Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Read this topic before posting a log.
DO NOT post a ComboFix log unless requested to.
Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.
When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.
Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
![]() ![]() |
Jun 11 2007, 11:42 PM
Post
#1
|
|
|
New Member ![]() Group: Members Posts: 13 Joined: 11-June 07 Member No.: 136,144 |
For the last two weeks I have been having trouble with my computer. I am connected to my brother's computer via a router (Linksys Wireless-G Wireless Network Monitor. WMP54Gv4SVC) About two weeks ago I think I picked up a nasty infection of some sort - my computer has been extremely sluggish and now I am plagued with a ceaseless barrage of of "Powered By ZEDO" pop ups while using IE. Programs are extremely slow and freeze and often a box pops up telling me to "Pleae wait while such-and-such a program closes." Searching in safe mode often freezes as well. I have run a multitude of Anti-Spyware/Virus/Malware programs: AVG7.5, Spy Sweeper, A-Squared, ATF Cleaner, CCleaner, Dr.Web Cureit and the free Panda scan in both normal start up and safe modes with no luck. My system is still very slow and still with pop ups. I have also Googled the Zedo cookie and tried several ways to remove it manually....no luck there either - many of the registry keys and .dll files I was told to delete are not present on my computer (core.sys & core.cache.dsk). I have blocked zedo.com as a cookie (apparently too late) but still can't get rid of it. I'm not at all computer savvy, so I apologize in advance. Here's my Hijackthis log: Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Softex\OmniPass\Omniserv.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe C:\Program Files\Softex\OmniPass\OPXPApp.exe C:\WINDOWS\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus8.hpwis.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {2C0E4C15-89D6-46C0-9BB3-1B2E0A103CD1} - C:\WINDOWS\system32\driverk.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1172825992515 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1172825953859 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing) |
|
|
|
Jun 12 2007, 05:18 AM
Post
#2
|
|
|
Malware Assassin ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 13,611 Joined: 13-July 06 Member No.: 75,975 |
Welcome to the BleepingComputer HijackThis Logs and Analysis forum Oowo
You’re running msconfig in Auto mode which means that you may have selectively unchecked some items in the past from starting up with Windows. This can be bad if they’re malware, so please re-enable those startup entries by doing the following: Click on Start>Run,type msconfig and then press Enter. When the ‘System Configuration Utility’ opens click on the ‘Startup’ tab,make sure all the boxes are checkmarked. Then press Apply/Ok to exit the utility. If it asks you to restart your pc,please don’t,it‘s not necessary to reboot to get the items to show in the Hijackthis log. ************************** Please download Combofix and save to your desktop: http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe Note: It is important that it is saved directly to your desktop Close any open browsers. Double click on combofix.exe and follow the prompts. When it's finished it will produce a log. Post the entire contents of C:\ComboFix.txt into your next reply. Note: Do not mouseclick combofix's window while it's running. That may cause the program to freeze/hang. Also post a new Hijackthis log please. -------------------- |
|
|
|
Jun 12 2007, 06:04 AM
Post
#3
|
|
|
New Member ![]() Group: Members Posts: 13 Joined: 11-June 07 Member No.: 136,144 |
Hi RichieUK,
Thanks so much for taking the time to go over my post. I greatly appreciate it. Here is my ComboFix Log: ComboFix 07-06-12.5 - C:\Documents and Settings\Owner\Desktop\ComboFix.exe "Owner" - 2007-06-12 6:36:03 - Service Pack 1 NTFS ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\install.log C:\WINDOWS\system32\driverk.dll C:\WINDOWS\system32\driverk.exe C:\WINDOWS\system32\wmvds32.dll ((((((((((((((((((((((((( Files Created from 2007-05-12 to 2007-06-12 ))))))))))))))))))))))))))))))) 2007-06-12 06:34 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-06-12 05:48 <DIR> d--h----- C:\WINDOWS\PIF 2007-06-12 04:52 53,248 --a------ C:\WINDOWS\system32\Process.exe 2007-06-12 04:42 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\interMute 2007-06-12 03:43 11,271 --a------ C:\syswyez.exe 2007-06-11 18:22 97,280 --a-s---- C:\WINDOWS\system32\monterreyk_redux.exe 2007-06-11 18:21 8,704 --a------ C:\WINDOWS\system32\regapi.exe 2007-06-04 19:26 20,045 --a------ C:\Program Files\cc_20070604_1925.reg 2007-06-04 19:13 <DIR> d-------- C:\Program Files\CCleaner 2007-06-04 19:12 2,719,216 --a------ C:\Program Files\ccsetup140.exe 2007-06-04 07:47 50,688 --a------ C:\Program Files\ATF-Cleaner.exe 2007-05-31 15:23 3,563,520 --a------ C:\DOCUME~1\Owner\ntuser.dat 2007-05-31 05:24 <DIR> d-------- C:\WINDOWS\system32\ActiveScan 2007-05-31 02:43 77,312 --a------ C:\WINDOWS\ua2.dll 2007-05-22 16:41 <DIR> d-------- C:\Program Files\Last.fm (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-12 08:52:39 364 ----a-w C:\WINDOWS\system32\tmp.reg 2007-06-04 23:56:06 -------- d-----w C:\Program Files\Common Files\Symantec Shared 2007-06-04 13:19:41 -------- d-----w C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor 2007-06-04 13:15:01 -------- d-----w C:\Program Files\a-squared Free 2007-05-31 09:59:58 -------- d-----w C:\Program Files\MSN Messenger 2007-05-11 22:22:09 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\SUPERAntiSpyware.com 2007-05-11 14:23:52 -------- d-----w C:\Program Files\Enigma Software Group 2007-04-29 23:56:26 -------- d-----w C:\Program Files\Firaxis Games 2007-04-29 23:53:18 -------- d--h--w C:\Program Files\InstallShield Installation Information 2007-04-29 23:52:38 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\My Games 2007-04-29 22:26:44 163,644 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-04-14 21:39:10 -------- d-----w C:\Program Files\Lavasoft 2007-03-25 03:57:29 0 ----a-w C:\autoexec.bat 2007-03-15 16:23:16 497,496 ----a-w C:\WINDOWS\system32\XceedZip.dll 2007-03-15 16:19:58 526,184 ----a-w C:\WINDOWS\system32\XceedCry.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-03-02 22:02] {53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 01:04] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll [2006-12-15 04:23] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-03-02 23:20] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 04:23] "StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [] "SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2006-07-07 18:16] "SpyHunter"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe" [] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-26 20:59] "KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 22:02] "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-05-11 05:23] "AlcxMonitor"="ALCXMNTR.EXE" [2003-04-03 23:35 C:\WINDOWS\ALCXMNTR.EXE] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [] "Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [] "MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:54] "AIM"="C:\Program Files\AIM\aim.exe" [2006-08-01 15:35] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina] C:\Program Files\Softex\OmniPass\opxpgina.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService] *Newly Created Service* - ALG *Newly Created Service* - IPNAT *Newly Created Service* - SHAREDACCESS ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-12 06:47:43 Windows 5.1.2600 Service Pack 1 NTFS scanning hidden processes ... cmd.exe [2924] scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-06-12 6:49:07 C:\ComboFix-quarantined-files.txt ... 2007-06-12 06:48 --- E O F --- **************************************************************************** And here is my new Hijackthis log with everything in msconfig start up checked: Logfile of HijackThis v1.99.1 Scan saved at 6:52:11 AM, on 6/12/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Softex\OmniPass\Omniserv.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe C:\Program Files\Softex\OmniPass\OPXPApp.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus8.hpwis.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1172825992515 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1172825953859 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing) Please note (not sure if it matters): Some processes in the start up menu are no longer on my computer and haven't been for a while, such as SuperAnti-Spyware, Spy Hunter and Spyware Doctor. This post has been edited by Oowo: Jun 12 2007, 06:07 AM |
|
|
|
Jun 12 2007, 06:34 AM
Post
#4
|
|
|
Malware Assassin ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 13,611 Joined: 13-July 06 Member No.: 75,975 |
Disable Spyware Doctor:
From within Spyware Doctor, click the "OnGuard" button on the left side. Uncheck "Activate OnGuard". ******************** Disable SpySweeper: If you have Spy Sweeper version 4: * Open it, Click Options over on the left, then Program options * Uncheck load at windows startup. * Over to the left, Click shields and Uncheck all there. * Uncheck home page shield. * Uncheck automatically restore default without notification. * Reboot your machine for the changes to take effect before running HJT. -------------------- If you have SpySweeper version 5: To disable SpySweeper Shields * Open SpySweeper. * Click Shield Settings on the right (or Shields on the left, depending what screen you're on). * Click Internet Explorer and uncheck all items. * Click Windows System and uncheck all items. * Click Hosts File and uncheck all items. * Click Startup Programs and uncheck all items. * Close SpySweeper. Reboot you computer, and ensure Spy Sweeper is disabled. ******************** Download Killbox by Option^Explicit: http://download.bleepingcomputer.com/spyware/KillBox.exe Save it to your desktop. Please double-click Killbox.exe to run it. Select: 'Delete on Reboot'. Then Click on the 'All Files' button. Please copy ALL the file paths inside the quote box below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy): QUOTE C:\syswyez.exe C:\WINDOWS\system32\monterreyk_redux.exe Return to Killbox,go to the File menu,and choose 'Paste from Clipboard'. Click the red-and-white Delete File button. Click 'Yes' at the 'Delete on Reboot' prompt. Click OK at any 'PendingFileRenameOperations' prompt. If your computer does not restart automatically,please restart it manually. After rebooting, open up Killbox again. Click 'File'>'Logs'>'Actions History Log'. Post this log in your next reply. ******************** Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'. Make sure all browser and all Windows Explorer windows are closed before fixing: O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE Exit Hijackthis. ******************** Download ATF Cleaner by Atribune: http://www.atribune.org/ccount/click.php?id=1 Double-click ATF-Cleaner.exe to run the program. Click 'Select All' found at the bottom of the list. Click the 'Empty Selected' button. If you use Firefox browser, do this also: Click Firefox at the top and choose 'Select All' from the list. Click the 'Empty Selected' button. NOTE: If you would like to keep your saved passwords,please click 'No' at the prompt. If you use Opera browser,do this also: Click Opera at the top and choose 'Select All' from the list. Click the 'Empty Selected' button. NOTE: If you would like to keep your saved passwords,please click 'No' at the prompt. Click 'Exit' on the Main menu to close the program. ******************* Your version of Sun Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older versions of Sun Java,and then update. 1. Download the latest version of Java Runtime Environment (JRE) 2. Scroll down to where it says 'Java Runtime Environment (JRE) 6u1'. 3. Click the "Download" button to the right. 4. Check the box that says: "Accept License Agreement". 5. The page will refresh. 6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop. 7. Close any programs you may have running - especially your web browser. 8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java. 9. Check any item with Java Runtime Environment (JRE or J2SE) in the name. 10. Click the Change/Remove button. 11. Repeat as many times as necessary to remove each Java versions. 12. Reboot your computer once all Java components are removed. 13. Then from your desktop double-click on jre-6u1-windows-i586-p.exe to install the newest version. ******************* Enable SpySweeper and Spyware Doctor. ******************* Restart your pc. Post a new Hijackthis log in your next reply. Let me know how your pc is running now. -------------------- |
|
|
|
Jun 12 2007, 01:15 PM
Post
#5
|
|
|
New Member ![]() Group: Members Posts: 13 Joined: 11-June 07 Member No.: 136,144 |
Hi RichieUK,
Thanks so much for your help!!!! SO appreciated! I did what you specified and the pop ups are gone! Hopefully, it is all fixed. Here are my logs: Pocket Killbox version 2.0.0.881 Running on Windows XP as Owner(Administrator) was started @ Tuesday, June 12, 2007, 1:53 PM # 1 [Delete on Reboot] Path = C:\syswyez.exe # 2 [Delete on Reboot] Path = C:\WINDOWS\system32\monterreyk_redux.exe I Rebooted @ 1:57:18 PM Killbox Closed(Exit) @ 1:57:23 PM __________________________________________________ Pocket Killbox version 2.0.0.881 Running on Windows XP as Owner(Administrator) was started @ Tuesday, June 12, 2007, 2:05 PM ******************************************************* Logfile of HijackThis v1.99.1 Scan saved at 2:06:29 PM, on 6/12/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Softex\OmniPass\Omniserv.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\Softex\OmniPass\OPXPApp.exe C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\notepad.exe C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus8.hpwis.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1172825992515 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1172825953859 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing) |
|
|
|
Jun 12 2007, 01:29 PM
Post
#6
|
|
|
Malware Assassin ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 13,611 Joined: 13-July 06 Member No.: 75,975 |
Your log is clean
If all's ok,please do the following: Find and delete: Combofix Killbox C:\QooBox C:\!Killbox Click on Start/All Programs/Accessories/System Tools/System Restore. In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'. In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'. The date and time will be created automatically. Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup. The 'Select Drive' box will appear,click on Ok. The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab. At the bottom in the 'System Restore' window,click on the 'Clean up...' button. A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'. Click on 'Yes' at 'Are you sure you want to perform these actions?'. Now wait until 'Disk Cleanup' finishes and the box disappears. Read through the information found here,to help you prevent any possible future infections. 'How to prevent Malware' by miekiemoes: http://users.telenet.be/bluepatchy/miekiem...prevention.html -------------------- |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 8th November 2009 - 08:57 AM |