This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

StartPage-DU.dll w/HJT and antivirus log

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
I am having the same problem that many people seem to be having with the StartPage-DU.dll Trojan. I now do not have any access to IE because it keeps shutting down with the about:blank as the home page. I am now using Mcaffe 8.0
Microsfot Antispywae and ad-awear se 1.06 I have scanned my computer with CWShredder, AdAware SE, Spybot S&D and McAfee(Virus Scan, Firewall,and SpamKiller), and in in safe mode. I also ran Hijack This and About Buster in safe mode. I do have Live Updates active for Microsoft and McAfee and always download all updates when asked. I am not very computer literate so detailed instructions for any kind of removal would be greatly appreciated. Here are the logs:


here are some of my logs….
@@@@
Logfile of HijackThis v1.99.1
Scan saved at 21:10:10, on 15/07/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Terry\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.wanadoo.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer brought to you by Planetis
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Class - {EA0A7054-1702-2B04-C264-3BFC6A677F95} - C:\WINDOWS\system32\sdkxn32.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [MegaXXX] C:\WINDOWS\MegaXXX.exe -n
O4 - HKLM\..\Run: [XXXmpeg] C:\Program Files\SCom\Dialers\XXXmpeg\XXXmpeg.exe /dontdial
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Imonitor] "C:\Program Files\McAfee\QuickClean\Plguni.exe" /START
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [Mskexe] c:\PROGRA~1\mcafee\SPAMKI~1\spamkiller.exe
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [dogtonseq32] C:\Documents and Settings\All Users\Application Data\Htm Obj Dog Tons\newblah.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\system32\qttask.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [RedLine Taskbar] C:\Program Files\RedLine\Taskbar.exe
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [atlju32.exe] C:\WINDOWS\atlju32.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunOnce: [ntgb.exe] C:\WINDOWS\ntgb.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: McAfee Desktop Firewall Tray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {1230CB21-C88D-11CF-B347-000000000000} - http://www.eingang69.de/EroticAccess/cabs/1726000.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\BOCconnect\VPN\Extranet_serv.exe
O23 - Service: McAfee Desktop Firewall Service (FireSvc) - Networks Associates Technology, Inc. - C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

AboutBuster 5.0 reference file 28
Scan started on [15/07/2005] at [21:18:46]
————————————————
Removed Stream! C:\WINDOWS\0.log:bheohz
Removed Stream! C:\WINDOWS\DtcInstall.log:xgmkag
Removed Stream! C:\WINDOWS\KB890859.log:oeipmu
Removed Stream! C:\WINDOWS\SchedLgU.Txt:aumnyu
————————————————
Removed File! : C:\Windows\System32\dynza.dat
————————————————
Scan was COMPLETED SUCCESSFULLY at 21:19:33


AboutBuster 5.0 reference file 28
Scan started on [15/07/2005] at [21:19:56]
————————————————
No Ads Found!
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 21:20:23


AboutBuster 5.0 reference file 30
Scan started on [15/07/2005] at [22:07:53]
————————————————
Removed Stream! C:\WINDOWS\0.log:bheohz
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 22:10:38


AboutBuster 5.0 reference file 30
Scan started on [15/07/2005] at [22:52:41]
————————————————
Removed Stream! C:\WINDOWS\0.log:bheohz
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 22:55:36
Here is the Mcafee log if it helps.. Basicly had no virues until now… 10/07/2005 06:53:25 DAT version = 4529 10/07/2005 06:53:25 Number of virus signatures in EXTRA.DAT = None 10/07/2005 06:53:25 Names of viruses that EXTRA.DAT can detect = None 10/07/2005 07:03:01 Statistics: 10/07/2005 07:03:01 Files scanned: 1659 10/07/2005 07:03:01 Files detected: 0 10/07/2005 07:03:01 Files cleaned: 0 10/07/2005 07:03:01 Files deleted: 0 10/07/2005 07:03:01 Files moved: 0 10/07/2005 07:23:36 Engine version = 4.4.00 10/07/2005 07:23:36 DAT version = 4529 10/07/2005 07:23:36 Number of virus signatures in EXTRA.DAT = None 10/07/2005 07:23:36 Names of viruses that EXTRA.DAT can detect = None 10/07/2005 15:21:12 Statistics: 10/07/2005 15:21:12 Files scanned: 1705 10/07/2005 15:21:12 Files detected: 0 10/07/2005 15:21:12 Files cleaned: 0 10/07/2005 15:21:12 Files deleted: 0 10/07/2005 15:21:12 Files moved: 0 10/07/2005 20:20:39 Engine version = 4.4.00 10/07/2005 20:20:39 DAT version = 4529 10/07/2005 20:20:39 Number of virus signatures in EXTRA.DAT = None 10/07/2005 20:20:39 Names of viruses that EXTRA.DAT can detect = None 10/07/2005 20:30:45 Statistics: 10/07/2005 20:30:45 Files scanned: 1343 10/07/2005 20:30:45 Files detected: 0 10/07/2005 20:30:45 Files cleaned: 0 10/07/2005 20:30:45 Files deleted: 0 10/07/2005 20:30:45 Files moved: 0 10/07/2005 21:14:52 Engine version = 4.4.00 10/07/2005 21:14:52 DAT version = 4529 10/07/2005 21:14:52 Number of virus signatures in EXTRA.DAT = None 10/07/2005 21:14:52 Names of viruses that EXTRA.DAT can detect = None 10/07/2005 21:54:48 Statistics: 10/07/2005 21:54:48 Files scanned: 1255 10/07/2005 21:54:48 Files detected: 0 10/07/2005 21:54:48 Files cleaned: 0 10/07/2005 21:54:48 Files deleted: 0 10/07/2005 21:54:48 Files moved: 0 11/07/2005 15:11:35 Engine version = 4.4.00 11/07/2005 15:11:35 DAT version = 4529 11/07/2005 15:11:35 Number of virus signatures in EXTRA.DAT = None 11/07/2005 15:11:35 Names of viruses that EXTRA.DAT can detect = None 11/07/2005 15:16:16 Statistics: 11/07/2005 15:16:16 Files scanned: 1620 11/07/2005 15:16:16 Files detected: 0 11/07/2005 15:16:16 Files cleaned: 0 11/07/2005 15:16:16 Files deleted: 0 11/07/2005 15:16:16 Files moved: 0 11/07/2005 16:55:16 Engine version = 4.4.00 11/07/2005 16:55:16 DAT version = 4529 11/07/2005 16:55:16 Number of virus signatures in EXTRA.DAT = None 11/07/2005 16:55:16 Names of viruses that EXTRA.DAT can detect = None 11/07/2005 17:00:41 Engine version = 4.4.00 11/07/2005 17:00:41 DAT version = 4532 11/07/2005 17:00:41 Number of virus signatures in EXTRA.DAT = None 11/07/2005 17:00:41 Names of viruses that EXTRA.DAT can detect = None 11/07/2005 17:07:20 Statistics: 11/07/2005 17:07:20 Files scanned: 1796 11/07/2005 17:07:20 Files detected: 0 11/07/2005 17:07:20 Files cleaned: 0 11/07/2005 17:07:20 Files deleted: 0 11/07/2005 17:07:20 Files moved: 0 11/07/2005 18:32:45 Engine version = 4.4.00 11/07/2005 18:32:45 DAT version = 4532 11/07/2005 18:32:45 Number of virus signatures in EXTRA.DAT = None 11/07/2005 18:32:45 Names of viruses that EXTRA.DAT can detect = None 11/07/2005 20:01:39 Statistics: 11/07/2005 20:01:39 Files scanned: 1089 11/07/2005 20:01:39 Files detected: 0 11/07/2005 20:01:39 Files cleaned: 0 11/07/2005 20:01:39 Files deleted: 0 11/07/2005 20:01:39 Files moved: 0 12/07/2005 16:20:50 Engine version = 4.4.00 12/07/2005 16:20:50 DAT version = 4532 12/07/2005 16:20:50 Number of virus signatures in EXTRA.DAT = None 12/07/2005 16:20:50 Names of viruses that EXTRA.DAT can detect = None 12/07/2005 16:43:10 Statistics: 12/07/2005 16:43:10 Files scanned: 3157 12/07/2005 16:43:10 Files detected: 0 12/07/2005 16:43:10 Files cleaned: 0 12/07/2005 16:43:10 Files deleted: 0 12/07/2005 16:43:10 Files moved: 0 12/07/2005 21:13:07 Engine version = 4.4.00 12/07/2005 21:13:07 DAT version = 4532 12/07/2005 21:13:07 Number of virus signatures in EXTRA.DAT = None 12/07/2005 21:13:07 Names of viruses that EXTRA.DAT can detect = None 12/07/2005 22:49:47 Engine version = 4.4.00 12/07/2005 22:49:47 DAT version = 4533 12/07/2005 22:49:47 Number of virus signatures in EXTRA.DAT = None 12/07/2005 22:49:47 Names of viruses that EXTRA.DAT can detect = None 12/07/2005 23:23:40 Moved (Clean failed) TERRY\Terry iexplore.exe C:\Documents and Settings\Terry\Local Settings\Temporary Internet Files\Content.IE5\E3L5PTGG\input[1].php JS/Exploit-DragDrop.b.gen (Trojan) 12/07/2005 23:23:40 Deleted TERRY\Terry iexplore.exe C:\Documents and Settings\Terry\Local Settings\Temporary Internet Files\Content.IE5\PPGX1NVX\input[1].htm JS/Exploit-DragDrop.b.gen (Trojan) 12/07/2005 23:23:41 Move failed (Clean failed) TERRY\Terry iexplore.exe C:\Documents and Settings\Terry\Local Settings\Temporary Internet Files\Content.IE5\0H03WFC3\mov06[1].exe Downloader-XC (Trojan) 12/07/2005 23:23:44 Move failed (Clean failed) TERRY\Terry iexplore.exe C:\Documents and Settings\Terry\Local Settings\Temporary Internet Files\Content.IE5\0H03WFC3\mov06[1].exe Downloader-XC (Trojan) 12/07/2005 23:23:49 No Action Taken TERRY\Terry iexplore.exe C:\Documents and Settings\Terry\Local Settings\Temporary Internet Files\Content.IE5\6VM3UHQF\vx_test2[1].htm Exploit-JavaPrxy (Trojan) 12/07/2005 23:23:50 Move failed (Clean failed because the file isn't cleanable) TERRY\Terry iexplore.exe C:\Documents and Settings\Terry\Local Settings\Temporary Internet Files\Content.IE5\6VM3UHQF\vx_test2[1].htm Exploit-JavaPrxy (Trojan) 12/07/2005 23:24:20 Deleted TERRY\Terry iexplore.exe C:\Documents and Settings\Terry\Local Settings\Temporary Internet Files\Content.IE5\GH4Z8FOJ\l[1].exe Downloader-XC (Trojan) 12/07/2005 23:31:37 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\zyeue.dll StartPage-DU.dll (Trojan) 12/07/2005 23:46:30 Statistics: 12/07/2005 23:46:30 Files scanned: 8984 12/07/2005 23:46:30 Files detected: 13 12/07/2005 23:46:30 Files cleaned: 0 12/07/2005 23:46:30 Files deleted: 4 12/07/2005 23:46:30 Files moved: 1 13/07/2005 16:53:30 Engine version = 4.4.00 13/07/2005 16:53:30 DAT version = 4533 13/07/2005 16:53:30 Number of virus signatures in EXTRA.DAT = None 13/07/2005 16:53:30 Names of viruses that EXTRA.DAT can detect = None 13/07/2005 17:22:58 Deleted TERRY\Sharon iexplore.exe C:\WINDOWS\davjr.dll StartPage-DU.dll (Trojan) 13/07/2005 17:26:41 Deleted TERRY\Sharon iexplore.exe C:\WINDOWS\system32\banto.dll StartPage-DU.dll (Trojan) 13/07/2005 20:27:00 Engine version = 4.4.00 13/07/2005 20:27:00 DAT version = 4534 13/07/2005 20:27:00 Number of virus signatures in EXTRA.DAT = None 13/07/2005 20:27:00 Names of viruses that EXTRA.DAT can detect = None 13/07/2005 20:28:05 Deleted TERRY\Sharon iexplore.exe C:\WINDOWS\ishdy.dll StartPage-DU.dll (Trojan) 13/07/2005 20:30:01 Deleted TERRY\Sharon iexplore.exe C:\WINDOWS\system32\ipyhe.dll StartPage-DU.dll (Trojan) 13/07/2005 20:30:52 Deleted TERRY\Sharon iexplore.exe C:\WINDOWS\system32\xkewh.dll StartPage-DU.dll (Trojan) :scratch: :scratch: 13/07/2005 20:31:09 Deleted TERRY\Sharon iexplore.exe C:\WINDOWS\ukjpq.dll StartPage-DU.dll (Trojan) 13/07/2005 20:31:37 Deleted TERRY\Sharon iexplore.exe C:\WINDOWS\jjtcm.dll StartPage-DU.dll (Trojan) 13/07/2005 20:59:39 Statistics: 13/07/2005 20:59:39 Files scanned: 22409 13/07/2005 20:59:39 Files detected: 7 13/07/2005 20:59:39 Files cleaned: 0 13/07/2005 20:59:39 Files deleted: 7 13/07/2005 20:59:39 Files moved: 0 13/07/2005 21:03:42 Engine version = 4.4.00 13/07/2005 21:03:42 DAT version = 4534 13/07/2005 21:03:42 Number of virus signatures in EXTRA.DAT = None 13/07/2005 21:03:42 Names of viruses that EXTRA.DAT can detect = None 13/07/2005 21:23:29 Deleted TERRY\Sharon iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 21:23:41 Deleted TERRY\Sharon iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 21:31:19 Statistics: 13/07/2005 21:31:19 Files scanned: 8848 13/07/2005 21:31:19 Files detected: 2 13/07/2005 21:31:19 Files cleaned: 0 13/07/2005 21:31:19 Files deleted: 2 13/07/2005 21:31:19 Files moved: 0 13/07/2005 21:33:00 Engine version = 4.4.00 13/07/2005 21:33:00 DAT version = 4534 13/07/2005 21:33:00 Number of virus signatures in EXTRA.DAT = None 13/07/2005 21:33:00 Names of viruses that EXTRA.DAT can detect = None 13/07/2005 21:39:45 Statistics: 13/07/2005 21:39:45 Files scanned: 1178 13/07/2005 21:39:45 Files detected: 0 13/07/2005 21:39:45 Files cleaned: 0 13/07/2005 21:39:45 Files deleted: 0 13/07/2005 21:39:45 Files moved: 0 13/07/2005 21:41:25 Engine version = 4.4.00 13/07/2005 21:41:25 DAT version = 4534 13/07/2005 21:41:25 Number of virus signatures in EXTRA.DAT = None 13/07/2005 21:41:25 Names of viruses that EXTRA.DAT can detect = None 13/07/2005 21:45:48 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 21:46:06 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 21:50:49 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 21:54:49 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 22:04:29 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 22:05:28 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 22:14:39 Statistics: 13/07/2005 22:14:39 Files scanned: 2137 13/07/2005 22:14:39 Files detected: 6 13/07/2005 22:14:39 Files cleaned: 0 13/07/2005 22:14:39 Files deleted: 6 13/07/2005 22:14:39 Files moved: 0 13/07/2005 22:16:19 Engine version = 4.4.00 13/07/2005 22:16:19 DAT version = 4534 13/07/2005 22:16:19 Number of virus signatures in EXTRA.DAT = None 13/07/2005 22:16:19 Names of viruses that EXTRA.DAT can detect = None 13/07/2005 22:21:41 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 22:21:49 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 22:21:58 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 22:23:54 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 22:27:58 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 22:37:57 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 22:39:29 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 22:56:35 Moved (Clean failed) TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 23:07:47 Engine version = 4.4.00 13/07/2005 23:07:47 DAT version = 4534 13/07/2005 23:07:47 Number of virus signatures in EXTRA.DAT = None 13/07/2005 23:07:47 Names of viruses that EXTRA.DAT can detect = None 13/07/2005 23:11:48 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 23:24:21 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 23:30:38 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\tjmfg.dll StartPage-DU.dll (Trojan) 13/07/2005 23:32:10 Statistics: 13/07/2005 23:32:10 Files scanned: 1306 13/07/2005 23:32:10 Files detected: 3 13/07/2005 23:32:10 Files cleaned: 0 13/07/2005 23:32:10 Files deleted: 3 13/07/2005 23:32:10 Files moved: 0 14/07/2005 18:20:17 Engine version = 4.4.00 14/07/2005 18:20:17 DAT version = 4534 14/07/2005 18:20:17 Number of virus signatures in EXTRA.DAT = None 14/07/2005 18:20:17 Names of viruses that EXTRA.DAT can detect = None 14/07/2005 18:23:09 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\aoxkp.dll StartPage-DU.dll (Trojan) 14/07/2005 18:42:24 Engine version = 4.4.00 14/07/2005 18:42:24 DAT version = 4535 14/07/2005 18:42:24 Number of virus signatures in EXTRA.DAT = None 14/07/2005 18:42:24 Names of viruses that EXTRA.DAT can detect = None 14/07/2005 18:46:12 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\bagva.dll StartPage-DU.dll (Trojan) 14/07/2005 18:47:54 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\aunct.dll StartPage-DU.dll (Trojan) 14/07/2005 18:55:09 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\fkune.dll StartPage-DU.dll (Trojan) 14/07/2005 19:30:13 Deleted TERRY\Terry Ad-Aware.exe C:\WINDOWS\xgyxl.dll StartPage-DU.dll (Trojan) 14/07/2005 19:36:24 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\iwcdy.dll StartPage-DU.dll (Trojan) 14/07/2005 19:36:35 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\imgfc.dll StartPage-DU.dll (Trojan) 14/07/2005 19:38:04 Deleted TERRY\Terry iexplore.exe C:\WINDOWS\system32\ktiuk.dll StartPage-DU.dll (Trojan) <_<
Hi Post my first request Posted Jul 16 2005, 12:57 PM.. Any chance someone can have a look at my hijack logs and advise which bits I need to delete extc.. cheer Terry
:( still got the problem <_<
New hijack log file
Logfile of HijackThis v1.99.1
Scan saved at 19:38:16, on 20/07/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Apps\ActivBoard\nhksrv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Apps\ActivBoard\MMKeybd.exe
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\McAfee\QuickClean\Plguni.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\qttask.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireTray.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Apps\ActivBoard\TrayMon.exe
C:\Apps\ActivBoard\OSD.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\slrundll.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Documents and Settings\Terry\Desktop\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.wanadoo.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = My Web Tool
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=http://www-cache.freeserve:8080;http=www-cache.freeserve.net:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Imonitor] "C:\Program Files\McAfee\QuickClean\Plguni.exe" /START
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [Mskexe] c:\PROGRA~1\mcafee\SPAMKI~1\spamkiller.exe
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [dogtonseq32] C:\Documents and Settings\All Users\Application Data\Htm Obj Dog Tons\newblah.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\system32\qttask.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKCU\..\Run: [Handy Backup 3.9] C:\PROGRA~1\Novosoft\HANDYB~1\hbagent.exe -logon
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - Global Startup: McAfee Desktop Firewall Tray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {1230CB21-C88D-11CF-B347-000000000000} - http://www.eingang69.de/EroticAccess/cabs/1726000.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: C-DillaCdaC11BA - Unknown owner - C:\WINDOWS\system32\drivers\CDAC11BA.EXE (file missing)
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\BOCconnect\VPN\Extranet_serv.exe
O23 - Service: McAfee Desktop Firewall Service (FireSvc) - Networks Associates Technology, Inc. - C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
Hi…. Looks Like I have finally got rid of it…
Loaded new Ad-aware se dat file tonight and run full scan all now gone ????
Date file = SE1R55 19.07.2005 …

Also remved reg key
R3 - Default URLSearchHook is missing


and run SFUninstaller.exe
You can read all info about SmartFinder here: http://looking-for.cc/smartfinder/

No longer dose my Ie get Hijacked.
still got a small issue that IE fires up on it's own, But I can live with that
and my wife will now be off my back, as she can get on eBay again

:D :rofl:
by the way here is my latest hijack this log

Logfile of HijackThis v1.99.1
Scan saved at 20:24:22, on 20/07/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Apps\ActivBoard\nhksrv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\slrundll.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Apps\ActivBoard\MMKeybd.exe
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\McAfee\QuickClean\Plguni.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee\SPAMKI~1\spamkiller.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\qttask.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireTray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Apps\ActivBoard\TrayMon.exe
C:\Apps\ActivBoard\OSD.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Terry\Desktop\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.wanadoo.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = My Web Tool
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=http://www-cache.freeserve:8080;http=www-cache.freeserve.net:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Imonitor] "C:\Program Files\McAfee\QuickClean\Plguni.exe" /START
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [Mskexe] c:\PROGRA~1\mcafee\SPAMKI~1\spamkiller.exe
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [dogtonseq32] C:\Documents and Settings\All Users\Application Data\Htm Obj Dog Tons\newblah.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\system32\qttask.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKCU\..\Run: [Handy Backup 3.9] C:\PROGRA~1\Novosoft\HANDYB~1\hbagent.exe -logon
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - Global Startup: McAfee Desktop Firewall Tray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {1230CB21-C88D-11CF-B347-000000000000} - http://www.eingang69.de/EroticAccess/cabs/1726000.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E88DAA4A-EFA6-4D8D-B403-DDDFD040B01C}: NameServer = 195.92.195.94 195.92.195.95
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: C-DillaCdaC11BA - Unknown owner - C:\WINDOWS\system32\drivers\CDAC11BA.EXE (file missing)
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\BOCconnect\VPN\Extranet_serv.exe
O23 - Service: McAfee Desktop Firewall Service (FireSvc) - Networks Associates Technology, Inc. - C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
Hello Terry_Topcat_Carter , welcome to the forum.

You might have a Lop.com infection. To remove it follow the instructions below.


Step #1
For Windows 2000/XP users

Click Start Select Control Panel
double click Add/Remove Programs
look for any of the following, and uninstall them:
Window Search
Window Searching
Lop.com
LOP SEARCH
Browser Enhancer
Ultimate Browser Enhancer

IMPORTANT!!!
you may find entries similair to the above but with Weird spacing in the names.

They are Lop.com, uninstall them.

You may be given a code to insert, do so and reboot when done.



If it is not listed in Add/Remove Programs, or if the uninstall does not seem to work go here:

http://lop.com/new_uninstall.exe

download and run this uninstaller. Reboot when done.


"copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Hi LDTate.
Thanks for the up date..
PC seems to be fine at the monent,
Don't remeber seeing any of these programs when I looked, But I will have another look tonight.

I have now also managed to stop IE running after log in… used microsoft built tool, MSCONFIG to check and found it in the start up tab..

Hi DLTate.
Just tried to do the download… http://lop.com/new_uninstall.exe
but the download is infected, and Mcafee is blocking it…
It has 2 viruses "ADware-lop (Adware) and Exploit-IEPage Spoof (trojan)
:(
Please download ewido Security Suite
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu."
  • Launch ewido, there should be a big "E" icon on your desktop, double-click it.
  • The program will prompt you to update click the "OK" button
  • The program will now go to the main screen

    You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Click on Start

    The update will start and a progress bar will show the updates being installed. After the updates are installed, exit ewido.

    Once the updates are installed do the following:
  • If you have an "always on" connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode.
  • Reboot into Safe Mode, you can do this by restarting your computer, then contiunally tapping F8 until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter. Then, run ewido.
  • Close all open windows/programs/folders. Have nothing else open while ewido performs its scan!
  • Click on scanner
  • Click on Settings
    • Under "How to scan" all boxes should be selected
    • Under "Possibly unwanted software" all boxes should be selected
    • Under "What to scan" select scan every file
    • Click OK
  • Click on Complete system scan
  • Let the program scan the machine
  • If ewido finds anything, it will pop up a notification. NOTE: We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, AOL, pcAnywhere and the game "Risk" have been flagged. In particular, watch for alerts that have the word "Heuristic" in them - if you recognize the file name as "friendly," these may actually be false positives) select "none" as the action. DO NOT check "Perform action with all infections." If you are unsure of an entry, select "none" for the time being. I'll see that in the log you will post later and let you know if ewido needs to be run again.

    Once the scan has completed, there will be a button located on the bottom of the screen named Save report.
  • Click Save report
  • Save the report to your desktop
  • Exit ewido

Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
Hi LDTate :D …
Sorry not got back to this sooner, as the PC was working, I was in no rush and have also been on Holiday…..
Just Like to say a big thanks so far….

Ok done as you have suggested and installed and run ewido… and run Hijack this as well. Here are the logs..

Cheers :thumbup:
Terry.

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 22:02:24, 16/08/2005
+ Report-Checksum: 93DDFF9D

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{BEB133E5-FD72-43b7-8AFF-681831CC72D9} -> Spyware.Hijacker.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{930A2B79-855E-4A18-80BB-4C0595B40798} -> Spyware.CometCursor : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{E61A0304-C605-441F-BD57-2833B65A69F1} -> Spyware.CometCursor : Cleaned with backup
HKU\S-1-5-21-1957994488-1708537768-725345543-1004\Software\comsoft -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\910000_200435_.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\m7.exe -> TrojanDownloader.Swizzor.bt : Cleaned with backup
C:\WINDOWS\Q810565.log:uxurja -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Q810833.log:mqnxdc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\SchedLgU.Txt:aumnyu -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\system32:weaa.dll -> TrojanDownloader.Small.azk : Cleaned with backup
C:\WINDOWS\_default.pif:mgvesm -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:qircq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:ufcry -> TrojanDownloader.Agent.bc : Cleaned with backup


::Report End

Hijack this
Logfile of HijackThis v1.99.1
Scan saved at 22:09:13, on 16/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Apps\ActivBoard\nhksrv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\slrundll.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Apps\ActivBoard\MMKeybd.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\qttask.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Apps\ActivBoard\TrayMon.exe
C:\Apps\ActivBoard\OSD.exe
C:\Program Files\Common Files\Teknum Systems\updsvc.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Documents and Settings\Terry\My Documents\TOOLS\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.wanadoo.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = My Web Tool
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=http://www-cache.freeserve:8080;http=www-cache.freeserve.net:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Imonitor] "C:\Program Files\McAfee\QuickClean\Plguni.exe" /START
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [Mskexe] c:\PROGRA~1\mcafee\SPAMKI~1\spamkiller.exe
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\system32\qttask.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Handy Backup 3.9] C:\PROGRA~1\Novosoft\HANDYB~1\hbagent.exe -logon
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [Update Service] C:\PROGRA~1\COMMON~1\TEKNUM~1\update.exe /startup
O4 - Global Startup: McAfee Desktop Firewall Tray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {1230CB21-C88D-11CF-B347-000000000000} - http://www.eingang69.de/EroticAccess/cabs/1726000.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: C-DillaCdaC11BA - Unknown owner - C:\WINDOWS\system32\drivers\CDAC11BA.EXE (file missing)
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\BOCconnect\VPN\Extranet_serv.exe
O23 - Service: McAfee Desktop Firewall Service (FireSvc) - Networks Associates Technology, Inc. - C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
I suggest you do this:

Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.wanadoo.co.uk

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = My Web Tool

O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\system32\qttask.exe

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKCU\..\Run: [Update Service] C:\PROGRA~1\COMMON~1\TEKNUM~1\update.exe /startup

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

O16 - DPF: {1230CB21-C88D-11CF-B347-000000000000} - http://www.eingang69.de/EroticAccess/cabs/1726000.cab


If you or your network administrator didn't set these, fix also.
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present


Close ALL windows and browsers except HijackThis and click "Fix checked"




Restart in Safe Mode:
Restart your computer.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.


Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.



Open C:\Windows\Prefetch\ Delete ALL files in this folder.



Do this also if these Temp Folders are part of your OS.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


Next navigate to the C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty the Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
:D Hi LDTate.
Once again thanks for your help.

I must admit, my PC, since last night does seem to be running better..
I and my son both like to plan Command & Conquer - Generals.
And I have to say that it seems to be running alot lot faster…

:thumbup:

I have done what you suggested.., and additional run a full Adaware SE, Micosfoft Antispyware and a full Macafee Virus scan as well.
I cleared out all the Tempary files for all the USer ID's. Got back about 20Meg when I did the Wife's ID. ( Thanks eBay)

Adawear SE did find some minor tracking files which I have also delted and I have just run the Hijack this and here is the log…
Hopeful this looks clean now

Just checked the Log file, any ide's what this is?, or can it be delted?

O23 - Service: C-DillaCdaC11BA - Unknown owner - C:\WINDOWS\system32\drivers\CDAC11BA.EXE (file missing)

Thanks from this very happy person :D
Terry


Logfile of HijackThis v1.99.1
Scan saved at 22:07:48, on 17/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Apps\ActivBoard\nhksrv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\slrundll.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Apps\ActivBoard\MMKeybd.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\McAfee\QuickClean\Plguni.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireTray.exe
C:\Apps\ActivBoard\TrayMon.exe
C:\Apps\ActivBoard\OSD.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Documents and Settings\Terry\My Documents\TOOLS\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.freeserve.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=http://www-cache.freeserve:8080;http=www-cache.freeserve.net:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Imonitor] "C:\Program Files\McAfee\QuickClean\Plguni.exe" /START
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [Mskexe] c:\PROGRA~1\mcafee\SPAMKI~1\spamkiller.exe
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [Handy Backup 3.9] C:\PROGRA~1\Novosoft\HANDYB~1\hbagent.exe -logon
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - Global Startup: McAfee Desktop Firewall Tray.lnk = ?
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: C-DillaCdaC11BA - Unknown owner - C:\WINDOWS\system32\drivers\CDAC11BA.EXE (file missing)
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\BOCconnect\VPN\Extranet_serv.exe
O23 - Service: McAfee Desktop Firewall Service (FireSvc) - Networks Associates Technology, Inc. - C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

Description:
cdac11ba.exe is a part of MacroVision safeCast copy protection software. This piece of software allows manufacturers to protect their products from illegal duplication. Disabling, or deleting this process may corrupt the product it was supplied with.

HJT sometimes will show File Missing when in fact it isn't.



Good Job :thumbup:


Log looks good :D

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Click Start> My Computer, select the Tools menu and then Folder Options, after the new window appears select the View tab…]
This time select the: Restore Defaults
Select: Apply, and click OK




If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI