Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Unchangable Background [CLOSED]


  • This topic is locked This topic is locked

#1
Kalb

Kalb

    New Member

  • Member
  • Pip
  • 6 posts
:tazz:


I have done all of the required steps to remove my computer of Malware, but they have failed to remove an unchangable background. The following is what the backgroud says
----------------------------------------
WARNING!
YOU'RE IN DANGER!

ALL YOU DO WITH COMPUTER IS STORED FOREVER IN YOUR HARD DISK. WHEN YOU VISIT SITES, SEND EMAILS... ALL YOUR ACTIONS ARE LOGGED. AND IT IS IMPOSSIBLE TO REMOVE THEM WITH STANDARD TOOLS. YOUR DATA IS STILL AVAILABLE FOR FORENSICS. AND IN SOME CASES FOR YOUR BOSS, YOUR FRIENDS, YOUR WIFE, YOUR CHILDREN.

Every site you or somebody or even something, like spyware, opened in your browser, with all images, and all downloaded and maybe later removed movies or mp3 songs - ARE STILL THERE and could broke your life!


SECURE YOURSELF RIGHT NOW!
REMOVE ALL SPYWARE FROM YOUR PC!

Removal instructions
----------------------------------------------------------------------------------------------
If I click removal instructions it links me to this site to a search engine which searches "spyware".

I have included my HijackThis log for you to analyse. Thank you for help in advance

------------------------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 12:54:14 PM, on 7/1/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS.000\System32\smss.exe
C:\WINDOWS.000\system32\csrss.exe
C:\WINDOWS.000\system32\winlogon.exe
C:\WINDOWS.000\system32\services.exe
C:\WINDOWS.000\system32\lsass.exe
C:\WINDOWS.000\system32\svchost.exe
C:\WINDOWS.000\system32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\system32\spoolsv.exe
C:\WINDOWS.000\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Media Pass\MediaPass.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Media Pass\MediaPassK.exe
c:\windows.000\system32\nhplcu.exe
C:\WINDOWS.000\system32\devldr32.exe
C:\Documents and Settings\All Users\Documents\HOTSYNC.EXE
C:\WINDOWS.000\System32\alg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS.000\system32\wuauclt.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Family\LOCALS~1\Temp\se.dll/spage.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Family\LOCALS~1\Temp\se.dll/spage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.000\SYSTEM\blank.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O1 - Hosts: 69.50.160.142 localhost
O1 - Hosts: 69.50.160.142 dl.aaascreensavers.com
O1 - Hosts: 69.50.160.142 abcsearch.com
O1 - Hosts: 69.50.160.142 admin.abcsearch.com
O1 - Hosts: 69.50.160.142 www3.abcsearch.com #[Browseraid]
O1 - Hosts: 69.50.160.142 www.abcsearch.com
O1 - Hosts: 69.50.160.142 acestats.com
O1 - Hosts: 69.50.160.142 www.acestats.com
O1 - Hosts: 69.50.160.142 ad-up.com
O1 - Hosts: 69.50.160.142 www.ad-up.com
O1 - Hosts: 69.50.160.142 adatom.com
O1 - Hosts: 69.50.160.142 aesp.adatom.com
O1 - Hosts: 69.50.160.142 adbest.com
O1 - Hosts: 69.50.160.142 adserv.adbonus.com
O1 - Hosts: 69.50.160.142 www.adbonus.com
O1 - Hosts: 69.50.160.142 ad2.adcept.net
O1 - Hosts: 69.50.160.142 ad3.adcept.net
O1 - Hosts: 69.50.160.142 www.adcept.net
O1 - Hosts: 69.50.160.142 adcomplete.com
O1 - Hosts: 69.50.160.142 www.adcomplete.com
O1 - Hosts: 69.50.160.142 www.adcopy.info
O1 - Hosts: 69.50.160.142 ads.adcorps.com
O1 - Hosts: 69.50.160.142 ads.addynamix.com
O1 - Hosts: 69.50.160.142 pt.server1.adexit.com
O1 - Hosts: 69.50.160.142 www.adexit.com
O1 - Hosts: 69.50.160.142 www.ad4ever.com
O1 - Hosts: 69.50.160.142 adhearus.com
O1 - Hosts: 69.50.160.142 display2.adhearus.com
O1 - Hosts: 69.50.160.142 ssl3.adhost.com
O1 - Hosts: 69.50.160.142 www2.adhost.com
O1 - Hosts: 69.50.160.142 www.addme.com
O1 - Hosts: 69.50.160.142 www.adinfinity.com
O1 - Hosts: 69.50.160.142 te.adlandpro.com
O1 - Hosts: 69.50.160.142 classic.adlink.de
O1 - Hosts: 69.50.160.142 regio.adlink.de
O1 - Hosts: 69.50.160.142 west.adlink.de
O1 - Hosts: 69.50.160.142 www.adminder.com
O1 - Hosts: 69.50.160.142 adsfac.net
O1 - Hosts: 69.50.160.142 www.adonweb.com
O1 - Hosts: 69.50.160.142 www.adrelevance.com #[NetRatings]
O1 - Hosts: 69.50.160.142 media.adrevolver.com
O1 - Hosts: 69.50.160.142 ads.adsag.com
O1 - Hosts: 69.50.160.142 di.adsag.com
O1 - Hosts: 69.50.160.142 img.adsag.com
O1 - Hosts: 69.50.160.142 adserv.com
O1 - Hosts: 69.50.160.142 www.adserv.com
O1 - Hosts: 69.50.160.142 downldcl.adtoolsinc.com
O1 - Hosts: 69.50.160.142 www.adtoolsinc.com
O1 - Hosts: 69.50.160.142 www.adtrader.com
O1 - Hosts: 69.50.160.142 survey.advantageresearch.com
O1 - Hosts: 69.50.160.142 ad.adver.com.tw
O1 - Hosts: 69.50.160.142 ads.advertise.net
O1 - Hosts: 69.50.160.142 adviva.com
O1 - Hosts: 69.50.160.142 www.adviva.com
O1 - Hosts: 69.50.160.142 ads.adviva.net
O1 - Hosts: 69.50.160.142 adstats.adviva.net
O1 - Hosts: 69.50.160.142 www.affiliatefuel.com
O1 - Hosts: 69.50.160.142 banners.affiliatefuel.com
O1 - Hosts: 69.50.160.142 affiliatetarget.com
O1 - Hosts: 69.50.160.142 www.affiliatetarget.com
O1 - Hosts: 69.50.160.142 fcds.affiliatetracking.net
O1 - Hosts: 69.50.160.142 our.affiliatetracking.net
O1 - Hosts: 69.50.160.142 www.affiliatetracking.net
O1 - Hosts: 69.50.160.142 www.affiliatetracking.com
O1 - Hosts: 69.50.160.142 adserver.aim4media.com
O1 - Hosts: 69.50.160.142 adtest.aim4media.com
O1 - Hosts: 69.50.160.142 pops.aim4media.com
O1 - Hosts: 69.50.160.142 www.aim4media.com
O1 - Hosts: 69.50.160.142 crs.akamai.com
O1 - Hosts: 69.50.160.142 soap.alexa.com #[Spyware.Alexa][Alexa Toolbar]
O1 - Hosts: 69.50.160.142 www.alexa.com
O1 - Hosts: 69.50.160.142 ads.as4x.tmcs.akadns.net #[Ticketmaster]
O1 - Hosts: 69.50.160.142 bantam.ai.net
O1 - Hosts: 69.50.160.142 fiona.ai.net
O1 - Hosts: 69.50.160.142 ads.amazingmedia.com
O1 - Hosts: 69.50.160.142 adserver04.ancestry.com #[RealMedia]
O1 - Hosts: 69.50.160.142 ads.antionline.com
O1 - Hosts: 69.50.160.142 junior.apk.net
O1 - Hosts: 69.50.160.142 banner.arttoday.com
O1 - Hosts: 69.50.160.142 associmg.com #[amazon.com]
O1 - Hosts: 69.50.160.142 audiogalaxy.com
O1 - Hosts: 69.50.160.142 www.audiogalaxy.com #[Restricted Zone site]
O1 - Hosts: 69.50.160.142 www.avres.net
O1 - Hosts: 69.50.160.142 www.aweber.com
O1 - Hosts: 69.50.160.142 www.baltictop.com
O1 - Hosts: 69.50.160.142 www.banner-mania.com
O1 - Hosts: 69.50.160.142 www.bannerspace.com #[Restricted Zone site]
O1 - Hosts: 69.50.160.142 www2.bannerspace.com
O1 - Hosts: 69.50.160.142 www3.bannerspace.com
O1 - Hosts: 69.50.160.142 www5.bannerspace.com
O1 - Hosts: 69.50.160.142 www6.bannerspace.com
O1 - Hosts: 69.50.160.142 www7.bannerspace.com
O1 - Hosts: 69.50.160.142 bannerswap.com
O1 - Hosts: 69.50.160.142 www.bannerswap.com
O1 - Hosts: 69.50.160.142 www.bidclix.com
O1 - Hosts: 69.50.160.142 bidclix.net
O1 - Hosts: 69.50.160.142 www.bidclix.net
O1 - Hosts: 69.50.160.142 bigtracker.com
O1 - Hosts: 69.50.160.142 bighits.net #[Restricted Zone site]
O1 - Hosts: 69.50.160.142 bigticker.bighits.net
O1 - Hosts: 69.50.160.142 bounty.bighits.net
O2 - BHO: Name - {0E04C828-9C16-4518-B9E4-2C9ABC3C5271} - C:\WINDOWS.000\System32\msqzg.dll (file missing)
O2 - BHO: (no name) - {38D4D5D0-423E-4220-B6F9-30918C2AE4A4} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {87924B2B-8E04-449A-A431-5188F62A22A7} - C:\WINDOWS.000\System32\ockj.dll (file missing)
O2 - BHO: Name - {AE7A5CC9-41E7-4485-9FC3-3363278595D6} - C:\WINDOWS.000\System32\msqzg.dll (file missing)
O2 - BHO: CIEExtension Object - {B51DC573-E998-4834-9B45-BAB7C2AE0A75} - C:\Program Files\Ad-Protect\ADPIEmonitor.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Name - {ED3D81EF-0797-4301-8235-5724CB3B7E1F} - C:\WINDOWS.000\System32\msqzg.dll (file missing)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [4.tmp] C:\DOCUME~1\CHRISM~1\LOCALS~1\Temp\4.tmp.exe 0 28129
O4 - HKLM\..\Run: [wincb32.exe] C:\WINDOWS.000\system32\wincb32.exe
O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPass.exe
O4 - HKLM\..\Run: [new32] media64.exe
O4 - HKLM\..\Run: [cmon14] media64.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare Test\BearShare.exe" /pause
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [hnapvcb] c:\windows.000\system32\nhplcu.exe r
O4 - HKCU\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Documents and Settings\All Users\Documents\HOTSYNC.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z....iTunesSetup.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{386CFD34-74FC-4B7D-851F-6A2242382650}: NameServer = 69.50.184.85,195.225.176.37
O18 - Filter: text/html - {C32ACBB2-2AD4-4A83-B34C-5BEEB3EA23DE} - C:\WINDOWS.000\System32\ockj.dll
O18 - Filter: text/plain - {C32ACBB2-2AD4-4A83-B34C-5BEEB3EA23DE} - C:\WINDOWS.000\System32\ockj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Super Ad Blocker Service (SABSVC) - Unknown owner - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE (file missing)
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS.000\svcproc.exe (file missing)
  • 0

Advertisements


#2
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Hi Kalb and welcome to the Geeks to Go Forums.

My name is Trevuren and I will be helping you with your log.

1. If you haven't logged in go to Geeks to Go and do so. Then proceed to item a.

If you already have logged in, go directly to item a.

a. Click on My Controls at the top right hand corner of the window.
b. In the left hand column, click "View Topics"
c. If you click on the title of your post, you will be taken there

2. Also, while at the My Controls page, check the box to the right of your post and then scroll down.
.Where it says "unsubscribe" click the pull-down menu and select "immediate email notification"

3. Please DELETE your current HJT program from its present location.

4. Download and run the following HijackThis autoinstall program from Here HJT needs to be in its own folder so that the program itself isn't deleted by accident. Having the backups could be VITAL to restoring your system if something went wrong in the FIX process!

A. Close ALL windows except HJT

B. SCAN with HJT and SAVE LOG. (a notepad window will open with the log in it when you click Save Log) (Ctrl-A to'select all', Ctrl-C to 'copy')

C. POST the log in this thread using 'Add Reply' (Ctrl-V to 'paste')


DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL WE CHECK THE LOG, AS MOST OF THE FILES ARE LEGIT AND VITAL TO THE FUNCTION OF YOUR COMPUTER


Note: You have 2-3 major infections going on at the same time here. They will have to be taken on individually.

Regards,

Trevuren

  • 0

#3
Kalb

Kalb

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Thank you for replying, and thank you for future help in advance :tazz:

The following is my recent HiJack This log file.

--------------------------------------------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 8:16:35 PM, on 7/1/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS.000\System32\smss.exe
C:\WINDOWS.000\system32\csrss.exe
C:\WINDOWS.000\system32\winlogon.exe
C:\WINDOWS.000\system32\services.exe
C:\WINDOWS.000\system32\lsass.exe
C:\WINDOWS.000\system32\svchost.exe
C:\WINDOWS.000\system32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\system32\spoolsv.exe
C:\WINDOWS.000\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Media Pass\MediaPass.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Media Pass\MediaPassK.exe
c:\windows.000\system32\nhplcu.exe
C:\WINDOWS.000\system32\devldr32.exe
C:\Documents and Settings\All Users\Documents\HOTSYNC.EXE
C:\WINDOWS.000\System32\alg.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Family\LOCALS~1\Temp\se.dll/spage.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Family\LOCALS~1\Temp\se.dll/spage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.000\SYSTEM\blank.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O1 - Hosts: 69.50.160.142 localhost
O1 - Hosts: 69.50.160.142 dl.aaascreensavers.com
O1 - Hosts: 69.50.160.142 abcsearch.com
O1 - Hosts: 69.50.160.142 admin.abcsearch.com
O1 - Hosts: 69.50.160.142 www3.abcsearch.com #[Browseraid]
O1 - Hosts: 69.50.160.142 www.abcsearch.com
O1 - Hosts: 69.50.160.142 acestats.com
O1 - Hosts: 69.50.160.142 www.acestats.com
O1 - Hosts: 69.50.160.142 ad-up.com
O1 - Hosts: 69.50.160.142 www.ad-up.com
O1 - Hosts: 69.50.160.142 adatom.com
O1 - Hosts: 69.50.160.142 aesp.adatom.com
O1 - Hosts: 69.50.160.142 adbest.com
O1 - Hosts: 69.50.160.142 adserv.adbonus.com
O1 - Hosts: 69.50.160.142 www.adbonus.com
O1 - Hosts: 69.50.160.142 ad2.adcept.net
O1 - Hosts: 69.50.160.142 ad3.adcept.net
O1 - Hosts: 69.50.160.142 www.adcept.net
O1 - Hosts: 69.50.160.142 adcomplete.com
O1 - Hosts: 69.50.160.142 www.adcomplete.com
O1 - Hosts: 69.50.160.142 www.adcopy.info
O1 - Hosts: 69.50.160.142 ads.adcorps.com
O1 - Hosts: 69.50.160.142 ads.addynamix.com
O1 - Hosts: 69.50.160.142 pt.server1.adexit.com
O1 - Hosts: 69.50.160.142 www.adexit.com
O1 - Hosts: 69.50.160.142 www.ad4ever.com
O1 - Hosts: 69.50.160.142 adhearus.com
O1 - Hosts: 69.50.160.142 display2.adhearus.com
O1 - Hosts: 69.50.160.142 ssl3.adhost.com
O1 - Hosts: 69.50.160.142 www2.adhost.com
O1 - Hosts: 69.50.160.142 www.addme.com
O1 - Hosts: 69.50.160.142 www.adinfinity.com
O1 - Hosts: 69.50.160.142 te.adlandpro.com
O1 - Hosts: 69.50.160.142 classic.adlink.de
O1 - Hosts: 69.50.160.142 regio.adlink.de
O1 - Hosts: 69.50.160.142 west.adlink.de
O1 - Hosts: 69.50.160.142 www.adminder.com
O1 - Hosts: 69.50.160.142 adsfac.net
O1 - Hosts: 69.50.160.142 www.adonweb.com
O1 - Hosts: 69.50.160.142 www.adrelevance.com #[NetRatings]
O1 - Hosts: 69.50.160.142 media.adrevolver.com
O1 - Hosts: 69.50.160.142 ads.adsag.com
O1 - Hosts: 69.50.160.142 di.adsag.com
O1 - Hosts: 69.50.160.142 img.adsag.com
O1 - Hosts: 69.50.160.142 adserv.com
O1 - Hosts: 69.50.160.142 www.adserv.com
O1 - Hosts: 69.50.160.142 downldcl.adtoolsinc.com
O1 - Hosts: 69.50.160.142 www.adtoolsinc.com
O1 - Hosts: 69.50.160.142 www.adtrader.com
O1 - Hosts: 69.50.160.142 survey.advantageresearch.com
O1 - Hosts: 69.50.160.142 ad.adver.com.tw
O1 - Hosts: 69.50.160.142 ads.advertise.net
O1 - Hosts: 69.50.160.142 adviva.com
O1 - Hosts: 69.50.160.142 www.adviva.com
O1 - Hosts: 69.50.160.142 ads.adviva.net
O1 - Hosts: 69.50.160.142 adstats.adviva.net
O1 - Hosts: 69.50.160.142 www.affiliatefuel.com
O1 - Hosts: 69.50.160.142 banners.affiliatefuel.com
O1 - Hosts: 69.50.160.142 affiliatetarget.com
O1 - Hosts: 69.50.160.142 www.affiliatetarget.com
O1 - Hosts: 69.50.160.142 fcds.affiliatetracking.net
O1 - Hosts: 69.50.160.142 our.affiliatetracking.net
O1 - Hosts: 69.50.160.142 www.affiliatetracking.net
O1 - Hosts: 69.50.160.142 www.affiliatetracking.com
O1 - Hosts: 69.50.160.142 adserver.aim4media.com
O1 - Hosts: 69.50.160.142 adtest.aim4media.com
O1 - Hosts: 69.50.160.142 pops.aim4media.com
O1 - Hosts: 69.50.160.142 www.aim4media.com
O1 - Hosts: 69.50.160.142 crs.akamai.com
O1 - Hosts: 69.50.160.142 soap.alexa.com #[Spyware.Alexa][Alexa Toolbar]
O1 - Hosts: 69.50.160.142 www.alexa.com
O1 - Hosts: 69.50.160.142 ads.as4x.tmcs.akadns.net #[Ticketmaster]
O1 - Hosts: 69.50.160.142 bantam.ai.net
O1 - Hosts: 69.50.160.142 fiona.ai.net
O1 - Hosts: 69.50.160.142 ads.amazingmedia.com
O1 - Hosts: 69.50.160.142 adserver04.ancestry.com #[RealMedia]
O1 - Hosts: 69.50.160.142 ads.antionline.com
O1 - Hosts: 69.50.160.142 junior.apk.net
O1 - Hosts: 69.50.160.142 banner.arttoday.com
O1 - Hosts: 69.50.160.142 associmg.com #[amazon.com]
O1 - Hosts: 69.50.160.142 audiogalaxy.com
O1 - Hosts: 69.50.160.142 www.audiogalaxy.com #[Restricted Zone site]
O1 - Hosts: 69.50.160.142 www.avres.net
O1 - Hosts: 69.50.160.142 www.aweber.com
O1 - Hosts: 69.50.160.142 www.baltictop.com
O1 - Hosts: 69.50.160.142 www.banner-mania.com
O1 - Hosts: 69.50.160.142 www.bannerspace.com #[Restricted Zone site]
O1 - Hosts: 69.50.160.142 www2.bannerspace.com
O1 - Hosts: 69.50.160.142 www3.bannerspace.com
O1 - Hosts: 69.50.160.142 www5.bannerspace.com
O1 - Hosts: 69.50.160.142 www6.bannerspace.com
O1 - Hosts: 69.50.160.142 www7.bannerspace.com
O1 - Hosts: 69.50.160.142 bannerswap.com
O1 - Hosts: 69.50.160.142 www.bannerswap.com
O1 - Hosts: 69.50.160.142 www.bidclix.com
O1 - Hosts: 69.50.160.142 bidclix.net
O1 - Hosts: 69.50.160.142 www.bidclix.net
O1 - Hosts: 69.50.160.142 bigtracker.com
O1 - Hosts: 69.50.160.142 bighits.net #[Restricted Zone site]
O1 - Hosts: 69.50.160.142 bigticker.bighits.net
O1 - Hosts: 69.50.160.142 bounty.bighits.net
O2 - BHO: Name - {0E04C828-9C16-4518-B9E4-2C9ABC3C5271} - C:\WINDOWS.000\System32\msqzg.dll (file missing)
O2 - BHO: (no name) - {38D4D5D0-423E-4220-B6F9-30918C2AE4A4} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {87924B2B-8E04-449A-A431-5188F62A22A7} - C:\WINDOWS.000\System32\ockj.dll (file missing)
O2 - BHO: Name - {AE7A5CC9-41E7-4485-9FC3-3363278595D6} - C:\WINDOWS.000\System32\msqzg.dll (file missing)
O2 - BHO: CIEExtension Object - {B51DC573-E998-4834-9B45-BAB7C2AE0A75} - C:\Program Files\Ad-Protect\ADPIEmonitor.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Name - {ED3D81EF-0797-4301-8235-5724CB3B7E1F} - C:\WINDOWS.000\System32\msqzg.dll (file missing)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [4.tmp] C:\DOCUME~1\CHRISM~1\LOCALS~1\Temp\4.tmp.exe 0 28129
O4 - HKLM\..\Run: [wincb32.exe] C:\WINDOWS.000\system32\wincb32.exe
O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPass.exe
O4 - HKLM\..\Run: [new32] media64.exe
O4 - HKLM\..\Run: [cmon14] media64.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare Test\BearShare.exe" /pause
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [hnapvcb] c:\windows.000\system32\nhplcu.exe r
O4 - HKCU\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Documents and Settings\All Users\Documents\HOTSYNC.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z....iTunesSetup.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{386CFD34-74FC-4B7D-851F-6A2242382650}: NameServer = 69.50.184.85,195.225.176.37
O18 - Filter: text/html - {C32ACBB2-2AD4-4A83-B34C-5BEEB3EA23DE} - C:\WINDOWS.000\System32\ockj.dll
O18 - Filter: text/plain - {C32ACBB2-2AD4-4A83-B34C-5BEEB3EA23DE} - C:\WINDOWS.000\System32\ockj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Super Ad Blocker Service (SABSVC) - Unknown owner - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE (file missing)
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS.000\svcproc.exe (file missing)
  • 0

#4
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Your system is vey heavily infected so we will have to proceed one step at a time to eradicate this mess. Please follow all my directions to the letter. If there is something you don't understand, please ask. We will start by attacking a variant of the About:Blank infection.

1. Download CWShredder

If you are using anything other than Windows xp you may need a zip program.
Please download the evaluation version of
Winzip.


2. Download SpSeHjfix.zip to the desktop.
  • Then right click on the desktop and select new >folder, name it spfix
  • Unzip SpSeHjfix.zip into the new folder.
3. Disconnect from the net and Close ALL OPEN PROGRAMS.
  • Run 'SpSeHjfix'. and click on "Start Disinfection".
  • When it's finished it will reboot your machine to finish the cleaning process.
  • The tool creates a log of the fix which will appear in the folder.
If it doesn't find any of the SE files or any hidden reinstallers it will say system clean and not go on to next stage.

4. Once it is finished, run CWShredder - Hit The FIX button!

5. Reboot and post a new HJT log and the log that was created by 'SpSeHjfix'.

Warning Note: On a few occasions it has been reported that after using the SPSEHjfix you cannot open Internet Explorer. To fix this, go into Control Panel >Internet Options >Programs & press reset web settings, then you can set your home page to what you want on the general tab.

Regards,

Trevuren

  • 0

#5
Kalb

Kalb

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
I have done all of the following steps, and here are my following two logs

--------------------------------------------------------------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 5:39:12 AM, on 7/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS.000\System32\smss.exe
C:\WINDOWS.000\system32\csrss.exe
C:\WINDOWS.000\system32\winlogon.exe
C:\WINDOWS.000\system32\services.exe
C:\WINDOWS.000\system32\lsass.exe
C:\WINDOWS.000\system32\svchost.exe
C:\WINDOWS.000\system32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\system32\spoolsv.exe
C:\WINDOWS.000\Explorer.EXE
C:\Program Files\Media Pass\MediaPass.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Documents and Settings\All Users\Documents\HOTSYNC.EXE
c:\windows.000\system32\gewjhja.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Media Pass\MediaPassK.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS.000\system32\devldr32.exe
C:\WINDOWS.000\System32\alg.exe
C:\WINDOWS.000\PCHealth\HelpCtr\Binaries\HelpHost.exe
C:\WINDOWS.000\system32\wuauclt.exe
C:\WINDOWS.000\System32\wbem\wmiprvse.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS.000\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.000\SYSTEM\blank.htm
O1 - Hosts: 69.50.160.142 localhost
O1 - Hosts: 69.50.160.142 dl.aaascreensavers.com
O1 - Hosts: 69.50.160.142 abcsearch.com
O1 - Hosts: 69.50.160.142 admin.abcsearch.com
O1 - Hosts: 69.50.160.142 www3.abcsearch.com #[Browseraid]
O1 - Hosts: 69.50.160.142 www.abcsearch.com
O1 - Hosts: 69.50.160.142 acestats.com
O1 - Hosts: 69.50.160.142 www.acestats.com
O1 - Hosts: 69.50.160.142 ad-up.com
O1 - Hosts: 69.50.160.142 www.ad-up.com
O1 - Hosts: 69.50.160.142 adatom.com
O1 - Hosts: 69.50.160.142 aesp.adatom.com
O1 - Hosts: 69.50.160.142 adbest.com
O1 - Hosts: 69.50.160.142 adserv.adbonus.com
O1 - Hosts: 69.50.160.142 www.adbonus.com
O1 - Hosts: 69.50.160.142 ad2.adcept.net
O1 - Hosts: 69.50.160.142 ad3.adcept.net
O1 - Hosts: 69.50.160.142 www.adcept.net
O1 - Hosts: 69.50.160.142 adcomplete.com
O1 - Hosts: 69.50.160.142 www.adcomplete.com
O1 - Hosts: 69.50.160.142 www.adcopy.info
O1 - Hosts: 69.50.160.142 ads.adcorps.com
O1 - Hosts: 69.50.160.142 ads.addynamix.com
O1 - Hosts: 69.50.160.142 pt.server1.adexit.com
O1 - Hosts: 69.50.160.142 www.adexit.com
O1 - Hosts: 69.50.160.142 www.ad4ever.com
O1 - Hosts: 69.50.160.142 adhearus.com
O1 - Hosts: 69.50.160.142 display2.adhearus.com
O1 - Hosts: 69.50.160.142 ssl3.adhost.com
O1 - Hosts: 69.50.160.142 www2.adhost.com
O1 - Hosts: 69.50.160.142 www.addme.com
O1 - Hosts: 69.50.160.142 www.adinfinity.com
O1 - Hosts: 69.50.160.142 te.adlandpro.com
O1 - Hosts: 69.50.160.142 classic.adlink.de
O1 - Hosts: 69.50.160.142 regio.adlink.de
O1 - Hosts: 69.50.160.142 west.adlink.de
O1 - Hosts: 69.50.160.142 www.adminder.com
O1 - Hosts: 69.50.160.142 adsfac.net
O1 - Hosts: 69.50.160.142 www.adonweb.com
O1 - Hosts: 69.50.160.142 www.adrelevance.com #[NetRatings]
O1 - Hosts: 69.50.160.142 media.adrevolver.com
O1 - Hosts: 69.50.160.142 ads.adsag.com
O1 - Hosts: 69.50.160.142 di.adsag.com
O1 - Hosts: 69.50.160.142 img.adsag.com
O1 - Hosts: 69.50.160.142 adserv.com
O1 - Hosts: 69.50.160.142 www.adserv.com
O1 - Hosts: 69.50.160.142 downldcl.adtoolsinc.com
O1 - Hosts: 69.50.160.142 www.adtoolsinc.com
O1 - Hosts: 69.50.160.142 www.adtrader.com
O1 - Hosts: 69.50.160.142 survey.advantageresearch.com
O1 - Hosts: 69.50.160.142 ad.adver.com.tw
O1 - Hosts: 69.50.160.142 ads.advertise.net
O1 - Hosts: 69.50.160.142 adviva.com
O1 - Hosts: 69.50.160.142 www.adviva.com
O1 - Hosts: 69.50.160.142 ads.adviva.net
O1 - Hosts: 69.50.160.142 adstats.adviva.net
O1 - Hosts: 69.50.160.142 www.affiliatefuel.com
O1 - Hosts: 69.50.160.142 banners.affiliatefuel.com
O1 - Hosts: 69.50.160.142 affiliatetarget.com
O1 - Hosts: 69.50.160.142 www.affiliatetarget.com
O1 - Hosts: 69.50.160.142 fcds.affiliatetracking.net
O1 - Hosts: 69.50.160.142 our.affiliatetracking.net
O1 - Hosts: 69.50.160.142 www.affiliatetracking.net
O1 - Hosts: 69.50.160.142 www.affiliatetracking.com
O1 - Hosts: 69.50.160.142 adserver.aim4media.com
O1 - Hosts: 69.50.160.142 adtest.aim4media.com
O1 - Hosts: 69.50.160.142 pops.aim4media.com
O1 - Hosts: 69.50.160.142 www.aim4media.com
O1 - Hosts: 69.50.160.142 crs.akamai.com
O1 - Hosts: 69.50.160.142 soap.alexa.com #[Spyware.Alexa][Alexa Toolbar]
O1 - Hosts: 69.50.160.142 www.alexa.com
O1 - Hosts: 69.50.160.142 ads.as4x.tmcs.akadns.net #[Ticketmaster]
O1 - Hosts: 69.50.160.142 bantam.ai.net
O1 - Hosts: 69.50.160.142 fiona.ai.net
O1 - Hosts: 69.50.160.142 ads.amazingmedia.com
O1 - Hosts: 69.50.160.142 adserver04.ancestry.com #[RealMedia]
O1 - Hosts: 69.50.160.142 ads.antionline.com
O1 - Hosts: 69.50.160.142 junior.apk.net
O1 - Hosts: 69.50.160.142 banner.arttoday.com
O1 - Hosts: 69.50.160.142 associmg.com #[amazon.com]
O1 - Hosts: 69.50.160.142 audiogalaxy.com
O1 - Hosts: 69.50.160.142 www.audiogalaxy.com #[Restricted Zone site]
O1 - Hosts: 69.50.160.142 www.avres.net
O1 - Hosts: 69.50.160.142 www.aweber.com
O1 - Hosts: 69.50.160.142 www.baltictop.com
O1 - Hosts: 69.50.160.142 www.banner-mania.com
O1 - Hosts: 69.50.160.142 www.bannerspace.com #[Restricted Zone site]
O1 - Hosts: 69.50.160.142 www2.bannerspace.com
O1 - Hosts: 69.50.160.142 www3.bannerspace.com
O1 - Hosts: 69.50.160.142 www5.bannerspace.com
O1 - Hosts: 69.50.160.142 www6.bannerspace.com
O1 - Hosts: 69.50.160.142 www7.bannerspace.com
O1 - Hosts: 69.50.160.142 bannerswap.com
O1 - Hosts: 69.50.160.142 www.bannerswap.com
O1 - Hosts: 69.50.160.142 www.bidclix.com
O1 - Hosts: 69.50.160.142 bidclix.net
O1 - Hosts: 69.50.160.142 www.bidclix.net
O1 - Hosts: 69.50.160.142 bigtracker.com
O1 - Hosts: 69.50.160.142 bighits.net #[Restricted Zone site]
O1 - Hosts: 69.50.160.142 bigticker.bighits.net
O1 - Hosts: 69.50.160.142 bounty.bighits.net
O2 - BHO: Name - {0E04C828-9C16-4518-B9E4-2C9ABC3C5271} - C:\WINDOWS.000\System32\msqzg.dll (file missing)
O2 - BHO: (no name) - {38D4D5D0-423E-4220-B6F9-30918C2AE4A4} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Name - {AE7A5CC9-41E7-4485-9FC3-3363278595D6} - C:\WINDOWS.000\System32\msqzg.dll (file missing)
O2 - BHO: CIEExtension Object - {B51DC573-E998-4834-9B45-BAB7C2AE0A75} - C:\Program Files\Ad-Protect\ADPIEmonitor.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Name - {ED3D81EF-0797-4301-8235-5724CB3B7E1F} - C:\WINDOWS.000\System32\msqzg.dll (file missing)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [4.tmp] C:\DOCUME~1\CHRISM~1\LOCALS~1\Temp\4.tmp.exe 0 28129
O4 - HKLM\..\Run: [wincb32.exe] C:\WINDOWS.000\system32\wincb32.exe
O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPass.exe
O4 - HKLM\..\Run: [new32] media64.exe
O4 - HKLM\..\Run: [cmon14] media64.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare Test\BearShare.exe" /pause
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ucmqfj] c:\windows.000\system32\gewjhja.exe r
O4 - HKCU\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Documents and Settings\All Users\Documents\HOTSYNC.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z....iTunesSetup.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{386CFD34-74FC-4B7D-851F-6A2242382650}: NameServer = 69.50.184.85,195.225.176.37
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Super Ad Blocker Service (SABSVC) - Unknown owner - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE (file missing)
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS.000\svcproc.exe (file missing)

--------------------------------------------------------------------------------------------------

SPSEHjFix Log


(7/2/05 5:30:04 AM) SPSeHjFix started v1.1.2
(7/2/05 5:30:04 AM) OS: WinXP Service Pack 2 (5.1.2600)
(7/2/05 5:30:04 AM) Language: english
(7/2/05 5:30:04 AM) Win-Path: C:\WINDOWS.000
(7/2/05 5:30:04 AM) System-Path: C:\WINDOWS.000\system32
(7/2/05 5:30:04 AM) Temp-Path: C:\DOCUME~1\Family\LOCALS~1\Temp\


(7/2/05 5:31:15 AM) SPSeHjFix started v1.1.2
(7/2/05 5:31:15 AM) OS: WinXP Service Pack 2 (5.1.2600)
(7/2/05 5:31:15 AM) Language: english
(7/2/05 5:31:15 AM) Win-Path: C:\WINDOWS.000
(7/2/05 5:31:15 AM) System-Path: C:\WINDOWS.000\system32
(7/2/05 5:31:15 AM) Temp-Path: C:\DOCUME~1\Family\LOCALS~1\Temp\
(7/2/05 5:31:17 AM) Disinfection started
(7/2/05 5:31:17 AM) Bad-Dll(IEP): c:\docume~1\family\locals~1\temp\se.dll
(7/2/05 5:31:17 AM) UBF: 7 - UBB: 9 - UBR: 11
(7/2/05 5:31:17 AM) FilterKey: HKCR\text/html (deleted)
(7/2/05 5:31:17 AM) FilterKey: HKCR\CLSID\{C32ACBB2-2AD4-4A83-B34C-5BEEB3EA23DE} (deleted)
(7/2/05 5:31:17 AM) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(7/2/05 5:31:17 AM) FilterKey: HKCR\text/plain (deleted)
(7/2/05 5:31:17 AM) FilterKey: HKCR\CLSID\{C32ACBB2-2AD4-4A83-B34C-5BEEB3EA23DE} (error while deleting)
(7/2/05 5:31:17 AM) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(7/2/05 5:31:17 AM) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{87924B2B-8E04-449A-A431-5188F62A22A7} (deleted)
(7/2/05 5:31:17 AM) BHO-Key: HKCR\CLSID\{87924B2B-8E04-449A-A431-5188F62A22A7} (deleted)
(7/2/05 5:31:17 AM) UBF: 5 - UBB: 8 - UBR: 11
(7/2/05 5:31:17 AM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\family\locals~1\temp\se.dll/spage.html
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\family\locals~1\temp\se.dll/spage.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(7/2/05 5:31:17 AM) Stealth-String not found
(7/2/05 5:31:17 AM) File added to delete: c:\windows.000\system32\ockj.dll
(7/2/05 5:31:17 AM) Reboot


(7/2/05 5:32:45 AM) SPSeHjFix started v1.1.2
(7/2/05 5:32:45 AM) OS: WinXP Service Pack 2 (5.1.2600)
(7/2/05 5:32:45 AM) Language: english
(7/2/05 5:32:45 AM) Win-Path: C:\WINDOWS.000
(7/2/05 5:32:45 AM) System-Path: C:\WINDOWS.000\system32
(7/2/05 5:32:45 AM) Temp-Path: C:\DOCUME~1\Family\LOCALS~1\Temp\


(7/2/05 5:34:35 AM) SPSeHjFix started v1.1.2
(7/2/05 5:34:35 AM) OS: WinXP Service Pack 2 (5.1.2600)
(7/2/05 5:34:35 AM) Language: english
(7/2/05 5:34:35 AM) Win-Path: C:\WINDOWS.000
(7/2/05 5:34:35 AM) System-Path: C:\WINDOWS.000\system32
(7/2/05 5:34:35 AM) Temp-Path: C:\DOCUME~1\Family\LOCALS~1\Temp\
(7/2/05 5:34:36 AM) Disinfection started
(7/2/05 5:34:36 AM) Bad-Dll(IEP): (not found)
(7/2/05 5:34:36 AM) Bad-Dll(IEP) in BHO: (not found)
(7/2/05 5:34:36 AM) UBF: 5 - UBB: 8 - UBR: 11
(7/2/05 5:34:36 AM) UBF: 5 - UBB: 8 - UBR: 11
(7/2/05 5:34:36 AM) Bad IE-pages: (none)
(7/2/05 5:34:36 AM) Stealth-String not found
(7/2/05 5:34:36 AM) Not infected->END
  • 0

#6
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Now for a big cleanup.

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order in which they are mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

1. Download the following program HOSTER.

2. Unzip and run the program.

3. You will be presented with a screen where you will find the following option:Restore Microsoft Original Hosts. Press it and Close the program.

4. Reboot your system.

5. First we need to make all files and folders VISIBLE:

Go to start>control panel>folder options>view (tab)
*choose to "show hidden files and folders,"
*uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
*Close the window with ok
*All hidden files will now be visible

Please RUN HijackThis.
. Click the SCAN button to produce a log.

Place a check mark beside each one of the following items:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.000\SYSTEM\blank.htm
O2 - BHO: Name - {0E04C828-9C16-4518-B9E4-2C9ABC3C5271} - C:\WINDOWS.000\System32\msqzg.dll (file missing)
O2 - BHO: (no name) - {38D4D5D0-423E-4220-B6F9-30918C2AE4A4} - (no file)
O2 - BHO: Name - {AE7A5CC9-41E7-4485-9FC3-3363278595D6} - C:\WINDOWS.000\System32\msqzg.dll (file missing)
O2 - BHO: CIEExtension Object - {B51DC573-E998-4834-9B45-BAB7C2AE0A75} - C:\Program Files\Ad-Protect\ADPIEmonitor.dll
O2 - BHO: Name - {ED3D81EF-0797-4301-8235-5724CB3B7E1F} - C:\WINDOWS.000\System32\msqzg.dll (file missing)
O4 - HKLM\..\Run: [4.tmp] C:\DOCUME~1\CHRISM~1\LOCALS~1\Temp\4.tmp.exe 0 28129
O4 - HKLM\..\Run: [wincb32.exe] C:\WINDOWS.000\system32\wincb32.exe
O4 - HKLM\..\Run: [new32] media64.exe
O4 - HKLM\..\Run: [cmon14] media64.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [ucmqfj] c:\windows.000\system32\gewjhja.exe r
O4 - HKCU\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS.000\svcproc.exe (file missing)



Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window and Reboot Your System in Safe Mode

How to use the F8 method to Start Your Computer in Safe Mode

*Restart the computer.
*as soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
*Use the arrow keys to select the Safe mode menu item
*press Enter.


Using Windows Explorer, locate the following files/folders, and DELETE them (if they are present):

FILES

C:\WINDOWS.000\System32\alg.exe
C:\WINDOWS.000\SYSTEM\blank.htm
C:\WINDOWS.000\System32\msqzg.dll
C:\DOCUME~1\CHRISM~1\LOCALS~1\Temp\4.tmp.exe 0 28129
C:\WINDOWS.000\system32\wincb32.exe
media64.exe<---You will have to look for this one
c:\windows.000\system32\gewjhja.exe
C:\WINDOWS.000\svcproc.exe

FOLDERS (with all their content)

C:\Program Files\Media Pass
C:\WINDOWS.000\System32\wbem
C:\Program Files\Security iGuard
C:\PROGRAM FILES\COMMON FILES\WinTools
C:\Program Files\Ad-Protect

Exit Explorer, and REBOOT BACK INTO NORMAL MODE

Finally, RUN Hijackthis again and produce a new HJT log. Post it in the forum so we can check how everytjhing looks now.

Regards,

Trevuren

  • 0

#7
Kalb

Kalb

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
hey, sorry about the delay on the response i went away for a week :tazz: ,

i completed all of the required steps however most of the files/folders were'nt present when i went to remove tem. With that said here what the curent HJ log looks like...

-----------------------------------------------------------------------------------------------------


Running processes:
C:\WINDOWS.000\System32\smss.exe
C:\WINDOWS.000\system32\csrss.exe
C:\WINDOWS.000\system32\winlogon.exe
C:\WINDOWS.000\system32\services.exe
C:\WINDOWS.000\system32\lsass.exe
C:\WINDOWS.000\system32\svchost.exe
C:\WINDOWS.000\system32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\system32\spoolsv.exe
C:\WINDOWS.000\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Documents and Settings\All Users\Documents\HOTSYNC.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS.000\system32\devldr32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPass.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare Test\BearShare.exe" /pause
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [zgvyqiu] c:\windows.000\system32\pmmtotz.exe r
O4 - Global Startup: HotSync Manager.lnk = C:\Documents and Settings\All Users\Documents\HOTSYNC.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z....iTunesSetup.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{386CFD34-74FC-4B7D-851F-6A2242382650}: NameServer = 69.50.184.85,195.225.176.37
O23 - Service: Application Layer Gateway Service (ALG) - Unknown owner - C:\WINDOWS.000\System32\alg.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Super Ad Blocker Service (SABSVC) - Unknown owner - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE (file missing)
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS.000\svcproc.exe (file missing)


-------------------------------------------------------------------------------------------------

thanks,
  • 0

#8
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
I am sorry but would you please post your complete HJT log. The top part is mising and is essential to a proper analysis. Thanks.

Regards,

Trevuren

  • 0

#9
Kalb

Kalb

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
sorry about that, i hope this is what u are looking for

-----------------------------------------------------------------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 8:02:57 PM, on 7/9/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS.000\System32\smss.exe
C:\WINDOWS.000\system32\csrss.exe
C:\WINDOWS.000\system32\winlogon.exe
C:\WINDOWS.000\system32\services.exe
C:\WINDOWS.000\system32\lsass.exe
C:\WINDOWS.000\system32\svchost.exe
C:\WINDOWS.000\system32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\system32\spoolsv.exe
C:\WINDOWS.000\Explorer.EXE
C:\Documents and Settings\All Users\Documents\HOTSYNC.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\World of Warcraft\WoW.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPass.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare Test\BearShare.exe" /pause
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - Global Startup: HotSync Manager.lnk = C:\Documents and Settings\All Users\Documents\HOTSYNC.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z....iTunesSetup.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{386CFD34-74FC-4B7D-851F-6A2242382650}: NameServer = 69.50.184.85,195.225.176.37
O23 - Service: Application Layer Gateway Service (ALG) - Unknown owner - C:\WINDOWS.000\System32\alg.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Super Ad Blocker Service (SABSVC) - Unknown owner - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE (file missing)
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS.000\svcproc.exe (file missing)



------------------------------------------------------------------------------------------------


Thanks,
  • 0

#10
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
A. We must stop, disable and delete an added service (023)

1. To stop a service and set to 'disabled'

Go to Start > Run and type in Services.msc then click OK

Click the Extended tab.

Scroll down until you find the service.

Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe

Click once on the service to highlight it.

Click Stop

Right-Click on the service.

Click on 'Properties'

Select the 'General' tab

Click the Arrow-down tab on the right-hand side on the 'Start-up Type' box

From the drop-down menu, click on 'Disabled'

Click the 'Apply' tab, then click 'OK'

The service is now stopped and disabled.


2. We will now delete the service:

1. Open HJT
2. Click on Config>>Misc Tools>>Delete an NT Service
3. Type SvcProc in the space provided and click OK
4. The program will ask you to REBOOT --- Accept

5. REBOOT into SAFE MODE

6. Using Windows Explorer, locate and DELETE the following file (if it still is present):

C:\WINDOWS\svcproc.exe

7. REBOOT back into Normal Mode

B. Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order in which they are mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

First we need to make all files and folders VISIBLE:

Go to start>control panel>folder options>view (tab)
*choose to "show hidden files and folders,"
*uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
*Close the window with ok
*All hidden files will now be visible

Please RUN HijackThis.
. Click the SCAN button to produce a log.

Place a check mark beside each one of the following items:

O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPass.exe
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O17 - HKLM\System\CCS\Services\Tcpip\..\{386CFD34-74FC-4B7D-851F-6A2242382650}: NameServer = 69.50.184.85,195.225.176.37



Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window and Reboot Your System in Safe Mode

How to use the F8 method to Start Your Computer in Safe Mode

*Restart the computer.
*as soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
*Use the arrow keys to select the Safe mode menu item
*press Enter.


Using Windows Explorer, locate the following folder, and DELETE it:

C:\Program Files\Media Pass

Exit Explorer, and REBOOT BACK INTO NORMAL MODE

Finally, RUN Hijackthis again and produce a new HJT log. Post it in the forum so we can check how everytjhing looks now.

Regards,

Trevuren

  • 0

#11
Kalb

Kalb

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
hey, i followed all the steps you gave me but when i went to delete "media pass" it wasnt there, i search my whole comp for it and it just said file not found. so heres what me new HJ log looks like.

----------------------------------------------------------------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 8:43:13 AM, on 7/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS.000\System32\smss.exe
C:\WINDOWS.000\system32\csrss.exe
C:\WINDOWS.000\system32\winlogon.exe
C:\WINDOWS.000\system32\services.exe
C:\WINDOWS.000\system32\lsass.exe
C:\WINDOWS.000\system32\svchost.exe
C:\WINDOWS.000\system32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\WINDOWS.000\system32\spoolsv.exe
C:\WINDOWS.000\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Documents and Settings\All Users\Documents\HOTSYNC.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS.000\system32\devldr32.exe
C:\WINDOWS.000\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: Name - {03D948DB-DBA5-41D1-969C-BF4DBAAACC5F} - C:\WINDOWS.000\System32\msqzg.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare Test\BearShare.exe" /pause
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - Global Startup: HotSync Manager.lnk = C:\Documents and Settings\All Users\Documents\HOTSYNC.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z....iTunesSetup.exe
O23 - Service: Application Layer Gateway Service (ALG) - Unknown owner - C:\WINDOWS.000\System32\alg.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Super Ad Blocker Service (SABSVC) - Unknown owner - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE (file missing


--------------------------------------------------------------------------------------------------


Thanks,
  • 0

#12
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
1. Please run the following program:
  • Please download WinHelp2002's DelDomains by right-clicking on the following link, and choosing "Save Target As":
    http://www.mvps.org/.../DelDomains.inf
  • Save the file to the desktop.
  • Then go to the desktop, right click on DelDomains.inf, and choose Install. You may not see any noticeable changes or prompts; this is normal.

2. Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order in which they are mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

First we need to make all files and folders VISIBLE:

Go to start>control panel>folder options>view (tab)
*choose to "show hidden files and folders,"
*uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
*Close the window with ok
*All hidden files will now be visible

Please RUN HijackThis.
. Click the SCAN button to produce a log.

Place a check mark beside each one of the following items:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: Name - {03D948DB-DBA5-41D1-969C-BF4DBAAACC5F} - C:\WINDOWS.000\System32\msqzg.dll (file missing)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z....iTunesSetup.exe



Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window and Reboot Your System in Safe Mode

How to use the F8 method to Start Your Computer in Safe Mode

*Restart the computer.
*as soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
*Use the arrow keys to select the Safe mode menu item
*press Enter.


Using Windows Explorer, locate the following files, and DELETE them (if they are present):

:\WINDOWS.000\System32\msqzg.dll

Exit Explorer, and REBOOT BACK INTO NORMAL MODE

Finally, RUN Hijackthis again and produce a new HJT log. Post it in the forum so we can check how everytjhing looks now.

Regards,

Trevuren

  • 0

#13
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP