Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Spyware / Virus Removal Spyware, virus, browser hijack and other malware removal.

Reply
 
Thread Tools Display Modes
  #1  
Old 02-12-2005, 08:50 PM
Melodi's Avatar
Melodi Melodi is offline
MCP Win XP
 
Join Date: Nov 2004
Location: Frozen Tundra ( Canadian Wanna Be)
Posts: 519
Send a message via MSN to Melodi Send a message via Yahoo to Melodi
Logfile of HijackThis v1.99.0
Scan saved at 7:47:31 PM, on 2/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\winlogon.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: scesrcl - {3EEDEB64-26CA-261A-9DB3-B2B5B2E8384B} - C:\WINDOWS\System32\SCESRCL.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {A69E2DF0-29D1-3E4E-32B4-C36165286F96} - C:\DOCUME~1\Ian\APPLIC~1\INTRAT~1\TIMELOCKS.exe (file missing)
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_12_0 .dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll (file missing)
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll (file missing)
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [NvCplScan] nvsc32.exe
O4 - HKLM\..\Run: [win32] winhost.exe
O4 - HKLM\..\Run: [bec] C:\WINDOWS\System32\bec.exe
O4 - HKLM\..\RunServices: [win32] winhost.exe
O4 - HKLM\..\RunServices: [NvCplScan] nvsc32.exe
O4 - HKLM\..\RunOnce: [NvCplScan] nvsc32.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/...gameloader.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/game...ts/y/jt0_x.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab30149.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab28578.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...StatsClient.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary...o.cab28578.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab28578.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.ex e
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
__________________
You know you are getting old when you hear music you listened to in high school playing on the oldies station.
Reply With Quote
Posted


  #2  
Old 02-12-2005, 09:05 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Rescan with hijack, insert a check next to these then close all other open windows and click "fix checked"

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com


O2 - BHO: (no name) - SOFTWARE - (no file)

O2 - BHO: scesrcl - {3EEDEB64-26CA-261A-9DB3-B2B5B2E8384B} - C:\WINDOWS\System32\SCESRCL.dll (file missing)

O2 - BHO: (no name) - {A69E2DF0-29D1-3E4E-32B4-C36165286F96} - C:\DOCUME~1\Ian\APPLIC~1\INTRAT~1\TIMELOCKS.exe (file missing)

O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll (file missing)

O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll (file missing)

O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll (file missing)

O4 - HKLM\..\Run: [win32] winhost.exe

O4 - HKLM\..\Run: [bec] C:\WINDOWS\System32\bec.exe

O4 - HKLM\..\RunServices: [win32] winhost.exe

O4 - HKLM\..\RunServices: [NvCplScan] nvsc32.exe

O4 - HKLM\..\RunOnce: [NvCplScan] nvsc32.exe


Then run an online scan Robin because there is a trojan on the system that isnt showing its face in the log ..


I recommend this :
<span style="color:#6600CC">Download TDS-3 trojan scanner from http://tds.diamondcs.com.au/index.php?page=download

Then you will need to manually update it so follow the instructions given here
http://tds.diamondcs.com.au/index.php?page=update

Now open the program, pause until its finished its mini test then click system testing / full scan

If anything is found, right click and select delete to each when the scan completes itself.</span>
Reply With Quote
  #3  
Old 02-12-2005, 09:06 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
And what software are you using for remote connecting ?
Reply With Quote
  #4  
Old 02-12-2005, 09:08 PM
Melodi's Avatar
Melodi Melodi is offline
MCP Win XP
 
Join Date: Nov 2004
Location: Frozen Tundra ( Canadian Wanna Be)
Posts: 519
Send a message via MSN to Melodi Send a message via Yahoo to Melodi
Yes, there is a trojan and norton keeps detecting it (so says the family) but when I got the computer i could only start it in safe mode, so the hjt is from safe mode. A little while ago I tried to download bitdefender and it wouldn't start, said failed to load interface
__________________
You know you are getting old when you hear music you listened to in high school playing on the oldies station.
Reply With Quote
  #5  
Old 02-12-2005, 09:11 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
so it wont start in reg mode. Look in msconfig for odd startup entries and disable them. You can actually disable all in msconfig then try restarting.
Reply With Quote
  #6  
Old 02-12-2005, 09:45 PM
Melodi's Avatar
Melodi Melodi is offline
MCP Win XP
 
Join Date: Nov 2004
Location: Frozen Tundra ( Canadian Wanna Be)
Posts: 519
Send a message via MSN to Melodi Send a message via Yahoo to Melodi
I was able to get panda to start and it's already found something.
__________________
You know you are getting old when you hear music you listened to in high school playing on the oldies station.
Reply With Quote
  #7  
Old 02-12-2005, 09:47 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Just watch carefully in the end of the scan as to whethewr or not it was cleanable or deletable and if not then note the file(s) path.
Reply With Quote
  #8  
Old 02-17-2005, 12:53 PM
Melodi's Avatar
Melodi Melodi is offline
MCP Win XP
 
Join Date: Nov 2004
Location: Frozen Tundra ( Canadian Wanna Be)
Posts: 519
Send a message via MSN to Melodi Send a message via Yahoo to Melodi
Sorry I didn't get back to you sooner, been busy at work. I did a Panda scan and it took care of 6 trojans and I didn't get a chance to run another hjt log, because I got sick and then she needed her computer back. Thanks for your help
__________________
You know you are getting old when you hear music you listened to in high school playing on the oldies station.
Reply With Quote
  #9  
Old 02-17-2005, 12:55 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Anytime and hope your feeling better.. :doctor:
Reply With Quote
  #10  
Old 02-20-2005, 11:32 AM
Melodi's Avatar
Melodi Melodi is offline
MCP Win XP
 
Join Date: Nov 2004
Location: Frozen Tundra ( Canadian Wanna Be)
Posts: 519
Send a message via MSN to Melodi Send a message via Yahoo to Melodi
Thank you, I"m pretty much feeling better now. I checked with the family and they said the puter is running great so it must be OK, or OK enough until they have to have me look at it again [img]style_emoticons/<#EMO_DIR#>/blink.gif[/img]
__________________
You know you are getting old when you hear music you listened to in high school playing on the oldies station.
Reply With Quote
Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump



    All times are GMT -5. The time now is 04:43 PM.


    Firefox 2