Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Read this topic before posting a log.
DO NOT post a ComboFix log unless requested to.
Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.
When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.
Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
Mar 15 2007, 06:16 PM
Post
#1
|
|
|
Member ![]() ![]() Group: Members Posts: 37 Joined: 23-February 07 From: Norwich , East Anglia Member No.: 113,565 |
Logfile of HijackThis v1.99.1
Scan saved at 22:46:52, on 15/03/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\Explorer.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\system32\svchosts.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe C:\Program Files\Ipwindows\ipwins.exe C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\STEM32~1\wuauclt.exe C:\Documents and Settings\kenneth fiddy\Application Data\F?nts\??xplore.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\WINDOWS\system32\cidaemon.exe C:\DOCUME~1\KENNET~1\LOCALS~1\Temp\Temporary Directory 1 for HijackThis.zip\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tesco.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_03\bin\ssv.dll (file missing) O2 - BHO: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{30E08~1\Bar888.dll O2 - BHO: (no name) - {E4487942-99A5-B557-A0DE-B7DECCB05CC4} - C:\WINDOWS\system32\rjcsxsx.dll O2 - BHO: (no name) - {E71B7D43-C9A1-B104-F7DE-B7DECCB05B95} - C:\WINDOWS\system32\sttgv.dll O3 - Toolbar: (no name) - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - (no file) O3 - Toolbar: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{30E08~1\Bar888.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [PixAlertMonitor] C:\Program Files\BOS\PixAlert Monitor Home\MCtrlA5-0.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [McafWelcome] C:\Program Files\McAfee.com\Agent\mcwelcom.exe O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto O4 - HKLM\..\Run: [Wmaamokforkdvd] C:\Documents and Settings\All Users\Application Data\Cityuserwmaamok\dumbfile.exe O4 - HKLM\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Euol] "C:\WINDOWS\STEM32~1\wuauclt.exe" -vt ndrv O4 - HKCU\..\Run: [Wvos] "C:\Documents and Settings\kenneth fiddy\Application Data\F?nts\??xplore.exe" 99001396 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: dllhost.exe O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider 'lsp32.dll' missing O11 - Options group: [INTERNATIONAL] International* O14 - IERESET.INF: START_PAGE_URL=http://www.iqon.ie -------------------- Solar Wind and Biodiesel I am doing my bit to stop Climate change to this World but What have the British Government done?
|
|
|
|
whitevanman Please Help .another Hijackthis Log Mar 15 2007, 06:16 PM
RichieUK Welcome to the BleepingComputer whitevanman :)
Y... Mar 16 2007, 04:01 AM
whitevanman installed avg 7.5 free found 319 bad things and de... Mar 16 2007, 07:28 PM
RichieUK Reboot your computer into [color=RED]SAFE MODE... Mar 16 2007, 07:36 PM
whitevanman SmitFraudFix v2.148
Scan done at 20:58:10.03, 17/... Mar 17 2007, 04:25 PM
RichieUK Click on Start>Run and type Services.msc then h... Mar 17 2007, 04:43 PM
whitevanman Computer is running better but still not A1
boxes ... Mar 17 2007, 06:14 PM
whitevanman Think I have something called ISTbar on this compu... Mar 18 2007, 06:20 AM
RichieUK Download LSPFix from:
http://www.bleepingcomputer.... Mar 18 2007, 08:32 AM
whitevanman Logfile of The Avenger version 1, by Swandog46
Run... Mar 18 2007, 05:37 PM
RichieUK Please download Combofix and save to the desktop:
... Mar 19 2007, 02:23 AM
whitevanman "kenneth fiddy" - 07-03-19 21:44:22 S... Mar 19 2007, 05:01 PM
RichieUK Find and delete the following files please:
C:... Mar 19 2007, 06:13 PM
whitevanman Mission complete
again thankyou for your time and... Mar 19 2007, 07:06 PM
RichieUK You're most welcome whitevanman,and thankyou f... Mar 19 2007, 07:41 PM![]() ![]() |
| Lo-Fi Version | Time is now: 21st November 2009 - 08:41 PM |