|
Re: HijackThisLog Analysis - Carole
Date: Thursday, 09 September, 2004 10:28 AM
Remember DO NOT run hijackthis.exe inside the zip file. Unzip (extract) it to your desktop then double click on "HijackThis.exe" icon in this way a backup for the removed key will be created on your desktop (useful if you remove them wrongly).
Here is what you should do.
Remove these search keys:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http:??www.qwifqoanqycu.us /Pf4bB5aScw5BpNsuS9ALyAIXRdwtAuec7kVAJaAD/YA.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http:??rd.yahoo.com/customize/ymsgr/defaults/*http:??my.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http:??www.viegnmjgtedo.com/Pf4bB5aScw7Lj2IziDbj5DsXxw /z1mQVYeC4MjbNKniLbN/oefMb9hO3D9XTSzav.html
Remove these additional browser plug-in keys (O2...O4):
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5_2_3_0.dll O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {107F8465-678F-E111-ED4C-AE85C75524D4} - C:\PROGRA~1\16BARB~1\64 flag.exe O4 - HKLM\..\Run: [pure ace] C:\PROGRA~1\AUDIOR~1\filmlinkjump.exe O4 - HKLM\..\Run: [curb copy grim second] C:\Documents and Settings\All Users\Application Data\pile cool curb copy\loud pop.exe
Review? and remove these ActiveX Objects (aka Downloaded Program Files) if you are not using them (O16): NOTE: Review the reference below to help you to decide on the ActiveX Object to remove.
O16 - DPF: {68A2C3BD-7809-11D3-8ACF-0050046F2F9A} (AXELPlayer Class) - http:??a1153.g.akamai.net/7/1153/5970/v0005 /www.mindavenue.com/downloads/akamai/AXELPlayerAX_Win32.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http:??messenger.zone.msn.com/binary/MessengerStatsClient.cab30149.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http:??messenger.zone.msn.com/binary/ZIntro.cab30149.cab O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http:??messenger.zone.msn.com/binary/WoF.cab30149.cab
Original log but with private information removed.
Logfile of HijackThis v1.97.7 Scan saved at 9:27:41 PM, on 9/8/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\System32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Grisoft\AVG6\avgserv.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\Common Files\Dell\EUSW\Support.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\SurfControl\CyberPatrol\CPHQ.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Messenger Plus! 3\MsgPlus.exe C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\SURFCO~1\CYBERP~1\cpserver.exe C:\Program Files\Microsoft Money\System\Money Express.exe C:\Program Files\Messenger\MSMSGS.EXE C:\PROGRA~1\SURFCO~1\CYBERP~1\cpACtrl.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe C:\PROGRA~1\SURFCO~1\CYBERP~1\cpCCtrl.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe C:\PROGRA~1\INCRED~1\bin\IMApp.exe C:\Program Files\SurfControl\CyberPatrol\cpkbinst.exe C:\WINDOWS\system32\fxssvc.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\WINDOWS\System32\HPZipm12.exe C:\Program Files\IncrediMail\bin\IncMail.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\System32\cidaemon.exe C:\WINDOWS\System32\cidaemon.exe c:\progra~1\intern~1\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\carole\Desktop\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http:??www.qwifqoanqycu.us/Pf4bB5aScw5BpNsuS9ALyAIXRdwtAuec7kVAJaAD/YA.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:??www.dellnet.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http:??rd.yahoo.com/customize/ymsgr/defaults/*http:??my.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http:??www.viegnmjgtedo.com/Pf4bB5aScw7Lj2IziDbj5DsXxw /z1mQVYeC4MjbNKniLbN/oefMb9hO3D9XTSzav.html O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5_2_3_0.dll O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {107F8465-678F-E111-ED4C-AE85C75524D4} - C:\PROGRA~1\16BARB~1\64 flag.exe O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [CyberPatrolNew] C:\Program Files\SurfControl\CyberPatrol\CPHQ.exe /m O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [pure ace] C:\PROGRA~1\AUDIOR~1\filmlinkjump.exe O4 - HKLM\..\Run: [curb copy grim second] C:\Documents and Settings\All Users\Application Data\pile cool curb copy\loud pop.exe O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: officejet 6100.lnk = ? O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res:??C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM) O9 - Extra button: MoneySide (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http:??messenger.zone.msn.com/binary/msgrchkr.cab30149.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http:??messenger.zone.msn.com/binary /MessengerStatsPAClient.cab30149.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http:??download.macromedia.com/pub/shockwave/cabs/director/sw.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http:??messenger.zone.msn.com/binary/MineSweeper.cab30149.cab O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http:??download.microsoft.com /download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB O16 - DPF: {68A2C3BD-7809-11D3-8ACF-0050046F2F9A} (AXELPlayer Class) - http:??a1153.g.akamai.net/7/1153/5970/v0005 /www.mindavenue.com/downloads/akamai/AXELPlayerAX_Win32.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http:??messenger.zone.msn.com/binary/MessengerStatsClient.cab30149.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http:??messenger.zone.msn.com/binary/ZIntro.cab30149.cab O16 - DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} (InstallShield Setup Player 2K2) - http:??www.cyberpatrol.com/cponline/setup.exe O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http:??download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http:??messenger.zone.msn.com/binary/WoF.cab30149.cab O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http:??www2.incredimail.com/contents/setup/downloader/imloader.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{98DC208F-3638-4710-927C-A4964839A227}: NameServer = 206.10.30.100,206.10.30.101te_Log
Reference:
|