It is currently Tue Sep 01, 2026 1:33 pm


Activity 1

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Activity 1

Postby debsteve1 » Fri Dec 17, 2004 8:49 pm

Hi, I have two pc's connected via a network cable (no router) so that the both pc's can access the internet via my BROADBAND connection. Now my trouble is sometimes when my main pc is just sitting idle, i can see "internet activity", i.e the little blue pc's in task bar are flashing. Now then as far as i know neither pc has anything running even in "the background" which should do this. I have zonealarm installed and also AVG antivruus. I have checked for virusus, spyware and all sorrts. Should this "activity" be happening?, I never used to have it before when I had dial-up, although I never had the other pc connected then. and i have double checked this IS the broadband p'cs in the task bar and not the ones for my network connection.

I have been asked to post my hijackthis files in here 1 for each PC. Please also see "activity 2"

Thanks and whilst your checking my files if you see anything else that would be great.


Logfile of HijackThis v1.98.2
Scan saved at 19:33:18, on 17/12/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Deb.Steve1\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [washindex] C:\Program Files\Washer\washidx.exe "Deb.Steve1"
O4 - HKCU\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe
O9 - Extra button: ICQ 4 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O16 - DPF: {0380E3AB-96DB-43E3-8A02-B59D598FEBAE} (DX3Download.clsDownload) - http://content.dx3.net/dx3media/cab/dx3dlman.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v ... 2636311000
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installer ... taller.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{10678CBA-16DA-4F4F-9E1F-330A94CC0B2B}: NameServer = 194.74.65.68 194.72.9.34
O17 - HKLM\System\CS1\Services\Tcpip\..\{10678CBA-16DA-4F4F-9E1F-330A94CC0B2B}: NameServer = 194.74.65.68 194.72.9.34

Thanks STeve.
User avatar
debsteve1
Geek
Geek
 
Posts: 31
Joined: Wed Jul 09, 2003 1:00 am

Thanks given:0
Thanks received:0
Top

Postby lilpinkflower » Fri Dec 17, 2004 8:58 pm

You need the new version of HijackThis 1.99

Also, make sure you place Hijackthis in a folder of its own not a temp file. When it makes backups you need these to be in a safe place in case you need to restore something.

Hope that's not too much extra work... don't hate me :)

lilpink x
System specs:

Clovebud No.7, Max Factor Hypersmooth, L'Oreal Lash Architect, The Body Shop Poudre Libre, 17 Nude blusher and hair by Uppercutz.


Image
User avatar
lilpinkflower
Moderator
Moderator
 
Posts: 1603
Joined: Wed Apr 07, 2004 1:00 am
Location: manchester, U.K

Thanks given:0
Thanks received:0
Top

Postby liljim » Fri Dec 17, 2004 11:18 pm

we'll go with 1.98 on this because there's not much there, however you still need to get hijack in a folder as lilpink suggest.Once you've done that.....

Turn off System Restore. (Turn it back on after this is repaired and you've rebooted.) Close all other open Windows and have HiJackThis Fix:

O16 - DPF: {0380E3AB-96DB-43E3-8A02-B59D598FEBAE} (DX3Download.clsDownload) - http://content.dx3.net/dx3media/cab/dx3dlman.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installer ... taller.cab


Now, empty all your TEMP Folders (WinXp has up to 4 of them) / Temporary Internet Files Folder and then empty your "Recycle Bin" and reboot.
User avatar
liljim
Moderator
Moderator
 
Posts: 3017
Joined: Mon Mar 03, 2003 1:00 am
Location: Louisiana
Operating System:

Thanks given:0
Thanks received:12
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron