It is currently Tue Sep 01, 2026 4:31 pm


Hijack this log help please?

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Hijack this log help please?

Postby candiceg » Tue Dec 07, 2004 9:44 am

I am having problems with spyware popping up ads constantly sometimes causing my system to crash. I have run SpyBot and Ad-Aware repeatedly but the problem persists. Below is my hijack this log:

Logfile of HijackThis v1.98.2
Scan saved at 7:32:28 PM, on 7/12/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\owccwq.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Nokia\Services\ServiceLayer.exe
C:\WINDOWS\system32\userinit.exe
C:\Documents and Settings\E183926.PACRIM1\Desktop\hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://as01hscspoint/sites/CP/default.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IntelAPMClient] C:\LDClient\amclient.exe /apm /s
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Station System Menu - {1F961D7B-0AB1-415c-8F34-65883272AC30} - C:\Program Files\Honeywell\Client\Station\HSCBHO.dll
O9 - Extra 'Tools' menuitem: Station System Menu - {1F961D7B-0AB1-415c-8F34-65883272AC30} - C:\Program Files\Honeywell\Client\Station\HSCBHO.dll
O9 - Extra button: Station Point Search - {210D5841-AEAE-4f52-B1DB-03D2406E2FCE} - C:\Program Files\Honeywell\Client\Station\HSCBHO.dll
O9 - Extra 'Tools' menuitem: Station Point Search - {210D5841-AEAE-4f52-B1DB-03D2406E2FCE} - C:\Program Files\Honeywell\Client\Station\HSCBHO.dll
O9 - Extra button: Station Alarm Acknowledge - {2F126B47-6136-4361-81B6-A871A36F24DF} - C:\Program Files\Honeywell\Client\Station\HSCBHO.dll
O9 - Extra 'Tools' menuitem: Station Alarm Acknowledge - {2F126B47-6136-4361-81B6-A871A36F24DF} - C:\Program Files\Honeywell\Client\Station\HSCBHO.dll
O9 - Extra button: (no name) - {477BCA22-9121-4ef5-AE7E-D29047F9A81A} - C:\Program Files\Honeywell\Client\Station\HSCBHO.dll
O9 - Extra 'Tools' menuitem: Station Logon... - {477BCA22-9121-4ef5-AE7E-D29047F9A81A} - C:\Program Files\Honeywell\Client\Station\HSCBHO.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.as01bcsupport
O15 - Trusted Zone: http://*.as01billwest
O15 - Trusted Zone: http://*.as01hscpizzabox
O15 - Trusted Zone: http://*.as01hsczenith
O15 - Trusted Zone: http://learning.hsc.honeywell.com.au
O16 - DPF: winrep - https://premier.microsoft.com/premier/O ... winrep.cab
O16 - DPF: {28BCFBB1-434A-4E15-8AC1-67351E12A4BD} (HWOPCBrowseCtl.OPCBrowse) - file://\\as01hsczulu\Experion PKS\Client\System\R210\sysOPCIntegrator_files\hwopcbrowsectl.CAB
O16 - DPF: {4A3CBDDD-C4DC-4C38-B44F-704DAEF628AE} (PjAdoInfo3 Class) - http://as01hsczenith/projectserver/objects/pjclient.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v ... 2384262858
O16 - DPF: {8EE82555-376E-4F89-A10F-F878986B2091} (HwOpciClient.OpciDashboard) - file://\\as01hsczulu\Experion PKS\Client\System\R210\sysOPCIntegrator_files\HwOpciClient.CAB
O16 - DPF: {A584D228-46A3-4208-BCF9-D6E399391B89} (HTStore.Application) - http://as01hscpizzabox/timesheet/HTStore.CAB
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://premier.microsoft.com/premier/O ... leXfer.cab
O16 - DPF: {AF9A1421-E128-4D5F-A37E-039F305867B9} (Pj11enuC Class) - http://as01hsczenith/projectserver/obje ... jcintl.cab
O16 - DPF: {F2A84794-EE6D-447B-8C21-3BA1DC77C5B4} (SDKInstall Class) - file://I:\DevTool\MicrosoftPlatformSDK\Aug01\controls\sdkinst.cab
O16 - DPF: {FB7FE605-A832-11D1-88A8-0000E8D220A6} (ScanServer Control) - http://bcsupport.hsc.ap.honeywell.com/W ... rver10.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = HSCSydney.hsc.honeywell.com.au
O17 - HKLM\Software\..\Telephony: DomainName = hscsydney.hsc.honeywell.com.au
O17 - HKLM\System\CCS\Services\Tcpip\..\{7FA786CA-E3CF-40A0-9741-EA1DBC198939}: NameServer = 159.99.24.16,159.99.1.233
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = HSCSydney.hsc.honeywell.com.au
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = hscsydney.hsc.honeywell.com.au,honeywell.com.au,iac.honeywell.com,honeywell.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = HSCSydney.hsc.honeywell.com.au
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = hscsydney.hsc.honeywell.com.au,honeywell.com.au,iac.honeywell.com,honeywell.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = hscsydney.hsc.honeywell.com.au,honeywell.com.au,iac.honeywell.com,honeywell.com
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll

Any help appreciated!
Thanks.
candiceg
User avatar
candiceg
Newbie
Newbie
 
Posts: 1
Joined: Tue Dec 07, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby liljim » Tue Dec 07, 2004 10:25 pm

Im sorry this is taking so long but im trying to find some info on "Honeywell" and unless your a aerospace engineer,i've got nothing.

I will wait until you or someone else might have an explination of it before i post any fixes.
User avatar
liljim
Moderator
Moderator
 
Posts: 3017
Joined: Mon Mar 03, 2003 1:00 am
Location: Louisiana
Operating System:

Thanks given:0
Thanks received:12
Top

Postby PCguy » Wed Dec 08, 2004 12:47 am

(\__/) This is Bunny.
(='.'=) Copy and paste bunny into your sig.
(")_(") Help Bunny gain World Domination.

Image
User avatar
PCguy
Lord of the Geeks
Lord of the Geeks
 
Posts: 2017
Joined: Sat Sep 15, 2001 1:00 am
Location: A Very Scarey Place
Operating System:

Thanks given:2
Thanks received:4
Top

Postby PCguy » Wed Dec 08, 2004 6:02 am

Before I begin, I am assuming you work for Honeywell. So I ignored anything that has to do with them. However, some of what I am asking you to remove might have to do with that. You need to ask your IT support to verify. The file I ask you to delete I cant find any info on. But I would simply rename it rather then delete it. Anything you remove can be put bac k via HJT, so dont be too scared. But if you delete a file and empty the recycle bin, it cant be returned.

Press Ctrl/Alt/Del and "End Task" or "End Process" on each of the following:

owccwq.exe

Turn off System Restore. (Turn it back on after this is repaired and you've rebooted.)
(This would also include the “GoBack” Program if it is installed.)
Close all other open Windows and have HiJackThis Fix:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://as01hscspoint/sites/CP/default.aspx
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O15 - Trusted Zone: http://*.as01bcsupport
O15 - Trusted Zone: http://*.as01billwest
O15 - Trusted Zone: http://*.as01hscpizzabox
O15 - Trusted Zone: http://*.as01hsczenith
O16 - DPF: {28BCFBB1-434A-4E15-8AC1-67351E12A4BD} (HWOPCBrowseCtl.OPCBrowse) - file://\\as01hsczulu\Experion PKS\Client\System\R210\sysOPCIntegrator_files\hwopcbrowsectl.CAB
O16 - DPF: {4A3CBDDD-C4DC-4C38-B44F-704DAEF628AE} (PjAdoInfo3 Class) - http://as01hsczenith/projectserver/objects/pjclient.cab
O16 - DPF: {8EE82555-376E-4F89-A10F-F878986B2091} (HwOpciClient.OpciDashboard) - file://\\as01hsczulu\Experion PKS\Client\System\R210\sysOPCIntegrator_files\HwOpciClient.CAB
O16 - DPF: {A584D228-46A3-4208-BCF9-D6E399391B89} (HTStore.Application) - http://as01hscpizzabox/timesheet/HTStore.CAB
O16 - DPF: {AF9A1421-E128-4D5F-A37E-039F305867B9} (Pj11enuC Class) - http://as01hsczenith/projectserver/obje ... jcintl.cab

Now this is where I would rename and not delete the following file:

C:\WINDOWS\system32\owccwq.exe

I would rename it to owccwq.old just in case.

The only other thing I noticed is you have no virus protection running. You may want to install one and do a system scan.
(\__/) This is Bunny.
(='.'=) Copy and paste bunny into your sig.
(")_(") Help Bunny gain World Domination.

Image
User avatar
PCguy
Lord of the Geeks
Lord of the Geeks
 
Posts: 2017
Joined: Sat Sep 15, 2001 1:00 am
Location: A Very Scarey Place
Operating System:

Thanks given:2
Thanks received:4
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron