MyTechSupport.ca :: Your Computer Technical Resource Headquarters! MyTechSupport.ca :: Your Computer Technical Resource Headquarters!
HOME FORUMS RESOURCES & TOOLS ARTICLES ONLINE STORE ABOUT US
Computer Support Forums arrow Internet & Network Support arrow Security & Viruses arrow Topic: Website Viewer
August 22, 2019, 01:37:03 PM
 

Home Forum Rules Help Search Mobile Version Login Register

Welcome, Guest. Please login or register.
Did you miss your activation email?
August 22, 2019, 01:37:03 PM

Login with username, password and session length
 
News
New  We now offer MyTechSupport.ca Merchandise! Every purchase goes towards maintaining our site.
Thank you for supporting MyTechSupport.ca!
  0 Members and 1 Guest are viewing this topic.
Pages: [1] Go Down Print
Author Topic: Website Viewer  (Read 3350 times)
chaddy2401
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 1


Bookmark and Share

View Profile
« on: March 10, 2005, 09:36:29 PM »

PLEASE SUPPLY RELEVANT INFORMATION:
Operating System Version:Windows 2000 Proffesional
Problem Application Name & Version:Website Viewer
Problem Hardware Make & Model:
Error Messages:



I have a terribly annoying problem. A program called website viewer disconnects my broadband about every 20 minutes and adds icons to my desktop named 's*x' 'mega p*rn' and other things like that.
Please help!!!

Logfile of HijackThis v1.99.1
Scan saved at 21:19:25, on 10/03/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINNT\vsnpt513.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\WINNT\system32\systime.exe
C:\WINNT\system32\Avb.exe
C:\WINNT\system32\cmd32.exe
C:\WINNT\nmstt.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINNT\system32\systime.exe
C:\Program Files\BT Broadband Basic Help\bin\mpbtn.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\BT Broadband Basic Help\bin\mad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\BT Voyager 105 ADSL Modem\BT Broadband.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\Windows\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchcentral.cc/search.php?v=4&aff=2384
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://213.159.117.134/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Windows\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://213.159.117.134/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Windows\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O1 - Hosts: 127.0.0.3 www.greg-tut.com
O1 - Hosts: 127.0.0.3 nylons*xy.com
O1 - Hosts: 127.0.0.3 www.nylons*xy.com
O1 - Hosts: 127.0.0.3 vparivalka.com
O1 - Hosts: 127.0.0.3 www.vparivalka.comtoescrowpay.com
O1 - Hosts: 127.0.0.3 www.awmdabest.com
O1 - Hosts: 127.0.0.3 www.s*xfiles.nu
O1 - Hosts: 127.0.0.3 awmdabest.com
O1 - Hosts: 127.0.0.3 s*xfiles.nu
O1 - Hosts: 127.0.0.3 allforadult.com
O1 - Hosts: 127.0.0.3 www.allforadult.com
O1 - Hosts: 127.0.0.3 www.iframe.biz
O1 - Hosts: 127.0.0.3 iframe.biz
O1 - Hosts: 127.0.0.3 www.newiframe.biz
O1 - Hosts: 127.0.0.3 newiframe.biz
O1 - Hosts: 127.0.0.3 www.vesbiz.biz
O1 - Hosts: 127.0.0.3 vesbiz.biz
O1 - Hosts: 127.0.0.3 www.pizdato.biz
O1 - Hosts: 127.0.0.3 pizdato.biz
O1 - Hosts: 127.0.0.3 www.aaas*xypics.com
O1 - Hosts: 127.0.0.3 aaas*xypics.com
O1 - Hosts: 127.0.0.3 www.virgin-tgp.net
O1 - Hosts: 127.0.0.3 virgin-tgp.net
O1 - Hosts: 127.0.0.3 www.awmcash.biz
O1 - Hosts: 127.0.0.3 awmcash.biz
O1 - Hosts: 127.0.0.3 buldog-stats.com
O1 - Hosts: 127.0.0.3 www.buldog-stats.com
O1 - Hosts: 127.0.0.3 fregat.drocherway.com
O1 - Hosts: 127.0.0.3 ****mania.biz
O1 - Hosts: 127.0.0.3 www.****mania.biz
O1 - Hosts: 127.0.0.3 toolbarpartner.com
O1 - Hosts: 127.0.0.3 www.toolbarpartner.com
O1 - Hosts: 127.0.0.3 www.megap*rnix.com
O1 - Hosts: 127.0.0.3 megap*rnix.com
O1 - Hosts: 127.0.0.3 www.sp2****ed.biz
O1 - Hosts: 127.0.0.3 sp2****ed.biz
O1 - Hosts: 127.0.0.3 greg-tut.com
O1 - Hosts: http://213.159.117.203/dkprogs/hosts.txt
O2 - BHO: DownloadRedirect Class - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - C:\Program Files\iMesh\iMesh5\iMeshBHO.dll
O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\2.bin\S4BAR.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0F9561D0-03B2-44a3-89A6-E95E417CBA25} - C:\WINNT\cerbmod.dll
O2 - BHO: (no name) - {3EEA19E7-7BEA-4D47-B8B7-6A0F2B51B260} - (no file)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: iMesh Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\2.bin\S4BAR.DLL
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SNPT513] C:\WINNT\vsnpt513.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
O4 - HKLM\..\Run: [FireWall] C:\WINNT\system32\_root_svchost.exe
O4 - HKLM\..\Run: [AIMMSG] C:\WINNT\system32\_root_AIM.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SysTime] C:\WINNT\system32\systime.exe
O4 - HKLM\..\Run: [Lvr] C:\WINNT\system32\Avb.exe
O4 - HKLM\..\Run: [ControlPanel] C:\WINNT\system32\cmd32.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [Son] C:\WINNT\Qfk.exe
O4 - HKLM\..\Run: [_Cat2] C:\WINNT\nmstt.exe
O4 - HKLM\..\Run: [Fag] C:\WINNT\Omc.exe
O4 - HKLM\..\Run: [Bjo] C:\WINNT\Ouq.exe
O4 - HKLM\..\Run: [Dkj] C:\WINNT\system32\Qfu.exe
O4 - HKLM\..\Run: [Dcb] C:\WINNT\system32\Cnu.exe
O4 - HKLM\..\Run: [Jdu] C:\WINNT\Oce.exe
O4 - HKLM\..\Run: [Pqg] C:\WINNT\system32\Agm.exe
O4 - HKLM\..\Run: [Jtr] C:\WINNT\system32\Mep.exe
O4 - HKLM\..\Run: [Rst] C:\WINNT\system32\Upt.exe
O4 - HKLM\..\Run: [Tbd] C:\WINNT\system32\Qts.exe
O4 - HKLM\..\Run: [Mdp] C:\WINNT\Ior.exe
O4 - HKLM\..\Run: [Tve] C:\WINNT\Aec.exe
O4 - HKLM\..\Run: [Rsd] C:\WINNT\Aen.exe
O4 - HKLM\..\Run: [Lqd] C:\WINNT\system32\Jub.exe
O4 - HKLM\..\Run: [Mvr] C:\WINNT\Mcg.exe
O4 - HKLM\..\Run: [Fbl] C:\WINNT\Vbm.exe
O4 - HKLM\..\Run: [Gdu] C:\WINNT\Jis.exe
O4 - HKLM\..\Run: [Nki] C:\WINNT\system32\Aso.exe
O4 - HKLM\..\Run: [Qqc] C:\WINNT\system32\Lpg.exe
O4 - HKLM\..\Run: [Fal] C:\WINNT\Ovl.exe
O4 - HKLM\..\Run: [Idr] C:\WINNT\system32\Bia.exe
O4 - HKLM\..\Run: [Umh] C:\WINNT\Dkh.exe
O4 - HKLM\..\Run: [Joh] C:\WINNT\Pic.exe
O4 - HKLM\..\Run: [Ooo] C:\WINNT\system32\Tkq.exe
O4 - HKLM\..\Run: [Jtq] C:\WINNT\system32\Qoe.exe
O4 - HKLM\..\Run: [Rcg] C:\WINNT\system32\Alh.exe
O4 - HKLM\..\Run: [Juv] C:\WINNT\system32\Ljg.exe
O4 - HKLM\..\Run: [Hbp] C:\WINNT\system32\Ctn.exe
O4 - HKLM\..\Run: [Mjc] C:\WINNT\Ouu.exe
O4 - HKLM\..\Run: [Fqg] C:\WINNT\system32\Leg.exe
O4 - HKLM\..\Run: [Nfv] C:\WINNT\system32\Ooe.exe
O4 - HKLM\..\Run: [Pqc] C:\WINNT\system32\Jia.exe
O4 - HKLM\..\Run: [Ocp] C:\WINNT\system32\Mal.exe
O4 - HKLM\..\Run: [Ojf] C:\WINNT\Cpk.exe
O4 - HKLM\..\Run: [Vkf] C:\WINNT\Jmg.exe
O4 - HKLM\..\Run: [Fcn] C:\WINNT\Shu.exe
O4 - HKLM\..\Run: [Jko] C:\WINNT\Kid.exe
O4 - HKLM\..\Run: [Olq] C:\WINNT\Qac.exe
O4 - HKLM\..\Run: [Fid] C:\WINNT\system32\Dfi.exe
O4 - HKLM\..\Run: [Skm] C:\WINNT\Rlq.exe
O4 - HKLM\..\Run: [Ula] C:\WINNT\system32\Hhk.exe
O4 - HKLM\..\Run: [Ker] C:\WINNT\Hol.exe
O4 - HKLM\..\Run: [Rci] C:\WINNT\Pjc.exe
O4 - HKLM\..\Run: [Ado] C:\WINNT\Tul.exe
O4 - HKLM\..\Run: [Act] C:\WINNT\Tpq.exe
O4 - HKLM\..\Run: [Ups] C:\WINNT\Bma.exe
O4 - HKLM\..\Run: [Kap] C:\WINNT\system32\Pjj.exe
O4 - HKLM\..\Run: [Sof] C:\WINNT\system32\Icb.exe
O4 - HKLM\..\Run: [Nbi] C:\WINNT\system32\Nsr.exe
O4 - HKLM\..\Run: [Ckb] C:\WINNT\Gcq.exe
O4 - HKLM\..\Run: [Iqe] C:\WINNT\Evm.exe
O4 - HKLM\..\Run: [Ngi] C:\WINNT\Cti.exe
O4 - HKLM\..\Run: [Eei] C:\WINNT\system32\Uei.exe
O4 - HKLM\..\Run: [Ssp] C:\WINNT\Djk.exe
O4 - HKLM\..\Run: [Fti] C:\WINNT\Idm.exe
O4 - HKLM\..\Run: [Hve] C:\WINNT\Qvl.exe
O4 - HKLM\..\Run: [Fkd] C:\WINNT\system32\Svn.exe
O4 - HKLM\..\Run: [Kgp] C:\WINNT\Nij.exe
O4 - HKLM\..\Run: [Hhr] C:\WINNT\Rse.exe
O4 - HKLM\..\Run: [Hss] C:\WINNT\system32\Acn.exe
O4 - HKLM\..\Run: [Cek] C:\WINNT\Ftk.exe
O4 - HKLM\..\Run: [Qet] C:\WINNT\system32\Tqb.exe
O4 - HKLM\..\Run: [Enh] C:\WINNT\Aah.exe
O4 - HKLM\..\Run: [Rpo] C:\WINNT\system32\Kgj.exe
O4 - HKLM\..\Run: [Hip] C:\WINNT\Muk.exe
O4 - HKLM\..\Run: [Pjv] C:\WINNT\system32\Bmm.exe
O4 - HKLM\..\Run: [Sdn] C:\WINNT\Iff.exe
O4 - HKLM\..\Run: [Via] C:\WINNT\Nfs.exe
O4 - HKLM\..\Run: [Mus] C:\WINNT\system32\Uap.exe
O4 - HKLM\..\Run: [Adj] C:\WINNT\system32\Onb.exe
O4 - HKLM\..\Run: [Pli] C:\WINNT\Ttj.exe
O4 - HKLM\..\Run: [Toq] C:\WINNT\system32\Fbn.exe
O4 - HKLM\..\Run: [Sal] C:\WINNT\Jjf.exe
O4 - HKLM\..\Run: [Ojt] C:\WINNT\system32\Fqu.exe
O4 - HKLM\..\Run: [iSpyKiller] C:\PROGRA~1\ISPYKI~1\iSpyKiller.exe
O4 - HKLM\..\Run: [Tqu] C:\WINNT\system32\Dma.exe
O4 - HKLM\..\Run: [Mqe] C:\WINNT\system32\Ukf.exe
O4 - HKLM\..\Run: [Hdp] C:\WINNT\system32\Ric.exe
O4 - HKLM\..\Run: [Kja] C:\WINNT\system32\Jgb.exe
O4 - HKLM\..\Run: [Flr] C:\WINNT\system32\Bqn.exe
O4 - HKLM\..\Run: [Ebb] C:\WINNT\system32\Lht.exe
O4 - HKLM\..\Run: [Elj] C:\WINNT\system32\Iaf.exe
O4 - HKLM\..\Run: [Hsf] C:\WINNT\Dui.exe
O4 - HKLM\..\Run: [Nii] C:\WINNT\Hff.exe
O4 - HKLM\..\Run: [Ejs] C:\WINNT\system32\Nmd.exe
O4 - HKLM\..\Run: [Klf] C:\WINNT\system32\Sjm.exe
O4 - HKLM\..\Run: [Bov] C:\WINNT\system32\Djl.exe
O4 - HKLM\..\Run: [Nts] C:\WINNT\Rle.exe
O4 - HKLM\..\Run: [Jls] C:\WINNT\Klh.exe
O4 - HKLM\..\Run: [Eng] C:\WINNT\system32\Dpi.exe
O4 - HKLM\..\Run: [Dqg] C:\WINNT\Fuh.exe
O4 - HKLM\..\Run: [Ksc] C:\WINNT\system32\Snt.exe
O4 - HKLM\..\Run: [Vak] C:\WINNT\Qlp.exe
O4 - HKLM\..\Run: [Qeo] C:\WINNT\system32\Qbl.exe
O4 - HKLM\..\Run: [Jlv] C:\WINNT\Lnc.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [SysTime] C:\WINNT\system32\systime.exe
O4 - HKCU\..\Run: [Lvr] C:\WINNT\system32\Avb.exe
O4 - HKCU\..\Run: [Son] C:\WINNT\Qfk.exe
O4 - HKCU\..\Run: [Fag] C:\WINNT\Omc.exe
O4 - HKCU\..\Run: [Bjo] C:\WINNT\Ouq.exe
O4 - HKCU\..\Run: [Dkj] C:\WINNT\system32\Qfu.exe
O4 - HKCU\..\Run: [Dcb] C:\WINNT\system32\Cnu.exe
O4 - HKCU\..\Run: [Jdu] C:\WINNT\Oce.exe
O4 - HKCU\..\Run: [Pqg] C:\WINNT\system32\Agm.exe
O4 - HKCU\..\Run: [Jtr] C:\WINNT\system32\Mep.exe
O4 - HKCU\..\Run: [Rst] C:\WINNT\system32\Upt.exe
O4 - HKCU\..\Run: [Tbd] C:\WINNT\system32\Qts.exe
O4 - HKCU\..\Run: [Mdp] C:\WINNT\Ior.exe
O4 - HKCU\..\Run: [Tve] C:\WINNT\Aec.exe
O4 - HKCU\..\Run: [Rsd] C:\WINNT\Aen.exe
O4 - HKCU\..\Run: [Lqd] C:\WINNT\system32\Jub.exe
O4 - HKCU\..\Run: [Mvr] C:\WINNT\Mcg.exe
O4 - HKCU\..\Run: [Fbl] C:\WINNT\Vbm.exe
O4 - HKCU\..\Run: [Gdu] C:\WINNT\Jis.exe
O4 - HKCU\..\Run: [Nki] C:\WINNT\system32\Aso.exe
O4 - HKCU\..\Run: [Qqc] C:\WINNT\system32\Lpg.exe
O4 - HKCU\..\Run: [Fal] C:\WINNT\Ovl.exe
O4 - HKCU\..\Run: [Idr] C:\WINNT\system32\Bia.exe
O4 - HKCU\..\Run: [Umh] C:\WINNT\Dkh.exe
O4 - HKCU\..\Run: [Joh] C:\WINNT\Pic.exe
O4 - HKCU\..\Run: [Ooo] C:\WINNT\system32\Tkq.exe
O4 - HKCU\..\Run: [Jtq] C:\WINNT\system32\Qoe.exe
O4 - HKCU\..\Run: [Rcg] C:\WINNT\system32\Alh.exe
O4 - HKCU\..\Run: [Juv] C:\WINNT\system32\Ljg.exe
O4 - HKCU\..\Run: [Hbp] C:\WINNT\system32\Ctn.exe
O4 - HKCU\..\Run: [Mjc] C:\WINNT\Ouu.exe
O4 - HKCU\..\Run: [Fqg] C:\WINNT\system32\Leg.exe
O4 - HKCU\..\Run: [Nfv] C:\WINNT\system32\Ooe.exe
O4 - HKCU\..\Run: [Pqc] C:\WINNT\system32\Jia.exe
O4 - HKCU\..\Run: [Ocp] C:\WINNT\system32\Mal.exe
O4 - HKCU\..\Run: [Ojf] C:\WINNT\Cpk.exe
O4 - HKCU\..\Run: [Vkf] C:\WINNT\Jmg.exe
O4 - HKCU\..\Run: [Fcn] C:\WINNT\Shu.exe
O4 - HKCU\..\Run: [Jko] C:\WINNT\Kid.exe
O4 - HKCU\..\Run: [Olq] C:\WINNT\Qac.exe
O4 - HKCU\..\Run: [Fid] C:\WINNT\system32\Dfi.exe
O4 - HKCU\..\Run: [Skm] C:\WINNT\Rlq.exe
O4 - HKCU\..\Run: [Ula] C:\WINNT\system32\Hhk.exe
O4 - HKCU\..\Run: [Ker] C:\WINNT\Hol.exe
O4 - HKCU\..\Run: [Rci] C:\WINNT\Pjc.exe
O4 - HKCU\..\Run: [Ado] C:\WINNT\Tul.exe
O4 - HKCU\..\Run: [Act] C:\WINNT\Tpq.exe
O4 - HKCU\..\Run: [Ups] C:\WINNT\Bma.exe
O4 - HKCU\..\Run: [Kap] C:\WINNT\system32\Pjj.exe
O4 - HKCU\..\Run: [Sof] C:\WINNT\system32\Icb.exe
O4 - HKCU\..\Run: [Nbi] C:\WINNT\system32\Nsr.exe
O4 - HKCU\..\Run: [Ckb] C:\WINNT\Gcq.exe
O4 - HKCU\..\Run: [Iqe] C:\WINNT\Evm.exe
O4 - HKCU\..\Run: [Ngi] C:\WINNT\Cti.exe
O4 - HKCU\..\Run: [Eei] C:\WINNT\system32\Uei.exe
O4 - HKCU\..\Run: [Ssp] C:\WINNT\Djk.exe
O4 - HKCU\..\Run: [Fti] C:\WINNT\Idm.exe
O4 - HKCU\..\Run: [Hve] C:\WINNT\Qvl.exe
O4 - HKCU\..\Run: [Fkd] C:\WINNT\system32\Svn.exe
O4 - HKCU\..\Run: [Kgp] C:\WINNT\Nij.exe
O4 - HKCU\..\Run: [Hhr] C:\WINNT\Rse.exe
O4 - HKCU\..\Run: [Hss] C:\WINNT\system32\Acn.exe
O4 - HKCU\..\Run: [Cek] C:\WINNT\Ftk.exe
O4 - HKCU\..\Run: [Qet] C:\WINNT\system32\Tqb.exe
O4 - HKCU\..\Run: [Enh] C:\WINNT\Aah.exe
O4 - HKCU\..\Run: [Rpo] C:\WINNT\system32\Kgj.exe
O4 - HKCU\..\Run: [Hip] C:\WINNT\Muk.exe
O4 - HKCU\..\Run: [Pjv] C:\WINNT\system32\Bmm.exe
O4 - HKCU\..\Run: [Sdn] C:\WINNT\Iff.exe
O4 - HKCU\..\Run: [Via] C:\WINNT\Nfs.exe
O4 - HKCU\..\Run: [Mus] C:\WINNT\system32\Uap.exe
O4 - HKCU\..\Run: [Adj] C:\WINNT\system32\Onb.exe
O4 - HKCU\..\Run: [Pli] C:\WINNT\Ttj.exe
O4 - HKCU\..\Run: [Toq] C:\WINNT\system32\Fbn.exe
O4 - HKCU\..\Run: [Sal] C:\WINNT\Jjf.exe
O4 - HKCU\..\Run: [Ojt] C:\WINNT\system32\Fqu.exe
O4 - HKCU\..\Run: [Tqu] C:\WINNT\system32\Dma.exe
O4 - HKCU\..\Run: [Mqe] C:\WINNT\system32\Ukf.exe
O4 - HKCU\..\Run: [Hdp] C:\WINNT\system32\Ric.exe
O4 - HKCU\..\Run: [Kja] C:\WINNT\system32\Jgb.exe
O4 - HKCU\..\Run: [Flr] C:\WINNT\system32\Bqn.exe
O4 - HKCU\..\Run: [Ebb] C:\WINNT\system32\Lht.exe
O4 - HKCU\..\Run: [Elj] C:\WINNT\system32\Iaf.exe
O4 - HKCU\..\Run: [Hsf] C:\WINNT\Dui.exe
O4 - HKCU\..\Run: [Nii] C:\WINNT\Hff.exe
O4 - HKCU\..\Run: [Ejs] C:\WINNT\system32\Nmd.exe
O4 - HKCU\..\Run: [Klf] C:\WINNT\system32\Sjm.exe
O4 - HKCU\..\Run: [Bov] C:\WINNT\system32\Djl.exe
O4 - HKCU\..\Run: [Nts] C:\WINNT\Rle.exe
O4 - HKCU\..\Run: [Jls] C:\WINNT\Klh.exe
O4 - HKCU\..\Run: [Eng] C:\WINNT\system32\Dpi.exe
O4 - HKCU\..\Run: [Dqg] C:\WINNT\Fuh.exe
O4 - HKCU\..\Run: [Ksc] C:\WINNT\system32\Snt.exe
O4 - HKCU\..\Run: [Vak] C:\WINNT\Qlp.exe
O4 - HKCU\..\Run: [Qeo] C:\WINNT\system32\Qbl.exe
O4 - HKCU\..\Run: [Jlv] C:\WINNT\Lnc.exe
O4 - Global Startup: BT Broadband Basic Help.lnk = C:\Program Files\BT Broadband Basic Help\bin\matcli.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O10 - Broken Internet access because of LSP provider 'xfire_lsp_9717.dll' missing
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.xxxtoolbar.com
O15 - Trusted Zone: *.ysbweb.com
O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.iframedollars.biz (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted Zone: *.ysbweb.com (HKLM)
O15 - Trusted IP range: 67.19.178.84
O15 - Trusted IP range: 67.19.178.84 (HKLM)
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - http://www.uclan.ac.uk/other/iss/remote/wficat.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www5.incredimail.com/contents/setup/downloader_sp1/imloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{960E7EFB-2404-47F7-8029-AE9BF21045D2}: NameServer = 194.74.65.68 194.72.9.38
O18 - Filter: text/html - {A68AD802-6EA6-4EF6-BC25-98ABF9F32F2B} - (no file)
O18 - Filter: text/plain - {A68AD802-6EA6-4EF6-BC25-98ABF9F32F2B} - (no file)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINNT\system32\ZoneLabs\vsmon.exe

Logged

 
Pancake
Global Moderator
Hero Member
*****

Karma: +78/-0
Offline Offline

Gender: Male
Posts: 3915


Bookmark and Share

View Profile
« Reply #1 on: March 11, 2005, 05:11:33 AM »

Hi and Welcome
You have one heck of a mess here..so lets see if we can clean it up.

It may help you if you print out or copy this page for easy reference.. Make sure to work through the fixes in the exact order its listed. Please Keep your browser and all open programs closed (except firewalls and antivirus) when you are carrying out the fixes.

Please do not run HJT on the desktop or a temp folder.Its best run in a dedicated folder of its own.

Turn off System Restore instructions (WinXP)
Rightclick My Computer | Properties | System Restore | check
« Last Edit: March 11, 2005, 05:13:43 AM by Pancake » Logged

An Australian Member of

EDDY
Pages: [1] Go Up Print 
 
Jump to:  

Powered by MySQL Powered by PHP

Powered by SMF 1.1.21 | SMF © 2015, Simple Machines

Valid XHTML 1.0! Valid CSS!

Disclaimer
This site is NOT responsible for any damage that the information on this site may cause to your system. Everything you try, whether inspired by the response given from this site or not, is entirely at your own risk. All product names and company names used herein are for identification purpose only and may be trademarks or registered trademarks of their respective owners. We are in no way affiliated or representing any of the companies on this site unless specified.
Back to Top
Stop Spam Harvesters, Join Project Honey Pot Fight Back Against Spammers! Get Firefox! Get Thunderbird! View Sylvain Amyots profile on LinkedIn
Back to Top
Google visited last this page January 08, 2018, 10:05:06 AM