my hijackthis log in increments

Reply

Join Date: Apr 2004
Posts: 104
Reputation: robinrofkar is an unknown quantity at this point 
Solved Threads: 1
robinrofkar's Avatar
robinrofkar robinrofkar is offline Offline
Junior Poster

my hijackthis log in increments

 
0
  #1
Apr 23rd, 2004
I am trying to find out which part of my log is infected, so i am posting my log in increments

Logfile of HijackThis v1.97.7
Scan saved at 1:34:32 PM, on 4/22/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\WINDOWS\wt\updater\wcmdmgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner.BOLIVER\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
C:\Program Files\WindowsUpdate\wuaudnld.tmp\cabs\com_microsoft.811630_XP_SP1_5915\Q811630_WXP_SP2_EN.exe
c:\c868ac0b70f3f4b8b0\xpsp1hfm.exe
c:\c868ac0b70f3f4b8b0\sp2\update\update.exe
Reply With Quote Quick reply to this message  
Join Date: Apr 2004
Posts: 104
Reputation: robinrofkar is an unknown quantity at this point 
Solved Threads: 1
robinrofkar's Avatar
robinrofkar robinrofkar is offline Offline
Junior Poster

Re: my hijackthis log in increments

 
0
  #2
Apr 23rd, 2004
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus9.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.emusic.com/promo/presario...ml?fref=148615
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_11_0.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
Reply With Quote Quick reply to this message  
Join Date: Apr 2004
Posts: 104
Reputation: robinrofkar is an unknown quantity at this point 
Solved Threads: 1
robinrofkar's Avatar
robinrofkar robinrofkar is offline Offline
Junior Poster

Re: my hijackthis log in increments

 
0
  #3
Apr 23rd, 2004
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O10 - Broken Internet access because of LSP provider 'spsublsp.dll' missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {1C955F3B-5B32-4393-A05D-24B4970CD2A1} - http://streamhc.redhotnetworks.com/cabs/videox.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinstc.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemp...veSecurity.cab
O16 - DPF: {A1A961DA-2BA6-4032-859E-01AC35357163} (One2One Viewer) - http://www.one2one.com/static/class/one2one.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/def...ploader_v5.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{BA0B9895-0E90-44DF-953E-0DC5D45B94DD}: NameServer = 151.164.14.201 151.164.1.8
Reply With Quote Quick reply to this message  
Join Date: Apr 2004
Posts: 104
Reputation: robinrofkar is an unknown quantity at this point 
Solved Threads: 1
robinrofkar's Avatar
robinrofkar robinrofkar is offline Offline
Junior Poster

Re: my hijackthis log in increments

 
0
  #4
Apr 23rd, 2004
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "c:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKLM\..\RunOnce: [Q828026] "C:\WINDOWS\INF\unregmp2.exe" /UpdateWMP
O4 - HKLM\..\RunOnce: [GrpConv] grpconv.exe -o
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: Digimax Viewer 2.0.lnk = ?
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
Reply With Quote Quick reply to this message  
Join Date: Apr 2004
Posts: 104
Reputation: robinrofkar is an unknown quantity at this point 
Solved Threads: 1
robinrofkar's Avatar
robinrofkar robinrofkar is offline Offline
Junior Poster

Re: my hijackthis log in increments

 
0
  #5
Apr 23rd, 2004
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_11_0.dll
Reply With Quote Quick reply to this message  
Join Date: Apr 2004
Posts: 104
Reputation: robinrofkar is an unknown quantity at this point 
Solved Threads: 1
robinrofkar's Avatar
robinrofkar robinrofkar is offline Offline
Junior Poster

Re: my hijackthis log in increments

 
0
  #6
Apr 23rd, 2004
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
Reply With Quote Quick reply to this message  
Join Date: Apr 2004
Posts: 104
Reputation: robinrofkar is an unknown quantity at this point 
Solved Threads: 1
robinrofkar's Avatar
robinrofkar robinrofkar is offline Offline
Junior Poster

Re: my hijackthis log in increments

 
0
  #7
Apr 23rd, 2004
O4 - HKLM\..\Run: [Hot Keys Cmds] C:\ WINDOWS\ System32\ hkcmd. exe
Reply With Quote Quick reply to this message  
Join Date: Apr 2004
Posts: 104
Reputation: robinrofkar is an unknown quantity at this point 
Solved Threads: 1
robinrofkar's Avatar
robinrofkar robinrofkar is offline Offline
Junior Poster

Re: my hijackthis log in increments

 
0
  #8
Apr 23rd, 2004
the last two were the ones that would not post.the one before this message and the one after this message, so i inserted some spaces to get it to post.
Reply With Quote Quick reply to this message  
Join Date: Apr 2004
Posts: 104
Reputation: robinrofkar is an unknown quantity at this point 
Solved Threads: 1
robinrofkar's Avatar
robinrofkar robinrofkar is offline Offline
Junior Poster

Re: my hijackthis log in increments

 
0
  #9
Apr 23rd, 2004
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
Reply With Quote Quick reply to this message  
Join Date: Apr 2004
Posts: 104
Reputation: robinrofkar is an unknown quantity at this point 
Solved Threads: 1
robinrofkar's Avatar
robinrofkar robinrofkar is offline Offline
Junior Poster

Re: my hijackthis log in increments

 
0
  #10
Apr 23rd, 2004
ok guys i really really apologize for all the posts lately, i found your website by chance and i think it is really awesome, so the last part of my log file(right above this) did not need spaces so i am not sure what is going on i guess it was just that one. but i have never had any problems(this is my first computer at home most i used at school and work.
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC