Help - Search - Members
Full Version: HijackThis Log Analys plz
Piriform Community Forums > Computer Help and Discussion > Spyware Hell
A--Viper
Logfile of HijackThis v1.99.1
Scan saved at 10:57:59, on 01.9.2005 г.
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
c:\windows\system32\wshield.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Outlook Express\msimn.exe
E:\Essentials\Tools\ANTI\7.hijackthis\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [Userinterface Report3r] M0USE.exe
O4 - HKLM\..\Run: [element furth] c:\windows\system32\repcale.exe c:\windows\system32\palzp.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\RunServices: [Userinterface Report3r] M0USE.exe
O4 - HKLM\..\RunServices: [System Service] iexplroer.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Userinterface Report3r] M0USE.exe
O4 - HKCU\..\Run: [DynAdvance Notifier] D:\TEMP\MailNotifier.Exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O17 - HKLM\System\CCS\Services\Tcpip\..\{E8B970CA-1801-405C-97F5-CF99287B5CE7}: NameServer = 193.200.15.133,193.200.15.129
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe


As long as I understand the only problem is:

O4 - HKLM\..\RunServices: [System Service] iexplroer.exe

which is a virus that I send to AVG and now my Free AVG Heal it, but start refference is alive.

Anything other stuff to be removed ?
rridgely
That line is bad but so is this:
O4 - HKLM\..\Run: [Userinterface Report3r] M0USE.exe
http://castlecops.com/s10095-M0USE_exe.html
Its part of the mytob worm.

Please run this online scanner and remove everything it finds:
http://housecall60.trendmicro.com/en/start_corp.asp?id=scan

Also do everything on this site as well.
http://downloads.locias.com/cleaning.html

Then post a new log after and only after you have done everything.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.