Unsolved

This post is more than 5 years old

3881

June 24th, 2004 17:00

i have hjl

my home page change to a searh page,popups, my email in ie has been damage, i have the ad-aware6, spybot and hijackthis.

the first time this happen i thought i could just correct it with hijackthis on my own. i was wrong. i need help.

Logfile of HijackThis v1.97.7
Scan saved at 10:43:17 AM, on 6/24/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\javaew32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\WINDOWS\ieyc32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\swzmy.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://swzmy.dll/index.html#96676
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://swzmy.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\swzmy.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://swzmy.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\swzmy.dll/sp.html#96676
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {9CE283E7-669A-45BB-4625-1B2CC10B8B40} - C:\WINDOWS\msav.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [javaew32.exe] C:\WINDOWS\javaew32.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.9\THGuard.exe"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Real.com (HKLM)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popcap/zuma/popcaploader_v5.cab

933 Posts

June 24th, 2004 19:00

Hi and thanks for posting your log.  I need to make you aware that many logs are being posted, and that we are all volunteers with families and real jobs.  One of the experts needs to take a look at your log, and if you will be patient, they will do so as soon as possible.  We work the logs in the order they come in.   I also need to make you aware of this fact:

Please be aware only the following DellForum members were trained at
TomCoyote.com and SpywareInfo.com to help with Hijackthis logs: Texruss,
Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley. (If you are one of our classmates and not on this list email me for an addition to this list...we need all the help we can get *;-)

Also be aware of this:

Special Notice! Hijackthis is a powerful tool that edits the brains of Windows (the Registry). DO NOT FIX anything in the Hijackthis log screen without assistance from the experts! Most of the line items in the scanned log are normal for Windows operation. Hijackthis should identify the vast majority of your problems and enable us to help you clean them off your system.
 

Stay in this thread for continuity. Reply to this message.
 
Thanks,
 
Pskelley

June 24th, 2004 21:00

 i don't know if i should take out all the   res://swzmy.dll/index.html#96676 are what?

the frist time i lost my email so this time i will wait for good advice.

June 25th, 2004 16:00

Thanks for the fast post. I didn't hit the reply button like you suggested . I'am still learning how to get around this forum.

181 Posts

June 25th, 2004 17:00

Hello,

Run Hijackthis after closing all browser windows. Put a check mark on all these entries and FIX CHECKED button.

O2 - BHO: (no name) - {9CE283E7-669A-45BB-4625-1B2CC10B8B40} - C:\WINDOWS\msav.dll

O4 - HKLM\..\Run: [javaew32.exe] C:\WINDOWS\javaew32.exe

DO NOT FIX ANYTHING ELSE ESPECIALLY THE R0 AND R1 ENTRIES

Then download this program from the link below,.

http://tools.zerosrealm.com/AboutBuster.zip

Unzip it and run it.Hit ok button.  Copy and paste the report it generates in a notepad file and save it.

Now run Hijackthis again. Fix the following entries.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\swzmy.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://swzmy.dll/index.html#96676

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://swzmy.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\swzmy.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://swzmy.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\swzmy.dll/sp.html#96676

Restart , rescan with Hijackthis and post a fresh log. Also post the report of About:Buster you have saved.

 


 

181 Posts

June 25th, 2004 18:00

Hello,.

Run hijackthis and fix these entries.

 

O16 - DPF: {2119776A-F1AD-4FCD-9548-F1E1C615350C} - http://www.stop-sign.com/pub/download/stop-sign_stp.cab

O4 - HKLM\..\Run: [EanthologyApp] "C:\Program Files\Common Files\eAcceleration\eanthology.exe" /b Startup
O4 - HKLM\..\Run: [eanth_system_patcher] C:\PROGRA~1\ACCELE~1\SYSTEM~1\sys_alert.exe /Startup
O4 - HKLM\..\Run: [WebScan] C:\Program Files\Acceleration Software\Anti-Virus\defscangui.exe -k
O4 - HKLM\..\Run: [javaew32.exe] C:\WINDOWS\javaew32.exe

Open taskmanager by pressing ctrl+alt+del keys simultaneously and in the processes tab,. look for

crrl.exe
javaew32.exe

Click on each item and hit END PROCESS button.

Then Find and delete ,..Unhide all files and folders.

http://www.xtra.co.nz/help/0,,4155-1916458,00.html How to unhide file and folders

C:\Program Files\Common Files\eAcceleration\ - -FOLDER

C:\PROGRA~1\ACCELE~1\ -- FOLDER

C:\WINDOWS\javaew32.exe - FOLDER

 C:\Program Files\Acceleration Software\ -- FOLDER

Then please run About :Buster again.

Now reboot, rescan with hijackthis and post a fresh log.

June 25th, 2004 18:00

ok when i did everything this is what i got? when i frist got on the internet my hmpage was google.

About:Buster Version 1.21
Error Removing! : C:\WINDOWS\javaew32.exe
Removed! : C:\WINDOWS\mfccz32.exe
Removed! : C:\WINDOWS\acmshz.dat
Removed! : C:\WINDOWS\agrabv.dat
Removed! : C:\WINDOWS\ammfip.dat
Removed! : C:\WINDOWS\asnwru.dat
Removed! : C:\WINDOWS\bdfkma.dat
Removed! : C:\WINDOWS\bkbrbu.dat
Removed! : C:\WINDOWS\bopzzw.dat
Removed! : C:\WINDOWS\budfah.dat
Removed! : C:\WINDOWS\cfbmhf.dat
Removed! : C:\WINDOWS\cjcxoc.dat
Removed! : C:\WINDOWS\cpftuw.dat
Removed! : C:\WINDOWS\dfobvo.dat
Removed! : C:\WINDOWS\diujum.dat
Removed! : C:\WINDOWS\djpxkp.dat
Removed! : C:\WINDOWS\dnheme.dat
Removed! : C:\WINDOWS\dpenma.dat
Removed! : C:\WINDOWS\dxyarf.dat
Removed! : C:\WINDOWS\eergic.dat
Removed! : C:\WINDOWS\emauxw.dat
Removed! : C:\WINDOWS\epdtzn.dat
Removed! : C:\WINDOWS\erhrez.dat
Removed! : C:\WINDOWS\euhgbb.dat
Removed! : C:\WINDOWS\exlxii.dat
Removed! : C:\WINDOWS\fadmvo.dat
Removed! : C:\WINDOWS\fcaorg.dat
Removed! : C:\WINDOWS\ftqgxj.dat
Removed! : C:\WINDOWS\fxvlky.dat
Removed! : C:\WINDOWS\gapwfm.dat
Removed! : C:\WINDOWS\gekmws.dat
Removed! : C:\WINDOWS\gklads.dat
Removed! : C:\WINDOWS\glqhue.dat
Removed! : C:\WINDOWS\gwkris.dat
Removed! : C:\WINDOWS\gwrfns.dat
Removed! : C:\WINDOWS\hajbiz.dat
Removed! : C:\WINDOWS\harzqz.dat
Removed! : C:\WINDOWS\hdkljw.dat
Removed! : C:\WINDOWS\hhswuj.dat
Removed! : C:\WINDOWS\hkmcs.dat
Removed! : C:\WINDOWS\hlxdmp.dat
Removed! : C:\WINDOWS\hnwwyz.dat
Removed! : C:\WINDOWS\hygpul.dat
Removed! : C:\WINDOWS\hzxblw.dat
Removed! : C:\WINDOWS\ihcnvz.dat
Removed! : C:\WINDOWS\imcwdg.dat
Removed! : C:\WINDOWS\ioiegk.dat
Removed! : C:\WINDOWS\ipuijy.dat
Removed! : C:\WINDOWS\irkhed.dat
Removed! : C:\WINDOWS\iwwjzv.dat
Removed! : C:\WINDOWS\iyhby.dat
Removed! : C:\WINDOWS\izrvoo.dat
Removed! : C:\WINDOWS\jgoslz.dat
Removed! : C:\WINDOWS\jhhutn.dat
Removed! : C:\WINDOWS\jjmvi.dat
Removed! : C:\WINDOWS\jkcshq.dat
Removed! : C:\WINDOWS\jkpqyd.dat
Removed! : C:\WINDOWS\jkqlhr.dat
Removed! : C:\WINDOWS\jovzwc.dat
Removed! : C:\WINDOWS\jrgsur.dat
Removed! : C:\WINDOWS\jzoguc.dat
Removed! : C:\WINDOWS\kcoizy.dat
Removed! : C:\WINDOWS\kelqrt.dat
Removed! : C:\WINDOWS\kexlqa.dat
Removed! : C:\WINDOWS\kifzpp.dat
Removed! : C:\WINDOWS\kjypgg.dat
Removed! : C:\WINDOWS\kxxpiu.dat
Removed! : C:\WINDOWS\kybthi.dat
Removed! : C:\WINDOWS\lcfqez.dat
Removed! : C:\WINDOWS\lcroox.dat
Removed! : C:\WINDOWS\lfawsz.dat
Removed! : C:\WINDOWS\lidqhb.dat
Removed! : C:\WINDOWS\lmsffh.dat
Removed! : C:\WINDOWS\lpihdg.dat
Removed! : C:\WINDOWS\lsgnbp.dat
Removed! : C:\WINDOWS\luajkn.dat
Removed! : C:\WINDOWS\lwobli.dat
Removed! : C:\WINDOWS\lwwgze.dat
Removed! : C:\WINDOWS\mflgxu.dat
Removed! : C:\WINDOWS\miltfg.dat
Removed! : C:\WINDOWS\miykcd.dat
Removed! : C:\WINDOWS\mlywcw.dat
Removed! : C:\WINDOWS\mmlpxs.dat
Removed! : C:\WINDOWS\mmxsny.dat
Removed! : C:\WINDOWS\mojow.dat
Removed! : C:\WINDOWS\mtzjes.dat
Removed! : C:\WINDOWS\nmflpv.dat
Removed! : C:\WINDOWS\nxqhjy.dat
Removed! : C:\WINDOWS\nydobj.dat
Removed! : C:\WINDOWS\nzzygp.dat
Removed! : C:\WINDOWS\obdwtq.dat
Removed! : C:\WINDOWS\ojwixc.dat
Removed! : C:\WINDOWS\ooxnzb.dat
Removed! : C:\WINDOWS\opnxsq.dat
Removed! : C:\WINDOWS\opppae.dat
Removed! : C:\WINDOWS\orukr.dat
Removed! : C:\WINDOWS\oulsmi.dat
Removed! : C:\WINDOWS\peoxgg.dat
Removed! : C:\WINDOWS\pjaddf.dat
Removed! : C:\WINDOWS\pmlajf.dat
Removed! : C:\WINDOWS\ppxacc.dat
Removed! : C:\WINDOWS\qawdln.dat
Removed! : C:\WINDOWS\qbjfox.dat
Removed! : C:\WINDOWS\qcqhjb.dat
Removed! : C:\WINDOWS\qgzrbi.dat
Removed! : C:\WINDOWS\qlgpe.dat
Removed! : C:\WINDOWS\qmetwn.dat
Removed! : C:\WINDOWS\qmhfki.dat
Removed! : C:\WINDOWS\qrpjmi.dat
Removed! : C:\WINDOWS\qruzzh.dat
Removed! : C:\WINDOWS\qvywqv.dat
Removed! : C:\WINDOWS\qxeowm.dat
Removed! : C:\WINDOWS\qywozp.dat
Removed! : C:\WINDOWS\rdfvlo.dat
Removed! : C:\WINDOWS\rfjeei.dat
Removed! : C:\WINDOWS\rfyols.dat
Removed! : C:\WINDOWS\rhjcly.dat
Removed! : C:\WINDOWS\rmqqjj.dat
Removed! : C:\WINDOWS\ronzoj.dat
Removed! : C:\WINDOWS\rtlkey.dat
Removed! : C:\WINDOWS\rupcls.dat
Removed! : C:\WINDOWS\rxktmu.dat
Removed! : C:\WINDOWS\rxocet.dat
Removed! : C:\WINDOWS\sgrlu.dat
Removed! : C:\WINDOWS\sjsooo.dat
Removed! : C:\WINDOWS\smbpcf.dat
Removed! : C:\WINDOWS\smccje.dat
Removed! : C:\WINDOWS\smhzaj.dat
Removed! : C:\WINDOWS\smqblj.dat
Removed! : C:\WINDOWS\syjtkc.dat
Removed! : C:\WINDOWS\tizyqa.dat
Removed! : C:\WINDOWS\tlokt.dat
Removed! : C:\WINDOWS\tndpmp.dat
Removed! : C:\WINDOWS\tqqlyz.dat
Removed! : C:\WINDOWS\tsqmxl.dat
Removed! : C:\WINDOWS\txjndq.dat
Removed! : C:\WINDOWS\txtmol.dat
Removed! : C:\WINDOWS\uifqyt.dat
Removed! : C:\WINDOWS\upayyp.dat
Removed! : C:\WINDOWS\uqwlyw.dat
Removed! : C:\WINDOWS\utgfcc.dat
Removed! : C:\WINDOWS\uykzgj.dat
Removed! : C:\WINDOWS\veuifj.dat
Removed! : C:\WINDOWS\vwbikr.dat
Removed! : C:\WINDOWS\vwqbpj.dat
Removed! : C:\WINDOWS\wajxem.dat
Removed! : C:\WINDOWS\wgtjet.dat
Removed! : C:\WINDOWS\winwds.dat
Removed! : C:\WINDOWS\wqjcha.dat
Removed! : C:\WINDOWS\wvwspm.dat
Removed! : C:\WINDOWS\wxlhyg.dat
Removed! : C:\WINDOWS\xfadwi.dat
Removed! : C:\WINDOWS\xixgzl.dat
Removed! : C:\WINDOWS\xtytxy.dat
Removed! : C:\WINDOWS\ydzfyr.dat
Removed! : C:\WINDOWS\yjmfza.dat
Removed! : C:\WINDOWS\yrujnw.dat
Removed! : C:\WINDOWS\yttzuh.dat
Removed! : C:\WINDOWS\yztvus.dat
Removed! : C:\WINDOWS\avhfb.dll
Removed! : C:\WINDOWS\d3dq.dll
Removed! : C:\WINDOWS\hvsec.dll
Removed! : C:\WINDOWS\System32\apiwj32.exe
Error Removing! : C:\WINDOWS\System32\crrl.exe
Removed! : C:\WINDOWS\System32\iebm32.exe
Removed! : C:\WINDOWS\System32\bmqbp.dll
Removed! : C:\WINDOWS\System32\kykxb.dll
Error Removing! : C:\WINDOWS\System32\nethj.dll
Removed! : C:\WINDOWS\System32\swzmy.dll
Removed! : C:\WINDOWS\System32\djkya.dat
Removed! : C:\WINDOWS\System32\gship.dat
Removed! : C:\WINDOWS\System32\pabvt.dat
Removed! : C:\WINDOWS\System32\wrrva.dat
Removed! : C:\WINDOWS\System32\wvvuv.dat
Removed! : C:\WINDOWS\System32\xsoam.dat
Removed! : C:\WINDOWS\System32\ysojg.dat
Attempted Clean Of Temp folder.
Removed LEGACY___NS_Service_3 Key
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset... Done!

 

 

 

 

Logfile of HijackThis v1.97.7
Scan saved at 2:00:09 PM, on 6/25/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\crrl.exe
C:\WINDOWS\javaew32.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\eAcceleration\eanthology.exe
C:\SPYBOT\HijackThis.exe
C:\PROGRA~1\ACCELE~1\SYSTEM~1\sys_alert.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Acceleration Software\Anti-Virus\defscangui.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Microsoft Money\System\mnyexpr.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {B0BAA0D3-B86E-A237-D6EA-D5428A8C6CBC} - C:\WINDOWS\adduh32.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.9\THGuard.exe"
O4 - HKLM\..\Run: [EanthologyApp] "C:\Program Files\Common Files\eAcceleration\eanthology.exe" /b Startup
O4 - HKLM\..\Run: [eanth_system_patcher] C:\PROGRA~1\ACCELE~1\SYSTEM~1\sys_alert.exe /Startup
O4 - HKLM\..\Run: [WebScan] C:\Program Files\Acceleration Software\Anti-Virus\defscangui.exe -k
O4 - HKLM\..\Run: [javaew32.exe] C:\WINDOWS\javaew32.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra 'Tools' menuitem: Block This Page (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: Real.com (HKLM)
O16 - DPF: {2119776A-F1AD-4FCD-9548-F1E1C615350C} - http://www.stop-sign.com/pub/download/stop-sign_stp.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popcap/zuma/popcaploader_v5.cab

 

June 25th, 2004 20:00

i tried to delete  C:\Program Files\Common Files\eAcceleration\ - -FOLDER but it has an error msg overwrite protected are something like that.

So how do you delete it.

June 25th, 2004 21:00

I have a new trojen javaew32.$$$ that was from my norton antivirus when i got on the internet.

 

So i finally uninstalled & delete Acceleration Software hope this helps.

 

About:Buster Version 1.21
Removed! : C:\WINDOWS\msfc.exe
Removed! : C:\WINDOWS\sdkda.exe
Removed! : C:\WINDOWS\dvebd.dll
Removed! : C:\WINDOWS\System32\addeh32.exe
Removed! : C:\WINDOWS\System32\atlbv32.exe
Removed! : C:\WINDOWS\System32\cror.exe
Removed! : C:\WINDOWS\System32\crrl.exe
Removed! : C:\WINDOWS\System32\d3xr32.exe
Attempted Clean Of Temp folder.
Removed LEGACY___NS_Service_3 Key
Removed __NS_Service_3 Key
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset... Done!

 

 

Logfile of HijackThis v1.97.7
Scan saved at 4:49:07 PM, on 6/25/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\syscr.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\nethj.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\SPYBOT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {B0BAA0D3-B86E-A237-D6EA-D5428A8C6CBC} - C:\WINDOWS\adduh32.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.9\THGuard.exe"
O4 - HKLM\..\Run: [nethj.exe] C:\WINDOWS\system32\nethj.exe
O4 - HKLM\..\Run: [ipnw.exe] C:\WINDOWS\system32\ipnw.exe
O4 - HKLM\..\Run: [mfcse.exe] C:\WINDOWS\system32\mfcse.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra 'Tools' menuitem: Block This Page (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: Real.com (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popcap/zuma/popcaploader_v5.cab

 

181 Posts

June 30th, 2004 16:00

Hello,

Please post a fresh Hijackthis log after rescanning with HIjackthis. Also, can you please find these files , zip them and email it to baskar1234 AT rediffmail.com

C:\WINDOWS\system32\nethj.exe
C:\WINDOWS\system32\ipnw.exe

C:\WINDOWS\system32\mfcse.exe

These files may be hidden.Be sure to unhide all files and folders.

http://www.xtra.co.nz/help/0,,4155-1916458,00.html How to unhide file and folders

Regards,

Baskar .

No Events found!

Top