Home » Spyware Protection » Hijacked Browser Analysis » 

Logfile of HijackThis v1.99.1 - mgolab

Hi  Mgolab,

The first thing I would do is to review the installed program that is in the Add/Remove Program on the control panel.  Remove those programs that you are not using or those that you think that was not installed by you. 

Please remember NOT to run hijackthis.exe inside the zip file.  Unzip (extract) it to your desktop then double click on "HijackThis.exe" icon in this way a backup for the removed key will be created on your desktop (useful if you remove them wrongly).

Re-run Hijackthis and and review (remove) the following entries:

R3 - Default URLSearchHook is missing

O2 - BHO: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C: \ Program Files \ QuickSearch \ QuickSearchBar3_28.dll
O3 - Toolbar: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C: \ Program Files \ QuickSearch \ QuickSearchBar3_28.dll
O4 - HKLM \ .. \ Run: [New.net Startup] rundll32 C: \ PROGRA~1 \ NEWDOT~1 \ NEWDOT~2.DLL,NewDotNetStartup -s

O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net

O15 - Trusted Zone: website: livephish.com
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - website: installengine.com / engine / isetup.cab
O16 - DPF: {CF38E898-0A6B-11D6-83C6-0080AD7D6076} (NPRemvuPluginControl) - website: 67.153.204.178 / webpages / NPRemvu.cab
O20 - Winlogon Notify: LogPack - lp32.dll (file missing)

Log file:

Scan saved at 11:17:39 PM, on 6 / 16 / 2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C: \ WINDOWS \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ csrss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ system32 \ logonui.exe
C: \ WINDOWS \ system32 \ brsvc01a.exe
C: \ WINDOWS \ system32 \ spoolsv.exe
C: \ WINDOWS \ system32 \ brss01a.exe
C: \ WINDOWS \ system32 \ CAPM1RSK.EXE
C: \ WINDOWS \ system32 \ netdde.exe
C: \ WINDOWS \ system32 \ clipsrv.exe
C: \ WINDOWS \ system32 \ crypserv.exe
C: \ PROGRA~1 \ SYMANT~1 \ SYMANT~1 \ DefWatch.exe
C: \ WINDOWS \ System32 \ msdtc.exe
C: \ PROGRA~1 \ SYMANT~1 \ SYMANT~1 \ Rtvscan.exe
C: \ WINDOWS \ System32 \ HPHipm11.exe
C: \ WINDOWS \ System32 \ locator.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ System32 \ dllhost.exe
C: \ WINDOWS \ System32 \ vssvc.exe
C: \ WINDOWS \ System32 \ wbem \ wmiapsrv.exe
C: \ WINDOWS \ SYSTEM32 \ YPCSER~1.EXE
C: \ WINDOWS \ System32 \ dllhost.exe
C: \ WINDOWS \ System32 \ wbem \ wmiprvse.exe
C: \ WINDOWS \ system32 \ logon.scr
C: \ WINDOWS \ system32 \ csrss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ rdpclip.exe
C: \ WINDOWS \ Explorer.EXE
C: \ Program Files \ Logitech \ iTouch \ iTouch.exe
C: \ Program Files \ MUSICMATCH \ MUSICMATCH Jukebox \ mm_tray.exe
C: \ Program Files \ MUSICMATCH \ MUSICMATCH Jukebox \ mmtask.exe
C: \ Program Files \ Common Files \ InstallShield \ UpdateService \ issch.exe
C: \ WINDOWS \ System32 \ hphmon04.exe
C: \ WINDOWS \ system32 \ rundll32.exe
C: \ Program Files \ Yahoo! \ browser \ ybrwicon.exe
C: \ Program Files \ QuickTime \ qttask.exe
C: \ Program Files \ Roxio \ Easy CD Creator 5 \ DirectCD \ DirectCD.exe
C: \ Program Files \ Logitech \ MouseWare \ system \ em_exec.exe
C: \ Program Files \ Messenger \ msmsgs.exe
C: \ PROGRA~1 \ Yahoo! \ browser \ ycommon.exe
C: \ Program Files \ Microsoft ActiveSync \ WCESCOMM.EXE
C: \ Program Files \ Adobe \ Acrobat 6.0 \ Distillr \ acrotray.exe
C: \ WINDOWS \ SYSTEM32 \ SPOOL \ DRIVERS \ W32X86 \ 3 \ CAPM1LAK.EXE
C: \ Program Files \ Dantz \ Retrospect Express HD \ retrorun.exe
C: \ WINDOWS \ System32 \ alg.exe
C: \ Program Files \ Symantec_Client_Security \ Symantec AntiVirus \ vpc32.exe
C: \ Program Files \ Webroot \ Spy Sweeper \ SpySweeper.exe
C: \ Program Files \ Webroot \ Spy Sweeper \ WRSSSDK.exe
C: \ DOCUME~1 \ DR7149~1.GOL \ LOCALS~1 \ Temp \ Temporary Directory 4 for 1217480.zip \ HijackThis.exe

R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main,Default_Page_URL = website: smbusiness.dellnet.com /
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main,Search Bar = website: red.clientapps.yahoo.com / customize / ie / defaults / sb / sbcydsl / *website: yahoo.com / search / ie.html
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main,Search Page = website: red.clientapps.yahoo.com / customize / ie / defaults / sp / sbcydsl / *website: yahoo.com
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main,Search Bar = website: red.clientapps.yahoo.com / customize / ie / defaults / sb / sbcydsl / *website: yahoo.com / search / ie.html
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main,Start Page = website: yahoo.sbc.com / dsl
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ SearchURL,(Default) = website: red.clientapps.yahoo.com / customize / ie / defaults / su / sbcydsl / *website: yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C: \ Program Files \ Yahoo! \ Common \ ycomp5_1_6_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c: \ Program Files \ Adobe \ Acrobat 6.0 \ Acrobat \ ActiveX \ AcroIEHelper.dll
O2 - BHO: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C: \ Program Files \ QuickSearch \ QuickSearchBar3_28.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - c: \ Program Files \ Adobe \ Acrobat 6.0 \ Acrobat \ AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c: \ Program Files \ Adobe \ Acrobat 6.0 \ Acrobat \ AcroIEFavClient.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C: \ Program Files \ Yahoo! \ Common \ ycomp5_1_6_0.dll
O3 - Toolbar: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C: \ Program Files \ QuickSearch \ QuickSearchBar3_28.dll
O4 - HKLM \ .. \ Run: [vptray] C: \ PROGRA~1 \ SYMANT~1 \ SYMANT~1 \ vptray.exe
O4 - HKLM \ .. \ Run: [zBrowser Launcher] C: \ Program Files \ Logitech \ iTouch \ iTouch.exe
O4 - HKLM \ .. \ Run: [MMTray] C: \ Program Files \ MUSICMATCH \ MUSICMATCH Jukebox \ mm_tray.exe
O4 - HKLM \ .. \ Run: [mmtask] C: \ Program Files \ MUSICMATCH \ MUSICMATCH Jukebox \ mmtask.exe
O4 - HKLM \ .. \ Run: [ISUSScheduler] "C: \ Program Files \ Common Files \ InstallShield \ UpdateService \ issch.exe" -start
O4 - HKLM \ .. \ Run: [ISUSPM Startup] C: \ PROGRA~1 \ COMMON~1 \ INSTAL~1 \ UPDATE~1 \ ISUSPM.exe -startup
O4 - HKLM \ .. \ Run: [IgfxTray] C: \ WINDOWS \ System32 \ igfxtray.exe
O4 - HKLM \ .. \ Run: [HPHUPD04] "C: \ Program Files \ HP Photosmart 11 \ hphinstall \ UniPatch \ hphupd04.exe"
O4 - HKLM \ .. \ Run: [HPHmon04] C: \ WINDOWS \ System32 \ hphmon04.exe
O4 - HKLM \ .. \ Run: [HPDJ Taskbar Utility] C: \ WINDOWS \ System32 \ spool \ drivers \ w32x86 \ 3 \ hpztsb07.exe
O4 - HKLM \ .. \ Run: [HotKeysCmds] C: \ WINDOWS \ System32 \ hkcmd.exe
O4 - HKLM \ .. \ Run: [BJCFD] C: \ Program Files \ BroadJump \ Client Foundation \ CFD.exe
O4 - HKLM \ .. \ Run: [New.net Startup] rundll32 C: \ PROGRA~1 \ NEWDOT~1 \ NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM \ .. \ Run: [YBrowser] C: \ Program Files \ Yahoo! \ browser \ ybrwicon.exe
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe" -atboottime
O4 - HKLM \ .. \ Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM \ .. \ Run: [AdaptecDirectCD] "C: \ Program Files \ Roxio \ Easy CD Creator 5 \ DirectCD \ DirectCD.exe"
O4 - HKLM \ .. \ Run: [MSConfig] C: \ WINDOWS \ PCHealth \ HelpCtr \ Binaries \ MSConfig.exe / auto
O4 - HKLM \ .. \ Run: [SpySweeper] "C: \ Program Files \ Webroot \ Spy Sweeper \ SpySweeper.exe" / startintray
O4 - HKCU \ .. \ Run: [MSMSGS] "C: \ Program Files \ Messenger \ msmsgs.exe" / background
O4 - HKCU \ .. \ Run: [H / PC Connection Agent] "C: \ Program Files \ Microsoft ActiveSync \ WCESCOMM.EXE"
O4 - Global Startup: Acrobat Assistant.lnk = C: \ Program Files \ Adobe \ Acrobat 6.0 \ Distillr \ acrotray.exe
O4 - Global Startup: Canon PC1200 iC D600 iR1200G Status Window.LNK = C: \ WINDOWS \ SYSTEM32 \ SPOOL \ DRIVERS \ W32X86 \ 3 \ CAPM1LAK.EXE
O4 - Global Startup: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office \ OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res: / / C: \ PROGRA~1 \ MICROS~2 \ Office10 \ EXCEL.EXE / 3000
O8 - Extra context menu item: Yahoo! Dictionary - file: / / / C: \ Program Files \ Yahoo! \ Common / ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file: / / / C: \ Program Files \ Yahoo! \ Common / ycsrch.htm
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C: \ Program Files \ Yahoo! \ Common \ ylogin.dll
O9 - Extra ´Tools´ menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C: \ Program Files \ Yahoo! \ Common \ ylogin.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C: \ Program Files \ Microsoft ActiveSync \ INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C: \ Program Files \ Microsoft ActiveSync \ INETREPL.DLL
O9 - Extra ´Tools´ menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C: \ Program Files \ Microsoft ActiveSync \ INETREPL.DLL
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C: \ Program Files \ Yahoo! \ Messenger \ yhexbmes.dll
O9 - Extra ´Tools´ menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C: \ Program Files \ Yahoo! \ Messenger \ yhexbmes.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C: \ Program Files \ Messenger \ msmsgs.exe
O9 - Extra ´Tools´ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C: \ Program Files \ Messenger \ msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O15 - Trusted Zone: website: livephish.com
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - website: installengine.com / engine / isetup.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https: / / h17000.www1.hp.com / ewfrf-JAVA / Secure / HPGetDownloadManager.ocx
O16 - DPF: {CF38E898-0A6B-11D6-83C6-0080AD7D6076} (NPRemvuPluginControl) - website: 67.153.204.178 / webpages / NPRemvu.cab
O17 - HKLM \ System \ CCS \ Services \ Tcpip \ .. \ {44CFA5F7-D46A-49F3-A3E7-5543A207E7B0}: NameServer = 66.254.31.254,66.254.29.134
O20 - Winlogon Notify: igfxcui - C: \ WINDOWS \ SYSTEM32 \ igfxsrvc.dll
O20 - Winlogon Notify: LogPack - lp32.dll (file missing)
O20 - Winlogon Notify: NavLogon - C: \ WINDOWS \ system32 \ NavLogon.dll
O20 - Winlogon Notify: PCANotify - C: \ WINDOWS \ SYSTEM32 \ PCANotify.dll
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C: \ WINDOWS \ system32 \ brsvc01a.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C: \ WINDOWS \ SYSTEM32 \ crypserv.exe
O23 - Service: DefWatch - Symantec Corporation - C: \ PROGRA~1 \ SYMANT~1 \ SYMANT~1 \ DefWatch.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C: \ PROGRA~1 \ SYMANT~1 \ SYMANT~1 \ Rtvscan.exe
O23 - Service: Pml Driver HPH11 - HP - C: \ WINDOWS \ System32 \ HPHipm11.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C: \ Program Files \ Dantz \ Retrospect Express HD \ retrorun.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C: \ Program Files \ Webroot \ Spy Sweeper \ WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ Security Center \ SymWSC.exe
O23 - Service: YPCService - Yahoo! Inc. - C: \ WINDOWS \ SYSTEM32 \ YPCSER~1.EXE


Mail this pageMail this page