1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

HJT log help 'deseperately' needed---bad stuff on computer???

Discussion in 'Virus & Other Malware Removal' started by 202e, Jan 25, 2006.

Thread Status:
Not open for further replies.
  1. 202e

    202e Thread Starter

    Dec 30, 2002

    I have some nasty stuff on my computer (but I have no idea what it is!)!!! Please help.

    I've run lots of scans on my computer since this all started, but here is the latest thing I just did before coming here:

    I use Ad-aware and Spybit S&D and AVG free on my computer so I made sure they were updated and just ran them again. The spyware programs found a few things and removed them. AVG found nothing. I also use Spywareblaster. I have always kept these updated and I ran the OFTEn, yet somehow some nasty stuff got through them.

    I just ran the pandasoftware.com Activescan and these are the results:

    Incident Status Location

    Spyware:spyware/whazit Not disinfected C:\WINDOWS\SYSTEM32\fiz1
    Adware:adware/virtualbouncer Not disinfected C:\WINDOWS\SYSTEM32\INNERADINSTALL.LOG
    Adware:adware/keenvalue Not disinfected C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.bho
    Adware:adware/ncase Not disinfected C:\WINDOWS\SYSTEM32\FLEOK
    Adware:adware/adwhere Not disinfected Windows Registry
    Spyware:Cookie/2o7.net Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[.2o7.net/]
    Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[.ads.pointroll.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[.apmebf.com/]
    Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[.ask.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[.bravenet.com/]
    Spyware:Cookie/2o7.net Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[.2o7.net/]
    Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[.fortunecity.com/]
    Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[.perf.overture.com/]
    Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[.statcounter.com/]
    Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[.tribalfusion.com/]
    Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[c.enhance.com/]
    Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[.advertising.com/]
    Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[.atdmt.com/]
    Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[.advertising.com/]
    Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[.doubleclick.net/]
    Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[.bfast.com/]
    Spyware:Cookie/2o7.net Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\cookies.txt[]
    Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
    Adware:Adware/IPInsight Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\Belt.ini
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc155.txt
    Spyware:Cookie/Belnk Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc156.txt
    Spyware:Cookie/Azjmp Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc157.txt
    Spyware:Cookie/Belnk Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc158.txt
    Spyware:Cookie/GoStats Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc159.txt
    Spyware:Cookie/360i Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc160.txt
    Spyware:Cookie/did-it Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc161.txt
    Spyware:Cookie/Belnk Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc162.txt
    Spyware:Cookie/GoStats Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc163.txt
    Spyware:Cookie/go Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc164.txt
    Spyware:Cookie/Kount Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc165.txt
    Spyware:Cookie/Qsrch Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc166.txt
    Spyware:Cookie/Rn11 Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc167.txt
    Spyware:Cookie/Searchportal Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc168.txt
    Spyware:Cookie/techtarget Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc169.txt
    Spyware:Cookie/Seeq Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc170.txt
    Spyware:Cookie/Tucows Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc171.txt
    Spyware:Cookie/Versiontracker Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc172.txt
    Spyware:Cookie/Seeq Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc173.txt
    Spyware:Spyware/BetterInet Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc177.inf
    Spyware:Spyware/BetterInet Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc178.inf
    Potentially unwanted tool:Application/HideWindow.A Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc180.exe
    Potentially unwanted tool:Application/KillApp.B Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc181.exe
    Potentially unwanted tool:Application/KillApp.A Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc182.exe
    Adware:Adware/SAHAgent Not disinfected C:\RECYCLER\S-1-5-21-1666441617-2075934254-3724457266-1003\Dc185.dll
    Spyware:Spyware/BetterInet Not disinfected C:\WINDOWS\Downloaded Program Files\flash.inf

    I also downloaded and ran Highjackthis and here is the log:
    (Is there a nerwer version? I downloaded this one from their web site but it might be outdated. I did not see any way to update it. When I tried to download it from a different link, I got a message that the 'certificate' was not valid, or something like that so I didn't download it.)

    Logfile of HijackThis v1.99.1
    Scan saved at 11:45:29 PM, on 1/24/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\CallWave\IAM.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
    C:\Program Files\EarthLink TotalAccess\FastLane\IPClient.exe
    C:\Program Files\Netscape\Netscape\Netscp.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie...ton/search.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\prefs.js)
    N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_04.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\kwlau70i.slt\prefs.js)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
    O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [MoneyStartUp10.0] "c:\Program Files\Microsoft Money\System\Activation.exe"
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [BlockTracker] c:\hp\bin\BlockTracker.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: CallWave.lnk = C:\Program Files\CallWave\IAM.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta...staller_gmn.cab
    O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.pcpitstop.com/pestscan/pestscan.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120...all/xscan53.cab
    O16 - DPF: {75565ED2-1560-4F15-B841-20358DE6A0D1} (ImageControl Class) - http://content.ancestry.com/asfiles/files/...ll/MFImgVwr.cab
    O16 - DPF: {861DB4B6-3838-11D2-8E50-002018200E57} (MrSIDI Control) - http://images.myfamily.net/isfiles/downloads/MrSIDI.cab
    O16 - DPF: {89D75D39-5531-47BA-9E4F-B346BA9C362C} (CWDL_DownLoadControl Class) - http://www.callwave.com/include/cab/CWDL_DownLoad.CAB
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {D68217F4-1DF9-45C1-BFA6-61DBD5464527} (Genealogy Browser) -
    O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://pcpitstop.com/antivirus/PitPav.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{6BC9C8B1-24AD-4FEC-9C01-0D42382F7467}: NameServer =
    O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer =
    O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer =
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
    O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

    I'm at a total loss as to what any of this is or what it is doing to my computer. Your help is GREATLY appreciated!!
  2. Cheeseball81

    Cheeseball81 Retired Moderator

    Mar 3, 2004
    Download KillBox here: http://www.downloads.subratam.org/KillBox.exe
    Save it to your desktop.
    DO NOT run it yet.

    Rescan with Hijack This.
    Close all browser windows except Hijack This.
    Put a check mark beside these entries and click "Fix Checked".

    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

    Boot into Safe Mode (start tapping the F8 key at Startup, before the Windows logo screen)

    * Double-click on Killbox.exe to run it.

    Put a tick by Standard File Kill.
    In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time:

    C:\WINDOWS\Downloaded Program Files\flash.inf

    Click on the button that has the red circle with the X in the middle after you enter each file.
    It will ask for confirmation to delete the file.
    Click Yes.
    Continue with that procedure until you have pasted all of these in the "Paste Full Path of File to Delete" box.
    Killbox may tell you that one or more files do not exist.
    If that happens, just continue on with all the files. Be sure you don't miss any.
    Next in Killbox go to Tools > Delete Temp Files
    In the window that pops up, put a check by ALL the options there except these three:
    XP Prefetch

    Now click the Delete Selected Temp Files button.
    Exit the Killbox.

    Finally go to Control Panel > Internet Options.
    On the General tab under "Temporary Internet Files" Click "Delete Files".
    Put a check by "Delete Offline Content" and click OK.
    Click on the Programs tab then click the "Reset Web Settings" button.
    Click Apply then OK.

    Empty the Recycle Bin.


    Download the Hoster from here:
    Run Hoster and press Restore Original Hosts, OK, and Exit Program.

    NOTE: If you use a customized hosts file to block certain sites, then this will overwrite all those entries as well and you will need to re-enter them.

    Post a new Hijack This log.
  3. 202e

    202e Thread Starter

    Dec 30, 2002

    Thank you SO MUCH for your reply!! I have a couple of questions though.

    1. When I downloaded the killbox.exe and opened it, I got a message saying that it could not be verified and was by an unknown author. That bothers me and doesn't sound like something I should trust!! Is this the way it is supposed to be and is it actually ok?? Or should I download it from somewhere else and get a verified one?

    2. What are "hosts", like you mention at the end of your email? How do I know if I have 'customized ones'??

    3. I have done some searching on the internet about killbox and wonder how risky it is to use on my computer. Can you assure me that nothing will get messed up if I use it as you direct me?

    Thanks again!
  4. Cheeseball81

    Cheeseball81 Retired Moderator

    Mar 3, 2004
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/437308

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice