murtu52 Posted March 20, 2005 Report Share Posted March 20, 2005 My friend has recently been attacked with many malware programs and viruses. I asked him to run A squared, which he was attempting to, and I also told him to run HijackThis, just to see whats on his computer. I am not yet perfect in my log analyzation, and his computer is in a really bad condition, so here you go, experts:Logfile of HijackThis v1.99.1Scan saved at 9:16:24 AM, on 3/20/2005Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\System32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\System32\gearsec.exeC:\WINDOWS\system32\HPConfig.exeC:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exeC:\WINDOWS\wanmpsvc.exeC:\WINDOWS\System32\secsrvrc.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\System32\carpserv.exeC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\Program Files\HPQ\One-Touch\OneTouch.EXEC:\Program Files\Synaptics\SynTP\SynTPLpr.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\System32\ezSP_Px.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\iPod\bin\iPodService.exeC:\windows\system32\qpourky.exeC:\WINDOWS\System32\winupdt.exeC:\WINDOWS\System32\RUNDLL32.exeC:\windows\system32\wjisdua.exeC:\windows\system32\calc.exeC:\WINDOWS\System32\ipvoice.exeC:\Program Files\AutoUpdate\AutoUpdate.exeC:\Documents and Settings\All Users\Application Data\msw\BMan1.exeC:\PROGRA~1\VBouncer\VirtualBouncer.exeC:\DOCUME~1\ALLUSE~1\APPLIC~1\msw\BMan.exeC:\WINDOWS\System32\rundll32.exeC:\WINDOWS\System32\sysmonnt.exeC:\WINDOWS\System32\inp40u.exeC:\Program Files\AdDestroyer\AdDestroyer.exeC:\WINDOWS\System32\wuauclt.exeC:\Program Files\America Online 8.0\aol.exeC:\Program Files\America Online 8.0\waol.exeC:\Program Files\America Online 8.0\aolwbspd.exeC:\Program Files\Internet Explorer\iexplore.exeC:\WINDOWS\System32\wintask.exeC:\Program Files\Common Files\WinTools\WToolsA.exeC:\Program Files\Common Files\WinTools\WSup.exeC:\Program Files\Toolbar\TBPS.exeC:\PROGRA~1\Toolbar\PIB.exec:\PROGRA~1\Toolbar\radio.exec:\PROGRA~1\Toolbar\WSG.exeC:\Program Files\Common Files\WinTools\WToolsS.exeC:\PROGRA~1\Toolbar\TBPSSvc.exeC:\WINDOWS\SysCheckBop32.exeC:\WINDOWS\sys012444125951.exeC:\Documents and Settings\Sebastian Park\Application Data\othb.exeC:\WINDOWS\system32\r?ndll.exeC:\WINDOWS\system\rbpwdv.exeC:\PROGRA~1\COMMON~1\rkik\rkikm.exeC:\PROGRA~1\COMMON~1\rkik\rkika.exeC:\Program Files\BullsEye Network\bin\bargains.exeC:\Program Files\CashBack\bin\cashback.exeC:\WINDOWS\System32\conime.exeC:\WINDOWS\system32\ntvdm.exeC:\Program Files\Media Pass\MediaPass.exeC:\Program Files\Media Pass\MediaPassK.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Documents and Settings\Sebastian Park\Desktop\HijackThis.exeR3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dllO2 - BHO: PynixObj Class - {00000000-DD60-0064-6EC2-6E0100000000} - C:\WINDOWS\Pynix.dllO2 - BHO: (no name) - {017C20C1-F86F-11D8-9B25-000ACD002AE3} - C:\WINDOWS\Helper101.dllO2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 59.dllO2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dllO2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dllO2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINDOWS\System32\rtneg.dllO2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dllO2 - BHO: &EliteSideBar - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - C:\WINDOWS\EliteSideBar\EliteSideBar 08.dllO2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dllO2 - BHO: (no name) - {F80E7B3F-E0D7-B92C-F82D-CEC9D7B66996} - C:\WINDOWS\System32\gaqajsdf.dllO3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 59.dllO3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dllO4 - HKLM\..\Run: [CARPService] carpserv.exeO4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exeO4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeO4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -dO4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exeO4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /sO4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXEO4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exeO4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exeO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [secsrvrc] C:\WINDOWS\System32\secsrvrc.exeO4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exeO4 - HKLM\..\Run: [myLinker] C:\PROGRA~1\myLinker\myLinker.exe /BO4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exeO4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exeO4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exeO4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exeO4 - HKLM\..\Run: [wjisdua] c:\windows\system32\wjisdua.exeO4 - HKLM\..\Run: [surfSideKick 2] C:\Program Files\SurfSideKick 2\Ssk.exeO4 - HKLM\..\Run: [vznqldbr] C:\Program Files\vznqldbr\vznqldbr.exeO4 - HKLM\..\Run: [tq8i38l] ipvoice.exeO4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"O4 - HKLM\..\Run: [bMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exeO4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitezvo32.exeO4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exeO4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exeO4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exeO4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exeO4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exeO4 - HKLM\..\Run: [systemCheck] C:\WINDOWS\SysCheckBop32O4 - HKLM\..\Run: [sys012444125951] C:\WINDOWS\sys012444125951.exeO4 - HKLM\..\Run: [bullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exeO4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashback.exeO4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPassK.exeO4 - HKLM\..\RunOnce: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe /bootO4 - HKLM\..\RunOnce: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe /bootO4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\mnyexpr.exe"O4 - HKCU\..\Run: [instant Access] rundll32.exe EGDACCESS_1057.dll,InstantAccessO4 - HKCU\..\Run: [sysmonnt] C:\WINDOWS\System32\sysmonntO4 - HKCU\..\Run: [surfSideKick 2] C:\Program Files\SurfSideKick 2\Ssk.exeO4 - HKCU\..\Run: [c9rsRUJtV] inp40u.exeO4 - HKCU\..\Run: [Aaou] C:\Documents and Settings\Sebastian Park\Application Data\othb.exeO4 - HKCU\..\Run: [Mgri] C:\WINDOWS\System32\r?ondll.exeO4 - HKCU\..\Run: [rkik] C:\PROGRA~1\COMMON~1\rkik\rkikm.exeO4 - HKCU\..\RunOnce: [enBrowser] C:\WINDOWS\mbop1-1.exeO4 - Startup: AdDestroyer.lnk = C:\Program Files\AdDestroyer\AdDestroyer.exeO4 - Global Startup: Microsoft Broadband Networking.lnk = %SystemRoot%\Installer\{2C84BB95-1DB9-4AC4-8750-F979BBCDD859}\_18be6784.exeO8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.htmlO8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.htmlO8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htmO8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htmO8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htmO8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htmO8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.htmlO8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.htmlO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dllO9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exeO9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exeO9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dllO14 - IERESET.INF: START_PAGE_URL=http://qus8l.hpwis.comO16 - DPF: {091CDD73-1401-4643-9B9C-65B091C88685} (MyLinker Control) - http://dizzo.contents.mylinker.co.kr/module/MyLinker.cabO16 - DPF: {26D73573-F1B3-48C9-A989-E6CE071957A1} - http://akamai.downloadv3.com/binaries/EGDA...ESS_1057_XP.cabO16 - DPF: {2B36F775-8CF5-4489-B454-2D1B80984CF2} (FXPluginCtl Object) - http://www.powerflasher.de/plugin/powerres.cabO16 - DPF: {51C99F40-9E0E-4BF1-A92A-77121CC01AD0} (IMBCClient Control) - http://touch.imbc.com/ocx/touch.cabO16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200312...meInstaller.exeO16 - DPF: {D8F001C6-43B1-4CFD-9DAF-C8BEAE0E2B6D} (Touch Control) - http://touch.imbc.com/ocx/Online.cabO16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{A6236EF6-D4D7-4A9E-8418-E5826BCE9031}: NameServer = 205.188.146.145O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dllO20 - Winlogon Notify: secsrvrc - C:\WINDOWS\SYSTEM32\secsrvrc.dllO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeO23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exeO23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exeO23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exeO23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exeO23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exeO23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exeO23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exeO23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exeO23 - Service: WebSeach Toolbar support NT service (TBPSSvc) - Unknown owner - C:\PROGRA~1\Toolbar\TBPSSvc.exeO23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exeO23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exeO23 - Service: ZESOFT - Unknown owner - C:\WINDOWS\zeta.exe Link to post Share on other sites
Dragon Posted March 21, 2005 Report Share Posted March 21, 2005 To clean some of it out already, please download Spybot: Search and Destroy from http://www.safer-networking.org/index.php?page=download . Check for Updates first, download ALL Updates and Do a Scan. When finished, make sure ALL RED items have been ticked, and click the "Fix Selected Problems" Button.I'd Also Recommend you Download AdAware, Another good Antispyware Program From http://www.lavasoftusa.com/support/download/ . Install The Program and Run it. Make Sure You Click the "Check for Updates" Button before starting a scan. Do a scan on AdAware and Remove Everything it suggests. After This, Reboot and Post a Fresh HijackThis log Link to post Share on other sites
Recommended Posts