Computing.Net > Forums > Security and Virus > My hijack log file

My hijack log file

Reply to Message Icon

Original Message
Name: Blazed7x
Date: January 10, 2004 at 21:27:48 Pacific
Subject: My hijack log file
OS: XP
CPU/Ram: 256mb
Comment:

This is my Hijackthis log, since I have a virus/trojan horse! KTTD told me to post. Can anyone help destroy my virus?! Here it is:


Logfile of HijackThis v1.97.7
Scan saved at 9:16:58 PM, on 01/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\System32\ltmsg.exe
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Free Surfer\fs20.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Netropa\OSD.exe
C:\Program Files\Eraser\eraser.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Kodak\KODAK Picture Transfer Software\pts.exe
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Nader\Local Settings\Temporary Internet Files\Content.IE5\2LJTL1EU\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.superwebsearch.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.superwebsearch.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.superwebsearch.com/ie/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.superwebsearch.com/ie/
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: (no name) - {0514BF06-B32B-C75D-3B51-AD8DD3D76BF1} - C:\WINDOWS\system32\gmpkctnu.dll
O2 - BHO: (no name) - {1E126BD0-B7E8-EBDB-C690-CFEB0C77AC2A} - C:\WINDOWS\system32\azkvjvaf.dll
O2 - BHO: (no name) - {1EA7AB55-1B40-B28E-4FAB-1A40B93ED8AD} - C:\WINDOWS\system32\mwnwcdwr.dll
O2 - BHO: (no name) - {3CA5B1DE-7563-5AFE-2FE1-F5EF35B55B2D} - C:\WINDOWS\system32\dvbedajl.dll
O2 - BHO: (no name) - {5B6CFA19-D35B-4DBD-8CEA-0ABB20FEECAE} - C:\WINDOWS\system32\slsbmsoh.dll
O2 - BHO: (no name) - {75FA6CFD-EDBC-F9FA-1E49-F2ADA424AEF8} - C:\WINDOWS\system32\jlfcmovr.dll
O2 - BHO: (no name) - {76F5BD6A-CA58-78B9-DFCD-058D7AC72266} - C:\WINDOWS\system32\hxeqango.dll
O2 - BHO: (no name) - {A732BD8C-B8EA-8C6E-DCDE-043CA0A7DB55} - C:\WINDOWS\system32\xtbfxboa.dll
O2 - BHO: (no name) - {C61458D1-D93B-DC9F-FA1A-BFABDEEBE941} - C:\WINDOWS\system32\zfueiwom.dll
O2 - BHO: (no name) - {DC77D24B-A6FA-4753-BCDF-1CAA374DF4EB} - C:\WINDOWS\system32\jutrjceh.dll
O2 - BHO: (no name) - {EFB3CD06-DCC4-DDA9-04C9-1AA09E53B6DD} - C:\WINDOWS\system32\zhgzpuzg.dll
O2 - BHO: (no name) - {F4840FA7-14EB-2538-B9E4-D5A5CEC54E7A} - C:\WINDOWS\system32\xppjtoni.dll
O2 - BHO: (no name) - {FA97CB15-33C1-45E4-B763-2670F100EFB8} - C:\WINDOWS\SYSTEM32\mob030612.dll
O2 - BHO: (no name) - {FE1A7544-BBBB-C13C-755B-D0F34D9883F8} - C:\WINDOWS\system32\tpiwhyvo.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\MSDXM.OCX
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Super Popup Blocker] C:\Saga\Super Popup Blocker\popkill.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [freesurfer] C:\Program Files\Free Surfer\fs20.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [] c:\WINDOWS\System32\
O4 - HKLM\..\Run: [WinPatrol] "C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe"
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Evidence Eliminator] C:\Program Files\Evidence Eliminator\ee.exe /m
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide
O4 - HKCU\..\Run: [Internet Washer Pro] C:\Program Files\Internet Washer Pro\iw.exe min
O4 - HKCU\..\Run: [Surf Shark] C:\Program Files\surfshark\shark.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [] c:\WINDOWS\System32\
O4 - Global Startup: Camio Viewer 2000.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O4 - Global Startup: KODAK Picture Transfer Software.lnk = ?
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Free Surfer (HKLM)
O9 - Extra 'Tools' menuitem: Free Surfer (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37986.7521990741



Report Offensive Message For Removal


Response Number 1
Name: Kevin The Tech Dude
Date: January 10, 2004 at 21:45:58 Pacific
Subject: My hijack log file
Reply: (edit)

Yes, I told him to post it. Stop using Kazaa and other P2P networks. I could remove your post for the fact you have Kazaa installed but I hope you have learned your lesson.

I will not help ya fix the problems though, others will.

KTTD



Report Offensive Follow Up For Removal

Response Number 2
Name: blender
Date: January 11, 2004 at 05:57:00 Pacific
Subject: My hijack log file
Reply: (edit)

Have only hijack running and check the following to fix:

First put hijack in its own folder because it makes backups of stuff deleted.

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.superwebsearch.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.superwebsearch.com/ie/

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.superwebsearch.com/ie/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.superwebsearch.com/ie/
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: (no name) - {0514BF06-B32B-C75D-3B51-AD8DD3D76BF1} - C:\WINDOWS\system32\gmpkctnu.dll
O2 - BHO: (no name) - {1E126BD0-B7E8-EBDB-C690-CFEB0C77AC2A} - C:\WINDOWS\system32\azkvjvaf.dll
O2 - BHO: (no name) - {1EA7AB55-1B40-B28E-4FAB-1A40B93ED8AD} - C:\WINDOWS\system32\mwnwcdwr.dll
O2 - BHO: (no name) - {3CA5B1DE-7563-5AFE-2FE1-F5EF35B55B2D} - C:\WINDOWS\system32\dvbedajl.dll
O2 - BHO: (no name) - {5B6CFA19-D35B-4DBD-8CEA-0ABB20FEECAE} - C:\WINDOWS\system32\slsbmsoh.dll
O2 - BHO: (no name) - {75FA6CFD-EDBC-F9FA-1E49-F2ADA424AEF8} - C:\WINDOWS\system32\jlfcmovr.dll
O2 - BHO: (no name) - {76F5BD6A-CA58-78B9-DFCD-058D7AC72266} - C:\WINDOWS\system32\hxeqango.dll
O2 - BHO: (no name) - {A732BD8C-B8EA-8C6E-DCDE-043CA0A7DB55} - C:\WINDOWS\system32\xtbfxboa.dll
O2 - BHO: (no name) - {C61458D1-D93B-DC9F-FA1A-BFABDEEBE941} - C:\WINDOWS\system32\zfueiwom.dll
O2 - BHO: (no name) - {DC77D24B-A6FA-4753-BCDF-1CAA374DF4EB} - C:\WINDOWS\system32\jutrjceh.dll
O2 - BHO: (no name) - {EFB3CD06-DCC4-DDA9-04C9-1AA09E53B6DD} - C:\WINDOWS\system32\zhgzpuzg.dll
O2 - BHO: (no name) - {F4840FA7-14EB-2538-B9E4-D5A5CEC54E7A} - C:\WINDOWS\system32\xppjtoni.dll
O2 - BHO: (no name) - {FA97CB15-33C1-45E4-B763-2670F100EFB8} - C:\WINDOWS\SYSTEM32\mob030612.dll
O2 - BHO: (no name) - {FE1A7544-BBBB-C13C-755B-D0F34D9883F8} - C:\WINDOWS\system32\tpiwhyvo.dll

O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART

O4 - HKLM\..\Run: [] c:\WINDOWS\System32\

O4 - HKCU\..\Run: [] c:\WINDOWS\System32\

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

Reboot and delete:

c:\windows\system32\p2p networking\p2p networking.exe <-the whole p2p networking folder.


Just to keep in mind...using p2p apps; over 45% of the files shared on them are infected by viruses/trojans/worms/spyware/and who knows what else.


Report Offensive Follow Up For Removal

Response Number 3
Name: Blazed7x
Date: January 11, 2004 at 11:32:53 Pacific
Subject: My hijack log file
Reply: (edit)

KTTD, I un-installed KaZaa about three months ago, I guarantee it! I just recently found out it has it on my PC for no reason...I don't have it currently installed


Blender, how am I supposed to put Hijackthis in its own 'folder'? I really need help here please..


Report Offensive Follow Up For Removal

Response Number 4
Name: Blazed7x
Date: January 11, 2004 at 11:53:15 Pacific
Subject: My hijack log file
Reply: (edit)

BLENDER...

Oh my God, may God bestow a pool of KUDOS to you....thank you so much, that irritating virus is FINALLY GONE!!

YOU rectified it when no other pathetic anti-virii program could work! You truly ROCK!

And I un-installed KaZaa like three months ago, so I don't know why it was still on there.

WinMX doesn't have spyware though, so that is safe to use.

Man, thank you so much! How did you do this? Your experienced in these fields?

Thanks...!


Report Offensive Follow Up For Removal

Response Number 5
Name: blender
Date: January 11, 2004 at 17:47:22 Pacific
Subject: My hijack log file
Reply: (edit)

Win MX is not full of spyware but still the main point that KTTD made is still there.
You are sharing files with people you don't know. These files can contain anything...THERE ARE NO SAFE P2P PROGRAMS!

Most antivirus programs do not do well to remove an infection...they are meant to stop the virus from infecting the system before you run the file. If the virus is caught before you run the file...it is easy to deal with...simply delete the file.
No one antivirus program can detect all viruses (there are only about 85,000 viruses out there) Antivirus programs are not designed to detect trojan horses (programs that allow unauthorized access to your pc) altho they will find some of the more common ones.
No antivirus is any good unless religiously kept up to date since it can't find what it does not know about.

How did I know what to fix?

HijackThis tutorial:

http://www.spywareinfo.com/~merijn/htlogtutorial.html

Startup list

http://sysinfo.org/startuplist.php

BHO list

http://sysinfo.org/bholist.php

Google helps alot and I hung around the forum for quite a while reading, learning, reading some more, and still learning (that never stops)
When I got my first computer...I was shown how to start it up, connect to the internet, start internet explorer...that is all I was shown. When I infected myself with a boatload of spyware, viruses, and had to pay someone to come over and clean the mess up, then I got hacked because I left the pc on all night downloading from p2p crap (also had no firewall)and after having to fdisk, format the hard drive and reinstall windows I decided I need to educate myself on why this was happening to me.
Now I have a network of 3 pc's...1 98, 2 xp.
Router
Firewall (not only to keep hackers out...monitors outgoing program access too)
Antivirus
Trojan scanner
Ad-aware (spyware scanner, remover)
Spybot (spyware scanner, immunizer, remover)
Spywareblaster (stops spyware downloads)
SpywareGuard (IE hijack protection)
Bazooka (spyware scanner)
And an assortment of other cleaners (most of which I use to help with cleaning other people's pc's.
I no longer use p2p programs, I keep everything up to date, scan everything I download and as a result have stayed problem free. I have since learned to read the licence agreement on downloads to help stay problem free.


Report Offensive Follow Up For Removal


Response Number 6
Name: techsupportgirl
Date: January 14, 2004 at 02:00:39 Pacific
Subject: My hijack log file
Reply: (edit)

Blender, I couldn't agree more. I work in IT support and you wouldn't believe the amount of time I waste removing that crap from users machines. Sometimes machines have to be wiped to remove all traces of the various spyware and viruses. Not to mention these people stop everyone else from using the network at full capacity by wasting bandwidth. Unfortunately we can't block all the ports used by p2p programs because some of them are used by legitimate applications as well.

I still occasionally use winmx and bittorrent at home when I need some obscure files you can't get anywhere else, like old TV programs, interviews, etc... but I'm extra careful. I use a firewall, antivirus, various spyware removers and I have IP Tools on all the time to check who is connecting/trying to connect to my machine.


Report Offensive Follow Up For Removal






Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: My hijack log file

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




How often do you use Computing.Net?

Every Day
Once a Week
Once a Month
This Is My First Time!


View Results

Poll Finishes In 3 Days.
Discuss in The Lounge