n3rrd Posted February 19, 2005 Report Share Posted February 19, 2005 Here is my log. I have been having an issue with this computer having icons added to the desktop at every restart. There was a whole slew of them at one point but now it is down to "Casino Online" and "Poker".As far as I understand, these are symptoms commonly associated with Lop... I have deleted all the files in "Bold File Move" and "Hole Store", aswell as "loud roam blah" etc. folders in the "Application Data" of each users folders...There were a whole slew of bookmarks added with all of this mess, too. My homepage also keeps trying to be changed to "http://www.sadfklemarawefasdf.com", or some similar random gibberish every so often.This is what happens with you have a disobedient thirteen year old sister who insists on installing MSN Plus, and the like, I suppose.I keep missing something because it keeps coming back. Can you check out the log and see if you can find anything that shouldn't be there?Here is the log:-----------------Logfile of HijackThis v1.99.1Scan saved at 4:17:39 PM, on 2/19/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exec:\PROGRA~1\mcafee.com\vso\mcvsrte.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\Tablet.exec:\PROGRA~1\mcafee.com\vso\mcshield.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\sstray.exeC:\WINDOWS\zHotkey.exeC:\Program Files\Multimedia Card Reader\shwicon2k.exeC:\Program Files\Logitech\iTouch\iTouch.exeC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXEC:\Program Files\Winamp\winampa.exeC:\Program Files\QuickTime\qttask.exeC:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exeC:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeC:\PROGRA~1\Java\J2RE14~1.2\bin\jusched.exeC:\PROGRA~1\mcafee.com\vso\mcvsshld.exeC:\PROGRA~1\mcafee.com\agent\mcagent.exeC:\Program Files\Logitech\Video\LogiTray.exeC:\Program Files\Microsoft AntiSpyware\gcasServ.exeC:\WINDOWS\system32\RUNDLL32.EXEC:\Program Files\Messenger\msmsgs.exeC:\Program Files\Microsoft Broadband Networking\MSBNTray.exeC:\Program Files\SEC\Natural Color\NaturalColorLoad.exeC:\WINDOWS\system32\WTablet\TabUserW.exec:\progra~1\mcafee.com\vso\mcvsescn.exeC:\Program Files\Internet Explorer\iexplore.exec:\progra~1\intern~1\iexplore.exeC:\Program Files\Logitech\MouseWare\system\em_exec.exeC:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exec:\progra~1\mcafee.com\vso\mcvsftsn.exeC:\WINDOWS\system32\LVComS.exeC:\Program Files\Logitech\Video\LowLight.exeC:\Program Files\Microsoft AntiSpyware\gcasDtServ.exeC:\WINDOWS\system32\wuauclt.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Documents and Settings\Brian\Desktop\New Folder\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.udohlgkqckx.com//_O01Lp2R/1pCAI...weK73wb5hd.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lwugrxywykzifng.com//_O01Lp2R/3...ZwHnIweBic.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.comR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /rO4 - HKLM\..\Run: [CHotkey] zHotkey.exeO4 - HKLM\..\Run: [sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exeO4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exeO4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.ExeO4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exeO4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] C:\PROGRA~1\Java\J2RE14~1.2\bin\jusched.exeO4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exeO4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktaskO4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exeO4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exeO4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exeO4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"O4 - HKLM\..\Run: [blahlinkactivepop] C:\Documents and Settings\All Users\Application Data\loud roam blah link\Plan Anti.exeO4 - HKLM\..\Run: [bird chin mpeg find] C:\Documents and Settings\All Users\Application Data\coalbasebirdchin\Jump up.exeO4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /autoO4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInitO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [Rule Road] C:\DOCUME~1\Brian\APPLIC~1\BOLDFI~1\sendeachloud.exeO4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exeO4 - Global Startup: Microsoft Broadband Networking.lnk = ?O4 - Global Startup: NaturalColorLoad.lnk = ?O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exeO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\J2RE14~1.2\bin\npjpi142_04.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\J2RE14~1.2\bin\npjpi142_04.dllO9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exeO9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exeO9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - blank (file missing)O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO14 - IERESET.INF: START_PAGE_URL=http://www.emachines.comO16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cabO16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab28578.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc...76/mcinsctl.cabO16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppD...sharingctrl.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab28578.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg...,16/mcgdmgr.cabO16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cabO16 - DPF: {EDFCDAF5-95D9-40E9-BBE6-10C33190C3EF} (cGameControl Class) - http://zone.msn.com/bingame/rmcb/default/RumbleCube.cabO23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exeO23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exeO23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exeO23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005\RpcDataSrv.exeO23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005\RpcSandraSrv.exeO23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\System32\Tablet.exe--------------I know the entries like "Jump Up" and "Plan Anti" shouldn't be there, but everytime I remove them and delete the folder they are in, etc. they come back anyways... Link to post Share on other sites
Canoeingkidd Posted February 19, 2005 Report Share Posted February 19, 2005 Hello n3rrd,I'm assuming you have already uninstalled Msg Plus? If you have not uninstall it from Add/Remove Programs now.This itemO4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /autosuggests you have disabled items in MSConfig. If you have, please re-enable them now so I can see other problems if they exsist.Run HijackThis, do a scan, and place a check next to the following items to be fixed:R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.udohlgkqckx.com//_O01Lp2R/1pCAI...weK73wb5hd.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lwugrxywykzifng.com//_O01Lp2R/3...ZwHnIweBic.htmlO4 - HKLM\..\Run: [blahlinkactivepop] C:\Documents and Settings\All Users\Application Data\loud roam blah link\Plan Anti.exeO4 - HKLM\..\Run: [bird chin mpeg find] C:\Documents and Settings\All Users\Application Data\coalbasebirdchin\Jump up.exeO4 - HKCU\..\Run: [Rule Road] C:\DOCUME~1\Brian\APPLIC~1\BOLDFI~1\sendeachloud.exeUnless you or an administrator set this place a check next to this item (Programs such as Spybot - S&D may set these also):O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present <-- Disables access to certain options in Internet ExplorerClose all browsers and windows except HijackThis and click "Fix checked".You may need to configure your computer to show hidden files. See HERE for how to show hidden files.Now reboot into Safe mode by tapping the F8 key while your computer starts up and selecting "Safe Mode" from the menu that appears. (You will not be able to access the internet while in Safe mode).Delete the folders in bold:C:\Documents and Settings\All Users\Application Data\loud roam blah link\C:\Documents and Settings\All Users\Application Data\coalbasebirdchin\C:\DOCUME~1\Brian\APPLIC~1\BOLDFI~1\Folders and files with a tilde (~) and a number at the end means that there is a file/folder that starts with the six characters in front of the tilde, note that there may be spaces in the name. If there are more than one, please report them back and do not delete!Reboot back to normal mode and post a new HijackThis log in a reply to this topic. If you have any other user accouns on XP please post logs from them also. Link to post Share on other sites
n3rrd Posted February 19, 2005 Author Report Share Posted February 19, 2005 Thanks for the quick response, CanoeingKidd. Yeah, I have a few programs that I just got tired of starting up at boot disabled, but I can enable them if that would help.At the moment, the computer that is having the difficulties is being used by my grandmother, so I cannot do much to it at the moment. I will post new log(s) as soon as I can, though. Sorry if this is an inconvenience to you!Those folders just keep coming back... I've deleted the keys/disabled them, and deleted the folders many many times. Another thing of interest, if you look through the log you'll notice two instances of iexplorer.exe, and those are caused by whatever is making the shortcuts.I have internet explorer disabled on the problematic computer, and it should not be able to run. Funny thing, is when you try to end the process, it immediately replaces itself. I have FireFox as the default and only enabled browser on all of the computers in this house to try and prevent the problems that my grandma and youngest sister cause.Thanks again for the quick response, though. I will have new logs up ASAP. Link to post Share on other sites
Dan Posted February 19, 2005 Report Share Posted February 19, 2005 Hi n3rrd,Sorry to barge in, I will let Canoeingkidd do the rest of the fix. iexplore is internet explorer. iexplorer is probably malware.Also, you can install MessengerPlus, but choose NO Sponsors. (Note: It is urged NOT to install this program if not necessary.)Please post a log.dk Link to post Share on other sites
n3rrd Posted February 19, 2005 Author Report Share Posted February 19, 2005 Yeah, sorry. I read it wrong, it is iexplore.exe. Regardless, it shouldn't be running in the background, especially if it's been disabled. I'll post a new log soon. Link to post Share on other sites
Canoeingkidd Posted May 28, 2005 Report Share Posted May 28, 2005 Due to the lack of feedback this Topic is closed. Link to post Share on other sites
Recommended Posts