Start a Conversation

Unsolved

This post is more than 5 years old

S

148

December 15th, 2005 23:00

Spyware Message Took Over my Desktop

​ Okay a message has taken over my dekstop. It says Spyware Infection, blah, blah. With a blue background. I can't change it. I've ran a number of Spyware programs and anti-virus programs. No luck. Also my Home page on IE keeps getting changed and I'm starting to get pop-ups. Here's the HJT log: ​
​ ​
​ Logfile of HijackThis v1.99.1 ​
​Scan saved at 7:12:57 PM, on 12/15/2005 ​
​Platform: Windows XP SP1 (WinNT 5.01.2600) ​
​MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) ​
​ Running processes: ​
​C:\WINDOWS\System32\smss.exe ​
​C:\WINDOWS\system32\winlogon.exe ​
​C:\WINDOWS\system32\services.exe ​
​C:\WINDOWS\system32\lsass.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\WINDOWS\system32\spoolsv.exe ​
​C:\WINDOWS\Explorer.EXE ​
​C:\WINDOWS\msxi32.exe ​
​C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe ​
​C:\Program Files\Alwil Software\Avast4\ashServ.exe ​
​C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe ​
​C:\WINDOWS\System32\nvsvc32.exe ​
​C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\WINDOWS\System32\MsPMSPSv.exe ​
​C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe ​
​C:\Program Files\Alwil Software\Avast4\ashWebSv.exe ​
​C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe ​
​C:\Program Files\Microsoft AntiSpyware\gcasServ.exe ​
​C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe ​
​C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe ​
​C:\WINDOWS\System32\ctfmon.exe ​
​C:\Program Files\iTunes\iTunesHelper.exe ​
​C:\Program Files\iPod\bin\iPodService.exe ​
​C:\WINDOWS\d3lx32.exe ​
​C:\DOCUME~1\Steve\LOCALS~1\Temp\A.tmp.exe ​
​C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe ​
​C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe ​
​C:\Program Files\WinZip\WZQKPICK.EXE ​
​C:\WINDOWS\System32\wuauclt.exe ​
​C:\Program Files\Internet Explorer\iexplore.exe ​
​C:\PROGRA~1\Yahoo!\browser\ycommon.exe ​
​C:\HJT\HijackThis.exe ​
​ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\muccq.dll/sp.html#77035 ​
​R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\muccq.dll/sp.html#77035 ​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank ​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\muccq.dll/sp.html#77035 ​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\muccq.dll/sp.html#77035 ​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\muccq.dll/sp.html#77035 ​
​R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\muccq.dll/sp.html#77035 ​
​R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\muccq.dll/sp.html#77035 ​
​R3 - Default URLSearchHook is missing ​
​O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll ​
​O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll ​
​O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll ​
​O2 - BHO: Class - {B36A4008-5663-2ECF-9E70-FA3F4CC8F486} - C:\WINDOWS\mfcqd.dll ​
​O2 - BHO: Class - {E5AFDF80-07CE-2536-3668-6A46D26F50CD} - C:\WINDOWS\system32\crne.dll ​
​O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) ​
​O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx ​
​O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file) ​
​O3 - Toolbar: (no name) - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - (no file) ​
​O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll ​
​O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup ​
​O4 - HKLM\..\Run: [nwiz] nwiz.exe /install ​
​O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe" ​
​O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" ​
​O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe" ​
​O4 - HKLM\..\Run: [ElbyCheckAnyDVD] "d:\Program Files\SlySoft\AnyDVD\ElbyCheck.exe" /L AnyDVD ​
​O4 - HKLM\..\Run: [AnyDVD] D:\My Shared Folder\CloneDVD 1.3.9.8 _ AnyDVD 2.0.0.4\SlySoft AnyDVD 2.0.0.4\SlySoft AnyDVD 2.0.0.4\hgo_a24f\AnyDVD.exe ​
​O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe ​
​O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe ​
​O4 - HKLM\..\Run: [qhwp] C:\WINDOWS\qhwp.exe ​
​O4 - HKLM\..\Run: [Jzdjw] C:\Program Files\Wvccww\Iniu.exe ​
​O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" ​
​O4 - HKLM\..\Run: [Norton Ghost 9.0] C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe ​
​O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" ​
​O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime ​
​O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" ​
​O4 - HKLM\..\Run: [alij] C:\WINDOWS\System32\run427.exe dummy ​
​O4 - HKLM\..\Run: [d3lx32.exe] C:\WINDOWS\d3lx32.exe ​
​O4 - HKLM\..\Run: [9.tmp] C:\DOCUME~1\Steve\LOCALS~1\Temp\9.tmp.exe ​
​O4 - HKLM\..\Run: [A.tmp] C:\DOCUME~1\Steve\LOCALS~1\Temp\A.tmp.exe ​
​O4 - HKLM\..\Run: [9.tmp.exe] C:\DOCUME~1\Steve\LOCALS~1\Temp\9.tmp.exe ​
​O4 - HKLM\..\Run: [A.tmp.exe] C:\DOCUME~1\Steve\LOCALS~1\Temp\A.tmp.exe ​
​O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe ​
​O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe ​
​O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background ​
​O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl ​
​O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe ​
​O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE ​
​O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE ​
​O8 - Extra context menu item: &Search - ​​http://ka.bar.need2find.com/KA/menusearch.html?p=KA​ ​
​O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000 ​
​O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll ​
​O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll ​
​O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll ​
​O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll ​
​O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll ​
​O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll ​
​O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe ​
​O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe ​
​O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe ​
​O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm ​
​O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm ​
​O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll ​
​O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE ​
​O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE ​
​O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - ​​http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409​​ ​
​O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll ​
​O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - ​​http://appldnld.m7z.net/content.info.apple.com/iTunes4/WW/win/019-0312.20050111.MmVrT/iTunesSetup.exe​​ ​
​O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - ​​http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,81/mcinsctl.cab​​ ​
​O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - ​​http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab​​ ​
​O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - ​​http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,19/mcgdmgr.cab​​ ​
​O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - ​​http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab​​ ​
​O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\msxi32.exe ​
​O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe ​
​O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe ​
​O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) ​
​O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) ​
​O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe ​
​O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe ​
​O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe ​
​O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe ​
​O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe ​
​ ​
​ ​
​ ​
​ Thanks in advance ​
No Responses!
No Events found!

Top