1
   

My comp has been Hijaked!!! - Lots O problems - Help?

 
 
Reply Sun 4 Jul, 2004 01:35 am
I have a feeling I have a TON of issues on my comp right now. I have just downloaded hijackthis and just made a log (i think i did it right). Somehow my norton has gone, gone. It dissapeared. And my latest problem is what appears to be a dialer, but keeps me from the internet. I can connect, but I soon get booted. I have a feeling im infested!!!

any help would be appreciated. I have both ad-aware and spybot and have run them both on many many occasions. I have also tried removing somethings I know are dialers or some type of something and they continue to come back.

Thanks in advance....

Here is the Hijack This log...

Logfile of HijackThis v1.98.0
Scan saved at 2:25:13 AM, on 7/4/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\ieee.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\INTRIG~1\pcbodyguard.exe
C:\documents and settings\daniel\local settings\temp\noGlrf.exe
C:\documents and settings\daniel\local settings\temp\Yn.exe
C:\WINDOWS\system32\ntji32.exe
C:\WINDOWS\system32\wintime.exe
C:\WINDOWS\System32\NDrv.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Documents and Settings\Daniel\Desktop\Antispyware\HiJackThis\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,C:\WINDOWS\System32\svcpack.exe
O2 - BHO: Yahoo! Companion BHO - {02478D28-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\common\ycomp5_0_8_6.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {8B1469AF-1D1F-652F-B133-940712E0812C} - C:\WINDOWS\apppl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\common\ycomp5_0_8_6.dll
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [tgcmdprovidersbc] C:\Documents and Settings\Daniel\Local Settings\Temp\CMINST\SPRT\vault\tg\tgcmd.exe /server /startmonitor /deaf /nosystray
O4 - HKLM\..\Run: [iehelper] C:\Program Files\syslaunch.exe
O4 - HKLM\..\Run: [PCBG] C:\PROGRA~1\INTRIG~1\pcbodyguard.exe /start
O4 - HKLM\..\Run: [noGlrf] C:\documents and settings\daniel\local settings\temp\noGlrf.exe
O4 - HKLM\..\Run: [Yn] C:\documents and settings\daniel\local settings\temp\Yn.exe
O4 - HKLM\..\Run: [Bakra] C:\Corel Draw Install\CorelDraw10\Corel\Graphics10\Register\IEHost.exe
O4 - HKLM\..\Run: [ntji32.exe] C:\WINDOWS\system32\ntji32.exe
O4 - HKLM\..\Run: [AutoLoaderxwt01WMSLRLJ] "C:\WINDOWS\System32\loaeacct.exe" /PC="AM.WILD" /HideUninstall
O4 - HKLM\..\Run: [WinTime] C:\WINDOWS\system32\wintime.exe
O4 - HKLM\..\Run: [x32i3qR] loaeacct.exe
O4 - HKLM\..\RunOnce: [ieee.exe] C:\WINDOWS\ieee.exe
O4 - HKLM\..\RunOnce: [crni.exe] C:\WINDOWS\crni.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q
O4 - HKCU\..\Run: [Iinl] C:\Documents and Settings\Daniel\Application Data\iptl.exe
O4 - HKCU\..\Run: [NDrv] C:\WINDOWS\System32\NDrv.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll
O9 - Extra button: TREND MICRO HouseCall - {2B5EA4F8-620A-4A8B-B003-4C8C5EBEA826} - http://uk.trendmicro-europe.com/enterprise/products/housecall_pre.php (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Programs\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone: *.masspass.com
O15 - Trusted Zone: *.mt-download.com
O16 - DPF: ConferenceRoom Java Client - http://webmaster.webchat.org/java/cr.cab
O16 - DPF: Video Poker - http://download.games.yahoo.com/games/clients/y/vpt0_x.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Gin - http://download.games.yahoo.com/games/clients/y/nt1_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt0_x.cab
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - ms-its:mhtml:file://C:\ss.MHT!http://toolbar.isearch.com/install/00003/chm.chm::/files/initial.cab
O16 - DPF: {405BBF5B-2FD8-4614-AC51-D8566F635B94} (SafeWallet Class) - http://idsm.citadelprocessing.com/SafeCommon/downloads/WalletCab.CAB
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} - http://fdl.msn.com/public/chat/msnchat42.cab
O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
O16 - DPF: {8B6193F1-837F-11D4-89E6-0050DA666184} (Sol2axctl Class) - http://download.solitaire.com/download/solitaire.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} - http://www.pcpowerscan.com/pcpowerscan.cab
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - (no file)
O21 - SSODL: System - {B5EA17D6-90CD-44E8-AB06-9D02652522B0} - C:\WINDOWS\system32\system32.dll
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 2,003 • Replies: 8
No top replies

 
sellout007
 
  1  
Reply Sun 4 Jul, 2004 01:41 am
Oh forgot to add
These are some things that I know are causing me problems..

123792.dlr
dial32.exe
ntji32.exe
0 Replies
 
sellout007
 
  1  
Reply Wed 7 Jul, 2004 06:54 pm
can someone help me with this?
0 Replies
 
Craven de Kere
 
  1  
Reply Thu 8 Jul, 2004 01:09 pm
1) Download, install, update and run both SpyBot and AdAware

2) Let them fix what they find

3) Reboot.

4) Run a full system scan for a virus. Here are some suggestions:

AVG Free Scanner: http://www.grisoft.com/us/us_dwnl_free.php

McAffee Stinger:

http://vil.nai.com/vil/stinger/


Norton Security Scan (browser based)

http://security.symantec.com/sscv6/vc_scan.asp

5) Let them fix what they find.

6) Reboot

7) Post a fresh log
0 Replies
 
sellout007
 
  1  
Reply Thu 29 Jul, 2004 02:33 am
Ran both S&D and Adaware, also ran Stinger and CWShredder.

Here is my new hijack this log. Also, when I try and run HijackThis i get an error message. Both are below...


Logfile of HijackThis v1.98.0
Scan saved at 3:32:32 AM, on 7/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Yahoo!\browser\YBrowser.exe
C:\Documents and Settings\Daniel\Desktop\Antispyware\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\zsztj.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://zsztj.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://zsztj.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\zsztj.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\zsztj.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://zsztj.dll/index.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {F509D80A-8460-C897-E7E2-CDE2D55C3BD9} - C:\WINDOWS\system32\ipna32.dll
O4 - HKLM\..\Run: [ntji32.exe] C:\WINDOWS\system32\ntji32.exe
O4 - HKLM\..\Run: [ipna32.exe] C:\WINDOWS\system32\ipna32.exe
O4 - HKLM\..\RunOnce: [crls.exe] C:\WINDOWS\crls.exe
O4 - HKLM\..\RunOnce: [addvz32.exe] C:\WINDOWS\system32\addvz32.exe
O4 - HKLM\..\RunOnce: [apioc.exe] C:\WINDOWS\system32\apioc.exe
O4 - HKLM\..\RunOnce: [apimj.exe] C:\WINDOWS\system32\apimj.exe
O4 - HKLM\..\RunOnce: [appmz32.exe] C:\WINDOWS\appmz32.exe
O4 - HKLM\..\RunOnce: [winjm.exe] C:\WINDOWS\system32\winjm.exe
O4 - HKLM\..\RunOnce: [mfcqq.exe] C:\WINDOWS\mfcqq.exe
O4 - HKLM\..\RunOnce: [atllu32.exe] C:\WINDOWS\system32\atllu32.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O17 - HKLM\System\CCS\Services\Tcpip\..\{959EA12D-B1F2-409D-ACFF-587C9313462B}: NameServer = 206.141.192.60 206.141.193.55
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - (no file)






Here is the error message I recieve on HijackThis...


"An unexpected error has occurred at procedure: cmdFix_Click()
Error #75 - Path/File access error (21 items in results list)

Please email me at [email protected], reporting the following:
* What you were doing when the error occurred
* How you can reproduce the error
* A complete HijackThis scan log, if possible

Windows version: Windows NT 5.01.2600
MSIE version: 6.0.2800.1106
HijackThis version: 1.98.0

This message has been copied to your clipboard."


*sigh*
0 Replies
 
Craven de Kere
 
  1  
Reply Thu 29 Jul, 2004 03:08 am
sellout007 wrote:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\zsztj.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://zsztj.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://zsztj.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\zsztj.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\zsztj.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://zsztj.dll/index.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {F509D80A-8460-C897-E7E2-CDE2D55C3BD9} - C:\WINDOWS\system32\ipna32.dll


Fix


Quote:
O4 - HKLM\..\Run: [ntji32.exe] C:\WINDOWS\system32\ntji32.exe
O4 - HKLM\..\Run: [ipna32.exe] C:\WINDOWS\system32\ipna32.exe
O4 - HKLM\..\RunOnce: [crls.exe] C:\WINDOWS\crls.exe
O4 - HKLM\..\RunOnce: [addvz32.exe] C:\WINDOWS\system32\addvz32.exe
O4 - HKLM\..\RunOnce: [apioc.exe] C:\WINDOWS\system32\apioc.exe
O4 - HKLM\..\RunOnce: [apimj.exe] C:\WINDOWS\system32\apimj.exe
O4 - HKLM\..\RunOnce: [appmz32.exe] C:\WINDOWS\appmz32.exe
O4 - HKLM\..\RunOnce: [winjm.exe] C:\WINDOWS\system32\winjm.exe
O4 - HKLM\..\RunOnce: [mfcqq.exe] C:\WINDOWS\mfcqq.exe
O4 - HKLM\..\RunOnce: [atllu32.exe] C:\WINDOWS\system32\atllu32.exe


Fix, most should also be deleted.

Quote:
O17 - HKLM\System\CCS\Services\Tcpip\..\{959EA12D-B1F2-409D-ACFF-587C9313462B}: NameServer = 206.141.192.60 206.141.193.55
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - (no file)


Fix

Quote:
Here is the error message I recieve on HijackThis...


If the baddies are disabling it I can't do much to help you, but you can try removing the startup files through other means and can try deleting the bad files in safemode before running HJT again.
0 Replies
 
sellout007
 
  1  
Reply Thu 29 Jul, 2004 11:51 am
How would I go about removing them other then using HJT?
0 Replies
 
sellout007
 
  1  
Reply Thu 29 Jul, 2004 12:21 pm
I tried to just go to the system32 file in C:\ -- Windows, but they were not there.

I did find alot similar things.

advapi32.dll
avicap32.dll
avicap.dll
avifil32.dll
avifile.dll
cfgmgr32.dll
cmcfg32.dll
comctl32.dll
comdlg32.dll
Cpuinf32.dll
crypt32.dll
ctl3d32.dll
ctl3dv2.dll
drwtsn32
drwatson
extrac32
glu32.dll
glmf32.dll
iedkcs32.dll



Should those all be there?
0 Replies
 
Craven de Kere
 
  1  
Reply Thu 29 Jul, 2004 01:29 pm
Go to Start > Run > msconfig > Startup tab

I did not research each of those to see if they should be there or not, try the following steps:

1) Search about each of them, unless you find a clear example of it being legit proceed to step 2

2) back the file up on a cd or floppy and remove them, if problems arise put them back
0 Replies
 
 

Related Topics

YouTube Is Doomed - Discussion by Shapeless
So I just joined Facebook.... - Discussion by DrewDad
Internet disinformation overload - Discussion by rosborne979
Participatory Democracy Online - Discussion by wandeljw
OpenDNS and net neutrality - Question by Butrflynet
Internet Explorer 8? - Question by Pitter
 
  1. Forums
  2. » My comp has been Hijaked!!! - Lots O problems - Help?
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.03 seconds on 09/29/2024 at 08:18:55