Snaxe Posted September 18, 2004 Report Share Posted September 18, 2004 Other thread in Spyware/Adware Removal forumLogfile of HijackThis v1.98.2Scan saved at 12:46:36 PM, on 9/18/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\System32\drivers\CDAC11BA.EXEC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\MsPMSPSv.exeC:\PROGRA~1\mcafee.com\agent\mcagent.exeC:\Program Files\iTunes\iTunesHelper.exeC:\WINDOWS\SM1BG.EXEC:\Program Files\Common Files\Real\Update_OB\realsched.exec:\progra~1\mcafee.com\vso\mcvsescn.exeC:\Program Files\Java\j2re1.4.2_04\bin\jusched.exeC:\WINDOWS\System32\hphmon04.exeC:\Program Files\Washer\washer.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\Trillian\trillian.exeC:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exec:\progra~1\mcafee.com\vso\mcvsftsn.exec:\PROGRA~1\mcafee.com\vso\mcvsshld.exec:\PROGRA~1\mcafee.com\vso\mcvsrte.exeC:\Program Files\McAfee.com\VSO\mcshield.exeC:\Adnan\blackbox\blackbox.exeC:\WINDOWS\system32\winlogon.exeC:\Adnan\HJT\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.thelazygamer.comO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe files\mcafee.com\agent\mcagent.exeO4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exeO4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktaskO4 - HKLM\..\Run: [indexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exeO4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exeO4 - HKLM\..\Run: [sM1BG] C:\WINDOWS\SM1BG.EXEO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [MSKUpd] C:\PROGRA~1\mcafee.com\shared\mghtml.exe mcp://C:\Program Files\McAfee\SpamKiller\mskupd.ui::chkupd.htmO4 - HKLM\..\Run: [Mskexe] c:\program files\mcafee\spamkiller\spamkiller.exeO4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exeO4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exeO4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"O4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeO4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quietO4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exeO4 - HKCU\..\Run: [Washer] c:\Program Files\Washer\washer.exe /0O4 - HKCU\..\Run: [PCBoost] "C:\Program Files\PCBoost\PCBoost.exe"O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - Startup: Trillian.lnk = ?O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.htmlO8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.htmlO8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.htmlO8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.htmlO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLLO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exeO9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cabO16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cabO16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cabO16 - DPF: Yahoo! Word Racer - http://download.games.yahoo.com/games/clients/y/wt0_x.cabO16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - http://bin.mcafee.com/molbin/Shared/ComCtl...22/ComCtl32.cabO16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cabO16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1408.g.akamai.net/7/1408/9955/2003...iTunesSetup.exeO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc...73/mcinsctl.cabO16 - DPF: {72C23FEC-3AF9-48FC-9597-241A8EBDFE0A} (InstallShield International Setup Player) - http://ftp.hp.com/pub/automatic/player/isetupML.cabO16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} - http://www.napster.com/client/isetup.cabO16 - DPF: {9FC87BC7-7963-4B70-8485-B1A41034C9A1} (CSonyPicturesGameDownloaderCtl Object) - http://www.shockwave.com/content/angelx/So...eDownloader.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg...,16/mcgdmgr.cabO16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d.../ITDetector.cabO16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.yahoo.com/...ebio5_0_2_0.cab Link to post Share on other sites
Besttechie Posted September 19, 2004 Report Share Posted September 19, 2004 Hi Snaxe,Your logfile looks clean. I don't see anything wrong with it nor do I see the toolbars you are talking about. Are you still having a problem with those toolbars? Can you explain exactly what problems you are having? B Link to post Share on other sites
Snaxe Posted September 19, 2004 Author Report Share Posted September 19, 2004 Well, it keeps showing up in Spybot and Ad Aware. I think the only thing of it that's on my computer is a few registry keys. I can go to them, but it says there's an error when I try to delete them. When I try to get rid of them with Spybot, it says that it couldn't be fixed and to try at startup. I did that and I also tried in safe mode. With Ad Aware, it just acts like it did, but if I immediately do another scan it finds the same thing. The registry key is HKEY_LOCAL_MACHINE\SOFTWARE\BTIEIN and when I try to delete it it says "Can not delete BTIEIN - Error while deleting key" Link to post Share on other sites
handplane Posted September 19, 2004 Report Share Posted September 19, 2004 Have you seen This.Found it with a google search.Hope it can help you!! Link to post Share on other sites
Snaxe Posted September 19, 2004 Author Report Share Posted September 19, 2004 Not exactly. From glancing at it, I can tell that I've done those steps and have posted about it in the Spyware/Adware Removal forum. The registry entries it mentions are non-existant. The same goes for the DLL. Link to post Share on other sites
handplane Posted September 19, 2004 Report Share Posted September 19, 2004 Sorry, I tried. Link to post Share on other sites
Nerelda Posted September 19, 2004 Report Share Posted September 19, 2004 You've already tried running all your scans and removing in safe mode, right?If the latest version of Spybot (1.3) doesn't work, then you could try Webroot SpySweeper, which has a free trial period. Link to post Share on other sites
Snaxe Posted September 19, 2004 Author Report Share Posted September 19, 2004 Yes I did in safe mode. I'll go try that Webroot SpySweeper now. Link to post Share on other sites
Snaxe Posted September 19, 2004 Author Report Share Posted September 19, 2004 Nope, Didn't work. Link to post Share on other sites
Chappy Posted September 21, 2004 Report Share Posted September 21, 2004 I noticed that you have more than one user logged on, you must run Spybot and Adaware under every user profile to ensure that this is cleaned up properly or it will reinfect.Dave Link to post Share on other sites
Snaxe Posted September 21, 2004 Author Report Share Posted September 21, 2004 Even if Spybot and Ad Aware are run on one user with none others logged on I should run them on each user? Link to post Share on other sites
tg1911 Posted September 21, 2004 Report Share Posted September 21, 2004 If those users have been surfing the net, yes. Link to post Share on other sites
Recommended Posts