Computing.Net > Forums > Security and Virus > Help me TomCruise!(or other expert)

Help me TomCruise!(or other expert)

Reply to Message Icon

Original Message
Name: JPNigro
Date: April 16, 2007 at 12:07:37 Pacific
Subject: Help me TomCruise!(or other expert)
OS: Microsoft Windows 2000 SP
CPU/Ram: Pentium4 2.4GHz/523 RAM
Model/Manufacturer: Built by a friend
Comment:

Hello, I had tried about a month ago to install an Active-X Object file, which turned out to be a virus. Uninstall efforts have failed, and it has slowly been dismantling my computer. Most everything works again, except I do not have access to the internet with a few exceptions. My AIM still works, as does Google and Yahoo searches. However, clicking on any links outside of those places leads to a severed internet connection, my browser simply does not work outside of those sites. Can anybody help me? I'm working on a friend's computer, but I still have AIM and hijackthis is installed, so I could post that if it would be helpful. Every virus scan I have run (ad-aware, Spybot, Spyware Begone, and McAfee) has not gotten my system up and running again.


Report Offensive Message For Removal

Response Number 1
Name: XpUser
Date: April 16, 2007 at 14:07:04 Pacific
Subject: Help me TomCruise!(or other expert)
Reply: (edit)

There's no Tom Cruise among us. Try Hollywood.

i_XpUser


Report Offensive Follow Up For Removal

Response Number 2
Name: JPNigro
Date: April 17, 2007 at 13:32:04 Pacific
Subject: Help me TomCruise!(or other expert)
Reply: (edit)

The Tom Cruise thing is a lighthearted joke, but my problem isn't. It's a line from Talladega Nights, when Will Ferrell is so desperate because he imagines himself on fire, that he cries for help to God, Oprah, and even Tom Cruise. Reading the title of every problem as "HELP ME ASAP!!!!1", I couldn't resist the Will Ferrell reference.

But any help you could give me on the problem would be greatly appreciated.


Report Offensive Follow Up For Removal

Response Number 3
Name: JPNigro
Date: April 21, 2007 at 13:20:20 Pacific
Subject: Help me TomCruise!(or other expert)
Reply: (edit)

Thanks XP User! As requested, here's the hijack this log.

Logfile of HijackThis v1.99.1
Scan saved at 3:18:22 PM, on 4/21/2007
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
(15:16:50) John-Paul Nigro: C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Cheetah Burner\Cheetah CD Burner\NMSAccess.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Cheetah Burner\Cheetah CD Burner\NMSAccess.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINNT\System32\khooker.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Spyware Begone\SpywareBeGone.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\Program Files\Microsoft Office 2000\Office\WINWORD.EXE
C:\Program Files\Gaim\gaim.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: IeHelper Class - {A491D208-B353-490F-B81A-A8A3DC97042D} - C:\WINNT\system32\smiehlp.dll
O2 - BHO: KansasCity-Royals.net - {CD292324-974F-4224-D944-828C611ACC3A} - C:\PROGRA~1\KANSAS~1.NET\Toolbar\Toolbar.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: KansasCity-Royals.net - {CD292324-974F-4224-D944-828C611ACC3A} - C:\PROGRA~1\KANSAS~1.NET\Toolbar\Toolbar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SiS KHooker] C:\WINNT\System32\khooker.exe
O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Svcs: Dnscache] C:\DOCUME~1\JOHN-P~1\LOCALS~1\Temp\26737\explorer.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINNT\system32\__c003853B.dat",setvm
O4 - HKLM\..\Run: [sysinter] C:\WINNT\system32\adirss.exe
O4 - HKCU\..\Run: [Spyware Begone] "C:\Program Files\Spyware Begone\SpywareBeGone.exe" -FastScan
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office 2000\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O10 - Broken Internet access because of LSP provider 'smnsp.dll' missing
O17 - HKLM\System\CCS\Services\Tcpip\..\{9AF19E7B-B6E1-44AC-88F5-F9F2DC6DBAF6}: NameServer = 62.94.0.2
O20 - Winlogon Notify: __c004BB8C - C:\WINNT\system32\__c004BB8C.dat
O20 - Winlogon Notify: __c00848C3 - C:\WINNT\system32\__c00848C3.dat
O20 - Winlogon Notify: __c008CDC2 - C:\WINNT\system32\__c008CDC2.dat
O21 - SSODL: reAaap - {10300843-BA9A-A2E9-99B9-4CF651AE06F3} - C:\WINNT\system32\knr.dll (file missing)
O21 - SSODL: DCOM Server 37389 - {2C1CD3D7-86AC-4068-93BC-A02304B37389} - (no file)
O21 - SSODL: DCOM Server 60787 - {2C1CD3D7-86AC-4068-93BC-A02304B60787} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\Cheetah Burner\Cheetah CD Burner\NMSAccess.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe


Report Offensive Follow Up For Removal







Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Help me TomCruise!(or other expert)

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software