This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Second Log

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.97.7
Scan saved at 5:31:28 PM, on 11/20/2003
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\RUNSERVICE.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
C:\PROGRAM FILES\MOTIVE\MOTMON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\MCBIN\AV\RT\MGAVRTCL.EXE
C:\PROGRAM FILES\WINPOET BROADBAND CONNECTION\WINPPPOVERETHERNET.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\AIM\AIM.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\WINDOWS\MCBIN\AV\RT\MGAVRTE.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\MY DOCUMENTS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://search.microgirls.com/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.microgirls.com/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.microgirls.com/index.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.microgirls.com/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.microgirls.com/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://search.microgirls.com/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.microgirls.com/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.microgirls.com/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.microgirls.com/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.microgirls.com/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = ,
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\WINDOWS\Application Data\Mozilla\Profiles\default\znmmb2gm.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRAM%20FILES%5CNETSCAPE%5CNETSCAPE%5Csearchplugins%5CSBWeb_01.src"); (C:\WINDOWS\Application Data\Mozilla\Profiles\default\znmmb2gm.slt\prefs.js)
O1 - Hosts: 69.56.129.54 www.altavista.com
O1 - Hosts: 69.56.129.54 altavista.com
O1 - Hosts: 69.56.129.54 search.microsoft.com
O1 - Hosts: 69.56.129.54 www.search.com
O1 - Hosts: 69.56.129.54 search.com
O1 - Hosts: 69.56.129.54 www.teoma.com
O1 - Hosts: 69.56.129.54 teoma.com
O1 - Hosts: 69.56.129.54 www.alltheweb.com
O1 - Hosts: 69.56.129.54 alltheweb.com
O1 - Hosts: 69.56.129.54 www.wisenut.com
O1 - Hosts: 69.56.129.54 wisenut.com
O1 - Hosts: 69.56.129.54 www.dmoz.org
O1 - Hosts: 69.56.129.54 dmoz.org
O1 - Hosts: 69.56.129.54 www.excite.com
O1 - Hosts: 69.56.129.54 excite.com
O1 - Hosts: 69.56.129.54 www.lycos.com
O1 - Hosts: 69.56.129.54 lycos.com
O1 - Hosts: 69.56.129.54 www.hotbot.com
O1 - Hosts: 69.56.129.54 hotbot.com
O1 - Hosts: 69.56.129.54 www.casino.com
O1 - Hosts: 69.56.129.54 casino.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_2_3_0.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_2_3_0.DLL
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\motmon.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [mgavrtclexe] C:\WINDOWS\MCBin\AV\Rt\mgavrtcl.exe
O4 - HKLM\..\Run: [a-winpoet-service] "C:\Program Files\WinPoET Broadband Connection\winpppoverethernet.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [mgavrtclexe] C:\WINDOWS\MCBin\AV\Rt\mgavrte.exe
O4 - HKLM\..\RunServices: [LicCtrl] runservice.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM\aim.exe -cnetwait.odl
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://hp.my.yahoo.com
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/23fa1fd3b8058c064823/…ip/RdxIE601.cab
O16 - DPF: DigiChat Applet - http://host5.digichat.com/DigiChat/DigiClasses/Client_IE.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/…7922.5772685185
That's a bit better - should really stick to the same thread but anyway…When carrying out the instructions below, make sure that you have no other browsers or windows open as this could compromise the operation. Open HJT, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://search.microgirls.com/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.microgirls.com/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.microgirls.com/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.microgirls.com/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.microgirls.com/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://search.microgirls.com/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.microgirls.com/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.microgirls.com/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.microgirls.com/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.microgirls.com/index.html
O1 - Hosts: 69.56.129.54 www.altavista.com
O1 - Hosts: 69.56.129.54 altavista.com
O1 - Hosts: 69.56.129.54 search.microsoft.com
O1 - Hosts: 69.56.129.54 www.search.com
O1 - Hosts: 69.56.129.54 search.com
O1 - Hosts: 69.56.129.54 www.teoma.com
O1 - Hosts: 69.56.129.54 teoma.com
O1 - Hosts: 69.56.129.54 www.alltheweb.com
O1 - Hosts: 69.56.129.54 alltheweb.com
O1 - Hosts: 69.56.129.54 www.wisenut.com
O1 - Hosts: 69.56.129.54 wisenut.com
O1 - Hosts: 69.56.129.54 www.dmoz.org
O1 - Hosts: 69.56.129.54 dmoz.org
O1 - Hosts: 69.56.129.54 www.excite.com
O1 - Hosts: 69.56.129.54 excite.com
O1 - Hosts: 69.56.129.54 www.lycos.com
O1 - Hosts: 69.56.129.54 lycos.com
O1 - Hosts: 69.56.129.54 www.hotbot.com
O1 - Hosts: 69.56.129.54 hotbot.com
O1 - Hosts: 69.56.129.54 www.casino.com
O1 - Hosts: 69.56.129.54 casino.com
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/23fa1fd3b8058c064823/…ip/RdxIE601.cab


Reboot when done. Let us know if everything is OK
Glad we could help. :)

If you need this topic reopened, please request this by sending
Email to Zero or
Email to cnm or
Email to Coyote
Choose only one of the above
Include your post user name and detail why you need it reopened with a valid link to your post, any bad links or emails that are not from the original poster will be deleted without response.

Others please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI