1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Web Browser Hijacked - Hijackthis log

Discussion in 'Windows XP' started by Pepperoni, 2006/11/28.

Thread Status:
Not open for further replies.
  1. 2006/11/28
    Pepperoni

    Pepperoni Inactive Thread Starter

    Joined:
    2006/11/28
    Messages:
    8
    Likes Received:
    0
    Hi there guys!

    My web browser has been hijacked and I was wondering if you could help analyze my Hijackthis log and tell me what to delete. Thanks

    ----WARNING WALL OF TEXT :p ----

    Logfile of HijackThis v1.99.1
    Scan saved at 12:51:33 PM, on 29/11/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\ZoneLabs\isafe.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\WINDOWS\system32\dmcjd.exe
    C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.ex e
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\system32\svchost.exe
    C:\DOCUME~1\Annie\LOCALS~1\Temp\Rar$EX01.219\Hijac kThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bzzvfzywzwrvedclvehkqh.co...u52tRKlq8.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.com.au/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {93859685-D5B4-FCC9-75BE-E678B419EB6D} - C:\PROGRA~1\MEOW32~1\SoftwareThat.exe (file missing)
    O2 - BHO: (no name) - {C3FA8F31-E41D-2AE8-9DC0-DEEB7F3B4666} - C:\DOCUME~1\Annie\APPLIC~1\MEOW32~1\SoftwareThat.e xe (file missing)
    O2 - BHO: (no name) - {C8466323-486A-F891-2387-FD9E70CC73A1} - C:\DOCUME~1\Annie\APPLIC~1\MEOW32~1\SoftwareThat.e xe (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [LXBYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBYtim e.dll,_RunDLLEntry@16
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [dmcjd.exe] C:\WINDOWS\system32\dmcjd.exe
    O4 - HKCU\..\Run: [Itch Beep] C:\DOCUME~1\Annie\APPLIC~1\ONECLO~1\debugdatatool. exe
    O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EA Link\Core.exe -silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/fu...tup1.0.0.6.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/ins...loader_v10.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{167D9244-015E-4CA7-BF61-A7C09F6F0873}: NameServer = 85.255.113.91,85.255.112.9
    O17 - HKLM\System\CCS\Services\Tcpip\..\{AFFBA3B1-213F-40E2-BE46-596B7C6242F0}: NameServer = 85.255.113.91,85.255.112.9
    O17 - HKLM\System\CCS\Services\Tcpip\..\{CC2AB334-5B27-4855-8EBC-89AD4284300B}: NameServer = 85.255.113.91,85.255.112.9
    O17 - HKLM\System\CCS\Services\Tcpip\..\{E0F5CA96-DBB7-46D7-B945-FAD660DA2A4F}: NameServer = 85.255.113.91,85.255.112.9
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = qld.bigpond.net.au
    O17 - HKLM\System\CS1\Services\VxD\MSTCP: SearchList = qld.bigpond.net.au
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.91 85.255.112.9
    O17 - HKLM\System\CS1\Services\Tcpip\..\{167D9244-015E-4CA7-BF61-A7C09F6F0873}: NameServer = 85.255.113.91,85.255.112.9
    O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = qld.bigpond.net.au
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = qld.bigpond.net.au
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.91 85.255.112.9
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: lxby_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbycoms.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
     
  2. 2006/11/28
    Bill Castner

    Bill Castner Inactive

    Joined:
    2006/08/30
    Messages:
    1,980
    Likes Received:
    0

  3. to hide this advert.

  4. 2006/11/28
    Pepperoni

    Pepperoni Inactive Thread Starter

    Joined:
    2006/11/28
    Messages:
    8
    Likes Received:
    0
    Done, I apologise.

    Can you see anything there that would contribute to the webpage hijacking?
     
  5. 2006/11/28
    Bill Castner

    Bill Castner Inactive

    Joined:
    2006/08/30
    Messages:
    1,980
    Likes Received:
    0
    You mean like these entries:


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bzzvfzywzwrvedclvehkqh.co...u52tRKlq8.html

    O2 - BHO: (no name) - {93859685-D5B4-FCC9-75BE-E678B419EB6D} - C:\PROGRA~1\MEOW32~1\SoftwareThat.exe (file missing)
    O2 - BHO: (no name) - {C3FA8F31-E41D-2AE8-9DC0-DEEB7F3B4666} - C:\DOCUME~1\Annie\APPLIC~1\MEOW32~1\SoftwareThat.exe (file missing)
    O2 - BHO: (no name) - {C8466323-486A-F891-2387-FD9E70CC73A1} - C:\DOCUME~1\Annie\APPLIC~1\MEOW32~1\SoftwareThat.exe (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O4 - HKLM\..\Run: [dmcjd.exe] C:\WINDOWS\system32\dmcjd.exe

    O17 - HKLM\System\CCS\Services\Tcpip\..\{167D9244-015E-4CA7-BF61-A7C09F6F0873}: NameServer = 85.255.113.91,85.255.112.9
    O17 - HKLM\System\CCS\Services\Tcpip\..\{AFFBA3B1-213F-40E2-BE46-596B7C6242F0}: NameServer = 85.255.113.91,85.255.112.9
    O17 - HKLM\System\CCS\Services\Tcpip\..\{CC2AB334-5B27-4855-8EBC-89AD4284300B}: NameServer = 85.255.113.91,85.255.112.9
    O17 - HKLM\System\CCS\Services\Tcpip\..\{E0F5CA96-DBB7-46D7-B945-FAD660DA2A4F}: NameServer = 85.255.113.91,85.255.112.9
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = qld.bigpond.net.au
    O17 - HKLM\System\CS1\Services\VxD\MSTCP: SearchList = qld.bigpond.net.au
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.91 85.255.112.9
    O17 - HKLM\System\CS1\Services\Tcpip\..\{167D9244-015E-4CA7-BF61-A7C09F6F0873}: NameServer = 85.255.113.91,85.255.112.9
    O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = qld.bigpond.net.au
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = qld.bigpond.net.au
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.91 85.255.112.9

    They will sort out in the spyware forum the hidden entries for Ruins. And hopefully update your Java.
     
  6. 2006/11/28
    Pepperoni

    Pepperoni Inactive Thread Starter

    Joined:
    2006/11/28
    Messages:
    8
    Likes Received:
    0
    Thanks, ill wait it out

    Feel free to delete this thread
     
  7. 2006/11/29
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Being handled here.

    This topic is locked.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.