Jump to content


Photo

Very Tricky Hijack(I'm NOT new to this)


  • Please log in to reply
1 reply to this topic

#1 DeLouvellier

DeLouvellier

    Member

  • New Member
  • Pip
  • 2 posts

Posted 29 June 2004 - 12:21 AM

Hello!
I'm having a bit of trouble locating a problem which is causing sporatic browser redirections. This problem also causes random fake "404" error messages, and prevents various images from loading correctly on web pages, which is annoying.
I'm not an expert, but I'm not new to this kind of thing either. CWShredder can't find anything, nor can Adaware or Spybot S&D. I thought it may have been related to a DSO Exploit issue, but I have since repaired the reg entries and the problems still come up. To me, my Hijackthis logfile appears to be clear, but I'll post it anyway in case an expert here can see something I missed a hundred times.
If there isn't anything here, I can post a startup log too.
Thanks.


Logfile of HijackThis v1.97.7
Scan saved at 1:17:03 AM, on 6/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\csrss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\SOUNDMAN.EXE
F:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe
F:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe
F:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe
F:\WINDOWS\System32\RUNDLL32.EXE
F:\Program Files\Saitek\Software\Profiler.exe
F:\WINDOWS\System32\rundll32.exe
F:\Program Files\Saitek\Software\SaiSmart.exe
F:\WINDOWS\System32\Optmouse.exe
F:\Program Files\Trend Micro\PC-cillin 2002\WebTrap.EXE
F:\WINDOWS\System32\nvsvc32.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
F:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
F:\Program Files\MSI\Live Update 3\LMonitor.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\MSN Messenger\msnmsgr.exe
F:\Documents and Settings\Matto\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - F:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [pccguide.exe] "F:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "F:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "F:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Profiler] F:\Program Files\Saitek\Software\Profiler.exe
O4 - HKLM\..\Run: [SaiSmart] F:\Program Files\Saitek\Software\SaiSmart.exe
O4 - HKLM\..\Run: [OPTMOUSEMOUSE] F:\WINDOWS\System32\Optmouse.exe
O4 - HKLM\..\Run: [LiveMonitor] F:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [Evidence Eliminator] F:\Program Files\Evidence Eliminator\ee.exe /m
O4 - HKCU\..\Run: [MsnMsgr] "F:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKLM\..\RunOnce: [hhctrl.ocx] F:\WINDOWS\System32\regsvr32 /s F:\WINDOWS\System32\hhctrl.ocx
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) - http://tw.msi.com.tw...nt/iftwclix.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...8162.7216898148
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab

#2 DeLouvellier

DeLouvellier

    Member

  • New Member
  • Pip
  • 2 posts

Posted 29 June 2004 - 03:23 PM

9th page? :thumbsdown:
Bump.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button