Start a Conversation

Unsolved

This post is more than 5 years old

Z

364

April 27th, 2006 20:00

Hi jacked...blue screening...please help !

​ Logfile of HijackThis v1.99.1 ​
​Scan saved at 22:06:55, on 4/27/2006 ​
​Platform: Windows XP SP2 (WinNT 5.01.2600) ​
​MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) ​
​ Running processes: ​
​C:\WINDOWS\System32\smss.exe ​
​C:\WINDOWS\system32\winlogon.exe ​
​C:\WINDOWS\system32\services.exe ​
​C:\WINDOWS\system32\lsass.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\WINDOWS\system32\spoolsv.exe ​
​C:\WINDOWS\Explorer.EXE ​
​C:\Program Files\Common Files\AOL\ACS\AOLDial.exe ​
​C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe ​
​C:\Program Files\Microsoft AntiSpyware\gcasServ.exe ​
​C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe ​
​C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe ​
​C:\WINDOWS\system32\ctfmon.exe ​
​C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe ​
​C:\Program Files\GhostSurf 2005\Proxy.exe ​
​C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe ​
​C:\Program Files\AOL\Broadband CheckUp\bin\mpbtn.exe ​
​C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe ​
​C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe ​
​C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe ​
​C:\WINDOWS\system32\CTsvcCDA.EXE ​
​C:\WINDOWS\system32\drivers\KodakCCS.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe ​
​C:\Program Files\AOL 9.0\waol.exe ​
​C:\Program Files\AOL 9.0\shellmon.exe ​
​C:\Program Files\Common Files\AOL\aoltpspd.exe ​
​C:\HJ\HijackThis.exe ​
​ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = ​​http://www.dell.co.uk/myway​​ ​
​R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = ​​http://www.dell.co.uk/myway​​ ​
​R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = ​​http://uk.mcafee.com/root/campaign.asp?cid=11425&affid=105-23&dtag=fbth81j​​ ​
​R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:7212 ​
​F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\userinit32.exe, ​
​O1 - Hosts: 222.89.98.219 ​​www.wo365.com​​ ​
​O1 - Hosts: 222.89.98.219 cmfu.com ​
​O1 - Hosts: 222.89.98.219 ​​www.cmfu.com​​ ​
​O1 - Hosts: 222.89.98.219 9i0.com ​
​O1 - Hosts: 222.89.98.219 ​​www.9flash.com​​ ​
​O1 - Hosts: 222.89.98.219 9flash.com ​
​O1 - Hosts: 222.89.98.219 ​​www.nowok.net​​ ​
​O1 - Hosts: 222.89.98.219 nowok.net ​
​O1 - Hosts: 222.89.98.219 wisa.com.cn ​
​O1 - Hosts: 222.89.98.219 ​​www.sia.com.cn​​ ​
​O1 - Hosts: 222.89.98.219 ​​www.wisa.cn​​ ​
​O1 - Hosts: 222.89.98.219 wisa.cn ​
​O1 - Hosts: 222.89.98.219 ​​www.zhao99.com​​ ​
​O1 - Hosts: 222.89.98.219 zhao99.com ​
​O1 - Hosts: 222.89.98.219 ​​www.wo123.com​​ ​
​O1 - Hosts: 222.89.98.219 wo123.com ​
​O1 - Hosts: 222.89.98.219 wo99.com ​
​O1 - Hosts: 222.89.98.219 ​​www.wo99.com​​ ​
​O1 - Hosts: 222.89.98.219 ​​www.page.com.cn​​ ​
​O1 - Hosts: 222.89.98.219 page.com.cn ​
​O1 - Hosts: 222.89.98.219 ​​www.432.cn​​ ​
​O1 - Hosts: 222.89.98.219 432.cn ​
​O1 - Hosts: 222.89.98.219 wysw.com ​
​O1 - Hosts: 222.89.98.219 14.com.cn
​O1 - Hosts: 222.89.98.219 ​​www.14.com.cn​ ​
​O1 - Hosts: 222.89.98.219 cnww.net ​
​O1 - Hosts: 222.89.98.219 ​​www.mv99.com​​ ​
​O1 - Hosts: 222.89.98.219 mv99.com ​
​O1 - Hosts: 222.89.98.219 ​​www.youav.com​​ ​
​O1 - Hosts: 222.89.98.219 ​​www.mtvav.com​​ ​
​O1 - Hosts: 222.89.98.219 ​​www.98983.com​​ ​
​O1 - Hosts: 222.89.98.219 98983.com ​
​O1 - Hosts: 222.89.98.219 ​​www.114.com.cn​ ​
​O1 - Hosts: 222.89.98.219 114.com.cn
​O1 - Hosts: 222.89.98.219 ​​www.net114.com​​ ​
​O1 - Hosts: 222.89.98.219 ​​www.skywz.com​​ ​
​O1 - Hosts: 222.89.98.219 skywz.com ​
​O1 - Hosts: 222.89.98.219 ​​www.hao6.com​​ ​
​O1 - Hosts: 222.89.98.219 hao6.com ​
​O1 - Hosts: 222.89.98.219 ​​www.678a.com​​ ​
​O1 - Hosts: 222.89.98.219 678a.com ​
​O1 - Hosts: 222.89.98.219 ​​www.7510.com​​ ​
​O1 - Hosts: 222.89.98.219 7510.com ​
​O1 - Hosts: 222.89.98.219 ​​www.zzkan.com​​ ​
​O1 - Hosts: 222.89.98.219 zzkan.com ​
​O1 - Hosts: 222.89.98.219 ​​www.ca183.com​​ ​
​O1 - Hosts: 222.89.98.219 ca183.com ​
​O1 - Hosts: 222.89.98.219 3tom.com ​
​O1 - Hosts: 222.89.98.219 ​​www.yhjm.com​​ ​
​O1 - Hosts: 222.89.98.219 yhjm.com ​
​O1 - Hosts: 222.89.98.219 ​​www.k369.com​​ ​
​O1 - Hosts: 222.89.98.219 ​​www.xxwww.com​​ ​
​O1 - Hosts: 222.89.98.219 xxwww.com ​
​O1 - Hosts: 222.89.98.219 ​​www.fm1000.net​​ ​
​O1 - Hosts: 222.89.98.219 fm1000.net ​
​O1 - Hosts: 222.89.98.219 ​​www.ok135.com​​ ​
​O1 - Hosts: 222.89.98.219 ok135.com ​
​O1 - Hosts: 222.89.98.219 ​​www.link999.com​​ ​
​O1 - Hosts: 222.89.98.219 link999.com ​
​O1 - Hosts: 222.89.98.219 ​​www.001wz.com​​ ​
​O1 - Hosts: 222.89.98.219 001wz.com ​
​O1 - Hosts: 222.89.98.219 ​​www.7t7t.com​​ ​
​O1 - Hosts: 222.89.98.219 7t7t.com ​
​O1 - Hosts: 222.89.98.219 ​​www.7k7k.com​​ ​
​O1 - Hosts: 222.89.98.219 7k7k.com ​
​O1 - Hosts: 222.89.98.219 ​​www.webcool.net​​ ​
​O1 - Hosts: 222.89.98.219 webcool.net ​
​O1 - Hosts: 222.89.98.219 ​​www.51sobu.com​​ ​
​O1 - Hosts: 222.89.98.219 51sobu.com ​
​O1 - Hosts: 222.89.98.219 cy.51sobu.com ​
​O1 - Hosts: 222.89.98.219 ​​www.fj3721.com​​ ​
​O1 - Hosts: 222.89.98.219 fj3721.com ​
​O1 - Hosts: 222.89.98.219 ​​www.msncn.com​​ ​
​O1 - Hosts: 222.89.98.219 msncn.com ​
​O1 - Hosts: 222.89.98.219 ​​www.6235.com​​ ​
​O1 - Hosts: 222.89.98.219 6235.com ​
​O1 - Hosts: 222.89.98.219 ​​www.8goo.com​​ ​
​O1 - Hosts: 222.89.98.219 8goo.com ​
​O1 - Hosts: 222.89.98.219 ​​www.baimin.com​​ ​
​O1 - Hosts: 222.89.98.219 baimin.com ​
​O1 - Hosts: 222.89.98.219 ​​www.bwwz.com​​ ​
​O1 - Hosts: 222.89.98.219 bwwz.com ​
​O1 - Hosts: 222.89.98.219 ​​www.howow.net​​ ​
​O1 - Hosts: 222.89.98.219 howow.net ​
​O1 - Hosts: 222.89.98.219 ​​www.tongchi.com​​ ​
​O1 - Hosts: 222.89.98.219 tongchi.com ​
​O1 - Hosts: 222.89.98.219 ​​www.65658.com​​ ​
​O1 - Hosts: 222.89.98.219 65658.com ​
​O1 - Hosts: 222.89.98.219 ​​www.7o7o.com​​ ​
​O1 - Hosts: 222.89.98.219 7o7o.com ​
​O1 - Hosts: 222.89.98.219 5126.net ​
​O1 - Hosts: 222.89.98.219 ​​www.5126.net​​ ​
​O1 - Hosts: 222.89.98.219 ​​www.wangzhiku.com​​ ​
​O1 - Hosts: 222.89.98.219 wangzhiku.com ​
​O1 - Hosts: 222.89.98.219 ​​www.soyeah.com​​ ​
​O1 - Hosts: 222.89.98.219 soyeah.com ​
​O1 - Hosts: 222.89.98.219 ​​www.sowang.cn​​ ​
​O1 - Hosts: 222.89.98.219 sowang.cn ​
​O1 - Hosts: 222.89.98.219 ​​www.77177.com​​ ​
​O1 - Hosts: 222.89.98.219 77177.com ​
​O1 - Hosts: 222.89.98.219 ​​www.look8.net​​ ​
​O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ​
​O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll ​
​O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file) ​
​O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll ​
​O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe ​
​O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" ​
​O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" ​
​O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP ​
​O4 - HKLM\..\Run: [GhostSurfDelSatellite] "C:\Program Files\GhostSurf 2005\DeleteSatellite.exe" ​
​O4 - HKLM\..\Run: [GhostSurf Reminder] "C:\Program Files\GhostSurf 2005\Privacy Control Center.exe" reminder ​
​O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" ​
​O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe ​
​O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime ​
​O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe ​
​O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k ​
​O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe ​
​O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R ​
​O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe ​
​O4 - Global Startup: AOL Broadband Check-Up.lnk = C:\Program Files\AOL\Broadband CheckUp\bin\matcli.exe ​
​O4 - Global Startup: GhostSurf proxy.lnk = C:\Program Files\GhostSurf 2005\Proxy.exe ​
​O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe ​
​O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 ​
​O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll ​
​O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll ​
​O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll ​
​O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ​
​O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ​
​O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll ​
​O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - ​​http://creative.com/su/ocx/15015/CTSUEng.cab​​ ​
​O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - ​​http://go.microsoft.com/fwlink/?linkid=48835​​ ​
​O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - ​​http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab​​ ​
​O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - ​​http://bin.mcafee.com/molbin/shared/mcinsctl/en-gb/4,0,0,84/mcinsctl.cab​​ ​
​O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - ​​http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1132687114921​​ ​
​O16 - DPF: {A243F6C2-34D2-4549-BCCD-A7BEF759B236} (Seekford Solutions, Inc.'s ssiPictureUploader Control) - ​​http://img.funtigo.com/images/uploader/ssiPictureUploader.cab​​ ​
​O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - ​​http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab​​ ​
​O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - ​​http://bin.mcafee.com/molbin/shared/mcgdmgr/en-gb/1,0,0,21/mcgdmgr.cab​​ ​
​O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - ​​http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4426/mcfscan.cab​​ ​
​O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - ​​http://creative.com/su/ocx/15016/CTPID.cab​​ ​
​O17 - HKLM\System\CCS\Services\Tcpip\..\{FDDCF629-9CA1-46A4-98D4-F451AF422CBF}: NameServer = 205.188.146.145 ​
​O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) ​
​O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll ​
​O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll ​
​O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe ​
​O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe ​
​O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe ​
​O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE ​
​O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe ​
​ ​

5.9K Posts

April 27th, 2006 22:00

This looks like what you have
 
 
I think you'd better follow their removal instructions.  But if they don't work then
 
This is what I see that needs to go but usually when it's that F2 line checking them (even in Safe Mode) doesn't work and we have to use something like Avenger to delete the line before the operating system starts.
 
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe, C:\WINDOWS\system32\userinit32.exe,
O1 - Hosts: 222.89.98.219 www.wo365.com
O1 - Hosts: 222.89.98.219 cmfu.com
O1 - Hosts: 222.89.98.219 www.cmfu.com
O1 - Hosts: 222.89.98.219 9i0.com
O1 - Hosts: 222.89.98.219 www.9flash.com
O1 - Hosts: 222.89.98.219 9flash.com
O1 - Hosts: 222.89.98.219 www.nowok.net
O1 - Hosts: 222.89.98.219 nowok.net
O1 - Hosts: 222.89.98.219 wisa.com.cn
O1 - Hosts: 222.89.98.219 www.sia.com.cn
O1 - Hosts: 222.89.98.219 www.wisa.cn
O1 - Hosts: 222.89.98.219 wisa.cn
O1 - Hosts: 222.89.98.219 www.zhao99.com
O1 - Hosts: 222.89.98.219 zhao99.com
O1 - Hosts: 222.89.98.219 www.wo123.com
O1 - Hosts: 222.89.98.219 wo123.com
O1 - Hosts: 222.89.98.219 wo99.com
O1 - Hosts: 222.89.98.219 www.wo99.com
O1 - Hosts: 222.89.98.219 www.page.com.cn
O1 - Hosts: 222.89.98.219 page.com.cn
O1 - Hosts: 222.89.98.219 www.432.cn
O1 - Hosts: 222.89.98.219 432.cn
O1 - Hosts: 222.89.98.219 wysw.com
O1 - Hosts: 222.89.98.219 14.com.cn
O1 - Hosts: 222.89.98.219 www.14.com.cn
O1 - Hosts: 222.89.98.219 cnww.net
O1 - Hosts: 222.89.98.219 www.mv99.com
O1 - Hosts: 222.89.98.219 mv99.com
O1 - Hosts: 222.89.98.219 www.youav.com
O1 - Hosts: 222.89.98.219 www.mtvav.com
O1 - Hosts: 222.89.98.219 www.98983.com
O1 - Hosts: 222.89.98.219 98983.com
O1 - Hosts: 222.89.98.219 www.114.com.cn
O1 - Hosts: 222.89.98.219 114.com.cn
O1 - Hosts: 222.89.98.219 www.net114.com
O1 - Hosts: 222.89.98.219 www.skywz.com
O1 - Hosts: 222.89.98.219 skywz.com
O1 - Hosts: 222.89.98.219 www.hao6.com
O1 - Hosts: 222.89.98.219 hao6.com
O1 - Hosts: 222.89.98.219 www.678a.com
O1 - Hosts: 222.89.98.219 678a.com
O1 - Hosts: 222.89.98.219 www.7510.com
O1 - Hosts: 222.89.98.219 7510.com
O1 - Hosts: 222.89.98.219 www.zzkan.com
O1 - Hosts: 222.89.98.219 zzkan.com
O1 - Hosts: 222.89.98.219 www.ca183.com
O1 - Hosts: 222.89.98.219 ca183.com
O1 - Hosts: 222.89.98.219 3tom.com
O1 - Hosts: 222.89.98.219 www.yhjm.com
O1 - Hosts: 222.89.98.219 yhjm.com
O1 - Hosts: 222.89.98.219 www.k369.com
O1 - Hosts: 222.89.98.219 www.xxwww.com
O1 - Hosts: 222.89.98.219 xxwww.com
O1 - Hosts: 222.89.98.219 www.fm1000.net
O1 - Hosts: 222.89.98.219 fm1000.net
O1 - Hosts: 222.89.98.219 www.ok135.com
O1 - Hosts: 222.89.98.219 ok135.com
O1 - Hosts: 222.89.98.219 www.link999.com
O1 - Hosts: 222.89.98.219 link999.com
O1 - Hosts: 222.89.98.219 www.001wz.com
O1 - Hosts: 222.89.98.219 001wz.com
O1 - Hosts: 222.89.98.219 www.7t7t.com
O1 - Hosts: 222.89.98.219 7t7t.com
O1 - Hosts: 222.89.98.219 www.7k7k.com
O1 - Hosts: 222.89.98.219 7k7k.com
O1 - Hosts: 222.89.98.219 www.webcool.net
O1 - Hosts: 222.89.98.219 webcool.net
O1 - Hosts: 222.89.98.219 www.51sobu.com
O1 - Hosts: 222.89.98.219 51sobu.com
O1 - Hosts: 222.89.98.219 cy.51sobu.com
O1 - Hosts: 222.89.98.219 www.fj3721.com
O1 - Hosts: 222.89.98.219 fj3721.com
O1 - Hosts: 222.89.98.219 www.msncn.com
O1 - Hosts: 222.89.98.219 msncn.com
O1 - Hosts: 222.89.98.219 www.6235.com
O1 - Hosts: 222.89.98.219 6235.com
O1 - Hosts: 222.89.98.219 www.8goo.com
O1 - Hosts: 222.89.98.219 8goo.com
O1 - Hosts: 222.89.98.219 www.baimin.com
O1 - Hosts: 222.89.98.219 baimin.com
O1 - Hosts: 222.89.98.219 www.bwwz.com
O1 - Hosts: 222.89.98.219 bwwz.com
O1 - Hosts: 222.89.98.219 www.howow.net
O1 - Hosts: 222.89.98.219 howow.net
O1 - Hosts: 222.89.98.219 www.tongchi.com
O1 - Hosts: 222.89.98.219 tongchi.com
O1 - Hosts: 222.89.98.219 www.65658.com
O1 - Hosts: 222.89.98.219 65658.com
O1 - Hosts: 222.89.98.219 www.7o7o.com
O1 - Hosts: 222.89.98.219 7o7o.com
O1 - Hosts: 222.89.98.219 5126.net
O1 - Hosts: 222.89.98.219 www.5126.net
O1 - Hosts: 222.89.98.219 www.wangzhiku.com
O1 - Hosts: 222.89.98.219 wangzhiku.com
O1 - Hosts: 222.89.98.219 www.soyeah.com
O1 - Hosts: 222.89.98.219 soyeah.com
O1 - Hosts: 222.89.98.219 www.sowang.cn
O1 - Hosts: 222.89.98.219 sowang.cn
O1 - Hosts: 222.89.98.219 www.77177.com
O1 - Hosts: 222.89.98.219 77177.com
O1 - Hosts: 222.89.98.219 www.look8.net
O4 - HKLM\..\Run: [GhostSurfDelSatellite] "C:\Program Files\GhostSurf 2005\DeleteSatellite.exe"
O4 - HKLM\..\Run: [GhostSurf Reminder] "C:\Program Files\GhostSurf 2005\Privacy Control Center.exe" reminder
 
HijackTHis has a Hosts File Editor that allows you to edit the hosts file in notepad.  The only line you really need is 127.0.0.1 local hosts.  Everything below that can be deleted.  Avenger can be used to get rid of the bad userinit line as well as the dll that they mention:
 
1. Please download The Avenger from
http://swandog46.geekstogo.com/avenger.zip
to your Desktop.
Rightclick on Avenger.zip and select Extract All
Extract avenger.exe to your desktop
2. Copy all the bold text contained between the stars (do not include the stars) below to your Clipboard by highlighting it and pressing (Ctrl+C):
*************************************************************
Files to Delete:
C:\WINDOWS\system32\userinit32.exe
C:\WINDOWS\mmsystem.dll
 
*****************************************************************
 
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
3. Now, start The Avenger program by clicking on its icon on your desktop.
Under "Script file to execute" choose "Input Script Manually".
Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
Paste the text copied to clipboard into this window by pressing (Ctrl+V).
Click Done
Now click on the Green Light to begin execution of the script
Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
On reboot, it will briefly open a black command window on your desktop, this is normal.
After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply and also tell me if the problem is gone.
 
 
Good luck.
 
Ron

 
No Events found!

Top