Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93104 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Hijacked By Think-adz And Zedo


  • This topic is locked This topic is locked
6 replies to this topic

#1 rickscript

rickscript

    New Member

  • Authentic Member
  • Pip
  • 3 posts

Posted 10 May 2007 - 09:48 PM

The origin of this problem is unknown. AVG first reported 3 separate trojans on boot-up and supposedly "healed" all of them. I then ran spybot which turned up 10 different nasties including New.net, UCmore, and a few others I can't remember. It removed all but 1 and needed to run at next startup. The next start up did not succeed in removing new.net. Since I hve spyware blaster installed, I tried revertig to an earlier "snapshot" but that didn't fix it either. I found Think-adz and zedo in my registry, along with a huge number of very nasty and squirrely domains which I have never visited. I do not want to re-load my system because it has a LOT of programs, activations etc. to go through. I have posted a HJT log below


Logfile of HijackThis v1.99.1
Scan saved at 8:44:06 PM, on 5/10/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
G:\PROGRAM FILES\DigitalPersona\Bin\DPWinLct.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
G:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
G:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
G:\PROGRAM FILES\DigitalPersona\Bin\DpHost.exe
C:\WINDOWS\System32\svchost.exe
G:\PROGRAM FILES\DigitalPersona\Bin\DPFUSMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\khooker.exe
G:\PROGRAM FILES\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
G:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MOTIVESB.EXE
G:\PROGRA~1\Grisoft\AVG7\avgcc.exe
G:\PROGRAM FILES\QuickTime\qttask.exe
G:\PROGRAM FILES\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
G:\PROGRAM FILES\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
G:\PROGRAM FILES\PROJECT LAB\DDS\DDS.EXE
G:\PROGRAM FILES\DigitalPersona\Bin\DPAgnt.exe
C:\windows\system32\vdsreg.exe
G:\Program Files\ashampoo\Ashampoo UnInstaller 2002-2003\UIWatcher.exe
G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOTASKBARICON.EXE
G:\PROGRAM FILES\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
G:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
G:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
C:\WINDOWS\System32\WgaTray.exe
C:\WINDOWS\system32\ntvdm.exe
G:\PROGRAM FILES\Microsoft Office\Office10\WINWORD.EXE
G:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\Ipen.exe
G:\Program Files\Visual CD\VisCD.exe
G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\Acrobat.exe
C:\DOCUME~1\default\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\DOCUME~1\default\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Internet Explorer\iexplore.exe
G:\PROGRAM FILES\Microsoft Office\Office10\EXCEL.EXE
C:\Program Files\Internet Explorer\iexplore.exe
L:\Downloads\Ad-aware-Spybot-anti-malware tools\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.verizon.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Ricks Internet Kingdom Searcher
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\PROGRAM FILES\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORM.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - g:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: &Google Notebook - {CCCCCCD3-666F-4F81-8B69-745DE9F6D897} - G:\PROGRAM FILES\Google\Google Notebook\gnotes1.0.2.19-1486484490.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORM.DLL
O3 - Toolbar: FingerSystem IE Memo - {8D13872E-6174-49C1-B8D2-793F90CCAFAC} - G:\PROGRAM FILES\FINGER SYSTEM INC\FINGERSYSTEM IPEN DRIVER\FGIEMEMO.DLL
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - g:\program files\google\googletoolbar4.dll
O3 - Toolbar: Google Notebook - {CCCCCCDB-4DDB-4703-95D4-DD2C526397BF} - G:\PROGRAM FILES\Google\Google Notebook\gnotes1.0.2.19-1486484490.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "G:\PROGRAM FILES\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [QuickFinder Scheduler] "G:\PROGRAM FILES\WORDPERFECT OFFICE 11\PROGRAMS\QFSCHD110.EXE"
O4 - HKLM\..\Run: [Motive SmartBridge] G:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MOTIVESB.EXE
O4 - HKLM\..\Run: [AVG7_CC] G:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "G:\PROGRAM FILES\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acronis True Image Monitor] "G:\PROGRAM FILES\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "G:\PROGRAM FILES\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [CCD Manager] "G:\PROGRAM FILES\PROJECT LAB\DDS\DDS.EXE"
O4 - HKLM\..\Run: [DPAgnt] G:\PROGRAM FILES\DigitalPersona\Bin\DPAgnt.exe
O4 - HKLM\..\Run: [Configuration Manager] C:\WINDOWS\cfg32.exe
O4 - HKLM\..\Run: [{9B-BB-B6-6E-ZN}] C:\windows\system32\vdsreg.exe SKY001
O4 - HKLM\..\Run: [SpyHunter] G:\PROGRAM FILES\Enigma Software Group\SpyHunter\SpyHunter.exe
O4 - HKCU\..\Run: [UIWatcher] G:\Program Files\ashampoo\Ashampoo UnInstaller 2002-2003\UIWatcher.exe
O4 - HKCU\..\Run: [swg] G:\PROGRAM FILES\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Creative Detector] "G:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\RoboTaskBarIcon.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: c-program files-filemap by bb v302-bootalert.LNK = C:\Program Files\FileMap By BB v302\Bootalert.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: GoBack.lnk = G:\Program Files\Roxio\GoBack\GBTray.exe
O4 - Global Startup: Microtek Scanner Finder.lnk = G:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search - C:\search\search.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Customize &Menu - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMCUSTOMIZEIEMENU.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - RES://G:\PROGRA~1\MICROS~2\OFFICE10\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms &] - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMFILLFORMS.HTML
O8 - Extra context menu item: Note this (Google Notebook) - res://G:\PROGRAM FILES\Google\Google Notebook\gnotes1.0.2.19-1486484490.dll/gn_menu1.html
O8 - Extra context menu item: Note this item (Google Notebook) - res://G:\PROGRAM FILES\Google\Google Notebook\gnotes1.0.2.19-1486484490.dll/gn_menu2.html
O8 - Extra context menu item: Save Forms &^ - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMSAVEPASS.HTML
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMFILLFORMS.HTML (file missing)
O9 - Extra 'Tools' menuitem: Fill Forms &] - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMFILLFORMS.HTML (file missing)
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMSAVEPASS.HTML (file missing)
O9 - Extra 'Tools' menuitem: Save Forms &^ - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMSAVEPASS.HTML (file missing)
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMSHOWTOOLBAR.HTML (file missing)
O9 - Extra 'Tools' menuitem: RF Toolbar &2 - {724d43aa-0d85-11d4-9908-00400523e39a} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMSHOWTOOLBAR.HTML (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O9 - Extra button: PDFill PDF Editor - {FB858B22-55E2-413f-87F5-30ADC5552151} - G:\PROGRAM FILES\PlotSoft\PDFill\\DownloadPDF.exe
O15 - Trusted Zone: http://esupport.sony.com
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai...l/installer.exe
O20 - AppInit_DLLs: C:\WINDOWS\System32\perfc000.dat
O20 - Winlogon Notify: DPWLN - C:\WINDOWS\System32\DPWLEvHd.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - G:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - G:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Windows XP FUS Manager (DPFUSMgr) - DigitalPersona, Inc. - G:\PROGRAM FILES\DigitalPersona\Bin\DPFUSMgr.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - G:\PROGRAM FILES\DigitalPersona\Bin\DpHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - G:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

    Advertisements

Register to Remove


#2 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 19 May 2007 - 06:52 AM

Hello and Welcome to the forum.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
SpyHunter <--Unless it's the paid for version



Close all windows and browsers.
Open HijackThis

Click on Open Misc Tools
Click on Delete a File On Reboot
Click once on the file below to select it:
C:\WINDOWS\System32\perfc000.dat

Click on the Back button to exit Process Manager


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O4 - HKLM\..\Run: [QuickTime Task] "G:\PROGRAM FILES\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [{9B-BB-B6-6E-ZN}] C:\windows\system32\vdsreg.exe SKY001
O4 - HKLM\..\Run: [SpyHunter] G:\PROGRAM FILES\Enigma Software Group\SpyHunter\SpyHunter.exe
O15 - Trusted Zone: http://esupport.sony.com
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai...l/installer.exe
O20 - AppInit_DLLs: C:\WINDOWS\System32\perfc000.dat

Fix the 06's unless you set these polices

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

Close ALL windows and browsers except HijackThis and click "Fix checked"


Delete these Files if listed:
C:\WINDOWS\System32\perfc000.dat
C:\windows\system32\vdsreg.exe



Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#3 rickscript

rickscript

    New Member

  • Authentic Member
  • Pip
  • 3 posts

Posted 19 May 2007 - 05:03 PM

LD Tate,
Thanks so much for your reply. I printed out your instructions and followed them as closely as I could. The first problem I encountered was that I did not have a file C:\windows\system 32\perfc000.dat. In that same folder I DID have a file called perfc009.dat so I selected that one in the process manager thinking that you may have made a typo (9 instead of 0).

After running the HJT system scan, I then selected everything on your list EXCEPT for the spyhunter.exe file which was not present (I actually removed it through Add?remove programs few days ago and the HJT log you saw was older than that). Oddly enough, the perfc000.dat file DID show up on the HJT log but was not present in the root directory of C:\windows\system 32 (according to my scan and also the microsoft search dog). I then had HJT fix the selected files.
I went back to the windows\system 32 folder and found vdsreg.exeand deleted it but once again, perfc000.dat was not found (yes, I am not hiding any operating system files)

I downloaded the ATF cleaner and ran it as instructed (it cleaned out 349 MB of drek-very cool). I then rebooted and it rebooted quickly and as soon as I opened a browser, I was taken directly to a Think-Adz page which actually wanted me to log in! Like I had a user name and password for their useless site. What gall! I have now run another, fresh HJT scan and am posting it below. I believe part of the problem here is a file named "swinsdv.exe SKY001". This file has been renamed, deleted and and it still comes back on every re-boot. My connection seems a bit slow and I have unrequested windows opening up with QT movies and various "offers". Surely I can't be the only one who sees these companies offerings and vows to buy from anyone BUT them. Anyway, I guess we haven't cleaned it up yet. Here's my log and I appreciate any help you can offer. Thanks.






Logfile of HijackThis v1.99.1
Scan saved at 3:20:06 PM, on 5/19/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
G:\PROGRAM FILES\DigitalPersona\Bin\DPWinLct.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
G:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
G:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
G:\PROGRAM FILES\DigitalPersona\Bin\DpHost.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\System32\svchost.exe
G:\PROGRAM FILES\DigitalPersona\Bin\DPFUSMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\khooker.exe
G:\PROGRAM FILES\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
G:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MOTIVESB.EXE
G:\PROGRA~1\Grisoft\AVG7\avgcc.exe
G:\PROGRAM FILES\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
G:\PROGRAM FILES\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
G:\PROGRAM FILES\PROJECT LAB\DDS\DDS.EXE
G:\PROGRAM FILES\DigitalPersona\Bin\DPAgnt.exe
G:\Program Files\ashampoo\Ashampoo UnInstaller 2002-2003\UIWatcher.exe
G:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\RoboTaskBarIcon.exe
G:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
G:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
C:\WINDOWS\System32\WgaTray.exe
L:\Downloads\Ad-aware-Spybot-anti-malware tools\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.verizon.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Ricks Internet Kingdom Searcher
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\PROGRAM FILES\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORM.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - g:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: &Google Notebook - {CCCCCCD3-666F-4F81-8B69-745DE9F6D897} - G:\PROGRAM FILES\Google\Google Notebook\gnotes1.0.2.19-1486484490.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORM.DLL
O3 - Toolbar: FingerSystem IE Memo - {8D13872E-6174-49C1-B8D2-793F90CCAFAC} - G:\PROGRAM FILES\FINGER SYSTEM INC\FINGERSYSTEM IPEN DRIVER\FGIEMEMO.DLL
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - g:\program files\google\googletoolbar4.dll
O3 - Toolbar: Google Notebook - {CCCCCCDB-4DDB-4703-95D4-DD2C526397BF} - G:\PROGRAM FILES\Google\Google Notebook\gnotes1.0.2.19-1486484490.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "G:\PROGRAM FILES\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [QuickFinder Scheduler] "G:\PROGRAM FILES\WORDPERFECT OFFICE 11\PROGRAMS\QFSCHD110.EXE"
O4 - HKLM\..\Run: [Motive SmartBridge] G:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MOTIVESB.EXE
O4 - HKLM\..\Run: [AVG7_CC] G:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Acronis True Image Monitor] "G:\PROGRAM FILES\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "G:\PROGRAM FILES\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [CCD Manager] "G:\PROGRAM FILES\PROJECT LAB\DDS\DDS.EXE"
O4 - HKLM\..\Run: [DPAgnt] G:\PROGRAM FILES\DigitalPersona\Bin\DPAgnt.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\System32\swinsndv.exe SKY001
O4 - HKCU\..\Run: [UIWatcher] G:\Program Files\ashampoo\Ashampoo UnInstaller 2002-2003\UIWatcher.exe
O4 - HKCU\..\Run: [Creative Detector] "G:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\RoboTaskBarIcon.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: c-program files-filemap by bb v302-bootalert.LNK = C:\Program Files\FileMap By BB v302\Bootalert.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: GoBack.lnk = G:\Program Files\Roxio\GoBack\GBTray.exe
O4 - Global Startup: Microtek Scanner Finder.lnk = G:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O8 - Extra context menu item: &Search - C:\search\search.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Customize &Menu - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMCUSTOMIZEIEMENU.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - RES://G:\PROGRA~1\MICROS~2\OFFICE10\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms &] - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMFILLFORMS.HTML
O8 - Extra context menu item: Note this (Google Notebook) - res://G:\PROGRAM FILES\Google\Google Notebook\gnotes1.0.2.19-1486484490.dll/gn_menu1.html
O8 - Extra context menu item: Note this item (Google Notebook) - res://G:\PROGRAM FILES\Google\Google Notebook\gnotes1.0.2.19-1486484490.dll/gn_menu2.html
O8 - Extra context menu item: Save Forms &^ - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMSAVEPASS.HTML
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMFILLFORMS.HTML (file missing)
O9 - Extra 'Tools' menuitem: Fill Forms &] - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMFILLFORMS.HTML (file missing)
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMSAVEPASS.HTML (file missing)
O9 - Extra 'Tools' menuitem: Save Forms &^ - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMSAVEPASS.HTML (file missing)
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMSHOWTOOLBAR.HTML (file missing)
O9 - Extra 'Tools' menuitem: RF Toolbar &2 - {724d43aa-0d85-11d4-9908-00400523e39a} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMSHOWTOOLBAR.HTML (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O9 - Extra button: PDFill PDF Editor - {FB858B22-55E2-413f-87F5-30ADC5552151} - G:\PROGRAM FILES\PlotSoft\PDFill\\DownloadPDF.exe
O20 - Winlogon Notify: DPWLN - C:\WINDOWS\System32\DPWLEvHd.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - G:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - G:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Windows XP FUS Manager (DPFUSMgr) - DigitalPersona, Inc. - G:\PROGRAM FILES\DigitalPersona\Bin\DPFUSMgr.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - G:\PROGRAM FILES\DigitalPersona\Bin\DpHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - G:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

#4 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 19 May 2007 - 06:19 PM

Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\System32\swinsndv.exe SKY001

Close ALL windows and browsers except HijackThis and click "Fix checked"


Delete this File if listed:
C:\WINDOWS\System32\swinsndv.exe


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#5 rickscript

rickscript

    New Member

  • Authentic Member
  • Pip
  • 3 posts

Posted 21 May 2007 - 08:12 AM

Hi,
Well, this set of instructions was short, sweet and easy to follow. I did the steps and, without going too far overbaord, I think we may have "keeked its leetle butt". Unlike past instances, this time our little friend (s) appear to have nOT replicated/recreated themselves. I haven't done much yet but so far I have not been re-directed anywhere and I haven't had any unsolicited offers to swallow a handful of viagras while I refi my mortgage so I can afford more weight loss programs. I beleve we are on the verge of success, thanks solely to your insightful observations and sage advice. I am posting my latest HJT log below and hopefully you can move on to help some other law-abiding citizen breathe free again. Thanks mr LD Tate.

Logfile of HijackThis v1.99.1
Scan saved at 6:54:01 AM, on 5/21/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
G:\PROGRAM FILES\DigitalPersona\Bin\DPWinLct.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
G:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
G:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
G:\PROGRAM FILES\DigitalPersona\Bin\DpHost.exe
C:\WINDOWS\System32\svchost.exe
G:\PROGRAM FILES\DigitalPersona\Bin\DPFUSMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\khooker.exe
G:\PROGRAM FILES\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
G:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MOTIVESB.EXE
G:\PROGRA~1\Grisoft\AVG7\avgcc.exe
G:\PROGRAM FILES\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
G:\PROGRAM FILES\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
G:\PROGRAM FILES\PROJECT LAB\DDS\DDS.EXE
G:\PROGRAM FILES\DigitalPersona\Bin\DPAgnt.exe
G:\Program Files\ashampoo\Ashampoo UnInstaller 2002-2003\UIWatcher.exe
G:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\RoboTaskBarIcon.exe
G:\PROGRAM FILES\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
G:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
C:\WINDOWS\System32\WgaTray.exe
L:\Downloads\Ad-aware-Spybot-anti-malware tools\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.verizon.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Ricks Internet Kingdom Searcher
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\PROGRAM FILES\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORM.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - g:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: &Google Notebook - {CCCCCCD3-666F-4F81-8B69-745DE9F6D897} - G:\PROGRAM FILES\Google\Google Notebook\gnotes1.0.2.19-1486484490.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORM.DLL
O3 - Toolbar: FingerSystem IE Memo - {8D13872E-6174-49C1-B8D2-793F90CCAFAC} - G:\PROGRAM FILES\FINGER SYSTEM INC\FINGERSYSTEM IPEN DRIVER\FGIEMEMO.DLL
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - g:\program files\google\googletoolbar4.dll
O3 - Toolbar: Google Notebook - {CCCCCCDB-4DDB-4703-95D4-DD2C526397BF} - G:\PROGRAM FILES\Google\Google Notebook\gnotes1.0.2.19-1486484490.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "G:\PROGRAM FILES\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [QuickFinder Scheduler] "G:\PROGRAM FILES\WORDPERFECT OFFICE 11\PROGRAMS\QFSCHD110.EXE"
O4 - HKLM\..\Run: [Motive SmartBridge] G:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MOTIVESB.EXE
O4 - HKLM\..\Run: [AVG7_CC] G:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Acronis True Image Monitor] "G:\PROGRAM FILES\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "G:\PROGRAM FILES\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [CCD Manager] "G:\PROGRAM FILES\PROJECT LAB\DDS\DDS.EXE"
O4 - HKLM\..\Run: [DPAgnt] G:\PROGRAM FILES\DigitalPersona\Bin\DPAgnt.exe
O4 - HKCU\..\Run: [UIWatcher] G:\Program Files\ashampoo\Ashampoo UnInstaller 2002-2003\UIWatcher.exe
O4 - HKCU\..\Run: [Creative Detector] "G:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [swg] G:\PROGRAM FILES\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: c-program files-filemap by bb v302-bootalert.LNK = C:\Program Files\FileMap By BB v302\Bootalert.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: GoBack.lnk = G:\Program Files\Roxio\GoBack\GBTray.exe
O4 - Global Startup: Microtek Scanner Finder.lnk = G:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O8 - Extra context menu item: &Search - C:\search\search.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://G:\PROGRAM FILES\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Customize &Menu - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMCUSTOMIZEIEMENU.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - RES://G:\PROGRA~1\MICROS~2\OFFICE10\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms &] - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMFILLFORMS.HTML
O8 - Extra context menu item: Note this (Google Notebook) - res://G:\PROGRAM FILES\Google\Google Notebook\gnotes1.0.2.19-1486484490.dll/gn_menu1.html
O8 - Extra context menu item: Note this item (Google Notebook) - res://G:\PROGRAM FILES\Google\Google Notebook\gnotes1.0.2.19-1486484490.dll/gn_menu2.html
O8 - Extra context menu item: Save Forms &^ - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMSAVEPASS.HTML
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMFILLFORMS.HTML (file missing)
O9 - Extra 'Tools' menuitem: Fill Forms &] - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMFILLFORMS.HTML (file missing)
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMSAVEPASS.HTML (file missing)
O9 - Extra 'Tools' menuitem: Save Forms &^ - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMSAVEPASS.HTML (file missing)
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMSHOWTOOLBAR.HTML (file missing)
O9 - Extra 'Tools' menuitem: RF Toolbar &2 - {724d43aa-0d85-11d4-9908-00400523e39a} - FILE://G:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORMCOMSHOWTOOLBAR.HTML (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O9 - Extra button: PDFill PDF Editor - {FB858B22-55E2-413f-87F5-30ADC5552151} - G:\PROGRAM FILES\PlotSoft\PDFill\\DownloadPDF.exe
O20 - Winlogon Notify: DPWLN - C:\WINDOWS\System32\DPWLEvHd.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - G:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - G:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Windows XP FUS Manager (DPFUSMgr) - DigitalPersona, Inc. - G:\PROGRAM FILES\DigitalPersona\Bin\DPFUSMgr.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - G:\PROGRAM FILES\DigitalPersona\Bin\DpHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - G:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

#6 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 21 May 2007 - 03:49 PM

You can remove any programs / Tools I had you install. Use Add/Remove Programs to remove if listed there otherwise just delete them and empty recycle bin.

Log looks good :D


You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.



If you dont have any programs like these, I would recommend that you get them.
Spywareblaster,
Spywareguard.


Also get a FREE FIREWALL and FREE ANTI VIRUS if you need one.

Only run one Anti-Virus and Firewall program.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Do not use Ad-aware if you have McAfee's VirusScan and AntiSpyware


Safe Surfing. :D

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#7 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 23 May 2007 - 07:15 AM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Coyote's Installed programs for prevention:

http://forums.tomcoy...showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users