swatkat said:
i have told to run HijackThis 3 times to u....if u cant download HijcakThis from ur computer , download it from a cybercafe or friend's comp or digit cd's , it's a 996kb file, and the copy it ur hdd, and run it.....
Here the scan I've done from an old Cd I'd .. Chck it out...
System log report, 2/20/05 3:03:15 PM
Detected: Microsoft Windows 98 SE
--------------------------------------------------
Running Processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\BULLETPROOFSOFT.COM\SPYWAREREMOVER\HS\HIJACK.EXE
--------------------------------------------------
Autorun entries from Registry:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
TaskMonitor = C:\WINDOWS\taskmon.exe
SystemTray = SysTray.Exe (file missing)
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme (file missing)
sp = rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall (file missing)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme (file missing)
SchedulingAgent = C:\WINDOWS\SYSTEM\mstask.exe
--------------------------------------------------
File association entry for:
[.EXE]
HKEY_CLASSES_ROOT\exefile\shell\open\command
(Default) = "%1" %*
[.COM]
HKEY_CLASSES_ROOT\comfile\shell\open\command
(Default) = "%1" %*
[.BAT]
HKEY_CLASSES_ROOT\batfile\shell\open\command
(Default) = "%1" %*
[.PIF]
HKEY_CLASSES_ROOT\piffile\shell\open\command
(Default) = "%1" %*
[.SCR]
HKEY_CLASSES_ROOT\scrfile\shell\open\command
(Default) = "%1" /S
[.HTA]
HKEY_CLASSES_ROOT\htafile\shell\open\command
(Default) = C:\WINDOWS\SYSTEM\MSHTA.EXE "%1" %*
--------------------------------------------------
Load/Run keys from WIN.INI:
load=
run=
--------------------------------------------------
Shell & screensaver key from SYSTEM.INI:
shell=Explorer.exe
drivers=mmsystem.dll power.drv
--------------------------------------------------
Verifying REGEDIT.EXE integrity:
- Regedit.exe found in C:\WINDOWS
- .reg open command is NOT normal ()
- Company name OK: Microsoft Corporation
- Original filename OK: REGEDIT.EXE
- File description OK: Registry Editor
Registry check NOT passed
--------------------------------------------------
C:\WINDOWS\WinInit.ini listing
[rename]
NUL=C:\WINDOWS\TEMP\GLB1A2B.EXE
--------------------------------------------------
C:\WINDOWS\WinInit.bak listing
[Rename]
C:\WINDOWS\SYSTEM\SHFOLDER.DLL=C:\WINDOWS\SYSTEM\TBME293.TMP
--------------------------------------------------
C:\Autoexec.bat listing
doskey
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\WINDOWS\SYSTEM\GKML.DLL - {A1C491A1-8340-11D9-9053-00805F119DA9}
--------------------------------------------------
Enumerating Task Scheduler jobs:
Tune-up Application Start.job
--------------------------------------------------
Enumerating Download Program Files:
[Microsoft XML Parser for Java]
CodeBase = file://C:\WINDOWS\Java\classes\xmldso.cab
OSD = C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
[DirectAnimation Java Classes]
CodeBase = file://C:\WINDOWS\SYSTEM\dajava.cab
OSD = C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd
[Internet Explorer Classes for Java]
CodeBase = file://C:\WINDOWS\SYSTEM\iejava.cab
OSD = C:\WINDOWS\Downloaded Program Files\Internet Explorer Classes for Java.osd
[HouseCall Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\XSCAN53.OCX
CodeBase = *a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
[Update Class]
InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
CodeBase = *v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38400.2651157407
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CodeBase = *download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
[{10003000-1000-0000-1000-000000000000}]
CodeBase = ms-its:mhtml:file://C:\foo.mht!*bin.wordsx.cc/JtUrTcec_L7JVmdToz82.chm::/on-line.exep
[Java Plug-in 1.5.0_01]
InProcServer32 = C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
CodeBase = *java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab
[Java Plug-in 1.5.0_01]
InProcServer32 = C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
CodeBase = *java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab
--------------------------------------------------
Enumerating Winsock LSP files:
NameSpace #1: C:\WINDOWS\SYSTEM\rnr20.dll
Protocol #1: C:\WINDOWS\SYSTEM\mswsosp.dll
Protocol #2: C:\WINDOWS\SYSTEM\msafd.dll
Protocol #3: C:\WINDOWS\SYSTEM\msafd.dll
Protocol #4: C:\WINDOWS\SYSTEM\msafd.dll
Protocol #5: C:\WINDOWS\SYSTEM\rsvpsp.dll
Protocol #6: C:\WINDOWS\SYSTEM\rsvpsp.dll
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL
--------------------------------------------------
[/list]