Jump to content


Photo

Dialer.9.N etc. (HiJackThis log)


  • Please log in to reply
1 reply to this topic

#1 imagino

imagino

    Member

  • New Member
  • Pip
  • 1 posts

Posted 19 July 2004 - 12:09 AM

I use daily updated antivirus AVG, Kerio firewall and sometimes Ad-Aware, CWShredder and SpyBot. Anyway trojan "Dialer.9.N" and "telnetxp.exe" (request for outgoing session) is trying nearly daily.

Thank you for your help.


Logfile of HijackThis v1.97.7
Scan saved at 0:37:01, on 19.7.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programy\AVG\avgamsvr.exe
C:\Programy\AVG\avgupsvc.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\Programy\Kerio\Personal Firewall 4\kpf4ss.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\Tablet.exe
C:\Programy\Kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\Explorer.EXE
C:\Programy\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Programy\GENIUS~1\mouseElf.exe
C:\Programy\AVG\avgcc.exe
C:\Programy\AVG\avgemc.exe
C:\Programy\FILEBA~1\FileBack.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Adobe\Acrobat\Distillr\acrotray.exe
C:\Programy\Extensis\Suitcase\Suitcase.exe
C:\Programy\Total Commander\TOTALCMD.EXE
C:\Programy\WinKey\WinKey.exe
C:\Programy\TheBat!\thebat.exe
c:\Programy\NoteTab Pro\NotePro.exe
C:\Programy\NetCaptor\NetCaptor.exe
C:\Program Files\Microsoft Office\Office10\EXCEL.EXE
C:\Programy\Mobile PhoneTools\mPhonetools.exe
C:\Programy\Corel 9\Programs\coreldrw.exe
C:\WINDOWS\System32\svchost.exe
C:\Inet\DirectConnect\!\CZDCPlusPlus.exe
c:\Programy\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: 3466690378 view.atdmt.com
O1 - Hosts: 3466690378 click.atdmt.com
O1 - Hosts: 3466690378 leader.linkexchange.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Adobe\Acrobat\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\Programy\FlashGet\jccatch.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Adobe\Acrobat\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {DFE47053-5FC6-4C7F-AC19-A1C4EF5D0067} - C:\WINDOWS\System32\mfplay.dll (file missing)
O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\System32\nzdd.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Programy\FlashGet\fgiebar.dll
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programy\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Net Snippets - {67970B26-F57D-4455-8262-81C3AE3B8B5E} - C:\Programy\NETSNI~1\NetSnip.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Adobe\Acrobat\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [mouseElf] C:\Programy\GENIUS~1\mouseElf.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\Programy\AVG\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\Programy\AVG\avgemc.exe
O4 - HKLM\..\Run: [AVG7_RegCleaner] C:\Programy\AVG\avgregcl.exe /BOOT
O4 - HKLM\..\Run: [FileBackPC] C:\Programy\FILEBA~1\FileBack.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Namedate] C:\Programy\Nezmeskej\nezmeskej.exe s s
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Adobe\Acrobat\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Suitcase Startup.lnk = ?
O4 - Global Startup: Total Commander 32.lnk = C:\Programy\Total Commander\TOTALCMD.EXE
O4 - Global Startup: WinKey.lnk = C:\Programy\WinKey\WinKey.exe
O8 - Extra context menu item: Add To Net Snippets - C:\Programy\NETSNI~1\Res\Clipper.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Programy\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Programy\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Programy\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Programy\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Stáhnout položku pomocí FlashGet - C:\Programy\FlashGet\jc_link.htm
O8 - Extra context menu item: Stáhnout všechny položky pomocí FlashGet - C:\Programy\FlashGet\jc_all.htm
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: Snippets (HKLM)
O9 - Extra button: FlashGet (HKLM)
O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.micros...tes/ieawsdc.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com...ex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macr...director/sw.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.micros...ontent/opuc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...8166.5736689815
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai...5/Installer.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DD6EC7DF-C48B-4BFC-99D6-1635307D2B8F}: NameServer = 160.218.10.201 194.228.2.1

#2 daveai

daveai

    Forum Deity

  • Retired Staff
  • PipPipPipPipPip
  • 1,214 posts

Posted 02 September 2004 - 11:06 PM

Thanks for sending your HijackThis logfile. We apologize for the delay in responding. The volunteers working here are swamped, and unfortunately some requests don't get ansered in a timely manner.

If you still need some help with your problem, please respond to this with a fresh HijackThis log.

I will be notified automatically when that happens.

Thanks
daveai
If you found our service worthwhile, and want to help keep SpwareInfo running please consider donating here.

"Applying computer technology is simply finding the right wrench to pound in the correct screw." Anonymous




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button