Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Hijack this log I had to use it in safe mode
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Hijack this log I had to use it in safe mode  
Forum Quick Jump
 
New Topic Post reply to : Hijack this log I had to use it in safe mode Printable version of : Hijack this log I had to use it in safe mode
[ << Previous Thread | Next Thread >> ]

baka101
New Member


Date Joined Jun 2007
Total Posts : 3
 
   Posted 7-20-2008 2:02 (GMT +1)    Quote: Hijack this log I had to use it in safe modeAlert an admin about: Hijack this log I had to use it in safe mode
I had to boot into safe mode to run hijack this as normal mode would pause up always, so here is my log thanks.


Deckard's System Scanner v20071014.68
Run by lobbadmin on 2008-07-19 21:38:52
Computer is in Safe Mode with Networking.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Failed to create restore point; computer is in safe mode.


-- Last 2 Restore Point(s) --
2: 2008-07-19 01:51:10 UTC - RP2 - Software Distribution Service 3.0
1: 2008-07-18 09:05:24 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 448 MiB (512 MiB recommended).


-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-07-19 21:39:57
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\pcoadmin\Desktop\New Folder\dss.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Google Search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Google
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Parliamentary Counsel Office
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = Google Search
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = %s - Google Search
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = Parliamentary Counsel Office
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=10.2.1.10:8080;https=10.2.1.10:8080
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Parliamentary Counsel Office
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = Google Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = Google Search
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: IE.Filter - {8B2AE9C0-1555-4C92-905A-531532F15698} - C:\WINDOWS\system32\ie_f.dll
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZH
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} () - http://us.chat1.yimg.com/us.yimg.com...45/yacscom.cab
O16 - DPF: {41D1977F-4161-4720-800F-EA4903983A38} (Jigsaw Genius Control) - http://www.worldwinner.com/games/v42/jigsaw/jigsaw.cab
O16 - DPF: {4F021AE3-9E98-11D0-A808-00C04FDCD94A} (Novell Directory Control) - http://intranet/ocx/nwdir.ocx
O16 - DPF: {4F5E4276-C120-11D6-A1FD-00508B9D48EA} (dldisplay Class) - http://www.gamehouse.com/ghdlctl.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.g...tl_0_0_0_2.ocx
O16 - DPF: {6F6DBC29-7A0C-4AC0-A42D-10EC70678526} (Word Cubes Control) - http://www.worldwinner.com/games/v44...e/wordcube.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} () - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.gamehouse.com/games/mjolauncher.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\WINDOWS\msxml4.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinner.com/games/v44/sol/sol.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} () - http://v4.windowsupdate.microsoft.co...169.8386458333
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - http://www.worldwinner.com/games/v40...an/hangman.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/amp...1.11_en_dl.cab
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} (Tile City Control) - http://www.worldwinner.com/games/v41...y/tilecity.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://www.gamehouse.com/games/zylom/zylomplayer.cab
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - http://www.worldwinner.com/games/v42/paint/paint.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub...sh/swflash.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/game...utLauncher.cab
O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\system32\msvidctl.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe


--
End of file - 7517 bytes

-- File Associations -----------------------------------------------------------

.reg - regfile - shell\open\command - regedit.exe "%1" %*
.scr - scrfile - shell\open\command - "%1" %*


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

All drivers whitelisted.


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

S2 a2free (a-squared Free Service) - c:\program files\a-squared free\a2service.exe <Not Verified; Emsi Software GmbH; a-squared>


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Files created between 2008-06-19 and 2008-07-19 -----------------------------

2008-07-19 16:56:56 0 d------c- C:\Program Files\Trend Micro
2008-07-19 14:57:23 0 d------c- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-19 14:45:18 0 d------c- C:\Documents and Settings\pcoadmin\Application Data\Mozilla
2008-07-19 13:58:31 118784 --a----c- C:\WINDOWS\system32\MSSTDFMT.DLL <Not Verified; Microsoft Corporation; MSSTDFMT Object Library>
2008-07-19 13:58:29 0 d------c- C:\Program Files\SpywareBlaster
2008-07-19 13:51:42 0 d------c- C:\WINDOWS\system32\PreInstall
2008-07-19 13:51:35 0 d--h---c- C:\WINDOWS\$hf_mig$
2008-07-19 13:30:09 0 d------c- C:\WINDOWS\system32\SoftwareDistribution
2008-07-19 08:25:49 0 d------c- C:\WINDOWS\Provisioning
2008-07-19 02:38:57 8192 --a------ C:\ntuser.dat
2008-07-19 02:11:10 0 d------c- C:\Documents and Settings\mjlobb\Application Data\Malwarebytes
2008-07-19 00:10:22 0 d------c- C:\Documents and Settings\pcoadmin\Application Data\URSoft
2008-07-19 00:09:46 0 d------c- C:\Program Files\Your Uninstaller 2008
2008-07-18 23:32:05 0 d------c- C:\Documents and Settings\pcoadmin\Application Data\Adobe
2008-07-18 23:14:31 0 d------c- C:\Program Files\Alwil Software
2008-07-18 22:49:02 0 d------c- C:\Documents and Settings\pcoadmin\Application Data\Malwarebytes
2008-07-18 22:48:10 0 d------c- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-18 22:48:08 0 d------c- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-18 22:25:07 0 d------c- C:\Program Files\Spyware Doctor
2008-07-18 22:25:07 0 d------c- C:\Documents and Settings\mjlobb\Application Data\PC Tools
2008-07-18 22:00:26 0 d------c- C:\Program Files\a-squared Free
2008-07-18 21:54:58 0 d------c- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-18 21:03:05 0 d------c- C:\WINDOWS\SoftwareDistribution
2008-07-18 21:02:28 0 d------c- C:\WINDOWS\Prefetch
2008-07-18 20:36:02 0 dr-h---c- C:\Documents and Settings\Default User\Local Settings
2008-07-14 11:42:12 20992 --a------ C:\WINDOWS\system32\ie_f.dll
2008-07-14 11:42:11 58887 --a----c- C:\Documents and Settings\mjlobb\scchost.exe
2008-07-12 21:00:31 0 d------c- C:\Documents and Settings\dmlobb\Application Data\Sun
2008-07-12 20:59:07 0 d---s--c- C:\Documents and Settings\dmlobb\UserData
2008-06-25 14:09:12 0 d------c- C:\Program Files\uTorrent
2008-06-25 14:09:08 0 d------c- C:\Documents and Settings\nalobb\Application Data\uTorrent


-- Find3M Report ---------------------------------------------------------------

2008-07-19 01:36:55 0 d------c- C:\Program Files\Common Files\Sandlot Shared
2008-07-19 00:50:55 0 d------c- C:\Program Files\Google
2008-07-19 00:50:19 0 d------c- C:\Program Files\Activision
2008-07-19 00:41:36 0 d------c- C:\Program Files\Ares Lite Edition
2008-07-18 21:54:58 0 d------c- C:\Program Files\Common Files
2008-07-18 20:49:41 0 d--h---c- C:\Program Files\WindowsUpdate
2008-07-18 20:49:06 0 d------c- C:\Program Files\Movie Maker
2008-07-18 20:47:04 22832 --a----c- C:\WINDOWS\system32\emptyregdb.dat
2008-07-18 20:46:20 0 d------c- C:\Program Files\Messenger
2008-07-18 20:46:17 0 d------c- C:\Program Files\Windows NT
2008-06-30 14:43:03 0 d------c- C:\Program Files\GameHouse
2008-06-19 15:31:35 0 d------c- C:\Program Files\PokerStars


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8B2AE9C0-1555-4C92-905A-531532F15698}]
14/07/2008 11:42 a.m. 20992 --a------ C:\WINDOWS\System32\ie_f.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WINDVDPatch"="CTHELPER.EXE" [02/07/2002 05:56 p.m. C:\WINDOWS\system32\CTHELPER.EXE]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [11/05/2000 01:00 a.m.]
"Jet Detection"="C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" [29/11/2001 01:00 a.m.]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [24/03/2004 10:04 a.m.]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [04/08/2004 01:07 p.m.]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe" [03/06/2004 10:05 p.m.]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [05/12/2007 02:00 a.m.]
"RegistryMechanic"="" []
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [10/06/2008 09:22 p.m.]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [1/10/2004 12:10:02 p.m.]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explor er]
"ForceStartMenuLogOff"=1 (0x1)
"Intellimenus"=1 (0x1)
"MemCheckBoxInRunDlg"=1 (0x1)
"NoTaskGrouping"=1 (0x1)
"NoAutoUpdate"=1 (0x1)
"NoSharedDocuments"=1 (0x1)
"NoAutoTrayNotify"=1 (0x1)
"NoDesktopCleanupWizard"=1 (0x1)
"ForceClassicControlPanel"=1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell ExecuteHooks]
"{B4870B70-F390-11d2-9FB9-F4ED725EA20D}"= C:\WINDOWS\System32\NalExpEx.dll [18/10/2002 11:17 a.m. 131072]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxs ervice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcore service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5 B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"




-- End of Deckard's System Scanner: finished at 2008-07-19 21:40:48 ------------


Any help would be much appreciated

Thanks
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13812
 
   Posted 7-20-2008 6:36 (GMT +1)    Quote: Hijack this log I had to use it in safe modeAlert an admin about: Hijack this log I had to use it in safe mode
Hello smile


Launch  Malwarebytes' Anti-Malware, 
                     
Once the program has loaded, select Perform full scan, then click Scan.
                     
When the scan is complete, click OK, then Show Results to view the results.
 
Be sure that everything is checked, and click Remove Selected.
 
When completed, a log will open in Notepad. Please save it to a convenient location.
 
Copy and Paste that log into your next reply.



Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

baka101
New Member


Date Joined Jun 2007
Total Posts : 3
 
   Posted 7-20-2008 10:40 (GMT +1)    Quote: Hijack this log I had to use it in safe modeAlert an admin about: Hijack this log I had to use it in safe mode
Malwarebytes' Anti-Malware 1.14
Database version: 800

8:33:32 p.m. 20/07/2008
mbam-log-7-20-2008 (20-33-32).txt

Scan type: Full Scan (C:\|)
Objects scanned: 68358
Time elapsed: 1 hour(s), 6 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Back to Top
 
New Topic Post reply to : Hijack this log I had to use it in safe mode Printable version of : Hijack this log I had to use it in safe mode
 
Forum Information
Currently it is Wednesday, December 03, 2008 6:17 AM (GMT +1)
There are a total of 64.512 posts in 15.910 threads.
In the last 3 days there were 19 new threads and 77 reply posts. View Active Threads
Who's Online
This forum has 27326 registered members. Please welcome our newest member, DooN.
42 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Help with a (win32 trojan gen other) (0)03-12-2008 02:25:45 (finz)
Ok...I'm infected, now what? (24)03-12-2008 02:11:28 (Zalen)
Antivirus disabled/URL Redirect Malware.Wont let me install MALEWAREBYTES (3)03-12-2008 02:08:19 (cgamm)
Trojan Horse Generic 12.KAO (5)03-12-2008 02:01:58 (Taryn)
No Safe Mode, explorer.exe crashes, no internet (0)03-12-2008 00:49:20 (roygbp)