Options

I have a intruder...

Some azzhole just took control of my machine...Is there something that you can see in my HJT file that is causing this. Thanks for your time...

Logfile of HijackThis v1.99.1
Scan saved at 4:19:38 PM, on 2/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: IeHelper Class - {A491D208-B353-490F-B81A-A8A3DC97042D} - C:\WINDOWS\system32\smiehlp.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1133541168879
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://cdn.messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Comments

  • TroganTrogan London, UK
    edited February 2006
    Your log is clean.

    What problems are you having? And how do you know for sure someone has taken over?

    You have a Firewall which is the best protection against hackers.
  • edited February 2006
    Your log is clean.

    What problems are you having? And how do you know for sure someone has taken over?

    You have a Firewall which is the best protection against hackers.

    My mouse started moving and they started to open programs and going thru my start button....that's when I unplugged my internet cable...the only other thing I can think of is I had MSN Messenger 7.5 running...is there some kind of exploit with msn messenger?

    thanks
  • TroganTrogan London, UK
    edited February 2006
    EDIT:\\ Before doing the following, check to see how the computer is doing. If its still acting strange then the best thing to do would be a System Restore.

    Strange! I don't think its MSN...

    Can you do the following


    Please download the trial version of Ewido Security Suite here:
    http://www.ewido.net/en/download/
    Install it, and update the definitions to the newest files. Do NOT run a scan yet.
    Next, please reboot your computer in Safe Mode by doing the following:
    1) Restart your computer
    2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
    3) Instead of Windows loading as normal, a menu should appear
    4) Select the first option, to run Windows in Safe Mode.

    For additional help in booting into Safe Mode, see the following site:
    http://www.pchell.com/support/safemode.shtml

    Once in Safe Mode, please run Ewido (Do not use the computer while Ewido is scanning as it may interrupt the scan)
    • Click on scanner
    • Click Complete System Scan and the scan will begin.
    • NOTE: During some scans with ewido it is finding cases of false positives.
    • You will need to step through the process of cleaning files one-by-one.
    • If ewido detects a file you KNOW to be legitimate, select none as the action.
    • DO NOT select "Perform action on all infections"
    • If you are unsure of any entry found select none for now.
    • When the scan is finished, click the Save report button at the bottom of the screen.
    • Save the report to your desktop
    Close Ewido

    Restart your computer in normal mode and please post log from the Ewido scan.
  • ArmoArmo Mr. Nice Guy Is Dead,Only Aqua Remains Member
    edited February 2006
    this crap happened to me last night, i had about 4 programs installed remotely on my computer used by R_ADMIN service or remote admin. odds are thats whats going on with you as well. first things first, is to disable remote administration in windows. to do this from your desktop right clikc my computer and go to properties-> Remote, and turn off remote assistance. Next is to do a google search on all of your running processes, you can check them by the old ALT+CTRL+DEL, you'll want to google search all of your services and make sure that YOU or windows installed them, i knew somehting was fishy when i sae a FTPServUDaemon.exe service running.

    also you can scan the services that start on your computer my clicking start->run->type MSCONFIG ( dosnt have to be in caps ) and click the servies tab. this area shows what services start when windows logs in. you want to look for somthing out of the ordinary. if you dont know what it is, do a google search on the service it will give you some good information.


    next is to scour your registries for any installed admin program, click start->run->and type regedit ( !!!WARNING!!! this is the registries for the copmputer, its the base that windows runs off of, only delete things that you know its safe to get rid of. ) and go to edit->find and in the find box you want to search for any of the services you need to get rid of.

    i solved my problem by doing a system restore from about a week ago, it got rid of all of the services and registry keys for the programs that the user in Amsterdam installed on my machine.

    also dont delete any servies untill you tell us what they are, just to make sure that windows will start up again if you tunr them off. also what ive deen doing for about 4 hours is watching the task manager ( cause it stays on top of your windows ) for any new processes that feel like they need to load, that how i spotted R_ADMIN.EXE service kick off, you'll want to focus on the user nam of SYSTEM, those are the servics that windows has control of starting and stopping. also Itunes has like 3 services, the itunesrv, itunes helper and 1 called gearsec, that through me off untill i did resaerch on them.

    heres the link for my post.
    http://www.short-media.com/forum/showthread.php?p=354620#post354620
  • edited February 2006
    yes...remote assistant was on..but I turned it off. I don't see any of the other stuff that you are talking about.

    Here is my log from ewido
    ewido anti-malware - Scan report

    + Created on: 7:52:57 PM, 2/4/2006
    + Report-Checksum: 21189FD

    + Scan result:

    HKLM\SOFTWARE\Classes\CLSID\{9F95F736-0F62-4214-A4B4-CAA6738D4C07} -> Spyware.SaveNow : Ignored
    HKLM\SOFTWARE\Classes\Interface\{C285D18D-43A2-4AEF-83FB-BF280E660A97} -> Spyware.SaveNow : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@as1.falkag[2].txt -> Spyware.Cookie.Falkag : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@atdmt[1].txt -> Spyware.Cookie.Atdmt : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@data3.perf.overture[1].txt -> Spyware.Cookie.Overture : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@ehg-bestbuy.hitbox[1].txt -> Spyware.Cookie.Hitbox : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@ehg-bskyb.hitbox[2].txt -> Spyware.Cookie.Hitbox : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@ehg-dig.hitbox[2].txt -> Spyware.Cookie.Hitbox : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@ehg-nvidia.hitbox[2].txt -> Spyware.Cookie.Hitbox : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@ehg-researchinmotion.hitbox[2].txt -> Spyware.Cookie.Hitbox : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@hitbox[2].txt -> Spyware.Cookie.Hitbox : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@partygaming.122.2o7[1].txt -> Spyware.Cookie.2o7 : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@perf.overture[1].txt -> Spyware.Cookie.Overture : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@pmads.valuead[1].txt -> Spyware.Cookie.Valuead : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@questionmarket[2].txt -> Spyware.Cookie.Questionmarket : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@server.iad.liveperson[2].txt -> Spyware.Cookie.Liveperson : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@www.myaffiliateprogram[1].txt -> Spyware.Cookie.Myaffiliateprogram : Ignored
    C:\Documents and Settings\timmer\Cookies\timmer@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Ignored
    C:\Program Files\180SearchAssistant -> Spyware.180Solutions : Ignored
    C:\Program Files\whInstall -> Adware.Webhancer : Ignored
    C:\Program Files\whInstall\Sporder.dll -> Adware.Webhancer : Cleaned with backup


    ::Report End
  • ArmoArmo Mr. Nice Guy Is Dead,Only Aqua Remains Member
    edited February 2006
    hmm. none of that stuff can do what your describing. i appologize for my spelling im on my web fone.

    do you use any remote software lilke a vnc client?

    thjat or remote administration are all i can think of that would cause thaty sort of action. how many times has this happebnend
  • edited February 2006
    It's happened twice in the last couple of months...must be some sort of bug planted on my harddrive somewhere...i've had msn running both times it happened.

    thanks for your help
  • TroganTrogan London, UK
    edited February 2006
    Good Luck with everything.

    Make sure your Firewall is enabled at ALL times.

    Have a look for a report log or something from your Firewall and check to see if anything suspicious is listed.
Sign In or Register to comment.