Answers to your tech questions
Computer forums for help with removing malicious software (malware) and improving computer security

Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)

 
Reply to this topicStart new topic
> Win2k Hijack Log
dougeast
post Apr 9 2007, 01:14 AM
Post #1


New Member
*

Group: New Member
Posts: 1
Joined: 9-April 07
Member No.: 69,363
Operating System: Win2k



Been trying to figure out this problem for a week. Hope you can offer me some help!

Thanks


Logfile of HijackThis v1.99.1
Scan saved at 3:06:21 AM, on 4/9/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\cisvc.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
z:\IMail\IMonitor.exe
z:\IMail\IWebCal.exe
z:\IMail\iwebmsg.exe
C:\Program Files\LogMeIn\RaMaint.exe
C:\Program Files\LogMeIn\LogMeIn.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\PROGRA~1\MICROS~3\MSSQL\binn\sqlservr.exe
C:\Program Files\NavNT\rtvscan.exe
z:\IMail\POP3D32.exe
z:\IMail\queuemgr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
z:\IMail\smtpd32.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\TEXASI~1\WFTPDP~1\WFTPD.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\PROGRA~1\WEBTRE~1\wtrs_ui.exe
C:\PROGRA~1\WEBTRE~1\wtrs.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\dns.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\system32\MsgSys.EXE
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINNT\System32\cidaemon.exe
C:\WINNT\system32\logon.scr
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\rdpclip.exe
C:\WINNT\explorer.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Documents and Settings\Administrator\Desktop\ProcessExplorer\procexp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\HijackThis.exe

O1 - Hosts: 65.16.121.85 glider.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1104723632281
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1125237569640
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} (InstallShield Setup Player 2K2) - http://ipswitch.com/Support/IMail/IMWMML/L...ackV1/setup.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = glider.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{468DB75C-9183-4236-9058-B7A1D515793E}: NameServer = 4.2.2.1,65.16.121.83,65.16.121.85
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = glider.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{468DB75C-9183-4236-9058-B7A1D515793E}: NameServer = 65.16.121.85
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = glider.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{468DB75C-9183-4236-9058-B7A1D515793E}: NameServer = 4.2.2.1,65.16.121.83,65.16.121.85
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = glider.com
O17 - HKLM\System\CS3\Services\Tcpip\..\{468DB75C-9183-4236-9058-B7A1D515793E}: NameServer = 4.2.2.1,65.16.121.83,65.16.121.85
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Persits Software Email Agent (EmailAgent) - Persits Software, Inc. - C:\PROGRA~1\PERSIT~1\AspEmail\EMAILA~1\BIN\EMAILA~1.EXE
O23 - Service: IMail FINGER Server (FINGRD32) - Ipswitch, Inc. - z:\IMail\FINGRD32.exe
O23 - Service: IMail IMAP4 Server (IMAP4D32) - Ipswitch, Inc. - z:\IMail\IMAP4D32.exe
O23 - Service: IMail Monitor Service (IMonitor) - Ipswitch, Inc. - z:\IMail\IMonitor.exe
O23 - Service: IMail Web Calendar Service (IWebCal) - Ipswitch, Inc. - z:\IMail\IWebCal.exe
O23 - Service: IMail Web Service (IWEBMSG) - Ipswitch, Inc. - z:\IMail\iwebmsg.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\RaMaint.exe
O23 - Service: LogMeIn Service (LogMeIn) - LogMeIn, Inc. - C:\Program Files\LogMeIn\LogMeIn.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Network DDE Drivers (NetworkDDEDrivers) - Unknown owner - C:\WINNT\I386\Drivers\core\ndis.exe" -k runservice (file missing)
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: OESH (Office Source Engine Help) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: IMail LDAP Service (OpenLDAP-slapd) - Unknown owner - z:\IMail\OpenLDAP\bin\slapd.exe
O23 - Service: IMail POP3 Server (POP3D32) - Ipswitch, Inc. - z:\IMail\POP3D32.exe
O23 - Service: IMail PWD Server (PSERVE) - Ipswitch, Inc. - z:\IMail\PSERVE.exe
O23 - Service: IMail Queue Manager Service (QueueMgr) - Ipswitch, Inc. - z:\IMail\queuemgr.exe
O23 - Service: IMail SMTP Server (SMTPD32) - Ipswitch, Inc. - z:\IMail\smtpd32.exe
O23 - Service: IMail Sys Logger Service (SYSLOGD) - Ipswitch, Inc. - z:\IMail\SYSLOGD.exe
O23 - Service: WFTPD Pro - Texas Imperial Software - C:\PROGRA~1\TEXASI~1\WFTPDP~1\WFTPD.EXE
O23 - Service: IMail WHOIS Server (WHOISD32) - Ipswitch, Inc. - z:\IMail\WHOISD32.exe
O23 - Service: WebTrends Reporting UI (wtinterface) - Unknown owner - C:\PROGRA~1\WEBTRE~1\wtrs_ui.exe
O23 - Service: WebTrends Reporting Center (wtrs) - WebTrends Corp. - C:\PROGRA~1\WEBTRE~1\wtrs.exe

Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 8th January 2009 - 10:57 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy