1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Microsoft.Windows.RedirectedHosts

Discussion in 'Malware and Virus Removal Archive' started by Charted, 2008/05/03.

  1. 2008/05/03
    Charted

    Charted Inactive Thread Starter

    Joined:
    2008/05/03
    Messages:
    2
    Likes Received:
    0
    Hi everyone so i ran a Spybot S&D test since i wasnt getting on to websites and it came up Microsoft.Windows.RedirectedHosts so i did a little research and found a topic in the forum about it and someone mentioned going to (C:)>Windows>System32>Drivers>ect>host Here is what was in their :
    127.0.0.1 fookit
    127.0.0.1 ihabback.co.uk

    127.0.0.1 habbotx.com

    127.0.0.1 SnGScriptConsole

    127.0.0.1 iHabbix

    92.48.81.32 iHabbixReloaded
    # Copyright (c) 1993-1999 Microsoft Corp.
    #
    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
    #
    # This file contains the mappings of IP addresses to host names. Each
    # entry should be kept on an individual line. The IP address should
    # be placed in the first column followed by the corresponding host name.
    # The IP address and the host name should be separated by at least one
    # space.
    #
    # Additionally, comments (such as these) may be inserted on individual
    # lines or following the machine name denoted by a '#' symbol.
    #
    # For example:
    #
    # 102.54.94.97 rhino.acme.com # source server
    # 38.25.63.10 x.acme.com # x client host



    127.0.0.1 localhost
    127.0.0.1 www.habbo.com
    127.0.0.1 http://habbo.com
    127.0.0.1 habbo.com
    127.0.0.1 http://www.habbo.com
    64.191.14.105 http://habbo.co.uk
    64.191.14.105 http://www.habbo.co.uk
    64.191.14.105 www.habbo.co.uk
    64.191.14.105 habbo.co.uk
    64.191.14.105 http://hotmail.com
    64.191.14.105 http://www.hotmail.com
    64.191.14.105 www.hotmail.com
    64.191.14.105 hotmail.com
    64.191.14.105 http://hotmail.co.uk
    64.191.14.105 www.hotmail.co.uk
    64.191.14.105 hotmail.co.uk
    64.191.14.105 http://www.hotmail.co.uk
    64.191.14.105 live.com
    64.191.14.105 www.live.com
    64.191.14.105 http://live.com
    64.191.14.105 http://www.live.com
    64.191.14.105 msn.com
    64.191.14.105 www.msn.com
    64.191.14.105 http://msn.com
    64.191.14.105 http://www.msn.com
    64.191.14.105 live.co.uk
    64.191.14.105 www.live.co.uk
    64.191.14.105 http://live.co.uk
    64.191.14.105 http://www.live.co.uk
    64.191.14.105 www.msn.co.uk
    64.191.14.105 http://msn.co.uk
    64.191.14.105 http://www.msn.co.uk
    64.191.14.105 msn.co.uk
    127.0.0.1 http://google.com
    127.0.0.1 http://www.google.com
    127.0.0.1 www.google.com
    127.0.0.1 google.com
    127.0.0.1 www.google.co.uk
    127.0.0.1 google.co.uk
    127.0.0.1 http://www.google.co.uk
    127.0.0.1 http://google.co.uk

    And then it kept on repeating itself and i realised that the websites it listed were the websites i couldnt get onto so does anyone have any ideas of what i could do?


    Here is the log!

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:28:38, on 03/05/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
    C:\Program Files\McAfee\Common Framework\UdaterUI.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\McAfee\Common Framework\McTray.exe
    C:\Program Files\NetWaiting\netWaiting.exe
    C:\Program Files\Dell Support\DSAgnt.exe
    C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=3061120
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=3061120
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/&s=Obgi-nMQvHg0kUEmWvL84m2Dwjg
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O1 - Hosts: 92.48.81.32 iHabbixReloaded
    O1 - Hosts: 64.191.14.105 http://habbo.co.uk
    O1 - Hosts: 64.191.14.105 http://www.habbo.co.uk
    O1 - Hosts: 64.191.14.105 www.habbo.co.uk
    O1 - Hosts: 64.191.14.105 habbo.co.uk
    O1 - Hosts: 64.191.14.105 http://hotmail.com
    O1 - Hosts: 64.191.14.105 http://www.hotmail.com
    O1 - Hosts: 64.191.14.105 www.hotmail.com
    O1 - Hosts: 64.191.14.105 hotmail.com
    O1 - Hosts: 64.191.14.105 http://hotmail.co.uk
    O1 - Hosts: 64.191.14.105 www.hotmail.co.uk
    O1 - Hosts: 64.191.14.105 hotmail.co.uk
    O1 - Hosts: 64.191.14.105 http://www.hotmail.co.uk
    O1 - Hosts: 64.191.14.105 live.com
    O1 - Hosts: 64.191.14.105 www.live.com
    O1 - Hosts: 64.191.14.105 http://live.com
    O1 - Hosts: 64.191.14.105 http://www.live.com
    O1 - Hosts: 64.191.14.105 msn.com
    O1 - Hosts: 64.191.14.105 www.msn.com
    O1 - Hosts: 64.191.14.105 http://msn.com
    O1 - Hosts: 64.191.14.105 http://www.msn.com
    O1 - Hosts: 64.191.14.105 live.co.uk
    O1 - Hosts: 64.191.14.105 www.live.co.uk
    O1 - Hosts: 64.191.14.105 http://live.co.uk
    O1 - Hosts: 64.191.14.105 http://www.live.co.uk
    O1 - Hosts: 64.191.14.105 www.msn.co.uk
    O1 - Hosts: 64.191.14.105 http://msn.co.uk
    O1 - Hosts: 64.191.14.105 http://www.msn.co.uk
    O1 - Hosts: 64.191.14.105 msn.co.uk
    O1 - Hosts: 64.191.14.105 http://habbo.co.uk
    O1 - Hosts: 64.191.14.105 http://www.habbo.co.uk
    O1 - Hosts: 64.191.14.105 www.habbo.co.uk
    O1 - Hosts: 64.191.14.105 habbo.co.uk
    O1 - Hosts: 64.191.14.105 http://hotmail.com
    O1 - Hosts: 64.191.14.105 http://www.hotmail.com
    O1 - Hosts: 64.191.14.105 www.hotmail.com
    O1 - Hosts: 64.191.14.105 hotmail.com
    O1 - Hosts: 64.191.14.105 http://hotmail.co.uk
    O1 - Hosts: 64.191.14.105 www.hotmail.co.uk
    O1 - Hosts: 64.191.14.105 hotmail.co.uk
    O1 - Hosts: 64.191.14.105 http://www.hotmail.co.uk
    O1 - Hosts: 64.191.14.105 live.com
    O1 - Hosts: 64.191.14.105 www.live.com
    O1 - Hosts: 64.191.14.105 http://live.com
    O1 - Hosts: 64.191.14.105 http://www.live.com
    O1 - Hosts: 64.191.14.105 msn.com
    O1 - Hosts: 64.191.14.105 www.msn.com
    O1 - Hosts: 64.191.14.105 http://msn.com
    O1 - Hosts: 64.191.14.105 http://www.msn.com
    O1 - Hosts: 64.191.14.105 live.co.uk
    O1 - Hosts: 64.191.14.105 www.live.co.uk
    O1 - Hosts: 64.191.14.105 http://live.co.uk
    O1 - Hosts: 64.191.14.105 http://www.live.co.uk
    O1 - Hosts: 64.191.14.105 www.msn.co.uk
    O1 - Hosts: 64.191.14.105 http://msn.co.uk
    O1 - Hosts: 64.191.14.105 http://www.msn.co.uk
    O1 - Hosts: 64.191.14.105 msn.co.uk
    O1 - Hosts: 64.191.14.105 http://habbo.co.uk
    O1 - Hosts: 64.191.14.105 http://www.habbo.co.uk
    O1 - Hosts: 64.191.14.105 www.habbo.co.uk
    O1 - Hosts: 64.191.14.105 habbo.co.uk
    O1 - Hosts: 64.191.14.105 http://hotmail.com
    O1 - Hosts: 64.191.14.105 http://www.hotmail.com
    O1 - Hosts: 64.191.14.105 www.hotmail.com
    O1 - Hosts: 64.191.14.105 hotmail.com
    O1 - Hosts: 64.191.14.105 http://hotmail.co.uk
    O1 - Hosts: 64.191.14.105 www.hotmail.co.uk
    O1 - Hosts: 64.191.14.105 hotmail.co.uk
    O1 - Hosts: 64.191.14.105 http://www.hotmail.co.uk
    O1 - Hosts: 64.191.14.105 live.com
    O1 - Hosts: 64.191.14.105 www.live.com
    O1 - Hosts: 64.191.14.105 http://live.com
    O1 - Hosts: 64.191.14.105 http://www.live.com
    O1 - Hosts: 64.191.14.105 msn.com
    O1 - Hosts: 64.191.14.105 www.msn.com
    O1 - Hosts: 64.191.14.105 http://msn.com
    O1 - Hosts: 64.191.14.105 http://www.msn.com
    O1 - Hosts: 64.191.14.105 live.co.uk
    O1 - Hosts: 64.191.14.105 www.live.co.uk
    O1 - Hosts: 64.191.14.105 http://live.co.uk
    O1 - Hosts: 64.191.14.105 http://www.live.co.uk
    O1 - Hosts: 64.191.14.105 www.msn.co.uk
    O1 - Hosts: 64.191.14.105 http://msn.co.uk
    O1 - Hosts: 64.191.14.105 http://www.msn.co.uk
    O1 - Hosts: 64.191.14.105 msn.co.uk
    O1 - Hosts: 64.191.14.105 http://habbo.co.uk
    O1 - Hosts: 64.191.14.105 http://www.habbo.co.uk
    O1 - Hosts: 64.191.14.105 www.habbo.co.uk
    O1 - Hosts: 64.191.14.105 habbo.co.uk
    O1 - Hosts: 64.191.14.105 http://hotmail.com
    O1 - Hosts: 64.191.14.105 http://www.hotmail.com
    O1 - Hosts: 64.191.14.105 www.hotmail.com
    O1 - Hosts: 64.191.14.105 hotmail.com
    O1 - Hosts: 64.191.14.105 http://hotmail.co.uk
    O1 - Hosts: 64.191.14.105 www.hotmail.co.uk
    O1 - Hosts: 64.191.14.105 hotmail.co.uk
    O1 - Hosts: 64.191.14.105 http://www.hotmail.co.uk
    O1 - Hosts: 64.191.14.105 live.com
    O1 - Hosts: 64.191.14.105 www.live.com
    O1 - Hosts: 64.191.14.105 http://live.com
    O1 - Hosts: 64.191.14.105 http://www.live.com
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll (file missing)
    O2 - BHO: (no name) - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - (no file)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: ActivationManager module - {86A44EF7-78FC-4e18-A564-B18F806F7F56} - C:\Program Files\ActivationManager\ActivationManager.dll (file missing)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe "
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe "
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe "
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
    O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\\Steam.exe -silent
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Dell Network Assistant.lnk = ?
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1179242804468
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
    O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
    O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
    O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

    --
    End of file - 15088 bytes
     
    Last edited: 2008/05/03
  2. 2008/05/04
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi Charted
    Welcome to Windowsbbs. :)

    Are you using a custom hosts file?

    Geri
     
    Geri,
    #2

  3. to hide this advert.

  4. 2008/05/04
    Charted

    Charted Inactive Thread Starter

    Joined:
    2008/05/03
    Messages:
    2
    Likes Received:
    0
    No this was just the way the file was found.
     
  5. 2008/05/05
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi Charted

    OK please do this.

    Download the HostsXpert 3.7 - Hosts File Manager.
    • Unzip HostsXpert 3.7 - Hosts File Manager to a convenient folder such as C:\HostsXpert
    • Click HostsXpert.exe to Run HostsXpert 3.7 - Hosts File Manager from its new home
    • Click "Make Hosts Writable?" in the upper right corner (If available).
    • Click Backup / Restore then Create Backup
    • Click Restore Microsoft's Hosts file and then click OK.
    • Click the X to exit the program.
    • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.

    Please re-open HiJackThis and scan only. Check the boxes next to all the entries listed below.

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/&s=Obgi-nMQvHg0kUEmWvL84m2Dwjg
    O2 - BHO: (no name) - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: ActivationManager module - {86A44EF7-78FC-4e18-A564-B18F806F7F56} - C:\Program Files\ActivationManager\ActivationManager.dll (file missing)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)


    Now close all windows other than HiJackThis, then click Fix Checked.

    Close HJT.

    Reboot your computer.

    Please post a new HJT log.

    I see you have P2P software ([color= "Red"] Limewire, BitTorrent uTorrent, BitComet etc… [/color]) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.

    Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares and their infections.

    References for the risk of these programs are here,
    here and here.

    I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

    Note: Please be advised that continued use of these programs after being warned of the danger of infections from them, may result in the discontinued help of future cleaning of your system here at Windowsbbs Virus and Spyware removal.

    Thanks
    Geri
     
    Geri,
    #4

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.