Hey guys. I was on a fantasy football website and something change state down my AVG and started going crazy on downloads. I started AVG back up and it identifies like 8 different malicious downloaders. Please help! Logfile of HijackThis v1.99.1Scan saved at 3:44 on 2007-08-21Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\system32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\svchost exeC:\WINDOWS\system32\spoolsv exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard exeC:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch exeC:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan exeC:\Program Files\Analog Devices\SoundMAX\SMAgent exeC:\Program Files\Viewpoint\Common\ViewpointService exeC:\Program Files\Intel\Intel(R) Active Monitor\imonnt exeC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr exeC:\Program Files\Analog Devices\SoundMAX\SMax4PNP exeC:\Program Files\Intel\Intel(R) Active Monitor\imontray exeC:\Program Files\QuickTime\qttask exeC:\Program Files\Logitech\MouseWare\system\em_exec exeC:\schedule Files\Common Files\Real\Update_OB\realsched exeC:\schedule Files\Grisoft\AVG Anti-Spyware 7.5\avgas exeC:\schedule Files\Java\jre1.5.0_11\bin\jusched exeC:\Program Files\Windows NT\quzema22011 exeC:\Program Files\Messenger\msmsgs exec:\windows\system32\lmdsrngq exeC:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr exeC:\PROGRA~1\COMMON~1\CROSOF~1. NET\javaw exeC:\WINDOWS\System32\svchost exeC:\Program Files\Web Buying\v1.8.2\webbuying exeC:\Program Files\?racle\ati2evxx exeC:\WINDOWS\System32\rundll32 exeC:\Program Files\Java\jre1.5.0_11\bin\jucheck exeC:\WINDOWS\explorer exeC:\Program Files\internet explorer\iexplore exeC:\schedule Files\hijackthis\HijackThis exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = O3 - Toolbar: &communicate - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm ocxO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP exeO4 - HKLM\..\Run: [Logitech Utility] Logi_MwX. ExeO4 - HKLM\..\Run: [IMONTRAY] C:\schedule Files\Intel\Intel(R) Active Monitor\imontray exeO4 - HKLM\..\Run: [QuickTime Task] "C:\schedule Files\QuickTime\qttask exe" -atboottimeO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\modify_OB\realsched exe" -osbootO4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\schedule Files\Grisoft\AVG Anti-Spyware 7.5\avgas exe" /minimizedO4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\schedule Files\Java\jre1.5.0_11\bin\jusched exe"O4 - HKLM\..\Run: [{EF-FC-CC-CD-ZN}] c:\windows\system32\lmdsrngq exe CHD003O4 - HKLM\..\Run: [quzema] C:\Program Files\Windows NT\quzema22011 exeO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs exe" /backgroundO4 - HKCU\..\Run: [Walgreens PhotoShow Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr exeO4 - HKCU\..\Run: [Odba] "C:\PROGRA~1\COMMON~1\CROSOF~1. NET\javaw exe" -vt yazbO4 - HKCU\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.8.2\webbuying exeO4 - HKCU\..\Run: [Kelsnryy] "C:\Program Files\?racle\ati2evxx exe"O4 - HKCU\..\Run: [WinPop] C:\Program Files\WinPop\winpop exeO4 - Startup: TA_Start lnk = C:\WINDOWS\system32\lmdsrngq exeO4 - Startup: Think-Adz lnk = C:\WINDOWS\system32\mwinnmdt exeO4 - Global Startup: Adobe Reader go Launch lnk = C:\schedule Files\Adobe\Acrobat 7.0\Reader\reader_sl exeO4 - Global Startup: QuickBooks 2001 Delivery Agent lnk = C:\schedule Files\apprehend\QuickBooks Pro\Components\QBAgent\qbdagent2001 exeO4 - Global Startup: QuickBooks modify Agent lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate exeO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL. EXE/3000O9 - Extra button: (no label) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\schedule Files\Java\jre1.5.0_11\bin\ssv dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv dllO9 - Extra add: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel exe (file missing)O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel exe (file missing)O9 - Extra button: investigate - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR. DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS. EXEO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\schedule Files\Messenger\MSMSGS. EXEO9 - Extra add: ProfitCents - {55CDE34F-44BF-4F3B-B117-990D070C5991} - (file missing) (HKCU)O9 - Extra 'Tools' menuitem: ProfitCents - {55CDE34F-44BF-4F3B-B117-990D070C5991} - (file missing) (HKCU)O12 - Plugin for spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
Forex Groups - Tips on Trading
Related article:
http://www.cybertechhelp.com/forums/showthread.php?t=163161
comments | Add comment | Report as Spam
|