This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

How To Use Hijackthis File To Remove About:blank

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is my HijackThis log. Can anyone advise me what to fix in this list?
Thank you!

Logfile of HijackThis v1.97.7
Scan saved at 7:09:19 PM, on 6/26/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\ibmpmsvc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\Hummbird\inetd32.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\AEIWLSTA.EXE
C:\WINNT\LTSMMSG.exe
C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe
C:\Program Files\Funk Software\Odyssey Client\OdTray.exe
C:\WINNT\tppaldr.exe
C:\Program Files\Maxtor Corporation\MaxTools\CBMon.EXE
C:\WINNT\AGRSMMSG.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Handspring\HOTSYNC.EXE
C:\Program Files\ThinkPad\Utilities\tponscr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
d:\Documents and Settings\charles.mcneill.BDP-986Z\My Documents\Hijack This Folder\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://d:\DOCUME~1\CHARLE~1.BDP\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://d:\DOCUME~1\CHARLE~1.BDP\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://intra.undp.org
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://intra.undp.org
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://intra.undp.org
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.undp.org/.proxy
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.undp.org:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://intra.undp.org
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://intra.undp.org
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://intra.undp.org/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AEIWLSTA.EXE] AEIWLSTA.EXE
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [TpHotkey] C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe
O4 - HKLM\..\Run: [OdTray.exe] "C:\Program Files\Funk Software\Odyssey Client\OdTray.exe"
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINNT\tppaldr.exe
O4 - HKLM\..\Run: [Indigita CBmon] C:\Program Files\Maxtor Corporation\MaxTools\CBMon.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [win32.exe] C:\WINNT\win32.exe
O4 - HKLM\..\Run: [SysUpd] C:\WINNT\sysupd.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Remndr] "C:\Program Files\CasinoOnline\CsRemnd.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Handspring\HOTSYNC.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {11111111-1111-1111-1111-111111111123} - file://c:\winnt\win.exe
O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://super-gals.com/scj/rotation/templates/um2/x.chm::/ad.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/…7875.3027777778
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup143.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = MSAD.undp.org
O17 - HKLM\System\CCS\Services\Tcpip\..\{48B9C9CD-1257-4994-84F9-70E6387A7396}: NameServer = 165.65.6.8,192.124.42.15
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = MSAD.undp.org
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = MSAD.undp.org
Click here to download CWShredder by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'. Reboot when done.

Click here to download Ad-Aware and install. Before scanning click on "check for updates now" to make sure you have the latest reference file. Then click the gear wheel at the top and check these options:

General> activate these: "Automatically save log-file" and "Automatically quarantine objects prior to removal"

Scanning > activate these: "Scan within archives", "Scan active processes", "Scan registry", "Deep scan registry", "Scan my IE Favorites for banned sites" and "Scan my Hosts file"

Tweaks > Scanning Engine> activate this: "Unload recognized processes during scanning."

Tweaks > Cleaning Engine: activate these: "Automatically try to unregister objects prior to deletion" and "Let Windows remove files in use after reboot."

Click "Proceed" to save your settings, then click "Start", make sure "Activate in-depth scan" is ticked green then scan your system. When the scan is finished, the screen will tell you if anything has been found, click "Next". The bad files will be listed, right click the pane and click "Select all objects" - this will put a check mark in the box at the side, click "Next" again and click "OK" at the prompt "# objects will be removed. Continue?".

Reboot when done.

Click here to download and install Registrar Lite. Install, run, copy and paste this line to reglite's address bar:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

and hit the "go" tab. Find: "Appinit_Dlls" value on the right side panel, DoubleClick, copy and post here the information in the 'Value' field.

Click here to download FindnFix.exe (2K/XP only!) by freeatlast. Double-click on the FINDnFIX.exe and it will install a folder called FINDnFIX on your system. Go to that folder and double-click on !LOG!.bat. The program takes a few minutes to collect the necessary information. When done post the contents of Log.txt in this thread.
Thank you SO much for this. Apologies for not seeing your reply earlier but the notice from Tom Coyote got screened out by an over active anti-spam service! I will take steps indicated here and post results. Sincere thanks, once again.
To:Forum God / Super Mod: Here is the 'Value' field of the 'Apinit_Dlls' line after running 'Registrar Lite": C:\WINNT\system32\comebj.dll Here is the "Log.txt" after double clicking on '!LOG!.bat' after using 'FindnFix.exe': »»»»»»»»»»»»»»»»»»*** freeatlast.100free.com ***»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»*** Read this first! ***»»»»»»»»»»»»»»»» Due to errors on various message boards I made some changes. You must know how to ID the file based on the filters provided in the scan, as not all the files flagged are bad. If you make a mistake or use the wrong guidance, it is completely your responsibility and the helper that assists you. If you are not sure about the nature of the file or how to proceed, I suggest you research it first before attempting to remove any *unknown file on your own. *For Helpers and/or users that are not familiar with any of the items on the scan results- I recommend using an alternative, once you know what to look for! »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» –The directory 'junkxxx' is now included as a Subfolder in the FINDnfix folder and is the destination for the file to be moved.. -*Previous directions will no longer work… »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» Microsoft Windows 2000 [Version 5.00.2195] »»»IE build and last SP(s) 6.0.2800.1106 SP1-Q822925-Q330994-Q824145-Q832894-Q831167-Q837009 The type of the file system is NTFS. C: is not dirty. Fri 07/09/2004 10:29pm up 0 days, 0:22 »»»»»»»»»»»»»»»»»»***LOG!***(*modified 7/8)»»»»»»»»»»»»»»»» Scanning for file(s)… »»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»» »»»»» (*1*) »»»»» ……… »»Locked or 'Suspect' file(s) found… C:\WINNT\System32\COMEBJ.DLL +++ File read error \\?\C:\WINNT\System32\COMEBJ.DLL +++ File read error »»»»» (*2*) »»»»»…….. **File C:\FINDnFIX\LIST.TXT COMEBJ.DLL Can't Open! »»»»» (*3*) »»»»»…….. C:\WINNT\SYSTEM32\ comebj.dll Sun Apr 18 2004 1:41:58a A…R 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K unknown/hidden files… No matches found. »»»»» (*4*) »»»»»……… Sniffing………. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINNT\SYSTEM32\COMEBJ.DLL »»»»»(*5*)»»»»» **File C:\WINNT\SYSTEM32\DLLXXX.TXT ¯ Access denied ® ………………… COMEBJ.DLL …..57344 18.04.2004 »»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»» »»»»»Search by size… C:\WINNT\SYSTEM32\ comebj.dll Sun Apr 18 2004 1:41:58a A…R 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K No matches found. No matches found. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINNT\SYSTEM32\COMEBJ.DLL Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. »»Size of Windows key: (*Default-450 *No AppInit-398 *fake(infected)-448,504,512…) Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 448 »»Dumping Values…….. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows AppInit_DLLs = (*** MISSING TRAILING NULL CHARACTER ***) DeviceNotSelectedTimeout = 15 GDIProcessHandleQuota = REG_DWORD 0x00002710 Spooler = yes swapdisk = TransmissionRetryTimeout = 90 USERProcessHandleQuota = REG_DWORD 0x00002710 »»Security settings for 'Windows' key: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: (NI) ALLOW Read BUILTIN\Users (IO) ALLOW Read BUILTIN\Users (NI) ALLOW Read BUILTIN\Power Users (IO) ALLOW Read BUILTIN\Power Users (NI) ALLOW Full access BUILTIN\Administrators (IO) ALLOW Full access BUILTIN\Administrators (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access BUILTIN\Administrators (IO) ALLOW Full access CREATOR OWNER Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: Read BUILTIN\Users Read BUILTIN\Power Users Full access BUILTIN\Administrators Full access NT AUTHORITY\SYSTEM »»Member of…: (Admin logon required!) User is a member of group BDP-986Z\None. User is a member of group \Everyone. User is a member of group BUILTIN\Administrators. User is a member of group BUILTIN\Users. User is a member of group NT AUTHORITY\INTERACTIVE. User is a member of group NT AUTHORITY\Authenticated Users. User is a member of group \LOCAL. »» Service search:(different variant) '"Network Security Service","__NS_Service_3"… [SC] GetServiceKeyName FAILED 1060: The specified service does not exist as an installed service. [SC] GetServiceDisplayName FAILED 1060: The specified service does not exist as an installed service. »»Notepad check…. C:\WINNT\ notepad.exe Tue May 8 2001 12:00:00p A…. 50,960 49.77 K 1 item found: 1 file, 0 directories. Total of file sizes: 50,960 bytes 49.77 K C:\WINNT\SYSTEM32\ notepad.exe Tue May 8 2001 12:00:00p A…. 50,960 49.77 K 1 item found: 1 file, 0 directories. Total of file sizes: 50,960 bytes 49.77 K C:\WINNT\SYSTEM32\DLLCACHE\ notepad.exe Tue May 8 2001 12:00:00p A…. 50,960 49.77 K 1 item found: 1 file, 0 directories. Total of file sizes: 50,960 bytes 49.77 K –a– W32i APP ENU 5.0.2140.1 shp 50,960 05-08-2001 notepad.exe Language 0x0409 (English (United States)) CharSet 0x04b0 Unicode OleSelfRegister Disabled CompanyName Microsoft Corporation FileDescription Notepad InternalName Notepad OriginalFilenam NOTEPAD.EXE ProductName Microsoft® Windows ® 2000 Operating System ProductVersion 5.00.2140.1 FileVersion 5.00.2140.1 LegalCopyright Copyright © Microsoft Corp. 1981-1999 VS_FIXEDFILEINFO: Signature: feef04bd Struc Ver: 00010000 FileVer: 00050000:085c0001 (5.0:2140.1) ProdVer: 00050000:085c0001 (5.0:2140.1) FlagMask: 0000003f Flags: 00000000 OS: 00040004 NT Win32 FileType: 00000001 App SubType: 00000000 FileDate: 00000000:00000000 »»»»»»Backups created…»»»»»» 10:30pm up 0 days, 0:24 Fri 07/09/2004 A C:\FINDnFIX\keyback.hiv –a– - - - - - 8,192 07-09-2004 keyback.hiv A C:\FINDnFIX\keys1\winkey.reg –a– - - - - - 287 07-09-2004 winkey.reg C:\FINDNFIX\ JUNKXXX Fri Jul 9 2004 10:29:06p .D… 1 item found: 0 files, 1 directory. »»Performing string scan…. 00001150: ? 00001190: 8 @ 000011D0: vk : , AppInit_DLLs4 e C : \ W I N N T \ s 00001210:y s t e m 3 2 \ c o m e b j . d l l vk h d 00001250:DeviceNotSelectedTimeout 1 5 H vk ' 00001290: 0 GDIProcessHandleQuota 0 vk 0 Spooler 000012D0: y e s 0 0 vk 0 swapdisk vk 0 00001310: , TransmissionRetryTimeout 9 0 vk ' 00001350: 0 USERProcessHandleQuota0 00001390: 000013D0: 00001410: 00001450: 00001490: 000014D0: 00001510: 00001550: 00001590: 000015D0: ———- WIN.TXT AppInit_DLLs4 ————– ————– C:\WINNT\system32\comebj.dll ————– ————– REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" "DeviceNotSelectedTimeout"="15" "GDIProcessHandleQuota"=dword:00002710 "Spooler"="yes" "swapdisk"="" "TransmissionRetryTimeout"="90" "USERProcessHandleQuota"=dword:00002710 A handle was successfully obtained for the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows key. This key has 0 subkeys. The AppInitDLLs value exists and reports as 58 bytes, including the 2 for string termination. [AppInitDLLs] Ansi string : "C:\WINNT\system32\comebj.dll" 0000 43 00 3a 00 5c 00 57 00 49 00 4e 00 4e 00 54 00 | C.:.\.W.I.N.N.T. 0010 5c 00 73 00 79 00 73 00 74 00 65 00 6d 00 33 00 | \.s.y.s.t.e.m.3. 0020 32 00 5c 00 63 00 6f 00 6d 00 65 00 62 00 6a 00 | 2.\.c.o.m.e.b.j. 0030 2e 00 64 00 6c 00 6c 00 00 00 | ..d.l.l…  Thank you!
In the keys1 folder, double click on FIX.bat. You will get an alert of about 15 seconds before reboot - allow it to reboot. On restart, open Explorer and navigate to C:\Windows\System32 folder, find the COMEBJ.DLL file (it should be visible now). Highlight the file and using top menu, click Edit>Move to folder…

Select C:\Findnfix\junkxxx as destination. Move the file.

Open the FINDnFIX folder again and double-click on RESTORE.bat. When it is finished, in FINDnFIX folder, there will be a file called Log1.txt - post it's contents in your next reply.
To: Forum God / Super Mod: Here is the 'Log1.txt' contents below: Thank you! … ササササササササササササササササササ*** freeatlast.100free.com ***ササササササササササササササササ Sat 07/10/2004 2:15pm up 0 days, 0:18 Microsoft Windows 2000 [Version 5.00.2195] サササIE build and last SP(s) 6.0.2800.1106 SP1-Q822925-Q330994-Q824145-Q832894-Q831167-Q837009 The type of the file system is NTFS. C: is not dirty. ササササササササササササササササササ***LOG1!***ササササササササササササササササ Scanning for file(s) in System32… サササササササ (1) サササササササ サササササササ (2) サササササササ **File C:\FINDnFIX\LIST.TXT サササササササ (3) サササササササ No matches found. Unknown/hidden files… No matches found. サササササササ (4) サササササササ Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. サササササ(5)サササササ **File C:\WINNT\SYSTEM32\DLLXXX.TXT サササササササ Search by size… No matches found. No matches found. No matches found. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. サササ*サササ Scanning for moved file… サササ*サササ * result\\?\C:\FINDnFIX\junkxxx\COMEBJ.222 C:\FINDNFIX\JUNKXXX\ comebj.222 Sun Apr 18 2004 1:41:58a A…. 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\FINDNFIX\JUNKXXX\COMEBJ.222 **File C:\FINDNFIX\JUNKXXX\COMEBJ.222 0000DEBE: 67 44 65 76 69 63 65 00 . 00 53 74 72 65 61 6D 69 gDevice. .Streami 0000DED3: 63 65 53 65 74 75 70 00 . 32 00 00 00 00 00 E0 01 ceSetup. 2…..・ A—– COMEBJ .222 0000E000 01:41.58 18/04/2004 –a– W32i - - - - 57,344 04-18-2004 comebj.222 A C:\FINDnFIX\junkxxx\comebj.222 File: CRC-32 : D5C9FB2E MD5 : C185B36F 9969D3A6 D2122BA7 CBC02249 ササPermissions: C:\FINDnFIX\junkxxx\comebj.222 Everyone:(special access:) SYNCHRONIZE FILE_EXECUTE NT AUTHORITY\SYSTEM:F BUILTIN\Administrators:F C:\FINDnFIX\junkxxx\comebj.222 Everyone:(special access:) SYNCHRONIZE FILE_EXECUTE NT AUTHORITY\SYSTEM:F BUILTIN\Administrators:F Directory "C:\FINDnFIX\junkxxx\." Permissions: Type Flags Inh. Mask Gen. Std. File Group or User ======= ======== ==== ======== ==== ==== ==== ================ Allow 00000003 tco- 001F01FF —- DSPO rw+x \Everyone Allow 00000009 –o- 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM Allow 00000002 tc– 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM Allow 00000009 –o- 001F01FF —- DSPO rw+x BUILTIN\Administrators Allow 00000002 tc– 001F01FF —- DSPO rw+x BUILTIN\Administrators Owner: BUILTIN\Administrators Primary Group: BDP-986Z\None Directory "C:\FINDnFIX\junkxxx\.." Permissions: Type Flags Inh. Mask Gen. Std. File Group or User ======= ======== ==== ======== ==== ==== ==== ================ Allow 00000003 tco- 001F01FF —- DSPO rw+x \Everyone Owner: BUILTIN\Administrators Primary Group: BDP-986Z\None File "C:\FINDnFIX\junkxxx\comebj.222" Permissions: Type Flags Inh. Mask Gen. Std. File Group or User ======= ======== ==== ======== ==== ==== ==== ================ Allow 00000000 t— 00100020 —- —- —x \Everyone Allow 00000000 t— 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM Allow 00000000 t— 001F01FF —- DSPO rw+x BUILTIN\Administrators Owner: BUILTIN\Administrators Primary Group: BDP-986Z\None ササSize of Windows key: (*Default-450 *No AppInit-398 *fake(infected)-448,504,512…) Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 450 ササDumping Values: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows DeviceNotSelectedTimeout = 15 GDIProcessHandleQuota = REG_DWORD 0x00002710 Spooler = yes swapdisk = TransmissionRetryTimeout = 90 USERProcessHandleQuota = REG_DWORD 0x00002710 AppInit_DLLs = ササSecurity settings for 'Windows' key: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: (NI) ALLOW Read BUILTIN\Users (IO) ALLOW Read BUILTIN\Users (NI) ALLOW Read BUILTIN\Power Users (IO) ALLOW Read BUILTIN\Power Users (NI) ALLOW Full access BUILTIN\Administrators (IO) ALLOW Full access BUILTIN\Administrators (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access BUILTIN\Administrators (IO) ALLOW Full access CREATOR OWNER Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: Read BUILTIN\Users Read BUILTIN\Power Users Full access BUILTIN\Administrators Full access NT AUTHORITY\SYSTEM ササNotepad check…. C:\WINNT\ notepad.exe Tue May 8 2001 12:00:00p A…. 50,960 49.77 K 1 item found: 1 file, 0 directories. Total of file sizes: 50,960 bytes 49.77 K C:\WINNT\SYSTEM32\ notepad.exe Tue May 8 2001 12:00:00p A…. 50,960 49.77 K 1 item found: 1 file, 0 directories. Total of file sizes: 50,960 bytes 49.77 K C:\WINNT\SYSTEM32\DLLCACHE\ notepad.exe Tue May 8 2001 12:00:00p A…. 50,960 49.77 K 1 item found: 1 file, 0 directories. Total of file sizes: 50,960 bytes 49.77 K –a– W32i APP ENU 5.0.2140.1 shp 50,960 05-08-2001 notepad.exe Language 0x0409 (English (United States)) CharSet 0x04b0 Unicode OleSelfRegister Disabled CompanyName Microsoft Corporation FileDescription Notepad InternalName Notepad OriginalFilenam NOTEPAD.EXE ProductName Microsoft® Windows ® 2000 Operating System ProductVersion 5.00.2140.1 FileVersion 5.00.2140.1 LegalCopyright Copyright © Microsoft Corp. 1981-1999 VS_FIXEDFILEINFO: Signature: feef04bd Struc Ver: 00010000 FileVer: 00050000:085c0001 (5.0:2140.1) ProdVer: 00050000:085c0001 (5.0:2140.1) FlagMask: 0000003f Flags: 00000000 OS: 00040004 NT Win32 FileType: 00000001 App SubType: 00000000 FileDate: 00000000:00000000 00001150: ? 00001190: rem H x 000011D0: vk d DeviceNotSelectedTimeout 1 5 00001210:H vk ' 0 GDIProcessHandleQuota 0 vk 00001250: h 0 Spooler y e s 0 0 vk 0 00001290:swapdisk vk , TransmissionRetryTimeout 9 0 000012D0: e F} vk ' 0 USERProcessHandleQuota0 00001310: vk M AppInit_DLLsultIcon JM ding bac 00001350:kup utilities or disk-intensive applications. If you need to 00001390: use Safe Mode to remove or disable components, restart your co 000013D0:mputer, press F8 to select Advanced Startup Options, and then s 00001410:elect Safe Mode. Refer to your Getting Started manual for mor 00001450:e information on troubleshooting Stop errors. If this 00001490:is the first time you've seen this Stop error screen, restart y 000014D0:our computer. If this screen appears again, follow these steps: 00001510: Check for viruses on your computer. Remove any newly install 00001550:e ———- NEWWIN.TXT AppInit_DLLsultIcon ————– ————– ————– No strings found.
Well done :D Nearly there, open the FINDnFIX folder again and open the Files2 folder. Double-click on the ZIPZAP.bat. It will quickly clean the rest and will make a copy of the bad file(s) in the same folder (junkxxx.zip) and open your email client with instructions. Simply drag and drop the junkxxx.zip file from the folder into the mail message and submit to the specified addresses.

Please be sure to include a link to this thread in the body of your email. Reboot when done, then delete the entire FINDnFIX folder. Could you click here to download CWShredder by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'. If you already have CWShredder, click 'Check for update' and make sure you are running version 1.59.1 Reboot when done. Rescan with HJT and post a new log in your next reply.
P.S. I noticed that in the procedures I undertook yesterday with CWShredder, Ad-Aware, Registrar Lite and FindnFix.exe, the list of 'Favorites' websites disappeared. This would be a small price to pay to get rid of 'About:Blank' but if there is a simple way to restore my 'Favorites', I would like to do that. Thank you.
To: Forum God / Super Mod:

Here is new log of HJT after rebooting after deleting 'FINDnFIX' folder:

Logfile of HijackThis v1.97.7
Scan saved at 3:13:25 PM, on 7/10/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\ibmpmsvc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\Hummbird\inetd32.exe
C:\WINNT\System32\NMSSvc.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\AEIWLSTA.EXE
C:\WINNT\LTSMMSG.exe
C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe
C:\Program Files\Funk Software\Odyssey Client\OdTray.exe
C:\WINNT\tppaldr.exe
C:\Program Files\Maxtor Corporation\MaxTools\CBMon.EXE
C:\WINNT\AGRSMMSG.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Handspring\HOTSYNC.EXE
d:\Documents and Settings\charles.mcneill.BDP-986Z\My Documents\Hijack This Folder\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://martfinder.com/index.htm?aff=4444
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://intra.undp.org
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://intra.undp.org
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://intra.undp.org
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.undp.org/.proxy
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.undp.org:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://intra.undp.org
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://intra.undp.org
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://intra.undp.org/
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AEIWLSTA.EXE] AEIWLSTA.EXE
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [TpHotkey] C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe
O4 - HKLM\..\Run: [OdTray.exe] "C:\Program Files\Funk Software\Odyssey Client\OdTray.exe"
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINNT\tppaldr.exe
O4 - HKLM\..\Run: [Indigita CBmon] C:\Program Files\Maxtor Corporation\MaxTools\CBMon.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [win32.exe] C:\WINNT\win32.exe
O4 - HKLM\..\Run: [SysUpd] C:\WINNT\sysupd.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Remndr] "C:\Program Files\CasinoOnline\CsRemnd.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Handspring\HOTSYNC.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {11111111-1111-1111-1111-111111111123} - file://c:\winnt\win.exe
O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://super-gals.com/scj/rotation/templates/um2/x.chm::/ad.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/…7875.3027777778
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup143.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = MSAD.undp.org
O17 - HKLM\System\CCS\Services\Tcpip\..\{48B9C9CD-1257-4994-84F9-70E6387A7396}: NameServer = 165.65.6.8,192.124.42.15
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = MSAD.undp.org
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = MSAD.undp.org

Thank you!
Create a new folder called C:\HijackThis, move the HijackThis.exe file into the new folder and run it from there. This is necessary to ensure you have backups should anything go wrong.

Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://martfinder.com/index.htm?aff=4444
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [win32.exe] C:\WINNT\win32.exe
O4 - HKLM\..\Run: [SysUpd] C:\WINNT\sysupd.exe
O4 - HKLM\..\Run: [Remndr] "C:\Program Files\CasinoOnline\CsRemnd.exe"
O16 - DPF: {11111111-1111-1111-1111-111111111123} - file://c:\winnt\win.exe
O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://super-gals.com/scj/rotation/templates/um2/x.chm::/ad.exe


If you didn't set these restrictions fix these entries also:

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

Click here, for instructions on how to enable hidden files and folders to be visible. After enabling, reboot into safe mode by tapping F8 after the BIOS has loaded, find and delete the following:

C:\WINNT\win32.exe
C:\WINNT\sysupd.exe
C:\Program Files\CasinoOnline\ <– folder

Reboot when done, rescan with HJT and post a new log here for a final check over.
To: Forum God / Super Mod:

I don't know how to thank you! This nasty hijacking software has been such a problem for months now. It seems that the nightmare is coming to an end! I am so grateful to you. What would I do without this help? And who are these crazies who generate this kind of Hijacking tricks? I offer you my most sincere thanks for your generous and expert help through this process.

Do you think that running an updated 'AdAware' will help avoid this in the future? Should I also install SpyBot?

Thank you very, very, very, very, very much, once again!!

Here is latest HJT file ….


Logfile of HijackThis v1.97.7
Scan saved at 11:09:00 AM, on 7/12/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\ibmpmsvc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\Hummbird\inetd32.exe
C:\WINNT\System32\NMSSvc.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\AEIWLSTA.EXE
C:\WINNT\LTSMMSG.exe
C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe
C:\Program Files\Funk Software\Odyssey Client\OdTray.exe
C:\WINNT\tppaldr.exe
C:\Program Files\Maxtor Corporation\MaxTools\CBMon.EXE
C:\WINNT\AGRSMMSG.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Handspring\HOTSYNC.EXE
d:\Documents and Settings\charles.mcneill.BDP-986Z\My Documents\Hijack This Folder\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://intra.undp.org
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://intra.undp.org
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://intra.undp.org
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.undp.org/.proxy
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.undp.org:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://intra.undp.org
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://intra.undp.org
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://intra.undp.org/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AEIWLSTA.EXE] AEIWLSTA.EXE
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [TpHotkey] C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe
O4 - HKLM\..\Run: [OdTray.exe] "C:\Program Files\Funk Software\Odyssey Client\OdTray.exe"
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINNT\tppaldr.exe
O4 - HKLM\..\Run: [Indigita CBmon] C:\Program Files\Maxtor Corporation\MaxTools\CBMon.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Handspring\HOTSYNC.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/…7875.3027777778
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup143.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = MSAD.undp.org
O17 - HKLM\System\CCS\Services\Tcpip\..\{48B9C9CD-1257-4994-84F9-70E6387A7396}: NameServer = 165.65.6.8,192.124.42.15
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = MSAD.undp.org
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = MSAD.undp.org
That looks OK now - how is it running?

The people responsible for these pests do not care about the misery and inconvenience they impose upon people. :angry:

Anyway, to help keep you clean follow the recommendations in Tony's article here:

So how did I get infected in the first place?
To: Super Moderator: My computer is running great and I am so relieved to have that wretched 'Alien' removed! (It reminds me a lot of the first 'Alien' movie that Sigouney Weaver starred in.) I really am very, very grateful to you, oh Masked Person, and thank you deeply for your help. Sincerely, A fellow traveller
You're welcome - glad to help :D



As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI