View Single Post
Old 03-11-2006, 05:32 PM   #7 (permalink)
em1
Registered User
 
Join Date: Mar 2005
Posts: 183
OS: Windows XP


hijack, ewido, and kaspersky logs

Thank you very much for the help w/ my pc problems. Below are the logs:


Logfile of HijackThis v1.99.1
Scan saved at 4:28:04 PM, on 3/11/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_AICN03.EXE
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\PROGRAM FILES\YAHOO!\BROWSER\YCOMMON.EXE
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Eric & Tabitha\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [EPSON Stylus COLOR 480] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_AICN03.EXE /A "C:\WINDOWS\system32\E_S34.tmp"
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES.DLL
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/k...an_unicode.cab
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe



---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 12:20:58 PM, 3/11/2006
+ Report-Checksum: 65B2A252

+ Scan result:

C:\gimmysmileys.exe -> Downloader.VB.xu : Cleaned with backup
C:\keyboard.exe -> Downloader.VB.xv : Cleaned with backup
C:\mousepad.exe -> Hijacker.VB.li : Cleaned with backup
C:\My Documents\l2mfix\backup.zip/dlls/enr6l19s1.dll -> Adware.Look2Me : Cleaned with backup
C:\My Documents\l2mfix\backup.zip/dlls/fpls0337e.dll -> Adware.Look2Me : Cleaned with backup
C:\My Documents\l2mfix\backup.zip/dlls/guard.tmp -> Adware.Look2Me : Cleaned with backup
C:\My Documents\l2mfix\backup.zip/dlls/h20q0cd5ef0.dll -> Adware.Look2Me : Cleaned with backup
C:\My Documents\l2mfix\backup.zip/dlls/m0po0a73ed.dll -> Adware.Look2Me : Cleaned with backup
C:\My Documents\l2mfix\backup.zip/dlls/mpxml3.dll -> Adware.Look2Me : Cleaned with backup
C:\My Documents\l2mfix\backup.zip/dlls/p8r40i9qe8.dll -> Adware.Look2Me : Cleaned with backup
C:\My Documents\l2mfix\dlls\enr6l19s1.dll -> Adware.Look2Me : Cleaned with backup
C:\My Documents\l2mfix\dlls\fpls0337e.dll -> Adware.Look2Me : Cleaned with backup
C:\My Documents\l2mfix\dlls\guard.tmp -> Adware.Look2Me : Cleaned with backup
C:\My Documents\l2mfix\dlls\h20q0cd5ef0.dll -> Adware.Look2Me : Cleaned with backup
C:\My Documents\l2mfix\dlls\m0po0a73ed.dll -> Adware.Look2Me : Cleaned with backup
C:\My Documents\l2mfix\dlls\mpxml3.dll -> Adware.Look2Me : Cleaned with backup
C:\My Documents\l2mfix\dlls\p8r40i9qe8.dll -> Adware.Look2Me : Cleaned with backup
:mozilla.7:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.8:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.9:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.10:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.19:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.21:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.22:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.23:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.24:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.25:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.26:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.27:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.28:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.29:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.30:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.33:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.34:C:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\iyzd5hrk.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.6:C:\WINDOWS\Application Data\Mozilla\Profiles\default\oypftari.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.7:C:\WINDOWS\Application Data\Mozilla\Profiles\default\oypftari.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.8:C:\WINDOWS\Application Data\Mozilla\Profiles\default\oypftari.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.9:C:\WINDOWS\Application Data\Mozilla\Profiles\default\oypftari.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.10:C:\WINDOWS\Application Data\Mozilla\Profiles\default\oypftari.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.14:C:\WINDOWS\Application Data\Mozilla\Profiles\default\oypftari.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.41:C:\WINDOWS\Application Data\Mozilla\Profiles\default\oypftari.slt\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.44:C:\WINDOWS\Application Data\Mozilla\Profiles\default\oypftari.slt\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.65:C:\WINDOWS\Application Data\Mozilla\Profiles\default\oypftari.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.66:C:\WINDOWS\Application Data\Mozilla\Profiles\default\oypftari.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.67:C:\WINDOWS\Application Data\Mozilla\Profiles\default\oypftari.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.68:C:\WINDOWS\Application Data\Mozilla\Profiles\default\oypftari.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.69:C:\WINDOWS\Application Data\Mozilla\Profiles\default\oypftari.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.70:C:\WINDOWS\Application Data\Mozilla\Profiles\default\oypftari.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\VM.exe -> Hijacker.Small.dl : Cleaned with backup
C:\WINDOWS\icont.exe -> Adware.AdURL : Cleaned with backup
C:\WINDOWS\iconu.exe -> Adware.Zestyfind : Cleaned with backup
C:\WINDOWS\lbbho.dll -> Adware.Neon : Cleaned with backup


::Report End





-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Saturday, March 11, 2006 15:02:50
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 11/03/2006
Kaspersky Anti-Virus database records: 181901
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
G:\

Scan Statistics:
Total number of scanned objects: 24485
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 4444 sec
No malware has been detected. The sections that have been scanned are CLEAN.

Scan process completed.
em1 is offline