MyTechSupport.ca :: Your Computer Technical Resource Headquarters! MyTechSupport.ca :: Your Computer Technical Resource Headquarters!
HOME FORUMS RESOURCES & TOOLS ARTICLES ONLINE STORE ABOUT US
Computer Support Forums arrow Internet & Network Support arrow Internet & Email arrow Topic: PLEASE HELP ASAP!! HIJACK THIS LOG
June 26, 2019, 11:41:55 PM
 

Home Forum Rules Help Search Mobile Version Login Register

Welcome, Guest. Please login or register.
Did you miss your activation email?
June 26, 2019, 11:41:55 PM

Login with username, password and session length
 
News
New  Looking for cheap hardware and/or software?
Visit our new Online Store where you will be able to purchase from a reputable vendor by country.
  0 Members and 1 Guest are viewing this topic.
Pages: [1] Go Down Print
Author Topic: PLEASE HELP ASAP!! HIJACK THIS LOG  (Read 2473 times)
viro
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 1


Bookmark and Share

View Profile
« on: August 24, 2004, 05:35:05 PM »

I've been having major spyware problems.  Here is my hijackthis log.  Can someone tell me which files to delete?  Thanks!

HijackThis v1.97.7
Scan saved at 1:32:20 PM, on 8/24/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\Program Files\CA\SharedComponents\DesktopCommonServices\DMPrimer\dmprimer.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\lotus\notes\ntmulti.exe
C:\WINDOWS\system32\mshd32.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\CA\Unicenter Remote Control\rcHost.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\tlntsvr.exe
C:\PROGRA~1\WinSNTP\winsntps.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\adrmcebq.exe
C:\WINDOWS\system32\mfcwx32.exe
C:\Documents and Settings\U202011\Application Data\msru.exe
C:\WINDOWS\System32\tevdnx.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Office\Office10\EXCEL.EXE
C:\Program Files\Thomson Financial\Thomson One\ThomsonONE.exe
C:\PROGRA~1\THOMSO~1\THOMSO~1\SHARED~1.EXE
C:\PROGRA~1\THOMSO~1\THOMSO~1\RDCDDE~1.EXE
C:\WINDOWS\regedit.exe
c:\Program Files\Internet Explorer\Iexplore.exe
C:\Documents and Settings\U202011\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\vzyxu.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vzyxu.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://business.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vzyxu.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\vzyxu.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vzyxu.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\vzyxu.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vzyxu.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Advest Internet Explorer
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
O2 - BHO: (no name) - {CA4938DF-EDB2-708B-0183-B1EF0CF56539} - C:\WINDOWS\system32\crzb.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [mfcwx32.exe] C:\WINDOWS\system32\mfcwx32.exe
O4 - HKLM\..\Run: [atlfk.exe] C:\WINDOWS\system32\atlfk.exe
O4 - HKCU\..\Run: [Cuec] C:\Documents and Settings\U202011\Application Data\msru.exe
O4 - HKCU\..\Run: [Bcnms] C:\WINDOWS\System32\tevdnx.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchmiracle.com
O16 - DPF: v2cab - http://searchmiracle.com/cab/v2cab.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {00028CF3-0000-0000-0000-000000000046} (XArray Object) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/Xarray32.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {079E8251-3A00-11D3-BF4E-0000832F7CAE} (DS100v32.clsUtility1) - http://bossadvestpa.cs.prusec.com/funcdevsuprt/SelfInstall110/DS100v32.cab
O16 - DPF: {07D7A18F-3385-11D2-B6D5-0004ACEEF34A} (TrackDetail.clsDetailConnector) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/pv299v32.cab
O16 - DPF: {0BA686AA-F7D3-101A-993E-0000C0EF6F5E} (Threed Checkbox Control) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/Threed32.cab
O16 - DPF: {0BA9C3E4-2E08-11D2-8CF7-00008326B9A0} (Enterprise Tabular Data Dll) - http://bossadvestpa.cs.prusec.com/funcdevsuprt/SelfInstall110/vb840v32.cab
O16 - DPF: {0D6234D0-DBA2-11D1-B5DF-0060976089D0} (True OLE DBGrid 6  Control) - http://bossadvestpa.cs.prusec.com/funcdevsuprt/SelfInstall110/todg6.cab
O16 - DPF: {0D62353B-DBA2-11D1-B5DF-0060976089D0} (APEX XArrayDB Object) - http://bossadvestpa.cs.prusec.com/funcdevsuprt/SelfInstall110/xarraydb.cab
O16 - DPF: {18858CA0-AE28-11D1-A40B-0000832F7DAA} (CheckImage.CheckImageControl) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/CheckCtl.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {3A08E130-8F65-11D0-9484-00A0C91110ED} (DataAdapter Object) - http://bossadvestpa.cs.prusec.com/funcdevsuprt/SelfInstall110/Dbadapt.cab
O16 - DPF: {3E3EE5DE-EA13-11D3-AC34-0004ACA27A2B} (PV307V32.clsPopulateFrame) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/pv307v32.cab
O16 - DPF: {4C1A13FC-D7CB-11D6-AF21-00B0D0714AD9} (View Class) - http://bossadvestpa.cs.prusec.com/IEMax.cab
O16 - DPF: {572E85D5-BCEE-11D1-A3D0-000083277A48} (bc Class) - http://bossadvestpa.cs.prusec.com/bs1.cab
O16 - DPF: {648BDFE3-ED75-11D1-85D7-444553540000} (Community Control) - http://bossadvestpa.cs.prusec.com/funcSTALERT/exe/comm.cab
O16 - DPF: {6496A905-45EB-11D3-A54B-00008361A802} (ds110v32.Installer) - http://bossadvestpa.cs.prusec.com/funcdevsuprt/Selfinstall110/DS110v32.cab
O16 - DPF: {661418B0-95B4-11D1-AB75-00A0C91CB2BD} (Virtual Places Base Control) - http://bossadvestpa.cs.prusec.com/funcSTALERT/exe/vpbase.cab
O16 - DPF: {6D835690-900B-11D0-9484-00A0C91110ED} (StdDataFormat Object) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/Msstdfmt.cab
O16 - DPF: {7E8AF2C1-09AC-11D5-AF01-000629AE9D93} (PV318V32.clsPopulateFrame) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/pv318v32.cab
O16 - DPF: {89B7BF01-D460-11D1-88E4-00008361DE49} (VB Calendar Control Sample) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/Msvbcldr.cab
O16 - DPF: {89C06158-1CAA-11D5-9BDD-0006290FF99C} (Enterprise Web Control) - http://bossadvestnj.cs.prusec.com/funcdevsuprt/SelfInstall110/Vb500v32.cab
O16 - DPF: {97CFDE36-37F9-11D4-BE80-006094FB2572} (pv106v32.clsRegCleanup) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/pv106v32.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {A0DEBDB1-5BF9-11D4-96E9-0004AC5B21C8} (STAlertCollectionCreator Class) - http://bossadvestpa.cs.prusec.com/funcSTALERT/exe/AlertMessage.cab
O16 - DPF: {A8BA71E3-BCF0-11D1-945D-00A0C91CB14D} (Om Control) - http://bossadvestpa.cs.prusec.com/funcSTALERT/exe/om.cab
O16 - DPF: {B038B7F1-D017-11D2-88F9-000083628EAE} (mu862v32.clsPrint) - http://bossadvestpa.cs.prusec.com/funcdevsuprt/SelfInstall110/mu862v32.cab
O16 - DPF: {B16553C0-06DB-101B-85B2-0000C009BE81} (SpinButton) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/Spin32.cab
O16 - DPF: {B7DB7E93-CA1A-41AB-AA2E-ACD8B13C80ED} (MSSMO.SoapMessage) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/MSSMO.cab
O16 - DPF: {BD10A9C1-07CC-11D2-BEFF-00A0C95A6A5C} (ReportExport Class) - http://bossadvestpa.cs.prusec.com/funcdevsuprt/SelfInstall110/sviewhlp.cab
O16 - DPF: {BE4F3AC5-AEC9-101A-947B-00DD010F7B46} (Outline Control) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/Msoutl32.cab
O16 - DPF: {BFD50F1D-3459-11D2-82EA-00008361D1E8} (Cm300v32.clsConnector) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/pv100v32.cab
O16 - DPF: {C34458B8-37A0-11D7-AF6D-0004AC5DE2C8} (Enterprise Authentication Control) - http://lbs04201.advest.mony.com/SiteInfo/AuthControl/vb520v32.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Smart Viewer 7) - http://bossadvestpa.cs.prusec.com/funcdevsuprt/SelfInstall110/crviewer.cab
O16 - DPF: {C68D2736-2D55-11D2-8CF6-00008326B9A0} (Enterprise Middleware Control) - http://bossadvestpa.cs.prusec.com/funcdevsuprt/SelfInstall110/vb260v32.cab
O16 - DPF: {CE1B5137-58EE-11D4-BE8A-006094E5ACA7} (PV107V32.PruServInstall) - http://psiwebnt04.cs.prusec.com/wexserv/pv100v32/self-install/PV107V32.CAB
O16 - DPF: {D21DD6A9-0295-11D5-AC6E-000629897D5C} (PV108V32.clsBulk) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/pv108v32.cab
O16 - DPF: {D2FFAA43-074A-11D1-BAA2-444553540000} (:-) VideoSoft vsPrinter3 Control) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/Vsview3.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://captaincooks.microgaming.com/captaincooks/FlashAX.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://firstclearing.webex.com/client/v_mywebex/training/ieatgpc.cab
O16 - DPF: {E80C823B-DE33-11D2-BEEC-00008326B6E8} (Enterprise Tabular Data Dll) - http://bossadvestpa.cs.prusec.com/funcdevsuprt/SelfInstall110/Ds800v32.cab
O16 - DPF: {EAF56DC0-6900-11D6-ACE2-0004AC5B6E47} (CM101V32.SoapExecute) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/CM101V32.cab
O16 - DPF: {F2CA2119-C8D2-11D1-BEBD-00A0C95A6A5C} (WebReportBroker Class) - http://bossadvestpa.cs.prusec.com/funcdevsuprt/SelfInstall110/swebrs.cab
O16 - DPF: {F5131C24-E56D-11CF-B78A-444553540000} (Ikonic Menu Control) - http://bossadvestpa.cs.prusec.com/funcdevsuprt/SelfInstall110/ikmenu.cab
O16 - DPF: {F9043C85-F6F2-101A-A3C9-08002B2F49FB} (Microsoft Common Dialog Control, version 6.0) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/comdlg32.cab
O16 - DPF: {FDE4A062-69AE-11D6-ACE2-0004AC5B6E47} (CM111V32.Request) - http://psiwebnt04.cs.prusec.com/funcdevsuprt/selfinstall110/Cm111V32.cab
O16 - DPF: {FF3B16A4-5C45-11D6-92AD-00B0D0714AE9} (AlertDlg Class) - http://bossadvestpa.cs.prusec.com/funcSTALERT/exe/AlertControl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{18A54EA2-CE60-481C-BF7C-B4E61C2C4BE2}: NameServer = 141.191.128.76,141.191.128.75
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = advest.mony.com,advest.com,mony.com,soc.mony.com,ho.mony.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{18A54EA2-CE60-481C-BF7C-B4E61C2C4BE2}: NameServer = 141.191.128.76,141.191.128.75
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = advest.mony.com,advest.com,mony.com,soc.mony.com,ho.mony.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{18A54EA2-CE60-481C-BF7C-B4E61C2C4BE2}: NameServer = 141.191.128.76,141.191.128.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = advest.mony.com,advest.com,mony.com,soc.mony.com,ho.mony.com


Logged

 
Pancake
Global Moderator
Hero Member
*****

Karma: +78/-0
Offline Offline

Gender: Male
Posts: 3915


Bookmark and Share

View Profile
« Reply #1 on: August 25, 2004, 07:07:38 AM »

Hi...
Run hjt in safe mode and fix these items.Any that I have listed and marked in Bold will need to be removed from your file system as well.   Make sure to have your system set to show hidden files and folders..  www.xtra.co.nz/help/0,,4155-1916458,00.html while still in safe mode,run "CWshreader".Post a new log when finished....

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\vzyxu.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vzyxu.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vzyxu.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\vzyxu.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vzyxu.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\vzyxu.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vzyxu.dll/sp.html#29126
O2 - BHO: (no name) - {CA4938DF-EDB2-708B-0183-B1EF0CF56539} - C:\WINDOWS\system32\crzb.dll
O4 - HKLM\..\Run: [mfcwx32.exe] C:\WINDOWS\system32\mfcwx32.exe
O4 - HKLM\..\Run: [atlfk.exe] C:\WINDOWS\system32\atlfk.exe
O4 - HKCU\..\Run: [Cuec] C:\Documents and Settings\U202011\Application Data\msru.exe
O4 - HKCU\..\Run: [Bcnms] C:\WINDOWS\System32\tevdnx.exe
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchmiracle.com
O16 - DPF: v2cab - http://searchmiracle.com/cab/v2cab.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
C:\WINDOWS\regedit.exe





« Last Edit: August 25, 2004, 07:11:46 AM by Pancake » Logged

An Australian Member of

EDDY
Pages: [1] Go Up Print 
 
Jump to:  

Powered by MySQL Powered by PHP

Powered by SMF 1.1.21 | SMF © 2015, Simple Machines

Valid XHTML 1.0! Valid CSS!

Disclaimer
This site is NOT responsible for any damage that the information on this site may cause to your system. Everything you try, whether inspired by the response given from this site or not, is entirely at your own risk. All product names and company names used herein are for identification purpose only and may be trademarks or registered trademarks of their respective owners. We are in no way affiliated or representing any of the companies on this site unless specified.
Back to Top
Stop Spam Harvesters, Join Project Honey Pot Fight Back Against Spammers! Get Firefox! Get Thunderbird! View Sylvain Amyots profile on LinkedIn
Back to Top
Google visited last this page March 25, 2019, 12:43:21 PM