Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Read this topic before posting a log.
DO NOT post a ComboFix log unless requested to.
Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.
When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.
Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
![]() ![]() |
Mar 8 2005, 05:08 PM
Post
#1
|
|
|
Member ![]() ![]() Group: Members Posts: 50 Joined: 8-March 05 Member No.: 13,897 |
Logfile of HijackThis v1.99.1 Scan saved at 21:51:48, on 3/8/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000) Running processes: C:\winnt\System32\smss.exe C:\winnt\system32\winlogon.exe C:\winnt\system32\services.exe C:\winnt\system32\lsass.exe C:\winnt\system32\svchost.exe C:\winnt\System32\svchost.exe C:\winnt\Explorer.EXE C:\winnt\system32\spoolsv.exe C:\winnt\System32\wfxsnt40.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\winnt\System32\nvsvc32.exe C:\winnt\System32\svchost.exe C:\WINNT\system32\ZONELABS\vsmon.exe C:\Program Files\QuickTime\qttask.exe C:\winnt\System32\ctfmon.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\WinMX\WinMX.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe C:\Program Files\Wireless Device\Wireless Mouse\MouseAp.exe C:\Program Files\Wireless Device\Wireless Keyboard\Magickey.exe C:\Program Files\Wireless Device\Wireless Keyboard\osd.exe C:\Program Files\Grisoft\AVG Free\avgwb.dat D:\Firefox\firefox.exe C:\winnt\System32\wuauclt.exe C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Documents and Settings\Mark Hibbert\Desktop\MY files\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jimbutt.com/stuffs/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default.home/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://www-cache.freeserve.com:8080;ftp=http://www-cache.freeserve.com:8080 R3 - URLSearchHook: transURL Class - {C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70} - C:\WINNT\System32\SEARCH~1.DLL O1 - Hosts: 222.89.98.219 www.wo365.com O1 - Hosts: 222.89.98.219 cmfu.com O1 - Hosts: 222.89.98.219 www.cmfu.com O1 - Hosts: 222.89.98.219 9i0.com O1 - Hosts: 222.89.98.219 www.9flash.com O1 - Hosts: 222.89.98.219 9flash.com O1 - Hosts: 222.89.98.219 www.nowok.net O1 - Hosts: 222.89.98.219 nowok.net O1 - Hosts: 222.89.98.219 wisa.com.cn O1 - Hosts: 222.89.98.219 www.sia.com.cn O1 - Hosts: 222.89.98.219 www.wisa.cn O1 - Hosts: 222.89.98.219 wisa.cn O1 - Hosts: 222.89.98.219 www.zhao99.com O1 - Hosts: 222.89.98.219 zhao99.com O1 - Hosts: 222.89.98.219 www.wo123.com O1 - Hosts: 222.89.98.219 wo123.com O1 - Hosts: 222.89.98.219 wo99.com O1 - Hosts: 222.89.98.219 www.wo99.com O1 - Hosts: 222.89.98.219 www.page.com.cn O1 - Hosts: 222.89.98.219 page.com.cn O1 - Hosts: 222.89.98.219 www.432.cn O1 - Hosts: 222.89.98.219 432.cn O1 - Hosts: 222.89.98.219 wysw.com O1 - Hosts: 222.89.98.219 14.com.cn O1 - Hosts: 222.89.98.219 www.14.com.cn O1 - Hosts: 222.89.98.219 cnww.net O1 - Hosts: 222.89.98.219 www.mv99.com O1 - Hosts: 222.89.98.219 mv99.com O1 - Hosts: 222.89.98.219 www.youav.com O1 - Hosts: 222.89.98.219 www.mtvav.com O1 - Hosts: 222.89.98.219 www.98983.com O1 - Hosts: 222.89.98.219 98983.com O1 - Hosts: 222.89.98.219 www.114.com.cn O1 - Hosts: 222.89.98.219 114.com.cn O1 - Hosts: 222.89.98.219 www.net114.com O1 - Hosts: 222.89.98.219 www.skywz.com O1 - Hosts: 222.89.98.219 skywz.com O1 - Hosts: 222.89.98.219 www.hao6.com O1 - Hosts: 222.89.98.219 hao6.com O1 - Hosts: 222.89.98.219 www.678a.com O1 - Hosts: 222.89.98.219 678a.com O1 - Hosts: 222.89.98.219 www.7510.com O1 - Hosts: 222.89.98.219 7510.com O1 - Hosts: 222.89.98.219 www.zzkan.com O1 - Hosts: 222.89.98.219 zzkan.com O1 - Hosts: 222.89.98.219 www.ca183.com O1 - Hosts: 222.89.98.219 ca183.com O1 - Hosts: 222.89.98.219 3tom.com O1 - Hosts: 222.89.98.219 www.yhjm.com O1 - Hosts: 222.89.98.219 yhjm.com O1 - Hosts: 222.89.98.219 www.k369.com O1 - Hosts: 222.89.98.219 www.xxwww.com O1 - Hosts: 222.89.98.219 xxwww.com O1 - Hosts: 222.89.98.219 www.fm1000.net O1 - Hosts: 222.89.98.219 fm1000.net O1 - Hosts: 222.89.98.219 www.ok135.com O1 - Hosts: 222.89.98.219 ok135.com O1 - Hosts: 222.89.98.219 www.link999.com O1 - Hosts: 222.89.98.219 link999.com O1 - Hosts: 222.89.98.219 www.001wz.com O1 - Hosts: 222.89.98.219 001wz.com O1 - Hosts: 222.89.98.219 www.7t7t.com O1 - Hosts: 222.89.98.219 7t7t.com O1 - Hosts: 222.89.98.219 www.7k7k.com O1 - Hosts: 222.89.98.219 7k7k.com O1 - Hosts: 222.89.98.219 www.webcool.net O1 - Hosts: 222.89.98.219 webcool.net O1 - Hosts: 222.89.98.219 www.51sobu.com O1 - Hosts: 222.89.98.219 51sobu.com O1 - Hosts: 222.89.98.219 cy.51sobu.com O1 - Hosts: 222.89.98.219 www.fj3721.com O1 - Hosts: 222.89.98.219 fj3721.com O1 - Hosts: 222.89.98.219 www.msncn.com O1 - Hosts: 222.89.98.219 msncn.com O1 - Hosts: 222.89.98.219 www.6235.com O1 - Hosts: 222.89.98.219 6235.com O1 - Hosts: 222.89.98.219 www.8goo.com O1 - Hosts: 222.89.98.219 8goo.com O1 - Hosts: 222.89.98.219 www.baimin.com O1 - Hosts: 222.89.98.219 baimin.com O1 - Hosts: 222.89.98.219 www.bwwz.com O1 - Hosts: 222.89.98.219 bwwz.com O1 - Hosts: 222.89.98.219 www.howow.net O1 - Hosts: 222.89.98.219 howow.net O1 - Hosts: 222.89.98.219 www.tongchi.com O1 - Hosts: 222.89.98.219 tongchi.com O1 - Hosts: 222.89.98.219 www.65658.com O1 - Hosts: 222.89.98.219 65658.com O1 - Hosts: 222.89.98.219 www.7o7o.com O1 - Hosts: 222.89.98.219 7o7o.com O1 - Hosts: 222.89.98.219 5126.net O1 - Hosts: 222.89.98.219 www.5126.net O1 - Hosts: 222.89.98.219 www.wangzhiku.com O1 - Hosts: 222.89.98.219 wangzhiku.com O1 - Hosts: 222.89.98.219 www.soyeah.com O1 - Hosts: 222.89.98.219 soyeah.com O1 - Hosts: 222.89.98.219 www.sowang.cn O1 - Hosts: 222.89.98.219 sowang.cn O1 - Hosts: 222.89.98.219 www.77177.com O1 - Hosts: 222.89.98.219 77177.com O1 - Hosts: 222.89.98.219 www.look8.net O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: BL Class - {28F65FCB-D130-11D8-BA48-8BE0C49AF370} - C:\WINNT\System32\popup_bl.dll O2 - BHO: HTDP Class - {9E6EC32A-7C19-4409-99E8-FC980BCDAF26} - C:\winnt\htass.dll (file missing) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: SToolbar - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\WINNT\stlbd.dll O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe O4 - HKLM\..\Run: [Wi32De75] \System\win32rt.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe O4 - HKLM\..\Run: [sThhxcU5O] C:\documents and settings\mark hibbert\local settings\temp\sThhxcU5O.exe O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\SpyHunter\SpyHunter.exe O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINNT\System32\bridge.dll",Load O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Piolet] C:\Program Files\Piolet\Piolet.exe SILENT O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NewsUpd] C:\Program Files\Creative\News\NewsUpd.EXE /q O4 - HKLM\..\Run: [mswspl] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [MMSystem] c:\winnt\rundll32.exe "c:\winnt\system32\mmsystem.dll"", RunDll32 O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" O4 - HKLM\..\Run: [LifeScape Media Detector] C:\Program Files\Picasa\PicasaMediaDetector.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\winnt\System32\ctfmon.exe O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - HKCU\..\Run: [WinMX] C:\Program Files\WinMX\WinMX.exe -m O4 - HKCU\..\Run: [Spyware Begone] c:\freescan\freescan.exe -FastScan O4 - HKCU\..\Run: [New Value #2] C:\Documents and Settings\Mark hibbert\desktop\wanadoo O4 - HKCU\..\Run: [New Value #1] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart O4 - HKCU\..\Run: [CTFMON32] C:\WINNT\System32\CTFMON32.EXE O4 - HKCU\..\Run: [CSRSSU] C:\WINNT\System32\CSRSSU.EXE O4 - HKCU\..\Run: [bindmags] C:\DOCUME~1\MARKHI~1\APPLIC~1\SCRDUP~1\Extra sign.exe O4 - Startup: PowerReg SchedulerV2.RB0 O4 - Startup: PowerReg SchedulerV2.exe O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe O4 - Global Startup: LG SyncManager.lnk = ? O4 - Global Startup: Enable Wireless Optical Mouse Driver.lnk = C:\Program Files\Wireless Device\Wireless Mouse\MouseAp.exe O4 - Global Startup: Enable Wireless Keyboard Driver.lnk = C:\Program Files\Wireless Device\Wireless Keyboard\Magickey.exe O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Search with Freeserve - res://C:\PROGRA~1\FREESE~1\FSBar\FSBar.dll/VSearch.htm O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll O9 - Extra button: Corel Network monitor worker - {A80EBD8F-C9CB-4F55-8429-21303C2132A2} - C:\WINNT\System32\intlmain.dll O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {A80EBD8F-C9CB-4F55-8429-21303C2132A2} - C:\WINNT\System32\intlmain.dll O9 - Extra button: Microsoft AntiSpyware helper - {22B798B9-7C50-4C4F-BA9F-EFD1EAEE27E3} - (no file) (HKCU) O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {22B798B9-7C50-4C4F-BA9F-EFD1EAEE27E3} - (no file) (HKCU) O9 - Extra button: Corel Network monitor worker - {A80EBD8F-C9CB-4F55-8429-21303C2132A2} - C:\WINNT\System32\intlmain.dll (HKCU) O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {A80EBD8F-C9CB-4F55-8429-21303C2132A2} - C:\WINNT\System32\intlmain.dll (HKCU) O16 - DPF: ChatSpace Full Java Client 3.1.0.246 - http://chat-a4.wanadoo.co.uk/Java/cfs31246.cab O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} (AsyncDownloader Class) - http://survey.otxresearch.com/Preloader.dll O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab28578.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by20fd.bay20.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab28578.cab O16 - DPF: {A243F6C2-34D2-4549-BCCD-A7BEF759B236} (Seekford Solutions, Inc.'s ssiPictureUploader Control) - http://www.funtigo.com/funtigo/pictureUplo...ureUploader.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab28578.cab O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\winnt\System32\nvsvc32.exe O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINNT\system32\ZONELABS\vsmon.exe Thankyou. |
|
|
|
Mar 9 2005, 04:46 PM
Post
#2
|
|
![]() Cleaner on Duty ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 5,480 Joined: 1-September 04 From: Bucharest, Romania Member No.: 2,383 |
Duplicate
http://www.bleepingcomputer.com/forums/ind...topic=13004&hl= Topic closed -------------------- |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 9th January 2009 - 06:23 AM |