Unsolved
This post is more than 5 years old
13 Posts
0
3391
February 13th, 2005 01:00
need help on my hijack log
Hi there: I'm having much difficulty with trojans (being costantly caught by MacAfee) and IE shut downs, and I'm not that computer literate. Can someone please look at this log and give me some advice! Your time is deeply appreciated -sc Logfile of HijackThis v1.99.0 Scan saved at 6:58:51 PM, on 2/12/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe C:\WINDOWS\system32\sle.exe C:\Program Files\Dell\Media Experience\PCMService.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\WINDOWS\System32\hkcmd.exe C:\WINDOWS\System32\DSentry.exe C:\WINDOWS\BCMSMMSG.exe C:\WINDOWS\System32\hphmon05.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\sysmonnt.exe C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\system32\drivers\KodakCCS.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\System32\ScsiAccess.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\HPZipm12.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Juno\bin\juno.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\HiJack This\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank R3 - Default URLSearchHook is missing O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000002230} - C:\Program Files\CSBB\CSBB.DLL O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINDOWS\BTGrab.dll (file missing) O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll (file missing) O2 - BHO: (no name) - {017C20C1-F86F-11D8-9B25-000ACD002AE3} - C:\WINDOWS\Helper101.dll O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: SDWin32 Class - {282A2F19-9E87-4112-9DCE-1FF2232DC605} - C:\WINDOWS\System32\solhl.dll O2 - BHO: SDWin32 Class - {4600BAD1-175C-4ED5-B3DD-379D9A315BF7} - C:\WINDOWS\System32\qgnib.dll O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - C:\WINDOWS\system32\fcpyvaxr.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - C:\WINDOWS\system32\xngzhckl.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file) O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe O4 - HKLM\..\Run: [zox] C:\WINDOWS\zox.exe O4 - HKLM\..\Run: [qgnibc] C:\WINDOWS\System32\qgnibc.exe O4 - HKLM\..\Run: [solhlc] C:\WINDOWS\System32\solhlc.exe O4 - HKLM\..\Run: [sle] C:\WINDOWS\system32\sle.exe O4 - HKLM\..\Run: [xapsdmh] C:\WINDOWS\xapsdmh.exe O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [sysmonnt] C:\WINDOWS\System32\sysmonnt O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe" O4 - Startup: PowerReg Scheduler V3.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409 O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{F2A9DC6C-D7C9-4521-B8B3-2E3C0F4BDB5F}: NameServer = 66.51.205.100 66.51.206.100 O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll O23 - Service: Kodak Camera Connection Software - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe O23 - Service: cobfavfewrwy - Unknown - C:\WINDOWS\system32\msupd6.exe (file missing) O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe O23 - Service: ScsiAccess - Unknown - C:\WINDOWS\System32\ScsiAccess.EXE
No Events found!


Midnight Star
4.8K Posts
0
February 13th, 2005 01:00
Can you post that log back, but this time include the line-feeds, so each entry appears on the same line.
Mike.
scenoch
13 Posts
0
February 13th, 2005 03:00
Thanks
sc
Logfile of HijackThis v1.99.0
Scan saved at 9:10:39 PM, on 2/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\system32\sle.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\sysmonnt.exe
C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\HPZipm12.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Juno\bin\juno.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\HiJack This\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000002230} - C:\Program Files\CSBB\CSBB.DLL
O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINDOWS\BTGrab.dll (file missing)
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll (file missing)
O2 - BHO: (no name) - {017C20C1-F86F-11D8-9B25-000ACD002AE3} - C:\WINDOWS\Helper101.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SDWin32 Class - {282A2F19-9E87-4112-9DCE-1FF2232DC605} - C:\WINDOWS\System32\solhl.dll
O2 - BHO: SDWin32 Class - {4600BAD1-175C-4ED5-B3DD-379D9A315BF7} - C:\WINDOWS\System32\qgnib.dll
O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - C:\WINDOWS\system32\fcpyvaxr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - C:\WINDOWS\system32\xngzhckl.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [zox] C:\WINDOWS\zox.exe
O4 - HKLM\..\Run: [qgnibc] C:\WINDOWS\System32\qgnibc.exe
O4 - HKLM\..\Run: [solhlc] C:\WINDOWS\System32\solhlc.exe
O4 - HKLM\..\Run: [sle] C:\WINDOWS\system32\sle.exe
O4 - HKLM\..\Run: [xapsdmh] C:\WINDOWS\xapsdmh.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [sysmonnt] C:\WINDOWS\System32\sysmonnt
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2A9DC6C-D7C9-4521-B8B3-2E3C0F4BDB5F}: NameServer = 66.51.205.100 66.51.206.100
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O23 - Service: Kodak Camera Connection Software - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: cobfavfewrwy - Unknown - C:\WINDOWS\system32\msupd6.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown - C:\WINDOWS\System32\ScsiAccess.EXE
Midnight Star
4.8K Posts
0
February 13th, 2005 14:00
sc,
I would guess those two are randomly named trojans; we can find more out if we submit those files to Kaspersky's for analysis, which we'll need to do for at lease one file.
-
Let's get started...
Go to www.kaspersky.com, then:
1. Click "Online virus scanner"
2. Click "Browse", then browse to, then doubleclick on the following file(s), one at a time:
3. Click "Submit"
4. Post back the results.
If you haven't ran HouseCall lately, let's go back to www.trendmicro.com, download the latest definitions, and run it.
Download, unzip to your desktop CWShredder and run it, then:
( If an update isn't available, skip to step #4.)
3. When the new version has been downloaded, click " Save".
Run HiJackThis then:
2. Click " Misc Tools"
3. Click " Open Process manager"
Now, let's open a command prompt and unregister the dll(s) we're going to remove, by entering the following:
regsvr32 /u Helper101.dll
regsvr32 /u solhl.dll
regsvr32 /u qgnib.dll
regsvr32 /u fcpyvaxr.dll
regsvr32 /u xngzhckl.dll
Run HiJackThis and click " Scan", then check(tick) the following, if present:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINDOWS\BTGrab.dll (file missing)
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll (file missing)
O2 - BHO: (no name) - {017C20C1-F86F-11D8-9B25-000ACD002AE3} - C:\WINDOWS\Helper101.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing)
O2 - BHO: SDWin32 Class - {282A2F19-9E87-4112-9DCE-1FF2232DC605} - C:\WINDOWS\System32\solhl.dll
O2 - BHO: SDWin32 Class - {4600BAD1-175C-4ED5-B3DD-379D9A315BF7} - C:\WINDOWS\System32\qgnib.dll
O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - C:\WINDOWS\system32\fcpyvaxr.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - C:\WINDOWS\system32\xngzhckl.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [qgnibc> C:\WINDOWS\System32\qgnibc.exe
O4 - HKLM\..\Run: [solhlc> C:\WINDOWS\System32\solhlc.exe
O4 - HKLM\..\Run: [xapsdmh> C:\WINDOWS\xapsdmh.exe
O4 - HKCU\..\Run: [sysmonnt> C:\WINDOWS\System32\sysmonnt
Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
C:\WINDOWS\Helper101.dll
C:\WINDOWS\System32\solhl.dll
C:\WINDOWS\System32\qgnib.dll
C:\WINDOWS\system32\fcpyvaxr.dll
C:\WINDOWS\system32\xngzhckl.dll
C:\WINDOWS\System32\qgnibc.exe
C:\WINDOWS\System32\solhlc.exe
C:\WINDOWS\xapsdmh.exe
Post back a new log, and let me know how everything goes.
scenoch
13 Posts
0
February 14th, 2005 23:00
Scanned file: sle.exe
sle.exeWarning: Trojan-Downloader.Win32.Lastad.d
sle.exeWarning:
zox eliminated by uping adaware’s settings
What is qgnibd.exe?
It was next to qgnibc.exe
Thanks for your time. Our machine is running much better already.
Logfile of HijackThis v1.99.0
Scan saved at 5:42:09 PM, on 2/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\SysCheckBop32.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\HPZipm12.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\HiJack This\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SysCheckBop32
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O23 - Service: Kodak Camera Connection Software - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown - C:\WINDOWS\System32\ScsiAccess.EXE
scenoch
13 Posts
0
February 15th, 2005 00:00
awile ago I saw qgnibd.exe pop up and close in the Task Manages processes tab. http://www.kaspersky.com said the following when I submitted the file:
Scanned file: qgnibd.exe
qgnibd.exe - infected by not-a-virus:AdWare.Adstart.bThat file doesnt appear in HijackThis. What do I do about that? :smileyindifferent:
scenoch
13 Posts
0
February 15th, 2005 02:00
I decided to go through suspicious files at http://www.kaspersky.com
Scanned file: BO2804040113.exe
BO2804040113.exe - infected by not-a-virus:AdWare.VirtualBouncer.d
Scanned file: CP18.exe
CP18.exe - infected by Trojan-Downloader.Win32.Small.ahx
Scanned file: randreco.exe
randreco.exe - infected by not-a-virus:AdWare.BetterInternet
Scanned file: wsxsvc.exe
wsxsvc.exe - infected by not-a-virus:AdWare.DelphinMediaViewer.c
Scanned file: systb.exe
systb.exe/systb.dll - infected by not-a-virus:AdWare.ToolBar.ImiBar.d
Scanned file: 1stpublisher.exe
1stpublisher.exe/data0001 - OK
1stpublisher.exe/data0002 - infected by not-a-virus:AdWare.ToolBar.HotSearchBar.b
58kd52fg.exe - does not even scan. Loads a blank page
activeshopper.exe - does not even scan. Loads a blank page
adl_dh.exe - does not even scan. Loads a blank page
adl_hl.exe - does not even scan. Loads a blank page
Scanned file: adl_mteststub.exe
adl_mteststub.exe - infected by not-a-virus:AdWare.EZula.ah
adl_zeno.exe
AdSmartMedia_bundle.exe
adv0ltc0m.exe
ast_5_adsav.exe
b2s-162813.exe
Beryllium1.exe
Beryllium.exe
bs5-goodyr1.exe
CSv12P108.exe
cxt_big.exe
cxt_wmg.exe
cxtpls_loader.exe
d_ic.exe
Decade.exe
dh_vl.exe
e2g51.exe
EDow_vl.exe
ei51.exe
Scanned file: ezStub_ropwo.exe
ezStub_ropwo.exe - infected by not-a-virus:AdWare.EZula.ah
gogotoolsSILAWO8pi.exe
Scanned file: HelperInstaller.exe
HelperInstaller.exe - infected by Trojan-Dropper.Win32.Delf.z
HLInstaller.exe
icmedia2_56.exe
ICMMedia_1cmm3d1a.exe
iehost.exe
installcasino.exe
KnNe1.exe
Scanned file: mfs.exe
mfs.exe/INSTALL.EXE - OK
mfs.exe/README.TXT - OK
mfs.exe/MAGIC.EXE - OK
mfs.exe/MFX - OK
mfs.exe/TB.EXE - OK
mfs.exe/MF.CHM/#IDXHDR - OK
mfs.exe/MF.CHM/#STRINGS - OK
mfs.exe/MF.CHM/#SYSTEM - OK
mfs.exe/MF.CHM/#TOPICS - OK
mfs.exe/MF.CHM/#URLSTR - OK
mfs.exe/MF.CHM/#URLTBL - OK
mfs.exe/MF.CHM/Auto_hiding_of_visible_folders.htm - OK
mfs.exe/MF.CHM/Automatic_Encryption.htm - OK
mfs.exe/MF.CHM/Backups.htm - OK
mfs.exe/MF.CHM/Batch_file_operation.htm - OK
mfs.exe/MF.CHM/Can_t_rename_parent_of_hidden_folder.htm - OK
mfs.exe/MF.CHM/Choosing_a_hot_key.htm - OK
mfs.exe/MF.CHM/Cleaning_of_My_Documents.htm - OK
mfs.exe/MF.CHM/Creating_your_list_of_Magic_Folders.htm - OK
mfs.exe/MF.CHM/Desktop_icon_problems.htm - OK
mfs.exe/MF.CHM/Don_t_hide_critical_system_files.htm - OK
mfs.exe/MF.CHM/dwnex.gif - OK
mfs.exe/MF.CHM/FirstTopic.htm - OK
mfs.exe/MF.CHM/Hidden_files_and_the_Recycle_Bin.htm - OK
mfs.exe/MF.CHM/How_do_I_uninstall.htm - OK
mfs.exe/MF.CHM/How_Much_.htm - OK
mfs.exe/MF.CHM/htmlhelp.css - OK
mfs.exe/MF.CHM/I_forgot_my_password.htm - OK
mfs.exe/MF.CHM/I_m_getting_a_blue_screen_when_I_use_CDs.htm - OK
mfs.exe/MF.CHM/Icon_and_Driver_naming.htm - OK
mfs.exe/MF.CHM/Images/mf2.ICO - OK
mfs.exe/MF.CHM/Inputting_the_Master_Account_password.htm - OK
mfs.exe/MF.CHM/Invisible_folders_are_still_visible.htm - OK
mfs.exeMF.CHM/Making_your_Magic_Folders_Visible_or_Invisible.htm - OK
mfs.exe/MF.CHM/master.js - OK
mfs.exe/MF.CHM/mf.hhc - OK
mfs.exe/MF.CHM/mf.hhk - OK
mfs.exe/MF.CHM/mf_decrypt.htm - OK
mfs.exe/MF.CHM/Moving_or_Copying_your_hidden_files.htm - OK
mfs.exe/MF.CHM/Multiple_Accounts.htm - OK
mfs.exe/MF.CHM/Multiple_Accounts2.htm - OK
mfs.exe/MF.CHM/Multiple_Boot_Systems.htm - OK
mfs.exe/MF.CHM/Mutliple_Account_Operation.htm - OK
mfs.exe/MF.CHM/Network_installation.htm - OK
mfs.exe/MF.CHM/Network_Overview.htm - OK
mfs.exe/MF.CHM/No_network_drives_listed.htm - OK
mfs.exe/MF.CHM/Operation.htm - OK
mfs.exe/MF.CHM/Overview.htm - OK
mfs.exe/MF.CHM/Removable_Drives.htm - OK
mfs.exe/MF.CHM/rtex.gif - OK
mfs.exe/MF.CHM/Run_Install_exe.htm - OK
mfs.exe/MF.CHM/Scrambling_of_Filenames.htm - OK
mfs.exe/MF.CHM/stranded_files.htm - OK
mfs.exe/MF.CHM/System_folders.htm - OK
mfs.exe/MF.CHM/Technical_Support.htm - OK
mfs.exe/MF.CHM/Thank_you_.htm - OK
mfs.exe/MF.CHM/Updates.htm - OK
mfs.exe/MF.CHM - OK
mfs.exe/CPY.EXE - OK
mfs.exe/EDECRYPT.EXE - OK
mfs.exe/FLDRVW51.OCX - OK
mfs.exe/FLDRVW51.OCX - OK
mfs.exe/ALI.EXE - OK
mfs.exe/MF.TXX - OK
mfs.exe/SYSTRAY.EXE - OK
mfs.exe/CDLOCK.DLL - OK
mfs.exe/INSTALL.EXE - OK
mfs.exe/README.TXT - OK
mfs.exe/MAGIC.EXE - OK
mfs.exe/MFX - OK
mfs.exe/TB.EXE - OK
mfs.exe/MF.CHM - OK
mfs.exe/CPY.EXE - OK
mfs.exe/EDECRYPT.EXE - OK
mfs.exe/FLDRVW51.OCX - OK
mfs.exe/FLDRVW51.OCX - OK
mfs.exe/ALI.EXE - OK
mfs.exe/MF.TXX - OK
mfs.exe/SYSTRAY.EXE - OK
mfs.exe/CDLOCK.DLL - OK
mfs.exe - OK
mfsetup.exe
Scanned file: mstub-pal_nmw_a352_r15800.exe
mstub-pal_nmw_a352_r15800.exe - OK
new_vcm.exe
newmb.exe
NzI0MDo4OjEy.exe
Scanned file: OTY2MTo4OjEy.exe
OTY2MTo4OjEy.exe - infected by not-a-virus:AdWare.ToolBar.ISearch.d
package8033_MARKETING5.exe
Scanned file: pounder.exe
pounder.exe/Script - OK
pounder.exe/data0001/EXE-file - OK
pounder.exe/data0001 - OK
pounder.exe - OK
rop_marketing_1_168.exe
ropbundle.exe
runsearch.exe
sahagent-dectest1001.exe
sahagent-onlinetrafficbroker1001.exe
sahagent-seedcorn1002.exe
Scanned file: saie1101.exe
saie1101.exe - infected by Trojan-Dropper.Win32.Small.mr
search_toolbar.exe
seedcorn.exe
Setup1171.exe
setup_Incredifind_TrafficSpec.exe
setupactiv2.exe
SetupCasino.exe
Scanned file: shopinst.exe
shopinst.exe - infected by Trojan-Downloader.Win32.Small.wj
ssee.exe
The size of a file exceeds 1024 Kb
Scanned file: SSK_B5.EXE
SSK_B5.EXE - infected by Trojan-Dropper.Win32.SurfSide.a
stlb2_seed.exe
Scanned file: thin-8-1-x-x.exe
thin-8-1-x-x.exe - infected by not-a-virus:AdWare.BetterInternet
Scanned file: tinko_vcm.exe
tinko_vcm.exe/data0001 - OK
tinko_vcm.exe/data0002 - OK
tinko_vcm.exe/data0003 - OK
tinko_vcm.exe/data0004 - OK
tinko_vcm.exe/data0005 - OK
tinko_vcm.exe/data0006 - OK
tinko_vcm.exe/data0007 - OK
tinko_vcm.exe/data0008 - OK
tinko_vcm.exe/data0009 - OK
tinko_vcm.exe/data0010 - OK
tinko_vcm.exe/data0011 - OK
tinko_vcm.exe/data0012 - OK
tinko_vcm.exe/data0013 - OK
tinko_vcm.exe/data0014 - OK
tinko_vcm.exe/data0015 - OK
tinko_vcm.exe/data0016 - OK
tinko_vcm.exe/data0017/#IDXHDR Corrupted
tinko_vcm.exe/data0017/#STRINGS Corrupted
tinko_vcm.exe/data0017/#SYSTEM - OK
tinko_vcm.exe/data0017/#TOPICS Corrupted
tinko_vcm.exe/data0017/#URLSTR Corrupted
tinko_vcm.exe/data0017/#URLTBL Corrupted
tinko_vcm.exe/data0017/$OBJINST Corrupted
tinko_vcm.exe/data0017/$WWAssociativeLinks/Property Corrupted
tinko_vcm.exe/data0017/$WWKeywordLinks/BTree Corrupted
tinko_vcm.exe/data0017/$WWKeywordLinks/Data Corrupted
tinko_vcm.exe/data0017/$WWKeywordLinks/Map Corrupted
tinko_vcm.exe/data0017/$WWKeywordLinks/Property Corrupted
tinko_vcm.exe/data0017/Email.htm - OK
tinko_vcm.exe/data0017/Email.jpg - OK
tinko_vcm.exe/data0017/Favorite.htm - OK
tinko_vcm.exe/data0017/Favorites.jpg - OK
tinko_vcm.exe/data0017/Features.htm - OK
tinko_vcm.exe/data0017/Index.hhk - OK
tinko_vcm.exe/data0017/Search.htm - OK
tinko_vcm.exe/data0017/Search.jpg Corrupted
tinko_vcm.exe/data0017/Table of Contents.hhc - OK
tinko_vcm.exe/data0017/TinkoPal.jpg - OK
tinko_vcm.exe/data0017/Uninstall.htm - OK
tinko_vcm.exe/data0017/Uninstall.jpg Corrupted
tinko_vcm.exe/data0017/Weather.htm - OK
tinko_vcm.exe/data0017/Weather.jpg - OK
tinko_vcm.exe/data0017/Website.htm - OK
tinko_vcm.exe/data0017/Welcome.htm - OK
tinko_vcm.exe/data0017 - OK
tinko_vcm.exe/data0018 - OK
tinko_vcm.exe/data0019 - OK
tinko_vcm.exe/data0020Warning: Trojan-Downloader.Win32.Lastad.d
tinko_vcm.exe/data0021 - OK
tinko_vcm.exe/data0022 - OK
tinko_vcm.exe/data0023 - OK
tinko_vcm.exe/data0024 - OK
tinko_vcm.exe/data0025 - OK
tinko_vcm.exe/data0026 - OK
tinko_vcm.exe/data0027 - OK
tinko_vcm.exe/data0028 - OK
tinko_vcm.exe/data0029 - OK
tinko_vcm.exe/data0030 - OK
tinko_vcm.exe/data0031 - OK
tinko_vcm.exe/data0032 - OK
tinko_vcm.exe/data0033 - OK
tinko_vcm.exe/data0034 - OK
tinko_vcm.exe/data0035 - OK
tinko_vcm.exe/data0036 - OK
tinko_vcm.exe/data0036Warning: Trojan-Downloader.Win32.Lastad.d
ucmoreiex.exe
ventura1.exe
Scanned file: videoinst.exe
videoinst.exe - infected by Trojan-Downloader.Win32.Small.wj
vrinstall_icmedia.exe
Scanned file: WebRebates_Auto_InstallSilent.exe
WebRebates_Auto_InstallSilent.exe/data0001 - OK
WebRebates_Auto_InstallSilent.exe/data0002 - OK
WebRebates_Auto_InstallSilent.exedata0003/data0001 - infected by not-a-virus:AdWare.WebRebates.g
WebRebates_Auto_InstallSilent.exe/data0003 - infected by not-a-virus:AdWare.WebRebates.d
WebRebates_Auto_InstallSilent.exe/data0004 - infected by not-a-virus:AdWare.WebRebates.d
WebRebates_Auto_InstallSilent.exe/data0005 - infected by not-a-virus:AdWare.WebRebates.c
WebRebates_Auto_InstallSilent.exe/data0006 - OK
WebRebates_Auto_InstallSilent.exe/data0007 - OK
WebRebates_Auto_InstallSilent.exe/data0008 - OK
WebRebates_Auto_InstallSilent.exe/data0009 - OK
WebRebates_Auto_InstallSilent.exe/data0010 - OK
WebRebates_Auto_InstallSilent.exe/data0011 - OK
WebRebates_Auto_InstallSilent.exe/data0012 - OK
WebRebates_Auto_InstallSilent.exe/data0013 - OK
WebRebates_Auto_InstallSilent.exe/data0014 - OK
WebRebates_Auto_InstallSilent.exe/data0015 - OK
WebRebates_Auto_InstallSilent.exe/data0016 - OK
WebRebates_Auto_InstallSilent.exe/data0017 - OK
WebRebates_Auto_InstallSilent.exe/data0018 - OK
WebRebates_Auto_InstallSilent.exe/data0019 - OK
WebRebates_Auto_InstallSilent.exe/data0020 - OK
WebRebates_Auto_InstallSilent.exe/data0021 - OK
WebRebates_Auto_InstallSilent.exe/data0022 - OK
WebRebates_Auto_InstallSilent.exe/data0023 - OK
WebRebates_Auto_InstallSilent.exe/data0024 - OK
WebRebates_Auto_InstallSilent.exe/data0025 - OK
WebRebates_Auto_InstallSilent.exe/data0026 - OK
WebRebates_Auto_InstallSilent.exe/data0027 - OK
WebRebates_Auto_InstallSilent.exe/data0028 - OK
WebRebates_Auto_InstallSilent.exe/data0029 - OK
WebRebates_Auto_InstallSilent.exe/data0030 - OK
WebRebates_Auto_InstallSilent.exe/data0031 - OK
winversion.exe
Scanned file: wrapperouter.exe
wrapperouter.exe/WISE0000.BIN - OK
wrapperouter.exe/WISE0001.BIN - OK
wrapperouter.exe/WISE0002.BIN - OK
wrapperouter.exe/WISE0003.BIN - OK
wrapperouter.exe/WISE0004.BIN - OK
wrapperouter.exe/WISE0005.BIN - OK
wrapperouter.exe/WISE0006.BIN - infected by not-a-virus:AdWare.VirtualBouncer.c
wrapperouter.exe/WISE0007.BIN/WISE0000.BIN - OK
wrapperouter.exeWISE0007.BIN/WISE0001.BIN - infected by not-a-virus:AdWare.VirtualBouncer.j
wrapperouter.exe/WISE0007.BIN/WISE0002.BIN - OK
wrapperouter.exe/WISE0007.BIN/WISE0003.BIN - OK
wrapperouter.exe/WISE0007.BIN/WISE0004.BIN - OK
wrapperouter.exe/WISE0007.BIN/WISE0005.BIN - OK
This following file has no info except size and date created - 1-31-05
Scanned file: cp.exe
cp.exe/EXE-file/Script - OK
cp.exe/EXE-file/data0001/EXE-file - OK
cp.exe/EXE-file/data0001/EXE-file - OK
cp.exe/EXE-file/data0001 - OK
cp.exe/EXE-file - OK
cp.exe - OK
servedby.advertising.com advertising.com and atdmt.com wanted to "store a file called a cookie" on my computer just randomly FOUR times. I hadn't clicked on anything in a while all four times times.
Midnight Star
4.8K Posts
0
February 15th, 2005 12:00
Run HiJackThis then:
2. Click " Misc Tools"
3. Click " Open Process manager"
Run HiJackThis and click " Scan", then check(tick) the following, if present:
O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - (no file)
O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - (no file)
Now, with all windows closed except HiJackThis, click " Fix checked".
Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
Download mwav.exe from MicroWorld, then:
2. Click " Scan".
3. When it completes, post back the results from the 'Virus log information' pane.
scenoch
13 Posts
0
February 20th, 2005 02:00
O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - (no file)
File C:\WINDOWS\systb.exe infected by "not-a-virus:AdWare.ToolBar.ImiBar.d" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\BO2802040113.dll infected by "not-a-virus:AdWare.VirtualBouncer.d" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\BO2804040113.exe infected by "not-a-virus:AdWare.VirtualBouncer.d" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\CP18.exe infected by "Trojan-Downloader.Win32.Small.ahx" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\msbb321.dll infected by "not-a-virus:AdWare.180Solutions" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\qgnibd.exe infected by "not-a-virus:AdWare.Adstart.b" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\qgnibf.exe infected by "not-a-virus:AdWare.Adstart.d" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\randreco.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\setup_incred_8.exe infected by "Trojan-Downloader.Win32.Keenval.e" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\solhld.exe infected by "not-a-virus:AdWare.Adstart.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\solhlf.exe infected by "not-a-virus:AdWare.Adstart.d" Virus. Action Taken: No Action Taken.
Thank you for your time!
Midnight Star
4.8K Posts
0
February 22nd, 2005 20:00
scenoch,
Ok, let's see what we have left; post back a new HiJackThis log after removing these files...
Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
files...
C:\WINDOWS\systb.exe
C:\WINDOWS\system32\BO2802040113.dll
C:\WINDOWS\system32\BO2804040113.exe
C:\WINDOWS\system32\CP18.exe
C:\WINDOWS\system32\msbb321.dll
C:\WINDOWS\system32\qgnibd.exe
C:\WINDOWS\system32\qgnibf.exe
C:\WINDOWS\system32\randreco.exe
C:\WINDOWS\system32\setup_incred_8.exe
C:\WINDOWS\system32\solhld.exe
C:\WINDOWS\system32\solhlf.exe
-
Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them from "Safe Mode".
Mike.
scenoch
13 Posts
0
February 23rd, 2005 02:00
how do I get rid of
wsxsvc.exe - infected by not-a-virus:AdWare.DelphinMediaViewer.c
or DMVlite?
Is the uninstall program worth downloading?
I could not get rid of
O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - (no file)
O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - (no file)
even in safe mode.
Midnight Star
4.8K Posts
0
February 24th, 2005 19:00
scenoch,
Try going to Add/Remove programs and uninstall(remove), the following:
Delfin Media Viewer
Let me see a fresh log to see what we have left to fix.
-
Mike.
Midnight Star
4.8K Posts
0
February 24th, 2005 19:00
Message Edited by Midnight Star on 02-24-2005 03:36 PM
scenoch
13 Posts
0
February 26th, 2005 00:00
Scan saved at 6:37:58 PM, on 2/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\sys11-1673214046.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\HPZipm12.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Messenger\msmsgs.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HiJack This\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sp/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com"); (C:\Documents and Settings\Enoch Family\Application Data\Mozilla\Profiles\default\tz2zi4r4.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Enoch Family\Application Data\Mozilla\Profiles\default\tz2zi4r4.slt\prefs.js)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [sys11-1673214046] C:\WINDOWS\sys11-1673214046.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O23 - Service: Kodak Camera Connection Software - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown - C:\WINDOWS\System32\ScsiAccess.EXE
scenoch
13 Posts
0
February 26th, 2005 00:00
Midnight Star
4.8K Posts
0
February 26th, 2005 02:00
On that i'm not 100% sure, but i'd venture to guess yes. If I wanted to uninstall it from my system, i'd try their uninstaller first, before doing anything else, just to make sure it removed (or at least should), everything that it installed on my system. Can you post back the link and take a quick look?
-
Let's take the next pass...
Download, then unzip to " C:\HJT", the newest version of HiJackThis; version 1.99.1. Then repost your log, either now, or after following the steps in the solution ( if provided in this post). This version has features that might be more helpful in 'cleaning' up your system.
Run HiJackThis then:
1. Click " Config..."
2. Click " Misc Tools"
3. Click " Open Process manager"
-
Next, while holding down the CTRL key, locate ( if present) and click on ( highlight) each of the following:
C:\WINDOWS\sys11-1673214046.exe
Now double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.
Run HiJackThis and click " Scan", then check(tick) the following, if present:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sp/*http://www.yahoo.com
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Enoch Family\Application Data\Mozilla\Profiles\default\tz2zi4r4.slt\prefs.js)
O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - (no file)
O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - (no file)
O4 - HKLM\..\Run: [sys11-1673214046] C:\WINDOWS\sys11-1673214046.exe
Now, with all windows closed except HiJackThis, click " Fix checked".
When your done, rescan your system and make sure the following isn't present:
N3 - Netscape ... 5CSBWeb_01.src
If it is, then fix that entry again; sometimes it'll take more than one pass. The actual entry is ok, and won't be deleted, it's the java wrapper marked in red that needs to be removed.
Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
files...
C:\WINDOWS\sys11-1673214046.exe
-
Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".
Post back a new log, and let me know how everything goes.
-
Mike