Hijack Log for 'system alert:adware & spyware problem' :S& - Geeks to Go Forums

Jump to content

Log in Register Register Malware removal guide How it works

Hijack Log for 'system alert:adware & spyware problem' :S&

#1 chenli

  • Group: Member
  • Posts: 23
  • Joined: 08-February 06

Posted 08 February 2006 - 04:08 PM

Original Topic:

I used the 'How To remove Spyaxe..." guide to get rid of the continuous problem of SpywareStrike. And assumed it would remove the:

Posted Image

Aswell the other varients of that particular pop-up type thing.

But it's only removed SpywareStrike, and I don't know what to do about the above popup mentioned. It's irritating beyond all believe, and this + the recently departed SpywareStrike have caused my comp alot of problems because using AdAware and the like managed to mess up my browser files, so I couldn't use Netscape.

Another pop up, I only recently got was:

Posted Image

Nor do I know how to remove this.

----

Having read the "you must read this topic", I was reminded that I'd scanned with Spybot and immunized, too, yet that did nothing. I scanned with CWShredder - nothing found. Trend Housecall wouldn't load, and Ewido hasn't solved the problem either. I also have AvastAntivirus, which ends up finding loads of viruses when I scan with ADAwareSE. Even System Restore doesn't work anymore. Both attempts at restoring failed.

So, I'm desperate here, and posting the hijack log.

Quote

Logfile of HijackThis v1.99.1
Scan saved at 21:49:11, on 08/02/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashserv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\SOINTGR.EXE
C:\Program Files\Perfect Keyboard PRO\pk32.exe
C:\DOCUME~1\Chris\LOCALS~1\Temp\RunMotive.exe
C:\Program Files\Zoom\CnxDslTb.exe
C:\Program Files\Perfect Keyboard PRO\_loader.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Perfect Keyboard PRO\_prog.exe
C:\WINDOWS\System32\atwtusb.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Pop Blocker\updatedl.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\WINDOWS\System32\mssearchnet.exe
C:\PROGRA~1\YAHOO!\MESSEN~1\YSERVER.EXE
C:\Program Files\AIM95\aim.exe
C:\Documents and Settings\Alex\My Documents\My Pictures\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bssfcxmpmecwyfhuhlfulnf.com/Rbn...t1J/7ug_9tx.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.btinternet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTinternet
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.znqqdrxlxhcpetbvuimelwzo.us/Rbnk2Qr2dFQ_8fpqH5Z0dinJGjhYlY2FGsMmwll8n0w.html"); (C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5Cmozilla.org%5CMozilla%5Csearchplugins%5Cgoogle.src"); (C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\prefs.js)
O1 - Hosts: comments (such as these) may be inserted on individual
O2 - BHO: (no name) - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - (no file)
O3 - Toolbar: Betfair Bar - {1D62BD48-16F6-4004-A54A-3C41E4955A87} - C:\Program Files\Betfair\BFTool_4.dll
O3 - Toolbar: Updated.Toolbar - {9F6A22E6-1682-4F82-9B72-6314794CB253} - C:\Program Files\Pop Blocker\Updated.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O4 - HKLM\..\Run: [SUPASTATUS] C:\Program Files\Internet Explorer\Connection Wizard\status.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [SO5 Integrator Pass Two] C:\WINDOWS\SOINTGR.EXE
O4 - HKLM\..\Run: [Gtwatch] C:\WINDOWS\gtwatch.exe
O4 - HKLM\..\Run: [Perfect Keyboard PRO] "C:\Program Files\Perfect Keyboard PRO\pk32.exe" /winstart
O4 - HKLM\..\Run: [RemHelp] remhelp.exe
O4 - HKLM\..\Run: [RunMotive] C:\DOCUME~1\Chris\LOCALS~1\Temp\RunMotive.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Program Files\Zoom\CnxDslTb.exe
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] DSLAGENT.EXE USB
O4 - HKLM\..\Run: [GsiFinal] rundll32 gspndll.dll,postInstall final
O4 - HKLM\..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Windows Update Files] C:\Program Files\microsoft hardware\dnetc.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KAZAA] "C:\Program Files\Kazaa Lite\kpp.exe" "C:\Program Files\Kazaa Lite\kazaalite.kpp" /SYSTRAY
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Open Site] "C:\Program Files\Open Site\opensite.exe"
O4 - HKLM\..\Run: [Hindustan] C:\Documents and Settings\Alex\My Documents\msn-fake\msmsgs.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [shhost] C:\Program Files\OutLaster\shhost.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [JVM0.12] C:\WINDOWS\System32\lzjerxb.exe
O4 - HKLM\..\Run: [JVM0.14] C:\WINDOWS\System32\hyrmif.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ms1src] c:\program files\common files\system\ms1src.exe /install
O4 - HKLM\..\Run: [blue bold deaf audio] C:\Documents and Settings\All Users\Application Data\MEET COPY BLUE BOLD\Window Upload.exe
O4 - HKLM\..\Run: [Microsoft System Restore Configuration] CBRSS.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [HOLE SITE] C:\DOCUME~1\Alex\APPLIC~1\FACENE~1\Find Exit.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Watch.lnk = C:\WINDOWS\twain_32\S6U12BX\WATCH.exe
O4 - Global Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband\Help\bin\matcli.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_90.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.btinternet.com/
O16 - DPF: ChatSpace Full Java Client 2.1.0.84 - http://about.chatspa...va/cs4fs084.cab
O16 - DPF: ChatSpace Full Java Client 3.1.0.220 - http://wiredreality....va/cfs31220.cab
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://irc.everywher...va/cfs31229.cab
O16 - DPF: ChatSpace Full Java Client 3.1.0.235 - http://205.177.13.10...va/cfs31235.cab
O16 - DPF: ChatSpace Java Client 2.1.0.79 - http://65.95.142.201/Java/cs4ms079.cab
O16 - DPF: ChatSpace Java Client 2.1.0.90 - http://servers.secur...va/cs4ms090.cab
O16 - DPF: ChatSpace Java Client 2.1.0.95 - http://chat.chatspac...va/cs4ms095.cab
O16 - DPF: ChatSpace Java Client 3.1.0.212 - http://moonchatuk.dy...va/cms31212.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cab
O16 - DPF: Yahoo! Chat 1.3 - http://cs5.chat.sc5....m/c174/chat.cab
O16 - DPF: Yahoo! Dots - http://download.game...ts/y/dtt1_x.cab
O16 - DPF: Yahoo! Go - http://download.game...nts/y/gt1_x.cab
O16 - DPF: {11111111-1111-1111-1111-111111111123} - file://c:\Recycled\1.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebpr...etup1.0.0.5.exe
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} -
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200112...meInstaller.exe
O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} -
O16 - DPF: {4E6F9E15-C8E3-4E19-B987-04EF390E9824} - http://www.betfair.c...stall/setup.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} -
O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} -
O16 - DPF: {88C51E90-8E9C-4C96-8A45-574D88B63FAF} - http://acceso.masmin...aaplicacion.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} -
O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} -
O16 - DPF: {D53B810F-6219-11D4-95B6-0040950375E7} -
O16 - DPF: {E62A47D8-74B1-4A93-963A-E5E43B7CC5C2} (UCSearch.ucUCSearch) - http://www.zuvio.com...te/UCSearch.CAB
O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} -
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} -
O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/gba1388.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{239D01FA-E874-43E0-BFDB-BF0613D4F9FD}: NameServer = 194.72.9.34 194.72.0.114
O17 - HKLM\System\CS1\Services\Tcpip\..\{239D01FA-E874-43E0-BFDB-BF0613D4F9FD}: NameServer = 194.72.9.34 194.72.0.114
O19 - User stylesheet: (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashserv.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe


I also have the results of the ewido scan, if those need to be posted.

Any help is GREATLY appreciated...:S

#2 Buckeye_Sam

  • Group: Member
  • Posts: 10,019
  • Joined: 10-July 05

Posted 09 February 2006 - 03:34 PM

Hi and welcome to GeeksToGo! My name is Sam and I will be helping you. :tazz:
I see quite a few issues in your log.

I need to see a different type of log from Hijackthis
  • Run Hijackthis.
  • Click on "Open the Misc Tools section".
  • Next click on "Open uninstall manager".
  • Press the button 'save list'. It will open a Notepad file.
  • Place the content of that file here in your in your next reply.


#3 chenli

  • Group: Member
  • Posts: 23
  • Joined: 08-February 06

Posted 10 February 2006 - 12:10 PM

Right, sorry about slow reply, been at college all day ^^;

Quote

20th Century Day by Day
800x600 Screen Saver
ABBYY FineReader 4.0 Sprint
Ad-Aware SE Personal
Adobe Acrobat 4.0
Adobe Illustrator CS
Adobe Photoshop 7.0
Adobe SVG Viewer 3.0
AIM Toolbar
AOL Instant Messenger
avast! Antivirus
Azureus
Betfair Bar
Betfair Poker
Brain Buster Quiz
BSPlayer
BT Broadband Help
BT Voyager ADSL Modem
BTinternet help
BTopenworld Dialler Manager 3.0
Chessmaster 7000
Compton’s 3D World Atlas Deluxe
Crossword Compiler 6
DivX
DivX Player
DivX Subtitle Displayer 4.54
EmpirePoker
ewido anti-malware
EyeStar Mail
Eyewitness Encyclopedia of Science 2.0
GSpot Codec Information Appliance
HijackThis 1.99.1
InstallShield for Microsoft Visual C++ 6
InterActual Player
Internet Explorer Q903235
iTunes
Java 2 Runtime Environment, SE v1.4.1_02
Java 2 Runtime Environment, SE v1.4.2_05
Java Web Start
Kazaa Media Desktop 2.1.1
Lexmark Supplies Monitor
Lexmark Z23-Z33
Matroska Pack - Lazy Man's MKV 0.9.7
Messenger Plus! 3
Microsoft Data Access Components KB870669
Microsoft Office XP Professional with FrontPage
Microsoft Visual Studio 6.0 Professional Edition
Microsoft Web Publishing Wizard 1.53
mIRC
MN100
ms1src
MSN Messenger 7.0
Mustek 1200 UB PLUS v1.1
My DSC
Netscape (7.2)
New.net Domains 6.90
NISIS USB Tablet Driver
Open Site
OutLaster
Oxford Revision Guides
Oz - TMA
Panda ActiveScan
PCFriendly
Perfect Keyboard PRO
Pirates of the Caribbean Screen Saver
PlayChess
Popup Blocker version 2.3
PowerDVD
Print Machine
QuickTime
Ragnarok Online
Ragnarok Sakray
RealOne Player
RTC Client API v1.2
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896426)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Selteco Flash Designer 4
Serif DrawPlus 4.0
Serif DrawPlus 4.0 Wizard Pack
Shockwave
Skype 1.4
Spybot - Search & Destroy 1.3
SpywareBlaster v3.5.1
StarOffice 5.2
the World Chess Network software
Tibia 7.55
Ulead Photo Express 3.0 SE
Update for Windows XP (KB898461)
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Viewpoint Toolbar (Remove Only)
WildTangent Web Driver
Winamp (remove only)
Window Searching
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player Hotfix [See Q828026 for more information]
Windows XP Hotfix - KB821557
Windows XP Hotfix - KB823182
Windows XP Hotfix - KB823559
Windows XP Hotfix - KB823980
Windows XP Hotfix - KB824105
Windows XP Hotfix - KB824141
Windows XP Hotfix - KB825119
Windows XP Hotfix - KB828035
Windows XP Hotfix - KB828741
Windows XP Hotfix - KB833987
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB835732
Windows XP Hotfix - KB837001
Windows XP Hotfix - KB839643
Windows XP Hotfix - KB839645
Windows XP Hotfix - KB840315
Windows XP Hotfix - KB840374
Windows XP Hotfix - KB840987
Windows XP Hotfix - KB841356
Windows XP Hotfix - KB841533
Windows XP Hotfix - KB841873
Windows XP Hotfix - KB842773
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB871250
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB873376
Windows XP Hotfix - KB883939
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB889293
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891711
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Hotfix - KB896727
Windows XP Hotfix - KB897715
Windows XP Hotfix (SP2) [See Q329048 for more information]
Windows XP Hotfix (SP2) [See Q329115 for more information]
Windows XP Hotfix (SP2) [See Q329390 for more information]
Windows XP Hotfix (SP2) [See Q329834 for more information]
Windows XP Hotfix (SP2) Q328310
Windows XP Hotfix (SP2) Q329170
Windows XP Hotfix (SP2) Q329441
Windows XP Hotfix (SP2) Q331953
Windows XP Hotfix (SP2) Q810565
Windows XP Hotfix (SP2) Q810577
Windows XP Hotfix (SP2) Q810833
Windows XP Hotfix (SP2) Q811493
Windows XP Hotfix (SP2) Q814033
Windows XP Hotfix (SP2) Q815021
Windows XP Hotfix (SP2) Q817287
Windows XP Hotfix (SP2) Q817606
Windows XP Hotfix (SP2) Q819696
WinRAR archiver
World Explorer
XviD MPEG-4 Video Codec
Yahoo! extras
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Toolbar
ZoneAlarm
Zoom USB ADSL WAN Adapter


#4 Buckeye_Sam

  • Group: Member
  • Posts: 10,019
  • Joined: 10-July 05

Posted 11 February 2006 - 05:12 PM

Please click Start -> Control Panel -> Add/Remove Programs and uninstall these programs:


ms1src
New.net Domains 6.90
Open Site
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Viewpoint Toolbar (Remove Only)
WildTangent Web Driver
Window Searching



Reboot and post a new hijackthis log(original log).

#5 chenli

  • Group: Member
  • Posts: 23
  • Joined: 08-February 06

Posted 11 February 2006 - 05:41 PM

Quote

Logfile of HijackThis v1.99.1
Scan saved at 23:37:50, on 11/02/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashserv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\SOINTGR.EXE
C:\Program Files\Perfect Keyboard PRO\pk32.exe
C:\DOCUME~1\Chris\LOCALS~1\Temp\RunMotive.exe
C:\Program Files\Zoom\CnxDslTb.exe
C:\Program Files\Perfect Keyboard PRO\_loader.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Perfect Keyboard PRO\_prog.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\atwtusb.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Documents and Settings\Alex\My Documents\My Pictures\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bssfcxmpmecwyfhuhlfulnf.com/Rbn...t1J/7ug_9tx.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.btinternet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTinternet
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.znqqdrxlxhcpetbvuimelwzo.us/Rbnk2Qr2dFQ_8fpqH5Z0dinJGjhYlY2FGsMmwll8n0w.html"); (C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5Cmozilla.org%5CMozilla%5Csearchplugins%5Cgoogle.src"); (C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\prefs.js)
O1 - Hosts: comments (such as these) may be inserted on individual
O2 - BHO: (no name) - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - (no file)
O3 - Toolbar: Betfair Bar - {1D62BD48-16F6-4004-A54A-3C41E4955A87} - C:\Program Files\Betfair\BFTool_4.dll
O3 - Toolbar: Updated.Toolbar - {9F6A22E6-1682-4F82-9B72-6314794CB253} - C:\Program Files\Pop Blocker\Updated.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SUPASTATUS] C:\Program Files\Internet Explorer\Connection Wizard\status.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [SO5 Integrator Pass Two] C:\WINDOWS\SOINTGR.EXE
O4 - HKLM\..\Run: [Gtwatch] C:\WINDOWS\gtwatch.exe
O4 - HKLM\..\Run: [Perfect Keyboard PRO] "C:\Program Files\Perfect Keyboard PRO\pk32.exe" /winstart
O4 - HKLM\..\Run: [RemHelp] remhelp.exe
O4 - HKLM\..\Run: [RunMotive] C:\DOCUME~1\Chris\LOCALS~1\Temp\RunMotive.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Program Files\Zoom\CnxDslTb.exe
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] DSLAGENT.EXE USB
O4 - HKLM\..\Run: [GsiFinal] rundll32 gspndll.dll,postInstall final
O4 - HKLM\..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Windows Update Files] C:\Program Files\microsoft hardware\dnetc.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KAZAA] "C:\Program Files\Kazaa Lite\kpp.exe" "C:\Program Files\Kazaa Lite\kazaalite.kpp" /SYSTRAY
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Hindustan] C:\Documents and Settings\Alex\My Documents\msn-fake\msmsgs.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [shhost] C:\Program Files\OutLaster\shhost.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [JVM0.12] C:\WINDOWS\System32\lzjerxb.exe
O4 - HKLM\..\Run: [JVM0.14] C:\WINDOWS\System32\hyrmif.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ms1src] c:\program files\common files\system\ms1src.exe /install
O4 - HKLM\..\Run: [blue bold deaf audio] C:\Documents and Settings\All Users\Application Data\MEET COPY BLUE BOLD\Window Upload.exe
O4 - HKLM\..\Run: [Microsoft System Restore Configuration] CBRSS.EXE
O4 - HKLM\..\Run: [Open Site] "C:\Program Files\Open Site\opensite.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [HOLE SITE] C:\DOCUME~1\Alex\APPLIC~1\FACENE~1\Find Exit.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Watch.lnk = C:\WINDOWS\twain_32\S6U12BX\WATCH.exe
O4 - Global Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband\Help\bin\matcli.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_90.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.btinternet.com/
O16 - DPF: ChatSpace Full Java Client 2.1.0.84 - http://about.chatspa...va/cs4fs084.cab
O16 - DPF: ChatSpace Full Java Client 3.1.0.220 - http://wiredreality....va/cfs31220.cab
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://irc.everywher...va/cfs31229.cab
O16 - DPF: ChatSpace Full Java Client 3.1.0.235 - http://205.177.13.10...va/cfs31235.cab
O16 - DPF: ChatSpace Java Client 2.1.0.79 - http://65.95.142.201/Java/cs4ms079.cab
O16 - DPF: ChatSpace Java Client 2.1.0.90 - http://servers.secur...va/cs4ms090.cab
O16 - DPF: ChatSpace Java Client 2.1.0.95 - http://chat.chatspac...va/cs4ms095.cab
O16 - DPF: ChatSpace Java Client 3.1.0.212 - http://moonchatuk.dy...va/cms31212.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cab
O16 - DPF: Yahoo! Chat 1.3 - http://cs5.chat.sc5....m/c174/chat.cab
O16 - DPF: Yahoo! Dots - http://download.game...ts/y/dtt1_x.cab
O16 - DPF: Yahoo! Go - http://download.game...nts/y/gt1_x.cab
O16 - DPF: {11111111-1111-1111-1111-111111111123} - file://c:\Recycled\1.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebpr...etup1.0.0.5.exe
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} -
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200112...meInstaller.exe
O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} -
O16 - DPF: {4E6F9E15-C8E3-4E19-B987-04EF390E9824} - http://www.betfair.c...stall/setup.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} -
O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} -
O16 - DPF: {88C51E90-8E9C-4C96-8A45-574D88B63FAF} - http://acceso.masmin...aaplicacion.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} -
O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} -
O16 - DPF: {D53B810F-6219-11D4-95B6-0040950375E7} -
O16 - DPF: {E62A47D8-74B1-4A93-963A-E5E43B7CC5C2} (UCSearch.ucUCSearch) - http://www.zuvio.com...te/UCSearch.CAB
O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} -
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} -
O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/gba1388.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{239D01FA-E874-43E0-BFDB-BF0613D4F9FD}: NameServer = 194.72.9.34 194.72.0.114
O17 - HKLM\System\CS1\Services\Tcpip\..\{239D01FA-E874-43E0-BFDB-BF0613D4F9FD}: NameServer = 194.72.9.34 194.72.0.114
O19 - User stylesheet: (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashserv.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe


#6 Buckeye_Sam

  • Group: Member
  • Posts: 10,019
  • Joined: 10-July 05

Posted 11 February 2006 - 06:48 PM

Please disable Spybot's Teatimer function before you proceed with this fix. If you're not sure how to do that, check this link.
http://russelltexas....re/teatimer.htm

Please follow these steps:
  • Please make sure that you can View Hidden Files
    • Click Start -> My Computer
    • Select Tools -> Folder options
    • Select the View tab and make sure that 'Show hidden files and folders' (or 'Show all files') is enabled.
    • Also make sure that 'Display the contents of system folders' is checked.
    • Make sure "Hide extensions for known file types" is unchecked
    • Make sure "Hide protected operating system files (recommended)" is unchecked
    • For more info on how to show hidden files click here.




  • Run Hijackthis again, click scan, and Put a checkmark next to each of these. Then close all other windows--you should only see HijackThis on your Desktop--and click the Fix Checked button.


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bssfcxmpmecwyfhuhlfulnf.com/Rbn...t1J/7ug_9tx.htm
    N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.znqqdrxlxhcpetbvuimelwzo.us/Rbnk2Qr2dFQ_8fpqH5Z0dinJGjhYlY2FGsMmwll8n0w.html"); (C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\prefs.js)
    O1 - Hosts: comments (such as these) may be inserted on individual
    O2 - BHO: (no name) - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - (no file)
    O3 - Toolbar: (no name) - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - (no file)
    O4 - HKLM\..\Run: [RunMotive] C:\DOCUME~1\Chris\LOCALS~1\Temp\RunMotive.exe
    O4 - HKLM\..\Run: [Windows Update Files] C:\Program Files\microsoft hardware\dnetc.exe
    O4 - HKLM\..\Run: [Hindustan] C:\Documents and Settings\Alex\My Documents\msn-fake\msmsgs.exe
    O4 - HKLM\..\Run: [shhost] C:\Program Files\OutLaster\shhost.exe
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
    O4 - HKLM\..\Run: [JVM0.12] C:\WINDOWS\System32\lzjerxb.exe
    O4 - HKLM\..\Run: [JVM0.14] C:\WINDOWS\System32\hyrmif.exe
    O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
    O4 - HKLM\..\Run: [ms1src] c:\program files\common files\system\ms1src.exe /install
    O4 - HKLM\..\Run: [blue bold deaf audio] C:\Documents and Settings\All Users\Application Data\MEET COPY BLUE BOLD\Window Upload.exe
    O4 - HKLM\..\Run: [Microsoft System Restore Configuration] CBRSS.EXE
    O4 - HKLM\..\Run: [Open Site] "C:\Program Files\Open Site\opensite.exe"
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKCU\..\Run: [HOLE SITE] C:\DOCUME~1\Alex\APPLIC~1\FACENE~1\Find Exit.exe
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {11111111-1111-1111-1111-111111111123} - file://c:\Recycled\1.exe
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebpr...etup1.0.0.5.exe
    O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) -
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} -
    O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} -
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
    O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} -
    O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} -
    O16 - DPF: {88C51E90-8E9C-4C96-8A45-574D88B63FAF} - http://acceso.masminutos.com/laaplicacion.cab
    O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} -
    O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} -
    O16 - DPF: {D53B810F-6219-11D4-95B6-0040950375E7} -
    O16 - DPF: {E62A47D8-74B1-4A93-963A-E5E43B7CC5C2} (UCSearch.ucUCSearch) - http://www.zuvio.com/opnste/UCSearch.CAB
    O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} -
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} -
    O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/gba1388.exe
    O19 - User stylesheet: (file missing)




  • Please reboot your computer in SafeMode by doing the following:
    • Restart your computer
    • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
    • Instead of Windows loading as normal, a menu should appear
    • Select the first option, to run Windows in Safe Mode.
    • If you have trouble getting into Safe mode go here for more info.





  • Once in Safe mode, delete these files or directories (Do not be concerned if they do not exist):


    C:\Program Files\microsoft hardware\dnetc.exe
    C:\Documents and Settings\Alex\My Documents\msn-fake\msmsgs.exe
    C:\Program Files\OutLaster\shhost.exe
    C:\WINDOWS\System32\lzjerxb.exe
    C:\WINDOWS\System32\hyrmif.exe
    C:\Program Files\WildTangent
    c:\program files\common files\system\ms1src.exe
    C:\Program Files\Open Site
    C:\Program Files\Viewpoint
    C:\DOCUME~1\Alex\APPLIC~1\FACENE~1
    C:\Documents and Settings\All Users\Application Data\MEET COPY BLUE BOLD
    CBRSS.EXE


Reboot your computer to go back to normal mode.


Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report along with a new hijackthis log.


#7 chenli

  • Group: Member
  • Posts: 23
  • Joined: 08-February 06

Posted 12 February 2006 - 10:37 AM

Active Scan Report:

[quote]
Incident Status Location

Dialer:dialer.xs Not disinfected C:\WINDOWS\SYSTEM32\DialerOffline.dll
Spyware:spyware/whazit Not disinfected C:\WINDOWS\SYSTEM32\kyf.dat
Adware:adware/securityerror Not disinfected C:\WINDOWS\SYSTEM32\mscornet.exe
Adware:adware/comet Not disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\cc.inf
Adware:adware/savenow Not disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\WUInst.dll
Adware:adware/clocksync Not disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\ClockSyncInst.inf
Adware:adware/fastvideoplayer Not disinfected C:\WINDOWS\INF\fastvideoplayer.inf
Adware:adware/gator Not disinfected C:\GatorPatch.log
Dialer:dialer.bny Not disinfected C:\WINDOWS\pcconfig.dat
Adware:adware/cws.bootconf Not disinfected C:\WINDOWS\default.css
Dialer:dialer generic Not disinfected C:\PROGRAM FILES\dialers
Spyware:spyware/new.net Not disinfected C:\PROGRAM FILES\NewDotNet
Potentially unwanted tool:application/mywebsearch Not disinfected C:\PROGRAM FILES\MyWebSearch
Adware:adware/lop Not disinfected C:\PROGRAM FILES\C2Media
Dialer:dialer.db Not disinfected HKEY_CURRENT_USER\SOFTWARE\MATRIX_HTML
Spyware:spyware/dluca Not disinfected Windows Registry
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Alex\Cookies\alex@stats1.reliablestats[1].txt
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Alex\Cookies\alex@webpower[3].txt
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\Alex\Cookies\alex@winfixer[2].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Alex\Cookies\alex@com[2].txt
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Alex\Cookies\alex@tickle[1].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Alex\Cookies\alex@ask[3].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Alex\Cookies\alex@xmts[2].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Alex\Cookies\alex@gostats[3].txt
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Alex\Cookies\alex@webpower[1].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Alex\Cookies\alex@c3.gostats[2].txt
Spyware:Cookie/Tucows Not disinfected C:\Documents and Settings\Alex\Cookies\alex@tucows[1].txt
Spyware:Cookie/TopRebates.com Not disinfected C:\Documents and Settings\Alex\Cookies\alex@www.toprebates[2].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Alex\Cookies\alex@go[2].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Alex\Cookies\alex@go[4].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Alex\Cookies\alex@888[5].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Alex\Cookies\alex@888[3].txt
Spyware:Cookie/Versiontracker Not disinfected C:\Documents and Settings\Alex\Cookies\alex@versiontracker[2].txt
Spyware:Cookie/Kazaa Networks Not disinfected C:\Documents and Settings\Alex\Cookies\alex@desktop.kazaa[2].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Alex\Cookies\alex@888[2].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Alex\Cookies\alex@xmts[3].txt
Spyware:Cookie/CaptainCode Not disinfected C:\Documents and Settings\Alex\Cookies\alex@www.captaincode[1].txt
Spyware:Cookie/Gorillanation Not disinfected C:\Documents and Settings\Alex\Cookies\alex@ads.gorillanation[1].txt
Spyware:Cookie/Inet-Traffic Not disinfected C:\Documents and Settings\Alex\Cookies\alex@inet-traffic[1].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Alex\Cookies\alex@go[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Alex\Cookies\alex@ad.yieldmanager[1].txt
Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\Alex\Cookies\alex@rightmedia[1].txt
Spyware:Cookie/Mircx Not disinfected C:\Documents and Settings\Alex\Cookies\alex@pop.mircx[2].txt
Spyware:Cookie/CWS Not disinfected C:\Documents and Settings\Alex\Cookies\alex@coolwebsearch[1].txt
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\Alex\Cookies\alex@fe.lea.lycos[1].txt
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Alex\Cookies\alex@webpower[2].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Alex\Cookies\alex@c2.gostats[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Alex\Cookies\alex@dist.belnk[2].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Alex\Cookies\alex@gostats[1].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Alex\Cookies\alex@888[1].txt
Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\Alex\Cookies\alex@rn11[2].txt
Spyware:Cookie/GangbangSquad Not disinfected C:\Documents and Settings\Alex\Cookies\alex@www.gangbangsquad[1].txt
Spyware:Cookie/Myfunstart Not disinfected C:\Documents and Settings\Alex\Cookies\alex@www.myfunstart[2].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Alex\Cookies\alex@toplist[1].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Alex\Cookies\alex@azjmp[2].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Alex\Cookies\alex@xmts[1].txt
Spyware:Cookie/Santa Monica networks inc Not disinfected C:\Documents and Settings\Alex\Cookies\alex@smni[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Alex\Cookies\alex@belnk[1].txt
Spyware:Cookie/Kount Not disinfected C:\Documents and Settings\Alex\Cookies\alex@kount[2].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Alex\Cookies\alex@ask[2].txt
Spyware:Cookie/Gorillanation Not disinfected C:\Documents and Settings\Alex\Cookies\alex@ads.gorillanation[2].txt
Spyware:Cookie/64.62.232 Not disinfected C:\Documents and Settings\Alex\Cookies\alex@64.62.232[2].txt
Spyware:Cookie/Mircx Not disinfected C:\Documents and Settings\Alex\Cookies\alex@pop.mircx[3].txt
Spyware:Cookie/Uproar Not disinfected C:\Documents and Settings\Alex\Cookies\alex@ads.uproar[2].txt
Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Alex\Cookies\alex@banner[2].txt
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Alex\Cookies\alex@tickle[3].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Alex\Cookies\alex@azjmp[3].txt
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\Alex\Cookies\alex@fe.lea.lycos[2].txt
Spyware:Cookie/Kount Not disinfected C:\Documents and Settings\Alex\Cookies\alex@kount[1].txt
Spyware:Cookie/Seeq Not disinfected C:\Documents and Settings\Alex\Cookies\alex@seeq[1].txt
Spyware:Cookie/Sandboxer Not disinfected C:\Documents and Settings\Alex\Cookies\alex@307[1].txt
Spyware:Cookie/MyWay Not disinfected C:\Documents and Settings\Alex\Cookies\alex@www.xzoomy[1].txt
Spyware:Cookie/Mp3s Hits Not disinfected C:\Documents and Settings\Alex\Cookies\alex@www.mp3shits[2].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Alex\Cookies\alex@searchportal.information[1].txt
Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Alex\Cookies\alex@banner[1].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Alex\Cookies\alex@ask[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Alex\Cookies\alex@xiti[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Alex\Cookies\alex@dist.belnk[3].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Alex\Cookies\alex@ath.belnk[2].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Alex\Cookies\alex@adultfriendfinder[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Alex\Cookies\alex@dist.belnk[4].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Alex\Cookies\alex@888[4].txt
Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\Alex\Cookies\alex@cassava[1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\cookies.txt[.burstnet.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\cookies.txt[.belnk.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\cookies.txt[.com.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\cookies.txt[.serving-sys.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\m6bocq98.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\m6bocq98.default\cookies.txt[.fortunecity.com/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\qwmd4yjj.Default User\cookies.txt[.fortunecity.com/]
Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\qwmd4yjj.Default User\cookies.txt[rightmedia.net/]
Dialer:Dialer.CPY Not disinfected C:\WINDOWS\system32\DialerOffline.dll
Dialer:Dialer.CSV Not disinfected C:\WINDOWS\system32\HotPleasureXXX-uninstall.exe
Adware:Adware/SpywareNo Not disinfected C:\WINDOWS\system32\1024\ldFA0A.tmp
Adware:Adware/SpywareStrike Not disinfected C:\WINDOWS\system32\hp62F6.tmp
Adware:Adware/StripPlayer Not disinfected C:\WINDOWS\inf\strip-player.inf
Spyware:Spyware/Smitfraud Not disinfected C:\WINDOWS\Temp\SSLanguage.ini
Adware:Adware/Gator Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\trickler3103.ex_[trickler3103.exe]
Dialer:Dialer.Gen Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\nsiDA.exe
Spyware:Spyware/BetterInet Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\biini.inf
Spyware:Spyware/Apropos Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\~apropos0\setup.inf
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\wtyuohis.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\Rem2.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\dmsqsvgu.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\axfszmyd.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\fsplqqbc.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\hireshye.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\dxlgybjp.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\sta3.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\1f3991.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\hqfhxquw.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\atxvaapa.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\298f81.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\12520d1.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\jqqpcstm.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\jslheosv.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\rclrnztp.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\bhphkmjx.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\8e8b7ed0.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\Inside Program.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\atiqqkun.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\hfpcadks.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\ezfmmblq.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\njixumfk.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\sta7.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\lkfzrjyt.exe
Adware:Adware/SafeSearch Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\lf_1DAC.tmp
Adware:Adware/SafeSearch Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\lf_1E90.tmp
Adware:Adware/SafeSearch Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\lf_6E8.tmp
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\8e881f12.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\sta2.exe
Spyware:Spyware/Smitfraud Not disinfected C:\Documents and Settings\Chris\Local Settings\Temp\SSLanguage.ini
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\WTK5GT25\newpass2[1].htm
Spyware:Cookie/Sandboxer Not disinfected C:\Documents and Settings\Chris\Cookies\chris@307[2].txt
Spyware:Cookie/Kount Not disinfected C:\Documents and Settings\Chris\Cookies\chris@kount[1].txt
Spyware:Cookie/Sexsuche Not disinfected C:\Documents and Settings\Chris\Cookies\chris@counter.sexsuche[2].txt
Spyware:Cookie/MyWay Not disinfected C:\Documents and Settings\Chris\Cookies\chris@www.xzoomy[1].txt
Spyware:Cookie/Intelli-tracker Not disinfected C:\Documents and Settings\Chris\Cookies\chris@www.intelli-tracker[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Chris\Cookies\chris@realmedia[1].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Chris\Cookies\chris@adultfriendfinder[1].txt
Spyware:Cookie/Errorguard Not disinfected C:\Documents and Settings\Chris\Cookies\chris@errorguard[2].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Chris\Cookies\chris@xiti[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Chris\Cookies\chris@dist.belnk[2].txt
Spyware:Cookie/SpywareStormer Not disinfected C:\Documents and Settings\Chris\Cookies\chris@spywarestormer[1].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Chris\Cookies\chris@adopt.hbmediapro[1].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Chris\Cookies\chris@toplist[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Chris\Cookies\chris@belnk[1].txt
Spyware:Cookie/Advnt Not disinfected C:\Documents and Settings\Chris\Cookies\chris@www.advnt01[1].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Chris\Cookies\chris@adultfriendfinder[2].txt
Spyware:Cookie/Hypercount Not disinfected C:\Documents and Settings\Chris\Cookies\chris@hypercount[2].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Chris\Cookies\chris@gostats[2].txt
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\Chris\Cookies\chris@winfixer[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Chris\Cookies\chris@dist.belnk[3].txt
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Chris\Cookies\chris@ct.360i[1].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Chris\Cookies\chris@adultfriendfinder[3].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Chris\Cookies\chris@apmebf[2].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Chris\Cookies\chris@xiti[2].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Chris\Cookies\chris@888[2].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Chris\Cookies\chris@go[2].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Chris\Cookies\chris@ccbill[2].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Chris\Cookies\chris@888[1].txt
Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\Chris\Cookies\chris@cassava[1].txt
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Chris\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-66d293ce-6ba662e9.zip[Counter.class]
Virus:Exploit/ByteVerify Disinfected

#8 chenli

  • Group: Member
  • Posts: 23
  • Joined: 08-February 06

Posted 12 February 2006 - 10:40 AM

Quote

Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Chris\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-66d293ce-6ba662e9.zip[Gummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Chris\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-66d293ce-6ba662e9.zip[VerifierBug.class]
Virus:Trj/Lowzones.KI Disinfected C:\Documents and Settings\Chris\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-66d293ce-6ba662e9.zip[web.exe]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Chris\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-66d293ce-6ba662e9.zip[Worker.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Chris\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-66d293ce-6ba662e9.zip[Xeyond.class]
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\plussoaperrorobj.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\iympogod.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\LiesOnceHeart.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\ydvbsmbz.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\wceflztp.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\qvjicova.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\tdbwdkuo.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\ozzrjaxs.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\cqfvbrwe.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\Find Exit.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\wgbnhjte.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\brckcdbs.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\ftdliwdx.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\hybuwojw.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\gpggvsff.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\odrjoiih.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\ivaysaev.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\FACENEWBEEP\qkgothdv.exe
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Chris\Application Data\Netscape\NSB\Profiles\um2xmgn2.default\cookies.txt[]
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris\Application Data\SixthDoesHope\2 ace.exe
Adware:Adware/SafeSearch Not disinfected C:\Documents and Settings\Alex\Local Settings\Temp\lf_190.tmp
Adware:Adware/SafeSearch Not disinfected C:\Documents and Settings\Alex\Local Settings\Temp\lf_8BC.tmp
Adware:Adware/SafeSearch Not disinfected C:\Documents and Settings\Alex\Local Settings\Temp\lf_684.tmp
Adware:Adware/SafeSearch Not disinfected C:\Documents and Settings\Alex\Local Settings\Temp\lf_7C0.tmp
Adware:Adware/SafeSearch Not disinfected C:\Documents and Settings\Alex\Local Settings\Temp\lf_824.tmp
Adware:Adware/SafeSearch Not disinfected C:\Documents and Settings\Alex\Local Settings\Temp\lf_8A0.tmp
Adware:Adware/SafeSearch Not disinfected C:\Documents and Settings\Alex\Local Settings\Temp\lf_898.tmp
Adware:Adware/SafeSearch Not disinfected C:\Documents and Settings\Alex\Local Settings\Temp\lf_268.tmp
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Alex\Local Settings\Temp\sta1B.exe
Dialer:Dialer.BEW Not disinfected C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\Content.IE5\RWY87YG0\access[1][Content]
Dialer:Dialer.BEW Not disinfected C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\Content.IE5\RWY87YG0\access[2][Content]
Dialer:Dialer.BEW Not disinfected C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\Content.IE5\QPMRRG91\access[1][Content]
Dialer:Dialer.BEW Not disinfected C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\Content.IE5\4LAJKT6B\access[1][Content]
Dialer:Dialer.BEW Not disinfected C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\Content.IE5\4LAJKT6B\access[2][Content]
Dialer:Dialer.BEW Not disinfected C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\Content.IE5\4LAJKT6B\access[3][Content]
Dialer:Dialer.BEW Not disinfected C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\Content.IE5\4LAJKT6B\access[4][Content]
Dialer:Dialer.BEW Not disinfected C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\Content.IE5\IM55CKID\access[1][Content]
Dialer:Dialer.BEW Not disinfected C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\Content.IE5\IM55CKID\access[1].cgi
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\Content.IE5\IM55CKID\smitRem[2].exe[Process.exe]
Dialer:Dialer.BEW Not disinfected C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\Content.IE5\EJEBEPQB\access[1].cgi
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\Content.IE5\EJEBEPQB\newpass2[2].htm
Dialer:Dialer.DZE Not disinfected C:\Documents and Settings\Alex\My Documents\My Pictures\Hijackthis\backups\backup-20060212-141541-891.inf
Adware:Adware/Opensite Not disinfected C:\Documents and Settings\Alex\My Documents\My Pictures\Hijackthis\backups\backup-20060212-141544-256.inf
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Alex\Desktop\smitRem.exe[Process.exe]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Alex\Desktop\smitRem\Process.exe
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Alex\Cookies\alex@stats1.reliablestats[1].txt
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Alex\Cookies\alex@webpower[3].txt
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\Alex\Cookies\alex@winfixer[2].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Alex\Cookies\alex@com[2].txt
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Alex\Cookies\alex@tickle[1].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Alex\Cookies\alex@ask[3].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Alex\Cookies\alex@xmts[2].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Alex\Cookies\alex@gostats[3].txt
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Alex\Cookies\alex@webpower[1].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Alex\Cookies\alex@c3.gostats[2].txt
Spyware:Cookie/Tucows Not disinfected C:\Documents and Settings\Alex\Cookies\alex@tucows[1].txt
Spyware:Cookie/TopRebates.com Not disinfected C:\Documents and Settings\Alex\Cookies\alex@www.toprebates[2].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Alex\Cookies\alex@go[2].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Alex\Cookies\alex@go[4].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Alex\Cookies\alex@888[5].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Alex\Cookies\alex@888[3].txt
Spyware:Cookie/Versiontracker Not disinfected C:\Documents and Settings\Alex\Cookies\alex@versiontracker[2].txt
Spyware:Cookie/Kazaa Networks Not disinfected C:\Documents and Settings\Alex\Cookies\alex@desktop.kazaa[2].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Alex\Cookies\alex@888[2].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Alex\Cookies\alex@xmts[3].txt
Spyware:Cookie/CaptainCode Not disinfected C:\Documents and Settings\Alex\Cookies\alex@www.captaincode[1].txt
Spyware:Cookie/Gorillanation Not disinfected C:\Documents and Settings\Alex\Cookies\alex@ads.gorillanation[1].txt
Spyware:Cookie/Inet-Traffic Not disinfected C:\Documents and Settings\Alex\Cookies\alex@inet-traffic[1].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Alex\Cookies\alex@go[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Alex\Cookies\alex@ad.yieldmanager[1].txt
Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\Alex\Cookies\alex@rightmedia[1].txt
Spyware:Cookie/Mircx Not disinfected C:\Documents and Settings\Alex\Cookies\alex@pop.mircx[2].txt
Spyware:Cookie/CWS Not disinfected C:\Documents and Settings\Alex\Cookies\alex@coolwebsearch[1].txt
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\Alex\Cookies\alex@fe.lea.lycos[1].txt
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Alex\Cookies\alex@webpower[2].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Alex\Cookies\alex@c2.gostats[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Alex\Cookies\alex@dist.belnk[2].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Alex\Cookies\alex@gostats[1].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Alex\Cookies\alex@888[1].txt
Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\Alex\Cookies\alex@rn11[2].txt
Spyware:Cookie/GangbangSquad Not disinfected C:\Documents and Settings\Alex\Cookies\alex@www.gangbangsquad[1].txt
Spyware:Cookie/Myfunstart Not disinfected C:\Documents and Settings\Alex\Cookies\alex@www.myfunstart[2].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Alex\Cookies\alex@toplist[1].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Alex\Cookies\alex@azjmp[2].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Alex\Cookies\alex@xmts[1].txt
Spyware:Cookie/Santa Monica networks inc Not disinfected C:\Documents and Settings\Alex\Cookies\alex@smni[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Alex\Cookies\alex@belnk[1].txt
Spyware:Cookie/Kount Not disinfected C:\Documents and Settings\Alex\Cookies\alex@kount[2].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Alex\Cookies\alex@ask[2].txt
Spyware:Cookie/Gorillanation Not disinfected C:\Documents and Settings\Alex\Cookies\alex@ads.gorillanation[2].txt
Spyware:Cookie/64.62.232 Not disinfected C:\Documents and Settings\Alex\Cookies\alex@64.62.232[2].txt
Spyware:Cookie/Mircx Not disinfected C:\Documents and Settings\Alex\Cookies\alex@pop.mircx[3].txt
Spyware:Cookie/Uproar Not disinfected C:\Documents and Settings\Alex\Cookies\alex@ads.uproar[2].txt
Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Alex\Cookies\alex@banner[2].txt
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Alex\Cookies\alex@tickle[3].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Alex\Cookies\alex@azjmp[3].txt
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\Alex\Cookies\alex@fe.lea.lycos[2].txt
Spyware:Cookie/Kount Not disinfected C:\Documents and Settings\Alex\Cookies\alex@kount[1].txt
Spyware:Cookie/Seeq Not disinfected C:\Documents and Settings\Alex\Cookies\alex@seeq[1].txt
Spyware:Cookie/Sandboxer Not disinfected C:\Documents and Settings\Alex\Cookies\alex@307[1].txt
Spyware:Cookie/MyWay Not disinfected C:\Documents and Settings\Alex\Cookies\alex@www.xzoomy[1].txt
Spyware:Cookie/Mp3s Hits Not disinfected C:\Documents and Settings\Alex\Cookies\alex@www.mp3shits[2].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Alex\Cookies\alex@searchportal.information[1].txt
Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Alex\Cookies\alex@banner[1].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Alex\Cookies\alex@ask[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Alex\Cookies\alex@xiti[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Alex\Cookies\alex@dist.belnk[3].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Alex\Cookies\alex@ath.belnk[2].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Alex\Cookies\alex@adultfriendfinder[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Alex\Cookies\alex@dist.belnk[4].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Alex\Cookies\alex@888[4].txt
Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\Alex\Cookies\alex@cassava[1].txt
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Alex\Application Data\eaiessgrllnl.lib
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\m6bocq98.default\cookies.txt[]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\qwmd4yjj.Default User\cookies.txt[]
Adware:Adware/WUpd Not disinfected C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\qwmd4yjj.Default User\Cache(2)\F1F8B163d01
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\cookies.txt[]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Alex\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-19061f19-2697fd5d.zip[GetAccess.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Alex\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-19061f19-2697fd5d.zip[InsecureClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Alex\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-19061f19-2697fd5d.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Alex\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-19061f19-2697fd5d.zip[Installer.class]
Adware:Adware/IST.ISTBar Not disinfected C:\Documents and Settings\Alex\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3cc46f89-6727a8e1.zip[InstallerApplet.class]
Hacktool:HackTool/Flood Not disinfected C:\Program Files\stat\dll\nhtmln.dll
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
Spyware:Cookie/Advertising Not disinfected C:\FOUND.003\FILE0001.CHK
Spyware:Cookie/Advertising Not disinfected C:\FOUND.003\FILE0002.CHK


#9 chenli

  • Group: Member
  • Posts: 23
  • Joined: 08-February 06

Posted 12 February 2006 - 10:43 AM

HijackThis report:

Quote

Logfile of HijackThis v1.99.1
Scan saved at 16:37:16, on 12/02/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashserv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\SOINTGR.EXE
C:\Program Files\Perfect Keyboard PRO\pk32.exe
C:\Program Files\Zoom\CnxDslTb.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Perfect Keyboard PRO\_loader.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Perfect Keyboard PRO\_prog.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\System32\atwtusb.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Alex\My Documents\My Pictures\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.pidkvgujxiixyf.us/Rbnk2Qr2dFRrU...d1J/7ug_9tx.jpg
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.btinternet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTinternet
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5Cmozilla.org%5CMozilla%5Csearchplugins%5Cgoogle.src"); (C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\prefs.js)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SUPASTATUS] C:\Program Files\Internet Explorer\Connection Wizard\status.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [SO5 Integrator Pass Two] C:\WINDOWS\SOINTGR.EXE
O4 - HKLM\..\Run: [Gtwatch] C:\WINDOWS\gtwatch.exe
O4 - HKLM\..\Run: [Perfect Keyboard PRO] "C:\Program Files\Perfect Keyboard PRO\pk32.exe" /winstart
O4 - HKLM\..\Run: [RemHelp] remhelp.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Program Files\Zoom\CnxDslTb.exe
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] DSLAGENT.EXE USB
O4 - HKLM\..\Run: [GsiFinal] rundll32 gspndll.dll,postInstall final
O4 - HKLM\..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KAZAA] "C:\Program Files\Kazaa Lite\kpp.exe" "C:\Program Files\Kazaa Lite\kazaalite.kpp" /SYSTRAY
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Watch.lnk = C:\WINDOWS\twain_32\S6U12BX\WATCH.exe
O4 - Global Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband\Help\bin\matcli.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_90.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.btinternet.com/
O16 - DPF: ChatSpace Full Java Client 2.1.0.84 - http://about.chatspa...va/cs4fs084.cab
O16 - DPF: ChatSpace Full Java Client 3.1.0.220 - http://wiredreality....va/cfs31220.cab
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://irc.everywher...va/cfs31229.cab
O16 - DPF: ChatSpace Full Java Client 3.1.0.235 - http://205.177.13.10...va/cfs31235.cab
O16 - DPF: ChatSpace Java Client 2.1.0.79 - http://65.95.142.201/Java/cs4ms079.cab
O16 - DPF: ChatSpace Java Client 2.1.0.90 - http://servers.secur...va/cs4ms090.cab
O16 - DPF: ChatSpace Java Client 2.1.0.95 - http://chat.chatspac...va/cs4ms095.cab
O16 - DPF: ChatSpace Java Client 3.1.0.212 - http://moonchatuk.dy...va/cms31212.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cab
O16 - DPF: Yahoo! Chat 1.3 - http://cs5.chat.sc5....m/c174/chat.cab
O16 - DPF: Yahoo! Dots - http://download.game...ts/y/dtt1_x.cab
O16 - DPF: Yahoo! Go - http://download.game...nts/y/gt1_x.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200112...meInstaller.exe
O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} -
O16 - DPF: {4E6F9E15-C8E3-4E19-B987-04EF390E9824} - http://www.betfair.c...stall/setup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{239D01FA-E874-43E0-BFDB-BF0613D4F9FD}: NameServer = 194.72.9.34 194.72.0.114
O17 - HKLM\System\CS1\Services\Tcpip\..\{239D01FA-E874-43E0-BFDB-BF0613D4F9FD}: NameServer = 194.72.9.34 194.72.0.114
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashserv.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe



#10 Buckeye_Sam

  • Group: Member
  • Posts: 10,019
  • Joined: 10-July 05

Posted 12 February 2006 - 07:47 PM

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only
    Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


===========


Please download the Killbox by Option^Explicit.

Note: In the event you already have Killbox, this is a new version that I need you to download.
  • Save it to your desktop.
  • Please double-click Killbox.exe to run it.
  • Select:
    • Delete on Reboot
    • then Click on the All Files button.

  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\Documents and Settings\Alex\Application Data\eaiessgrllnl.lib
    C:\Program Files\stat\dll\nhtmln.dll
    C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
    C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
    C:\WINDOWS\SYSTEM32\DialerOffline.dll
    C:\WINDOWS\SYSTEM32\kyf.dat
    C:\WINDOWS\SYSTEM32\mscornet.exe
    C:\WINDOWS\DOWNLOADED PROGRAM FILES\cc.inf
    C:\WINDOWS\DOWNLOADED PROGRAM FILES\WUInst.dll
    C:\WINDOWS\DOWNLOADED PROGRAM FILES\ClockSyncInst.inf
    C:\WINDOWS\INF\fastvideoplayer.inf
    C:\GatorPatch.log
    C:\WINDOWS\pcconfig.dat
    C:\WINDOWS\default.css
    C:\WINDOWS\system32\DialerOffline.dll
    C:\WINDOWS\system32\HotPleasureXXX-uninstall.exe
    C:\WINDOWS\system32\1024\ldFA0A.tmp
    C:\WINDOWS\system32\hp62F6.tmp
    C:\WINDOWS\inf\strip-player.inf
    C:\WINDOWS\Temp\SSLanguage.ini



  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.

  • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).

If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.


==========


Please download SmitRem
  • Save the file to your desktop.
  • Right click on the file and extract it to it's own folder on the desktop.



Please reboot your computer in SafeMode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
* if you have trouble getting into Safe mode go here for more info.



Once in Safe mode, follow these steps:
  • Delete these folders:

    C:\PROGRAM FILES\MyWebSearch
    C:\PROGRAM FILES\dialers
    C:\PROGRAM FILES\NewDotNet
    C:\PROGRAM FILES\C2Media
    C:\Documents and Settings\Chris\Application Data\FACENEWBEEP
    C:\Documents and Settings\Chris\Application Data\SixthDoesHope



  • Now open the smitRem folder, then double click the RunThis.bat file to start the tool.
  • Follow the prompts on screen.
  • Wait for the tool to complete and disk cleanup to finish.
  • The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.


Reboot back into normal mode.
Post the log file from Smitrem as well as a new hijackthis log.

#11 chenli

  • Group: Member
  • Posts: 23
  • Joined: 08-February 06

Posted 13 February 2006 - 01:17 PM

HijackThis Logfile:

Quote

Logfile of HijackThis v1.99.1
Scan saved at 19:11:19, on 13/02/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashserv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\SOINTGR.EXE
C:\Program Files\Perfect Keyboard PRO\pk32.exe
C:\Program Files\Perfect Keyboard PRO\_loader.exe
C:\Program Files\Perfect Keyboard PRO\_prog.exe
C:\Program Files\Zoom\CnxDslTb.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\atwtusb.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Documents and Settings\Alex\My Documents\My Pictures\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.pidkvgujxiixyf.us/Rbnk2Qr2dFRrU...d1J/7ug_9tx.jpg
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.btinternet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTinternet
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5Cmozilla.org%5CMozilla%5Csearchplugins%5Cgoogle.src"); (C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\prefs.js)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SUPASTATUS] C:\Program Files\Internet Explorer\Connection Wizard\status.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [SO5 Integrator Pass Two] C:\WINDOWS\SOINTGR.EXE
O4 - HKLM\..\Run: [Gtwatch] C:\WINDOWS\gtwatch.exe
O4 - HKLM\..\Run: [Perfect Keyboard PRO] "C:\Program Files\Perfect Keyboard PRO\pk32.exe" /winstart
O4 - HKLM\..\Run: [RemHelp] remhelp.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Program Files\Zoom\CnxDslTb.exe
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] DSLAGENT.EXE USB
O4 - HKLM\..\Run: [GsiFinal] rundll32 gspndll.dll,postInstall final
O4 - HKLM\..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KAZAA] "C:\Program Files\Kazaa Lite\kpp.exe" "C:\Program Files\Kazaa Lite\kazaalite.kpp" /SYSTRAY
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Watch.lnk = C:\WINDOWS\twain_32\S6U12BX\WATCH.exe
O4 - Global Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband\Help\bin\matcli.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_90.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.btinternet.com/
O16 - DPF: ChatSpace Full Java Client 2.1.0.84 - http://about.chatspa...va/cs4fs084.cab
O16 - DPF: ChatSpace Full Java Client 3.1.0.220 - http://wiredreality....va/cfs31220.cab
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://irc.everywher...va/cfs31229.cab
O16 - DPF: ChatSpace Full Java Client 3.1.0.235 - http://205.177.13.10...va/cfs31235.cab
O16 - DPF: ChatSpace Java Client 2.1.0.79 - http://65.95.142.201/Java/cs4ms079.cab
O16 - DPF: ChatSpace Java Client 2.1.0.90 - http://servers.secur...va/cs4ms090.cab
O16 - DPF: ChatSpace Java Client 2.1.0.95 - http://chat.chatspac...va/cs4ms095.cab
O16 - DPF: ChatSpace Java Client 3.1.0.212 - http://moonchatuk.dy...va/cms31212.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cab
O16 - DPF: Yahoo! Chat 1.3 - http://cs5.chat.sc5....m/c174/chat.cab
O16 - DPF: Yahoo! Dots - http://download.game...ts/y/dtt1_x.cab
O16 - DPF: Yahoo! Go - http://download.game...nts/y/gt1_x.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200112...meInstaller.exe
O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} -
O16 - DPF: {4E6F9E15-C8E3-4E19-B987-04EF390E9824} - http://www.betfair.c...stall/setup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{239D01FA-E874-43E0-BFDB-BF0613D4F9FD}: NameServer = 194.72.9.34 194.72.0.114
O17 - HKLM\System\CS1\Services\Tcpip\..\{239D01FA-E874-43E0-BFDB-BF0613D4F9FD}: NameServer = 194.72.9.34 194.72.0.114
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashserv.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe


As for smitrem, everytime I try to run it, I get this:

Posted Image

Come up. So basically it won't run properly :S I'm guessing.

#12 Buckeye_Sam

  • Group: Member
  • Posts: 10,019
  • Joined: 10-July 05

Posted 13 February 2006 - 07:19 PM

Did you download Smitrem previously to my last post? If so, delete it now and download the latest version.

You still have a LOP infection, which is being caused by the sponsor program in Messenger Plus.
Uninstall Messenger Plus and the LOP infection will be gone also.


Try to run Smitrem once again after downloading the latest version and let me know if you still get the same error.

#13 chenli

  • Group: Member
  • Posts: 23
  • Joined: 08-February 06

Posted 14 February 2006 - 01:15 PM

Deleted messenger plus. Re-downloaded Smitrem latest version. Still same error though.

#14 Buckeye_Sam

  • Group: Member
  • Posts: 10,019
  • Joined: 10-July 05

Posted 14 February 2006 - 07:41 PM

Please post a new hijackthis log.

#15 chenli

  • Group: Member
  • Posts: 23
  • Joined: 08-February 06

Posted 20 February 2006 - 12:04 PM

Sorry I haven't rsponded for ages; I've not been on this comp since last tuesday. :S

Quote

Logfile of HijackThis v1.99.1
Scan saved at 18:02:44, on 20/02/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashserv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\SOINTGR.EXE
C:\Program Files\Perfect Keyboard PRO\pk32.exe
C:\Program Files\Perfect Keyboard PRO\_loader.exe
C:\Program Files\Zoom\CnxDslTb.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Perfect Keyboard PRO\_prog.exe
C:\WINDOWS\System32\atwtusb.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Program Files\Common Files\Real\Update_OB\realevent.exe
C:\Program Files\Common Files\Real\Update_OB\realevent.exe
C:\Program Files\AIM95\aim.exe
C:\Documents and Settings\Alex\My Documents\My Pictures\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.pidkvgujxiixyf.us/Rbnk2Qr2dFRrU...d1J/7ug_9tx.jpg
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.btinternet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTinternet
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5Cmozilla.org%5CMozilla%5Csearchplugins%5Cgoogle.src"); (C:\Documents and Settings\Alex\Application Data\Mozilla\Profiles\default\wssokl0w.slt\prefs.js)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SUPASTATUS] C:\Program Files\Internet Explorer\Connection Wizard\status.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [SO5 Integrator Pass Two] C:\WINDOWS\SOINTGR.EXE
O4 - HKLM\..\Run: [Gtwatch] C:\WINDOWS\gtwatch.exe
O4 - HKLM\..\Run: [Perfect Keyboard PRO] "C:\Program Files\Perfect Keyboard PRO\pk32.exe" /winstart
O4 - HKLM\..\Run: [RemHelp] remhelp.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Program Files\Zoom\CnxDslTb.exe
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] DSLAGENT.EXE USB
O4 - HKLM\..\Run: [GsiFinal] rundll32 gspndll.dll,postInstall final
O4 - HKLM\..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KAZAA] "C:\Program Files\Kazaa Lite\kpp.exe" "C:\Program Files\Kazaa Lite\kazaalite.kpp" /SYSTRAY
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Watch.lnk = C:\WINDOWS\twain_32\S6U12BX\WATCH.exe
O4 - Global Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband\Help\bin\matcli.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_90.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.btinternet.com/
O16 - DPF: ChatSpace Full Java Client 2.1.0.84 - http://about.chatspa...va/cs4fs084.cab
O16 - DPF: ChatSpace Full Java Client 3.1.0.220 - http://wiredreality....va/cfs31220.cab
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://irc.everywher...va/cfs31229.cab
O16 - DPF: ChatSpace Full Java Client 3.1.0.235 - http://205.177.13.10...va/cfs31235.cab
O16 - DPF: ChatSpace Java Client 2.1.0.79 - http://65.95.142.201/Java/cs4ms079.cab
O16 - DPF: ChatSpace Java Client 2.1.0.90 - http://servers.secur...va/cs4ms090.cab
O16 - DPF: ChatSpace Java Client 2.1.0.95 - http://chat.chatspac...va/cs4ms095.cab
O16 - DPF: ChatSpace Java Client 3.1.0.212 - http://moonchatuk.dy...va/cms31212.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cab
O16 - DPF: Yahoo! Chat 1.3 - http://cs5.chat.sc5....m/c174/chat.cab
O16 - DPF: Yahoo! Dots - http://download.game...ts/y/dtt1_x.cab
O16 - DPF: Yahoo! Go - http://download.game...nts/y/gt1_x.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200112...meInstaller.exe
O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} -
O16 - DPF: {4E6F9E15-C8E3-4E19-B987-04EF390E9824} - http://www.betfair.c...stall/setup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{239D01FA-E874-43E0-BFDB-BF0613D4F9FD}: NameServer = 194.72.9.34 194.72.0.114
O17 - HKLM\System\CS1\Services\Tcpip\..\{239D01FA-E874-43E0-BFDB-BF0613D4F9FD}: NameServer = 194.72.9.34 194.72.0.114
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashserv.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe


Share this topic:


  • 2 Pages +
  • 1
  • 2