Solved: pls help.....i got infected

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

prophercer

Thread Starter
Joined
Dec 25, 2003
Messages
157
Hi.folks pls help. i went to some chinese websites and download some softwares and in the end got infected.my pc was shut down at ist and i restart and quickly delete those programs.my desktop keep changing.the folders i got after infected are DoDoorRSSFinder,pcast.IE - BAR and HuaCi

below is a list of my Hijackthis log.
Logfile of HijackThis v1.98.0
Scan saved at 7:44:48 AM, on 7/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\LoadPlugin.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~1.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\ProxyWay\proxyway.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgwb.dat
C:\unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com.sg/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\E26Start.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\inituser.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\IEHelper_4795.dll
O2 - BHO: IE Address Browser Helper - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:\Program Files\SearchNet\SNHpr.dll (file missing)
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\unzipped\Norton AntiVirus 2004 Pro FINAL\Norton.Antivirus.2004.PRO FINAL\NAV\EXTERNAL\NORTON\APP\NAVShExt.dll
O2 - BHO: Letscool System Helper - {F0C15012-7DBD-4068-95A2-0A82DB03AC35} - C:\WINDOWS\system32\CoolBho.dll
O2 - BHO: IEHlprObj Class - {F5B3ECED-9BF3-4f7e-882B-A6E75343C499} - C:\Progra~1\NetMeeting\netinit.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\unzipped\Norton AntiVirus 2004 Pro FINAL\Norton.Antivirus.2004.PRO FINAL\NAV\EXTERNAL\NORTON\APP\NAVShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn0\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int113777.exe -auto
O4 - HKLM\..\Run: [win32] winhost.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Registry Crawler] C:\PROGRA~1\RCRAWLER\RCrawler.exe -TRAYONLY
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [spoolsv] C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer
O4 - HKLM\..\Run: [] C:\WINDOWS\system32\E26Start.exe
O4 - HKLM\..\Run: [LetsCool] C:\Program Files\LetsCool\LetsCool.exe
O4 - HKLM\..\Run: [xw7i] RunDll32 "C:\WINDOWS\Downlo~1\xw7i.dll",Run
O4 - HKLM\..\RunServices: [win32] winhost.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe
O4 - HKCU\..\Run: [caishowmanage] C:\Program Files\CaiShow Tech\CaiShow\UpdateManager.EXE
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120338589703
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocx
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {87CCFDB0-C4BE-4BC2-A78C-9EAA7CF96667} (pcastup Class) - http://ps.itv.mop.com/dn/files/vodupdate_1.0.0.8_20051009.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) - http://ps.itv.mop.com/dn/files/pCastCtl_1.0.0.75_20051031.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll"

pls help!!!!!!!!
 

JSntgRvr

José
Retired Moderator and Malware Specialist
Joined
Jul 1, 2003
Messages
18,552
Hi, prophercer.

Welcome to TSG.

Your Hijackthis is outdated.

* Click here to download HJTsetup.exe
  • Save HJTsetup.exe to your desktop.
  • Doubleclick on the HJTsetup.exe icon on your desktop.
  • By default it will install to C:\Program Files\Hijack This.
  • Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
  • Put a check by Create a desktop icon then click Next again.
  • Continue to follow the rest of the prompts from there.
  • At the final dialogue box click Finish and it will launch Hijack This.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
 

prophercer

Thread Starter
Joined
Dec 25, 2003
Messages
157
using AVG anti virus software..i found the follwing virus

Trojan horse Dropper.Small.19.AO C:\Documents and Settings\fai\Local Settings\Temporary Internet Files\Content.IE5\XTRXIRRW\20060708[1].exe 7/23/2006 6:35 20060708[1].exe 2.77 MB

Trojan horse Downloader.Agent.EDZ C:\Program Files\Internet Explorer\LoadDriver.exe 7/23/2006 6:38 LoadDriver.exe 100 KB

Trojan horse Generic.XLX C:\WINDOWS\System32\msicn\plugins\bse.dll 7/23/2006 6:38 bse.dll 92 KB

Trojan horse Downloader.Agent.EHU C:\WINDOWS\System32\VIPTray.exe 7/23/2006 6:39 VIPTray.exe 124 KB

Trojan horse PSW.Agent.BXK C:\Documents and Settings\fai\Local Settings\Temp\s5wg\ServeHost.exe 7/23/2006 6:50 ServeHost.exe 52 KB

Trojan horse Generic.XLX C:\WINDOWS\System32\MSICN\plugins\bse.dll 7/23/2006 7:22 bse.dll 92 KB
 

prophercer

Thread Starter
Joined
Dec 25, 2003
Messages
157
Logfile of HijackThis v1.99.1
Scan saved at 8:29:32 AM, on 7/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\LoadPlugin.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~1.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\ProxyWay\proxyway.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgwb.dat
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com.sg/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\E26Start.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\inituser.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\IEHelper_4644.dll
O2 - BHO: IE Address Browser Helper - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:\Program Files\SearchNet\SNHpr.dll (file missing)
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ActiveBHO Class - {63C55A7F-6E29-8D4F-5C76-4F850F28D13A} - C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\unzipped\Norton AntiVirus 2004 Pro FINAL\Norton.Antivirus.2004.PRO FINAL\NAV\EXTERNAL\NORTON\APP\NAVShExt.dll
O2 - BHO: Letscool System Helper - {F0C15012-7DBD-4068-95A2-0A82DB03AC35} - C:\WINDOWS\system32\CoolBho.dll
O2 - BHO: IEHlprObj Class - {F5B3ECED-9BF3-4f7e-882B-A6E75343C499} - C:\Progra~1\NetMeeting\netinit.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\unzipped\Norton AntiVirus 2004 Pro FINAL\Norton.Antivirus.2004.PRO FINAL\NAV\EXTERNAL\NORTON\APP\NAVShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn0\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int113777.exe -auto
O4 - HKLM\..\Run: [win32] winhost.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Registry Crawler] C:\PROGRA~1\RCRAWLER\RCrawler.exe -TRAYONLY
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [spoolsv] C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer
O4 - HKLM\..\Run: [] C:\WINDOWS\system32\E26Start.exe
O4 - HKLM\..\Run: [LetsCool] C:\Program Files\LetsCool\LetsCool.exe
O4 - HKLM\..\Run: [xw7i] RunDll32 "C:\WINDOWS\Downlo~1\xw7i.dll",Run
O4 - HKLM\..\RunServices: [win32] winhost.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe
O4 - HKCU\..\Run: [caishowmanage] C:\Program Files\CaiShow Tech\CaiShow\UpdateManager.EXE
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120338589703
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocx
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {87CCFDB0-C4BE-4BC2-A78C-9EAA7CF96667} (pcastup Class) - http://ps.itv.mop.com/dn/files/vodupdate_1.0.0.8_20051009.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) - http://ps.itv.mop.com/dn/files/pCastCtl_1.0.0.75_20051031.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: ComPlusSetup - C:\WINDOWS\System32\catsrvut.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (file missing)
O23 - Service: ClipBoard - Unknown owner - C:\WINDOWS\system32\LoadPlugin.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Remote Log - Unknown owner - C:\WINDOWS\system32\ServeHost.exe (file missing)
O23 - Service: SAVScan - Unknown owner - C:\Program Files\Norton AntiVirus\SAVScan.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)
 

JSntgRvr

José
Retired Moderator and Malware Specialist
Joined
Jul 1, 2003
Messages
18,552
Hi, prophercer. :)

Using the Norton Removal Tool

Please click here and follow the instructions therein to completely remove Norton Antivirus from your computer.

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only

  • Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Please download ewido anti-spyware from HERE and save that file to your desktop.
This is a 30 day trial of the program
  1. Once you have downloaded ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
  2. Once the setup is complete you will need run ewido and update the definition files.
  3. On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  4. Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  6. Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly in Safe Mode.

Now copy these instructions to notepad and save them to your desktop. You will need them to refer to in safe mode.

Boot into Safe Mode:

Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Perform the following steps in safe mode:

IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  • Close ewido .
Restart back into Windows normally now.

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post a fresh Hijackthis log along with the Ewido and ActiveScan reports.
 

prophercer

Thread Starter
Joined
Dec 25, 2003
Messages
157
Logfile of HijackThis v1.99.1
Scan saved at 10:56:35 AM, on 7/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\LoadPlugin.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~1.EXE
C:\Program Files\LetsCool\LetsCool.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\ProxyWay\proxyway.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com.sg/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\E26Start.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\inituser.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\IEHelper_4795.dll (file missing)
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ActiveBHO Class - {63C55A7F-6E29-8D4F-5C76-4F850F28D13A} - C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll (file missing)
O2 - BHO: Letscool System Helper - {F0C15012-7DBD-4068-95A2-0A82DB03AC35} - C:\WINDOWS\system32\CoolBho.dll
O2 - BHO: IEHlprObj Class - {F5B3ECED-9BF3-4f7e-882B-A6E75343C499} - C:\Progra~1\NetMeeting\netinit.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn0\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int113777.exe -auto
O4 - HKLM\..\Run: [win32] winhost.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Registry Crawler] C:\PROGRA~1\RCRAWLER\RCrawler.exe -TRAYONLY
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [LetsCool] C:\Program Files\LetsCool\LetsCool.exe
O4 - HKLM\..\Run: [xw7i] RunDll32 "C:\WINDOWS\Downlo~1\xw7i.dll",Run
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [MoveSearch] C:\Program Files\HuaCi\huaci\zsearch.exe
O4 - HKLM\..\Run: [] C:\WINDOWS\system32\E26Start.exe
O4 - HKLM\..\RunServices: [win32] winhost.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe
O4 - HKCU\..\Run: [caishowmanage] C:\Program Files\CaiShow Tech\CaiShow\UpdateManager.EXE
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: »®´ÊËÑË÷.lnk = C:\Program Files\HuaCi\huaci\zsearch.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120338589703
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocx
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {87CCFDB0-C4BE-4BC2-A78C-9EAA7CF96667} (pcastup Class) - http://ps.itv.mop.com/dn/files/vodupdate_1.0.0.8_20051009.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) - http://ps.itv.mop.com/dn/files/pCastCtl_1.0.0.75_20051031.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: ComPlusSetup - C:\WINDOWS\System32\catsrvut.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ClipBoard - Unknown owner - C:\WINDOWS\system32\LoadPlugin.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Remote Log - Unknown owner - C:\WINDOWS\system32\ServeHost.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)
 

prophercer

Thread Starter
Joined
Dec 25, 2003
Messages
157
Activescan report

Incident Status Location

Adware:adware/igetnet Not disinfected c:\windows\system\rules.dat
Adware:adware/clocksync Not disinfected c:\windows\downloaded program files\ClockSyncInst.inf
Adware:adware/virtualbouncer Not disinfected c:\windows\downloaded program files\VbouncerOuter1124030508.exe
Spyware:application/bestoffer Not disinfected c:\windows\smdat32m.sys
Adware:adware/xupiter Not disinfected C:\Documents and Settings\fai\Favorites\Cool Stuff
Spyware:spyware/escorcher Not disinfected Windows Registry
Adware:adware/diytoolbar Not disinfected Windows Registry
Adware:adware/pigsearch Not disinfected Windows Registry
Adware:adware/fastlook Not disinfected Windows Registry
Adware:adware/dudu Not disinfected Windows Registry
Potentially unwanted tool:application/altnet Not disinfected hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\AltnetDM
Adware:adware/ncase Not disinfected Windows Registry
Adware:Adware Program Not disinfected C:\WINDOWS\Downloaded Program Files\test.INF
Hacktool:HackTool/EvID Not disinfected C:\Program Files\Common Files\Synacast\SynaLive\EvID4226Patch.exe
Hacktool:HackTool/EvID Not disinfected C:\Program Files\PPLive TV\SynaLiveSetup.exe[EvID4226Patch.exe]
Adware:Adware/WSearch Not disinfected C:\Program Files\HuaCi\huaci\Mouse1.dll
Adware:Adware/WSearch Not disinfected C:\Program Files\HuaCi\huaci\SearchM.dll
Adware:Adware/WSearch Not disinfected C:\Program Files\HuaCi\huaci\zsup.exe
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\fai\Cookies\[email protected]ola[1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\fai\Cookies\[email protected][2].txt
 

prophercer

Thread Starter
Joined
Dec 25, 2003
Messages
157
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 10:17:51 AM 7/23/2006

+ Scan result:



C:\WINDOWS\SYSTEM32\wuwebex.dll -> Adware.Accelerator : Cleaned with backup (quarantined).
C:\Program Files\NetMeeting\nmview.dll -> Adware.AdMedia : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1116\ntjdo\ntjcn.emm -> Adware.AllSum : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1116\tqppmtw\tqppmtw.fyf -> Adware.AllSum : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\msicn\msibm.dll -> Adware.AllSum : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\spoolsv\spoolsv.exe -> Adware.AllSum : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\shdocvw2.dll -> Adware.Baidu : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Bargain Buddy -> Adware.BargainBuddy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1 -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
C:\Documents and Settings\fai\tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007862.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007864.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007871.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007872.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008915.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008917.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008921.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008922.exe -> Adware.Dm : Error during cleaning.
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009857.exe/tool.exe -> Adware.Dm : Error during cleaning.
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009859.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009867.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009868.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010866.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010867.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011136.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011153.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\caishow.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tool6.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tool9.exe/tool.exe -> Adware.Dm : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\wmpcda.exe -> Adware.Dmad : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0006873.exe -> Adware.Dmedia : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{0A00D11E-B1E7-44b5-AD88-C9190876AAC4} -> Adware.Dyibar : Cleaned with backup (quarantined).
HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\eScorcher -> Adware.eScorcher : Cleaned with backup (quarantined).
HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\eScorcher\General -> Adware.eScorcher : Cleaned with backup (quarantined).
HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\eScorcher\URL1 -> Adware.eScorcher : Cleaned with backup (quarantined).
HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\eScorcher\URL2 -> Adware.eScorcher : Cleaned with backup (quarantined).
HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\eScorcher\URL3 -> Adware.eScorcher : Cleaned with backup (quarantined).
HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\eScorcher\URL4 -> Adware.eScorcher : Cleaned with backup (quarantined).
HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\eScorcher\URL5 -> Adware.eScorcher : Cleaned with backup (quarantined).
HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\eScorcher\debug -> Adware.eScorcher : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{2A0176FE-008B-4706-90F5-BBA532A49731} -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0176FE-008B-4706-90F5-BBA532A49731} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1957994488-1580818891-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A0176FE-008B-4706-90F5-BBA532A49731} -> Adware.Generic : Cleaned with backup (quarantined).
C:\Program Files\DoDoorRSSFinder\ActiveBandObject.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\Program Files\DoDoorRSSFinder\BandObjs.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\Program Files\NetMeeting\netinit.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007857.exe -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007870.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008912.exe -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008920.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009854.exe -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009866.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010868.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010874.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010882.exe -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010883.exe -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011121.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\IEHelper_4644.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\IEHelper_4708.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\IEHelper_4795.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\RssInstaller.exe -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\dllcache\netup.dll -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\inituser.exe -> Adware.IEHlpr : Cleaned with backup (quarantined).
HKLM\SOFTWARE\PerfectNav -> Adware.KeenValue : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009852.exe -> Adware.Netw : Cleaned with backup (quarantined).
C:\WINDOWS\estAlive.dll -> Adware.Netw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP56\snapshot\MFEX-3.DAT -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP56\snapshot\MFEX-4.DAT -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP57\snapshot\MFEX-3.DAT -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP57\snapshot\MFEX-4.DAT -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP68\A0005247.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP68\A0005253.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP68\A0005254.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP68\A0005255.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP68\A0005256.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP69\A0005546.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\Program Files\HuaCi\huaci\Mouse1.dll -> Adware.WSearch : Error during cleaning.
C:\Program Files\HuaCi\huaci\SearchM.dll -> Adware.WSearch : Error during cleaning.
C:\Program Files\HuaCi\huaci\abhcop.sys -> Adware.WSearch : Error during cleaning.
C:\Program Files\HuaCi\huaci\mUin.exe -> Adware.WSearch : Error during cleaning.
C:\Program Files\HuaCi\huaci\reg.exe/DeskUn.exe -> Adware.WSearch : Error during cleaning.
C:\Program Files\HuaCi\huaci\zsearch.exe -> Adware.WSearch : Error during cleaning.
C:\Program Files\HuaCi\huaci\zsup.exe -> Adware.WSearch : Error during cleaning.
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007847.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007848.dll -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007850.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007859.exe/Mouse1.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007859.exe/SearchM.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007859.exe/abhcop.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007859.exe/hcalway.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007859.exe/mUin.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007859.exe/zsearch.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0007859.exe/zsup.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008893.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008894.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008895.dll -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008897.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008898.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008904.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008913.exe/Mouse1.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008913.exe/SearchM.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008913.exe/abhcop.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008913.exe/hcalway.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008913.exe/mUin.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008913.exe/zsearch.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008913.exe/zsup.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009855.exe/Mouse1.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009855.exe/SearchM.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009855.exe/abhcop.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009855.exe/hcalway.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009855.exe/mUin.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009855.exe/zsearch.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009855.exe/zsup.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009871.dll -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0009872.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010853.exe/Mouse1.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010853.exe/SearchM.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010853.exe/abhcop.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010853.exe/hcalway.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010853.exe/mUin.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010853.exe/zsearch.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010853.exe/zsup.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010858.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010859.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010860.dll -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010862.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010863.EXE -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010876.dll -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010877.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010879.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0010880.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011112.exe/Mouse1.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011112.exe/SearchM.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011112.exe/abhcop.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011112.exe/hcalway.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011112.exe/mUin.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011112.exe/zsearch.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011112.exe/zsup.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011149.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011155.dll -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0011156.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\DRIVERS\hcalway.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\DRIVERS\s5wg.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tool4.exe/Mouse1.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tool4.exe/SearchM.dll.zgx -> Adware.WSearch : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tool4.exe/abhcop.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tool4.exe/hcalway.sys -> Adware.WSearch : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tool4.exe/mUin.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tool4.exe/zsearch.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tool4.exe/zsup.exe -> Adware.WSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008905.exe -> Adware.Zhongsou : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\DialerX.ocx -> Dialer.Telemedia.b : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\E26Start.exe -> Downloader.Delf.ald : Cleaned with backup (quarantined).
C:\Program Files\pcast\PodcastbarMini\update.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7A3291A4-4BCF-484A-8C40-817F6C064B7C}\RP80\A0008926.rbf -> Downloader.Small : Cleaned with backup (quarantined).
C:\Program Files\starhub\starhub.exe -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\windrvNT.sys -> Rootkit.NtRootKit.131 : Cleaned with backup (quarantined).
:mozilla.23:C:\Documents and Settings\fai\Application Data\Mozilla\Firefox\Profiles\rdq0dy4k.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).


::Report end
 

JSntgRvr

José
Retired Moderator and Malware Specialist
Joined
Jul 1, 2003
Messages
18,552
Hi, prophercer :)

Please read this post completely, it may make it easier for you if you copy and paste this post to a new text document or print it for reference later.

This will likely be a few step process in removing the malware that has infected your system. I encourage you to stick with it and follow my directions as closely as possible so as to avoid complicating the problem further.

Please download the Killbox by Option^Explicit.

Note: In the event you already have Killbox, this is a new version that I need you to download.
  • Save it to your desktop.

The steps that I am about to suggest involve modifying the registry. Modifying the registry can be dangerous so we will make a backup of the registry first.
Modification of the registry can be EXTREMELY dangerous if you do not know exactly what you are doing so follow the steps that are listed below EXACTLY. if you cannot preform some of these steps or if you have ANY questions please ask BEFORE proceeding.

Backing Up Your Registry
  1. Go Here and download ERUNT
    (ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)
  2. Install ERUNT by following the prompts
    (use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)
  3. Start ERUNT
    (either by double clicking on the desktop icon or choosing to start the program at the end of the setup)
  4. Choose a location for the backup
    (the default location is C:\WINDOWS\ERDNT which is acceptable).
  5. Make sure that at least the first two check boxes are ticked
  6. Press OK
  7. Press YES to create the folder.
Registry Modifications

Download the enclosed file and extract its contents to the desktop. It is a registry entries file, Shellfix.reg. Do nothing with it yet.

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\WINDOWS\Profiles\All Users\Application Data\Microsoft\IEHelper\IEHelper_4795.dll (file missing)
O2 - BHO: IEHlprObj Class - {F5B3ECED-9BF3-4f7e-882B-A6E75343C499} - C:\Progra~1\NetMeeting\netinit.dll (file missing)
O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int113777.exe -auto
O4 - HKLM\..\Run: [win32] winhost.exe
O4 - HKLM\..\Run: [xw7i] RunDll32 "C:\WINDOWS\Downlo~1\xw7i.dll",Run
O4 - HKLM\..\Run: [MoveSearch] C:\Program Files\HuaCi\huaci\zsearch.exe
O4 - HKLM\..\Run: [] C:\WINDOWS\system32\E26Start.exe
O4 - HKLM\..\RunServices: [win32] winhost.exe
O4 - HKCU\..\Run: [caishowmanage] C:\Program Files\CaiShow Tech\CaiShow\UpdateManager.EXE
O4 - Startup: »®´ÊËÑË÷.lnk = C:\Program Files\HuaCi\huaci\zsearch.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) - http://ps.itv.mop.com/dn/files/pCast...5_20051031.cab

Now close all windows and browsers, other than HiJackThis, then click Fix Checked.

Close Hijackthis.

Double click on the Shellfix.reg file and select Yes when prompted to merge it into your registry.

Go to Start->Run, type CMD and click Ok. The MSDOS window will be displayed. At the prompt type the following and press Enter after each line:

SC Stop "Symantec Core LC"
SC Delete "Symantec Core LC"
Exit

  • Please double-click Killbox.exe to run it.
  • Select:
    • Delete on Reboot
    • then Click on the All Files button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\winhost.exe
    C:\WINDOWS\winhost.exe
    C:\WINDOWS\downloaded program files\xw7i.dll
    C:\WINDOWS\system32\inituser.exe
    C:\WINDOWS\system32\E26Start.exe
    C:\WINDOWS\Downloaded Program Files\test.INF
    C:\Program Files\Common Files\Synacast\SynaLive\EvID4226Patch.exe
    C:\Program Files\PPLive TV\SynaLiveSetup.exe
    c:\windows\system\rules.dat
    c:\windows\downloaded program files\ClockSyncInst.inf
    c:\windows\downloaded program files\VbouncerOuter1124030508.exe
    c:\windows\smdat32m.sys
    C:\Documents and Settings\fai\Favorites\Cool Stuff\
    C:\Program Files\HuaCi\
    C:\Program Files\websx\
    C:\Program Files\CaiShow Tech\


  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
  • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).

If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

1. Launch Notepad, and copy/paste the contents of the quote box below into a new Notepad file. Save it with file name options.txt and save as file type: all files to your desktop.

RegSearch Options File

[Search]
escorcher
diytoolbar
pigsearch
fastlook
dudu
altnet
ncase

[Exclude]

[Options]
Filter=KVDLUI
2. Download Registry Search to your desktop.
  • Right click on the compressed RegSearch folder, and choose "Extract All". In the box that pops open, click "Next", then "Next" again, and then "Finish". You now have another RegSearch folder on your desktop.
  • Open the new folder, and double click on regsearch.exe
  • Click "Import" in the lower left corner and browse to the options.txt file that you just saved on your desktop. Do not choose the one in the RegSearch folder itself.
  • Click OK and Registry Search will scan your registry for the file(s), and a Notepad box will open with a report.
  • Please reply here with the entire contents of the Notepad file from RegSearch.

Also re-scan with Hijackthis and post a fresh log.
 

Attachments

prophercer

Thread Starter
Joined
Dec 25, 2003
Messages
157
REGEDIT4

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.1.0

; Results at 7/23/2006 8:17:37 PM for strings:
; 'escorcher'
; 'diytoolbar'
; 'pigsearch'
; 'fastlook'
; 'dudu'
; 'altnet'
; 'ncase'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SOFTWARE\Ahead\Nero - Burning Rom\Browser]
"ShowPureUpperNamesInDownCases"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\dudu]

[HKEY_LOCAL_MACHINE\SOFTWARE\dudu\pCast]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AltnetDM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DIYTOOLBARV1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DIYTOOLBARV1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DIYTOOLBARV1]
"DisplayName"="DIYTOOLBAR - Toolbar"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\Pcast\\VOD\\dudupros.exe"="C:\\Program Files\\Pcast\\VOD\\dudupros.exe:*:Enabled:dudupros"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\Pcast\\VOD\\dudupros.exe"="C:\\Program Files\\Pcast\\VOD\\dudupros.exe:*:Enabled:dudupros"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\Pcast\\VOD\\dudupros.exe"="C:\\Program Files\\Pcast\\VOD\\dudupros.exe:*:Enabled:dudupros"

[HKEY_USERS\S-1-5-21-1957994488-1580818891-839522115-1003\Software\ahead\Nero - Burning Rom\Browser]
"ShowPureUpperNamesInDownCases"=dword:00000000

[HKEY_USERS\S-1-5-21-1957994488-1580818891-839522115-1003\Software\DIYTOOLBAR]

[HKEY_USERS\S-1-5-21-1957994488-1580818891-839522115-1003\Software\DIYTOOLBAR\V1]

[HKEY_USERS\S-1-5-21-1957994488-1580818891-839522115-1003\Software\DIYTOOLBAR\V1\Historys1]

[HKEY_USERS\S-1-5-21-1957994488-1580818891-839522115-1003\Software\dudu]

[HKEY_USERS\S-1-5-21-1957994488-1580818891-839522115-1003\Software\dudu\pCast]

[HKEY_USERS\S-1-5-21-1957994488-1580818891-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Altnet]

; End Of The Log...
 

prophercer

Thread Starter
Joined
Dec 25, 2003
Messages
157
Logfile of HijackThis v1.99.1
Scan saved at 8:20:13 PM, on 7/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\LoadPlugin.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~1.EXE
C:\Program Files\LetsCool\LetsCool.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\ProxyWay\proxyway.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com.sg/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ActiveBHO Class - {63C55A7F-6E29-8D4F-5C76-4F850F28D13A} - C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll (file missing)
O2 - BHO: Letscool System Helper - {F0C15012-7DBD-4068-95A2-0A82DB03AC35} - C:\WINDOWS\system32\CoolBho.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn0\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Registry Crawler] C:\PROGRA~1\RCRAWLER\RCrawler.exe -TRAYONLY
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~2\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [LetsCool] C:\Program Files\LetsCool\LetsCool.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120338589703
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocx
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {87CCFDB0-C4BE-4BC2-A78C-9EAA7CF96667} (pcastup Class) - http://ps.itv.mop.com/dn/files/vodupdate_1.0.0.8_20051009.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: ComPlusSetup - C:\WINDOWS\System32\catsrvut.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ClipBoard - Unknown owner - C:\WINDOWS\system32\LoadPlugin.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Remote Log - Unknown owner - C:\WINDOWS\system32\ServeHost.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
 

JSntgRvr

José
Retired Moderator and Malware Specialist
Joined
Jul 1, 2003
Messages
18,552
Hi, prophercer :)

The steps that I am about to suggest involve modifying the registry. Modifying the registry can be dangerous so we will make a backup of the registry first.
Modification of the registry can be EXTREMELY dangerous if you do not know exactly what you are doing so follow the steps that are listed below EXACTLY. if you cannot preform some of these steps or if you have ANY questions please ask BEFORE proceeding.

Backing Up Your Registry
  1. Go Here and download ERUNT
    (ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)
  2. Install ERUNT by following the prompts
    (use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)
  3. Start ERUNT
    (either by double clicking on the desktop icon or choosing to start the program at the end of the setup)
  4. Choose a location for the backup
    (the default location is C:\WINDOWS\ERDNT which is acceptable).
  5. Make sure that at least the first two check boxes are ticked
  6. Press OK
  7. Press YES to create the folder.
Registry Modifications

Download the enclosed file and extract its contents to the desktop. It is a registry entries file, Regfix.reg. Once extracted doubleclick on the Regfix.reg file and select Yes when propted to merge it into your registry.

1. Please download The Avenger by Swandog46 to your Desktop.
  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop

2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Files to delete:
C:\WINDOWS\system32\winhost.exe
C:\WINDOWS\winhost.exe
C:\WINDOWS\downloaded program files\xw7i.dll
C:\WINDOWS\system32\inituser.exe
C:\WINDOWS\system32\E26Start.exe
C:\WINDOWS\Downloaded Program Files\test.INF
C:\Program Files\Common Files\Synacast\SynaLive\EvID4226Patch.exe
C:\Program Files\PPLive TV\SynaLiveSetup.exe
c:\windows\system\rules.dat
c:\windows\downloaded program files\ClockSyncInst.inf
c:\windows\downloaded program files\VbouncerOuter1124030508.exe
c:\windows\smdat32m.sys

Folders to delete:
C:\Documents and Settings\fai\Favorites\Cool Stuff
C:\Program Files\HuaCi
C:\Program Files\websx
C:\Program Files\CaiShow Tech
C:\Program Files\Pcast

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.
  • Under "Script file to execute" choose "Input Script Manually".
  • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
  • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
  • Click Done
  • Now click on the Green Light to begin execution of the script
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log by using Add/Reply

How is the computer doing?
 

Attachments

prophercer

Thread Starter
Joined
Dec 25, 2003
Messages
157
ogfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\tqxfomub

*******************

Script file located at: \??\C:\Program Files\mjjxnesp.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



File C:\WINDOWS\system32\winhost.exe not found!
Deletion of file C:\WINDOWS\system32\winhost.exe failed!

Could not process line:
C:\WINDOWS\system32\winhost.exe
Status: 0xc0000034



File C:\WINDOWS\winhost.exe not found!
Deletion of file C:\WINDOWS\winhost.exe failed!

Could not process line:
C:\WINDOWS\winhost.exe
Status: 0xc0000034



File C:\WINDOWS\downloaded program files\xw7i.dll not found!
Deletion of file C:\WINDOWS\downloaded program files\xw7i.dll failed!

Could not process line:
C:\WINDOWS\downloaded program files\xw7i.dll
Status: 0xc0000034



File C:\WINDOWS\system32\inituser.exe not found!
Deletion of file C:\WINDOWS\system32\inituser.exe failed!

Could not process line:
C:\WINDOWS\system32\inituser.exe
Status: 0xc0000034



File C:\WINDOWS\system32\E26Start.exe not found!
Deletion of file C:\WINDOWS\system32\E26Start.exe failed!

Could not process line:
C:\WINDOWS\system32\E26Start.exe
Status: 0xc0000034



File C:\WINDOWS\Downloaded Program Files\test.INF not found!
Deletion of file C:\WINDOWS\Downloaded Program Files\test.INF failed!

Could not process line:
C:\WINDOWS\Downloaded Program Files\test.INF
Status: 0xc0000034



File C:\Program Files\Common Files\Synacast\SynaLive\EvID4226Patch.exe not found!
Deletion of file C:\Program Files\Common Files\Synacast\SynaLive\EvID4226Patch.exe failed!

Could not process line:
C:\Program Files\Common Files\Synacast\SynaLive\EvID4226Patch.exe
Status: 0xc0000034



File C:\Program Files\PPLive TV\SynaLiveSetup.exe not found!
Deletion of file C:\Program Files\PPLive TV\SynaLiveSetup.exe failed!

Could not process line:
C:\Program Files\PPLive TV\SynaLiveSetup.exe
Status: 0xc0000034



File c:\windows\system\rules.dat not found!
Deletion of file c:\windows\system\rules.dat failed!

Could not process line:
c:\windows\system\rules.dat
Status: 0xc0000034



File c:\windows\downloaded program files\ClockSyncInst.inf not found!
Deletion of file c:\windows\downloaded program files\ClockSyncInst.inf failed!

Could not process line:
c:\windows\downloaded program files\ClockSyncInst.inf
Status: 0xc0000034



File c:\windows\downloaded program files\VbouncerOuter1124030508.exe not found!
Deletion of file c:\windows\downloaded program files\VbouncerOuter1124030508.exe failed!

Could not process line:
c:\windows\downloaded program files\VbouncerOuter1124030508.exe
Status: 0xc0000034



File c:\windows\smdat32m.sys not found!
Deletion of file c:\windows\smdat32m.sys failed!

Could not process line:
c:\windows\smdat32m.sys
Status: 0xc0000034



Folder C:\Documents and Settings\fai\Favorites\Cool Stuff not found!
Deletion of folder C:\Documents and Settings\fai\Favorites\Cool Stuff failed!

Could not process line:
C:\Documents and Settings\fai\Favorites\Cool Stuff
Status: 0xc0000034

Folder C:\Program Files\HuaCi deleted successfully.


Folder C:\Program Files\websx not found!
Deletion of folder C:\Program Files\websx failed!

Could not process line:
C:\Program Files\websx
Status: 0xc0000034



Folder C:\Program Files\CaiShow Tech not found!
Deletion of folder C:\Program Files\CaiShow Tech failed!

Could not process line:
C:\Program Files\CaiShow Tech
Status: 0xc0000034

Folder C:\Program Files\Pcast deleted successfully.

Completed script processing.

*******************

Finished! Terminate.
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Top