Hijacker log -- Can anyone help?

MacGyverMacGyver Canada New
edited May 2004 in Spyware & Virus Removal
Here's my log.
I'm having alot of computer problems right now, and I don't know what files I should delete out of this. Any help is appreciated!



Logfile of HijackThis v1.97.7
Scan saved at 6:16:51 PM, on 29/05/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Documents and Settings\Tyler\My Documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hotmail.com/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Freedom Popup Killer - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\Freedom\pkR.dll
O2 - BHO: (no name) - {4BCF322B-9621-4e90-9678-F1424EB7584E} - C:\WINDOWS\udpmod.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Freedom BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [APIMon] C:\WINDOWS\System32\apimon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msmc.exe
O4 - HKCU\..\Run: [Freedom] C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: ICQ 4.0 (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt2_x.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5AF8C104-41AC-4E7E-98DD-E70CB953354F}: NameServer = 206.47.244.52 206.47.244.79

Comments

  • shwaipshwaip bluffin' with my muffin Icrontian
    edited May 2004
    do you have the latest version of spybot S&D installed, as well as the latest update? I see that you have SDHelper running, which indicates that you have a version installed. Also, have you tried running adaware?

    Both are available from the link in my sig.
  • Straight_ManStraight_Man Geeky, in my own way Naples, FL Icrontian
    edited May 2004
    O17 - HKLM\System\CCS\Services\Tcpip\..\{5AF8C104-41AC-4E7E-98DD-E70CB953354F}: NameServer = 206.47.244.52 206.47.244.79

    Quarantine this! If things still work, delete later, if not, restore it, should not be needed.
    these are not servers I can even FIND from here with traceroute. That entry will redirect your web access through those servers-- they could send you anywhere from when your box asks them where to go to find sites with that entry there. Possible DNS hijacking. My HJT, with valid DNS NameServers in place, does not list a 017 at all, on my XP box.
  • vanagon40vanagon40 Indiana Member
    edited May 2004
    msmc.exe may be spyware (Clientman????)

    I would get confirmation before removing though.
  • MacGyverMacGyver Canada New
    edited May 2004
    shwaip wrote:
    do you have the latest version of spybot S&D installed, as well as the latest update? I see that you have SDHelper running, which indicates that you have a version installed. Also, have you tried running adaware?

    Both are available from the link in my sig.

    Yeah, I have them both.
    Neither can seem to take off the **** I keep getting.
    Ads are over-taking sections of websites that never used to be there, I think it's MessageBroadcaster that's doing it, but I can't take it off. Also, everytime I log on, WebsiteViewer keeps bringing up a porn site. I take it out everytime, but it never goes away.
  • shwaipshwaip bluffin' with my muffin Icrontian
    edited May 2004
    here ya go...i thought that was you reposting your log:

    remove the following in safe mode:

    O2 - BHO: (no name) - {4BCF322B-9621-4e90-9678-F1424EB7584E} - C:\WINDOWS\udpmod.dll
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msmc.exe

    then delete the file udpmod.dll
  • MacGyverMacGyver Canada New
    edited May 2004
    shwaip wrote:
    here ya go...i thought that was you reposting your log:

    remove the following in safe mode:

    O2 - BHO: (no name) - {4BCF322B-9621-4e90-9678-F1424EB7584E} - C:\WINDOWS\udpmod.dll
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msmc.exe

    then delete the file udpmod.dll

    How come I have to do this in Safe Mode?
  • shwaipshwaip bluffin' with my muffin Icrontian
    edited May 2004
    some of them may be in use if do this in "normal" mode, and therefore you won't be able to delete them.
  • MacGyverMacGyver Canada New
    edited May 2004
    shwaip wrote:
    some of them may be in use if do this in "normal" mode, and therefore you won't be able to delete them.

    Oh ok!
    Thanks, i'll try it!
  • MacGyverMacGyver Canada New
    edited May 2004
    That porn thing still comes up everytime I log in. :mean:
  • shwaipshwaip bluffin' with my muffin Icrontian
    edited May 2004
    the problem appears to be in apimon.exe. do you have a virus-scan that you can run?

    if not...download avg from here:
    http://www.grisoft.com/us/us_index.php
  • MacGyverMacGyver Canada New
    edited May 2004
    Schwaip: You're a ****in' GENIUS!
    I deleted the apimon.exe thing, and now the porn thing is gone.
    Thanks so much! How did you figure that out?

    I have an anti-virus, but for some reason, the whole program keeps saying that there is an error opening the dat file, and then won't open. I'm using FREEDOM from Sympatico. I tried taking it off, and re-installing it, but that doesn't help. What could be going on?
  • LeonardoLeonardo Wake up and smell the glaciers Eagle River, Alaska Icrontian
    edited May 2004
    I don't know how to fix your AV program other than to uninstall it and reinstall it.

    Actually, I'd try AVG - freeware for home use, and very good; better than some commercial, pay-for software.
  • shwaipshwaip bluffin' with my muffin Icrontian
    edited May 2004
    MacGyver wrote:
    Schwaip: You're a ****in' GENIUS!
    I deleted the apimon.exe thing, and now the porn thing is gone.
    Thanks so much! How did you figure that out?

    lots of google searching :)

    Glad to help.
Sign In or Register to comment.