Hi everyone, take a glance at this hijack log if you have the time please. - Techist - Tech Forum

Go Back   Techist - Tech Forum > Security | Computer, Devices, Software and Systems > Viruses, Spyware and Malware > HijackThis Logs (finished)
Click Here to Login
 
 
Thread Tools Display Modes
 
Old 03-26-2005, 03:01 PM   #1 (permalink)
Newb Techie
 
Join Date: Mar 2005
Posts: 23
Default Hi everyone, take a glance at this hijack log if you have the time please.

Logfile of HijackThis v1.99.1
Scan saved at 12:58:08 PM, on 3/26/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\System32\msiexec.exe
C:\Documents and Settings\drew\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.smbvlgrmheqgk.com/n4nC3im...w/yYsFzmh.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.avvgyhezjwhaiymm.com/n4nC...bu_B8S2cXg.htm
O1 - Hosts: 216.239.57.99 www.google.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {C3D25DA8-57AA-F5DA-E43A-820E97D10625} - C:\DOCUME~1\drew\APPLIC~1\MP3IDO~1\Barb defy.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [GLOBAL GLUE LOUD MEOW] C:\Documents and Settings\All Users.WINDOWS\Application Data\amenpeakglobalglue\time copy.exe
O4 - HKCU\..\Run: [Noun Admin] C:\DOCUME~1\drew\APPLIC~1\BIKEFA~1\poke draw.exe
O4 - HKCU\..\Run: [Internet Download Accelerator] C:\Program Files\IDA\ida.exe -autorun
O4 - HKCU\..\Run: [Asmw Soft Popups Burner] C:\Program Files\AsmwSoft\Asmw PC-Optimizer Pro\popups burner.exe
O4 - HKCU\..\Run: [Asmw Eraser] C:\Program Files\AsmwSoft\Asmw PC-Optimizer Pro\eraser.exe s
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1107828665784
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
__________________

__________________
dudedrew18 is offline  
Old 03-27-2005, 06:21 PM   #2 (permalink)
True Techie
 
Join Date: Mar 2005
Posts: 138
Default

Running processes are OK...


Fix these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.smbvlgrmheqgk.com/ n4nC3...mw/yYsFzmh.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.avvgyhezjwhaiymm.com/n4n...ibu_B8S2cXg.htm
O4 - HKLM\..\Run: [GLOBAL GLUE LOUD MEOW] C:\Documents and Settings\All Users.WINDOWS\Application Data\amenpeakglobalglue\time copy.exe
O4 - HKCU\..\Run: [Noun Admin] C:\DOCUME~1\drew\APPLIC~1\BIKEFA~1\poke draw.exe
__________________

z3phyr04 is offline  
Old 05-20-2005, 05:25 PM   #3 (permalink)
Techie Beyond Description
 
Osiris's Avatar
 
Join Date: Jan 2005
Location: Kentucky
Posts: 36,817
Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris
Default

Remove entries at your own risk


O1 - Hosts: 216.239.57.99 www.google.com This entry should be fixed immediately! Must be fixed!

O2 - BHO: (no name) - {C3D25DA8-57AA-F5DA-E43A-820E97D10625} - C:\DOCUME~1\drew\APPLIC~1\MP3IDO~1\Barb defy.exe
__________________
Osiris is offline  
 

« Help | analyze »
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off




Copyright 2002- Social Knowledge, LLC All Rights Reserved.

All times are GMT -5. The time now is 08:15 PM.


Powered by vBulletin® Version 3.8.8 Beta 1
Copyright ©2000 - 2018, vBulletin Solutions, Inc.