Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijackthis Log


  • This topic is locked This topic is locked
2 replies to this topic

#1 PooKer

PooKer

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:12:38 PM

Posted 12 January 2005 - 03:16 PM

Ok. I've run Pestpatrol, spyware doctor, but nothing is being detected.
ran windows update and no change.
I get a bar come up on IE with the type thats on MSN Plus sponcer. I've uninstalled msn plus and re-installed making sure the sponcer isnt installed. Im guess that it could be another user on the PC that i cant scan. any way i can remove it from this user? heres the hijackthis log. i cant see anything that shouldnt be there. unless one of the mp3 player software has spyware on it :\

Logfile of HijackThis v1.99.0
Scan saved at 19:24:51, on 12/01/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\System32\Ati2evxx.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
G:\WINDOWS\system32\LEXBCES.EXE
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\System32\CTSvcCDA.EXE
G:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
G:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
G:\WINDOWS\System32\svchost.exe
G:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
G:\WINDOWS\System32\MsPMSPSv.exe
G:\WINDOWS\system32\Ati2evxx.exe
G:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
G:\WINDOWS\Explorer.EXE
G:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
G:\PROGRA~1\Labtec\LABTEC~1\Keyboard.exe
G:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
G:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
G:\Program Files\PHILIPS\HDDDMM\DMM\bin\AutoLaunchHDD70.exe
G:\Program Files\Lexmark X5100 Series\lxbabmon.exe
G:\WINDOWS\System32\lexpps.exe
G:\Program Files\TGTSoft\StyleXP\StyleXP.exe
G:\WINDOWS\System32\ctfmon.exe
G:\Program Files\Spyware Doctor\swdoctor.exe
G:\PROGRA~1\COMMON~1\PHILIP~1\USBCON~1.EXE
G:\Program Files\Internet Explorer\iexplore.exe
G:\WINDOWS\system32\rundll32.exe
G:\Program Files\Messenger Plus! 3\MsgPlus.exe
G:\Program Files\MSN Messenger\msnmsgr.exe
G:\Program Files\PestPatrol\PPUpdater.exe
c:\Program Files\PestPatrol\PPUpdater.exe
c:\Program Files\PestPatrol\ppmemcheck.exe
c:\Program Files\PestPatrol\ppcontrol.exe
c:\Program Files\PestPatrol\pestpatrol.exe
G:\Program Files\Internet Explorer\iexplore.exe
G:\Documents and Settings\Zoe\My Documents\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = G:\WINDOWS\about.htm
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {4908C9FF-3E34-734A-DE58-CDC512CA52F0} - G:\DOCUME~1\Cathy\APPLIC~1\ONCENA~1\setupbolt.exe (file missing)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - G:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - g:\program files\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - G:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - G:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - G:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - g:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] G:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [KeyBoard] G:\PROGRA~1\Labtec\LABTEC~1\Keyboard.exe
O4 - HKLM\..\Run: [NeroFilterCheck] G:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Lexmark X5100 Series] "G:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [PestPatrol Control Center] G:\Program Files\PestPatrol\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] G:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [/AutoLaunchHDD70] G:\Program Files\PHILIPS\HDDDMM\DMM\bin\AutoLaunchHDD70.exe
O4 - HKLM\..\Run: [IdolMapiSecondFord] G:\Documents and Settings\All Users\Application Data\Fast Debug Idol Mapi\jumplogo.exe
O4 - HKLM\..\Run: [MessengerPlus3] "G:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKCU\..\Run: [STYLEXP] G:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Doctor] "G:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [msnmsgr] "G:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Microsoft Office.lnk = G:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://g:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://g:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://g:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://G:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://g:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://g:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - G:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O12 - Plugin for .spop: G:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1095608007484
O23 - Service: Ati HotKey Poller - Unknown - G:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - G:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - G:\WINDOWS\System32\CTSvcCDA.EXE
O23 - Service: Kerio Personal Firewall 4 - Kerio Technologies - G:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: LexBce Server - Lexmark International, Inc. - G:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: StyleXPService - Unknown - G:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

thanks to anyone who can help
PooKer

BC AdBot (Login to Remove)

 


#2 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:12:38 PM

Posted 14 January 2005 - 08:30 AM

Go to your Control Panel -> Add/Remove Programs and uninstall MessengerPlus 3


Download Ad-aware SE from: http://www.majorgeeks.com/download506.html

Install the program and launch it.

First, in the main window, look in the bottom right corner and click on Check for updates now and download the latest reference files.

Exit Adaware for now.


Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Run Hijackthis again, click scan, and Put a checkmark next to each of these. Then close all other windows--you should only see HijackThis on your Desktop--and click the Fix Checked button.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = G:\WINDOWS\about.htm
O2 - BHO: (no name) - {4908C9FF-3E34-734A-DE58-CDC512CA52F0} - G:\DOCUME~1\Cathy\APPLIC~1\ONCENA~1\setupbolt.exe (file missing)
O4 - HKLM\..\Run: [IdolMapiSecondFord] G:\Documents and Settings\All Users\Application Data\Fast Debug Idol Mapi\jumplogo.exe

Reboot your computer into Safe Mode

Then delete these files or directories (Do not be concerned if they do not exist)

G:\WINDOWS\about.htm
G:\DOCUME~1\Cathy\APPLIC~1\ONCENA~1\setupbolt.exe
G:\Documents and Settings\All Users\Application Data\Fast Debug Idol Mapi\jumplogo.exe


Run a full scan with Adaware.


Reboot your computer to go back to normal mode and post a new log.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#3 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:12:38 PM

Posted 12 February 2005 - 06:03 PM

This topic has been closed due to a lack of response. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users