View Single Post
Old 08-17-2005, 05:13 AM   #1 (permalink)
hplus10
Registered User
 
Join Date: Aug 2005
Posts: 14
OS: xp


WinFixer returns

Winfixer 2005 tries to download whenever internet is connected. I have run Ewido (log below), CWShredder (it seemed to have problems on the restart with a window declaring it had problems), SpyBot, and AdAware. All found stuff and supposedly deleted them. I then ran Hyjackthis (log is below). Would appreciate help in reading the log and further actions. Thank you in advance.

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 5:13:20 AM, 8/17/2005
+ Report-Checksum: 3E5FF344

+ Scan result:

[220] C:\WINDOWS\system32\mvhgrcoi.dll -> Spyware.Look2Me : Error during cleaning
[652] C:\WINDOWS\system32\dItime.dll -> Spyware.Look2Me : Error during cleaning
[728] C:\WINDOWS\system32\dItime.dll -> Spyware.Look2Me : Error during cleaning
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\Y507EXGN\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\RECYCLER\NPROTECT\00044247.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00044277.EXE -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173784.dll -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173785.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173786.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173787.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173788.ocx -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173789.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173796.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173797.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173798.exe -> Spyware.CashBack : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173799.exe -> Spyware.CashBack : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173802.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173803.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173804.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173805.exe -> Spyware.CashBack : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173806.exe -> Spyware.CashBack : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173816.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173820.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173823.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173824.dll -> Spyware.WurldMedia : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173825.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173826.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173827.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173828.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173829.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173830.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173831.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173832.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{0E4BB6DE-EB56-4CFF-8ACD-23F3666BAD33}\RP509\A0173842.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\cMtsrv.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dlgeng.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\guard.tmp -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\JPIUtil4.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kldhe220.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kzdcz2.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\Temp\b.com -> TrojanDropper.Agent.pb : Cleaned with backup


::Report End

Logfile of HijackThis v1.99.1
Scan saved at 5:53:33 AM, on 8/17/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Venturi2\Configurator\ventcfg.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\S3tray2.exe
C:\PROGRA~1\HPONE-~1\OneTouch.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Venturi2\Client\ventc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Documents and Settings\Owner\My Documents\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4nb.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4nb.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us4nb.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com/info/e-center-p
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4nb.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4nb.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us4nb.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://srch-us4nb.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://srch-us4nb.hpwis.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [AirCardEnabler] C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Venturi Configurator] C:\Program Files\Venturi2\Configurator\ventcfg.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HPONE-~1\OneTouch.EXE
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\Wireless Network PC Card\WPC11CFG.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com/info/e-center-p
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/co...rolLite_EN.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...67&clcid=0x409
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) - http://208.62.27.145/TSCOM_TOOL/IFTW...S/IFTWCLIX.CAB
O16 - DPF: {6BA1270C-B969-4234-B827-7B3BBB4F5FFC} - http://63.99.207.62/builds//build1539/install.cab
O16 - DPF: {74F5614A-8A8C-43B4-8CC2-4B4EFAF4A6C5} (TSCCInstall Class) - http://www.trainingclips.com/stream/TSCCinst.cab
O16 - DPF: {7CEEAB76-D59E-11D3-8394-00C04F7BDF10} (Application Class) - http://www.tradestation.com/tscom/Cl...gIn/tsTemp.cab
O20 - Winlogon Notify: Internet Settings - C:\WINDOWS\system32\mvhgrcoi.dll
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Venturi2 Client (Venturi2) - Venturi Wireless - C:\Program Files\Venturi2\Client\ventc.exe
hplus10 is offline  
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here