Home / Software / Computer viruses and spyware / clicked random .cn php link
0 Members and 2 Guests are viewing this topic. « previous next »
Pages: 1 2 [All] - (Bottom) Print
Author Topic: clicked random .cn php link  (Read 2293 times)
deere1ee7
Guest
« on: July 26, 2007, 02:19:26 PM »

Yeah so i was browsing WoW Forums and accidentally went on some links leading to php scripts -__-

Need someone who knows what his doing to check out my hijackthis log

Heres what i get from HiJackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:38:42, on 26/07/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\PnkBstrA.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\JetAudio\jetAudio.exe
C:\Documents and Settings\gamboo\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner\RivaTuner.exe" /S
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [SpybotDeletingA8090] command /c del "C:\Program Files\BearShare\BSidle.dll_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9592] cmd /c del "C:\Program Files\BearShare\BSidle.dll_tobedeleted_old"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\RunOnce: [SpybotDeletingB1731] command /c del "C:\Program Files\BearShare\BSidle.dll_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1706] cmd /c del "C:\Program Files\BearShare\BSidle.dll_tobedeleted_old"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Shortcut to SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/229?5c533e70d42145ba891fde4c38291a8b
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/230?5c533e70d42145ba891fde4c38291a8b
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Unknown owner - C:\Program Files\Ares\chatServer.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\System32\PnkBstrB.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Common Files\wuoqyjigu.html

--
End of file - 5792 bytes

Thanks btw :)
IP logged
unlovedwarrior
Guru



Thanked: 13
Posts: 3,818

someday this name will be known

« Reply #1 on: July 26, 2007, 02:55:19 PM »

first off why do you only have sp1 not sp2? what protections are you running? are expenicing any problems if os what kind
IP logged
deere1ee7
Guest
« Reply #2 on: July 26, 2007, 03:28:37 PM »

I choose not to have SP2 because it creates lag for a FPS game I play this also applies for security programs so I don't have them running but I do scan with them now and then or when i think I have fallen for some form of spyware but I cant exactly trust software to such a extent and so feel like getting a HiJackThis log checked.

I also wouldn't be able to check whether they have tried attaining my details for world of warcraft after the scan and removal of spyware found on spybot and AVG since I straight away contacted someone trustworthy on phone to change my details for me via the game's website after I had clicked the link.

There may not be something suspicous in the HiJackThis log but knowing the link was a blatant key logger and not trusting software to its full extent I would really appreciate it if someone with the general experience could check the log for me.
IP logged
unlovedwarrior
Guru



Thanked: 13
Posts: 3,818

someday this name will be known

« Reply #3 on: July 26, 2007, 03:40:13 PM »

well i have sp2 and my wow works fine, but you should never install sp2 on an infected machine what protection programs do you have
IP logged
deere1ee7
Guest
« Reply #4 on: July 26, 2007, 04:01:47 PM »

sorry but I am not sure what you mean by protection programs, could you please go into more detail
IP logged
unlovedwarrior
Guru



Thanked: 13
Posts: 3,818

someday this name will be known

« Reply #5 on: July 26, 2007, 04:09:54 PM »

anti-virus anti-spyware/malware firewall etc
IP logged
deere1ee7
Guest
« Reply #6 on: July 26, 2007, 04:20:20 PM »

free versions of AVG Anti Virus and StopZilla but I choose to use AVG only for scans
IP logged
unlovedwarrior
Guru



Thanked: 13
Posts: 3,818

someday this name will be known

« Reply #7 on: July 26, 2007, 04:23:33 PM »

then y have stopzilla?? google
trend mivro house call and see what that finds
IP logged
deere1ee7
Guest
« Reply #8 on: July 26, 2007, 04:45:12 PM »

sorry for the inconvenience but during the first scan my browser closed halfway through it and now when attempt to try again it keeps closing after i accept to do a scan. my specs matched the minimum requirements so I am not quite sure why this happened but I am happy enough to try an alternative site if you have one in mind
IP logged
Deerpark
Egghead



Thanked: 1
Posts: 2,908




« Reply #9 on: July 26, 2007, 04:48:01 PM »

Kaspersky is supposedly pretty good.

Panda ActiveScan also got a good reputation
IP logged

Any sufficiently advanced technology is indistinguishable from magic.
Arthur C. Clarke (1917 - 2008)
deere1ee7
Guest
« Reply #10 on: July 26, 2007, 04:54:19 PM »

yeah i started a panda scan before i made my previous post and here are the results

;*********************************************************
ANALYSIS: 2007-07-26 23:53:34
PROTECTIONS: 0
MALWARE: 9
SUSPECTS: 0
;*********************************************************
PROTECTIONS
Description                                  Version                       Active    Updated
;==========================================
;==========================================
MALWARE
Id        Description                        Type                Active    Severity  Disinfectable  Disinfected Location
;==========================================
00139061  Cookie/Doubleclick                 TrackingCookie      No        0         Yes            No           C:\Documents and Settings\gamboo\Application Data\Mozilla\Firefox\Profiles\h2owhgth.default\cookies.txt[.doubleclick.net/]
00139064  Cookie/Atlas DMT                   TrackingCookie      No        0         Yes            No           C:\Documents and Settings\gamboo\Application Data\Mozilla\Firefox\Profiles\h2owhgth.default\cookies.txt[.atdmt.com/]
00145731  Cookie/Tribalfusion                TrackingCookie      No        0         Yes            No           C:\Documents and Settings\gamboo\Application Data\Mozilla\Firefox\Profiles\h2owhgth.default\cookies.txt[.tribalfusion.com/]
00145738  Cookie/Mediaplex                   TrackingCookie      No        0         Yes            No           C:\Documents and Settings\gamboo\Application Data\Mozilla\Firefox\Profiles\h2owhgth.default\cookies.txt[.mediaplex.com/]
00167642  Cookie/Com.com                     TrackingCookie      No        0         Yes            No           C:\Documents and Settings\gamboo\Application Data\Mozilla\Firefox\Profiles\h2owhgth.default\cookies.txt[.com.com/]
00170304  Cookie/WebtrendsLive               TrackingCookie      No        0         Yes            No           C:\Documents and Settings\gamboo\Application Data\Mozilla\Firefox\Profiles\h2owhgth.default\cookies.txt[statse.webtrendslive.com/]
00235842  Application/RealSpy                HackTools           No        0         Yes            No           C:\WINDOWS\system32\actskn45.ocx
00379781  Adware/Yazzle                      Adware              No        0         No             No           C:\WINDOWS\system32\lo.exe[¦++\Yazzle1396OinAdmin.exe]
00504058  Adware/Yazzle                      Adware              No        0         Yes            No           C:\WINDOWS\system32\lo.exe
;==========================================
SUSPECTS
Location
;==========================================

[Post edited to avoid stretching the page.]
« Last Edit: July 26, 2007, 08:00:17 PM by CBMatt » IP logged
unlovedwarrior
Guru



Thanked: 13
Posts: 3,818

someday this name will be known

« Reply #11 on: July 26, 2007, 05:06:28 PM »

could you remove them ?
IP logged
deere1ee7
Guest
« Reply #12 on: July 26, 2007, 05:11:16 PM »

nope the membership costs
IP logged
CBMatt
Mod & Malware Specialist
Prodigy



Thanked: 160
Posts: 6,033

Experience: Experienced
OS: Windows 7


Sad and lonely...and loving every minute of it.

1
« Reply #13 on: July 26, 2007, 07:57:04 PM »

I see that you have HijackThis running from your desktop.  You have it in a permanent location, which is good because it makes important backups that you may end up needing.  However, to help you avoid clutter and to help ensure that the backups stay safe, I would like you to move it to a special location.
  • Double-click on My Computer to open it and navigate to C:\Program Files.
  • Right-click on the empty (white) space and go to New > Folder.
  • Name the folder something like HJT and move HijackThis into that new folder.
  • If you would still like to run HijackThis from the desktop for convenience, right-click on HijackThis and click on Create Shortcut.  This will create a shortcut to the program; move the shortcut to the desktop.
 

You should open HijackThis and close all other windows.  Scan and place a checkmark next to the following...

O4 - HKLM\..\RunOnce: [SpybotDeletingA8090] command /c del "C:\Program Files\BearShare\BSidle.dll_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9592] cmd /c del "C:\Program Files\BearShare\BSidle.dll_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1731] command /c del "C:\Program Files\BearShare\BSidle.dll_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1706] cmd /c del "C:\Program Files\BearShare\BSidle.dll_tobedeleted_old"

O24 - Desktop Component 0: (no name) - C:\Program Files\Common Files\wuoqyjigu.html


Then go ahead and click on Fix Checked.  Then update your AVG and then reboot into Safe Mode.  Perform a full scan and enable hidden files and folders.  If they still exist, delete the following files...

C:\Program Files\BearShare\BSidle.dll_tobedeleted_old
C:\Program Files\Common Files\wuoqyjigu.html
C:\WINDOWS\system32\actskn45.ocx
C:\WINDOWS\system32\lo.exe


Restart your computer and post back with your results and how things are running, as well as a fresh HijackThis log.  Also...what are your specs?  SP2 shouldn't cause you any trouble with playing WoW.
« Last Edit: July 26, 2007, 08:09:20 PM by CBMatt » IP logged

Quote
An undefined problem has an infinite number of solutions.
—Robert A. Humphrey

Actually, the name's Chris...
patio
Moderator
Genius



Thanked: 1069
Posts: 11,354

Experience: Beginner
OS: Windows 7


Maud' Dib

« Reply #14 on: July 28, 2007, 02:46:59 PM »

I think you're spinning your wheels trying to diagnose this without having SP2....

It is a MAJOR OS upgrade not just a security patch as everyone likes to think.

Personally i wouldn't waste any more time without updating XP Period.
IP logged

   
"
All generalizations are false, including this one.  "
deere1ee7
Guest
« Reply #15 on: July 31, 2007, 05:27:21 AM »

Sorry for not showing this forum thread an eye for the last couple of days I had a holiday, well the AVG scan in safe mode found no threats so I guess I am clear :)

Also SP2 creates lag for RTCW: Enemy Territory.

Thanks for all the help.
IP logged
CBMatt
Mod & Malware Specialist
Prodigy



Thanked: 160
Posts: 6,033

Experience: Experienced
OS: Windows 7


Sad and lonely...and loving every minute of it.

1
« Reply #16 on: July 31, 2007, 07:33:29 PM »

Again, I'm wondering what your specs are.  Also, what kind of connection you have.
Enemy Territory runs pretty smoothly on my computer with SP2.  The only thing that has ever caused me lag is my connection.
IP logged

Quote
An undefined problem has an infinite number of solutions.
—Robert A. Humphrey

Actually, the name's Chris...
patio
Moderator
Genius



Thanked: 1069
Posts: 11,354

Experience: Beginner
OS: Windows 7


Maud' Dib

« Reply #17 on: August 01, 2007, 06:16:10 PM »

Both games you mentioned have Forums and not many references to trouble with SP2...
I agree with CBMatt.
IP logged

   
"
All generalizations are false, including this one.  "
CBMatt
Mod & Malware Specialist
Prodigy



Thanked: 160
Posts: 6,033

Experience: Experienced
OS: Windows 7


Sad and lonely...and loving every minute of it.

1
« Reply #18 on: August 12, 2007, 03:32:38 AM »

Due to lack of feedback, I am closing this topic.  If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
IP logged

Quote
An undefined problem has an infinite number of solutions.
—Robert A. Humphrey

Actually, the name's Chris...
Pages: 1 2 [All] - (Top) Print 
Home / Software / Computer viruses and spyware / clicked random .cn php link « previous next »
 


Login with username, password and session length

Old Forum Search | Forum Rules
Copyright © 2010 Computer Hope ® All rights reserved.
Powered by SMF 2.0 RC3 | SMF © 2006–2010, Simple Machines LLC
Page created in 0.137 seconds with 19 queries.