1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Hijackthis log and stuff..

Discussion in 'Virus & Other Malware Removal' started by Tagi, Sep 10, 2004.

Thread Status:
Not open for further replies.
Advertisement
  1. Tagi

    Tagi Thread Starter

    Joined:
    May 11, 2004
    Messages:
    6
    Hi! Just got back 2 my computer after having been away.. So thought I'd run Ad-aware just 2 have a looksie.. The scan turned out with somthing called "Possible browser hijack attempt" or somthing like that. The problems I've experienced are: MSN not willing 2 log on properly, and the graphics in my computer games etc looks crappy. I'm allmost sure there's some new processes running etc, but I'm not sure what's what...

    I scanned with Hijackthis as well, and I'll post the outcome of that now:


    Logfile of HijackThis v1.97.7
    Scan saved at 21:40:43, on 10.09.2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Apache2\bin\Apache.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\PROGRA~1\DIRECT~1\DUService.exe
    C:\Programfiler\Fellesfiler\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\svchost.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Apache2\bin\Apache.exe
    C:\Programfiler\WZCBDL Service\WZCBDLS.exe
    C:\WINDOWS\System32\Fast.exe
    C:\Programfiler\D-Link\Air USB Utility\AirCFG.exe
    D:\Alt\Surround Mixer\CTSysVol.exe
    D:\Alt\DVDAudio\CTDVDDet.EXE
    C:\WINDOWS\System32\CTHELPER.EXE
    D:\Alt\MsgPlus.exe
    C:\Programfiler\DirectUpdate\DUControl.exe
    C:\WINDOWS\System32\taskswitch.exe
    C:\WINDOWS\System32\fast.exe
    C:\Programfiler\iTunes\iTunesHelper.exe
    C:\Programfiler\Fellesfiler\Logitech\QCDriver3\LVCOMS.EXE
    C:\Programfiler\Messenger\msmsgs.exe
    C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\Apache2\bin\ApacheMonitor.exe
    C:\Programfiler\iPod\bin\iPodService.exe
    C:\Documents and Settings\Eier\Skrivebord\Ventrilo.exe
    D:\mIRC\mirc.exe
    D:\Alt\Winamp\winamp.exe
    D:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-aware.exe
    C:\Documents and Settings\Eier\Skrivebord\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\alt\Reader\ActiveX\AcroIEHelper.ocx
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [D-Link Air USB Utility] C:\Programfiler\D-Link\Air USB Utility\AirCFG.exe
    O4 - HKLM\..\Run: [CTSysVol] D:\Alt\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] D:\Alt\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
    O4 - HKLM\..\Run: [SBDrvDet] C:\Programfiler\Creative\SB Drive Det\SBDrvDet.exe /r
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [MessengerPlus3] "D:\Alt\MsgPlus.exe"
    O4 - HKLM\..\Run: [DUControl] C:\Programfiler\DirectUpdate\DUControl.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe
    O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\System32\fast.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] C:\Programfiler\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [LVCOMS] C:\Programfiler\Fellesfiler\Logitech\QCDriver3\LVCOMS.EXE
    O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Programfiler\Logitech\ImageStudio\ISStart.exe
    O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Programfiler\Logitech\ImageStudio\LogiTray.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "D:\Alt\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [LDM] C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [Steam] C:\Programfiler\Steam\Steam.exe -silent
    O4 - HKCU\..\Run: [Pulse] C:\Programfiler\Pulse\Pulse.exe -splash
    O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Monitor Apache Servers.lnk = C:\Apache2\bin\ApacheMonitor.exe
    O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Oppslag (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://ringblad.kamera.ringnett.no/activex/AxisCamControl.ocx
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38008.073587963
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    If someone could help me with this, (since I don't have any idea of what 2 remove when scanning with hijackthis..) I'd be a happy girl!

    Thanx 2 everyone who's helped in the past! =)! Love, Tagi
     
  2. LDTate

    LDTate Malware Specialist

    Joined:
    Aug 13, 2004
    Messages:
    789
    Hello Tagi. Your HijackThis is out dated. Delete the one you have now and download HijackThis from my signature. Be sure to keep it in it's own folder.

    Scan and post a new HJT log.
     
  3. Tagi

    Tagi Thread Starter

    Joined:
    May 11, 2004
    Messages:
    6
    Logfile of HijackThis v1.98.2
    Scan saved at 18:07:54, on 11.09.2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Apache2\bin\Apache.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\PROGRA~1\DIRECT~1\DUService.exe
    C:\Programfiler\Fellesfiler\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\svchost.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Apache2\bin\Apache.exe
    C:\Programfiler\WZCBDL Service\WZCBDLS.exe
    C:\WINDOWS\System32\Fast.exe
    C:\Programfiler\D-Link\Air USB Utility\AirCFG.exe
    D:\Alt\Surround Mixer\CTSysVol.exe
    D:\Alt\DVDAudio\CTDVDDet.EXE
    C:\WINDOWS\System32\CTHELPER.EXE
    D:\Alt\MsgPlus.exe
    C:\Programfiler\DirectUpdate\DUControl.exe
    C:\WINDOWS\System32\taskswitch.exe
    C:\WINDOWS\System32\fast.exe
    C:\Programfiler\iTunes\iTunesHelper.exe
    C:\Programfiler\Fellesfiler\Logitech\QCDriver3\LVCOMS.EXE
    C:\Programfiler\Messenger\msmsgs.exe
    C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\Apache2\bin\ApacheMonitor.exe
    C:\Programfiler\iPod\bin\iPodService.exe
    D:\mIRC\mirc.exe
    C:\Programfiler\Steam\Steam.exe
    C:\WINDOWS\system32\sndvol32.exe
    C:\Documents and Settings\Eier\Skrivebord\Ventrilo.exe
    D:\Alt\Winamp\winamp.exe
    C:\Programfiler\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Eier\Lokale innstillinger\Temp\Midlertidig mappe 2 for hijackthis.zip\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\alt\Reader\ActiveX\AcroIEHelper.ocx
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [D-Link Air USB Utility] C:\Programfiler\D-Link\Air USB Utility\AirCFG.exe
    O4 - HKLM\..\Run: [CTSysVol] D:\Alt\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] D:\Alt\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
    O4 - HKLM\..\Run: [SBDrvDet] C:\Programfiler\Creative\SB Drive Det\SBDrvDet.exe /r
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [MessengerPlus3] "D:\Alt\MsgPlus.exe"
    O4 - HKLM\..\Run: [DUControl] C:\Programfiler\DirectUpdate\DUControl.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe
    O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\System32\fast.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] C:\Programfiler\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [LVCOMS] C:\Programfiler\Fellesfiler\Logitech\QCDriver3\LVCOMS.EXE
    O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Programfiler\Logitech\ImageStudio\ISStart.exe
    O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Programfiler\Logitech\ImageStudio\LogiTray.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "D:\Alt\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [LDM] C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [Steam] C:\Programfiler\Steam\Steam.exe -silent
    O4 - HKCU\..\Run: [Pulse] C:\Programfiler\Pulse\Pulse.exe -splash
    O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Monitor Apache Servers.lnk = C:\Apache2\bin\ApacheMonitor.exe
    O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\MSMSGS.EXE
    O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://ringblad.kamera.ringnett.no/activex/AxisCamControl.ocx

    This is the result of the new scan! Thanx for letting me now that I needed to "update" my hijakthis =)!
     
  4. LDTate

    LDTate Malware Specialist

    Joined:
    Aug 13, 2004
    Messages:
    789
    I suggest you do this:

    Run Hijack This again and put a check by these. Close ALL windows except HijackThis and click "Fix checked"

    O4 - HKLM\..\Run: [MessengerPlus3] "D:\Alt\MsgPlus.exe"
    O4 - HKCU\..\Run: [MessengerPlus3] "D:\Alt\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [LDM] C:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

    You really need to remove MessengerPlus3. It's loaded with Malware and you'll continue to have issues until you do.

    1. Open My Computer
    2. Right click on your hard drive that you wish to clean (C drive, for example)
    3. In the context menu that opens, select properties
    4. Under the general tab you should select Disk Cleanup
    5. Windows will scan your drive which will take a few seconds/minutes
    6. A box will display the various files you can remove.
    Check all boxes except compress old files

    7. Click OK and windows will comply.

    Reboot and post a new HijackThis log
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/272487

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice