1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

another annoying pop up "filost"

Discussion in 'Malware and Virus Removal Archive' started by mutebr, 2005/02/27.

Thread Status:
Not open for further replies.
  1. 2005/02/27
    mutebr

    mutebr Inactive Thread Starter

    Joined:
    2005/02/27
    Messages:
    1
    Likes Received:
    0
    Well first off i really dont get much of fixing these spywares never use to have it ... but i have this FILOST one now. Can't seem to get it clean. I acctually only get the http://www.filost.com/stop.htm pop up and seems like only appears after a reboot the machine and when i first open the ie. Might seem pretty much like this one above but i'm not sure. I did follow the one above quite entirely the only thing i didnt get it is how to delete these last ones

    Delete these files.
    c:\eied_s7.cab
    c:\ex.cab
    C:\WINDOWS\System32\vbsys2.dll

    or how to delete with this HJT. I can scan and save a log but to delete just highlight and hit del? Never tried ... anyways i did a log and im posting here just like the others see if i get any help and save me from formating the disk thats a pain and its boring ^^

    one more thig .... what does this spyware acctually do? is it that dangerous?! Thx in advance

    Logfile of HijackThis v1.99.1
    Scan saved at 22:42:37, on 27/2/2005
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Arquivos de programas\WindowBlinds\wbload.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\Mixer.exe
    C:\Arquivos de programas\ZoneAlarm\zlclient.exe
    C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Arquivos de programas\Messenger Plus! 3\MsgPlus.exe
    C:\Arquivos de programas\Microsoft AntiSpyware\gcasServ.exe
    C:\Arquivos de programas\Webshots\WebshotsTray.exe
    C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\pctspk.exe
    C:\WINDOWS\system32\ZONELABS\vsmon.exe
    C:\Arquivos de programas\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Arquivos de programas\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE
    C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE
    C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\Kei-kun\Desktop\hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cuhtrxyahy.com/ZFGVOexj1tMDHOFmh0DDLhECWUk/SC0d05wqbNWr7PgmbfseBAie0E0M48fd_4xm.htm
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cuhtrxyahy.com/ZFGVOexj1tMDHOFmh0DDLhECWUk/SC0d05wqbNWr7PgmbfseBAie0E0M48fd_4xm.htm
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Arquivos de programas\ZoneAlarm\zlclient.exe "
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Arquivos de programas\Messenger Plus! 3\MsgPlus.exe "
    O4 - HKLM\..\Run: [gcasServ] "C:\Arquivos de programas\Microsoft AntiSpyware\gcasServ.exe "
    O4 - Startup: Webshots.lnk = C:\Arquivos de programas\Webshots\WebshotsTray.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\MSMSGS.EXE
    O12 - Plugin for .spop: C:\Arquivos de programas\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1101314893664
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab
    O20 - Winlogon Notify: WB - C:\ARQUIV~1\WINDOW~4\fastload.dll
    O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe

    Not even sure if this is wat u guys need ..... if not let me know
     
  2. 2005/02/28
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    I split your HJT log off of the other thread.

    Disable System Restore, disable MSN Messenger from starting up and reboot.
    Uninstall Messenger Plus! and reboot.

    Go to Start\Run, type in Services.Msc and then press Enter.
    Find the service named SystemCheck2, click on it, then Stop the service. Right click on it and select Properties, and set it to Disable.

    With all internet browsers and Windows Explorer windows closed, remove these items with HJT.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cuhtrxyahy.com/ZFGVOexj1tMDH...E0M48fd_4xm.htm
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cuhtrxyahy.com/ZFGVOexj1tMDH...E0M48fd_4xm.htm
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Arquivos de programas\Messenger Plus! 3\MsgPlus.exe "
    O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
    O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll

    Go to Start\Run, type in Services.Msc and then press Enter.
    Find the service named SystemCheck2, click on it, then Stop the service. Right click on it and select Properties, and set it to Disable.

    Reboot into Safe Mode and delete this folder.
    C:\Arquivos de programas\Messenger Plus! 3

    Then delete these files. They are Hidden, in Windows Explorer, go to the toolbar at Tools\Folder Options, click on the View tab, then select to Show All Files.

    C:\WINDOWS\System32\vbsys2.dll
    c:\eied_s7.cab
    c:\ex.cab
     

  3. to hide this advert.

Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.