Jump to content


hijacked (and possibly screwed!?)

  • Please log in to reply
1 reply to this topic

#1 trag



  • New Member
  • Pip
  • 2 posts

Posted 27 June 2004 - 06:12 PM

My coworker is having a problem with his pc. I figured I would post up his hijackthis log and perhaps someone can help me figure it out.

I know the R1 entries are all screwed up. I've deleted them, but they keep coming back over and over. I'm not sure how to get them to stop.

xpkec.dll and mxogc.dll are two dlls that keep coming back no matter what I do, even when I delete them straight out of the registry. I ran Spybot and AdAware, and these dlls are still coming back.

Drop a line if anyone has an idea on what the prob is. Thanks a bunch.


Logfile of HijackThis v1.97.7
Scan saved at 6:11:04 PM, on 6/27/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WASTE\WASTE.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\aschuman\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\xpkec.dll/sp.html#22776
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://xpkec.dll/index.html#22776
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://xpkec.dll/index.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\xpkec.dll/sp.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://xpkec.dll/index.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\xpkec.dll/sp.html#22776
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://by18fd.bay18....2e77e1&fti=yes"); (C:\Documents and Settings\aschuman\Application Data\Mozilla\Profiles\default\e8hwey2q.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\aschuman\Application Data\Mozilla\Profiles\default\e8hwey2q.slt\prefs.js)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2E9CAFF6-30C7-4208-8807-E79D4EC6F806} - C:\Program Files\Submit\submithook.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {C3B52B2A-75CE-35EA-B7CE-0FE89E685E1F} - C:\WINDOWS\system32\ipvf32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [apphe32.exe] C:\WINDOWS\apphe32.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Ad-aware] C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe +c
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKLM\..\RunOnce: [iexp32.exe] C:\WINDOWS\system32\iexp32.exe
O4 - HKLM\..\RunOnce: [mfcrv.exe] C:\WINDOWS\mfcrv.exe
O4 - HKLM\..\RunOnce: [ipln32.exe] C:\WINDOWS\ipln32.exe
O4 - HKLM\..\RunOnce: [mfcnc32.exe] C:\WINDOWS\system32\mfcnc32.exe
O4 - HKLM\..\RunOnce: [crxv32.exe] C:\WINDOWS\crxv32.exe
O4 - HKLM\..\RunOnce: [iepy.exe] C:\WINDOWS\iepy.exe
O4 - HKLM\..\RunOnce: [addbi.exe] C:\WINDOWS\system32\addbi.exe
O4 - HKLM\..\RunOnce: [d3bh.exe] C:\WINDOWS\system32\d3bh.exe
O4 - HKLM\..\RunOnce: [javaxx.exe] C:\WINDOWS\javaxx.exe
O4 - HKLM\..\RunOnce: [sdkyt32.exe] C:\WINDOWS\sdkyt32.exe
O4 - HKLM\..\RunOnce: [sdkua.exe] C:\WINDOWS\system32\sdkua.exe
O4 - HKLM\..\RunOnce: [wintx.exe] C:\WINDOWS\wintx.exe
O4 - HKLM\..\RunOnce: [ntgs.exe] C:\WINDOWS\system32\ntgs.exe
O4 - HKLM\..\RunOnce: [winhd.exe] C:\WINDOWS\system32\winhd.exe
O4 - HKLM\..\RunOnce: [appuy32.exe] C:\WINDOWS\appuy32.exe
O4 - HKLM\..\RunOnce: [mfcug32.exe] C:\WINDOWS\system32\mfcug32.exe
O4 - HKLM\..\RunOnce: [netqg32.exe] C:\WINDOWS\system32\netqg32.exe
O4 - HKLM\..\RunOnce: [d3vk32.exe] C:\WINDOWS\d3vk32.exe
O4 - HKLM\..\RunOnce: [sdkbb.exe] C:\WINDOWS\sdkbb.exe
O4 - Startup: Map Drive for alienbrain.lnk = C:\WINDOWS\SYSTEM32\MapDrive.exe
O4 - Startup: WASTE.lnk = C:\Program Files\WASTE\WASTE.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)

#2 trag



  • New Member
  • Pip
  • 2 posts

Posted 27 June 2004 - 06:55 PM

bump... still looking for some help. thanks a lot.

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button