HiJack this.. need help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Needinhelpfast, Jun 29, 2004.

  1. Needinhelpfast

    Needinhelpfast Private E-2

    Ok, I started out doing a search for downloader.agent.bf, and found this website. I have this crazy thing on my machine and I am ready to pull my hair out. It took me a while to figure out how to get that hijack log I read so much about, but I finally got it and scanned my machine... Here is my log... Please help, I work off of this computer and I am so far behind because of this...

    Logfile of HijackThis v1.98.0
    Scan saved at 5:08:17 PM, on 6/29/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\WINDOWS\System32\LXSUPMON.EXE
    C:\WINDOWS\javaam32.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\ACT\SideACT.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\Grisoft\AVG6\AVGCC32.EXE
    C:\Program Files\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ujksx.dll/sp.html#26980
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ujksx.dll/index.html#26980
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ujksx.dll/index.html#26980
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\ujksx.dll/sp.html#26980
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ujksx.dll/sp.html#26980
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ujksx.dll/index.html#26980
    R3 - Default URLSearchHook is missing
    F0 - system.ini: Shell=
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
    O2 - BHO: (no name) - {CDD3C145-875B-3A3F-8949-B02CBCD81C33} - C:\WINDOWS\system32\atlqk.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
    O4 - HKLM\..\Run: [javaam32.exe] C:\WINDOWS\javaam32.exe
    O4 - HKLM\..\RunOnce: [ntfy.exe] C:\WINDOWS\system32\ntfy.exe
    O4 - HKLM\..\RunOnce: [sdkrz32.exe] C:\WINDOWS\sdkrz32.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: SideACT!.lnk = C:\Program Files\ACT\SideACT.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{9D0160D4-4588-4750-937F-E0AAD087A53E}: NameServer = 207.69.188.187 207.69.188.186
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds