This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

homepage locked

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey, new to the malware, my computer is safe but my friends on the other hand, heres the hijack this log. the hompage is locked, all kind of pop ups, ad-aware finds new stuff every 10mins as well as CA security. if some could please help

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:48:34 PM, on 3/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\All Users\Documents\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\Datawire\NAM-IP\namservice.exe
C:\Program Files\Datawire\NAM-IP\dwnam_ip.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\MAKTray.exe
C:\Program Files\PDF Complete\pdfsty.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\PDF Complete\pdfsaver.exe
C:\WINDOWS\MAKHKEY.EXE
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\PVSW\Bin\W3DBSMGR.EXE
C:\3apps\Catapult\Sched.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Rsposics\rsposics.exe
C:\Program Files\RABCO\X_RABCOse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\3apps\Catapult\pos.exe
C:\WINDOWS\system32\P32HELP.EXE
C:\3apps\Catapult\appipc.exe
C:\3apps\Catapult\3uparc.exe
C:\3apps\services\wruncbl.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://quicknews.info/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
F2 - REG:system.ini: UserInit=userinit.exe,C:\WINDOWS\system\lsass.exe
O1 - Hosts: 172.26.16.27 ntfcfspa.corp.radioshack.net # FTP Server
O1 - Hosts: 139.60.220.2 dfva.radioshack.com # VPN Server A
O1 - Hosts: 139.60.220.8 dfvb.radioshack.com # VPN Server B
O1 - Hosts: 172.23.22.81 dev1.tis.tandy.com # Development SAP Server
O1 - Hosts: 172.23.22.82 dist.tis.tandy.com # Tandem SAP Server
O1 - Hosts: 129.33.160.116 vxn1.datawire.net # ############ #
O1 - Hosts: 216.22.36.75 vxn.datawire.net # Datawire #
O1 - Hosts: 64.243.142.36 vxn2.datawire.net # Redirect #
O1 - Hosts: 216.112.91.167 vxn3.datawire.net # ############ #
O2 - BHO: (no name) - {03A6CDEC-AFCD-4450-8ECE-530FDCACA99A} - C:\Program Files\microsoft frontpage\budi89104.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {91223DE9-F8E6-4FFD-8889-BE6784C18696} - C:\WINDOWS\system32\byxwusr.dll (file missing)
O2 - BHO: (no name) - {a4acf702-f697-4e12-95af-164e19f70f53} - (no file)
O2 - BHO: {eaa6004c-862b-d1c8-f7c4-85857f504b8b} - {b8b405f7-5858-4c7f-8c1d-b268c4006aae} - C:\WINDOWS\system32\mqkxkxtg.dll
O2 - BHO: (no name) - {C3A554B1-7375-4656-BFEB-AE89FDB064EC} - C:\WINDOWS\system32\ssttu.dll (file missing)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [MAKTray] MAKTray.exe
O4 - HKLM\..\Run: [PDF Complete] "C:\Program Files\PDF Complete\pdfsty.exe"
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] D:\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [904384a3] rundll32.exe "C:\WINDOWS\system32\giwgplos.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [FEW] "C:\Program Files\_wef_\sf.exe" /scan
O4 - HKCU\..\Run: [JavaCore] C:\Program Files\\JavaCore\\JavaCore.exe
O4 - HKCU\..\Run: [nvcoi] C:\Program Files\nvcoi\nvcoi.exe
O4 - Startup: Eagle Listener.lnk = C:\3apps\Catapult\3listen.exe
O4 - Startup: Eagle Scheduler.lnk = C:\3apps\Catapult\Sched.exe
O4 - Startup: RABCO - Auto Update.lnk = C:\Program Files\RABCO\RABCOse.exe
O4 - Startup: RadioShack POS.lnk = C:\Rsposics\rsposics.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Pervasive.SQL Workgroup Engine.lnk = C:\PVSW\Bin\W3DBSMGR.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.sckiosks.com
O16 - DPF: {1A26F07F-0D60-4835-91CF-1E1766A0EC56} - http://scanner2.malware-scan.com/setup/webinst.cab
O16 - DPF: {1A55C1F2-9D51-BE3B-311F-498C05AADF56} - http://performanceoptimizer.com/files/Perf…e_Installer.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/securityadvisor/virusinfo/webscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B947A3D0-CC6D-4D09-A1B7-9F0024166E3D}: NameServer = 4.2.2.1,4.2.2.2
O20 - Winlogon Notify: byxwusr - byxwusr.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Documents and Settings\All Users\Documents\aawservice.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: DWNAMService - Unknown owner - C:\Program Files\Datawire\NAM-IP\namservice.exe
O23 - Service: GhostStartService - Unknown owner - D:\GhostStartService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 7989 bytes
well i looked around everywhere, got some ideas, dl'ed atf cleaner, mbam, spybot, and vundofix
ran all three- aftershuting down of course. these are the reports from MBAM. vundofix didnt find anything.
homepage is still locked

Malwarebytes' Anti-Malware 1.09
Database version: 507

Scan type: Full Scan (C:\|F:\|H:\|)
Objects scanned: 79505
Time elapsed: 15 minute(s), 14 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 17
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 5
Files Infected: 60

Memory Processes Infected:
c:\program files\RABCO\x_rabcose.exe (Adware.RABCO) -> No action taken.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1a26f07f-0d60-4835-91cf-1e1766a0ec56} (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\BO1jiZmwnF2zhi (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\xInsiDERexe (Adware.Agent) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RABCO (Adware.RABCO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\RABCO (Adware.RABCO) -> No action taken.
HKEY_CURRENT_USER\Software\RABCO (Adware.RABCO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\RABCO (Adware.RABCO) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.

Registry Values Infected:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\JavaCore (Trojan.Downloader) -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\Administrator\Local Settings\Temp\NI.UGA6P_0001_N122M2802 (Rogue.Multiple) -> No action taken.
C:\WINDOWS\system32\iDlo01 (Trojan.Downloader) -> No action taken.
C:\Program Files\Temporary (Trojan.Agent) -> No action taken.
C:\Program Files\RABCO (Adware.RABCO) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Rabio (Adware.Rabio) -> No action taken.

Files Infected:
c:\program files\RABCO\x_rabcose.exe (Adware.RABCO) -> No action taken.
C:\Documents and Settings\Administrator\Local Settings\Temp\winvsnet.exe (Rogue.Installer) -> No action taken.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\TLHUBZTI\winvsnet[1].exe (Rogue.Installer) -> No action taken.
C:\Program Files\RABCO\RABCO.dll (Adware.RABCO) -> No action taken.
C:\Program Files\RABCO\RABCOse.exe (Adware.RABCO) -> No action taken.
C:\Program Files\RABCO\un_RABCOSetup_16230.exe (Adware.Rabio) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP176\A0009884.exe (Trojan.DownLoader) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP176\A0009895.exe (Adware.WebBuying) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP176\A0009896.exe (Trojan.DownLoader) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP176\A0009901.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP176\A0010899.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP177\A0010919.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP177\A0010957.exe (Trojan.DownLoader) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP179\A0010998.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP179\A0011022.exe (Trojan.DownLoader) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP179\A0011023.exe (Trojan.DownLoader) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP179\A0011026.dll (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP179\A0011027.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP179\A0011029.exe (Adware.Rabio) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP179\A0011030.exe (Trojan.DownLoader) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP179\A0011031.dll (Adware.Agent) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP179\A0011032.dll (Adware.TTC) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP179\A0011033.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP179\A0011034.exe (Adware.TTC) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP179\A0011049.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP180\A0011073.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP180\A0012103.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP180\A0012121.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP183\A0012172.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP183\A0012188.exe (Trojan.Insider) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP183\A0012189.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP183\A0012193.dll (Adware.Agent) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP183\A0012198.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP186\A0012235.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP188\A0012262.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP188\A0012282.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP190\A0012299.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP190\A0012314.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP191\A0012337.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP191\A0012350.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP191\A0012363.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP192\A0013364.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP194\A0013400.exe (Trojan.Insider) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP194\A0013410.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP194\A0013427.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP194\A0013440.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP194\A0013449.exe (Adware.RABCO) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP197\A0013488.dll (Adware.TTC) -> No action taken.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP197\A0013542.exe (Adware.RABCO) -> No action taken.
C:\WINDOWS\system32\c4\np89104.exe (Adware.TTC) -> No action taken.
C:\WINDOWS\system32\k8\ravecom3.exe (Adware.RABCO) -> No action taken.
C:\Documents and Settings\Administrator\Local Settings\Temp\NI.UGA6P_0001_N122M2802\settings.ini (Rogue.Multiple) -> No action taken.
C:\Program Files\RABCO\ExecutionDll.dll (Adware.RABCO) -> No action taken.
C:\Program Files\RABCO\RABCO.dll.intermediate.manifest (Adware.RABCO) -> No action taken.
C:\Program Files\RABCO\RABCOse.info (Adware.RABCO) -> No action taken.
C:\Program Files\RABCO\RABCOse.original (Adware.RABCO) -> No action taken.
C:\Program Files\RABCO\Setup.log (Adware.RABCO) -> No action taken.
C:\Program Files\RABCO\un_RABCOSetup_16230.txt (Adware.RABCO) -> No action taken.
C:\Program Files\RABCO\X_RABCOse.log (Adware.RABCO) -> No action taken.
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\RABCO - Auto Update.lnk (Adware.RABCO) -> No action taken.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:02:34 PM, on 3/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\All Users\Documents\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\Datawire\NAM-IP\namservice.exe
C:\Program Files\Datawire\NAM-IP\dwnam_ip.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\MAKTray.exe
C:\Program Files\PDF Complete\pdfsty.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\MAKHKEY.EXE
C:\Program Files\PDF Complete\pdfsaver.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PVSW\Bin\W3DBSMGR.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\3apps\Catapult\Sched.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\3apps\Catapult\pos.exe
C:\WINDOWS\system32\P32HELP.EXE
C:\3apps\Catapult\appipc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://quicknews.info/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
O1 - Hosts: 172.26.16.27 ntfcfspa.corp.radioshack.net # FTP Server
O1 - Hosts: 139.60.220.2 dfva.radioshack.com # VPN Server A
O1 - Hosts: 139.60.220.8 dfvb.radioshack.com # VPN Server B
O1 - Hosts: 172.23.22.81 dev1.tis.tandy.com # Development SAP Server
O1 - Hosts: 172.23.22.82 dist.tis.tandy.com # Tandem SAP Server
O1 - Hosts: 129.33.160.116 vxn1.datawire.net # ############ #
O1 - Hosts: 216.22.36.75 vxn.datawire.net # Datawire #
O1 - Hosts: 64.243.142.36 vxn2.datawire.net # Redirect #
O1 - Hosts: 216.112.91.167 vxn3.datawire.net # ############ #
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {91223DE9-F8E6-4FFD-8889-BE6784C18696} - C:\WINDOWS\system32\byxwusr.dll (file missing)
O2 - BHO: (no name) - {a4acf702-f697-4e12-95af-164e19f70f53} - (no file)
O2 - BHO: (no name) - {C3A554B1-7375-4656-BFEB-AE89FDB064EC} - C:\WINDOWS\system32\ssttu.dll (file missing)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [MAKTray] MAKTray.exe
O4 - HKLM\..\Run: [PDF Complete] "C:\Program Files\PDF Complete\pdfsty.exe"
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] D:\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [904384a3] rundll32.exe "C:\WINDOWS\system32\giwgplos.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [FEW] "C:\Program Files\_wef_\sf.exe" /scan
O4 - HKCU\..\Run: [nvcoi] C:\Program Files\nvcoi\nvcoi.exe
O4 - Startup: Eagle Listener.lnk = C:\3apps\Catapult\3listen.exe
O4 - Startup: Eagle Scheduler.lnk = C:\3apps\Catapult\Sched.exe
O4 - Startup: RadioShack POS.lnk = C:\Rsposics\rsposics.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Pervasive.SQL Workgroup Engine.lnk = C:\PVSW\Bin\W3DBSMGR.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.sckiosks.com
O16 - DPF: {1A55C1F2-9D51-BE3B-311F-498C05AADF56} - http://performanceoptimizer.com/files/Perf…e_Installer.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/securityadvisor/virusinfo/webscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B947A3D0-CC6D-4D09-A1B7-9F0024166E3D}: NameServer = 4.2.2.1,4.2.2.2
O20 - Winlogon Notify: byxwusr - byxwusr.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Documents and Settings\All Users\Documents\aawservice.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: DWNAMService - Unknown owner - C:\Program Files\Datawire\NAM-IP\namservice.exe
O23 - Service: GhostStartService - Unknown owner - D:\GhostStartService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 7245 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI