Home » Spyware Protection » Hijacked Browser Analysis » 

Re: HijackThisLog Analysis - Rahul

Date: Friday, 17 September, 2004 9:16 PM

iehost.exe.. ? dou know what it is cos it take up a lot of RAM..any help would be great thanks.. rahul.

Hi Rahul,

Before you start, you may like to consider uninstalling P2P Networking from Add/Remove Software.  You can always reinstall them after you have clean up your system.  More information on IEHOST.exe can be found here

Update from Rahul on 22 September 2004:

Thanks alot for your reply .. it help loads.. and my coputer seems spy ware free.

Reference:

Here is what you should do.

End the below suspicious process :

C:\WINDOWS\System32\IEHost.exe
C:\WINDOWS\system32\pcs\pcsvc.exe
C:\WINDOWS\System32\CMUTIL46.exe

Remove these search keys:

O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C: \ Program Files \ MyWay \ SrchAstt \ 1.bin \ MYSRCHAS.DLL (file missing)

Remove these additional browser plug-in keys (O2...O4):

O4 - HKLM \ .. \ Run: [Bakra] C: \ WINDOWS \ System32 \ IEHost.exe
O4 - HKLM \ .. \ Run: [Pcsv] C: \ WINDOWS \ system32 \ pcs \ pcsvc.exe
O4 - HKLM \ .. \ Run: [13248e5c62d1] C: \ WINDOWS \ System32 \ CMUTIL46.exe

Remove these extra items in IE menu (O8...O9):

O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C: \ WINDOWS \ System32 \ ms.exe
O9 - Extra ´Tools´ menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C: \ WINDOWS \ System32 \ ms.exe

Reboot the computer and put it to safe mode.  Then delete these files from your C: drive.

C:\WINDOWS\System32\IEHost.exe
C:\WINDOWS\system32\pcs\pcsvc.exe
C:\WINDOWS\System32\CMUTIL46.exe

Original log but with private information removed.


Logfile of HijackThis v1.98.2
Scan saved at 14:15:18, on 17 / 09 / 2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C: \ WINDOWS \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ system32 \ spoolsv.exe
C: \ WINDOWS \ System32 \ DRIVERS \ CDANTSRV.EXE
C: \ WINDOWS \ System32 \ CTsvcCDA.exe
C: \ Program Files \ Norton AntiVirus \ navapsvc.exe
C: \ WINDOWS \ System32 \ nvsvc32.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ System32 \ Tablet.exe
C: \ WINDOWS \ System32 \ MsPMSPSv.exe
C: \ WINDOWS \ Explorer.EXE
C: \ WINDOWS \ BCMSMMSG.exe
C: \ WINDOWS \ System32 \ DSentry.exe
C: \ PROGRA~1 \ NORTON~1 \ navapw32.exe
C: \ Program Files \ Roxio \ Easy CD Creator 5 \ DirectCD \ DirectCD.exe
C: \ Program Files \ ScanSoft \ OmniPageSE \ opware32.exe
C: \ Program Files \ iPod \ bin \ iPodManager.exe
C: \ Program Files \ MUSICMATCH \ MUSICMATCH Jukebox \ mm_tray.exe
C: \ Program Files \ Microsoft Hardware \ Mouse \ point32.exe
C: \ Program Files \ QuickTime \ qttask.exe
C: \ WINDOWS \ System32 \ P2P Networking \ P2P Networking.exe
C: \ WINDOWS \ System32 \ IEHost.exe
C: \ WINDOWS \ system32 \ pcs \ pcsvc.exe
C: \ WINDOWS \ System32 \ CMUTIL46.exe
C: \ Program Files \ MSN Messenger \ msnmsgr.exe
C: \ Program Files \ Adobe \ Acrobat 5.0 \ Distillr \ AcroTray.exe
C: \ Program Files \ Wacom \ TabUserW.exe
C: \ Program Files \ WinZip \ WZQKPICK.EXE
C: \ Program Files \ Creative \ SBLive \ Diagnostics \ diagent.exe
C: \ Program Files \ iPod \ bin \ iPodService.exe
C: \ Program Files \ Internet Explorer \ iexplore.exe
C: \ Documents and Settings \ Rahul \ Desktop \ 1188084 \ HijackThis.exe

R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main,Default_Page_URL = website: euro.dell.com / countries / uk / enu / gen / default.htm
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main,Search Bar = file: / / C: \ WINDOWS \ System32 \ SearchBar.htm
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main,Start Page = website: bbc.co.uk /
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main,Default_Page_URL = website: euro.dell.com / countries / uk / enu / gen / default.htm
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main,Start Page = website: euro.dell.com / countries / uk / enu / gen / default.htm
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main,Window Title = Tiscali 10.0
O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C: \ Program Files \ MyWay \ SrchAstt \ 1.bin \ MYSRCHAS.DLL (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C: \ Program Files \ Adobe \ Acrobat 5.0 \ Reader \ ActiveX \ AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c: \ program files \ google \ googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C: \ Program Files \ Norton AntiVirus \ NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C: \ WINDOWS \ System32 \ msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C: \ Program Files \ Norton AntiVirus \ NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c: \ program files \ google \ googletoolbar1.dll
O4 - HKLM \ .. \ Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM \ .. \ Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM \ .. \ Run: [diagent] "C: \ Program Files \ Creative \ SBLive \ Diagnostics \ diagent.exe" startup
O4 - HKLM \ .. \ Run: [UpdReg] C: \ WINDOWS \ UpdReg.EXE
O4 - HKLM \ .. \ Run: [DVDSentry] C: \ WINDOWS \ System32 \ DSentry.exe
O4 - HKLM \ .. \ Run: [NAV Agent] C: \ PROGRA~1 \ NORTON~1 \ navapw32.exe
O4 - HKLM \ .. \ Run: [AdaptecDirectCD] "C: \ Program Files \ Roxio \ Easy CD Creator 5 \ DirectCD \ DirectCD.exe"
O4 - HKLM \ .. \ Run: [Omnipage] C: \ Program Files \ ScanSoft \ OmniPageSE \ opware32.exe
O4 - HKLM \ .. \ Run: [iPodManager] C: \ Program Files \ iPod \ bin \ iPodManager.exe
O4 - HKLM \ .. \ Run: [MMTray] C: \ Program Files \ MUSICMATCH \ MUSICMATCH Jukebox \ mm_tray.exe
O4 - HKLM \ .. \ Run: [POINTER] point32.exe
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe" -atboottime
O4 - HKLM \ .. \ Run: [P2P Networking] C: \ WINDOWS \ System32 \ P2P Networking \ P2P Networking.exe / AUTOSTART
O4 - HKLM \ .. \ Run: [Bakra] C: \ WINDOWS \ System32 \ IEHost.exe
O4 - HKLM \ .. \ Run: [Pcsv] C: \ WINDOWS \ system32 \ pcs \ pcsvc.exe
O4 - HKLM \ .. \ Run: [13248e5c62d1] C: \ WINDOWS \ System32 \ CMUTIL46.exe
O4 - HKCU \ .. \ Run: [msnmsgr] "C: \ Program Files \ MSN Messenger \ msnmsgr.exe" / background
O4 - HKCU \ .. \ Run: [Symantec NetDriver Monitor] C: \ PROGRA~1 \ SYMNET~1 \ SNDMon.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Acrobat Assistant.lnk = C: \ Program Files \ Adobe \ Acrobat 5.0 \ Distillr \ AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C: \ Program Files \ Common Files \ Adobe \ Calibration \ Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office10 \ OSA.EXE
O4 - Global Startup: NETGEAR WG311v2 Smart Configuration.lnk = C: \ Program Files \ NETGEAR WG311v2 Adapter \ wlancfg5.exe
O4 - Global Startup: TabUserW.lnk = C: \ Program Files \ Wacom \ TabUserW.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C: \ Program Files \ WinZip \ WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll / cmsearch.html
O8 - Extra context menu item: Backward &Links - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll / cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll / cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res: / / C: \ PROGRA~1 \ MICROS~3 \ Office10 \ EXCEL.EXE / 3000
O8 - Extra context menu item: Si&milar Pages - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll / cmsimilar.html
O8 - Extra context menu item: Translate into English - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll / cmtrans.html
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C: \ WINDOWS \ System32 \ ms.exe
O9 - Extra ´Tools´ menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C: \ WINDOWS \ System32 \ ms.exe
O12 - Plugin for .spop: C: \ Program Files \ Internet Explorer \ Plugins \ NPDocBox.dll
O16 - DPF: ppctlcab - website: pestscan.com / scanner / ppctlcab.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - website: pestscan.com / scanner / axscanner.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - website: messenger.zone.msn.com / binary / MessengerStatsClient.cab28578.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - website: messenger.zone.msn.com / binary / SolitaireShowdown.cab28578.cab


Mail this pageMail this page