newb Posted November 2, 2004 Report Share Posted November 2, 2004 Logfile of HijackThis v1.98.2Scan saved at 20:25:19, on 02-11-2004Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\HPConfig.exeC:\Programas\HPQ\Notebook Utilities\HPWirelessMgr.exeC:\Programas\Ficheiros comuns\Microsoft Shared\VS7Debug\mdm.exeC:\WINDOWS\System32\svchost.exeC:\Programas\Trend Micro\Internet Security\Tmntsrv.exeC:\Programas\Trend Micro\Internet Security\tmproxy.exeC:\Programas\Trend Micro\Internet Security\PccPfw.exeC:\WINDOWS\Explorer.EXEC:\Programas\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\Programas\HPQ\One-Touch\OneTouch.EXEC:\Programas\Synaptics\SynTP\SynTPLpr.exeC:\Programas\Synaptics\SynTP\SynTPEnh.exeC:\WINDOWS\system32\wuauclt.exeC:\Programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exeC:\WINDOWS\system32\carpserv.exeC:\Programas\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exeC:\Programas\QuickTime\qttask.exeC:\Programas\Trend Micro\Internet Security\pccguide.exeC:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exeC:\Programas\Trend Micro\Internet Security\PCClient.exeC:\Programas\Trend Micro\Internet Security\TMOAgent.exeC:\Programas\Creative\Video Blaster WebCam Control\CAMTRAY.EXEC:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exeC:\Programas\Messenger Plus! 3\MsgPlus.exeC:\Programas\Lavasoft\Ad-aware 6\Ad-watch.exeC:\WINDOWS\system32\ctfmon.exeC:\Programas\Paltalk\pnetaware.exec:\progra~1\intern~1\iexplore.exeC:\Programas\Internet Explorer\iexplore.exeC:\Programas\Microsoft Office\Office10\msoffice.exeC:\DOCUME~1\FJS\DEFINI~1\Temp\Directório temporário 1 para hijackthis.zip\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.jshcahnvezclzjdr.us/J4HgDYXfpYr...Zn3MbhV0ABN.jpgR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = HiperligaçõesO4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exeO4 - HKLM\..\Run: [Cpqset] C:\Programas\HPQ\Default Settings\cpqset.exeO4 - HKLM\..\Run: [ATIPTA] C:\Programas\ATI Technologies\ATI Control Panel\atiptaxx.exeO4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -dO4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exeO4 - HKLM\..\Run: [Display Settings] C:\Programas\HPQ\Notebook Utilities\hptasks.exe /sO4 - HKLM\..\Run: [QT4HPOT] C:\Programas\HPQ\One-Touch\OneTouch.EXEO4 - HKLM\..\Run: [synTPLpr] C:\Programas\Synaptics\SynTP\SynTPLpr.exeO4 - HKLM\..\Run: [synTPEnh] C:\Programas\Synaptics\SynTP\SynTPEnh.exeO4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"O4 - HKLM\..\Run: [CARPService] carpserv.exeO4 - HKLM\..\Run: [CXMon] "C:\Programas\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"O4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Programas\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Programas\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [pccguide.exe] "C:\Programas\Trend Micro\Internet Security\pccguide.exe"O4 - HKLM\..\Run: [PCClient.exe] "C:\Programas\Trend Micro\Internet Security\PCClient.exe"O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Programas\Trend Micro\Internet Security\TMOAgent.exe" /runO4 - HKLM\..\Run: [Creative WebCam Tray] C:\Programas\Creative\Video Blaster WebCam Control\CAMTRAY.EXEO4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exeO4 - HKLM\..\Run: [MessengerPlus3] "C:\Programas\Messenger Plus! 3\MsgPlus.exe"O4 - HKLM\..\Run: [Ad-aware] C:\Programas\Lavasoft\Ad-aware 6\Ad-aware.exe +cO4 - HKLM\..\Run: [Ad-watch] C:\Programas\Lavasoft\Ad-aware 6\Ad-watch.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [longbait] C:\DOCUME~1\FJS\APPLIC~1\FRAGRE~1\internetdupepure.exeO4 - Startup: PalNetaware.lnk = C:\Programas\Paltalk\pnetaware.exeO4 - Global Startup: Microsoft Office.lnk = C:\Programas\Microsoft Office\Office10\OSA.EXEO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exeO14 - IERESET.INF: START_PAGE_URL=http://www.creaf.comO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...StatsClient.cabO16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cabO16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cabProblematic bar pic here:http://animedvdcompare.no.sapo.pt/barra_explorer.JPGIt's the bottom bar... the top one was alreday removed... Link to post Share on other sites
therock247uk Posted November 2, 2004 Report Share Posted November 2, 2004 1. Please move Hijackthis to a permanent folder like c:/ so backups can be made.2. Then open Hijackthis from c:/hjt and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis.R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.jshcahnvezclzjdr.us/J4HgDYXfpYr...Zn3MbhV0ABN.jpgO4 - HKCU\..\Run: [longbait] C:\DOCUME~1\FJS\APPLIC~1\FRAGRE~1\internetdupepure.exe3. Reboot and delete the folders.C:\Documents and Settings\FJS\Application Data\FRAGRE~1\ < Folder starts with FRAGRE4. Then post a new Hijackthis log here in a reply. Link to post Share on other sites
Recommended Posts