Start a Conversation

Unsolved

This post is more than 5 years old

K

269

August 25th, 2006 00:00

Help! Safetyhomepage!

​ Hijack this log ​
​ ​
​ Logfile of HijackThis v1.99.1 ​
​Scan saved at 9:16:10 PM, on 8/24/2006 ​
​Platform: Windows XP SP2 (WinNT 5.01.2600) ​
​MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) ​
​ Running processes: ​
​C:\WINDOWS\System32\smss.exe ​
​C:\WINDOWS\system32\winlogon.exe ​
​C:\WINDOWS\system32\services.exe ​
​C:\WINDOWS\system32\lsass.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\Program Files\Windows Defender\MsMpEng.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\WINDOWS\system32\spoolsv.exe ​
​C:\WINDOWS\system32\cisvc.exe ​
​c:\program files\mcafee.com\agent\mcdetect.exe ​
​c:\PROGRA~1\mcafee.com\vso\mcshield.exe ​
​c:\PROGRA~1\mcafee.com\agent\mctskshd.exe ​
​C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe ​
​C:\Program Files\Softex\OmniPass\Omniserv.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\Program Files\Softex\OmniPass\OPXPApp.exe ​
​C:\WINDOWS\Explorer.EXE ​
​C:\windows\system\hpsysdrv.exe ​
​C:\WINDOWS\system32\hkcmd.exe ​
​C:\HP\KBD\KBD.EXE ​
​C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe ​
​C:\WINDOWS\system32\igfxtray.exe ​
​C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe ​
​C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe ​
​C:\Program Files\QuickTime\qttask.exe ​
​C:\Program Files\Common Files\Real\Update_OB\realsched.exe ​
​C:\Program Files\McAfee.com\VSO\mcvsshld.exe ​
​C:\Program Files\McAfee.com\VSO\oasclnt.exe ​
​c:\program files\mcafee.com\agent\mcagent.exe ​
​c:\progra~1\mcafee.com\vso\mcvsescn.exe ​
​C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe ​
​C:\PROGRA~1\mcafee.com\mps\mscifapp.exe ​
​C:\Program Files\Windows Defender\MSASCui.exe ​
​C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe ​
​C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe ​
​C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe ​
​C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ​
​C:\WINDOWS\system32\cidaemon.exe ​
​C:\Program Files\ewido anti-spyware 4.0\ewido.exe ​
​C:\Program Files\Internet Explorer\iexplore.exe ​
​C:\PROGRA~1\WINZIP\winzip32.exe ​
​C:\Documents and Settings\Owner\My Documents\Unzipped\hijackthis[1]\HijackThis.exe ​
​ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = ​
​R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=:0 ​
​R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost ​
​O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll ​
​O2 - BHO: (no name) - {202a961f-23ae-42b1-9505-ffe3c818d717} - C:\Program Files\IntCodec\isaddon.dll ​
​O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll ​
​O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll ​
​O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll ​
​O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\googletoolbar1.dll ​
​O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar1.dll ​
​O3 - Toolbar: Protection Bar - {a2595f37-48d0-46a1-9b51-478591a97764} - C:\Program Files\IntCodec\iesplugin.dll ​
​O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe ​
​O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe ​
​O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE ​
​O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE ​
​O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe ​
​O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe ​
​O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" ​
​O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe ​
​O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE ​
​O4 - HKLM\..\Run: [hplampc] C:\WINDOWS\System32\hplampc.exe ​
​O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime ​
​O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot ​
​O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe ​
​O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask ​
​O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe ​
​O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe ​
​O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe ​
​O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe ​
​O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding ​
​O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide ​
​O4 - HKCU\..\Run: [StartersOrdersSetup.exe] E:\games\START~15.EXE /r ​
​O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe ​
​O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe ​
​O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe ​
​O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ​
​O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML ​
​O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar1.dll/cmsearch.html ​
​O8 - Extra context menu item: &Search - ​​http://ka.bar.need2find.com/KA/menusearch.html?p=KA​ ​
​O8 - Extra context menu item: &Translate English Word - res://c:\windows\GoogleToolbar1.dll/cmwordtrans.html ​
​O8 - Extra context menu item: Backward Links - res://c:\windows\GoogleToolbar1.dll/cmbacklinks.html ​
​O8 - Extra context menu item: Cached Snapshot of Page - res://c:\windows\GoogleToolbar1.dll/cmcache.html ​
​O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000 ​
​O8 - Extra context menu item: Similar Pages - res://c:\windows\GoogleToolbar1.dll/cmsimilar.html ​
​O8 - Extra context menu item: Translate Page into English - res://c:\windows\GoogleToolbar1.dll/cmtrans.html ​
​O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll ​
​O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll ​
​O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll ​
​O15 - Trusted Zone: ​​www.bravenet.com​​ ​
​O15 - Trusted Zone: ​​http://www.hotmail.com​​ ​
​O15 - Trusted Zone: g.msn.com ​
​O15 - Trusted Zone: ​​http://www.msn.com​​ ​
​O15 - Trusted Zone: ​​http://zone.msn.com​​ ​
​O15 - Trusted Zone: ​​www.mypoints.com​​ ​
​O15 - Trusted Zone: ​​http://login.passport.net​​ ​
​O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - ​​http://go.microsoft.com/fwlink/?linkid=39204​​ ​
​O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - ​​http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll​​ ​
​O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - ​​http://aolcc.aol.com/computercheckup/qdiagcc.cab​​ ​
​O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - ​​http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab​​ ​
​O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} - ​​http://www.imagestation.com/common/classes/batchdwnl.cab?version=4,3,2,20802​​ ​
​O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - ​​http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1127953986000​​ ​
​O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - ​​http://zone.msn.com/bingame/luxr/default/mjolauncher.cab​​ ​
​O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - ​​http://toolbar.google.com/data/GoogleActivate.cab​​ ​
​O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - ​​http://www.snapfish.com/SnapfishUpload.cab​​ ​
​O16 - DPF: {96D338F5-8757-4A1C-AFEA-770A4036752F} - ​​https://setup.bellsouth.net/wizlet/BellSouthDial/static/controls/WebflowActiveXCab.CAB​​ ​
​O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - ​​http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab​​ ​
​O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - ​​http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab​​ ​
​O16 - DPF: {BE964208-66F0-48FB-8F53-0C2BC35A610A} (UMediaPlayer Class) - ​​http://www.umediaserver.net/bin/UMediaControl3.cab​​ ​
​O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - ​​http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab​​ ​
​O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll ​
​O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll ​
​O20 - Winlogon Notify: srvbak - C:\WINDOWS\java\classes\srvbak.dll (file missing) ​
​O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll ​
​O21 - SSODL: bestreak - {874443fe-aa33-4ebf-a6ac-73208787e62d} - (no file) ​
​O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll ​
​O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe ​
​O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe ​
​O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe ​
​O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe ​
​O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe ​
​O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe ​
​O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe ​
​O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe ​
​O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe ​
​ ​
​ rapport.txt ​
​ ​
​ SmitFraudFix v2.81 ​
​ Scan done at 21:12:32.75, Thu 08/24/2006 ​
​Run from C:\Documents and Settings\Owner\My Documents\Unzipped\SmitfraudFix[1]\SmitfraudFix ​
​OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT ​
​Fix ran in normal mode ​
​ »»»»»»»»»»»»»»»»»»»»»»»» C:\ ​
​ ​
​»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS ​
​ C:\WINDOWS\desktop.html FOUND ! ​
​ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system ​
​ ​
​»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web ​
​ ​
​»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 ​
​ ​
​»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles ​
​ ​
​»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner\Application Data ​
​ ​
​»»»»»»»»»»»»»»»»»»»»»»»» Start Menu ​
​ C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND ! ​
​C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND ! ​
​ »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\owner\FAVORI~1 ​
​ ​
​»»»»»»»»»»»»»»»»»»»»»»»» Desktop ​
​ C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url FOUND ! ​
​ »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files ​
​ C:\Program Files\IntCodec\ FOUND ! ​
​C:\Program Files\SpyQuake2.com\ FOUND ! ​
​ »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys ​
​ ​
​»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components ​
​ ​
​ ​
​ »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler ​
​!!!Attention, following keys are not inevitably infected!!! ​
​ SrchSTS.exe by S!Ri ​
​Search SharedTaskScheduler's .dll ​
​ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] ​
​"bestreak"="{874443fe-aa33-4ebf-a6ac-73208787e62d}" ​
​ ​
​»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection ​
​ ​
​»»»»»»»»»»»»»»»»»»»»»»»» End ​
​ ​
​ ​
​ I have already installed the ediwo thing. PLEASE HELP!!! ​

3.3K Posts

August 25th, 2006 21:00

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Just to make sure you still have the executable, please download:
SmitfraudFix (by S!Ri)
Extract the contents (a folder named SmitfraudFix) to your Desktop.

Next, reboot the computer into Safemode.

Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press" Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into your Normal Windows user mode.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.

Also post a fresh hijackthis log
No Events found!

Top