Can someone assist with my Hijackthispc log
Results 1 to 6 of 6

Thread: Can someone assist with my Hijackthispc log

  1. #1
    Join Date
    Nov 1999
    Posts
    438

    Can someone assist with my Hijackthispc log

    Can someone direct me to which files I can remove, It's running Win XP, thx in advance. .

    Logfile of HijackThis v1.97.7
    Scan saved at 4:10:28 PM, on 4/15/04
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\drivers\trcboot.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\Program Files\CA\eTrust\Antivirus\InoRpc.exe
    C:\Program Files\CA\eTrust\Antivirus\InoRT.exe
    C:\Program Files\CA\eTrust\Antivirus\InoTask.exe
    C:\Program Files\Personal Communications\PCS_AGNT.EXE
    c:\em\opt\tivoli\lcf\bin\w32-ix86\mrt\LCFD.EXE
    C:\WINDOWS\LogWatNT.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\RCSERV.EXE
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    c:\EM\OPT\TIVOLI\Mobile\mobile.exe
    C:\WINDOWS\System32\atiptaxx.exe
    C:\WINDOWS\System32\pctspk.exe
    C:\PROGRA~1\CA\eTrust\ANTIVI~1\realmon.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Zone Labs\Integrity Client\iclient.exe
    C:\Program Files\Jabber\Messenger\JabberMessenger.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
    D:\Documents and Settings\KZWKHK.EDSADCA\My Documents\Downloads\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.portalsearching.com/search/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.portalsearching.com/search.php
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.infocanada.ca.eds.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.portalsearching.com/search/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.portalsearching.com/search/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.portalsearching.com/search.php
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.infocanada.ca.eds.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.portalsearching.com/search.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by EDS COE Canada
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.portalsearching.com/search.php?phrase=%s
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = internet2.can.eds.com:8080
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *eds.com;*eds.ca;<local>
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\ActiveX\ACROIE~1.OCX
    O3 - Toolbar: WebFerret - {A58686ED-FC46-44C3-95C6-4A812AB776F1} - C:\Program Files\FerretSoft\WebFerret\FerretBand.dll
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [Refresh] C:\Windows\COE\refresh.exe
    O4 - HKLM\..\Run: [Tivoli] c:\windows\coe\tivoli.vbs
    O4 - HKLM\..\Run: [HWINV2K] C:\Em\Bin\Tivoli_EM\HwInv2K.exe
    O4 - HKLM\..\Run: [Mobile] c:\EM\OPT\TIVOLI\Mobile\epspawn.exe -w c:\EM\OPT\TIVOLI\Mobile c:\EM\OPT\TIVOLI\Mobile\mobile.exe
    O4 - HKLM\..\Run: [SwdisUsrPCN.tmp_ad17740b52] "c:\em\opt\tivoli\lcf\dat\1\cache\lib\w32-ix86\wdusrpcn.exe" "c:\em\opt\tivoli\swdis\1\wdusrpcn.env"
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
    O4 - HKLM\..\Run: [SwdisUsrPCN.w2kzwkhk03] "c:\em\opt\tivoli\lcf\dat\1\cache\lib\w32-ix86\wdusrpcn.exe" "c:\em\opt\tivoli\swdis\2\wdusrpcn.env"
    O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\eTrust\ANTIVI~1\realmon.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\Integrity Client\iclient.exe"
    O4 - HKCU\..\Run: [EDS_Asset_Data_Collector] D:\Documents and Settings\KZWKHK.EDSADCA\Application Data\Asset Data Collector\scanner_check.vbs
    O4 - HKCU\..\Run: [Jabber Messenger] C:\Program Files\Jabber\Messenger\JabberMessenger.exe -hidden
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.infocanada.ca.eds.com/
    O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - https://www.ibm.com/pc/support/acces...d/IbmEgath.cab
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/threatinfo/virusinfo/webscan.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
    O16 - DPF: {D6862A22-1DD6-11D3-BB7C-444553540000} - http://www.sexxx-direct.com/BHO.CAB
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://aperture.webex.com/client/la...ex/ieatgpc.cab
    O16 - DPF: {EAF26D6B-B8E6-11D1-9941-444553540001} - http://www.eds.com/emf/scanner.cab
    My Web Site - 1970 Z28 Camaro
    Retired from 35 yrs IT Hardware Planning Analyst
    Cheers
    Mark

  2. #2
    Join Date
    Jun 2002
    Location
    Israel
    Posts
    5,132
    This is the only real bad one I found:
    O16 - DPF: {D6862A22-1DD6-11D3-BB7C-444553540000} - http://www.sexxx-direct.com/BHO.CAB

    Although, you do have an aweful lot of unnecesary stuff on there. If it was my computer, I would get rid of half of that stuff.

  3. #3
    Join Date
    Nov 1999
    Posts
    438
    This is my laptop I use at work....thx
    My Web Site - 1970 Z28 Camaro
    Retired from 35 yrs IT Hardware Planning Analyst
    Cheers
    Mark

  4. #4
    Join Date
    Feb 2003
    Location
    Minneapolis, MN USA
    Posts
    3,733
    Here is a tutorial that will help in determining what the different entries mean.

    http://www.bleepingcomputer.com/foru...howtutorial=42

  5. #5
    Join Date
    Feb 2004
    Location
    Mandurah, Western Australia
    Posts
    10,157
    Get rid of all the portalsearching.com entries too. I followed the link & it asks if you want to put 2020 on your computer, a known baddy.

  6. #6
    Join Date
    Nov 1999
    Posts
    438
    great...thx!!
    My Web Site - 1970 Z28 Camaro
    Retired from 35 yrs IT Hardware Planning Analyst
    Cheers
    Mark

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •