Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Post Logfile of HijackThis - Win 2003


  • This topic is locked This topic is locked
1 reply to this topic

#1 Azim

Azim

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:04:58 AM

Posted 10 October 2004 - 07:02 AM

Logfile of HijackThis v1.98.2
Scan saved at 14.01.25, on 10/10/2004
Platform: Unknown Windows (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 (6.00.3790.0000)

Running processes:
J:\WINDOWS\System32\smss.exe
J:\WINDOWS\system32\winlogon.exe
J:\WINDOWS\system32\services.exe
J:\WINDOWS\system32\lsass.exe
J:\WINDOWS\system32\svchost.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\system32\spoolsv.exe
J:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\system32\inetsrv\inetinfo.exe
J:\Programmi\Ahead\InCD\InCDsrv.exe
J:\Programmi\Network Associates\Common Framework\FrameworkService.exe
J:\Programmi\Network Associates\VirusScan\Mcshield.exe
J:\Programmi\Network Associates\VirusScan\VsTskMgr.exe
J:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
J:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe
J:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\System32\ups.exe
J:\Programmi\RealVNC\VNC4\WinVNC4.exe
J:\WINDOWS\system32\Dfssvc.exe
J:\Programmi\File comuni\System\MSSearch\Bin\mssearch.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\Explorer.EXE
J:\PROGRA~1\MICROS~4\MSSQL\binn\sqlagent.exe
J:\WINDOWS\SOUNDMAN.EXE
J:\Programmi\Analog Devices\SoundMAX\SMTray.exe
J:\Programmi\Network Associates\VirusScan\SHSTAT.EXE
J:\Programmi\Network Associates\Common Framework\UpdaterUI.exe
J:\Programmi\QuickTime\qttask.exe
J:\Programmi\Ahead\InCD\InCD.exe
J:\Programmi\Babylon\Babylon.exe
J:\WINDOWS\system32\ctfmon.exe
J:\Programmi\MSN Messenger\MsnMsgr.Exe
J:\Programmi\Messenger\MSMSGS.EXE
J:\Programmi\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
G:\PROGRAMMI\Sicurezza\Hijsck\HijackThis.exe
J:\Programmi\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tartaclub.net/forum/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.tartaclub.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - J:\Programmi\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - J:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - J:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - J:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - J:\Programmi\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Smapp] J:\Programmi\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [ShStatEXE] "J:\Programmi\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "J:\Programmi\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [NeroFilterCheck] J:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "J:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [InCD] J:\Programmi\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Babylon Client] J:\Programmi\Babylon\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "J:\Programmi\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKCU\..\Run: [CTFMON.EXE] J:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "J:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = J:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = J:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Gestione servizi.lnk = J:\Programmi\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://J:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - J:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - J:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - J:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Programmi\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Programmi\Messenger\MSMSGS.EXE
O12 - Plugin for .tif: J:\Programmi\Internet Explorer\PLUGINS\npqtplugin6.dll
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN.cab
O16 - DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} (CentraDownloaderCtl Class) - http://prod1.centra.com/SiteRoots/main/Ins...aDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{68138A30-7BBF-41D5-8CCE-E0711672890A}: NameServer = 151.99.125.2,151.99.250.2
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - J:\Programmi\File comuni\Microsoft Shared\Help\hxds.dll

BC AdBot (Login to Remove)

 


#2 12g

12g

  • Members
  • 450 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Scotland
  • Local time:10:58 AM

Posted 10 October 2004 - 06:15 PM

Make sure all browsers and windows are closed except for hijackthis and put a check against the following and click 'fix checked';

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com

O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN.cab

Reboot in Normal Mode, then post a fresh logfile so that I can check to see if it is clean.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users