"bri"
Topic_Title:
"HJT-Log"
Topic_Description:
"possible_CmosBattery+possible_dialupConnect_probs"
This is my very 2nd (second) issue with the g2g team/staff..
This time, another WIN98SE Malware-Removal issue: my backup school work-study computer.
I've had some problems that may suggest the machine may need the cmos battery replaced: the clock has been acting up in various ways (from both being unplugged and while remaining plugged) as well as (though i'm unsure if related) new power management setting profiles refusing to remain saved.. and regarding the clock, sometimes it will be unplugged for about 20 min or so, and that's the total time lost when replugged back in at another locale (as i have been doing malware removal up on campus and have been toting the machine up onto campus for most of the downloads). I have a replacement battery lined up at a local store whose technician is currently tracking down a mobo upgrade for my original pc (primary school work-study computer), which they are willing to sell for five dollars, but the jury is still out as to whether i need the battery or not. I am curious what the opinion will be of the geeks to go staff member who decides to help me.
Regarding the connection problem: it seems i've been having dialup problems on 2 or 3 pc machines which i have been doing malware removal on, this year, from home (as opposed to ethernet connection to the school's lan right now, on those days which i am up on campus with the pc). These three machines have all had varying degrees of problems from time to time when connecting via 56k modem dialup from home, and all three having three differing types of modems, but all three running win98se, and connecting to the school's network via dialup. The most recent difficulty i have experienced, is that, i can connect to sites such as msn's entertainment tv guide listings, or to google for web browsing searches, but!.. i am completely unable to connect up on campus to the few major sites therein which i tried (again, mind you, using dialup networking modem connection on win98se from 56k modem dialup from home). Please Help! Also, I will be trying to take my machine up to the OIT department to see if they can fix it directly from there. (I've struck out on the cs campus though, as the student computer support team member found little to help me with there at the scst office, as they have no more dialup connections from that campus - it's all voip or something else or other, not sure, sorry: regardless though, it's not normal dialup any more up here).
Finally, I would just like to know if any of the above issues could be explained via any possible malware that may yet remain on my (this) machine, and what you would suggest:
I've provided the HJT here-in, bottom (below), and as for the "start_here" page, everything seemed to go off ok, i hope: aaw removed a ton of stuff, and avg found a bunch of warnings of things i had previously put on my own system myself, with a little c programming and a bat file i wrote - some possible false positives all of my own doing (?perhaps?). However, as for the rest of the malware removal, if i'm remembering correctly: i ran both housecall (which came up empty - no infected files) and activescan (which came up with 7 objects of spyware and 1 object of adware) which were Not disinfected.
I kept logs of everything and as with my last case, i endeavored to do all instructions in the order in which they were prescribed, again, as per the "start_here" page.
One thing notable is that i've recently reinstalled win98se on this machine, but the errors i received, i'm told by the scst team here (student computer support team), should Not have anything to do with the problems i'm experiencing: i eliminated the anti-virus faults by re-installing again from win98se startup disk clean-bootup method; and 2nd of three errors regards having a 5.25" floppy drive connected when win98se setup is looking to create a startup disk and thereby getting drive errors writing to A: and finding a 5.25" there; and lastly, third of three errors, ..
c:\Program Files\Common Files\SYSTEM\wab32.dll
..was reported at the end of both reinstalls also (in addition to the startup disk creation error), as being wrongly installed or possibly corrupted, but again, scst reported that this dll has to do with windows outlook express address book files or some such, and i dont use any sort of local email, other than webmail (via ie6 or netscape 4.77) from hotmail and also a custom client for the school, via the webfront, from time to time (otherwise i read my mail from a telnet or ssh (putty) client from one of my school unix/linux accounts).
<-SNIP->
Logfile of HijackThis v1.99.1
Scan saved at 11:18:43 PM, on 10/25/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\ACCSTAT.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\ptsnoop.exe
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\MIXER.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\MY DOCUMENTS\_G2G\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.worldnet....arch/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape...nsearch200.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AT&T WorldNet Service
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.199.57.33:8080
F1 - win.ini: load=ptsnoop.exe
N1 - Netscape 4: user_pref("browser.startup.homepage", "about:blank"); (C:\Program Files\Netscape\Users\User00\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [ALiUSBfix] C:\WINDOWS\SYSTEM\GREENMK.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakLogon
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: AOL Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE (file missing)
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredim...er/imloader.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real...ArcadeRdxIE.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/...aploader_v5.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab32846.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/z...s/heartbeat.cab
O16 - DPF: {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo Control) - http://www.sis.com/ocis/OSInfo.cab
O16 - DPF: {BA549C46-AD38-11D7-A476-00D0590EC9DE} (SiS_OCX98 Control) - http://www.sis.com/o...utodetect98.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
Edited by bri, 25 October 2005 - 10:58 PM.