Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Need Help! Hijackthis Log!


  • Please log in to reply
1 reply to this topic

#1 sombras

sombras

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:03:37 PM

Posted 26 January 2006 - 05:47 PM

I am having so many problems with my compter, I've got coolwebsearch and homesearch assistant. Can you please take a look at my hijack log and tell me what I should get rid of?

Logfile of HijackThis v1.99.1
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\NVSVC.EXE
C:\WINDOWS\SYSTEM\SYSHR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\IWP\NPFMNTOR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\EN-GB\MSNAPPAU.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\CRLE32.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\BLUEYONDER IST\BIN\MPBTN.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\ADOBE\ACROBAT 4.0\READER\ACRORD32.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\UNZIPPED\HIJACKTHIS[1]\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.msn.com/access/allinone.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\raqgm.dll/sp.html#71345%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\raqgm.dll/sp.html#71345%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\raqgm.dll/sp.html#71345%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\raqgm.dll/sp.html#71345%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\raqgm.dll/sp.html#71345%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\raqgm.dll/sp.html#71345%resultposition.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\raqgm.dll/sp.html#71345%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by blueyonder
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\PROGRAM FILES\BLUEYONDER\PCGUARD\FBHR.DLL
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\PROGRAM FILES\BLUEYONDER\PCGUARD\PKR.DLL
O2 - BHO: (no name) - {CFBC0E5C-0127-6228-3FD0-4BBC58A6802D} - (no file)
O2 - BHO: (no name) - {BA74EE4C-BD0E-31A5-EDCB-852DD8499EFF} - (no file)
O2 - BHO: (no name) - {EAA21319-8AF3-391F-D65B-F8DC9A1BE340} - (no file)
O2 - BHO: (no name) - {60315168-4625-9371-95C8-1DF81A38AF24} - (no file)
O2 - BHO: (no name) - {5964E3A2-2B4D-8894-0FC6-3BCB784625AD} - (no file)
O2 - BHO: (no name) - {B94F3A1B-8227-18B7-A243-4D762348758B} - (no file)
O2 - BHO: (no name) - {5F0FDF6E-D2AC-4D0F-341D-86699A5C3A3F} - (no file)
O2 - BHO: (no name) - {8704DF49-0E57-AB82-9B58-3C3BAEDCDFC9} - (no file)
O2 - BHO: (no name) - {61678A0C-2475-DA5D-295B-F19B263E630E} - (no file)
O2 - BHO: (no name) - {4A7FA6F9-1FF5-5963-0F97-EBB535B64A83} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {D321F1B2-258B-8BA4-5BA7-B58A457F3391} - (no file)
O2 - BHO: (no name) - {0B7E66CC-F3AC-46D1-230A-345337071200} - (no file)
O2 - BHO: (no name) - {2793A518-B131-6A45-A669-D11F76853A3C} - (no file)
O2 - BHO: (no name) - {FB67C2D6-4EEA-A705-D170-92B04EC26483} - (no file)
O2 - BHO: (no name) - {A764757D-5FD4-2312-E88E-5CF1C41EB7E2} - (no file)
O2 - BHO: (no name) - {79FED68F-557B-E50C-4282-87434007B6F9} - (no file)
O2 - BHO: (no name) - {ADF96347-3F19-C655-40D2-F7597E5875AA} - (no file)
O2 - BHO: (no name) - {8D180685-5C69-10CF-5661-F3D98794CEBA} - (no file)
O2 - BHO: Class - {2DA8F58E-6FCB-AD1E-2632-874D56CA88C4} - C:\WINDOWS\SYSTEM\SDKEZ32.DLL (file missing)
O2 - BHO: Class - {6FAA77FE-F83E-4CC6-7BAD-CBD84B1D066C} - C:\WINDOWS\SYSTEM\MSLN.DLL (file missing)
O2 - BHO: (no name) - {2B4D7BB4-8681-4CA0-C521-E8676541199C} - (no file)
O2 - BHO: Class - {B288C773-0ADE-754D-254F-7D7707CB8801} - C:\WINDOWS\NETLF32.DLL (file missing)
O2 - BHO: Class - {ED9E0C3E-BCBD-A6CF-B224-8D038E904F47} - C:\WINDOWS\SYSTEM\ATLNS.DLL (file missing)
O2 - BHO: Class - {97DB42AA-550F-63DF-AE90-197E36BD4BC7} - C:\WINDOWS\SYSTEM\APITV32.DLL (file missing)
O2 - BHO: Class - {1C41EA19-F010-C8C9-B542-ECB8825621D2} - C:\WINDOWS\IEMB.DLL (file missing)
O2 - BHO: Class - {F47E61BF-8B36-9049-7ADF-E6CEA1AF3150} - C:\WINDOWS\SYSTEM\WINDV32.DLL (file missing)
O2 - BHO: Class - {25AEC155-1A3F-6021-34B6-97B5405E8A06} - C:\WINDOWS\SYSTEM\IPPO.DLL
O2 - BHO: Class - {2D9FEC19-DDF5-AEC4-F0FA-72793B060DAA} - C:\WINDOWS\SYSTEM\SDKKC.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [msnappau] "c:\program files\MSN Apps\Updater\01.03.0000.1005\en-gb\msnappau.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CRLE32.EXE] C:\WINDOWS\CRLE32.EXE
O4 - HKLM\..\Run: [Symantec Core LC] "C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe" start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [PCMMRealtime] C:\Program Files\PC MightyMax\pcmm.exe /R
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [NVSvc] C:\WINDOWS\SYSTEM\nvsvc.exe -runservice
O4 - HKLM\..\RunServices: [SYSHR.EXE] C:\WINDOWS\SYSTEM\SYSHR.EXE /s
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [NPFMonitor] C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [SDKXA.EXE] C:\WINDOWS\SYSTEM\SDKXA.EXE /s
O4 - HKLM\..\RunServices: [SDKWZ32.EXE] C:\WINDOWS\SYSTEM\SDKWZ32.EXE /s
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/dba2161.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} - http://installs.spamblockerutility.com/ins...ckerutility.cab
O20 - Winlogon Notify: st3 - C:\WINDOWS\Q612230.DLL (file missing)

BC AdBot (Login to Remove)

 


m

#2 OwNt

OwNt

  • Members
  • 56 posts
  • OFFLINE
  •  
  • Location:Omaha, NE, USA
  • Local time:03:37 PM

Posted 29 January 2006 - 01:25 PM

Hello sombras,

This is a badly infected computer, so please bear with me as we get it cleaned up. :thumbsup:

I need to get you to move HijackThis to a folder of its own so that nothing gets deleted by mistake.

1. Right click in an empty space on your desktop.

2. From the Menu, click New, then Folder and a folder will appear on your desktop.

3. Name the folder HJT

4. Copy/Paste your current version of HijackThis into the new Folder that was just created.

Now post a fresh Hijackthis log into this thread, please.
If you are happy with the service I provided, please consider making a donation to help me continue the fight against Malware Posted Image

Please do not PM me asking for support. My first reply will direct you to the forums instead.
Please post the final results, good or bad. We like to know!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users