This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack This Log

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Have win XP, just got latest updates w SP 1. Have IE 6. Cannot get Goggle when accessing internet, also getting strange websites added to my favorites. Below is my "hijackthis" log, please help.


Logfile of HijackThis v1.98.2
Scan saved at 9:56:42 AM, on 8/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\STOPzilla!\szntsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\SpyHunter\PopupBlocker\EnigmaPopupStop.exe
C:\Program Files\STOPzilla!\Stopzilla.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Intuit\QuickBooks Basic\Components\QBAgent\qbdagent2002.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\DRose\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\WINDOWS\explorer.exe

R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://jevpzn.outhost.info/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowws.cc/hp.htm?id=9
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://google.com/
R3 - Default URLSearchHook is missing
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\DRose\Application Data\Mozilla\Profiles\default\iz0zodim.slt\prefs.js)
O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - (no file)
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\System32\SZIEBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: SuperBar - {D71B5CC1-7EF3-4F54-8CF7-9E8CD6BC6DDB} - C:\Program Files\SuperBar\SuperBar.Dll
O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Key2] C:\WINDOWS\system\serve.exe
O4 - HKLM\..\Run: [EnigmaPopupStop] C:\Program Files\SpyHunter\PopupBlocker\EnigmaPopupStop.exe
O4 - HKLM\..\Run: [ICQ Net] C:\WINDOWS\winlogon.exe -stealth
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [BPZHRM] C:\WINDOWS\BPZHRM.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [pnpsvc_lock] C:\WINDOWS\System32\696604.exe
O4 - HKLM\..\Run: [WebInstall2] C:\Program Files\ClipGenie\WebInstall.exe /R
O4 - HKLM\..\Run: [romahere] C:\WINDOWS\System32\matrixhere.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [romahere] C:\WINDOWS\System32\matrixhere.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks 2002 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Basic\Components\QBAgent\qbdagent2002.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Home Equity Loan - http://213.159.118.226/tools.php?qq=Home+Equity+Loan
O8 - Extra context menu item: Incorporate - http://213.159.118.226/tools.php?qq=Incorporate
O8 - Extra context menu item: Refinancing My Mortgage - http://213.159.118.226/tools.php?qq=Refinancing+My+Mortgage
O8 - Extra context menu item: Sell Future Payment - http://213.159.118.226/tools.php?qq=Sell+Future+Payment
O8 - Extra context menu item: Time Clock - http://213.159.118.226/tools.php?qq=Time+Clock
O8 - Extra context menu item: Tramadol - http://213.159.118.226/tools.php?qq=Tramadol
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll
O9 - Extra button: (no name) - {1A00C40B-DA85-4aa3-A67F-582D9347EECD} - C:\WINDOWS\System32\TD.exe
O9 - Extra 'Tools' menuitem: Turbo Download - {1A00C40B-DA85-4aa3-A67F-582D9347EECD} - C:\WINDOWS\System32\TD.exe
O9 - Extra button: (no name) - {2BF6CEC9-A099-4D97-AD5A-EAB9CAB33AAE} - http://213.159.118.226/Refinancing+My+Mortgage.html (file missing)
O9 - Extra 'Tools' menuitem: Refinancing My Mortgage - {2BF6CEC9-A099-4D97-AD5A-EAB9CAB33AAE} - http://213.159.118.226/Refinancing+My+Mortgage.html (file missing)
O9 - Extra button: Cosmi Popup Blocker - {4B3520B0-D518-4443-BA9E-2D4CE7F773C5} - C:\Program Files\Cosmi\Pop Up Ad Blocker\PopupBlock.exe
O9 - Extra 'Tools' menuitem: Cosmi Popup Blocker - {4B3520B0-D518-4443-BA9E-2D4CE7F773C5} - C:\Program Files\Cosmi\Pop Up Ad Blocker\PopupBlock.exe
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Ebates - {7F241C00-DAB6-11d5-AAA8-0001028DF1BC} - file://C:\Program Files\EbatesMoeMoneyMaker\System\Temp\ebates_script0.htm (HKCU)
O12 - Plugin for .fpx: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .ivr: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O15 - Trusted Zone: *.greg-search.com
O16 - DPF: {0191ABF4-9421-435E-9FFD-CD827A2A82D8} (SBITAX7Ctrl Class) - http://directplugin.com/tl7000.dll
O16 - DPF: {11111111-1111-1111-1111-111111111157} - file://C:\Program Files\Internet Explorer\Q330994.exe
O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} - http://download.abetterinternet.com/downlo…34006/lotto.cab
O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4…006_regular.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {D9EC0A76-03BF-11D4-A509-0090270F86E3} - http://cdn2.adsdk.com/bannerfarm/47309/Bun…r1132031209.EXE
O16 - DPF: {F48EAB92-8BCE-4C77-BE98-D10060BD8590} (SpyBouncer.SBDownloader) - http://www.spybouncer.com/downloader/downloader.ocx
O18 - Filter: text/plain - (no CLSID) - (no file)
O19 - User stylesheet: C:\WINDOWS\system32\o463.w1f
O20 - AppInit_DLLs: pe8mxtubijoj8.tlb 2o6rmsbgptbd.tlb
Thanks for sending your HijackThis logfile. We apologize for the delay in responding. If you still need some help with your problem, please respond to this thread with a fresh HijackThis log. I will be notified automatically when that happens. Thanks daveai
Thank you for responding. Below is latest "hijack this " log.

Logfile of HijackThis v1.98.2
Scan saved at 3:07:23 PM, on 9/3/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\STOPzilla!\szntsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\mHotkey.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\SpyHunter\PopupBlocker\EnigmaPopupStop.exe
C:\Program Files\STOPzilla!\Stopzilla.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\0isbncyo66n.exe
C:\Program Files\Intuit\QuickBooks Basic\Components\QBAgent\qbdagent2002.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowws.cc/hp.htm?id=9
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://google.com/
R3 - Default URLSearchHook is missing
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\DRose\Application Data\Mozilla\Profiles\default\iz0zodim.slt\prefs.js)
O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - (no file)
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\System32\SZIEBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: SuperBar - {D71B5CC1-7EF3-4F54-8CF7-9E8CD6BC6DDB} - C:\Program Files\SuperBar\SuperBar.Dll
O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Key2] C:\WINDOWS\system\serve.exe
O4 - HKLM\..\Run: [EnigmaPopupStop] C:\Program Files\SpyHunter\PopupBlocker\EnigmaPopupStop.exe
O4 - HKLM\..\Run: [ICQ Net] C:\WINDOWS\winlogon.exe -stealth
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [BPZHRM] C:\WINDOWS\BPZHRM.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [pnpsvc_lock] C:\WINDOWS\System32\174488187.exe
O4 - HKLM\..\Run: [WebInstall2] C:\Program Files\ClipGenie\WebInstall.exe /R
O4 - HKLM\..\Run: [Network Security Guard] C:\WINDOWS\System32\0isbncyo66n.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks 2002 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Basic\Components\QBAgent\qbdagent2002.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Home Equity Loan - http://213.159.118.226/tools.php?qq=Home+Equity+Loan
O8 - Extra context menu item: Incorporate - http://213.159.118.226/tools.php?qq=Incorporate
O8 - Extra context menu item: Refinancing My Mortgage - http://213.159.118.226/tools.php?qq=Refinancing+My+Mortgage
O8 - Extra context menu item: Sell Future Payment - http://213.159.118.226/tools.php?qq=Sell+Future+Payment
O8 - Extra context menu item: Time Clock - http://213.159.118.226/tools.php?qq=Time+Clock
O8 - Extra context menu item: Tramadol - http://213.159.118.226/tools.php?qq=Tramadol
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll
O9 - Extra button: (no name) - {1A00C40B-DA85-4aa3-A67F-582D9347EECD} - C:\WINDOWS\System32\TD.exe
O9 - Extra 'Tools' menuitem: Turbo Download - {1A00C40B-DA85-4aa3-A67F-582D9347EECD} - C:\WINDOWS\System32\TD.exe
O9 - Extra button: (no name) - {2BF6CEC9-A099-4D97-AD5A-EAB9CAB33AAE} - http://213.159.118.226/Refinancing+My+Mortgage.html (file missing)
O9 - Extra 'Tools' menuitem: Refinancing My Mortgage - {2BF6CEC9-A099-4D97-AD5A-EAB9CAB33AAE} - http://213.159.118.226/Refinancing+My+Mortgage.html (file missing)
O9 - Extra button: Cosmi Popup Blocker - {4B3520B0-D518-4443-BA9E-2D4CE7F773C5} - C:\Program Files\Cosmi\Pop Up Ad Blocker\PopupBlock.exe
O9 - Extra 'Tools' menuitem: Cosmi Popup Blocker - {4B3520B0-D518-4443-BA9E-2D4CE7F773C5} - C:\Program Files\Cosmi\Pop Up Ad Blocker\PopupBlock.exe
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Ebates - {7F241C00-DAB6-11d5-AAA8-0001028DF1BC} - file://C:\Program Files\EbatesMoeMoneyMaker\System\Temp\ebates_script0.htm (HKCU)
O12 - Plugin for .fpx: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .ivr: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {0191ABF4-9421-435E-9FFD-CD827A2A82D8} (SBITAX7Ctrl Class) - http://directplugin.com/tl7000.dll
O16 - DPF: {11111111-1111-1111-1111-111111111157} - file://C:\Program Files\Internet Explorer\Q330994.exe
O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} - http://download.abetterinternet.com/downlo…34006/lotto.cab
O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4…006_regular.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {D9EC0A76-03BF-11D4-A509-0090270F86E3} - http://cdn2.adsdk.com/bannerfarm/47309/Bun…r1132031209.EXE
O16 - DPF: {F48EAB92-8BCE-4C77-BE98-D10060BD8590} (SpyBouncer.SBDownloader) - http://www.spybouncer.com/downloader/downloader.ocx
O18 - Filter: text/plain - (no CLSID) - (no file)
O19 - User stylesheet: C:\WINDOWS\system32\o463.w1f
O20 - AppInit_DLLs: pe8mxtubijoj8.tlb 2o6rmsbgptbd.tlb ogokkzd0fy0us.tlb ea204kegr76yd.tlb r41p14zub8rl.tlb
scpovet – Thanks for sending your HijackThis logfile. You have a CoolWebSearch infection among other malware problems.

You are running SpyHunter (or Spykiller). This is a program that advertises itself as removing spyware, but it apparently gives false positives to get you to buy it and then does a miserable job. Some even thing that it may install malware. I recommend that you remove it in Add/Remove Programs, and have included the items to fix in HJT in this post. See this post for details about these programs:
this link

Go ahead and print these instructions, or save them to your desktop, to help keep track of the steps.

To start, allow yourself to view "Hidden files". Open Windows Explorer and go to "Tools" => "Folder Options" => "View" then click on the "Show Hidden Files and Folders" option, and un-check "Hide extensions for known file types" and "Hide protected operating system files" options. Then click the "Apply To All Folders" button.

1 – Please see How to use Ad-Aware SE to remove Spyware for instructions on how to download, install and then use this software.

Don´t use AdAware yet.

If you already have AdAwareinstalled, then make sure it's up to date. Just open Adaware and click on "Check for Updates Now" and then "Connect". It will find a new reference-file. Click "ok" and let it download and install the updates by clicking on "Finish" .This will return you to the main screen. You should now see Reference File # : 01R337 11.08.2004 or higher listed.

Don´t use AdAware yet.

2 – Download the newest version of CWShredder by Merijn Bellekom (1.59.1). Run it, hit 'fix' as opposed to 'scan only'.

3 – Run HijackThis, and press Scan, and put a check against the following entries, if they still show up: (NOTE that some of these are likely to be gone because of CWShredder) Make sure all browsers and program windows are closed except for HijackThis.

R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowws.cc/hp.htm?id=9
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - (no file)

O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL

O4 - HKLM\..\Run: [EnigmaPopupStop] C:\Program Files\SpyHunter\PopupBlocker\EnigmaPopupStop.exe

O4 - HKLM\..\Run: [ICQ Net] C:\WINDOWS\winlogon.exe -stealth
O4 - HKLM\..\Run: [BPZHRM] C:\WINDOWS\BPZHRM.exe
O4 - HKLM\..\Run: [pnpsvc_lock] C:\WINDOWS\System32\174488187.exe
O4 - HKLM\..\Run: [WebInstall2] C:\Program Files\ClipGenie\WebInstall.exe /R
O4 - HKLM\..\Run: [Network Security Guard] C:\WINDOWS\System32\0isbncyo66n.exe

O16 - DPF: {0191ABF4-9421-435E-9FFD-CD827A2A82D8} (SBITAX7Ctrl Class) - http://directplugin.com/tl7000.dll
O16 - DPF: {11111111-1111-1111-1111-111111111157} - file://C:\Program Files\Internet Explorer\Q330994.exe
O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} - http://download.abetterinternet.com/downlo…34006/lotto.cab
O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4…006_regular.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {D9EC0A76-03BF-11D4-A509-0090270F86E3} - http://cdn2.adsdk.com/bannerfarm/47309/Bun…r1132031209.EXE

Once you have selected all the items for HJT to fix, make sure all browsers and program windows are closed except for HijackThis, and click fix checked.

4 – Reboot into Safe Mode (How do I boot into "Safe" mode?).

Use Windows Explorer to delete the following lists of program files and folders, if they still exist.

C:\WINDOWS\winlogon.exe <– this file NOTE, THE FOLDER on this one…it IS NOT "C:\WINDOWS\system32\winlogon.exe" which is a required file!!!!

C:\WINDOWS\BPZHRM.exe <– this file
C:\WINDOWS\bad3074.exe <– this file (may already be gone)

C:\WINDOWS\System32\174488187.exe <– this file
C:\WINDOWS\System32\0isbncyo66n.exe <– this file


C:\Program Files\ClipGenie\ <– this folder
C:\Program Files\SpyHunter\ <– this folder
C:\Program Files\MyWay\ <– this folder

Please let me know about any problems with the file/folder deletes.

5 – Then, while still in safe mode, use "Start > Run" and type in "%temp%" (without the quotes). Delete the entire contents of that "temp" folder (use "Edit > Select All", press "Delete", click "Yes").

Then, to completely empty your Temporary Internet Cache completely, please close all instances of Outlook and Internet Explorer, then use "Control Panel > Internet Options > General tab" and click the "Delete File" button. When prompted place a check in: "Delete all offline content", then click "OK".

Then, use Windows Explorer to empty out ALL the other temp folders on your system (navigate to each folder, use "Edit > Select All", press "Delete", click "Yes"):

* C:\Documents and Settings\\Local Settings\Temp\
* C:\Documents and Settings\\Local Settings\Temporary Internet Files\
* C:\Documents and Settings\\Local Settings\Temp\
* Empty your "Recycle Bin".

Please let me know about any problems with the temp file deletes.

6 – Now scan with Adaware SE and let it remove any bad files found.

Please let me know if anything can not be cleaned by AdAware SE.

7 – Reboot into normal mode and post a fresh HijackThis log in this thread. And, if you had any problems with the steps outlined above, please let us know what they were. Your response and the new logfile will determine the next steps for this fix.
.
Thanks
daveai
daveai: Thanks for reviewing my HJ scan and your response. Per your suggestions, and in order of the procedures you provided, I did the following:
1. Uninstalled Spyhunter/Spykiller.
2. Downloaded AdAware SE and instructions for it.
3. Ran Using CWShredder (1.59.1) fix (although not much done here).
4. Ran HJ Scan and checked all of your suggested items and only a couple were not present, most were.
5. I could not locate C:\Windows\winlogon.exe but did a search for it and the search revealed a c:\windows\prefetch\winlogon.exe with the type file as PF which was created 9/9/2003 and last modified 9/2/04. I did not delete this file not sure if one you were referring to.
6. Following files and folders were not present:
*c:\windows\bpzhrm.exe
*c:\windows\bad3074.exe
*c:\program files\clipgenie
*c:\program files\spyhunter and c:\program files\MyWay were deleted
7. Deleted entire contents of that %temp% file
8. Emptied the 4 temp folders and files you identified
9. Scanned with the ADAware SE and it deleted (not quarantined) all files none were left behind.
10. Rebooted and ran the enclosed HJ Log

Am now awaiting your review and response to determine next step(s) to be taken and again thanks for your time and patience.

Logfile of HijackThis v1.98.2
Scan saved at 3:03:22 PM, on 9/4/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\STOPzilla!\szntsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\mHotkey.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\STOPzilla!\Stopzilla.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\0isbncyo66n.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Intuit\QuickBooks Basic\Components\QBAgent\qbdagent2002.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\System32\0isbncyo66n.exe
C:\WINDOWS\System32\0isbncyo66n.exe
C:\WINDOWS\System32\0isbncyo66n.exe
C:\WINDOWS\System32\0isbncyo66n.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\0isbncyo66n.exe
C:\WINDOWS\System32\0isbncyo66n.exe
C:\WINDOWS\System32\0isbncyo66n.exe
C:\WINDOWS\System32\0isbncyo66n.exe
C:\WINDOWS\System32\0isbncyo66n.exe
C:\WINDOWS\System32\0isbncyo66n.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowws.cc/hp.htm?id=9
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://google.com/
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\DRose\Application Data\Mozilla\Profiles\default\iz0zodim.slt\prefs.js)
O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - (no file)
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\System32\SZIEBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: SuperBar - {D71B5CC1-7EF3-4F54-8CF7-9E8CD6BC6DDB} - C:\Program Files\SuperBar\SuperBar.Dll (file missing)
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Key2] C:\WINDOWS\system\serve.exe
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Network Security Guard] C:\WINDOWS\System32\0isbncyo66n.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks 2002 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Basic\Components\QBAgent\qbdagent2002.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Home Equity Loan - http://213.159.118.226/tools.php?qq=Home+Equity+Loan
O8 - Extra context menu item: Incorporate - http://213.159.118.226/tools.php?qq=Incorporate
O8 - Extra context menu item: Refinancing My Mortgage - http://213.159.118.226/tools.php?qq=Refinancing+My+Mortgage
O8 - Extra context menu item: Sell Future Payment - http://213.159.118.226/tools.php?qq=Sell+Future+Payment
O8 - Extra context menu item: Time Clock - http://213.159.118.226/tools.php?qq=Time+Clock
O8 - Extra context menu item: Tramadol - http://213.159.118.226/tools.php?qq=Tramadol
O9 - Extra button: (no name) - {2BF6CEC9-A099-4D97-AD5A-EAB9CAB33AAE} - http://213.159.118.226/Refinancing+My+Mortgage.html (file missing)
O9 - Extra 'Tools' menuitem: Refinancing My Mortgage - {2BF6CEC9-A099-4D97-AD5A-EAB9CAB33AAE} - http://213.159.118.226/Refinancing+My+Mortgage.html (file missing)
O9 - Extra button: Cosmi Popup Blocker - {4B3520B0-D518-4443-BA9E-2D4CE7F773C5} - C:\Program Files\Cosmi\Pop Up Ad Blocker\PopupBlock.exe
O9 - Extra 'Tools' menuitem: Cosmi Popup Blocker - {4B3520B0-D518-4443-BA9E-2D4CE7F773C5} - C:\Program Files\Cosmi\Pop Up Ad Blocker\PopupBlock.exe
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .fpx: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .ivr: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {F48EAB92-8BCE-4C77-BE98-D10060BD8590} (SpyBouncer.SBDownloader) - http://www.spybouncer.com/downloader/downloader.ocx
O19 - User stylesheet: C:\WINDOWS\system32\o463.w1f
O20 - AppInit_DLLs: 4yhpg4hpb4tw.tlb 6xvs7eohdgj.tlb aale6jt4oh2.tlb suzt71z2a514.tlb 3lezyc9ymeu8s.tlb 3g9zzfk88h4a.tlb dwfjvacg0ds.tlb m37cy0rd2vt.tlb 10vbyvr5r0v.tlb y2xa8bto77va.tlb jpee5pnzcibuc.tlb pveyvl4k6iusu.tlb 72l54ml6zo6pjx.tlb cm7ezm6hez.tlb 5n6970m7exj8jx.tlb u5288hl0r53k.tlb enni7oztfra3h3.tlb amrgdw343vo.tlb dibvk6a9i2.tlb umom38caiueeb.tlb x7ldn0808eee.tlb s0lhd2vid5li.tlb fu77ab7ytn76bv.tlb pban9ei7ihtbs4.tlb 4zajltdopp7ob8.tlb gbdt7x93s2osk.tlb sw4d5zy05lc5c.tlb dip2o0u56fd8x.tlb 2g7ab8ntg6y2p5.tlb 5y70j8i77ehnn.tlb ljbmxhoctxz.tlb x6j2etmypy1.tlb z8gci9tzmz5yrt.tlb 9skn6d3x1ioii3.tlb zwn707j1fa94pr.tlb 8g8w3hf8di.tlb czzlm2aevio.tlb as4rk84x7bim66.tlb y85jhgco9r4hp.tlb iohv65fcgmmb.tlb um0fjrdsxl40p9.tlb fgwvrvr032c1.tlb 2nthefdy0ulp.tlb

Thanks,
scpovet
scpovet – Thanks for sending your HijackThis log.

Your log still shows signs of infection, Including remnants of SpyKiller I didn't realize were there until doing some additional research. Also, I'm sorry to say I missed two HJT items inthe last fix :( My apologies. The fix below should take care of these.

Go ahead and print these instructions, or save them to your desktop, to help keep track of the steps.

1 – Reboot into Safe Mode (How do I boot into "Safe" mode?).

2 – Run HijackThis, and press Scan, and put a check against the following entries, if they still show up. Make sure all browsers and program windows are closed except for HijackThis.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowws.cc/hp.htm?id=9

O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - (no file)

O3 - Toolbar: SuperBar - {D71B5CC1-7EF3-4F54-8CF7-9E8CD6BC6DDB} - C:\Program Files\SuperBar\SuperBar.Dll (file missing)

O4 - HKLM\..\Run: [Network Security Guard] C:\WINDOWS\System32\0isbncyo66n.exe

O8 - Extra context menu item: Home Equity Loan - http://213.159.118.226/tools.php?qq=Home+Equity+Loan
O8 - Extra context menu item: Incorporate - http://213.159.118.226/tools.php?qq=Incorporate
O8 - Extra context menu item: Refinancing My Mortgage - http://213.159.118.226/tools.php?qq=Refinancing+My+Mortgage
O8 - Extra context menu item: Sell Future Payment - http://213.159.118.226/tools.php?qq=Sell+Future+Payment
O8 - Extra context menu item: Time Clock - http://213.159.118.226/tools.php?qq=Time+Clock
O8 - Extra context menu item: Tramadol - http://213.159.118.226/tools.php?qq=Tramadol

O9 - Extra button: (no name) - {2BF6CEC9-A099-4D97-AD5A-EAB9CAB33AAE} - http://213.159.118.226/Refinancing+My+Mortgage.html (file missing)
O9 - Extra 'Tools' menuitem: Refinancing My Mortgage - {2BF6CEC9-A099-4D97-AD5A-EAB9CAB33AAE} - http://213.159.118.226/Refinancing+My+Mortgage.html (file missing)

O9 - Extra button: Cosmi Popup Blocker - {4B3520B0-D518-4443-BA9E-2D4CE7F773C5} - C:\Program Files\Cosmi\Pop Up Ad Blocker\PopupBlock.exe
O9 - Extra 'Tools' menuitem: Cosmi Popup Blocker - {4B3520B0-D518-4443-BA9E-2D4CE7F773C5} - C:\Program Files\Cosmi\Pop Up Ad Blocker\PopupBlock.exe

O19 - User stylesheet: C:\WINDOWS\system32\o463.w1f

O20 - AppInit_DLLs: 4yhpg4hpb4tw.tlb 6xvs7eohdgj.tlb aale6jt4oh2.tlb suzt71z2a514.tlb 3lezyc9ymeu8s.tlb 3g9zzfk88h4a.tlb dwfjvacg0ds.tlb m37cy0rd2vt.tlb 10vbyvr5r0v.tlb y2xa8bto77va.tlb jpee5pnzcibuc.tlb pveyvl4k6iusu.tlb 72l54ml6zo6pjx.tlb cm7ezm6hez.tlb 5n6970m7exj8jx.tlb u5288hl0r53k.tlb enni7oztfra3h3.tlb amrgdw343vo.tlb dibvk6a9i2.tlb umom38caiueeb.tlb x7ldn0808eee.tlb s0lhd2vid5li.tlb fu77ab7ytn76bv.tlb pban9ei7ihtbs4.tlb 4zajltdopp7ob8.tlb gbdt7x93s2osk.tlb sw4d5zy05lc5c.tlb dip2o0u56fd8x.tlb 2g7ab8ntg6y2p5.tlb 5y70j8i77ehnn.tlb ljbmxhoctxz.tlb x6j2etmypy1.tlb z8gci9tzmz5yrt.tlb 9skn6d3x1ioii3.tlb zwn707j1fa94pr.tlb 8g8w3hf8di.tlb czzlm2aevio.tlb as4rk84x7bim66.tlb y85jhgco9r4hp.tlb iohv65fcgmmb.tlb um0fjrdsxl40p9.tlb fgwvrvr032c1.tlb 2nthefdy0ulp.tlb


Once you have selected all the items for HJT to fix, make sure all browsers and program windows are closed except for HijackThis, and click fix checked.

3 – While still in safe mode, use Windows Explorer to delete the following lists of program files and folders, if they still exist.

C:\WINDOWS\System32\0isbncyo66n.exe <– this file

C:\WINDOWS\system32\o463.w1f <– this file

C:\Program Files\Cosmi\ <– this folder
C:\Program Files\SuperBar\ <– this folder

Please let me know about any problems with the file/folder deletes.

4 – Next, clean out all the temporary files and cookies on your system. Go to Start > Run and enter: cleanmgr. Let it scan your system for files to remove. Check these three boxes and then press ok to remove: Temporary Files, Temporary Internet Files, Recycle Bin.

5 – And run both of these two Online virus scans: Panda Active Scan and TrendMicro Housecall and put on Auto Clean.


Now, reboot normally, and create a new HJT logfile. Repost it here, and if you had any problems with the steps outlined above, please let us know what they were. Your response and the new logfile will determine the next steps for this fix.

Thanks
daveai
daveai: The following are the results per your procedures of 9/6/04. Numbered per your suggestions.

1. Reboot into Safe Mode: Could not. Am running XP…pressed F8 selected "Safe Mode" but only got Black Screen filled with multi(0)disk(0)rd(0)partition(1) and with numerous windows\system32\driver files and with "C" drive clicking away. After a period of time the normal full screen appeared to log on.
2. Ran HJThis and scanned and selected those items per your suggestion and then selected "Fix" with no problems.
3. While in normal mode (different from Safe Mode) deleted the following folders or files per suggestions for this step:'
*c:\windows\system 32\o463.w1f deleted
*c:\program files\Cosmi\ deleted
*c:\program files\Super Bar\ Win Explorer did not list it and
could not find it on search of c: drive
*c:\windows\systems 32\0isbncy66nexe was "Access Denied" and could delete this file.

4. Deleted all Temp Files and Recycle Bin

5. Ran Pada Active Scan and had 100 infected files of which 100 were disinfected. Ran TendMicro Scan which located 11 infected files classified as "non-cleanable". These were titled Sobit A and Sanbox A and Trojan Mojial A. Since there was only the choice of "non cleanable and delete, I pressed delete. Also, you suggested I put on Auto Clean but was not certain what or where I could locate this program. Please advise!!!

6. After procedures 1 thru 5 procedures concluded, checked new HJThis scan file and found that your #2 procedure RO-HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=…….returned, and the 02 and 04-HKLM\Network Security Guard files returned. Again checked those and indicated ignore and now these results are indicated below.

Continuing thanks for your assistance and help
scpovet-DRose

Logfile of HijackThis v1.98.2
Scan saved at 3:06:46 PM, on 9/6/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\STOPzilla!\szntsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\mHotkey.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\STOPzilla!\Stopzilla.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\0isbncyo66n.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Intuit\QuickBooks Basic\Components\QBAgent\qbdagent2002.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://google.com/
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\DRose\Application Data\Mozilla\Profiles\default\iz0zodim.slt\prefs.js)
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\System32\SZIEBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Key2] C:\WINDOWS\system\serve.exe
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks 2002 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Basic\Components\QBAgent\qbdagent2002.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .fpx: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .ivr: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {F48EAB92-8BCE-4C77-BE98-D10060BD8590} (SpyBouncer.SBDownloader) - http://www.spybouncer.com/downloader/downloader.ocx
O20 - AppInit_DLLs: zba8d5l225gtx.tlb s5lblmlec8m.tlb 2d29wmencbxea.tlb


Thanks,
scpovet
scpovet – Thanks for the reply.

The safemode reboot problem you had prevented you from deleting "C:\WINDOWS\System32\0isbncyo66n.exe" which I believe is an infected (or infecting) file.

Also, by having HJT "ignore" the offending R0, O2, O4 entries, we mask the problem, since it is still there, but now is not being reported by HJT. The infected O20 in your last log is evidence of continued problems.

Your question about "Auto Clean:" This is a check box that appears on the "Scan Now" page at Housecall (below the "Scan" button). Simply check the box. You did right to delete the offending files.

Please do this:

1 – Reboot to dafe mode by using the System Configuration Utility (msconfig). See the instructions in my previous link, and click open the "Windows XP" plus sign for instructions (near the bottom of hte page).

Then delete c:\windows\systems 32\0isbncy66nexe <– this file

if you can.

2 – Then, run the online trojan scan at: http://www.windowsecurity.com/trojanscan/ and delete any problem it finds.

3 – Then rerun HJT, get rid of the ignore settings, and create a new log for me.

I'll follow up with updated instructions to clean out the remaining problems.

Thanks
daveai
daveai:
Thank you for your reply. I am sorry about the "Safe Mode" problem but I finally did get to it and deleted the c:\windows\system32\0isbncy66nexe file. Then I got back to normal mode and ran the trojan scan @ windowsecurity.com as you suggested. This scan showed 0 infections.

I reran the HJT scan again…without any ignores (sorry again) and it is presented below. I am still having problems with my home page being hijacked, I prefer the Goggle search page but get something different and when I insert goggle.com all I get is a spyhunter site which begins scanning my computer. Will I ever get rid of this.

Logfile of HijackThis v1.98.2
Scan saved at 9:05:29 PM, on 9/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\STOPzilla!\szntsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\STOPzilla!\Stopzilla.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\mHotkey.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Intuit\QuickBooks Basic\Components\QBAgent\qbdagent2002.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\DRose\Application Data\Mozilla\Profiles\default\iz0zodim.slt\prefs.js)
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\System32\SZIEBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [Key2] C:\WINDOWS\system\serve.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks 2002 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Basic\Components\QBAgent\qbdagent2002.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .fpx: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .ivr: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.windowsecurity.com/trojanscan/TDECntrl.CAB
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

Thanks Again,
scpovet
Thanks for the response. I can find no malware in your log :)

Yes…we'll defeat the search page hijack. Given your clean logfile, I think the problem is one of resetting the page that you default to for searching.

The instructions quoted below are for IE…but I think I see you using Netscape. If so, this may be as easy as resetting the Microsoft browser to defaults, then importing the IE settings into Netscape. You may need to change your homepage after that, since Microsoft defaults go to MSN.

Or, you can take a look at the Netscape option to find a way to reset your default search page. If all else fails, I can query some of the Netscape users who are experts (on the anti-spyware boards I contribute to) to find out what the particular Netscape option is that they would point you at.

Either way, let me know what happens with this.

To reset Internet Explorer Web settings

If you installed another Web browser after installing Internet Explorer and Internet Tools, some of your Internet Explorer settings may have changed. You can reset your Internet Explorer settings to their original defaults, including your home page and search pages, and choice of default browser, without changing your other browser's settings.

On the Tools menu, click Internet Options.
Click the Programs tab.
Click the Reset Web Settings button.




Next, here are two optional items you may choose to fix using HJT:

Application Scheduler is installed along with RealOne Player and is running in startup, and is not needed. Once installed, it runs independently of RealOne Player and consumes resources. You can fix this with HJT, but you will also need to set it not to load in RealPlayer itself to keep it from resetting itself: (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK This is the item to fix in HJT:
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

Office Startup Asistant is an optional item that if checked, will eliminate a known resource hog. You will still be able to start Office components from the Start menu. This is the item to fix in HJT:
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE





And lastly for this post, please allow me to suggest some prevention steps to keep your computer clean and secure going forward. You may have already taken a few of the steps, but it never hurts to take a quick look :)

1 – Use an AntiVirus Software, and be sure you update it at least once a week. There are several very good free programs available. Grinler offers an outstanding overview at Virus, Spyware, and Malware Protection and Removal Resources

2 – To reduce re-infection potential for malware in the future, I strongly recommend installing three free programs: SpywareBlaster, SpywareGuard, and IE/Spyad.

3 – Use AdAware SE and Spybot S&D; to regularly to scan your system.

4 – It is very important to make sure that both Internet Explorer and XP are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.

5 – Consider using a Firewall. Just by using a Firewall in its default configuration can lower your risk greatly. Check out what Lawrence Abrams has to say at Understanding and Using Firewalls

An excellent overview is: So how did I get infected in the first place?. Be sure to visit the browser test link at the end of the article to really see how secure your system is!!

Thanks
daveai
Glad we could be of assistance. This topic is now closed. If you wish it
reopened, please send us an email (Click here to email) with a link to your thread.


Donations in support of this Web Site are always appreciated

Do not bother contacting us if you are not the topic starter. A valid,
working link to the closed topic is required along with the user name used.
If the user name does not match the one in the thread linked, the email will be deleted.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI