View Full Version : Whenever I restart my computer
*Pleasant Tomorrow* 10-22-2005, 11:13 PM which lately is about 20 times a day, this muther pops up:
idctup20.exe Unable to locate componate
This application has failed to start because commcoss.dll was not found. Re-installing the application may fix this problem.
It's been doing this for quite awile, but being a computer moron I just let it go because it wasn't doing anything to it. Now my computer is freezing constantly, the icons are disappearing from my desktop and the windows won't minimize. I don't know if that's the problem because it wasn't doing anything before, but whether it is or not I don't know what to do. My computers too much of an ass right now for me to even get to click on any spyware things I have.
robyrob 10-22-2005, 11:23 PM which lately is about 20 times a day, this muther pops up:
idctup20.exe Unable to locate componate
This application has failed to start because commcoss.dll was not found. Re-installing the application may fix this problem.
It's been doing this for quite awile, but being a computer moron I just let it go because it wasn't doing anything to it. Now my computer is freezing constantly, the icons are disappearing from my desktop and the windows won't minimize. I don't know if that's the problem because it wasn't doing anything before, but whether it is or not I don't know what to do. My computers too much of an ass right now for me to even get to click on any spyware things I have.
i think that you've got some spyware junk left over in there - at least "commcoss.dll" is, but to get it to stop popping up every time, run HijackThis and post your log, or just remove the entry from the registry at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [intdctrr] C:\WINDOWS\System32\idctup20.exe
Jenya 10-22-2005, 11:40 PM I get an error alot when I'm on this forum using Firefox. It shuts down the browser and a pop-up window comes up and asks me what website I was at, and what error I keep getting. Then, I guess, it sends my complaint off to their website automatically.
This happens a lot, and I still get an error- even when I describe this in detail to them. :(
EmoJoe 10-22-2005, 11:48 PM That sort of sounds like what happened to my old computer. Yeah, we just gave up on it and got a new one, sorry, im not a big help...
robyrob 10-22-2005, 11:50 PM I get an error alot when I'm on this forum using Firefox. It shuts down the browser and a pop-up window comes up and asks me what website I was at, and what error I keep getting. Then, I guess, it sends my complaint off to their website automatically.
This happens a lot, and I still get an error- even when I describe this in detail to them. :(
what exactly are you doing when it happens?
have you tried creating a new profile to see if it fixes it? (close firefox, then type in firefox.exe -profilemanager into the Run command, then click on the Create Profile button - you can always switch back to your old profile afterwards)
Jenya 10-23-2005, 12:01 AM what exactly are you doing when it happens?
Just visiting, and quoting. Nothing fancey. I asked someone at work about this, and he told me to shut off the Firefox pop-up blocker option, and just download a seperate one. I did that today, and I don't have any problems so far. But if this happens again, I'll try your suggestion.
Thanks. :)
*Pleasant Tomorrow* 10-23-2005, 01:14 AM i think that you've got some spyware junk left over in there - at least "commcoss.dll" is, but to get it to stop popping up every time, run HijackThis and post your log, or just remove the entry from the registry at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [intdctrr] C:\WINDOWS\System32\idctup20.exe
What do you mean by 'post your log?'
*Pleasant Tomorrow* 10-23-2005, 05:52 PM *le bump*
robyrob 10-23-2005, 07:47 PM What do you mean by 'post your log?'
- download HijackThis! (http://tinyurl.com/ysp9h)
- click on the Do a system scan and save a logfile button
- it will open up the log in Notepad, do a CTRL + A to select all, and CTRL C to copy, then paste it into your post here with a CTRL + V
when it is time to "fix" the problem, you will need to click on the box at the front of each line that needs to be removed in the HijackThis window, then click on the "Fix Checked" button
*Pleasant Tomorrow* 10-23-2005, 08:11 PM Logfile of HijackThis v1.99.1
Scan saved at 8:09:00 PM, on 10/23/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\System32\AOLMSNGR.EXE
C:\WINNT\System32\actxprxy.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\WINNT\System32\2r261bh4.exe
C:\windows\mrjj.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINNT\System32\n?lookup.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mim.exe
C:\Program Files\sder\dees.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\AOL\1126391078\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1126391078\ee\AOLServiceHost.exe
C:\Program Files\Common Files\AOL\1126391078\ee\AOLServiceHost.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\DlenJ.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\VjrU.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINNT\System32\wuauclt.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\AIM+\AIM+.exe
C:\Program Files\AIM95\aim.exe
C:\program files\internet explorer\iexplore.exe
C:\Documents and Settings\Owner\Local Settings\Temp\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\about.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;dynhost.inetcam.com;register.inetcam.com;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
F2 - REG:system.ini: UserInit=C:\WINNT\System32\Userinit.exe
O1 - Hosts: indows.
O1 - Hosts: tyfind.com
O1 - Hosts: tyfind.com
O1 - Hosts: styfind.com
O1 - Hosts: styfind.com
O1 - Hosts: estyfind.com
O1 - Hosts: estyfind.com
O1 - Hosts: .zestyfind.com
O1 - Hosts: .zestyfind.com
O1 - Hosts: ww.zestyfind.com
O1 - Hosts: .com
O1 - Hosts: ww.zestyfind.com
O1 - Hosts: on.com
O1 - Hosts: 127.0.0.
O1 - Hosts: ind.com
O1 - Hosts: yfind.com
O1 - Hosts: styfind.com
O1 - Hosts: w.zestyfind.com
O1 - Hosts: 127.0
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CATLEvents Object - {55E301E5-BA44-4095-BB0B-14E0123CCF71} - C:\DOCUME~1\Owner\LOCALS~1\Temp\yek.dat
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {E7C11A5E-A2BB-824F-907D-DAC81E8E2C94} - C:\WINNT\System32\cgrg.dll
O2 - BHO: CATLEvents Object - {ED5ABC42-8E4F-4C39-9972-F0CF619D672F} - C:\DOCUME~1\Owner\LOCALS~1\Temp\niwnu.dat
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [intdctrr] C:\WINNT\System32\idctup20.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [GyArQRm] C:\documents and settings\owner\local settings\temp\GyArQRm.exe
O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\Cjp9g.exe
O4 - HKLM\..\Run: [AOL Instent Messenger] AOLMSNGR.EXE
O4 - HKLM\..\Run: [To] C:\documents and settings\owner\local settings\temp\To.exe
O4 - HKLM\..\Run: [da] C:\documents and settings\owner\local settings\temp\da.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe
O4 - HKLM\..\Run: [31c696a648aa] C:\WINNT\System32\actxprxy.exe
O4 - HKLM\..\Run: [*WindowsUpd1] C:\WINNT\WindowsUpd1.exe
O4 - HKLM\..\Run: [*tapieula] C:\WINNT\repair\tapieula.exe
O4 - HKLM\..\Run: [*msdisk] C:\WINNT\msagent\chars\msdisk.exe
O4 - HKLM\..\Run: [*olecr] C:\WINNT\Web\printers\olecr.exe
O4 - HKLM\..\Run: [*key] C:\WINNT\Config\key.exe
O4 - HKLM\..\Run: [*unwin] C:\WINNT\Driver Cache\unwin.exe
O4 - HKLM\..\Run: [2MJ] C:\documents and settings\owner\local settings\temp\2MJ.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1126391078\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [2r261bh4] C:\WINNT\System32\2r261bh4.exe
O4 - HKLM\..\Run: [noC=] C:\windows\mrjj.exe
O4 - HKCU\..\Run: [SysUpd] C:\WINNT\WindowsUpd1.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [Jmlhod] C:\WINNT\System32\n?lookup.exe
O4 - HKCU\..\Run: [Ltho] "C:\Program Files\sder\dees.exe" -vt rbnd
O4 - HKCU\..\RunOnce: [AOL Instent Messenger] AOLMSNGR.EXE
O4 - Startup: Download Plus.lnk = C:\Documents and Settings\Owner\Application Data\DownloadPlus.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINNT\System32\maxspeed.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINNT\System32\maxspeed.exe
O9 - Extra button: Whistle - {220E39C3-B081-4719-AB1A-9A884DCBD05C} - C:\Progra~1\whistlesoftware\WselServices\webband.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROProj.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab
O16 - DPF: {12589FA1-C456-11CE-BF01-10AA1055595A} - http://www.wsel.net/imcupdatefiles/whistlesilent610.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab28578.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/bestfriends/retro64_loader.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {7149E79C-DC19-4C5E-A53C-A54DDF75EEE9} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/joysaver.cab
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} (MSN Chat Control 4.2) - http://fdl.msn.com/public/chat/msnchat42.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab28578.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab28578.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab28578.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v5.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: PictureTaker - Unknown owner - c:\fixit\pt\PCTKRNT.SYS (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
Mmkaye, got it. Now you said to post it here?...
robyrob 10-23-2005, 08:54 PM Mmkaye, got it. Now you said to post it here?...
stuff to fix/remove:
Running processes: (you can't fix these with HijackThis, you'll need to close in task manager CTRL+ALT+DEL, or run your scans in SAFEMODE)
C:\WINNT\System32\actxprxy.exe - SPYWARE - run your Spybot and Adaware
C:\WINNT\System32\2r261bh4.exe - VIRUS - please update your AV software and run a scan
C:\windows\mrjj.exe - SPYWARE
C:\WINNT\System32\n?lookup.exe - SPYWARE
C:\Program Files\sder\dees.exe - SPYWARE
C:\Program Files\LimeWire\LimeWire.exe - PROBABLY THE CAUSE OF ALL THIS SPYWARE!!! :grr:
C:\WINNT\System32\DlenJ.exe - SPYWARE
C:\WINNT\System32\VjrU.exe - SPYWARE
C:\Program Files\AIM+\AIM+.exe - SPYWARE
Fix ALL of these items by checking them then click on "FIX CHECKED" in HijackThis
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;dynhost.inetcam.com;register.inetcam.com;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
F2 - REG:system.ini: UserInit=C:\WINNT\System32\Userinit.exe
O1 - Hosts: indows.
O1 - Hosts: tyfind.com
O1 - Hosts: tyfind.com
O1 - Hosts: styfind.com
O1 - Hosts: styfind.com
O1 - Hosts: estyfind.com
O1 - Hosts: estyfind.com
O1 - Hosts: .zestyfind.com
O1 - Hosts: .zestyfind.com
O1 - Hosts: ww.zestyfind.com
O1 - Hosts: .com
O1 - Hosts: ww.zestyfind.com
O1 - Hosts: on.com
O1 - Hosts: 127.0.0.
O1 - Hosts: ind.com
O1 - Hosts: yfind.com
O1 - Hosts: styfind.com
O1 - Hosts: w.zestyfind.com
O1 - Hosts: 127.0
O2 - BHO: CATLEvents Object - {55E301E5-BA44-4095-BB0B-14E0123CCF71} - C:\DOCUME~1\Owner\LOCALS~1\Temp\yek.dat
O2 - BHO: (no name) - {E7C11A5E-A2BB-824F-907D-DAC81E8E2C94} - C:\WINNT\System32\cgrg.dll
O2 - BHO: CATLEvents Object - {ED5ABC42-8E4F-4C39-9972-F0CF619D672F} - C:\DOCUME~1\Owner\LOCALS~1\Temp\niwnu.dat
O4 - HKLM\..\Run: [intdctrr] C:\WINNT\System32\idctup20.exe
O4 - HKLM\..\Run: [GyArQRm] C:\documents and settings\owner\local settings\temp\GyArQRm.exe
O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\Cjp9g.exe
O4 - HKLM\..\Run: [To] C:\documents and settings\owner\local settings\temp\To.exe
O4 - HKLM\..\Run: [da] C:\documents and settings\owner\local settings\temp\da.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe
O4 - HKLM\..\Run: [31c696a648aa] C:\WINNT\System32\actxprxy.exe
O4 - HKLM\..\Run: [*WindowsUpd1] C:\WINNT\WindowsUpd1.exe
O4 - HKLM\..\Run: [*tapieula] C:\WINNT\repair\tapieula.exe
O4 - HKLM\..\Run: [*msdisk] C:\WINNT\msagent\chars\msdisk.exe
O4 - HKLM\..\Run: [*olecr] C:\WINNT\Web\printers\olecr.exe
O4 - HKLM\..\Run: [*key] C:\WINNT\Config\key.exe
O4 - HKLM\..\Run: [*unwin] C:\WINNT\Driver Cache\unwin.exe
O4 - HKLM\..\Run: [2MJ] C:\documents and settings\owner\local settings\temp\2MJ.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1126391078\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [2r261bh4] C:\WINNT\System32\2r261bh4.exe
O4 - HKLM\..\Run: [noC=] C:\windows\mrjj.exe
O4 - HKCU\..\Run: [SysUpd] C:\WINNT\WindowsUpd1.exe
O4 - HKCU\..\Run: [Jmlhod] C:\WINNT\System32\n?lookup.exe
O4 - HKCU\..\Run: [Ltho] "C:\Program Files\sder\dees.exe" -vt rbnd
O4 - Startup: Download Plus.lnk = C:\Documents and Settings\Owner\Application Data\DownloadPlus.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINNT\System32\maxspeed.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINNT\System32\maxspeed.exe
O9 - Extra button: Whistle - {220E39C3-B081-4719-AB1A-9A884DCBD05C} - C:\Progra~1\whistlesoftware\WselServices\webband.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {12589FA1-C456-11CE-BF01-10AA1055595A} - http://www.wsel.net/imcupdatefiles/whistlesilent610.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/bestfriends/retro64_loader.dll
O16 - DPF: {7149E79C-DC19-4C5E-A53C-A54DDF75EEE9} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/joysaver.cab
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} (MSN Chat Control 4.2) - http://fdl.msn.com/public/chat/msnchat42.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v5.cab
O23 - Service: PictureTaker - Unknown owner - c:\fixit\pt\PCTKRNT.SYS (file missing)
...in other words, you have a TON of crap on there; after removing these items with Hijack this you are going to need to run CoolwebShredder (http://tinyurl.com/5lstv), AdAware (http://tinyurl.com/du0h) and Spybot (http://tinyurl.com/37t9f) in SAFEMODE (http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam) - it also looks like you've got VX2 on there, try downloading Adaware's tool for removing it (http://www.lavasoftusa.com/software/addons/vx2cleaner.shtml)
run ALL of those programs then reboot back into normal mode. run HijackThis again and post a new log to see what's left.
*Pleasant Tomorrow* 10-23-2005, 09:32 PM Thankssss Roby, this is really helping alot. Quick question...I'm not trying to restart in safemode...one of the steps is to go to System Configuration Utility...where's this? erm...
robyrob 10-23-2005, 09:40 PM Thankssss Roby, this is really helping alot. Quick question...I'm not trying to restart in safemode...one of the steps is to go to System Configuration Utility...where's this? erm...
to get there you go to the Run command on the Start menu (or hold down the Windows key and press the R) then type in msconfig and go to the Startup tab...
the problem is most of that spyware will just put itself back in there if you try to disable it from the System Configuration utility - you NEED to run CoolwebShredder and the VX2 cleaner, probably in safemode too.
*Pleasant Tomorrow* 10-23-2005, 09:42 PM to get there you go to the Run command on the Start menu (or hold down the Windows key and press the R) then type in msconfig and go to the Startup tab...
the problem is most of that spyware will just put itself back in there if you try to disable it from the System Configuration utility - you NEED to run CoolwebShredder and the VX2 cleaner, probably in safemode too.
Startup tag...erm...do you mind taking a screen cap?
ARgh, am I driving you crazy? I'm sorrrry :lol:
PZelda 10-23-2005, 09:50 PM Startup tag...erm...do you mind taking a screen cap?
ARgh, am I driving you crazy? I'm sorrrry :lol:
Roby is talking about this tab. The checked boxes are the programs (your printer, speakers, instant messaging programs, etc) that automatically start up when you start up your computer. It's a very helpful thing to have...Helps your computer start up faster.
robyrob 10-23-2005, 09:53 PM Startup tag...erm...do you mind taking a screen cap?
ARgh, am I driving you crazy? I'm sorrrry :lol:
Allison beat me to it but yeah :)
and no, you aren't bothering me - i already AM crazy :crazy: :p :sheep:
*Pleasant Tomorrow* 10-23-2005, 09:59 PM Roby is talking about this tab. The checked boxes are the programs (your printer, speakers, instant messaging programs, etc) that automatically start up when you start up your computer. It's a very helpful thing to have...Helps your computer start up faster.
How do I get to System Configuration Utility in the first place? I'm doung the run and typing in msconfig, then clicking okay...is there somewhere I'm supposed to go to get to SCU?
*Pleasant Tomorrow* 10-23-2005, 10:00 PM Allison beat me to it but yeah :)
and no, you aren't bothering me - i already AM crazy :crazy: :p :sheep:
lol okay, just makin' sure
*Pleasant Tomorrow* 10-23-2005, 10:02 PM Argh, I know the problem. As soon as you push enter after typing in msconfig its supposed to pop up...and it's not. It just did for a split second. Good Lord. :wallbang
robyrob 10-23-2005, 10:30 PM Argh, I know the problem. As soon as you push enter after typing in msconfig its supposed to pop up...and it's not. It just did for a split second. Good Lord. :wallbang
thats the spyware preventing you from opening it - you are going to have to do all of this in safemode - its the only way to make sure that all of that crap isn't still running
*Pleasant Tomorrow* 10-23-2005, 10:39 PM thats the spyware preventing you from opening it - you are going to have to do all of this in safemode - its the only way to make sure that all of that crap isn't still running
But arn't those steps to get into safemode in the first place? Is there another way to do it?
PZelda 10-23-2005, 10:49 PM But arn't those steps to get into safemode in the first place? Is there another way to do it?
Restart your computer -- you are on XP, so when your computer is starting up, hit the F8 key until it takes you to a screen where you can select 'Safe Mode' there. It will start up as it should, and you will know you are in safe mode because your desktop will have SAFE MODE printed in all four corners of the screen.
I would suggest you print out Roby's post with his directions in it NOW -- when you are working in safe mode, you won't be able to access the Internet.
robyrob 10-23-2005, 11:14 PM Restart your computer -- you are on XP, so when your computer is starting up, hit the F8 key until it takes you to a screen where you can select 'Safe Mode' there. It will start up as it should, and you will know you are in safe mode because your desktop will have SAFE MODE printed in all four corners of the screen.
I would suggest you print out Roby's post with his directions in it NOW -- when you are working in safe mode, you won't be able to access the Internet.
that and you dont WANT to connect to the internet until you have cleaned this stuff up - your hosts file has been hijacked and your security zones have been taken over - download and install Mike's Hosts file (http://tinyurl.com/coye), then while in safemode, open the Internet Options applet in the Control Panel, click on the 'Security' tab, click on 'Custom Level', then select 'medium-high' in the reset-to dropdown box and click on the "reset" button
you will probably need to go back and delete all the leftover crap afterwards too - download CCleaner (http://www.ccleaner.com/ccdownload.asp)for that
- sorry if the instructions are complex, but there really is some nasty stuff in there :(
*Pleasant Tomorrow* 10-23-2005, 11:14 PM Okay, thanks guys. I'll try that tomorrow. I must be off now. Goodnighty :wave:
*Pleasant Tomorrow* 10-23-2005, 11:15 PM - sorry if the instructions are complex, but there really is some nasty stuff in there :(
Naw, you're really helping a lot. Thanks :wave:
*Pleasant Tomorrow* 10-24-2005, 04:24 PM Logfile of HijackThis v1.99.1
Scan saved at 4:23:31 PM, on 10/24/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\System32\AOLMSNGR.EXE
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\MusicMatch\MusicMatch Jukebox\mim.exe
C:\Program Files\Common Files\AOL\1126391078\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1126391078\ee\AOLServiceHost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\HfrR.exe
C:\WINNT\System32\QwyRa.exe
C:\WINNT\System32\wuauclt.exe
C:\Documents and Settings\Owner\Local Settings\Temp\HijackThis.exe
C:\WINNT\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\about.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AOL Instent Messenger] AOLMSNGR.EXE
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\WcjB.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINNT\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] "C:\Program Files\AIM+\AIM+.exe" -cnetwait.odl
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\RunOnce: [AOL Instent Messenger] AOLMSNGR.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROProj.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab28578.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab28578.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab28578.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab28578.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
I ran everything I could in safemode, though Mike's Host File and CCleaner weren't working?...And then I ran hijack this in normal mode and this is what's left.
PZelda 10-24-2005, 04:58 PM Looks MUCH MUCH better to me. Roby will assist you better than I can, in this case... However, I do have a suggestion to make. Maybe you could uninstall some of the progs you have. It appears you (or somebody else in your family) likes to play on MSN Zone. Some of the games can be uninstalled, if you wish. But only uninstall these games if they haven't been played in a long time. RealPlayer is nothing but annoying so if you don't use it very often, you should uninstall that too. I had a lot of trouble with RealPlayer, and I never used that program to begin with so I don't have it installed anymore.
Also, if you are now able to access msconfig, go to the Startup tab, look through it and uncheck some of the stuff. You can turn off your instant messaging programs from starting up every time you start up your computer so they won't appear in the taskbar until you decide you want to log on.
¤I Love Clay Aiken¤ 10-24-2005, 06:16 PM Rooooooooooooob, tengo un pregunta por favor!! I want to DL some spyware removers etc., what do you suggest? Also, is there ANYWAY to get rid of those damn aurora popups?! They dont say Aurora anymore, now they have a little flower instead and uggggggh. I have popup blockers that block everything else except them. Thanks Kermie.
*Pleasant Tomorrow* 10-24-2005, 06:30 PM Looks MUCH MUCH better to me. Roby will assist you better than I can, in this case... However, I do have a suggestion to make. Maybe you could uninstall some of the progs you have. It appears you (or somebody else in your family) likes to play on MSN Zone. Some of the games can be uninstalled, if you wish. But only uninstall these games if they haven't been played in a long time. RealPlayer is nothing but annoying so if you don't use it very often, you should uninstall that too. I had a lot of trouble with RealPlayer, and I never used that program to begin with so I don't have it installed anymore.
Also, if you are now able to access msconfig, go to the Startup tab, look through it and uncheck some of the stuff. You can turn off your instant messaging programs from starting up every time you start up your computer so they won't appear in the taskbar until you decide you want to log on.
I've downloaded games before but not from MSN zone :grr: Don't think my sister has either. Welp, okay. I'll try getting rid of that. Thanks for thee suggestion :)
PZelda 10-24-2005, 08:03 PM I've downloaded games before but not from MSN zone :grr: Don't think my sister has either. Welp, okay. I'll try getting rid of that. Thanks for thee suggestion :)
I saw the following items in your HT log that come from MSN Zone:
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab28578.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab28578.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab28578.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary...o.cab28578.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary...t.cab28578.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab28578.cab
These games tend to take up a lot of space, so just uninstall what you can. I've never played games on MSN Messenger before, but they look like games that can be played over MSN Messenger.
You're welcome, by the way. ;)
Rooooooooooooob, tengo un pregunta por favor!! I want to DL some spyware removers etc., what do you suggest? Also, is there ANYWAY to get rid of those damn aurora popups?! They dont say Aurora anymore, now they have a little flower instead and uggggggh. I have popup blockers that block everything else except them. Thanks Kermie.
Crystal, my dear Crystal... Refer to the thread Cathy started two months back about Aurora. I noticed you replied to that thread. You should have done it soon after replying to that thread. :p
http://www.sitcomsonline.com/boards/showthread.php?t=148035&highlight=Aurora
As for antispyware programs... Spybot, Adaware and Microsoft Anti-Spyware are three excellent programs to start out with. Also download HijackThis -- it will assist in removing stubborn spyware that antispyware programs don't catch. Refer to Roby's sig for the links to said programs.
*Pleasant Tomorrow* 10-24-2005, 08:14 PM I saw the following items in your HT log that come from MSN Zone:
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab28578.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab28578.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab28578.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary...o.cab28578.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary...t.cab28578.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab28578.cab
These games tend to take up a lot of space, so just uninstall what you can. I've never played games on MSN Messenger before, but they look like games that can be played over MSN Messenger.
I got rid of them. Argh, my computer is doing so much better thanks to you guysssss
robyrob 10-24-2005, 10:17 PM Logfile of HijackThis v1.99.1
Scan saved at 4:23:31 PM, on 10/24/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\System32\AOLMSNGR.EXE
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\MusicMatch\MusicMatch Jukebox\mim.exe
C:\Program Files\Common Files\AOL\1126391078\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1126391078\ee\AOLServiceHost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\HfrR.exe
C:\WINNT\System32\QwyRa.exe
C:\WINNT\System32\wuauclt.exe
C:\Documents and Settings\Owner\Local Settings\Temp\HijackThis.exe
C:\WINNT\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\about.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AOL Instent Messenger] AOLMSNGR.EXE
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\WcjB.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINNT\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] "C:\Program Files\AIM+\AIM+.exe" -cnetwait.odl
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\RunOnce: [AOL Instent Messenger] AOLMSNGR.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROProj.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab28578.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab28578.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab28578.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab28578.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
I ran everything I could in safemode, though Mike's Host File and CCleaner weren't working?...And then I ran hijack this in normal mode and this is what's left.
ok - you still have the peper virus, the W32/SDBOT-JF worm and I'm still analyzing the rest of your post :)
Use Taskmanager (Ctrl-Alt-Del) to end these running processes if you can (right click on each and end process)
AOLMSNGR.EXE
AOLHostManager.exe
AOLServiceHost.exe
HfrR.exe
QwyRa.exe
wuauclt.exe
optimize.exe
in safemode, delete the C:\Program Files\Common Files\AOL\1126391078\ee\ folder
Download the peper fix here (http://downloads.subratam.org/PeperFix.exe). Make sure you are connected to the net and run it. If asked by your firewall for permission to access the net, give it permission. Reboot and run it a second time while connected to the net.
trojan removal:
- download Stinger (http://vil.nai.com/vil/stinger/)and save it to your desktop
- Double-click on the stinger.exe file to open it
- Choose your entire hard drive to scan.
- Choose Scan Now
- Stinger will fix anything that it finds
- Click the File menu and select Save report to file
- Post the log file results here in this thread.
try these steps then post another HijackThis log...
(other trojan removal tools we may want to try:
http://www.trojanhunter.com/products/TrojanHunter.exe
http://www.softpedia.com/get/Antivirus/asquared-a2-personal.shtml
*Pleasant Tomorrow* 10-24-2005, 10:35 PM ok - you still have the peper virus, the W32/SDBOT-JF worm and I'm still analyzing the rest of your post :)
Use Taskmanager (Ctrl-Alt-Del) to end these running processes if you can (right click on each and end process)
AOLMSNGR.EXE
AOLHostManager.exe
AOLServiceHost.exe
HfrR.exe
QwyRa.exe
wuauclt.exe
optimize.exe
in safemode, delete the C:\Program Files\Common Files\AOL\1126391078\ee\ folder
Download the peper fix here (http://downloads.subratam.org/PeperFix.exe). Make sure you are connected to the net and run it. If asked by your firewall for permission to access the net, give it permission. Reboot and run it a second time while connected to the net.
trojan removal:
- download Stinger (http://vil.nai.com/vil/stinger/)and save it to your desktop
- Double-click on the stinger.exe file to open it
- Choose your entire hard drive to scan.
- Choose Scan Now
- Stinger will fix anything that it finds
- Click the File menu and select Save report to file
- Post the log file results here in this thread.
try these steps then post another HijackThis log...
(other trojan removal tools we may want to try:
http://www.trojanhunter.com/products/TrojanHunter.exe
http://www.softpedia.com/get/Antivirus/asquared-a2-personal.shtmlOkay, Robit, thanks. I gotta go so I'll try that tomorrow. Goodnighty :wave:
robyrob 10-24-2005, 10:40 PM Rooooooooooooob, tengo un pregunta por favor!! I want to DL some spyware removers etc., what do you suggest? Also, is there ANYWAY to get rid of those damn aurora popups?! They dont say Aurora anymore, now they have a little flower instead and uggggggh. I have popup blockers that block everything else except them. Thanks Kermie.
I don't think allison left anything out, but if you want to post a HijackThis log, I can take a look at it :)
¤I Love Clay Aiken¤ 10-25-2005, 12:24 AM I don't think allison left anything out, but if you want to post a HijackThis log, I can take a look at it :)
Im downloading Hijack This! right now. Just lastnight I got a nasty AIM virus because I clicked on a link, so I had to uninstall it AND reinstall it all over again. The first time I did it, I didnt fully uninstall it I guess, so when it was loading back up to dl it was all.. WINDOWS IS TRYING TO SHUTDOWN and something about MCI or MCR. So I did it again, and when it was finishing setting up, it did it again. I just X'd it out and Windows never shutdown, so I have NO idea what that means. Ive done virus checkups, and everything comes back fine. *shrugs*
¤I Love Clay Aiken¤ 10-25-2005, 12:25 AM Logfile of HijackThis v1.99.1
Scan saved at 12:26:47 AM, on 10/25/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
c:\windows\system32\gfakccc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\WINDOWS\System32\windir32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Common Files\AOL\1124398566\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1124398566\ee\AOLServiceHost.exe
C:\WINDOWS\etb\pokapoka78.exe
C:\Program Files\Secretmaker\secretmaker.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\System32\MiniDef32.exe
C:\Program Files\Common Files\AOL\1124398566\ee\AOLServiceHost.exe
C:\Documents and Settings\Crystal\My Documents\My Pictures\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.the818search-co.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://awesomestart.com/britneyspears/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.the818search-co.com/sp2.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.netzero.net/s/sp?r=al&cf=sp&mem=mvclb4&login=65201bc759a59402cb9545cfce3efdf6/mvclb4:netzero.net/1116814795/30/sss.0.1208/&ts=42913dcb&A=0&B=1102665600000&C=1102665600000&D=1079856000000&I=7.NQ3&N=PL&O=A&UT=companion
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NZSearch\SearchEnh1.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Tray Temperature] C:\DOCUME~1\Crystal\LOCALS~1\Temp\MiniBug.exe 1
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1124398566\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [ihkquhf] c:\windows\system32\gfakccc.exe r
O4 - HKLM\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [x1CxN5] C:\WINDOWS\uskjdvca.exe
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [Firewall Policy] MiniDef32.exe
O4 - HKLM\..\Run: [System service78] C:\WINDOWS\etb\pokapoka78.exe
O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe
O4 - HKLM\..\RunServices: [Firewall Policy] MiniDef32.exe
O4 - HKLM\..\RunOnce: [Register C:\Program Files\Common Files\AOL\AOL Toolbar\AOLHelper.dll] regsvr32.exe /s "C:\Program Files\Common Files\AOL\AOL Toolbar\AOLHelper.dll"
O4 - HKLM\..\RunOnce: [Register C:\Program Files\Common Files\AOL\AOL Toolbar\smartbox.dll] regsvr32.exe /s "C:\Program Files\Common Files\AOL\AOL Toolbar\smartbox.dll"
O4 - HKLM\..\RunOnce: [Register C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll] regsvr32.exe /s "C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll"
O4 - HKLM\..\RunOnce: [b7eq3o.exe] C:\WINDOWS\System32\b7eq3o.exe /k
O4 - HKCU\..\Run: [spc_w] "C:\Program Files\NZSearch\nzspc.exe" -w
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: SECRETMAKER.lnk = C:\Program Files\Secretmaker\secretmaker.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll
O9 - Extra button: AIM Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - C:\Program Files\AIM Phone\n2paim.exe
O9 - Extra 'Tools' menuitem: AIM Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - C:\Program Files\AIM Phone\n2paim.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.neededware.com
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: NDWCab - http://www.neededware.com/ndw3.cab
O16 - DPF: v3cab - http://searchmiracle.com/cab/12.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) - http://www.tbcode.com/ist/softwares/v4.0/0006_regular.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7AB3BA80-7DC4-42A7-828F-C779ED0588D3}: NameServer = 64.136.20.121 64.136.28.121
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O_O!!!!
PZelda 10-25-2005, 12:52 AM *runs out of thread, screaming* Crystal...I think your log is right up there with Ashlee's. AGGGHHHHHH MY EYES. Roby can do this one. What I can tell you is that your R0's, R1's and O4's are just about all spyware. I'm not liking any of the items after the O12's, either. You have a lot of serious cleaning up to do and will more than likely have to work in safe mode to remove the items Roby tells you to.
I notice you are running Windows XP SP1 (Service Pack 1). SP2 came out a few months back. SP2 takes care of a lot of vulnerable security sports, therefore it is recommended you update to SP2. To do this, go to Start > Windows Update. I would recommend updating to SP2 after you have finished cleaning up your system.
¤I Love Clay Aiken¤ 10-25-2005, 02:50 AM *runs out of thread, screaming* Crystal...I think your log is right up there with Ashlee's. AGGGHHHHHH MY EYES. Roby can do this one. What I can tell you is that your R0's, R1's and O4's are just about all spyware. I'm not liking any of the items after the O12's, either. You have a lot of serious cleaning up to do and will more than likely have to work in safe mode to remove the items Roby tells you to.
I notice you are running Windows XP SP1 (Service Pack 1). SP2 came out a few months back. SP2 takes care of a lot of vulnerable security sports, therefore it is recommended you update to SP2. To do this, go to Start > Windows Update. I would recommend updating to SP2 after you have finished cleaning up your system.
The Window on the taskbar is always telling me to update. I never do. :snob: Maybe I should -.-
And, gracias.
PZelda 10-25-2005, 09:51 AM The Window on the taskbar is always telling me to update. I never do. :snob: Maybe I should -.-
And, gracias.
:lol: Yup, ya really should. ;) Just do the critical updates -- those are the most important at the moment. If the Windows Update page finds any other optional updates, wait on that one. You're welcome, by the way. :)
¤I Love Clay Aiken¤ 10-25-2005, 12:10 PM Ive downloaded every program I was told to. I ran HiJack This! and removed all the boo-boos, yet now I seem to have another problem. All of a sudden, its as if something is constantly running on my computer because now my pointer is constantly going from pointer to hourglass&pointer and I have NOTHING open. As soon as I get online it does that. This started yesterday evening and after all the crap Ive managed to get rid of, this seems to be acting up. Ever since I got that AIM virus the other night, everything has been acting up.
¤I Love Clay Aiken¤ 10-25-2005, 01:03 PM My computer, all of a sudden has taken a toll for the worse. The pointer is driving me up a friggan wall, and just now I had to restart because all of a sudden IE and programs didnt want to open up for whatever reason. I removed what I was supposed to and I dont know what else to do! I DONT want to have to reformat AGAIN, and Id like to try everything else before that. And... HOW DO I PUT MY COMPUTER IN SAFE MODE? By going into safemode, will I lose all my saved crap? :mrtarver:
PZelda 10-25-2005, 01:08 PM Ive downloaded every program I was told to. I ran HiJack This! and removed all the boo-boos, yet now I seem to have another problem. All of a sudden, its as if something is constantly running on my computer because now my pointer is constantly going from pointer to hourglass&pointer and I have NOTHING open. As soon as I get online it does that. This started yesterday evening and after all the crap Ive managed to get rid of, this seems to be acting up. Ever since I got that AIM virus the other night, everything has been acting up.
Could you post a new HT log? Remember that Spybot, AdAware and Microsoft AntiSpyware will not get rid of the nasties on your system. It is recommended to have a virus protection program installed and to keep it constantly updated. Also check at least once a week for any new Windows updates. Plus, always check for new definitions every time you run your antispyware programs. I suspect you still have some very nasty spyware left over and it will show up in your HT log if you can post your latest log.
¤I Love Clay Aiken¤ 10-25-2005, 01:25 PM Could you post a new HT log? Remember that Spybot, AdAware and Microsoft AntiSpyware will not get rid of the nasties on your system. It is recommended to have a virus protection program installed and to keep it constantly updated. Also check at least once a week for any new Windows updates. Plus, always check for new definitions every time you run your antispyware programs. I suspect you still have some very nasty spyware left over and it will show up in your HT log if you can post your latest log.
o0o those dont get rid of the nasties? -__________________________- what do you suggest for a [free] virus program that will actually REMOVE them? Anyways, here is my latest log:
Logfile of HijackThis v1.99.1
Scan saved at 1:26:34 PM, on 10/25/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
c:\windows\system32\juwlxdw.exe
C:\WINDOWS\etb\pokapoka78.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Common Files\AOL\1124398566\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1124398566\ee\AOLServiceHost.exe
C:\Program Files\NetZero\exec.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Crystal\My Documents\My Pictures\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.24-7searching-and-more.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.24-7searching-and-more.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.24-7searching-and-more.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.24-7searching-and-more.com/sp2.php
O4 - HKLM\..\Run: [djkkpec] c:\windows\system32\juwlxdw.exe r
O4 - HKLM\..\Run: [System service78] C:\WINDOWS\etb\pokapoka78.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: NDWCab - http://www.neededware.com/ndw3.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7AB3BA80-7DC4-42A7-828F-C779ED0588D3}: NameServer = 64.136.20.121 64.136.28.121
¤I Love Clay Aiken¤ 10-25-2005, 01:27 PM o0o those dont get rid of the nasties? -__________________________- what do you suggest for a [free] virus program that will actually REMOVE them? Anyways, here is my latest log:
Logfile of HijackThis v1.99.1
Scan saved at 1:26:34 PM, on 10/25/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
c:\windows\system32\juwlxdw.exe
C:\WINDOWS\etb\pokapoka78.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Common Files\AOL\1124398566\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1124398566\ee\AOLServiceHost.exe
C:\Program Files\NetZero\exec.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Crystal\My Documents\My Pictures\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.24-7searching-and-more.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.24-7searching-and-more.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.24-7searching-and-more.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.24-7searching-and-more.com/sp2.php
O4 - HKLM\..\Run: [djkkpec] c:\windows\system32\juwlxdw.exe r
O4 - HKLM\..\Run: [System service78] C:\WINDOWS\etb\pokapoka78.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: NDWCab - http://www.neededware.com/ndw3.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7AB3BA80-7DC4-42A7-828F-C779ED0588D3}: NameServer = 64.136.20.121 64.136.28.121
I just deleted all the RI's.
Fig Newtons and Margaritas to Alison and Rob! :biglove:
PZelda 10-25-2005, 03:49 PM M'mm, Fig Newtons. Thankies! :D
Okay, let me see. The following items look suspicious to me, and I would recommend removing these in safe mode. Roby, can you confirm this? I am still by no means an expert but I learn new stuff every day. :)
O4 - HKLM\..\Run: [djkkpec] c:\windows\system32\juwlxdw.exe r
O4 - HKLM\..\Run: [System service78] C:\WINDOWS\etb\pokapoka78.exe
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: NDWCab - http://www.neededware.com/ndw3.cab
ViewPoint Manager is associated with AIM -- I had ViewPoint Manager on my computer last year and it was nothing but annoying. I don't recall how I removed it. Check in the 'Add/Remove Programs' menu [Start > Settings > Control Panel > Add/Remove Programs] for ViewPoint. There will most likely be a listing for that... Remove VP from there, if you can. It serves no real purpose, except to annoy you while logged on to AIM.
Some more suggestions: run AdAware, Spybot and Microsoft AntiSpyware all in safe mode JUST TO MAKE SURE there are no more nasty buggers left over. And do a Windows Update after you are finished working in safe mode, for Pete's sake. ;)
¤I Love Clay Aiken¤ 10-25-2005, 04:01 PM Yes Ma'am!!! Will do. But, you never told me how to run my computer in safe mode? -________-
¤I Love Clay Aiken¤ 10-25-2005, 04:14 PM Right now Im currently downloading well, I forget. One of the anti virus things in Robs sign. Anyways, as soon as its done Im going to restart my computer AGAIN, because for the 47347832th time today my computer wont let me open up anything [when I try this popsup: C:\Program Files\Windows NT\Accessories\wordpad.exe (or whatever it is Im trying to open.. right there it was WordPad) Insufficent system resources exist to complete the requested service.] and remove all the temp. crap AGAIN. Then I will go into safemode. When I go into safemode, what should I do? What programs should I use to permantly remove this crap? Muchas gracias! :grady:
robyrob 10-25-2005, 04:30 PM M'mm, Fig Newtons. Thankies! :D
Okay, let me see. The following items look suspicious to me, and I would recommend removing these in safe mode. Roby, can you confirm this? I am still by no means an expert but I learn new stuff every day. :)
O4 - HKLM\..\Run: [djkkpec] c:\windows\system32\juwlxdw.exe r
O4 - HKLM\..\Run: [System service78] C:\WINDOWS\etb\pokapoka78.exe
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: NDWCab - http://www.neededware.com/ndw3.cab
ViewPoint Manager is associated with AIM -- I had ViewPoint Manager on my computer last year and it was nothing but annoying. I don't recall how I removed it. Check in the 'Add/Remove Programs' menu [Start > Settings > Control Panel > Add/Remove Programs] for ViewPoint. There will most likely be a listing for that... Remove VP from there, if you can. It serves no real purpose, except to annoy you while logged on to AIM.
Some more suggestions: run AdAware, Spybot and Microsoft AntiSpyware all in safe mode JUST TO MAKE SURE there are no more nasty buggers left over. And do a Windows Update after you are finished working in safe mode, for Pete's sake. ;)those are all definately bad ones - pokapoka78 is a component of the Elitebar Trojan, the Viewpoint is definately bad, and there is at least one other Trojan or virus on there (although probably more)
I can help you with this, but it is definately going to take a little more time than I can devote to it while I'm at work....
you COULD try to reboot into Safemode (you wont lose anything in safemode, its just booting up without loading any background programs) then run the AntiSpyware programs and the trojan removal programs I posted for ashlee and check those items in HijackThis to remove them... you are definately going to have to do this in safemode anyways...
for an antivirus, you could try AVG - its free, link in my sig :)
robyrob 10-25-2005, 04:34 PM Right now Im currently downloading well, I forget. One of the anti virus things in Robs sign. Anyways, as soon as its done Im going to restart my computer AGAIN, because for the 47347832th time today my computer wont let me open up anything [when I try this popsup: C:\Program Files\Windows NT\Accessories\wordpad.exe (or whatever it is Im trying to open.. right there it was WordPad) Insufficent system resources exist to complete the requested service.] and remove all the temp. crap AGAIN. Then I will go into safemode. When I go into safemode, what should I do? What programs should I use to permantly remove this crap? Muchas gracias! :grady:
to get into safemode - as alison said, just keep tapping on the F8 function key as the computer is restarting, it should take you to the "startup options menu" and select safemode (i think its F5 to select)
PZelda 10-25-2005, 05:00 PM Yes Ma'am!!! Will do. But, you never told me how to run my computer in safe mode? -________-
Ashlee asked the same thing earlier in this thread, when you first start up your computer, keep hitting F8. This has to be done within the first few seconds your computer is starting up. IT will take you to a different screen where you are able to choose SAFE MODE from the list of options there.
I told Ashlee this and I am telling you now, I strongly recommend NOT going on the Internet while in safe mode. So if you need to, print out the necessary instructions, then you can go restart your computer, get into safe mode and work on removing the nasties there. When you are done, just restart once more and you will be back to normal mode once more.
¤I Love Clay Aiken¤ 10-25-2005, 06:13 PM WELL I ran AdAware, SpyBot, HiJack This!, AND did a Virus scan with AntiVir all in safemode and am now now in regular mode. I reran HiJack This! when I started up, and this is what I got:
Logfile of HijackThis v1.99.1
Scan saved at 6:09:05 PM, on 10/25/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Common Files\AOL\1124398566\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1124398566\ee\AOLServiceHost.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Common Files\AOL\1124398566\ee\AOLServiceHost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Crystal\My Documents\My Pictures\hijackthis\HijackThis.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{7AB3BA80-7DC4-42A7-828F-C779ED0588D3}: NameServer = 64.136.28.120 64.136.20.120
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
Am I done? Or has everything I spent all day on, just been removed temporarily? Thanks b's. :triplets:
PZelda 10-25-2005, 06:36 PM Looks MUUUUUUUUUUUUUUUUUUUCH better AND clean, too! I declare you spyware-free. ;) Be ABSOLUTELY SURE to run your antispyware programs often so that you don't run into the same thing again. :) And, oh yes, you can do your Windows Update now. :D
¤I Love Clay Aiken¤ 10-25-2005, 08:24 PM Yay!!! :woohoo: THANKS!! How often? Once a week? Once a day? Should I run them ALL? :crazy:
PZelda 10-25-2005, 09:03 PM Yay!!! :woohoo: THANKS!! How often? Once a week? Once a day? Should I run them ALL? :crazy:
If you baby your computer, you can get away with running the progs once a week. And yes, it's a good idea to run them all, but not at the same time. Just do one after the other. I usually do Spybot first, Adaware second and Microsoft third.
robyrob 10-25-2005, 09:46 PM Yay!!! :woohoo: THANKS!! How often? Once a week? Once a day? Should I run them ALL? :crazy:
once a week is probably ok - just make sure you update the programs and your antivirus each time before you use them.
It looks clean now - but I would also suggest you install SpywareBlaster (http://tinyurl.com/g1d9)and Mike's Hosts FIle (http://tinyurl.com/coye) to help prevent stuff from getting in there again - they act as a "black list" of known bad programs/sites that it will automatically deny any access to, they dont run in the background or slow you down at all either.
(you probably only need to update those about once a month or so)
*Pleasant Tomorrow* 10-25-2005, 10:46 PM ok - you still have the peper virus, the W32/SDBOT-JF worm and I'm still analyzing the rest of your post :)
Use Taskmanager (Ctrl-Alt-Del) to end these running processes if you can (right click on each and end process)
AOLMSNGR.EXE
AOLHostManager.exe
AOLServiceHost.exe
HfrR.exe
QwyRa.exe
wuauclt.exe
optimize.exe
in safemode, delete the C:\Program Files\Common Files\AOL\1126391078\ee\ folder
Download the peper fix here (http://downloads.subratam.org/PeperFix.exe). Make sure you are connected to the net and run it. If asked by your firewall for permission to access the net, give it permission. Reboot and run it a second time while connected to the net.
trojan removal:
- download Stinger (http://vil.nai.com/vil/stinger/)and save it to your desktop
- Double-click on the stinger.exe file to open it
- Choose your entire hard drive to scan.
- Choose Scan Now
- Stinger will fix anything that it finds
- Click the File menu and select Save report to file
- Post the log file results here in this thread.
try these steps then post another HijackThis log...
(other trojan removal tools we may want to try:
http://www.trojanhunter.com/products/TrojanHunter.exe
http://www.softpedia.com/get/Antivirus/asquared-a2-personal.shtml
Okay, currently running Stinger...when I ran the peper it said nothing was detected? And When I went to end processes AOLMSNGR.EXE, HfrR.exe,QwyRa.exe and optimize.exe weren't listed...
er, also when I went to deleted C:\Program Files\Common Files\AOL\1126391078\ee\ folder what I did was search folders and typed that in, and 5 different things came up...none with that exact file name...it went up to \ee\ and then it was different.
robyrob 10-25-2005, 10:53 PM Okay, currently running Stinger...when I ran the peper it said nothing was detected? And When I went to end processes AOLMSNGR.EXE, HfrR.exe,QwyRa.exe and optimize.exe weren't listed...
er, also when I went to deleted C:\Program Files\Common Files\AOL\1126391078\ee\ folder what I did was search folders and typed that in, and 5 different things came up...none with that exact file name...it went up to \ee\ and then it was different.
thats ok - if things aren't showing up again - especially after a reboot, that's a good indication that they are gone :)
post another HijackThis log after Stinger is done and we'll see how it looks
*Pleasant Tomorrow* 10-25-2005, 10:56 PM thats ok - if things aren't showing up again - especially after a reboot, that's a good indication that they are gone :)
post another HijackThis log after Stinger is done and we'll see how it looks
Okay. The stinger's taking a long time so I'll probably get to the log and posting it tomorrow. Thankies and goodnight :)
robyrob 10-25-2005, 11:04 PM Okay. The stinger's taking a long time so I'll probably get to the log and posting it tomorrow. Thankies and goodnight :)
'kay man :wave:
¤I Love Clay Aiken¤ 10-25-2005, 11:37 PM once a week is probably ok - just make sure you update the programs and your antivirus each time before you use them.
It looks clean now - but I would also suggest you install SpywareBlaster (http://tinyurl.com/g1d9)and Mike's Hosts FIle (http://tinyurl.com/coye) to help prevent stuff from getting in there again - they act as a "black list" of known bad programs/sites that it will automatically deny any access to, they dont run in the background or slow you down at all either.
(you probably only need to update those about once a month or so)
Awesome, thanks! Will download those. If it werent for you and Alison, I wouldve given up and had my dad reformat!
MsOrange 10-26-2005, 06:26 AM this has officially turned into the "Roby Help!" thread
*Pleasant Tomorrow* 10-26-2005, 05:34 PM Aye, I got all the way to saving the report file and then another desktop icon is created and when I click on it it says: Windows cannot find NOTEPAD.EXE. This program is need for opening files of type 'Text Document.' Type in the executable file to be used instead: and then a space with C:\ and then room to type more
Erm, heres the hijack this log, though.
Logfile of HijackThis v1.99.1
Scan saved at 5:35:21 PM, on 10/26/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Common Files\AOL\1126391078\ee\AOLHostManager.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mim.exe
C:\Program Files\Common Files\AOL\1126391078\ee\AOLServiceHost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\s_t_i_n_g_e_r.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Owner\Local Settings\Temp\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\about.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\QlsPBA55.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROProj.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
PZelda 10-26-2005, 06:21 PM Aye, I got all the way to saving the report file and then another desktop icon is created and when I click on it it says: Windows cannot find NOTEPAD.EXE. This program is need for opening files of type 'Text Document.' Type in the executable file to be used instead: and then a space with C:\ and then room to type more
Erm, heres the hijack this log, though.
Logfile of HijackThis v1.99.1
Scan saved at 5:35:21 PM, on 10/26/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Common Files\AOL\1126391078\ee\AOLHostManager.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mim.exe
C:\Program Files\Common Files\AOL\1126391078\ee\AOLServiceHost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\s_t_i_n_g_e_r.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Owner\Local Settings\Temp\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\about.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\QlsPBA55.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROProj.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
Right now, I don't have much time to help you as I have a class in 15 minutes but I am particularly concerned about the following items:
C:\Program Files\Common Files\AOL\1126391078\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1126391078\ee\AOLServiceHost.exe
C:\Documents and Settings\Owner\Desktop\s_t_i_n_g_e_r.exe -- I am assuming that this is the 'notepad' icon that popped up on your desktop.
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\QlsPBA55.exe
It's Roby's call. There is definitely some nasty spyware action going on in your system. :eek:
*Pleasant Tomorrow* 10-26-2005, 08:25 PM Right now, I don't have much time to help you as I have a class in 15 minutes but I am particularly concerned about the following items:
C:\Program Files\Common Files\AOL\1126391078\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1126391078\ee\AOLServiceHost.exe
C:\Documents and Settings\Owner\Desktop\s_t_i_n_g_e_r.exe -- I am assuming that this is the 'notepad' icon that popped up on your desktop.
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\QlsPBA55.exe
It's Roby's call. There is definitely some nasty spyware action going on in your system. :eek:
Roby told me to download stinger, no? *confuzed*
The others don't look familiar though. I'll take your word for it :)
PZelda 10-26-2005, 08:28 PM Roby told me to download stinger, no? *confuzed*
The others don't look familiar though. I'll take your word for it :)
Oops, you're right. Disregard the stinger part. :lol: Lights go off in my head every time I see filenames that are gibberish or have an overuse of the underscore.
I'm at home now, so I can check out the others for ya. :) I didn't find a whole lot, just that Peper is still on your system.
*Pleasant Tomorrow* 10-26-2005, 08:32 PM Oops, you're right. Disregard the stinger part. :lol: Lights go off in my head every time I see filenames that are gibberish or have an overuse of the underscore.
I'm at home now, so I can check out the others for ya. :)
Heh, thanks. You are awesome for doing so :notworthy
By the way, I couldn't find C:\Program Files\Common Files\AOL\1126391078\ee\AOLHostManager.exe
and
C:\Program Files\Common Files\AOL\1126391078\ee\AOLServiceHost.exe on the list...:confused:
PZelda 10-26-2005, 08:38 PM Heh, thanks. You are awesome for doing so :notworthy
By the way, I couldn't find C:\Program Files\Common Files\AOL\1126391078\ee\AOLHostManager.exe
and
C:\Program Files\Common Files\AOL\1126391078\ee\AOLServiceHost.exe on the list...:confused:
Anytime. :)
I can't really think of anything else. Can you see hidden files and folders? (hidden files/folders appear transparent) If not, it's pretty easy. Simply launch your My Computer, click on Tools > Folder Options... and go to the View tab. There should be a line that says Hidden files and folders near the top of the scrollbox, and it has two radio button options below it. Click on the radio button next to the Show hidden files and folders, then accept the changes. Now see if you can navigate to C:\Program Files\Common Files\AOL\ and delete the 1236391078 folder from there. But if you find that you can't locate the folder, even with that option turned on, you can just go back and disable the show hidden files/folder option.
I wouldn't recommend doing that now though, see what Roby says first. :) I just want to see if you can find that folder with the 'show hidden files and folders' option turned on.
*Pleasant Tomorrow* 10-26-2005, 08:43 PM Anytime. :)
I can't really think of anything else. Can you see hidden files and folders? (hidden files/folders appear transparent) If not, it's pretty easy. Simply launch your My Computer, click on Tools > Folder Options... and go to the View tab. There should be a line that says Hidden files and folders near the top of the scrollbox, and it has two radio button options below it. Click on the radio button next to the Show hidden files and folders, then accept the changes. Now see if you can navigate to C:\Program Files\Common Files\AOL\ and delete the 1236391078 folder from there. But if you find that you can't locate the folder, even with that option turned on, you can just go back and disable the show hidden files/folder option.
I wouldn't recommend doing that now though, see what Roby says first. :) I just want to see if you can find that folder with the 'show hidden files and folders' option turned on.
Ah, okay thanks. I'll wait then :)
robyrob 10-26-2005, 11:10 PM Right now, I don't have much time to help you as I have a class in 15 minutes but I am particularly concerned about the following items:
C:\Program Files\Common Files\AOL\1126391078\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1126391078\ee\AOLServiceHost.exe
C:\Documents and Settings\Owner\Desktop\s_t_i_n_g_e_r.exe -- I am assuming that this is the 'notepad' icon that popped up on your desktop.
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\QlsPBA55.exe
It's Roby's call. There is definitely some nasty spyware action going on in your system. :eek:i'm not as concerned about the aim 'bestfriends' virus - just dont use the aim for now
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k this is created by Windows after a crash, its normal
O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\QlsPBA55.exe this is the trojan that is still on your system - download and run the removal tool, reboot and run it again
http://www.bleepingcomputer.com/files/virus/PeperFix.exe
how old is that Norton Antivirus? have you tried to update it and run a scan? if that is a very old version, you are going to need to upgrade, or switch to a different AV program
can you try to run an online scan at http://housecall.trendmicro.com/
robyrob 10-26-2005, 11:18 PM i'm not as concerned about the aim 'bestfriends' virus - just dont use the aim for now
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k this is created by Windows after a crash, its normal
O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\QlsPBA55.exe this is the trojan that is still on your system - download and run the removal tool, reboot and run it again
http://www.bleepingcomputer.com/files/virus/PeperFix.exe
how old is that Norton Antivirus? have you tried to update it and run a scan? if that is a very old version, you are going to need to upgrade, or switch to a different AV program
can you try to run an online scan at http://housecall.trendmicro.com/
actually you can try the aimfix removal tool,
http://www.jayloden.com/aimfix.htm
*Pleasant Tomorrow* 10-28-2005, 07:30 PM I havn't updated Norton Anti Virus in forever...erm...
*Pleasant Tomorrow* 10-28-2005, 07:35 PM And downloading AIM fix won't work? I download, an icon appears on my computer...I click, it's black with...wording and codes in gray...
*Pleasant Tomorrow* 10-28-2005, 09:12 PM And downloading AIM fix won't work? I download, an icon appears on my computer...I click, it's black with...wording and codes in gray...
heh nevermind, that's what it's supposed to do
|