Dan Posted August 27, 2004 Report Share Posted August 27, 2004 Here it is:Logfile of HijackThis v1.98.2Scan saved at 4:28:56 PM, on 8/26/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEc:\Program Files\Common Files\Symantec Shared\ccSetMgr.exec:\Program Files\Norton Personal Firewall\NISUM.EXEc:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\windows\system\hpsysdrv.exeC:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exeC:\WINDOWS\System32\hphmon05.exeC:\HP\KBD\KBD.EXEC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\WINDOWS\ALCXMNTR.EXEC:\WINDOWS\LTMSG.exeC:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exeC:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exeC:\WinAMP\winampa.exeC:\WINDOWS\System32\aqyjnzxc.exeC:\Program Files\CashBack\bin\cashback.exeC:\Program Files\NaviSearch\bin\nls.exeC:\Program Files\Messenger\msmsgs.exeC:\WINDOWS\System32\flt.exeC:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exeC:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\interMute\SpamSubtract\SpamSub.exeC:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exec:\Program Files\Norton Personal Firewall\ccPxySvc.exec:\Program Files\Norton AntiVirus\navapsvc.exeC:\Program Files\HijackThis\HijackThis.exeC:\Program Files\Mozilla Firefox\firefox.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearchR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blankR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.netzero.net/s/signup?r=quick-startR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon OnlineR3 - Default URLSearchHook is missingO2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dllO2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)O2 - BHO: (no name) - {648725EA-13AE-4AC9-98A5-FCF43374F82E} - C:\WINDOWS\System32\mlfg.dll (file missing)O2 - BHO: (no name) - {6B89385F-B53F-54B6-D101-105508A22B68} - C:\WINDOWS\System32\eixgc.dllO2 - BHO: G1.GZ - {79C03BC5-6C55-4B5B-921F-C02B6F1ABD7B} - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pribi\Pribi.dll (file missing)O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dllO2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dllO2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dllO2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dllO2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dllO3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\NetZero\toolbar.dllO3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exeO4 - HKLM\..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exeO4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exeO4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exeO4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXEO4 - HKLM\..\Run: [updateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [VTTimer] VTTimer.exeO4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXEO4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exeO4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exeO4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exeO4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exeO4 - HKLM\..\Run: [WinampAgent] C:\WinAMP\winampa.exeO4 - HKLM\..\Run: [ildikxnbznae] C:\WINDOWS\System32\aqyjnzxc.exeO4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashback.exeO4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exeO4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"O4 - HKLM\..\Run: [sSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exeO4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHookO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [Zxbtwzr] C:\WINDOWS\System32\flt.exeO4 - HKCU\..\Run: [\Pribi.exe] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pribi\Pribi.exeO4 - HKCU\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exeO4 - Startup: PowerReg Scheduler V3.exeO4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exeO4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exeO4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeO4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exeO4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exeO8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.htmlO8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.htmlO8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.htmlO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLLO16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\wwlffnwv.exeO16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cabO16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files...up145.caLogfile Link to post Share on other sites
Besttechie Posted August 27, 2004 Report Share Posted August 27, 2004 Hi dknoppix,Please make new post with just ONE HijackThis logfile. It will make it much easier to help you if you post only ONE.ThanksB Link to post Share on other sites
Dan Posted August 27, 2004 Author Report Share Posted August 27, 2004 this is only one log.I did ran HJT and then saved the log. I then opened it and copied it. Link to post Share on other sites
Besttechie Posted August 27, 2004 Report Share Posted August 27, 2004 Yes, it is only one log BUT there are many of them in your post get it? Like there are multiple copies of the same log in that post. If you don't mind I will edit it for you to show you what I am talking about and so that way it is easier to help you fix your problem.B Link to post Share on other sites
Dan Posted August 27, 2004 Author Report Share Posted August 27, 2004 that would be coolThanks,Dan Link to post Share on other sites
Besttechie Posted August 27, 2004 Report Share Posted August 27, 2004 That's how it should look the next time you post a logfile. Now lets get you cleaned up.B Link to post Share on other sites
Dan Posted August 27, 2004 Author Report Share Posted August 27, 2004 Thanks alot!!!!!!!!!!! Link to post Share on other sites
Besttechie Posted August 27, 2004 Report Share Posted August 27, 2004 Hi,First off go to the task manager and end these processes (Ctrl Alt Del)aqyjnzxc.execashback.exenls.exeflt.exeThen Download and Run:CWShredderMake sure you close all explorer windows and only have CWShredder open. Click the Fix button to have it fix the CWS hijacks.sphjfixMake sure all explorer windows are closed and then open it and run it. Click the disinfectint button. Then you should be clean from the rest of the CWS hijack.Then reboot and post a new logfile. Your log will still need more work.B Link to post Share on other sites
Dan Posted August 27, 2004 Author Report Share Posted August 27, 2004 thanks, this may take a while because i'm trying to fix my friends computer. Thanks alot and I'll be in touch.Dan Link to post Share on other sites
Besttechie Posted August 27, 2004 Report Share Posted August 27, 2004 No Problem. I'll be here. Just remember to post that new log when you finish what I said so we can proceed and fix the rest of the PC.B Link to post Share on other sites
Dan Posted August 27, 2004 Author Report Share Posted August 27, 2004 thanks alot Link to post Share on other sites
Dan Posted September 1, 2004 Author Report Share Posted September 1, 2004 do you want me to post the sphjfix log??? If yes, here it is:8/31/2004 9:02:06 PM SPhjFix started v1.078/31/2004 9:02:06 PM Stealth-String found8/31/2004 9:02:09 PM Restart8/31/2004 9:04:00 PM 2nd Step 8/31/2004 9:04:00 PM Error while deleting Hijack-DLL 8/31/2004 9:04:00 PM BHO-DLL: (not found)8/31/2004 9:04:00 PM Bad IE-pages found:8/31/2004 9:04:06 PM CleanedBy the way, I used wordpad to open it, because norton was blocking it when I was trying to do it with notepad...hope this is good,danny Link to post Share on other sites
Besttechie Posted September 1, 2004 Report Share Posted September 1, 2004 Make sure you click the disinfectint button in sphjfix. Then reboot and open hijackthis have it scan and then post a new log. B Link to post Share on other sites
Dan Posted September 1, 2004 Author Report Share Posted September 1, 2004 ok thanks. just wondering if I should post that one or the HJT one. Here it is:Logfile of HijackThis v1.98.2Scan saved at 11:06:12 AM, on 9/1/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEc:\Program Files\Common Files\Symantec Shared\ccSetMgr.exec:\Program Files\Norton Personal Firewall\NISUM.EXEc:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\windows\system\hpsysdrv.exeC:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exeC:\WINDOWS\System32\hphmon05.exeC:\HP\KBD\KBD.EXEC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\WINDOWS\ALCXMNTR.EXEC:\WINDOWS\LTMSG.exeC:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exeC:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exeC:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exeC:\WinAMP\winampa.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exeC:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeC:\Program Files\interMute\SpamSubtract\SpamSub.exeC:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exec:\Program Files\Norton Personal Firewall\ccPxySvc.exec:\Program Files\Norton AntiVirus\navapsvc.exeC:\Program Files\NaviSearch\bin\nls.exeC:\Program Files\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearchR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.netzero.net/s/signup?r=quick-startR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon OnlineR3 - Default URLSearchHook is missingO2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {648725EA-13AE-4AC9-98A5-FCF43374F82E} - C:\WINDOWS\System32\mlfg.dll (file missing)O2 - BHO: (no name) - {6B89385F-B53F-54B6-D101-105508A22B68} - C:\WINDOWS\System32\eixgc.dllO2 - BHO: G1.GZ - {79C03BC5-6C55-4B5B-921F-C02B6F1ABD7B} - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pribi\Pribi.dll (file missing)O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dllO2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dllO2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dllO2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exeO4 - HKLM\..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exeO4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exeO4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exeO4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXEO4 - HKLM\..\Run: [updateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [VTTimer] VTTimer.exeO4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXEO4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exeO4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exeO4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exeO4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exeO4 - HKLM\..\Run: [WinampAgent] C:\WinAMP\winampa.exeO4 - HKLM\..\Run: [ildikxnbznae] C:\WINDOWS\System32\aqyjnzxc.exeO4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashback.exeO4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exeO4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"O4 - HKLM\..\Run: [sSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exeO4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHookO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [Zxbtwzr] C:\WINDOWS\System32\flt.exeO4 - HKCU\..\Run: [\Pribi.exe] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pribi\Pribi.exeO4 - HKCU\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exeO4 - Startup: PowerReg Scheduler V3.exeO4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exeO4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exeO4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeO4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exeO4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exeO8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.htmlO8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.htmlO8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.htmlO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLLO16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cabO16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup145.cab Link to post Share on other sites
Besttechie Posted September 1, 2004 Report Share Posted September 1, 2004 Hi,First off go to the task manager and end these processes (Ctrl Alt Del)nls.exeThen close all explorer windows except for hijackthis and have hijackthis fix these.R3 - Default URLSearchHook is missing.........O2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dllO2 - BHO: (no name) - {648725EA-13AE-4AC9-98A5-FCF43374F82E} - C:\WINDOWS\System32\mlfg.dll (file missing)O2 - BHO: (no name) - {6B89385F-B53F-54B6-D101-105508A22B68} - C:\WINDOWS\System32\eixgc.dllO2 - BHO: G1.GZ - {79C03BC5-6C55-4B5B-921F-C02B6F1ABD7B} - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pribi\Pribi.dll (file missing)O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dllO2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dllO2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll.........O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file).........O4 - HKLM\..\Run: [ildikxnbznae] C:\WINDOWS\System32\aqyjnzxc.exeO4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashback.exeO4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exeO4 - HKCU\..\Run: [Zxbtwzr] C:\WINDOWS\System32\flt.exeO4 - HKCU\..\Run: [\Pribi.exe] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pribi\Pribi.exeO4 - Startup: PowerReg Scheduler V3.exe.........Then reboot into Safe Mode and delete the following files/folders. Also, make sure you unhide hidden files and folders. Here are links that show you how to do both things.How to boot into Safe ModeHow to unhide hidden files and foldersDelete what is in redC:\WINDOWS\System32\aqyjnzxc.exeC:\Program Files\CashBack\bin\cashback.exeC:\Program Files\NaviSearch\bin\nls.exeC:\WINDOWS\System32\flt.exeC:\DOCUME~1\ALLUSE~1\APPLIC~1\Pribi\Pribi.exeDelete this from the startup folder.PowerReg Scheduler V3.exeThen reboot into Normal mode have hijackthis rescan and then post a new logfile.After I say it's clean follow these directions.Prevention:Use Spybot Search and Destroy to scan your system for spyware every couple of weeks or once a week depending on how you feel.Spybot Search & DestroyAlso Download:SpywareBlasterThis program helps prevent spyware from being installed on your system.IE-SPYADBlocks over 5000 bad sites from putting cookies and other bad stuff on your system. Only works in IE though.Another thing to consider is how to setup your browsers security settings.Here are a number of recommendations that will help tighten them, and which will contribute to making you a less likely victim:1) Watch what you download!Many freeware programs, and P2P programs like Grokster, Imesh, Kazaa and others are amongst the most notorious, come with an enormous amount of bundled spyware that will eat system resources, slow down your system, clash with other installed software, or just plain crash your browser or even Windows itself.2) Go to IE > Tools > Windows Update > Product Updates, and install ALL Security Updates listed.It's important to always keep current with the latest security fixes from Microsoft.Install those patches for Internet Explorer, and make sure your installation of Java VM is up-to-date. There are some well known security bugs with Microsoft Java VM which are exploited regularly by browser hijackers.3) Go to Internet Options/Security/Internet, press 'default level', then OK.Now press "Custom Level."In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to 'prompt', and 'Initialize and Script ActiveX controls not marked as safe" to 'disable'.Now you will be asked whether you want ActiveX objects to be executed and whether you want software to be installed.Sites that you know for sure are above suspicion can be moved to the Trusted Zone in Internet Option/security.So why is activex so dangerous that you have to increase the security for it?When your browser runs an activex control, it is running an executable program. It's no different from doubleclicking an exe file on your hard drive.Would you run just any random file downloaded off a web site without knowing what it is and what it does?There is some helpful information. Remember to keep safe online.B Link to post Share on other sites
Dan Posted September 1, 2004 Author Report Share Posted September 1, 2004 Here is my log:Logfile of HijackThis v1.98.2Scan saved at 3:58:53 PM, on 9/1/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEc:\Program Files\Common Files\Symantec Shared\ccSetMgr.exec:\Program Files\Norton Personal Firewall\NISUM.EXEc:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\windows\system\hpsysdrv.exeC:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exeC:\WINDOWS\System32\hphmon05.exeC:\HP\KBD\KBD.EXEC:\Program Files\Common Files\Sonic\Update Manager\sgtray.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\WINDOWS\LTMSG.exeC:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exeC:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exeC:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exeC:\WinAMP\winampa.exeC:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeC:\Program Files\interMute\SpamSubtract\SpamSub.exeC:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exec:\Program Files\Norton Personal Firewall\ccPxySvc.exec:\Program Files\Norton AntiVirus\navapsvc.exeC:\WINDOWS\System32\wuauclt.exeC:\Program Files\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearchR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.netzero.net/s/signup?r=quick-startR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon OnlineO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exeO4 - HKLM\..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exeO4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exeO4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exeO4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXEO4 - HKLM\..\Run: [updateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [VTTimer] VTTimer.exeO4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exeO4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exeO4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exeO4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exeO4 - HKLM\..\Run: [WinampAgent] C:\WinAMP\winampa.exeO4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"O4 - HKLM\..\Run: [sSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exeO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exeO4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exeO4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeO4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exeO4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exeO8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.htmlO8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.htmlO8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.htmlO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL Link to post Share on other sites
Dan Posted September 1, 2004 Author Report Share Posted September 1, 2004 IE-SPYADBlocks over 5000 bad sites from putting cookies and other bad stuff on your system. Only works in IE though.Is there anything to work with Firefox??? Link to post Share on other sites
Besttechie Posted September 1, 2004 Report Share Posted September 1, 2004 Ok, your log looks clean now. Now as for IE-SPYAD working with Firefox, no I don't know of anything like IE-SPYAD that does. Although SpywareBlaster does block a lot of bad sites just like IE-SPYAD does with IE, but SpywareBlaster works for IE, Mozilla, and Firefox. I would get IE-SPYAD also just in case you have to use IE for something you never know. Make sure you follow all the directions I gave and get all the programs I gave links too.Good luck you are now clean.B Link to post Share on other sites
Dan Posted September 1, 2004 Author Report Share Posted September 1, 2004 Thanks alot B!! I thank you for taking your time to help me with all of my problems!!Thanks, Danny Link to post Share on other sites
Besttechie Posted September 1, 2004 Report Share Posted September 1, 2004 No Prob. Glad to help.B Link to post Share on other sites
WiredMonkey Posted September 1, 2004 Report Share Posted September 1, 2004 IE-SPYADBlocks over 5000 bad sites from putting cookies and other bad stuff on your system. Only works in IE though.Is there anything to work with Firefox??? In some ways, Firefox works with Firefox. What I mean by that is - Since a lot of these cookies were designed to only work on IE, you won't even experience them using Firefox. So, just by using the browser itself you're going to have a safer web-surfing experience.As far as further protection go for Firefox, there's some extensions you can get out at Mozilla Update that will allow you to further manage your cookies, but I don't know of a list that will be provided automatically blocking certain sites like IE-SPYAD. But, as I said, that may be because Firefox users are protected just by using the browser. Anyone else?Edit: I took a while typing I guess...go with what B says on the SpywareBlaster cause that is good and will protect you from outside the browser...doesn't auto-block cookies, but stops installation of spyware. That's good stuff. Link to post Share on other sites
Recommended Posts