Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

spyware


  • This topic is locked This topic is locked

#1
slut

slut

    New Member

  • Member
  • Pip
  • 1 posts
StartupList report, 03/02/2005, 10:19:06 AM
StartupList version: 1.52.2
Started from : C:\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\WDA3CD27\HIJACKTHIS[1].EXE
Detected: Windows ME (Win9x 4.90.3000)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================

Running processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\P2P NETWORKING\P2P NETWORKING.EXE
C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.EXE
C:\PROGRAM FILES\COMMON FILES\GMT\GMT.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
D:\PROGRAM FILES\WEBSHOTS\WEBSHOTSTRAY.EXE
C:\PROGRAM FILES\SYMPATICO\ACCESS MANAGER\APP\ENTERNET.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\WDA3CD27\HIJACKTHIS[1].EXE

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\WINDOWS\Start Menu\Programs\StartUp]
GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
Webshots.lnk = D:\Program Files\Webshots\WebshotsTray.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
SystemTray = SysTray.Exe
MSConfigReminder = C:\WINDOWS\SYSTEM\msconfig.exe /reminder
Symantec NetDriver Monitor = C:\PROGRA~1\SYMNET~1\SNDMON.EXE
P2P NETWORKING = C:\WINDOWS\SYSTEM\P2P NETWORKING\P2P NETWORKING.EXE /AUTOSTART
CMESys = "C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.EXE"

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

ccEvtMgr = "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
ScriptBlocking = "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
SchedulingAgent = mstask.exe

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Tsa2 = C:\PROGRAM FILES\COMMON FILES\TSA\TSM2.EXE

--------------------------------------------------

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = C:\WINDOWS\NOTEPAD.EXE %1

--------------------------------------------------

C:\AUTOEXEC.BAT listing:

SET windir=C:\WINDOWS
SET winbootdir=C:\WINDOWS
SET COMSPEC=C:\WINDOWS\COMMAND.COM
SET PATH="C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier";C:\WINDOWS\TEMP;C:\WINDOWS\TEMP;C:\WINDOWS;C:\WINDOWS\COMMAND;C:\PROGRA~1\ULTRAE~1;C:\PROGRA~1\ZONELA~1\ZONEAL~1\tools;"C:\Program Files\Common Files\Roxio Shared\DLLShared"
SET PROMPT=$p$g
SET TEMP=C:\WINDOWS\TEMP
SET TMP=C:\WINDOWS\TEMP

--------------------------------------------------

C:\WINDOWS\WINSTART.BAT listing:

C:\WINDOWS\tmpcpyis.bat

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}
(no name) - c:\program files\google\googletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\PROGRAM FILES\SIDEFIND\SFBHO.DLL - {A3FDD654-A057-4971-9844-4ED8E67DBBB8}
(no name) - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
(no name) - C:\PROGRAM FILES\MSN APPS\ST\01.02.3000.1002\EN-XU\STMAIN.DLL - {9394EDE7-C8B5-483E-8773-474BF36AF6E4}

--------------------------------------------------

Enumerating Task Scheduler jobs:

Tune-up Application Start.job
Symantec NetDetect.job
Norton AntiVirus - Scan my computer.job
Maintenance-Defragment programs.job
Maintenance-ScanDisk.job
Maintenance-Disk cleanup.job
PCHealth Scheduler for Data Collection.job

--------------------------------------------------

Enumerating Download Program Files:

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://download.macr...ash/swflash.cab

[QuickTime Object]
InProcServer32 = C:\WINDOWS\SYSTEM\QTPLUGIN.OCX
CODEBASE = http://www.apple.com...ex/qtplugin.cab

[MSN Chat Control 4.5]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\MSNCHAT45.OCX
CODEBASE = http://chat.msn.com/bin/msnchat45.cab

[YInstStarter Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YINSTHELPER.DLL
CODEBASE = http://download.yaho...s/yse/yinst.cab

[Yahoo! Audio Conferencing]
InProcServer32 = C:\WINDOWS\DOWNLO~1\CONFLICT.2\YACSCOM.DLL
CODEBASE = http://jcs.chat.dcn....v45/yacscom.cab

[Web P2P Installer]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\WEBP2PINSTALLER.DLL

[StarInstall Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\STARIN~1.OCX
CODEBASE = http://install.premi...StarInstall.ocx

[EURAS_Portal.Gateway]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\EURAS.OCX
CODEBASE = http://www.euras.com...ivex2/euras.CAB

[IBM Access Support]
InProcServer32 = C:\WINDOWS\DOWNLO~1\IBMEGATH.DLL
CODEBASE = https://www.pc.ibm.c...er/IbmEgath.cab

[Installer Class]
InProcServer32 = C:\WINDOWS\DOWNLO~1\ISTACT~1.DLL
CODEBASE = http://www.xxxtoolba...006_regular.cab

[Installer Class]
InProcServer32 = C:\WINDOWS\DOWNLO~1\YSBACT~1.DLL
CODEBASE = http://www.ysbweb.co...ysb_regular.cab

[{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\WINTASKADX.DLL
CODEBASE = http://public.windup...1f64dc3f0db6853

[DeviceEnum Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\HPBASICDETECTION3.DLL
CODEBASE = http://h20270.www2.h...cdetection3.cab

[QDiagHUpdateObj Class]
InProcServer32 = C:\WINDOWS\SYSTEM\QDIAGH.OCX
CODEBASE = http://h30043.www3.h.../qdiagh.cab?326

--------------------------------------------------
End of report, 7,205 bytes
Report generated in 0.150 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Thankx you guyz are the best..
  • 0

Advertisements


#2
Dragon

Dragon

    All Around Computer Nut

  • Retired Staff
  • 2,682 posts
Welcome to Geeks to Go,

Did you follow the recomendations here?

As there has been no response from the original poster, this topic is now closed. If you have any other problems, please post a new topic.

Edited by bananafanafo, 24 April 2005 - 01:48 AM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP