Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help!


  • Please log in to reply
2 replies to this topic

#1 kitzmark

kitzmark

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:03:20 PM

Posted 05 January 2005 - 09:44 PM

thanks guys...

Logfile of HijackThis v1.97.7
Scan saved at 4:19:53 PM, on 1/5/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\MS\SMS\CORE\BIN\CLISVCL.EXE
C:\WINDOWS\MS\SMS\clicomp\apa\Bin\smsapm32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\MS\SMS\CORE\BIN\LAUNCH32.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\WINDOWS\MS\SMS\CLICOMP\SWDist32\bin\smsmon32.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Ps2000\Prt9532.exe
C:\Program Files\Winzip\WZQKPICK.EXE
C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe
C:\PROGRA~1\Citrix\ICACLI~1\Wfcrun32.exe
C:\PROGRA~1\Citrix\ICACLI~1\WFICA32.EXE
C:\WINDOWS\System32\drojjva.exe
C:\Program Files\Hummingbird\Connectivity\8.00\Exceed\xstart.exe
C:\PROGRA~1\HUMMIN~1\CONNEC~1\8.00\Exceed\EXCEED.EXE
C:\Program Files\Windows Media Player\wmplayer.exe
C:\orant\BIN\PLUS80W.EXE
C:\WINDOWS\System32\drojjva.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
H:\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.go.shopko.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.go.shopko.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.go.shopko.com/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {A78860C8-EE1A-46DF-A97F-E3E6D433E80B} - C:\WINDOWS\system32\qz65j4i.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SMS Application Launcher] C:\WINDOWS\MS\SMS\CORE\BIN\LAUNCH32.EXE
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [vptray] c:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKLM\..\RunOnce: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe /k
O4 - Global Startup: Microsoft Find Fast.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Office Startup.lnk = ?
O4 - Global Startup: Printscreen 2000.lnk = C:\Program Files\Ps2000\Prt9532.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\Winzip\WZQKPICK.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.go.shopko.com
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/get/shock...director/sw.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) - http://cinfo3/viewer/activeXViewer/activexviewer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get/shock...ash/swflash.cab
O16 - DPF: {e2258010-b53c-11d6-b64d-00c04faedb18} (Oracle JInitiator 1.1.8.20) -
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ad.shopko.com
O17 - HKLM\Software\..\Telephony: DomainName = ad.shopko.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ad.shopko.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = go.shopko.com,ad.pamida.com,inet.pamida.com,dc.shopko.com,st.shopko.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = go.shopko.com,ad.pamida.com,inet.pamida.com,dc.shopko.com,st.shopko.com

BC AdBot (Login to Remove)

 


#2 kitzmark

kitzmark
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:03:20 PM

Posted 06 January 2005 - 09:02 AM

any idears from anyone?

#3 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,504 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:03:20 PM

Posted 15 January 2005 - 05:25 PM

Please post a brand new log if you are still having problems and I will help you. Sorry for the delay :thumbsup:




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users