This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My Hijack This log and FixWareout report

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hijack this report first and then the FixWareout report. This is regards to the JUPK problem.


Logfile of HijackThis v1.99.1
Scan saved at 23:01:55, on 30/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UAService7.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Batty2\Batty2.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Mr Robson\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…age=about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HPAiODevice(hp officejet v series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Microsoft AntiSpyware helper - {053CB081-7920-4415-A209-2A390D87B323} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {053CB081-7920-4415-A209-2A390D87B323} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {09AC082D-F09D-4156-ADD5-68F720E58794} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {09AC082D-F09D-4156-ADD5-68F720E58794} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {18FEF272-03F0-410B-8B84-5184CCA2B156} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {18FEF272-03F0-410B-8B84-5184CCA2B156} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {20CD2521-4764-481E-927C-E9CCF4FE5DD3} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {20CD2521-4764-481E-927C-E9CCF4FE5DD3} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {285B1B30-AC24-41ED-B4C6-5E7FC8610D86} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {285B1B30-AC24-41ED-B4C6-5E7FC8610D86} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {2CC153EF-E1AA-4FAF-9E5E-CE79BC0BD29C} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {2CC153EF-E1AA-4FAF-9E5E-CE79BC0BD29C} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {42A7AC99-6B22-4C28-8692-6754CE42E4D0} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {42A7AC99-6B22-4C28-8692-6754CE42E4D0} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {43DC5512-8249-4049-B9DF-68896F24C937} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {43DC5512-8249-4049-B9DF-68896F24C937} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {4B77FA34-DFCE-4AD4-9892-CC4351103F62} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {4B77FA34-DFCE-4AD4-9892-CC4351103F62} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {66837FED-E3E9-44DB-BA29-1BB334A99D8D} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {66837FED-E3E9-44DB-BA29-1BB334A99D8D} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {722017DC-77FB-4F63-8165-AC2CCEC764B3} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {722017DC-77FB-4F63-8165-AC2CCEC764B3} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {784603C1-AD2A-442F-B965-C0EE683810AE} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {784603C1-AD2A-442F-B965-C0EE683810AE} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {7DBCE1D8-C0C5-4A16-8BD5-7BC3DA0D8614} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7DBCE1D8-C0C5-4A16-8BD5-7BC3DA0D8614} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {7E021926-9DA0-4E4F-9070-C20159FA6243} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7E021926-9DA0-4E4F-9070-C20159FA6243} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {7EA83D50-565D-456B-B651-39EDE5F38A04} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7EA83D50-565D-456B-B651-39EDE5F38A04} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {88B8236A-1244-41ED-A4A5-4D8C9E7160FD} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {88B8236A-1244-41ED-A4A5-4D8C9E7160FD} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {8E8B3EF7-9F34-43C6-A1EE-27C45043F6EB} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {8E8B3EF7-9F34-43C6-A1EE-27C45043F6EB} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {8FEDE94F-6053-40B0-AA79-C6B13A2109DA} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {8FEDE94F-6053-40B0-AA79-C6B13A2109DA} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {904C71C6-0AC2-4AD5-BEFC-1C55D51372CD} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {904C71C6-0AC2-4AD5-BEFC-1C55D51372CD} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {99FAA7F8-319F-4CFD-A3EF-19F7B5351410} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {99FAA7F8-319F-4CFD-A3EF-19F7B5351410} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {A2CE1600-1751-4B99-BA19-5804C834BA1E} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {A2CE1600-1751-4B99-BA19-5804C834BA1E} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {B26229DA-2856-46BC-9B35-E8ADE8913862} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {B26229DA-2856-46BC-9B35-E8ADE8913862} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {BC7F4395-5253-48B8-95A5-8966AC5049D9} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {BC7F4395-5253-48B8-95A5-8966AC5049D9} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {C573389F-9379-4FB7-A73C-1F0668401159} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {C573389F-9379-4FB7-A73C-1F0668401159} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {CE90ECB4-F423-4D18-A85C-A8DC43B1297D} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {CE90ECB4-F423-4D18-A85C-A8DC43B1297D} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {DD63DCAD-DBD9-482C-BE5C-0D3B28EB35D0} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {DD63DCAD-DBD9-482C-BE5C-0D3B28EB35D0} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {F1263D8C-82C4-4135-83BC-BB1867C033D7} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {F1263D8C-82C4-4135-83BC-BB1867C033D7} - (no file) (HKCU)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143423295109
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0D498338-BC76-4728-938D-C0563E9F99C5}: NameServer = 85.255.116.83
O17 - HKLM\System\CCS\Services\Tcpip\..\{939AE5C1-E6DB-4938-BA50-70E3B0921B19}: NameServer = 85.255.116.83
O17 - HKLM\System\CCS\Services\Tcpip\..\{F6491105-4698-4C02-AF90-9707D9FF1C78}: NameServer = 85.255.116.83
O17 - HKLM\System\CS1\Services\Tcpip\..\{0D498338-BC76-4728-938D-C0563E9F99C5}: NameServer = 85.255.116.83
O17 - HKLM\System\CS2\Services\Tcpip\..\{0D498338-BC76-4728-938D-C0563E9F99C5}: NameServer = 85.255.116.83
O17 - HKLM\System\CS3\Services\Tcpip\..\{0D498338-BC76-4728-938D-C0563E9F99C5}: NameServer = 85.255.116.83
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE27-738B1E346F99} - C:\Program Files\Batty2\Batty2.dll
O20 - AppInit_DLLs: BattyRun2.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: DirMS_Defragmentation - Unknown owner - C:\Program Files\MATCO\DirmsService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\System32\UAService7.exe







Fixwareout ver 1.003
Last edited 8/11/2006
Post this report in the forums please

Reg Entries that were deleted
…

Microsoft ® Windows Script Host Version 5.6
Random Runs removed from HKLM
…

PLEASE NOTE, There WILL be LEGITIMATE FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.

»»»»» Searching by size/names…
* csr.exe C:\WINDOWS\System32\CSDPG.EXE

»»»»»
Search five digit cs, dm and jb files.
This WILL/CAN also list Legit Files, Submit them at Virustotal
C:\WINDOWS\SYSTEM32\CSDPG.EXE 51,239 2006-03-09

Other suspects.
Directory of C:\WINDOWS\system32

»»»»» Misc files.

»»»»» Checking for older varients covered by the Rem3 tool.
Hello and Welcome to the forum.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed
to.



1. Copy and paste this bold box text into a text editor such as Notepad.


REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""



2. Save this text as ResetAppInit.reg. Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop. Include the word REGEDIT4

3. Double-click on ResetAppInit.reg. When it asks you to merge the information to the registry click Yes.



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…age=about:blank
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O17 - HKLM\System\CCS\Services\Tcpip\..\{0D498338-BC76-4728-938D-C0563E9F99C5}: NameServer = 85.255.116.83
O17 - HKLM\System\CCS\Services\Tcpip\..\{939AE5C1-E6DB-4938-BA50-70E3B0921B19}: NameServer = 85.255.116.83
O17 - HKLM\System\CCS\Services\Tcpip\..\{F6491105-4698-4C02-AF90-9707D9FF1C78}: NameServer = 85.255.116.83
O17 - HKLM\System\CS1\Services\Tcpip\..\{0D498338-BC76-4728-938D-C0563E9F99C5}: NameServer = 85.255.116.83
O17 - HKLM\System\CS2\Services\Tcpip\..\{0D498338-BC76-4728-938D-C0563E9F99C5}: NameServer = 85.255.116.83
O17 - HKLM\System\CS3\Services\Tcpip\..\{0D498338-BC76-4728-938D-C0563E9F99C5}: NameServer = 85.255.116.83
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE27-738B1E346F99} - C:\Program Files\Batty2\Batty2.dll
O20 - AppInit_DLLs: BattyRun2.dll

Close ALL windows and browsers except HijackThis and click "Fix checked"



Delete these Files if listed:
C:\Program Files\Batty2\Batty2.dll
C:\WINDOWS\SYSTEM32\CSDPG.EXE


Delete these Folders if listed:
C:\Program Files\Batty2


Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hi


I cant remove C:\Program Files\Batty2, there was a Batty and a Batty 2 folders the first one i did remove.

When i go to google or ebay etc… it is now replaced with bxnu.com to which the sites look they same as before.


When it came to the:

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


i tryed saving it as ResetAppInit.reg *ResetAppInit*.reg and *ResetAppInit.reg* the latter two would not save at all it just flashed and the first one did nothing when i double clicked on it. All was saved as All Files.
i also fixed all that was said to do in hijackthis.

Here is my latest log:


Logfile of HijackThis v1.99.1
Scan saved at 15:35:13, on 01/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UAService7.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Mr Robson\Desktop\HijackThis.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iolo\System Mechanic Professional 6\SysMech6.exe

O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HPAiODevice(hp officejet v series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Microsoft AntiSpyware helper - {053CB081-7920-4415-A209-2A390D87B323} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {053CB081-7920-4415-A209-2A390D87B323} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {09AC082D-F09D-4156-ADD5-68F720E58794} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {09AC082D-F09D-4156-ADD5-68F720E58794} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {18FEF272-03F0-410B-8B84-5184CCA2B156} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {18FEF272-03F0-410B-8B84-5184CCA2B156} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {20CD2521-4764-481E-927C-E9CCF4FE5DD3} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {20CD2521-4764-481E-927C-E9CCF4FE5DD3} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {285B1B30-AC24-41ED-B4C6-5E7FC8610D86} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {285B1B30-AC24-41ED-B4C6-5E7FC8610D86} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {2CC153EF-E1AA-4FAF-9E5E-CE79BC0BD29C} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {2CC153EF-E1AA-4FAF-9E5E-CE79BC0BD29C} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {42A7AC99-6B22-4C28-8692-6754CE42E4D0} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {42A7AC99-6B22-4C28-8692-6754CE42E4D0} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {43DC5512-8249-4049-B9DF-68896F24C937} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {43DC5512-8249-4049-B9DF-68896F24C937} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {4B77FA34-DFCE-4AD4-9892-CC4351103F62} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {4B77FA34-DFCE-4AD4-9892-CC4351103F62} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {66837FED-E3E9-44DB-BA29-1BB334A99D8D} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {66837FED-E3E9-44DB-BA29-1BB334A99D8D} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {722017DC-77FB-4F63-8165-AC2CCEC764B3} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {722017DC-77FB-4F63-8165-AC2CCEC764B3} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {784603C1-AD2A-442F-B965-C0EE683810AE} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {784603C1-AD2A-442F-B965-C0EE683810AE} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {7DBCE1D8-C0C5-4A16-8BD5-7BC3DA0D8614} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7DBCE1D8-C0C5-4A16-8BD5-7BC3DA0D8614} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {7E021926-9DA0-4E4F-9070-C20159FA6243} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7E021926-9DA0-4E4F-9070-C20159FA6243} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {7EA83D50-565D-456B-B651-39EDE5F38A04} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7EA83D50-565D-456B-B651-39EDE5F38A04} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {88B8236A-1244-41ED-A4A5-4D8C9E7160FD} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {88B8236A-1244-41ED-A4A5-4D8C9E7160FD} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {8E8B3EF7-9F34-43C6-A1EE-27C45043F6EB} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {8E8B3EF7-9F34-43C6-A1EE-27C45043F6EB} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {8FEDE94F-6053-40B0-AA79-C6B13A2109DA} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {8FEDE94F-6053-40B0-AA79-C6B13A2109DA} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {904C71C6-0AC2-4AD5-BEFC-1C55D51372CD} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {904C71C6-0AC2-4AD5-BEFC-1C55D51372CD} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {99FAA7F8-319F-4CFD-A3EF-19F7B5351410} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {99FAA7F8-319F-4CFD-A3EF-19F7B5351410} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {A2CE1600-1751-4B99-BA19-5804C834BA1E} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {A2CE1600-1751-4B99-BA19-5804C834BA1E} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {B26229DA-2856-46BC-9B35-E8ADE8913862} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {B26229DA-2856-46BC-9B35-E8ADE8913862} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {BC7F4395-5253-48B8-95A5-8966AC5049D9} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {BC7F4395-5253-48B8-95A5-8966AC5049D9} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {C573389F-9379-4FB7-A73C-1F0668401159} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {C573389F-9379-4FB7-A73C-1F0668401159} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {CE90ECB4-F423-4D18-A85C-A8DC43B1297D} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {CE90ECB4-F423-4D18-A85C-A8DC43B1297D} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {DD63DCAD-DBD9-482C-BE5C-0D3B28EB35D0} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {DD63DCAD-DBD9-482C-BE5C-0D3B28EB35D0} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {F1263D8C-82C4-4135-83BC-BB1867C033D7} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {F1263D8C-82C4-4135-83BC-BB1867C033D7} - (no file) (HKCU)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143423295109
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: DirMS_Defragmentation - Unknown owner - C:\Program Files\MATCO\DirmsService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\System32\UAService7.exe
Click Start> Run> type in CMD tap enter key Copy/Paste: ipconfig /flushdns Now lets check some settings on your system. Enter your Control Panel and double-click on Network Connections Then right click on your Default Connection Usually Local Area Connection for Cable and DSL Left click on Properties Double-Click on the Internet Protocol (TCP/IP) item Select the radio dial that says Obtain DNS Servers Automatically Press OK twice to get out of the properties screen and reboot if it asks Let me know if that worked
Good Job :thumbup:

Log looks good :D


You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.



If you dont have any programs like these, I would recommend that you get them.
Spywareblaster,
Spywareguard.
IE Spyads
They will add 1000's of sites to your resticted zone and block some hijacks from happening.

Also get a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI