Everying was fine before i used broadband, but after about 20 minutes of unprotected activity on IE (and my ignorance) with it, i accumulated a bunch of garbage. I did the usual things to do to clean the stuff up…run ad-ware, spybot, reboot and the such. Got what it can find and clean up, disabled what i knew what was spware in startup, but still get a pop-up here and there; even with my AOL. I read up on Hijackthis from a bunch of sources (PC mag for one) and decide to give it a go. I pretty much can tell what is spyware by looking at the filename of what hijackthis has shown me, but to be on the safe side I'm refering to expert (or certain) assistance and advice. I no better, and have fixed friends and fams computers before, but this one has got me baffled this time around.
P.S. > does ad-ware and spybot actually remove all parts of spyware or just some…i mean, u can still find it in the msconfig startup menu…is this where this program comes in to remove it ?
i also put an asterik on what i thought was spyware after the file name; just seeing if i was as knowing as i thought
heres my hijack this log:
Logfile of HijackThis v1.99.0
Scan saved at 11:54:52 PM, on 3/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\IEXPLOR.EXE
C:\WINDOWS\System32\wintask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\System32\exp.exe
C:\WINDOWS\system\rokbwsgpn.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\America Online 8.0\waol.exe
C:\Program Files\America Online 8.0\shellmon.exe
C:\Program Files\America Online 8.0\aolwbspd.exe
C:\WINDOWS\system32\slrundll.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com *
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com *
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com *
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [C:\WINDOWS\IEXPLOR.EXE] C:\WINDOWS\IEXPLOR.EXE
O4 - HKLM\..\Run: [AtxBrw] C:\WINDOWS\IEXPLOR.exe *
O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitevmj32.exe *
O4 - HKLM\..\Run: [xylitbaj] C:\WINDOWS\System32\vubvome\xylitbaj.exe *
O4 - HKLM\..\Run: [wtkdxhv] C:\WINDOWS\System32\egrqej\wtkdxhv.exe *
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe *
O4 - HKLM\..\Run: [vbgnr] C:\WINDOWS\System32\rpyhxtuj\vbgnr.exe *
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [PaciSoft] C:\WINDOWS\System32\pacis.exe *
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe *
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe *
O4 - HKLM\..\Run: [cvxmoit] C:\WINDOWS\System32\werc\cvxmoit.exe *
O4 - HKLM\..\Run: [739i3FO] cmprnr.exe *
O4 - HKLM\..\Run: [usqusrhd] c:\windows\system32\usqusrhd.exe *
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [M0qsRPisQ] clerclnr.exe *
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1111261087106
O17 - HKLM\System\CCS\Services\Tcpip\..\{D91AB0F6-67E5-49B8-B544-3D1C6848EDA8}: NameServer = 205.188.146.145
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe