Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Noticed the following:
- Google redirecting links
- Unable to reinstall McAfee
- Unable to get to McAfee and Lavasoft websites
- Unable to run Malware or ComboFix (even when renaming exe files)
- Folder Options missing
- Display pictures in IE not set in preferencesHere are the results from Hijack This log:
åogfile of Trend Micro HijackThiå v2.0.2
Scan saved at 4:15:54 åM, on 12/28/2008
Platform: Winåows XP SP3 (WinNT 5.01.2600)
MåIE: Internet Explorer v7.00 (7.å0.6000.16762)
Boot mode: NormaåRunning processes:
C:\WINDåWS\System32\smss.exe
C:\WINDOWå\system32\winlogon.exe
C:\WINDåWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINåOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Påogram Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\åxplorer.exe
C:\WINDOWS\system3å\WDBtnMgr.exe
C:\WINDOWS\systeå32\RUNDLL32.exe
C:\Program Filås\Microsoft IntelliType Pro\ityåe.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Påogram Files\Java\jre6\bin\juschåd.exe
C:\WINDOWS\system32\rundål32.exe
C:\WINDOWS\system32\spåol\drivers\w32x86\3\hpztsb09.exå
C:\Program Files\HP\hpcoretecå\hpcmpmgr.exe
C:\Program FilesåHewlett-Packard\HP Software Updåte\HPWuSchd2.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program åiles\iTunes\iTunesHelper.exe
Cå\DOCUME~1\Carl\LOCALS~1\Temp\winloggn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleåoolbarNotifier.exe
C:\Program åiles\HP\hpcoretech\comp\hptskmgå.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exå
C:\Program Files\Bonjour\mDNSåesponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Progråm Files\Analog Devices\SoundMAXåSMAgent.exe
C:\Program Files\CåeckPoint\SecuRemote\bin\SR_WatcåDog.exe
C:\WINDOWS\system32\svåhost.exe
C:\Program Files\ChecåPoint\SecuRemote\bin\SR_GUI.exeå
C:\WINDOWS\system32\svchost.exå
C:\Program Files\Canon\CAL\CAåMAIN.exe
C:\Program Files\iPodåbin\iPodService.exe
C:\WINDOWSåsystem32\HPZipm12.exe
C:\Progråm Files\CheckPoint\SecuRemote\bån\SR_Service.exe
C:\DOCUME~1\Cårl\LOCALS~1\Temp\csrssc.exe
C:åDocuments and Settings\Carl\Desåtop\mbam-setup.exe
C:\Documents and Settings\Carl\Desktop\mbam-setup.exe
C:\Documents and Setåings\Carl\Desktop\ComboFix.exe
åC:\Documents and Settings\Carl\åesktop\HiJackThis.exeR1 - HåCU\Software\Microsoft\Internet Explorer\Main,Search Page = httpå//go.microsoft.com/fwlink/?Linkåd=54896
R1 - HKLM\Software\Micåosoft\Internet Explorer\Main,Deåault_Page_URL = http://go.microsoft.com/fwlink/?Lin...
Rå - HKLM\Software\Microsoft\Inteånet Explorer\Main,Default_Searcå_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\åoftware\Microsoft\Internet Explårer\Main,Search Page = http://go.microsoft.com/fwlink/?Lin...
R0 - HKLM\Software\Microsoåt\Internet Explorer\Main,Start åage = http://go.microsoft.com/fwlink/?Lin...
R0 - HKLM\Såftware\Microsoft\Internet Exploåer\Search,SearchAssistant =
Rå - HKLM\Software\Microsoft\Inteånet Explorer\Search,CustomizeSeårch =
R1 - HKCU\Software\Micråsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Readår Link Helper - {06849E9F-C8D7-åD59-B87D-784B7D6BE0B3} - C:\Proåram Files\Common Files\Adobe\Acåobat\ActiveX\AcroIEHelper.dll
å2 - BHO: Java(tm) Plug-In SSV Hålper - {761497BB-D6F0-462C-B6EBåD4DAF1D92D43} - C:\Program Fileå\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58åD58-01DD-4d91-8333-CF10577473F7å - c:\program files\google\googåetoolbar1.dll
O2 - BHO: GoogleåToolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -åC:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: (no name) - {CDE8åAB9-CEF3-4885-B12F-26960A25C800å - (no file)
O2 - BHO: Java(tmå Plug-In 2 SSV Helper - {DBC800å4-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStaråDetectorImpl - {E7E6F031-17CE-4å07-BC86-EABFE594F69C} - C:\Progåam Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbår: (no name) - {0BF43445-2F28-4å51-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: &Google - {231åC2B1-4965-11d4-9B18-009027A5CD4å} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Ruå: [NeroFilterCheck] C:\WINDOWS\åystem32\NeroCheck.exe
O4 - HKLå\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spoolåDRIVERS\W32X86\3\E_FATI9EA.exe åP26 "EPSON Stylus CX6600 Serieså /O6 "USB001" /M "Stylus CX6600"
O4 - HKLM\..\Run: [WD Button åanager] WDBtnMgr.exe
O4 - HKLMå..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [åwiz] nwiz.exe /install
O4 - HKåM\..\Run: [NvMediaCenter] RUNDLå32.exe C:\WINDOWS\System32\NvMcåray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [hcsystray] C:\ProgramåFiles\Kuma Games\hcsystray\Kumaåar_tray.exe
O4 - HKLM\..\Run: åitype] "c:\Program Files\Microsåft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntålliPoint\ipoint.exe"
O4 - HKLMå..\Run: [Adobe Reader Speed Lauåcher] "C:\Program Files\Adobe\Råader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdatåSched] "C:\Program Files\Java\jåe6\bin\jusched.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] Cå\WINDOWS\system32\spool\driversåw32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program åiles\Hewlett-Packard\\{5372B9A6å6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
O4 - HKLM\..\Run: [Hå Component Manager] "C:\ProgramåFiles\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Softwaåe Update] "C:\Program Files\Hewåett-Packard\HP Software Update\åPWuSchd2.exe"
O4 - HKLM\..\Runå [HPHmon05] C:\WINDOWS\system32åhphmon05.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotiåier.exe
O4 - HKLM\..\Run: [QuiåkTime Task] "C:\Program Files\QåickTime\qttask.exe" -atboottimeå
O4 - HKLM\..\Run: [iTunesHelpeå] "C:\Program Files\iTunes\iTunåsHelper.exe"
O4 - HKLM\..\Run:å[jsf8j34rgfght] C:\DOCUME~1\Carå\LOCALS~1\Temp\winloggn.exe
O4å- HKLM\..\RunOnce: [Malwarebyteå' Anti-Malware] C:\Program Fileå\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - åKCU\..\Run: [ctfmon.exe] C:\WINåOWS\system32\ctfmon.exe
O4 - HåCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\åoogleToolbarNotifier.exe
O4 - åKCU\..\Run: [jsf8j34rgfght] C:\åOCUME~1\Carl\LOCALS~1\Temp\winlåggn.exe
O4 - HKCU\..\Run: [Jnsådfmf9eldfd] C:\DOCUME~1\Carl\LOåALS~1\Temp\csrssc.exe
O4 - HKLå\..\Policies\Explorer\Run: [rarå] C:\Program Files\Video Activeå Access\imsmain.exe
O4 - HKLM\..\Policies\Explorer\Run: [user3å.dll] C:\Program Files\Video AcåiveX Access\iesmn.exe
O7 - HKCU\Software\Microsoft\Windows\CuråentVersion\Policies\System, DisåbleRegedit=1
O9 - Extra buttonå (no name) - {e2e2dd38-d088-413å-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.eåe
O9 - Extra 'Tools' menuitem:å@xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -åC:\WINDOWS\Network Diagnostic\xånetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2åBB9E-00C04F795683} - C:\ProgramåFiles\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windowå Messenger - {FB5F1910-F110-11då-BB9E-00C04F795683} - C:\Prograå Files\Messenger\msmsgs.exe
O1å - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0CCA191D-13A6å4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - håtp://upload.facebook.com/controås/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {4EDåDDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/åolbin/...
O16 - DPF: {5D637åAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://cdn.smugmug.com/photos/activ...
O16 - DPF: {6E32070A-766D-4åE6-879C-DC1FA91D2FC3} (MUWebConårol Class) - http://update.microsoft.com/microso...
O16 - DPF: {åF15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - htåps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DåF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Uåload Manager Class) - http://wwå.kodakgallery.com/downlo...
O16 å DPF: {BCC0FF27-31D9-4614-A68E-å18E1ADA4389} - http://download.mcafee.com/molbin/s...
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://3dlifeplayer.dl.3dvia.com/pl...
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://81.175.116.204/activex/AMC.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E7716BCD-1273-4CB7-857F-8B8903D09863}: Domain = nyse.com
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe--
End of file - 10033 bytes
Thanks in advance.

I wish this forum would allow you to post Hijack This logs without a request but for now it does not.
You can edit out the Hijack This log and the post will not be deleted, otherwise it will be deleted.

Actually, I was able to run the Malware Antivirus by renaming all the .exe files. It deleted all the viruses and looks like it fixed all the noted problems above.
Thanks anyway!

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |