Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijack Removal


  • Please log in to reply
1 reply to this topic

#1 lizablair

lizablair

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:41 PM

Posted 13 June 2005 - 06:00 AM

Logfile of HijackThis v1.99.1
Scan saved at 5:59:04 AM, on 6/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Mary Blair\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://smbusiness.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://smbusiness.dellnet.com/
O4 - HKLM\..\RunOnce: [ntgz32.exe] C:\WINDOWS\ntgz32.exe
O4 - HKLM\..\RunOnce: [addhn.exe] C:\WINDOWS\addhn.exe
O4 - HKLM\..\RunOnce: [apilr.exe] C:\WINDOWS\apilr.exe
O4 - HKLM\..\RunOnce: [iego32.exe] C:\WINDOWS\system32\iego32.exe
O4 - HKLM\..\RunOnce: [netpm.exe] C:\WINDOWS\netpm.exe
O4 - HKLM\..\RunOnce: [mfcsv.exe] C:\WINDOWS\mfcsv.exe
O4 - HKLM\..\RunOnce: [atliq.exe] C:\WINDOWS\atliq.exe
O4 - HKLM\..\RunOnce: [ntve32.exe] C:\WINDOWS\system32\ntve32.exe
O4 - HKLM\..\RunOnce: [ipgo.exe] C:\WINDOWS\ipgo.exe
O4 - HKLM\..\RunOnce: [crzl32.exe] C:\WINDOWS\crzl32.exe
O4 - HKLM\..\RunOnce: [appjr.exe] C:\WINDOWS\appjr.exe
O4 - HKLM\..\RunOnce: [ntyg32.exe] C:\WINDOWS\system32\ntyg32.exe
O4 - HKLM\..\RunOnce: [atlrx.exe] C:\WINDOWS\system32\atlrx.exe
O4 - HKLM\..\RunOnce: [d3xb.exe] C:\WINDOWS\system32\d3xb.exe
O4 - HKLM\..\RunOnce: [mfcrn.exe] C:\WINDOWS\system32\mfcrn.exe
O4 - HKLM\..\RunOnce: [addgu.exe] C:\WINDOWS\system32\addgu.exe
O4 - HKLM\..\RunOnce: [mfcuw.exe] C:\WINDOWS\system32\mfcuw.exe
O4 - HKLM\..\RunOnce: [addpi.exe] C:\WINDOWS\addpi.exe
O4 - HKLM\..\RunOnce: [iehg32.exe] C:\WINDOWS\iehg32.exe
O4 - HKLM\..\RunOnce: [netho.exe] C:\WINDOWS\system32\netho.exe
O4 - HKLM\..\RunOnce: [atlls32.exe] C:\WINDOWS\atlls32.exe
O4 - HKLM\..\RunOnce: [sysbi.exe] C:\WINDOWS\system32\sysbi.exe
O4 - HKLM\..\RunOnce: [javaay32.exe] C:\WINDOWS\system32\javaay32.exe
O4 - HKLM\..\RunOnce: [apizn32.exe] C:\WINDOWS\apizn32.exe
O4 - HKLM\..\RunOnce: [atlup.exe] C:\WINDOWS\atlup.exe
O4 - HKLM\..\RunOnce: [ntyt32.exe] C:\WINDOWS\system32\ntyt32.exe
O4 - HKLM\..\RunOnce: [apiib.exe] C:\WINDOWS\apiib.exe
O4 - HKLM\..\RunOnce: [netnq32.exe] C:\WINDOWS\system32\netnq32.exe
O4 - HKLM\..\RunOnce: [msxw.exe] C:\WINDOWS\system32\msxw.exe
O4 - HKLM\..\RunOnce: [atlut32.exe] C:\WINDOWS\atlut32.exe
O4 - HKLM\..\RunOnce: [netkb.exe] C:\WINDOWS\netkb.exe
O4 - HKLM\..\RunOnce: [javagx32.exe] C:\WINDOWS\javagx32.exe
O4 - HKLM\..\RunOnce: [appdz32.exe] C:\WINDOWS\appdz32.exe
O4 - HKLM\..\RunOnce: [winyl32.exe] C:\WINDOWS\system32\winyl32.exe
O4 - HKLM\..\RunOnce: [winjf32.exe] C:\WINDOWS\system32\winjf32.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /1
O4 - HKCU\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "Mary Blair"
O17 - HKLM\System\CCS\Services\Tcpip\..\{36AA60A3-3B7B-4547-ACF0-6222FFE6099A}: NameServer = 216.231.160.2 209.102.191.47
O17 - HKLM\System\CS1\Services\Tcpip\..\{36AA60A3-3B7B-4547-ACF0-6222FFE6099A}: NameServer = 216.231.160.2 209.102.191.47
O23 - Service: Network Security Service (NSS) ( 11F#`I) - Unknown owner - C:\WINDOWS\adduo32.exe" /s (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe

BC AdBot (Login to Remove)

 


m

#2 groovicus

groovicus

  • Security Colleague
  • 9,963 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Centerville, SD
  • Local time:07:41 PM

Posted 14 June 2005 - 09:32 AM

If you still need help, could you post a fresh log please?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users