Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

hijackthis log - please help


  • This topic is locked This topic is locked

#1
sasik

sasik

    New Member

  • Member
  • Pip
  • 9 posts
My browser (IE) stalls after couple of minutew and eny url is directed to http://badurl.gree....


Logfile of HijackThis v1.99.1
Scan saved at 12:29:32 PM, on 8/28/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\PROGRAM FILES\CISCO SYSTEMS\VPN CLIENT\CVPND.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\WINDOWS\SYSTEM\BTWS.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\SPEEDKEY.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\WINDOWS\SYSTEM\NISVCLOC.EXE
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\MOTIVE\MOTMON.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\TEMP\TD_0003.DIR\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drs...esearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drs...esearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\DSR.DLL
O2 - BHO: CeresObj Class - {00000049-8F91-4D9C-9573-F016E7626484} - C:\WINDOWS\CERES.DLL
O4 - HKLM\..\Run: [Microsoft IntelliType Pro] "C:\Program Files\Microsoft Hardware\Keyboard\speedkey.exe"
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [LVComs] C:\WINDOWS\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [niSvcLoc] C:\WINDOWS\SYSTEM\niSvcLoc.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\motmon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\SYGATE\SPF\SMC.EXE -startgui
O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKLM\..\RunServices: [Windows Session Manager] SMSS32.EXE
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [CVPND] "C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe" start
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [SmcService] C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {ED90FFBF-84E3-49E4-83CD-10206F78D9AC} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {B5491C29-9C4D-4880-A3A8-2A4808244D4E} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: Support - {5AD7C94D-F780-47AE-891E-49BDA8443A9E} - http://www.comcastsupport.com (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield Setup Player) - http://ftp.hp.com/pu...ayer/isetup.cab
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.bitstream...er/tdserver.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150...ip/RdxIE601.cab
O16 - DPF: {768D513A-C75B-4FAA-8452-E906CDAB6545} (FVLiteLoad Class) - http://digitalflip.b...ite/fvliteY.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.comcastsu...oad/tgctlcm.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.dell..../SysProfLCD.CAB
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.my-etrust...r/axscanner.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spys...tterInstall.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup...bridge-c382.cab
O16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} (Installer Class) - http://www.ysbweb.co...ysb_regular.cab
O16 - DPF: {5E8FD788-C323-4357-AB76-7CBCEFBA573C} (SpyBouncer.SBDownloader) - http://www.spybounce.../downloader.ocx
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.co...rols/Rovion.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - http://www.ysbweb.co...ysb_regular.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup...bridge-c293.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai...0/Installer.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.co...up1.0.0.8-2.cab
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.../ST/ActiveX.ocx
O16 - DPF: {7149E79C-DC19-4C5E-A53C-A54DDF75EEE9} (IObjSafety.DemoCtl) - http://cabs.media-mo...bs/joysaver.cab

Edited by sasik, 28 August 2005 - 03:29 PM.

  • 0

Advertisements


#2
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Hi and welcome to GeeksToGo! My name is Sam and I will be helping you. :tazz:

You are currently using hijackthis from a temp directory. This can cause problems. Please create a directory on your c: drive called c:\hijackthis and download and unzip hijackthis into that directory. Run the program from that directory from now on. It is essential that you follow these steps or certain important features of the program will not function correctly.

When you have Hijackthis running from a permanent folder, please reboot and post a new hijackthis log.
  • 0

#3
sasik

sasik

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Hi

This is my new hijack log
my browser works only for a couple of minutes after that it stalls I can not open any web page

Thanks for ur help

Logfile of HijackThis v1.99.1
Scan saved at 8:22:38 PM, on 8/30/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\PROGRAM FILES\CISCO SYSTEMS\VPN CLIENT\CVPND.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\SPEEDKEY.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\WINDOWS\SYSTEM\NISVCLOC.EXE
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\MOTIVE\MOTMON.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\HIJACKTHIS\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [Microsoft IntelliType Pro] "C:\Program Files\Microsoft Hardware\Keyboard\speedkey.exe"
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [LVComs] C:\WINDOWS\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [niSvcLoc] C:\WINDOWS\SYSTEM\niSvcLoc.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\motmon.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\SYGATE\SPF\SMC.EXE -startgui
O4 - HKLM\..\Run: [dnam] C:\D140113.A.STUB.EXE
O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKLM\..\RunServices: [Windows Session Manager] SMSS32.EXE
O4 - HKLM\..\RunServices: [CVPND] "C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe" start
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [SmcService] C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {ED90FFBF-84E3-49E4-83CD-10206F78D9AC} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {B5491C29-9C4D-4880-A3A8-2A4808244D4E} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: Support - {5AD7C94D-F780-47AE-891E-49BDA8443A9E} - http://www.comcastsupport.com (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield Setup Player) - http://ftp.hp.com/pu...ayer/isetup.cab
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.bitstream...er/tdserver.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150...ip/RdxIE601.cab
O16 - DPF: {768D513A-C75B-4FAA-8452-E906CDAB6545} (FVLiteLoad Class) - http://digitalflip.b...ite/fvliteY.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.comcastsu...oad/tgctlcm.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.dell..../SysProfLCD.CAB
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.my-etrust...r/axscanner.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spys...tterInstall.cab
O16 - DPF: {5E8FD788-C323-4357-AB76-7CBCEFBA573C} (SpyBouncer.SBDownloader) - http://www.spybounce.../downloader.ocx
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.co...rols/Rovion.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup...bridge-c293.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai...0/Installer.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.co...up1.0.0.8-2.cab
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.../ST/ActiveX.ocx
  • 0

#4
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Please make sure that you can VIEW ALL HIDDEN FILES.

Run Hijackthis again, click scan, and Put a checkmark next to each of these. Then close all other windows--you should only see HijackThis on your Desktop--and click the Fix Checked button.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [dnam] C:\D140113.A.STUB.EXE
O4 - HKLM\..\RunServices: [Windows Session Manager] SMSS32.EXE
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150...ip/RdxIE601.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup...bridge-c293.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.co...up1.0.0.8-2.cab




Please reboot your computer in SafeMode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
* if you have trouble getting into Safe mode go here for more info.




Once in Safe mode, delete these files or directories (Do not be concerned if they do not exist):

C:\D140113.A.STUB.EXE
SMSS32.EXE



Reboot back to normal mode.


Please download and install AVG antivirus. Follow the prompts to download and install all updates and then run a complete scan.

http://free.grisoft....E/lng/us/tpl/v5

Let me know what AVG finds.


Please post a new hijackthis log.
  • 0

#5
sasik

sasik

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
new hijack log
installes the avg nti virus and cleaned.
currently no virus found except in c:\ _restore\temp

still having the same problem
IE stalls after few minutes of starting the coomputer

thanks


Logfile of HijackThis v1.99.1
Scan saved at 8:46:54 PM, on 9/1/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\PROGRAM FILES\CISCO SYSTEMS\VPN CLIENT\CVPND.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\SPEEDKEY.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\WINDOWS\SYSTEM\NISVCLOC.EXE
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\MOTIVE\MOTMON.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\HIJACKTHIS\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O4 - HKLM\..\Run: [Microsoft IntelliType Pro] "C:\Program Files\Microsoft Hardware\Keyboard\speedkey.exe"
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [LVComs] C:\WINDOWS\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [niSvcLoc] C:\WINDOWS\SYSTEM\niSvcLoc.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\motmon.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\SYGATE\SPF\SMC.EXE -startgui
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKLM\..\RunServices: [CVPND] "C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe" start
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [SmcService] C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {ED90FFBF-84E3-49E4-83CD-10206F78D9AC} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {B5491C29-9C4D-4880-A3A8-2A4808244D4E} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: Support - {5AD7C94D-F780-47AE-891E-49BDA8443A9E} - http://www.comcastsupport.com (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield Setup Player) - http://ftp.hp.com/pu...ayer/isetup.cab
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.bitstream...er/tdserver.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {768D513A-C75B-4FAA-8452-E906CDAB6545} (FVLiteLoad Class) - http://digitalflip.b...ite/fvliteY.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.comcastsu...oad/tgctlcm.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.dell..../SysProfLCD.CAB
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.my-etrust...r/axscanner.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spys...tterInstall.cab
O16 - DPF: {5E8FD788-C323-4357-AB76-7CBCEFBA573C} (SpyBouncer.SBDownloader) - http://www.spybounce.../downloader.ocx
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.co...rols/Rovion.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai...0/Installer.exe
  • 0

#6
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Please download WebRoot SpySweeper from HERE (It's a 2 week trial):
  • Click the Free Trial link under to "SpySweeper" to download the program.
  • Install it.
  • Once the program is installed, it will open.
  • It will prompt you to update to the latest definitions, click Yes.
  • Once the definitions are installed, click Sweep Now on the left side.
  • Click the Start button.
  • When it's done scanning, click the Next button.
  • Make sure everything has a check next to it, then click the Next button.
  • It will remove all of the items found.
  • Click Session Log in the upper right corner, copy everything in that window.
  • Click the Summary tab and click Finish.
  • Paste the contents of the session log you copied into your next reply.

  • 0

#7
sasik

sasik

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Hi
I did spy sweep. it cleaned some files.

it did not help.
I will attach the log later , as I am not at my computer.

But I noticed something which might help you suggest.

After few minutes the IE is not connecting to any web site , it says page not found.

But it seems to be connecting to https:// , secured sites as I was able to connect to my work eamil site.

it is not connecting to any http: sites after first few minutes

is it something to with ie settings?

I tried 'reset settings' but it did not help.

does it give any idea?

thanks

this is my spsweeper log

********
10:32 PM: |··· Start of Session, Thursday, September 01, 2005 ···|
10:32 PM: Spy Sweeper started
10:32 PM: Sweep initiated using definitions version 492
10:32 PM: Starting Memory Sweep
10:33 PM: Warning: Failed to load image: C:\WINDOWS\SYSTEM\MSGSRV32.EXE
10:33 PM: Warning: Failed to load image: C:\WINDOWS\SYSTEM\MMTASK.TSK
10:33 PM: Warning: Failed to load image: C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
10:35 PM: Memory Sweep Complete, Elapsed Time: 00:02:16
10:35 PM: Starting Registry Sweep
10:35 PM: Found Trojan Horse: 2nd-thought
10:35 PM: HKCR\applications\mypcsearch.exe\ (ID = 647795)
10:35 PM: HKCR\applications\stc.exe\ (3 subtraces) (ID = 647796)
10:35 PM: HKCR\clsid\{8940e505-72c6-44de-be85-1d746780efbf}\ (13 subtraces) (ID = 647799)
10:35 PM: HKCR\interface\{6e0ed53c-9908-49ed-b055-7cb31b162577}\ (7 subtraces) (ID = 647800)
10:35 PM: HKCR\interface\{8c53bd8e-b12d-4c8f-ad0e-c9ddc39d1273}\ (8 subtraces) (ID = 647801)
10:35 PM: HKCR\interface\{9bcdd51b-4a7b-446c-8452-d32d38004582}\ (7 subtraces) (ID = 647802)
10:35 PM: HKCR\interface\{49db48ff-02b5-4645-b676-94a4df1aa026}\ (7 subtraces) (ID = 647803)
10:35 PM: HKCR\interface\{830d3aed-2fa9-454f-b266-d931862bbf34}\ (7 subtraces) (ID = 647804)
10:35 PM: HKCR\interface\{a986f4db-792e-4571-8974-0bb6e024766f}\ (7 subtraces) (ID = 647805)
10:35 PM: HKCR\interface\{bccab53d-0895-40c3-a942-a03538ce227a}\ (7 subtraces) (ID = 647806)
10:35 PM: HKCR\interface\{c0f88e9e-dceb-4655-968a-ae508a677c39}\ (7 subtraces) (ID = 647807)
10:35 PM: HKCR\interface\{d7eac2d8-2d52-4010-a4ad-dfdf60c1706c}\ (7 subtraces) (ID = 647808)
10:35 PM: HKU\.DEFAULT\software\2nd\ (2 subtraces) (ID = 647809)
10:35 PM: HKU\.DEFAULT\software\bundles\ (60 subtraces) (ID = 647810)
10:35 PM: HKLM\software\classes\applications\mypcsearch.exe\ (ID = 647811)
10:35 PM: HKLM\software\classes\applications\stc.exe\ (3 subtraces) (ID = 647812)
10:35 PM: HKLM\software\classes\interface\{6e0ed53c-9908-49ed-b055-7cb31b162577}\ (7 subtraces) (ID = 647815)
10:35 PM: HKLM\software\classes\interface\{8c53bd8e-b12d-4c8f-ad0e-c9ddc39d1273}\ (8 subtraces) (ID = 647816)
10:35 PM: HKLM\software\classes\interface\{9bcdd51b-4a7b-446c-8452-d32d38004582}\ (7 subtraces) (ID = 647817)
10:35 PM: HKLM\software\classes\interface\{49db48ff-02b5-4645-b676-94a4df1aa026}\ (7 subtraces) (ID = 647818)
10:35 PM: HKLM\software\classes\interface\{830d3aed-2fa9-454f-b266-d931862bbf34}\ (7 subtraces) (ID = 647819)
10:35 PM: HKLM\software\classes\interface\{a986f4db-792e-4571-8974-0bb6e024766f}\ (7 subtraces) (ID = 647820)
10:35 PM: HKLM\software\classes\interface\{bccab53d-0895-40c3-a942-a03538ce227a}\ (7 subtraces) (ID = 647821)
10:35 PM: HKLM\software\classes\interface\{c0f88e9e-dceb-4655-968a-ae508a677c39}\ (7 subtraces) (ID = 647822)
10:35 PM: HKLM\software\classes\interface\{d7eac2d8-2d52-4010-a4ad-dfdf60c1706c}\ (7 subtraces) (ID = 647823)
10:35 PM: HKLM\software\classes\swrt01.rt\ (3 subtraces) (ID = 647824)
10:35 PM: HKCR\swrt01.rt\ (3 subtraces) (ID = 647846)
10:35 PM: Found Adware: addestroyer
10:35 PM: HKCR\clsid\{417386c3-8d4a-4611-9b91-e57e89d603ac}\ (13 subtraces) (ID = 648530)
10:35 PM: HKCR\clsid\{d52433a9-a44c-43ab-a013-24b3c756dd2b}\ (13 subtraces) (ID = 648531)
10:35 PM: HKCR\interface\{10d7db96-56dc-4617-8eab-ec506abe6c7e}\ (8 subtraces) (ID = 648532)
10:35 PM: HKCR\interface\{6cdc3337-01f7-4a79-a4af-0b19303cc0be}\ (8 subtraces) (ID = 648534)
10:35 PM: HKCR\interface\{795398d0-dc2f-4118-a69c-592273ba9c2b}\ (8 subtraces) (ID = 648535)
10:35 PM: HKCR\interface\{b288f21c-a144-4ca2-9b70-8afa1fae4b06}\ (8 subtraces) (ID = 648536)
10:35 PM: HKCR\popoops2.popoops\ (3 subtraces) (ID = 648537)
10:35 PM: HKCR\swlad1.swlad\ (3 subtraces) (ID = 648538)
10:35 PM: HKLM\software\classes\clsid\{417386c3-8d4a-4611-9b91-e57e89d603ac}\ (13 subtraces) (ID = 648539)
10:35 PM: HKLM\software\classes\clsid\{d52433a9-a44c-43ab-a013-24b3c756dd2b}\ (13 subtraces) (ID = 648540)
10:35 PM: HKLM\software\classes\interface\{10d7db96-56dc-4617-8eab-ec506abe6c7e}\ (8 subtraces) (ID = 648541)
10:35 PM: HKLM\software\classes\interface\{6cdc3337-01f7-4a79-a4af-0b19303cc0be}\ (8 subtraces) (ID = 648543)
10:35 PM: HKLM\software\classes\interface\{795398d0-dc2f-4118-a69c-592273ba9c2b}\ (8 subtraces) (ID = 648544)
10:35 PM: HKLM\software\classes\interface\{b288f21c-a144-4ca2-9b70-8afa1fae4b06}\ (8 subtraces) (ID = 648545)
10:35 PM: HKLM\software\classes\popoops2.popoops\ (3 subtraces) (ID = 648546)
10:35 PM: HKLM\software\classes\swlad1.swlad\ (3 subtraces) (ID = 648547)
10:35 PM: HKLM\software\classes\typelib\{d0c29a75-7146-4737-98ee-bc4d7cf44af9}\ (9 subtraces) (ID = 648548)
10:35 PM: HKLM\software\classes\typelib\{e0d3b292-a0b0-4640-975c-2f882e039f52}\ (9 subtraces) (ID = 648549)
10:35 PM: HKCR\typelib\{d0c29a75-7146-4737-98ee-bc4d7cf44af9}\ (9 subtraces) (ID = 648552)
10:35 PM: HKCR\typelib\{e0d3b292-a0b0-4640-975c-2f882e039f52}\ (9 subtraces) (ID = 648553)
10:35 PM: Found Trojan Horse: alwaysupdatednews
10:35 PM: HKU\.default\software\aun\ (4 subtraces) (ID = 649315)
10:35 PM: HKU\.DEFAULT\software\aun\ (4 subtraces) (ID = 649322)
10:35 PM: Found Trojan Horse: backdoor-bdi
10:35 PM: HKLM\software\goidr\ (8 subtraces) (ID = 649661)
10:35 PM: Found Adware: blazefind_adstat
10:35 PM: HKLM\software\classes\winstatx.installer\ (3 subtraces) (ID = 650252)
10:35 PM: HKCR\winstatx.installer\ (3 subtraces) (ID = 650258)
10:35 PM: Found Adware: bonzi buddy
10:35 PM: HKCR\interface\{4bb35a55-a91a-11cf-ba7c-00a0d1001a5a}\ (8 subtraces) (ID = 650349)
10:35 PM: HKLM\software\classes\interface\{4bb35a55-a91a-11cf-ba7c-00a0d1001a5a}\ (8 subtraces) (ID = 650450)
10:35 PM: Found Adware: bookedspace
10:35 PM: HKLM\software\configuration manager\cfgmgr52\ (6 subtraces) (ID = 650537)
10:35 PM: Found Adware: cashback
10:35 PM: HKCR\clsid\{c0ef89ee-eec7-4535-a041-f1ebf79560a7}\ (14 subtraces) (ID = 651042)
10:35 PM: HKLM\software\classes\clsid\{c0ef89ee-eec7-4535-a041-f1ebf79560a7}\ (14 subtraces) (ID = 651045)
10:35 PM: HKLM\software\classes\typelib\{52cacfdf-9170-46a9-ae2e-e594d324c72a}\ (9 subtraces) (ID = 651047)
10:35 PM: HKLM\software\classes\webinstaller.cexecute\ (5 subtraces) (ID = 651048)
10:35 PM: HKCR\typelib\{52cacfdf-9170-46a9-ae2e-e594d324c72a}\ (9 subtraces) (ID = 651056)
10:35 PM: HKCR\webinstaller.cexecute\ (5 subtraces) (ID = 651057)
10:35 PM: Found Adware: cws-aboutblank
10:35 PM: HKU\.DEFAULT\software\microsoft\internet explorer\main\ || search bar_bak (ID = 661615)
10:35 PM: HKU\.DEFAULT\software\microsoft\internet explorer\main\ || search page_bak (ID = 661616)
10:36 PM: Found Adware: delfin
10:36 PM: HKU\.default\software\mvu\ (5 subtraces) (ID = 670560)
10:36 PM: HKLM\software\dsi\ (ID = 670577)
10:36 PM: HKLM\software\microsoft\windows\currentversion\uninstall\displayutility\ (2 subtraces) (ID = 670603)
10:36 PM: HKLM\software\motoin\ (2 subtraces) (ID = 670607)
10:36 PM: HKU\.DEFAULT\software\mvu\ (5 subtraces) (ID = 670608)
10:36 PM: HKLM\software\mvu\ (6 subtraces) (ID = 670609)
10:36 PM: HKLM\software\skin\ (ID = 670616)
10:36 PM: Found Adware: elitebar
10:36 PM: HKLM\software\ohbbackup\ (36 subtraces) (ID = 671442)
10:36 PM: HKLM\software\ohbbackup\elitesidebar\ (10 subtraces) (ID = 671443)
10:36 PM: HKLM\software\ohbbackup\elitetoolbar\ (24 subtraces) (ID = 671444)
10:36 PM: Found Adware: gain-supported software
10:36 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/hdplugin1019.dll\ (2 subtraces) (ID = 672409)
10:36 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\hdplugin1019.dll (ID = 672430)
10:36 PM: Found Adware: ieplugin
10:36 PM: HKCR\remove\ (ID = 673808)
10:36 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/wupdt.exe\ (1 subtraces) (ID = 673845)
10:36 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\wupdt.exe (ID = 673850)
10:36 PM: Found Adware: interads
10:36 PM: HKLM\software\interads\ (34470 subtraces) (ID = 674511)
10:36 PM: Found Adware: isearch toolbar
10:36 PM: HKU\.default\software\microsoft\internet explorer\extensions\cmdmapping\ || {1a00c40b-da85-4aa3-a67f-582d9347eecd} (ID = 674662)
10:36 PM: HKU\.DEFAULT\software\microsoft\internet explorer\extensions\cmdmapping\ || {1a00c40b-da85-4aa3-a67f-582d9347eecd} (ID = 674673)
10:36 PM: Found Adware: istbar
10:36 PM: HKCR\clsid\{7c559105-9ecf-42b8-b3f7-832e75edd959}\ (6 subtraces) (ID = 674702)
10:36 PM: HKCR\interface\{2ddd90d6-f153-4ea7-a324-4b2d83d1027e}\ (8 subtraces) (ID = 674715)
10:36 PM: HKCR\istx.installer\ (3 subtraces) (ID = 674725)
10:36 PM: HKLM\software\classes\clsid\{7c559105-9ecf-42b8-b3f7-832e75edd959}\ (6 subtraces) (ID = 674731)
10:36 PM: HKLM\software\classes\interface\{2ddd90d6-f153-4ea7-a324-4b2d83d1027e}\ (8 subtraces) (ID = 674739)
10:36 PM: HKLM\software\classes\istx.installer\ (3 subtraces) (ID = 674748)
10:36 PM: HKLM\software\classes\istx.installer\clsid\ (1 subtraces) (ID = 674749)
10:36 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\istactivex.dll (ID = 674828)
10:36 PM: Found Adware: 180search assistant
10:36 PM: HKU\.DEFAULT\software\180ax\ (18 subtraces) (ID = 681213)
10:36 PM: HKLM\software\180ax\ (13 subtraces) (ID = 681214)
10:36 PM: Found Adware: neededware
10:36 PM: HKLM\software\nwserv\ (6 subtraces) (ID = 681430)
10:36 PM: Found Adware: purityscan
10:36 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediaticketsinstaller.ocx\ (2 subtraces) (ID = 683425)
10:36 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\mediaticketsinstaller.ocx (ID = 684517)
10:36 PM: Found Adware: roings search enhancment
10:36 PM: HKCR\clsid\{7149e79c-dc19-4c5e-a53c-a54ddf75eee9}\ (27 subtraces) (ID = 685466)
10:36 PM: HKLM\software\classes\clsid\{7149e79c-dc19-4c5e-a53c-a54ddf75eee9}\inprocserver32\ (2 subtraces) (ID = 685516)
10:36 PM: HKLM\software\classes\clsid\{7149e79c-dc19-4c5e-a53c-a54ddf75eee9}\miscstatus\ (3 subtraces) (ID = 685517)
10:36 PM: HKLM\software\classes\clsid\{7149e79c-dc19-4c5e-a53c-a54ddf75eee9}\progid\ (1 subtraces) (ID = 685518)
10:36 PM: HKLM\software\classes\clsid\{7149e79c-dc19-4c5e-a53c-a54ddf75eee9}\toolboxbitmap32\ (1 subtraces) (ID = 685519)
10:36 PM: HKLM\software\classes\clsid\{7149e79c-dc19-4c5e-a53c-a54ddf75eee9}\typelib\ (1 subtraces) (ID = 685520)
10:36 PM: HKLM\software\classes\clsid\{7149e79c-dc19-4c5e-a53c-a54ddf75eee9}\version\ (1 subtraces) (ID = 685521)
10:36 PM: HKLM\software\classes\typelib\{466c63ac-f26e-49f1-861a-e07da768a46a}\ (9 subtraces) (ID = 685567)
10:36 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/m67m.ocx\ (2 subtraces) (ID = 685606)
10:36 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\m67m.ocx (ID = 685635)
10:36 PM: HKCR\typelib\{466c63ac-f26e-49f1-861a-e07da768a46a}\ (9 subtraces) (ID = 685659)
10:36 PM: Found Adware: searchbar toolbar
10:36 PM: HKCR\clsid\{aa8c93e1-7e5f-497e-b67c-cc8fe2a40d3b}\ (10 subtraces) (ID = 686226)
10:36 PM: HKCR\interface\{9ce15eb5-6b39-4656-9e1f-2d219ee42e0e}\ (8 subtraces) (ID = 686227)
10:36 PM: HKCR\searchbartoolbar.isubclass\ (3 subtraces) (ID = 686228)
10:36 PM: HKCR\searchbartoolbar.searchbar\ (3 subtraces) (ID = 686229)
10:36 PM: HKLM\software\classes\clsid\{aa8c93e1-7e5f-497e-b67c-cc8fe2a40d3b}\ (10 subtraces) (ID = 686232)
10:36 PM: HKLM\software\classes\interface\{9ce15eb5-6b39-4656-9e1f-2d219ee42e0e}\ (8 subtraces) (ID = 686233)
10:36 PM: HKLM\software\classes\searchbartoolbar.isubclass\ (3 subtraces) (ID = 686234)
10:36 PM: HKLM\software\classes\searchbartoolbar.searchbar\ (3 subtraces) (ID = 686235)
10:36 PM: HKU\.DEFAULT\software\e-ventures n.v.\ (ID = 686237)
10:36 PM: Found Adware: seekseek
10:36 PM: HKLM\software\jawa32\ (4 subtraces) (ID = 686945)
10:36 PM: Found Adware: seekseek.com hijacker
10:36 PM: HKLM\software\microsoft\internet explorer\search\ || search assistant (ID = 686991)
10:36 PM: Found Adware: shopathomeselect
10:36 PM: HKLM\software\ || test (ID = 687102)
10:36 PM: HKLM\software\classes\webinstaller.cexecute.1\ (3 subtraces) (ID = 687111)
10:36 PM: HKCR\webinstaller.cexecute.1\ (3 subtraces) (ID = 687153)
10:37 PM: Found Adware: subsearch
10:37 PM: HKCR\clsid\{9e992732-295f-4987-8be3-16fac1639198}\ (13 subtraces) (ID = 688502)
10:37 PM: HKCR\clsid\{d72a7651-8a16-476e-953c-347f0241fd32}\ (13 subtraces) (ID = 688506)
10:37 PM: HKCR\e.hh\ (3 subtraces) (ID = 688510)
10:37 PM: HKCR\e.zza\ (3 subtraces) (ID = 688511)
10:37 PM: HKCR\interface\{5a4e1627-8677-41f7-b78c-4cacdf5b12ff}\ (8 subtraces) (ID = 688516)
10:37 PM: HKCR\interface\{47d8f3a0-c511-4d91-a963-f00dddee4e49}\ (8 subtraces) (ID = 688518)
10:37 PM: HKLM\software\classes\clsid\{9e992732-295f-4987-8be3-16fac1639198}\ (13 subtraces) (ID = 688530)
10:37 PM: HKLM\software\classes\clsid\{d72a7651-8a16-476e-953c-347f0241fd32}\ (13 subtraces) (ID = 688534)
10:37 PM: HKLM\software\classes\e.hh\ (3 subtraces) (ID = 688538)
10:37 PM: HKLM\software\classes\e.zza\ (3 subtraces) (ID = 688539)
10:37 PM: HKLM\software\classes\interface\{5a4e1627-8677-41f7-b78c-4cacdf5b12ff}\ (8 subtraces) (ID = 688544)
10:37 PM: HKLM\software\classes\interface\{47d8f3a0-c511-4d91-a963-f00dddee4e49}\ (8 subtraces) (ID = 688546)
10:37 PM: HKLM\software\classes\typelib\{b929c108-045f-48d1-8638-e3195ad6ff03}\ (9 subtraces) (ID = 688559)
10:37 PM: HKCR\typelib\{b929c108-045f-48d1-8638-e3195ad6ff03}\ (9 subtraces) (ID = 688570)
10:37 PM: Found Adware: surfsidekick
10:37 PM: HKU\.default\software\surfsidekick3\ (3 subtraces) (ID = 688850)
10:37 PM: HKLM\software\surfsidekick2\ (2 subtraces) (ID = 688874)
10:37 PM: HKU\.DEFAULT\software\surfsidekick3\ (3 subtraces) (ID = 688875)
10:37 PM: HKLM\software\surfsidekick3\ (2 subtraces) (ID = 688876)
10:37 PM: Found Adware: teenxxx (tinybar)
10:37 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\istactivex.dll (ID = 689125)
10:37 PM: Found Adware: virtualbouncer
10:37 PM: HKLM\software\classes\clsid\{8940e505-72c6-44de-be85-1d746780efbf}\ (13 subtraces) (ID = 690965)
10:37 PM: HKLM\software\classes\typelib\{5e594162-60a9-487d-84b8-dbdd716cb862}\ (9 subtraces) (ID = 690967)
10:37 PM: HKCR\typelib\{5e594162-60a9-487d-84b8-dbdd716cb862}\ (9 subtraces) (ID = 690981)
10:37 PM: Found Adware: abetterinternet
10:37 PM: HKLM\software\sdf7sdfgs324\ (ID = 691546)
10:37 PM: Found Adware: webrebates
10:37 PM: HKCR\clsid\{01fc5803-8644-45d7-877b-5a3924d8ecc4}\ (13 subtraces) (ID = 691718)
10:37 PM: HKCR\imgconv.clsimgconv\ (3 subtraces) (ID = 691719)
10:37 PM: HKLM\software\classes\clsid\{01fc5803-8644-45d7-877b-5a3924d8ecc4}\ (13 subtraces) (ID = 691720)
10:37 PM: HKLM\software\classes\imgconv.clsimgconv\ (3 subtraces) (ID = 691721)
10:37 PM: HKLM\software\classes\typelib\{15e7d23b-736e-46fa-bffd-cbec4126befd}\ (9 subtraces) (ID = 691722)
10:37 PM: HKCR\typelib\{15e7d23b-736e-46fa-bffd-cbec4126befd}\ (9 subtraces) (ID = 691736)
10:37 PM: Found Adware: websearch toolbar
10:37 PM: HKCR\protocols\name-space handler\res\ (ID = 691796)
10:37 PM: HKLM\software\classes\protocols\name-space handler\res\ (ID = 691859)
10:37 PM: HKLM\software\classes\typelib\{8992b6ca-b8c9-4aed-bf89-0a17f6296a06}\ (9 subtraces) (ID = 691877)
10:37 PM: HKCR\typelib\{8992b6ca-b8c9-4aed-bf89-0a17f6296a06}\ (9 subtraces) (ID = 691967)
10:37 PM: Found Adware: winad
10:37 PM: HKCR\mediaaccx.installer\ (3 subtraces) (ID = 692591)
10:37 PM: HKLM\software\classes\mediaaccx.installer\ (3 subtraces) (ID = 692606)
10:37 PM: HKLM\software\media access\ (5 subtraces) (ID = 692616)
10:37 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediaaccx.dll\ (2 subtraces) (ID = 692625)
10:37 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\mediaaccx.dll (ID = 692656)
10:37 PM: Found Adware: yoursitebar
10:37 PM: HKCR\clsid\{42f2c9ba-614f-47c0-b3e3-ecfd34eed658}\ (8 subtraces) (ID = 693268)
10:37 PM: HKCR\clsid\{771a1334-6b08-4a6b-aedc-cf994ba2cebe}\ (11 subtraces) (ID = 693269)
10:37 PM: HKCR\interface\{bf06da8e-2beb-4816-9bbd-f7625246e245}\ (8 subtraces) (ID = 693273)
10:37 PM: HKLM\software\classes\clsid\{771a1334-6b08-4a6b-aedc-cf994ba2cebe}\ (11 subtraces) (ID = 693275)
10:37 PM: HKLM\software\classes\interface\{bf06da8e-2beb-4816-9bbd-f7625246e245}\ (8 subtraces) (ID = 693279)
10:37 PM: HKLM\software\classes\typelib\{db447818-96b4-40df-8a55-720da496f514}\ (9 subtraces) (ID = 693283)
10:37 PM: HKLM\software\classes\ysbactivex.installer.1\ (3 subtraces) (ID = 693287)
10:37 PM: HKLM\software\classes\ysbactivex.installer\ (3 subtraces) (ID = 693288)
10:37 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/ysbactivex.dll\ (2 subtraces) (ID = 693293)
10:37 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\ysbactivex.dll (ID = 693297)
10:37 PM: HKCR\typelib\{db447818-96b4-40df-8a55-720da496f514}\ (9 subtraces) (ID = 693303)
10:37 PM: HKCR\ysbactivex.installer.1\ (3 subtraces) (ID = 693307)
10:37 PM: HKCR\ysbactivex.installer.1\clsid\ (1 subtraces) (ID = 693308)
10:37 PM: HKCR\ysbactivex.installer\ (3 subtraces) (ID = 693309)
10:37 PM: Registry Sweep Complete, Elapsed Time:00:02:15
10:37 PM: Starting Cookie Sweep
10:37 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
10:37 PM: Starting File Sweep
10:37 PM: Warning: Failed to open file "c:\windows\win386.swp". The process cannot access the file because it is being used by another process
10:38 PM: Found Adware: ie driver
10:38 PM: setup304.exe (ID = 594175)
10:38 PM: Found Adware: look2me
10:38 PM: wrapperouter.exe (ID = 597299)
10:38 PM: Found System Monitor: networkessentials
10:38 PM: inetfuel.exe (ID = 602540)
10:38 PM: edow_as2.exe (ID = 616084)
10:38 PM: abasaasdadadasdasdadad5jrp.fdasfexesfsaf (ID = 607525)
10:38 PM: thin-175-1-x-x.exe (ID = 615666)
10:38 PM: jawa32.dat (ID = 607177)
10:38 PM: jawa32e.bin (ID = 607179)
10:38 PM: Found Adware: zestyfind desktop links
10:38 PM: iconz2.exe (ID = 623434)
10:38 PM: Found Adware: spyblocs
10:38 PM: icont.exe (ID = 608554)
10:38 PM: Found Adware: bargain buddy
10:38 PM: ahadp.exe (ID = 580885)
10:38 PM: Found Adware: adlogix
10:38 PM: nmznce.xml (ID = 579665)
10:38 PM: nmznca.xml (ID = 579661)
10:38 PM: nmzncb.xml (ID = 579662)
10:38 PM: sslstr.dll (ID = 597214)
10:38 PM: swrt01.dll (ID = 614935)
10:38 PM: dnstyle.dll (ID = 597214)
10:38 PM: ckbinet.dll (ID = 597214)
10:38 PM: doolsav.dat (ID = 590534)
10:38 PM: udbui.dll (ID = 597214)
10:38 PM: rz3228_8.dll (ID = 597101)
10:38 PM: ibs.dll (ID = 597101)
10:38 PM: winupdt.bin (ID = 578628)
10:38 PM: notdi.dll (ID = 597214)
10:38 PM: fnntext.dll (ID = 597214)
10:38 PM: wevdmoe.dll (ID = 597214)
10:38 PM: ipcenc.dll (ID = 597214)
10:38 PM: itthka.xml (ID = 579611)
10:38 PM: itthkb.xml (ID = 579670)
10:38 PM: itthkd.exe (ID = 579573)
10:38 PM: itthke.xml (ID = 579588)
10:38 PM: itthkf.exe (ID = 579674)
10:38 PM: mlcn30.dll (ID = 597214)
10:38 PM: lrui2.dll (ID = 597214)
10:38 PM: mfwebdvd.dll (ID = 597214)
10:38 PM: Found Adware: couponage
10:38 PM: dosync.dll (ID = 585420)
10:38 PM: mgvcp60d.dll (ID = 597214)
10:38 PM: lctif11n.dll (ID = 597214)
10:38 PM: jdsd400.dll (ID = 597214)
10:38 PM: lurtrend.dll (ID = 597214)
10:38 PM: jxvaprxy.dll (ID = 597214)
10:38 PM: wxnmm.dll (ID = 597214)
10:38 PM: mvacm32.dll (ID = 597214)
10:38 PM: vhp6renu.dll (ID = 597107)
10:38 PM: nnini32.dll (ID = 597101)
10:38 PM: ricreg32.dll (ID = 597101)
10:38 PM: hftplug.dll (ID = 597101)
10:38 PM: mkdocs.dll (ID = 597101)
10:38 PM: wli.dll (ID = 597101)
10:38 PM: cpoosusr.dll (ID = 597214)
10:38 PM: nwtbios.dll (ID = 597214)
10:38 PM: vaar332.dll (ID = 597101)
10:38 PM: aykrnl32.dll (ID = 597101)
10:38 PM: lbexpand.dll (ID = 597101)
10:38 PM: prspl.dll (ID = 597101)
10:38 PM: aasnw.dll (ID = 597101)
10:38 PM: nkcpl.dll (ID = 597101)
10:38 PM: mels31.dll (ID = 597214)
10:38 PM: mxrpjt40.dll (ID = 597214)
10:38 PM: uebui.dll (ID = 597101)
10:38 PM: dyavi.dll (ID = 597101)
10:38 PM: fr10.dll (ID = 597214)
10:38 PM: brtmeter.dll (ID = 597214)
10:38 PM: raaserv.dll (ID = 597214)
10:38 PM: mbdbg.dll (ID = 597214)
10:38 PM: rbgwizc.dll (ID = 597214)
10:38 PM: mkrepl35.dll (ID = 597214)
10:38 PM: wnbvw.dll (ID = 597214)
10:38 PM: ozbcint.dll (ID = 597214)
10:38 PM: mbwsock.dll (ID = 597214)
10:38 PM: smverrc.dll (ID = 597214)
10:38 PM: mvcn30.dll (ID = 597214)
10:38 PM: mrdbg.dll (ID = 597107)
10:38 PM: lzsock.dll (ID = 597101)
10:38 PM: mpxml4.dll (ID = 597214)
10:38 PM: nltdi.dll (ID = 597107)
10:38 PM: vhblock.dll (ID = 597214)
10:38 PM: dktaclen.dll (ID = 597107)
10:38 PM: drnim.dll (ID = 597107)
10:38 PM: woascr.dll (ID = 597107)
10:38 PM: pf.dll (ID = 597107)
10:38 PM: mcdxmlc.dll (ID = 597107)
10:38 PM: afsldp.dll (ID = 597107)
10:38 PM: sigr.dll (ID = 597101)
10:38 PM: imgconv.dll (ID = 616086)
10:38 PM: wwpapi32.dll (ID = 597101)
10:38 PM: siwiudll.dll (ID = 597101)
10:38 PM: thapi.dll (ID = 597101)
10:38 PM: mbnsspc.dll (ID = 597101)
10:38 PM: unregister.exe (ID = 606720)
10:38 PM: wlastatd.dll (ID = 597101)
10:38 PM: etenu.dll (ID = 597101)
10:38 PM: wvw32.dll (ID = 597101)
10:38 PM: aocodc32.dll (ID = 597101)
10:38 PM: dutrans.dll (ID = 597101)
10:38 PM: wpw32.dll (ID = 597101)
10:38 PM: sq5x_32.dll (ID = 597101)
10:38 PM: wuw32.dll (ID = 597101)
10:38 PM: dhdxof.dll (ID = 597101)
10:38 PM: nptdi.dll (ID = 597101)
10:38 PM: ahicap.dll (ID = 597101)
10:38 PM: hcd.dll (ID = 597101)
10:38 PM: vob32.dll (ID = 597101)
10:38 PM: irsapi32.dll (ID = 597101)
10:38 PM: mvdbgen.dll (ID = 597101)
10:38 PM: snsthunk.dll (ID = 597101)
10:38 PM: vqb32.dll (ID = 597101)
10:38 PM: iumupg.dll (ID = 597101)
10:38 PM: dtvcon32.dll (ID = 597101)
10:38 PM: mddbg.dll (ID = 597101)
10:38 PM: meapsspc.dll (ID = 597101)
10:38 PM: iathk.dll (ID = 597101)
10:39 PM: c:\windows\start menu\programs\web search tools (ID = 620009)
10:39 PM: sskknwrd.dll (ID = 609890)
10:39 PM: sskcwrd.dll (ID = 609870)
10:39 PM: Found Adware: tvmedia
10:39 PM: tvmknwrd.dll (ID = 613773)
10:39 PM: hbovst08.dll (ID = 597101)
10:39 PM: hodci.dll (ID = 597101)
10:39 PM: bsseball.dll (ID = 597101)
10:39 PM: vdodctl.dll (ID = 597101)
10:39 PM: whpns.dll (ID = 597101)
10:39 PM: mubind.dll (ID = 597101)
10:39 PM: owtlwab.dll (ID = 597101)
10:39 PM: htzc3212.dll (ID = 597101)
10:39 PM: dmound3d.dll (ID = 597101)
10:39 PM: cyrviddc.dll (ID = 597101)
10:39 PM: arsnw.dll (ID = 597101)
10:39 PM: uaer32.dll (ID = 597101)
10:39 PM: wxpns.dll (ID = 597101)
10:40 PM: backup-20050828-174911-680.dll (ID = 615365)
10:40 PM: backup-20050828-203738-650.dll (ID = 615365)
10:40 PM: ysbactivex.inf (ID = 623317)
10:40 PM: hdplugin1019.dll (ID = 592296)
10:40 PM: hdplugin1019.inf (ID = 592297)
10:40 PM: hdplugin1019.dll (ID = 592296)
10:40 PM: hdplugin1019.inf (ID = 592297)
10:40 PM: hdplugin1019.dll (ID = 592296)
10:40 PM: hdplugin1019.inf (ID = 592297)
10:40 PM: hdplugin1019.dll (ID = 592296)
10:40 PM: hdplugin1019.inf (ID = 592297)
10:40 PM: hdplugin1101.dll (ID = 592301)
10:40 PM: hdplugin1101.inf (ID = 592304)
10:40 PM: c:\windows\all users\application data\ieservice (1 subtraces) (ID = 609579)
10:40 PM: c:\windows\all users\application data\nsv (17 subtraces) (ID = 588507)
10:40 PM: c:\windows\all users\application data\vmss (2 subtraces) (ID = 588511)
10:40 PM: c:\windows\all users\application data\picsvr (1 subtraces) (ID = 588509)
10:41 PM: c:\windows\bundles (54 subtraces) (ID = 578638)
10:41 PM: hdplugin1019.dll (ID = 592296)
10:41 PM: hdplugin1019.dll (ID = 592296)
10:41 PM: hdplugin1019.inf (ID = 592297)
10:41 PM: hdplugin1019.dll (ID = 592296)
10:41 PM: hdplugin1019.inf (ID = 592297)
10:41 PM: hdplugin1019.dll (ID = 592296)
10:41 PM: hdplugin1019.inf (ID = 592297)
10:41 PM: wmv2007.dbd (ID = 588360)
10:41 PM: wmv1125.ddx (ID = 588352)
10:41 PM: wmv1920.dbd (ID = 588359)
10:41 PM: wmv1909.ddx (ID = 588351)
10:41 PM: Found Trojan Horse: trojan-downloader-bookedspace
10:41 PM: bs5-cvuacy.exe (ID = 612437)
10:41 PM: Found Adware: my daily horoscope
10:41 PM: setup_silent_14725.exe (ID = 601658)
10:41 PM: webrebates_auto_installsilent.exe (ID = 616141)
10:41 PM: thin-8-1-x-x.exe (ID = 615640)
10:41 PM: Found Adware: clearsearch
10:41 PM: csv10p070.exe (ID = 583230)
10:41 PM: beryllium.exe (ID = 604598)
10:41 PM: bs5-goodyr1.exe (ID = 582066)
10:41 PM: adl_mteststub.exe (ID = 588337)
10:41 PM: c:\windows\bsx32 (77 subtraces) (ID = 582101)
10:42 PM: Found Adware: ezula ilookup
10:42 PM: ezstub_ropwo.exe (ID = 591213)
10:42 PM: wrapperouter.exe (ID = 614890)
10:42 PM: Found Adware: tinkopal
10:42 PM: new_vcm.exe (ID = 611775)
10:43 PM: removedisplayutility.exe (ID = 588445)
10:45 PM: c:\program files\vbouncer (ID = 614994)
10:46 PM: c:\program files\recommended hotfix - 421701d (2 subtraces) (ID = 602548)
10:46 PM: Found Adware: starware toolbar
10:46 PM: c:\program files\starware (1 subtraces) (ID = 609079)
10:46 PM: c:\program files\adtools service (1 subtraces) (ID = 622656)
10:47 PM: Found Adware: adtools
10:47 PM: adtools.exe (ID = 579764)
10:48 PM: d3d2d4.tmp (ID = 607180)
10:48 PM: ~901495.tmp (ID = 619149)
10:48 PM: ~901460.tmp (ID = 619149)
10:48 PM: ~895878.tmp (ID = 619149)
10:48 PM: ~895852.tmp (ID = 619149)
10:48 PM: ~872097.tmp (ID = 619149)
10:48 PM: ~868673.tmp (ID = 619149)
10:48 PM: ~868637.tmp (ID = 619149)
10:48 PM: ~854515.tmp (ID = 619149)
10:48 PM: ~854491.tmp (ID = 619149)
10:48 PM: ~796054.tmp (ID = 619149)
10:48 PM: ~796052.tmp (ID = 619149)
10:48 PM: tvm.upd (ID = 613699)
10:48 PM: tvm_.exe (ID = 613689)
10:48 PM: coreak.dll (ID = 595004)
10:48 PM: File Sweep Complete, Elapsed Time: 00:11:15
10:48 PM: Full Sweep has completed. Elapsed time 00:15:49
10:48 PM: Traces Found: 36063
10:49 PM: Removal process initiated
10:49 PM: Quarantining All Traces: 2nd-thought
10:49 PM: Quarantining All Traces: addestroyer
10:49 PM: Quarantining All Traces: alwaysupdatednews
10:49 PM: Quarantining All Traces: backdoor-bdi
10:49 PM: Quarantining All Traces: blazefind_adstat
10:49 PM: Quarantining All Traces: bonzi buddy
10:49 PM: Quarantining All Traces: bookedspace
10:49 PM: Quarantining All Traces: cashback
10:49 PM: Quarantining All Traces: cws-aboutblank
10:49 PM: Quarantining All Traces: delfin
10:49 PM: Quarantining All Traces: elitebar
10:49 PM: Quarantining All Traces: gain-supported software
10:49 PM: Quarantining All Traces: ieplugin
10:49 PM: Quarantining All Traces: interads
10:49 PM: Quarantining All Traces: isearch toolbar
10:49 PM: Quarantining All Traces: istbar
10:49 PM: Quarantining All Traces: 180search assistant
10:49 PM: Quarantining All Traces: neededware
10:49 PM: Quarantining All Traces: purityscan
10:49 PM: Quarantining All Traces: roings search enhancment
10:49 PM: Quarantining All Traces: searchbar toolbar
10:49 PM: Quarantining All Traces: seekseek
10:49 PM: Quarantining All Traces: seekseek.com hijacker
10:50 PM: Quarantining All Traces: shopathomeselect
10:50 PM: Quarantining All Traces: subsearch
10:50 PM: Quarantining All Traces: surfsidekick
10:50 PM: Quarantining All Traces: teenxxx (tinybar)
10:50 PM: Quarantining All Traces: virtualbouncer
10:50 PM: Quarantining All Traces: abetterinternet
10:50 PM: Quarantining All Traces: webrebates
10:50 PM: Quarantining All Traces: websearch toolbar
10:50 PM: Quarantining All Traces: winad
10:50 PM: Quarantining All Traces: yoursitebar
10:50 PM: Quarantining All Traces: ie driver
10:50 PM: Quarantining All Traces: look2me
10:52 PM: Quarantining All Traces: networkessentials
10:52 PM: Quarantining All Traces: zestyfind desktop links
10:52 PM: Quarantining All Traces: spyblocs
10:52 PM: Quarantining All Traces: bargain buddy
10:52 PM: Quarantining All Traces: adlogix
10:52 PM: Quarantining All Traces: couponage
10:52 PM: Quarantining All Traces: tvmedia
********

Edited by sasik, 02 September 2005 - 04:33 PM.

  • 0

#8
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Follow the instructions at this page to repair IE.

http://support.earth...0/8458.psc.html


Let me know if that resolves your problem. It looks like Spysweeper got rid of a lot of malware for you.

Please post a new hijackthis log.
  • 0

#9
sasik

sasik

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Hi
I did repair the IE
it does not help

Actually IE does not connect to any http: after few minutes of starting the computer. but connecting to https: sites for few more minutes.
after that it does not connet to any sites.
it says page can not br found.

this is the hijack log when the IE stops working

thanks

BUT when IE is not able to connect , pinging and VPN connections are working fine.

it seems after few minutes of starting the computer something is blocking internet connection.

thanks

Logfile of HijackThis v1.99.1
Scan saved at 11:26:27 AM, on 9/3/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\PROGRAM FILES\CISCO SYSTEMS\VPN CLIENT\CVPND.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\SPEEDKEY.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE
C:\WINDOWS\SYSTEM\NISVCLOC.EXE
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\MOTIVE\MOTMON.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\WRSSSDK.EXE
C:\HIJACKTHIS\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O4 - HKLM\..\Run: [Microsoft IntelliType Pro] "C:\Program Files\Microsoft Hardware\Keyboard\speedkey.exe"
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [LVComs] C:\WINDOWS\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [niSvcLoc] C:\WINDOWS\SYSTEM\niSvcLoc.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\motmon.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [SpySweeper] "C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE" /startintray
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\SYGATE\SPF\SMC.EXE -startgui
O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKLM\..\RunServices: [CVPND] "C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe" start
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [SmcService] C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {ED90FFBF-84E3-49E4-83CD-10206F78D9AC} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {B5491C29-9C4D-4880-A3A8-2A4808244D4E} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: Support - {5AD7C94D-F780-47AE-891E-49BDA8443A9E} - http://www.comcastsupport.com (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield Setup Player) - http://ftp.hp.com/pu...ayer/isetup.cab
O16 - DPF: {768D513A-C75B-4FAA-8452-E906CDAB6545} (FVLiteLoad Class) - http://digitalflip.b...ite/fvliteY.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.comcastsu...oad/tgctlcm.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.dell..../SysProfLCD.CAB

Edited by sasik, 03 September 2005 - 10:23 AM.

  • 0

#10
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Follow the instructions on this page for restoring IE settings.
http://www.xtra.co.n...-561047,00.html


Open Notepad, and copy everything in the code box below and paste it into a new notepad file. Change the "Save As Type" to "All Files". Save it as fixme.reg on your Desktop. Make sure there is NO blank line above "REGEDIT4"!


REGEDIT4 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search] 
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" 
"CustomizeSearch"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm" 
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Bar"="Search Bar"="http://search.msn.com/intl/searchpane/en-au/prov2.htm"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] 
""="http://home.microsoft.com/access/autosearch.asp?p=%s" 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\main] 
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Bar"="http://search.msn.com/spbasic.htm"
"Use Custom Search URL"= dword:00000000

[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="" 

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
@="http://"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes]
"ftp"="ftp://"
"gopher"="gopher://"
"home"="http://"
"mosaic"="http://"
"www"="http://"


Locate fixme.reg on your Desktop and double-click on it. When it asks if you want to merge with the registry, click YES.



If you are still having problems after these steps download and run Winsock Fix.

http://www.geekstogo...tion=show&id=21



Let me know how it goes. There may be one more thing we can check, but I want to see if these steps work first.
  • 0

Advertisements


#11
sasik

sasik

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Hi

I did reset and winsock fix also.

It does not seem to help . I even stopped running firewall

this is the hijack log

thanks


Logfile of HijackThis v1.99.1
Scan saved at 12:12:28 PM, on 9/4/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\PROGRAM FILES\CISCO SYSTEMS\VPN CLIENT\CVPND.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\SPEEDKEY.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\WINDOWS\SYSTEM\NISVCLOC.EXE
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\MOTIVE\MOTMON.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\WRSSSDK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HIJACKTHIS\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O4 - HKLM\..\Run: [Microsoft IntelliType Pro] "C:\Program Files\Microsoft Hardware\Keyboard\speedkey.exe"
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [LVComs] C:\WINDOWS\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [niSvcLoc] C:\WINDOWS\SYSTEM\niSvcLoc.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\motmon.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [SpySweeper] "C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE" /startintray
O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKLM\..\RunServices: [CVPND] "C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe" start
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {ED90FFBF-84E3-49E4-83CD-10206F78D9AC} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {B5491C29-9C4D-4880-A3A8-2A4808244D4E} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: Support - {5AD7C94D-F780-47AE-891E-49BDA8443A9E} - http://www.comcastsupport.com (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield Setup Player) - http://ftp.hp.com/pu...ayer/isetup.cab
O16 - DPF: {768D513A-C75B-4FAA-8452-E906CDAB6545} (FVLiteLoad Class) - http://digitalflip.b...ite/fvliteY.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.comcastsu...oad/tgctlcm.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.dell..../SysProfLCD.CAB
  • 0

#12
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Download and install Firefox as an alternate browser.

http://www.mozilla.o...oducts/firefox/


Let me know if you are having any problems with it, or is it just IE.
  • 0

#13
sasik

sasik

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
I had mozilla installed earlier. just yesterday I uninstalled it. it also had the same issue.

it does not work even if the pc is idle for few minutes after starting.

it seems the theinternat connection is geting blocked. but strangely https:// is working when any http:// it says 'page not found' it is really frustrating.

I even did a restore to the point before I did not have this issue. but still the problem was not resolved.

Edited by sasik, 04 September 2005 - 06:32 PM.

  • 0

#14
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
So the problem is not solely with IE, if you have the same issues with Firefox.

Have you completely uninstalled Sygate firewall, or just disabled it?
Did you have another firewall installed prior to that?
  • 0

#15
sasik

sasik

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Yes I unistalled it.
I had EZ trust firewall before that. I unistalled that too.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP