Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

pop-ups killing my computer [RESOLVED]


  • This topic is locked This topic is locked

#1
greece58

greece58

    New Member

  • Member
  • Pip
  • 8 posts
My computer has been suffering for weeks with two pop-up origins: 1) 209.200.10.90 and 2) adyieldmanager. I need serious help! tried everything to rid myself of them to no avail (spybot; anti-viruses; etc) I tried to go thru my hidden files, find them and delete them. but all that did was delete already shown items.
  • 0

Advertisements


#2
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
Click here to download HijackThis by Merijn Bellekom. Doubleclick the file, click Unzip and extract the application to C:\HijackThis. Run it from there to scan your computer.

When the scan is finished, the "Scan" button will change into a "Save Log" button. Save the log, Ctrl-A to Select All and post it here for examination. Don't fix anything yet as most of what it lists will be harmless.
  • 0

#3
greece58

greece58

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Logfile of HijackThis v1.99.1
Scan saved at 2:39:31 PM, on 9/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\??xplore.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\rrou\etop.exe
C:\Program Files\AVPersonal\AVSched32.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\ROBERT~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: ohb Class - {8037F7F0-80B6-453A-A7CB-5371A4A09BB8} - C:\WINDOWS\system32\nstE3.dll
O2 - BHO: (no name) - {A17F099C-9B26-A5E8-7840-ECECDF911897} - C:\WINDOWS\system32\mboyo.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {B08E264C-B0F6-DC6D-F5F4-97CB2DB909C4} - C:\WINDOWS\system32\vdcj.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [hjzmnpe] c:\windows\system32\btohevc.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSched32.EXE /min
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Qvls] C:\WINDOWS\system32\??xplore.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Uuso] C:\Program Files\rrou\etop.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - http://greece-notes1...y.us/iNotes.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.host...ler/1041274.exe
O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} - http://akamai.downlo...slv32_EN_XP.cab
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
  • 0

#4
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
We'll use some clean-up tools first - if you already have any of these and you are sure they are the latest version then just skip and move on to the next one.

Click here to download Ad-Aware SE and install. Before scanning click on "check for updates now" to make sure you have the latest reference file.
  • Click "Start"
  • Select "Perform Full System scan"
  • Click "Next" to start the scan.
When the scan is finished, the screen will tell you if anything has been found.
  • Click "Next". The bad files will be listed.
  • Right click the pane and click "Select all objects" - this will put a check mark in the box at the side.
  • Click "Next" again
  • Click "OK" at the prompt "# objects will be removed. Continue?".
Reboot when done.

Click here to download Microsoft AntiSpyware Beta, check for updates and run it. Reboot when done.

Click here to download ewido security suite - it is a trial version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed. If you are having problems with the updater, you can use this link to manually update ewido. Then:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin (do not open any folders or open the windows control panel while the scan is in progress).
  • While the scan is in progress you will be prompted to clean files, click OK
  • When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.

Rescan with HJT and post a new log here together with the ewido log so that any remnants can be removed manually.
  • 0

#5
greece58

greece58

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 8:48:00 AM, 9/3/2005
+ Report-Checksum: E5D25C93

+ Scan result:

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKU\S-1-5-21-1993962763-1606980848-839522115-1004\Software\Microsoft\Internet Explorer\Extensions\{6685509E-B47B-4f47-8E16-9A5F3A62F683} -> Spyware.MoneyMaker : Cleaned with backup
HKU\S-1-5-21-1993962763-1606980848-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6685509E-B47B-4F47-8E16-9A5F3A62F683} -> Spyware.MoneyMaker : Cleaned with backup
C:\Documents and Settings\robert peters\Cookies\robert peters@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\robert peters\Cookies\robert peters@adopt.specificclick[2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\robert peters\Cookies\robert peters@microsofteup.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\robert peters\Cookies\robert peters@paypopup[2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\robert peters\Cookies\robert peters@rotator.adjuggler[1].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\robert peters\Cookies\robert peters@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10000.qit -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10001.qit -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10002.qit -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10003.qit -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10004.qit -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10005.qit -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10007.qit -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10008.qit -> Spyware.Cookie.Overture : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10009.qit -> Spyware.Cookie.Overture : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10010.qit -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10012.qit -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10013.qit -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10014.qit -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10015.qit -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10016.qit -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10017.qit -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\10-7-2005-16-49-1\ 10018.qit -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\16-7-2005-10-27-31\ 10000.qit -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\16-7-2005-10-27-31\ 10002.qit -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\16-7-2005-10-27-31\ 10003.qit -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\16-7-2005-10-27-31\ 10004.qit -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\16-7-2005-10-27-31\ 10005.qit -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\16-7-2005-10-27-31\ 10006.qit -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\18-6-2005-10-38-46\ 10000.qit -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\18-6-2005-10-38-46\ 10003.qit -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\19-6-2005-6-57-3\ 10000.qit -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\19-6-2005-6-57-3\ 10002.qit -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\19-6-2005-6-57-3\ 10003.qit -> Spyware.Cookie.Overture : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\19-6-2005-6-57-3\ 10004.qit -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\19-6-2005-6-57-3\ 10005.qit -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\21-6-2005-14-1-24\ 10000.qit -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\21-6-2005-14-1-24\ 10001.qit -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\21-8-2005-17-51-48\ 10000.qit -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\21-8-2005-17-51-48\ 10002.qit -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\21-8-2005-17-51-48\ 10003.qit -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\21-8-2005-17-51-48\ 10004.qit -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\21-8-2005-17-51-48\ 10005.qit -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\21-8-2005-17-51-48\ 10006.qit -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\21-8-2005-17-51-48\ 10007.qit -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\21-8-2005-17-51-48\ 10008.qit -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\21-8-2005-17-51-48\ 10009.qit -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\21-8-2005-17-51-48\ 10010.qit -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\21-8-2005-17-51-48\ 10012.qit -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\21-8-2005-17-51-48\ 10013.qit -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\21-8-2005-17-51-48\ 10015.qit -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10000.qit -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10003.qit -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10004.qit -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10005.qit -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10006.qit -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10008.qit -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10009.qit -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10010.qit -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10011.qit -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10012.qit -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10013.qit -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10015.qit -> Spyware.Cookie.Overture : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10016.qit -> Spyware.Cookie.Overture : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10017.qit -> Spyware.Cookie.Paycounter : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10018.qit -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10020.qit -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10021.qit -> Spyware.Cookie.Sexcounter : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10022.qit -> Spyware.Cookie.Sexlist : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10023.qit -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10024.qit -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10025.qit -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10026.qit -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10027.qit -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10028.qit -> Spyware.Cookie.Valuead : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\29-7-2005-10-58-28\ 10029.qit -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\3-8-2005-19-20-21\ 10000.qit -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\3-8-2005-19-20-21\ 10003.qit -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\3-8-2005-19-20-21\ 10004.qit -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\3-8-2005-19-20-21\ 10005.qit -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\3-8-2005-19-20-21\ 10008.qit -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\30-7-2005-11-20-25\ 10000.qit -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\30-7-2005-11-20-25\ 10001.qit -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\30-7-2005-11-20-25\ 10002.qit -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\30-7-2005-11-20-25\ 10003.qit -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\5-8-2005-17-17-2\ 10000.qit -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\5-8-2005-17-17-2\ 10001.qit -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\5-8-2005-17-17-2\ 10002.qit -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\5-8-2005-17-17-2\ 10003.qit -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\AdwareAlert\Quarantine\5-8-2005-17-17-2\ 10004.qit -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\AVPersonal\INFECTED\A0015370.EXE.VIR -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\AVPersonal\INFECTED\A0015389.EXE.VIR -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\AVPersonal\INFECTED\A0015481.EXE.VIR -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\AVPersonal\INFECTED\A0015556.EXE.VIR -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\AVPersonal\INFECTED\A0015557.EXE.VIR -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\AVPersonal\INFECTED\A0015676.EXE.VIR -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\AVPersonal\INFECTED\A0015705.EXE.VIR -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\AVPersonal\INFECTED\A0015866.EXE.VIR -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\AVPersonal\INFECTED\A0015896.EXE.VIR -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\AVPersonal\INFECTED\A0021323.EXE.VIR -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\AVPersonal\INFECTED\A0021345.EXE.VIR -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\AVPersonal\INFECTED\A0021372.EXE.VIR -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\AVPersonal\INFECTED\A0022792.EXE.VIR -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\AVPersonal\INFECTED\A0023806.EXE.VIR -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\AVPersonal\INFECTED\A0023823.EXE.VIR -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\AVPersonal\INFECTED\A0029195.DLL.VIR -> Trojan.P2E.bg : Cleaned with backup
C:\WINDOWS\Adulti.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\1041274.exe -> Dialer.Generic : Cleaned with backup


::Report End
  • 0

#6
greece58

greece58

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Logfile of HijackThis v1.99.1
Scan saved at 9:45:18 AM, on 9/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\AVPersonal\AVSched32.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\??xplore.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\rrou\etop.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\robert peters\Local Settings\Temporary Internet Files\Content.IE5\O8FR9OS0\HijackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: (no name) - {A17F099C-9B26-A5E8-7840-ECECDF911897} - C:\WINDOWS\system32\mboyo.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {B08E264C-B0F6-DC6D-F5F4-97CB2DB909C4} - C:\WINDOWS\system32\vdcj.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [hjzmnpe] c:\windows\system32\btohevc.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSched32.EXE /min
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Qvls] C:\WINDOWS\system32\??xplore.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Uuso] C:\Program Files\rrou\etop.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - http://greece-notes1...y.us/iNotes.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.host...ler/1041274.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
  • 0

#7
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
HijackThis is being run from a temporary folder; this means that any backups it creates as a result of fixes made with it will be lost. Please create a new folder for it and place the program into that new folder.

Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

O2 - BHO: (no name) - {A17F099C-9B26-A5E8-7840-ECECDF911897} - C:\WINDOWS\system32\mboyo.dll (file missing)
O2 - BHO: (no name) - {B08E264C-B0F6-DC6D-F5F4-97CB2DB909C4} - C:\WINDOWS\system32\vdcj.dll
O4 - HKLM\..\Run: [hjzmnpe] c:\windows\system32\btohevc.exe
O4 - HKCU\..\Run: [Qvls] C:\WINDOWS\system32\??xplore.exe
O4 - HKCU\..\Run: [Uuso] C:\Program Files\rrou\etop.exe
O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.host...ler/1041274.exe


Exit HijackThis when done. Reboot into Safe Mode by tapping F8 after the BIOS has loaded. Using Windows Explorer, find and delete the following:

c:\windows\system32\btohevc.exe
C:\Program Files\rrou <-- folder

Exit Explorer and reboot into Normal Mode. Rescan with HijackThis and post a new log here.
  • 0

#8
greece58

greece58

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Logfile of HijackThis v1.99.1
Scan saved at 4:45:08 PM, on 9/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\AVPersonal\AVSched32.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\??xplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\rrou\etop.exe
C:\Documents and Settings\robert peters\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSched32.EXE /min
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Uuso] C:\Program Files\rrou\etop.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - http://greece-notes1...y.us/iNotes.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
  • 0

#9
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
Please repeat my last post - some entries are still showing up.
  • 0

#10
greece58

greece58

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Logfile of HijackThis v1.99.1
Scan saved at 6:46:06 AM, on 9/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\AVPersonal\AVSched32.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\robert peters\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSched32.EXE /min
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - http://greece-notes1...y.us/iNotes.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
  • 0

#11
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
That's better - how is it running now?
  • 0

#12
greece58

greece58

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
knock on wood , so far so good. i have been on for a few hours and no pop-ups of 209.200.10.90 or adyieldmanager! thx and i will send you a donation as soon as i remember my paypal password:)) i will have to cotact them for it cuz it has been ages since i have used them and actually forgot i was a member:)) again thx and i hope i wont need you evern again:))
  • 0

#13
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
You're welcome - glad to help :tazz:

To help keep you clean follow the recommendations in Tony's article here:

So how did I get infected in the first place?



As this problem has been resolved the topic will be closed. If you need this topic reopened, please email the moderating team - be sure to include the address of the thread and the name you posted under.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP