Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.| Important Announcement: The winners of the BC Million Post contest have been announced. You can read who the winners are at this post. - BleepingComputer Management |
Read this topic before posting a log.
DO NOT post a ComboFix log unless requested to.
Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.
When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.
Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
![]() ![]() |
Dec 22 2004, 11:06 AM
Post
#1
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 20-December 04 Member No.: 7,475 |
here is the log: Logfile of HijackThis v1.99.0 Scan saved at 09:46:26, on 2004-12-20 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe C:\WINNT\system32\spoolsv.exe C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe C:\WINNT\system32\drivers\CDAC11BA.EXE C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\regsvc.exe C:\Program Files\Symantec AntiVirus\SavRoam.exe C:\WINNT\system32\MSTask.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\WINNT\Explorer.EXE C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Free Surfer\fs20.exe C:\Program Files\ISTsvc\istsvc.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\ACAD2000\acad.exe C:\Documents and Settings\Station-10\Bureau\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.queb.ca R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.buldog-search.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.buldog-search.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.queb.ca R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.altavista.com R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = www.altavista.com R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = www.altavista.com O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O9 - Extra button: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\Free Surfer\FS20.exe O9 - Extra 'Tools' menuitem: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\Free Surfer\FS20.exe O16 - DPF: {00130000-B1BA-11CE-ABC6-F5B2E79D9E3F} (LEAD Main Control (13.0)) - http://transaction.hydroquebec.com/lg/document/Lgd_Vue1.CAB O16 - DPF: {31549E82-43C3-4220-BF26-008CB8946C85} (Lgd_Vue2.lgdvue) - http://transaction.hydroquebec.com/lg/document/Lgd_Vue2.CAB O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab O16 - DPF: {B2BE75F3-9197-11CF-ABF4-08000996E931} (Autodesk WHIP! Control) - ftp://ftp.autodesk.com/pub/autocad/plugin/whip.cab O23 - Service: Avertissement - Unknown - C:\WINNT\System32\services.exe O23 - Service: Gestion d'applications - Unknown - C:\WINNT\system32\services.exe O23 - Service: Autodesk Licensing Service - Unknown - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: Explorateur d'ordinateur - Unknown - C:\WINNT\System32\services.exe O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\system32\drivers\CDAC11BA.EXE O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: Client DHCP - Unknown - C:\WINNT\System32\services.exe O23 - Service: Service d'administration du Gestionnaire de disque logique - Unknown - C:\WINNT\System32\dmadmin.exe O23 - Service: Gestionnaire de disque logique - Unknown - C:\WINNT\System32\services.exe O23 - Service: Client DNS - Unknown - C:\WINNT\System32\services.exe O23 - Service: Journal des événements - Unknown - C:\WINNT\system32\services.exe O23 - Service: Service de télécopie - Unknown - C:\WINNT\system32\faxsvc.exe O23 - Service: Serveur - Unknown - C:\WINNT\System32\services.exe O23 - Service: Station de travail - Unknown - C:\WINNT\System32\services.exe O23 - Service: Service d'application d'assistance TCP/IP NetBIOS - Unknown - C:\WINNT\System32\services.exe O23 - Service: Affichage des messages - Unknown - C:\WINNT\System32\services.exe O23 - Service: Partage de Bureau à distance NetMeeting - Unknown - C:\WINNT\System32\mnmsrvc.exe O23 - Service: DDE réseau - Unknown - C:\WINNT\system32\netdde.exe O23 - Service: DSDM DDE réseau - Unknown - C:\WINNT\system32\netdde.exe O23 - Service: Ouverture de session réseau - Unknown - C:\WINNT\System32\lsass.exe O23 - Service: Fournisseur de la prise en charge de sécurité LM NT - Unknown - C:\WINNT\System32\lsass.exe O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe O23 - Service: Plug-and-Play - Unknown - C:\WINNT\system32\services.exe O23 - Service: Agent de stratégie IPSEC - Unknown - C:\WINNT\System32\lsass.exe O23 - Service: Emplacement protégé - Unknown - C:\WINNT\system32\services.exe O23 - Service: Gestionnaire de comptes de sécurité - Unknown - C:\WINNT\system32\lsass.exe O23 - Service: SAVRoam - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Prise en charge des cartes à puces - Unknown - C:\WINNT\System32\SCardSvr.exe O23 - Service: Carte à puce - Unknown - C:\WINNT\System32\SCardSvr.exe O23 - Service: Planificateur de tâches - Unknown - C:\WINNT\system32\MSTask.exe O23 - Service: Service d'exécution par délégation - Unknown - C:\WINNT\system32\services.exe O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: SoundMAX Agent Service - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe O23 - Service: Journaux et alertes de performance - Unknown - C:\WINNT\system32\smlogsvc.exe O23 - Service: Telnet - Unknown - C:\WINNT\system32\tlntsvr.exe O23 - Service: Client de suivi de lien distribué - Unknown - C:\WINNT\system32\services.exe O23 - Service: Gestionnaire d'utilitaires - Unknown - C:\WINNT\System32\UtilMan.exe O23 - Service: Horloge Windows - Unknown - C:\WINNT\System32\services.exe O23 - Service: Infrastructure de gestion Windows - Unknown - C:\WINNT\System32\WBEM\WinMgmt.exe O23 - Service: Extensions du pilote WMI - Unknown - C:\WINNT\system32\Services.exe please help me ! |
|
|
|
Dec 23 2004, 03:42 PM
Post
#2
|
|
![]() Cleaner on Duty ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 5,480 Joined: 1-September 04 From: Bucharest, Romania Member No.: 2,383 |
Hi
QUOTE Hi, i'm having the bulldgo-search problem with hhnt.exe file. Download KillBox here: KillBox. Unzip it to your desktop. Start Killbox and click on Tools --> Select Delete Temp Files. Click OK. Select the Delete on reboot option. Copy and paste the following file to the field labeled "Full path of file to delete" C:\WINDOWS\hhnt.exe Press the Delete button (the button that looks like a red circle with a white X in it). A first dialog box will ask if you want to delete the file on reboot, press the YES button. A second dialog box will ask you if you want to REBOOT now. Press the YES button. Your computer will reboot. Run HijackThis!, press Scan, and put a check mark next to all these: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.buldog-search.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.buldog-search.com/ Close all other windows and browsers, and press the Fix Checked button. REBOOT your computer and post a new log please. -------------------- |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 22nd November 2008 - 03:24 AM |