Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 01-01-2006, 07:28 AM   #1 (permalink)
Registered User
 
Join Date: Dec 2005
Posts: 13
OS: xp


Downloader

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 2:25:56 PM, 1/1/2006
+ Report-Checksum: C79C1512

+ Scan result:

[516] VM_00D60000 -> Downloader.Agent.uj : Error during cleaning
[540] VM_00BF0000 -> Downloader.Agent.uj : Error during cleaning
[1340] VM_007B0000 -> Downloader.Agent.uj : Error during cleaning
[352] VM_00930000 -> Downloader.Agent.uj : Error during cleaning
[112] VM_008F0000 -> Downloader.Agent.uj : Error during cleaning
[400] VM_00890000 -> Downloader.Agent.uj : Error during cleaning
[480] VM_01000000 -> Downloader.Agent.uj : Error during cleaning
[492] VM_009E0000 -> Downloader.Agent.uj : Error during cleaning
[560] VM_00A40000 -> Downloader.Agent.uj : Error during cleaning
[680] VM_00870000 -> Downloader.Agent.uj : Error during cleaning
[2336] VM_003A0000 -> Downloader.Agent.uj : Error during cleaning
[2620] VM_007D0000 -> Downloader.Agent.uj : Error during cleaning


::Report End

Then...

Logfile of HijackThis v1.99.1
Scan saved at 2:26:58 PM, on 1/1/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\Fast.exe
C:\Program Files\ZyXEL\ZyXEL USB ADSL\CnxDslTb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Slim Multimedia Keyboard\MagicKey.exe
C:\Program Files\Slim Multimedia Keyboard\OSD.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe

R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
F1 - win.ini: run= C:\WESTWOOD\REDALERT\INSTICON.EXE
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZyXEL\ZyXEL USB ADSL\CnxDslTb.exe" "ZyXEL\ZyXEL USB ADSL"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKCU\..\Run: [Advanced Spyware Remover] C:\Program Files\Evonsoft\ASR\Asr.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Slim Multimedia Keyboard.lnk = C:\Program Files\Slim Multimedia Keyboard\MagicKey.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {87632451-1331-3451-2621-452727222157} - ms-its:mhtml:file://C:\nosuch.mht!http://loli.enacre.net/chm.chm::/exe.exe
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8885291C-1BE4-450E-B494-91FF12DED8C8}: NameServer = 85.255.116.23 85.255.112.166
O17 - HKLM\System\CCS\Services\Tcpip\..\{99DBC017-2C09-4A01-80C7-653FD17A181C}: NameServer = 85.255.116.23,85.255.112.166
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\System32\ZoneLabs\isafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Please Help Sir!
leila83 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 01-01-2006, 09:55 AM   #2 (permalink)
Analyst, Security Team
 
greyknight17's Avatar
 
Join Date: Jul 2004
Location: New York
Posts: 14,331
OS: Windows 98 & Windows XP Home/Pro

My System

You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://swandog46.geekstogo.com/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install. Make sure 'Run fixit' is checked and click Finish. The fix will begin. Follow the prompts. You will be asked to reboot your computer. Your system may take longer than usual to load - this is normal.

When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items:

O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O16 - DPF: {87632451-1331-3451-2621-452727222157} - ms-its:mhtml:file://C:\nosuch.mht!http://loli.enacre.net/chm.chm::/exe.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{8885291C-1BE4-450E-B494-91FF12DED8C8}: NameServer = 85.255.116.23 85.255.112.166
O17 - HKLM\System\CCS\Services\Tcpip\..\{99DBC017-2C09-4A01-80C7-653FD17A181C}: NameServer = 85.255.116.23,85.255.112.166


Click Fix Checked. Close HijackThis and click OK to proceed.

Delete this folder:

C:\Program Files\winupdates\

At the end of the fix, you may need to restart your computer again.

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.

Please download Ewido Security Suite at http://www.ewido.net/en/download/.

1. Install Ewido Security Suite.
2. When installing, under 'Additional Options' uncheck:
* Install background guard
* Install scan via context menu
3. Launch Ewido, there should be an icon on your desktop, double click it.
4. The program will now open to the main screen.
5. When you run Ewido for the first time, you will get a warning 'Database could not be found!'. Click OK. We will fix this in a moment.
6. You will need to update Ewido to the latest definition files.
* On the left hand side of the main screen click update.
* Then click on Start Update.
7. The update will start and a progress bar will show the updates being installed. The status bar at the bottom will display 'Update successful'.
8. Exit Ewido. DO NOT scan yet.

If you are having problems with the updater, you can go to http://www.ewido.net/en/download/updates/ to update manually.

Download CleanUp! http://cleanup.stevengould.org/ (Alternate Link if main link don't work - http://www.greyknight17.com/spy/CleanUp.exe ) and install it. Don't run it yet.

Restart your computer and boot into Safe Mode (if you don't know how, go to http://www.bleepingcomputer.com/foru...howtutorial=61 ).

CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp!. Run CleanUp! and click on the Options button. Uncheck 'Scan local drives for temporary files'. Also uncheck those two Newsgroup entries if you don't want to delete them. Click OK and then click on the CleanUp! button. Let it run. After it's done, choose Yes to logoff.

Now open Ewido and do a scan on your system.

* Click on scanner.
* Click on 'Complete System Scan' and the scan will begin.
* While the scan is in progress you will be prompted to clean the first infected file it finds. Choose 'Remove', then put a check next to 'Perform action on all infections' in the left corner of the box so you don't have to sit and watch Ewido the whole time. Click OK.
Exit Ewido when it's done.
* Once the scan has completed, there will be a button located on the bottom of the screen named 'Save report'.
* Click 'Save report'.
* Save the report to your desktop.

Restart your computer to get back to Normal Mode. Post the Ewido report and a new HijackThis log here. Also post the contents of the logfile C:\fixwareout\report.txt here.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it.

greyknight17 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-01-2006, 07:38 PM   #3 (permalink)
Registered User
 
Join Date: Dec 2005
Posts: 13
OS: xp


Reports

Fixwareout ver 1.003
Last edited 12/5/2005
Post this report in the forums please

Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\xedocne
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\gib_ogol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\repiwoh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\23plhps
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\mgcppp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\tesvaf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\32refaselif
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\xedocne

PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.

»»»»» Search by size and names...
C:\WINDOWS\SYSTEM32\CSLZI.EXE

»»»»» Misc files

»»»»» Checking for older varients covered by the Rem3 tool

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 2:36:59 AM, 1/2/2006
+ Report-Checksum: F8789B72

+ Scan result:

C:\Documents and Settings\Tommy Cheung\Complete\Able2Extract Pro 3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Acronis Privacy Expert Suite 8.0.789.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\All Adobe DVD-X.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Asylum.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Aurora MPEG To DVD Burner 4.76.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\AutoScreenRecorder 2.1.281 Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\AutoScreenRecorder Pro 2.1.281.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\BloodRayne 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Copy DVD Gold 2.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\DialogBlocks 2.06.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\DVDFab Platinum 2.9.65.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Enemy Of The State.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Flash Player Pro 2.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Game Collector 2.02.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\HyperCam 2.13.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Led Zeppelin - Box Set (4 cds).zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\MeggieSoft Canasta 16.4 16404.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\MeggieSoft Euchre and Ecarte 16.4 164.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Microsoft Office 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Musicmatch Jukebox Plus 10.00.4015c.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Need For Speed Most Wanted Black.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Partiton Magic 8.05.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Partners.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\PayPal Flash Button Creator 1.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\PhotoLine 32 - 12.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Prime (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Pro Evolution Soccer 5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Rounders.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Silence Becomes You.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Spyware Doctor.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\SuperVideoCap 4.38.510.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\SWAT 4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Symantec Norton Ghost 10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\The 40 Year Old Virgin.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\The Man.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\The Polar Express.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Vanilla Sky.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Vietcong 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\Warcraft III The Frozen Throne.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Complete\XmlBlueprint XML Editor 3.9.1220.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Desktop\Diagnostics\ZoneAlarm 6.0.667.000 Pro\Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Tommy Cheung\Desktop\ZoneAlarm 6.0.667.000 Pro\Setup.exe -> Worm.VB.an : Cleaned with backup
C:\RECYCLER\S-1-5-21-1177238915-115176313-725345543-1003\Dc1.tmp -> Worm.VB.an : Cleaned with backup
C:\RECYCLER\S-1-5-21-1177238915-115176313-725345543-1003\Dc2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\WINDOWS\system32\cslzi.exe -> Downloader.Agent.uj : Cleaned with backup

Logfile of HijackThis v1.99.1
Scan saved at 2:39:01 AM, on 1/2/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\Fast.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ZyXEL\ZyXEL USB ADSL\CnxDslTb.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Slim Multimedia Keyboard\MagicKey.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Slim Multimedia Keyboard\OSD.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ewido\security suite\SecuritySuite.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe

R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
F1 - win.ini: run= C:\WESTWOOD\REDALERT\INSTICON.EXE
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZyXEL\ZyXEL USB ADSL\CnxDslTb.exe" "ZyXEL\ZyXEL USB ADSL"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [Advanced Spyware Remover] C:\Program Files\Evonsoft\ASR\Asr.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Slim Multimedia Keyboard.lnk = C:\Program Files\Slim Multimedia Keyboard\MagicKey.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\System32\ZoneLabs\isafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe




::Report End
leila83 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-02-2006, 07:28 PM   #4 (permalink)
Manager Emeritus - Security Center, Expert Analyst, Moderator - Security Team; Rangemaster, TSF Academy & Supporter
 
MicroBell's Avatar
 
Join Date: Sep 2004
Location: Carmichaels, PA-USA
Posts: 6,963
OS: Windows 7


Send a message via ICQ to MicroBell Send a message via MSN to MicroBell
Perform an online scan with Internet Explorer with Panda ActiveScan
** click on "Free use ActiveScan" located on the top right hand corner
  1. Click Check Now & a 'pop up' window shall appear. *ensure that your pop up blocker doesn't block it
  2. Enter your e-mail address, country, and state & click Scan Now ...begins downloading 8 MB Panda's ActiveX controls
Begin the scan by selecting My Computer
  • If it finds any malware, it will offer you a report.
  • Please ignore any entry it finds and wants you to buy the program for removal as we will address this later.
  • Click on see report. Then click Save report
Please post that log in your next reply.
__________________
We Are The BORG Spyware KILLER and Adware Destroyer!





Spyware/Adware Removal Tools
Hijackthis
Ad-aware SE
Spybot Search&Destroy
SpywareBlaster
CWShredder
MicroBell is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-06-2006, 06:25 AM   #5 (permalink)
Registered User
 
Join Date: Dec 2005
Posts: 13
OS: xp


thread finished computer broke down
leila83 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 12:02 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85