1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Can someone check my HJT log file please?

Discussion in 'Malware and Virus Removal Archive' started by KevKev, 2004/07/23.

Thread Status:
Not open for further replies.
  1. 2004/07/23
    KevKev

    KevKev Inactive Thread Starter

    Joined:
    2004/07/23
    Messages:
    1
    Likes Received:
    0
    Whenever I open internet explorer, a window opens up looking for my MS office XP disc. It then will open to a spyware site. I have read a few posts so I have run adaware and spybot, and now run HJT and created a log, and now i need help with what to check... Thank you very much.

    Logfile of HijackThis v1.98.0
    Scan saved at 7:50:32 AM, on 7/23/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\gearsec.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\Tablet.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\apist32.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ntlx.exe
    C:\WINDOWS\system32\tbctray.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\javaw.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Lime_Shop\Limeshop1.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Lime_Shop\Limeshop0.exe
    C:\Documents and Settings\Kevin Adams.HAL\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\porka.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\porka.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\porka.dll/sp.html#37049
    R3 - Default URLSearchHook is missing
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {9AA49064-D97B-D33A-6D53-161E61C7D8F3} - C:\WINDOWS\system32\atlws32.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe "
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [Limeshop0] "C:\Program Files\Lime_Shop\Limeshop0.exe "
    O4 - HKLM\..\Run: [ntlx.exe] C:\WINDOWS\system32\ntlx.exe
    O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\system32\tbctray.exe
    O4 - HKLM\..\RunOnce: [apist32.exe] C:\WINDOWS\apist32.exe
    O4 - HKLM\..\RunOnce: [winad.exe] C:\WINDOWS\winad.exe
    O4 - HKLM\..\RunOnce: [addmh.exe] C:\WINDOWS\system32\addmh.exe
    O4 - HKLM\..\RunOnce: [mfcye32.exe] C:\WINDOWS\system32\mfcye32.exe
    O4 - HKLM\..\RunOnce: [ipka.exe] C:\WINDOWS\ipka.exe
    O4 - HKLM\..\RunOnce: [ntbk.exe] C:\WINDOWS\ntbk.exe
    O4 - HKLM\..\RunOnce: [atlfc32.exe] C:\WINDOWS\system32\atlfc32.exe
    O4 - HKLM\..\RunOnce: [d3fv.exe] C:\WINDOWS\system32\d3fv.exe
    O4 - HKLM\..\RunOnce: [winwd.exe] C:\WINDOWS\system32\winwd.exe
    O4 - HKLM\..\RunOnce: [mfcwu32.exe] C:\WINDOWS\mfcwu32.exe
    O4 - HKLM\..\RunOnce: [ntdf32.exe] C:\WINDOWS\system32\ntdf32.exe
    O4 - HKLM\..\RunOnce: [apiwr.exe] C:\WINDOWS\apiwr.exe
    O4 - HKLM\..\RunOnce: [netcm.exe] C:\WINDOWS\netcm.exe
    O4 - HKLM\..\RunOnce: [sdksu32.exe] C:\WINDOWS\system32\sdksu32.exe
    O4 - HKLM\..\RunOnce: [iecs32.exe] C:\WINDOWS\system32\iecs32.exe
    O4 - HKLM\..\RunOnce: [crop32.exe] C:\WINDOWS\crop32.exe
    O4 - HKLM\..\RunOnce: [ntpg32.exe] C:\WINDOWS\ntpg32.exe
    O4 - HKLM\..\RunOnce: [netqg.exe] C:\WINDOWS\netqg.exe
    O4 - HKLM\..\RunOnce: [atlwm.exe] C:\WINDOWS\system32\atlwm.exe
    O4 - HKLM\..\RunOnce: [javamk.exe] C:\WINDOWS\javamk.exe
    O4 - HKLM\..\RunOnce: [atlci32.exe] C:\WINDOWS\atlci32.exe
    O4 - HKLM\..\RunOnce: [apijs32.exe] C:\WINDOWS\apijs32.exe
    O4 - HKLM\..\RunOnce: [msec32.exe] C:\WINDOWS\system32\msec32.exe
    O4 - HKLM\..\RunOnce: [mfckr.exe] C:\WINDOWS\system32\mfckr.exe
    O4 - HKLM\..\RunOnce: [iplq.exe] C:\WINDOWS\system32\iplq.exe
    O4 - HKLM\..\RunOnce: [d3em.exe] C:\WINDOWS\d3em.exe
    O4 - HKLM\..\RunOnce: [ieaf.exe] C:\WINDOWS\system32\ieaf.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: LimeWire 3.8.9.lnk = C:\Program Files\LimeWire\3.8.9\LimeWire.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\Lime_Shop\Sy700\Tp700\scri700a.htm
    O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
    O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52...pple.com/mickey/us/win/QuickTimeInstaller.exe
    O16 - DPF: {861FDA2A-2B57-4BDA-8B8B-305C9D5D8604} (_Multimedia Player) - http://www.pussyharem.com/stream/mmp.cab
    O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
     
  2. 2004/07/23
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Lets check something first
    Go to Start > Run > Services.msc
    (dont do anything yet please if they are there)

    Scroll down to the REMOTE PROCEDURE CALL (RPC) HELPER service, <is this there?
    WARNING: There's also a REMOTE PROCEDURE CALL (RPC) service, but that's a legitimate item.

    or it might be called "WORKSTATION NETLOGON SERVICE " <<<<<?
     

  3. to hide this advert.

Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.