Request advice or guidance re hijackthis log

Discussion in 'adware, spyware & hijack cleaning' started by navalair, Apr 14, 2004.

Thread Status:
Not open for further replies.
  1. navalair

    navalair Registered Member

    Joined:
    Jan 4, 2003
    Posts:
    14
    Any advice or recommendations regarding troublesome line items would truly be appreciated. Thanks in advance.

    Logfile of HijackThis v1.97.7
    Scan saved at 2:45:30 AM, on 4/14/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Eset\nod32krn.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\NSClean\BOClean\BOClean.exe
    C:\Program Files\Eset\nod32kui.exe
    C:\PROGRA~1\NSClean\BOClean\BOCSEC.EXE
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZONELABS\VSMON.EXE
    C:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
    C:\Documents and Settings\Russell Fromholz\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [BOCleanautostart] C:\PROGRA~1\NSClean\BOClean\BOClean.exe
    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
    O10 - Broken Internet access because of LSP provider 'imon.dll' missing
    O15 - Trusted Zone: http://www.abxzone.com
    O15 - Trusted Zone: http://www.chadwicks.com
    O15 - Trusted Zone: http://delltalk.us.dell.com
    O15 - Trusted Zone: http://*.dslreports.com
    O15 - Trusted Zone: http://www.enidnews.com
    O15 - Trusted Zone: http://www.intel.com
    O15 - Trusted Zone: http://www.newegg.com
    O15 - Trusted Zone: http://www.nws.noaa.gov
    O15 - Trusted Zone: https://www.wilderssecurity.com
    O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://imc.rccd.cc.ca.us//AxisCamControl.ocx
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37865.5235763889
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
     
  2. dvk01

    dvk01 Global Moderator

    Joined:
    Oct 9, 2003
    Posts:
    3,131
    Location:
    Loughton, Essex. UK
    it all looks clean to me

    are you having problems?
     
  3. navalair

    navalair Registered Member

    Joined:
    Jan 4, 2003
    Posts:
    14
    No problems with the exception of, what I consider to be, far too many cookies, etc. showing up on a system that disallows third party cookies. It seemed unusual to me that AdAware and Spybot keep displaying as many as 9 items to be deleted when I can't recall having visited any questionable web sites. I installed Spyware Blaster recently (4/12/04), so I assume I will begin to notice fewer unexpected/unwanted bots. Too paranoid perhaps.

    While it may have turned out to have been unnecessary, I do appreciate your having had a look and receiving your comment that all appears okay, dvk01. My thanks to you for taking the time to prove my doubts unwarranted.
     
  4. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    Hi navalair,

    You can custom block cookies with IE6:
    http://privacy.getnetwise.org/browsing/tools/ie6/cookiesedit
    So if you make notes of what gets found you can add them and certainly Javacool would appreciate to be informed of the ones SpywareBlaster does not block and that are reported by AdAWare and Spybot S&D.

    Regards,

    Pieter
     
Thread Status:
Not open for further replies.