This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Searching All Has Got Me Cold

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am attaching my Hijack Scan Log, as instructed. Thanks in advance for all your help.

Logfile of HijackThis v1.99.0
Scan saved at 8:14:53 AM, on 12/18/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\winnt\system32\NtlogonWrk.EXE
C:\WINNT\SYSTEM32\DNTUS26.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\Clipsru.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\NtlogonWrk.EXE
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\ntlogon.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\w32time.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\mmdcd.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\qttask.exe
C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\TINASH~1\LOCALS~1\Temp\Rar$EX00.025\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchingall.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchingall.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchingall.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchingall.com/search/ssearch.php?q=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: SYpKOsbia1Obj Class - {068E7D1A-5C17-4403-ADA6-62FC25E2EF3D} - C:\WINNT\system32\drivers\input.dll
F2 - REG:system.ini: UserInit=C:\WINNT\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SYpKOsbia1 - {068E7D1A-5C17-4403-ADA6-62FC25E2EF3D} - C:\WINNT\system32\drivers\input.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Secure] net share ADMIN$ /delete /Y
O4 - HKLM\..\Run: [QuickTime Task] C:\WINNT\system32\qttask.exe
O4 - HKLM\..\Run: [NetworkStartup] net share /delete IPC$ /Y
O4 - HKLM\..\Run: [Secure1] net share /delete C$ /Y
O4 - HKLM\..\Run: [Secure2] net share /delete D$ /Y
O4 - HKLM\..\Run: [Secure3] net stop server /Y
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\RunOnce: [WMC_0] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\drmstor.dll"
O4 - HKLM\..\RunOnce: [WMC_1] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\drmclien.dll"
O4 - HKLM\..\RunOnce: [WMC_2] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\asfsipc.dll"
O4 - HKLM\..\RunOnce: [WMC_3] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\drmv2clt.dll"
O4 - HKLM\..\RunOnce: [WMC_4] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\blackbox.dll"
O4 - HKLM\..\RunOnce: [WMC_5] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\msnetobj.dll"
O4 - HKLM\..\RunOnce: [WMC_6] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\msisam11.dll"
O4 - HKLM\..\RunOnce: [WMC_7] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\mindex.dll"
O4 - HKLM\..\RunOnce: [WMC_8] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmstream.dll"
O4 - HKLM\..\RunOnce: [WMC_9] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmnetmgr.dll"
O4 - HKLM\..\RunOnce: [WMC_10] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmidx.ocx"
O4 - HKLM\..\RunOnce: [WMC_11] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmadmoe.dll"
O4 - HKLM\..\RunOnce: [WMC_12] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmadmod.dll"
O4 - HKLM\..\RunOnce: [WMC_13] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmsdmoe.dll"
O4 - HKLM\..\RunOnce: [WMC_14] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmsdmod.dll"
O4 - HKLM\..\RunOnce: [WMC_15] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmvdmoe.dll"
O4 - HKLM\..\RunOnce: [WMC_16] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmvdmod.dll"
O4 - HKLM\..\RunOnce: [WMC_17] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmv8dmoe.dll"
O4 - HKLM\..\RunOnce: [WMC_18] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmv8dmod.dll"
O4 - HKLM\..\RunOnce: [WMC_19] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\mpg4dmod.dll"
O4 - HKLM\..\RunOnce: [WMC_20] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\laprxy.dll"
O4 - HKLM\..\RunOnce: [WMC_21] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmvcore.dll"
O4 - HKLM\..\RunOnce: [WMC_22] "C:\WINNT\system32\logagent.exe" /RegServer
O4 - HKLM\..\RunOnce: [WMC_23] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\mswmdm.dll"
O4 - HKLM\..\RunOnce: [WMC_24] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\msscp.dll"
O4 - HKLM\..\RunOnce: [WMC_25] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\mspmsp.dll"
O4 - HKLM\..\RunOnce: [WMC_26] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmdmps.dll"
O4 - HKLM\..\RunOnce: [WMC_27] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmdmlog.dll"
O4 - HKLM\..\RunOnce: [WMC_28] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\CEWMDM.dll"
O4 - HKLM\..\RunOnce: [WMC_29] C:\WINNT\system32\mspmspsv.exe -i
O4 - HKLM\..\RunOnce: [WMC_30] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmpui.dll"
O4 - HKLM\..\RunOnce: [WMC_31] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmp.ocx"
O4 - HKLM\..\RunOnce: [WMC_32] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmpcore.dll"
O4 - HKLM\..\RunOnce: [WMC_33] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\wmpcd.dll"
O4 - HKLM\..\RunOnce: [WMC_34] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\pdbrowse.dll"
O4 - HKLM\..\RunOnce: [WMC_35] "C:\WINNT\INF\unregmp2.exe" /Shortcuts /RegExts
O4 - HKLM\..\RunOnce: [WMC_36] C:\WINNT\system32\regsvr32.exe /s "C:\WINNT\system32\l3codeca.acm"
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: TELUS eCare.lnk = C:\Program Files\TELUS eCare\bin\matcli.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4C226336-4032-489F-9674-67E74225979B} (OTXMovie Class) - http://www.otxresearch.com/OTXMedia/OTXMedia.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O23 - Service: alerter - Unknown - c:\winnt\system32\srvany.Exe
O23 - Service: ASP-Net StateServ - Unknown - C:\WINNT\system32\service.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: NtlogonWrk Service: ClipBook - Unknown - C:\winnt\system32\NtlogonWrk.EXE
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare NT Utilities 2.6 - DameWare Development - C:\WINNT\SYSTEM32\DNTUS26.EXE
O23 - Service: Fax - Unknown - C:\WINNT\system32\_faxsv.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NtlogonWrk Service: NtLogon - Unknown - C:\WINNT\system32\\NtlogonWrk.EXE
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: NtlogonWrk Service: sec - Unknown - C:\WINNT\system32\\NtlogonWrk.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Windows Time - Unknown - C:\WINNT\system32\w32time.exe
O23 - Service: FireDaemon Service: win32 - Unknown - e:\recycler\S-1-5-21-194267318-534581036-2087665911-5001\here\FireDaemon.EXE (file missing)
O23 - Service: WinSys Win System - Unknown - C:\WINNT\mmdcd.exe
Hello weesie welcome to the forum.

Important: Do this before any fix

Please put your HijackThis in it's own folder, (I create a new folder in C:\ named HJT).
You can do a Right Click on any open area on the desktop, New> Folder, then rename the folder HJT.

Go to where your HijackThis is and Right Click on HijackThis.exe, select Cut, then open the new folder you just created (HJT) Right Click in the folder and select paste.

The reason we do this is Hijackthis creates backup files just in case you'd need to restore one and we'll be cleaning out the temp files.




This is what I suggest you do.

Download CWShredder from my signature below. Unzip it on the desktop.
Open CWShredder and with ALL other windows closed, click fix.


Go here and run online scans (all), allow them to delete whatever they find:

TrendMicro HouseCall
eTrust AntiVirus Web Scanner
Panda ActiveScan
Note any thing that can't be fixed
Reboot when done.

Next:

Even if you've already run these, make SURE they're up-to-date and run per instructions.

Make sure you have the up-to-date versions of Spybot V 1.3 and Ad-aware SE Build 1.05 . All are free and available below.

Download Spybot, install and update. Then download Ad-aware, install, and update.

Spybot:

Install the program and launch it.

Go to Start > Programs >Spybot > Search & Destroy and choose Spybot S&D

Close ALL windows except Spybot S&D
Click the button to "Search for Updates" and download and install the Updates.
Next click the button "Check for Problems"
When Spybot is complete, it will be showing "RED" (RED) entries "BLACK" entries and "GREEN" (GREEN) entries in the window
Put a check mark beside the RED (RED) entries ONLY.
Choose "Fix Selected Problems" and allow Spybot to fix the RED (RED) entries.

Ad-Aware FULL SCAN:

Install the program and launch it.

First in the main window look in the bottom right corner and click on Check for updates now then click Connect and download the latest reference files.

From main window :Click Start then under Select a scan Mode check Perform full system scan.
Next deselect Search for negligible risk entries.
Now to scan just click the Next button.

When the scan is finished mark everything for removal and get rid of it.(Right-click the window and choose select all from the drop down menu and click Next)

Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Logfile of HijackThis v1.99.0
Scan saved at 8:49:15 PM, on 12/26/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\winnt\system32\NtlogonWrk.EXE
C:\WINNT\SYSTEM32\DNTUS26.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\Clipsru.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\mmdcd.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\qttask.exe
C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\DOCUME~1\TINASH~1\LOCALS~1\Temp\Rar$EX00.178\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchingall.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchingall.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchingall.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchingall.com/search/ssearch.php?q=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: SYpKOsbia1Obj Class - {068E7D1A-5C17-4403-ADA6-62FC25E2EF3D} - C:\WINNT\system32\drivers\input.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
F2 - REG:system.ini: UserInit=C:\WINNT\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SYpKOsbia1 - {068E7D1A-5C17-4403-ADA6-62FC25E2EF3D} - C:\WINNT\system32\drivers\input.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Secure] net share ADMIN$ /delete /Y
O4 - HKLM\..\Run: [QuickTime Task] C:\WINNT\system32\qttask.exe
O4 - HKLM\..\Run: [NetworkStartup] net share /delete IPC$ /Y
O4 - HKLM\..\Run: [Secure1] net share /delete C$ /Y
O4 - HKLM\..\Run: [Secure2] net share /delete D$ /Y
O4 - HKLM\..\Run: [Secure3] net stop server /Y
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: TELUS eCare.lnk = C:\Program Files\TELUS eCare\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O16 - DPF: {4C226336-4032-489F-9674-67E74225979B} (OTXMovie Class) - http://www.otxresearch.com/OTXMedia/OTXMedia.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O23 - Service: alerter - Unknown - c:\winnt\system32\srvany.Exe
O23 - Service: ASP-Net StateServ - Unknown - C:\WINNT\system32\service.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: NtlogonWrk Service: ClipBook - Unknown - C:\winnt\system32\NtlogonWrk.EXE
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare NT Utilities 2.6 - DameWare Development - C:\WINNT\SYSTEM32\DNTUS26.EXE
O23 - Service: Fax - Unknown - C:\WINNT\system32\_faxsv.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NtlogonWrk Service: NtLogon - Unknown - C:\WINNT\system32\\NtlogonWrk.EXE
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: NtlogonWrk Service: sec - Unknown - C:\WINNT\system32\\NtlogonWrk.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Windows Time - Unknown - C:\WINNT\system32\w32time.exe (file missing)
O23 - Service: FireDaemon Service: win32 - Unknown - e:\recycler\S-1-5-21-194267318-534581036-2087665911-5001\here\FireDaemon.EXE (file missing)
O23 - Service: WinSys Win System - Unknown - C:\WINNT\mmdcd.exe



That's the latest Log file after I followed all your instructions. I used all the sites and noticed that the same file kept coming up on each of the sites as being "unable to fix", but once I rebooted with Spyware opening upon reboot, it managed to fix the problem.

This is what I remember so far:
My computer, upon opening Internet Explorer, automatically defaults to a page entitled "SearchingAll.com". No matter how many times I try to reset my home page back to Google, it keeps going back to Searching All. My computer also seems to be saving the last five or six websites I visit - page by page, onto my desktop, in my Favourites folder, and also onto my shortcut bar. I must delete each one at a time.

When I am browsing the internet, every once in a while I will get an error message. This message ticks off a box entitled restart Internet Explorer, and also gives me the option of sending an error report or not.

Even after all this scanning, etc., my browser is automatically defaulting to searching all.

Hope this information helps.

weesie
C:\DOCUME~1\TINASH~1\LOCALS~1\Temp\Rar$EX00.178\HijackThis.exe

Important: Do this before any fix. HijackThis is still in a temp folder :thumbdown:

Please put your HijackThis in it's own folder, (I create a new folder in C:\ named HJT).
You can do a Right Click on any open area on the desktop, New> Folder, then rename the folder HJT.

Go to where your HijackThis is and Right Click on HijackThis.exe, select Cut, then open the new folder you just created (HJT) Right Click in the folder and select paste.

The reason we do this is Hijackthis creates backup files just in case you'd need to restore one and we'll be cleaning out the temp files.




I suggest you do this:

Use Add/Remove Programs and remove these:
SpyKiller
BestPopUpKiller


Run Hijack This again and put a check by these.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchingall.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchingall.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchingall.com

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchingall.com/search/ssearch.php?q=%s

R3 - URLSearchHook: SYpKOsbia1Obj Class - {068E7D1A-5C17-4403-ADA6-62FC25E2EF3D} - C:\WINNT\system32\drivers\input.dll

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)

O2 - BHO: SYpKOsbia1 - {068E7D1A-5C17-4403-ADA6-62FC25E2EF3D} - C:\WINNT\system32\drivers\input.dll

O4 - HKLM\..\Run: [LoadQM] loadqm.exe

O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup

O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE


Close ALL windows and browsers except HijackThis and click "Fix checked"


1. Open My Computer
2. Right click on your hard drive that you wish to clean (C drive, for example)
3. In the context menu that opens, select properties
4. Under the general tab you should select Disk Cleanup
5. Windows will scan your drive which will take a few seconds/minutes
6. A box will display the various files you can remove.
Check all boxes except compress old files (If listed)
7. Click OK and windows will comply.

Restart your computer.

Reboot and "copy/paste" a new log file into this thread.
Logfile of HijackThis v1.99.0
Scan saved at 7:46:57 PM, on 12/27/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\winnt\system32\NtlogonWrk.EXE
C:\WINNT\SYSTEM32\DNTUS26.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\Clipsru.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\mmdcd.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\qttask.exe
C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\Tina Shull\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
F2 - REG:system.ini: UserInit=C:\WINNT\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Secure] net share ADMIN$ /delete /Y
O4 - HKLM\..\Run: [QuickTime Task] C:\WINNT\system32\qttask.exe
O4 - HKLM\..\Run: [NetworkStartup] net share /delete IPC$ /Y
O4 - HKLM\..\Run: [Secure1] net share /delete C$ /Y
O4 - HKLM\..\Run: [Secure2] net share /delete D$ /Y
O4 - HKLM\..\Run: [Secure3] net stop server /Y
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - Global Startup: TELUS eCare.lnk = C:\Program Files\TELUS eCare\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O16 - DPF: {4C226336-4032-489F-9674-67E74225979B} (OTXMovie Class) - http://www.otxresearch.com/OTXMedia/OTXMedia.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O23 - Service: alerter - Unknown - c:\winnt\system32\srvany.Exe
O23 - Service: ASP-Net StateServ - Unknown - C:\WINNT\system32\service.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: NtlogonWrk Service: ClipBook - Unknown - C:\winnt\system32\NtlogonWrk.EXE
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare NT Utilities 2.6 - DameWare Development - C:\WINNT\SYSTEM32\DNTUS26.EXE
O23 - Service: Fax - Unknown - C:\WINNT\system32\_faxsv.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NtlogonWrk Service: NtLogon - Unknown - C:\WINNT\system32\\NtlogonWrk.EXE
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: NtlogonWrk Service: sec - Unknown - C:\WINNT\system32\\NtlogonWrk.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Windows Time - Unknown - C:\WINNT\system32\w32time.exe (file missing)
O23 - Service: FireDaemon Service: win32 - Unknown - e:\recycler\S-1-5-21-194267318-534581036-2087665911-5001\here\FireDaemon.EXE (file missing)
O23 - Service: WinSys Win System - Unknown - C:\WINNT\mmdcd.exe


This is my new log file which I completed after following most of your instructions. I was unable to find Spykiller and the other program you suggested I remove through the ADD/REMOVE Software thingme.

Weesie
Log looks good :D :thumbup: How is it running any issues?

If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.


To help keep you clean follow the recommendations in Tony's article here:
So how did I get infected in the first place?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI