This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I Hate Think-adz

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi this is my first time so to say i'm a newb would be a gross understatement.
Anyway, i had a bunch of malaware on my computer which have been deleted via Adaware and Spybot Search&Destroy.
However, every time I run Internet Explorer, it's slow and there are pop up adz that abound, even though I have Google Pop-Up Ad blocker. I'm almost 100% sure it's b/c of Think-Adz which has somehow seeped into my startup. I have deleted Think-Adz programs from Remove Programs and even Hijacked this and deleted the two Think-Adz entries. I don't think I should have done the last step on my own. Now my computer startsup funny and internet is still a problem. Any assistance would be so greatly appreciated. Below is my hijack log:

Logfile of HijackThis v1.99.1
Scan saved at 3:15:45 PM, on 6/19/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\aikhznf.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\xgcf\uqjyrgs.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\aikhznfA.exe
C:\windows\system32\mpdsregr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\rwinqndt.exe
C:\Program Files\Logitech\SetPoint\kem.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\James Uhm\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [axej] C:\Program Files\xgcf\uqjyrgs.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [MP3PAgent] C:\Program Files\Hanmaro\MediaRose\USBSync\MP3PAgent.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\adatiu.exe reg_run
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [poolsv] "C:\WINDOWS\poolsv.exe"
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\System32\rwinqndt.exe CHD003
O4 - HKLM\..\Run: [aikhznfA] C:\WINDOWS\aikhznfA.exe
O4 - HKLM\..\Run: [{00-0A-A0-0D-ZN}] C:\windows\system32\mpdsregr.exe CHD003
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O13 - DefaultPrefix:
O13 - WWW Prefix:
O13 - Home Prefix:
O13 - Mosaic Prefix:
O13 - FTP Prefix:
O13 - Gopher Prefix:
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {00001024-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter24 Class) - http://download.netmarble.com/web/nmstarter/NMStarter24.cab
O16 - DPF: {04E7BADF-F3B9-420D-B82D-8D8CADEFE4F9} (CyImage2Ctl Class) - http://cyimg6.cyworld.nate.com/ImageUpload…mageUpload3.cab
O16 - DPF: {447F9423-2046-4267-9B93-11626D001183} (RewardNetwork amLauncher Class) - http://affiliate.rewardnetwork.net/codebas…/WSgooddayi.cab
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} - https://member.netmarble.net/kdefense/kdfense8237.cab
O16 - DPF: {A671DC03-71D0-4CF0-895C-7D4A248FC1F1} (skcbgmset Class) - http://cyimg7.cyworld.nate.com/cymusic/package/skcbgmset.cab
O16 - DPF: {AF60D574-F249-4243-8040-5521AAA5BB5E} (PandoraTVSet Class) - http://imgcdn.pandora.tv/pan_img/p3player/…ge/pdrtvset.cab
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\aikhznf.exe
Hello riparian and welcome to the TomCoyote Forums

My name is Trevuren and I will be helping you with your problem. If you are still in need of assistance please do the following:

A. I need to get you to move HijackThis to a folder of its own so that nothing gets deleted by mistake

1. Right click in an empty space on your desktop.

2. From the Menu, click New, then Folder and a folder will appear on your desktop.

3. Name the folder HJT

4. Drag the current HijackThis icon from your desktop into the new Folder that was just created.

5. Now, run the program and post a fresh HJT log for review.


B. In addition, I will require a list of uninstallable programs:


To Provide a List of Installed Programs
  • Run HijackThis.
  • Click Config>>Miscellaneous Tools>>Open Uninstall Manager>>Save List
  • Save list to Desktop
  • Copy the Notepad list and Paste it into this thread.
Regards,

Trevuren
Hello Trevuren, I really appreciate your assistance. For some reason, whenever i dragged hijackthis program onto new folder on desktop as instructed, it kept making shortcuts instead of moving the program. So i moved the program onto a new folder which is what i think you wanted. Here is the new file:

Logfile of HijackThis v1.99.1
Scan saved at 2:40:20 PM, on 6/28/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\tokiuucp.exe
C:\WINDOWS\aikhznf.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\xgcf\uqjyrgs.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\aikhznfA.exe
C:\windows\system32\mpdsregr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\rwinqndt.exe
C:\Program Files\Logitech\SetPoint\kem.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\System32\iyvckjvu.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\James Uhm\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [axej] C:\Program Files\xgcf\uqjyrgs.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [MP3PAgent] C:\Program Files\Hanmaro\MediaRose\USBSync\MP3PAgent.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\adatiu.exe reg_run
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [poolsv] "C:\WINDOWS\poolsv.exe"
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\System32\rwinqndt.exe CHD003
O4 - HKLM\..\Run: [aikhznfA] C:\WINDOWS\aikhznfA.exe
O4 - HKLM\..\Run: [{00-0A-A0-0D-ZN}] C:\windows\system32\mpdsregr.exe CHD003
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\System32\slsspimk.dll",forkonce
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\SYSTEM32\rwinqndt.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O13 - DefaultPrefix:
O13 - WWW Prefix:
O13 - Home Prefix:
O13 - Mosaic Prefix:
O13 - FTP Prefix:
O13 - Gopher Prefix:
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {00001024-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter24 Class) - http://download.netmarble.com/web/nmstarter/NMStarter24.cab
O16 - DPF: {04E7BADF-F3B9-420D-B82D-8D8CADEFE4F9} (CyImage2Ctl Class) - http://cyimg7.cyworld.com/ImageUpload/CyIm…pload_10212.cab
O16 - DPF: {447F9423-2046-4267-9B93-11626D001183} (RewardNetwork amLauncher Class) - http://affiliate.rewardnetwork.net/codebas…/WSgooddayi.cab
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} - https://member.netmarble.net/kdefense/kdfense8237.cab
O16 - DPF: {A671DC03-71D0-4CF0-895C-7D4A248FC1F1} (skcbgmset Class) - http://cyimg7.cyworld.nate.com/cymusic/package/skcbgmset.cab
O16 - DPF: {AF60D574-F249-4243-8040-5521AAA5BB5E} (PandoraTVSet Class) - http://imgcdn.pandora.tv/pan_img/p3player/…ge/pdrtvset.cab
O23 - Service: DomainService - - C:\WINDOWS\System32\tokiuucp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\aikhznf.exe




with regards to the uninstall manager, whenever i press save list, the hijackthis program just disappears and no list is evident. i will type out the list for you manually here:

uTorrent
Ad-aware SE personal
Adobe Flash Player 9 Active X
Adober Reader 7.0.8
Apple Software Update
Backup Dell-Installed Programs
Dell Resource CD
Divx Codec
Divx Content Uploader
Divx Converter
Divx Player
Divx Web Player
Doom II
Google Toolbar for Internet Explorer
Half-Life
HijackThis 1.99.1
iTunes
Java SE Runtime Environment 6 Update 1
Logitech Setpoint
Microsoft Office 2000 Premium
NJStar Communicator
Quicktime
Realplayer
WD Diagnostics
Winamp (Remove Only)
Windows Overlay Components
WinRar Archiver
Winzip


A while ago i did uninstall Think-Adz and some other rogue program. Windows Overlay Components looks fishy to me, but you are the expert. I eagerly await for your response, thanks again.
What a kettle of fish!!! A lot of bad stuff in that log.

Please download this file - combofix.exe by sUBs
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

Regards,

Trevuren

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI