gg allin
2007-10-08, 14:38
hi im new here sorry if i'm not following protocol im not totally sure but i think i have the win32 trogan because im getting fake windows messages telling me to download a spyware program,pages seem to open automatically without clicking,i have nod32 antivirus and have just run the latest version of spybot search and destroy,and deleted all the red symbols i have a txt file i saved from it but its rather long,nod 32 cant detect whatever trogan i have neither can spybot,im sick of this popup coming up asking me to download ultimate defender can someone please help heres the results of the latest version of hijack this
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
O1 - Hosts: 213.239.215.227 cache9.winmxgroup.com
O1 - Hosts: 62.49.233.225 cache8.winmxgroup.com
O1 - Hosts: 82.38.219.252 cache7.winmxgroup.com
O1 - Hosts: 74.208.72.61 cache6.winmxgroup.com
O1 - Hosts: 203.173.20.140 cache5.winmxgroup.com
O1 - Hosts: 74.208.72.61 cache4.winmxgroup.com
O1 - Hosts: 213.239.215.227 cache3.winmxgroup.com
O1 - Hosts: 82.38.219.252 cache2.winmxgroup.com
O1 - Hosts: 203.173.20.140 cache1.winmxgroup.com
O1 - Hosts: 81.149.88.127 cache0.winmxgroup.com
O1 - Hosts: 213.239.215.227 cache19.winmxgroup.net
O1 - Hosts: 62.49.233.225 cache18.winmxgroup.net
O1 - Hosts: 82.38.219.252 cache17.winmxgroup.net
O1 - Hosts: 74.208.72.61 cache16.winmxgroup.net
O1 - Hosts: 203.173.20.140 cache15.winmxgroup.net
O1 - Hosts: 81.149.88.127 cache14.winmxgroup.net
O1 - Hosts: 213.239.215.227 cache13.winmxgroup.net
O1 - Hosts: 62.49.233.225 cache12.winmxgroup.net
O1 - Hosts: 82.38.219.252 cache11.winmxgroup.net
O1 - Hosts: 74.208.72.61 cache10.winmxgroup.net
O1 - Hosts: 203.173.20.140 cache9.winmxgroup.net
O1 - Hosts: 81.149.88.127 cache8.winmxgroup.net
O1 - Hosts: 213.239.215.227 cache7.winmxgroup.net
O1 - Hosts: 62.49.233.225 cache6.winmxgroup.net
O1 - Hosts: 82.38.219.252 cache5.winmxgroup.net
O1 - Hosts: 74.208.72.61 cache4.winmxgroup.net
O1 - Hosts: 203.173.20.140 cache3.winmxgroup.net
O1 - Hosts: 81.149.88.127 cache2.winmxgroup.net
O1 - Hosts: 213.239.215.227 cache1.winmxgroup.net
O1 - Hosts: 62.49.233.225 cache0.winmxgroup.net
O1 - Hosts: 82.38.219.252 test6.winmxgroup.net
O1 - Hosts: 74.208.72.61 test5.winmxgroup.net
O1 - Hosts: 203.173.20.140 test4.winmxgroup.net
O1 - Hosts: 81.149.88.127 test3.winmxgroup.net
O1 - Hosts: 213.239.215.227 test2.winmxgroup.net
O1 - Hosts: 62.49.233.225 test1.winmxgroup.net
O1 - Hosts: 82.38.219.252 test0.winmxgroup.net
O1 - Hosts: 81.149.88.127 winmx-com-v30.winmxgroup.com
O1 - Hosts: 81.149.88.127 winmx.com
O1 - Hosts: 81.149.88.127 winmx-com.winmxgroup.com
O1 - Hosts: 81.149.88.127 blocklist.winmxgroup.net
O1 - Hosts: 81.149.88.127 blocklist-master.winmxgroup.net
O1 - Hosts: 81.149.88.127 flooders.block-list.winmxgroup.com
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O21 - SSODL: sysdx - {42EAF0A0-CE8F-4B1F-823E-AF64EE7AE7D8} - C:\WINDOWS\sysdx.dll
O21 - SSODL: msvb - {44ADA429-076F-4AA6-A6C7-4ACFA35E4569} - C:\WINDOWS\msvb.dll
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
O1 - Hosts: 213.239.215.227 cache9.winmxgroup.com
O1 - Hosts: 62.49.233.225 cache8.winmxgroup.com
O1 - Hosts: 82.38.219.252 cache7.winmxgroup.com
O1 - Hosts: 74.208.72.61 cache6.winmxgroup.com
O1 - Hosts: 203.173.20.140 cache5.winmxgroup.com
O1 - Hosts: 74.208.72.61 cache4.winmxgroup.com
O1 - Hosts: 213.239.215.227 cache3.winmxgroup.com
O1 - Hosts: 82.38.219.252 cache2.winmxgroup.com
O1 - Hosts: 203.173.20.140 cache1.winmxgroup.com
O1 - Hosts: 81.149.88.127 cache0.winmxgroup.com
O1 - Hosts: 213.239.215.227 cache19.winmxgroup.net
O1 - Hosts: 62.49.233.225 cache18.winmxgroup.net
O1 - Hosts: 82.38.219.252 cache17.winmxgroup.net
O1 - Hosts: 74.208.72.61 cache16.winmxgroup.net
O1 - Hosts: 203.173.20.140 cache15.winmxgroup.net
O1 - Hosts: 81.149.88.127 cache14.winmxgroup.net
O1 - Hosts: 213.239.215.227 cache13.winmxgroup.net
O1 - Hosts: 62.49.233.225 cache12.winmxgroup.net
O1 - Hosts: 82.38.219.252 cache11.winmxgroup.net
O1 - Hosts: 74.208.72.61 cache10.winmxgroup.net
O1 - Hosts: 203.173.20.140 cache9.winmxgroup.net
O1 - Hosts: 81.149.88.127 cache8.winmxgroup.net
O1 - Hosts: 213.239.215.227 cache7.winmxgroup.net
O1 - Hosts: 62.49.233.225 cache6.winmxgroup.net
O1 - Hosts: 82.38.219.252 cache5.winmxgroup.net
O1 - Hosts: 74.208.72.61 cache4.winmxgroup.net
O1 - Hosts: 203.173.20.140 cache3.winmxgroup.net
O1 - Hosts: 81.149.88.127 cache2.winmxgroup.net
O1 - Hosts: 213.239.215.227 cache1.winmxgroup.net
O1 - Hosts: 62.49.233.225 cache0.winmxgroup.net
O1 - Hosts: 82.38.219.252 test6.winmxgroup.net
O1 - Hosts: 74.208.72.61 test5.winmxgroup.net
O1 - Hosts: 203.173.20.140 test4.winmxgroup.net
O1 - Hosts: 81.149.88.127 test3.winmxgroup.net
O1 - Hosts: 213.239.215.227 test2.winmxgroup.net
O1 - Hosts: 62.49.233.225 test1.winmxgroup.net
O1 - Hosts: 82.38.219.252 test0.winmxgroup.net
O1 - Hosts: 81.149.88.127 winmx-com-v30.winmxgroup.com
O1 - Hosts: 81.149.88.127 winmx.com
O1 - Hosts: 81.149.88.127 winmx-com.winmxgroup.com
O1 - Hosts: 81.149.88.127 blocklist.winmxgroup.net
O1 - Hosts: 81.149.88.127 blocklist-master.winmxgroup.net
O1 - Hosts: 81.149.88.127 flooders.block-list.winmxgroup.com
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O21 - SSODL: sysdx - {42EAF0A0-CE8F-4B1F-823E-AF64EE7AE7D8} - C:\WINDOWS\sysdx.dll
O21 - SSODL: msvb - {44ADA429-076F-4AA6-A6C7-4ACFA35E4569} - C:\WINDOWS\msvb.dll
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe