Start a Conversation

Unsolved

This post is more than 5 years old

D

279

August 30th, 2005 00:00

Winfixer HELP!!!!!

​ ​
​ Here is a copy of my HJT File. Winfixer has downloaded itself on my computer. I have tried everything to remove this and nothing works. It just continues to bog down my computer. Thank you for your help. ​
​ ​
​ ​
​ ​
​ ​
​ ​
​ Logfile of HijackThis v1.99.1 ​
​Scan saved at 6:11:41 PM, on 8/29/2005 ​
​Platform: Windows XP SP2 (WinNT 5.01.2600) ​
​MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) ​
​ ​
​ Running processes: ​
​C:\WINDOWS\System32\smss.exe ​
​C:\WINDOWS\system32\winlogon.exe ​
​C:\WINDOWS\system32\services.exe ​
​C:\WINDOWS\system32\lsass.exe ​
​C:\WINDOWS\system32\Ati2evxx.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\Program Files\Common Files\Symantec Shared\ccProxy.exe ​
​C:\WINDOWS\system32\Ati2evxx.exe ​
​C:\WINDOWS\Explorer.EXE ​
​C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe ​
​C:\Program Files\Norton Internet Security\ISSVC.exe ​
​C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe ​
​C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe ​
​C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe ​
​C:\WINDOWS\system32\LEXBCES.EXE ​
​C:\WINDOWS\system32\spoolsv.exe ​
​C:\WINDOWS\system32\LEXPPS.EXE ​
​C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe ​
​C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ​
​C:\WINDOWS\zHotkey.exe ​
​C:\WINDOWS\SOUNDMAN.EXE ​
​C:\Program Files\Digital Media Reader\shwiconem.exe ​
​C:\Program Files\dvd43\dvd43_tray.exe ​
​C:\Program Files\QuickTime\qttask.exe ​
​C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe ​
​C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe ​
​C:\Program Files\Common Files\Symantec Shared\ccApp.exe ​
​C:\WINDOWS\Downloaded Program Files\UWFX5LP_0001_0802NetInstaller.exe ​
​C:\Program Files\Messenger\msmsgs.exe ​
​C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe ​
​C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe ​
​C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe ​
​C:\Program Files\Internet Explorer\iexplore.exe ​
​C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe ​
​C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for HJT.zip\HijackThis.exe ​
​ ​
​ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = ​​http://securityresponse.symantec.com/avcenter/fix_homepage​​ ​
​R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet ​
​O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll ​
​O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL (file missing) ​
​O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-90F0-F66AB581A933} - (no file) ​
​O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll ​
​O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll ​
​O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll ​
​O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll ​
​O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll ​
​O2 - BHO: (no name) - {DE23E67C-07CA-0E6E-BE08-7C22811619E5} - C:\WINDOWS\system32\oiirq.dll ​
​O2 - BHO: (no name) - {DE74E77C-03C9-0F3E-B859-7C22811619E5} - C:\WINDOWS\system32\oiirq.dll ​
​O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll ​
​O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll ​
​O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll ​
​O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll ​
​O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE ​
​O4 - HKLM\..\Run: [CHotkey] zHotkey.exe ​
​O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe ​
​O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE ​
​O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe ​
​O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe ​
​O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe ​
​O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe ​
​O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime ​
​O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe" ​
​O4 - HKLM\..\Run: [InstaFinderK] C:\Program Files\INSTAFINK\InstaFinderK_inst.exe ​
​O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" ​
​O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe ​
​O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0802] "C:\WINDOWS\Downloaded Program Files\UWFX5LP_0001_0802NetInstaller.exe" ​
​O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background ​
​O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet ​
​O4 - Global Startup: Picture Package Menu.lnk = ? ​
​O4 - Global Startup: Picture Package VCD Maker.lnk = ? ​
​O8 - Extra context menu item: &Search - ​​http://ka.bar.need2find.com/KA/menusearch.html?p=KA​ ​
​O8 - Extra context menu item: &Yahoo! Search - ​​file:///C:\Program​​ Files\Yahoo!\Common/ycsrch.htm ​
​O8 - Extra context menu item: Yahoo! &Dictionary - ​​file:///C:\Program​​ Files\Yahoo!\Common/ycdict.htm ​
​O8 - Extra context menu item: Yahoo! &Maps - ​​file:///C:\Program​​ Files\Yahoo!\Common/ycmap.htm ​
​O8 - Extra context menu item: Yahoo! &SMS - ​​file:///C:\Program​​ Files\Yahoo!\Common/ycsms.htm ​
​O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll ​
​O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll ​
​O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ​
​O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ​
​O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - ​​http://zone.msn.com/binFrameWork/v10/StagingUI.cab34120.cab​​ ​
​O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - ​​http://go.microsoft.com/fwlink/?linkid=39204​​ ​
​O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll ​
​O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - ​​http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab​​ ​
​O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - ​​http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab​​ ​
​O16 - DPF: {9BFC2253-B9D9-477E-9488-CA450232620D} (BinAg1 Class) - ​​https://fastconnectkitsetup.cox.net/wizlet/CoxNA/static/controls/WebflowActiveX.CAB​​ ​
​O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - ​​http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab​​ ​
​O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - ​​http://download.toontown.com/sv1.0.15.38/ttinst.cab​​ ​
​O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) - ​​http://zone.msn.com/bingame/zpagames/zpa_pool.cab36107.cab​​ ​
​O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - ​​https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab​​ ​
​O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - ​​http://zone.msn.com/bingame/gold/default/gf.cab​​ ​
​O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - ​​http://zone.msn.com/binframework/v10/StProxy.cab35645.cab​​ ​
​O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - ​​http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab​​ ​
​O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe ​
​O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe ​
​O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe ​
​O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe ​
​O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe ​
​O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe ​
​O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE ​
​O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe ​
​O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS ​
​O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe ​
​O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe ​
​O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe ​
​O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe ​
​O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ​
​ ​
​ ​
​ ​

5.9K Posts

August 30th, 2005 16:00

You are running hijackthis from a temp file which is dangerous.  Please download it again and save it to its own folder. 

Download the Hoster from:


http://www.funkytoad.com/

Unpack to your desktop and run it.  If you have green print at the top then just press Restore Original Hosts then OK. 
IF you have red print then press make Hosts Writeable first.
 


Get DelDomain.inf from:
 
http://www.mvps.org/winhelp2002/restricted.htm  and then right click on it and Install. 

 

Shutdown and Restart and Boot into Safe Mode by tapping the F8 key when you see the PC
maker's logo.
Keep tapping until it tells you it is going to Safe Mode or you see the Safe
Mode menu. Select the top option.

Run HijackThis and just do a Scan only. Check then Fix
Checked the following (most or all of the O1's may be gone thanks to Hoster):

O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL (file missing)
O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-90F0-F66AB581A933} - (no file)
O2 - BHO: (no name) - {DE23E67C-07CA-0E6E-BE08-7C22811619E5} - C:\WINDOWS\system32\oiirq.dll
O2 - BHO: (no name) - {DE74E77C-03C9-0F3E-B859-7C22811619E5} - C:\WINDOWS\system32\oiirq.dll
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0802] "C:\WINDOWS\Downloaded Program Files\UWFX5LP_0001_0802NetInstaller.exe"
 
Reboot into regular mode and install deldomain.inf and run hoster / Restore Default Hosts
just to make sure. 

Start, Run, cmd, OK to open a black cmd screen.  Type:

dir /a \windows\tasks

If you see something besides sa.data and desktop.ini highlight the result and press Enter. 
Then start a reply and Edit Paste or Ctrl + v

Run another HijackThis log and post it in the same reply. Let's
see how we did.

Ron

No Events found!

Top