MyTechSupport.ca :: Your Computer Technical Resource Headquarters! MyTechSupport.ca :: Your Computer Technical Resource Headquarters!
HOME FORUMS RESOURCES & TOOLS ARTICLES ONLINE STORE ABOUT US
Computer Support Forums arrow Internet & Network Support arrow Security & Viruses arrow Topic: Need some expert help here.
June 27, 2019, 03:31:41 AM
 

Home Forum Rules Help Search Mobile Version Login Register

Welcome, Guest. Please login or register.
Did you miss your activation email?
June 27, 2019, 03:31:41 AM

Login with username, password and session length
 
News
New  Looking for cheap hardware and/or software?
Visit our new Online Store where you will be able to purchase from a reputable vendor by country.
  0 Members and 1 Guest are viewing this topic.
Pages: [1] Go Down Print
Author Topic: Need some expert help here.  (Read 1705 times)
Hadrian
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 8


Bookmark and Share

View Profile
« on: April 27, 2005, 07:22:38 PM »

PLEASE SUPPLY RELEVANT INFORMATION:
Operating System Version:
Problem Application Name & Version:
Problem Hardware Make & Model:
Error Messages:



I have tried to clean this pc up as much as I could, but I couldnt get it to run very well.  I have ran kaspersky's online antivurs and erased 73 virsues.  I have also ran adaware and spybot S&D, which also erased many problems.  However, I still can not change the homepage, and there are about a million popups while connected or not connected.  Here is my highjack this log, and your help is greatly appreciated.


Logfile of HijackThis v1.99.1
Scan saved at 3:37:38 PM, on 4/26/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\HPQ\One-Touch\OneTouch.EXE
C:\Program Files\eDonkey2000\edonkey2000.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINDOWS\System32\?hkdsk.exe
C:\wp.exe
C:\windows\gtlflkb.exe
C:\windows\yvnvrfk.exe
C:\windows\yvnvrfk.exe
C:\windows\yvnvrfk.exe
C:\windows\yvnvrfk.exe
C:\windows\yvnvrfk.exe
C:\windows\yvnvrfk.exe
C:\windows\yvnvrfk.exe
C:\windows\sacxjig.exe
C:\windows\sacxjig.exe
C:\windows\pqyuhsc.exe
C:\windows\pqyuhsc.exe
C:\windows\xvvvdjn.exe
C:\Documents and Settings\Abbey Castonia\Application Data\elat.exe
C:\windows\jecvyof.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Documents and Settings\Abbey Castonia\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://w-find.com/index.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus8l.hpwis.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus8l.hpwis.com/
R3 - URLSearchHook: US Class - {1FFED2CB-FC98-49f8-B3D0-678D03350F1E} - C:\WINDOWS\mscore.dll
O2 - BHO: DLMaxObj Class - {00000000-59D4-4008-9058-080011001200} - C:\WINDOWS\dlmax.dll
O2 - BHO: FlashEnhancer Extender - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - c:\Program Files\Flen\flen.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {C247C1A2-2A43-7790-1AFD-71E29F222CC6} - C:\WINDOWS\System32\dfx.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [eDonkey2000] "C:\Program Files\eDonkey2000\edonkey2000.exe" -t
O4 - HKLM\..\Run: [BS Player] BSPLAYER.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [Rxagik] C:\WINDOWS\Meruoq.exe
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdtl.exe
O4 - HKLM\..\Run: [Ydftkfp] C:\WINDOWS\Qtstel.exe
O4 - HKLM\..\Run: [pgtaff] C:\WINDOWS\pgtaff.exe
O4 - HKLM\..\Run: [USB controller] "C:\WINDOWS\TEMP\svcmm32.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [aqadcup] C:\WINDOWS\aqadcup.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [Tb] C:\windows\system32\Tb.exe
O4 - HKLM\..\Run: [vypk.exe] c:\windows\system32\vypk.exe
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\npvnpa.exe
O4 - HKLM\..\Run: [uhmt] C:\WINDOWS\uhmt.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\System32\picsvr\picsvr.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe
O4 - HKLM\..\Run: [DI2] "C:\DOCUME~1\ABBEYC~1\LOCALS~1\Temp\27.exe\27.exe"
O4 - HKLM\..\Run: [FlenCPY] "C:\Program Files\Common Files\Java\flencpy.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [umdmxfrm] C:\WINDOWS\System32\umdmxfrm.exe
O4 - HKCU\..\Run: [ZAx6RQcEh] dmils.exe
O4 - HKCU\..\Run: [Cbghbmht] C:\WINDOWS\System32\?hkdsk.exe
O4 - HKCU\..\Run: [solnmwr] c:\windows\gtlflkb.exe
O4 - HKCU\..\Run: [WindowsFY] c:\wp.exe
O4 - HKCU\..\Run: [yfyelge] c:\windows\gtlflkb.exe
O4 - HKCU\..\Run: [gjfghbm] c:\windows\urxeifo.exe
O4 - HKCU\..\Run: [fsusd] C:\WINDOWS\System32\fsusd.exe
O4 - HKCU\..\Run: [niuyqlv] c:\windows\urxeifo.exe
O4 - HKCU\..\Run: [dvdeqhl] c:\windows\yvnvrfk.exe
O4 - HKCU\..\Run: [ytlnaqg] c:\windows\yvnvrfk.exe
O4 - HKCU\..\Run: [kpukpos] c:\windows\yvnvrfk.exe
O4 - HKCU\..\Run: [hshtspn] c:\windows\yvnvrfk.exe
O4 - HKCU\..\Run: [fbtqlvf] c:\windows\yvnvrfk.exe
O4 - HKCU\..\Run: [tsccmxh] c:\windows\yvnvrfk.exe
O4 - HKCU\..\Run: [fmunypf] c:\windows\yvnvrfk.exe
O4 - HKCU\..\Run: [idbvqoa] c:\windows\yvnvrfk.exe
O4 - HKCU\..\Run: [kahbkfg] c:\windows\yvnvrfk.exe
O4 - HKCU\..\Run: [ivwdcbt] c:\windows\yvnvrfk.exe
O4 - HKCU\..\Run: [fmgtbir] c:\windows\yvnvrfk.exe
O4 - HKCU\..\Run: [gdplmcj] c:\windows\yvnvrfk.exe
O4 - HKCU\..\Run: [iojeeld] c:\windows\yvnvrfk.exe
O4 - HKCU\..\Run: [bygjoyq] c:\windows\yvnvrfk.exe
O4 - HKCU\..\Run: [femprtg] c:\windows\sacxjig.exe
O4 - HKCU\..\Run: [wutaoja] c:\windows\sacxjig.exe
O4 - HKCU\..\Run: [rogeqtq] c:\windows\pqyuhsc.exe
O4 - HKCU\..\Run: [fmwnlsl] c:\windows\pqyuhsc.exe
O4 - HKCU\..\Run: [qqbjywm] c:\windows\pqyuhsc.exe
O4 - HKCU\..\Run: [awgjjnc] c:\windows\pqyuhsc.exe
O4 - HKCU\..\Run: [tugfmwf] c:\windows\paaemsq.exe
O4 - HKCU\..\Run: [oaclyrd] c:\windows\xvvvdjn.exe
O4 - HKCU\..\Run: [eawnkpx] c:\windows\xvvvdjn.exe
O4 - HKCU\..\Run: [peamchx] c:\windows\xvvvdjn.exe
O4 - HKCU\..\Run: [qcbheti] c:\windows\xvvvdjn.exe
O4 - HKCU\..\Run: [vjrheag] c:\windows\ilrqmyg.exe
O4 - HKCU\..\Run: [Lerm] C:\Documents and Settings\Abbey Castonia\Application Data\elat.exe
O4 - HKCU\..\Run: [tdxnxtu] c:\windows\jecvyof.exe
O4 - HKCU\..\Run: [pdnyeyh] c:\windows\jecvyof.exe
O4 - HKCU\..\Run: [ckvfbks] c:\windows\jecvyof.exe
O4 - HKCU\..\Run: [ynchfsx] c:\windows\jecvyof.exe
O4 - HKCU\..\Run: [oxabail] c:\windows\kpigfhr.exe
O4 - HKCU\..\Run: [vtjhuxx] c:\windows\chwnfvg.exe
O4 - HKCU\..\Run: [dpsnpol] c:\windows\tamvgju.exe
O4 - HKCU\..\Run: [ktelelw] c:\windows\vvwybmk.exe
O4 - HKCU\..\Run: [rtbajsv] c:\windows\sqjfaha.exe
O4 - HKCU\..\Run: [jyrtoci] c:\windows\bxuxytk.exe
O4 - HKCU\..\Run: [hcrufrx] c:\windows\rwsyftc.exe
O4 - HKCU\..\Run: [ylvxtrw] c:\windows\fhbocnn.exe
O4 - HKCU\..\Run: [ghfeoik] c:\windows\wyqwcbd.exe
O4 - HKCU\..\Run: [siktdyr] c:\windows\kpigfhr.exe
O4 - HKCU\..\Run: [mjjlpyv] c:\windows\chwnfvg.exe
O4 - HKCU\..\Run: [gjhccaa] c:\windows\tamvgju.exe
O4 - HKCU\..\Run: [ebldilv] c:\windows\bxuxytk.exe
O4 - HKCU\..\Run: [lebqsqy] c:\windows\vvwybmk.exe
O4 - HKCU\..\Run: [xcktuma] c:\windows\sqjfaha.exe
O4 - HKCU\..\Run: [aildqxn] c:\windows\rwsyftc.exe
O4 - HKCU\..\Run: [sfwpfsl] c:\windows\wyqwcbd.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {BE62A02F-DBE4-42C2-A74D-76FF401D9054} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {BE62A02F-DBE4-42C2-A74D-76FF401D9054} - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\lspak.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://qus8l.hpwis.com
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan.cab
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50203/QDow_AS2.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Loading Outpost Connections (KDE) - Unknown owner - C:\WINDOWS\System32\cmdtel.exe (file missing)
O23 - Service: Debug oupost relations (LAGOS) - Unknown owner - C:\WINDOWS\System32\ahtun.exe (file missing)
Logged

 
Geekgirl
Global Moderator
Hero Member
*****

Karma: +25/-1
Offline Offline

Gender: Female
Posts: 3175



Bookmark and Share

View Profile
« Reply #1 on: April 28, 2005, 04:35:18 PM »

Hello and Welcome to MyTechSupport.ca

You have alot of work ahead of you, take your time plz. Please do not skip the scanning for virus section, you are very riddled with viruses.

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are following the procedures below.

You have placed HJT in a Temporary location. Please move to a proper location before doing the fix.
(Always create a Folder for HiJackThis anywhere but your Temp/Temporary Internet Folders or Desktop. A good place to make a folder would be in My Documents, as this is where it will save the backup files needed if there's a problem.)

Download / Install / Update / and Run:
Adaware SE check for any updates before running it.
Get the plug-in for fixing VX2 variants. You can download it at this SITE
 To run this tool, install to the hard drive, then open Ad-aware->Add-ons and select VX2 Cleaner. Then click Run Tool and OK to start it. If it's clean, it will say Status System Clean. Otherwise, you will have to click on the Clean button to remove the VX2 infection.


Scan your pc with one of these free online scanners:
Panda ActiveScan
RAV AntiVirus
Housecall.  Be sure to put a check the box beside AutoClean.

The Temp folders should be cleaned out periodically as installation programs and hijack programs leave a lot of junk there.  Download CleanUp! (Alternate Link if main link don't work) and install it. You will use this later.

Download WinsockFix and unzip it. Then double-click on it to run it.

Go to My Computer >Tools >Folder Options >View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing / visible. Uncheck the Hide protected operating system files option.

Reboot your system in Safe Mode (By repeatedly tapping the F8 key until the menu appears).

Go into Hijack This->Config->Misc. Tools->Open process manager. Select the following and click Kill process for each one (You must kill them one at a time).

C:\Program Files\eDonkey2000\edonkey2000.exe
C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINDOWS\System32\?hkdsk.exe
C:\wp.exe
C:\windows\gtlflkb.exe
C:\windows\yvnvrfk.exe
C:\windows\yvnvrfk.exe
C:\windows\yvnvrfk.exe
C:\windows\yvnvrfk.exe
C:\windows\yvnvrfk.exe
C:\windows\yvnvrfk.exe
C:\windows\yvnvrfk.exe
C:\windows\sacxjig.exe
C:\windows\sacxjig.exe
C:\windows\pqyuhsc.exe
C:\windows\pqyuhsc.exe
C:\windows\xvvvdjn.exe
C:\Documents and Settings\Abbey Castonia\Application Data\elat.exe
C:\windows\jecvyof.exe



Click > Start > Control Panel > Add / Remove Programs and uninstall the following programs:

eDonkey2000 <---------I see you have P2P software installed on your machine (i.e.). We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation. I will make recommendations below for removal, which you can choose to ignore, where this P2P application is involved. I
Logged




Girlz Rule ...Boyz Drool
____________________________
ALWAYS BACKUP YOUR REGISTRY BEFORE EDITING
Hadrian
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 8


Bookmark and Share

View Profile
« Reply #2 on: May 02, 2005, 09:01:54 PM »

Hello Geek Girl, Thank you so much for your reply, I really appreciate the time you have put into this.  I have been trying to do eveything that you told me to, however, I now can not get any programs to run.  For example, I click on adaware to install it or run it, and nothing happens.  I can use the internet and dl things no problem, but when it comes to things on the pc, I can not open or run them.  Also, when I try to use notepad, it says windows can not find notepad.exe, so I cant even use that.  I was wondering if you have any ideas on what I can do besides reformating.  Thanks again for all the time you have already put into this.  Also, I was wondering if by going out of oreder in the things you told me to do, if that would maybe free some stuff up to get some programs working?
Logged

 
Geekgirl
Global Moderator
Hero Member
*****

Karma: +25/-1
Offline Offline

Gender: Female
Posts: 3175



Bookmark and Share

View Profile
« Reply #3 on: May 02, 2005, 10:01:06 PM »

Can you at least open HJT and do the fixes?
Logged




Girlz Rule ...Boyz Drool
____________________________
ALWAYS BACKUP YOUR REGISTRY BEFORE EDITING
Hadrian
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 8


Bookmark and Share

View Profile
« Reply #4 on: May 02, 2005, 10:31:11 PM »

Well, some good news, the programs are now running, so I am now removing everything, I will submit another HJT log when I go thru everything.  Thanks a lot for the quick response, and I will submit this next log as soon as possible.
Logged

 
Hadrian
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 8


Bookmark and Share

View Profile
« Reply #5 on: May 03, 2005, 01:26:57 AM »

Ok Geek Girl, I have done everything you asked, and it seemed to clear up some things, however, I still get a win min error on shutdown.  Thank you so much for all your help w/ this.  My new HJT log is:

Logfile of HijackThis v1.99.1
Scan saved at 9:13:45 PM, on 5/2/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\HPQ\One-Touch\OneTouch.EXE
C:\Program Files\AIM\aim.exe
C:\windows\ihxbysq.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
c:\windows\system32\ucklukb.exe
C:\Documents and Settings\Abbey Castonia\My Documents\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus8l.hpwis.com/
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll
O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O2 - BHO: Loader Class - {2E246FAE-8420-11D9-870D-000C2917DE7F} - C:\WINDOWS\SYSTEM\Loader.dll
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {C247C1A2-2A43-7790-1AFD-71E29F222CC6} - C:\WINDOWS\System32\dfx.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [BS Player] BSPLAYER.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [lbuafvk] c:\windows\system32\ucklukb.exe
O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [vcbtlvw] c:\windows\kpigfhr.exe
O4 - HKCU\..\Run: [ijdlqhl] c:\windows\chwnfvg.exe
O4 - HKCU\..\Run: [fjuvrqp] c:\windows\bxuxytk.exe
O4 - HKCU\..\Run: [uqedwtb] c:\windows\tamvgju.exe
O4 - HKCU\..\Run: [rqwmwde] c:\windows\sqjfaha.exe
O4 - HKCU\..\Run: [ofhmdvp] c:\windows\vvwybmk.exe
O4 - HKCU\..\Run: [jvydgki] c:\windows\rwsyftc.exe
O4 - HKCU\..\Run: [aammtfi] c:\windows\wyqwcbd.exe
O4 - HKCU\..\Run: [dmgxicn] c:\windows\kpigfhr.exe
O4 - HKCU\..\Run: [yctkctw] c:\windows\chwnfvg.exe
O4 - HKCU\..\Run: [fflyoei] c:\windows\bxuxytk.exe
O4 - HKCU\..\Run: [uqiwvlg] c:\windows\tamvgju.exe
O4 - HKCU\..\Run: [atyliur] c:\windows\sqjfaha.exe
O4 - HKCU\..\Run: [afglxus] c:\windows\vvwybmk.exe
O4 - HKCU\..\Run: [hxrkolf] c:\windows\rwsyftc.exe
O4 - HKCU\..\Run: [mxwxfut] c:\windows\wyqwcbd.exe
O4 - HKCU\..\Run: [mgvsuep] c:\windows\kpigfhr.exe
O4 - HKCU\..\Run: [bnmbrdp] c:\windows\chwnfvg.exe
O4 - HKCU\..\Run: [dyyjtxn] c:\windows\bxuxytk.exe
O4 - HKCU\..\Run: [quekpcp] c:\windows\tamvgju.exe
O4 - HKCU\..\Run: [sgqsqwn] c:\windows\sqjfaha.exe
O4 - HKCU\..\Run: [eaovaqn] c:\windows\vvwybmk.exe
O4 - HKCU\..\Run: [xxejxfo] c:\windows\rwsyftc.exe
O4 - HKCU\..\Run: [wwowrno] c:\windows\wyqwcbd.exe
O4 - HKCU\..\Run: [gsguogo] c:\windows\kpigfhr.exe
O4 - HKCU\..\Run: [casgkuc] c:\windows\chwnfvg.exe
O4 - HKCU\..\Run: [opkvgvl] c:\windows\bxuxytk.exe
O4 - HKCU\..\Run: [whfrgko] c:\windows\tamvgju.exe
O4 - HKCU\..\Run: [kwwhcky] c:\windows\sqjfaha.exe
O4 - HKCU\..\Run: [hpvxfwa] c:\windows\vvwybmk.exe
O4 - HKCU\..\Run: [llsjrqb] c:\windows\rwsyftc.exe
O4 - HKCU\..\Run: [slhgtpn] c:\windows\wyqwcbd.exe
O4 - HKCU\..\Run: [cnwimeu] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [cgrlnah] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [ncvgdvu] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [ahiylrx] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [wiokwua] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [tuorqdo] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [opbcloo] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [rjteoud] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [iwvfdup] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [gtxyruq] c:\windows\ymxsgiu.exe
O4 - HKCU\..\Run: [wnpivtv] c:\windows\ymxsgiu.exe
O4 - HKCU\..\Run: [eyjxswt] c:\windows\ymxsgiu.exe
O4 - HKCU\..\Run: [awyxjnf] c:\windows\ymxsgiu.exe
O4 - HKCU\..\Run: [ugoicll] c:\windows\ahhtajr.exe
O4 - HKCU\..\Run: [uxvfmiq] c:\windows\ahhtajr.exe
O4 - HKCU\..\Run: [bmreygq] c:\windows\ahhtajr.exe
O4 - HKCU\..\Run: [ggvwsdm] c:\windows\ahhtajr.exe
O4 - HKCU\..\Run: [xvsciux] c:\windows\ahhtajr.exe
O4 - HKCU\..\Run: [nnykskg] c:\windows\kooaulx.exe
O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {BE62A02F-DBE4-42C2-A74D-76FF401D9054} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {BE62A02F-DBE4-42C2-A74D-76FF401D9054} - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\lspak.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://qus8l.hpwis.com
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan.cab
O16 - DPF: {2100CDAA-8115-3E0A-82F6-3F4D10B91D95} - http://69.50.182.94/1/rdgUS1882.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Loading Outpost Connections (KDE) - Unknown owner - C:\WINDOWS\System32\cmdtel.exe (file missing)
O23 - Service: Debug oupost relations (LAGOS) - Unknown owner - C:\WINDOWS\System32\ahtun.exe (file missing)
O23 - Service: System Startup Service  (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe


« Last Edit: May 03, 2005, 01:31:56 AM by Hadrian » Logged

 
Geekgirl
Global Moderator
Hero Member
*****

Karma: +25/-1
Offline Offline

Gender: Female
Posts: 3175



Bookmark and Share

View Profile
« Reply #6 on: May 03, 2005, 02:04:32 AM »

Hmmm ok lets try this again.......

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are following the procedures below.

Download Ewido Security Suite
Update it
« Last Edit: May 03, 2005, 02:06:29 AM by Geekgirl » Logged




Girlz Rule ...Boyz Drool
____________________________
ALWAYS BACKUP YOUR REGISTRY BEFORE EDITING
Hadrian
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 8


Bookmark and Share

View Profile
« Reply #7 on: May 05, 2005, 04:24:59 PM »

I dont know what happened, but when I got to the HJT part, the log has changed itself and it now appears this way:

Logfile of HijackThis v1.99.1
Scan saved at 12:19:59 PM, on 5/5/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\HPQ\One-Touch\OneTouch.EXE
C:\Program Files\AIM\aim.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Abbey Castonia\My Documents\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://w-find.com/index.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://w-find.com/index.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus8l.hpwis.com/
O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O2 - BHO: Loader Class - {2E246FAE-8420-11D9-870D-000C2917DE7F} - C:\WINDOWS\SYSTEM\Loader.dll (file missing)
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {C247C1A2-2A43-7790-1AFD-71E29F222CC6} - C:\WINDOWS\System32\dfx.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [dioaxt] c:\windows\system32\mrhndc.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [vcbtlvw] c:\windows\kpigfhr.exe
O4 - HKCU\..\Run: [ijdlqhl] c:\windows\chwnfvg.exe
O4 - HKCU\..\Run: [fjuvrqp] c:\windows\bxuxytk.exe
O4 - HKCU\..\Run: [uqedwtb] c:\windows\tamvgju.exe
O4 - HKCU\..\Run: [rqwmwde] c:\windows\sqjfaha.exe
O4 - HKCU\..\Run: [ofhmdvp] c:\windows\vvwybmk.exe
O4 - HKCU\..\Run: [jvydgki] c:\windows\rwsyftc.exe
O4 - HKCU\..\Run: [aammtfi] c:\windows\wyqwcbd.exe
O4 - HKCU\..\Run: [dmgxicn] c:\windows\kpigfhr.exe
O4 - HKCU\..\Run: [yctkctw] c:\windows\chwnfvg.exe
O4 - HKCU\..\Run: [fflyoei] c:\windows\bxuxytk.exe
O4 - HKCU\..\Run: [uqiwvlg] c:\windows\tamvgju.exe
O4 - HKCU\..\Run: [atyliur] c:\windows\sqjfaha.exe
O4 - HKCU\..\Run: [afglxus] c:\windows\vvwybmk.exe
O4 - HKCU\..\Run: [hxrkolf] c:\windows\rwsyftc.exe
O4 - HKCU\..\Run: [mxwxfut] c:\windows\wyqwcbd.exe
O4 - HKCU\..\Run: [mgvsuep] c:\windows\kpigfhr.exe
O4 - HKCU\..\Run: [bnmbrdp] c:\windows\chwnfvg.exe
O4 - HKCU\..\Run: [dyyjtxn] c:\windows\bxuxytk.exe
O4 - HKCU\..\Run: [quekpcp] c:\windows\tamvgju.exe
O4 - HKCU\..\Run: [sgqsqwn] c:\windows\sqjfaha.exe
O4 - HKCU\..\Run: [eaovaqn] c:\windows\vvwybmk.exe
O4 - HKCU\..\Run: [xxejxfo] c:\windows\rwsyftc.exe
O4 - HKCU\..\Run: [wwowrno] c:\windows\wyqwcbd.exe
O4 - HKCU\..\Run: [gsguogo] c:\windows\kpigfhr.exe
O4 - HKCU\..\Run: [casgkuc] c:\windows\chwnfvg.exe
O4 - HKCU\..\Run: [opkvgvl] c:\windows\bxuxytk.exe
O4 - HKCU\..\Run: [whfrgko] c:\windows\tamvgju.exe
O4 - HKCU\..\Run: [kwwhcky] c:\windows\sqjfaha.exe
O4 - HKCU\..\Run: [hpvxfwa] c:\windows\vvwybmk.exe
O4 - HKCU\..\Run: [llsjrqb] c:\windows\rwsyftc.exe
O4 - HKCU\..\Run: [slhgtpn] c:\windows\wyqwcbd.exe
O4 - HKCU\..\Run: [cnwimeu] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [cgrlnah] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [ncvgdvu] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [ahiylrx] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [wiokwua] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [tuorqdo] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [opbcloo] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [rjteoud] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [iwvfdup] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [gtxyruq] c:\windows\ymxsgiu.exe
O4 - HKCU\..\Run: [wnpivtv] c:\windows\ymxsgiu.exe
O4 - HKCU\..\Run: [eyjxswt] c:\windows\ymxsgiu.exe
O4 - HKCU\..\Run: [awyxjnf] c:\windows\ymxsgiu.exe
O4 - HKCU\..\Run: [ugoicll] c:\windows\ahhtajr.exe
O4 - HKCU\..\Run: [uxvfmiq] c:\windows\ahhtajr.exe
O4 - HKCU\..\Run: [bmreygq] c:\windows\ahhtajr.exe
O4 - HKCU\..\Run: [ggvwsdm] c:\windows\ahhtajr.exe
O4 - HKCU\..\Run: [xvsciux] c:\windows\ahhtajr.exe
O4 - HKCU\..\Run: [nnykskg] c:\windows\kooaulx.exe
O4 - HKCU\..\Run: [ntvyfwc] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [bqsteqr] c:\windows\cbxwlyr.exe
O4 - HKCU\..\Run: [tqmpifn] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [clpgmlb] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [ipyxidy] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [wxobwor] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [adbcksv] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [kcjnmvg] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [tftkfcg] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [plmubnn] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [kwicfkp] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [xujmmio] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [nmdnbxr] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [njxabet] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [frgcnfq] c:\windows\lfyqufn.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {BE62A02F-DBE4-42C2-A74D-76FF401D9054} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {BE62A02F-DBE4-42C2-A74D-76FF401D9054} - (no file) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://qus8l.hpwis.com
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan.cab
O16 - DPF: {2100CDAA-8115-3E0A-82F6-3F4D10B91D95} - http://69.50.182.94/1/rdgUS1882.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Loading Outpost Connections (KDE) - Unknown owner - C:\WINDOWS\System32\cmdtel.exe (file missing)
O23 - Service: Debug oupost relations (LAGOS) - Unknown owner - C:\WINDOWS\System32\ahtun.exe (file missing)
O23 - Service: System Startup Service  (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)


I have no idea why it changed itself, but I didnt want to go on, as things didnt appear the same way, if I should just proceed, let me know, and thanks in advance.
Logged

 
Geekgirl
Global Moderator
Hero Member
*****

Karma: +25/-1
Offline Offline

Gender: Female
Posts: 3175



Bookmark and Share

View Profile
« Reply #8 on: May 06, 2005, 04:45:40 PM »


Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are following the procedures below.


Go to My Computer >Tools >Folder Options >View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing / visible. Uncheck the Hide protected operating system files option.

Reboot your system in Safe Mode (By repeatedly tapping the F8 key until the menu appears).


Open Hijack This and click on Scan. Check the following entries (make sure you do not miss any)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://w-find.com/index.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://w-find.com/index.htm

O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O2 - BHO: Loader Class - {2E246FAE-8420-11D9-870D-000C2917DE7F} - C:\WINDOWS\SYSTEM\Loader.dll (file missing)
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll (file missing)
O2 - BHO: (no name) - {C247C1A2-2A43-7790-1AFD-71E29F222CC6} - C:\WINDOWS\System32\dfx.dll (file missing)

O4 - HKLM\..\Run: [dioaxt] c:\windows\system32\mrhndc.exe
O4 - HKCU\..\Run: [vcbtlvw] c:\windows\kpigfhr.exe
O4 - HKCU\..\Run: [ijdlqhl] c:\windows\chwnfvg.exe
O4 - HKCU\..\Run: [fjuvrqp] c:\windows\bxuxytk.exe
O4 - HKCU\..\Run: [uqedwtb] c:\windows\tamvgju.exe
O4 - HKCU\..\Run: [rqwmwde] c:\windows\sqjfaha.exe
O4 - HKCU\..\Run: [ofhmdvp] c:\windows\vvwybmk.exe
O4 - HKCU\..\Run: [jvydgki] c:\windows\rwsyftc.exe
O4 - HKCU\..\Run: [aammtfi] c:\windows\wyqwcbd.exe
O4 - HKCU\..\Run: [dmgxicn] c:\windows\kpigfhr.exe
O4 - HKCU\..\Run: [yctkctw] c:\windows\chwnfvg.exe
O4 - HKCU\..\Run: [fflyoei] c:\windows\bxuxytk.exe
O4 - HKCU\..\Run: [uqiwvlg] c:\windows\tamvgju.exe
O4 - HKCU\..\Run: [atyliur] c:\windows\sqjfaha.exe
O4 - HKCU\..\Run: [afglxus] c:\windows\vvwybmk.exe
O4 - HKCU\..\Run: [hxrkolf] c:\windows\rwsyftc.exe
O4 - HKCU\..\Run: [mxwxfut] c:\windows\wyqwcbd.exe
O4 - HKCU\..\Run: [mgvsuep] c:\windows\kpigfhr.exe
O4 - HKCU\..\Run: [bnmbrdp] c:\windows\chwnfvg.exe
O4 - HKCU\..\Run: [dyyjtxn] c:\windows\bxuxytk.exe
O4 - HKCU\..\Run: [quekpcp] c:\windows\tamvgju.exe
O4 - HKCU\..\Run: [sgqsqwn] c:\windows\sqjfaha.exe
O4 - HKCU\..\Run: [eaovaqn] c:\windows\vvwybmk.exe
O4 - HKCU\..\Run: [xxejxfo] c:\windows\rwsyftc.exe
O4 - HKCU\..\Run: [wwowrno] c:\windows\wyqwcbd.exe
O4 - HKCU\..\Run: [gsguogo] c:\windows\kpigfhr.exe
O4 - HKCU\..\Run: [casgkuc] c:\windows\chwnfvg.exe
O4 - HKCU\..\Run: [opkvgvl] c:\windows\bxuxytk.exe
O4 - HKCU\..\Run: [whfrgko] c:\windows\tamvgju.exe
O4 - HKCU\..\Run: [kwwhcky] c:\windows\sqjfaha.exe
O4 - HKCU\..\Run: [hpvxfwa] c:\windows\vvwybmk.exe
O4 - HKCU\..\Run: [llsjrqb] c:\windows\rwsyftc.exe
O4 - HKCU\..\Run: [slhgtpn] c:\windows\wyqwcbd.exe
O4 - HKCU\..\Run: [cnwimeu] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [cgrlnah] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [ncvgdvu] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [ahiylrx] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [wiokwua] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [tuorqdo] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [opbcloo] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [rjteoud] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [iwvfdup] c:\windows\ihxbysq.exe
O4 - HKCU\..\Run: [gtxyruq] c:\windows\ymxsgiu.exe
O4 - HKCU\..\Run: [wnpivtv] c:\windows\ymxsgiu.exe
O4 - HKCU\..\Run: [eyjxswt] c:\windows\ymxsgiu.exe
O4 - HKCU\..\Run: [awyxjnf] c:\windows\ymxsgiu.exe
O4 - HKCU\..\Run: [ugoicll] c:\windows\ahhtajr.exe
O4 - HKCU\..\Run: [uxvfmiq] c:\windows\ahhtajr.exe
O4 - HKCU\..\Run: [bmreygq] c:\windows\ahhtajr.exe
O4 - HKCU\..\Run: [ggvwsdm] c:\windows\ahhtajr.exe
O4 - HKCU\..\Run: [xvsciux] c:\windows\ahhtajr.exe
O4 - HKCU\..\Run: [nnykskg] c:\windows\kooaulx.exe
O4 - HKCU\..\Run: [ntvyfwc] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [bqsteqr] c:\windows\cbxwlyr.exe
O4 - HKCU\..\Run: [tqmpifn] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [clpgmlb] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [ipyxidy] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [wxobwor] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [adbcksv] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [kcjnmvg] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [tftkfcg] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [plmubnn] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [kwicfkp] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [xujmmio] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [nmdnbxr] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [njxabet] c:\windows\cqifynr.exe
O4 - HKCU\..\Run: [frgcnfq] c:\windows\lfyqufn.exe

O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm

O9 - Extra button: Microsoft AntiSpyware helper - {BE62A02F-DBE4-42C2-A74D-76FF401D9054} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {BE62A02F-DBE4-42C2-A74D-76FF401D9054} - (no file) (HKCU)


O14 - IERESET.INF: START_PAGE_URL=http://qus8l.hpwis.com

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan.cab
O16 - DPF: {2100CDAA-8115-3E0A-82F6-3F4D10B91D95} - http://69.50.182.94/1/rdgUS1882.exe

O23 - Service: Loading Outpost Connections (KDE) - Unknown owner - C:\WINDOWS\System32\cmdtel.exe (file missing)
O23 - Service: Debug oupost relations (LAGOS) - Unknown owner - C:\WINDOWS\System32\ahtun.exe (file missing)
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)



Please remember to close all other windows, including browsers then click Fix checked.


 Delete the following Files indicated in RED and Folders indicated in BLUE if they still exist.

c:\windows\system32\mrhndc.exe
c:\windows\kpigfhr.exe
c:\windows\chwnfvg.exe
c:\windows\bxuxytk.exe
c:\windows\tamvgju.exe
c:\windows\sqjfaha.exe
c:\windows\vvwybmk.exe
 c:\windows\rwsyftc.exe
c:\windows\wyqwcbd.exe
c:\windows\ihxbysq.exe
c:\windows\ymxsgiu.exe
c:\windows\ahhtajr.exe
c:\windows\kooaulx.exe
c:\windows\cqifynr.exe
c:\windows\cbxwlyr.exe
c:\windows\lfyqufn.exe

Run CleanUp! and click on CleanUp! button.  When it asks you if you want to logoff, click on Yes.
Empty your Recycle Bin.

Reboot your System in normal mode.

Please post a fresh Hijack This log so that we can check if your system is clean.

Logged




Girlz Rule ...Boyz Drool
____________________________
ALWAYS BACKUP YOUR REGISTRY BEFORE EDITING
Hadrian
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 8


Bookmark and Share

View Profile
« Reply #9 on: May 11, 2005, 04:41:33 AM »

Well, I did everything you said and I thought it fixed it, however it seems as though everything is worse.  I dont know what happened, or if I am just missing something, but there is no longer a start button, the icons on the desktop are all messed up, and I cant get a log from highjack this.  This is a nightmare.
Logged

 
Pages: [1] Go Up Print 
 
Jump to:  

Powered by MySQL Powered by PHP

Powered by SMF 1.1.21 | SMF © 2015, Simple Machines

Valid XHTML 1.0! Valid CSS!

Disclaimer
This site is NOT responsible for any damage that the information on this site may cause to your system. Everything you try, whether inspired by the response given from this site or not, is entirely at your own risk. All product names and company names used herein are for identification purpose only and may be trademarks or registered trademarks of their respective owners. We are in no way affiliated or representing any of the companies on this site unless specified.
Back to Top
Stop Spam Harvesters, Join Project Honey Pot Fight Back Against Spammers! Get Firefox! Get Thunderbird! View Sylvain Amyots profile on LinkedIn
Back to Top
Google visited last this page October 07, 2016, 02:57:31 PM