Windows 7 Support
Become a Fan of PCHF on Facebook!
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs
Register for a Free Account

[Fixed] Hijackthis! Logs - Virus posted in the Security & Safety forums; I have ran a HTJ log and this is a copy. Please take a look and let me know what you thnk. Logfile of Trend Micro HijackThis v2.0.2 Scan saved ...

Advertisement
Advertisement

Reply
Recommended Driver Scanner
Old 01-01-2008   #1
New Poster
 
Join Date: Jan 2008
Posts: 1
PC Experience: PC Illiterate
Default Virus

I have ran a HTJ log and this is a copy. Please take a look and let me know what you thnk.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:45:07 AM, on 1/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\system32\svchost.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\NavNT\vptray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Adelphia.net - Home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0d10c15f-a1d3-43c0-a779-3ceb66c798ac} - C:\WINDOWS\system32\magpcn.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: {498D520C-88E1-4F11-861D-B70A69F53691} - {8369F655-E0A5-4512-85DF-3B5DEBA80FE6} - C:\WINDOWS\system32\awvvtts.dll
O2 - BHO: {1f46950f-6fea-d899-d6b4-fed9dfc70b9c} - {c9b07cfd-9def-4b6d-998d-aef6f05964f1} - C:\WINDOWS\system32\tmp242.tmp.dll
O2 - BHO: {486058d3-a53d-556a-1ff4-1708ee965fcc} - {ccf569ee-8071-4ff1-a655-d35a3d850684} - C:\WINDOWS\system32\tmp243.tmp.dll
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [84e5e4b7] rundll32.exe "C:\WINDOWS\khebax.dll",b
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: officejet 6100.lnk = ?
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O20 - AppInit_DLLs: c:\windows\system32\ddabcby.dll
O20 - Winlogon Notify: ds1onv - ds1onv.dll (file missing)
O20 - Winlogon Notify: forfat - forfat.dll (file missing)
O20 - Winlogon Notify: imaplui - imaplui.dll (file missing)
O20 - Winlogon Notify: lmhnsi - lmhnsi.dll (file missing)
O20 - Winlogon Notify: magpcn - C:\WINDOWS\SYSTEM32\magpcn.dll
O21 - SSODL: mssms - {83353FCE-25CB-45B2-B235-59F6D34C9669} - C:\WINDOWS\mssms.dll (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 6551 bytes
gregp310 is offline   Reply With Quote
Old 01-01-2008   #2
Senior Security Analyst
 
Pancake's Avatar
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 8,297
PC Experience: Elite PC Guru
Default Re: Virus

Have "Hijack This" fix all the following items in the list below by placing a check in the appropriate boxes.Confirm that you have only the listed ones checked, then press <Fix checked> and Close HJT.

O2 - BHO: {498D520C-88E1-4F11-861D-B70A69F53691} - {8369F655-E0A5-4512-85DF-3B5DEBA80FE6} - C:\WINDOWS\system32\awvvtts.dll
O2 - BHO: {1f46950f-6fea-d899-d6b4-fed9dfc70b9c} - {c9b07cfd-9def-4b6d-998d-aef6f05964f1} - C:\WINDOWS\system32\tmp242.tmp.dll
O2 - BHO: {486058d3-a53d-556a-1ff4-1708ee965fcc} - {ccf569ee-8071-4ff1-a655-d35a3d850684} - C:\WINDOWS\system32\tmp243.tmp.dll
O4 - HKLM\..\Run: [84e5e4b7] rundll32.exe "C:\WINDOWS\khebax.dll",b
O20 - AppInit_DLLs: c:\windows\system32\ddabcby.dll
O20 - Winlogon Notify: ds1onv - ds1onv.dll (file missing)
O20 - Winlogon Notify: forfat - forfat.dll (file missing)
O20 - Winlogon Notify: imaplui - imaplui.dll (file missing)
O20 - Winlogon Notify: lmhnsi - lmhnsi.dll (file missing)
O20 - Winlogon Notify: magpcn - C:\WINDOWS\SYSTEM32\magpcn.dll
O21 - SSODL: mssms - {83353FCE-25CB-45B2-B235-59F6D34C9669} - C:\WINDOWS\mssms.dll (file missing)

Reboot...
========================
This will help to identify malware on your system.
Please download Combofix from any of these locations:
Here
or
Here
Save ComboFix to the desktop and please ensure that you disable realtime security/virus programs that monitors your PC while CF is running.
1. Double click on combo.exe & follow the prompts.
2. When finished, it will produce a logfile located at C:\ComboFix.txt.
3. Copy and Paste the contents of that log in your next reply with a new hijackthis log. Do not use Code or html unless asked for.
Note: Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang.
Caution...Never run and remove files using ComboFix without being supervised by a security analyst.
__________________
  • An Australian Member of
My real name is Eddy
Pancake is offline   Reply With Quote

Reply

Bookmarks

Tags
virus
Similar discussions...
Thread Thread Starter Forum Replies Last Post
[Fixed] services.exe error, comp keeps restarting Frish [Fixed] Hijackthis! Logs 13 01-25-2007 10:33 AM
[Resolved] Computer Slow upgrader [Fixed] Hijackthis! Logs 20 09-21-2006 06:54 AM
[Fixed] winlogon hook ; ; syztem [Fixed] Hijackthis! Logs 14 09-06-2006 11:42 PM
[Fixed] Major Problem, Need Help!!! naqeeb23 [Fixed] Hijackthis! Logs 16 08-12-2006 01:30 PM
Information: Active Virus Shield (Free AV based on Kaspersky) joe5 Anti-Virus (AV) 0 08-09-2006 09:50 PM

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 07:39 PM.
Powered by vBulletin
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2