conman
Topic Starter
Hi guys
My computer has started opening IE and going to Spyware pages need help please!!!
Below is my Hijack this post.
Logfile of HijackThis v1.99.1
Scan saved at 17:14:23, on 12/06/2007
Platform: Windows 2000 SP4 (WinNT
5.00.2195)
MSIE: Internet Explorer v6.00 SP1
(6.00.2800.1106)
Running processes:
F:\WINNT\System32\smss.exe
F:\WINNT\system32\winlogon.exe
F:\WINNT\system32\services.exe
F:\WINNT\system32\lsass.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\system32\spoolsv.exe
F:\Program Files\Grisoft\AVG
Anti-Spyware 7.5\guard.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\System32\svchost.exe
F:\WINNT\system32\regsvc.exe
F:\WINNT\system32\MSTask.exe
F:\WINNT\system32\stisvc.exe
F:\WINNT\System32\WBEM\WinMgmt.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\Explorer.EXE
F:\WINNT\system32\wuauclt.exe
F:\Program
Files\Java\jre1.6.0_01\bin\jusched.ex
e
F:\Program Files\Common
Files\Real\Update_OB\realsched.exe
F:\WINNT\system32\??sembly\dllhost.ex
e
F:\Documents and
Settings\andy\Desktop\hijack
this\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Local Page =
O2 - BHO: (no name) -
{57E218E6-5A80-4f0c-AB25-83598F25D7E9
} - F:\WINNT\system32\kooraluh.dll
(file missing)
O2 - BHO: SSVHelper Class -
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43
} - F:\Program
Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) -
{7F5FFCB8-4838-43CD-80EA-A7EC9C744281
} - F:\WINNT\system32\rqromnn.dll
(file missing)
O2 - BHO: (no name) -
{8A61098D-612B-4EF2-943D-64E920684061
} - F:\WINNT\system32\pmnonkl.dll
O2 - BHO: (no name) -
{8FF0D061-045C-4014-B375-C576E48A5D27
} - F:\WINNT\system32\xxyxw.dll (file
missing)
O2 - BHO: (no name) -
{900F4B18-F6A4-EF5A-D90E-8AADAFE373B4
} - F:\WINNT\system32\whnyunu.dll
O3 - Toolbar: &Radio -
{8E718888-423F-11D2-876E-00A0C9082467
} - F:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [NeroCheck]
F:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run:
[SunJavaUpdateSched] "F:\Program
Files\Java\jre1.6.0_01\bin\jusched.ex
e"
O4 - HKLM\..\Run: [TkBellExe]
"F:\Program Files\Common
Files\Real\Update_OB\realsched.exe"
-osboot
O4 - HKCU\..\Run: [Ndro]
"F:\WINNT\CROSOF~1\fast.exe" -vt yazb
O4 - HKCU\..\Run: [Qqknd]
F:\WINNT\system32\??sembly\dllhost.ex
e
O4 - Global Startup: Adobe Gamma
Loader.lnk = F:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma
Loader.exe
O8 - Extra context menu item: Convert
for CLIÉ - F:\Program
Files\Sony\Image Converter\menu.htm
O8 - Extra context menu item: E&xport
to Microsoft Excel -
res://F:\PROGRA~1\MICROS~3\OFFICE11\E
XCEL.EXE/3000
O9 - Extra button: (no name) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501
} - F:\Program
Files\Java\jre1.6.0_01\bin\npjpi160_0
1.dll
O9 - Extra 'Tools' menuitem: Sun Java
Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501
} - F:\Program
Files\Java\jre1.6.0_01\bin\npjpi160_0
1.dll
O15 - Trusted Zone:
*.registration.sonystyle-europe.com
(HKLM)
O16 - DPF:
{17492023-C23A-453E-A040-C7C580BBF700
} (Windows Genuine Advantage
Validation Tool) -
http://go.microsoft.com/fwlink/?linki
d=39204
O16 - DPF:
{6414512B-B978-451D-A0D8-FCFDF33E833C
} (WUWebControl Class) -
http://update.microsoft.com/windowsup
date/v6/V5Controls/en/x86/client/wuwe
b_site.cab?1150718231732
O16 - DPF:
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3
} (MUWebControl Class) -
http://update.microsoft.com/microsoft
update/v6/V5Controls/en/x86/client/mu
web_site.cab?1150718337614
O20 - Winlogon Notify: pmnonkl -
F:\WINNT\SYSTEM32\pmnonkl.dll
O20 - Winlogon Notify: rqromnn -
rqromnn.dll (file missing)
O20 - Winlogon Notify: winwrk32 -
F:\WINNT\SYSTEM32\winwrk32.dll
O20 - Winlogon Notify: xxyxw -
F:\WINNT\system32\xxyxw.dll (file
missing)
O23 - Service: Ati HotKey Poller -
Unknown owner -
F:\WINNT\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard
- Anti-Malware Development a.s. -
F:\Program Files\Grisoft\AVG
Anti-Spyware 7.5\guard.exe
O23 - Service: Logical Disk Manager
Administrative Service (dmadmin) -
VERITAS Software Corp. -
F:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table
Manager (IDriverT) - Macrovision
Corporation - F:\Program Files\Common
Files\InstallShield\Driver\11\Intel
32\IDriverT.exe
O23 - Service: iPodService - Apple
Computer, Inc. - F:\Program
Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP
- F:\WINNT\system32\HPZipm12.exe
My computer has started opening IE and going to Spyware pages need help please!!!
Below is my Hijack this post.
Logfile of HijackThis v1.99.1
Scan saved at 17:14:23, on 12/06/2007
Platform: Windows 2000 SP4 (WinNT
5.00.2195)
MSIE: Internet Explorer v6.00 SP1
(6.00.2800.1106)
Running processes:
F:\WINNT\System32\smss.exe
F:\WINNT\system32\winlogon.exe
F:\WINNT\system32\services.exe
F:\WINNT\system32\lsass.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\system32\spoolsv.exe
F:\Program Files\Grisoft\AVG
Anti-Spyware 7.5\guard.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\System32\svchost.exe
F:\WINNT\system32\regsvc.exe
F:\WINNT\system32\MSTask.exe
F:\WINNT\system32\stisvc.exe
F:\WINNT\System32\WBEM\WinMgmt.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\Explorer.EXE
F:\WINNT\system32\wuauclt.exe
F:\Program
Files\Java\jre1.6.0_01\bin\jusched.ex
e
F:\Program Files\Common
Files\Real\Update_OB\realsched.exe
F:\WINNT\system32\??sembly\dllhost.ex
e
F:\Documents and
Settings\andy\Desktop\hijack
this\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Local Page =
O2 - BHO: (no name) -
{57E218E6-5A80-4f0c-AB25-83598F25D7E9
} - F:\WINNT\system32\kooraluh.dll
(file missing)
O2 - BHO: SSVHelper Class -
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43
} - F:\Program
Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) -
{7F5FFCB8-4838-43CD-80EA-A7EC9C744281
} - F:\WINNT\system32\rqromnn.dll
(file missing)
O2 - BHO: (no name) -
{8A61098D-612B-4EF2-943D-64E920684061
} - F:\WINNT\system32\pmnonkl.dll
O2 - BHO: (no name) -
{8FF0D061-045C-4014-B375-C576E48A5D27
} - F:\WINNT\system32\xxyxw.dll (file
missing)
O2 - BHO: (no name) -
{900F4B18-F6A4-EF5A-D90E-8AADAFE373B4
} - F:\WINNT\system32\whnyunu.dll
O3 - Toolbar: &Radio -
{8E718888-423F-11D2-876E-00A0C9082467
} - F:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [NeroCheck]
F:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run:
[SunJavaUpdateSched] "F:\Program
Files\Java\jre1.6.0_01\bin\jusched.ex
e"
O4 - HKLM\..\Run: [TkBellExe]
"F:\Program Files\Common
Files\Real\Update_OB\realsched.exe"
-osboot
O4 - HKCU\..\Run: [Ndro]
"F:\WINNT\CROSOF~1\fast.exe" -vt yazb
O4 - HKCU\..\Run: [Qqknd]
F:\WINNT\system32\??sembly\dllhost.ex
e
O4 - Global Startup: Adobe Gamma
Loader.lnk = F:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma
Loader.exe
O8 - Extra context menu item: Convert
for CLIÉ - F:\Program
Files\Sony\Image Converter\menu.htm
O8 - Extra context menu item: E&xport
to Microsoft Excel -
res://F:\PROGRA~1\MICROS~3\OFFICE11\E
XCEL.EXE/3000
O9 - Extra button: (no name) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501
} - F:\Program
Files\Java\jre1.6.0_01\bin\npjpi160_0
1.dll
O9 - Extra 'Tools' menuitem: Sun Java
Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501
} - F:\Program
Files\Java\jre1.6.0_01\bin\npjpi160_0
1.dll
O15 - Trusted Zone:
*.registration.sonystyle-europe.com
(HKLM)
O16 - DPF:
{17492023-C23A-453E-A040-C7C580BBF700
} (Windows Genuine Advantage
Validation Tool) -
http://go.microsoft.com/fwlink/?linki
d=39204
O16 - DPF:
{6414512B-B978-451D-A0D8-FCFDF33E833C
} (WUWebControl Class) -
http://update.microsoft.com/windowsup
date/v6/V5Controls/en/x86/client/wuwe
b_site.cab?1150718231732
O16 - DPF:
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3
} (MUWebControl Class) -
http://update.microsoft.com/microsoft
update/v6/V5Controls/en/x86/client/mu
web_site.cab?1150718337614
O20 - Winlogon Notify: pmnonkl -
F:\WINNT\SYSTEM32\pmnonkl.dll
O20 - Winlogon Notify: rqromnn -
rqromnn.dll (file missing)
O20 - Winlogon Notify: winwrk32 -
F:\WINNT\SYSTEM32\winwrk32.dll
O20 - Winlogon Notify: xxyxw -
F:\WINNT\system32\xxyxw.dll (file
missing)
O23 - Service: Ati HotKey Poller -
Unknown owner -
F:\WINNT\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard
- Anti-Malware Development a.s. -
F:\Program Files\Grisoft\AVG
Anti-Spyware 7.5\guard.exe
O23 - Service: Logical Disk Manager
Administrative Service (dmadmin) -
VERITAS Software Corp. -
F:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table
Manager (IDriverT) - Macrovision
Corporation - F:\Program Files\Common
Files\InstallShield\Driver\11\Intel
32\IDriverT.exe
O23 - Service: iPodService - Apple
Computer, Inc. - F:\Program
Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP
- F:\WINNT\system32\HPZipm12.exe