|
Logfile of HijackThis v1.99.1 - mgolab
Hi Mgolab,
The first thing I would do is to review the installed program that is in the Add/Remove Program on the control panel. Remove those programs that you are not using or those that you think that was not installed by you.
Please remember NOT to run hijackthis.exe inside the zip file. Unzip (extract) it to your desktop then double click on "HijackThis.exe" icon in this way a backup for the removed key will be created on your desktop (useful if you remove them wrongly).
Re-run Hijackthis and and review (remove) the following entries:
R3 - Default URLSearchHook is missing
O2 - BHO: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C: \ Program Files \ QuickSearch \ QuickSearchBar3_28.dll O3 - Toolbar: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C: \ Program Files \ QuickSearch \ QuickSearchBar3_28.dll O4 - HKLM \ .. \ Run: [New.net Startup] rundll32 C: \ PROGRA~1 \ NEWDOT~1 \ NEWDOT~2.DLL,NewDotNetStartup -s
O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net
O15 - Trusted Zone: website: livephish.com O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - website: installengine.com / engine / isetup.cab O16 - DPF: {CF38E898-0A6B-11D6-83C6-0080AD7D6076} (NPRemvuPluginControl) - website: 67.153.204.178 / webpages / NPRemvu.cab O20 - Winlogon Notify: LogPack - lp32.dll (file missing)
Log file:
Scan saved at 11:17:39 PM, on 6 / 16 / 2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes: C: \ WINDOWS \ System32 \ smss.exe C: \ WINDOWS \ system32 \ csrss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ WINDOWS \ system32 \ logonui.exe C: \ WINDOWS \ system32 \ brsvc01a.exe C: \ WINDOWS \ system32 \ spoolsv.exe C: \ WINDOWS \ system32 \ brss01a.exe C: \ WINDOWS \ system32 \ CAPM1RSK.EXE C: \ WINDOWS \ system32 \ netdde.exe C: \ WINDOWS \ system32 \ clipsrv.exe C: \ WINDOWS \ system32 \ crypserv.exe C: \ PROGRA~1 \ SYMANT~1 \ SYMANT~1 \ DefWatch.exe C: \ WINDOWS \ System32 \ msdtc.exe C: \ PROGRA~1 \ SYMANT~1 \ SYMANT~1 \ Rtvscan.exe C: \ WINDOWS \ System32 \ HPHipm11.exe C: \ WINDOWS \ System32 \ locator.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ WINDOWS \ System32 \ dllhost.exe C: \ WINDOWS \ System32 \ vssvc.exe C: \ WINDOWS \ System32 \ wbem \ wmiapsrv.exe C: \ WINDOWS \ SYSTEM32 \ YPCSER~1.EXE C: \ WINDOWS \ System32 \ dllhost.exe C: \ WINDOWS \ System32 \ wbem \ wmiprvse.exe C: \ WINDOWS \ system32 \ logon.scr C: \ WINDOWS \ system32 \ csrss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ rdpclip.exe C: \ WINDOWS \ Explorer.EXE C: \ Program Files \ Logitech \ iTouch \ iTouch.exe C: \ Program Files \ MUSICMATCH \ MUSICMATCH Jukebox \ mm_tray.exe C: \ Program Files \ MUSICMATCH \ MUSICMATCH Jukebox \ mmtask.exe C: \ Program Files \ Common Files \ InstallShield \ UpdateService \ issch.exe C: \ WINDOWS \ System32 \ hphmon04.exe C: \ WINDOWS \ system32 \ rundll32.exe C: \ Program Files \ Yahoo! \ browser \ ybrwicon.exe C: \ Program Files \ QuickTime \ qttask.exe C: \ Program Files \ Roxio \ Easy CD Creator 5 \ DirectCD \ DirectCD.exe C: \ Program Files \ Logitech \ MouseWare \ system \ em_exec.exe C: \ Program Files \ Messenger \ msmsgs.exe C: \ PROGRA~1 \ Yahoo! \ browser \ ycommon.exe C: \ Program Files \ Microsoft ActiveSync \ WCESCOMM.EXE C: \ Program Files \ Adobe \ Acrobat 6.0 \ Distillr \ acrotray.exe C: \ WINDOWS \ SYSTEM32 \ SPOOL \ DRIVERS \ W32X86 \ 3 \ CAPM1LAK.EXE C: \ Program Files \ Dantz \ Retrospect Express HD \ retrorun.exe C: \ WINDOWS \ System32 \ alg.exe C: \ Program Files \ Symantec_Client_Security \ Symantec AntiVirus \ vpc32.exe C: \ Program Files \ Webroot \ Spy Sweeper \ SpySweeper.exe C: \ Program Files \ Webroot \ Spy Sweeper \ WRSSSDK.exe C: \ DOCUME~1 \ DR7149~1.GOL \ LOCALS~1 \ Temp \ Temporary Directory 4 for 1217480.zip \ HijackThis.exe
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main,Default_Page_URL = website: smbusiness.dellnet.com / R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main,Search Bar = website: red.clientapps.yahoo.com / customize / ie / defaults / sb / sbcydsl / *website: yahoo.com / search / ie.html R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main,Search Page = website: red.clientapps.yahoo.com / customize / ie / defaults / sp / sbcydsl / *website: yahoo.com R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main,Search Bar = website: red.clientapps.yahoo.com / customize / ie / defaults / sb / sbcydsl / *website: yahoo.com / search / ie.html R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main,Start Page = website: yahoo.sbc.com / dsl R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ SearchURL,(Default) = website: red.clientapps.yahoo.com / customize / ie / defaults / su / sbcydsl / *website: yahoo.com R3 - Default URLSearchHook is missing O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C: \ Program Files \ Yahoo! \ Common \ ycomp5_1_6_0.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c: \ Program Files \ Adobe \ Acrobat 6.0 \ Acrobat \ ActiveX \ AcroIEHelper.dll O2 - BHO: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C: \ Program Files \ QuickSearch \ QuickSearchBar3_28.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - c: \ Program Files \ Adobe \ Acrobat 6.0 \ Acrobat \ AcroIEFavClient.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c: \ Program Files \ Adobe \ Acrobat 6.0 \ Acrobat \ AcroIEFavClient.dll O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C: \ Program Files \ Yahoo! \ Common \ ycomp5_1_6_0.dll O3 - Toolbar: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C: \ Program Files \ QuickSearch \ QuickSearchBar3_28.dll O4 - HKLM \ .. \ Run: [vptray] C: \ PROGRA~1 \ SYMANT~1 \ SYMANT~1 \ vptray.exe O4 - HKLM \ .. \ Run: [zBrowser Launcher] C: \ Program Files \ Logitech \ iTouch \ iTouch.exe O4 - HKLM \ .. \ Run: [MMTray] C: \ Program Files \ MUSICMATCH \ MUSICMATCH Jukebox \ mm_tray.exe O4 - HKLM \ .. \ Run: [mmtask] C: \ Program Files \ MUSICMATCH \ MUSICMATCH Jukebox \ mmtask.exe O4 - HKLM \ .. \ Run: [ISUSScheduler] "C: \ Program Files \ Common Files \ InstallShield \ UpdateService \ issch.exe" -start O4 - HKLM \ .. \ Run: [ISUSPM Startup] C: \ PROGRA~1 \ COMMON~1 \ INSTAL~1 \ UPDATE~1 \ ISUSPM.exe -startup O4 - HKLM \ .. \ Run: [IgfxTray] C: \ WINDOWS \ System32 \ igfxtray.exe O4 - HKLM \ .. \ Run: [HPHUPD04] "C: \ Program Files \ HP Photosmart 11 \ hphinstall \ UniPatch \ hphupd04.exe" O4 - HKLM \ .. \ Run: [HPHmon04] C: \ WINDOWS \ System32 \ hphmon04.exe O4 - HKLM \ .. \ Run: [HPDJ Taskbar Utility] C: \ WINDOWS \ System32 \ spool \ drivers \ w32x86 \ 3 \ hpztsb07.exe O4 - HKLM \ .. \ Run: [HotKeysCmds] C: \ WINDOWS \ System32 \ hkcmd.exe O4 - HKLM \ .. \ Run: [BJCFD] C: \ Program Files \ BroadJump \ Client Foundation \ CFD.exe O4 - HKLM \ .. \ Run: [New.net Startup] rundll32 C: \ PROGRA~1 \ NEWDOT~1 \ NEWDOT~2.DLL,NewDotNetStartup -s O4 - HKLM \ .. \ Run: [YBrowser] C: \ Program Files \ Yahoo! \ browser \ ybrwicon.exe O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe" -atboottime O4 - HKLM \ .. \ Run: [Logitech Utility] Logi_MwX.Exe O4 - HKLM \ .. \ Run: [AdaptecDirectCD] "C: \ Program Files \ Roxio \ Easy CD Creator 5 \ DirectCD \ DirectCD.exe" O4 - HKLM \ .. \ Run: [MSConfig] C: \ WINDOWS \ PCHealth \ HelpCtr \ Binaries \ MSConfig.exe / auto O4 - HKLM \ .. \ Run: [SpySweeper] "C: \ Program Files \ Webroot \ Spy Sweeper \ SpySweeper.exe" / startintray O4 - HKCU \ .. \ Run: [MSMSGS] "C: \ Program Files \ Messenger \ msmsgs.exe" / background O4 - HKCU \ .. \ Run: [H / PC Connection Agent] "C: \ Program Files \ Microsoft ActiveSync \ WCESCOMM.EXE" O4 - Global Startup: Acrobat Assistant.lnk = C: \ Program Files \ Adobe \ Acrobat 6.0 \ Distillr \ acrotray.exe O4 - Global Startup: Canon PC1200 iC D600 iR1200G Status Window.LNK = C: \ WINDOWS \ SYSTEM32 \ SPOOL \ DRIVERS \ W32X86 \ 3 \ CAPM1LAK.EXE O4 - Global Startup: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office \ OSA9.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res: / / C: \ PROGRA~1 \ MICROS~2 \ Office10 \ EXCEL.EXE / 3000 O8 - Extra context menu item: Yahoo! Dictionary - file: / / / C: \ Program Files \ Yahoo! \ Common / ycdict.htm O8 - Extra context menu item: Yahoo! Search - file: / / / C: \ Program Files \ Yahoo! \ Common / ycsrch.htm O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C: \ Program Files \ Yahoo! \ Common \ ylogin.dll O9 - Extra ´Tools´ menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C: \ Program Files \ Yahoo! \ Common \ ylogin.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C: \ Program Files \ Microsoft ActiveSync \ INETREPL.DLL O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C: \ Program Files \ Microsoft ActiveSync \ INETREPL.DLL O9 - Extra ´Tools´ menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C: \ Program Files \ Microsoft ActiveSync \ INETREPL.DLL O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C: \ Program Files \ Yahoo! \ Messenger \ yhexbmes.dll O9 - Extra ´Tools´ menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C: \ Program Files \ Yahoo! \ Messenger \ yhexbmes.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C: \ Program Files \ Messenger \ msmsgs.exe O9 - Extra ´Tools´ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C: \ Program Files \ Messenger \ msmsgs.exe O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O15 - Trusted Zone: website: livephish.com O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - website: installengine.com / engine / isetup.cab O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https: / / h17000.www1.hp.com / ewfrf-JAVA / Secure / HPGetDownloadManager.ocx O16 - DPF: {CF38E898-0A6B-11D6-83C6-0080AD7D6076} (NPRemvuPluginControl) - website: 67.153.204.178 / webpages / NPRemvu.cab O17 - HKLM \ System \ CCS \ Services \ Tcpip \ .. \ {44CFA5F7-D46A-49F3-A3E7-5543A207E7B0}: NameServer = 66.254.31.254,66.254.29.134 O20 - Winlogon Notify: igfxcui - C: \ WINDOWS \ SYSTEM32 \ igfxsrvc.dll O20 - Winlogon Notify: LogPack - lp32.dll (file missing) O20 - Winlogon Notify: NavLogon - C: \ WINDOWS \ system32 \ NavLogon.dll O20 - Winlogon Notify: PCANotify - C: \ WINDOWS \ SYSTEM32 \ PCANotify.dll O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C: \ WINDOWS \ system32 \ brsvc01a.exe O23 - Service: Crypkey License - Kenonic Controls Ltd. - C: \ WINDOWS \ SYSTEM32 \ crypserv.exe O23 - Service: DefWatch - Symantec Corporation - C: \ PROGRA~1 \ SYMANT~1 \ SYMANT~1 \ DefWatch.exe O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C: \ PROGRA~1 \ SYMANT~1 \ SYMANT~1 \ Rtvscan.exe O23 - Service: Pml Driver HPH11 - HP - C: \ WINDOWS \ System32 \ HPHipm11.exe O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C: \ Program Files \ Dantz \ Retrospect Express HD \ retrorun.exe O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C: \ Program Files \ Webroot \ Spy Sweeper \ WRSSSDK.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ Security Center \ SymWSC.exe O23 - Service: YPCService - Yahoo! Inc. - C: \ WINDOWS \ SYSTEM32 \ YPCSER~1.EXE
|