PDA

View Full Version : Please help....malware infection!



Scofield
2006-05-31, 15:15
Here is my HJT log.....Thanks a ton!

Logfile of HijackThis v1.99.1
Scan saved at 7:01:22 PM, on 5/30/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\atmclk.exe
C:\WINDOWS\System32\dcomcfg.exe
C:\WINDOWS\System32\68e8f6f7.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\gyu\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Nothing - {f79fd28e-36ee-4989-aa61-9dd8e30a82fa} - C:\WINDOWS\System32\hp100.tmp
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [68e8f6f7.exe] C:\WINDOWS\System32\68e8f6f7.exe
O4 - HKLM\..\RunOnce: [InnoSetupRegFile.0000000001] "C:\WINDOWS\is-EVCV5.exe" /REG
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [68e8f6f7.exe] C:\Documents and Settings\gyu\Local Settings\Application Data\68e8f6f7.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {666E4D35-E955-11D0-A707-000000521958} - http://ads.dropspam.com/landing/aac/upgrade.cab
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe

Scofield
2006-05-31, 23:49
I just re-read the "please read before posting" thread. I guess I'm not supposed to just post HJT logs...... I keep getting popups saying I have a critical system error and that my machine is loaded with spyware. I have the current, updated version of Spybot, ran a check, and fixed 11 entries. How should I proceed or is more info. needed? Thanks.

tashi
2006-06-01, 07:30
Hello Scofield :)

This a third computer correct?

http://forums.spybot.info/showthread.php?t=3429
http://forums.spybot.info/showthread.php?t=3674

The instructions in the sticky topic were to run an on-line anti virus scanner and then run Spybot-S&D in safe mode.

The topic also gave instructions that HJT should not be ran out of a temp folder or zip.
BEFORE you post a log, and who will advise you. Preliminary Steps (http://forums.spybot.info/showthread.php?t=288)

Please read:
You and Windows, a joint effort (http://forums.spybot.info/showpost.php?p=25290&postcount=4)

Cheers.

Scofield
2006-06-01, 18:03
Thanks Tashi....yes, this is my brothers computer that he's had running without any spyware protection or firewalls. I shall follow all the advice in the sticky threads and get back to you. Thanks again.

tashi
2006-06-01, 18:32
Ok, but do heed the warning in the sticky:
Have you updated Windows? Security Programs? Links and Tips. (http://forums.spybot.info/showthread.php?t=425)

However, you must ensure the computer is free of malware before you upgrade to Windows XP SP2 (Service Pack 2)

Cheers. :)

LonnyRJones
2006-06-05, 15:01
Hi

Can i see a fresh Hijackthis log with hijackthis in a folder of its own, provided it is unziped.

Scofield
2006-06-07, 23:41
Thanks for all your help everyone.....my brother has chosen to re-format his computer agains't my advice (I told him that you guys could fix it!) It's out of my hands. Again, thanks!

LonnyRJones
2006-06-08, 03:49
Thanks for letting us know, please ensure they get all updates as soon as windows is installed this time.