manson1966 Posted April 14, 2009 Report Share Posted April 14, 2009 thanks in advanceLogfile of Trend Micro HijackThis v2.0.2Scan saved at 10:36:59 PM, on 4/13/2009Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:D:\WINDOWS\System32\smss.exeD:\WINDOWS\system32\winlogon.exeD:\WINDOWS\system32\services.exeD:\WINDOWS\system32\lsass.exeD:\WINDOWS\system32\svchost.exeD:\WINDOWS\System32\svchost.exeD:\WINDOWS\system32\svchost.exeD:\WINDOWS\system32\spoolsv.exeE:\Program Files\Avira\AntiVir Desktop\sched.exeE:\Program Files\Avira\AntiVir Desktop\avguard.exeD:\WINDOWS\System32\TuneUpDefragService.exed:\Program Files\TightVNC\WinVNC.exeD:\WINDOWS\Explorer.EXED:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exeE:\Program Files\Avira\AntiVir Desktop\avgnt.exeE:\Program Files\MagicDisc\MagicDisc.exeD:\Excursion9.5\mIRC.ExCurSioN.exeD:\WINDOWS\System32\svchost.exeD:\WINDOWS\system32\svchost.exeE:\Program Files\CometBird\CometBird.exeD:\Program Files\IncrediMail\bin\IMApp.exeD:\Program Files\Windows Live\Messenger\msnmsgr.exeD:\Program Files\Windows Live\Contacts\wlcomm.exeD:\Program Files\BitComet\BitComet.exee:\Program Files\Trend Micro\HijackThis\HijackThis.exed:\program files\mozilla firefox\firefox.exeD:\Program Files\Java\jre6\bin\java.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/m/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dllO2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\Program Files\BitComet\tools\BitCometBHO_1.3.1.15.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - D:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dllO2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO4 - HKLM\..\Run: [HPDJ Taskbar Utility] D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exeO4 - HKLM\..\Run: [avgnt] "E:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /minO4 - Startup: BitComet.lnk = D:\Program Files\BitComet\BitComet.exeO4 - Startup: MagicDisc.lnk = E:\Program Files\MagicDisc\MagicDisc.exeO4 - Startup: Shortcut (2) to mIRC.ExCurSioN.exe.lnk = D:\Excursion9.5\mIRC.ExCurSioN.exeO4 - Startup: xpval.batO8 - Extra context menu item: &D&ownload &with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddLink.htmO8 - Extra context menu item: &D&ownload all video with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddVideo.htmO8 - Extra context menu item: &D&ownload all with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddAllLink.htmO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dllO23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - E:\Program Files\Avira\AntiVir Desktop\sched.exeO23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - E:\Program Files\Avira\AntiVir Desktop\avguard.exeO23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - D:\WINDOWS\System32\TuneUpDefragService.exeO23 - Service: VNC Server (winvnc) - TightVNC Group - d:\Program Files\TightVNC\WinVNC.exe--End of file - 4386 bytes Link to post Share on other sites
Rorschach112 Posted April 14, 2009 Report Share Posted April 14, 2009 helloDownload Rooter.exe to your desktopThen doubleclick it to start the toolA Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that hereDownload OTListIt2 to your desktop.Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.When the window appears, underneath Output at the top change it to Minimal Output.Check the boxes beside LOP Check and Purity Check.Under Custom Scan paste this innetsvcsmsconfigsafebootminimalsafebootnetworkactivexdrivers32%systemroot%\System32\antiwpa.dll%systemroot%\SYSTEM32\wpa.dll%systemroot%\setup\scripts\biestart.exe%systemroot%\system32\drivers\royal.sys%SYSTEMDRIVE%\*.%PROGRAMFILES%\*.Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in. Link to post Share on other sites
Rorschach112 Posted April 18, 2009 Report Share Posted April 18, 2009 Inactive topic...If you still need help on this problem, contact me or one of the Moderators to re-open this up.Topic closed. Link to post Share on other sites
Recommended Posts