blackoscar Posted October 6, 2005 Share Posted October 6, 2005 (edited) Usually cannot submit the problem as soon as I hit any kind of upload or link button Explorer just shuts down.Can anyone helpNo idea what files are good or bad after HIJACKTHIS scanLogfile of HijackThis v1.99.1Scan saved at 12:30:04 PM, on 5/10/2005Platform: Windows 2000 SP3 (WinNT 5.00.2195)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\spoolsv.exeC:\WINNT\System32\svchost.exeC:\WINNT\System32\NMSSvc.exeC:\WINNT\system32\regsvc.exeC:\WINNT\system32\MSTask.exeC:\WINNT\System32\WBEM\WinMgmt.exeC:\WINNT\System32\mspmspsv.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\svchost.exeC:\WINNT\Explorer.EXEC:\Program Files\Analog Devices\SoundMAX\Smtray.exeC:\program files\Telstra\Signup\tbpt.exeC:\Program Files\Error Fixer\ErrorFixer.ExeC:\WINNT\System32\nof.exeC:\Program Files\Nokia\PC Suite for Nokia 6600\connmngmntbox.exeC:\Program Files\Nokia\PC Suite for Nokia 6600\ectaskscheduler.exeC:\Program Files\WinZip\WZQKPICK.EXEC:\PROGRA~1\Nokia\PCSUIT~1\Elogerr.exeC:\Program Files\Intuwave\Shared\mRouterRunTime\mRouterRuntime.exeC:\PROGRA~1\Nokia\PCSUIT~1\BROADC~1.EXEC:\PROGRA~1\Nokia\PCSUIT~1\SCRFS.exeC:\Program Files\Microsoft Office\Office\OUTLOOK.EXEC:\WINNT\System32\wuauclt.exeC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\PROGRA~1\WINZIP\winzip32.exeC:\unzipped\hijackthis[1]\HijackThis.exeO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocxO4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logonO4 - HKLM\..\Run: [smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exeO4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exeO4 - HKLM\..\Run: [{F7D90BD2-14A9-11d3-AD9E-00AA0064EC94}] C:\program files\Telstra\Signup\tbpt.exeO4 - HKLM\..\Run: [ff] nof.exeO4 - HKLM\..\RunServices: [ff] nof.exeO4 - HKLM\..\RunServices: [mouse] mouse.exeO4 - HKCU\..\Run: [ErrorFixer] "C:\Program Files\Error Fixer\ErrorFixer.Exe" /bootO4 - HKCU\..\Run: [ff] nof.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXEO4 - Global Startup: PCSuiteForNokia6600 Detect.lnk = C:\Program Files\Nokia\PC Suite for Nokia 6600\connmngmntbox.exeO4 - Global Startup: PCSuiteForNokia6600 TS.lnk = C:\Program Files\Nokia\PC Suite for Nokia 6600\ectaskscheduler.exeO4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXEO9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htmO9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htmO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1127954007453O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/bejeweled...aploader_v6.cabO16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{D69C604A-5688-4F47-8496-350842F09ABA}: NameServer = 203.49.70.20 139.134.2.190O20 - Winlogon Notify: f3dsl - C:\WINNT\SYSTEM32\lsd_f3.dllO23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exeO23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exeO23 - Service: Remote_Procedure_Call (svchost) - Unknown owner - %windir%\system32\svchost.cmd (file missing) Edited October 6, 2005 by blackoscar Link to comment Share on other sites More sharing options...
chilifrei64 Posted October 6, 2005 Share Posted October 6, 2005 I would run your Big 3 anti spyware (MS, lavasoft, spybot).. you definately have spywarethese ones look fishy to meC:\program files\Telstra\Signup\tbpt.exeC:\Program Files\Error Fixer\ErrorFixer.ExeC:\WINNT\System32\nof.exe Link to comment Share on other sites More sharing options...
epic Posted October 9, 2005 Share Posted October 9, 2005 (edited) It could possibly have something to do with your Phone software installed on your PC. You may want to role back to a later date when the software was not installed and try installing it again. Besides that, remove all the quick startup programs like WinZip, Nero, smtray and the Intel card. They are not needed to function.Do you even use Veritas software (i.e. Backup tools)?IE does not like 3rd party plugin's at times, suggest disabling 3rd party plugins in Tools-Internet Options-Advanced.O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx,O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm,O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm,Big no no....O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/bejeweled...aploader_v6.cabO16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{D69C604A-5688-4F47-8496-350842F09ABA}: NameServer = 203.49.70.20 139.134.2.190O20 - Winlogon Notify: f3dsl - C:\WINNT\SYSTEM32\lsd_f3.dll (a.k.a. PWSteal.Banker.B )Unsure of nof.exe, errorfixer is (from what I understand) scamware, tbpt.exe do you have some kind of TELE / mobile services (if not delete / remove)?O4 - HKLM\..\Run: [{F7D90BD2-14A9-11d3-AD9E-00AA0064EC94}] C:\program files\Telstra\Signup\tbpt.exeO4 - HKLM\..\Run: [ff] nof.exeO4 - HKCU\..\Run: [ErrorFixer] "C:\Program Files\Error Fixer\ErrorFixer.Exe" /bootO4 - HKCU\..\Run: [ff] nof.exeOther than that I see a lot of phone software running on your pc as a resident, not needed. Edited October 9, 2005 by epic Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now