe and keep everything working right. God bless everyone. Link to post Share on other sites
Dragon Posted November 12, 2004 Report Share Posted November 12, 2004 Hi RackTracker,I'm not home now, so I'll do this when I get there.I'm curious as to why Yahoo is in need of fixes. Oh well.Thanks.hi there, in reference to your question dealing with the Yahoo entries, the RedClientsApp section is the concern, Red Clients is a form of spyware. it tracks the websites you go to so that spam can be sent to your email account that is on record with Yahoo. By fixing these entries, it removes the red client app, but keeps your homepage set to Yahoo like you want. Link to post Share on other sites
Recommended Posts