Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Ads, Help Requested.


  • Please log in to reply
3 replies to this topic

#1 ProtocolXIII

ProtocolXIII

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:46 PM

Posted 07 April 2006 - 01:27 PM

Okay, I was on the internet one day, looking for flash animations because I was bored, and Lo' and behold, my computer gets a few pieces of adware on it.

I have completely removed surfsidekick :thumbsup:(Including the repairs.dll thingy) , But there is still something else.
It just gives me random ads, and makes my internet experience a living nightmare.

If possible, can we try and AVOID safe mode? as my computer just seems to hang when trying to boot to that mode.

HJT Log -
Logfile of HijackThis v1.99.1
Scan saved at 19:25:58, on 07/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Voyager 105 ADSL Modem\dslstat.exe
C:\Program Files\Voyager 105 ADSL Modem\dslagent.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\DOfidon\MYDOCU~1\winzip32.exe
C:\DOCUME~1\TheKid\LOCALS~1\Temp\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [p2pnetworking] p2pnetworking.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\Voyager 105 ADSL Modem\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\Voyager 105 ADSL Modem\dslagent.exe
O4 - HKLM\..\Run: [webHancer Agent] C:\Program Files\webHancer\Programs\whagent.exe
O4 - HKLM\..\RunServices: [p2pnetworking] p2pnetworking.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: MacroMaker.lnk = ?
O4 - Startup: MSNP13 Downgrader.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O15 - Trusted Zone: http://support.euro.dell.com
O15 - Trusted Zone: *.moove.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1DA3C4AB-E6B6-47A6-B0F3-1BD81524B51B} (ActiveWorldsDownload Control) - http://www.activeworlds.com/products/ActiveWorldsDownload.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/pm/activex/eBay_Enhanced_Picture_Control_v1-0-3-30.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/0102068785c9ba645d06/netzip/RdxIE601.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{36C1306F-2E0D-4F29-9498-AA8D34CFFE61}: NameServer = 212.159.6.10 212.159.6.9
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: MediaContentIndex - C:\WINDOWS\system32\gpn4l35q1.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

All help would be nice.

BC AdBot (Login to Remove)

 


#2 ProtocolXIII

ProtocolXIII
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:46 PM

Posted 07 April 2006 - 02:03 PM

-Ran Look2Me Destroyer as a wild stab in the dark..and...

Look2Me-Destroyer V1.0.12

Scanning for infected files.....
Scan started at 07/04/2006 19:49:01

Infected! C:\WINDOWS\system32\gpn4l35q1.dll
Infected! C:\WINDOWS\SYSTEM32\vwsapi.dll
Infected! C:\WINDOWS\SYSTEM32\ilakeng.dll
Infected! C:\WINDOWS\SYSTEM32\ktr0l79m1.dll
Infected! C:\WINDOWS\SYSTEM32\mirating.dll
Infected! C:\WINDOWS\SYSTEM32\en4ul1h91.dll
Infected! C:\WINDOWS\SYSTEM32\h4n0le5m1h.dll
Infected! C:\WINDOWS\SYSTEM32\SacProc_ssp.dll
Infected! C:\WINDOWS\SYSTEM32\q4680ejueho80.dll
Infected! C:\WINDOWS\SYSTEM32\gpn4l35q1.dll
Infected! C:\WINDOWS\SYSTEM32\kt66l7js1.dll
Infected! C:\WINDOWS\SYSTEM32\h8j40i1qe8.dll
Infected! C:\WINDOWS\SYSTEM32\irr2l59o1.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP269\A0105134.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP269\A0105143.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP270\A0106146.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0107191.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0107395.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0107396.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0107397.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0107413.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0110419.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0110434.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0110442.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0111167.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0111176.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0112213.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0112216.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0112224.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0112227.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0112235.dll
Infected! C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0113296.dll

Attempting to delete infected files...

Attempting to delete: C:\WINDOWS\system32\gpn4l35q1.dll
C:\WINDOWS\system32\gpn4l35q1.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\vwsapi.dll
C:\WINDOWS\SYSTEM32\vwsapi.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\ilakeng.dll
C:\WINDOWS\SYSTEM32\ilakeng.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\ktr0l79m1.dll
C:\WINDOWS\SYSTEM32\ktr0l79m1.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\mirating.dll
C:\WINDOWS\SYSTEM32\mirating.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\en4ul1h91.dll
C:\WINDOWS\SYSTEM32\en4ul1h91.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\h4n0le5m1h.dll
C:\WINDOWS\SYSTEM32\h4n0le5m1h.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\SacProc_ssp.dll
C:\WINDOWS\SYSTEM32\SacProc_ssp.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\q4680ejueho80.dll
C:\WINDOWS\SYSTEM32\q4680ejueho80.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\gpn4l35q1.dll
C:\WINDOWS\SYSTEM32\gpn4l35q1.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\kt66l7js1.dll
C:\WINDOWS\SYSTEM32\kt66l7js1.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\h8j40i1qe8.dll
C:\WINDOWS\SYSTEM32\h8j40i1qe8.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\irr2l59o1.dll
C:\WINDOWS\SYSTEM32\irr2l59o1.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP269\A0105134.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP269\A0105134.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP269\A0105143.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP269\A0105143.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP270\A0106146.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP270\A0106146.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0107191.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0107191.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0107395.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0107395.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0107396.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0107396.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0107397.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0107397.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0107413.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0107413.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0110419.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0110419.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0110434.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0110434.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0110442.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0110442.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0111167.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0111167.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0111176.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0111176.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0112213.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0112213.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0112216.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0112216.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0112224.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0112224.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0112227.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0112227.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0112235.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0112235.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0113296.dll
C:\System Volume Information\_restore{E72048B9-FFA5-4C63-BBA0-79CAC283CA5A}\RP271\A0113296.dll Deleted successfully!

Making registry repairs.

Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MediaContentIndex

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{FEF10FA2-355E-4e06-9381-9B24D7F7CC88}"
HKCR\Clsid\{FEF10FA2-355E-4e06-9381-9B24D7F7CC88}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{53C74826-AB99-4d33-ACA4-3117F51D3788}"
HKCR\Clsid\{53C74826-AB99-4d33-ACA4-3117F51D3788}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{1CC21653-2C84-4AF6-A079-3605FFC71217}"
HKCR\Clsid\{1CC21653-2C84-4AF6-A079-3605FFC71217}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{FF418433-75C3-46AE-8712-C06DC73160D1}"
HKCR\Clsid\{FF418433-75C3-46AE-8712-C06DC73160D1}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded

Now posting a fresh HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 20:01:49, on 07/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Voyager 105 ADSL Modem\dslstat.exe
C:\Program Files\Voyager 105 ADSL Modem\dslagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\TheKid\LOCALS~1\Temp\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [p2pnetworking] p2pnetworking.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\Voyager 105 ADSL Modem\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\Voyager 105 ADSL Modem\dslagent.exe
O4 - HKLM\..\RunServices: [p2pnetworking] p2pnetworking.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: MacroMaker.lnk = ?
O4 - Startup: MSNP13 Downgrader.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://support.euro.dell.com
O15 - Trusted Zone: *.moove.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1DA3C4AB-E6B6-47A6-B0F3-1BD81524B51B} (ActiveWorldsDownload Control) - http://www.activeworlds.com/products/ActiveWorldsDownload.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/pm/activex/eBay_Enhanced_Picture_Control_v1-0-3-30.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/0102068785c9ba645d06/netzip/RdxIE601.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{36C1306F-2E0D-4F29-9498-AA8D34CFFE61}: NameServer = 212.159.6.9 212.159.6.10
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

Will see if the Ads are gone.

#3 ProtocolXIII

ProtocolXIII
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:46 PM

Posted 07 April 2006 - 03:47 PM

Seems like I helped myself, Ads are completely gone ^_^

#4 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:12:46 PM

Posted 12 April 2006 - 05:11 PM

Hi there and welcome to Bleeping Computer ! :thumbsup:
As you may have noticed already, the forums are very busy at the moment and i have noticed your log has gone unanswered so far!

We look at the oldest logs first, and we were wondering that if you still need help, please start by posting a new HijackThis log in this topic and i will then be able to take a look!

Thanks very much :flowers:

David




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users