Start a Conversation

Unsolved

This post is more than 5 years old

J

428

September 7th, 2005 00:00

Please Help...winfix 2005 got me down!

​ ​
​ Logfile of HijackThis v1.99.1 ​
​Scan saved at 12:01:48 AM, on 9/6/2005 ​
​Platform: Windows XP (WinNT 5.01.2600) ​
​MSIE: Internet Explorer v6.00 (6.00.2600.0000) ​
​ ​
​ ​
​ ​
​ Running processes: ​
​C:\WINDOWS\System32\smss.exe ​
​C:\WINDOWS\system32\winlogon.exe ​
​C:\WINDOWS\system32\services.exe ​
​C:\WINDOWS\system32\lsass.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\WINDOWS\system32\spoolsv.exe ​
​C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe ​
​C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe ​
​C:\PROGRA~1\Iomega\System32\AppServices.exe ​
​c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe ​
​C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe ​
​C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe ​
​C:\WINDOWS\wanmpsvc.exe ​
​c:\PROGRA~1\mcafee.com\vso\mcshield.exe ​
​C:\WINDOWS\Explorer.EXE ​
​C:\PROGRA~1\mcafee.com\agent\mcagent.exe ​
​C:\Program Files\Common Files\AOL\ACS\AOLDial.exe ​
​C:\Program Files\WildTangent\Apps\GameChannel.exe ​
​C:\windows\system32\taskmgn.exe ​
​C:\Program Files\Winamp\winampa.exe ​
​C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe ​
​C:\Program Files\Common Files\Real\Update_OB\realsched.exe ​
​C:\Program Files\support.com\bin\tgcmd.exe ​
​C:\PROGRA~1\MI948F~1\GAMECO~1\Common\SWTrayV4.exe ​
​C:\Program Files\QuickTime\qttask.exe ​
​c:\progra~1\mcafee.com\vso\mcvsescn.exe ​
​C:\Program Files\Tvtbbbp\Tizekfc.exe ​
​C:\WINDOWS\system32\rundll32.exe ​
​C:\WINDOWS\Downloaded Program Files\UWFX5LP_0001_0715NetInstaller.exe ​
​C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe ​
​C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe ​
​C:\WINDOWS\kdx\KHost.exe ​
​C:\Program Files\Microsoft IntelliPoint\point32.exe ​
​C:\WINDOWS\System32\hkcmd.exe ​
​C:\Program Files\Iomega HotBurn\Autolaunch.exe ​
​C:\program files\desksite\bin\cma.exe ​
​C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe ​
​C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe ​
​C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe ​
​C:\WINDOWS\System32\ctfmon.exe ​
​C:\PROGRA~1\COMMON~1\AOL\110087~1\EE\AOLHOS~1.EXE ​
​C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe ​
​C:\WINDOWS\System32\r?ndll32.exe ​
​C:\PROGRA~1\COMMON~1\AOL\110087~1\EE\AOLServiceHost.exe ​
​C:\Program Files\MTV Networks\VOpt\MTVOptTray.exe ​
​C:\Program Files\MTV Networks\VOpt\MTVOptQueue.exe ​
​C:\Program Files\Internet Explorer\iexplore.exe ​
​C:\Program Files\America Online 9.0\waol.exe ​
​C:\Program Files\America Online 9.0\shellmon.exe ​
​C:\Documents and Settings\Cheryl\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe ​
​ ​
​ ​
​ ​
​ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = ​​http://www.comcast.net/​​ ​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = ​​http://www.websearch.com/ie.aspx?tb_id=%tb_id​​ ​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = ​​http://www.searchv.com/search.html​​ ​
​R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast ​
​R3 - URLSearchHook: (no name) - _{D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - (no file) ​
​R3 - URLSearchHook: (no name) - _{CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - (no file) ​
​R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) ​
​F3 - REG:win.ini: load=? ???????Ÿ ​
​?? ?? ???? ​
​F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe ​
​O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL ​
​O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll ​
​O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll ​
​O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll ​
​O3 - Toolbar: (no name) - {CE0A34D3-C30F-4F3D-B0D3-9B936EDFBD91} - (no file) ​
​O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file) ​
​O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx ​
​O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll ​
​O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe ​
​O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe ​
​O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe ​
​O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe ​
​O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe ​
​O4 - HKLM\..\Run: [Windows Task Manager] C:\windows\system32\taskmgn.exe ​
​O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ​
​O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask ​
​O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" ​
​O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u ​
​O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot ​
​O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server ​
​O4 - HKLM\..\Run: [susp] C:\WINDOWS\susp.exe ​
​O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MI948F~1\GAMECO~1\Common\SWTrayV4.exe ​
​O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime ​
​O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run ​
​O4 - HKLM\..\Run: [Paoasz] C:\Program Files\Tvtbbbp\Tizekfc.exe ​
​O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0715] "C:\WINDOWS\Downloaded Program Files\UWFX5LP_0001_0715NetInstaller.exe" ​
​O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe ​
​O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe ​
​O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers ​
​O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe ​
​O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" ​
​O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe ​
​O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe ​
​O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1100877153\EE\AOLHostManager.exe ​
​O4 - HKLM\..\Run: [Drag'n'Drop_Autolaunch] "C:\Program Files\Iomega HotBurn\Autolaunch.exe" ​
​O4 - HKLM\..\Run: [Desksite CMA] c:\program files\desksite\bin\cma.exe ​
​O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" ​
​O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" ​
​O4 - HKLM\..\Run: [Á³# L"h'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\tdvgv.exe ​
​O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" ​
​O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background ​
​O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe ​
​O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" ​
​O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Derek\Application Data\eetu.exe ​
​O4 - HKCU\..\Run: [Vvdjdy] C:\WINDOWS\System32\r?ndll32.exe ​
​O4 - HKCU\..\Run: [TimeLeft] C:\Program Files\TimeLeft\timeleft.exe ​
​O4 - HKCU\..\Run: [Mcgxar] C:\WINDOWS\System32\w?aclt.exe ​
​O4 - HKCU\..\Run: [HistoryKill] C:\Program Files\HistoryKill\histkill.exe /startup ​
​O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b ​
​O4 - Global Startup: MTV Networks Video Optimizer.lnk = C:\Program Files\MTV Networks\VOpt\MTVOptTray.exe ​
​O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML ​
​O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html ​
​O8 - Extra context menu item: &Search - ​​http://ka.bar.need2find.com/KA/menusearch.html?p=KA​ ​
​O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html ​
​O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html ​
​O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 ​
​O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html ​
​O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html ​
​O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll ​
​O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll ​
​O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - ​​http://www.comcast.net/​​ (file missing) ​
​O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - ​​http://www.comcastsupport.com/​​ (file missing) ​
​O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - ​​http://online.comcast.net/help/​​ (file missing) ​
​O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm ​
​O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm ​
​O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) ​
​O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\WINDOWS\System32\shdocvw.dll ​
​O16 - DPF: JavaConnect - ​​http://im.cwinsider.com/sametime/javaconnect/JavaConnect.cab​​ ​
​O16 - DPF: {02BED220-FBC7-4392-93A2-3A50B056F78E} - ​​http://down.plaxo.com/down/release/instub.cab​​ ​
​O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - ​​http://www.photoparade.com/autoinstall/phpsetup.cab​​ ​
​O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - ​​http://housecall60.trendmicro.com/housecall/xscan60.cab​​ ​
​O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - ​​http://go.microsoft.com/fwlink/?linkid=39204​​ ​
​O16 - DPF: {2226ED4E-6E9A-472E-97ED-B6D54F3B620B} (STURLConnection Control) - ​​http://im.cwinsider.com/sametime/javaconnect/STUrlConLoader.cab​​ ​
​O16 - DPF: {36C66BBD-E667-4DAD-9682-58050E7C9FDC} (CDKey Class) - ​​http://www.cdkeybonus.com/cdkey/ITCDKey.cab​​ ​
​O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - ​​https://inotes.cwinsider.com/mailpt10/iNotes6.cab​​ ​
​O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - ​​http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe​​ ​
​O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - ​​http://aolcc.aol.com/computercheckup/qdiagcc.cab​​ ​
​O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - ​​http://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab​​ ​
​O16 - DPF: {53F92AF2-3C1E-4A63-B2EA-2E33DA6286B7} (STAutoAway Control) - ​​http://im.cwinsider.com/sametime/javaconnect/STAutoAwayLoader.cab​​ ​
​O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - ​​http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1109001355265​​ ​
​O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - ​​http://a19.g.akamai.net/7/19/7125/4047/ftp.coupons.com/v3123/cpbrkpie.cab​​ ​
​O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - ​​http://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab​​ ​
​O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - ​​http://www.gamespot.com/KDX22/download/kdx.cab​​ ​
​O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll ​
​O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\dnrs0197e.dll ​
​O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe ​
​O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe ​
​O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe ​
​O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe ​
​O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe ​
​O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe ​
​O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe ​
​O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing) ​
​O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe ​
​ ​
​ ​
​ ​
​ ​
​ ​

5.9K Posts

September 7th, 2005 01:00

Download the Hoster from:
Unpack to your desktop and run it.  If you have green print at the top then just press Restore Original Hosts then OK. 
IF you have red print then press make Hosts Writeable first.
 
 
Get DelDomain.inf from:
 
http://www.mvps.org/winhelp2002/DelDomains.inf  and then right click on it and Install. 
 

Shutdown and restart and
Boot into Safe Mode by tapping the F8 key when you see the PC maker's logo.
Keep tapping until it tells you it is going to Safe Mode or you see the Safe
Mode menu. Select the top option.
Run HijackThis and check the box in front of each
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=%tb_id
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/search.html
R3 - URLSearchHook: (no name) - _{D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - (no file)
R3 - URLSearchHook: (no name) - _{CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F3 - REG:win.ini: load=? ???????Ÿ
?? ?? ????
O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL
O3 - Toolbar: (no name) - {CE0A34D3-C30F-4F3D-B0D3-9B936EDFBD91} - (no file)
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O4 - HKLM\..\Run: [Windows Task Manager] C:\windows\system32\taskmgn.exe
O4 - HKLM\..\Run: [susp] C:\WINDOWS\susp.exe
O4 - HKLM\..\Run: [Paoasz] C:\Program Files\Tvtbbbp\Tizekfc.exe
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0715] "C:\WINDOWS\Downloaded Program Files\UWFX5LP_0001_0715NetInstaller.exe"
O4 - HKLM\..\Run: [Á³#  L"h'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\tdvgv.exe
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Derek\Application Data\eetu.exe
O4 - HKCU\..\Run: [Vvdjdy] C:\WINDOWS\System32\r?ndll32.exe
O4 - HKCU\..\Run: [Mcgxar] C:\WINDOWS\System32\w?aclt.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4047/ftp.coupons.com/v3123/cpbrkpie.cab
O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\dnrs0197e.dll
Close HijackThis.
Run Microsoft AntiSpy.  Do a full scan.  (Look under Scan Options and check all three options). 
Reboot into regular mode
Run HijackThis and make a new log and post it as a Reply.
Ron
No Events found!

Top