Archived from groups: microsoft.public.windowsxp.help_and_support (
More info?)
Logfile of HijackThis v1.99.1
Scan saved at 19:19:02, on 14/09/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Messenger\msmsgs.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\FTPExpert\FTPXpert.exe
C:\Program Files\Microsoft Office\Office\FRONTPG.EXE
C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Paint Shop Pro.exe
C:\DOCUME~1\chrissy\LOCALS~1\Temp\Temporary Directory 1 for
HijackThis.zip\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} -
c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe"
/checktask
O4 - HKLM\..\Run: [VirusScan Online]
"c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus!
3\MsgPlus.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"
/background
O8 - Extra context menu item: &Google Search - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program
Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\MSMSGS.EXE
O9 - Extra button: Messenger Addon -
{FB5F1911-F110-11d2-BB9E-00C04F795683} -
http://messenger.ipfox.com (file
missing)
O9 - Extra 'Tools' menuitem: &Messenger Addon -
{FB5F1911-F110-11d2-BB9E-00C04F795683} -
http://messenger.ipfox.com (file
missing)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} (MaxisHotDateTeleX
Control) -
http://thesims.ea.com/teleport/hotdate/MaxisHotDateTeleX.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage
Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan
Control) -
http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating
System Class) -
http://download.mcafee.com/molbin/shared/mcinsctl/en-gb/4,0,0,83/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by15fd.bay15.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) -
http://www.my-etrust.com/Support/PestScanner/pestscan.cab
O16 - DPF: {5D1E3FA5-64FF-4387-9418-F1D67AFB2247} (MaxisSuperstarTeleX
Control) -
http://thesims.ea.com/teleport/superstar/MaxisSuperstarTeleX.cab
O16 - DPF: {63DF43C2-469A-41F3-B119-17B1ACE8BB34} (Sony SNC-RZ30 Image
Viewer) -
http://64.119.5.59/home/SonySncRz30View.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1126716994206
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
http://www3.ca.com/virusinfo/webscan.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) -
http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {A44B714B-EE0F-453E-9300-A69B321FEF6C} (MaxisSimsFamilyTeleX
Control) -
http://thesims.ea.com/teleport/families/MaxisSimsFamilyTeleX.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://download.mcafee.com/molbin/shared/mcgdmgr/en-gb/1,0,0,20/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4576/mcfscan.cab
O20 - AppInit_DLLs: MsgPlusLoader.dll
O23 - Service: McAfee.com McShield (McShield) - Unknown owner -
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee,
Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) -
Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: SmartLinkService (SLService) - -
C:\WINDOWS\SYSTEM32\slserv.exe
There is one thing that noticed in MSCONFIG / startup There is a blank
space added but the location is
SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN
I know this is a new entry as I often check my start up list. Could this be
something?
Thanks
Chris
"pcbutts1" <pcbutts1@seedsv.com> wrote in message
news:Is_Ve.2007$Op3.1573@newssvr25.news.prodigy.net...
> No it will not. It is safe.
>
> --
>
>
> The best live web video on the internet
http://www.seedsv.com/webdemo.htm
> NEW Embedded system W/Linux. We now sell DVR cards.
> See it all at
http://www.seedsv.com/products.htm
> Sharpvision simply the best
http://www.seedsv.com
>
>
>
> "Katie" <anonymous@discussions.microsoft.com> wrote in message
> news:eZUJ9pVuFHA.4080@TK2MSFTNGP12.phx.gbl...
>> How safe is it to copy and paste my hijack file here?
>> Will the info that I show here in any way compromise my security more?
>> Thanks
>> Chris
>>
>> "Katie" <anonymous@discussions.microsoft.com> wrote in message
>> news:eMvbPgVuFHA.1028@TK2MSFTNGP12.phx.gbl...
>>>I tried both these programs last night, I also tried so many different
>>>programs for spyware and viruses that i had added about 7 new programs
>>>onto my laptop. I didnt want all these extra programs at once and as I
>>>didnt know which was the best to keep I went back to my original Adaware
>>>and Mcafee the Google tool bar which stops popups.. Up until now (for the
>>>past 5 years) I have been able to stop most of the annoying problems
>>>(such as this current one) from my laptop, but this one beats me.
>>> Sorry I didnt keep the log files and it didnt cure my problem. But maybe
>>> I will try again and with your help we can get shot of this problem.
>>> I really am grateful to you for taking the trouble to try and help.
>>> Thanks
>>> Chris
>>> "pcbutts1" <pcbutts1@seedsv.com> wrote in message
>>> news:0gZVe.830$5n4.154@newssvr29.news.prodigy.net...
>>>> Use these 2 programs and post your HJT log please.
>>>>
>>>> Ewido Security Suite Trial version
>>>>
http://www.pcbutts1.com/downloads/ewidosetup.exe
>>>>
>>>>
>>>> If none of the above fixes the issue then download Hijack this, run it,
>>>> save a copy of the log file and cut and paste it back here to this
>>>> group so that I can analyze it. Ignore anyone especially the troll
>>>> Leythos, who will tag along a nonsense post to this message, who tells
>>>> you to post it elsewhere. I need to see it not them.
>>>>
>>>>
>>>> HijackThis
>>>>
http://www.pcbutts1.com/downloads/HijackThis.zip
>>>>
>>>>
>>>>
>>>> --
>>>>
>>>>
>>>> The best live web video on the internet
>>>>
http://www.seedsv.com/webdemo.htm
>>>> NEW Embedded system W/Linux. We now sell DVR cards.
>>>> See it all at
http://www.seedsv.com/products.htm
>>>> Sharpvision simply the best
http://www.seedsv.com
>>>>
>>>>
>>>>
>>>> "Katie" <anonymous@discussions.microsoft.com> wrote in message
>>>> news:ee2kL0UuFHA.3424@tk2msftngp13.phx.gbl...
>>>>>I have done a thorough spyware test and so many different virus checks,
>>>>>I have done reg cleaning but still I have this problem. Nothing can
>>>>>detect what this thing is and more to the point how to make it go away.
>>>>> So far this has only affected one website and now I have been able to
>>>>> get around that issue by going to a different part of the website (a
>>>>> sub page) and accessing it through that.
>>>>> Good luck for you and I hope some kind person will be able to help
>>>>> solve this problem.
>>>>>
>>>>> <anthonyyates@btinternet.com> wrote in message
>>>>> news:1126711124.878616.168320@f14g2000cwb.googlegroups.com...
>>>>>> If you read all the posts you'll see its got nothing to do with a web
>>>>>> site owner paying the bill. If it was that simple I would not be
>>>>>> asking
>>>>>> for help.
>>>>>> It's various web sites, one example is www.theaa.com, but it has
>>>>>> nothing to do with them not paying the bill as the site works fine
>>>>>> from
>>>>>> other computers. For some reason certain web sites seem to be
>>>>>> redirected to this page saying the web site has been suspended. I've
>>>>>> seen others report the same issue on some other posts but no solution
>>>>>> found yet.
>>>>>>
>>>>>
>>>>>
>>>>
>>>>
>>>
>>>
>>
>>
>
>