| | | 
New Member
         
Group: Forum Members Last Login: 1/22/2004 3:54 AM Posts: 9, Visits: 1 |
| Hi,
I am a bit worried about www.couldnotfind.com, there is probabely more as well
Logfile of HijackThis v1.97.7 Scan saved at 19:05:47, on 13/12/2003 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\unldrexe.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe C:\windows\system32\win32gb.exe C:\windows\system32\mscnt.exe C:\WINDOWS\System32\ctfmon.exe C:\WINDOWS\System32\atievxx.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Messenger\msmsgs.exe C:\Documents and Settings\Nicholas Yu.PIKACHU\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=132702 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=132702 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start-site.co.uk R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=132702 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start-site.co.uk R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaults/sb/*http://www.yahoo.com/ext/search/search.html R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchgateway.net/search/%s R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.start-site.co.uk/ F1 - win.ini: run=c:\windows\system32\unldrexe.exe O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - C:\WINDOWS\bi.dll (disabled by BHODemon) O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: Yahoo! Companion BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\Program Files\Yahoo!\Companion\ycomp5_0_2_4.dll O2 - BHO: OpinionBar IE monitor - {6607C683-AE7C-11D4-ACD7-0050DAC291A2} - C:\PROGRA~1\OPINIO~1\MyIEMonitor.dll O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\ycomp5_0_2_4.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\PERFECT SERIES\The Complete Mouse List\4.0\lwb3dapp.exe O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe O4 - HKLM\..\Run: [win32gb] c:\windows\system32\win32gb.exe /noconnect O4 - HKLM\..\Run: [Mscnt] c:\windows\system32\mscnt.exe /noconnect O4 - HKLM\..\Run: [Belt] C:\WINDOWS\Belt.exe O4 - HKLM\..\Run: [31171816.exe] C:\WINDOWS\System32\31171816.exe O4 - HKLM\..\Run: [99450320.exe] C:\WINDOWS\System32\99450320.exe O4 - HKLM\..\Run: [Unldrexe] c:\windows\system32\unldrexe.exe O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [SpySweeper] D:\NTLWebroot\Spy Sweeper\SpySweeper.exe /0 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: PersTray.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM) O9 - Extra button: ICQ Pro (HKLM) O9 - Extra 'Tools' menuitem: ICQ (HKLM) O12 - Plugin for .png: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/bcd48c18cb7498/housecall.antivirus.com/housecall/xscan53.cab O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/essentials/ymmapi_0727.dll O16 - DPF: {A9FD89D6-C839-11D3-B0FE-0050044B8FE9} (OBInstallRunner Control) - http://www.opinionbar.com/download/resources/OBInstallCabinet.CAB O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/1d/player.virtools.com/downloads/player/Install2.1/Installer.exe O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab
Nando |
| | | | 
Senior Forum Advisor
         
Group: Senior Advisor Last Login: 12/4/2005 12:31 AM Posts: 4,743, Visits: 5 |
| Hi Nando, welcome.
Yes, there is quite a bit more. 
Have Hijack This fix the following by placing a check in the appropriate boxes and selecting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=132702 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=132702 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start-site.co.uk R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=132702 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start-site.co.uk R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchgateway.net/search/%s R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.start-site.co.uk/ F1 - win.ini: run=c:\windows\system32\unldrexe.exe O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - C:\WINDOWS\bi.dll (disabled by BHODemon) O4 - HKLM\..\Run: [win32gb] c:\windows\system32\win32gb.exe /noconnect O4 - HKLM\..\Run: [Mscnt] c:\windows\system32\mscnt.exe /noconnect O4 - HKLM\..\Run: [Belt] C:\WINDOWS\Belt.exe O4 - HKLM\..\Run: [31171816.exe] C:\WINDOWS\System32\31171816.exe O4 - HKLM\..\Run: [99450320.exe] C:\WINDOWS\System32\99450320.exe O4 - HKLM\..\Run: [Unldrexe] c:\windows\system32\unldrexe.exe
Reboot to safe mode and delete: How to start your computer in safe mode
c:\windows\system32\win32gb.exe <-- file c:\windows\system32\mscnt.exe <-- file C:\WINDOWS\Belt.exe <-- file C:\WINDOWS\System32\31171816.exe <-- file C:\WINDOWS\System32\99450320.exe <-- file
This next one seems funky and I cannot find much info on it. c:\windows\system32\unldrexe.exe <-- file Could you please locate it, right click > sendto > compressed (zipped) folder and then mail it: >>THIS MAIL ADDRESS<< It may indeed be a new nasty. It would be appreciated. Thank-You.
NOTE: To avoid the risk of any of the above not being found due to them having the 'Hidden' attribute, first make sure that in Folder Options > View hidden and operating system files are set to show: How to Show Hidden/System Files http://www.xtra.co.nz/help/0,,4155-1916458,00.html
Also: Did you wittingly install OPINIONBAR ?
Download CWShredder: http://www.spywareinfo.com/~merijn/files/cwshredder.zip Unzip, run and hit the ->next tab to fix all found problems Reboot.
Please post a fresh HJT log when done. /
Cheers
|
| | | | 
New Member
         
Group: Forum Members Last Login: 1/22/2004 3:54 AM Posts: 9, Visits: 1 |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start-site.co.uk R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start-site.co.uk R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.start-site.co.uk/
Do I really need to check the above.
Start-Site.co.UK is the Portal I use and this is harmless. Let me know what you think and why I should get rid of this
Nando |
| | | | 
Senior Forum Advisor
         
Group: Senior Advisor Last Login: 12/4/2005 12:31 AM Posts: 4,743, Visits: 5 |
| [QUOTE=Nando]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start-site.co.uk R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start-site.co.uk R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.start-site.co.uk/
Do I really need to check the above.
Start-Site.co.UK is the Portal I use and this is harmless. Let me know what you think and why I should get rid of this
[/QUOTE]
Just leave them, or reset them when you open IE again.
.
Cheers
|
| | | | 
Senior Forum Advisor
         
Group: Senior Advisor Last Login: 12/4/2005 12:31 AM Posts: 4,743, Visits: 5 |
|
F1 - win.ini: run=c:\windows\system32\unldrexe.exe O4 - HKLM\..\Run: [Unldrexe] c:\windows\system32\unldrexe.exe
Downloader.Crypter.A virus found in attachment by AVG.
Cheers
|
| |
|
|