Start a Conversation

Unsolved

This post is more than 5 years old

D

214

February 11th, 2008 22:00

HiJackThis2

​Well alright it looks a lot better already but heres the HijackThis thank you so much for all the help your giving ill put the combofix on my next post.​

​Don​

​ ​

​Logfile of Trend Micro HijackThis v2.0.2​
​Scan saved at 7:50:44 PM, on 2/11/2008​
​Platform: Windows XP SP2 (WinNT 5.01.2600)​
​MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)​
​Boot mode: Normal​

​Running processes:​
​C:\WINDOWS\System32\smss.exe​
​C:\WINDOWS\system32\winlogon.exe​
​C:\WINDOWS\system32\services.exe​
​C:\WINDOWS\system32\lsass.exe​
​C:\WINDOWS\system32\svchost.exe​
​C:\WINDOWS\System32\svchost.exe​
​C:\WINDOWS\system32\spoolsv.exe​
​c:\program files\mcafee.com\agent\mcdetect.exe​
​c:\PROGRA~1\mcafee.com\agent\mctskshd.exe​
​C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe​
​C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe​
​C:\WINDOWS\System32\svchost.exe​
​C:\WINDOWS\system32\hkcmd.exe​
​C:\WINDOWS\system32\dla\tfswctrl.exe​
​C:\PROGRA~1\mcafee.com\agent\mcagent.exe​
​C:\WINDOWS\BCMSMMSG.exe​
​C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe​
​C:\Program Files\iTunes\iTunesHelper.exe​
​C:\Program Files\QuickTime\qttask.exe​
​C:\Program Files\Mzcqq\Seel.exe​
​C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe​
​C:\Program Files\MSN Messenger\MsnMsgr.Exe​
​C:\Program Files\Messenger\msmsgs.exe​
​C:\Program Files\AIM6\aim6.exe​
​C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe​
​C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe​
​C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe​
​C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe​
​C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe​
​c:\windows\system32\dwdsregt.exe​
​C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe​
​C:\Program Files\iPod\bin\iPodService.exe​
​C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe​
​C:\Program Files\AIM6\aolsoftware.exe​
​C:\WINDOWS\System32\svchost.exe​
​C:\WINDOWS\explorer.exe​
​C:\WINDOWS\system32\PdeSrv2.exe​
​C:\WINDOWS\system32\notepad.exe​
​C:\Program Files\Internet Explorer\IEXPLORE.EXE​
​c:\program files\aol\aim toolbar 5.0\AolTbServer.exe​
​C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe​
​C:\Documents and Settings\Owner\My Documents\hijackthis.exe​

​R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = ​​http://searchbar.findthewebsiteyouneed.com​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = ​​http://searchbar.findthewebsiteyouneed.com​
​R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank​
​R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1​
​R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL Search\AOLSearch.dll​
​R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)​
​O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\bxxs5.dll​
​O2 - BHO: AOL Search Enhancement - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL Search\AOLSearch.dll​
​O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll​
​O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll​
​O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem303.dll​
​O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll​
​O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll​
​O3 - Toolbar: NavExcel Toolbar - {5AA06644-BC46-4220-A460-47A6EB47C96D} - C:\Program Files\NavExcel Search Toolbar\NavExcelBar.dll​
​O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB57.dll​
​O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll​
​O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll​
​O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe​
​O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe​
​O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe​
​O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r​
​O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask​
​O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"​
​O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe​
​O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe​
​O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe​
​O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe​
​O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe​
​O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"​
​O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime​
​O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"​
​O4 - HKLM\..\Run: [{5C-C2-21-12-ZN}] c:\windows\system32\dwdsregt.exe CORN001​
​O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\bxxs5.dll,DllRun​
​O4 - HKLM\..\Run: [Fifgnzt] C:\Program Files\Mzcqq\Seel.exe​
​O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe​
​O4 - HKCU\..\Run: [SFP] C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.EXE /s​
​O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background​
​O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h​
​O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background​
​O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp​
​O4 - HKCU\..\Run: [qwmm] C:\Program Files\InetGet2\stub_109_4_0_4_0.exe​
​O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe​
​O4 - Global Startup: hp psc 1000 series.lnk = ?​
​O4 - Global Startup: hpoddt01.exe.lnk = ?​
​O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm​
​O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html​
​O8 - Extra context menu item: &Search - ​​http://ka.bar.need2find.com/KA/menusearch.html?p=KA
​O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll​
​O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll​
​O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll​
​O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe​
​O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe​
​O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll​
​O15 - Trusted Zone: *.05p.com​
​O15 - Trusted Zone: *.scoobidoo.com​
​O15 - Trusted Zone: *.05p.com (HKLM)​
​O15 - Trusted Zone: ​​http://click.getmirar.com​​ (HKLM)​
​O15 - Trusted Zone: ​​http://click.mirarsearch.com​​ (HKLM)​
​O15 - Trusted Zone: ​​http://redirect.mirarsearch.com​​ (HKLM)​
​O15 - Trusted Zone: ​​http://awbeta.net-nucleus.com​​ (HKLM)​
​O15 - Trusted Zone: *.scoobidoo.com (HKLM)​
​O15 - Trusted IP range: 206.161.125.149​
​O15 - Trusted IP range: 206.161.125.149 (HKLM)​
​O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)​
​O16 - DPF: {10000000-1000-0000-1000-000000000000} - ​​file://C:\Program​​ Files\Internet Explorer\ckyqbgbc.exe​
​O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - ​​http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab​
​O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} - ​​http://cabs.elitemediagroup.net/cabs/mediaview.cab​
​O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - ​​http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab​
​O16 - DPF: {E4C29FDC-F547-4219-ACFD-571F2A7A564A} (WebCamTest Class) - ​​http://click.mirarsearch.com/CABUPDATES/winwcd.cab​
​O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe​
​O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe​
​O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe​
​O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe​
​O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe​
​O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe​
​O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe​
​O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe​
​O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe​
​O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe​

​--​
​End of file - 9498 bytes​

​ ​

​ ​

20.5K Posts

February 11th, 2008 23:00

Your log is being handled here:
http://forums.us.dell.com/supportforums/board/message?board.id=si_hijack&message.id=79180#M79180

Please keep your replies in that thread. Thank you. :)
No Events found!

Top