Computing.Net > Forums > Security and Virus > Browser Hijack?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Browser Hijack?

Reply to Message Icon

Name: Ken Moore
Date: July 22, 2003 at 14:49:20 Pacific
OS: Win2000pro
CPU/Ram: P3-550/256
Comment:

A short time ago my browswer (IE5.5, recently upgraded from 5.0) started showing evidence of being hijacked. Sometimes when it started up and sometimes during use it would link to one of a number of pages and thence on to various porn sites. In fact on start up it would sometimes do this even though not connected to the internet.

The original links seen have been to pages on www7.paypopup.com, kathic.offshorechicks.com, www.xtrocash.org, www.exitorcash.com, www.cashexits.com.

Scans with AdAware and SpyBot Search and Destry have revealed nothing in particular and currently I've got my machine protected by AdSubtract and PopUpCop, which are doing fine in closing down the windows but are also having a detrimental effect of closing things I might want.

I have been a little suspicious of a module IstSVCwnd because I don't know what it is or where it came from and it sometimes is the cauise of machine hangs.

A recent connection also gave cause for doubt (incuding the word 'ist') when PopupCop said that a site was trying to download 'FREE SEX-XXXTOOLBAR' with a requesting web page of http://www.slotch.com/ist/scripts/istsvc_ads.php?version=1005...etc
and a download location of http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab


I'm running Win2000pro behing Outpost firewall and with (up to date) AVG virus scanner.

Any suggestions would be appreciated.



Sponsored Link
Ads by Google

Response Number 1
Name: Setter
Date: July 22, 2003 at 15:15:17 Pacific
Reply:

I suggest going to http://www.tomcoyote.org/hjt/ and downloading HijackThis. After starting HijackThis, click the scan button which will change into a save log button. Save the logfile and also copy and paste the results back here in this thread. Most items reported by HijackThis are valid, so don’t fix anything yet.


0

Response Number 2
Name: Abnormal
Date: July 22, 2003 at 15:57:35 Pacific
Reply:

You also have a powerful firewall,
websites you listed can be blocked.

You can block Ip adresses with "Block post plug-in".

Another thing to look into is, AGNIS for Outpost ad block list.

Something to check out after you post
your HijackThis log.


0

Response Number 3
Name: Gavster
Date: July 26, 2003 at 02:19:11 Pacific
Reply:

I'm having the same problem as the person who started the thread. I have taken the steps mentioned in the first reply and below is the log. I hope ot hear from someone soon.

Thanks In Advance

Logfile of HijackThis v1.95.1
Scan saved at 10:08:06, on 26/07/03
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\MEDIASCAPE\ONSCREEN DISPLAY\OSD.exe
C:\WINDOWS\SYSTEM\GSICON.exe
C:\WINDOWS\SYSTEM\DSLAGENT.exe
C:\WINDOWS\LOADQM.exe
C:\PROGRAM FILES\WIDCOMM\BLUETOOTH SOFTWARE\BTTRAY.exe
C:\WINDOWS\SYSTEM\DDHELP.exe
C:\PROGRAM FILES\WIDCOMM\BLUETOOTH SOFTWARE\BTSTACKSERVER.exe
C:\WINDOWS\SYSTEM\RNAAPP.exe
C:\WINDOWS\SYSTEM\TAPISRV.exe
C:\PROGRAM FILES\KAZAA LITE\KAZAALITE.KPP
C:\PROGRAM FILES\KAZAA LITE\SPEED UP.exe
C:\WINDOWS\SYSTEM\PSTORES.exe
C:\WINDOWS\EXPLORER.exe
C:\WINDOWS\DESKTOP\HIJACKTHIS.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qpr.premiumtv.co.uk/home/view/home_page/0,,10373,00.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
O2 - BHO: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {a4019fe0-5fdd-11d7-be86-444553540000} - (no file)
O2 - BHO: (no name) - {A8B9F08F-2FC4-4ADE-9049-CFBA586971BA} - C:\WINDOWS\SYSTEM\BHO2.DLL
O2 - BHO: (no name) - {66F67511-2665-4C34-9E20-FAC2C0954EF2} - C:\WINDOWS\WHATTT.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [VortexTray] ASP4TRAY.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [OnScreen Display] C:\Mediascape\OnScreen Display\OSD.exe
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.exe /LOADQUIET
O4 - HKLM\..\Run: [RegShave] C:\Progra~1\REGSHAVE\REGSHAVE.exe /autorun
O4 - HKLM\..\Run: [GSICONEXE] GSICON.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [System Tray] C:\WINDOWS\MSCCN32.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.exe" -atboottime
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [MsnMsgr] "c:\Program Files\MSN Messenger\MsnMsgr.exe" /background
O4 - HKCU\..\Run: [System Tray] C:\WINDOWS\MSCCN32.exe
O4 - HKCU\..\Run: [System MScvb] C:\WINDOWS\MSCVB32.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\NETSCAPE\COMMUNICATOR\PROGRAM\AIM\aim.exe -cnetwait.odl
O4 - Startup: BTTray.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
O9 - Extra button: AIM (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-gb/4,0,0,5/mcinsctl.cab
O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - http://bin.mcafee.com/molbin/Shared/ComCtl32/6,0,80,22/ComCtl32.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37603.6279166667
O16 - DPF: {8522F9B3-38C5-4AA4-AE40-7401F1BBC851} - http://home.wanadoo.nl/century.music/mp3_plugin.exe
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt0_x.cab
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht0_x.cab
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Fleet - http://download.games.yahoo.com/games/clients/y/fltt1_x.cab
O16 - DPF: {A8B9F08F-2FC4-4ADE-9049-CFBA586971BA} (BHO.clsUrlSearch) - http://207.44.176.11/auth/rh/IeInstall_2.exe
O16 - DPF: {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB} (Zoom Class) - http://www.zoomify.com/download/zoomify305.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as/asinst.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: Yahoo! Chat (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {DCF0768D-BA7A-101A-B57A-0000C0C3ED5F} - http://outwar.whazit.com/10041.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab



0

Response Number 4
Name: Setter
Date: July 26, 2003 at 14:49:51 Pacific
Reply:

Hi Gavster,

Make sure to run an updated Spybot Search and Destroy before fixing these items using HijackThis.

Please read the comments I made before fixing the items. Why your two different Anti-Virus programs did not pick the viruses up I don’t know? But you should use the removal tools I gave URL’s to before fixing using HijackThis. There is a possible NEW malware BHO please could you send it to the e-mail I mentioned. And one of the BHO’s I gave a link for further removal instructions after fixing with HijackThis.

After running Spybot S&D, reboot. Close all browser windows and then fix all the following items using HijackThis. Reboot and check if everything listed is gone.

O2 - BHO: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: (no name) - {a4019fe0-5fdd-11d7-be86-444553540000} - (no file)

------------------
O2 - BHO: (no name) - {A8B9F08F-2FC4-4ADE-9049-CFBA586971BA} - C:\WINDOWS\SYSTEM\BHO2.DLL

Could you please send this BHO2.DLL to the e-mail submit-stuff@xs4all.nl for examination? This is the e-mail direct to Tony Klein creator of http://www.spywareinfo.com/bhos/ I sent him an e-mail with the following asking for a response (Please copy and paste the following also in the body of the e-mail):

This one is confusing as the CLSID {A8B9F08F-2FC4-4ADE-9049-CFBA586971BA}is associated with a known bad ActiveX control and BHO.DLL is associated with a known bad BHO called “HighTraffic” http://www.doxdesk.com/parasite/HighTraffic.html which clicking on the Link leads to http://www.doxdesk.com/parasite/SubSearch.html which is also a bad BHO.

And this is the response I received:

Hi Mark,
Bho2.dll is also an existing HighTraffic browser plugin, up to now however listed as having the following Class iD: {53E10C2C-43B2-4657-BA29-AAE179E7D35C} this may be an all new one. I'd appreciate a copy of the file, if that would be possible! :)\
TIA! :)
Cheers, Tony

Please wait for a response before fixing. Thanks.
--------------

O2 - BHO: (no name) - {66F67511-2665-4C34-9E20-FAC2C0954EF2} - C:\WINDOWS\WHATTT.DLL
Spyware/Malware called Whazit See http://www.doxdesk.com/parasite/Whazit.html You can safely fix this entry using HijackThis but also read this link for further removal instructions http://www.spywareinfo.com/articles/whazit/

O4 - HKLM\..\Run: [System Tray] C:\WINDOWS\MSCCN32.exe
Fix after using the removal tool (the tool may remove this entry)
Added as a result of the “W32.Sobig.B@mm” VIRUS! See http://securityresponse.symantec.com/avcenter/venc/data/w32.sobig.b@mm.html Warning - spreading via infected E-mail attachments with the sender address faked as support@microsoft.com. Symantec Security Response has developed a removal tool available from http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.mankx.removal.tool.html to clean infections of W32.Sobig.B@mm

O4 - HKCU\..\Run: [System Tray] C:\WINDOWS\MSCCN32.exe
?? A second instance of the virus above! Strange.

O4 - HKCU\..\Run: [System MScvb] C:\WINDOWS\MSCVB32.exe
Fix after using the removal tool (the tool may remove this entry)
Added as a result of the “W32.Sobig.C@mm” VIRUS! See http://www.symantec.com/avcenter/venc/data/w32.sobig.c@mm.html
Symantec Security Response has created a tool available from http://securityresponse.symantec.com/avcenter/venc/data/w32.sobig.c.removal.tool.html to remove W32.Sobig.C@mm, which is the easiest way to remove this threat.

The following ActiveX controls should be removed. The sites these ActiveX controls come from are blocked by one or more of the following: JD5000's Proxomitron config. file and IE-Spyad (IE Restricted Sites) and Hpguru's hosts file.

O16 - DPF: {8522F9B3-38C5-4AA4-AE40-7401F1BBC851} - http://home.wanadoo.nl/century.music/mp3_plugin.exe

O16 - DPF: {A8B9F08F-2FC4-4ADE-9049-CFBA586971BA} (BHO.clsUrlSearch) - http://207.44.176.11/auth/rh/IeInstall_2.exe

O16 - DPF: {DCF0768D-BA7A-101A-B57A-0000C0C3ED5F} - http://outwar.whazit.com/10041.cab


Also I noticed in the running processes you are using KAZAALITE this is a P2P that you should seriously consider removing this malware portal. Up to you, LOL


For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Good Luck!



0

Response Number 5
Name: Setter
Date: July 26, 2003 at 15:03:56 Pacific
Reply:

Gavster,

Sorry I did some copying and pasteing from another resonce I gave someone else so there are a couple of confusing things:

The statement: "Also I noticed in the running processes you are using KAZAALITE this is a P2P that you should seriously consider removing this malware portal."

Should read: "Also I noticed in the running processes you are using KAZAALITE this P2P malware portal is one security risk you should seriously consider removing."
--
And "In addition to using SpywareBlaster (mentioned in the thread)" does not apply to this thread LOL

Mark



0

Related Posts

See More



Response Number 6
Name: Tom41
Date: July 27, 2003 at 04:31:16 Pacific
Reply:

Also, if you haven't had HT fix it already, send Tony a copy of this ActiveX control:

O16 - DPF: {A8B9F08F-2FC4-4ADE-9049-CFBA586971BA} (BHO.clsUrlSearch) - http://207.44.176.11/auth/rh/IeInstall_2.exe

It's what is installing this BHO:

O2 - BHO: (no name) - {A8B9F08F-2FC4-4ADE-9049-CFBA586971BA} - C:\WINDOWS\SYSTEM\BHO2.DLL


0

Response Number 7
Name: Setter
Date: July 27, 2003 at 09:17:34 Pacific
Reply:

Thanks Tom, that is a good idea.

I just realized that the two entries for the “W32.Sobig.B@mm” VIRUS! are different
O4 - HKLM\..\Run: [System Tray] C:\WINDOWS\MSCCN32.exe
O4 - HKCU\..\Run: [System Tray] C:\WINDOWS\MSCCN32.exe

One is in the registry location HKLM and the other in HKCU. The removal tool given with the HKLM entry will likely remove the HKCU entry as well.


0

Response Number 8
Name: zebra
Date: July 29, 2003 at 13:42:18 Pacific
Reply:

I've had exactely the same thing. here's my log file. PLEASE HELP ,iv tried everything

Logfile of HijackThis v1.95.1
Scan saved at 22:29:06, on 29-7-2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.exe
C:\ATI-CPanel\atiptaxx.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
C:\WINDOWS\System32\NotifyPhoneBook.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=0&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=0&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=0&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=0&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=0&s=
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://www.the-huns-yellow-pages.com/sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://stopxxxpics.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=0&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=0&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=0&s=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=0&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=0&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://i21740.wflu.com/passthrough/index.html?about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\System32\System32.exe
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com
O2 - BHO: (no name) - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh304181.dll (disabled by BHODemon)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {bf29c082-fc31-4e3f-9daf-81b404e2128b} - C:\DOCUME~1\Jelle\APPLIC~1\jmtckgrpro.dll (disabled by BHODemon)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [CloseDNF] C:\WINDOWS\System32\Utility.exe \1008
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [logon.exe] c:\windows\system32\logon.exe
O4 - HKLM\..\Run: [sys] regedit /s sys.reg
O4 - HKLM\..\Run: [EasyDates_be] C:\Program Files\ComSoft\Dialers\EasyDates_be\EasyDates_be.exe /dontdial
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) - http://a840.g.akamai.net/7/840/537/2003071801/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as/asinst.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.communities.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: {FE5D6722-826F-11D5-A24E-0060B0F1A5AE} (Tukati Launcher) - http://3dgamers.tukati.com/tukati/1.7.20.20/tukati.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E116C3B3-390B-4DFB-9ADA-163448E7CDB1}: NameServer = 195.238.2.21 195.238.2.22


0

Response Number 9
Name: zebra
Date: July 29, 2003 at 13:49:44 Pacific
Reply:

well ,whenever i typ an url in internet explorer ,i arrive at that thing to install that xxxtoolbar ,and sometimes another pornographic website (i dont know how it got there ,honestly ,i dont really visit those websites (hjust take my word))


0

Response Number 10
Name: Setter
Date: July 29, 2003 at 17:34:18 Pacific
Reply:

Hi Zebra

Run an updated Spybot Search and Destroy (http://security.kolla.de/) and after closing all browser windows fix the items that are left using HijackThis and then reboot.

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=0&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=0&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=0&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=0&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=0&s=
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://www.the-huns-yellow-pages.com/sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://stopxxxpics.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=0&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=0&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=0&s=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=0&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=0&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://i21740.wflu.com/passthrough/index.html?about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\System32\System32.exe
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com
O2 - BHO: (no name) - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh304181.dll (disabled by BHODemon)
O2 - BHO: (no name) - {bf29c082-fc31-4e3f-9daf-81b404e2128b} - C:\DOCUME~1\Jelle\APPLIC~1\jmtckgrpro.dll (disabled by BHODemon)

O4 - HKLM\..\Run: [CloseDNF] C:\WINDOWS\System32\Utility.exe \1008
Do you know what this is? If not you may fix this also.

O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
Messenger Plus comes with Lop but I don’t see Lop so you must have installed it without installing sponsor software, if you did not install MessengerPlus2, fix it also.

O4 - HKLM\..\Run: [logon.exe] c:\windows\system32\logon.exe
O4 - HKLM\..\Run: [sys] regedit /s sys.reg
O4 - HKLM\..\Run: [EasyDates_be] C:\Program Files\ComSoft\Dialers\EasyDates_be\EasyDates_be.exe /dontdial

O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
Messenger Plus comes with Lop but I don’t see Lop so you must have installed it without installing sponsor software, if you did not install MessengerPlus2, fix it also.

After Reboot then delete:
The folder Comsoft at C:\Program Files\ComSoft
The file logon.exe at c:\windows\system32\logon.exe

And if you did remove Messenger Plus delete the following also:
The folder Messenger Plus! 2 at C:\Program Files\Messenger Plus! 2

Good Luck!


0

Response Number 11
Name: zebra
Date: July 30, 2003 at 06:04:11 Pacific
Reply:

well ,its not over yet... But I see i didn't close my browser windows while scanning ,so i did it again but they were all deleted so :S what to do? i've done everything now ,and it still there


0

Response Number 12
Name: Setter
Date: July 30, 2003 at 14:30:05 Pacific
Reply:

Zebra, Ok, Please post an another HijackThis logfile and so we can take a look at it again.
Sometimes this takes a bit of work to get of the problem.


0

Response Number 13
Name: graphyxz
Date: August 1, 2003 at 13:19:08 Pacific
Reply:

Looks like I have the same thing..

Attached is my log file can anyone tell me what how I can clear this annoyance?

Thanks,

Logfile of HijackThis v1.96.0
Scan saved at 21:01:58, on 01/08/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\NISUM.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Trust\Ami Mouse 300 Optical Dual Scroll\Amoumain.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CConnect\CConnect.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~3\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinAce\WinAce.exe
C:\Documents and Settings\Phil\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=131567
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=131567
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.freeserve.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=131567
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = C:\Program Files\Copernic 2001 Pro\Search Bar.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = www.ntlworld.com/broadband/broadband.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL = 
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {10955232-B671-11D7-8066-0040F6F477E4} - C:\WINDOWS\whattn.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {66F67511-2665-4C34-9E20-FAC2C0954EF2} - C:\WINDOWS\whattt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {D7D7004C-A763-4F8C-B0D4-55A7E017E69D} - C:\WINDOWS\newones.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\PROGRA~1\COPERN~2\COPERN~1.DLL
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WheelMouse] C:\Program Files\Trust\Ami Mouse 300 Optical Dual Scroll\Amoumain.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [WinBrush] C:\Program Files\WinBrush 2002\winbrush.exe /S
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CorrectConnect.lnk = C:\Program Files\CConnect\CConnect.exe
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O8 - Extra context menu item: Search Using Copernic Agent - C:\Program Files\Copernic Agent\Web\SearchExt.htm
O9 - Extra 'Tools' menuitem: Launch Copernic Agent (HKLM)
O9 - Extra button: Copernic Agent (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.co.uk
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - http://moneymanager.egg.com/activex/accounttracking.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37647.0254398148
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/TemplateGallery/downloads/outc.cab



0

Response Number 14
Name: Setter
Date: August 1, 2003 at 19:19:19 Pacific
Reply:

Hi graphyxz,

Run an updated Spybot Search and Destroy http://security.kolla.de/) and after rebooting, close all browser windows and fix the items listed below that are left using HijackThis and then reboot again.

Please read any comments given before fixing the items using HijackThis.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=131567

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=131567

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.freeserve.co.uk/
If the URL is not the provider of your computer or you’re ISP, have HijackThis fix it.

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=131567

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.co.uk
If the URL is not the provider of your computer or you’re ISP, have HijackThis fix it.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = www.ntlworld.com/broadband/broadband.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL =

O2 - BHO: (no name) - {10955232-B671-11D7-8066-0040F6F477E4} - C:\WINDOWS\whattn.dll
Whazit See- http://www.doxdesk.com/parasite/Whazit.html

O2 - BHO: (no name) - {66F67511-2665-4C34-9E20-FAC2C0954EF2} - C:\WINDOWS\whattt.dll
Part of Whazit, See above

O2 - BHO: (no name) - {D7D7004C-A763-4F8C-B0D4-55A7E017E69D} - C:\WINDOWS\newones.dll
Part of Whazit, See above

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O4 - Global Startup: Image Transfer.lnk = ?

O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.co.uk
If the URL is not the provider of your computer or you’re ISP, have HijackThis fix it.

O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab

For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.


0

Response Number 15
Name: kombienzle
Date: August 2, 2003 at 04:37:52 Pacific
Reply:

Looks like I am another victim of the xxxtoolbar. Same problem: from time to time when I type an url into the browser bar, it changes to the xxxtoolbar site. I ran spybot and removed the items. Then I ran hijack this. Here is the logfile. Would be great if somebody can give me advice, what to remove. Thx a lot!

Logfile of HijackThis v1.96.0
Scan saved at 13:24:12, on 02.08.2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\atievxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Programme\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Programme\Internet Explorer\IEXPLORE.exe
D:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.spiegel.de/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.searchv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchv.com/search.php?qq=%s (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAF} - C:\DOKUME~1\Micha\LOKALE~1\Temp\msdgbp.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\WINDOWS\Downloaded Program Files\googlenav.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ElbyCheckElbyCDFL] "C:\Programme\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - Global Startup: Acrobat Assistant.lnk = C:\Programme\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.exe


0

Response Number 16
Name: Setter
Date: August 2, 2003 at 09:53:52 Pacific
Reply:

Hi kombienzle,

After closing all browser windows, fix the items listed below using HijackThis and then reboot.

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.searchv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchv.com/search.php?qq=%s (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=

O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAF} - C:\DOKUME~1\Micha\LOKALE~1\Temp\msdgbp.dll

Also (not related) both Windows and IE don’t have the latest updates (Both currently at SP1) Recommend doing so. :-)


I know you have seen this above, but here it is again!
--------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!


0

Response Number 17
Name: jpx21
Date: August 4, 2003 at 00:04:43 Pacific
Reply:

I came across this site in search of a solution to a problem I have similar to that of kombienzle's. Everytime I tpye in a URL, it is rerouted and opened through "http://vrape.hardloved.com", then there is a default. For example, I'll type in "www.google.com", get the default page telling me "can't find 'www.google.com': other possible sites: 'www.google.com'". I have no problems of being taken to the "xxxtoolbar" site, but if there is a way for this particular problem to be solved, I would greatly appreciate anyone's advice. Thanks! =)



0

Response Number 18
Name: Setter
Date: August 4, 2003 at 08:20:39 Pacific
Reply:

Hi jpx21,

Download the program HijackThis from http://www.tomcoyote.org/hjt/ (Quick Start "usage instructions" on the site) then scan and save the log, then post your logfile here, we will help you get rid of the problem.


0

Response Number 19
Name: MT
Date: August 4, 2003 at 09:20:14 Pacific
Reply:

got a similar problem
have a constant pop-up stating Only the best, plus the vrape URL's
here is my content from hijack this.
thanks a lot guys

Logfile of HijackThis v1.96.0
Scan saved at 12:39:07 PM, on 8/4/2003
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\System32\mspmspsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Microsoft Office\Office\Osa.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\Palm\HOTSYNC.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\system32\notepad.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/
O2 - BHO: WinShow module - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - C:\WINDOWS\winshow.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Gator] "C:\Program Files\Gator.com\Gator\Offers.exe"
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.exe
O4 - Global Startup: HotSync Manager.LNK = C:\Palm\hotsync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: Ebates - file://c:\Program Files\topMoxie\HTML\ebates_script.htm
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O9 - Extra button: Dell Home (HKCU)
O9 - Extra button: Ebates (HKCU)
O12 - Plugin for .ica: C:\PROGRA~1\INTERN~1\PLUGINS\NPICAN.DLL
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37729.6792013889
O16 - DPF: {A1DC3241-B122-195F-B21A-000000000000} - http://pluginaccess.com/Browser_Plugin.cab
O16 - DPF: {C7B05B62-C8D7-438C-840B-4994DAAA8EEE} - http://webpdp.gator.com/v3/download/pdpplugin5094_hd3ptdmgainads.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = PARTSAMLA.COM
O17 - HKLM\System\CCS\Services\Tcpip\..\{07F69278-6AFD-43F3-B228-EC4C6F925EA0}: Domain = Partsamerica.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = PARTSAMLA.COM
O17 - HKLM\System\CS1\Services\Tcpip\..\{07F69278-6AFD-43F3-B228-EC4C6F925EA0}: Domain = Partsamerica.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = PARTSAMLA.COM
O17 - HKLM\System\CS2\Services\Tcpip\..\{07F69278-6AFD-43F3-B228-EC4C6F925EA0}: Domain = Partsamerica.com


0

Response Number 20
Name: Setter
Date: August 4, 2003 at 09:58:07 Pacific
Reply:

Hi MT,

Run an updated Spybot Search and Destroy http://security.kolla.de/) and after rebooting, close all browser windows and fix the items listed below that are left using HijackThis and then reboot again.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/

O2 - BHO: WinShow module - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - C:\WINDOWS\winshow.dll
Hijacker, pop-up opener - See http://www.doxdesk.com/parasite/Winshow.html

O4 - HKLM\..\Run: [Gator] "C:\Program Files\Gator.com\Gator\Offers.exe"

O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
ISTBar foistware - See http://www.doxdesk.com/parasite/ISTbar.html

O8 - Extra context menu item: Ebates - file://c:\Program Files\topMoxie\HTML\ebates_script.htm

O9 - Extra button: Ebates (HKCU)

O16 - DPF: {A1DC3241-B122-195F-B21A-000000000000} - http://pluginaccess.com/Browser_Plugin.cab
O16 - DPF: {C7B05B62-C8D7-438C-840B-4994DAAA8EEE} - http://webpdp.gator.com/v3/download/pdpplugin5094_hd3ptdmgainads.cab


I know you have seen this above, but here it is again!
--------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.


0

Response Number 21
Name: Setter
Date: August 4, 2003 at 10:07:54 Pacific
Reply:

Hi MT,

Whoops, I forgot to have you delete the following folders.

The folder Gator.com at C:\Program Files\Gator.com
The folder ISTsvc at C:\Program Files\ISTsvc
The folder topMoxie at c:\Program Files\topMoxie


0

Response Number 22
Name: Setter
Date: August 4, 2003 at 10:09:12 Pacific
Reply:

Hi MT,

Whoops, I forgot to have you delete the following folders. AFTER REBOOT LOL


0

Response Number 23
Name: jpx21
Date: August 4, 2003 at 11:47:15 Pacific
Reply:

**here's the Logfile...Thanks for taking a look at it! I hope we can solve the problem!

Logfile of HijackThis v1.96.0
Scan saved at 1:46:00 PM, on 8/4/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\AIM95\aim.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMJB.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\Program Files\Microsoft Money\System\urlmap.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Emi.YOUR-M5D4U9R2UV\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vrape.hardloved.com/top/search.php?id=1&s=www.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us5.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com
O2 - BHO: (no name) - {00000273-8230-4DD4-BE4F-6889D1E74167} - C:\WINDOWS\host.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {2662BDD7-05D6-408F-B241-FF98FACE6054} - C:\Program Files\Xupiter\XTUpdate.dll
O2 - BHO: Freedom BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Searchit Toolbar - {6C413541-29A1-4ffe-894C-9D68313C9F73} - C:\WINDOWS\Downloaded Program Files\srchitbar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Xupiter - {57E69D5A-6539-4d7d-9637-775DE8A385B4} - C:\Program Files\Xupiter\XupiterToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O9 - Extra button: MktBrowser (HKLM)
O9 - Extra 'Tools' menuitem: MarketBrowser (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} - http://www.comcastsupport.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {0EC4C9E3-EC6A-11CF-8E3B-444553540000} (WaveTab Control) - http://www.riffinteractive.com/setup/RiffLick.cab
O16 - DPF: {1000026A-8230-4DD4-BE4F-6889D1E74167} - http://cr.stop-popup-ads-now.com/download/cabs/BANN8002/stoppop.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {3717DF57-0396-463D-98B7-647C7DC6898A} - http://www.searchit.com/toolbar/srchitbar.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003071801/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://128.252.39.99/activex/AxisCamControl.cab
O16 - DPF: {A27CFCAE-9351-4D74-BFFC-21EB19693D8C} - http://www.xupiter.com/search2/install/XupiterToolbarLoader.cab
O16 - DPF: {AFDBB6D0-6B96-419C-8BC6-FF0B99368C0B} - http://www.memorymeter.com/MemoryMeter.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Installer/104/rsinstaller.cab


0

Response Number 24
Name: Setter
Date: August 4, 2003 at 12:26:11 Pacific
Reply:

Hi again jpx21,

First run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and rebooting. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vrape.hardloved.com/top/search.php?id=1&s=www.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us5.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=

O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com

O2 - BHO: (no name) - {00000273-8230-4DD4-BE4F-6889D1E74167} - C:\WINDOWS\host.dll
Transponder variant – See http://www.doxdesk.com/parasite/Transponder.html

O2 - BHO: (no name) - {2662BDD7-05D6-408F-B241-FF98FACE6054} - C:\Program Files\Xupiter\XTUpdate.dll
Xupiter - See http://www.doxdesk.com/parasite/Xupiter.html (The latest updates of Spybot S&D and Ad-Aware can remove all Xupiter variants.)

O3 - Toolbar: Searchit Toolbar - {6C413541-29A1-4ffe-894C-9D68313C9F73} - C:\WINDOWS\Downloaded Program Files\srchitbar.dll

O3 - Toolbar: Xupiter - {57E69D5A-6539-4d7d-9637-775DE8A385B4} - C:\Program Files\Xupiter\XupiterToolbar.dll
Xupiter - See http://www.doxdesk.com/parasite/Xupiter.html (The latest updates of Spybot S&D and Ad-Aware can remove all Xupiter variants.)

O9 - Extra button: MktBrowser (HKLM)
O9 - Extra 'Tools' menuitem: MarketBrowser (HKLM)

O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=1&s=

O16 - DPF: {1000026A-8230-4DD4-BE4F-6889D1E74167} - http://cr.stop-popup-ads-now.com/download/cabs/BANN8002/stoppop.cab
O16 - DPF: {3717DF57-0396-463D-98B7-647C7DC6898A} - http://www.searchit.com/toolbar/srchitbar.cab
O16 - DPF: {A27CFCAE-9351-4D74-BFFC-21EB19693D8C} - http://www.xupiter.com/search2/install/XupiterToolbarLoader.cab
O16 - DPF: {AFDBB6D0-6B96-419C-8BC6-FF0B99368C0B} - http://www.memorymeter.com/MemoryMeter.cab
O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Installer/104/rsinstaller.cab

After reboot then locate and delete the folder Xupiter at C:\Program Files\Xupiter (Note: Spybot S&D will probably remove this folder)


I know you have seen this above, but here it is again!
--------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.


0

Response Number 25
Name: Setter
Date: August 4, 2003 at 12:35:05 Pacific
Reply:

jpx21

Thought I'd mention that the toolbar
---------------------
O3 - Toolbar: Searchit Toolbar - {6C413541-29A1-4ffe-894C-9D68313C9F73} - C:\WINDOWS\Downloaded Program Files\srchitbar.dll
--------------------
is Pugi - See http://www.doxdesk.com/parasite/Pugi.html

And of course in the sentence "...fix all items in RED and rebooting" rebooting should be reboot.


0

Response Number 26
Name: Rstrummin
Date: August 4, 2003 at 22:56:44 Pacific
Reply:

WHat do I do now? Here is what my HIJACK Run Log says.

Logfile of HijackThis v1.96.0
Scan saved at 12:46:56 AM, on 8/5/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Totem Shared\Uninstall0001\upd.exe
C:\Program Files\DownloadWare\dw.exe
C:\Program Files\Winamp3\winampa.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\dpps2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\CMEII\CMESys.exe
C:\Program Files\Common Files\Totem Shared\Uninstall0002\upd.exe
C:\WINDOWS\System32\rundll32.exe
C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.exe
C:\PROGRA~1\MESSEN~1\msmsgs.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\Bin\HPOstr05.exe
C:\Program Files\WinZip\WZQKPICK.exe
C:\Program Files\PrecisionTime\PrecisionTime.exe
C:\Program Files\Date Manager\DateManager.exe
C:\Program Files\Common Files\GMT\GMT.exe
C:\Paltalk\pnetaware.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\bin\HPOVDX05.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\WINDOWS\System32\hpoipm07.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\Program Files\America Online 8.0\aol.exe
C:\Program Files\America Online 8.0\waol.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vrape.hardloved.com/top/search.php?id=1&s=www.espn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL = 
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAF} - C:\DOCUME~1\RICK\LOCALS~1\Temp\winhgac.dll
O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet5_20.dll
O2 - BHO: WinShow module - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - C:\WINDOWS\winshow.dll
O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\Program Files\MediaLoads Enhanced\ME1.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM32\NZDD.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [Uninstall0001] "C:\Program Files\Common Files\Totem Shared\Uninstall0001\upd.exe" LASTCALL!adverts.virtuagirl.com!StatsVirtuaGirl
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [MediaLoads Installer] "C:\Program Files\DownloadWare\dw.exe" /H
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [PromulGate] "C:\Program Files\DelFin\PromulGate\PgMonitr.exe"
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRA~1\PANICW~1\POP-UP~1\dpps2.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BookmarkCentral] C:\PROGRA~1\BMCENT~1\BMLauncher.exe
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [Uninstall0002] "C:\Program Files\Common Files\Totem Shared\Uninstall0002\upd.exe" LASTCALL!adverts.virtuagirl.com!StatsVirtuaGirl
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup
O4 - HKLM\..\Run: [CreateCD50] C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.exe -r
O4 - HKCU\..\Run: [MSMSGS] "C:\PROGRA~1\MESSEN~1\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - Startup: PalNetaware.lnk = C:\Paltalk\pnetaware.exe
O4 - Global Startup: Reality Fusion GameCam SE.lnk = C:\Program Files\Intel\Createshare\program\PC Camera Games\Program\RFTray.exe
O4 - Global Startup: HP OfficeJet Series 700 Startup.lnk = C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\Bin\HPOstr05.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.exe
O4 - Global Startup: AOL Companion.lnk = ?
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: SEARCH (HKLM)
O9 - Extra button: ENTERTAINMENT (HKLM)
O9 - Extra button: SECURITY (HKLM)
O9 - Extra button: SEARCH (HKLM)
O9 - Extra button: ANTIVIRUS (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O16 - DPF: Talk City EZTalk 3.0 - http://chat.talkcity.com/java/ezmed/ezmed.cab
O16 - DPF: Yahoo! Chat - http://cs5.chat.sc5.yahoo.com/c381/chat.cab
O16 - DPF: Yahoo! MLB StatTracker - http://aud10.sports.yahoo.com/java/y/mlbst8244_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {0122955E-1FB0-11D2-A238-006097FAEE8B} (CscClnt Class) - http://install.clevercontent.com/3217/02020124/cccabs/CleverContent.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://fusion.umsl.edu/CFIDE/classes/CFJava.cab
O16 - DPF: {0EC4C9E3-EC6A-11CF-8E3B-444553540000} (WaveTab Control) - http://www.riffinteractive.com/setup/RiffLick.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {1954A4B1-9627-4CF2-A041-58AA2045CB35} (Brix6ie Control) - http://a19.g.akamai.net/7/19/7125/1240/ftp.coupons.com/v6/brix6ie.cab
O16 - DPF: {28F00B0F-DC4E-11D3-ABEC-005004A44EEB} (Register Class) - http://content.hiwirenetworks.net/inbrowser/cabfiles/2.5.30/Hiwire.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021017/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/2395b128ef6761655a18/netzip/RdxIE2.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {73020B72-CDD6-4F80-8098-1B2ECD9CA4CA} (HearMe VoiceCREATOR) - http://vp.hearme.com/products/vp/embedded/plugins/evp.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {869F3BBC-A812-4D13-A93B-7B3FC816DCD5} (McAfee.com Updater) - http://download.mcafee.com/molbin/clinic/virusscan/mcasupd.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! WebCam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as/asinst.cab
O16 - DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} (WebCam Control) - http://webcamnow.com/broadcast/ActiveXWebCam.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37292.5303240741
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} (IEAnimBehaviorFactory Class) - http://download.microsoft.com/download/vizact2000/Install/10/WIN98Me/EN-US/msorun.cab
O16 - DPF: {ABE92375-8159-4759-A4B2-BF29E11CAAC3} (HearMe Microphone Configuration Wizard) - http://www.hearme.com/products/vp/config/plugins/evpcfg.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://sea2fd.sea2.hotmail.msn.com/activex/HMAtchmt.ocx
O16 - DPF: {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB} (Zoom Class) - http://www.zoomify.com/download/zoomify214.cab
O16 - DPF: {FEC3E5A3-50F7-4B0C-97D8-01CF69DFBFC7} (Measurement Service Client) - http://ccon.madonion.com/global/msc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B713D39F-A1C9-4A6D-923B-4C01C5341C1D}: NameServer = 152.163.194.134
Thanks for your help


0

Response Number 27
Name: Setter
Date: August 5, 2003 at 00:28:04 Pacific
Reply:

Hi Rstrummin,

First run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vrape.hardloved.com/top/search.php?id=1&s=www.espn.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL =

O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAF} - C:\DOCUME~1\RICK\LOCALS~1\Temp\winhgac.dll

O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet5_20.dll

O2 - BHO: WinShow module - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - C:\WINDOWS\winshow.dll

O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\Program Files\MediaLoads Enhanced\ME1.DLL

O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM32\NZDD.DLL

O4 - HKLM\..\Run: [Uninstall0001] "C:\Program Files\Common Files\Totem Shared\Uninstall0001\upd.exe" LASTCALL!adverts.virtuagirl.com!StatsVirtuaGirl
Adult content based screen saver

O4 - HKLM\..\Run: [MediaLoads Installer] "C:\Program Files\DownloadWare\dw.exe" /H
DownloadWare - executes arbitrary code from advertisers

O4 - HKLM\..\Run: [PromulGate] "C:\Program Files\DelFin\PromulGate\PgMonitr.exe"
Adware based media viewer by The Delfin Project

O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
Part of Gator advertising spyware

O4 - HKLM\..\Run: [Uninstall0002] "C:\Program Files\Common Files\Totem Shared\Uninstall0002\upd.exe" LASTCALL!adverts.virtuagirl.com!StatsVirtuaGirl
Adult content based screen saver

O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup
Advertising spyware

O4 - Global Startup: AOL Companion.lnk = ?
Missing

O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
Spyware/adware based provided by The Gator Corporation

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net

O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=1&s=

O16 - DPF: Yahoo! MLB StatTracker - http://aud10.sports.yahoo.com/java/y/mlbst8244_x.cab

O16 - DPF: {0122955E-1FB0-11D2-A238-006097FAEE8B} (CscClnt Class) - http://install.clevercontent.com/3217/02020124/cccabs/CleverContent.cab

O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab

O16 - DPF: {28F00B0F-DC4E-11D3-ABEC-005004A44EEB} (Register Class) - http://content.hiwirenetworks.net/inbrowser/cabfiles/2.5.30/Hiwire.cab

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/2395b128ef6761655a18/netzip/RdxIE2.cab

O16 - DPF: {73020B72-CDD6-4F80-8098-1B2ECD9CA4CA} (HearMe VoiceCREATOR) - http://vp.hearme.com/products/vp/embedded/plugins/evp.cab

O16 - DPF: {ABE92375-8159-4759-A4B2-BF29E11CAAC3} (HearMe Microphone Configuration Wizard) - http://www.hearme.com/products/vp/config/plugins/evpcfg.cab


After reboot then locate and delete the following folders:

DownloadWare at C:\Program Files\DownloadWare
DelFin at C:\Program Files\DelFin
CMEII at C:\Program Files\Common Files\CMEII
Totem Shared at C:\Program Files\Common Files\Totem Shared
NEWDOT~1 at C:\PROGRA~1\NEWDOT~1
Date Manager at C:\Program Files\Date Manager


You should also do a Windows Update as there are currently security updates for both your OS Windows XP and Internet Explorer.

I know you have seen this above, but here it is again!
--------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.


0

Response Number 28
Name: jpx21
Date: August 5, 2003 at 09:54:20 Pacific
Reply:

Thank you so very much! The problem's been solved! =)


0

Response Number 29
Name: Setter
Date: August 5, 2003 at 11:12:34 Pacific
Reply:

Hi Sherurcij,

This computer may have been seriously compromised; the virus Backdoor.Jeem is a Trojan horse that allows a hacker to remotely control an infected computer. See entries marked **** for viruses. Removal instructions are in the links given.

----------
First run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://193.125.201.50
Do you recognize the URL at the end? If you don't, check it and have HijackThis fix it.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchv.com/search.php?qq=%s (obfuscated)

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 24.132.205.46:80
Do you recognize the URL at the end? If you don't, check it and have HijackThis fix it.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://search.xrenoder.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL =

O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com

O2 - BHO: (no name) - {0096CC0A-623C-4829-AD9C-19AF0DC9D8FE} - C:\Program Files\DAP\DAPIEBar.dll
If you did not install DAP personally then fix this.

O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)

O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
ZTGServerswitch is part of Sony's Vaio support agent - designed by Support.com. Not required if the user does not wish to use the Vaio support agent and regarded as spyware

O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
This P2P malware portal is one security risk you should seriously consider removing. UP TO YOU!!!

O4 - HKLM\..\Run: [Windows Update] C:\WINDOWS\winupdate.exe
**** w32.hllw.warpigs.b VIRUS - See http://www.ghost.com/avcenter/venc/data/w32.hllw.warpigs.b.html for REMOVAL instructions.

O4 - HKLM\..\Run: [System Service] C:\WINDOWS\System32\msrexe.exe
**** Backdoor.Jeem VIRUS! – See http://www.symantec.com.mx/avcenter/venc/data/backdoor.jeem.html for REMOVAL instructions.

O4 - HKLM\..\Run: [logon.exe] c:\windows\system32\logon.exe
Homepage hijacker

O4 - HKLM\..\Run: [winmain] winmain.exe
One of the first of a new breed of malware. When run it immediately loads MSHTA.exe from the Windows folder, placing it on "hot standby", ready to accept HTA scripting within a web page and then EXECUTE what is embedded IN the page as a program! In other words, it's possible for a "rogue" website to actually embed trojans, worms and/or viruses directly into a web page. BOClean's HTA Stop available at http://www.nsclean.com/freebies.html offers an easy way to toggle this capability, or rather vulnerability, on and off. I suggest you leave it disabled!

O4 - HKCU\..\Run: [Windows Update] C:\WINDOWS\winupdate.exe
**** Part of the w32.hllw.warpigs.b VIRUS above

O4 - HKCU\..\Run: [logon.exe] c:\windows\system32\logon.exe
Homepage hijacker

O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Real-time Monitor.lnk = ?
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
As with the DAP entry above; If you did not install DAP personally then fix this.

O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone: http://holocom.swcombine.com

O16 - DPF: {20000273-8230-4DD4-BE4F-6889D1E74167} - http://download.abetterinternet.com/download/cabs/TURB8106/payload2.cab
O16 - DPF: {26E8361F-BCE7-4F75-A347-98C88B418322} - http://dst.trafficsyndicate.com/Dnl/T_50023/QDow.cab


After reboot then locate and delete the following DAP folder only if you removed DAP; C:\Program Files\DAP


You should also do a Windows Update as there are currently security updates for both your OS Windows XP and Internet Explorer.

I know you have seen this above, but here it is again! (These won’t stop VIRUSES, Only Spyware)
--------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!


0

Response Number 30
Name: Setter
Date: August 5, 2003 at 11:28:57 Pacific
Reply:

Hi again Sherurcij,

I don't see that you are using a software firewall. I suggest using ZoneAlarm (the free version) Download link http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp

You will be able to then control inbound and outbound communication.


0

Response Number 31
Name: devilsknight
Date: August 6, 2003 at 09:14:39 Pacific
Reply:

here is my hijack file...i will be running spybot search and destroy shortly anything on the list that i can get rid of will be great

thanks

Logfile of HijackThis v1.96.0
Scan saved at 11:55:48 AM, on 06/08/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Nhksrv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\DELLMMKB.exe
C:\Program Files\HP CD-Writer\Mmenu\hpcdtray.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
C:\Program Files\TimeCalendarLE\TCLE.exe
C:\windows\winlogon.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Javelin.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\KaZaA\Kazaa.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\devilsknight\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dellnet.msn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://www.the-huns-yellow-pages.com/sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lustler.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL = 1
O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DellTouch] "C:\WINDOWS\DELLMMKB.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe /Spoil /RemAdvDef /Migration32"
O4 - HKLM\..\Run: [IMEKRMIG6.1] "C:\WINDOWS\ime\imkr6_1\IMEKRMIG.exe"
O4 - HKLM\..\Run: [MSPY2002] "C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe " /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe /SYNC"
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe /IMEName"
O4 - HKLM\..\Run: [Adaptec DirectCD] "C:\PROGRA~1\HPCD-W~1\DirectCD\directcd.exe"
O4 - HKLM\..\Run: [HP CD-Writer] "C:\Program Files\HP CD-Writer\Mmenu\hpcdtray.exe"
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] "C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup"
O4 - HKLM\..\Run: [NeroCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [SysPnP] "rundll32 setupapi,InstallHinfSection OemVideoPnP 128 oemsyspnp.inf"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [ipmessageblocker] "C:\Documents and Settings\devilsknight\Desktop\messageblockerdemo.exe"
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [TimeCalendar] "C:\Program Files\TimeCalendarLE\TCLE.exe" auto
O4 - HKCU\..\Run: [NvMediaCenter] "RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit"
O4 - HKCU\..\Run: [NVIEW] "rundll32.exe " nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [winlogon] c:\windows\winlogon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsupp/activedata/symsupportutil.CAB
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2F824F9A-F14B-4847-83DE-616D7B589CD0} (Viair Address Book Importer) - http://mytelus.wirelessinbox.com/contacts/addrbook2.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20011217/qtinstall.info.apple.com/qt505/us/win/QuickTimeInstaller.exe
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://ftp.us.dell.com/fixes/PROFILER.CAB
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_03) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553542500} - http://active.macromedia.com/flash2/cabs/swflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {FEC3E5A3-50F7-4B0C-97D8-01CF69DFBFC7} (Measurement Service Client) - http://ccon.madonion.com/global/msc.cab



0

Response Number 32
Name: Setter
Date: August 6, 2003 at 11:15:45 Pacific
Reply:

Hi devilsknight.

First, run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot.

Second, run the removal tool CoolWebShredder from http://www.spywareinfo.com/~merijn/files/cwshredder.zip (This is a direct link and you will be downloading the file cwshredder.zip)

Third, after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.


R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://www.the-huns-yellow-pages.com/sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lustler.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.allhyperlinks.com/redir?lang={SUB_RFC1766}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL = 1

O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com

O4 - HKLM\..\Run: [SysPnP] "rundll32 setupapi,InstallHinfSection OemVideoPnP 128 oemsyspnp.inf"
Search hijacker, a version of the CWS hijack. All the links point to allhyperlinks.com which is in fact Coolwebsearch. You will have already run the removal tool CoolWebShredder from http://www.spywareinfo.com/~merijn/files/cwshredder.zip

O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=1&s=

O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab

O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab

O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_03) -
------------

You should also do a Windows Update as there are currently security updates for both your OS Windows XP and Internet Explorer.

--------------
If you have not yet purchased this so-called program (from http://www.ipmessageblocker.com/downloads.htm) that just turns off a service in XP yet DON’T. They call these guys “Messenger Service scammers” as in one easy sentence they could tell you what XP service to disable. In this case the service is named “Messenger” Imagine that!!! See - http://www.blkviper.com/WINXP/service411.htm#Messenger
Reference HijackThis item: O4 - HKCU\..\Run: [ipmessageblocker] "C:\Documents and Settings\devilsknight\Desktop\messageblockerdemo.exe"
--------------

I know you have seen this above, but here it is again!

For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!


0

Response Number 33
Name: Kaba
Date: August 6, 2003 at 19:15:28 Pacific
Reply:

I have the same problem. Here is my log. Ihope you can help. Thnks.

Logfile of HijackThis v1.96.0
Scan saved at 02:36:49, on 07/08/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpcc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\S3apphk.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpcc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\AOL 8.0\aoltray.exe
C:\Program Files\AOL 8.0\waol.exe
C:\Program Files\AOL 8.0\shellmon.exe
C:\Documents and Settings\All Users\Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=131903
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uku.co.uk/?m=t
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=131903
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=0&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.uku.co.uk/?m=t
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by UKU
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=0&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.uku.co.uk/?m=t
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/
O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SUPASTATUS] C:\Program Files\Internet Explorer\Connection Wizard\status.exe
O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
O4 - HKLM\..\Run: [SA] C:\Program Files\Logitech\QuickCam\SA3.exe
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [AVPCC] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpcc.exe" /wait
O4 - HKLM\..\Run: [logon.exe] c:\windows\system32\logon.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [logon.exe] c:\windows\system32\logon.exe
O4 - Global Startup: AOL 8.0 Tray Icon.lnk = C:\Program Files\AOL 8.0\aoltray.exe
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=0&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=0&s=
O14 - IERESET.INF: START_PAGE_URL=http://www.uku.co.uk/?m=t
O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A769FE93-4DD6-4FCB-BE43-0FC87DB49C5D}: NameServer = 195.93.48.134


0

Response Number 34
Name: dom
Date: August 6, 2003 at 21:03:31 Pacific
Reply:

help.. i have the same prob....

Logfile of HijackThis v1.96.0
Scan saved at 12:13:11 PM, on 8/7/2003
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\PROGRAM FILES\TREND PC-CILLIN 2000\PCCIOMON.exe
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\WINDOWS\SYSTEM\SSDPSRV.exe
C:\PROGRAM FILES\COMMON FILES\SYSTEM\MOSEARCH\BIN\MOSEARCH.exe
C:\WINDOWS\EXPLORER.exe
C:\WINDOWS\SYSTEM\PSTORES.exe
C:\WINDOWS\SYSTEM\RESTORE\STMGR.exe
C:\WINDOWS\TASKMON.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\WINDOWS\LOADQM.exe
C:\PROGRAM FILES\TREND PC-CILLIN 2000\POP3TRAP.exe
C:\PROGRAM FILES\TREND PC-CILLIN 2000\WEBTRAP.exe
C:\WINDOWS\SM56HLPR.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\WINDOWS\SYSTEM\KHOOKER.exe
C:\WINDOWS\SYSTEM\DDHELP.exe
C:\WINDOWS\SYSTEM\LVCOMS.exe
C:\WINDOWS\MSBB.exe
C:\WINDOWS\SYSTEM\CTFMON.exe
C:\WINDOWS\SYSTEM\SPOOL32.exe
C:\WINDOWS\SYSTEM\E_SICN03.exe
C:\WINDOWS\SYSTEM\STIMON.exe
C:\WINDOWS\SYSTEM\RNAAPP.exe
C:\WINDOWS\SYSTEM\TAPISRV.exe
C:\PROGRAM FILES\KAZAA\KAZAA.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.exe
C:\PROGRAM FILES\WINZIP\WINZIP32.exe
C:\WINDOWS\TEMP\HIJACKTHIS.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=131567
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=131567
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL = 
F1 - win.ini: run=PTLSEQ.CPL
O2 - BHO: (no name) - {66F67511-2665-4C34-9E20-FAC2C0954EF2} - C:\WINDOWS\WHATTT.DLL
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMMON\YCOMP5_1_5_0.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [PCCIOMON.EXE] "C:\Program Files\Trend PC-cillin 2000\PCCIOMON.exe"
O4 - HKLM\..\Run: [pop3trap.exe] "C:\Program Files\Trend PC-cillin 2000\pop3trap.exe"
O4 - HKLM\..\Run: [WebTrap.exe] "C:\Program Files\Trend PC-cillin 2000\WebTrap.exe"
O4 - HKLM\..\Run: [SM56ACL] sm56hlpr.exe
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\SYSTEM\khooker.exe
O4 - HKLM\..\Run: [LVComs] C:\WINDOWS\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [LIU] C:\Program Files\Logitech\QuickCam\Rubicon.exe RUBICON_LIVE
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [msbb] C:\WINDOWS\MSBB.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\RunServices: [PCCIOMON.EXE] "C:\Program Files\Trend PC-cillin 2000\PCCIOMON.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [MOSearch] C:\PROGRA~1\COMMON~1\SYSTEM\MOSEARCH\BIN\MOSEARCH.exe
O4 - HKLM\..\RunServices: [VidSvr]
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\RunServices: [ctfmon.exe] ctfmon.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O4 - Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\SYSTEM\E_SRCV03.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE10\EXCEL.EXE/3000
O8 - Extra context menu item: Download with Go!Zilla - file://C:\PROGRAM FILES\GO!ZILLA\download-with-gozilla.html
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: RealGuide (HKLM)
O9 - Extra button: Researcher (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O12 - Plugin for .cub: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .emb: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .gau: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .mol: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .mop: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .pdb: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .rxn: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .skc: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .tgf: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .xyz: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .embl: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .cube: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .csm: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .csml: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .jdx: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .dx: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .spt: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .scr: C:\PROGRA~1\INTERN~1\Plugins\npchime.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .swf: C:\PROGRA~1\INTERN~1\PLUGINS\NPSWF32.dll
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.groups.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab
O16 - DPF: {02C20140-76F8-4763-83D5-B660107B7A90} (Loader Class) - http://connect.online-dialer.com/MaConnect.cab
O16 - DPF: {E9041F85-3C18-4A7E-A29D-E24F84B79BF1} - http://216.133.83.162/downloads/UGO20.exe
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/patch/MaxisSimCity4PatcherX.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
O16 - DPF: {DCF0768D-BA7A-101A-B57A-0000C0C3ED5F} - http://media.windowsmediasolutions.com/10001/downloader.cab


0

Response Number 35
Name: Setter
Date: August 7, 2003 at 00:15:20 Pacific
Reply:

Hi Kaba,

First run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=131903

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=131903
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=0&s=

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=0&s=

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/
O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com

O4 - HKLM\..\Run: [logon.exe] c:\windows\system32\logon.exe
Homepage hijacker

O4 - HKCU\..\Run: [logon.exe] c:\windows\system32\logon.exe
Homepage hijacker

O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=0&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=0&s=

O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab


I know you have seen this above, but here it is again!

For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!


0

Response Number 36
Name: Setter
Date: August 7, 2003 at 00:54:23 Pacific
Reply:

Hi dom,

First run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=131567

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=131567

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
The only reason I’m removing this is the URL does not resolve.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL =

F1 - win.ini: run=PTLSEQ.CPL

O2 - BHO: (no name) - {66F67511-2665-4C34-9E20-FAC2C0954EF2} - C:\WINDOWS\WHATTT.DLL
Whazit - See http://www.doxdesk.com/parasite/Whazit.html

O4 - HKLM\..\Run: [msbb] C:\WINDOWS\MSBB.exe
Advertising spyware

O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
ISTBar foistware - See http://www.doxdesk.com/parasite/ISTbar.html

O4 - HKLM\..\RunServices: [MOSearch] C:\PROGRA~1\COMMON~1\SYSTEM\MOSEARCH\BIN\MOSEARCH.exe

O4 - HKLM\..\RunServices: [VidSvr]
??? Location Missing, I would just fix this.

O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
If you did not personally load Download Accelerator Plus (DAP), then fix this

O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.groups.yahoo.com/ocx/us/yexplorer1_9us.cab

O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab

O16 - DPF: {02C20140-76F8-4763-83D5-B660107B7A90} (Loader Class) - http://connect.online-dialer.com/MaConnect.cab

O16 - DPF: {E9041F85-3C18-4A7E-A29D-E24F84B79BF1} - http://216.133.83.162/downloads/UGO20.exe

O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll

O16 - DPF: {DCF0768D-BA7A-101A-B57A-0000C0C3ED5F} - http://media.windowsmediasolutions.com/10001/downloader.cab

I know you have seen this above, but here it is again!

For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!


0

Response Number 37
Name: mattb
Date: August 7, 2003 at 09:16:25 Pacific
Reply:

Please help. Im having the same problem.

logfile of HijackThis v1.96.0
Scan saved at 18:12:26, on 07/08/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\Program Files\Norton Utilities\NPROTECT.exe
C:\Program Files\Speed Disk\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\McAfee\McAfee VirusScan\Webscanx.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\S3hotkey.exe
C:\WINDOWS\System32\S3tray2.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\Program Files\Norton Utilities\SYSDOC32.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\GPSoftware\Directory Opus\DOpus.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Matt\LOCALS~1\Temp\dtemp-1a5fc603317880-20.dop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.worldonline.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by World Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL = 
O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [S3hotkey] S3hotkey.exe
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O4 - Global Startup: Norton System Doctor.lnk = C:\Program Files\Norton Utilities\SYSDOC32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: FlashGet (HKLM)
O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O14 - IERESET.INF: START_PAGE_URL=http://www.worldonline.cz
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://apple.speedera.net/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} (WebCam Control) - http://www.webcamnow.com/broadcast/ActiveXWebCam.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{46ED497B-9B55-4DB8-BFF3-28E9960629AD}: NameServer = 212.11.105.4 195.146.100.5
O17 - HKLM\System\CCS\Services\Tcpip\..\{67340272-AD6D-4EAB-A544-A64DE0DE7EC5}: NameServer = 192.168.120.252,192.168.120.253



0

Response Number 38
Name: Setter
Date: August 7, 2003 at 10:58:12 Pacific
Reply:

Hi mattb,

First run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL =

O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com

O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=1&s=


You should also do a Windows Update as there are currently security updates for both your OS Windows XP and Internet Explorer.


I know you have seen this above, but here it is again!
--------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!


0

Response Number 39
Name: bigkevin
Date: August 7, 2003 at 11:02:33 Pacific
Reply:

hey, im having that problem with vrape.hardloved showing up in the browser. here is a copy of my log--thanks
Logfile of HijackThis v1.96.0
Scan saved at 12:43:38 PM, on 8/7/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\Scandisk.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\DELLMMKB.exe
C:\Program Files\DownloadWare\dw.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\WINDOWS\System32\server.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\sbnet\ShowBehind.exe
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\Program Files\MSN Messenger\MsnMsgr.exe
C:\Program Files\Netropa\OSD.exe
C:\Palm\HOTSYNC.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Microsoft Office\Office\OSA.exe
C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\kevin hentz\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchgateway.net/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://stopxxxpics.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://stopxxxpics.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=2&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=2&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchgateway.net/search/%s (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL = no
R3 - URLSearchHook: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - C:\PROGRA~1\COMMON~1\BTLINK\btlink.dll
F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\Scandisk.exe
F1 - win.ini: run=C:\WINDOWS\Scandisk.exe
O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com
O2 - BHO: (no name) - {00000580-C637-11D5-831C-00105AD6ACF0} - C:\WINDOWS\MSView.dll
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {63B78BC1-A711-4D46-AD2F-C581AC420D41} - C:\WINDOWS\System32\btiein.dll
O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\Program Files\MediaLoads Enhanced\ME2.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - C:\PROGRA~1\COMMON~1\BTLINK\btlink.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.exe
O4 - HKLM\..\Run: [MediaLoads Installer] "C:\Program Files\DownloadWare\dw.exe" /H
O4 - HKLM\..\Run: [DownloadWare] "C:\Program Files\DownloadWare\dw.exe" /H
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [RunProg] C:\WINDOWS\System32\server.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ShowBehind] C:\WINDOWS\sbnet\ShowBehind.exe
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\KaZaA\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [MS Scandisk] C:\WINDOWS\Scandisk.exe
O4 - HKLM\..\Run: [uaipcsn] "C:\WINDOWS\System32\uaipcsn.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [MS Scandisk] C:\WINDOWS\Scandisk.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.exe" /background
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Camio Viewer 2000.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.exe
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=2&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=2&s=
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {1E89F686-B78D-4C85-9EFC-3474516E3FE2} - http://directplugin.com/plugin/111329.exe
O16 - DPF: {26E8361F-BCE7-4F75-A347-98C88B418322} - http://dst.trafficsyndicate.com/Dnl/T_50010/btiein.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {69FD62B1-0216-4C31-8D55-840ED86B7C8F} - http://installs.hotbar.com/installs/hotbar/programs/hotbar.cab
O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} - http://fdl.msn.com/public/chat/msnchat42.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} - http://download.weatherbug.com/minibug/tricklers/AWS/minibuginstaller.cab
O16 - DPF: {A45F39DC-3608-4237-8F0E-139F1BC49464} - http://www.sexyplugin.com/diallerfiles/034891.exe
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} (loader Class) - http://dload.ipbill.com/del/loader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E87A6788-1D0F-4444-8898-1D25829B6755} - http://fdl.msn.com/public/chat/msnchat4.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: {FC327B3F-377B-4CB7-8B61-27CD69816BC3} - http://www.clock-sync.com/ClockSyncAutoSYNC0007.cab



0

Response Number 40
Name: tom_m
Date: August 7, 2003 at 14:20:58 Pacific
Reply:

hey guys,
afraid im having exaclty the same problem with vrape.hardlove appearing in my explore bar, so any help would be greatly appreciated!! thanks v much,
here is my log

Logfile of HijackThis v1.96.0
Scan saved at 22:12:12, on 07/08/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\Program Files\Norton Internet Security\NISSERV.exe
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\necmfk\necmfk.exe
C:\ATI Control Panel\atiptaxx.exe
C:\apps\ActivSurf\4448364\Program\backweb-4448364.exe
C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Norton Internet Security\IAMAPP.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Norton Internet Security\ATRACK.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://www-cache.freeserve.com:8080;ftp=http://www-cache.freeserve.com:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL = 
O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [NECMFK] C:\Program Files\necmfk\necmfk.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ActivSurf] C:\apps\ActivSurf\4448364\Program\backweb-4448364.exe
O4 - HKLM\..\Run: [NECStartPage] C:\apps\HomePage\HomePgui.exe
O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.exe" /background
O4 - HKCU\..\Run: [Update Service] C:\PROGRA~1\COMMON~1\TEKNUM~1\update.exe /startup
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Packard Bell (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {54E7E082-1DA6-412E-96B5-C290FCEF5329} (DFRun Class) - http://webpdp.gator.com/v3/download/iegator_4090_hd3ptdmgainads.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37655.5452893519
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} (loader Class) - http://dload.ipbill.com/del/loader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A4D8EB1-8CC2-4FD5-8D0D-9B13DAF8D066}: NameServer = 207.44.140.102 64.191.22.247
O17 - HKLM\System\CS1\Services\Tcpip\..\{1A4D8EB1-8CC2-4FD5-8D0D-9B13DAF8D066}: NameServer = 207.44.140.102 64.191.22.247



0

Response Number 41
Name: craig123
Date: August 7, 2003 at 14:26:00 Pacific
Reply:

Logfile of HijackThis v1.96.0
Scan saved at 5:21:40 PM, on 8/7/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\CTHELPER.exe
C:\Program Files\Winamp3\winampa.exe
C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\wininetd.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Mindbeat\Invisible! 2001\invisible.exe
C:\Program Files\MSN Messenger\MsnMsgr.exe
C:\windows\explore.exe
C:\Documents and Settings\Home1\Local Settings\Temp\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\system32\search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CCHelper - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper Pro\CCHelper.dll
O2 - BHO: (no name) - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\E2G\IeBHOs.dll
O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet5_20.dll
O2 - BHO: WinShow module - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - C:\WINDOWS\winshow.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - C:\Program Files\Panicware\Pop-Up Stopper Pro\popuppro.dll
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.exe TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Invisible! 2001] "C:\Program Files\Mindbeat\Invisible! 2001\invisible.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.exe" /background
O4 - HKCU\..\Run: [explore] c:\windows\explore.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {C3FDA8CE-9414-4E33-AC6B-4922922259A5} - http://www.jambalala.com/movies.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E9041F85-3C18-4A7E-A29D-E24F84B79BF1} - http://216.133.83.162/downloads/UGO20.exe


0

Response Number 42
Name: JeffGuthrie
Date: August 7, 2003 at 19:15:24 Pacific
Reply:

I too have been hit with this. Below is my HijackThis.log. I also had the XXXTOOLBAR and removed it through Add/Remove Programs.

Other observations:
If you manually type "http://" in the front of your desired URL it seems to by-pass the redirect.

Lately, when I do manage to get to a site, I get a pop-up window telling me that I am about to download "US from sa.payment.aol.com". I downloaded it and saved it as a .txt file. I have included the contents below as well.

I hope this additional information helps. Let me know what I need to do to clean this up. thx.


HijackThis.log

Logfile of HijackThis v1.96.0
Scan saved at 8:54:33 PM, on 8/7/2003
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\ZipToA.exe
C:\WINNT\Explorer.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\Program Files\Bargain Buddy\bin\bargains.exe
C:\Program Files\ISP50\bin\bartshel.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\winnt\winlogon.exe
C:\Program Files\America Online 7.0\aoltray.exe
C:\Program Files\QUICKENW\QWDLLS.exe
C:\PROGRA~1\ISP50\bin\ppshared.exe
D:\Downloads\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.xrenoder.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.searchv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://search.xrenoder.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/
O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com
O2 - BHO: (no name) - {3DE88907-3E38-11D4-BEB2-CBE76C0598DD} - C:\Program Files\ISP50\bin\BandObject.dll
O2 - BHO: Url Catcher - {CE31A1F7-3D90-4874-8FBE-A5D97F8BC8F1} - C:\PROGRA~1\BARGAI~1\bin\apuc.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [Bargains] C:\Program Files\Bargain Buddy\bin\bargains.exe
O4 - HKLM\..\Run: [Bart Station] C:\Program Files\ISP50\hta\station.sbrt
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKCU\..\Run: [winlogon] c:\winnt\winlogon.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.exe
O4 - Global Startup: Forget Me Not.lnk = C:\Program Files\Broderbund\AG CreataCard\AGRemind.exe
O4 - Global Startup: Kodak Picture Easy 3.1 Batch Transfer.lnk = C:\Program Files\Kodak\Picture Easy Software\Program\PezDownload.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.exe
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab
O16 - DPF: {02C20140-76F8-4763-83D5-B660107B7A90} (Loader Class) - http://connect.online-dialer.com/MaConnect.cab


US.txt

‹ í½ûwÚº0úóæ¯p|÷i¡!ï6mCÝ~$! -¯iÚ¦ÝYÆ6à0µM}üïßÌH²%#Hº÷>gݵîí9;XÒh4F£ÑëÕ0^çr¯†ží¾Î½ZYƒÆûƒ£#ck}ËÀÄŽ½Ø6†qíVNk­Jûè´.L¼£Îû^+ ¦yŠ)‡¡}—7Êí.Ób_(²ªŽ´ÓÝ?Õ5öþ‰F>ö«0ÌUZ:ðZ¹ÚÖd¨VŽjŸô ªžáõc]l³ ²×9k¶k‡«ù~³}¬jW*¢æXº¨x³®k­v²ìŸ6týr¿ý©Vnh)f)'ͺ®aOkÇ•ýòqgí}§ªË|ªcÏé§Ãª®ÎÊŸZ' Â5ˆPß—!ý¸Y;z‡>•OšMX”ë­zSÓž Mµn³?‡ºNy gëÁ(PåƒjWSYHϪï4BPmœV»J>©¸FCbéÒª•û§Ÿ?k$á Y>8Ñ!—úl·yXÖÞ¬Ö÷«ÀÅÓŽN. ¦røé fírM—½Þ:í”õ[§ î¨ß:‡Õ6СËæ®N‹4;Ý­„ ŠmB9í”‡ÇЊڑæ ]>ÂÎvpÒ¬hDÒ?5kZÂÛåÏŸº¢Ëe25A·5޵åvNŽª•š®ß¡5þ¡ªÉvX©U˺x%ÔÆïôI˜L´»@Éq³y¨ÍÎÆ¢jãÝ[iô\*^Ñ0˜:vÓè2ÈŠ#“R&C&
º£j£Ú9©Uµ£Å$UÚk-°–*j£K0Íãæ¦kÈBÏ=“1/Lh¥-.r¹,m¯îñ™®­ŽÛЂí6RÓñã´ÞÒEªƒTÑ ØI¹V9n7µÒ ú¦c¢®_
Ÿ°Î ‘5Éû͇U³Âç kuÖÙI¥\ëžt+u”WÀ¢=é4u#ßI¥öy¿Ò>æM¢«Hg³ýé¨Ü®ë$䤊=r‰¦Æ±ó°Òjêå¤5/Ÿ)dõ Ù8ªvaê¦#¢ZGS·¡·yª
°ÿÒTCNêTOºÍÓ.Ù
óļ†kõíA«ÒhT4ÝéíÁÙ ’©K™
˜œÀfiF•CÓȘÔÑþѪ}þ½†óT†:˜f­§C˜5¹v‘ O;Ýú§Nõ³f }W=ìTu-I8$œhÚWˆr‘ öLÓ“
Ì ë§'uí þ®òú°^A ÍvK§ÔÄ ÍZ€I T\«šp¾²]¹{ Š¥¦kjÕ÷§ÕCE_Jù«Ð¦åö§ãÓjM£j5˜®j&Úè ét+’9¼|øüCå@ÇÚéÁ»Oû0¾…¢t² 뀞«‘aùÀé2(Ùcnô©* ú¤vš@ñûM¦IŠp%¬¨dY)cØ[^¦†@»Uæ“% Í.èo˜ÝéÚ¾ÞüP­5jBxô¦T3Œ9=Ðhvu# ¥©“§åEu;•ƒSèkÍ:]»×Ayƒtºú?Hå"™l”;0oÕdk”Q¹”ašÞj¶uʪSÓ»­:Gûš1£sDãŸl¤iÀÉÃêñg]J³&H³}\n é©‡¨U2>Ž4柚:£­ƒ&ä>X8媶×A·ü´i«Z9®èT+M¥JÿJÇ"•ô¹©5çÏöõ“Î3˜Íÿ³U©.ÆîË;¥àãÖæ|ñŸj8ÚËï÷M›à‘élµJWYSšÛrAð'-Îê¡’ ÄZy( .v×qI ÆÝ‡ÒPm§ƒí‚½”W}›|Õæ}ͳ†d2̯ ³ú=SÐwûɲãyX”Y¨êDMÄš:´”(W‚ÐN«P?O£L4É ™‚§—ÀÀ«,‡ZãîhˆäçBèÄ¢>*wª
uöª±¹)SwÞ†›3ìXk¦#A
©JbÙù&Áx®¯Gž3 ½õ;{l+kµEPs[]“ômJ·Ç^è;öÄ»BJ”Ù!Çýž=¹Ê$>¥Dלൺ€g0 ®gÑÄ‹3‰»”8îM ìØvœùŸ. Ûq|ãã½(ZË„3y^PžÚÉÛLüKŠ»£onnÖGe;MD["COSTCO.COM"] = false;MD["COUNTRYHOMESANDGARDENS.COM"] = true;MD["CRAFTERSCHOICE.COM"] = true;MD["CRAYOLA.COM"] = false;MD["CRAZYTREE.COM"] = true;MD["CROSSINGS.COM"] = true;MD["CRUTCHFIELD.COM"] = false;MD["DATAVIS.COM"] = true;MD["DELIAS.COM"] = true;MD["DICKBLICK.COM"] = true;MD["DICKSSPORTINGGOODS.COM"] = true;MD["DISCOUNTINKJET.COM"] = new MerchantProp( new Array("shopcart.com"), false );MD["DOUBLEDAYBOOKCLUB.COM"] = true;MD["DRUGSTORE.COM"] = true;MD["DUNHAMSSPORTS.COM"] = true;MD["EA.COM"] = false;MD["EANGLER.COM"] = false;MD["EASTBAY.COM"] = true;MD["EBAGS.COM"] = false;MD["EBAY.COM"] = false;MD["EBGAMES.COM"] = false;MD["ECOST.COM"] = true;MD["EDDIEBAUER.COM"] = false;MD["ELISABETH.COM"] = false;MD["ELUXURY.COM"] = true;MD["ESTEELAUDER.COM"] = true;MD["ESTYLE.COM"] = false;MD["ETOYS.COM"] = true;MD["EYESAVE.COM"] = false;MD["FANBUZZ.COM"] = false;MD["FIGLEAVES.COM"] = true;MD["FINISHLINE.COM"] = false;MD["FISHER-PRICESTORE.COM"] = false;MD["FOGDOG.COM"] = true;MD["FOODANDWINE.COM"] = new MerchantProp( new Array("AMEXPUB.COM"), false );MD["FOSSIL.COM"] = false;MD["FOXSPORTS.COM"] = true;MD["FRANKLINMINT.COM"] = true;MD["FREDERICKS.COM"] = false;MD["GAMESTOP.COM"] = false;MD["GAP.COM"] = false;MD["GARDENERS.COM"] = true;MD["GATEWAY.COM"] = true;MD["GIFTBASKETS.COM"] = false;MD["GIGAGOLF.COM"] = true;MD["GOCOLLECT.COM"] = false;MD["GODIVA.COM"] = false;MD["GOLDANDDIAMOND.COM"] = false;MD["GOLFWAREHOUSE.COM"] = new MerchantProp( new Array("TGW.COM"), false );MD["GREATARRIVALS.COM"] = true;MD["GUMPS.COM"] = true;MD["GYMBOREE.COM"] = false;MD["HALEGROVES.COM"] = true;MD["HAMMACHER.COM"] = true;MD["HARRYANDDAVID.COM"] = true;MD["HBO.COM"] = new MerchantProp( new Array("EMERCHANDISE.COM"), true );MD["HEALTHTEX.COM"] = false;MD["HEARTHSONG.COM"] = true;MD["HELZBERGDIAMONDS.COM"] = true;MD["HICKORYFARMS.COM"] = false;MD["HISTORYBOOKCLUB.COM"] = true;MD["HOMEDEPOT.COM"] = false;MD["HP.COM"] = true;MD["ICE.COM"] = false;MD["ICONFITNESS.COM"] = false;MD["IMATERNITY.COM"] = false;MD["INPHONIC.COM"] = false;MD["INSIGHTOUTBOOKS.COM"] = true;MD["JANDR.COM"] = true;MD["JCPENNEY.COM"] = true;MD["JCWHITNEY.COM"] = true;MD["JESSICALONDON.COM"] = false;MD["JEWELCLAIMCENTER.COM"] = false;MD["JEWELERS-SERVICES.COM"] = false;MD["JOINTRADITIONSBOOKCLUB.COM"] = false;MD["JUSTMYSIZE.COM"] = true;MD["KIDSEDGE.COM"] = false;MD["KIDSTOYSHOP.COM"] = false;MD["KINGSIZEDIRECT.COM"] = true;MD["KITCHENANDMUCHMORE.COM"] = true;MD["KMART.COM"] = new MerchantProp( new Array("KMARTCORP.COM"), false );MD["KMARTCORP.COM"] = false;MD["KOHLS.COM"] = true;MD["LANDSEND.COM"] = false;MD["LANEBRYANTCATALOG.COM"] = true;MD["LIQUIDGOLF.COM"] = false;MD["LITERARYGUILD.COM"] = true;MD["LLBEAN.COM"] = true;MD["LOWESTDEAL.COM"] = new MerchantProp( new Array("ACTIVEC.COM"), false );MD["LUCKYBRANDJEANS.COM"] = false;MD["MARSHALLFIELDS.COM"] = new MerchantProp( new Array("TARGET.COM"), true );MD["MATCH.COM"] = false;MD["MATCHBOX.COM"] = false;MD["MATCHBOXSHOP.COM"] = true;MD["MCSPORTS.COM"] = false;MD["MILITARYBOOKCLUB.COM"] = true;MD["MONEYBOOKCLUB.COM"] = false;MD["MOTHERHOOD.COM"] = false;MD["MOVIEFONE.COM"] = new MerchantProp( new Array("MOVIETICKETS.COM"), true );MD["MUSICNOTES.COM"] = true;MD["MUSICTODAY.COM"] = new MerchantProp( new Array("MTSECURECOMMERCE.COM"), false );MD["MYFAMILY.COM"] = false;MD["MYSTERYGUILD.COM"] = true;MD["NASCAR.COM"] = false;MD["NATIONALGEOGRAPHIC.COM"] = true;MD["NBA.COM"] = false;MD["NBWEBEXPRESS.COM"] = false;MD["NETMARKET.COM"] = false;MD["NETSCAPE.COM"] = false;MD["NEWBALANCEWEBEXPRESS.COM"] = new MerchantProp( new Array("NBWEBEXPRESS.COM"), false );MD["NEWLINE.COM"] = false;MD["NEWPORT-NEWS.COM"] = false;MD["NORDSTROM.COM"] = true;MD["NORTHERNTOOL.COM"] = false;MD["OFFICEDEPOT.COM"] = false;MD["OFFICEINNOVATIONS.COM"] = new MerchantProp( new Array("YAHOO.COM"), true );MD["OFFICEMAX.COM"] = true;MD["OLDNAVY.COM"] = true;MD["OMAHASTEAKS.COM"] = false;MD["ONEHANESPLACE.COM"] = true;MD["ONESPIRIT.COM"] = true;MD["ORVIS.COM"] = true;MD["OSHMANS.COM"] = true;MD["OUTDOORSMANSEDGE.COM"] = true;MD["OVERLAND.COM"] = false;MD["OVERSTOCK.COM"] = true;MD["PACSUN.COM"] = true;MD["PAYLESS.COM"] = true;MD["PCCONNECTION.COM"] = false;MD["PERFUMEOUTLET.NET"] = false;MD["PERFUMESTATION.COM"] = false;MD["PERSONALCREATIONS.COM"] = false;MD["PHILIPS.COM"] = false;MD["POPCORNMAKER.COM"] = false;MD["PROGRESSIVEFARMER.COM"] = new MerchantProp( new Array("SOUTHERNPROGRESS.COM"), true );MD["PUSA-STORE.COM"] = false;MD["QPB.COM"] = true;MD["QUILLCORP.COM"] = false;MD["RADIOSHACK.COM"] = true;MD["REALSIZE.COM"] = new MerchantProp( new Array("YAHOO.COM"), false );MD["REI-OUTLET.COM"] = true;MD["REI.COM"] = true;MD["RHAPSODYBOOKCLUB.COM"] = true;MD["RHINO.COM"] = new MerchantProp( new Array("TIMEWARNERORDERCENTER.COM"), true );MD["RIGHTSTART.COM"] = true;MD["RITZCAMERA.COM"] = new MerchantProp( new Array("BORDERFREE.COM"), true );MD["ROADRUNNERSPORTS.COM"] = true;MD["SELECTCOMFORT.COM"] = false;MD["SEPHORA.COM"] = false;MD["SFBC.COM"] = true;MD["SFMUSICBOX.COM"] = true;MD["SHINDIGZ.COM"] = true;MD["SHOPGETORGANIZED.COM"] = true;MD["SHOPLIFESTYLE.COM"] = true;MD["SIMAYOF.COM"] = false;MD["SMARTBARGAINS.COM"] = false;MD["SONYSTYLE.COM"] = true;MD["SPIEGEL.COM"] = false;MD["SPORTCHALET.COM"] = true;MD["SPRINTPCS.COM"] = false;MD["STAGENSCREEN.COM"] = false;MD["STAPLES.COM"] = false;MD["STEPHENKINGLIBRARY.COM"] = false;MD["STEVEMADDEN.COM"] = new MerchantProp( new Array("MICRONEXX.COM"), false );MD["SWATCH.COM"] = true;MD["SYMANTEC.COM"] = false;MD["SYMANTECSTORE.COM"] = false;MD["T-SHIRTKING.COM"] = false;MD["TECHFORLESS.COM"] = false;MD["TGW.COM"] = false;MD["THEATHLETESFOOT.COM"] = true;MD["THEBABYOUTLET.COM"] = false;MD["THEDAVE.COM"] = new MerchantProp( new Array("TIMEWARNERORDERCENTER.COM"), true );MD["THEGOODCOOK.COM"] = true;MD["THEKNOT.COM"] = false;MD["THESPORTSAUTHORITY.COM"] = true;MD["TICKETMASTER.COM"] = false;MD["TICKETWEB.COM"] = false;MD["TIGERDIRECT.COM"] = false;MD["TIMELIFE.COM"] = true;MD["TIMEWARNERORDERCENTER.COM"] = true;MD["TIRERACK.COM"] = true;MD["TOWERRECORDS.COM"] = new MerchantProp( new Array("CJ.COM", "TOWERFRANCHISES.COM"), true );MD["TRAVELANDLEISURE.COM"] = new MerchantProp( new Array("AMEXPUB.COM"), false );MD["TRAVELOCITY.COM"] = new MerchantProp( new Array("LMDEALS.COM"), false );MD["ULTIMATEOUTLET.COM"] = false;MD["VENUSBOOKCLUB.COM"] = true;MD["VICTORIASSECRET.COM"] = true;MD["VSDIAMONDBROKERS.COM"] = false;MD["WALMART.COM"] = false;MD["WARESONTHEWEB1.COM"] = new MerchantProp( new Array("CARLTONCARDS.COM"), false );MD["WARNERVIDEOCLUB.COM"] = new MerchantProp( new Array("TIMEWARNERORDERCENTER.COM"), true );MD["WATCHZONE.COM"] = false;MD["WBSHOP.COM"] = true;MD["WOLFCAMERA.COM"] = new MerchantProp( new Array("BORDERFREE.COM"), false );MD["WORLDBOOK.COM"] = false;MD["X10.COM"] = true;MD["YLIGHTING.COM"] = new MerchantProp( new Array("YAHOO.COM"), false );SD["ANIMATEDGREETINGS.COM"] = "1800FLOWERS.COM";SD["GREETME.COM"] = "1800FLOWERS.COM";SD["AMERICANGREETINGS.COM"] = "1800FLOWERS.COM";SD["EGREETINGS.COM"] = "1800FLOWERS.COM";SD["BLUEMOUNTAIN.COM"] = "1800FLOWERS.COM";SD["AMERICANGIRL.COM"] = "AMERICANGIRLSTORE.COM";SD["CALLOWAYGOLFPREOWNED.COM"] = "CALLAWAYGOLF.COM";SD["CNN.COM"] = "CNNSI.COM";SD["CDHQ.COM"] = "COLUMBIAHOUSE.COM";SD["CHDVD.COM"] = "COLUMBIAHOUSE.COM";SD["DISCOUNTINKJETS.COM"] = "DISCOUNTINKJET.COM";SD["DUNHAMSPORTS.COM"] = "DUNHAMSSPORTS.COM";SD["FISHERPRICE.COM"] = "FISHER-PRICESTORE.COM";SD["FISHER-PRICE.COM"] = "FISHER-PRICESTORE.COM";SD["GUMPSBYMAIL.COM"] = "GUMPS.COM";SD["HAMMACHERSCHLEMMER.COM"] = "HAMMACHER.COM";SD["HELZBERG.COM"] = "HELZBERGDIAMONDS.COM";SD["WORKOUTWAREHOUSE.COM"] = "ICONFITNESS.COM";SD["EJEWELRY.COM"] = "JEWELERS-SERVICES.COM";SD["KBKIDS.COM"] = "KBTOYS.COM";SD["FAMILYEDGE.COM"] = "KIDSEDGE.COM";SD["BLUELIGHT.COM"] = "KMART.COM";SD["SOUTHERNPROGRESS.COM"] = "PROGRESSIVEFARMER.COM";SD["RHINOVIDEO.COM"] = "RHINO.COM";SD["RHINOHANDMADE.COM"] = "RHINO.COM";SD["RHINO-EXPRESSCHECKOUT.COM"] = "RHINO.COM";SD["LIFESTYLEFASCINATION.COM"] = "SHOPLIFESTYLE.COM";SD["TSHIRTKING.COM"] = "T-SHIRTKING.COM";SD["WARNERVIDEO.COM"] = "WARNERVIDEOCLUB.COM";resHosts[0] = "edit.secure.yahoo.com";resHosts[1] = "payment.aol.com";resHosts[2] = "americanexpress.com";resHosts[3] = "citibank.com";resHosts[4] = "discovercard.com";resHosts[5] = "novusnet.com";resHosts[6] = "mbnanetaccess.com";resHosts[7] = "shopattwireless-shopattwireless.com";resHosts[8] = "LHJ.com";resHosts[9] = "https://www.llbean.com/webapp/wcs/stores/servlet/ShowRegistrationAccountMaintenance";resHosts[10] = "citi.com";resHosts[11] = "llbean-llbean.com";resHosts[12] = "amex.com";resHosts[13] = "xxx.com";resHosts[14] = "http://money.cnn.com";resHosts[15] = "netdeals.com";resHosts[16] = "store.aolshopdirect.com";resHosts[17] = "store.compuserve.com";resHosts[18] = "netscapestore.netscape.com";resHosts[19] = "store.icq.comstore.netscape.com";resHosts[20] = "netdeals.netscape.com";resHosts[21] = "storestage.netscape.com";resHosts[22] = "cd.netscape.com";resHosts[23] = "bankrate.com";resHosts[24] = "jcpenney.com";resHosts[25] = "http://www.newport-news.com/my/my_profile.asp";resHosts[26] = "microsoft.com";resHosts[27] = "https://www.micronexx.com/STORE/CLUB_STEVE/REGISTER/speedy_checkout.html";resHosts[28] = "mbna.com";resHosts[29] = "aolshop.com";resHosts[30] = "firstusa.com";resHosts[31] = "jcpenney.com/jcp/BillingDom.asp?action=CommitEdit";resHosts[32] = "https://www.agnesb.net/personalsetup.cfm";resHosts[33] = "jcpenney.com/jcp/BillingDom.asp?action=CommitAdd";resHosts[34] = "jcpenney.com/jcp/BillingDom.aspx?action=CommitAdd";resHosts[35] = "jcpenney.com/jcp/BillingDom.aspx?action=CommitEdit";resHosts[36] = "jcpenney.com/jcp/BillingIntl.asp?action=CommitAdd";resHosts[37] = "jcpenney.com/jcp/BillingIntl.asp?action=CommitEdit";resHosts[38] = "jcpenney.com/jcp/BillingIntl.aspx?action=CommitAdd";resHosts[39] = "jcpenney.com/jcp/BillingIntl.aspx?action=CommitEdit";resHosts[40] = "jcpenney.com/jcp/ShippingIntl.aspx?action=CommitAdd";resHosts[41] = "jcpenney.com/jcp/ShippingIntl.aspx?action=CommitEdit";resHosts[42] = "jcpenney.com/jcp/ShippingDom.aspx?action=CommitAdd";resHosts[43] = "jcpenney.com/jcp/ShippingDom.aspx?action=CommitEdit";resHosts[44] = "jcpenney.com/jcp/ShippingIntl.asp?action=CommitAdd";resHosts[45] = "jcpenney.com/jcp/ShippingIntl.asp?action=CommitEdit";resHosts[46] = "jcpenney.com/jcp/ShippingDom.asp?action=CommitAdd";resHosts[47] = "jcpenney.com/jcp/ShippingDom.asp?action=CommitEdit";resHosts[48] = "oldnavy-oldnavy.com";resHosts[49] = "https://www.petco.com/register2.asp";resHosts[50] = "http://www.personalcreations.com/myaccount/create_account.asp";resHosts[51] = "members.aol.com";resHosts[52] = "attws-attws.com";resHosts[53] = "target.com";resHosts[54] = "qccertify.aol.com";resHosts[55] = "aolcc.bankproduct.com";resHosts[56] = "more-more.com";}
////////// End of releases/03_07_30_1204_ie_AOL_US/ie/AOL/US/qcff/scripts/QcffLists.js


////////// Contents of releases/03_07_30_1204_ie_AOL_US/ie/AOL/US/qcff/scripts/QcffSites.js
function MerchantProp(cI,dY){this.cI=cI;this.dY=dY;}function QcffSites(){this.isQcffMappedDomain=isQcffMappedDomain;this.isQcffBillingDomain=isQcffBillingDomain;this.getQcffAliasedDomain=getQcffAliasedDomain;this.isQcffAliasedDomain=isQcffAliasedDomain;
this.isRestrictedSite=isRestrictedSite;this.checkDomainHasRules=checkDomainHasRules;bQ=new Array();eI=new Array();aN=new Array();QcffLists(aN,bQ,eI);function isQcffMappedDomain(domain){var eW=domain.toUpperCase();return(((typeof(aN[eW])!="undefined")||(
typeof(bQ[eW])!="undefined"))?true:false);}function isQcffBillingDomain(aV,gv){try{if(typeof(aN[aV])=="undefined"||typeof(aN[aV].cI)=="undefined")return false;for(index in aN[aV].cI){if(aN[aV].cI[index]==gv)return true;}return false;}catch(e){return false;
}}function getQcffAliasedDomain(bz){return((typeof(bQ[bz.toUpperCase()])!="undefined")?bQ[bz.toUpperCase()]:bz.toUpperCase());}function isQcffAliasedDomain(domain,bz){var fy=false;if(typeof(bQ[domain.toUpperCase()])!="undefined")fy=(bQ[domain.toUpperCase
()]==bz.toUpperCase());return fy;}function isRestrictedSite(g9){for(var i=0;i


////////// Contents of releases/03_07_30_1204_ie_AOL_US/ie/AOL/US/qcff/scripts/QcffLib.js
function QcffLib(){bJ=null;fv=null;eC=null;var dM=new RegExp("^([^:]+)://([^/\\\\]+)((/|\\\\)*.*)$");var gH=1;var f5=2;var gq=3;var g2=new RegExp("^([^@]*@)?([^:]+)(:[0-9]{0,5})?$");var gx=2;var gA=new RegExp(
"^(\\d{1,3}\\\.\\d{1,3}\\\.\\d{1,3}\\\.\\d{1,3})$");this.extractCurDomain=extractCurDomain;this.extractFullDomain=extractFullDomain;this.extractScheme=extractScheme;this.extractPath=extractPath;this.bL=new QcffSites();this.getDocument=getDocument;this.
getAllDocuments=getAllDocuments;this.getDomain=getDomain;this.getUrl=getUrl;this.hasCheckoutForm=hasCheckoutForm;this.getFormsData=getFormsData;this.isQcffMappedDomain=isQcffMappedDomain;this.isQcffBillingDomain=isQcffBillingDomain;this.
getQcffAliasedDomain=getQcffAliasedDomain;this.isQcffAliasedDomain=isQcffAliasedDomain;this.isRestrictedSite=isRestrictedSite;this.getAllForms=getAllForms;this.fillForm=fillForm;this.getFormFillResult=getFormFillResult;this.getCookieData=getCookieData;this
.setCookie=setCookie;this.getFormIdentificationCodes=getFormIdentificationCodes;this.getNodeList=getNodeList;this.getNoArgsUrl=getNoArgsUrl;this.errorReporting=errorReporting;this.getWinProcObj=getWinProcObj;this.debugMessage=debugMessage;this.
storeAllDocuments=storeAllDocuments;this.storeCurDomain=storeCurDomain;this.stringEndsWith=stringEndsWith;this.getXMLRoot=getXMLRoot;this.getNodeText=getNodeText;this.getNodeList=getNodeList;this.selectNodeWithPattern=selectNodeWithPattern;this.
createParser=createParser;this.a6=null;function getDocument(){return window.external.getTopDocument();}function storeCurDomain(){try{eC=this.extractCurDomain();}catch(e){debugMessage(QCFF_DBGSTATUS,"storeCurDomain : "+e.H);eC=null;}}function
storeAllDocuments(){fv=window.external.getAllDocuments();}function getAllDocuments(){return fv;}function getUrl(){try{var gQ=getAllDocuments();var gz=gQ.item(0);return gz.URL;}catch(e){return"";}}function getDomain(){return eC.toLowerCase();}function
extractCurDomain(){var domain="";try{var a9=this.extractFullDomain();var f3=gA.exec(a9);if(f3!=null){domain=a9;}else{var e4=(this.stringEndsWith(a9.toLowerCase(),".uk")?3:2);var dc=a9.lastIndexOf(".");while(e4>0){if(domain.length>0)domain="."+domain;if(dc
!=-1){domain=a9.substr(dc+1)+domain;a9=a9.substr(0,dc);dc=a9.lastIndexOf(".");}else{domain=a9+domain;break;}e4--;}while(domain.charAt(0)==".")domain=domain.substr(1);}}catch(e){qcffLib.debugMessage(QCFF_DBGSTATUS,"extractCurDomain()==> "+e.H);domain="";}
return domain;}function extractFullDomain(){try{var cb=dM.exec(getUrl());var fZ=g2.exec(cb[f5]);return fZ[gx];}catch(e){qcffLib.debugMessage(QCFF_DBGSTATUS,"extractFullDomain()==> "+e.H);return"";}}function extractScheme(){try{var cb=dM.exec(getUrl());
return cb[gH];}catch(e){qcffLib.debugMessage(QCFF_DBGSTATUS,"extractScheme()==> "+e.H);return"";}}function extractPath(){try{var cb=dM.exec(getUrl());var br=cb[gq];var fB=br.indexOf("?");if(fB!=-1)br=br.substr(0,fB);return br;}catch(e){qcffLib.debugMessage
(QCFF_DBGSTATUS,"extractPath()==> "+e.H);return"/";}}function getAllForms(){var ea=getAllDocuments();var aq=new Array();if(ea){var cC;for(var i=0;i0)return fu[0];else return null;}function errorReporting(gh,f1){var v=new Object();v["errorCode"]=gh;v["errorDesc"]=f1;v["siteDomain"]=qcffDriver.
getQcffShoppingDomain();var q=QCFF_SERVER+"/OH";var ay;var ah=new Request(ay,"membershipWin","requestForm");ah.get(q,v,1);}function debugMessage(gT,gp){if(gT==true)alert(gp);}}
////////// End of releases/03_07_30_1204_ie_AOL_US/ie/AOL/US/qcff/scripts/QcffLib.js


////////// Contents of releases/03_07_30_1204_ie_AOL_US/ie/AOL/US/qcff/scripts/QcffUserLib.js
function QcffUserLib(){this.getScreenName=getScreenName;this.setScreenName=setScreenName;this.getUserPrefs=getUserPrefs;this.setUserData=setUserData;this.getUserData=getUserData;this.setDecryptKey=setDecryptKey;this.getDecryptKey=getDecryptKey;this.
isWalletExpired=isWalletExpired;this.isQcffEnabled=isQcffEnabled;this.enableQcff=enableQcff;this.askAgainLater=askAgainLater;this.getInfoFromUserData=getInfoFromUserData;this.decryptUserData=decryptUserData;this.clearUserData=clearUserData;this.
getUserDataArry=getUserDataArry;this.bX="";var bq=null;var e1="wallet_key";var eH="_QCFFEnabled";function setScreenName(gn){if(this.bX=="")this.bX=gn;}function getScreenName(){return this.bX;}function getUserPrefs(){return true;}function setUserData(X,dG){
var f6=new ActiveXObject("Ebrowser.FatWallet");f6.setWallet(X,dG);}function getUserData(){return new ActiveXObject("Ebrowser.FatWallet").getWallet();}functi


0

Response Number 43
Name: Setter
Date: August 7, 2003 at 19:37:49 Pacific
Reply:

Hi bigkevin,

First, you have two viruses (see associated notes). One may have seriously compromised your computer. Remove the viruses if possible using an anti-virus program. Or an online AV scanner such as:
- Panda ActiveScan http://www.pandasoftware.es/activescan/activescan-com.asp
- Trend Micro Housecall http://housecall.antivirus.com/
Recommend Panda ActiveScan first, Trend HouseCall second, as the two best online scans, in that order.

Second, run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchgateway.net/search/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://stopxxxpics.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://stopxxxpics.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=2&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=2&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchgateway.net/search/%s (obfuscated)

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL = no
R3 - URLSearchHook: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - C:\PROGRA~1\COMMON~1\BTLINK\btlink.dll

****F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\Scandisk.exe
Added as a result of the GANDA.A VIRUS! – See http://www.symantec.com/avcenter/venc/data/w32.ganda.a@mm.html

****F1 - win.ini: run=C:\WINDOWS\Scandisk.exe
See GANDA.A VIRUS above

O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com

O2 - BHO: (no name) - {00000580-C637-11D5-831C-00105AD6ACF0} - C:\WINDOWS\MSView.dll
VX2 Transponder variant - See http://www.doxdesk.com/parasite/Transponder.html

O2 - BHO: (no name) - {63B78BC1-A711-4D46-AD2F-C581AC420D41} - C:\WINDOWS\System32\btiein.dll
HuntBar – See http://217.115.153.73/parasite/HuntBar.html

O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\Program Files\MediaLoads Enhanced\ME2.DLL
DownloadWare: Executes arbitrary code from advertisers and not considered to be adware but is a security risk (see http://and.doxdesk.com/parasite/DownloadWare.html). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent

O2 - BHO: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - C:\PROGRA~1\COMMON~1\BTLINK\btlink.dll
HuntBar – See http://217.115.153.73/parasite/HuntBar.html

O4 - HKLM\..\Run: [MediaLoads Installer] "C:\Program Files\DownloadWare\dw.exe" /H
See DownloadWare above

O4 - HKLM\..\Run: [DownloadWare] "C:\Program Files\DownloadWare\dw.exe" /H
See DownloadWare above

****O4 - HKLM\..\Run: [RunProg] C:\WINDOWS\System32\server.exe
Added as a result of the OPTIX.04.A VIRUS! See http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_OPTIX.04.A
This backdoor malware allows remote users to access and manipulate a compromised system.

O4 - HKLM\..\Run: [ShowBehind] C:\WINDOWS\sbnet\ShowBehind.exe
Advertisement display which can be stopped here http://www.showbehind.com/adremove.exe

****O4 - HKLM\..\Run: [MS Scandisk] C:\WINDOWS\Scandisk.exe
See GANDA.A VIRUS above

O4 - HKLM\..\Run: [uaipcsn] "C:\WINDOWS\System32\uaipcsn.exe"

****O4 - HKCU\..\Run: [MS Scandisk] C:\WINDOWS\Scandisk.exe
See GANDA.A VIRUS above

O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?

O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=2&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=2&s=

O16 - DPF: {1E89F686-B78D-4C85-9EFC-3474516E3FE2} - http://directplugin.com/plugin/111329.exe
O16 - DPF: {26E8361F-BCE7-4F75-A347-98C88B418322} - http://dst.trafficsyndicate.com/Dnl/T_50010/btiein.cab

O16 - DPF: {69FD62B1-0216-4C31-8D55-840ED86B7C8F} - http://installs.hotbar.com/installs/hotbar/programs/hotbar.cab

O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} - http://download.weatherbug.com/minibug/tricklers/AWS/minibuginstaller.cab
O16 - DPF: {A45F39DC-3608-4237-8F0E-139F1BC49464} - http://www.sexyplugin.com/diallerfiles/034891.exe
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} (loader Class) - http://dload.ipbill.com/del/loader.cab

O16 - DPF: {FC327B3F-377B-4CB7-8B61-27CD69816BC3} - http://www.clock-sync.com/ClockSyncAutoSYNC0007.cab


You should also do a Windows Update as there are currently security updates for both Windows XP and Internet Explorer.
-Platform: Windows XP is currently at SP1
-MSIE: Internet Explorer is currently at v6.00 SP1

--------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!


0

Response Number 44
Name: Setter
Date: August 7, 2003 at 19:58:19 Pacific
Reply:

Hi tom_m,

Run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL =

O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com

O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=1&s=

O16 - DPF: {54E7E082-1DA6-412E-96B5-C290FCEF5329} (DFRun Class) - http://webpdp.gator.com/v3/download/iegator_4090_hd3ptdmgainads.cab

O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} (loader Class) - http://dload.ipbill.com/del/loader.cab

You should also do a Windows Update as there are currently security updates for both Windows XP and Internet Explorer.
-Platform: Windows XP is currently at SP1
-MSIE: Internet Explorer is currently at v6.00 SP1

--------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!


0

Response Number 45
Name: Setter
Date: August 7, 2003 at 20:36:08 Pacific
Reply:

Hi JeffGuthrie,

Run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.xrenoder.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.searchv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://search.xrenoder.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/

O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com

O2 - BHO: Url Catcher - {CE31A1F7-3D90-4874-8FBE-A5D97F8BC8F1} - C:\PROGRA~1\BARGAI~1\bin\apuc.dll
Bargain Buddy, advertising spyware - See http://www.safersite.com/PestInfo/B/BargainBuddy.asp OR http://217.115.153.73/parasite/BargainBuddy.html

O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
ISTBar foistware – See http://www.doxdesk.com/parasite/ISTbar.html

O4 - HKLM\..\Run: [Bargains] C:\Program Files\Bargain Buddy\bin\bargains.exe
Bargain Buddy - See Above

O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=1&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=1&s=

O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab
O16 - DPF: {02C20140-76F8-4763-83D5-B660107B7A90} (Loader Class) - http://connect.online-dialer.com/MaConnect.cab


About the pop-up window "US from sa.payment.aol.com"
------------------------
Since you’re using AOhelL :-) Go to Settings, Preferences, Internet Options
Your browser properties will open and you'll see a tab for Shopping Assistant. Go there and uncheck the box.


You should also do a Windows Update as there are currently security updates for both Windows XP and Internet Explorer.
-Platform: Windows 2000 is currently at SP4
-MSIE: Internet Explorer is currently at v6.00 SP1

--------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!


0

Response Number 46
Name: Setter
Date: August 7, 2003 at 21:11:55 Pacific
Reply:

Hi craig123,

First, you have at least one virus (Identified by ****). Remove the virus (or viruses) using an anti-virus program. Or you can use an online AV scanner such as:
- Panda ActiveScan http://www.pandasoftware.es/activescan/activescan-com.asp
- Trend Micro Housecall http://housecall.antivirus.com/
Recommend Panda ActiveScan first, Trend HouseCall second, as the two best online scans, in that order.

Second, run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/

O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet5_20.dll
NewDotNet – See http://www.doxdesk.com/parasite/NewDotNet.html

O2 - BHO: WinShow module - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - C:\WINDOWS\winshow.dll
Winshow pop-up opener - See http://www.doxdesk.com/parasite/Winshow.html

****O4 - HKCU\..\Run: [explore] c:\windows\explore.exe
Added as a result of the NETBUS and other VIRUSES! See http://www.ikarus.at/english/vttrojan.htm#nb160

O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net

O16 - DPF: {C3FDA8CE-9414-4E33-AC6B-4922922259A5} - http://www.jambalala.com/movies.exe

O16 - DPF: {E9041F85-3C18-4A7E-A29D-E24F84B79BF1} - http://216.133.83.162/downloads/UGO20.exe

--------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!


0

Response Number 47
Name: Setter
Date: August 7, 2003 at 21:45:21 Pacific
Reply:

bigkevin, JeffGuthrie, craig123,

Dad Burn it, I forgot to have you all delete files after everything is fixed.
(Does not include virus files)

bigkevin,
Delete the folder MediaLoads Enhanced at C:\Program Files\MediaLoads Enhanced
Delete the folder DownloadWare at C:\Program Files\DownloadWare
Delete the folder sbnet at C:\WINDOWS\sbnet
Delete the file uaipcsn.exe at C:\WINDOWS\System32\uaipcsn.exe

JeffGuthrie,
Delete the folder BARGAI~1 at C:\PROGRA~1\BARGAI~1
Delete the folder ISTsvc at C:\Program Files\ISTsvc
Delete the folder Bargain Buddy at C:\Program Files\Bargain Buddy

craig123,
Delete the folder NewDotNet at C:\Program Files\NewDotNet


0

Response Number 48
Name: brockz
Date: August 8, 2003 at 05:36:50 Pacific
Reply:

Hi this is the whole log file! I have had this problem for a couple of weeks now and have tried loads of things, but no sucess :(. i was even going to reinstall windows last week. please help me.. thanks so much.

Logfile of HijackThis v1.96.0
Scan saved at 13:16:08, on 08/08/2003
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\PackethSvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\Explorer.exe
C:\WINNT\system32\cmd32.exe
C:\WINNT\loadqm.exe
C:\Program Files\Messenger Plus! Extension\MsgPlus.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.exe
C:\WINNT\System32\internat.exe
C:\WINNT\System32\rundll32.exe
C:\America Online 6.0\aoltray.exe
C:\America Online 6.0\waol.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.searching-4u.com/search_page.php
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Default_Search_URL = http://www.search-explorer.net/go/to.php?id=g404
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.searching-4u.com/search_page.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searching-4u.com/search_page.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.searching-4u.com/search_page.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searching-4u.com/search_page.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\System32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/
F0 - system.ini: Shell=Explorer.exe C:\WINNT\System32\cmd32.exe
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MessengerPlus] "C:\Program Files\Messenger Plus! Extension\MsgPlus.exe"
O4 - HKLM\..\Run: [PAV.EXE] C:\WINNT
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OCAudioIni] C:\Program Files\One-click Audio Converter\OCAudioIni.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\RunServices: [CMD] cmd32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [327962] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327962.cpl
O4 - HKCU\..\Run: [65770] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65770.cpl
O4 - HKCU\..\Run: [65768] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65768.cpl
O4 - HKCU\..\Run: [65828] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65828.cpl
O4 - HKCU\..\Run: [65788] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65788.cpl
O4 - HKCU\..\Run: [65800] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65800.cpl
O4 - HKCU\..\Run: [131256] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131256.cpl
O4 - HKCU\..\Run: [65910] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65910.cpl
O4 - HKCU\..\Run: [65804] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65804.cpl
O4 - HKCU\..\Run: [65778] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65778.cpl
O4 - HKCU\..\Run: [131240] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131240.cpl
O4 - HKCU\..\Run: [65782] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65782.cpl
O4 - HKCU\..\Run: [65790] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65790.cpl
O4 - HKCU\..\Run: [196802] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196802.cpl
O4 - HKCU\..\Run: [65832] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65832.cpl
O4 - HKCU\..\Run: [65806] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65806.cpl
O4 - HKCU\..\Run: [196892] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196892.cpl
O4 - HKCU\..\Run: [131334] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131334.cpl
O4 - HKCU\..\Run: [131196] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131196.cpl
O4 - HKCU\..\Run: [131212] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131212.cpl
O4 - HKCU\..\Run: [196844] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196844.cpl
O4 - HKCU\..\Run: [131284] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131284.cpl
O4 - HKCU\..\Run: [131214] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131214.cpl
O4 - HKCU\..\Run: [131342] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131342.cpl
O4 - HKCU\..\Run: [131276] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131276.cpl
O4 - HKCU\..\Run: [131316] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131316.cpl
O4 - HKCU\..\Run: [196856] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196856.cpl
O4 - HKCU\..\Run: [196834] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196834.cpl
O4 - HKCU\..\Run: [131330] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131330.cpl
O4 - HKCU\..\Run: [196886] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196886.cpl
O4 - HKCU\..\Run: [131388] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131388.cpl
O4 - HKCU\..\Run: [131302] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131302.cpl
O4 - HKCU\..\Run: [131324] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131324.cpl
O4 - HKCU\..\Run: [131390] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131390.cpl
O4 - HKCU\..\Run: [131286] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131286.cpl
O4 - HKCU\..\Run: [131344] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131344.cpl
O4 - HKCU\..\Run: [131396] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131396.cpl
O4 - HKCU\..\Run: [131394] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131394.cpl
O4 - HKCU\..\Run: [262378] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262378.cpl
O4 - HKCU\..\Run: [131322] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131322.cpl
O4 - HKCU\..\Run: [131378] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131378.cpl
O4 - HKCU\..\Run: [131294] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131294.cpl
O4 - HKCU\..\Run: [196944] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196944.cpl
O4 - HKCU\..\Run: [131200] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131200.cpl
O4 - HKCU\..\Run: [196828] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196828.cpl
O4 - HKCU\..\Run: [196826] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196826.cpl
O4 - HKCU\..\Run: [131312] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131312.cpl
O4 - HKCU\..\Run: [196924] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196924.cpl
O4 - HKCU\..\Run: [196920] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196920.cpl
O4 - HKCU\..\Run: [131406] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131406.cpl
O4 - HKCU\..\Run: [65938] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65938.cpl
O4 - HKCU\..\Run: [131408] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131408.cpl
O4 - HKCU\..\Run: [131368] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131368.cpl
O4 - HKCU\..\Run: [196938] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196938.cpl
O4 - HKCU\..\Run: [328004] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\328004.cpl
O4 - HKCU\..\Run: [262368] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262368.cpl
O4 - HKCU\..\Run: [196922] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196922.cpl
O4 - HKCU\..\Run: [131186] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131186.cpl
O4 - HKCU\..\Run: [196818] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196818.cpl
O4 - HKCU\..\Run: [262438] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262438.cpl
O4 - HKCU\..\Run: [131386] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131386.cpl
O4 - HKCU\..\Run: [131402] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131402.cpl
O4 - HKCU\..\Run: [131382] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131382.cpl
O4 - HKCU\..\Run: [131370] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131370.cpl
O4 - HKCU\..\Run: [262472] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262472.cpl
O4 - HKCU\..\Run: [196914] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196914.cpl
O4 - HKCU\..\Run: [262482] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262482.cpl
O4 - HKCU\..\Run: [131410] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131410.cpl
O4 - HKCU\..\Run: [131268] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131268.cpl
O4 - HKCU\..\Run: [131208] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131208.cpl
O4 - HKCU\..\Run: [262460] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262460.cpl
O4 - HKCU\..\Run: [65866] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65866.cpl
O4 - HKCU\..\Run: [131318] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131318.cpl
O4 - HKCU\..\Run: [262352] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262352.cpl
O4 - HKCU\..\Run: [131288] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131288.cpl
O4 - HKCU\..\Run: [65914] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65914.cpl
O4 - HKCU\..\Run: [131380] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131380.cpl
O4 - HKCU\..\Run: [196930] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196930.cpl
O4 - HKCU\..\Run: [262374] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262374.cpl
O4 - HKCU\..\Run: [262350] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262350.cpl
O4 - HKCU\..\Run: [262404] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262404.cpl
O4 - HKCU\..\Run: [262372] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262372.cpl
O4 - HKCU\..\Run: [196902] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196902.cpl
O4 - HKCU\..\Run: [262470] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262470.cpl
O4 - HKCU\..\Run: [327938] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327938.cpl
O4 - HKCU\..\Run: [196748] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196748.cpl
O4 - HKCU\..\Run: [524428] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\524428.cpl
O4 - HKCU\..\Run: [196722] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196722.cpl
O4 - HKCU\..\Run: [196852] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196852.cpl
O4 - HKCU\..\Run: [196832] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196832.cpl
O4 - HKCU\..\Run: [262354] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262354.cpl
O4 - HKCU\..\Run: [131308] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131308.cpl
O4 - HKCU\..\Run: [327896] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327896.cpl
O4 - HKCU\..\Run: [459080] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\459080.cpl
O4 - HKCU\..\Run: [458978] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\458978.cpl
O4 - HKCU\..\Run: [393462] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393462.cpl
O4 - HKCU\..\Run: [262382] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262382.cpl
O4 - HKCU\..\Run: [131270] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131270.cpl
O4 - HKCU\..\Run: [196866] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196866.cpl
O4 - HKCU\..\Run: [393500] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393500.cpl
O4 - HKCU\..\Run: [196862] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196862.cpl
O4 - HKCU\..\Run: [393512] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393512.cpl
O4 - HKCU\..\Run: [196948] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196948.cpl
O4 - HKCU\..\Run: [262376] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262376.cpl
O4 - HKCU\..\Run: [262362] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262362.cpl
O4 - HKCU\..\Run: [262396] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262396.cpl
O4 - HKCU\..\Run: [196880] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196880.cpl
O4 - HKCU\..\Run: [327894] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327894.cpl
O4 - HKCU\..\Run: [327934] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327934.cpl
O4 - HKCU\..\Run: [393474] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393474.cpl
O4 - HKCU\..\Run: [262348] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262348.cpl
O4 - HKCU\..\Run: [131184] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131184.cpl
O4 - HKCU\..\Run: [131518] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131518.cpl
O4 - HKCU\..\Run: [262386] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262386.cpl
O4 - HKCU\..\Run: [393458] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393458.cpl
O4 - HKCU\..\Run: [196896] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196896.cpl
O4 - HKCU\..\Run: [131258] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131258.cpl
O4 - HKCU\..\Run: [327956] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327956.cpl
O4 - HKCU\..\Run: [196840] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196840.cpl
O4 - HKCU\..\Run: [590060] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\590060.cpl
O4 - HKCU\..\Run: [197008] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\197008.cpl
O4 - HKCU\..\Run: [328012] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\328012.cpl
O4 - HKCU\..\Run: [459082] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\459082.cpl
O4 - HKCU\..\Run: [196784] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196784.cpl
O4 - HKCU\..\Run: [393444] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393444.cpl
O4 - HKCU\..\Run: [131362] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131362.cpl
O4 - HKCU\..\Run: [327852] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327852.cpl
O4 - HKCU\..\Run: [327918] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327918.cpl
O4 - HKCU\..\Run: [131252] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131252.cpl
O4 - HKCU\..\Run: [196848] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196848.cpl
O4 - HKCU\..\Run: [196822] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196822.cpl
O4 - HKCU\..\Run: [327942] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327942.cpl
O4 - HKCU\..\Run: [196918] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196918.cpl
O4 - HKCU\..\Run: [196820] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196820.cpl
O4 - HKCU\..\Run: [196766] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196766.cpl
O4 - HKCU\..\Run: [262388] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262388.cpl
O4 - HKCU\..\Run: [262406] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262406.cpl
O4 - HKCU\..\Run: [196928] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196928.cpl
O4 - HKCU\..\Run: [131372] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131372.cpl
O4 - HKCU\..\Run: [458980] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\458980.cpl
O4 - HKCU\..\Run: [131260] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131260.cpl
O4 - HKCU\..\Run: [327936] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327936.cpl
O4 - HKCU\..\Run: [458932] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\458932.cpl
O4 - HKCU\..\Run: [262340] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262340.cpl
O4 - HKCU\..\Run: [262256] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262256.cpl
O4 - HKCU\..\Run: [262446] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262446.cpl
O4 - HKCU\..\Run: [196926] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196926.cpl
O4 - HKCU\..\Run: [65786] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65786.cpl
O4 - HKCU\..\Run: [65840] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65840.cpl
O4 - HKCU\..\Run: [65818] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65818.cpl
O4 - HKCU\..\Run: [196830] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196830.cpl
O4 - HKCU\..\Run: [327948] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327948.cpl
O4 - HKCU\..\Run: [196890] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196890.cpl
O4 - HKCU\..\Run: [262428] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262428.cpl
O4 - HKCU\..\Run: [262442] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262442.cpl
O4 - HKCU\..\Run: [131412] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131412.cpl
O4 - HKCU\..\Run: [65878] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65878.cpl
O4 - HKCU\..\Run: [262476] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262476.cpl
O4 - HKCU\..\Run: [8454372] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\8454372.cpl
O4 - HKCU\..\Run: [262414] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262414.cpl
O4 - HKCU\..\Run: [65858] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65858.cpl
O4 - HKCU\..\Run: [196872] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196872.cpl
O4 - HKCU\..\Run: [393486] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393486.cpl
O4 - HKCU\..\Run: [196906] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196906.cpl
O4 - HKCU\..\Run: [131364] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131364.cpl
O4 - HKCU\..\Run: [131292] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131292.cpl
O4 - HKCU\..\Run: [131278] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131278.cpl
O4 - HKCU\..\Run: [197030] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\197030.cpl
O4 - HKCU\..\Run: [65772] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65772.cpl
O4 - HKCU\..\Run: [327954] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327954.cpl
O4 - HKCU\..\Run: [327968] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327968.cpl
O4 - HKCU\..\Run: [65798] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65798.cpl
O4 - HKCU\..\Run: [327908] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327908.cpl
O4 - HKCU\..\Run: [327842] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327842.cpl
O4 - HKCU\..\Run: [131340] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131340.cpl
O4 - HKCU\..\Run: [196874] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196874.cpl
O4 - HKCU\..\Run: [131326] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131326.cpl
O4 - HKCU\..\Run: [327920] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327920.cpl
O4 - HKCU\..\Run: [327868] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327868.cpl
O4 - HKCU\..\Run: [459004] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\459004.cpl
O4 - HKCU\..\Run: [131400] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131400.cpl
O4 - HKCU\..\Run: [131314] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131314.cpl
O4 - HKCU\..\Run: [524474] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\524474.cpl
O4 - HKCU\..\Run: [131366] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131366.cpl
O4 - HKCU\..\Run: [131418] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131418.cpl
O4 - HKCU\..\Run: [196962] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196962.cpl
O4 - HKCU\..\Run: [196868] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196868.cpl
O4 - HKCU\..\Run: [393438] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393438.cpl
O4 - HKCU\..\Run: [131262] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131262.cpl
O4 - HKCU\..\Run: [393542] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393542.cpl
O4 - HKCU\..\Run: [262392] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262392.cpl
O4 - HKCU\..\Run: [458928] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\458928.cpl
O4 - HKCU\..\Run: [196842] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196842.cpl
O4 - HKCU\..\Run: [65880] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65880.cpl
O4 - HKCU\..\Run: [327928] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327928.cpl
O4 - HKCU\..\Run: [524492] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\524492.cpl
O4 - HKCU\..\Run: [196810] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196810.cpl
O4 - HKCU\..\Run: [393432] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393432.cpl
O4 - HKCU\..\Run: [131454] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131454.cpl
O4 - HKCU\..\Run: [262346] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262346.cpl
O4 - HKCU\..\Run: [196824] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196824.cpl
O4 - HKCU\..\Run: [459008] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\459008.cpl
O4 - HKCU\..\Run: [327848] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327848.cpl
O4 - HKCU\..\Run: [131384] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131384.cpl
O4 - HKCU\..\Run: [590034] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\590034.cpl
O4 - HKCU\..\Run: [1114426] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\1114426.cpl
O4 - HKCU\..\Run: [458984] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\458984.cpl
O4 - HKCU\..\Run: [131244] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131244.cpl
O4 - HKCU\..\Run: [327926] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327926.cpl
O4 - HKCU\..\Run: [196894] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196894.cpl
O4 - HKCU\..\Run: [327800] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327800.cpl
O4 - HKCU\..\Run: [65854] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65854.cpl
O4 - HKCU\..\Run: [131404] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131404.cpl
O4 - HKCU\..\Run: [65846] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65846.cpl
O4 - HKCU\..\Run: [196860] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196860.cpl
O4 - HKCU\..\Run: [458994] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\458994.cpl
O4 - HKCU\..\Run: [458970] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\458970.cpl
O4 - HKCU\..\Run: [262344] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262344.cpl
O4 - HKCU\..\Run: [65836] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65836.cpl
O4 - HKCU\..\Run: [327906] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327906.cpl
O4 - HKCU\..\Run: [262360] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262360.cpl
O4 - HKCU\..\Run: [262480] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262480.cpl
O4 - HKCU\..\Run: [459026] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\459026.cpl
O4 - HKCU\..\Run: [262416] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262416.cpl
O4 - HKCU\..\Run: [262484] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262484.cpl
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [65856] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65856.cpl
O4 - HKCU\..\Run: [65918] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65918.cpl
O4 - HKCU\..\Run: [262400] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262400.cpl
O4 - HKCU\..\Run: [131398] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131398.cpl
O4 - HKCU\..\Run: [262452] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262452.cpl
O4 - HKCU\..\Run: [196878] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196878.cpl
O4 - HKCU\..\Run: [655572] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\655572.cpl
O4 - HKCU\..\Run: [65830] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65830.cpl
O4 - HKCU\..\Run: [65876] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65876.cpl
O4 - HKCU\..\Run: [65908] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65908.cpl
O4 - HKCU\..\Run: [262402] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262402.cpl
O4 - HKCU\..\Run: [327878] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327878.cpl
O4 - HKCU\..\Run: [327884] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327884.cpl
O4 - HKCU\..\Run: [65924] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65924.cpl
O4 - HKCU\..\Run: [65826] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65826.cpl
O4 - HKCU\..\Run: [458936] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\458936.cpl
O4 - HKCU\..\Run: [393492] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393492.cpl
O4 - HKCU\..\Run: [327974] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327974.cpl
O4 - HKCU\..\Run: [196876] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196876.cpl
O4 - HKCU\..\Run: [262322] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262322.cpl
O4 - HKCU\..\Run: [196764] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196764.cpl
O4 - HKCU\..\Run: [262308] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262308.cpl
O4 - HKCU\..\Run: [131462] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131462.cpl
O4 - HKCU\..\Run: [131428] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131428.cpl
O4 - HKCU\..\Run: [328020] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\328020.cpl
O4 - HKCU\..\Run: [393426] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393426.cpl
O4 - HKCU\..\Run: [459060] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\459060.cpl
O4 - HKCU\..\Run: [262456] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262456.cpl
O4 - HKCU\..\Run: [262408] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262408.cpl
O4 - HKCU\..\Run: [524518] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\524518.cpl
O4 - HKCU\..\Run: [262444] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262444.cpl
O4 - HKCU\..\Run: [196850] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196850.cpl
O4 - HKCU\..\Run: [393472] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393472.cpl
O4 - HKCU\..\Run: [196814] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196814.cpl
O4 - HKCU\..\Run: [66024] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\66024.cpl
O4 - HKCU\..\Run: [262410] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262410.cpl
O4 - HKCU\..\Run: [328002] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\328002.cpl
O4 - HKCU\..\Run: [65974] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65974.cpl
O4 - HKCU\..\Run: [131346] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131346.cpl
O4 - HKCU\..\Run: [196864] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196864.cpl
O4 - HKCU\..\Run: [458988] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\458988.cpl
O4 - HKCU\..\Run: [196898] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196898.cpl
O4 - HKCU\..\Run: [327924] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327924.cpl
O4 - HKCU\..\Run: [524506] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\524506.cpl
O4 - HKCU\..\Run: [131350] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131350.cpl
O4 - HKCU\..\Run: [196932] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196932.cpl
O4 - HKCU\..\Run: [131356] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131356.cpl
O4 - HKCU\..\Run: [393436] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393436.cpl
O4 - HKCU\..\Run: [196854] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196854.cpl
O4 - HKCU\..\Run: [196946] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196946.cpl
O4 - HKCU\..\Run: [262328] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262328.cpl
O4 - HKCU\..\Run: [65942] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65942.cpl
O4 - HKCU\..\Run: [196770] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196770.cpl
O4 - HKCU\..\Run: [327964] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327964.cpl
O4 - HKCU\..\Run: [327882] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327882.cpl
O4 - HKCU\..\Run: [327966] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327966.cpl
O4 - HKCU\..\Run: [393518] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393518.cpl
O4 - HKCU\..\Run: [262300] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262300.cpl
O4 - HKCU\..\Run: [196816] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196816.cpl
O4 - HKCU\..\Run: [65920] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65920.cpl
O4 - HKCU\..\Run: [524516] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\524516.cpl
O4 - HKCU\..\Run: [131352] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131352.cpl
O4 - HKCU\..\Run: [327872] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327872.cpl
O4 - HKCU\..\Run: [327932] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327932.cpl
O4 - HKCU\..\Run: [131282] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131282.cpl
O4 - HKCU\..\Run: [459000] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\459000.cpl
O4 - HKCU\..\Run: [196884] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\196884.cpl
O4 - HKCU\..\Run: [328128] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\328128.cpl
O4 - HKCU\..\Run: [327890] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327890.cpl
O4 - HKCU\..\Run: [327892] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327892.cpl
O4 - HKCU\..\Run: [262432] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\262432.cpl
O4 - HKCU\..\Run: [327990] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327990.cpl
O4 - HKCU\..\Run: [65808] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65808.cpl
O4 - HKCU\..\Run: [65976] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65976.cpl
O4 - HKCU\..\Run: [131572] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131572.cpl
O4 - HKCU\..\Run: [393430] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393430.cpl
O4 - Startup: America Online 6.0 Tray Icon.lnk = C:\America Online 6.0\aoltray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE88603C-1277-4CB9-886D-54C6DC77665D}: NameServer = 195.93.35.134



0

Response Number 49
Name: doomkult
Date: August 8, 2003 at 07:53:24 Pacific
Reply:

Hi there. I am having a problem with my computer similar to those listed above. Any time i type in an internet address into AOL I am redirected to something called "http://vrape.hardloved.com". I am not sure where the heck I picked this up but its really bothersome. I used "Hijack This" and here is my log, any help would be greatly appreciated. Thanks!

Logfile of HijackThis v1.96.0
Scan saved at 10:37:15 AM, on 8/8/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\DELLMMKB.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\America Online 8.0\aoltray.exe
C:\Program Files\Netropa\OSD.exe
C:\Program Files\AOL Companion\companion.exe
C:\Program Files\America Online 8.0\aol.exe
C:\Program Files\America Online 8.0\waol.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Documents and Settings\Michael\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/WINDOWS/system32/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\system32\search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=2&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\system32\search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=2&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=2&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchv.com/search.php?qq=%s (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://super-spider.com/main/hp.php
O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.exe /P19 "EPSON Stylus CX3200" /O6 "USB002" /M "Stylus CX3200"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=2&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=2&s=
O16 - DPF: {28F00B0F-DC4E-11D3-ABEC-005004A44EEB} (Register Class) - http://content.hiwirenetworks.net/inbrowser/cabfiles/4.1.1/Hiwire.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (YBIOCtrl Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/yiebio4028.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C058CDF5-5F17-4F72-91F8-DD334DACA0E5}: NameServer = 205.188.196.4


0

Response Number 50
Name: T Waf
Date: August 8, 2003 at 10:19:04 Pacific
Reply:

I am having a problem with my computer similar to those listed above. Any time I type in an internet address into AOL I am redirected to something called "http://vrape.hardloved.com". I used "Hijack This" and here is my log, any help would be greatly appreciated. Thanks!

Logfile of HijackThis v1.96.0
Scan saved at 9:19:24 AM, on 8/8/2003
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\ibmpmsvc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\MS\SMS\CLICOMP\RemCtrl\Wuser32.exe
C:\WINNT\MS\SMS\clicomp\apa\Bin\smsapm32.exe
C:\WINNT\Explorer.exe
C:\WINNT\System32\tp4serv.exe
C:\WINNT\LTSMMSG.exe
C:\WINNT\System32\PRPCUI.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.exe
C:\WINNT\System32\qttask.exe
C:\WINNT\MS\SMS\CORE\BIN\LAUNCH32.exe
C:\WINNT\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\Program Files\ClearSearch\Loader.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Program Files\Microsoft Office\Office\OSA.exe
C:\Program Files\America Online 7.0\aoltray.exe
C:\WINNT\MS\SMS\CLICOMP\SWDist32\bin\smsmon32.exe
C:\Program Files\America Online 7.0\waol.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\tjwaffle\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.martfinder.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchv.com/5/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.searchv.com/5/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://search.unipages.cc/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchv.com/5/search.php?qq=%s (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\System32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.ewebsearch.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/
O2 - BHO: WinShow module - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - C:\WINNT\winshow.dll
O2 - BHO: Clear Search - {947E6D5A-4B9F-4CF4-91B3-562CA8D03313} - C:\Program Files\ClearSearch\IE_ClrSch.DLL
O2 - BHO: (no name) - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\VT_Run\IEHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [tourpath] regedit /s c:\winnt\tour.reg
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.exe
O4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.exe -CHECK
O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.exe
O4 - HKLM\..\Run: [QuickTime Task] C:\WINNT\System32\qttask.exe
O4 - HKLM\..\Run: [SMS Application Launcher] C:\WINNT\MS\SMS\CORE\BIN\LAUNCH32.exe
O4 - HKLM\..\Run: [SetTravelMode] C:\WINNT\SetTravelMode.exe /s
O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [ClrSchLoader] C:\Program Files\ClearSearch\Loader.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=2&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=2&s=
O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} (RdxIE Class) - http://207.188.7.150/057bf91e1e7480e68423/netzip/RdxIE.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20011217/qtinstall.info.apple.com/qt505/us/win/QuickTimeInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,64/mcinsctl.cab
O16 - DPF: {6BD4FB43-470E-11D2-B99D-00104B02C956} (AtDownloadIE Class) - http://beckman.webex.com/client/webex/atbootie.cab
O16 - DPF: {A1DC3241-B122-195F-B21A-000000000000} - http://pluginaccess.com/cd/Browser_Plugin.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,13/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - http://beckman.webex.com/client/latest/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = beckman.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3E3F64F-5CA1-411D-8135-0535045B3781}: NameServer = 198.81.16.134
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = beckman.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = beckman.com
O19 - User stylesheet: c:\winnt\java\my.css



0

Response Number 51
Name: Setter
Date: August 8, 2003 at 10:36:24 Pacific
Reply:

Hi brockz,

First, you have at least three viruses (Identified by ****). Remove the or viruses using an anti-virus program or the removal instructions provided with the links. Or you can use an online AV scanner such as:
- Panda ActiveScan http://www.pandasoftware.es/activescan/activescan-com.asp
- Trend Micro Housecall http://housecall.antivirus.com/
Recommend Panda ActiveScan first, Trend HouseCall second, as the two best online scans, in that order.
You really should be running a resident AV program anyway.

Second, run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.


R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.searching-4u.com/search_page.php
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Default_Search_URL = http://www.search-explorer.net/go/to.php?id=g404
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.searching-4u.com/search_page.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searching-4u.com/search_page.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.searching-4u.com/search_page.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searching-4u.com/search_page.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=1&s=

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=1&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/

****F0 - system.ini: Shell=Explorer.exe C:\WINNT\System32\cmd32.exe

****O4 - HKLM\..\Run: [PAV.EXE] C:\WINNT
Added as a result of the KITRO.D - See http://securityresponse.symantec.com/avcenter/venc/data/w32.kitro.d.worm.html (or ARGEN.A – See http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_ARGEN.A&VSect=T ) VIRUS!.

****O4 - HKLM\..\RunServices: [CMD] cmd32.exe
Added as a result of the P2P.TANKED See http://www.viruslibrary.com/virusinfo/Worm.P2P.Tanked.htm VIRUS!


------------------
All these O4 entries (Entry format [rundll32.exe shell32.dll, Control_RunDLL ...123456.cpl] where 123456 can be any random 3 to 6 digit number) are added as a result of the KITRO.C - See http://securityresponse.symantec.com/avcenter/venc/data/w32.kitro.c.worm.html (or DANDI.A – See http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DANDI.A&VSect=T ) VIRUS!

**** ALL
O4 - HKCU\..\Run: [327962] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327962.cpl
O4 - HKCU\..\Run: [65770] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65770.cpl
O4 - HKCU\..\Run: [65768] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65768.cpl
O4 - HKCU\..\Run: [65828] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65828.cpl
O4 - HKCU\..\Run: [65788] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65788.cpl
O4 - HKCU\..\Run: [65800] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65800.cpl
O4 - HKCU\..\Run: [131256] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131256.cpl
O4 - HKCU\..\Run: [65910] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65910.cpl

(I did not list a whole bunch of these entries as the problem is the same)

O4 - HKCU\..\Run: [65976] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65976.cpl
O4 - HKCU\..\Run: [131572] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131572.cpl
O4 - HKCU\..\Run: [393430] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393430.cpl
-----------------


You should also do a Windows Update as there are currently security updates for both Windows XP and Internet Explorer.
-Platform: Windows 2000 is currently at SP4
-MSIE: Internet Explorer is currently at v6.00 SP1

--------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!


0

Response Number 52
Name: Setter
Date: August 8, 2003 at 10:49:54 Pacific
Reply:

Hi doomkult,

Run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=2&s=

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=2&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vrape.hardloved.com/top/search.php?id=2&s=

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=2&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://vrape.hardloved.com/top/search.php?id=2&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchv.com/search.php?qq=%s (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://super-spider.com/main/hp.php

O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com

O2 - BHO: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=2&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=2&s=

O16 - DPF: {28F00B0F-DC4E-11D3-ABEC-005004A44EEB} (Register Class) - http://content.hiwirenetworks.net/inbrowser/cabfiles/4.1.1/Hiwire.cab


You should also do a Windows Update as there are currently security updates for both Windows XP and Internet Explorer.
-Platform: Windows XP is currently at SP1
-MSIE: Internet Explorer is currently at SP1


--------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!


0

Response Number 53
Name: Setter
Date: August 8, 2003 at 11:26:59 Pacific
Reply:

Hi T Waf,

Run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.martfinder.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchv.com/5/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.searchv.com/5/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://search.unipages.cc/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchv.com/5/search.php?qq=%s (obfuscated)

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.ewebsearch.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/

O2 - BHO: WinShow module - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - C:\WINNT\winshow.dll
Winshow/searchv.com Hijacker - See http://www.doxdesk.com/parasite/Winshow.html

O2 - BHO: Clear Search - {947E6D5A-4B9F-4CF4-91B3-562CA8D03313} - C:\Program Files\ClearSearch\IE_ClrSch.DLL
Clearsearch variant of IGetNet - See http://www.doxdesk.com/parasite/IGetNet.html

O2 - BHO: (no name) - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\VT_Run\IEHelper.dll

O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
ISTBar foistware -- See http://www.doxdesk.com/parasite/ISTbar.html

O4 - HKLM\..\Run: [ClrSchLoader] C:\Program Files\ClearSearch\Loader.exe
Clearsearch variant of IGetNet - See http://www.doxdesk.com/parasite/IGetNet.html

O13 - DefaultPrefix: http://vrape.hardloved.com/top/search.php?id=2&s=
O13 - WWW Prefix: http://vrape.hardloved.com/top/search.php?id=2&s=

O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab

O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} (RdxIE Class) - http://207.188.7.150/057bf91e1e7480e68423/netzip/RdxIE.cab

O16 - DPF: {A1DC3241-B122-195F-B21A-000000000000} - http://pluginaccess.com/cd/Browser_Plugin.cab

O19 - User stylesheet: c:\winnt\java\my.css


You should also do a Windows Update as there are currently security updates for both Windows 2000 and Internet Explorer.
-Platform: Windows 2000 is currently at SP4
-MSIE: Internet Explorer is currently at V6.00 SP1

--------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051 In addition to using SpywareBlaster (mentioned in the thread) I would also use SpywareGuard http://www.wilderssecurity.net/spywareguard.html

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!


0

Response Number 54
Name: T Waf
Date: August 8, 2003 at 12:43:30 Pacific
Reply:

Thank You! Thank You! Thank You!
Your suggestions worked! No more problems!


0

Response Number 55
Name: Steve Harris
Date: August 8, 2003 at 14:40:56 Pacific
Reply:

Hi out there...

I really hope you guys can help me out...

I found out I had the CWS Hijack and so I downloaded and ran CW Shredder which cured the problem - BUT - now my IE5 scrolling has just started to become really jerky - not the smooth movement when pressing the up and down arrow keys!! and there is a slight delay when clicking on a link on a web page to it actually pressing the link...!!!

It's making using the Net a real pain!!

Please help as I don't want to have to reformat and install just yet!!!

Regards

Steve Harris
P266 Win 98SE


0

Response Number 56
Name: Setter
Date: August 8, 2003 at 16:02:23 Pacific
Reply:

Hi Steve Harris,

I suggest going to http://www.tomcoyote.org/hjt/ and downloading HijackThis. After starting HijackThis, click the scan button which will change into a save log button. Save the logfile and also copy and paste the results back here in this thread. Most items reported by HijackThis are valid, so don’t fix anything yet.


0

Response Number 57
Name: Steve Harris
Date: August 9, 2003 at 04:49:39 Pacific
Reply:

Hi again,

Here is the log file from Hijack this.. I hope you can spot something untoward as my IE5 has definitely slowed down as if something is "sitting on top of it"

Here's the logfile... Regards Steve

Logfile of HijackThis v1.96.0
Scan saved at 12:43:11, on 09/08/2003
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\PROGRAM FILES\COMMON FILES\EPSON\EBAPI\SAGENT2.exe
C:\PROGRAM FILES\NORTON ANTIVIRUS\RTVSCN95.exe
C:\PROGRAM FILES\NORTON ANTIVIRUS\DEFWATCH.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.exe
C:\WINDOWS\SYSTEM\RPCSS.exe
C:\WINDOWS\SYSTEM\RNAAPP.exe
C:\WINDOWS\SYSTEM\TAPISRV.exe
C:\WINDOWS\EXPLORER.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\WINDOWS\SYSTEM\ATICWD32.exe
C:\WINDOWS\SYSTEM\ATITASK.exe
C:\PROGRAM FILES\FARSTONE\VIRTUALDRIVE\VDTASK.exe
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.exe
C:\PROGRAM FILES\NORTON ANTIVIRUS\VPTRAY.exe
C:\TEMP\FREERAM XP PRO 1.11.exe
C:\WINDOWS\SYSTEM\DSLAGENT.exe
C:\WINDOWS\LOADQM.exe
C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.exe
C:\PROGRAM FILES\COMMON FILES\ADAPTEC SHARED\CREATECD\CREATECD50.exe
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZAPRO.exe
C:\TEMP\TRANS\TRANSPARENTW.exe
C:\TEMP\THE BUTTON\PTFB.exe
C:\PROGRAM FILES\PLANNET CRAFTERS\FLYWHEEL\FLYWHEEL.exe
C:\PROGRAM FILES\UNISYN\AUTOMATE4\AUTOMATE.exe
C:\PROGRAM FILES\WONDERFUL\WONDERFL.exe
C:\PROGRAM FILES\SONY HANDHELD\HOTSYNC.exe
C:\PROGRAM FILES\GAJITS\DLGXRSIZER\DLGXRSIZER.exe
C:\PROGRAM FILES\TRAYICON STANDARD\TS.exe
C:\PROGRAM FILES\CAM2PC\CAM2PC.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\PROGRAM FILES\ADOBE PHOTOSHOP INTERFACE IMPROVER\APIMPR.exe
C:\WINDOWS\SYSTEM\SPOOL32.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.exe
C:\WINCMD\TOTALCMD.exe
C:\WINDOWS\TEMP\_TC\HIJACKTHIS.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie-search.com/srchasst.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie-search.com/home.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie-search.com/srchasst.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie-search.com/srchasst.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie-search.com/srchasst.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ie-search.com/home.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL = 
O2 - BHO: (no name) - {CD4C3CF0-4B15-11D1-ABED-709549C10000} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\ACROBAT\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\googletoolbar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.exe TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM\..\Run: [AtiKey] Atitask.exe
O4 - HKLM\..\Run: [Virtual Drive] "C:\Program Files\FarStone\VirtualDrive\vdtask.exe"
O4 - HKLM\..\Run: [RegShave] C:\Progra~1\REGSHAVE\REGSHAVE.exe /autorun
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [vptray] C:\Program Files\Norton AntiVirus\vptray.exe
O4 - HKLM\..\Run: [FreeRAM XP] "C:\TEMP\FREERAM XP PRO 1.11.exe" -win
O4 - HKLM\..\Run: [MOD] C:\Program Files\Microangelo\muamgr.exe
O4 - HKLM\..\Run: [Logitech Utility] LOGI_MWX.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.exe" -atboottime
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [CreateCD50] C:\PROGRA~1\COMMON~1\ADAPTE~1\CREATECD\CREATE~1.exe -r
O4 - HKLM\..\RunServices: [SAgent2ExePath] C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O4 - HKLM\..\RunServices: [rtvscn95] C:\Program Files\Norton AntiVirus\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] C:\Program Files\Norton AntiVirus\defwatch.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.exe -service
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - Startup: Tclockex.lnk = C:\Program Files\Clock\TCLOCKEX.exe
O4 - Startup: TransparentW.lnk = C:\TEMP\trans\TransparentW.exe
O4 - Startup: PTFB.lnk = C:\TEMP\The Button\PTFB.exe
O4 - Startup: Flywheel.lnk = C:\Program Files\Plannet Crafters\Flywheel\Flywheel.exe
O4 - Startup: AutoMate Task Service.lnk = C:\Program Files\Unisyn\AutoMate4\Automate.exe
O4 - Startup: The Wonderful Icon.lnk = C:\Program Files\Wonderful\wonderfl.exe
O4 - Startup: HotSync Manager.LNK = C:\Program Files\Sony Handheld\HOTSYNC.exe
O4 - Startup: DlgXRSizer.lnk = C:\Program Files\Gajits\DlgXRSizer\DlgXRSizer.exe
O4 - Startup: TrayIcon Standard.lnk = C:\Program Files\TrayIcon Standard\ts.exe
O4 - Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM\E_SRCV02.exe
O4 - Startup: cam2pc - Tray Icon.lnk = C:\Program Files\cam2pc\cam2pc.exe
O4 - Startup: Adobe Photoshop Interface Improver.lnk = C:\Program Files\Adobe Photoshop Interface Improver\ApImpr.exe
O4 - User Startup: Tclockex.lnk = C:\Program Files\Clock\TCLOCKEX.exe
O4 - User Startup: TransparentW.lnk = C:\TEMP\trans\TransparentW.exe
O4 - User Startup: PTFB.lnk = C:\TEMP\The Button\PTFB.exe
O4 - User Startup: Flywheel.lnk = C:\Program Files\Plannet Crafters\Flywheel\Flywheel.exe
O4 - User Startup: AutoMate Task Service.lnk = C:\Program Files\Unisyn\AutoMate4\Automate.exe
O4 - User Startup: The Wonderful Icon.lnk = C:\Program Files\Wonderful\wonderfl.exe
O4 - User Startup: HotSync Manager.LNK = C:\Program Files\Sony Handheld\HOTSYNC.exe
O4 - User Startup: DlgXRSizer.lnk = C:\Program Files\Gajits\DlgXRSizer\DlgXRSizer.exe
O4 - User Startup: TrayIcon Standard.lnk = C:\Program Files\TrayIcon Standard\ts.exe
O4 - User Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM\E_SRCV02.exe
O4 - User Startup: cam2pc - Tray Icon.lnk = C:\Program Files\cam2pc\cam2pc.exe
O4 - User Startup: Adobe Photoshop Interface Improver.lnk = C:\Program Files\Adobe Photoshop Interface Improver\ApImpr.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\GOOGLETOOLBAR.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\WINDOWS\GOOGLETOOLBAR.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\WINDOWS\GOOGLETOOLBAR.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\WINDOWS\GOOGLETOOLBAR.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page - res://C:\WINDOWS\GOOGLETOOLBAR.DLL/cmtrans.html
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37839.5806944444
O19 - User stylesheet: c:\windows\system.css


0

Response Number 58
Name: Setter
Date: August 9, 2003 at 09:05:37 Pacific
Reply:


Hi Steve Harris,

Ok, you have a Datanotary-style of hijack: http://www.spywareinfo.com/articles/datanotary/ this will cause Scrolling on Internet Explorer very slow.

Run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie-search.com/srchasst.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie-search.com/home.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie-search.com/srchasst.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie-search.com/srchasst.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie-search.com/srchasst.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ie-search.com/home.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Use Custom Search URL =

O2 - BHO: (no name) - {CD4C3CF0-4B15-11D1-ABED-709549C10000} - (no file)

O19 - User stylesheet: c:\windows\system.css


After rebooting your computer delete the file “system.css” at c:\windows\system.css

--------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!


0

Response Number 59
Name: Steve Harris
Date: August 9, 2003 at 10:07:29 Pacific
Reply:

Hi Setter,

Brilliant - thank you very much indeed - that seems to have done the trick!!!!!

I did have Spybot Search and Destroy (current version etc) already installed but it didn't pick anything up like this??

Is there an automatic foolproof way to stop this from happening again?

Regards

Steve Harris


0

Response Number 60
Name: Setter
Date: August 9, 2003 at 11:32:53 Pacific
Reply:

Steve,

Foolproof? Well no, as new spyware and hijack methods are being developed everyday. However, the anti-spyware/security community does do a good job of keeping on top of what's new or variations of old, based on peoples problems.

If you tighten up your ActiveX settings, use the above previously mentioned programs (all freeware) and keep them updated you will be very well protected from spyware.

In addition to those mentioned programs, if you want to delve even deeper into computer security, I also use:

-Script Sentry *EASY to use (Blocks possible malicious script using known file extensions, but allows you to bypass the progy when trying to run a known or good script file.)

-IE-Spyad *EASY to use (Adds over 4000 bad URL's to the Restricted Sites Zone)

-HPGURU Hosts file *HARDer to use (Adds over 17,500 bad URL's to your hosts file. What happens is if a URL in the list is encountered the site will not open as it is redirected to the localhost/your computer)

-Proxomitron *even HARDer to use (A personal proxy that allows filtering of anything on HTTP/HTTPS web pages. I use JD5000's config file which also blocks known bad URL's among many other things.)

-System Safety Monitor *Easy to use (but not much documentation and the program is in beta. But this program has saved me from trouble.)

Additional Security Fixes *All easy to use:
-UnPlug n Pray
-WMP Scripting Fix
-HTAstop
-DSOStop2

All may be found by doing a name search. The only program that you would have trouble finding/gathering information on would be Proxomitron.

And when I say HARD to use, the difficulty is in understanding not usage for the most part.

I don't recall if you were using a software firewall, but it is a good idea to do so. Allows you to control inbound and outbound communications.

Good Luck in malware avoidance LOL :-)

Mark

-----------------
Here is some Proxomitron information if you were interested in using/looking at it.
---------------------
Unfortunately the developer/creator of Proxomitron has quit developing/creating his software, nobody really knows why. Here is a thread that discussed this sad happening http://www.dslreports.com/forum/remark,7009848~root=security,1~mode=flat~start=0 Maybe it just was not fun for him anymore. Anyway the last release was on June 1, 2003 and is version 4.5

The original Proxomitron site is also down and will probably be that way for sometime or forever that is up to Scott Lemmon. This may be a little confusing, but since the site is down the program must be obtained from other sources. The program may be downloaded here http://www.computercops.biz/downloads-cats-19-10-10.html After installing (here is the confusion) then download the “Proxomitron EXE Unsupported Patch 4.5” (6-1-2003) from here http://www.computercops.biz/downloads-cat-19.html Replace the original .exe file, with the new patched version (identified by the Green triangle), and you’re good to go. You might as well also place the Proxomitron .exe file in your startup folder so it starts-up automatically at cold boot, as Proxomitron will need to be running in order to access the internet if the browser is configured properly.

Proxomitron instructions are now found here http://www.computercops.biz/modules.php?name=Proxomitron and in the Proxomitron help files

Anyway even though Scott has quit; Proxomitron is far from dead. By using configuration files created by others, Proxomitron will continue to be around and very useful for years to come.



0

Response Number 61
Name: Steve Harris
Date: August 9, 2003 at 11:54:32 Pacific
Reply:

Thanks Mark,

I will take your advice...

I do already have ZoneAlarm Pro (which is always ON), but that didn't stop me getting this "Datanotary" hijack.

How would I have got this particular one? and would any current Anti Spyware progs have got rid of it without your kind help?

Steve Harris



0

Response Number 62
Name: Setter
Date: August 9, 2003 at 12:43:27 Pacific
Reply:

Steve,

First, I should mention that all the progys mentioned above are free.

"How would I have got this particular one?"
--------------------
I don't know, it may have been a script on a HTML page, it may have been an ActiveX control that automatically installed (if your ActiveX setting are too low. It may have been and HTA exploit (though I doubt it as that exploit is fairly new)

"and would any current Anti Spyware progs have got rid of it without your kind help?"
--------------------
Not currently, I don't think. This type of hijack has been around for sometime, but some items are just hard to target effectively as they either are random in nature (example would be Rapidblaster; where a separate removal program was needed) or as in this case, it is hard to target as it did not change the registry. Registry hijack/changes with Class Identifiers (CLSIDs) are much easier to have killbits inserted to stop installation ...etc. It is very possible that SpywareGuard could guard against the Datanotary-style of hijack; I don't know.

Spyware has only been around for less than three years. In Dec. of 1999 there were I believe eight known spyware bots. In January or February of this year, they counted 5,800. Today there are over 7,000.

If people like Javacool did not create SpywareBlaster (Progy inserts killbits) and SpywareGuard we would be just fighting a removal game, but with these progy's we have prevention tools also.

And just think if Spyware S&D (and Ad-Aware) were not created.

That fellow Merijn; the creator of HijackThis and CoolWebShredder, deserves a medal also for giving his time to the cause. If HijackThis was not created, the ease of finding and removing items not targeted by automatic removal programs (Spybot S&D) would be very difficult.



0

Response Number 63
Name: Setter
Date: August 9, 2003 at 13:07:17 Pacific
Reply:

Steve,

I thought I would mention also, that HijackThis is the main program in use today to help identify new (and existing malware not targeted by removal programs) malware for inclusion into the removal programs future updates, that is why making sure you have the current updates is important.

There are many security sites that help, report, notify, identify etc. and work together with the creators of these anti-spyware programs, sharing information.



0

Response Number 64
Name: brockz
Date: August 10, 2003 at 04:36:18 Pacific
Reply:

@ Setter...

thanks, even though i couldnt find those listed below the problem is now fixed. thanks again.

O4 - HKCU\..\Run: [327962] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\327962.cpl

O4 - HKCU\..\Run: [65976] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\65976.cpl
O4 - HKCU\..\Run: [131572] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\131572.cpl
O4 - HKCU\..\Run: [393430] rundll32.exe shell32.dll,Control_RunDLL C:\WINNT\393430.cpl


0

Response Number 65
Name: AnthonyG
Date: August 13, 2003 at 17:25:31 Pacific
Reply:

I am having the same problems as mentioned in most of the above messages. Can someone please help me? Thank you!

Logfile of HijackThis v1.96.0
Scan saved at 8:12:50 PM, on 8/13/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\xl.exe
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\systnnhp.exe
C:\HP\KBD\KBD.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\AIM95\aim.exe
C:\PROGRA~1\HPINST~1\plugin\bin\PCHButton.exe
C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.exe
C:\Program Files\Microsoft Office\Office\OSA.exe
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://out.true-counter.com/b/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://out.true-counter.com/c/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://out.true-counter.com/b/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://out.true-counter.com/a/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://out.true-counter.com/b/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://out.true-counter.com/c/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://out.true-counter.com/b/?656387 (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://out.true-counter.com/b/?656387 (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://out.true-counter.com/b/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAF} - C:\DOCUME~1\Owner\LOCALS~1\Temp\comlhio.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [ScreenSaver] C:\DOCUME~1\Owner\LOCALS~1\Temp\systnnhp.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyStartUp] C:\Program Files\Microsoft Money\System\Money Startup.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HPINST~1\plugin\bin\PCHButton.exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.exe
O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.msn.com
O16 - DPF: {0DC0D258-FC70-456F-8F79-83D7DC20F0AC} (MPChWrapper.Util) - http://instantsupport.hp.com/update/030227/MPChWrapper.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {5B2745C4-8488-432C-A985-77C3E2EFA64F} (PpayWallet) - https://www26.americanexpress.com/privatepayments/ppayspw.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37373.3696064815
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O19 - User stylesheet: C:\WINDOWS\Web\oslogo.bmp


0

Response Number 66
Name: Setter
Date: August 13, 2003 at 18:26:39 Pacific
Reply:

Hi AnthonyG,

Run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://out.true-counter.com/b/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://out.true-counter.com/c/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://out.true-counter.com/b/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://out.true-counter.com/a/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://out.true-counter.com/b/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://out.true-counter.com/c/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://out.true-counter.com/b/?656387 (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://out.true-counter.com/b/?656387 (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://out.true-counter.com/b/?656387 (obfuscated)

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vrape.hardloved.com/top/search.php?id=2&s=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/

O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAF} - C:\DOCUME~1\Owner\LOCALS~1\Temp\comlhio.dll

O4 - HKLM\..\Run: [ScreenSaver] C:\DOCUME~1\Owner\LOCALS~1\Temp\systnnhp.exe

O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.exe
Complete utter waste of space! Part of MS Office - searches disk drives for Office file types and creates an index to make opening them easier

O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
User Interface for HP Center - See below

O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
Based upon HP's own description from http://www.hp.com/hpinfo/newsroom/press/12oct01a.htm - "With the My HP Center, consumers have access directly from the desktop to Internet sites featuring special offers for HP customers ranging from personal finance and shopping to digital imaging and music" – this is classified as adware.

O15 - Trusted Zone: *.msn.com

O19 - User stylesheet: C:\WINDOWS\Web\oslogo.bmp

--------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!


0

Response Number 67
Name: fergie
Date: August 14, 2003 at 05:46:05 Pacific
Reply:

I'm having the same problem too. I've installed and run all the software mentioned above and have ended up with the logfile below. Is there any kind soul who could look it over?
Thanks so much.
Fergus

Logfile of HijackThis v1.96.0
Scan saved at 13:22:56, on 14/08/2003
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.exe
C:\WINNT\system32\ICONSPY.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\HotKey Utility\HKserv.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\WLANSTA.exe
C:\WINNT\System32\P2P Networking\P2P Networking.exe
C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\CreateCD.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\PowerPanel\Program\PcfMgr.exe
C:\Program Files\WinZip\WZQKPICK.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=100
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=100
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = +w
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=100
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTopenworld
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.123found.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://approvedlinks.com/
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O1 - Hosts: 193.125.201.50 ie.search.msn.com
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICONSPY.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WLANSTA.EXE] WLANSTA.exe START
O4 - HKLM\..\Run: [Shell] C:\WINNT/DOWNLO~1/tray.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINNT\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s
O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\CreateCD.exe -r
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: VAIO Action Setup (Server).lnk = C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
O4 - Global Startup: PowerPanel.lnk = C:\Program Files\PowerPanel\Program\PcfMgr.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.exe
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct0_x.cab
O16 - DPF: {03C543A1-C090-418F-A1D0-FB96380D601D} (preload control) - http://www.thepaymentcentre.com/build/preload.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003080601/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37838.0774652778
O16 - DPF: {A0F0D762-D1DE-43AF-B70E-D87864743EB3} (NSLiteUpdateCtrl Class) - http://217.145.76.16/nslite/nslite.cab
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O19 - User stylesheet: C:\WINNT/my.css


0

Response Number 68
Name: Setter
Date: August 14, 2003 at 11:02:54 Pacific
Reply:

HI Fergus (fergie),

Run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=100
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=100

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = +w
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=100

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.123found.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://approvedlinks.com/
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O1 - Hosts: 193.125.201.50 ie.search.msn.com

O4 - HKLM\..\Run: [Shell] C:\WINNT/DOWNLO~1/tray.exe

O16 - DPF: {03C543A1-C090-418F-A1D0-FB96380D601D} (preload control) - http://www.thepaymentcentre.com/build/preload.cab

O16 - DPF: {A0F0D762-D1DE-43AF-B70E-D87864743EB3} (NSLiteUpdateCtrl Class) - http://217.145.76.16/nslite/nslite.cab
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab

O19 - User stylesheet: C:\WINNT/my.css


After reboot then delete the following:
The file tray.exe at C:\WINNT/DOWNLO~1/tray.exe (I assume “DOWNLO~1” is Downloaded Program Files)
The file my.css at C:\WINNT/my.css

--------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!



0

Response Number 69
Name: fergie
Date: August 15, 2003 at 00:51:10 Pacific
Reply:


followed instructions and everythings back to normal. Many, many thanks.


0

Response Number 70
Name: MGZAVIS
Date: August 15, 2003 at 17:18:49 Pacific
Reply:

Help! I'm a relative novice...have done the scan with HijackLog (see below). Can anyone help me now? Profoundly grateful if you can.

Logfile of HijackThis v1.96.0
Scan saved at 01:01:35, on 16/08/2003
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\WINDOWS\SYSTEM\SSDPSRV.exe
C:\WINDOWS\SYSTEM\MDM.exe
C:\WINDOWS\SYSTEM\STIMON.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\DEVLDR16.exe
C:\WINDOWS\SYSTEM\RESTORE\STMGR.exe
C:\WINDOWS\EXPLORER.exe
C:\WINDOWS\TASKMON.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\PROGRAM FILES\CREATIVE\SHAREDLL\CTNOTIFY.exe
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.exe
C:\PROGRAM FILES\AHEAD\INCD\INCD.exe
C:\PROGRAM FILES\CREATIVE\SHAREDLL\MEDIADET.exe
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.exe
C:\PROGRAM FILES\NORTON ANTIVIRUS\POPROXY.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\PROGRAM FILES\ALCATEL\SPEEDTOUCH USB\DRAGDIAG.exe
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\EVNTSVC.exe
C:\PROGRAM FILES\SAVE\SAVE.exe
C:\WINDOWS\SYSTEM\QTTASK.exe
C:\PROGRAM FILES\DOWNLOADWARE\DW.exe
C:\WINDOWS\WT\UPDATER\WCMDMGR.exe
C:\PROGRAM FILES\KAZAA\KAZAA.exe
C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\TYPE32.exe
C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.exe
C:\WINDOWS\SYSTEM\PSTORES.exe
C:\WINDOWS\RUNDLL32.exe
C:\PROGRAM FILES\DELFIN\PROMULGATE\PGMONITR.exe
C:\PROGRAM FILES\WEATHERCAST\WEATHER.exe
C:\WINDOWS\SYSTEM\DDHELP.exe
C:\PROGRAM FILES\BIGFIX\BIGFIX.exe
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.exe
C:\PALM\HOTSYNC.exe
C:\WINDOWS\SYSTEM\TAPISRV.exe
C:\S.exe
C:\SYWER.exe
C:\WINDOWS\TEMP\DIA9140.exe
C:\WINDOWS\TEMP\TD_0001.DIR\HIJACKTHIS.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.ewebsearch.net/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.ewebsearch.net/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ewebsearch.net/sp.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ewebsearch.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.ewebsearch.net/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTopenworld
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/
F1 - win.ini: load=c:\afterdrk\adw30.exe
O1 - Hosts: 66.250.171.136 auto.search.msn.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {0A68C5A2-64AE-4415-88A2-6542304A4745} - C:\PROGRA~1\COMMON~1\MSIETS\MSIETS.DLL (file missing)
O2 - BHO: (no name) - {A6250FB8-2206-499E-A7AA-E1EC437E71C0} - C:\PROGRA~1\COMMON~1\MSIETS\MSIELINK.DLL (file missing)
O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\PROGRAM FILES\MEDIALOADS ENHANCED\ME1.DLL
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\downloaded program files\googletoolbar_en_1.1.70-deleon.dll
O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet5_20.dll
O3 - Toolbar: &Related Links - {59450DB0-341D-4436-B380-B8377D8B6796} - C:\PROGRA~1\COMMON~1\MSIETS\MSIELINK.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\downloaded program files\googletoolbar_en_1.1.70-deleon.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\NORTON~1\DEFALERT.exe
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.exe /LOADQUIET
O4 - HKLM\..\Run: [Norton eMail Protect] C:\Program Files\Norton AntiVirus\POPROXY.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [WhenUSave] C:\PROGRA~1\SAVE\Save.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.exe" -atboottime
O4 - HKLM\..\Run: [MediaLoads Installer] "C:\Program Files\DownloadWare\dw.exe" /H
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [ADQuickAccess] C:\AFTERDRK\ADTRAY.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
O4 - HKLM\..\Run: [PromulGate] "C:\Program Files\DelFin\PromulGate\PgMonitr.exe"
O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.exe
O4 - HKCU\..\Run: [WeatherCast] C:\Program Files\WeatherCast\Weather.exe /q
O4 - Startup: Bigfix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.exe
O8 - Extra context menu item: Power Search - res://C:\PROGRAM FILES\COMMON FILES\MSIETS\MSIELINK.DLL//iemenu
O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLETOOLBAR_EN_1.1.70-DELEON.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLETOOLBAR_EN_1.1.70-DELEON.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLETOOLBAR_EN_1.1.70-DELEON.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLETOOLBAR_EN_1.1.70-DELEON.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLETOOLBAR_EN_1.1.70-DELEON.DLL/cmtrans.html
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O9 - Extra button: Researcher (HKLM)
O9 - Extra button: HuntBar (HKLM)
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .mpg: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.btopenworld.com/
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {8A05273A-2EA5-42DE-AA75-59EA7D9D50D7} (&Search Toolbar) - http://www.trafficsyndicate.com/TB/Cabs/T_64/toolbar_new.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://apple.speedera.net/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/TemplateGallery/downloads/outc.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} (WTHoster Class) - http://install.wildtangent.com/bgn/partners/shockwave/meninblackII/install.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: HushEncryptionEngine - https://mailserver1.hushmail.com/shared/HushEncryptionEngine.cab



0

Response Number 71
Name: ray w
Date: August 15, 2003 at 22:33:22 Pacific
Reply:

Logfile of HijackThis v1.96.0
Scan saved at 1:30:36 AM, on 8/16/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.exe
C:\Program Files\America Online 8.0\aoltray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\AccessDirect\DadTray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\s.exe
C:\f117.exe
C:\DOCUME~1\LEEWOO~1\LOCALS~1\Temp\dia2.exe
C:\Program Files\America Online 8.0\aol.exe
C:\Program Files\America Online 8.0\waol.exe
C:\Program Files\Browser Hijack Blaster\bhblaster.exe
C:\Documents and Settings\Lee Wooldridge\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.ewebsearch.net/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.ewebsearch.net/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ewebsearch.net/sp.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ewebsearch.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://out.true-counter.com/a/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://out.true-counter.com/b/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.ewebsearch.net/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://out.true-counter.com/b/?656387 (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://out.true-counter.com/b/?656387 (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://out.true-counter.com/b/?656387 (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://out.true-counter.com/b/?656387 (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://out.true-counter.com/c/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/
O1 - Hosts: 645238813 auto.search.msn.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O15 - Trusted Zone: *.coolwwwsearch.com
O15 - Trusted Zone: *.msn.com
O16 - DPF: Pop Fu by pogo.com - http://popfu.pogo.com/applet/popfu/popfu-ob-assets.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {ED3ADB6E-5AA9-41B0-9DDC-6F31A34552BE} - http://www.fsc2k.com/install.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{150CA79C-227C-4F38-B80E-806A18443B26}: NameServer = 205.188.197.134
O17 - HKLM\System\CS1\Services\Tcpip\..\{150CA79C-227C-4F38-B80E-806A18443B26}: NameServer = 205.188.197.134
O19 - User stylesheet: C:\WINDOWS\Web\oslogo.bmp

i need some help. .. bad


0

Response Number 72
Name: Setter
Date: August 16, 2003 at 23:30:41 Pacific
Reply:

Hi MGZAVIS,

Run an UPDATED Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.ewebsearch.net/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.ewebsearch.net/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ewebsearch.net/sp.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ewebsearch.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.ewebsearch.net/sp.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/

O1 - Hosts: 66.250.171.136 auto.search.msn.com

O2 - BHO: (no name) - {0A68C5A2-64AE-4415-88A2-6542304A4745} - C:\PROGRA~1\COMMON~1\MSIETS\MSIETS.DLL (file missing)
File missing was HuntBar a search hijacker – See http://www.doxdesk.com/parasite/HuntBar.html

O2 - BHO: (no name) - {A6250FB8-2206-499E-A7AA-E1EC437E71C0} - C:\PROGRA~1\COMMON~1\MSIETS\MSIELINK.DLL (file missing)
File missing - See HuntBar above

O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\PROGRAM FILES\MEDIALOADS ENHANCED\ME1.DLL
DownloadWare – See http://217.115.153.73/parasite/DownloadWare.html

O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet5_20.dll
NewDotNet – See http://www.doxdesk.com/parasite/NewDotNet.html

O3 - Toolbar: &Related Links - {59450DB0-341D-4436-B380-B8377D8B6796} - C:\PROGRA~1\COMMON~1\MSIETS\MSIELINK.DLL (file missing)
File missing – See HuntBar above

O4 - HKLM\..\Run: [WhenUSave] C:\PROGRA~1\SAVE\Save.exe
Rebranded version of SaveNow advertising spyware

O4 - HKLM\..\Run: [MediaLoads Installer] "C:\Program Files\DownloadWare\dw.exe" /H
DownloadWare – See http://www.doxdesk.com/parasite/DownloadWare.html

O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
See NewDotNet above

O4 - HKLM\..\Run: [PromulGate] "C:\Program Files\DelFin\PromulGate\PgMonitr.exe"
Adware based media viewer by The Delfin Project

O8 - Extra context menu item: Power Search - res://C:\PROGRAM FILES\COMMON FILES\MSIETS\MSIELINK.DLL//iemenu
See HuntBar above

O9 - Extra button: HuntBar (HKLM)
See HuntBar above


Do not fix these O10 entries using HijackThis. Spybot S&D should fix these when it removes New.net, if it does not you must repair the Winsock 2 settings using LSPFix from http://www.cexx.org/lspfix.htm
----------------
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net

O16 - DPF: {8A05273A-2EA5-42DE-AA75-59EA7D9D50D7} (&Search Toolbar) - http://www.trafficsyndicate.com/TB/Cabs/T_64/toolbar_new.cab

O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} (WTHoster Class) - http://install.wildtangent.com/bgn/partners/shockwave/meninblackII/install.cab

O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab

After reboot then delete the following:
The folder MEDIALOADS ENHANCED at C:\PROGRAM FILES\MEDIALOADS ENHANCED
The folder NewDotNet at C:\Program Files\NewDotNet
The folder SAVE at C:\Program Files\SAVE
The folder DownloadWare at C:\Program Files\DownloadWare
The folder MSIETS at C:\PROGRAM FILES\COMMON FILES\MSIETS
The folder DelFin at C:\Program Files\DelFin


These Running processes concern me:
----------------
C:\S.exe (Possible Trojan – See http://www.secadministrator.com/Panda/Index.cfm?FuseAction=Virus&virusID=1103 and http://vil.nai.com/vil/content/v_99107.htm)

C:\SYWER.exe (Any search reference to execute file - Not Found)

If these are indeed naughty running processes you should be able to end the processes using the task manager and the delete the execute (*.EXE) files. By doing this any related registry entries will remain but the programs won’t be able to execute. To remove some of the possible related entries, use a registry cleaner such as EasyCleaner 2.0 BETA 1 from http://www.toniarts.com/betas.htm

----------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!


0

Response Number 73
Name: Setter
Date: August 17, 2003 at 00:15:53 Pacific
Reply:

Hi Ray w,

Ah heck!!! Another logfile with this running process? C:\s.exe (Look at the post Response Number 73 above this one.) And nothing found on this? C:\f117.exe
Could you please zip these files and send them to Pieter Arntz at the e-mail listed at this address (http://www.wilderssecurity.com/index.php?action=viewprofile;user=Pieter_Arntz) and please reference Response Number 72 and 74 of this thread (http://www.computing.net/security/wwwboard/forum/5728.html). Then wait for a response before doing anything with the two files. Please let me know the result, Thanks Much.

After e-mailing the files then download and run CoolwebShredder from http://www.spywareinfo.com/~merijn/files/cwshredder.zip (direct download)

Then run an UPDATED Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.ewebsearch.net/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.ewebsearch.net/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ewebsearch.net/sp.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ewebsearch.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://out.true-counter.com/a/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://out.true-counter.com/b/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.ewebsearch.net/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://out.true-counter.com/b/?656387 (obfuscated)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://out.true-counter.com/b/?656387 (obfuscated)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://out.true-counter.com/b/?656387 (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://out.true-counter.com/b/?656387 (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://out.true-counter.com/c/?656387 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/

O1 - Hosts: 645238813 auto.search.msn.com

O15 - Trusted Zone: *.coolwwwsearch.com
O15 - Trusted Zone: *.msn.com

O16 - DPF: {ED3ADB6E-5AA9-41B0-9DDC-6F31A34552BE} - http://www.fsc2k.com/install.exe

O19 - User stylesheet: C:\WINDOWS\Web\oslogo.bmp


-----------------
For the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051

Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.

Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.

Good Luck!



0

Response Number 74
Name: JayCobb
Date: August 22, 2003 at 09:24:08 Pacific
Reply:

Help! I've also had the same problem. I manually got rid of garbage entries that I found in my HOSTS file and ran ad aware, but my home page is still changing. Here is my HijackThis log:

Logfile of HijackThis v1.96.1
Scan saved at 12:23:38 PM, on 8/22/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
C:\WINDOWS\runservice.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\ZipToA.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\DELLMMKB.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\Netropa\OSD.exe
C:\Program Files\Iomega\AutoDisk\AD2KClient.exe
C:\Program Files\AutoSizer\AutoSizer.exe
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\inKline Global\Stay Connected!\StayCon.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\moveover\webstuff\EditPad.exe
C:\Program Files\Lavasoft\Ad-aware 6\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://smbusiness.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://go.microsoft.com/fwlink/?LinkId=17
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\Wkfud.exe
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.exe
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKCU\..\Run: [Iomega Active Disk] C:\Program Files\Iomega\AutoDisk\AD2KClient.exe
O4 - HKCU\..\Run: [AutoSizer] "C:\Program Files\AutoSizer\AutoSizer.exe" /h
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct0_x.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{17ABDF88-49A7-45D5-8B18-31412A38AA15}: NameServer = 206.134.133.10 206.134.224.5

Any help is greatly appreciated!


0

Response Number 75
Name: Setter
Date: August 22, 2003 at 10:44:47 Pacific
Reply:

JayCobb,

This logfile is clean.

Your Home Page is changing? can you explain.

Recommend updating:
------------
Platform: Windows XP is currently at SP1 with security patches; critical and otherwise.

MSIE: Internet Explorer v6.00 is currently at SP1


0

Response Number 76
Name: Jay Cobb
Date: August 22, 2003 at 18:52:14 Pacific
Reply:

My home page (the default startup page for IE) was changing from google to some site called, I think, hi-search.com. It was also adding pornographic bookmarks to my Favorites. It hasn't happened since I rebooted so I must've done something right to get rid of it.

Thanks for your help anyway :)


0

Response Number 77
Name: Dwight
Date: August 22, 2003 at 19:19:54 Pacific
Reply:

I to am having the same problem. Here is my log. I would greatly appreciate any suggestions.

Cheers, Dwight

Logfile of HijackThis v1.96.1
Scan saved at 10:16:37 PM, on 8/22/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\WINDOWS\MWW32\MANAGER\MWSSW32.exe
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.exe
C:\WINDOWS\SYSTEM\MSDTCW.exe
C:\WINDOWS\SYSTEM\RPCSS.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.exe
C:\WINDOWS\TASKMON.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.exe
C:\WINDOWS\LOADQM.exe
C:\PROGRAM FILES\XUPITER\XUPITERSTARTUP2003.exe
C:\PROGRAM FILES\ISTSVC\ISTSVC.exe
C:\PROGRAM FILES\STOPZILLA!\STOPZILLA.exe
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.exe
C:\PALM\HOTSYNC.exe
C:\PROGRAM FILES\WESYNC.COM\WESYNC\WESYNC.exe
C:\WINDOWS\DVZCOMMON\DVZMSGR.exe
C:\PROGRAM FILES\WINZIP\WZQKPICK.exe
C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\DISTILLR\ACROTRAY.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\PROGRAM FILES\COMMON FILES\GMT\GMT.exe
C:\WINDOWS\SYSTEM\DDHELP.exe
C:\WINDOWS\SYSTEM\PSTORES.exe
C:\WINDOWS\RUNDLL32.exe
C:\UNZIPPED\HIJACKTHIS[1]\HIJACKTHIS.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://mommykiss.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mommykiss.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://mommykiss.com/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.markerman.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=129355
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://mommykiss.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://mommykiss.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.xupiter.com/toolbar2
R3 - URLSearchHook: XTSearchHook Class - {6E6DD93E-1FC3-4F43-8AFB-1B7B90C9D3EB} - C:\PROGRAM FILES\XUPITER\XTSEARCH.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\PROGRAM FILES\WS_FTP PRO\WSBHO2K0.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\ACROBAT\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {2662BDD7-05D6-408F-B241-FF98FACE6054} - C:\PROGRAM FILES\XUPITER\XTUPDATE.DLL
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\SYSTEM\StopzillaBHO.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Xupiter - {57E69D5A-6539-4d7d-9637-775DE8A385B4} - C:\PROGRAM FILES\XUPITER\XUPITERTOOLBAR.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] systray.exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SoundFusion] RunDll32 cwcprops.cpl,CrystalControlWnd
O4 - HKLM\..\Run: [Modem Update Reminder] C:\WINDOWS\MWW32\manager\mwremind.exe autorun
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [XupiterStartup] C:\Program Files\Xupiter\XupiterStartup2003.exe
O4 - HKLM\..\Run: [XupiterCfgLoader] C:\Program Files\Xupiter\XTCfgLoader.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [CMESys] "C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.exe"
O4 - HKLM\..\Run: [STOPzilla] C:\Program Files\STOPzilla!\Stopzilla.exe /autorun
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [MSDTC] msdtcw -start
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.exe" /background
O4 - Startup: ThinkPad Modem Copyright.lnk = C:\WINDOWS\MWW32\MANAGER\MWCPYRT.exe
O4 - Startup: Microsoft Office.lnk = C:\WINDOWS\Application Data\Microsoft\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\misc.exe
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.exe
O4 - Startup: WeSync.lnk = C:\Program Files\WeSync.com\WeSync\wesync.exe
O4 - Startup: DataViz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\PROGRA~1\WINZIP\wzqkpick.exe
O4 - Startup: Acrobat Assistant.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37714.4017476852
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.hihiltonhead.com/AxisCamControl.ocx
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://webexevents.webex.com/client/latest/event/ieatgpc.cab
O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab



0

Response Number 78
Name: Randolermo
Date: August 23, 2003 at 16:23:06 Pacific
Reply:

Having same XXXTOOLBAR problem. Here's my Hijackthis log. Thanks for the help.

Logfile of HijackThis v1.96.1
Scan saved at 5:21:52 PM, on 8/23/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.exe
C:\PROGRA~1\MICROS~1\GAMECO~1\common\swtrayv4.exe
C:\Program Files\DIGStream\digstream.exe
C:\WINDOWS\wt\updater\wcmdmgr.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\PANICW~1\POP-UP~2\PSFREE.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\Program Files\ScanSuite\SDetect.exe
C:\Program Files\Common Files\GMT\GMT.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\SYSTEM32\ZONELABS\VSMON.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SYSTEM32\rundll32.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Default\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.topsearcher.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.topsearcher.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.topsearcher.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.topsearcher.com/ie/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\system32\search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.topsearcher.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.topsearcher.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.searchv.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://findloss.com/srchasst.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchv.com/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\system32\search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.searchv.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.searchv.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.topsearcher.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AT&T Broadband Internet
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchv.com/search.php?qq=%s
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://66.250.130.194/main/hp.php
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet5_20.dll
O2 - BHO: WinShow module - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - C:\WINDOWS\winshow.dll
O2 - BHO: (no name) - {9FD12933-810D-4526-B7C4-0914E098D384} - C:\Program Files\Kontiki\bin\BH205171.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ATTRedUpate] C:\PROGRA~1\COMMON~1\AT&T\REDCON\programs\AutoUpdate.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\AudioHQ\AHQTB.exe
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.exe
O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MICROS~1\GAMECO~1\common\swtrayv4.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [USSShReg] C:\PROGRA~1\ULEADS~1\ULEADP~1\SSaver\Ussshreg.exe /r
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [WhenUSave] C:\PROGRA~1\Save\Save.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [spp] regedit -s C:\spp.reg
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - Global Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O4 - Global Startup: Scanner Detector.lnk = C:\Program Files\ScanSuite\SDetect.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: Pop-Up Stopper.lnk = C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe
O8 - Extra context menu item: &Highlight - C:\WINDOWS\WEB\highlight.htm
O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm
O8 - Extra context menu item: &Web Search - C:\WINDOWS\WEB\selsearch.htm
O8 - Extra context menu item: Download with GetRight - C:\PROGRA~1\GETRIGHT\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Get It With Kontiki - res://C:\Program Files\Kontiki\bin\BH205171.dll/201
O8 - Extra context menu item: I&mages List - C:\WINDOWS\Web\imglist.htm
O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\PROGRA~1\GETRIGHT\GRbrowse.htm
O8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htm
O8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htm
O9 - Extra button: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O9 - Extra button: Dell Home (HKCU)
O10 - Hijacked Internet access by New.Net
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msspi.dll
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - http://www.spywarenuker.com/product/camp/SpywareNuker_com/SpywareNukerInstaller.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a224.g.akamai.net/7/224/52/20010620/qtinstall.info.apple.com/qt502/us/win/QuickTimeInstaller.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O19 - User stylesheet: c:\windows\system.css



0

Response Number 79
Name: nas22
Date: August 25, 2003 at 08:06:45 Pacific
Reply:

Logfile of HijackThis v1.96.2
Scan saved at 11:00:20 AM, on 8/25/2003
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Dell\OpenManage\Client\ActionAgent.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\DMI\WIN32\bin\DellDmi.exe
C:\Program Files\Dell\OpenManage\Client\EventAgt.exe
C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
C:\Program Files\Dell\OpenManage\Client\DLT.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\dmi\win32\bin\Win32sl.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\WINNT\Explorer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft Office\Office\OSA.exe
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\gibsonp\My Documents\My Deliveries\HijackThis.exe

O1 - Hosts: 149.32.33.180 at.na.baesystems.com
O1 - Hosts: 149.32.33.176 mdrci-c02-exch
O1 - Hosts: 149.32.33.170 mdrci-s005.at.na.baesystems.com
O2 - BHO: (no name) - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh304181.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.exe
O8 - Extra context menu item: Get It With Kontiki - res://C:\Program Files\Kontiki\bin\bh304181.dll/201
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = tst.tracor.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = tst.tracor.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = tst.tracor.com



0

Response Number 80
Name: jeffreyjmb
Date: August 27, 2003 at 13:13:43 Pacific
Reply:

My Browser was apparently hijacked. I ran Spybot search & Destroy, and HijackThis. The results of HijackThis are below. My biggest problem is that I can not reset my homepage. When I go to IE 6, Tools, Internet Options, the General Tab is missing. Any idea of how to get it back?

Logfile of HijackThis v1.96.2
Scan saved at 1:56:31 PM, on 8/27/2003
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Net Nanny\nnsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINNT\System32\CCM\CcmExec.exe
C:\WINNT\Explorer.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Net Nanny\nntray.exe
C:\WINNT\system32\starter.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Motive\motmon.exe
C:\Program Files\Real\RealPlayer\realplay.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Picasa\PicasaMediaDetector.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.exe
C:\PROGRA~1\AIM95\aim.exe
C:\PROGRA~1\AWS\WEATHE~1\WEATHER.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Adaptec\USBControl\Ausbctrl.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\WINNT\DownloadWizard\DownloadWizard.exe
C:\Program Files\Webshots\WebshotsTray.exe
C:\WINNT\System32\MDM.exe
C:\Program Files\Gateway eSupport\bin\mpbtn.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\WINNT\system32\DllHost.exe
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\jmb.DWR\LOCALS~1\Temp\HijackThis.exe
C:\Program Files\Network Associates\Common Framework\McScript.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = cwcb.state.co.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = cwcb.state.co.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = Cwcb.state.co.us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = cwcb.state.co.us
O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {08351226-6472-43BD-8A40-D9221FF1C4CE} - C:\WINNT\Downloaded Program Files\SbCIe026.dll
O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINNT\System32\nzdd.dll
O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\motmon.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\realplay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LifeScape Media Detector] C:\Program Files\Picasa\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.exe
O4 - HKLM\..\Run: [NNTray] C:\Program Files\Net Nanny\nnstart.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.exe"
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\WEATHER.exe 1
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Startup: eBot.lnk = C:\WINNT\DownloadWizard\DownloadWizard.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: Gateway eSupport.lnk = C:\Program Files\Gateway eSupport\bin\matcli.exe
O4 - Global Startup: RealDownload.lnk = C:\Program Files\Real\RealDownload\Realdownload.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: USBControl.lnk = C:\Program Files\Adaptec\USBControl\Ausbctrl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
O9 - Extra 'Tools' menuitem: Search the Internet (HKLM)
O9 - Extra button: SideStep (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O9 - Extra button: Searchalot (HKCU)
O9 - Extra button: Downloads (HKCU)
O9 - Extra button: WeatherBug (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?rand=20035118
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {78A730D4-0DF3-4B65-8DD2-BFCD433CEE30} - http://www.surfsecret.com/inst/SSInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?1048607528041
O16 - DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.3.1_02) - https://tkdev.state.co.us/wfc/plugins/j2re-1_3_1_02-win.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = dwr.state.co.us
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = dwr.state.co.us
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = dwr.state.co.us



0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Browser Hijack?

Browser Hijack www.computing.net/answers/security/browser-hijack/13936.html

Browser hijacking www.computing.net/answers/security/browser-hijacking/8374.html

Browser Hijacking www.computing.net/answers/security/browser-hijacking/6714.html