Site Statistics
 
Threads: 4,062
Posts: 17,767
Members: 3,097
Users Online: 8
Newest Member: ronjohnson715


Go Back   PC101 > Computer Related Forums > PC Security

PC Security A place to discuss new threats, firewalls, virus scanners, and all other aspects of keeping your computer secure from threats. Learn how to stop spyware... hackers ... identity thieves... and more!


Reply
 
LinkBack Thread Tools Display Modes
Old 11-03-2006, 01:03 PM   #1
Junior
 
Join Date: Mar 2006
Posts: 176
Rep Power: 3 eeeboy is on a distinguished road
Exclamation Browser Hijack

One of my neighbors suddenly called me yesterday as he was facing some problem after clicking a link came to him through mail . From that , he could not open "run" or task manager. So , I suggested him to Install Hijackthis ,and to send me the log. I have got the log. I am bit confused about this log. need your help look at this.

Code:
Logfile of HijackThis v1.99.1
Scan saved at 23:38:18, on 11/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
D:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\PROGRA~1\DAP\DAP.EXE
C:\DOCUME~1\admin\LOCALS~1\Temp\svhost.exe
C:\WINDOWS\system32\rundll32.exe
E:\dls\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://nsl-school.org
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [DU Meter] D:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [Task Manager] C:\WINDOWS\svhost32.exe
O4 - HKLM\..\Run: [svchost] C:\WINDOWS\svhost.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Download with &DAP - D:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - D:\PROGRA~1\DAP\dapextie2.htm
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - D:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{29FDAA12-E675-44B7-AF7A-26D0FD0B7623}: NameServer = 202.40.176.12 202.40.176.13
O17 - HKLM\System\CS1\Services\Tcpip\..\{29FDAA12-E675-44B7-AF7A-26D0FD0B7623}: NameServer = 202.40.176.12 202.40.176.13
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
is there any process named svhost.exe which runs from temp ? I knew svchost.exe run by SYSTEM. anyway , Is there other malicious something?

than in Advance

regards

eeeboy
eeeboy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-04-2006, 02:07 PM   #2
Professor
 
Join Date: Jul 2005
Posts: 2,208
Rep Power: 6 Will.Spencer is on a distinguished road
You are exactly correct, that svchost.exe is actually the RBOT.QG worm.

Also, DAP.EXE promoted itself as a "download accellerator", but it's really annoying adware.

And why is RegEdit disabled in the registry?
Will.Spencer is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft, Mozilla look into browser flaws Lyte PC Security 0 02-19-2007 06:39 PM
Your favorite browser? JustNewbie Software 33 12-28-2006 12:40 PM
What browser is best? sinja PC & Tech Related News, Events and More! 46 08-07-2006 03:49 PM
The World Fastest Browser kamesh PC & Tech Related News, Events and More! 22 07-23-2006 02:21 PM
Making your own web browser in Visual Basic imported_krish Software Development 3 06-05-2006 07:10 PM



All times are GMT -5. The time now is 04:33 AM.

Powered by vBulletin Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0 RC5