Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Home search and other crap


  • Please log in to reply
1 reply to this topic

#1 JJ88

JJ88

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:05:27 PM

Posted 08 December 2004 - 05:04 PM

can someone plz help me, I have 3 programs that installed themselves on to my computer and wont go away. here's my hijackthis log.

Logfile of HijackThis v1.97.7
Scan saved at 4:46:26 PM, on 12/8/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\PROGRAM FILES\COMMON FILES\EPSON\EBAPI\SAGENT2.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\STOPZILLA!\SZNTSVC.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\STOPZILLA!\STOPZILLA.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\E_S10IC1.EXE
C:\PROGRAM FILES\GREETINGS WORKSHOP\GWREMIND.EXE
C:\PROGRAM FILES\INTERMUTE\SPYSUBTRACT\SPYSUB.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\NETZM32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\MY DOCUMENTS\MY MUSIC\NEW FOLDER\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\qyhlv.dll/sp.html#37680
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qyhlv.dll/sp.html#37680
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\qyhlv.dll/sp.html#37680
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\qyhlv.dll/sp.html#37680
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qyhlv.dll/sp.html#37680
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\qyhlv.dll/sp.html#37680
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\qyhlv.dll/sp.html#37680
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {3DD18F99-F4B2-E2CE-4499-B56B124A4263} - C:\WINDOWS\SYSTEM\APPKR.DLL
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [abu] abu.exe
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NETZM32.EXE] C:\WINDOWS\SYSTEM\NETZM32.EXE
O4 - HKLM\..\Run: [ADDLS32.EXE] C:\WINDOWS\SYSTEM\ADDLS32.EXE
O4 - HKLM\..\Run: [ADDBU32.EXE] C:\WINDOWS\SYSTEM\ADDBU32.EXE
O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe
O4 - HKLM\..\Run: [APIUH32.EXE] C:\WINDOWS\SYSTEM\APIUH32.EXE
O4 - HKLM\..\Run: [CRHR32.EXE] C:\WINDOWS\SYSTEM\CRHR32.EXE
O4 - HKLM\..\Run: [CRMC.EXE] C:\WINDOWS\SYSTEM\CRMC.EXE
O4 - HKLM\..\Run: [CRYV.EXE] C:\WINDOWS\SYSTEM\CRYV.EXE
O4 - HKLM\..\Run: [IPRS32.EXE] C:\WINDOWS\SYSTEM\IPRS32.EXE
O4 - HKLM\..\Run: [NTRI32.EXE] C:\WINDOWS\SYSTEM\NTRI32.EXE
O4 - HKLM\..\Run: [SYSCA.EXE] C:\WINDOWS\SYSTEM\SYSCA.EXE
O4 - HKLM\..\Run: [wklsakifr] C:\WINDOWS\SYSTEM\jedgiepj.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [SndSrvc] C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSRVC.EXE
O4 - HKLM\..\RunServices: [SAgent2ExePath] C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [STOPzilla Service] C:\PROGRAM FILES\STOPZILLA!\SZNTSVC.EXE
O4 - HKLM\..\RunServices: [IEJD.EXE] C:\WINDOWS\SYSTEM\IEJD.EXE
O4 - HKLM\..\RunServices: [NTTN32.EXE] C:\WINDOWS\NTTN32.EXE
O4 - HKLM\..\RunServices: [WINLM.EXE] C:\WINDOWS\WINLM.EXE
O4 - HKLM\..\RunServices: [ADDFG.EXE] C:\WINDOWS\SYSTEM\ADDFG.EXE
O4 - HKLM\..\RunServices: [WINHM.EXE] C:\WINDOWS\WINHM.EXE
O4 - HKLM\..\RunServices: [JAVABG.EXE] C:\WINDOWS\JAVABG.EXE
O4 - HKLM\..\RunServices: [WINAR.EXE] C:\WINDOWS\SYSTEM\WINAR.EXE
O4 - HKLM\..\RunServices: [MSRQ.EXE] C:\WINDOWS\MSRQ.EXE
O4 - HKLM\..\RunServices: [NETGL.EXE] C:\WINDOWS\SYSTEM\NETGL.EXE
O4 - HKLM\..\RunServices: [SYSQV32.EXE] C:\WINDOWS\SYSTEM\SYSQV32.EXE
O4 - HKLM\..\RunServices: [APPGV.EXE] C:\WINDOWS\APPGV.EXE
O4 - HKLM\..\RunServices: [ADDEU.EXE] C:\WINDOWS\ADDEU.EXE
O4 - HKLM\..\RunServices: [APIVR.EXE] C:\WINDOWS\SYSTEM\APIVR.EXE
O4 - HKLM\..\RunServices: [SDKAT.EXE] C:\WINDOWS\SYSTEM\SDKAT.EXE
O4 - HKLM\..\RunServices: [SYSGF32.EXE] C:\WINDOWS\SYSTEM\SYSGF32.EXE
O4 - HKLM\..\RunServices: [ADDDP32.EXE] C:\WINDOWS\ADDDP32.EXE
O4 - HKLM\..\RunServices: [ADDSA32.EXE] C:\WINDOWS\SYSTEM\ADDSA32.EXE
O4 - HKLM\..\RunServices: [APPHX.EXE] C:\WINDOWS\SYSTEM\APPHX.EXE
O4 - HKLM\..\RunServices: [ATLDC32.EXE] C:\WINDOWS\SYSTEM\ATLDC32.EXE
O4 - HKLM\..\RunServices: [WINFA.EXE] C:\WINDOWS\WINFA.EXE
O4 - HKLM\..\RunServices: [WINCV32.EXE] C:\WINDOWS\WINCV32.EXE
O4 - HKLM\..\RunServices: [NETPH.EXE] C:\WINDOWS\NETPH.EXE
O4 - HKLM\..\RunServices: [NETUK32.EXE] C:\WINDOWS\NETUK32.EXE
O4 - HKLM\..\RunServices: [D3VE32.EXE] C:\WINDOWS\D3VE32.EXE
O4 - HKLM\..\RunServices: [CRQO.EXE] C:\WINDOWS\CRQO.EXE
O4 - HKLM\..\RunServices: [MFCLD.EXE] C:\WINDOWS\SYSTEM\MFCLD.EXE
O4 - HKLM\..\RunServices: [NETGN32.EXE] C:\WINDOWS\NETGN32.EXE
O4 - HKLM\..\RunServices: [SYSZT32.EXE] C:\WINDOWS\SYSZT32.EXE
O4 - HKLM\..\RunServices: [JAVAQL32.EXE] C:\WINDOWS\JAVAQL32.EXE
O4 - HKLM\..\RunServices: [APPOC32.EXE] C:\WINDOWS\SYSTEM\APPOC32.EXE
O4 - HKLM\..\RunServices: [APPRR32.EXE] C:\WINDOWS\SYSTEM\APPRR32.EXE
O4 - HKLM\..\RunServices: [JAVAES.EXE] C:\WINDOWS\SYSTEM\JAVAES.EXE
O4 - HKLM\..\RunServices: [CRQL.EXE] C:\WINDOWS\CRQL.EXE
O4 - HKLM\..\RunServices: [D3TY32.EXE] C:\WINDOWS\D3TY32.EXE
O4 - HKLM\..\RunServices: [D3ZX32.EXE] C:\WINDOWS\D3ZX32.EXE
O4 - HKLM\..\RunServices: [NETRX32.EXE] C:\WINDOWS\SYSTEM\NETRX32.EXE
O4 - HKLM\..\RunServices: [APPDB32.EXE] C:\WINDOWS\APPDB32.EXE
O4 - HKLM\..\RunServices: [NETFU32.EXE] C:\WINDOWS\NETFU32.EXE
O4 - HKLM\..\RunServices: [CRNJ.EXE] C:\WINDOWS\CRNJ.EXE
O4 - HKLM\..\RunServices: [NTUC32.EXE] C:\WINDOWS\NTUC32.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\PROGRAM FILES\ARES\ARES.EXE" -h
O4 - HKCU\..\Run: [SuperAdBlocker] C:\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER\SADBLOCK.EXE
O4 - HKCU\..\Run: [EPSON Stylus C42 Series] C:\WINDOWS\SYSTEM\E_S10IC1.EXE /A "C:\WINDOWS\SYSTEM\E_S9101.TMP"
O4 - HKLM\..\RunOnce: [apiwv.exe] C:\WINDOWS\apiwv.exe
O4 - HKLM\..\RunOnce: [javavo.exe] C:\WINDOWS\system\javavo.exe
O4 - HKLM\..\RunOnce: [winrv32.exe] C:\WINDOWS\winrv32.exe
O4 - HKLM\..\RunOnce: [sdkfx32.exe] C:\WINDOWS\system\sdkfx32.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Greetings Workshop Reminders.lnk = C:\Program Files\Greetings Workshop\GWREMIND.EXE
O4 - Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O10 - Unknown file in Winsock LSP: c:\program files\oemji\oemjisearchplus\sfbnsp.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O15 - Trusted Zone: *.iframe.biz
O15 - Trusted Zone: *.sp2admin.biz
O15 - Trusted Zone: *.c4tdownload.com
O15 - Trusted Zone: *.overpro.com
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/27603f7599b24a...ip/RdxIE601.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...director/sw.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...8255.7182060185
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d.../ITDetector.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/...tterInstall.cab

BC AdBot (Login to Remove)

 


m

#2 Daisuke

Daisuke

    Cleaner on Duty


  • Members
  • 5,575 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Romania
  • Local time:05:27 PM

Posted 12 December 2004 - 09:48 AM

Hi

Sorry for this delay.

If you still have problems read below.

You are running an outdated version of HijackThis.. Delete the copy you have and download the latest version of HijackThis!: Download here HJT 1.98.2. Save it on your Desktop. You will need now to unzip hijackthis.exe to a permanent folder, such as c:\hjt . This has to be done as HijackThis creates backups. You may need to use these backups.

First create a new folder:
A. Click My Computer icon on your desktop
B. Click C: drive
C. Click the File menu --> New --> Folder, a folder "New folder" will be created.
D. Rename it HJT

Unzip hijackthis.exe to the c:\HJT folder.


Follow this link to download ServiceFilter: ServiceFilter download

Unzip the content to a folder, such as c:\ServiceFilter.

Navigate to c:\ServiceFilter folder and (double)click the ServiceFilter.vbs file.

If you have a script blocking program you will get a warning asking if you want to allow ServiceFilter.vbs to run. Allow the script to run.

Note: The script DOES NOT find bad services, it simply filters out what is known to be ok.

Follow the instructions on the screen and WordPad will open.

In WordPad click
Edit menu --> Select All
then
Edit menu --> Copy


Right click in the message area and click on the paste option to paste the log into the post.


Post please also a fresh HJT log.

From the moment you post your list, until you see a detailed fix written up, DO NOT reboot your system or log off. If you do, the service will have changed and the fix provided will not work.
Everyday is virus day. Do you know where your recovery CDs are ?
Did you create them yet ?

Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users