1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Can someone help me see this hijackthis log?

Discussion in 'Malware and Virus Removal Archive' started by 10NY, 2005/07/21.

Thread Status:
Not open for further replies.
  1. 2005/07/21
    10NY

    10NY Inactive Thread Starter

    Joined:
    2004/06/08
    Messages:
    7
    Likes Received:
    0
    My comp has been slowed down a fair bit
    and tried virus detection and spyware detection
    but nothing is shown


    Logfile of HijackThis v1.97.7
    Scan saved at 10:02:38 PM, on 7/21/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Sygate\SPF\smc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\AGRSMMSG.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\PROGRA~1\INTERN~2\mum.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\MATLAB7\webserver\bin\win32\matlabserver.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\wuauclt.exe
    C:\PROGRA~1\WINZIP\winzip32.exe
    C:\Documents and Settings\10NY Wong\Local Settings\Temp\HijackThis.exe

    O1 - Hosts: 72.36.156.164 view.atdmt.com
    O1 - Hosts: 72.36.156.164 us.a1.yimg.com
    O1 - Hosts: 72.36.156.164 ad.n2434.doubleclick.net
    O1 - Hosts: 72.36.156.164 n3349ad.doubleclick.net
    O1 - Hosts: 72.36.156.164 altfarm.mediaplex.com
    O1 - Hosts: 72.36.156.164 ad.doubleclick.net
    O1 - Hosts: 72.36.156.164 z1.adserver.com
    O1 - Hosts: 72.36.156.164 ar.atwola.com
    O1 - Hosts: 72.36.156.164 ar1.atwola.com
    O1 - Hosts: 72.36.156.164 disney.go.com
    O1 - Hosts: 72.36.156.164 rcm.amazon.com
    O1 - Hosts: 72.36.156.164 familyfun.go.com
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {6B925150-4E3E-4EC7-B642-57392A9394C1} - C:\WINDOWS\system32\javamcore.dll
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe "
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKCU\..\Run: [InternodeUsage] C:\PROGRA~1\INTERN~2\mum.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
     
    10NY,
    #1
  2. 2005/07/21
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Have you emptied your Temporary Internet Files and Temp files?

    Before one of our experts takes a look at your log please download the latest version of HijackThis through Quicklinks in my signature, save it to a folder on your hard drive, say C:\HJT - not to the desktop or a temporary folder - run it and post a new log. This will save time as it will be the first request from our experts.
     

  3. to hide this advert.

  4. 2005/07/21
    10NY

    10NY Inactive Thread Starter

    Joined:
    2004/06/08
    Messages:
    7
    Likes Received:
    0
    ok

    done
    here is the latest HijackThis log

    Logfile of HijackThis v1.99.1
    Scan saved at 5:25:52 AM, on 7/22/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Sygate\SPF\smc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\PROGRA~1\INTERN~2\mum.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\MATLAB7\webserver\bin\win32\matlabserver.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
    C:\WINDOWS\msagent\AgentSvr.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\PROGRA~1\WINZIP\winzip32.exe
    C:\Documents and Settings\10NY Wong\Desktop\HijackThis.exe
    C:\HJT\HijackThis.exe

    R3 - Default URLSearchHook is missing
    O1 - Hosts: 72.36.156.164 view.atdmt.com
    O1 - Hosts: 72.36.156.164 us.a1.yimg.com
    O1 - Hosts: 72.36.156.164 ad.n2434.doubleclick.net
    O1 - Hosts: 72.36.156.164 n3349ad.doubleclick.net
    O1 - Hosts: 72.36.156.164 altfarm.mediaplex.com
    O1 - Hosts: 72.36.156.164 ad.doubleclick.net
    O1 - Hosts: 72.36.156.164 z1.adserver.com
    O1 - Hosts: 72.36.156.164 ar.atwola.com
    O1 - Hosts: 72.36.156.164 ar1.atwola.com
    O1 - Hosts: 72.36.156.164 disney.go.com
    O1 - Hosts: 72.36.156.164 rcm.amazon.com
    O1 - Hosts: 72.36.156.164 familyfun.go.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Java Machine Support Dll - {6B925150-4E3E-4EC7-B642-57392A9394C1} - C:\WINDOWS\system32\javamcore.dll
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe "
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKCU\..\Run: [InternodeUsage] C:\PROGRA~1\INTERN~2\mum.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB7\webserver\bin\win32\matlabserver.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
     
    10NY,
    #3
  5. 2005/07/21
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Right click on the Microsoft AntiSpyware icon (looks like a target) and click on Security Agents Status (Enabled) and click on Disable Real-time Protection.

    Scan again with HijackThis, place a check next to the following entries, close all other windows and click fix.

    R3 - Default URLSearchHook is missing
    O1 - Hosts: 72.36.156.164 view.atdmt.com
    O1 - Hosts: 72.36.156.164 us.a1.yimg.com
    O1 - Hosts: 72.36.156.164 ad.n2434.doubleclick.net
    O1 - Hosts: 72.36.156.164 n3349ad.doubleclick.net
    O1 - Hosts: 72.36.156.164 altfarm.mediaplex.com
    O1 - Hosts: 72.36.156.164 ad.doubleclick.net
    O1 - Hosts: 72.36.156.164 z1.adserver.com
    O1 - Hosts: 72.36.156.164 ar.atwola.com
    O1 - Hosts: 72.36.156.164 ar1.atwola.com
    O1 - Hosts: 72.36.156.164 disney.go.com
    O1 - Hosts: 72.36.156.164 rcm.amazon.com
    O1 - Hosts: 72.36.156.164 familyfun.go.com
    O2 - BHO: Java Machine Support Dll - {6B925150-4E3E-4EC7-B642-57392A9394C1} - C:\WINDOWS\system32\javamcore.dll
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u


    Reboot and run Panda ActiveScan. Save the report and post it's contents here, along with a new HijackThis log. Let us know how your computer is behaving.

    You can re-enable MSAS too. ;)
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.