Hi Guys,
I am having problems with some sort of spyware. When I open IE the following website keeps coming up "res://ejwjc.dll/index.htm
l#22776". When IE is open pop-up ads keep coming up in my screen.
have included the Hijackthis log below:
Logfile of HijackThis v1.97.7
Scan saved at 10:23:09, on 22-6-2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon
.exe
C:\WINNT\system32\services
.exe
C:\WINNT\system32\lsass.ex
e
C:\WINNT\system32\svchost.
exe
C:\WINNT\system32\spoolsv.
exe
C:\WINNT\System32\svchost.
exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.e
xe
C:\WINNT\system32\MSTask.e
xe
C:\WINNT\System32\WBEM\Win
Mgmt.exe
C:\WINNT\system32\svchost.
exe
C:\WINNT\system32\d3nf.exe
C:\WINNT\system32\MsgSys.E
XE
C:\WINNT\Explorer.EXE
C:\WINNT\system32\Smtray.e
xe
C:\WINNT\system32\Promon.e
xe
C:\WINNT\System32\igfxtray
.exe
C:\WINNT\System32\hkcmd.ex
e
C:\Program Files\NavNT\vptray.exe
C:\Program Files\GFI\FAXmaker Client\FMSTART.EXE
C:\WINNT\system32\iemf.exe
C:\WINNT\system32\internat
.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Documents and Settings\tanja\Menu Start\Programma's\Opstarte
n\stickit.
exe
C:\hijackthis\HijackThis.e
xe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINNT\ejwjc.dll/s
p.html#227
76
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page = res://ejwjc.dll/index.html
#22776
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page = res://ejwjc.dll/index.html
#22776
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINNT\ejwjc.dll/s
p.html#227
76
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = res://ejwjc.dll/index.html
#22776
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL = res://C:\WINNT\ejwjc.dll/s
p.html#227
76
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyServer = ntserv-02:8080
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = 192.168;<local>
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName = Koppelingen
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEH
elper.ocx
O2 - BHO: (no name) - {D10DA978-70A7-8F99-2AA0-C
F485138A6D
6} - C:\WINNT\system32\ntln.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINNT\System32\msdxm.oc
x
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Smapp] Smtray.exe
O4 - HKLM\..\Run: [Promon.exe] Promon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray
.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.ex
e
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [FMStart] "C:\Program Files\GFI\FAXmaker Client\FMSTART.EXE"
O4 - HKLM\..\Run: [iemf.exe] C:\WINNT\system32\iemf.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Startup: Snelkoppeling naar stickit.lnk = C:\Documents and Settings\tanja\Menu Start\Programma's\Opstarte
n\stickit.
exe
O4 - Startup: stickit.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = hq.nieuwenhuis.com
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = hq.nieuwenhuis.com
O17 - HKLM\System\CS2\Services\T
cpip\Param
eters: Domain = hq.nieuwenhuis.com
I think the first seven entries (including then string ejwjc.dll) should be deleted, but I am not sure about these:
{8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINNT\System32\msdxm.oc
x
O2 - BHO: (no name) - {D10DA978-70A7-8F99-2AA0-C
F485138A6D
6} - C:\WINNT\system32\ntln.dll
O4 - HKLM\..\Run: [iemf.exe] C:\WINNT\system32\iemf.exe
Can someone help me with this problem?
Thanks in advance !
Regards,
Jasper Scholtes
Start Free Trial