Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93100 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

My HJT Log, require assistance asap.


  • This topic is locked This topic is locked
6 replies to this topic

#1 Corpus

Corpus

    New Member

  • Authentic Member
  • Pip
  • 18 posts
  • Interests:My fiance, computers, and music.

Posted 17 April 2006 - 06:10 PM

Logfile of HijackThis v1.99.1
Scan saved at 8:02:53 PM, on 4/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Ron\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.h...sario&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.h...sario&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.comcast.net
O15 - Trusted Zone: http://flyff.gpotato.com
O15 - Trusted Zone: www.myspace.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WB - C:\Program Files\AlienGUIse\fastload.dll
O20 - Winlogon Notify: winjrs32 - C:\WINDOWS\SYSTEM32\winjrs32.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
Posted Image
A thousand eyes for an eye,
Vengence is mine.

    Advertisements

Register to Remove


#2 MrCharlie

MrCharlie

    SuperMember

  • Malware Team
  • 2,949 posts

Posted 18 April 2006 - 06:24 PM

Welcome to the forum.


Download the trial version of Spy Sweeper from the link below:
http://www.webroot.c...4bf9729da8fd856

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!

When the sweep has finished, click Remove. Click Select All and then Next

From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.

Exit Spy Sweeper.

Empty Recycle Bin

Post the log from Spy Sweeper and a fresh HJT log, MrC


#3 Corpus

Corpus

    New Member

  • Authentic Member
  • Pip
  • 18 posts
  • Interests:My fiance, computers, and music.

Posted 21 April 2006 - 01:17 AM

Logfile of HijackThis v1.99.1
Scan saved at 3:08:17 AM, on 4/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Ron\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.h...sario&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.comcast.net
O15 - Trusted Zone: http://flyff.gpotato.com
O15 - Trusted Zone: www.myspace.com
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WB - C:\Program Files\AlienGUIse\fastload.dll
O20 - Winlogon Notify: winjrs32 - C:\WINDOWS\SYSTEM32\winjrs32.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe

********
2:24 AM: | Start of Session, Friday, April 21, 2006 |
2:24 AM: Spy Sweeper started
2:24 AM: Sweep initiated using definitions version 662
2:24 AM: Found Adware: coolwebsearch (cws)
2:24 AM: HKCR\clsid\{2d38a51a-23c9-48a1-a33c-48675aa2b494}\inprocserver32\ (2 subtraces) (ID = 1183061)
2:24 AM: winres.dll (ID = 1183061)
2:24 AM: Starting Memory Sweep
2:29 AM: Memory Sweep Complete, Elapsed Time: 00:05:18
2:29 AM: Starting Registry Sweep
2:29 AM: Found Adware: altnet
2:29 AM: HKCR\adm4.adm4.1\ (3 subtraces) (ID = 103443)
2:29 AM: HKCR\adm4.adm4\ (3 subtraces) (ID = 103444)
2:29 AM: HKCR\adm25.adm25.1\ (3 subtraces) (ID = 103445)
2:29 AM: HKCR\adm25.adm25\ (3 subtraces) (ID = 103446)
2:29 AM: HKCR\appid\adm.exe\ (1 subtraces) (ID = 103448)
2:29 AM: HKCR\appid\altnet signing module.exe\ (1 subtraces) (ID = 103449)
2:29 AM: HKLM\software\classes\adm4.adm4.1\ (3 subtraces) (ID = 103484)
2:29 AM: HKLM\software\classes\adm4.adm4\ (3 subtraces) (ID = 103485)
2:29 AM: HKLM\software\classes\adm25.adm25.1\ (3 subtraces) (ID = 103486)
2:29 AM: HKLM\software\classes\adm25.adm25\ (3 subtraces) (ID = 103487)
2:29 AM: HKLM\software\classes\appid\adm.exe\ (1 subtraces) (ID = 103488)
2:29 AM: HKLM\software\classes\appid\altnet signing module.exe\ (1 subtraces) (ID = 103489)
2:29 AM: HKLM\software\classes\clsid\{b7156514-a76c-4545-9d5b-a4e1d02c7aec}\ (23 subtraces) (ID = 103494)
2:29 AM: HKCR\clsid\{2d38a51a-23c9-48a1-a33c-48675aa2b494}\ (11 subtraces) (ID = 107171)
2:29 AM: HKLM\software\classes\clsid\{2d38a51a-23c9-48a1-a33c-48675aa2b494}\ (11 subtraces) (ID = 108560)
2:29 AM: HKLM\software\classes\typelib\{344ee577-2027-4714-82ff-0d7538488547}\ (9 subtraces) (ID = 109797)
2:29 AM: HKLM\software\classes\winres.windowsresources.1\ (3 subtraces) (ID = 109808)
2:29 AM: HKLM\software\classes\winres.windowsresources\ (5 subtraces) (ID = 109809)
2:29 AM: HKCR\typelib\{344ee577-2027-4714-82ff-0d7538488547}\ (9 subtraces) (ID = 112503)
2:29 AM: HKCR\winres.windowsresources.1\ (3 subtraces) (ID = 112518)
2:29 AM: HKCR\winres.windowsresources\ (5 subtraces) (ID = 112519)
2:29 AM: Found Adware: purityscan
2:29 AM: HKLM\software\clickspring\ (2 subtraces) (ID = 137699)
2:29 AM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediaticketsinstaller.ocx\ (2 subtraces) (ID = 137986)
2:29 AM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\mediaticketsinstaller.ocx (ID = 139077)
2:29 AM: Found Adware: topsearch
2:29 AM: HKCR\clsid\{b7156514-a76c-4545-9d5b-a4e1d02c7aec}\ (23 subtraces) (ID = 143925)
2:29 AM: HKLM\software\classes\topsearch.tslink\ (5 subtraces) (ID = 143926)
2:29 AM: HKLM\software\classes\topsearch.tslink.1\ (3 subtraces) (ID = 143927)
2:29 AM: HKLM\software\classes\typelib\{edd3b3e9-3ffd-4836-a6de-d4a9c473a971}\ (9 subtraces) (ID = 143928)
2:29 AM: HKCR\topsearch.tslink\ (5 subtraces) (ID = 143929)
2:29 AM: HKCR\typelib\{edd3b3e9-3ffd-4836-a6de-d4a9c473a971}\ (9 subtraces) (ID = 143930)
2:29 AM: Found Adware: rx toolbar
2:29 AM: HKCR\rxresult.rxresultfilter\ (3 subtraces) (ID = 729537)
2:29 AM: HKCR\rxresult.rxresultfilter\clsid\ (1 subtraces) (ID = 729539)
2:29 AM: HKCR\rxresult.rxresultfilter.1\ (3 subtraces) (ID = 729541)
2:29 AM: HKCR\rxresult.rxresultfilter.1\clsid\ (1 subtraces) (ID = 729543)
2:29 AM: HKCR\rxresult.rxresulttracker\ (3 subtraces) (ID = 729545)
2:29 AM: HKCR\rxresult.rxresulttracker\clsid\ (1 subtraces) (ID = 729547)
2:29 AM: HKCR\rxresult.rxresulttracker.1\ (3 subtraces) (ID = 729549)
2:29 AM: HKCR\rxresult.rxresulttracker.1\clsid\ (1 subtraces) (ID = 729551)
2:29 AM: HKCR\clsid\{2ab289ae-4b90-4281-b2ae-1f4bb034b647}\ (10 subtraces) (ID = 729553)
2:29 AM: HKCR\clsid\{59879fa4-4790-461c-a1cc-4ec4de4ca483}\ (8 subtraces) (ID = 729564)
2:29 AM: HKCR\typelib\{05563f82-69a7-40a6-8670-153b635a7ef6}\ (9 subtraces) (ID = 729573)
2:29 AM: HKLM\software\classes\rxresult.rxresultfilter\ (3 subtraces) (ID = 729616)
2:29 AM: HKLM\software\classes\rxresult.rxresultfilter\clsid\ (1 subtraces) (ID = 729618)
2:29 AM: HKLM\software\classes\rxresult.rxresultfilter.1\ (3 subtraces) (ID = 729620)
2:29 AM: HKLM\software\classes\rxresult.rxresultfilter.1\clsid\ (1 subtraces) (ID = 729622)
2:29 AM: HKLM\software\classes\rxresult.rxresulttracker\ (3 subtraces) (ID = 729624)
2:29 AM: HKLM\software\classes\rxresult.rxresulttracker\clsid\ (1 subtraces) (ID = 729626)
2:29 AM: HKLM\software\classes\rxresult.rxresulttracker.1\ (3 subtraces) (ID = 729628)
2:29 AM: HKLM\software\classes\rxresult.rxresulttracker.1\clsid\ (1 subtraces) (ID = 729630)
2:29 AM: HKLM\software\classes\clsid\{2ab289ae-4b90-4281-b2ae-1f4bb034b647}\ (10 subtraces) (ID = 729632)
2:29 AM: HKLM\software\classes\clsid\{59879fa4-4790-461c-a1cc-4ec4de4ca483}\ (8 subtraces) (ID = 729643)
2:29 AM: HKLM\software\classes\typelib\{05563f82-69a7-40a6-8670-153b635a7ef6}\ (9 subtraces) (ID = 729652)
2:29 AM: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{59879fa4-4790-461c-a1cc-4ec4de4ca483}\ (ID = 729662)
2:29 AM: Found Trojan Horse: trojan agent winlogonhook
2:29 AM: HKLM\software\microsoft\mssmgr\ (14 subtraces) (ID = 937101)
2:30 AM: Registry Sweep Complete, Elapsed Time:00:00:15
2:30 AM: Starting Cookie Sweep
2:30 AM: Found Spy Cookie: 2o7.net cookie
2:30 AM: ron@2o7[1].txt (ID = 1957)
2:30 AM: Found Spy Cookie: yieldmanager cookie
2:30 AM: ron@ad.yieldmanager[1].txt (ID = 3751)
2:30 AM: Found Spy Cookie: adrevolver cookie
2:30 AM: ron@adrevolver[2].txt (ID = 2088)
2:30 AM: ron@adrevolver[3].txt (ID = 2088)
2:30 AM: Found Spy Cookie: pointroll cookie
2:30 AM: ron@ads.pointroll[1].txt (ID = 3148)
2:30 AM: Found Spy Cookie: advertising cookie
2:30 AM: ron@advertising[2].txt (ID = 2175)
2:30 AM: Found Spy Cookie: aptimus cookie
2:30 AM: ron@aptimus[2].txt (ID = 2233)
2:30 AM: Found Spy Cookie: atwola cookie
2:30 AM: ron@ar.atwola[1].txt (ID = 2256)
2:30 AM: Found Spy Cookie: ask cookie
2:30 AM: ron@ask[1].txt (ID = 2245)
2:30 AM: Found Spy Cookie: atlas dmt cookie
2:30 AM: ron@atdmt[2].txt (ID = 2253)
2:30 AM: ron@atwola[1].txt (ID = 2255)
2:30 AM: Found Spy Cookie: casalemedia cookie
2:30 AM: ron@casalemedia[1].txt (ID = 2354)
2:30 AM: Found Spy Cookie: overture cookie
2:30 AM: ron@data2.perf.overture[2].txt (ID = 3106)
2:30 AM: Found Spy Cookie: ru4 cookie
2:30 AM: ron@edge.ru4[1].txt (ID = 3269)
2:30 AM: Found Spy Cookie: fastclick cookie
2:30 AM: ron@fastclick[1].txt (ID = 2651)
2:30 AM: Found Spy Cookie: mediaplex cookie
2:30 AM: ron@mediaplex[2].txt (ID = 6442)
2:30 AM: ron@network.aptimus[1].txt (ID = 2235)
2:30 AM: Found Spy Cookie: realmedia cookie
2:30 AM: ron@network.realmedia[1].txt (ID = 3236)
2:30 AM: ron@perf.overture[1].txt (ID = 3106)
2:30 AM: Found Spy Cookie: questionmarket cookie
2:30 AM: ron@questionmarket[2].txt (ID = 3217)
2:30 AM: ron@realmedia[1].txt (ID = 3235)
2:30 AM: Found Spy Cookie: revenue.net cookie
2:30 AM: ron@revenue[1].txt (ID = 3257)
2:30 AM: Found Spy Cookie: serving-sys cookie
2:30 AM: ron@serving-sys[2].txt (ID = 3343)
2:30 AM: Found Spy Cookie: trafficmp cookie
2:30 AM: ron@trafficmp[2].txt (ID = 3581)
2:30 AM: Found Spy Cookie: tribalfusion cookie
2:30 AM: ron@tribalfusion[1].txt (ID = 3589)
2:30 AM: Found Spy Cookie: tripod cookie
2:30 AM: ron@tripod[1].txt (ID = 3591)
2:30 AM: Found Spy Cookie: zedo cookie
2:30 AM: ron@zedo[1].txt (ID = 3762)
2:30 AM: Cookie Sweep Complete, Elapsed Time: 00:00:04
2:30 AM: Starting File Sweep
2:30 AM: c:\program files\rxtoolbar (8 subtraces) (ID = -2147476417)
2:30 AM: Found Adware: bullguard popup ad
2:30 AM: c:\windows\temp\bullguard (1 subtraces) (ID = -2147476409)
2:30 AM: c:\windows\temp\altnet (18 subtraces) (ID = -2147481435)
2:35 AM: pminstall.cab (ID = 49857)
2:35 AM: backup-20060417-195630-627.inf (ID = 73158)
2:38 AM: dminfo3.cab (ID = 49824)
2:40 AM: winres.dll (ID = 282896)
2:44 AM: adm4.dll (ID = 49779)
2:44 AM: adm25.dll (ID = 49782)
2:44 AM: admdata.dll (ID = 49784)
2:44 AM: admdloader.dll (ID = 49786)
2:44 AM: admfdi.dll (ID = 49789)
2:44 AM: admprog.dll (ID = 49790)
2:44 AM: adm.exe (ID = 111765)
2:45 AM: asmfiles.cab (ID = 49805)
2:45 AM: dmfiles.cab (ID = 49818)
2:45 AM: dminstall7.cab (ID = 49829)
2:46 AM: bulldownload.exe (ID = 52017)
2:46 AM: pmexe.cab (ID = 49854)
2:46 AM: pmfiles.cab (ID = 49856)
2:49 AM: __unin__.exe (ID = 49793)
2:49 AM: setup.exe (ID = 49875)
2:49 AM: Found Trojan Horse: trojan-downloader-aux
2:49 AM: win38.tmp.exe (ID = 282640)
2:49 AM: Found Trojan Horse: trojan-downloader-errlook
2:49 AM: win44.tmp.exe (ID = 283245)
2:56 AM: File Sweep Complete, Elapsed Time: 00:26:06
2:56 AM: Full Sweep has completed. Elapsed time 00:31:45
2:56 AM: Traces Found: 401
2:58 AM: Removal process initiated
2:58 AM: Quarantining All Traces: purityscan
2:58 AM: Quarantining All Traces: coolwebsearch (cws)
2:58 AM: coolwebsearch (cws) is in use. It will be removed on reboot.
2:58 AM: winres.dll is in use. It will be removed on reboot.
2:58 AM: Quarantining All Traces: trojan agent winlogonhook
2:58 AM: Quarantining All Traces: trojan-downloader-aux
2:58 AM: Quarantining All Traces: trojan-downloader-errlook
2:58 AM: Quarantining All Traces: altnet
2:58 AM: Quarantining All Traces: bullguard popup ad
2:58 AM: Quarantining All Traces: rx toolbar
2:58 AM: Quarantining All Traces: topsearch
2:58 AM: Quarantining All Traces: 2o7.net cookie
2:58 AM: Quarantining All Traces: adrevolver cookie
2:58 AM: Quarantining All Traces: advertising cookie
2:58 AM: Quarantining All Traces: aptimus cookie
2:58 AM: Quarantining All Traces: ask cookie
2:58 AM: Quarantining All Traces: atlas dmt cookie
2:58 AM: Quarantining All Traces: atwola cookie
2:58 AM: Quarantining All Traces: casalemedia cookie
2:58 AM: Quarantining All Traces: fastclick cookie
2:58 AM: Quarantining All Traces: mediaplex cookie
2:58 AM: Quarantining All Traces: overture cookie
2:58 AM: Quarantining All Traces: pointroll cookie
2:58 AM: Quarantining All Traces: questionmarket cookie
2:58 AM: Quarantining All Traces: realmedia cookie
2:58 AM: Quarantining All Traces: revenue.net cookie
2:58 AM: Quarantining All Traces: ru4 cookie
2:58 AM: Quarantining All Traces: serving-sys cookie
2:58 AM: Quarantining All Traces: trafficmp cookie
2:58 AM: Quarantining All Traces: tribalfusion cookie
2:58 AM: Quarantining All Traces: tripod cookie
2:58 AM: Quarantining All Traces: yieldmanager cookie
2:58 AM: Quarantining All Traces: zedo cookie
2:58 AM: Removal process completed. Elapsed time 00:00:44
********
2:23 AM: | Start of Session, Friday, April 21, 2006 |
2:23 AM: Spy Sweeper started
2:23 AM: Sweep initiated using definitions version 662
2:23 AM: Found Adware: coolwebsearch (cws)
2:23 AM: HKCR\clsid\{2d38a51a-23c9-48a1-a33c-48675aa2b494}\inprocserver32\ (2 subtraces) (ID = 1183061)
2:23 AM: winres.dll (ID = 1183061)
2:23 AM: Starting Memory Sweep
2:24 AM: Sweep Canceled
2:24 AM: Memory Sweep Complete, Elapsed Time: 00:00:10
2:24 AM: Traces Found: 4
2:24 AM: | End of Session, Friday, April 21, 2006 |
********
2:23 AM: | Start of Session, Friday, April 21, 2006 |
2:23 AM: Spy Sweeper started
2:23 AM: Your spyware definitions have been updated.
2:23 AM: | End of Session, Friday, April 21, 2006 |
Posted Image
A thousand eyes for an eye,
Vengence is mine.

#4 MrCharlie

MrCharlie

    SuperMember

  • Malware Team
  • 2,949 posts

Posted 21 April 2006 - 02:29 PM

Please do this for me........

Download and unzip the KillBox to a folder - we'll use it later.


Enable Hidden files:

Because XP will not always show you hidden files and folders by default, Go to Start > Search and under "More advanced search options".
Make sure there is a check by "Search System Folders" and "Search hidden files and folders" and "Search system subfolders"

Next click on My Computer. Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and "Hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"
(please reverse this procedure, rehide the files, when we are done)

Close ALL programs down, leaving ONLY HijackThis running - Click Scan and.....
Place a check against the following items:

O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O20 - Winlogon Notify: winjrs32 - C:\WINDOWS\SYSTEM32\winjrs32.dll

Click on Fix Checked and exit HijackThis.

Now open up the KillBox.
Select the Delete on Reboot option.
In the field labeled Full Path of File to Delete copy and paste this in.

C:\WINDOWS\SYSTEM32\winjrs32.dll

Hit the delete button
OK
Reboot the computer
If you recieve an error message and your computer doesn't restart, please restart it manually.

Reboot and post a fresh HijackThis log and we'll take another look. MrC


#5 Corpus

Corpus

    New Member

  • Authentic Member
  • Pip
  • 18 posts
  • Interests:My fiance, computers, and music.

Posted 22 April 2006 - 07:29 AM

Logfile of HijackThis v1.99.1
Scan saved at 9:20:18 AM, on 4/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\AIM\aim.exe
C:\Documents and Settings\Ron\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.h...sario&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.comcast.net
O15 - Trusted Zone: http://flyff.gpotato.com
O15 - Trusted Zone: www.myspace.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WB - C:\Program Files\AlienGUIse\fastload.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
Posted Image
A thousand eyes for an eye,
Vengence is mine.

#6 MrCharlie

MrCharlie

    SuperMember

  • Malware Team
  • 2,949 posts

Posted 22 April 2006 - 07:54 AM

Looks OK How's it runnig?

Did you place these in your Internet Explorers Trusted Zone? If not please have HJT fix them.

O15 - Trusted Zone: http://www.comcast.net
O15 - Trusted Zone: http://flyff.gpotato.com
O15 - Trusted Zone: www.myspace.com


Let me know, MrC


#7 MrCharlie

MrCharlie

    SuperMember

  • Malware Team
  • 2,949 posts

Posted 04 May 2006 - 04:46 PM

Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoy...showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users