Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

AIM crashes constantly, HijackThis log attatched..


  • Please log in to reply

#1
JeremyC

JeremyC

    New Member

  • Member
  • Pip
  • 1 posts
So, whenever I receive an IM or whenever I double click someone's name to IM them, BOOM, AIM crashes...Someone please help me out, this is very frustrating.

Here's my HijackThis log...


Logfile of HijackThis v1.99.1
Scan saved at 4:08:43 PM, on 8/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Communities.com\ThePalace\Palace32.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iolo\Search and Recover 3\SearchAndRecover.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Media Player\wmplayer.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Jeremy Collins\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\idlnl.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\idlnl.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\idlnl.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\idlnl.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\idlnl.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\idlnl.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {2055AB9C-D601-4B4E-27D9-C624057DDAA5} - C:\WINDOWS\msbk.dll
O2 - BHO: Class - {3F168309-460C-3C13-633D-8B2D81732BD0} - C:\WINDOWS\apieu.dll
O2 - BHO: Class - {5B86A516-4121-F602-C428-DD7BCCE4EE39} - C:\WINDOWS\wincq32.dll
O2 - BHO: Class - {9E3D1C5A-F8F5-338E-1E66-F07121E58D61} - C:\WINDOWS\mfcox32.dll
O2 - BHO: Class - {FFB2B347-F318-AD04-9CDF-925741BAA0FA} - C:\WINDOWS\ntqq.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [winsf32.exe] C:\WINDOWS\winsf32.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [crbs.exe] C:\WINDOWS\crbs.exe
O4 - HKLM\..\RunOnce: [crhj.exe] C:\WINDOWS\system32\crhj.exe
O4 - HKLM\..\RunOnce: [nteo32.exe] C:\WINDOWS\nteo32.exe
O4 - HKLM\..\RunOnce: [sdkoe32.exe] C:\WINDOWS\sdkoe32.exe
O4 - HKLM\..\RunOnce: [crjz.exe] C:\WINDOWS\system32\crjz.exe
O4 - HKLM\..\RunOnce: [apijm.exe] C:\WINDOWS\apijm.exe
O4 - HKLM\..\RunOnce: [atlmy.exe] C:\WINDOWS\atlmy.exe
O4 - HKLM\..\RunOnce: [ipvn32.exe] C:\WINDOWS\system32\ipvn32.exe
O4 - HKLM\..\RunOnce: [msai.exe] C:\WINDOWS\system32\msai.exe
O4 - HKLM\..\RunOnce: [d3gt32.exe] C:\WINDOWS\system32\d3gt32.exe
O4 - HKLM\..\RunOnce: [apisk32.exe] C:\WINDOWS\system32\apisk32.exe
O4 - HKLM\..\RunOnce: [netai32.exe] C:\WINDOWS\netai32.exe
O4 - HKLM\..\RunOnce: [iexj32.exe] C:\WINDOWS\iexj32.exe
O4 - HKLM\..\RunOnce: [msfr32.exe] C:\WINDOWS\msfr32.exe
O4 - HKLM\..\RunOnce: [sdknc.exe] C:\WINDOWS\system32\sdknc.exe
O4 - HKLM\..\RunOnce: [atlwm.exe] C:\WINDOWS\atlwm.exe
O4 - HKLM\..\RunOnce: [javaiz.exe] C:\WINDOWS\system32\javaiz.exe
O4 - HKLM\..\RunOnce: [applp32.exe] C:\WINDOWS\applp32.exe
O4 - HKLM\..\RunOnce: [crmv.exe] C:\WINDOWS\system32\crmv.exe
O4 - HKLM\..\RunOnce: [mfcvy.exe] C:\WINDOWS\mfcvy.exe
O4 - HKLM\..\RunOnce: [ipaa.exe] C:\WINDOWS\system32\ipaa.exe
O4 - HKLM\..\RunOnce: [netmq.exe] C:\WINDOWS\system32\netmq.exe
O4 - HKLM\..\RunOnce: [msvw32.exe] C:\WINDOWS\system32\msvw32.exe
O4 - HKLM\..\RunOnce: [atlak.exe] C:\WINDOWS\system32\atlak.exe
O4 - HKLM\..\RunOnce: [javagi32.exe] C:\WINDOWS\system32\javagi32.exe
O4 - HKLM\..\RunOnce: [d3th32.exe] C:\WINDOWS\system32\d3th32.exe
O4 - HKLM\..\RunOnce: [applm.exe] C:\WINDOWS\system32\applm.exe
O4 - HKLM\..\RunOnce: [apiub.exe] C:\WINDOWS\apiub.exe
O4 - HKLM\..\RunOnce: [javawj.exe] C:\WINDOWS\javawj.exe
O4 - HKLM\..\RunOnce: [ntlj32.exe] C:\WINDOWS\ntlj32.exe
O4 - HKLM\..\RunOnce: [atlxh.exe] C:\WINDOWS\system32\atlxh.exe
O4 - HKLM\..\RunOnce: [sdkkt.exe] C:\WINDOWS\system32\sdkkt.exe
O4 - HKLM\..\RunOnce: [javate32.exe] C:\WINDOWS\system32\javate32.exe
O4 - HKLM\..\RunOnce: [apimv.exe] C:\WINDOWS\apimv.exe
O4 - HKLM\..\RunOnce: [addad32.exe] C:\WINDOWS\addad32.exe
O4 - HKLM\..\RunOnce: [apiyz.exe] C:\WINDOWS\apiyz.exe
O4 - HKLM\..\RunOnce: [sdkda32.exe] C:\WINDOWS\system32\sdkda32.exe
O4 - HKLM\..\RunOnce: [ienr32.exe] C:\WINDOWS\system32\ienr32.exe
O4 - HKLM\..\RunOnce: [sdkkf32.exe] C:\WINDOWS\system32\sdkkf32.exe
O4 - HKLM\..\RunOnce: [netrw.exe] C:\WINDOWS\system32\netrw.exe
O4 - HKLM\..\RunOnce: [mfctk.exe] C:\WINDOWS\system32\mfctk.exe
O4 - HKLM\..\RunOnce: [appme32.exe] C:\WINDOWS\system32\appme32.exe
O4 - HKLM\..\RunOnce: [appcf.exe] C:\WINDOWS\appcf.exe
O4 - HKLM\..\RunOnce: [appie.exe] C:\WINDOWS\system32\appie.exe
O4 - HKLM\..\RunOnce: [winqb.exe] C:\WINDOWS\winqb.exe
O4 - HKLM\..\RunOnce: [msxs32.exe] C:\WINDOWS\msxs32.exe
O4 - HKLM\..\RunOnce: [mfcjf.exe] C:\WINDOWS\system32\mfcjf.exe
O4 - HKLM\..\RunOnce: [atlnd.exe] C:\WINDOWS\atlnd.exe
O4 - HKLM\..\RunOnce: [ntrf.exe] C:\WINDOWS\ntrf.exe
O4 - HKLM\..\RunOnce: [netad.exe] C:\WINDOWS\system32\netad.exe
O4 - HKLM\..\RunOnce: [addzt32.exe] C:\WINDOWS\system32\addzt32.exe
O4 - HKLM\..\RunOnce: [sysyl.exe] C:\WINDOWS\system32\sysyl.exe
O4 - HKLM\..\RunOnce: [winhx32.exe] C:\WINDOWS\system32\winhx32.exe
O4 - HKLM\..\RunOnce: [iekz32.exe] C:\WINDOWS\system32\iekz32.exe
O4 - HKLM\..\RunOnce: [javajm32.exe] C:\WINDOWS\javajm32.exe
O4 - HKLM\..\RunOnce: [nethz32.exe] C:\WINDOWS\system32\nethz32.exe
O4 - HKLM\..\RunOnce: [javabw.exe] C:\WINDOWS\system32\javabw.exe
O4 - HKLM\..\RunOnce: [ipxi.exe] C:\WINDOWS\ipxi.exe
O4 - HKLM\..\RunOnce: [ipzr.exe] C:\WINDOWS\ipzr.exe
O4 - HKLM\..\RunOnce: [appkq32.exe] C:\WINDOWS\appkq32.exe
O4 - HKLM\..\RunOnce: [ieyy.exe] C:\WINDOWS\system32\ieyy.exe
O4 - HKLM\..\RunOnce: [sysmb32.exe] C:\WINDOWS\system32\sysmb32.exe
O4 - HKLM\..\RunOnce: [sysjv.exe] C:\WINDOWS\sysjv.exe
O4 - HKLM\..\RunOnce: [sysen.exe] C:\WINDOWS\system32\sysen.exe
O4 - HKLM\..\RunOnce: [apicy.exe] C:\WINDOWS\system32\apicy.exe
O4 - HKLM\..\RunOnce: [crvk32.exe] C:\WINDOWS\system32\crvk32.exe
O4 - HKLM\..\RunOnce: [d3do.exe] C:\WINDOWS\system32\d3do.exe
O4 - HKLM\..\RunOnce: [apieu.exe] C:\WINDOWS\apieu.exe
O4 - HKLM\..\RunOnce: [d3yd.exe] C:\WINDOWS\system32\d3yd.exe
O4 - HKLM\..\RunOnce: [appwy.exe] C:\WINDOWS\appwy.exe
O4 - HKLM\..\RunOnce: [addxy32.exe] C:\WINDOWS\addxy32.exe
O4 - HKLM\..\RunOnce: [ntoe.exe] C:\WINDOWS\ntoe.exe
O4 - HKLM\..\RunOnce: [netyd.exe] C:\WINDOWS\netyd.exe
O4 - HKLM\..\RunOnce: [d3cn.exe] C:\WINDOWS\system32\d3cn.exe
O4 - HKLM\..\RunOnce: [addge.exe] C:\WINDOWS\addge.exe
O4 - HKLM\..\RunOnce: [javamb32.exe] C:\WINDOWS\system32\javamb32.exe
O4 - HKLM\..\RunOnce: [mfcae.exe] C:\WINDOWS\mfcae.exe
O4 - HKLM\..\RunOnce: [mfcdv32.exe] C:\WINDOWS\mfcdv32.exe
O4 - HKLM\..\RunOnce: [sdknl.exe] C:\WINDOWS\sdknl.exe
O4 - HKLM\..\RunOnce: [mfcav.exe] C:\WINDOWS\system32\mfcav.exe
O4 - HKLM\..\RunOnce: [crvf32.exe] C:\WINDOWS\crvf32.exe
O4 - HKLM\..\RunOnce: [sdkzp.exe] C:\WINDOWS\sdkzp.exe
O4 - HKLM\..\RunOnce: [apiyc.exe] C:\WINDOWS\apiyc.exe
O4 - HKLM\..\RunOnce: [crcj32.exe] C:\WINDOWS\system32\crcj32.exe
O4 - HKLM\..\RunOnce: [ipax32.exe] C:\WINDOWS\ipax32.exe
O4 - HKLM\..\RunOnce: [addgz.exe] C:\WINDOWS\system32\addgz.exe
O4 - HKLM\..\RunOnce: [ntqf.exe] C:\WINDOWS\system32\ntqf.exe
O4 - HKLM\..\RunOnce: [ntsx.exe] C:\WINDOWS\system32\ntsx.exe
O4 - HKLM\..\RunOnce: [sdkyl32.exe] C:\WINDOWS\system32\sdkyl32.exe
O4 - HKLM\..\RunOnce: [winhs.exe] C:\WINDOWS\system32\winhs.exe
O4 - HKLM\..\RunOnce: [winkj32.exe] C:\WINDOWS\winkj32.exe
O4 - HKLM\..\RunOnce: [crpf32.exe] C:\WINDOWS\crpf32.exe
O4 - HKLM\..\RunOnce: [sdkea.exe] C:\WINDOWS\sdkea.exe
O4 - HKLM\..\RunOnce: [mfcxz32.exe] C:\WINDOWS\system32\mfcxz32.exe
O4 - HKLM\..\RunOnce: [winwm32.exe] C:\WINDOWS\winwm32.exe
O4 - HKLM\..\RunOnce: [apphx32.exe] C:\WINDOWS\system32\apphx32.exe
O4 - HKLM\..\RunOnce: [ipsw.exe] C:\WINDOWS\ipsw.exe
O4 - HKLM\..\RunOnce: [apipr.exe] C:\WINDOWS\apipr.exe
O4 - HKLM\..\RunOnce: [msyx32.exe] C:\WINDOWS\system32\msyx32.exe
O4 - HKLM\..\RunOnce: [apisg.exe] C:\WINDOWS\system32\apisg.exe
O4 - HKLM\..\RunOnce: [ntyi.exe] C:\WINDOWS\ntyi.exe
O4 - HKLM\..\RunOnce: [addbf32.exe] C:\WINDOWS\system32\addbf32.exe
O4 - HKLM\..\RunOnce: [winke32.exe] C:\WINDOWS\winke32.exe
O4 - HKLM\..\RunOnce: [apioo32.exe] C:\WINDOWS\apioo32.exe
O4 - HKLM\..\RunOnce: [crsf32.exe] C:\WINDOWS\system32\crsf32.exe
O4 - HKLM\..\RunOnce: [sysqn.exe] C:\WINDOWS\sysqn.exe
O4 - HKLM\..\RunOnce: [apiga32.exe] C:\WINDOWS\system32\apiga32.exe
O4 - HKLM\..\RunOnce: [addfn32.exe] C:\WINDOWS\addfn32.exe
O4 - HKLM\..\RunOnce: [msda32.exe] C:\WINDOWS\system32\msda32.exe
O4 - HKLM\..\RunOnce: [iept32.exe] C:\WINDOWS\system32\iept32.exe
O4 - HKLM\..\RunOnce: [winoz.exe] C:\WINDOWS\winoz.exe
O4 - HKLM\..\RunOnce: [ntri32.exe] C:\WINDOWS\system32\ntri32.exe
O4 - HKLM\..\RunOnce: [addrq32.exe] C:\WINDOWS\addrq32.exe
O4 - HKLM\..\RunOnce: [appzw.exe] C:\WINDOWS\appzw.exe
O4 - HKLM\..\RunOnce: [apptq32.exe] C:\WINDOWS\system32\apptq32.exe
O4 - HKLM\..\RunOnce: [netsd.exe] C:\WINDOWS\system32\netsd.exe
O4 - HKLM\..\RunOnce: [winjl32.exe] C:\WINDOWS\system32\winjl32.exe
O4 - HKLM\..\RunOnce: [syssj32.exe] C:\WINDOWS\syssj32.exe
O4 - HKLM\..\RunOnce: [d3cr.exe] C:\WINDOWS\d3cr.exe
O4 - HKLM\..\RunOnce: [mfckp32.exe] C:\WINDOWS\system32\mfckp32.exe
O4 - HKLM\..\RunOnce: [atloh32.exe] C:\WINDOWS\system32\atloh32.exe
O4 - HKLM\..\RunOnce: [mfcov32.exe] C:\WINDOWS\system32\mfcov32.exe
O4 - HKLM\..\RunOnce: [sdkni.exe] C:\WINDOWS\system32\sdkni.exe
O4 - HKLM\..\RunOnce: [appmq32.exe] C:\WINDOWS\system32\appmq32.exe
O4 - HKLM\..\RunOnce: [mfcgh32.exe] C:\WINDOWS\system32\mfcgh32.exe
O4 - HKLM\..\RunOnce: [atluw.exe] C:\WINDOWS\system32\atluw.exe
O4 - HKLM\..\RunOnce: [netuj.exe] C:\WINDOWS\netuj.exe
O4 - HKLM\..\RunOnce: [ieot32.exe] C:\WINDOWS\ieot32.exe
O4 - HKLM\..\RunOnce: [addcv32.exe] C:\WINDOWS\system32\addcv32.exe
O4 - HKLM\..\RunOnce: [d3hf32.exe] C:\WINDOWS\d3hf32.exe
O4 - HKLM\..\RunOnce: [winoy32.exe] C:\WINDOWS\winoy32.exe
O4 - HKLM\..\RunOnce: [netyp32.exe] C:\WINDOWS\netyp32.exe
O4 - HKLM\..\RunOnce: [atlix.exe] C:\WINDOWS\atlix.exe
O4 - HKLM\..\RunOnce: [ieto.exe] C:\WINDOWS\system32\ieto.exe
O4 - HKLM\..\RunOnce: [crxs.exe] C:\WINDOWS\crxs.exe
O4 - HKLM\..\RunOnce: [crzj.exe] C:\WINDOWS\crzj.exe
O4 - HKLM\..\RunOnce: [d3fg.exe] C:\WINDOWS\d3fg.exe
O4 - HKLM\..\RunOnce: [msnm32.exe] C:\WINDOWS\msnm32.exe
O4 - HKLM\..\RunOnce: [javaxs.exe] C:\WINDOWS\system32\javaxs.exe
O4 - HKLM\..\RunOnce: [winnh32.exe] C:\WINDOWS\winnh32.exe
O4 - HKLM\..\RunOnce: [crgy32.exe] C:\WINDOWS\system32\crgy32.exe
O4 - HKLM\..\RunOnce: [iptg.exe] C:\WINDOWS\system32\iptg.exe
O4 - HKLM\..\RunOnce: [ipna32.exe] C:\WINDOWS\system32\ipna32.exe
O4 - HKLM\..\RunOnce: [apilv32.exe] C:\WINDOWS\system32\apilv32.exe
O4 - HKLM\..\RunOnce: [mfcmt32.exe] C:\WINDOWS\mfcmt32.exe
O4 - HKLM\..\RunOnce: [addwb.exe] C:\WINDOWS\system32\addwb.exe
O4 - HKLM\..\RunOnce: [javaez.exe] C:\WINDOWS\javaez.exe
O4 - HKLM\..\RunOnce: [sysjr32.exe] C:\WINDOWS\system32\sysjr32.exe
O4 - HKLM\..\RunOnce: [appow.exe] C:\WINDOWS\appow.exe
O4 - HKLM\..\RunOnce: [crcq.exe] C:\WINDOWS\system32\crcq.exe
O4 - HKLM\..\RunOnce: [ipfc32.exe] C:\WINDOWS\ipfc32.exe
O4 - HKLM\..\RunOnce: [apiqa.exe] C:\WINDOWS\apiqa.exe
O4 - HKLM\..\RunOnce: [crts.exe] C:\WINDOWS\crts.exe
O4 - HKLM\..\RunOnce: [addxc.exe] C:\WINDOWS\addxc.exe
O4 - HKLM\..\RunOnce: [mfcqb.exe] C:\WINDOWS\system32\mfcqb.exe
O4 - HKLM\..\RunOnce: [atlzb.exe] C:\WINDOWS\atlzb.exe
O4 - HKLM\..\RunOnce: [atlus32.exe] C:\WINDOWS\atlus32.exe
O4 - HKLM\..\RunOnce: [iezp.exe] C:\WINDOWS\iezp.exe
O4 - HKLM\..\RunOnce: [apiiv32.exe] C:\WINDOWS\apiiv32.exe
O4 - HKLM\..\RunOnce: [sdkgq.exe] C:\WINDOWS\sdkgq.exe
O4 - HKLM\..\RunOnce: [mfcoe32.exe] C:\WINDOWS\mfcoe32.exe
O4 - HKLM\..\RunOnce: [ntmr.exe] C:\WINDOWS\ntmr.exe
O4 - HKLM\..\RunOnce: [appez.exe] C:\WINDOWS\appez.exe
O4 - HKLM\..\RunOnce: [addnx.exe] C:\WINDOWS\system32\addnx.exe
O4 - HKLM\..\RunOnce: [apixy32.exe] C:\WINDOWS\apixy32.exe
O4 - HKLM\..\RunOnce: [winqp32.exe] C:\WINDOWS\system32\winqp32.exe
O4 - HKLM\..\RunOnce: [sysfl32.exe] C:\WINDOWS\sysfl32.exe
O4 - HKLM\..\RunOnce: [adder.exe] C:\WINDOWS\system32\adder.exe
O4 - HKLM\..\RunOnce: [sdkza32.exe] C:\WINDOWS\sdkza32.exe
O4 - HKLM\..\RunOnce: [appzi32.exe] C:\WINDOWS\appzi32.exe
O4 - HKLM\..\RunOnce: [atlhw.exe] C:\WINDOWS\atlhw.exe
O4 - HKLM\..\RunOnce: [mfcvz32.exe] C:\WINDOWS\mfcvz32.exe
O4 - HKLM\..\RunOnce: [msef.exe] C:\WINDOWS\system32\msef.exe
O4 - HKLM\..\RunOnce: [javatm.exe] C:\WINDOWS\javatm.exe
O4 - HKLM\..\RunOnce: [msyo.exe] C:\WINDOWS\system32\msyo.exe
O4 - HKLM\..\RunOnce: [mfciu32.exe] C:\WINDOWS\system32\mfciu32.exe
O4 - HKLM\..\RunOnce: [ipmy.exe] C:\WINDOWS\ipmy.exe
O4 - HKLM\..\RunOnce: [ippq32.exe] C:\WINDOWS\system32\ippq32.exe
O4 - HKLM\..\RunOnce: [crfx.exe] C:\WINDOWS\system32\crfx.exe
O4 - HKLM\..\RunOnce: [ipek.exe] C:\WINDOWS\system32\ipek.exe
O4 - HKLM\..\RunOnce: [crao32.exe] C:\WINDOWS\system32\crao32.exe
O4 - HKLM\..\RunOnce: [winmy32.exe] C:\WINDOWS\system32\winmy32.exe
O4 - HKLM\..\RunOnce: [mfcxx32.exe] C:\WINDOWS\system32\mfcxx32.exe
O4 - HKLM\..\RunOnce: [wintd32.exe] C:\WINDOWS\system32\wintd32.exe
O4 - HKLM\..\RunOnce: [iepn32.exe] C:\WINDOWS\iepn32.exe
O4 - HKLM\..\RunOnce: [sysiy.exe] C:\WINDOWS\sysiy.exe
O4 - HKLM\..\RunOnce: [crhl.exe] C:\WINDOWS\system32\crhl.exe
O4 - HKLM\..\RunOnce: [javaqr.exe] C:\WINDOWS\javaqr.exe
O4 - HKLM\..\RunOnce: [mfcph32.exe] C:\WINDOWS\mfcph32.exe
O4 - HKLM\..\RunOnce: [crlr.exe] C:\WINDOWS\system32\crlr.exe
O4 - HKLM\..\RunOnce: [apikq32.exe] C:\WINDOWS\apikq32.exe
O4 - HKLM\..\RunOnce: [neteh32.exe] C:\WINDOWS\neteh32.exe
O4 - HKLM\..\RunOnce: [winxy.exe] C:\WINDOWS\winxy.exe
O4 - HKLM\..\RunOnce: [atlxm32.exe] C:\WINDOWS\system32\atlxm32.exe
O4 - HKLM\..\RunOnce: [nthc.exe] C:\WINDOWS\nthc.exe
O4 - HKLM\..\RunOnce: [crad32.exe] C:\WINDOWS\system32\crad32.exe
O4 - HKLM\..\RunOnce: [sdkvn32.exe] C:\WINDOWS\sdkvn32.exe
O4 - HKLM\..\RunOnce: [apiua32.exe] C:\WINDOWS\system32\apiua32.exe
O4 - HKLM\..\RunOnce: [ipnl.exe] C:\WINDOWS\system32\ipnl.exe
O4 - HKLM\..\RunOnce: [atlmz.exe] C:\WINDOWS\atlmz.exe
O4 - HKLM\..\RunOnce: [ipid.exe] C:\WINDOWS\system32\ipid.exe
O4 - HKLM\..\RunOnce: [appvn.exe] C:\WINDOWS\system32\appvn.exe
O4 - HKLM\..\RunOnce: [d3jh.exe] C:\WINDOWS\d3jh.exe
O4 - HKLM\..\RunOnce: [ntft32.exe] C:\WINDOWS\ntft32.exe
O4 - HKLM\..\RunOnce: [netxs.exe] C:\WINDOWS\system32\netxs.exe
O4 - HKLM\..\RunOnce: [syslu.exe] C:\WINDOWS\system32\syslu.exe
O4 - HKLM\..\RunOnce: [d3hy32.exe] C:\WINDOWS\d3hy32.exe
O4 - HKLM\..\RunOnce: [sdkzf.exe] C:\WINDOWS\sdkzf.exe
O4 - HKLM\..\RunOnce: [ntaf.exe] C:\WINDOWS\ntaf.exe
O4 - HKLM\..\RunOnce: [apisd32.exe] C:\WINDOWS\apisd32.exe
O4 - HKLM\..\RunOnce: [ntxg32.exe] C:\WINDOWS\system32\ntxg32.exe
O4 - HKLM\..\RunOnce: [apprh32.exe] C:\WINDOWS\system32\apprh32.exe
O4 - HKLM\..\RunOnce: [msej.exe] C:\WINDOWS\system32\msej.exe
O4 - HKLM\..\RunOnce: [winvz.exe] C:\WINDOWS\winvz.exe
O4 - HKLM\..\RunOnce: [iesu.exe] C:\WINDOWS\iesu.exe
O4 - HKLM\..\RunOnce: [sdklk.exe] C:\WINDOWS\system32\sdklk.exe
O4 - HKLM\..\RunOnce: [ipbg.exe] C:\WINDOWS\system32\ipbg.exe
O4 - HKLM\..\RunOnce: [d3gh.exe] C:\WINDOWS\system32\d3gh.exe
O4 - HKLM\..\RunOnce: [javapg.exe] C:\WINDOWS\javapg.exe
O4 - HKLM\..\RunOnce: [nttp.exe] C:\WINDOWS\system32\nttp.exe
O4 - HKLM\..\RunOnce: [ieic32.exe] C:\WINDOWS\ieic32.exe
O4 - HKLM\..\RunOnce: [javahq32.exe] C:\WINDOWS\system32\javahq32.exe
O4 - HKLM\..\RunOnce: [d3aj32.exe] C:\WINDOWS\system32\d3aj32.exe
O4 - HKLM\..\RunOnce: [addlh32.exe] C:\WINDOWS\addlh32.exe
O4 - HKLM\..\RunOnce: [sdkzc32.exe] C:\WINDOWS\sdkzc32.exe
O4 - HKLM\..\RunOnce: [addii32.exe] C:\WINDOWS\system32\addii32.exe
O4 - HKLM\..\RunOnce: [sysdr.exe] C:\WINDOWS\sysdr.exe
O4 - HKLM\..\RunOnce: [apibe.exe] C:\WINDOWS\system32\apibe.exe
O4 - HKLM\..\RunOnce: [ieph.exe] C:\WINDOWS\ieph.exe
O4 - HKLM\..\RunOnce: [apizn32.exe] C:\WINDOWS\apizn32.exe
O4 - HKLM\..\RunOnce: [atljm.exe] C:\WINDOWS\atljm.exe
O4 - HKLM\..\RunOnce: [ntyb32.exe] C:\WINDOWS\system32\ntyb32.exe
O4 - HKLM\..\RunOnce: [msxw.exe] C:\WINDOWS\system32\msxw.exe
O4 - HKLM\..\RunOnce: [ipwe.exe] C:\WINDOWS\system32\ipwe.exe
O4 - HKLM\..\RunOnce: [apifc.exe] C:\WINDOWS\system32\apifc.exe
O4 - HKLM\..\RunOnce: [mfcvx.exe] C:\WINDOWS\system32\mfcvx.exe
O4 - HKLM\..\RunOnce: [sysoo32.exe] C:\WINDOWS\sysoo32.exe
O4 - HKLM\..\RunOnce: [winwc.exe] C:\WINDOWS\winwc.exe
O4 - HKLM\..\RunOnce: [crwp32.exe] C:\WINDOWS\crwp32.exe
O4 - HKLM\..\RunOnce: [netjz.exe] C:\WINDOWS\netjz.exe
O4 - HKLM\..\RunOnce: [apinp.exe] C:\WINDOWS\apinp.exe
O4 - HKLM\..\RunOnce: [sdkxi32.exe] C:\WINDOWS\sdkxi32.exe
O4 - HKLM\..\RunOnce: [mfcqg32.exe] C:\WINDOWS\system32\mfcqg32.exe
O4 - HKLM\..\RunOnce: [apiym32.exe] C:\WINDOWS\system32\apiym32.exe
O4 - HKLM\..\RunOnce: [appit32.exe] C:\WINDOWS\appit32.exe
O4 - HKLM\..\RunOnce: [ieza.exe] C:\WINDOWS\system32\ieza.exe
O4 - HKLM\..\RunOnce: [appax32.exe] C:\WINDOWS\system32\appax32.exe
O4 - HKLM\..\RunOnce: [syskd32.exe] C:\WINDOWS\system32\syskd32.exe
O4 - HKLM\..\RunOnce: [ieiw.exe] C:\WINDOWS\system32\ieiw.exe
O4 - HKLM\..\RunOnce: [crhx.exe] C:\WINDOWS\system32\crhx.exe
O4 - HKLM\..\RunOnce: [atles.exe] C:\WINDOWS\atles.exe
O4 - HKLM\..\RunOnce: [winoz32.exe] C:\WINDOWS\system32\winoz32.exe
O4 - HKLM\..\RunOnce: [atlcb32.exe] C:\WINDOWS\system32\atlcb32.exe
O4 - HKLM\..\RunOnce: [msnu32.exe] C:\WINDOWS\msnu32.exe
O4 - HKLM\..\RunOnce: [ntxx32.exe] C:\WINDOWS\system32\ntxx32.exe
O4 - HKLM\..\RunOnce: [addtu.exe] C:\WINDOWS\addtu.exe
O4 - HKLM\..\RunOnce: [winek.exe] C:\WINDOWS\winek.exe
O4 - HKLM\..\RunOnce: [winxr.exe] C:\WINDOWS\system32\winxr.exe
O4 - HKLM\..\RunOnce: [javafd.exe] C:\WINDOWS\system32\javafd.exe
O4 - HKLM\..\RunOnce: [sysey32.exe] C:\WINDOWS\system32\sysey32.exe
O4 - HKLM\..\RunOnce: [javagb32.exe] C:\WINDOWS\javagb32.exe
O4 - HKLM\..\RunOnce: [atljq.exe] C:\WINDOWS\system32\atljq.exe
O4 - HKLM\..\RunOnce: [ipim32.exe] C:\WINDOWS\ipim32.exe
O4 - HKLM\..\RunOnce: [sdkuk32.exe] C:\WINDOWS\sdkuk32.exe
O4 - HKLM\..\RunOnce: [netej32.exe] C:\WINDOWS\netej32.exe
O4 - HKLM\..\RunOnce: [msiy32.exe] C:\WINDOWS\system32\msiy32.exe
O4 - HKLM\..\RunOnce: [sdkhe.exe] C:\WINDOWS\sdkhe.exe
O4 - HKLM\..\RunOnce: [winbp.exe] C:\WINDOWS\system32\winbp.exe
O4 - HKLM\..\RunOnce: [syslv.exe] C:\WINDOWS\system32\syslv.exe
O4 - HKLM\..\RunOnce: [msiq.exe] C:\WINDOWS\system32\msiq.exe
O4 - HKLM\..\RunOnce: [sdkth.exe] C:\WINDOWS\sdkth.exe
O4 - HKLM\..\RunOnce: [apixt.exe] C:\WINDOWS\apixt.exe
O4 - HKLM\..\RunOnce: [msvm.exe] C:\WINDOWS\msvm.exe
O4 - HKLM\..\RunOnce: [apikm32.exe] C:\WINDOWS\apikm32.exe
O4 - HKLM\..\RunOnce: [d3oe32.exe] C:\WINDOWS\system32\d3oe32.exe
O4 - HKLM\..\RunOnce: [iphv.exe] C:\WINDOWS\iphv.exe
O4 - HKLM\..\RunOnce: [atlud32.exe] C:\WINDOWS\atlud32.exe
O4 - HKLM\..\RunOnce: [sysoz32.exe] C:\WINDOWS\system32\sysoz32.exe
O4 - HKLM\..\RunOnce: [iecu.exe] C:\WINDOWS\iecu.exe
O4 - HKLM\..\RunOnce: [sysxl.exe] C:\WINDOWS\system32\sysxl.exe
O4 - HKLM\..\RunOnce: [crkt32.exe] C:\WINDOWS\system32\crkt32.exe
O4 - HKLM\..\RunOnce: [mshx.exe] C:\WINDOWS\system32\mshx.exe
O4 - HKLM\..\RunOnce: [sdkgl.exe] C:\WINDOWS\sdkgl.exe
O4 - HKLM\..\RunOnce: [netea.exe] C:\WINDOWS\netea.exe
O4 - HKLM\..\RunOnce: [apiqo.exe] C:\WINDOWS\apiqo.exe
O4 - HKLM\..\RunOnce: [ipnu.exe] C:\WINDOWS\system32\ipnu.exe
O4 - HKLM\..\RunOnce: [crba32.exe] C:\WINDOWS\crba32.exe
O4 - HKLM\..\RunOnce: [appih32.exe] C:\WINDOWS\appih32.exe
O4 - HKLM\..\RunOnce: [sysmj.exe] C:\WINDOWS\sysmj.exe
O4 - HKLM\..\RunOnce: [msce32.exe] C:\WINDOWS\msce32.exe
O4 - HKLM\..\RunOnce: [syswv32.exe] C:\WINDOWS\system32\syswv32.exe
O4 - HKLM\..\RunOnce: [ieii32.exe] C:\WINDOWS\system32\ieii32.exe
O4 - HKLM\..\RunOnce: [iegm.exe] C:\WINDOWS\iegm.exe
O4 - HKLM\..\RunOnce: [appst.exe] C:\WINDOWS\appst.exe
O4 - HKLM\..\RunOnce: [netls.exe] C:\WINDOWS\netls.exe
O4 - HKLM\..\RunOnce: [d3ob.exe] C:\WINDOWS\system32\d3ob.exe
O4 - HKLM\..\RunOnce: [javakl.exe] C:\WINDOWS\javakl.exe
O4 - HKLM\..\RunOnce: [sdktj.exe] C:\WINDOWS\system32\sdktj.exe
O4 - HKLM\..\RunOnce: [iegt.exe] C:\WINDOWS\system32\iegt.exe
O4 - HKLM\..\RunOnce: [sdkfp32.exe] C:\WINDOWS\system32\sdkfp32.exe
O4 - HKLM\..\RunOnce: [apiyl32.exe] C:\WINDOWS\apiyl32.exe
O4 - HKLM\..\RunOnce: [aping.exe] C:\WINDOWS\system32\aping.exe
O4 - HKLM\..\RunOnce: [appfm32.exe] C:\WINDOWS\appfm32.exe
O4 - HKLM\..\RunOnce: [msfy.exe] C:\WINDOWS\msfy.exe
O4 - HKLM\..\RunOnce: [ntyp32.exe] C:\WINDOWS\system32\ntyp32.exe
O4 - HKLM\..\RunOnce: [sdkft.exe] C:\WINDOWS\sdkft.exe
O4 - HKLM\..\RunOnce: [appjm.exe] C:\WINDOWS\appjm.exe
O4 - HKLM\..\RunOnce: [addnc.exe] C:\WINDOWS\system32\addnc.exe
O4 - HKLM\..\RunOnce: [msun32.exe] C:\WINDOWS\msun32.exe
O4 - HKLM\..\RunOnce: [ipoe.exe] C:\WINDOWS\system32\ipoe.exe
O4 - HKLM\..\RunOnce: [sdknr32.exe] C:\WINDOWS\sdknr32.exe
O4 - HKLM\..\RunOnce: [iexq32.exe] C:\WINDOWS\system32\iexq32.exe
O4 - HKLM\..\RunOnce: [netml32.exe] C:\WINDOWS\system32\netml32.exe
O4 - HKLM\..\RunOnce: [sysvr.exe] C:\WINDOWS\sysvr.exe
O4 - HKLM\..\RunOnce: [mfcfp32.exe] C:\WINDOWS\system32\mfcfp32.exe
O4 - HKLM\..\RunOnce: [msie.exe] C:\WINDOWS\system32\msie.exe
O4 - HKLM\..\RunOnce: [ntbd.exe] C:\WINDOWS\ntbd.exe
O4 - HKLM\..\RunOnce: [syskj32.exe] C:\WINDOWS\syskj32.exe
O4 - HKLM\..\RunOnce: [d3ui.exe] C:\WINDOWS\d3ui.exe
O4 - HKLM\..\RunOnce: [javaeo.exe] C:\WINDOWS\system32\javaeo.exe
O4 - HKLM\..\RunOnce: [crns32.exe] C:\WINDOWS\system32\crns32.exe
O4 - HKLM\..\RunOnce: [sdkqb.exe] C:\WINDOWS\sdkqb.exe
O4 - HKLM\..\RunOnce: [ipjy32.exe] C:\WINDOWS\system32\ipjy32.exe
O4 - HKLM\..\RunOnce: [ipfv32.exe] C:\WINDOWS\ipfv32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: WinZip Quick Pick.lnk = ?
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\ipfv32.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: SmartFinder Uninstall (SmartFinder_Uninstall) - Unknown owner - C:\Documents and Settings\Jeremy Collins\My Documents\SFUninstaller.exe" service (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Let me know what I have to delete, please.
  • 0

Advertisements


#2
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Hi JeremyC and Welcome to GeekstoGo!

Thats a nasty CWS Infection you have there!!

Please Download these utilities but dont run them until I ask you to!

Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/

Please read Ewido Setup Instructions
Install it, and update the definitions to the newest files. Do NOT run a scan yet.

CWShredder
http://cwshredder.ne.../CWShredder.exe

Double Click CWShredder.exe to run it>>Click Check Check For Update
Close it out once updated,We will run it in Safe Mode!


ABout Buster
http://www.besttechi...?showtopic=1488

Follow the Instructions inside the link to Update it,We will run it it Safe Mode!

CleanUp!
http://downloads.ste...p/CleanUp40.exe


Click Start-> Run-> Type in Services.msc and Click OK!

Scroll that list and locate this entry

Remote Procedure Call (RPC) Helper<- Match that Name exact!

Dont mess with Remote Procedure Call (RPC) or Remote Procedure Call (RPC) Locater

Right Click that entry and Select Properties-> Click Stop-> Go up and change the Startup Type to Disabled!

Click Apply-> OK and Exit the Services Page!


Reboot into SAFE MODE(Tap F8 when restarting)
Here is a link on how to boot into Safe Mode:
http://service1.syma...src=sec_doc_nam


Run CWShredder

Click "Fix ->" and click "OK" at the prompt.
CWShredder will scan and clean your system of CWS files.
Click "Next->" and then "Exit"


Run ABout Buster just as described in the link!

Please run it until you get these Results:

No ADS found on system
Attempted Clean Of Temp folder.
Pages Reset... Done!



Run CleanUp!

Click on the "CleanUp!" Tab and let it do its thing-> When Prompted to Log Off-> Click NO!


Now Scan the entire System with Ewido-> Clean all it finds-> Be sure to click the tab to Save a Report!


Run MSCONFIG and enable everything in the startup area. To get to MSCONFIG, click on Start -> Run -> type in MSCONFIG -> click OK!

Under the "General" Tab
Make Sure Normal Startup is Checked!!

Click Apply>>Close>>Follow the Prompts to Restart!!

Restart Normal and have the PC Scanned here:
Panda Active Scan

You will need to be using Internet Explorer for the Scan to work!

Save the Report it generates


Post back with a fresh HijackThis log and the reports from Ewido and Panda!
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP