It is currently Tue Sep 01, 2026 2:28 pm


desktop weirdness

Discuss security related topics in here (Hacking, Cracking, and Protecting)
Do not post HJT Logs here

Moderator: PCguy

desktop weirdness

Postby lilpinkflower » Mon May 17, 2004 7:08 am

i have had a livin nightmare the last 24 hours

i downloaded some software for gettin mp3s....i shouldn't have done... i should have followed my instinct...!

anyway....i was absolutely covered in spyware... i have never seen so much!!

i think it's all gone...well anything dat mite spark itself off anys

ive run spybot, adaware, deleted obvious stuff from the registry, virus chek....

computer is running loads faster but has started to do something strange

(but not all the time :o/)

if i right clik on a shortcut on my desktop seemingly random stuff is comin up...or double clik

for example i double clikked on IE a few mins ago n the mouse properties window came up!!!

at one point this morn ALL my desktop stuff was my internet connection shortcut !!! EEEK!

i rightclikked on anythin n it gave me the rightclik for Tiscali broadband connection

its v v v v weird!!!

but i rebooted...everythin okies...but it keeps appenin!

also sometimes b4 i access somethin on my desktop... the comp slows like its not gunna let me but then it dus..... but an error message comes up... an access denied one ....for windows/desktop/shortcut to tiscali broadband

feels like somethin is IN my comp...but i cant find anymore traces ????!!

help !!!!

lilpink x
User avatar
lilpinkflower
Moderator
Moderator
 
Posts: 1603
Joined: Wed Apr 07, 2004 1:00 am
Location: manchester, U.K

Thanks given:0
Thanks received:0
Top

Postby brad » Mon May 17, 2004 7:28 am

Operating System?

Download and install . Now Run it and post a copy of the Log File here.

brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby lilpinkflower » Mon May 17, 2004 10:10 am

i will do latas wen i'm home from work.

wondering if sumethin nasty could damage my operating system??.. or maybe my win98 didnt need any help lol

ta

lilpink x
User avatar
lilpinkflower
Moderator
Moderator
 
Posts: 1603
Joined: Wed Apr 07, 2004 1:00 am
Location: manchester, U.K

Thanks given:0
Thanks received:0
Top

Postby lilpinkflower » Mon May 17, 2004 12:35 pm

my comp runnin really fast....n good... not had the weird problem 2day...not sure why !!?

anyhow here's me hijackthis...

Logfile of HijackThis v1.97.7
Scan saved at 12:33:49, on 17/05/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\MESSENGER PLUS! 2\MSGPLUS.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPROXY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\GENIUS NETSCROLL+ SERIES\GNETMOUS.EXE
C:\WINDOWS\MHOTKEY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\WINDOWS\ptsnoop.exe
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\E_S10IC2.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\EPROMPTER\EPROMPTER.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Lilpinkflower :oP
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {96C8A587-2D76-FC77-355E-D161E5EC8F32} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\GENIUS~1\GNETMOUS.EXE
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccProxy] C:\PROGRA~1\COMMON~1\SYMANT~1\CCPROXY.EXE
O4 - HKLM\..\RunServices: [SndSrvc] C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSRVC.EXE
O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM\E_SRCV02.EXE
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: Real.com (HKLM)
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: ICQ 4.0 (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shoc ... tor/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/sh ... wflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} (WebCam Control) - http://www.webcamnow.com/broadcast/ActiveXWebCam.cab
O16 - DPF: {72C23FEC-3AF9-48FC-9597-241A8EBDFE0A} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetupml.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... 3912847222
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: LiveWorld EZTalk 3.0 - http://bizchat.liveworld.com/java/ezmed/ezmed.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200 ... taller.exe
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... Client.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/So ... owdown.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/c ... potc_x.cab
O16 - DPF: {9F637568-E5F7-4CB2-BD01-818CF6C561F9} (PhotosCtrlUK Class) - http://uk.f1.pg.photos.yahoo.com/ocx/uk ... r1_9uk.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/se ... loader.cab
O16 - DPF: {B160422D-0A48-11D4-BD9B-00A0C9B0AB7B} (Download Class) - http://expressit.broderbund.com/plugin/Download.cab
O16 - DPF: {20AD521D-3A3E-11D4-BC32-0050040D952B} (SwIcdInstall Class) - http://www.picturebuzz.com/common/programs/swicdad.cab
O16 - DPF: {4DB79B88-84B2-11D3-81B4-525400E7AB54} (Axe Control) - http://www.picturebuzz.com/picturebuzz/ ... se/axe.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.dll


ta

lilpink x
User avatar
lilpinkflower
Moderator
Moderator
 
Posts: 1603
Joined: Wed Apr 07, 2004 1:00 am
Location: manchester, U.K

Thanks given:0
Thanks received:0
Top

Postby teststrips » Mon May 17, 2004 1:30 pm

I'd start by getting rid of these two

O2 - BHO: (no name) - {96C8A587-2D76-FC77-355E-D161E5EC8F32} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll (file missing)

I was looking at the 04-hklm section, here are the ones that stuck out.

Gnetmous.exe is a mouse driver that only needs to be loaded IF you changed the default actions for what the mouse buttons do (or if the mouse has more than 3 buttons + scroll wheel)
mHotkey.exe seems to be a progam that makes the special keys on "chicony" keyboards work (buttons like e-mail, vol+, vol-, mute, etc.) If you don't have a multimedia keyboard, you could probably get rid of that.
pctptt.exe is used for PCTEL modems. If you no longer use the modem you could get rid of this. Most websites clasify this as harmless
PTsnoop.exe is "is essential to the good funtioning of PCTEL modems"
msgplus.exe is some sort of chat program. If you don't need it to start durring the boot-up process, you can get rid of it, and start the program manually
msnmsgr - microsoft messenger program - again you could start it manually if you wanted to

Everything else in the 04 section looks OK. Hey i need to go to work, hopefully someone else will finish up. (all info I found was gotten through goole - i just tpyed in the process name (ie msgplus.exe)

one more thing, the .spop /npdocbox.dll is for a very old version of Adobe Acrobat reader. Newer versions no longer need this file. If you acrobat 6.0, delete the file. If you are still on 5.0 I'd upgrade.
User avatar
teststrips
Geek Alumni
 
Posts: 542
Joined: Fri Jan 24, 2003 1:00 am
Location: USA - Pennsylvania

Thanks given:0
Thanks received:0
Top

Postby brad » Mon May 17, 2004 1:52 pm

You're right, it does look pretty good.
You might want to close all other open Windows and have HiJackThis Fix:
O2 - BHO: (no name) - {96C8A587-2D76-FC77-355E-D161E5EC8F32} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll (file missing)

brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby lilpinkflower » Mon May 17, 2004 5:00 pm

ta brad ! :P

believe me it didn't 'look gud' this time yesterday !! i was up til half one in the morn sortin the spyware...did a virus chek wile i slept (i couldn't even get to sleep lol) n then up at 6...bak on me comp n its runnin really fast

BUT since i came home its behaving weirdly agen

trubs is i dont kno wetha its a 'security' issue....ive noticed certain things happenin over bout a week or 2...blamed it on a defragger (don't sue me mr Diskeeper lol) but i dont kno wuts up wid it

me friend is tellin me to buy xp n reformat...but i hate bein 'beat' !! n as we all kno...if this can appen on 98 it will probs happen on xp lol

not sure wetha to post on this thread wot's happenin...or has happened...fink i will cos it may well be down to a security issue...who knows

in fact...ive never had a virus BUT the way my comp feels at the moment...it's like its got one....ded spooky... the virus chek came up with bout 3 or 4 spyware threats...one of wich it cudnt delete...so i went to its program file and deleted it... n it deleted....dont kno wetha that was the rite thing to do BUT ...lol

the problems i'm havin started b4 then so i kno its not me bein cluless n rekless causin da probs lol

these r fings that r happenin that r WEIRD... they may b easily explainable i dunno but they r spooky to me

- the text size keeps changin on IE... i keep changin bak to medium but ive ad every size in its option list lolz

-sumtimes wen i go to type in a box... example was jus a few mins ago...signin into to the forum... the type is not 'normal' ...im on mozilla at mo...cos it workt ok on mozilla lol.. but the type was like...characters u wunt use very often...maybe letters wid accents n stuff... i wudnt even kno ow to type em if i wanted to lol

- the desktop is becomin V V V spooky indeed....wen i booted up in my dinner break it behaved perfectly but wen i booted up after work...it started normally... but then i noticed it wasnt deselecting the icons i had clikkt on ...it usually dus this as u select another?.... well i fort i'd found a big clu.... it was showin me the right clik list of any of the many selected icons.... but it wasnt that simple
cos i then rebooted to chek it agen n i dubble clikkt straightaway on my broadband connection and i got its 'properties' !! i got online by right clikkin n selecting 'connect'...so the right clikkt workt but dubble clik on the icon didnt

- for a week or so i have noticed things eitha not startin up straight away or takin v long time to do so... so i have started chekkin my tasklist to see wots goin on.... and its always ccapp (norton?) not respondin.... but it goes like this wen 'lucomserver' n 'Aupdate' have appeared in the tasklist too
i'm presuming these r Norton...
if i stop 'lucomserver' everything springs into action on me computer... n then i permit it bak thru the firewall...n things run smoothly agen


i'm trying to decide whether the desktop problems ive got r happenin wen im offline...ive got a feeling they r ok wen im offline n it's ony wen i'm online the trubs start

other than that the comp is ded fast n best it's bin 4 ages....!!!!

:|

mad mad mad lol

lilpink x
User avatar
lilpinkflower
Moderator
Moderator
 
Posts: 1603
Joined: Wed Apr 07, 2004 1:00 am
Location: manchester, U.K

Thanks given:0
Thanks received:0
Top

Postby lilpinkflower » Mon May 17, 2004 5:04 pm

oh n thanks teststrips too :wink: ... in my haste at readin replies i assumed twas all Brad lolz

ow rong ya can b

ta !!

lilpink x
User avatar
lilpinkflower
Moderator
Moderator
 
Posts: 1603
Joined: Wed Apr 07, 2004 1:00 am
Location: manchester, U.K

Thanks given:0
Thanks received:0
Top

Postby brad » Mon May 17, 2004 7:21 pm

Try reading this:
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby poisonedchalice » Mon May 17, 2004 10:39 pm

ok, I'll try again seeing as brad doesn't appear to respond to pm's..... :|

Jane can't post anything at the moment coz her keyboard is playing silly billy's. When she tries to type, some keys activate the keyboard shortcuts, other keys display alternative language characters i.e accented e's etc and others don't type at all.

She's looked at the link brad posted, it may have something to do with her problem, but she has Norton Internet Security so feels sure everything is configuring ok by default.

She's in the process of booting from Norton disk at the moment, in desperation!!!!

xxxxxxxxxxxxx
suzii
poisonedchalice
Geek
Geek
 
Posts: 97
Joined: Mon May 03, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby lilpinkflower » Mon May 17, 2004 11:20 pm

testin testin 123....lol

latest attempt at computer sanity...tuk me keyboard off start up...its a multimedia one.... n i'm typin at mo !!! but then ccapp is runnin okies not 'not respondin'...gunna keep a sharp eye on me tasklist to diagnose stuff

thanks everyone for ya help...n fanx Suzii 4 bein my lifeline :wink:

lilpink x
User avatar
lilpinkflower
Moderator
Moderator
 
Posts: 1603
Joined: Wed Apr 07, 2004 1:00 am
Location: manchester, U.K

Thanks given:0
Thanks received:0
Top

Postby brad » Tue May 18, 2004 10:18 am

brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby poisonedchalice » Tue May 18, 2004 3:09 pm

poisonedchalice
Geek
Geek
 
Posts: 97
Joined: Mon May 03, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Tue May 18, 2004 3:16 pm

brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby poisonedchalice » Tue May 18, 2004 4:13 pm

hmmm, my psychic powers must've failed me, I was sure you were being arrogant! Image

lol

Easy mistake to make, Image

xxxxxxxx
poisonedchalice
Geek
Geek
 
Posts: 97
Joined: Mon May 03, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Next

Return to Security

Who is online

Users browsing this forum: No registered users and 0 guests

cron