My hijackthis log

Hyperlite

Diamond Member
May 25, 2004
5,664
2
76
i'm having a lot of trouble with idle transmission on dial-up. can someone take a look at my hijackthis log?

Logfile of HijackThis v1.98.2
Scan saved at 8:23:02 PM, on 9/7/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Motherboard Monitor 5\MBM5.exe
C:\Program Files\Motherboard Monitor 5\DLL\display.dll
C:\Game Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.weather.com/weather...WeatherLocalUndeclared
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
O4 - HKLM\..\Run: [MBM 5] "C:\Program Files\Motherboard Monitor 5\MBM5.EXE"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\xhoaammg.exe
O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\llcedoi.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\RunServices: [Java Virtual Machine] javaw.exe
O4 - HKLM\..\RunServices: [WindowsReg% update] cicaiahjzpb.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.micros...site.cab?1093916757421
O17 - HKLM\System\CCS\Services\Tcpip\..\{CA134504-162B-4277-8F96-95B485B23AAF}: NameServer = 204.116.57.2 206.74.254.2
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll

i just ordered a SP2 CD, so i will have that shortly, and i'm about to install Norton System works 2004, which is actually a great program...i'm downloading AntiVir at the moment.

thanks for the help
 

yankeesfan

Diamond Member
Aug 6, 2004
5,922
1
71
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm [/b](Uninstall the program associated with it from add/remove programs, too)
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm [/b](Uninstall the program associated with it from add/remove programs, too)
O4 - HKLM\..\RunServices: [WindowsReg% update] cicaiahjzpb.exe (what's this?)

All I found (might be more)
 

Hyperlite

Diamond Member
May 25, 2004
5,664
2
76
Originally posted by: yankeesfan
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm [/b](Uninstall the program associated with it from add/remove programs, too)
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm [/b](Uninstall the program associated with it from add/remove programs, too)
O4 - HKLM\..\RunServices: [WindowsReg% update] cicaiahjzpb.exe (what's this?)

All I found (might be more)

those DAP files i know are there, i put them there. its my download manager, so they are fine....i just ran about 5 virus scan programs with updated defs on all of them, and everything seems to be fine, or fixed rather. if there is nothing else there of note, then i guess its a good thing. that last thing, 04, i have no idea what that is...
 

MechxWarrior

Senior member
Mar 2, 2004
565
0
76
O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\xhoaammg.exe
O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\llcedoi.exe
O4 - HKLM\..\RunServices: [WindowsReg% update] cicaiahjzpb.exe

Those seem bogus to me...not sure if its with SP2 tho but id kill em with a backup.
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
im at a 5 minute break for a clan match, DAP is not your friend, see this, i will post a solution when i get finished with the match.
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
Hello Hyperlite,

Before you do anything
1. Uninstall Download Accelrator plus, see this page for why and to find an alternate, spyware free download manager.
2. Make sure that you have extracted HiJackthis to a folder that is isolated before removing anything, for hijackthis makes backups within the folder it is in.
3. Reboot into safe mode
4. Close all browsers/windows explorer

fix the following in hijackthis(kill the process in process viewer, if its there)

  • O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
    O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\xhoaammg.exe
    O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\llcedoi.exe
    O4 - HKLM\..\RunServices: [WindowsReg% update] cicaiahjzpb.exe
    O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
    O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm

 

Hyperlite

Diamond Member
May 25, 2004
5,664
2
76
alrighty i did all that, and so far so good. thanks alot for the help. i'll use your link to find a suitable download manager.