system
10
- Here’s my log from Hijackthis:
Logfile of HijackThis v1.99.0
Scan saved at 1:48:56 PM, on 12/29/04
Platform: Windows 95 C (Win9x 4.00.1212)
MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\SPOWER.DRV
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\THOTKEY.EXE
C:\WINDOWS\SYSTEM\TPWRMGR.EXE
C:\WINDOWS\SYSTEM\LOADWC.EXE
C:\PROGRAM FILES\NOPOPS\NOPOPS.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
C:\WINDOWS\SYSTEM\IPCFG.EXE
C:\WINDOWS\SYSTEM\SCANDS32.EXE
C:\WINDOWS\SYSTEM\SNNPAPI.EXE
C:\PROGRAM FILES\IE NEW WINDOW MAXIMIZER\IEMAXIMIZER.EXE
C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOTASKBARICON.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://nkvd.us (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://nkvd.us (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = http://fastsearchweb.com/srh.php?q=%s
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://nkvd.us (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = ,
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\SYSTEM\SNNPAPI.DLL/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://4-counter.com/?a=2&b=igon
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://4-counter.com/?a=2&b=igon
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Hawk Communications
R3 - URLSearchHook: (no name) - {870538D5-2A7E-A53E-51B9-154EE75BE772} - EXE32EXE.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORM.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O4 - HKLM..\Run: [SystemTray] SysTray.Exe
O4 - HKLM..\Run: [THotkey] THotkey.Exe
O4 - HKLM..\Run: [TPwrMgr] TPwrMgr.Exe
O4 - HKLM..\Run: [TDspOff] TDspOff.Exe B
O4 - HKLM..\Run: [TFunckey] TFuncKey.exe
O4 - HKLM..\Run: [TEscKey] TEscKey.exe
O4 - HKLM..\Run: [BrowserWebCheck] loadwc.exe
O4 - HKLM..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM..\Run: [NoPops] C:\PROGRAM FILES\NOPOPS\NOPOPS.EXE
O4 - HKLM..\Run: [Pgu.exe] C:\WINDOWS\TEMP\PGU.EXE
O4 - HKLM..\Run: [5G8ZKBL3BLZZFS] C:\WINDOWS\SYSTEM\Fsm6BY.exe
O4 - HKLM..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
O4 - HKLM..\Run: [ipcfg.exe] C:\WINDOWS\SYSTEM\IPCFG.EXE
O4 - HKLM..\Run: [scands32.exe] C:\WINDOWS\SYSTEM\SCANDS32.EXE
O4 - HKLM..\Run: [SysTray] C:\WINDOWS\SYSTEM\SNNPAPI.EXE
O4 - HKLM..\Run: [trycrt] _ctcp.exe
O4 - HKLM..\Run: [xxtoolbar] MsNetHelper.exe
O4 - HKLM..\RunServices: [TSPower] SPower.drv
O4 - HKLM..\RunServices: [TDockNUndock] TEject.drv
O4 - HKLM..\RunServices: [TWarmBay] TWarmBay.drv
O4 - HKLM..\RunServices: [TWBrowse] TWBrowse.drv
O4 - HKLM..\RunServices: [TCDPlay] TCDPlay.drv
O4 - HKLM..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 - HKCU..\Run: [IE New Window Maximizer] C:\Program Files\IE New Window Maximizer\iemaximizer.exe
O4 - HKCU..\Run: [RoboForm] “C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\RoboTaskBarIcon.exe”
O4 - HKCU..\Run: [Windows Internet Protocol] C:\WINDOWS\SYSTEM32\WINPROC32.EXE
O4 - HKCU..\Run: [WareOut] “C:\Program Files\WareOut\WareOut.exe”
O4 - HKCU..\Run: [JAguAr] Trayz.exe
O4 - HKCU..\Run: [Bogobot] uio.exe
O4 - HKCU..\Run: [SAPSTR] SysEntry.exe
O8 - Extra context menu item: Fill Forms &] - file://C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\RoboFormComFillForms.html
O8 - Extra context menu item: Save Forms &[ - file://C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\RoboFormComSavePass.html
O8 - Extra context menu item: Customize Menu &4 - file://C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\RoboFormComCustomizeIEMenu.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\RoboFormComShowToolbar.html
O9 - Extra ‘Tools’ menuitem: RF Toolbar &2 - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\RoboFormComShowToolbar.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\RoboFormComFillForms.html
O9 - Extra ‘Tools’ menuitem: Fill Forms &] - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\RoboFormComSavePass.html
O9 - Extra ‘Tools’ menuitem: Save Forms &[ - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\RoboFormComSavePass.html
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.63.219.181.7
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O18 - Filter: text/html - {D0D33336-AB52-4C7A-A3A5-9071680D8A4F} - C:\WINDOWS\SYSTEM\SNNPAPI.DLL
O18 - Filter: text/plain - {D0D33336-AB52-4C7A-A3A5-9071680D8A4F} - C:\WINDOWS\SYSTEM\SNNPAPI.DLL
- Ref: Technical’s Posting
I changed my Avast setting as you described…no change. Still cannot connect to the internet via Internet Explorer 5.5.
I have Windows 95 , no firewall with dial-up connection.
Thanks for all your responses.