Welcome to your place for tech questions! ( Log In or Join today ) Get answers from experts today. (it's 100% free) Virus removal forum
![]() ![]() |
Mar 29 2004, 09:20 PM
Post
#1
|
|
|
New Member ![]() Group: Authentic Member Posts: 16 Joined: 29-March 04 From: Broken Arrow Oklahoma Member No.: 3,508 |
Alice Logfile of HijackThis v1.97.7 Scan saved at 9:15:21 PM, on 3/29/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe C:\Program Files\Lexmark X5100 Series\lxbabmon.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe C:\Program Files\Kazaa Lite K++\Kazaa.kpp C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Yahoo!\Messenger\YPager.exe C:\PROGRA~1\mcafee.com\agent\McDash.exe c:\program files\mcafee.com\shared\mghtml.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Alice\Desktop\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://lcsbpc.t.muxa.cc/s.php?aid=227 (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://lcsbpc.t.muxa.cc/s.php?aid=227 (obfuscated) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lcsbpc.t.muxa.cc/h.php?aid=227 (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://lcsbpc.t.muxa.cc/s.php?aid=227 (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lcsbpc.t.muxa.cc/h.php?aid=227 (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://lcsbpc.t.muxa.cc/s.php?aid=227 (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://lcsbpc.t.muxa.cc/s.php?aid=227 (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://lcsbpc.t.muxa.cc/s.php?aid=227 (obfuscated) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com* R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://lcsbpc.t.muxa.cc/h.php?aid=227 (obfuscated) O1 - Hosts file is located at: C:\WINDOWS\nsdb\hosts O1 - Hosts: 81.211.105.69 lender-search.com O1 - Hosts: 81.211.105.68 hot-searches.com O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [sys] regedit -s sys.reg O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe" O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun O4 - HKLM\..\Run: [VirusScan Online] c:\program files\mcafee.com\vso\mcvsshld.exe O4 - HKCU\..\Run: [SPYKILLER] C:\Program Files\Anonymizer\sk\SpyWareKiller.exe /BOOT O4 - HKLM\..\RunOnce: [tlc] C:\WINDOWS\update12.js O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_SRCV02.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O9 - Extra button: Cosmi Popup Blocker (HKLM) O9 - Extra 'Tools' menuitem: Cosmi Popup Blocker (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120...all/xscan53.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{FA274ABD-CB0D-4FA5-B2EB-825D5E426DF4}: NameServer = 192.168.0.1
Attached File(s)
|
|
|
|
Mar 30 2004, 11:15 AM
Post
#2
|
|
![]() Retired Staff-Malware Expert ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 3,521 Joined: 1-November 03 From: UK Member No.: 668 Operating System: Windows XP |
Could you click here to download CWShredder by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'.
Create a new folder called C:\HijackThis, move the HijackThis.exe file into the new folder and run it from there. This is necessary to ensure you have backups should anything go wrong and avoids them cluttering up your desktop. Then rescan with HJT and post a new log here so that any remnants can be removed manually. |
|
|
|
Mar 30 2004, 10:31 PM
Post
#3
|
|
|
New Member ![]() Group: Authentic Member Posts: 16 Joined: 29-March 04 From: Broken Arrow Oklahoma Member No.: 3,508 |
i downloaded and ran it. i also made a new log. wasnt shur if i was suposed to restart before making the log so didnt. if i do need to plese inform me. im new to this stuff. thanks in advance
Alice Logfile of HijackThis v1.97.7 Scan saved at 10:26:42 PM, on 3/30/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe C:\Program Files\Lexmark X5100 Series\lxbabmon.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe C:\Program Files\Kazaa Lite K++\Kazaa.kpp C:\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com* O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe" O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" O4 - HKCU\..\Run: [SPYKILLER] C:\Program Files\Anonymizer\sk\SpyWareKiller.exe /BOOT O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_SRCV02.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O9 - Extra button: Cosmi Popup Blocker (HKLM) O9 - Extra 'Tools' menuitem: Cosmi Popup Blocker (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc...76/mcinsctl.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120...all/xscan53.cab O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg...,16/mcgdmgr.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{FA274ABD-CB0D-4FA5-B2EB-825D5E426DF4}: NameServer = 192.168.0.1 |
|
|
|
Mar 31 2004, 12:22 AM
Post
#4
|
|
![]() Retired Staff-Malware Expert ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 3,521 Joined: 1-November 03 From: UK Member No.: 668 Operating System: Windows XP |
That's better, bit more to do. Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com* Reboot when done and you should be good to go. |
|
|
|
Mar 31 2004, 07:21 PM
Post
#5
|
|
|
New Member ![]() Group: Authentic Member Posts: 16 Joined: 29-March 04 From: Broken Arrow Oklahoma Member No.: 3,508 |
i just did that and made a new log. thanks for all the help.
Alice Logfile of HijackThis v1.97.7 Scan saved at 7:18:15 PM, on 3/31/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe C:\Program Files\Lexmark X5100 Series\lxbabmon.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe C:\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://members.cox.net/omega1979/ O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe" O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" O4 - HKCU\..\Run: [SPYKILLER] C:\Program Files\Anonymizer\sk\SpyWareKiller.exe /BOOT O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_SRCV02.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O9 - Extra button: Cosmi Popup Blocker (HKLM) O9 - Extra 'Tools' menuitem: Cosmi Popup Blocker (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc...76/mcinsctl.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120...all/xscan53.cab O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg...,16/mcgdmgr.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{FA274ABD-CB0D-4FA5-B2EB-825D5E426DF4}: NameServer = 192.168.0.1 |
|
|
|
Apr 1 2004, 12:12 AM
Post
#6
|
|
![]() Retired Staff-Malware Expert ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 3,521 Joined: 1-November 03 From: UK Member No.: 668 Operating System: Windows XP |
Clean log - well done
|
|
|
|
Apr 1 2004, 07:15 AM
Post
#7
|
|
|
New Member ![]() Group: Authentic Member Posts: 16 Joined: 29-March 04 From: Broken Arrow Oklahoma Member No.: 3,508 |
Cool thanks. i have leatned a valuble help. i apreceat all the help u gave me. a thousand times thank you. my browser is finaly working right.
Alice |
|
|
|
Apr 1 2004, 01:30 PM
Post
#8
|
|
![]() Retired Staff-Malware Expert ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 3,521 Joined: 1-November 03 From: UK Member No.: 668 Operating System: Windows XP |
You're welcome - glad to help
As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link (Click for address) The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
5 | -David Worrell- | 4,840 | 10th November 2003 - 07:06 PM Last post by: cnm |
|||
![]() |
4 | -janky@adelphia.net- | 2,743 | 13th November 2003 - 07:42 PM Last post by: cnm |
|||
![]() |
6 | Steiner | 2,951 | 19th November 2003 - 07:54 PM Last post by: cnm |
|||
![]() |
17 | NickArnold | 4,310 | 26th March 2005 - 08:47 PM Last post by: LDTate |
|||
![]() |
10 | Biker-T | 2,593 | 16th March 2005 - 08:12 PM Last post by: lethal |
|||
|
Time is now: 20th May 2013 - 07:18 AM |