|
|
|||||||||
|
|||||||||
| |||||||||
|
|
|
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
#1
|
|||
|
|||
|
desktop hijacked, help me figure out what to delete in "hijack this"
my desktop is hijacked and i cant right click it or right click in mycomputer etc.
i got hijack this and ran the scan but was told to get help one what to get rid of heres the scan Logfile of HijackThis v1.99.1 Scan saved at 4:41:44 PM, on 3/28/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\System32\Cdl.exe C:\WINDOWS\hostdll.exe C:\Program Files\AIM\aim.exe C:\Program Files\Valve\Steam\Steam.exe C:\WINDOWS\System32\auao.exe C:\WINDOWS\System32\j?vaw.exe C:\WINDOWS\System32\wuauclt.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe C:\WINDOWS\System32\wpabaln.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\HijackThis.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\8b5e9cdb91dddbb342695fbdc36fe0e4\update\update.exe O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: (no name) - {EC17B4A1-8F8D-4ECF-BB33-7DC17CF6CC28} - C:\WINDOWS\System32\jkggoib.dll (file missing) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [Thk] C:\WINDOWS\System32\Cdl.exe O4 - HKLM\..\Run: [hostdll.exe] C:\WINDOWS\hostdll.exe O4 - HKLM\..\Run: [Eha] C:\WINDOWS\System32\Ija.exe O4 - HKLM\..\Run: [Ifh] C:\WINDOWS\Iho.exe O4 - HKLM\..\Run: [Lua] C:\WINDOWS\Rbm.exe O4 - HKLM\..\Run: [Pmp] C:\WINDOWS\Qjc.exe O4 - HKLM\..\Run: [Rjt] C:\WINDOWS\Aud.exe O4 - HKLM\..\Run: [Kje] C:\WINDOWS\Mds.exe O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\Steam.exe -silent O4 - HKCU\..\Run: [Thk] C:\WINDOWS\System32\Cdl.exe O4 - HKCU\..\Run: [Mrrl] C:\WINDOWS\System32\auao.exe O4 - HKCU\..\Run: [Omzqw] C:\WINDOWS\System32\j?vaw.exe O4 - HKCU\..\Run: [Eha] C:\WINDOWS\System32\Ija.exe O4 - HKCU\..\Run: [Ifh] C:\WINDOWS\Iho.exe O4 - HKCU\..\Run: [Lua] C:\WINDOWS\Rbm.exe O4 - HKCU\..\Run: [Pmp] C:\WINDOWS\Qjc.exe O4 - HKCU\..\Run: [Rjt] C:\WINDOWS\Aud.exe O4 - HKCU\..\Run: [Kje] C:\WINDOWS\Mds.exe O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: PokerNow - {2DB0FBAF-5223-4c96-8C25-F60D5E437D34} - C:\Program Files\PokerNow\PokerNow.exe O9 - Extra 'Tools' menuitem: PokerNow - {2DB0FBAF-5223-4c96-8C25-F60D5E437D34} - C:\Program Files\PokerNow\PokerNow.exe O9 - Extra button: Intertops Poker - {5706EACE-252A-4af9-AA8D-1F8813B50469} - C:\Program Files\Intertops Poker\IntertopsPoker.exe O9 - Extra 'Tools' menuitem: Intertops Poker - {5706EACE-252A-4af9-AA8D-1F8813B50469} - C:\Program Files\Intertops Poker\IntertopsPoker.exe O9 - Extra button: MultiPoker - {641F4F4E-6C91-4159-869E-9F5CE6F0F64E} - C:\Program Files\MultiPoker\MultiPoker.exe O9 - Extra 'Tools' menuitem: MultiPoker - {641F4F4E-6C91-4159-869E-9F5CE6F0F64E} - C:\Program Files\MultiPoker\MultiPoker.exe O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe O15 - Trusted Zone: *.skoobidoo.com O15 - Trusted Zone: *.slotchbar.com O15 - Trusted Zone: *.windupdates.com O15 - Trusted Zone: *.skoobidoo.com (HKLM) O15 - Trusted Zone: *.slotchbar.com (HKLM) O15 - Trusted Zone: *.windupdates.com (HKLM) O15 - Trusted IP range: 67.19.185.246 O15 - Trusted IP range: 67.19.185.246 (HKLM) O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/6247971CanadaInc/ie/bridge-c7.cab O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe thx for the help |
|
#2
|
|||
|
|||
|
Hi david burkholde,
I would like you to perform an onlne virus scan at Trend Micro Housecall http://housecall.trendmicro.com/ Select all of your drives listed for scanning. Please check "Auto clean" before scanning. Please copy and paste the report logs from the scan into your next post. If you can't capture the information, please write down what was found and if anything was or was not deleted. Please include this information in your next post. Next.... I'd like you to do a couple of trojan scans. Install and perform a full system scan with each of these trial programs: Please download Trojan Hunter http://www.misec.net/trojanhunter/ Perform a full system scan. Please write down any files found and include this information in your next post. Delete any files that come up as a positive identification. Next... Please download DiamondCS TDS-3 http://tds.diamondcs.com.au/ Install the program, but do not scan with it yet! Update the Radius definitions file. Right click this link and select "Save as". Save it to the directory where you installed TDS3 and let it replace the old Radius file. http://www.diamondcs.com.au/tds/radius.td3 Start TDS3 > at the top of the program click System Testing > Full system scan > after scanning right-click the report, save as scandump.txt > submit the scandump.txt file into your next post. Finally, right click the items in the list that come up a a Positive Identification and select delete. Along with the information from the two scans above, please post a fresh HijackThis log. Tom
__________________
HijackThis Ad-aware Spybot Search & Destroy SpywareBlaster SpywareGuard Housecall Online A/V Scan Please read the stickys at the top of the forum before posting! |
![]() |
| Viewing: Dev Shed Forums > System Administration > Antivirus Protection > desktop hijacked, help me figure out what to delete in "hijack this" |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
|
|