angeloftheflames Posted December 8, 2004 Report Share Posted December 8, 2004 Logfile of HijackThis v1.98.2Scan saved at 8:53:12 PM, on 12/7/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exec:\WINDOWS\Resources\Themes\StyleXP\StyleXPService.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\Nhksrv.exeC:\WINDOWS\System32\CTSvcCDA.EXEC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\Program Files\Network Associates\VirusScan\mcshield.exeC:\Program Files\Network Associates\VirusScan\vstskmgr.exeC:\WINDOWS\System32\nvsvc32.exeC:\Program Files\PRTG Traffic Grapher 4\prtg4.exeC:\Program Files\PRTG Traffic Grapher 4\prtg4.exeC:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exeC:\Program Files\Winamp\winampa.exeC:\WINDOWS\System32\ctfmon.exeC:\Program Files\Microsoft ActiveSync\WCESCOMM.EXEC:\Program Files\Webroot\Spy Sweeper\SpySweeper.exeC:\Documents and Settings\Morning Star\Application Data\swnr.exeC:\PROGRA~1\Serv-U\ServUDaemon.exeC:\Program Files\Analog Devices\SoundMAX\SMAgent.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\MsPMSPSv.exeC:\Program Files\Microsoft ActiveSync\WCESMgr.exeC:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXEC:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\AIM\aim.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\WinRAR\WinRAR.exeC:\DOCUME~1\MORNIN~1\LOCALS~1\Temp\Rar$EX00.323\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\winxp\system32\blank.htmR3 - Default URLSearchHook is missingO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {9CC9DE59-1EE8-1363-BC2B-3976146B5796} - C:\WINDOWS\System32\sdq.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe /rO4 - HKLM\..\Run: [updReg] C:\WINDOWS\UpdReg.EXEO4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exeO4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -sO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exeO4 - HKCU\..\Run: [sTYLEXP] C:\WINDOWS\Resources\Themes\StyleXP\StyleXP.exe -HideO4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /backgroundO4 - HKCU\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /1O4 - HKCU\..\Run: [Clock] C:\WINDOWS\msswchx.exeO4 - HKCU\..\Run: [Oiir] C:\Documents and Settings\Morning Star\Application Data\swnr.exeO4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\eMule.exe -AutoStartO4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.htmlO8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.htmlO8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.htmlO9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLLO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...382/mcfscan.cabO16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://sea2fd.sea2.hotmail.msn.com/activex/HMAtchmt.ocxO17 - HKLM\System\CCS\Services\Tcpip\..\{CE701EB7-DBF8-4077-A700-04166A1ECA9C}: NameServer = 209.47.15.118,64.157.143.38,207.69.188.185,207.69.188.186 Link to post Share on other sites
angeloftheflames Posted December 8, 2004 Author Report Share Posted December 8, 2004 Logfile of HijackThis v1.98.2Scan saved at 9:35:53 PM, on 12/7/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exec:\WINDOWS\Resources\Themes\StyleXP\StyleXPService.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\Nhksrv.exeC:\WINDOWS\System32\CTSvcCDA.EXEC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\Program Files\Network Associates\VirusScan\mcshield.exeC:\Program Files\Network Associates\VirusScan\vstskmgr.exeC:\WINDOWS\System32\nvsvc32.exeC:\Program Files\PRTG Traffic Grapher 4\prtg4.exeC:\Program Files\PRTG Traffic Grapher 4\prtg4.exeC:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exeC:\Program Files\Winamp\winampa.exeC:\WINDOWS\System32\ctfmon.exeC:\Program Files\Microsoft ActiveSync\WCESCOMM.EXEC:\Program Files\Webroot\Spy Sweeper\SpySweeper.exeC:\Documents and Settings\Morning Star\Application Data\swnr.exeC:\PROGRA~1\Serv-U\ServUDaemon.exeC:\Program Files\Analog Devices\SoundMAX\SMAgent.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\MsPMSPSv.exeC:\Program Files\Microsoft ActiveSync\WCESMgr.exeC:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXEC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\AIM\aim.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\HJT\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\winxp\system32\blank.htmR3 - Default URLSearchHook is missingO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {9CC9DE59-1EE8-1363-BC2B-3976146B5796} - C:\WINDOWS\System32\sdq.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe /rO4 - HKLM\..\Run: [updReg] C:\WINDOWS\UpdReg.EXEO4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exeO4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -sO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exeO4 - HKCU\..\Run: [sTYLEXP] C:\WINDOWS\Resources\Themes\StyleXP\StyleXP.exe -HideO4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /backgroundO4 - HKCU\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /1O4 - HKCU\..\Run: [Clock] C:\WINDOWS\msswchx.exeO4 - HKCU\..\Run: [Oiir] C:\Documents and Settings\Morning Star\Application Data\swnr.exeO4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\eMule.exe -AutoStartO4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.htmlO8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.htmlO8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.htmlO9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLLO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...382/mcfscan.cabO16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://sea2fd.sea2.hotmail.msn.com/activex/HMAtchmt.ocxO17 - HKLM\System\CCS\Services\Tcpip\..\{CE701EB7-DBF8-4077-A700-04166A1ECA9C}: NameServer = 209.47.15.118,64.157.143.38,207.69.188.185,207.69.188.186 Link to post Share on other sites
Dragon Posted December 8, 2004 Report Share Posted December 8, 2004 You have a Large Amount of Trojans and Viruses on Your Computer.Download a Free Trial of Trojan Hunter at http://www.misec.net/products/TrojanHunter.exe first. Next, take a free Online Virus scan at http://www.housecall.trendmicro.com or http://www3.ca.com/virusinfo/virusscan.aspx. After this, Reboot and Post a fresh HijackThis log.We still have a long way to go. Link to post Share on other sites
angeloftheflames Posted December 8, 2004 Author Report Share Posted December 8, 2004 Logfile of HijackThis v1.98.2Scan saved at 9:56:36 PM, on 12/7/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exec:\WINDOWS\Resources\Themes\StyleXP\StyleXPService.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\Nhksrv.exeC:\WINDOWS\System32\CTSvcCDA.EXEC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\Program Files\Network Associates\VirusScan\mcshield.exeC:\Program Files\Network Associates\VirusScan\vstskmgr.exeC:\WINDOWS\System32\nvsvc32.exeC:\Program Files\PRTG Traffic Grapher 4\prtg4.exeC:\Program Files\PRTG Traffic Grapher 4\prtg4.exeC:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exeC:\WINDOWS\System32\ctfmon.exeC:\Program Files\Microsoft ActiveSync\WCESCOMM.EXEC:\Program Files\Webroot\Spy Sweeper\SpySweeper.exeC:\Documents and Settings\Morning Star\Application Data\swnr.exeC:\PROGRA~1\Serv-U\ServUDaemon.exeC:\Program Files\Analog Devices\SoundMAX\SMAgent.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\MsPMSPSv.exeC:\Program Files\Microsoft ActiveSync\WCESMgr.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exeC:\Program Files\HJT\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\winxp\system32\blank.htmR3 - Default URLSearchHook is missingO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {9CC9DE59-1EE8-1363-BC2B-3976146B5796} - C:\WINDOWS\System32\sdq.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe /rO4 - HKLM\..\Run: [updReg] C:\WINDOWS\UpdReg.EXEO4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exeO4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -sO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exeO4 - HKCU\..\Run: [sTYLEXP] C:\WINDOWS\Resources\Themes\StyleXP\StyleXP.exe -HideO4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /backgroundO4 - HKCU\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /1O4 - HKCU\..\Run: [Clock] C:\WINDOWS\msswchx.exeO4 - HKCU\..\Run: [Oiir] C:\Documents and Settings\Morning Star\Application Data\swnr.exeO4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\eMule.exe -AutoStartO4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.htmlO8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.htmlO8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.htmlO9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLLO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...382/mcfscan.cabO16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://sea2fd.sea2.hotmail.msn.com/activex/HMAtchmt.ocxO17 - HKLM\System\CCS\Services\Tcpip\..\{CE701EB7-DBF8-4077-A700-04166A1ECA9C}: NameServer = 209.47.15.118,64.157.143.38,207.69.188.185,207.69.188.186 Link to post Share on other sites
angeloftheflames Posted December 8, 2004 Author Report Share Posted December 8, 2004 Logfile of HijackThis v1.98.2Scan saved at 10:26:12 AM, on 12/8/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exec:\WINDOWS\Resources\Themes\StyleXP\StyleXPService.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\Nhksrv.exeC:\WINDOWS\System32\CTSvcCDA.EXEC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\Program Files\Network Associates\VirusScan\mcshield.exeC:\Program Files\Network Associates\VirusScan\vstskmgr.exeC:\WINDOWS\System32\nvsvc32.exeC:\Program Files\PRTG Traffic Grapher 4\prtg4.exeC:\Program Files\PRTG Traffic Grapher 4\prtg4.exeC:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exeC:\WINDOWS\System32\ctfmon.exeC:\Program Files\Microsoft ActiveSync\WCESCOMM.EXEC:\Program Files\Webroot\Spy Sweeper\SpySweeper.exeC:\Documents and Settings\Morning Star\Application Data\swnr.exeC:\PROGRA~1\Serv-U\ServUDaemon.exeC:\Program Files\Analog Devices\SoundMAX\SMAgent.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\MsPMSPSv.exeC:\Program Files\Microsoft ActiveSync\WCESMgr.exeC:\Program Files\mIRC\mirc.exeC:\WINDOWS\winampa.exeC:\Program Files\Winamp\winamp.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\HJT\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\winxp\system32\blank.htmR3 - Default URLSearchHook is missingO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {9CC9DE59-1EE8-1363-BC2B-3976146B5796} - C:\WINDOWS\System32\sdq.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe /rO4 - HKLM\..\Run: [updReg] C:\WINDOWS\UpdReg.EXEO4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exeO4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -sO4 - HKLM\..\Run: [THGuard] C:\Program Files\TrojanHunter 4.0\THGuard.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exeO4 - HKCU\..\Run: [sTYLEXP] C:\WINDOWS\Resources\Themes\StyleXP\StyleXP.exe -HideO4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /backgroundO4 - HKCU\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /1O4 - HKCU\..\Run: [Clock] C:\WINDOWS\msswchx.exeO4 - HKCU\..\Run: [Oiir] C:\Documents and Settings\Morning Star\Application Data\swnr.exeO4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\eMule.exe -AutoStartO4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.htmlO8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.htmlO8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.htmlO9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLLO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...382/mcfscan.cabO16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://sea2fd.sea2.hotmail.msn.com/activex/HMAtchmt.ocxO17 - HKLM\System\CCS\Services\Tcpip\..\{CE701EB7-DBF8-4077-A700-04166A1ECA9C}: NameServer = 209.47.15.118,64.157.143.38,207.69.188.185,207.69.188.186 Link to post Share on other sites
Besttechie Posted December 8, 2004 Report Share Posted December 8, 2004 Hi,Please be patient. Efwis will be back to finish your log as soon as possible. B Link to post Share on other sites
Dragon Posted December 9, 2004 Report Share Posted December 9, 2004 Hello sorry for the delay;Please look over the Following Entries I have listed, run Hijack This again and check them and then, making sure you have No Internet Explorer Windows open, including this one, Press the "Fix Checked" Button with HijackThis.Reboot If I have specified below, and Post a Fresh HijackThis log.R3 - Default URLSearchHook is missingO2 - BHO: (no name) - {9CC9DE59-1EE8-1363-BC2B-3976146B5796} - C:\WINDOWS\System32\sdq.dllO4 - HKLM\..\Run: [updReg] C:\WINDOWS\UpdReg.EXEO4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -sO4 - HKCU\..\Run: [Oiir] C:\Documents and Settings\Morning Star\Application Data\swnr.exedid you set these up? if not go ahead and click on these and fix them too.O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentAfter this, Reboot and Delete the following files:C:\WINDOWS\System32\sdq.dllC:\PROGRA~1\NEWDOT~1C:\Documents and Settings\Morning StarNote: Make sure you have Set Windows to show Hidden Files & Folders before you Start Sending Them to us For Analysis, or you're deleting them. This can be done by looking at the instructions at This Webpage http://www.xtra.co.nz/help/0,,4155-1916458,00.htmlTo Delete These Files/Folders, You Will need to Boot into Safe Mode. This can be done by tapping F8 while your machine restarts.Then reboot into normal mode and post a new Hijack this log. Link to post Share on other sites
angeloftheflames Posted December 9, 2004 Author Report Share Posted December 9, 2004 Thanks for posting Efwis, my browser is fixed but if you see anything more please tell me so i can remove itLogfile of HijackThis v1.98.2Scan saved at 4:43:01 PM, on 12/9/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exec:\WINDOWS\Resources\Themes\StyleXP\StyleXPService.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Nhksrv.exeC:\WINDOWS\System32\alg.exeC:\WINDOWS\System32\CTSvcCDA.EXEC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\Program Files\Network Associates\VirusScan\mcshield.exeC:\Program Files\Network Associates\VirusScan\vstskmgr.exeC:\WINDOWS\System32\nvsvc32.exeC:\Program Files\PRTG Traffic Grapher 4\prtg4.exeC:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exeC:\Program Files\PRTG Traffic Grapher 4\prtg4.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exeC:\Program Files\Winamp\winampa.exeC:\WINDOWS\System32\ctfmon.exeC:\Program Files\Microsoft ActiveSync\WCESCOMM.EXEC:\Program Files\AIM\aim.exeC:\Program Files\MSN Messenger\msnmsgr.exeC:\Program Files\Webroot\Spy Sweeper\SpySweeper.exeC:\Program Files\eMule\eMule.exeC:\PROGRA~1\Serv-U\ServUDaemon.exeC:\Program Files\Analog Devices\SoundMAX\SMAgent.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\wdfmgr.exeC:\WINDOWS\System32\MsPMSPSv.exeC:\Program Files\mIRC\mirc.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\HJT\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\winxp\system32\blank.htmO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe /rO4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exeO4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exeO4 - HKCU\..\Run: [sTYLEXP] C:\WINDOWS\Resources\Themes\StyleXP\StyleXP.exe -HideO4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /backgroundO4 - HKCU\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /1O4 - HKCU\..\Run: [Clock] C:\WINDOWS\msswchx.exeO4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\eMule.exe -AutoStartO4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.htmlO8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.htmlO8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.htmlO9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLLO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...382/mcfscan.cabO16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://sea2fd.sea2.hotmail.msn.com/activex/HMAtchmt.ocxO17 - HKLM\System\CCS\Services\Tcpip\..\{CE701EB7-DBF8-4077-A700-04166A1ECA9C}: NameServer = 209.47.15.118,64.157.143.38,207.69.188.185,207.69.188.186 Link to post Share on other sites
Dragon Posted December 10, 2004 Report Share Posted December 10, 2004 fixing via chatroom at #killspyware Link to post Share on other sites
angeloftheflames Posted December 10, 2004 Author Report Share Posted December 10, 2004 Logfile of HijackThis v1.98.2Scan saved at 11:25:08 PM, on 12/9/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exec:\WINDOWS\Resources\Themes\StyleXP\StyleXPService.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\Nhksrv.exeC:\WINDOWS\System32\alg.exeC:\WINDOWS\System32\CTSvcCDA.EXEC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\Program Files\Network Associates\VirusScan\mcshield.exeC:\Program Files\Network Associates\VirusScan\vstskmgr.exeC:\WINDOWS\System32\nvsvc32.exeC:\Program Files\PRTG Traffic Grapher 4\prtg4.exeC:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exeC:\Program Files\PRTG Traffic Grapher 4\prtg4.exeC:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exeC:\Program Files\Winamp\winampa.exeC:\WINDOWS\System32\ctfmon.exeC:\Program Files\Microsoft ActiveSync\WCESCOMM.EXEC:\Program Files\AIM\aim.exeC:\Program Files\MSN Messenger\msnmsgr.exeC:\Program Files\Webroot\Spy Sweeper\SpySweeper.exeC:\Program Files\eMule\eMule.exeC:\Program Files\Analog Devices\SoundMAX\SMAgent.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\wdfmgr.exeC:\WINDOWS\System32\MsPMSPSv.exeC:\WINDOWS\System32\wuauclt.exeC:\Program Files\HJT\HijackThis.exeO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe /rO4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exeO4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exeO4 - HKCU\..\Run: [sTYLEXP] C:\WINDOWS\Resources\Themes\StyleXP\StyleXP.exe -HideO4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /backgroundO4 - HKCU\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /1O4 - HKCU\..\Run: [Clock] C:\WINDOWS\msswchx.exeO4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\eMule.exe -AutoStartO4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.htmlO8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.htmlO8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.htmlO9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLLO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...382/mcfscan.cabO16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://sea2fd.sea2.hotmail.msn.com/activex/HMAtchmt.ocxO17 - HKLM\System\CCS\Services\Tcpip\..\{CE701EB7-DBF8-4077-A700-04166A1ECA9C}: NameServer = 209.47.15.118,64.157.143.38,207.69.188.185,207.69.188.186 Link to post Share on other sites
Dragon Posted December 10, 2004 Report Share Posted December 10, 2004 Your Log is Clean, But You Need to Update Windows and IE to get all the Latest Security Patches that Protects Your Computer.This can be accessed by going to http://www.windowsupdate.com/ and following the prompts Get SP2.For Future ProtectionDownload and install:SpywareBlaster will block bad ActiveX and malevolent cookies. http://www.javacoolsoftware.com/spywareblaster.htmlIE-SPYAD puts over 4000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.https://netfiles.uiuc.edu/ehowes/www/resource.htm#IESPYADBoth are very small free programs that you run once, and then just occasionally to check for updates.And also see So how did I get infected in the first place? Link to post Share on other sites
Dragon Posted December 11, 2004 Report Share Posted December 11, 2004 As it seems that this is straightened out, i am locking this thread. If you need this thread re-opened please contact a moderator with a link to this thread to have it reopened.If this is not your thread, please start a new topicThank you Link to post Share on other sites
Psykel Posted December 11, 2004 Report Share Posted December 11, 2004 there seem,s to be anohter problem so Im gonna take over.. Link to post Share on other sites
angeloftheflames Posted December 11, 2004 Author Report Share Posted December 11, 2004 Logfile of HijackThis v1.98.2Scan saved at 6:40:46 PM, on 12/11/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exec:\WINDOWS\Resources\Themes\StyleXP\StyleXPService.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\Nhksrv.exeC:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exeC:\WINDOWS\System32\alg.exeC:\Program Files\Winamp\winampa.exeC:\WINDOWS\System32\CTSvcCDA.EXEC:\WINDOWS\System32\ctfmon.exeC:\Program Files\Microsoft ActiveSync\WCESCOMM.EXEC:\Program Files\AIM\aim.exeC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\Program Files\MSN Messenger\msnmsgr.exeC:\Program Files\Webroot\Spy Sweeper\SpySweeper.exeC:\Program Files\Network Associates\VirusScan\mcshield.exeC:\Program Files\Network Associates\VirusScan\vstskmgr.exeC:\WINDOWS\System32\nvsvc32.exeC:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exeC:\Program Files\PRTG Traffic Grapher 4\prtg4.exeC:\Program Files\PRTG Traffic Grapher 4\prtg4.exeC:\Program Files\Analog Devices\SoundMAX\SMAgent.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\wdfmgr.exeC:\WINDOWS\System32\MsPMSPSv.exeC:\WINDOWS\System32\wuauclt.exeC:\Program Files\mIRC\mirc.exeC:\Program Files\HJT\HijackThis.exeO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe /rO4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exeO4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exeO4 - HKCU\..\Run: [sTYLEXP] C:\WINDOWS\Resources\Themes\StyleXP\StyleXP.exe -HideO4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /backgroundO4 - HKCU\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /1O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\eMule.exe -AutoStartO4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.htmlO8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.htmlO8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.htmlO9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLLO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLLO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...382/mcfscan.cabO16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://sea2fd.sea2.hotmail.msn.com/activex/HMAtchmt.ocxO17 - HKLM\System\CCS\Services\Tcpip\..\{CE701EB7-DBF8-4077-A700-04166A1ECA9C}: NameServer = 209.47.15.118,64.157.143.38,207.69.188.185,207.69.188.186 Link to post Share on other sites
angeloftheflames Posted December 12, 2004 Author Report Share Posted December 12, 2004 127.0.0.1 localhost127.0.0.1 www.doubleclick.net127.0.0.1 ad.preferances.com127.0.0.1 ad.doubleclick.com127.0.0.1 ads.web.aol.com127.0.0.1 ad.doubleclick.net127.0.0.1 ad.preferences.com127.0.0.1 ad.washingtonpost.com127.0.0.1 adpick.switchboard.com127.0.0.1 ads.doubleclick.com127.0.0.1 ads.infospace.com127.0.0.1 ads.msn.com127.0.0.1 ads.switchboard.com127.0.0.1 ads.enliven.com127.0.0.1 oz.valueclick.com127.0.0.1 doubleclick.net127.0.0.1 ads.doubleclick.net127.0.0.1 ad2.doubleclick.net127.0.0.1 ad3.doubleclick.net127.0.0.1 ad4.doubleclick.net127.0.0.1 ad5.doubleclick.net127.0.0.1 ad6.doubleclick.net127.0.0.1 ad7.doubleclick.net127.0.0.1 ad8.doubleclick.net127.0.0.1 ad9.doubleclick.net127.0.0.1 ad10.doubleclick.net127.0.0.1 ad11.doubleclick.net127.0.0.1 ad12.doubleclick.net127.0.0.1 ad13.doubleclick.net127.0.0.1 ad14.doubleclick.net127.0.0.1 ad15.doubleclick.net127.0.0.1 ad16.doubleclick.net127.0.0.1 ad17.doubleclick.net127.0.0.1 ad18.doubleclick.net127.0.0.1 ad19.doubleclick.net127.0.0.1 ad20.doubleclick.net127.0.0.1 ad.ch.doubleclick.net127.0.0.1 ad.linkexchange.com127.0.0.1 banner.linkexchange.com127.0.0.1 ads*.focalink.com127.0.0.1 ads.imdb.com127.0.0.1 commonwealth.riddler.com127.0.0.1 globaltrak.net127.0.0.1 nrsite.com127.0.0.1 www.nrsite.com127.0.0.1 ad-up.com127.0.0.1 ad.adsmart.net127.0.0.1 ad.atlas.cz127.0.0.1 ad.blm.net127.0.0.1 ad.dogpile.com127.0.0.1 ad.infoseek.com127.0.0.1 ad.net-service.de127.0.0.1 ad.preferences.com127.0.0.1 ad.vol.at127.0.0.1 adbot.com127.0.0.1 adbureau.net127.0.0.1 adcount.hollywood.com127.0.0.1 add.yaho.com127.0.0.1 adex3.flycast.com127.0.0.1 adforce.adtech.de127.0.0.1 adforce.imgis.com127.0.0.1 adimage.blm.net127.0.0.1 adlink.deh.de127.0.0.1 ads.criticalmass.com127.0.0.1 ads.csi.emcweb.com127.0.0.1 ads.filez.com127.0.0.1 ads.imagine-inc.com127.0.0.1 ads.imdb.com127.0.0.1 ads.infospace.com127.0.0.1 ads.jwtt3.com127.0.0.1 ads.mirrormedia.co.uk127.0.0.1 ads.msn.com127.0.0.1 ads.narrowline.com127.0.0.1 ads.newcitynet.com127.0.0.1 ads.realcities.com127.0.0.1 ads.realmedia.com127.0.0.1 ads.switchboard.com127.0.0.1 ads.tripod.com127.0.0.1 ads.usatoday.com127.0.0.1 ads.washingtonpost.com127.0.0.1 ads.web.de127.0.0.1 ads.web21.com127.0.0.1 adserv.newcentury.net127.0.0.1 adservant.guj.de127.0.0.1 adservant.mediapoint.de127.0.0.1 adserver-espnet.sportszone.com127.0.0.1 advert.heise.de127.0.0.1 banners.internetextra.com127.0.0.1 bannerswap.com127.0.0.1 dino.mainz.ibm.de127.0.0.1 ganges.imagine-inc.com127.0.0.1 globaltrack.com127.0.0.1 207-87-18-203.wsmg.digex.net127.0.0.1 garden.ngadcenter.net127.0.0.1 ogilvy.ngadcenter.net127.0.0.1 responsemedia-ad.flycast.com127.0.0.1 suissa-ad.flycast.com127.0.0.1 ugo.eu-adcenter.net127.0.0.1 vnu.eu-adcenter.net127.0.0.1 ad-adex3.flycast.com127.0.0.1 ad.adsmart.net127.0.0.1 ad.ca.doubleclick.net127.0.0.1 ad.de.doubleclick.net127.0.0.1 ad.fr.doubleclick.net127.0.0.1 ad.jp.doubleclick.net127.0.0.1 ad.linkexchange.com127.0.0.1 ad.linksynergy.com127.0.0.1 ad.nl.doubleclick.net127.0.0.1 ad.no.doubleclick.net127.0.0.1 ad.sma.punto.net127.0.0.1 ad.uk.doubleclick.net127.0.0.1 ad.webprovider.com127.0.0.1 ad08.focalink.com127.0.0.1 adcontroller.unicast.com127.0.0.1 adcreatives.imaginemedia.com127.0.0.1 adforce.ads.imgis.com127.0.0.1 adforce.imgis.com127.0.0.1 adfu.blockstackers.com127.0.0.1 adimages.earthweb.com127.0.0.1 adimg.egroups.com127.0.0.1 admedia.xoom.com127.0.0.1 adremote.pathfinder.com127.0.0.1 ads.admaximize.com127.0.0.1 ads.bfast.com127.0.0.1 ads.clickhouse.com127.0.0.1 ads.fairfax.com.au127.0.0.1 ads.fool.com127.0.0.1 ads.freshmeat.net127.0.0.1 ads.hollywood.com127.0.0.1 ads.i33.com127.0.0.1 ads.infi.net127.0.0.1 ads.link4ads.com127.0.0.1 ads.lycos.com127.0.0.1 ads.madison.com127.0.0.1 ads.mediaodyssey.com127.0.0.1 ads.msn.com127.0.0.1 ads.ninemsn.com.au127.0.0.1 ads.seattletimes.com127.0.0.1 ads.smartclicks.com127.0.0.1 ads.smartclicks.net127.0.0.1 ads.sptimes.com127.0.0.1 ads.web.aol.com127.0.0.1 ads.x10.com127.0.0.1 ads.xtra.co.nz127.0.0.1 ads.zdnet.com127.0.0.1 ads01.focalink.com127.0.0.1 ads02.focalink.com127.0.0.1 ads03.focalink.com127.0.0.1 ads04.focalink.com127.0.0.1 ads05.focalink.com127.0.0.1 ads06.focalink.com127.0.0.1 ads08.focalink.com127.0.0.1 ads09.focalink.com127.0.0.1 ads1.activeagent.at127.0.0.1 ads10.focalink.com127.0.0.1 ads11.focalink.com127.0.0.1 ads12.focalink.com127.0.0.1 ads14.focalink.com127.0.0.1 ads16.focalink.com127.0.0.1 ads17.focalink.com127.0.0.1 ads18.focalink.com127.0.0.1 ads19.focalink.com127.0.0.1 ads2.zdnet.com127.0.0.1 ads20.focalink.com127.0.0.1 ads21.focalink.com127.0.0.1 ads22.focalink.com127.0.0.1 ads23.focalink.com127.0.0.1 ads24.focalink.com127.0.0.1 ads25.focalink.com127.0.0.1 ads3.zdnet.com127.0.0.1 ads5.gamecity.net127.0.0.1 adserv.iafrica.com127.0.0.1 adserv.quality-channel.de127.0.0.1 adserver.dbusiness.com127.0.0.1 adserver.garden.com127.0.0.1 adserver.janes.com127.0.0.1 adserver.merc.com127.0.0.1 adserver.monster.com127.0.0.1 adserver.track-star.com127.0.0.1 adserver1.ogilvy-interactive.de127.0.0.1 adtegrity.spinbox.net127.0.0.1 antfarm-ad.flycast.com127.0.0.1 au.ads.link4ads.com127.0.0.1 banner.media-system.de127.0.0.1 banner.orb.net127.0.0.1 banner.relcom.ru127.0.0.1 banners.easydns.com127.0.0.1 banners.looksmart.com127.0.0.1 banners.wunderground.com127.0.0.1 barnesandnoble.bfast.com127.0.0.1 beseenad.looksmart.com127.0.0.1 bizad.nikkeibp.co.jp127.0.0.1 bn.bfast.com127.0.0.1 c3.xxxcounter.com127.0.0.1 califia.imaginemedia.com127.0.0.1 cds.mediaplex.com127.0.0.1 click.avenuea.com127.0.0.1 click.go2net.com127.0.0.1 click.linksynergy.com127.0.0.1 cookies.cmpnet.com127.0.0.1 cornflakes.pathfinder.com127.0.0.1 counter.hitbox.com127.0.0.1 crux.songline.com127.0.0.1 erie.smartage.com127.0.0.1 etad.telegraph.co.uk127.0.0.1 fp.valueclick.com127.0.0.1 gadgeteer.pdamart.com127.0.0.1 gm.preferences.com127.0.0.1 gp.dejanews.com127.0.0.1 hg1.hitbox.com127.0.0.1 image.click2net.com127.0.0.1 image.eimg.com127.0.0.1 images2.nytimes.com127.0.0.1 jobkeys.ngadcenter.net127.0.0.1 kansas.valueclick.com127.0.0.1 leader.linkexchange.com127.0.0.1 liquidad.narrowcastmedia.com127.0.0.1 ln.doubleclick.net127.0.0.1 m.doubleclick.net127.0.0.1 macaddictads.snv.futurenet.com127.0.0.1 maximumpcads.imaginemedia.com127.0.0.1 media.preferences.com127.0.0.1 mercury.rmuk.co.uk127.0.0.1 mojofarm.sjc.mediaplex.com127.0.0.1 nbc.adbureau.net127.0.0.1 newads.cmpnet.com127.0.0.1 ng3.ads.warnerbros.com127.0.0.1 ngads.smartage.com127.0.0.1 nsads.hotwired.com127.0.0.1 ntbanner.digitalriver.com127.0.0.1 ph-ad05.focalink.com127.0.0.1 ph-ad07.focalink.com127.0.0.1 ph-ad16.focalink.com127.0.0.1 ph-ad17.focalink.com127.0.0.1 ph-ad18.focalink.com127.0.0.1 realads.realmedia.com127.0.0.1 redherring.ngadcenter.net127.0.0.1 redirect.click2net.com127.0.0.1 retaildirect.realmedia.com127.0.0.1 s2.focalink.com127.0.0.1 sh4sure-images.adbureau.net127.0.0.1 spin.spinbox.net127.0.0.1 static.admaximize.com127.0.0.1 stats.superstats.com127.0.0.1 sview.avenuea.com127.0.0.1 thinknyc.eu-adcenter.net127.0.0.1 tracker.clicktrade.com127.0.0.1 tsms-ad.tsms.com127.0.0.1 v0.extreme-dm.com127.0.0.1 v1.extreme-dm.com127.0.0.1 van.ads.link4ads.com127.0.0.1 view.accendo.com127.0.0.1 view.avenuea.com127.0.0.1 w113.hitbox.com127.0.0.1 w25.hitbox.com127.0.0.1 web2.deja.com127.0.0.1 webads.bizservers.com127.0.0.1 www.postmasterbannernet.com127.0.0.1 www.ad-up.com127.0.0.1 www.admex.com127.0.0.1 www.alladvantage.com127.0.0.1 www.burstnet.com127.0.0.1 www.commission-junction.com127.0.0.1 www.eads.com127.0.0.1 www.freestats.com127.0.0.1 www.imaginemedia.com127.0.0.1 www.netdirect.nl127.0.0.1 www.oneandonlynetwork.com127.0.0.1 www.targetshop.com127.0.0.1 www.teknosurf2.com127.0.0.1 www.teknosurf3.com127.0.0.1 www.valueclick.com127.0.0.1 www.websitefinancing.com127.0.0.1 www2.burstnet.com127.0.0.1 www4.trix.net127.0.0.1 www80.valueclick.com127.0.0.1 z.extreme-dm.com127.0.0.1 z0.extreme-dm.com127.0.0.1 z1.extreme-dm.com127.0.0.1 ads.forbes.net127.0.0.1 ads.newcity.com127.0.0.1 ads.ign.com127.0.0.1 adserver.ign.com127.0.0.1 ads.scifi.com127.0.0.1 adengine.theglobe.com127.0.0.1 ads.tucows.com127.0.0.1 adcontent.gamespy.com127.0.0.1 ads4.advance.net127.0.0.1 ads1.advance.net127.0.0.1 eur.yimg.com127.0.0.1 us.a1.yimg.com127.0.0.1 ad.harmony-central.com127.0.0.1 sg.yimg.com127.0.0.1 adverity.adverity.com127.0.0.1 ads.bloomberg.com127.0.0.1 mojofarm.mediaplex.com127.0.0.1 ads.mysimon.com127.0.0.1 ad.img.yahoo.co.kr127.0.0.1 adimages.go.com127.0.0.1 kr-adimage.lycos.co.kr127.0.0.1 ad.kimo.com.tw127.0.0.1 ads.paxnet.co.kr127.0.0.1 ads.paxnet.com127.0.0.1 ads.eu.msn.com127.0.0.1 ads.admonitor.net127.0.0.1 wwa.hitbox.com127.0.0.1 ads.nytimes.com127.0.0.1 ads.erotism.com127.0.0.1 banner.rootsweb.com127.0.0.1 ads.ole.com127.0.0.1 adimg1.chosun.com127.0.0.1 ss.mtree.com127.0.0.1 adpulse.ads.targetnet.com127.0.0.1 adserver.ugo.com127.0.0.1 ad.sales.olympics.com127.0.0.1 m2.doubleclick.net127.0.0.1 ph-ad21.focalink.com127.0.0.1 focusin.ads.targetnet.com127.0.0.1 www.datais.com127.0.0.1 oas.mmd.ch127.0.0.1 pub-g.ifrance.com127.0.0.1 ads.bianca.com127.0.0.1 wap.adlink.de127.0.0.1 click.adlink.de127.0.0.1 banner.adlink.de127.0.0.1 hurricane.adlink.de127.0.0.1 west.adlink.de127.0.0.1 scand.adlink.de127.0.0.1 regio.adlink.de127.0.0.1 direct.adlink.de127.0.0.1 classic.adlink.de127.0.0.1 adlui001.adlink.de127.0.0.1 banner1.adlink.de127.0.0.1 click.mp3.com127.0.0.1 adcodes.bla-bla.com127.0.0.1 icover.realmedia.com127.0.0.1 ca.fp.sandpiper.net127.0.0.1 adfarm.mediaplex.com127.0.0.1 ads.tmcs.net127.0.0.1 amedia.techies.com127.0.0.1 www.exchange-it.com127.0.0.1 www.ad.tomshardware.com127.0.0.1 ad.tomshardware.com127.0.0.1 ads.currantbun.com127.0.0.1 phoenix-adrunner.mycomputer.com127.0.0.1 ads15.focalink.com127.0.0.1 ads13.focalink.com127.0.0.1 adserver.colleges.com127.0.0.1 ads.nwsource.com127.0.0.1 ads.guardianunlimited.co.uk127.0.0.1 ads.newsint.co.uk127.0.0.1 ads.starnews.com127.0.0.1 www.linksynergy.com127.0.0.1 ieee-images.adbureau.net127.0.0.1 connect.247media.ads.link4ads.com127.0.0.1 ads.newsdigital.net127.0.0.1 arc5.msn.com127.0.0.1 arc4.msn.com127.0.0.1 arc3.msn.com127.0.0.1 arc2.msn.com127.0.0.1 arc1.msn.com127.0.0.1 ads.discovery.com127.0.0.1 im.800.com127.0.0.1 img.cmpnet.com127.0.0.1 ad7.internetadserver.com127.0.0.1 ads.dai.net127.0.0.1 ads.cbc.ca127.0.0.1 www75.valueclick.com127.0.0.1 ads.clearbluemedia.com127.0.0.1 ti.click2net.com127.0.0.1 www.onresponse.com127.0.0.1 ads.list-universe.com127.0.0.1 advert.bayarea.com127.0.0.1 www3.pagecount.com127.0.0.1 www.netsponsors.com127.0.0.1 adthru.com127.0.0.1 ads.newtimes.com127.0.0.1 ads.ugo.com127.0.0.1 ads.belointeractive.com127.0.0.1 wwb.hitbox.com127.0.0.1 comtrack.comclick.com127.0.0.1 www.24pm-affiliation.com127.0.0.1 www.click-fr.com127.0.0.1 www.cibleclick.com127.0.0.1 reply.mediatris.net127.0.0.1 cgi.declicnet.com127.0.0.1 pubs.mgn.net127.0.0.1 ads.mcafee.com127.0.0.1 ads1.ad-flow.com127.0.0.1 ad.be.doubleclick.net127.0.0.1 ad.adtraq.com127.0.0.1 ad.sg.doubleclick.net127.0.0.1 adpop.theglobe.com127.0.0.1 ads-03.tor.focusin.ads.targetnet.com127.0.0.1 ads.adflight.com127.0.0.1 ads.detelefoongids.nl127.0.0.1 ads.ecircles.com127.0.0.1 ads.god.co.uk127.0.0.1 ads.hyperbanner.net127.0.0.1 ads.jpost.com127.0.0.1 ads.netmechanic.com127.0.0.1 ads.webcash.nl127.0.0.1 adserver.netcast.nl127.0.0.1 adserver.webads.com127.0.0.1 adserver.webads.nl127.0.0.1 adserver1.realtracker.com127.0.0.1 adserver2.realtracker.com127.0.0.1 adserver3.realtracker.com127.0.0.1 delivery1.ads.telegraaf.nl127.0.0.1 holland.hyperbanner.net127.0.0.1 images.webads.nl127.0.0.1 sc.clicksupply.com127.0.0.1 service.bfast.com127.0.0.1 www.ad4ex.com127.0.0.1 www.bannercampaign.com127.0.0.1 www.cyberbounty.com127.0.0.1 www.netvertising.be127.0.0.1 www.speedyclick.com127.0.0.1 www.webads.nl127.0.0.1 ads.snowball.com127.0.0.1 ads.amazingmedia.com127.0.0.1 www10.valueclick.com127.0.0.1 js1.hitbox.com127.0.0.1 rd1.hitbox.com127.0.0.1 mt37.mtree.com127.0.0.1 ads.gameanswers.com127.0.0.1 ads7.udc.advance.net127.0.0.1 www23.valueclick.com127.0.0.1 ads.fortunecity.com127.0.0.1 banners.nextcard.com127.0.0.1 ads.iwon.com127.0.0.1 www.qksrv.net127.0.0.1 clickserve.cc-dt.com127.0.0.1 ads-b.focalink.com127.0.0.1 ad2.peel.com127.0.0.1 ads.floridatoday.com127.0.0.1 stats.adultrevenueservice.com127.0.0.1 ads18.bpath.com127.0.0.1 ph-ad06.focalink.com127.0.0.1 global.msads.net127.0.0.1 pluto1.iserver.net127.0.0.1 ads1.intelliads.com127.0.0.1 primetime.ad.asap-asp.net127.0.0.1 ads.stileproject.com127.0.0.1 di.image.eshop.msn.com127.0.0.1 www.blissnet.net127.0.0.1 www.consumerinfo.com127.0.0.1 ads.rottentomatoes.com127.0.0.1 k5ads.osdn.com127.0.0.1 actionsplash.com127.0.0.1 campaigns.f2.com.au127.0.0.1 adserver.news.com.au127.0.0.1 servedby.advertising.com127.0.0.1 java.yahoo.com127.0.0.1 ad.howstuffworks.com127.0.0.1 ads.1for1.com127.0.0.1 images.ads.fairfax.com.au127.0.0.1 ads.devx.com127.0.0.1 utils.mediageneral.com127.0.0.1 banners.friendfinder.com127.0.0.1 adserver.matchcraft.com127.0.0.1 www.dnps.com127.0.0.1 creative.whi.co.nz127.0.0.1 rmedia.boston.com127.0.0.1 webaffiliate.covad.com127.0.0.1 ad.iwin.com127.0.0.1 www.nailitonline2.com127.0.0.1 mds.centrport.net127.0.0.1 oas.dispatch.com127.0.0.1 adserver.ads360.com127.0.0.1 banners.adultfriendfinder.com127.0.0.1 ads.as4x.tmcs.net127.0.0.1 ads.clickagents.com127.0.0.1 banners.chek.com127.0.0.1 zi.r.tv.com127.0.0.1 ph-ad19.focalink.com127.0.0.1 ads.greensboro.com127.0.0.1 ad2.adcept.net127.0.0.1 ads.colo.kiva.net127.0.0.1 adsrv.iol.co.za127.0.0.1 mjxads.internet.com127.0.0.1 adimage.asiaone.com.sg127.0.0.1 ads.vnuemedia.com127.0.0.1 affiliate.doteasy.com127.0.0.1 m.tribalfusion.com127.0.0.1 oas.lee.net127.0.0.1 www.banneroverdrive.com127.0.0.1 ad3.peel.com127.0.0.1 ad1.peel.comwww.xbn.ru127.0.0.1 adserver.snowball.com127.0.0.1 media15.fastclick.net127.0.0.1 ads5.advance.net127.0.0.1 ads3.advance.net127.0.0.1 ads2.advance.net127.0.0.1 ads.advance.net127.0.0.1 usbytecom.orbitcycle.com127.0.0.1 adbanner.sweepsclub.com127.0.0.1 oas.villagevoice.com127.0.0.1 www.ad-flow.com127.0.0.1 ads.guardian.co.uk127.0.0.1 ads.hitcents.com127.0.0.1 media19.fastclick.net127.0.0.1 a.tribalfusion.com127.0.0.1 ads.nypost.com127.0.0.1 ads.premiumnetwork.com127.0.0.1 ads.ad-flow.com127.0.0.1 adserver.hispavista.com127.0.0.1 ads.musiccity.com127.0.0.1 banners.revenuelink.com127.0.0.1 ads1.sptimes.com127.0.0.1 adserver.bizland-inc.net127.0.0.1 ads.adtegrity.net127.0.0.1 media13.fastclick.net127.0.0.1 adserver.ukplus.co.uk127.0.0.1 ads.live365.com127.0.0.1 ads.fredericksburg.com127.0.0.1 banners.affiliatefuel.com127.0.0.1 ar.atwola.com127.0.0.1 ads.bigcitytools.com127.0.0.1 netshelter.adtrix.com127.0.0.1 y.ibsys.com127.0.0.1 adserver.nydailynews.com127.0.0.1 s0b.bluestreak.com127.0.0.1 images.scripps.com127.0.0.1 images.cybereps.com127.0.0.1 altfarm.mediaplex.com127.0.0.1 krd.realcities.com127.0.0.1 www3.bannerspace.com127.0.0.1 view.atdmt.com127.0.0.1 ads7.advance.net127.0.0.1 ad.abcnews.com127.0.0.1 ads.newsquest.co.uk127.0.0.1 secure.webconnect.net127.0.0.1 ads.nandomedia.com127.0.0.1 banners.babylon-x.com127.0.0.1 media17.fastclick.net127.0.0.1 techreview-images.adbureau.net127.0.0.1 ads.exhedra.com127.0.0.1 ad.trafficmp.com127.0.0.1 realmedia-a800.d4p.net127.0.0.1 banner.northsky.com127.0.0.1 ftp.nacorp.com127.0.0.1 www.digitalbettingcasinos.com127.0.0.1 c1.zedo.com127.0.0.1 ads4.condenet.com127.0.0.1 www.brilliantdigital.com127.0.0.1 desktop.kazaa.com127.0.0.1 shop.kazaa.com127.0.0.1 www.bonzi.com127.0.0.1 www.b3d.com127.0.0.1 neighborhood.standard.net127.0.0.1 ads.telegraph.co.uk127.0.0.1 spinbox.techtracker.com127.0.0.1 toads.osdn.com127.0.0.1 ads.themes.org127.0.0.1 adserver.trb.com127.0.0.1 media.fastclick.net127.0.0.1 banner.easyspace.com127.0.0.1 www.banner2u.com127.0.0.1 ads.thestar.com127.0.0.1 ads.digitalmedianet.com127.0.0.1 www.fineclicks.com127.0.0.1 ads.mdchoice.com127.0.0.1 ad.horvitznewspapers.net127.0.0.1 adtegrity.thruport.com127.0.0.1 a.mktw.net127.0.0.1 ads.pennyweb.com127.0.0.1 www3.ad.tomshardware.com127.0.0.1 www4.ad.tomshardware.com127.0.0.1 www6.ad.tomshardware.com127.0.0.1 www8.ad.tomshardware.com127.0.0.1 www15.ad.tomshardware.com127.0.0.1 ads.forbes.com127.0.0.1 ads.desmoinesregister.com127.0.0.1 adserver.tribuneinteractive.com127.0.0.1 bannerads.anytimenews.com127.0.0.1 ads1.condenet.com127.0.0.1 adserver.anm.co.uk127.0.0.1 zrap.zdnet.com.com127.0.0.1 bidclix.net127.0.0.1 media.popuptraffic.com127.0.0.1 coreg.flashtrack.net127.0.0.1 rmads.msn.com127.0.0.1 ads.icq.com127.0.0.1 cb.icq.com127.0.0.1 cf.icq.com127.0.0.1 www2.newtopsites.com127.0.0.1 adserv.internetfuel.com127.0.0.1 images.fastclick.net127.0.0.1 adserver.securityfocus.com127.0.0.1 www.avsads.com127.0.0.1 banners.moviegoods.com127.0.0.1 ads.bitsonthewire.com127.0.0.1 ads.iambic.com127.0.0.1 sfads.osdn.com127.0.0.1 fl01.ct2.comclick.com127.0.0.1 adserver.phillyburbs.com127.0.0.1 marketing.nyi.net127.0.0.1 www.netflip.com127.0.0.1 image.imgfarm.com127.0.0.1 ads.viaarena.com127.0.0.1 phpads2.cnpapers.com127.0.0.1 ads.astalavista.us127.0.0.1 banner.coza.com127.0.0.1 adcreative.tribuneinteractive.com127.0.0.1 ads.democratandchronicle.com127.0.0.1 adlog.com.com127.0.0.1 adimg.com.com127.0.0.1 adimage.bankrate.com127.0.0.1 ads.mediadevil.com127.0.0.1 imageserv.adtech.de127.0.0.1 ad.se.doubleclick.net127.0.0.1 ads.cashsurfers.com127.0.0.1 ads.specificpop.com127.0.0.1 z1.adserver.com127.0.0.1 images.bizrate.com127.0.0.1 q.pni.com127.0.0.1 ad01.mediacorpsingapore.com127.0.0.1 adimage.asia1.com.sg127.0.0.1 images.newsx.cc127.0.0.1 www.adireland.com127.0.0.1 ads.iafrica.com127.0.0.1 ads.nyi.net127.0.0.1 geoads.osdn.com127.0.0.1 www.crisscross.com127.0.0.1 netcomm.spinbox.net127.0.0.1 i.i.com.com127.0.0.1 ads.videoaxs.com127.0.0.1 mediamgr.ugo.com127.0.0.1 adserver.pollstar.com127.0.0.1 information.gopher.com127.0.0.1 ads.adviva.net127.0.0.1 adsrv.bankrate.com127.0.0.1 a207.p.f.qz3.net127.0.0.1 ehg-bestbuy.hitbox.com127.0.0.1 ehg-intel.hitbox.com127.0.0.1 ehg-espn.hitbox.com127.0.0.1 ehg-macromedia.hitbox.com127.0.0.1 ehg-dig.hitbox.com127.0.0.1 speed.pointroll.com127.0.0.1 amch.questionmarket.com127.0.0.1 ads.gamespy.com127.0.0.1 spd.atdmt.com127.0.0.1 ads.columbian.com127.0.0.1 clickit.go2net.com127.0.0.1 vpdc.ru4.com127.0.0.1 ads.developershed.com127.0.0.1 ads.globeandmail.com127.0.0.1 ads.nerve.com127.0.0.1 iv.doubleclick.net127.0.0.1 ads2.condenet.com127.0.0.1 www.burstnet.com127.0.0.1 ads5.canoe.ca127.0.0.1 askmen.thruport.com127.0.0.1 adsrv2.gainesvillesun.com127.0.0.1 ads.theolympian.com127.0.0.1 ads.courierpostonline.com127.0.0.1 i.timeinc.net127.0.0.1 oasads.whitepages.com127.0.0.1 rad.msn.com127.0.0.1 serve.thisbanner.com127.0.0.1 images.trafficmp.com127.0.0.1 www.kaplanindex.com127.0.0.1 kaplanindex.com127.0.0.1 1.httpdads.com127.0.0.1 spinbox.maccentral.com127.0.0.1 akaads-abc.starwave.com127.0.0.1 webad.ajeeb.com127.0.0.1 ads.granadamedia.com127.0.0.1 oas.uniontrib.com127.0.0.1 ads.wnd.com127.0.0.1 a3.suntimes.com127.0.0.1 tmsads.tribune.com127.0.0.1 ads.peel.com127.0.0.1 ads.mh5.com127.0.0.1 ad.usatoday.com127.0.0.1 adserver.digitalpartners.com127.0.0.1 ads.mediaturf.net127.0.0.1 ads4.clearchannel.com127.0.0.1 ads.clearchannel.com127.0.0.1 ads2.clearchannel.com127.0.0.1 ads.jacksonsun.com127.0.0.1 servads.aip.org127.0.0.1 ad.au.doubleclick.net127.0.0.1 adng.ascii24.com127.0.0.1 engage.speedera.net127.0.0.1 ads.msn-ppe.com127.0.0.1 ad.openfind.com.tw127.0.0.1 adi.mainichi.co.jp127.0.0.1 ads.northjersey.com127.0.0.1 ad.moscowtimes.ru127.0.0.1 banners.valuead.com127.0.0.1 ad1.aaddzz.com127.0.0.1 ds.eyeblaster.com127.0.0.1 adserver.digitalpartners.com127.0.0.1 oas.uniontrib.com127.0.0.1 ads.statesmanjournal.com127.0.0.1 ads.centralohio.com Link to post Share on other sites
Atribune Posted December 12, 2004 Report Share Posted December 12, 2004 Angeloftheflames, Efwis, PsykelI ended up helping angeloftheflames in chat. It would seem as though Search.findwhatevernow.com changes the primary and secondary DNS. We reset it to his isp's DNS and all seems good now.Good luck Akio and happy surfing. Link to post Share on other sites
Recommended Posts