My HijackThis Log

  • Thread starter Thread starter Andrew
  • Start date Start date
A

Andrew

For anyone who can help... I'm also going to be following some others'
suggestions and post this in some other forums as well.. just in case.

------------------------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 7:12:47 AM, on 3/22/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\d4fw41ta\d4fw41ta.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system\jgatupnxx.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\d4fw41ta\25231640.exe
C:\Documents and Settings\Andrew\Desktop\hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName
=
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [rtwgnx] c:\windows\system32\rtwgnx.exe
O4 - HKLM\..\Run: [d4fw41ta] C:\Program Files\d4fw41ta\d4fw41ta.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ap9h4qmo] C:\WINDOWS\System32\ap9h4qmo.exe
O4 - HKLM\..\Run: [etbrun] C:\windows\system32\eliteynl32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /
background
O4 - HKCU\..\Run: [EPSON Stylus C80 Series] C:
\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE /P23
"EPSON Stylus C80 Series" /O6 "USB001" /M "Stylus C80"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office10\OSA.EXE
O4 - Global Startup: Mobile User VPN.lnk = C:\Program
Files\WatchGuard\Mobile User VPN\SafeCfg.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program
Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:
\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop
Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows
Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?
linkid=36467&clcid=0x409
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://
a1540.g.akamai.net/7/1540/52/20041120/qtinstall.info.apple.com/
pthalo/us/win/QuickTimeFullInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl
Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/
en/x86/client/wuweb_site.cab?1097002918961
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control)
- http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader
Object) - http://download.games.yahoo.com/games/web_games/popcap/
insaniquarium/popcaploader_v6.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer =
10.1.1.80
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer =
10.1.1.80
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer =
10.1.1.80
O23 - Service: SafeNet Monitor Service (IPSECMON) - SafeNet - C:\Program
Files\WatchGuard\Mobile User VPN\IPSecMon.exe
O23 - Service: SafeNet IKE Service (IreIKE) - SafeNet - C:\Program
Files\WatchGuard\Mobile User VPN\IreIKE.exe
 
For anyone who can help... I'm also going to be following some others'
suggestions and post this in some other forums as well.. just in case.

<SNIP>

Andrew,

If you're multi-posting this (bad procedure BTW) you'll probably get a lot of
questions about:
C:\Program Files\d4fw41ta\d4fw41ta.exe
C:\WINDOWS\system\jgatupnxx.exe
C:\Program Files\d4fw41ta\25231640.exe
O4 - HKLM\..\Run: [rtwgnx] c:\windows\system32\rtwgnx.exe
O4 - HKLM\..\Run: [d4fw41ta] C:\Program Files\d4fw41ta\d4fw41ta.exe

This ia a bad one:
O4 - HKLM\..\Run: [ap9h4qmo] C:\WINDOWS\System32\ap9h4qmo.exe
http://www.superadblocker.com/A/AP9H4QMO.EXE-2503.html

CrossPost - Don't MultiPost
http://www.uwasa.fi/~ts/http/crospost.html
http://www.blakjak.demon.co.uk/mul_crss.htm

How about links to your other posts so we can all learn?
 
For anyone who can help... I'm also going to be following some others'
suggestions and post this in some other forums as well.. just in case.

<SNIP>

Andrew,

If you're multi-posting this (bad procedure BTW) you'll probably get a lot of
questions about:
C:\Program Files\d4fw41ta\d4fw41ta.exe
C:\WINDOWS\system\jgatupnxx.exe
C:\Program Files\d4fw41ta\25231640.exe
O4 - HKLM\..\Run: [rtwgnx] c:\windows\system32\rtwgnx.exe
O4 - HKLM\..\Run: [d4fw41ta] C:\Program Files\d4fw41ta\d4fw41ta.exe
O4 - HKLM\..\Run: [etbrun] C:\windows\system32\eliteynl32.exe

This ia a bad one:
O4 - HKLM\..\Run: [ap9h4qmo] C:\WINDOWS\System32\ap9h4qmo.exe
http://www.superadblocker.com/A/AP9H4QMO.EXE-2503.html

CrossPost - Don't MultiPost
http://www.uwasa.fi/~ts/http/crospost.html
http://www.blakjak.demon.co.uk/mul_crss.htm

How about links to your other posts so we can all learn?
 
For anyone who can help... I'm also going to be following some others'
suggestions and post this in some other forums as well.. just in case.

<SNIP>

Andrew,

Find as many of these modules as you can, and scan each at VirusTotal -
http://www.virustotal.com/flash/index_en.html. Use the Browse button at the top
to upload each module, if possible.

What are these?
C:\Program Files\d4fw41ta\d4fw41ta.exe
C:\WINDOWS\system\jgatupnxx.exe
C:\Program Files\d4fw41ta\25231640.exe
O4 - HKLM\..\Run: [rtwgnx] c:\windows\system32\rtwgnx.exe
O4 - HKLM\..\Run: [d4fw41ta] C:\Program Files\d4fw41ta\d4fw41ta.exe
O4 - HKLM\..\Run: [etbrun] C:\windows\system32\eliteynl32.exe

This ia a bad one:
O4 - HKLM\..\Run: [ap9h4qmo] C:\WINDOWS\System32\ap9h4qmo.exe
http://www.superadblocker.com/A/AP9H4QMO.EXE-2503.html

CrossPost - Don't MultiPost
http://www.uwasa.fi/~ts/http/crospost.html
http://www.blakjak.demon.co.uk/mul_crss.htm

How about links to your other posts so we can all learn?
 
I agree with Chuck as to the identity of the bad guys.

I like to boot into Safe Mode (F8) before I check/Fix
Checked them tho you can also try to use Pocket Killbox

http://www.bleepingcomputer.com/files/killbox.php

to stop the running programs

C:\Program Files\d4fw41ta\d4fw41ta.exe
C:\WINDOWS\system\jgatupnxx.exe
C:\Program Files\d4fw41ta\25231640.exe

without rebooting first and then do HijackThis. But often
a process from the same stable will regenerate its brother
process before you can kill them both.

O4 - HKLM\..\Run: [rtwgnx] c:\windows\system32\rtwgnx.exe
O4 - HKLM\..\Run: [d4fw41ta] C:\Program
Files\d4fw41ta\d4fw41ta.exe
O4 - HKLM\..\Run: [ap9h4qmo] C:\WINDOWS\System32
\ap9h4qmo.exe
O4 - HKLM\..\Run: [etbrun] C:\windows\system32
\eliteynl32.exe


Remove the folder

C:\Program Files\d4fw41ta too. Easiest way is to
Start,Run,cmd,OK to bring up a CMD window, then type:

rmdir /s /q "C:\Program Files\d4fw41ta"

Ron
 
Hi Guys -

I haven't crossposted... hey, enough to do in one place ;)

thanks so much for your help. I'm on a tight deadline but will get to this
thoroughly asap.

Cheers
Andrew
-----Original Message-----
For anyone who can help... I'm also going to be following some others'
suggestions and post this in some other forums as well.. just in case.

<SNIP>

Andrew,

Find as many of these modules as you can, and scan each at VirusTotal -
http://www.virustotal.com/flash/index_en.html. Use the Browse button at the top
to upload each module, if possible.

What are these?
C:\Program Files\d4fw41ta\d4fw41ta.exe
C:\WINDOWS\system\jgatupnxx.exe
C:\Program Files\d4fw41ta\25231640.exe
O4 - HKLM\..\Run: [rtwgnx] c:\windows\system32\rtwgnx.exe
O4 - HKLM\..\Run: [d4fw41ta] C:\Program Files\d4fw41ta\d4fw41ta.exe
O4 - HKLM\..\Run: [etbrun] C:\windows\system32\eliteynl32.exe

This ia a bad one:
O4 - HKLM\..\Run: [ap9h4qmo] C:\WINDOWS\System32\ap9h4qmo.exe
http://www.superadblocker.com/A/AP9H4QMO.EXE-2503.html

CrossPost - Don't MultiPost
http://www.uwasa.fi/~ts/http/crospost.html
http://www.blakjak.demon.co.uk/mul_crss.htm

How about links to your other posts so we can all learn?

--
Cheers,
Chuck
Paranoia comes from experience - and is not necessarily a bad thing.
.
 
Back
Top