1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

http://213.159.117.134/index.php

Discussion in 'Windows XP' started by fhaslangka, Sep 21, 2004.

Thread Status:
Not open for further replies.
Advertisement
  1. fhaslangka

    fhaslangka Thread Starter

    Joined:
    Aug 2, 2004
    Messages:
    461
    Pls. check this log!

    Logfile of HijackThis v1.98.2
    Scan saved at 3:43:55 PM, on 9/21/2004
    Platform: Windows 2000 SP2 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\OfficeScan NT\ntrtscan.exe
    C:\WINNT\System32\nvsvc32.exe
    C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\OfficeScan NT\tmlisten.exe
    D:\Program Files\VMware\VMware Workstation\vmware-authd.exe
    C:\WINNT\System32\vmnat.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\System32\vmnetdhcp.exe
    C:\OfficeScan NT\ofcdog.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\System32\RUNDLL32.EXE
    C:\WINNT\System32\dktime.exe
    C:\OfficeScan NT\pccntmon.exe
    C:\WINNT\System32\ctfmon.exe
    C:\WINNT\System32\dktime.exe
    C:\Program Files\ipmsgr\IPMSG.exe
    C:\WINNT\System32\rundll32.exe
    C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://213.159.117.134/index.php
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://213.159.117.134/index.php
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=10.11.1.11:88;gopher=10.11.1.11:88;http=10.11.1.10:88;https=10.11.1.10:88
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.*;<local>
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [ImmediateSetting] regedit.exe /s C:\immediate.reg
    O4 - HKLM\..\Run: [DKTime] C:\WINNT\System32\dktime.exe
    O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
    O4 - HKCU\..\Run: [DKTime] C:\WINNT\System32\dktime.exe
    O4 - Startup: Shortcut to IPMSG.lnk = C:\Program Files\ipmsgr\IPMSG.exe
    O4 - Startup: SpywareBlaster.lnk = C:\Program Files\SpywareBlaster\spywareblaster.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office XP\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} (ObjWinNTCheck Class) - http://10.11.1.4/officescan/ClientInstall/WinNTChk.cab
    O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupIniCtrl Class) - http://10.11.1.4/officescan/clientinstall/setupini.cab
    O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) - http://10.11.1.4/officescan/clientinstall/setup.cab
    O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class) - http://10.11.1.4/officescan/clientinstall/RemoveCtrl.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = its.com
    O17 - HKLM\System\CCS\Services\Tcpip\..\{7F7CD981-30C9-4D33-850B-D25ED118B9EF}: NameServer = 10.11.1.110
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = its.com
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = its.com
     
  2. fhaslangka

    fhaslangka Thread Starter

    Joined:
    Aug 2, 2004
    Messages:
    461
    Thanks to all of you but i think i found the cause of this why it always change my default homepage entry. I checked the running programs at task manager and i notice the file dktime.exe running so to double check run registry editor and go to HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run then found the entry dktime.exe and its path c:\winnt\system32\dktime.exe and also in HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run so i delete those entry and i also dktime.exe delete the file in the C:\winnt\system32.

    Now my system is properly working now! I hope this could also help others.
     
  3. Chicon

    Chicon

    Joined:
    Jul 29, 2004
    Messages:
    6,650
    Hi fhaslangka,

    What do you think about this entry :
    O4 - HKLM\..\Run: [ImmediateSetting] regedit.exe /s C:\immediate.reg ?

    Do you know what it does ?
     
  4. fhaslangka

    fhaslangka Thread Starter

    Joined:
    Aug 2, 2004
    Messages:
    461
    yup! it comes with my sophos antivirus software.
     
  5. $teve

    $teve

    Joined:
    Oct 9, 2001
    Messages:
    9,396
    You should also run CWShredder.

    Go to http://computercops.biz/downloads-cat-14.html , and download the latest version of CWShredder by Merijn Bellekom, the creator of HijackThis.
    Before you run it.....check for and download any updates.Press 'Fix', and allow it to fix all it finds.
    And remember to click "Fix" (Not "Scan only")
    After its done its thing hit the"How do i prevent reinfection" tab....
    In particular pay attention to the patches for the operating system regarding the ByteVerify vulnerability.

    When it is finished restart your computer and post an updated log please.

    ;)
    ;)
     
  6. fhaslangka

    fhaslangka Thread Starter

    Joined:
    Aug 2, 2004
    Messages:
    461
    thanks steve but already done that and it doesn't detect a thing.
     
  7. Flrman1

    Flrman1

    Joined:
    Jul 26, 2002
    Messages:
    46,329
    You reported this solved, but you have not explained what you did to solve it.
     
  8. fhaslangka

    fhaslangka Thread Starter

    Joined:
    Aug 2, 2004
    Messages:
    461

    i think i said it here.... sorry if it wasn't clear.
     
  9. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/276379

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice