It is currently Tue Sep 01, 2026 4:30 pm


Hijackthis log...please help!

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Hijackthis log...please help!

Postby thug » Thu Nov 25, 2004 9:59 pm

I'm getting lots of pop-ups. Could someone tell me how to get rid of them? Log below. Thanks to all that reply.

Logfile of HijackThis v1.98.2
Scan saved at 2:55:50 PM, on 11/25/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\NMSSvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINNT\system32\searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/w/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
F1 - win.ini: run=C:\WINNT\..\PROGRA~1\COMMON~1\MICROS~1\MSInfo\msinfo.exe
O1 - Hosts: 216.200.3.32 worldsex.com
O1 - Hosts: 216.200.3.32 www.worldsex.com
O1 - Hosts: 216.200.3.32 sexocean.com
O1 - Hosts: 216.200.3.32 easypic.com
O1 - Hosts: 216.200.3.32 free6.com
O1 - Hosts: 216.200.3.32 al4a.com
O1 - Hosts: 216.200.3.32 www.al4a.com
O1 - Hosts: 216.200.3.32 thumbnailpost.com
O1 - Hosts: 216.200.3.32 www.thumbnailpost.com
O1 - Hosts: 216.200.3.32 drbizzaro.com
O1 - Hosts: 216.200.3.32 www.drbizzaro.com
O1 - Hosts: 216.200.3.32 hoes.com
O1 - Hosts: 216.200.3.32 www.hoes.com
O1 - Hosts: 216.200.3.32 absolut-series.com
O1 - Hosts: 216.200.3.32 www.absolut-series.com
O1 - Hosts: 216.200.3.32 elephantlist.com
O1 - Hosts: 216.200.3.32 www.elephantlist.com
O1 - Hosts: 216.200.3.32 ah-me.com
O1 - Hosts: 216.200.3.32 www.ah-me.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {DA4F48A8-5794-401F-A979-72C8A7B0DBEE} - C:\WINNT\system32\mbl.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINNT\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Forget Me Not.lnk = C:\Program Files\Broderbund\AG CreataCard\AGRemind.exe
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O18 - Filter: text/html - {CAD816CB-C6DC-45A3-826E-048BA282ADFA} - C:\WINNT\system32\mbl.dll
O18 - Filter: text/plain - {CAD816CB-C6DC-45A3-826E-048BA282ADFA} - C:\WINNT\system32\mbl.dll
O19 - User stylesheet: (file missing)
User avatar
thug
Geek in Training
Geek in Training
 
Posts: 22
Joined: Wed Mar 24, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby PCguy » Thu Nov 25, 2004 10:11 pm

Turn off System Restore. (Turn it back on after this is repaired and you've rebooted.)
(This would also include the “GoBack” Program if it is installed.)
Close all other open Windows and have HiJackThis Fix:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINNT\system32\searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/w/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
F1 - win.ini: run=C:\WINNT\..\PROGRA~1\COMMON~1\MICROS~1\MSInfo\msinfo.exe
O1 - Hosts: 216.200.3.32 worldsex.com
O1 - Hosts: 216.200.3.32 www.worldsex.com
O1 - Hosts: 216.200.3.32 sexocean.com
O1 - Hosts: 216.200.3.32 easypic.com
O1 - Hosts: 216.200.3.32 free6.com
O1 - Hosts: 216.200.3.32 al4a.com
O1 - Hosts: 216.200.3.32 www.al4a.com
O1 - Hosts: 216.200.3.32 thumbnailpost.com
O1 - Hosts: 216.200.3.32 www.thumbnailpost.com
O1 - Hosts: 216.200.3.32 drbizzaro.com
O1 - Hosts: 216.200.3.32 www.drbizzaro.com
O1 - Hosts: 216.200.3.32 hoes.com
O1 - Hosts: 216.200.3.32 www.hoes.com
O1 - Hosts: 216.200.3.32 absolut-series.com
O1 - Hosts: 216.200.3.32 www.absolut-series.com
O1 - Hosts: 216.200.3.32 elephantlist.com
O1 - Hosts: 216.200.3.32 www.elephantlist.com
O1 - Hosts: 216.200.3.32 ah-me.com
O1 - Hosts: 216.200.3.32 www.ah-me.com
O2 - BHO: (no name) - {DA4F48A8-5794-401F-A979-72C8A7B0DBEE} - C:\WINNT\system32\mbl.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O18 - Filter: text/html - {CAD816CB-C6DC-45A3-826E-048BA282ADFA} - C:\WINNT\system32\mbl.dll
O18 - Filter: text/plain - {CAD816CB-C6DC-45A3-826E-048BA282ADFA} - C:\WINNT\system32\mbl.dll
O19 - User stylesheet: (file missing)
(\__/) This is Bunny.
(='.'=) Copy and paste bunny into your sig.
(")_(") Help Bunny gain World Domination.

Image
User avatar
PCguy
Lord of the Geeks
Lord of the Geeks
 
Posts: 2017
Joined: Sat Sep 15, 2001 1:00 am
Location: A Very Scarey Place
Operating System:

Thanks given:2
Thanks received:4
Top

Postby PCguy » Thu Nov 25, 2004 10:14 pm

Make sure you delete all your tempory internet files as well.
(\__/) This is Bunny.
(='.'=) Copy and paste bunny into your sig.
(")_(") Help Bunny gain World Domination.

Image
User avatar
PCguy
Lord of the Geeks
Lord of the Geeks
 
Posts: 2017
Joined: Sat Sep 15, 2001 1:00 am
Location: A Very Scarey Place
Operating System:

Thanks given:2
Thanks received:4
Top

Postby thug » Thu Nov 25, 2004 10:45 pm

Alright...did what you said and still have the problem. More specifically whatever is messing up my computer is resetting my internet homepage to about:blank and then there is a pop-up from vv3.s13.topx.cc. Those are really the only problems. I ran hijackthis again and posted log below. Thanks for the help so far.

Logfile of HijackThis v1.98.2
Scan saved at 3:42:37 PM, on 11/25/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\wuauclt.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {CFE2E0A8-63C7-4D4A-96AC-BC2CE986D6ED} - C:\WINNT\system32\mbl.dll
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Forget Me Not.lnk = C:\Program Files\Broderbund\AG CreataCard\AGRemind.exe
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Filter: text/html - {29B8DF87-7B0B-4D31-BFCF-471F2422151C} - C:\WINNT\system32\mbl.dll
O18 - Filter: text/plain - {29B8DF87-7B0B-4D31-BFCF-471F2422151C} - C:\WINNT\system32\mbl.dll
User avatar
thug
Geek in Training
Geek in Training
 
Posts: 22
Joined: Wed Mar 24, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby PCguy » Fri Nov 26, 2004 4:23 am

You sitll have some nasties. And your homepage will be reset to blank when we are done with this. Once all the nasties are gone, set your homepage as needed.

Have HijackThis fix this:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
O2 - BHO: (no name) - {CFE2E0A8-63C7-4D4A-96AC-BC2CE986D6ED} - C:\WINNT\system32\mbl.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Filter: text/html - {29B8DF87-7B0B-4D31-BFCF-471F2422151C} - C:\WINNT\system32\mbl.dll
O18 - Filter: text/plain - {29B8DF87-7B0B-4D31-BFCF-471F2422151C} - C:\WINNT\system32\mbl.dll

Now delete these Folders or Files that are Highlighted: (You may need enable "Show all Files" and disable "Hide System Files" in Windows Explorer / Tools / Folder Options / View Tab) (You may have to boot to "Safe Mode" and rename them, in order to delete some Files/Folders) You may also have to do a search for find them as well.

C:\WINNT\system32\mbl.dll
C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

Now, empty all your TEMP Folders (WinXp has up to 4 of them) / Temporary Internet Files Folder and then empty your "Recycle Bin" and reboot.
(\__/) This is Bunny.
(='.'=) Copy and paste bunny into your sig.
(")_(") Help Bunny gain World Domination.

Image
User avatar
PCguy
Lord of the Geeks
Lord of the Geeks
 
Posts: 2017
Joined: Sat Sep 15, 2001 1:00 am
Location: A Very Scarey Place
Operating System:

Thanks given:2
Thanks received:4
Top

Postby liljim » Fri Nov 26, 2004 4:30 am

Run Aboutbuster

you can get it

After that, have hijack fix (if there still there)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {CFE2E0A8-63C7-4D4A-96AC-BC2CE986D6ED} - C:\WINNT\system32\mbl.dll
O18 - Filter: text/html - {29B8DF87-7B0B-4D31-BFCF-471F2422151C} - C:\WINNT\system32\mbl.dll
O18 - Filter: text/plain - {29B8DF87-7B0B-4D31-BFCF-471F2422151C} - C:\WINNT\system32\mbl.dll


Then go to C:\WINNT\system32 and delete mbl.dll
(You might have to do this in safe mode)
User avatar
liljim
Moderator
Moderator
 
Posts: 3017
Joined: Mon Mar 03, 2003 1:00 am
Location: Louisiana
Operating System:

Thanks given:0
Thanks received:12
Top

Postby liljim » Fri Nov 26, 2004 4:34 am

Sorry PCGuy,simultainous post
User avatar
liljim
Moderator
Moderator
 
Posts: 3017
Joined: Mon Mar 03, 2003 1:00 am
Location: Louisiana
Operating System:

Thanks given:0
Thanks received:12
Top

Postby PCguy » Fri Nov 26, 2004 4:36 am

Nice to see we are on the same page. :)
(\__/) This is Bunny.
(='.'=) Copy and paste bunny into your sig.
(")_(") Help Bunny gain World Domination.

Image
User avatar
PCguy
Lord of the Geeks
Lord of the Geeks
 
Posts: 2017
Joined: Sat Sep 15, 2001 1:00 am
Location: A Very Scarey Place
Operating System:

Thanks given:2
Thanks received:4
Top

Postby liljim » Fri Nov 26, 2004 4:39 am

"Great minds think alike"
User avatar
liljim
Moderator
Moderator
 
Posts: 3017
Joined: Mon Mar 03, 2003 1:00 am
Location: Louisiana
Operating System:

Thanks given:0
Thanks received:12
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron