smitfraud-c
Posted by ~Ray @ 2007-10-17 14:38:29
here is the logfile re smitfraud-cLogfile of HijackThis v1.99.1Scan saved at 2:10:24 PM on 9/13/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\system32\csrss exeC:\WINDOWS\system32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\svchost exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\system32\spoolsv exeC:\WINDOWS\Explorer. EXEC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\alg exeC:\WINDOWS\system32\hkcmd exeC:\WINDOWS\system32\wuauclt exeC:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1. EXEC:\schedule Files\OpenOffice org 2.1\program\soffice exeC:\Program Files\OpenOffice org 2.1\program\soffice. BINC:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32 exeC:\schedule Files\Internet Explorer\IEXPLORE. EXEC:\WINDOWS\system32\dllhost exeC:\WINDOWS\system32\msdtc exeC:\WINDOWS\system32\f02WtR\f02WtR1065 exec:\windows\system32\dwdsrngt exeC:\WINDOWS\system32\twinnldt exeC:\schedule Files\Web Buying\v1.8.3\webbuying exeC:\schedule Files\Messenger\hobyqa22011 exeC:\WINDOWS\retadpu1000106 exeC:\WINDOWS\SnVkeQ\dominate exeC:\WINDOWS\system32\f02WtR\f02WtR1065 exeC:\WINDOWS\system32\rundll32 exeC:\Program Files\Internet Explorer\IEXPLORE. EXEC:\Documents and Settings\Judy\Desktop\HijackThis exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)O4 - HKLM\..\Run: [SoundMAXPnP] C:\schedule Files\Analog Devices\Core\smax4pnp exeO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd exeO4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers exeO4 - HKLM\..\Run: [SunJavaUpdateSched] C:\schedule Files\Java\jre1.5.0_03\bin\jusched exeO4 - HKLM\..\Run: [QuickTime Task] "C:\schedule Files\QuickTime\qttask exe" -atboottimeO4 - HKLM\..\Run: [ISUSPM Startup] "C:\schedule Files\Common Files\InstallShield\UpdateService\isuspm exe" -startupO4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch exe" -startO4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv exeO4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud exeO4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\schedule Files\Microsoft Works\WksSb exe /AllUsersO4 - HKLM\..\Run: [Microsoft Works modify Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind exeO4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct exe /uninstallO4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck exeO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\modify_OB\realsched exe" -osbootO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper exe"O4 - HKLM\..\Run: [Adobe Reader go Launcher] "C:\schedule Files\Adobe\Reader 8.0\Reader\Reader_sl exe"O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost exe"O4 - HKLM\..\Run: [hobyqa] C:\schedule Files\Messenger\hobyqa22011 exeO4 - HKLM\..\Run: [{82-2B-BB-BF-ZN}] c:\windows\system32\dwdsrngt exe CHD003O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\twinnldt exe CHD003O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu1000106 exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - examine & undo\SpybotSD.[ADVERTHERE]Related article:
http://www.geekstogo.com/forum/index.php?showtopic=170734
0 Comments:
No comments have been posted yet!
|