ampshock Posted October 7, 2005 Report Share Posted October 7, 2005 (edited) Logfile of HijackThis v1.99.1Scan saved at 3:06:18 PM, on 10/7/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exeC:\Program Files\Norton AntiVirus\navapsvc.exeC:\Program Files\Norton AntiVirus\IWP\NPFMntor.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\Program Files\ATI Technologies\ATI.ACE\cli.exeC:\WINDOWS\system32\RunDll32.exeC:\Program Files\Java\j2re1.4.2_02\bin\jusched.exeC:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exeC:\Program Files\ASUS\WLAN Card Utilities\Center.exeC:\Program Files\ASUS\Ai Booster\OverClk.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\QuickTime\qttask.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\winsupdater\winsupdater.exeC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\ProSiteFinder\ProSiteFinder.exeC:\Program Files\ISTsvc\istsvc.exeC:\Program Files\winupdates\winupdates.exeC:\WINDOWS\system32\cmd.exeC:\Program Files\Common Files\services.exeC:\Program Files\Common Files\Windows\services32.exeC:\Program Files\ATI Technologies\ATI.ACE\CLI.exeC:\Program Files\Stardock\ObjectDock\ObjectDock.exeC:\Program Files\Common Files\Windows\services32.exeC:\WINDOWS\system32\cmd.exeC:\Program Files\Common Files\services.exeC:\Program Files\ProSiteFinder\prositefinderh.exeC:\Program Files\ProSiteFinder\ProSiteFinder.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Documents and Settings\Tyler.me\Desktop\tools\HijackThis-1.exeR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=192.168.0.1:83O2 - BHO: (no name) - {00000000-0000-436A-B96F-84A0C2FA4969} - C:\Program Files\ProSiteFinder\ProSiteFinder.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dllO2 - BHO: Internet Explorer Web Content Catcher - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} - C:\Program Files\DNS\Catcher.dllO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dllO4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeO4 - HKLM\..\Run: [] winlog.exeO4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtimeO4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exeO4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWndO4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_02\bin\jusched.exeO4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exeO4 - HKLM\..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exeO4 - HKLM\..\Run: [Launch Ai Booster] C:\Program Files\ASUS\Ai Booster\OverClk.exeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [winsupdater] C:\Program Files\winsupdater\winsupdater.exe /autoO4 - HKLM\..\Run: [180sa] c:\program files\180search assistant\180sa.exeO4 - HKLM\..\Run: [ProSiteFinder] "C:\Program Files\ProSiteFinder\ProSiteFinder.exe"O4 - HKLM\..\Run: [aXRcE] C:\WINDOWS\xwwebhfa.exeO4 - HKLM\..\Run: [iST Service] C:\Program Files\ISTsvc\istsvc.exeO4 - HKLM\..\Run: [KmeOkbvF5] C:\WINDOWS\sudfpt.exeO4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /ConsumerO4 - HKLM\..\Run: [KmeOkbvùõš/‚²‘ÆßfÃC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\sudfpt.exeO4 - HKLM\..\Run: [ó# ë"h'þ9ÓœW3rÅ°WC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\sudfpt.exeO4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /autoO4 - HKLM\..\RunServices: [] winlog.exeO4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [sTYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -HideO4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000137.exeO4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000137.exeO4 - HKCU\..\Run: [GoogleDCClient] C:\Program Files\GoogleDCC\GoogleDCC.exe -startupO4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exeO4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXEO4 - Global Startup: RAID Manager.lnk = ?O4 - Global Startup: Sam.lnk = ?O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dllO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cabO20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dllO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exeO23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeO23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exeO23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exeO23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exeO23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeO23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exeO23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeThis is my first time doing a log, but here it is. My computer has been having gliches and isnt very stable, I was wondering if yall could help. Edited October 7, 2005 by ampshock Link to post Share on other sites
ampshock Posted October 7, 2005 Author Report Share Posted October 7, 2005 And if I press Ctrl-Alt-Delete and click task manager it wont come up. It was working a few days ago. Link to post Share on other sites
tj416 Posted October 7, 2005 Report Share Posted October 7, 2005 (edited) Hi ampshock,Since HijackThis does not scan the entire system and only certain areas are scanned to help diagnose the presence of undetected malware in some of the telltale places it hides. It is extremely important that you run a full system scan tool like an online virus scan, Ad-aware SE and Spybot S&D. I would like to START with those steps and finish the cleanup of strays or undetected items with HJT. I have provided instructions on how to run scans with a Online virus scanner, Ad-aware SE and Spybot S&D in this post.1) Run one of these Online virus scanners:HousecallPandaRAV Anti-virus OnlineeTrust Anti-virus Scanner2) Download, install, update and run a scan with Spybot S&D:Download and Install Spybot S&D, accepting the Default Settings.In the Menu Bar at the top of the Spybot window you will see 'Mode'. Make certain that 'default mode' has a check mark beside it.Close ALL windows except Spybot S&DClick the button to ‘Search for Updates’ and then download and install all available Updates.Next click the button ‘Check for Problems’ When Spybot is complete, it will be showing ‘RED’ entries bold 'Black' entries and ‘GREEN’ entries in the window.Make certain there is a check mark beside all of the RED entries ONLY.Choose ‘Fix Selected Problems’ and allow Spybot to fix the RED entries.REBOOT to complete the scan and clear memory.3) Download, install, update, configure and run a scan with Ad-aware SE:Download and Install Ad-Aware SE, keeping the default options. However, some of the settings will need to be changed before your first scan.Close ALL windows except Ad-Aware SE.Click on the‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window:In the ‘General’ window make sure the following are selected in green:Under Safety:Automatically save log-fileAutomatically quarantine objects prior to removalSafe Mode (always request confirmation)[*]Under Definitions:Prompt to update outdated definitions - set the number of days[*]Click on the ‘Scanning’ button on the left and select in green :Under Driver, Folders & Files:Scan Within Archives[*]Under Select drives & folders to scan:choose all hard drives[*]Under Memory & Registry: all greenScan Active ProcessesScan RegistryDeep Scan RegistryScan my IE favorites for banned URL’sScan my Hosts file[*]Click on the ‘Advanced’ button on the left and select in green:Under Shell Integration:Move deleted files to recycle bin[*]Under Logfile Detail Level: (all green)include addtional object informationDESELECT - include negligible objects informationinclude environment information[*]Under Alternate Data Streams:Don't log streams smaller than 0 bytesDon't log ADS with the following names: CA_INOCULATEIT[*]Click the ‘Tweak’ button and select in green:Under ‘Scanning Engine’:Unload recognized processes during scanningScan registry for all users instead of current user only[*]Under ‘Cleaning Engine’:Let Windows remove files in use at next reboot[*]Under Log Files:Include basic Ad-aware SE settings in logfileInclude additional Ad-aware SE settings in logfilePlease do not check: Include Module list in logfile[*]Click on ‘Proceed’ to save the settings.[*]Click ‘Start’[*]Choose 'Perform Full System Scan'[*]DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.[*]Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically. [*]If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window[*]Save the log file when it asks and then click ‘Finish’[*]REBOOT to complete the removal of what Ad-Aware SE found.4) Prepare in your reply:A fresh HijackThis log. Edited October 7, 2005 by tj416 Link to post Share on other sites
ampshock Posted October 8, 2005 Author Report Share Posted October 8, 2005 (edited) Logfile of HijackThis v1.99.1Scan saved at 1:45:21 PM, on 10/8/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\Program Files\ATI Technologies\ATI.ACE\cli.exeC:\WINDOWS\system32\RunDll32.exeC:\Program Files\Java\j2re1.4.2_02\bin\jusched.exeC:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exeC:\Program Files\ASUS\WLAN Card Utilities\Center.exeC:\Program Files\ASUS\Ai Booster\OverClk.exeC:\Program Files\QuickTime\qttask.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Common Files\Windows\services32.exeC:\WINDOWS\system32\cmd.exeC:\Program Files\Common Files\services.exeC:\Program Files\ATI Technologies\ATI.ACE\CLI.exeC:\Program Files\Stardock\ObjectDock\ObjectDock.exeC:\Program Files\Mozilla Firefox\firefox.exeD:\My Documents\tools\HijackThis-1.exeR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=192.168.0.1:83O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: Internet Explorer Web Content Catcher - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} - C:\Program Files\DNS\Catcher.dllO4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeO4 - HKLM\..\Run: [] winlog.exeO4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtimeO4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exeO4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWndO4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_02\bin\jusched.exeO4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exeO4 - HKLM\..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exeO4 - HKLM\..\Run: [Launch Ai Booster] C:\Program Files\ASUS\Ai Booster\OverClk.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [winsupdater] C:\Program Files\winsupdater\winsupdater.exe /autoO4 - HKLM\..\Run: [aXRcE] C:\WINDOWS\xwwebhfa.exeO4 - HKLM\..\Run: [KmeOkbvF5] C:\WINDOWS\sudfpt.exeO4 - HKLM\..\Run: [KmeOkbvùõš/‚²‘ÆßfÃC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\sudfpt.exeO4 - HKLM\..\Run: [ó# ë"h'þ9ÓœW3rÅ°WC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\sudfpt.exeO4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /autoO4 - HKLM\..\RunServices: [] winlog.exeO4 - HKCU\..\Run: [sTYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -HideO4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000140.exeO4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000140.exeO4 - HKCU\..\Run: [GoogleDCClient] C:\Program Files\GoogleDCC\GoogleDCC.exe -startupO4 - HKCU\..\Run: [WinRoll] C:\Program Files\WinRoll\winroll.exeO4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exeO4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXEO4 - Global Startup: RAID Manager.lnk = ?O4 - Global Startup: Sam.lnk = ?O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dllO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cabO16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cabO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exeO23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeThanks for the clean out. I think it got rid of some junk. Here is the new one, I am able to use the task manager again. So, is it bad Doc? Edited October 8, 2005 by ampshock Link to post Share on other sites
tj416 Posted October 9, 2005 Report Share Posted October 9, 2005 Hi ampshock,You may want to print out these instructions or save them to your desktop as a text file with Notepad because we will be restarting into Safe Mode later on in the fix and you might not be able to access the Internet.Go to Add/Remove Programs and uninstall (if present):winsupdaterwinupdatesISTsvcDNSThen, open HijackThis, run a scan and check these items:O2 - BHO: Internet Explorer Web Content Catcher - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} - C:\Program Files\DNS\Catcher.dllO4 - HKLM\..\Run: [] winlog.exeO4 - HKLM\..\Run: [winsupdater] C:\Program Files\winsupdater\winsupdater.exe /autoO4 - HKLM\..\Run: [aXRcE] C:\WINDOWS\xwwebhfa.exeO4 - HKLM\..\Run: [KmeOkbvF5] C:\WINDOWS\sudfpt.exeO4 - HKLM\..\Run: [KmeOkbvùõš/‚²‘ÆßfÃC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\sudfpt.exeO4 - HKLM\..\Run: [ó# ë"h'þ9ÓœW3rÅ°WC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\sudfpt.exeO4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /autoO4 - HKLM\..\RunServices: [] winlog.exeO4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000140.exeO4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000140.exeNow please close all windows and browsers, except HijackThis, and have HijackThis fix them by clicking on Fix Checked.Then, reboot in Safe mode. To reboot in Safe mode:Restart your computer and immediately begin tapping the F8 key on your keyboard. If done right a Windows Advanced Options menu will appear. Select the Safe Mode option and press Enter. You will need to configure Windows XP to show all files and folders.Open My Computer.Select the Tools menu and click Folder Options.Select the View Tab.Under the Hidden files and folders heading select Show hidden files and folders.Uncheck the Hide protected operating system files (recommended) option.Click Yes to confirm.Click OK.Then, delete these files:C:\Program Files\Common Files\mc-58-12-0000140.exeC:\Program Files\Common Files\Windows\mc-58-12-0000140.exeC:\Program Files\Common Files\Windows\services32.exeC:\Program Files\Common Files\services.exeC:\WINDOWS\xwwebhfa.exeC:\WINDOWS\sudfpt.exeThen, search for this file and delete it:winlog.exeThesn, delete these folders:C:\Program Files\winsupdaterC:\Program Files\winupdatesC:\Program Files\ISTsvcC:\Program Files\DNSThen, clean out temporary files:Start | Run | type cleanmgr | OKLet it scan your system for files to remove.Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.Click "OK" to remove them.Click "Yes" to confirm the deletion.Then, reboot (in the normal mode) and post a fresh log in this thread. Link to post Share on other sites
ampshock Posted October 9, 2005 Author Report Share Posted October 9, 2005 Logfile of HijackThis v1.99.1Scan saved at 6:25:18 PM, on 10/9/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\Program Files\ATI Technologies\ATI.ACE\cli.exeC:\WINDOWS\system32\RunDll32.exeC:\Program Files\Java\j2re1.4.2_02\bin\jusched.exeC:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exeC:\Program Files\ASUS\WLAN Card Utilities\Center.exeC:\Program Files\ASUS\Ai Booster\OverClk.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeC:\Program Files\ATI Technologies\ATI.ACE\CLI.exeC:\Program Files\Stardock\ObjectDock\ObjectDock.exeC:\Documents and Settings\Tyler.me\Desktop\tools\HijackThis-1.exeR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=192.168.0.1:83O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeO4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtimeO4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exeO4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWndO4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_02\bin\jusched.exeO4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exeO4 - HKLM\..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exeO4 - HKLM\..\Run: [Launch Ai Booster] C:\Program Files\ASUS\Ai Booster\OverClk.exeO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKCU\..\Run: [sTYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -HideO4 - HKCU\..\Run: [GoogleDCClient] C:\Program Files\GoogleDCC\GoogleDCC.exe -startupO4 - HKCU\..\Run: [WinRoll] C:\Program Files\WinRoll\winroll.exeO4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exeO4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXEO4 - Global Startup: RAID Manager.lnk = ?O4 - Global Startup: Sam.lnk = ?O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dllO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cabO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exeO23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)I did every thing you listed in your instructions. Is it clean now? Link to post Share on other sites
tj416 Posted October 11, 2005 Report Share Posted October 11, 2005 Hi ampshock,Your log looks clean. How is everything running? Link to post Share on other sites
ampshock Posted October 12, 2005 Author Report Share Posted October 12, 2005 Looks good and stable, no glitches or problems.Thanks, Good Job TJ. Link to post Share on other sites
tj416 Posted October 12, 2005 Report Share Posted October 12, 2005 Hi ampshock,Don't forget to re-hide all files and folders. To re-hide all files and folders:Open My Computer.Select the Tools menu and click Folder Options.Select the View Tab.Under the Hidden files and folders heading deselect "Show hidden files and folders".Check the Hide protected operating system files (recommended) option.Click Yes to confirm.Click OK.To prevent re-infection in the future:I suggest you download Spyware Blaster to prevent the installation of Spyware in the first place.IE-Spyad puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all and I suggest you download it. Another excellent program I recommend is SpywareGuard. It provides a degree of real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method. I recommend that you read a thead titled So how do I get infected in the first place? by Tony Klein which informs you on how to tighten the security of your PC.Take care,TJ Link to post Share on other sites
Matt Posted December 5, 2005 Report Share Posted December 5, 2005 This thread is being closed because it has been resolved. If you would like it to be reopened please a member of the Moderating team.Matt Link to post Share on other sites
Recommended Posts