MyTechSupport.ca :: Your Computer Technical Resource Headquarters! MyTechSupport.ca :: Your Computer Technical Resource Headquarters!
HOME FORUMS RESOURCES & TOOLS ARTICLES ONLINE STORE ABOUT US
Computer Support Forums arrow Internet & Network Support arrow Security & Viruses arrow Topic: Alot of viruses and spyware
November 13, 2019, 05:14:38 PM
 

Home Forum Rules Help Search Mobile Version Login Register

Welcome, Guest. Please login or register.
Did you miss your activation email?
November 13, 2019, 05:14:38 PM

Login with username, password and session length
 Featured Sites:
News
New  We now offer MyTechSupport.ca Merchandise! Every purchase goes towards maintaining our site.
Thank you for supporting MyTechSupport.ca!
  0 Members and 1 Guest are viewing this topic.
Pages: [1] Go Down Print
Author Topic: Alot of viruses and spyware  (Read 1483 times)
sys_seven
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Female
Posts: 24


Bookmark and Share

View Profile
« on: May 09, 2005, 08:10:41 PM »

PLEASE SUPPLY RELEVANT INFORMATION:
Operating System Version: Windows XP
Problem Application Name & Version:
Problem Hardware Make & Model:
Error Messages:


Logfile of HijackThis v1.99.1
Scan saved at 3:54:40 PM, on 5/9/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Renee\Desktop\protect window program\PrcView.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\netfb.exe
C:\WINDOWS\system32\atlfn32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Renee\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\uydex.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\uydex.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\uydex.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\uydex.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\uydex.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\uydex.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\uydex.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ca.red.clientapps.yahoo.com/customize/rogers/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Rogers Hi-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
F3 - REG:win.ini: load=C:\\asdasd.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7869E6B3-D323-6BCB-ADD4-E5D10D876F39} - C:\WINDOWS\system32\apiwj.dll
O2 - BHO: (no name) - {8C398A6C-966D-5E10-A3AF-31B060FD103A} - C:\WINDOWS\system32\ntkb32.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [Kazaa Download Accelerator Updater] regsvr32 /s C:\WINDOWS\System32\kdpupd.dll
O4 - HKLM\..\Run: [Kazaa Download Accelerator Updater (required)] regsvr32 /s C:\WINDOWS\System32\KDP23ec.dll
O4 - HKLM\..\Run: [appps.exe] C:\WINDOWS\system32\appps.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [crmu.exe] C:\WINDOWS\system32\crmu.exe
O4 - HKLM\..\Run: [netni32.exe] C:\WINDOWS\system32\netni32.exe
O4 - HKLM\..\Run: [atlmo.exe] C:\WINDOWS\system32\atlmo.exe
O4 - HKLM\..\Run: [apiqv32.exe] C:\WINDOWS\system32\apiqv32.exe
O4 - HKLM\..\Run: [winrj32.exe] C:\WINDOWS\system32\winrj32.exe
O4 - HKLM\..\Run: [ipvs32.exe] C:\WINDOWS\system32\ipvs32.exe
O4 - HKLM\..\Run: [netmr32.exe] C:\WINDOWS\system32\netmr32.exe
O4 - HKLM\..\Run: [sdkch.exe] C:\WINDOWS\system32\sdkch.exe
O4 - HKLM\..\Run: [d3oi32.exe] C:\WINDOWS\system32\d3oi32.exe
O4 - HKLM\..\Run: [winvr32.exe] C:\WINDOWS\system32\winvr32.exe
O4 - HKLM\..\Run: [msco.exe] C:\WINDOWS\system32\msco.exe
O4 - HKLM\..\Run: [apiiq32.exe] C:\WINDOWS\system32\apiiq32.exe
O4 - HKLM\..\Run: [mfcct.exe] C:\WINDOWS\system32\mfcct.exe
O4 - HKLM\..\Run: [sysuy.exe] C:\WINDOWS\system32\sysuy.exe
O4 - HKLM\..\Run: [apihk32.exe] C:\WINDOWS\system32\apihk32.exe
O4 - HKLM\..\Run: [atlnn.exe] C:\WINDOWS\system32\atlnn.exe
O4 - HKLM\..\Run: [msmp32.exe] C:\WINDOWS\system32\msmp32.exe
O4 - HKLM\..\Run: [netiz.exe] C:\WINDOWS\system32\netiz.exe
O4 - HKLM\..\Run: [ntnc.exe] C:\WINDOWS\system32\ntnc.exe
O4 - HKLM\..\Run: [mfcgm32.exe] C:\WINDOWS\system32\mfcgm32.exe
O4 - HKLM\..\Run: [addat.exe] C:\WINDOWS\system32\addat.exe
O4 - HKLM\..\Run: [addmv32.exe] C:\WINDOWS\system32\addmv32.exe
O4 - HKLM\..\Run: [sysho32.exe] C:\WINDOWS\system32\sysho32.exe
O4 - HKLM\..\Run: [addhr.exe] C:\WINDOWS\system32\addhr.exe
O4 - HKLM\..\Run: [javaok.exe] C:\WINDOWS\system32\javaok.exe
O4 - HKLM\..\Run: [addbt.exe] C:\WINDOWS\system32\addbt.exe
O4 - HKLM\..\Run: [ntlt.exe] C:\WINDOWS\system32\ntlt.exe
O4 - HKLM\..\Run: [appoy.exe] C:\WINDOWS\system32\appoy.exe
O4 - HKLM\..\Run: [netpk32.exe] C:\WINDOWS\system32\netpk32.exe
O4 - HKLM\..\Run: [ipgu.exe] C:\WINDOWS\system32\ipgu.exe
O4 - HKLM\..\Run: [msbx.exe] C:\WINDOWS\system32\msbx.exe
O4 - HKLM\..\Run: [addfz32.exe] C:\WINDOWS\system32\addfz32.exe
O4 - HKLM\..\Run: [appyz.exe] C:\WINDOWS\system32\appyz.exe
O4 - HKLM\..\Run: [mszn32.exe] C:\WINDOWS\system32\mszn32.exe
O4 - HKLM\..\Run: [mfcyy.exe] C:\WINDOWS\system32\mfcyy.exe
O4 - HKLM\..\Run: [javaqw32.exe] C:\WINDOWS\system32\javaqw32.exe
O4 - HKLM\..\Run: [ntol.exe] C:\WINDOWS\system32\ntol.exe
O4 - HKLM\..\Run: [syscy.exe] C:\WINDOWS\system32\syscy.exe
O4 - HKLM\..\Run: [netjb32.exe] C:\WINDOWS\system32\netjb32.exe
O4 - HKLM\..\Run: [javaqi.exe] C:\WINDOWS\system32\javaqi.exe
O4 - HKLM\..\Run: [ieed.exe] C:\WINDOWS\system32\ieed.exe
O4 - HKLM\..\Run: [apphi.exe] C:\WINDOWS\system32\apphi.exe
O4 - HKLM\..\Run: [d3uk.exe] C:\WINDOWS\system32\d3uk.exe
O4 - HKLM\..\Run: [mfcol.exe] C:\WINDOWS\system32\mfcol.exe
O4 - HKLM\..\Run: [mfcdt32.exe] C:\WINDOWS\system32\mfcdt32.exe
O4 - HKLM\..\Run: [sysbl.exe] C:\WINDOWS\system32\sysbl.exe
O4 - HKLM\..\Run: [javaxd.exe] C:\WINDOWS\system32\javaxd.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [netuz32.exe] C:\WINDOWS\system32\netuz32.exe
O4 - HKLM\..\Run: [winxw32.exe] C:\WINDOWS\system32\winxw32.exe
O4 - HKLM\..\Run: [crwe.exe] C:\WINDOWS\system32\crwe.exe
O4 - HKLM\..\Run: [mfcao.exe] C:\WINDOWS\system32\mfcao.exe
O4 - HKLM\..\Run: [d3su.exe] C:\WINDOWS\system32\d3su.exe
O4 - HKLM\..\Run: [iecw.exe] C:\WINDOWS\system32\iecw.exe
O4 - HKLM\..\Run: [mfcxe.exe] C:\WINDOWS\system32\mfcxe.exe
O4 - HKLM\..\Run: [javakv32.exe] C:\WINDOWS\system32\javakv32.exe
O4 - HKLM\..\Run: [sdkgn.exe] C:\WINDOWS\system32\sdkgn.exe
O4 - HKLM\..\Run: [sdkzt32.exe] C:\WINDOWS\system32\sdkzt32.exe
O4 - HKLM\..\Run: [d3ct.exe] C:\WINDOWS\system32\d3ct.exe
O4 - HKLM\..\Run: [adddt.exe] C:\WINDOWS\system32\adddt.exe
O4 - HKLM\..\Run: [mfckg32.exe] C:\WINDOWS\system32\mfckg32.exe
O4 - HKLM\..\Run: [msaq.exe] C:\WINDOWS\system32\msaq.exe
O4 - HKLM\..\Run: [sdknn32.exe] C:\WINDOWS\system32\sdknn32.exe
O4 - HKLM\..\Run: [apihx.exe] C:\WINDOWS\system32\apihx.exe
O4 - HKLM\..\Run: [netoi32.exe] C:\WINDOWS\system32\netoi32.exe
O4 - HKLM\..\Run: [netlr.exe] C:\WINDOWS\system32\netlr.exe
O4 - HKLM\..\Run: [msib.exe] C:\WINDOWS\system32\msib.exe
O4 - HKLM\..\Run: [netvw32.exe] C:\WINDOWS\system32\netvw32.exe
O4 - HKLM\..\Run: [apprk.exe] C:\WINDOWS\system32\apprk.exe
O4 - HKLM\..\Run: [ntgj.exe] C:\WINDOWS\system32\ntgj.exe
O4 - HKLM\..\Run: [apicr32.exe] C:\WINDOWS\system32\apicr32.exe
O4 - HKLM\..\Run: [crou.exe] C:\WINDOWS\system32\crou.exe
O4 - HKLM\..\Run: [netmm32.exe] C:\WINDOWS\system32\netmm32.exe
O4 - HKLM\..\Run: [apidx32.exe] C:\WINDOWS\system32\apidx32.exe
O4 - HKLM\..\Run: [ieiw32.exe] C:\WINDOWS\system32\ieiw32.exe
O4 - HKLM\..\Run: [atlyv.exe] C:\WINDOWS\system32\atlyv.exe
O4 - HKLM\..\Run: [ipcx32.exe] C:\WINDOWS\system32\ipcx32.exe
O4 - HKLM\..\Run: [apiqh32.exe] C:\WINDOWS\system32\apiqh32.exe
O4 - HKLM\..\Run: [atlhd.exe] C:\WINDOWS\system32\atlhd.exe
O4 - HKLM\..\Run: [javagt.exe] C:\WINDOWS\system32\javagt.exe
O4 - HKLM\..\Run: [sysqx32.exe] C:\WINDOWS\system32\sysqx32.exe
O4 - HKLM\..\Run: [winyb.exe] C:\WINDOWS\system32\winyb.exe
O4 - HKLM\..\Run: [winqz32.exe] C:\WINDOWS\system32\winqz32.exe
O4 - HKLM\..\Run: [atlam32.exe] C:\WINDOWS\system32\atlam32.exe
O4 - HKLM\..\Run: [atlbw.exe] C:\WINDOWS\system32\atlbw.exe
O4 - HKLM\..\Run: [winyc.exe] C:\WINDOWS\system32\winyc.exe
O4 - HKLM\..\Run: [mstj.exe] C:\WINDOWS\system32\mstj.exe
O4 - HKLM\..\Run: [ntqh32.exe] C:\WINDOWS\system32\ntqh32.exe
O4 - HKLM\..\Run: [appdp.exe] C:\WINDOWS\system32\appdp.exe
O4 - HKLM\..\Run: [sdkoq32.exe] C:\WINDOWS\system32\sdkoq32.exe
O4 - HKLM\..\Run: [apiqu.exe] C:\WINDOWS\system32\apiqu.exe
O4 - HKLM\..\Run: [netzr.exe] C:\WINDOWS\system32\netzr.exe
O4 - HKLM\..\Run: [appuq32.exe] C:\WINDOWS\system32\appuq32.exe
O4 - HKLM\..\Run: [sysbh.exe] C:\WINDOWS\system32\sysbh.exe
O4 - HKLM\..\Run: [mscu32.exe] C:\WINDOWS\system32\mscu32.exe
O4 - HKLM\..\Run: [sdkhj32.exe] C:\WINDOWS\system32\sdkhj32.exe
O4 - HKLM\..\Run: [mfcnl.exe] C:\WINDOWS\system32\mfcnl.exe
O4 - HKLM\..\Run: [javanm.exe] C:\WINDOWS\system32\javanm.exe
O4 - HKLM\..\Run: [apitw32.exe] C:\WINDOWS\system32\apitw32.exe
O4 - HKLM\..\Run: [crbd.exe] C:\WINDOWS\system32\crbd.exe
O4 - HKLM\..\Run: [ipon.exe] C:\WINDOWS\system32\ipon.exe
O4 - HKLM\..\Run: [ieco32.exe] C:\WINDOWS\system32\ieco32.exe
O4 - HKLM\..\Run: [winuv.exe] C:\WINDOWS\system32\winuv.exe
O4 - HKLM\..\Run: [d3lx32.exe] C:\WINDOWS\system32\d3lx32.exe
O4 - HKLM\..\Run: [netbv32.exe] C:\WINDOWS\system32\netbv32.exe
O4 - HKLM\..\Run: [mfcmy32.exe] C:\WINDOWS\system32\mfcmy32.exe
O4 - HKLM\..\Run: [sdkai32.exe] C:\WINDOWS\system32\sdkai32.exe
O4 - HKLM\..\Run: [ntwn32.exe] C:\WINDOWS\system32\ntwn32.exe
O4 - HKLM\..\Run: [winlj.exe] C:\WINDOWS\system32\winlj.exe
O4 - HKLM\..\Run: [ntqb.exe] C:\WINDOWS\system32\ntqb.exe
O4 - HKLM\..\Run: [javanb32.exe] C:\WINDOWS\system32\javanb32.exe
O4 - HKLM\..\Run: [appti.exe] C:\WINDOWS\system32\appti.exe
O4 - HKLM\..\Run: [atlvl.exe] C:\WINDOWS\system32\atlvl.exe
O4 - HKLM\..\Run: [sdkpe32.exe] C:\WINDOWS\system32\sdkpe32.exe
O4 - HKLM\..\Run: [mslc.exe] C:\WINDOWS\system32\mslc.exe
O4 - HKLM\..\Run: [addmn32.exe] C:\WINDOWS\system32\addmn32.exe
O4 - HKLM\..\Run: [apikj.exe] C:\WINDOWS\system32\apikj.exe
O4 - HKLM\..\Run: [winef.exe] C:\WINDOWS\system32\winef.exe
O4 - HKLM\..\Run: [sysuu.exe] C:\WINDOWS\system32\sysuu.exe
O4 - HKLM\..\Run: [winbb32.exe] C:\WINDOWS\system32\winbb32.exe
O4 - HKLM\..\Run: [mshg32.exe] C:\WINDOWS\system32\mshg32.exe
O4 - HKLM\..\Run: [atlfn32.exe] C:\WINDOWS\system32\atlfn32.exe
O4 - HKLM\..\Run: [apior32.exe] C:\WINDOWS\system32\apior32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [sdkpx.exe] C:\WINDOWS\system32\sdkpx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [ieex.exe] C:\WINDOWS\system32\ieex.exe
O4 - HKLM\..\Run: [sysfd.exe] C:\WINDOWS\system32\sysfd.exe
O4 - HKLM\..\Run: [mfcpb.exe] C:\WINDOWS\system32\mfcpb.exe
O4 - HKLM\..\Run: [zzzHPSETUP] D:\Setup.exe
O4 - HKLM\..\Run: [appyd32.exe] C:\WINDOWS\system32\appyd32.exe
O4 - HKLM\..\Run: [msnsched2] msnsched2.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\RunServices: [msnsched2] msnsched2.exe
O4 - HKLM\..\RunOnce: [netfb.exe] C:\WINDOWS\netfb.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NDrv] C:\WINDOWS\System32\NDrv.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button:
« Last Edit: May 09, 2005, 08:39:02 PM by Ageless » Logged

 
Pancake
Global Moderator
Hero Member
*****

Karma: +78/-0
Offline Offline

Gender: Male
Posts: 3915


Bookmark and Share

View Profile
« Reply #1 on: May 12, 2005, 09:29:17 AM »

Hi.You have one heck of a mess here....



It may help you if you print out or copy this page for easy reference.. Make sure to work through the fixes in the exact order its listed. Please Keep your browser and all open programs closed (except firewalls and antivirus) when you are carrying out the fixes
.These instructions are for HJT v1.99.1 only


Download any of the required programs before attempting to start any of the fixes.

Please do NOT run Hijack This  in a TEMPorary folder or on the Desktop. I recommend c:/program files/HJT/


Turn off System Restore instructions (WinXP)
Rightclick My Computer | Properties | System Restore | check
Logged

An Australian Member of

EDDY
Pages: [1] Go Up Print 
 
Jump to:  

Powered by MySQL Powered by PHP

Powered by SMF 1.1.21 | SMF © 2015, Simple Machines

Valid XHTML 1.0! Valid CSS!

Disclaimer
This site is NOT responsible for any damage that the information on this site may cause to your system. Everything you try, whether inspired by the response given from this site or not, is entirely at your own risk. All product names and company names used herein are for identification purpose only and may be trademarks or registered trademarks of their respective owners. We are in no way affiliated or representing any of the companies on this site unless specified.
Back to Top
Stop Spam Harvesters, Join Project Honey Pot Fight Back Against Spammers! Get Firefox! Get Thunderbird! View Sylvain Amyots profile on LinkedIn
Back to Top
Google visited last this page September 24, 2018, 03:27:35 AM