Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Please Help!


  • Please log in to reply
1 reply to this topic

#1 Iglesias

Iglesias

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:04:16 AM

Posted 24 March 2006 - 09:36 AM

Reading this log I'm not sure if i am inected or not and if yes which entry should I safe delete.
Thank you

This is the log



hijackThis
Logfile of HijackThis v1.99.1
Scan saved at 07:42:47, on 24/03/2006
Platform: windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\wINDowS\System32\smss.exe C:\wINDows\system32\csrss.exe C:\wINDows\system32\services.exe C:\wINDows\system32\savedump.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\wINDows\system32\svchost.exe C:\wINDows\system32\svchost.exe C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main, Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,search Bar = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main, Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank RO - HKLM\Software\Microsoft\Internet Explorer\Search,5earchAssistant = about:blank
RO - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank Ri - HKCU\Software\Microsoft\Internet Connection wizard,ShellNext = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
02 - BHO: AcrolEHlprobj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\Activex\AcrolEHelper.ocx
02 - BHO: C:\wINDows\lbbho.dll - {4EC967BA-4B64-4A60-8E19-57EBB740A7C5} - C:\wINDows\lbbho.dll (file missing)
02 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot- Search & Destroy\SDHelper.dll
02 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\wINDows\system32\dla\tfswshx.dl1
02 - BHO: SSVHelper class - {761497BB-D6FO-4620-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jrel.5.0_06\bin\ssv.dll
02 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
02 - BHO: CmjBrowserHelperobject object - {AC41D38F-B56D-40AD-94E0-B493D130C959} - c:\Program Files\Mindjet\MindManager 6\Mm61nternetExplorer.dl1
03 - Toolbar: (no name) - {2318C2B1-4965-iid4-9B18-009027A5CD4F} - (no file)
04 - HKLM\..\Run: [IgfxTray] c:\wINDows\system32\igfxtray.exe
04 - HKLM\..\Run: [HotKeysCmds] C:\wINDows\system32\hkcmd.exe
04 - HKLM\..\Run: [dial C:\WINDOWS\system32\dla\tfswctrl.exe
04 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
04 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
04 - HKLM\..\Run: [Seticon] C:\Program Files\Icons\Seticon.exe
04 - HKLM\..\Run: [ADuserMon] c:\Program Files\Iomega\AutoDisk\ADUserMon.exe 04 HKLM\..\Run: [sunjavaUpdatesched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
04 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\Imglcon.exe
04 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
04 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Internet Security\PCClient.exe"
04 - HKLM\..\Run: [TM outbreak Agent] "C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run
04 - HKLM\..\Run: [Dell Photo AIO Printer 922] "c:\Program Files\Dell Photo AIO Printer 922\dlbtbm r.exe"
04 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
04 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive
Software\Diskeeper\Dklcon.exe"
04 - HKLM\..\Run: [Quicklime Task] "C:\Program FileS\Quicklime\qttask.exe" -atboottime
04 - HKLM\..\Run: [RoxioDrafToDisc] "E:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
04 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"
04 - HKLM\..\Run: [keyboard] C:\windows\keyboard5.exe
04 - HKLM\..\Run: [newname] C:\windows\newname5.exe
04 - HKLM\..\Run: [mousepad] C:\windows\mousepad5.exe
04 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k 04 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
04 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
04 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
04 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
04 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe 04 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe 04 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
04 - Global startup: Digital Line Detect.lnk = ?
04 - Global startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sglmangr.exe
08 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA-1\MICROSN4\OFFICE11\EXCEL.EXE/3000
09 - Extra button: (no name) - {08BOE5CO-4FCB-11CF-AAA5-004010608501} - C:\Program Files\Java\jrel.5.0_06\bin\ssv.dll
09 - Extra 'Tools' menuitem: Sun Java Console - {08BOE5CO-4FCB-11CF-AAA5-004010608501} - C:\Program Files\Java\'rel.5.0_06\bin\ssv.dll
09 - Extra button: Create Mobile Favorite - {2EAF5BB1-070E-11D3-9307-O0004FAE2D4F} - C:\PROGRA.1\M13AA1-1\INetRe l.dll 09 - Extra button: (no name) - {2EAF5BB2-070E-11D3-9307-O0004FAE2D4F} - C:\PROGRAN1\M13AA1.1\INetRepl.dl1
09 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070E-11D3-9307-O0004FAE2D4F} - C:\PROGRAN1\M13AA1-1\INetRepl.dll 09 - Extra button: Send to Mindjet MindManager - {531B9DC0-D8EE-4c76-A6EE-6C1E50569655} - C:\Program Files\Mindjet\MindManager 6\Mm6lnternetExplorer.dll
09 - Extra button: Research - {92780825-18CC-4108-B9BE-3C9C571A8263} - C:\PROGRA-1\MICROS--3\OFFICE11\REFIEBAR.DLL
09 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-OOCOF0318AFE} - (no file)
09 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-O0004F795683} - C:\Program Files\Messenger\msmsgs.exe
09 - Extra 'Tools' menuitem: windows Messenger - {FB5F1910-F110-11d2-BB9E-00004F795683} - C:\Program Files\Messenger\msmsgs.exe
010 - Unknown file in winsock LSP: c:\program files\bonjour\mdnsns .dll
012 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll 014 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk/ 016 - DPF: {04E214E5-63AF-4236-8306-A7ADCBF9BD02} (Housecall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
016 - DPF: {406B5949-7190-4245-91A9-30A17DE16ADO} (Snapfish Activia) - http://www.truprint.co.uk/TruprintActivia.cab
016 - DPF: {556DDE35-E955-11DO-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
016 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecal165.trendmicro.com/housecal...6/win32/activex /hcimpl.cab
016 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} (Java Plug-in) -
016 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader class) - http://static.photobox.co.uk/sg/common/uploader.cab
020 - winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll 020 - Winlogon Notify: mmx4xt - C:\WINDOWS\SYSTEM32\mmx4xt.dll
020 - Winlogon Notify: RunServicesOnce - C:\WINDOWS\system32\mcricons.dll 023 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program
Files\Bonjour\mDNSResponder.exe
023 - Service: Diskeeper - Executive Software International, Inc. - c:\Program Files\Executive software\Diskeeper\DkService.exe
023 - service: dlbt_device - Dell - c:\wINDOwS\System32\dlbtcoms.exe
023 - Service: ewido security suite control - ewido networks - e:\Program Files\ewido anti-malware\ewidoctrl.exe
023 - Service: ewido security suite guard - ewido networks - e:\Program Files\ewido anti-malware\ewidoguard.exe
023 - Service: InstallDriver Table manager (IDriverT) - Macrovision corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe 023 - Service: Iomega App services - 'omega corporation - C:\PROGRA.1\Iomega\System32\AppServices.exe
023 - Service: iPodService - Apple Computer, Inc. - c:\Program Files\iPod\bin\iPodService.exe
023 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISIcSERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe




Page 3

BC AdBot (Login to Remove)

 


m

#2 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:12:16 AM

Posted 29 March 2006 - 06:46 PM

Hello Iglesias and welcome to the BC HijackThis forum. First let's try to get a good log posted. Please follow the directions below to post a new HijackThis log.

We need a complete HijackThis (HJT) log file to be able to analyze what is happening on your computer.

Boot normally, start HijackThis and click the Do a system scan and save a log button to perform a scan and create a log file. When the scan is complete, Notepad will open up with the log file in it. While in Notepad, press Ctrl-A to select all text and then Ctrl-C to copy the text to the clipboard.

POST the log back in this thread using the Add Reply button. Click in the data-entry window and press Ctrl-V to paste the log into the window. Add any other comments which you believe might be helpful in our analysis. and click the Add Reply button.

I will review your log when it comes in.


DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL I CHECK THE LOG, AS SOME OF THE FILES ARE LEGIT AND VITAL TO THE FUNCTION OF YOUR COMPUTER

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users