1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

I need help with a virus i think

Discussion in 'Malware and Virus Removal Archive' started by tiffanyc, 2007/05/11.

  1. 2007/05/11
    tiffanyc

    tiffanyc Inactive Thread Starter

    Joined:
    2007/05/11
    Messages:
    48
    Likes Received:
    0
    Well my computer crashes a lot lately....everytime i try to run a virus scan or spybot or anything it crashes without finishing....It crashes and starts making this beeping sound so I turn the power strip(for the whole computer) off and this noise keeps going about 20 seconds after there is no power to the computer......then i wait about 15 minutes start it back up and its fine for a little while but eventually will crash again
    HELP!!!!!!!!!!!!!!
     
  2. 2007/05/11
    Hill

    Hill Inactive

    Joined:
    2002/03/16
    Messages:
    130
    Likes Received:
    0
    Sound like its no fun.
    I'll help you get the ball rolling until a REAL malware removal expert comes by. Download HJT and follow the directions. Good Luck

    http://www.thespykiller.co.uk/files/HJTsetup.exe
    download HJTsetup.exe

    * Save HJTsetup.exe to your desktop.
    * Doubleclick on the HJTsetup.exe icon on your desktop.
    * By default it will install to C:\Program Files\Hijack This.
    * Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
    * Put a check by Create a desktop icon then click Next again.
    * Continue to follow the rest of the prompts from there.
    * At the final dialogue box click Finish and it will launch Hijack This.
    * Click on the Scan button.
    You will notice the [Scan] button will turn into a [Save Log] button. [/b] It will scan and the log should open in notepad.
    * Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
    * Come back here to this thread and Paste the log in your next reply.
    * DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
     
    Hill,
    #2

  3. to hide this advert.

  4. 2007/05/11
    tiffanyc

    tiffanyc Inactive Thread Starter

    Joined:
    2007/05/11
    Messages:
    48
    Likes Received:
    0
    ok i hope this is right

    Logfile of HijackThis v1.99.1
    Scan saved at 1:40:24 PM, on 5/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16441)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
    C:\Program Files\Messenger\MSMSGS.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\AIM6\aim6.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Program Files\AIM6\aolsoftware.exe
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
    C:\PROGRA~1\SHORTK~1\shklite.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
    O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe "
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe "
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe "
    O4 - HKLM\..\RunServices: [Microsoft Service] c:\hidden\leetbot.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
    O4 - Global Startup: ShortKeys Lite.lnk = ?
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
    O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4FAE30E1-EE9C-477D-8D06-BF8D3429B60F} (WebIQ Technology Client) - https://www.webiqonline.com/WebIQ/bin/WebIQ.cab
    O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
    O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
     
  5. 2007/05/12
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi tiffanyc
    This could be a hardware problem, but there is one files I would like scanned.

    Please do this for me.

    Jotti File Submission:
    • Please go to Jotti's malware scan
    • Copy and paste the following file path into the "File to upload & scan "box on the top of the page:
      • c:\hidden\leetbot.exe
    • Click on the submit button
    • Please post the results in your next reply.

    Thanks
    Geri
     
    Geri,
    #4
  6. 2007/05/12
    tiffanyc

    tiffanyc Inactive Thread Starter

    Joined:
    2007/05/11
    Messages:
    48
    Likes Received:
    0
    This is what I got

    The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file
     
  7. 2007/05/13
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi tiffanyc

    OK Please do this for me. We need to find out what that file is.
    So a friend is going to take a look at it.

    Please download Suspicious file Packer from Safer-Networking.Org and unzip it to your desktop.

    Copy the below bold list to a notepad file so you have access in safe mode.

    Boot to safe mode.

    Run SFP.exe.

    Please copy the following line:

    c:\hidden\leetbot.exe

    and paste it in the box in SFP, then click "Continue ".

    It will copy the file and zip it up to a cab file on your desktop.
    Called something like "Requested files [time/date].cab "

    Please upload the cab file to this site when you get back to normal mode.

    http://www.thespykiller.co.uk/index.php?board=1.0

    Start yourself a new topic
    Put in topic title "Request to Blender "
    Put in body of messege the link to our thread here.
    then press the browse button and then navigate to & select the cab file on desktop.
    press Post to upload the file

    It is normal you will not see the file you just posted cus only approved members can see em to download them.

    Let me know here when you have posted.

    Thanks
    Geri
     
    Geri,
    #6
  8. 2007/05/13
    tiffanyc

    tiffanyc Inactive Thread Starter

    Joined:
    2007/05/11
    Messages:
    48
    Likes Received:
    0
    ok i did everything you said and have uploaded that file to the link you gave me!!!! Thank you very much......
     
  9. 2007/05/13
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi tiffanyc
    Thanks.

    Please be patent, Blender is very busy at other forms also.
    She will get back to me as soon as she can.

    Thanks
    Geri
     
    Geri,
    #8
  10. 2007/05/16
    tiffanyc

    tiffanyc Inactive Thread Starter

    Joined:
    2007/05/11
    Messages:
    48
    Likes Received:
    0
    ok no problem whenever your friend gets a chance is good with me!!!!! I will be out of town may 22-30 in case you are wondering where i went!!!Thanks so much!!!!!!!
     
  11. 2007/05/16
    bbbobins

    bbbobins Banned

    Joined:
    2007/02/01
    Messages:
    129
    Likes Received:
    0
    Hi Tiffany

    I will try to address the possible hardware problem while awaiting the Spyware Mavens.

    The Virus and Spyware scanners usually try to read almost every file on the disk.

    In doing so they may hit a bad spot on the disk. This will also hinder such things as HiJackThis. Some programs may handle it others may freeze.

    So go to start-run and type
    chkdsk c: /r
    click OK.

    It will not want to do this untill next reboot. So reboot and let it complete.

    When it arrives back to the desktop update but do not run the Virus and spyware scanners that give this problem.

    Then reboot to safe mode (tap several times F8 key while booting before windows loads). Safe Mode only not Safe Mode with networking.

    In safe mode run all the programs. Then report the results back here and wait for Blender.

    Bob
     
  12. 2007/05/16
    bbbobins

    bbbobins Banned

    Joined:
    2007/02/01
    Messages:
    129
    Likes Received:
    0
    Had a few extra moments to research your Leetbot file.

    It is an obvious Virus and reportedly can be removed by most all Virus scanners. If they can be run.

    See links below:

    http://research.sunbelt-software.co...name=Backdoor.Win32.Leetbot.b&threatid=128069

    http://www.emsisoft.com/en/malware/?Backdoor.Win32.Leetbot

    In this case a Safe Mode Scan is likely to complete and fix this. So after a Safe Mode Scan as I advised above if it completes, repost a fresh HJT log.

    This program will bring in other things so depending on how long you have had it you likely have others. So even if the scan completes and fixes this and others you may not know about, you still need to post the HJT log and let Blender take it from there.

    Bob
     
    Last edited: 2007/05/16
  13. 2007/05/17
    tiffanyc

    tiffanyc Inactive Thread Starter

    Joined:
    2007/05/11
    Messages:
    48
    Likes Received:
    0
    I did everything you said!! I ran the avg anti virus and it finished with no threats..I then tried to run the avg anti spyware and as it was just about to finish it made my computer crash??? Is there a better anti virus that will pick this virus up that you can suggest?????
     
  14. 2007/05/17
    bbbobins

    bbbobins Banned

    Joined:
    2007/02/01
    Messages:
    129
    Likes Received:
    0
    Hi Tiffany

    Since the Mavens are not here yet and it has been 2 days we will proceed.

    Print this out so you will have it when you boot to safe mode.

    No the AVG is as good as any. It is a very good Virus scanner. But no Virus scanner can get everything. What one misses another may get.

    So we will use 2 other scanners. An online Scan and a stand alone scan. A stand alone you just download and run, it is not installed like AVG.

    But first we good directly after the leetbot

    Download http://killbox.net/downloads/KillBox.exe

    Boot to safe mode

    run KillBox
    select "Delete on Reboot "

    in full path to delete type
    C:\hidden\leetbot.exe
    click the red X at end of "Full path of file to delete"

    reboot to full mode

    go to start - run
    type cmd click ok
    at prompt type
    attrib c:\leetbot.* /s
    if it says file not found then we have suceeded in deleteing it.
    if it still exists get back to us

    then either way do the following Panda online scan in full mode
    http://www.pandasoftware.com/products/activescan.htm

    Finally downlod unzip and run AVZ, first to bottom Right and select the Update then select drive C: to scan.
    http://z-oleg.com/avz4en.zip

    Try you scann that failed again

    Now back to us with a fresh HJT log

    Bob
     
  15. 2007/05/18
    tiffanyc

    tiffanyc Inactive Thread Starter

    Joined:
    2007/05/11
    Messages:
    48
    Likes Received:
    0
    I did the killbox it said path not found is that the same as file not found or did it not work???
    Everytime I do the panda online it crashes my computer the furthest it has gotten is to 123 spyware and 2 hacking tools???? I did not do the last stpe yet ebcuase i have been trying to get the panda to work any help is appreciated Thanks so much!!!!
     
  16. 2007/05/18
    bbbobins

    bbbobins Banned

    Joined:
    2007/02/01
    Messages:
    129
    Likes Received:
    0
    Hi Tiffany

    No need to keep trying the Panda

    Do this
    start-run
    type
    taskmgr
    click the process tab

    look down the list for leetbot
    if found rt click it an try to end the process
    it may not allow it

    does or not

    start-run
    type
    cmd
    hit enter or click OK

    a command window will open

    at the prompt
    type
    attrib c:\leetbot.* -h -s -r /s

    when it finishes
    at prompt
    type
    rd c:\hidden /s

    when that finishes
    at prompt
    type
    del c:\leetbot.* /s

    Then run the AVZ as i directed in my last post.

    Then get back with results.

    Bob

    I will be available so let me know when you want to leave so i will not wait for you.
     
  17. 2007/05/18
    tiffanyc

    tiffanyc Inactive Thread Starter

    Joined:
    2007/05/11
    Messages:
    48
    Likes Received:
    0
    ok i did not see leetbot when i did the first step you told me...I did the rest and downloaded the avz the scan showed nothing..i then did the avg anit spyware again and it crashed my computer again?????
     
  18. 2007/05/18
    bbbobins

    bbbobins Banned

    Joined:
    2007/02/01
    Messages:
    129
    Likes Received:
    0
    ok

    repost a new Hijackthis log

    bob
     
  19. 2007/05/18
    bbbobins

    bbbobins Banned

    Joined:
    2007/02/01
    Messages:
    129
    Likes Received:
    0
    Tifany

    Just do another HiJackThis log like you did on page 1 post 3.

    Bob
     
  20. 2007/05/18
    tiffanyc

    tiffanyc Inactive Thread Starter

    Joined:
    2007/05/11
    Messages:
    48
    Likes Received:
    0
    Logfile of HijackThis v1.99.1
    Scan saved at 2:46:59 PM, on 5/18/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16441)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Messenger\MSMSGS.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\AIM6\aim6.exe
    C:\Program Files\AIM6\aolsoftware.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\MySpace\IM\MySpaceIM.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    c:\program files\aim6\anotify.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
    O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe "
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe "
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\RunServices: [Microsoft Service] c:\hidden\leetbot.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
    O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4FAE30E1-EE9C-477D-8D06-BF8D3429B60F} (WebIQ Technology Client) - https://www.webiqonline.com/WebIQ/bin/WebIQ.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
     
  21. 2007/05/18
    bbbobins

    bbbobins Banned

    Joined:
    2007/02/01
    Messages:
    129
    Likes Received:
    0
    Ok run HJT choose scan only

    check the below items to remove them
    then at botton click fix checked

    O4 - HKLM\..\RunServices: [Microsoft Service] c:\hidden\leetbot.exe
    O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    then download and run Xclean

    http://www.xblock.com/download/xclean_micro.exe

    Delete all it finds, it may offer a reboot after each entry it finds say no untill it finishes.

    I think we have eradicated the leetbot.

    Uninstall from Add/Remove the RegistryBooster

    Uninstall avg AntiSpy (not AVG Virus) and download a new one and re-install it.

    We may be virus and spyware free and are now coming up against a hardware problem.

    We will go after that next.

    Bob
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.