Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)
![]() ![]() |
Aug 4 2008, 03:36 PM
Post
#1
|
|
|
New Member ![]() Group: New Member Posts: 2 Joined: 4-August 08 Member No.: 80,753 Operating System: Windows XP |
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:35: VIRUS ALERT!, on 8/4/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Safe mode with network support Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.safewebnavigate2008.com/index.p...aid=0&pid=0 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing) O2 - BHO: QXK Olive - {25F82259-85DE-46B8-AC72-D84F8FC77AC5} - C:\WINDOWS\wnlmdakqoxv.dll (file missing) O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: (no name) - {81A35F39-4850-474E-92C9-B4CF283207E0} - C:\WINDOWS\system32\mstask64.dll (file missing) O3 - Toolbar: bgrqfetx - {8A11BBE3-E0B5-40FB-9D86-E08A52B51B47} - C:\WINDOWS\bgrqfetx.dll (file missing) O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [Adobe Photo Downloader] "D:\Chiraag\Programs\Adobe Photoshop 6\apdproxy.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [PCPrivacyCleaner] C:\Program Files\PCPrivacyCleaner\pcpc.exe O4 - HKLM\..\Run: [lphcpmgj0elfl] C:\WINDOWS\system32\lphcpmgj0elfl.exe O4 - HKLM\..\Run: [SMrhctmgj0elfl] C:\Program Files\rhctmgj0elfl\rhctmgj0elfl.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing) O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinner.com/games/v47/famil.../familyfeud.cab O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/mpp_236/w...OCX/FlashAX.cab O21 - SSODL: xokvrpwg - {35DE5CF1-CDE6-4176-AA81-B68635DEDF7D} - C:\WINDOWS\xokvrpwg.dll (file missing) O21 - SSODL: tfnslopk - {EDEAF004-47F1-49F3-95CC-FE76477E0042} - C:\WINDOWS\tfnslopk.dll (file missing) O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe -- End of file - 5738 bytes |
|
|
|
Aug 5 2008, 01:49 AM
Post
#2
|
|
![]() Advanced Member Group: Malware Team Posts: 912 Joined: 25-July 06 From: Yorkshire, England Member No.: 58,927 Operating System: XP |
Looking over your log, back ASAP.
|
|
|
|
Aug 5 2008, 01:55 AM
Post
#3
|
|
![]() Advanced Member Group: Malware Team Posts: 912 Joined: 25-July 06 From: Yorkshire, England Member No.: 58,927 Operating System: XP |
QUOTE Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections. If you think you have similar problems, please post a log in the HJT forum and wait for help. Unless informed of in advance, failure to post replies within 5 days will result in this thread being closed. Hi chiraagm I'm Gary R, I'll be glad to help you with your computer problems. Please observe these rules while we work:
If you can do these things, everything should go smoothly.
QUOTE It may be helpful to you to print out or take a copy of any instructions given, as sometimes it is necessary to go offline and you will lose access to them. Download SDFix and save it to your Desktop.
Reboot your computer into Safe Mode by doing the following :
Note: if you cannot boot into safe mode using this method, DO NOT attempt to do so by using MSConfig, this could result in your computer becoming unbootable. Just let me know. Once in safe mode.
Next
Then Please download Malwarebytes' Anti-Malware to your Desktop.
You can also access the log by doing the following
Finally Run a new scan with HJT and post the log back here please. Summary of the logs I need from you in your next post:
Please post each log separately to prevent them being cut off by the forum post size limiter. |
|
|
|
Aug 5 2008, 06:04 AM
Post
#4
|
|
|
New Member ![]() Group: New Member Posts: 2 Joined: 4-August 08 Member No.: 80,753 Operating System: Windows XP |
Hi Gary,
Thanks a lot for your help. However, I managed to format my computer and its back to normal now. But again, thanks for your time. |
|
|
|
Aug 5 2008, 08:48 AM
Post
#5
|
|
![]() Advanced Member Group: Malware Team Posts: 912 Joined: 25-July 06 From: Yorkshire, England Member No.: 58,927 Operating System: XP |
You're welcome, glad you got your computer back running normally again.
|
|
|
|
Aug 5 2008, 08:48 AM
Post
#6
|
|
![]() Advanced Member Group: Malware Team Posts: 912 Joined: 25-July 06 From: Yorkshire, England Member No.: 58,927 Operating System: XP |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
7 | Leemo | 70 | Today, 11:03 AM Last post by: Leemo |
|||
![]() |
5 | pc storm | 64 | Today, 09:46 AM Last post by: pc storm |
|||
![]() |
0 | aqua88 | 20 | Today, 08:05 AM Last post by: aqua88 |
|||
![]() |
4 | harrycontests | 51 | Today, 07:33 AM Last post by: DFW |
|||
![]() |
6 | RAIDANLIT | 42 | Today, 07:02 AM Last post by: BHowett |
|||
|
Time is now: 7th October 2008 - 12:19 PM |