|
#1
|
|||
|
|||
|
Hijack This Log
Can someone analyze this log for me...
Logfile of HijackThis v1.97.2 Scan saved at 9:18:41 PM, on 10/7/2003 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\MWW32\MANAGER\MWMDMSVC.EXE C:\WINDOWS\MWW32\MANAGER\MWSSW32.EXE C:\PROGRA~1\Grisoft\AVG6\avgserv.exe C:\WINDOWS\system32\regsvc.exe C:\WINDOWS\system32\MSTask.exe C:\WINDOWS\System32\WBEM\WinMgmt.exe C:\WINDOWS\System32\mspmspsv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\tp4mon.exe C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe C:\Program Files\NoAds\NoAds.exe C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe \Simon\simon\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = ;<local> O1 - Hosts: 64.200.25.145 gator.com #cooklop O1 - Hosts: 64.200.25.145 www.gator.com #cooklop O1 - Hosts: 64.200.25.145 doubleclick.net #cooklop O1 - Hosts: 64.200.25.145 www.doubleclick.net #cooklop O1 - Hosts: 64.200.25.145 tripod.com #cooklop O1 - Hosts: 64.200.25.145 www.tripod.com #cooklop O1 - Hosts: 64.200.25.145 adultfriendfinder.com #cooklop O1 - Hosts: 64.200.25.145 www.adultfriendfinder.com #cooklop O1 - Hosts: 64.200.25.145 cj.com #cooklop O1 - Hosts: 64.200.25.145 www.cj.com #cooklop O1 - Hosts: 64.200.25.145 paypopup.com #cooklop O1 - Hosts: 64.200.25.145 www.paypopup.com #cooklop O1 - Hosts: 64.200.25.145 worldsex.com #cooklop O1 - Hosts: 64.200.25.145 www.worldsex.com #cooklop O1 - Hosts: 64.200.25.145 free6.com #cooklop O1 - Hosts: 64.200.25.145 trafficmp.com #cooklop O1 - Hosts: 64.200.25.145 www.trafficmp.com #cooklop O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\ACROBAT\ACTIVEX\ACROIEHELPER.OCX O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\PROGRAM FILES\WS_FTP PRO\WSBHO2K0.DLL O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP O4 - HKLM\..\Run: [LoadQM] loadqm.exe O4 - HKLM\..\Run: [POINTER] point32.exe O4 - HKCU\..\Run: [NoAds] "C:\Program Files\NoAds\NoAds.exe" O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...ctor/swdir.cab O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...CAB?37849.6075 O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/Sha.../bin/cabsa.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab |
|
#2
|
||||
|
||||
|
Your hosts file has been hijacked. Run Hijack This again and use it to fix the below entries:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = ;<local> O1 - Hosts: 64.200.25.145 gator.com #cooklop O1 - Hosts: 64.200.25.145 www.gator.com #cooklop O1 - Hosts: 64.200.25.145 doubleclick.net #cooklop O1 - Hosts: 64.200.25.145 www.doubleclick.net #cooklop O1 - Hosts: 64.200.25.145 tripod.com #cooklop O1 - Hosts: 64.200.25.145 www.tripod.com #cooklop O1 - Hosts: 64.200.25.145 adultfriendfinder.com #cooklop O1 - Hosts: 64.200.25.145 www.adultfriendfinder.com #cooklop O1 - Hosts: 64.200.25.145 cj.com #cooklop O1 - Hosts: 64.200.25.145 www.cj.com #cooklop O1 - Hosts: 64.200.25.145 paypopup.com #cooklop O1 - Hosts: 64.200.25.145 www.paypopup.com #cooklop O1 - Hosts: 64.200.25.145 worldsex.com #cooklop O1 - Hosts: 64.200.25.145 www.worldsex.com #cooklop O1 - Hosts: 64.200.25.145 free6.com #cooklop O1 - Hosts: 64.200.25.145 trafficmp.com #cooklop O1 - Hosts: 64.200.25.145 www.trafficmp.com #cooklop Reboot and post back a new Hijack This log.
__________________
Moderator: Vista Forum Microsoft MVP - Windows Desktop Experience 2004-2008 If we have helped you, please consider supporting Cyber Tech Help with a subscription Please do not send me Emails or Private Messages for personal support. Last time I checked, there were still only 24 hours in a day. Thank you. How to help prevent re-infection |
|
#3
|
|||
|
|||
|
Thanks. I will fix the entries tonight when I get home & repost.
Shouldn't Adaware & Spybot catch these things? |
|
#4
|
|||
|
|||
|
Quote:
Hi Lover (wow haven't said that for awhile); If installed I'd run Spybot & Adaware and then Hijack This just to see if it misses anything. It's a curiosity thing. |
|
#5
|
|||
|
|||
|
I ran both adaware & spybot before running hijack this & posting the log.
Both adaware & spybot definitions are up to date as well. |
|
#6
|
|||
|
|||
|
Quote:
Interesting indeed! Sounds like it's time to follow AnnMarie's suggestion and use Hijackthis to clean those critters up. |
|
#7
|
||||
|
||||
|
Hi Trish-A...long time no see
__________________
Moderator: Vista Forum Microsoft MVP - Windows Desktop Experience 2004-2008 If we have helped you, please consider supporting Cyber Tech Help with a subscription Please do not send me Emails or Private Messages for personal support. Last time I checked, there were still only 24 hours in a day. Thank you. How to help prevent re-infection |
|
#8
|
|||
|
|||
|
Quote:
I thought that looked like you... LOL |
|
#9
|
|||
|
|||
|
Here is the new log after deleting the entries mentioned...
Logfile of HijackThis v1.97.2 Scan saved at 7:24:56 PM, on 10/8/2003 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\MWW32\MANAGER\MWMDMSVC.EXE C:\WINDOWS\MWW32\MANAGER\MWSSW32.EXE C:\PROGRA~1\Grisoft\AVG6\avgserv.exe C:\WINDOWS\system32\regsvc.exe C:\WINDOWS\system32\MSTask.exe C:\WINDOWS\System32\WBEM\WinMgmt.exe C:\WINDOWS\System32\mspmspsv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\tp4mon.exe C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe C:\Program Files\NoAds\NoAds.exe C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe \Simon\simon\FTP\Software\Hijack This\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\ACROBAT\ACTIVEX\ACROIEHELPER.OCX O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\PROGRAM FILES\WS_FTP PRO\WSBHO2K0.DLL O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP O4 - HKLM\..\Run: [LoadQM] loadqm.exe O4 - HKLM\..\Run: [POINTER] point32.exe O4 - HKCU\..\Run: [NoAds] "C:\Program Files\NoAds\NoAds.exe" O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...ctor/swdir.cab O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...CAB?37849.6075 O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/Sha.../bin/cabsa.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab |
|
#10
|
||||
|
||||
|
Your log looks fine now 2337lover. Do you have any problems now?
__________________
Moderator: Vista Forum Microsoft MVP - Windows Desktop Experience 2004-2008 If we have helped you, please consider supporting Cyber Tech Help with a subscription Please do not send me Emails or Private Messages for personal support. Last time I checked, there were still only 24 hours in a day. Thank you. How to help prevent re-infection |
|
#11
|
|||
|
|||
|
Hi 2337lover,
Just a thought, but in your Ad-aware configuration settings (click the gear in the upper right of the main AAW status window) open the scan settings window by clicking the button on the left that says "scanning" and look in the lower section under Memory & Registry and see if the "Scan my Hosts file" option is checked (Green instead of red). If it is red it means that the option is turned off, so Ad-aware won't scan your Hosts file. |
![]() |
| Bookmarks |
«
Previous Topic
|
Next Topic
»
| Topic Tools | |
|
|
All times are GMT +1. The time now is 10:08 PM.
[
RSS ]








