This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Desparate For Help ! Computer Going Crazy

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i have tried a lot of spyware removal ,,,,but nothing works…so please help!!! somone….here is my log —->

Logfile of HijackThis v1.98.2
Scan saved at 11:53:29 AM, on 11/11/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\River Sumida.bmp:chaxh
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Documents and Settings\3dsoundz\Application Data\wamo.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\Bwd0m.exe
C:\WINDOWS\System32\Bwd0m.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\system32\javacj32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\aiivn.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.heretofind.com/show.php?id=37&q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://xysearch.biz?wmid=3305
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\aiivn.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\aiivn.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.heretofind.com/show.php?id=37&q=%s
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://xysearch.biz?wmid=3305
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=Userinit.exe,TGBRFV_
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {B02C8A79-166D-EAED-C15F-3D1CC66CC436} - C:\WINDOWS\system32\javaka32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll (file missing)
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [an4] C:\WINDOWS\system32\an4.exe
O4 - HKLM\..\Run: [E9A840E6] C:\WINDOWS\system32\bnyf7zmjv.exe
O4 - HKLM\..\Run: [2ac74.exe] 2ac74.exe
O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"
O4 - HKLM\..\Run: [fwQiB] C:\documents and settings\3dsoundz\local settings\temp\fwQiB.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [javahv.exe] C:\WINDOWS\system32\javahv.exe
O4 - HKLM\..\Run: [d3yc.exe] C:\WINDOWS\system32\d3yc.exe
O4 - HKLM\..\Run: [apprn.exe] C:\WINDOWS\system32\apprn.exe
O4 - HKLM\..\Run: [u3enD] C:\documents and settings\3dsoundz\local settings\temp\u3enD.exe
O4 - HKLM\..\Run: [hgrN] c:\documents and settings\3dsoundz\local settings\temp\hgrN.exe
O4 - HKLM\..\Run: [31352cb07b8b] C:\WINDOWS\System32\appmgmts.exe
O4 - HKLM\..\Run: [3JR5B8429NJGXX] C:\WINDOWS\System32\VbhrYQop.exe
O4 - HKLM\..\Run: [javacj32.exe] C:\WINDOWS\system32\javacj32.exe
O4 - HKCU\..\Run: [an4] C:\WINDOWS\system32\an4.exe
O4 - HKCU\..\Run: [E9A840E6] C:\WINDOWS\system32\bnyf7zmjv.exe
O4 - HKCU\..\Run: [SearchSetter] C:\WINDOWS\System32\searchsetter[1].exe
O4 - HKCU\..\Run: [Iyfs] C:\WINDOWS\System32\?ervices.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Soce] C:\Documents and Settings\3dsoundz\Application Data\wamo.exe
O9 - Extra button: Corel Network monitor worker - {0C165A2B-E562-40CA-BD0A-91239FB3515B} - (no file)
O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {0C165A2B-E562-40CA-BD0A-91239FB3515B} - (no file)
O9 - Extra button: (no name) - {237AA178-C3BC-4f67-A8BB-D8BC14BA0B89} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Corel Network monitor worker - {0C165A2B-E562-40CA-BD0A-91239FB3515B} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {0C165A2B-E562-40CA-BD0A-91239FB3515B} - (no file) (HKCU)
O9 - Extra button: (no name) - {237AA178-C3BC-4f67-A8BB-D8BC14BA0B89} - (no file) (HKCU)
O13 - Home Prefix: http://www.heretofind.com/show.php?id=37&q=
O13 - Mosaic Prefix: http://www.heretofind.com/show.php?id=37&q=
O13 - Gopher Prefix: http://www.heretofind.com/show.php?id=37&q=
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44297DA} - http://bannerfarm.ace.advertising.com/bann…r1154041108.EXE
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN_XP.cab
O16 - DPF: {6A84C2AA-743E-5B05-E1FA-71A77E1E71A2} - http://209.8.161.54/1/rdgUS1022.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
hello 3dsoundz

You have one of the more difficult types of malware to get rid of and it will take several steps to complete the fix.
Step#1:

1. Please download Service Filter
2. Extract it to it's own folder.
3. Click on ServiceFilter.vbs
4. A text file called POST_THIS will be in the same folder
5. Please use Edit>Select all then Edit>Copy to obtain the contents
6. Please Post them into this thread using 'Add Reply'
This topic will be closed because it has been inactive for 21 days.

If you need it reopened, please send an email to the following (Click for address) with the Subject line of the email "Reopen".


To receive a response, please include in your email: your post user name, details of why you need it reopened, and a valid link to your post.

Emails with bad links to the post, emails that are not from the original poster, and emails that do not have "ReOpen" as the subject line, will be deleted without being opening.

Please start a New Topic if this is not your thread. Thank-you for your co-operation.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI