Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

HijackThis log, and Panda scan log...


  • Please log in to reply

#1
oranges

oranges

    New Member

  • Member
  • Pip
  • 1 posts
First, I would like to say thanks to anyone who will be helping me.
Also, the computer automatically restarts when I use Ad-Aware.

-----------

Logfile of HijackThis v1.99.1
Scan saved at 1:04:50 PM, on 12/9/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\drivers\CDAC11BA.EXE
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S4I2D1.EXE
C:\Program Files\Java\j2re1.4.2_11\bin\jusched.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Envara\EnvaraConfig\WindGuiC.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Java\j2re1.4.2_11\bin\jucheck.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: Lexico Toolbar - {11359F4A-B191-42d7-905A-594F8CF0387B} - C:\WINNT\Downloaded Program Files\lexbar.dll
O2 - BHO: WsftpBrowserHelper Class - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Dictionary.com - {11359F4A-B191-42D7-905A-594F8CF0387B} - C:\WINNT\Downloaded Program Files\lexbar.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [EPSON Stylus C84 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S4I2D1.EXE /P23 "EPSON Stylus C84 Series" /O16 "IP_192.168.1.149" /M "Stylus C84"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_11\bin\jusched.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Envara Configuration Utility.lnk = C:\Program Files\Envara\EnvaraConfig\WindGuiC.exe
O4 - Global Startup: Envara Configuration Utility.lnk = C:\Program Files\Envara\EnvaraConfig\WindGuiC.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Search &Dictionary - C:\Program files\Lexico\Toolbar\dictionary.htm
O8 - Extra context menu item: Search &Thesaurus - C:\Program files\Lexico\Toolbar\thesaurus.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ٶ - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - C:\WINNT\System32\shdocvw.dll
O11 - Options group: [!IESearch] !IESearch
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.co...81/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1165619810713
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - http://bar.baidu.com...te/IESearch.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.co...,19/mcgdmgr.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://esilicon.web...bex/ieatgpc.cab
O16 - DPF: {F0E2D69A-DC2F-4E9B-A993-684FB1C21DBC} - http://dictionary.re...lbar/lexico.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9C642FE7-3F40-4D92-95F2-34B559625F01}: NameServer = 192.168.1.1
O18 - Protocol: relatedlinks - {CD8D1CAA-FE4A-45DF-A06C-028AAF1821DE} - (no file)
O20 - AppInit_DLLs: netdde.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

-----------


Incident Status Location

Adware:adware/comet Not disinfected c:\winnt\downloaded program files\dm.inf
Potentially unwanted tool:application/funweb Not disinfected c:\winnt\downloaded program files\f3initialsetup1.0.0.5.inf
Adware:adware/delfinmedia Not disinfected c:\keys.ini
Virus:trj/briz.f Disinfected Operating system
Adware:adware/sidesearch Not disinfected c:\winnt\sepsd.bin
Adware:adware/wintools Not disinfected c:\program files\common files\BTLINK
Potentially unwanted tool:application/mywebsearch Not disinfected hkey_current_user\software\ToolBar
Adware:adware/bdsearch Not disinfected Windows Registry
Adware:adware/savenow Not disinfected Windows Registry
Adware:adware/statblaster Not disinfected Windows Registry
Adware:adware/keenvalue Not disinfected Windows Registry
Adware:adware/exact.bargainbuddy Not disinfected Windows Registry
Adware:adware/exact.searchbar Not disinfected Windows Registry
Adware:adware/memorywatcher Not disinfected Windows Registry
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Mozilla\Firefox\Profiles\mzhltnyn.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Mozilla\Firefox\Profiles\mzhltnyn.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Mozilla\Firefox\Profiles\mzhltnyn.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Mozilla\Firefox\Profiles\mzhltnyn.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Mozilla\Firefox\Profiles\mzhltnyn.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Mozilla\Firefox\Profiles\mzhltnyn.default\cookies.txt[.overture.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Mozilla\Firefox\Profiles\mzhltnyn.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Mozilla\Firefox\Profiles\mzhltnyn.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Mozilla\Firefox\Profiles\mzhltnyn.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Phoenix\Profiles\default\nb7qisyx.slt\cookies.txt[.ads.addynamix.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Phoenix\Profiles\default\nb7qisyx.slt\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/CentrPort Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Phoenix\Profiles\default\nb7qisyx.slt\cookies.txt[.centrport.net/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Phoenix\Profiles\default\nb7qisyx.slt\cookies.txt[.fortunecity.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Phoenix\Profiles\default\nb7qisyx.slt\cookies.txt[.realmedia.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Phoenix\Profiles\default\nb7qisyx.slt\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Phoenix\Profiles\default\nb7qisyx.slt\cookies.txt[rightmedia.net/]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Benjamin Nham\Application Data\Phoenix\Profiles\default\nb7qisyx.slt\cookies.txt[stat.onestat.com/]
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\Benjamin Nham\Local Settings\Temp\!update.exe
Possible Virus. Not disinfected C:\Documents and Settings\Benjamin Nham\Local Settings\Temp\ctxad.exe[NDrv.dll]
Possible Virus. Not disinfected C:\Documents and Settings\Benjamin Nham\Local Settings\Temp\ctxad.exe[NDrv.exe]
Potentially unwanted tool:Application/DriveCleaner Not disinfected C:\Program Files\Common Files\DriveCleaner 2006\DCPChk.dll
Spyware:Cookie/2o7 Not disinfected C:\Program Files\K-Meleon\Profiles\default\1yf3caa7.slt\cookies.txt[.2o7.net/]
Spyware:Cookie/Atwola Not disinfected C:\Program Files\K-Meleon\Profiles\default\1yf3caa7.slt\cookies.txt[.atwola.com/]
Spyware:Cookie/Go Not disinfected C:\Program Files\K-Meleon\Profiles\default\1yf3caa7.slt\cookies.txt[.go.com/]
Adware:Adware/BDSToolbar Not disinfected C:\WINNT\Downloaded Program Files\BDSearch.inf
Virus:Trj/Qhost.EV Disinfected C:\WINNT\hosts.sam


Thanks...
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP