Computing.Net > Forums > Security and Virus > My aim is messed up

My aim is messed up

Reply to Message Icon

Original Message
Name: maddog1533@msn.com
Date: March 18, 2004 at 14:32:00 Pacific
Subject: My aim is messed up
OS: Windows XP
CPU/Ram: 256
Comment:

I accidentallu clicked on this gurlz profile that said "Veiw Buddyprofile". right when i did i clicked off and closed it but i gues i didnt get it in time......Now when im on AIM after every like 2 minutes an away message pops up saying "new profile http://ugleague.net/aimprofile.scr !"........will someone please help me


Report Offensive Message For Removal

Response Number 1
Name: blender
Date: March 18, 2004 at 15:58:53 Pacific
Subject: My aim is messed up
Reply: (edit)

Hi

I tried that link....you have w32/sdbot.worm.gen (according to mcafee av)
It automatically tried to install the virus on my puter but my av killed it.

Do you have an antivirus program?
If so...make sure it is up to date, boot to safe mode (tap f8 on boot) and run a full scan

Alternatively try an online scanner.
Boot to safe mode with networking so they can remove the virus.
You will still need to remove that crappy link in your Aim profile.

Pandascan

Housecall

Post back if you still have problems.
_____________________________________

I never give up!

Windows Update


Report Offensive Follow Up For Removal

Response Number 2
Name: maddog1533@msn.com
Date: March 19, 2004 at 17:58:54 Pacific
Subject: My aim is messed up
Reply: (edit)

Logfile of HijackThis v1.97.7
Scan saved at 8:55:51 PM, on 3/19/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\PROGRA~1\ACCELE~1\ANTI-V~1\DEFSCA~1.EXE
C:\PROGRA~1\ACCELE~1\VELOZD~1\velozsys.exe
C:\Program Files\The Cleaner\tca.exe
C:\Program Files\The Cleaner\tcm.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\aim\aim.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\Program Files\AOL Companion\companion.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\ESPN\BottomLine\bline.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\Documents and Settings\Good Customer\Local Settings\Temp\Temporary Directory 2 for hijackthis[1].zip\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = home.netscape.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://pop.popuptoast.com/9894/search/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=99
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\ycomp5_0_2_4.dll
O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file)
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O3 - Toolbar: 2020SEARCH2 - {4E7BD74F-2B8D-469E-92C6-CE7EB590A94D} - C:\WINDOWS\2020Search2.dll (file missing)
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [WebScan] C:\PROGRA~1\ACCELE~1\ANTI-V~1\DEFSCA~1.EXE -k
O4 - HKLM\..\Run: [eMailEncryption] C:\PROGRA~1\ACCELE~1\VELOZD~1\velozsys.exe runstart
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\aim\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ESPN BottomLine] C:\Program Files\ESPN\BottomLine\bline.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - Startup: Download Plus.lnk = C:\Documents and Settings\Good Customer\Application Data\DownloadPlus.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O9 - Extra button: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pot2_x.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {58172624-85DD-4482-9E64-02ADCA637E96} (shizmoo Class) - http://www.shizmoo.com/activex/web588.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} - http://fdl.msn.com/public/chat/msnchat42.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (&Yahoo! Companion) - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/my/yiebio4_0_2_10.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{30D5C3E4-4F73-4A73-A9F5-5F966B7E46F1}: NameServer = 170.147.45.175 170.147.113.54

Can I Delete anything to help my problem?


Report Offensive Follow Up For Removal

Response Number 3
Name: blender
Date: March 20, 2004 at 11:09:36 Pacific
Subject: My aim is messed up
Reply: (edit)

Derek

You have quite the spyware mess that will take a few steps to fix it.

I assume you have kazaa installed or was at one time.
Kazaa installs a pile of crapware slowing you down tons.

Not that I promote filesharing applications but WinMX is not full of junk and most people that use it like it.

If you have kazaa...doing the following may not allow it to run since it will only run with the crapware.

First put hijack in its own folder (not a temporary folder or the desktop.
It makes backups in case something goes wrong and we cant recover it if run from a temp folder.

Start hijackthis again while offline and check the following entries:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://pop.popuptoast.com/9894/search/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=99
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file)
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O3 - Toolbar: 2020SEARCH2 - {4E7BD74F-2B8D-469E-92C6-CE7EB590A94D} - C:\WINDOWS\2020Search2.dll (file missing)

O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [WebScan] C:\PROGRA~1\ACCELE~1\ANTI-V~1\DEFSCA~1.EXE -k
O4 - HKLM\..\Run: [eMailEncryption] C:\PROGRA~1\ACCELE~1\VELOZD~1\velozsys.exe runstart

O4 - Startup: Download Plus.lnk = C:\Documents and Settings\Good Customer\Application Data\DownloadPlus.exe

O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -

Once done that close all windows except hijack and click "fix checked"

Reboot the computer and delete the following:

c:\program files\myway <-folder
c:\program files\power scan <-folder
c:\program files\Acceleration <-folder
c:\Documents and Settings\Good Customer\application data\Downloadplus.exe <-file
c:\windows\system32\p2p networking <-folder

Empty out your temporary internet files:

Right click IE on desktop
Properties
Click delete files
Check delete offline content
Click ok


Next download Ad-aware from here:

http://www.lavasoftusa.com/support/download/

Once installed, update it and set up the scan as it shows here:

http://www.lavahelp.com/howto/fullscan/index.html

Once you get it set up go offline and run its scan. Make sure custom mode is checked (not smartscan)

Select all in results window, next, yes at the prompt.

Reboot

I see you have done those virus scans mentioned above... Did they help any?

That stop-sign antivirus I had you remove..it installs a ton of crapware...not recommended.

A decent free antivirus program...3 to choose from:

AVG free
Avast4 personal
Anti vir personal

With avg or avast you need to enter a valid email addy for them to send key code to install.

Once installed update it, and run its scan.
If still infected run the scan in safe mode (tap f8 on boot, choose safe mode, hit enter)

Next visit windows update, install all updates including sp1 for both windows and internet explorer.
Without the updates you are open to repeated hijacks, exploits, and other security issues.

When done that...post new hijack log along with names of any viruses if any found and where they are located.
___________________________________

I never give up!

Windows Update


Report Offensive Follow Up For Removal

Response Number 4
Name: maddog1533@msn.com
Date: March 24, 2004 at 17:05:21 Pacific
Subject: My aim is messed up
Reply: (edit)

Logfile of HijackThis v1.97.7
Scan saved at 8:01:32 PM, on 3/24/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\The Cleaner\tca.exe
C:\Program Files\The Cleaner\tcm.exe
C:\WINDOWS\System32\iexpl0re.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\Program Files\AOL Companion\companion.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Good Customer\Local Settings\Temp\Temporary Directory 2 for hijackthis[1].zip\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = home.netscape.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\ycomp5_0_2_4.dll
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
O4 - HKLM\..\Run: [Internet Explorer] iexpl0re.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\RunServices: [Internet Explorer] iexpl0re.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ESPN BottomLine] C:\Program Files\ESPN\BottomLine\bline.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O9 - Extra button: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pot2_x.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {58172624-85DD-4482-9E64-02ADCA637E96} (shizmoo Class) - http://www.shizmoo.com/activex/web588.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} - http://fdl.msn.com/public/chat/msnchat42.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38068.643125
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (&Yahoo! Companion) - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/my/yiebio4_0_2_10.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{30D5C3E4-4F73-4A73-A9F5-5F966B7E46F1}: NameServer = 170.147.45.175 170.147.113.54



Report Offensive Follow Up For Removal

Response Number 5
Name: blender
Date: March 25, 2004 at 07:22:57 Pacific
Subject: My aim is messed up
Reply: (edit)

Hello

Hmmmmm..you have a new infection since last log altho much of the other junk seems to be gone.
You are still running hijackthis from a temporary directory which means if something goes wrong and we need to restore something with hijack....we cant.
Make a new folder in c:\ called HJT
Put hijackthis.exe in it.
Run hijackthis from that location from now on.

I would like you to check properties of a file located in c:\program files\msn\msn core files\msn6.exe <-this file
Go thru the properties tabs...I want to know company name, file name, date, etc...
Dont do anything with it just yet.
If you have msn6...the exe that should be running is msnmsgr.exe.
You do have windows messanger (msmsgs.exe) which is fine.

Next start hijackthis again and check the following to fix:

O4 - HKLM\..\Run: [Internet Explorer] iexpl0re.exe

O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART

O4 - HKLM\..\RunServices: [Internet Explorer] iexpl0re.exe

Once checked close all windows except hijack and click "fix checked"

Reboot

Remove the following files/folders:

c:\windows\system32\p2p networking <-folder (kazaa works fine without it)

c:\windows\system32\iexp10re.exe <-file

Has any of what we done so far fixed your aim?
Did housecall virus scan find anything?

Post a fresh hijack log when done.
_____________________________________

I never give up!

Windows Update


Report Offensive Follow Up For Removal


Response Number 6
Name: maddog1533@msn.com
Date: March 28, 2004 at 12:26:45 Pacific
Subject: My aim is messed up
Reply: (edit)

I would like you to check properties of a file located in c:\program files\msn\msn core files\msn6.exe <-this file
Go thru the properties tabs...I want to know company name, file name, date, etc...
Dont do anything with it just yet.
If you have msn6...the exe that should be running is msnmsgr.exe.
You do have windows messanger (msmsgs.exe) which is fine.

---How do i get there? And where do i get the acual file of hijackthis.exe?

---My profile still says "veiw buddyprofile" thing


Report Offensive Follow Up For Removal

Response Number 7
Name: maddog1533@msn.com
Date: March 28, 2004 at 14:10:53 Pacific
Subject: My aim is messed up
Reply: (edit)

The housecall scaned 16 things of "Troj Golid"......


Report Offensive Follow Up For Removal

Response Number 8
Name: blender
Date: March 29, 2004 at 00:08:18 Pacific
Subject: My aim is messed up
Reply: (edit)

Derek

The msn6 is ok...that is msn explorer that comes with xp...my blank moment there...

Just download a new HijackThis from:

http://www.lurkhere.com/~nicefiles/

Save it to the hijack folder you made.

That troj.Golid is an adware program...it downloads programs to your computer to display popups and other crap.

Try this program:

http://www.lavasoftusa.com/support/download

Once installed update it (globe icon)

Now do the following:

- Under Ad-aware 6 > Settings (Gear at the top) > Scanning > Check all you can in there.

- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Scanning Engine:
check: "Unload recognized processes during scanning."

- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Cleaning Engine:
Check: "Let Windows remove files in use after reboot."

Press "Scan Now"

- Check option "Use Custom scanning options"
- Check option "Activate In-Depth Scan"
- Press "Select drives\folders to scan"
- Select the active partition which is usually C:

Now press "Next" to let Ad-aware scan your drives...
It will find a number of "bad" files and registry keys.
Right-click in that pane and choose "select all"

Now press "Next" again.
It will ask you whether you'd like to remove all checked items. Click OK.

Finally, close Ad-Aware, and reboot.

Start hijackthis again from the one you just downloaded and post a new log.
_______________________________________

I never give up!

Windows Update


Report Offensive Follow Up For Removal

Response Number 9
Name: maddog1533@msn.com
Date: March 29, 2004 at 14:22:22 Pacific
Subject: My aim is messed up
Reply: (edit)

Logfile of HijackThis v1.97.7
Scan saved at 5:20:45 PM, on 3/29/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\The Cleaner\tca.exe
C:\Program Files\The Cleaner\tcm.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\AOL Companion\companion.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\Documents and Settings\Good Customer\My Documents\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = home.netscape.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ESPN BottomLine] C:\Program Files\ESPN\BottomLine\bline.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O9 - Extra button: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pot2_x.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {58172624-85DD-4482-9E64-02ADCA637E96} (shizmoo Class) - http://www.shizmoo.com/activex/web588.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} - http://fdl.msn.com/public/chat/msnchat42.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38068.643125
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{30D5C3E4-4F73-4A73-A9F5-5F966B7E46F1}: NameServer = 170.147.45.175 170.147.113.54



Report Offensive Follow Up For Removal

Response Number 10
Name: blender
Date: March 29, 2004 at 21:28:50 Pacific
Subject: My aim is messed up
Reply: (edit)

Derek

Start hijackthis again and check the following to fix:

F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe

O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART

Reboot and delete:

C:\windows\system32\p2p networking <-whole folder

You will likely need to delete that link in your aim profile.

Did Ad-aware clean out a bunch of stuff? Any improvement or remaning issues?

To help protect yourself in the future...there are a few things you need to do:

1. Visit windows update and install all critical updates listed for both windows and internet explorer including sp1.

2. Get an antivirus program...there a few free ones available that are free and use little resorces:

AVG Free

Avast

Anti Vir

Whichever antivirus you install...make sure you update it and keep it updated.

I don't run AIM so I am unsure of it's update procedure....There may be security updates available.

3. Download and install Spywareblaster...it blocks all kinds of crapware downloads. (also free)

You can get it here:

Spywareblaster

Check for updates about once a week.
_____________________________________


I never give up!

Windows Update


Report Offensive Follow Up For Removal

Response Number 11
Name: maddog1533@msn.com
Date: March 31, 2004 at 15:21:34 Pacific
Subject: My aim is messed up
Reply: (edit)

It wont let me Delete P2P Networking....it says that it is bein used by another person or program....and I don't have anything up that has to do with that......what should i do?


Report Offensive Follow Up For Removal

Response Number 12
Name: blender
Date: April 1, 2004 at 08:35:30 Pacific
Subject: My aim is messed up
Reply: (edit)

Derek

Did you reboot the computer after removing the entries I listed?

Once you reboot...it should not start up...
Anyhow you can "end process" on that program.

Hit ctrl+alt+del at same time
Click the processes tab
Scroll down the displayed list to p2p networking.exe
Hilight it
click end process
Ok the warning
Now delete the p2p networking folder.

Before doing above...there may be a listing in add/remove programs for p2p networking or Altnet points manager
If either is present...remove it.
Removing Altnet will also remove p2p networking. (ok all the silly warnings you get)
You will still need to delete the p2p networking folder.
There will also likely be a p2p networking.exe file in C:\windows\temp...get rid of that too.

Do you have any other users on your system?

Make sure you are logged in as either administrator or have admin privlages...all other users (if any) should be logged off.
(If you were able to do all the stuff in above posts...you have admin privlages)

If you have other users....I will want to look at hijack logs from them too. (other than yourself, admin, ASP.NET)
_______________________________________


I never give up!

Windows Update


Report Offensive Follow Up For Removal

Response Number 13
Name: maddog1533@msn.com
Date: April 1, 2004 at 13:15:10 Pacific
Subject: My aim is messed up
Reply: (edit)

No I don't have any other users on my computer......the thing in my profile is away......im not sure if it'll com eback but ive done all the things you have told me and THANK YOU for all your help.....do you want to see my hijackthis log again?


Report Offensive Follow Up For Removal

Response Number 14
Name: blender
Date: April 1, 2004 at 22:27:04 Pacific
Subject: My aim is messed up
Reply: (edit)

Derek

Ya just to make sure all is clean....put up a fresh hijack log.
_______________________________________

I never give up!

Windows Update


Report Offensive Follow Up For Removal

Response Number 15
Name: maddog1533@msn.com
Date: April 3, 2004 at 08:42:13 Pacific
Subject: My aim is messed up
Reply: (edit)

Logfile of HijackThis v1.97.7
Scan saved at 11:40:24 AM, on 4/3/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\The Cleaner\tca.exe
C:\Program Files\The Cleaner\tcm.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\BigFix\BigFix.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\Documents and Settings\Good Customer\My Documents\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = home.netscape.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ESPN BottomLine] C:\Program Files\ESPN\BottomLine\bline.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O9 - Extra button: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pot2_x.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} - http://fdl.msn.com/public/chat/msnchat42.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38068.643125
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{30D5C3E4-4F73-4A73-A9F5-5F966B7E46F1}: NameServer = 170.147.45.175 170.147.113.54

Im goin to Florida for a couple of days....ill be back the 10th....thank you for ALL your help...please still post after my log for when I come back


Report Offensive Follow Up For Removal

Response Number 16
Name: blender
Date: April 4, 2004 at 06:17:49 Pacific
Subject: My aim is messed up
Reply: (edit)

Derek

Looks pretty good...
You still have that P2P networking thing tho...

Start hijackthis again and tick off this one:

O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART

Close all windows except hijack, click fix checked.

Reboot and delete the p2p networking folder from:

C:\windows\system32\p2p networking <-whole folder

You still have no antivirus program....check out the choices from above post...all are free.
It is alot better having antivirus catch a virus before it does its damage than trying like hell to clean it out after.
The Cleaner is good for trojans....not viruses.

You still also need to install your windows updates...there are many security issues and exploits fixed....It will take several visits to get them all.

Also don't forget about spywareblaster....good to keep all kinds of crap off the system. It even offers to set up IE more secure.

Things working better now?

Just in case I go nuts cleaning out "my computing.net"...hit the alert me button so I can find the thread again.
_________________________________________


I never give up!

Windows Update


Report Offensive Follow Up For Removal






Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: My aim is messed up

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software