home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Ask a Tech Support Question (free)!

I been hijacked !

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 2037
Discussions: 200,503, Posts: 2,374,345, Members: 245,827
Old March 26th, 2007, 05:17 PM   Digg it!   #1 (permalink)
Junior Member
 
Join Date: Mar 2004
Posts: 6
I been hijacked !

Ok noticed this problem for about a week and came here to read up on what is needed to fix ... Hi I need help here is my hijack this log file

Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\WINDOWS\explorer.exe
C:\DOCUME~1\dad\LOCALS~1\Temp\Temporary Directory 1 for hijackthis_199.zip\HijackThis.exe
1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...p=ZNxmk788KUUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.downloadcontrol.com/files...reeInstall.cab
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/service_c...ex/TmHcmsX.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://sympatico.zone.msn.com/bingam...jolauncher.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/dim2/def...ploader_v6.cab
O16 - DPF: {F7B91BD4-2325-47E1-8EBD-AA4262C577A5} - http://www.ikbtws.com/download/traffix.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{09DD7503-3E84-4AE2-9AE9-10927EB4C0D7}: NameServer = 85.255.116.25,85.255.112.94
O17 - HKLM\System\CCS\Services\Tcpip\..\{41B869D8-A32B-4DA7-B941-2E4ADE54A2CD}: NameServer = 85.255.116.25,85.255.112.94
O17 - HKLM\System\CCS\Services\Tcpip\..\{711218DB-7804-41A0-BD6D-24A81048B747}: NameServer = 85.255.116.25,85.255.112.94
O17 - HKLM\System\CCS\Services\Tcpip\..\{7415842B-785A-43AB-9847-815EBD9EBF76}: NameServer = 85.255.116.25,85.255.112.94
O17 - HKLM\System\CCS\Services\Tcpip\..\{8AEC986E-C7F6-4115-AFEB-15F9696B022A}: NameServer = 85.255.116.25,85.255.112.94
O17 - HKLM\System\CCS\Services\Tcpip\..\{C8A03B72-36A5-4C74-8F62-C57FB4BB6894}: NameServer = 85.255.116.25,85.255.112.94
O17 - HKLM\System\CS1\Services\Tcpip\..\{09DD7503-3E84-4AE2-9AE9-10927EB4C0D7}: NameServer = 85.255.116.25,85.255.112.94
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

I have deinstalled all the old java updates and found an i-search gladiator program hiding in one of them which I got out.
I can not do disk clean-ups, searches, and Ad-Aware SE locks up every time in the temp internet files at a certain point everytime so please tell me what to look for as I will be reading other posts here and seeing if there is anything I can do in the mean time.

Thanks ahead of time for the help
relaxedman is offline   Reply With Quote
Old March 26th, 2007, 05:29 PM     #2 (permalink)
Ultimate Member
 
Milwaukee's Avatar
 
Join Date: Apr 2006
Location: ????????
Posts: 1,271
Hey try that http://free.grisoft.com/softw/70free...p-7.5.0.50.exe
__________________
sorry for my bad grammar!
Milwaukee is offline   Reply With Quote
Old March 26th, 2007, 06:41 PM     #3 (permalink)
SoMuchAnime-SoLittleTime
 
EXreaction's Avatar
 
Join Date: Aug 2003
Location: Plymouth, WI
Posts: 14,972
Blog Entries: 1
Send a message via MSN to EXreaction
Bad ones I noticed:
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...p=ZNxmk788KUUS
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
Unknown
O16 - DPF: {F7B91BD4-2325-47E1-8EBD-AA4262C577A5} - http://www.ikbtws.com/download/traffix.cab

Also, if you did not manually configure your IP address settings, fix all of the O17 stuff.
__________________
My photography: Flickr

Lithium Studios - phpBB3, PHP, and Web Development
EXreaction is offline   Reply With Quote
Old March 26th, 2007, 07:04 PM     #4 (permalink)
Junior Member
 
Join Date: Mar 2004
Posts: 6
What about the R1's ?
oh and when I do a yahoo search for anything I get
PC-illin a warning that it's a dangerous page with the following address given

http://85.255.119.186/frame.php

Oh and when I do my ADware scan I stop on the following spot everytime
C:\Documents and Settings\dad/Local Settings\Temp\Temporary Internet Files\Content.IE5\KPAJK917
I do a search on this and I get a windows error and it kicks me out everytime.

Last edited by relaxedman : March 26th, 2007 at 07:38 PM.
relaxedman is offline   Reply With Quote
Old March 26th, 2007, 07:47 PM     #5 (permalink)
SoMuchAnime-SoLittleTime
 
EXreaction's Avatar
 
Join Date: Aug 2003
Location: Plymouth, WI
Posts: 14,972
Blog Entries: 1
Send a message via MSN to EXreaction
Ok, then it sounds like the problem is from all those O17's I mentioned. Someone is making you go through their proxy (could be recording anything you send, including passwords and other sensitive data).

Then install Crap Cleaner and run it.
http://www.filehippo.com/download/df...a0eb/download/
EXreaction is offline   Reply With Quote
Old March 26th, 2007, 08:43 PM     #6 (permalink)
Junior Member
 
Join Date: Mar 2004
Posts: 6
Well the cleaner got me to where I can do scans now and I don't get that warning when I use a search engine so thank you

if anyone sees stuff on there that also needs to get blocked/taken off please let me know
relaxedman is offline   Reply With Quote
Old March 27th, 2007, 12:17 AM     #7 (permalink)
Ultimate Member
 
kenboyles72's Avatar
 
Join Date: Aug 2004
Location: Gladewater, TX
Posts: 1,189
Send a message via MSN to kenboyles72
Delete these (bad):

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...p=ZNxmk788KUUS

This is QuickTime Installer, safe to delete or fix.
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe

The following point to xbox.dedi.inhoster.com, this may be you ISP. If you do not recognize this, delete/fix it.

O17 - HKLM\System\CCS\Services\Tcpip\..\{09DD7503-3E84-4AE2-9AE9-10927EB4C0D7}: NameServer = 85.255.116.25,85.255.112.94

O17 - HKLM\System\CCS\Services\Tcpip\..\{41B869D8-A32B-4DA7-B941-2E4ADE54A2CD}: NameServer = 85.255.116.25,85.255.112.94

O17 - HKLM\System\CCS\Services\Tcpip\..\{711218DB-7804-41A0-BD6D-24A81048B747}: NameServer = 85.255.116.25,85.255.112.94

O17 - HKLM\System\CCS\Services\Tcpip\..\{7415842B-785A-43AB-9847-815EBD9EBF76}: NameServer = 85.255.116.25,85.255.112.94

O17 - HKLM\System\CCS\Services\Tcpip\..\{8AEC986E-C7F6-4115-AFEB-15F9696B022A}: NameServer = 85.255.116.25,85.255.112.94

O17 - HKLM\System\CCS\Services\Tcpip\..\{C8A03B72-36A5-4C74-8F62-C57FB4BB6894}: NameServer = 85.255.116.25,85.255.112.94

O17 - HKLM\System\CS1\Services\Tcpip\..\{09DD7503-3E84-4AE2-9AE9-10927EB4C0D7}: NameServer = 85.255.116.25,85.255.112.94
kenboyles72 is offline   Reply With Quote
Old March 27th, 2007, 01:58 AM     #8 (permalink)
Member
 
Join Date: Apr 2006
Location: Illinois
Posts: 195
Send a message via AIM to FRANKSnBEANS Send a message via MSN to FRANKSnBEANS
FRANKSnBEANS is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
Please help, hijacked by spyware!! dlpetey General Tech Discussion 9 October 31st, 2005 12:34 AM
am i hijacked? simbob Applications and Operating Systems 2 June 10th, 2005 09:39 PM
IE hijacked rex028 Technical Support 5 April 7th, 2005 07:51 AM
hijacked by nowfind ad5mb Security and Privacy Issues 5 March 13th, 2005 01:18 AM
Immediate Help. network hijacked? blubomber General Tech Discussion 5 February 1st, 2005 04:37 PM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (1624)
FT HOOD attack: 7 killed 12 injured (60)
HELP!!! What do you think of this s.. (14)
Looking for a graphic card that wil.. (30)
Assosiations (21495)
My 1st pc build (39)
Aero in Vista (7)
core i7 extreme 975, nvidia 9400gt (9)
Motherboards and my curse... (24)
PC Modern Warfare 2: it's much wors.. (12)
Building my first computer (13)
How to Ship a PC (16)
slaving laptop drive (7)
[F@H SPAM 11/1/09]New month . . . n.. (33)
Recent Discussions
Freezing During Music/Movies (1)
Windows Experience Index is screwed u.. (2)
My 1st pc build (39)
Internet very slow since updating AVG.. (4)
ext. sound card laptop to stereo syst.. (2)
Remote Desktop via SSH and error mess.. (2)
HELP!!! What do you think of this sys.. (14)
Help and Support disappeared from my .. (0)
FAT32 to NTFS file system in Win2kpro (1)
[F@H SPAM 11/1/09]New month . . . new.. (33)
Basic applications needed for "r.. (1)
core i7 extreme 975, nvidia 9400gt (9)
hard drive problem (2)
Win7 TrustedInstaller Permissions (2)
Speed up Win 7 boot time a bit (1)
Hard Drive test program (2)
wireless westell versalink model 327w (1)
New build 10 second reboot cycle! Won.. (3)
New Linksys Routers (2)
sometime power/Amber light (0)
Motherboards and my curse... (24)
Mic won't work. (2)
Weird Vista Internet Issue (2)
1st ever Harddisk benchmark thread (87)
high network traffic (0)


All times are GMT -4. The time now is 09:44 PM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28