Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Braviax.exe


  • Please log in to reply

#1
Lapino

Lapino

    New Member

  • Member
  • Pip
  • 1 posts
Thanx in advance for the help! :)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:33:53 PM, on 8/26/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\DSentry.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Documents and Settings\Lloyd Lopez\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://live.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [USRobotics Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\system32\DSentry.exe
O4 - HKCU\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\VI3W8Z5W\AXBOX_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\AXSKY_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\FOSQVT6W\AXBANN~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\FOSQVT6W\ADS_1_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\CLICK_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\FASTLE~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\BUDSBO~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\VI3W8Z5W\CLICK_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\TCYH4ECN\BUDSLE~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\FOSQVT6W\FASTSK~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\VI3W8Z5W\AXLEAD~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\TCYH4ECN\STATS_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\INDEX
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://utilities.pcp...a/PCPitStop.CAB
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onec...lscbase5036.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1219737890859
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: AplDsc - {26299438-EA22-2AA5-8B34-0923437708C1} - C:\Program Files\zipnrrd\AplDsc.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 6113 bytes



StartupList report, 8/26/2008, 12:35:42 PM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\Lloyd Lopez\Desktop\HiJackThis.EXE
Detected: Windows XP SP3 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16705)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\DSentry.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Documents and Settings\Lloyd Lopez\Desktop\HiJackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

mcagent_exe = C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
USRobotics Wireless Manager UI = C:\WINDOWS\system32\WLTRAY.exe
DVDSentry = C:\WINDOWS\system32\DSentry.exe

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

DelayShred = "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\VI3W8Z5W\AXBOX_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\AXSKY_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\FOSQVT6W\AXBANN~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\FOSQVT6W\ADS_1_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\CLICK_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\FASTLE~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\BUDSBO~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\VI3W8Z5W\CLICK_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\TCYH4ECN\BUDSLE~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\FOSQVT6W\FASTSK~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\VI3W8Z5W\AXLEAD~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\TCYH4ECN\STATS_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\INDEX_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\TCYH4ECN\FASTBO~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\160X60~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\VI3W8Z5W\BUDSSK~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\Temp\CABGEN~1\DirOne\default.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\Temp\CABGEN~1\DirOne.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\Temp\CABGEN~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\Temp\HSPERF~1.SH!

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
=

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Task Scheduler jobs:

AppleSoftwareUpdate.job
McDefragTask.job
McQcTask.job

--------------------------------------------------

Enumerating Download Program Files:

[PCPitstop Utility]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\PCPitstop.dll
CODEBASE = http://utilities.pcp...a/PCPitStop.CAB

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\Adobe\Director\swdir.dll
CODEBASE = http://download.macr...director/sw.cab

[Windows Live Safety Center Base Module]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\wlscBase.dll
CODEBASE = http://cdn.scan.onec...lscbase5036.cab

[MUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\muweb.dll
CODEBASE = http://update.micros...b?1219737890859

[{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
CODEBASE = http://fpdownload.ma...t/ultrashim.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #4: C:\Program Files\Bonjour\mdnsNSP.dll

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
UPnPMonitor: C:\WINDOWS\system32\upnpui.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll
AplDsc: C:\Program Files\zipnrrd\AplDsc.dll

--------------------------------------------------
End of report, 6,583 bytes
Report generated in 0.370 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only




  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP