FIRE! FIRE! HELP!!!!!!!!!!!!

W

Waltc

Now that I got someone's attention could you please help
me if you know how to interpret this data. I had posted
a request earlier this week, and one respondent said to
post my "HIjack this" log. I did so, but then they never
replied back after I posted it. The problem I'm having
is unstopppable "pop-ups". I have Google tool bar, and
another anti-pop-up loaded, but they just keep coming!
My firewall is enabled in XP also! ??????????

Logfile of HijackThis v1.97.7
Scan saved at 3:29:15 PM, on 7/15/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\APC\APC PowerChute Personal
Edition\mainserv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common files\WinTools\WToolsS.exe
C:\WINDOWS\System32\BRMFRSMG.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common files\WinTools\WToolsA.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\WinTools\WSup.exe
C:\Program Files\Logitech\MouseWare\System\Em_exec.exe
C:\Documents and Settings\Walter\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Bar =
http://www.websearch.com/ie.aspx?tb_id=50038
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page = http://www.foxnews.com/
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =
http://www.websearch.com/ie.aspx?tb_id=50038
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,SearchAssistant =
http://www.websearch.com/ie.aspx?tb_id=50038
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-
3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-
3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-
CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-
FADC6B084872} - C:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-
7859DF00B1D6} - C:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-
009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common
files\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common
Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common
Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1
\NORTON~1\AdvTools\ADVCHK.EXE
O4 - Global Startup: Opera.lnk = C:\Program Files\Opera75
\opera.exe
O4 - Global Startup: Read Me.lnk = C:\Program
Files\Opera75\Readme.txt
O4 - Global Startup: Software License Agreement.lnk =
C:\Program Files\Opera75\License.txt
O8 - Extra context menu item: &Google Search -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://imgfarm.com/images/nocache/funwebproducts/ei/PopSwa
tterInitialSetup1.0.0.8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
(Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/sw
flash.cab
 
P

Peter Jam

Waltc said:
Now that I got someone's attention could you please help
me if you know how to interpret this data. I had posted
a request earlier this week, and one respondent said to
post my "HIjack this" log. I did so, but then they never
replied back after I posted it. The problem I'm having
is unstopppable "pop-ups". I have Google tool bar, and
another anti-pop-up loaded, but they just keep coming!
My firewall is enabled in XP also! ??????????

Logfile of HijackThis v1.97.7
Scan saved at 3:29:15 PM, on 7/15/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\APC\APC PowerChute Personal
Edition\mainserv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common files\WinTools\WToolsS.exe
C:\WINDOWS\System32\BRMFRSMG.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common files\WinTools\WToolsA.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\WinTools\WSup.exe
C:\Program Files\Logitech\MouseWare\System\Em_exec.exe
C:\Documents and Settings\Walter\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Bar =
http://www.websearch.com/ie.aspx?tb_id=50038
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page = http://www.foxnews.com/
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =
http://www.websearch.com/ie.aspx?tb_id=50038
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,SearchAssistant =
http://www.websearch.com/ie.aspx?tb_id=50038
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-
3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-
3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-
CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-
FADC6B084872} - C:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-
7859DF00B1D6} - C:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-
009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common
files\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common
Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common
Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1
\NORTON~1\AdvTools\ADVCHK.EXE
O4 - Global Startup: Opera.lnk = C:\Program Files\Opera75
\opera.exe
O4 - Global Startup: Read Me.lnk = C:\Program
Files\Opera75\Readme.txt
O4 - Global Startup: Software License Agreement.lnk =
C:\Program Files\Opera75\License.txt
O8 - Extra context menu item: &Google Search -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://imgfarm.com/images/nocache/funwebproducts/ei/PopSwa
tterInitialSetup1.0.0.8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
(Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/sw
flash.cab

Waltc:
I am not a Hijackthis expert, but I would think anything (no name)
cannot be good.
Did you try CWshredder.exe it is a little more user friendly by the
same programmer.

Hopefully somneone will respond who knows Hijackthis.
good luck
 
C

Carey Frisch [MVP]

Sorry, this is not a data analysis/interpretation newsgroup.

--
Carey Frisch
Microsoft MVP
Windows XP - Shell/User

Be Smart! Protect your PC!
http://www.microsoft.com/security/protect/

------------------------------------------------------------------------------------


| Now that I got someone's attention could you please help
| me if you know how to interpret this data. I had posted
| a request earlier this week, and one respondent said to
| post my "HIjack this" log. I did so, but then they never
| replied back after I posted it. The problem I'm having
| is unstopppable "pop-ups". I have Google tool bar, and
| another anti-pop-up loaded, but they just keep coming!
| My firewall is enabled in XP also! ??????????
|
| Logfile of HijackThis v1.97.7
| Scan saved at 3:29:15 PM, on 7/15/2004
| Platform: Windows XP SP1 (WinNT 5.01.2600)
| MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
|
| Running processes:
| C:\WINDOWS\System32\smss.exe
| C:\WINDOWS\system32\winlogon.exe
| C:\WINDOWS\system32\services.exe
| C:\WINDOWS\system32\lsass.exe
| C:\WINDOWS\system32\svchost.exe
| C:\WINDOWS\System32\svchost.exe
| C:\WINDOWS\system32\spoolsv.exe
| C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
| C:\Program Files\APC\APC PowerChute Personal
| Edition\mainserv.exe
| C:\Program Files\Norton AntiVirus\navapsvc.exe
| C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
| C:\WINDOWS\System32\nvsvc32.exe
| C:\WINDOWS\System32\svchost.exe
| C:\Program Files\Common files\WinTools\WToolsS.exe
| C:\WINDOWS\System32\BRMFRSMG.EXE
| C:\WINDOWS\Explorer.EXE
| C:\Program Files\Common files\WinTools\WToolsA.exe
| C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
| C:\Program Files\Common Files\Symantec Shared\ccApp.exe
| C:\Program Files\Common Files\WinTools\WSup.exe
| C:\Program Files\Logitech\MouseWare\System\Em_exec.exe
| C:\Documents and Settings\Walter\Desktop\HijackThis.exe
|
| R1 - HKCU\Software\Microsoft\Internet
| Explorer\Main,Search Bar =
| http://www.websearch.com/ie.aspx?tb_id=50038
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
| Page = http://www.foxnews.com/
| R0 - HKLM\Software\Microsoft\Internet
| Explorer\Search,CustomizeSearch =
| R0 - HKLM\Software\Microsoft\Internet
| Explorer\Search,SearchAssistant =
| http://www.websearch.com/ie.aspx?tb_id=50038
| R1 - HKLM\Software\Microsoft\Internet
| Explorer\Main,SearchAssistant =
| http://www.websearch.com/ie.aspx?tb_id=50038
| R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-
| 3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
| O2 - BHO: (no name) - {87766247-311C-43B4-8499-
| 3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
| O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-
| CF10577473F7} - c:\program files\google\googletoolbar1.dll
| O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-
| FADC6B084872} - C:\Program Files\Norton
| AntiVirus\NavShExt.dll
| O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-
| 7859DF00B1D6} - C:\Program Files\Norton
| AntiVirus\NavShExt.dll
| O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-
| 009027A5CD4F} - c:\program files\google\googletoolbar1.dll
| O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common
| files\WinTools\WToolsA.exe
| O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
| Files\Java\j2re1.4.2_04\bin\jusched.exe
| O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common
| Files\Symantec Shared\ccApp.exe"
| O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common
| Files\Symantec Shared\ccRegVfy.exe"
| O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1
| \NORTON~1\AdvTools\ADVCHK.EXE
| O4 - Global Startup: Opera.lnk = C:\Program Files\Opera75
| \opera.exe
| O4 - Global Startup: Read Me.lnk = C:\Program
| Files\Opera75\Readme.txt
| O4 - Global Startup: Software License Agreement.lnk =
| C:\Program Files\Opera75\License.txt
| O8 - Extra context menu item: &Google Search -
| res://C:\Program
| Files\Google\GoogleToolbar1.dll/cmsearch.html
| O8 - Extra context menu item: Backward &Links -
| res://C:\Program
| Files\Google\GoogleToolbar1.dll/cmbacklinks.html
| O8 - Extra context menu item: Cac&hed Snapshot of Page -
| res://C:\Program
| Files\Google\GoogleToolbar1.dll/cmcache.html
| O8 - Extra context menu item: Si&milar Pages -
| res://C:\Program
| Files\Google\GoogleToolbar1.dll/cmsimilar.html
| O8 - Extra context menu item: Translate into English -
| res://C:\Program
| Files\Google\GoogleToolbar1.dll/cmtrans.html
| O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
| O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
| http://imgfarm.com/images/nocache/funwebproducts/ei/PopSwa
| tterInitialSetup1.0.0.8.cab
| O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
| (Shockwave Flash Object) -
| http://download.macromedia.com/pub/shockwave/cabs/flash/sw
| flash.cab
|
|
 
G

Guest

My firewall is enabled in XP also! ??????????

get a REAL firewall and configure it properly.
ICF will only stop some externel to internal traffic.
A real firewall will also monitor internal to external traffic, and guess
what,
most if the sh*t people end up with on their machines was 'invited' by
themselves, 'cuz they were curious and clicked on a button or installed
something they (most of the time) knew was iffy to begin with.
It's kind'o like not practicing safe s*x, no point in coming whining if you
catch something...

my 2c
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top