1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Too many popups! Hijackthis log included

Discussion in 'Malware and Virus Removal Archive' started by jbh, 2005/03/29.

Thread Status:
Not open for further replies.
  1. 2005/03/29
    jbh

    jbh Inactive Thread Starter

    Joined:
    2004/04/20
    Messages:
    149
    Likes Received:
    0
    My Moms computer is killing her w/pop ups. I've had her install and run ad-ware and spybot. Also had her check for viruses on/with rav.

    This is her hijack log. Don't know what else to do so need your help. Thanks, JBH

    Logfile of HijackThis v1.99.1
    Scan saved at 7:53:02 PM, on 3/25/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Intel\Modem Event
    Monitor\IntelMEM.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\Program Files\MUSICMATCH\Musicmatch
    Jukebox\mm_tray.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
    C:\Program Files\Common
    Files\Real\Update_OB\realsched.exe
    C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\Program Files\Dell Support\DSAgnt.exe
    C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
    C:\Program Files\Yahoo!\Messenger\ypager.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
    C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
    C:\Program Files\Spybot - Search &
    Destroy\TeaTimer.exe
    C:\Program Files\Hewlett-Packard\AiO\hp psc 700
    series\Bin\hpobrt07.exe
    C:\Program Files\Microsoft
    Office\Office\1033\OLFSNT40.EXE
    C:\PROGRA~1\Webshots\webshots.scr
    c:\progra~1\mcafee.com\vso\mcvsftsn.exe
    C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\hpoipm07.exe
    C:\Program
    Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
    C:\WINDOWS\system32\svchost.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    C:\Program Files\Common
    Files\Real\Update_OB\RealOneMessageCenter.exe
    C:\PROGRA~1\NETSCAPE\NETSCAPE\NETSCP.EXE
    C:\DOCUME~1\Brennan\LOCALS~1\Temp\Temporary Directory
    1 for hijackthis.zip\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet
    Explorer\Main,Default_Page_URL =
    http://www.dell4me.com/myway
    R0 - HKCU\Software\Microsoft\Internet
    Explorer\Main,Start Page = http://www.my.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet
    Explorer\Main,Default_Page_URL =
    http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet
    Explorer\Main,Default_Search_URL =
    http://red.clientapps.yahoo.com/cus...//www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet
    Explorer\Main,Search Bar =
    http://red.clientapps.yahoo.com/cus...rch/search.html
    R1 - HKLM\Software\Microsoft\Internet
    Explorer\Main,Search Page =
    http://red.clientapps.yahoo.com/cus...//www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet
    Explorer\Main,Start Page =
    http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet
    Explorer\SearchURL,(Default) =
    http://red.clientapps.yahoo.com/cus...//www.yahoo.com
    N3 - Netscape 7: user_pref( "browser.startup.homepage ",
    "http://daily.webshots.com "); (C:\Documents and
    Settings\Brennan\Application
    Data\Mozilla\Profiles\default\52cedqcc.slt\prefs.j s)
    N3 - Netscape 7:
    user_pref( "browser.search.defaultengine ",
    "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csea rchplugins%5CSBWeb_01.src ");
    (C:\Documents and Settings\Brennan\Application
    Data\Mozilla\Profiles\default\52cedqcc.slt\prefs.j s)
    O3 - Toolbar: McAfee VirusScan -
    {BA52B914-B692-46c4-B683-905236F6F655} -
    c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O4 - HKLM\..\Run: [IgfxTray]
    C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds]
    C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [IntelMeM] C:\Program
    Files\Intel\Modem Event Monitor\IntelMEM.exe
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program
    Files\CyberLink\PowerDVD\DVDLauncher.exe "
    O4 - HKLM\..\Run: [MCAgentExe]
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe]
    C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [MMTray] "C:\Program
    Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe "
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program
    Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
    Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MPFExe]
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe
    "C:\Program
    Files\WildTangent\Apps\CDA\cdaEngine0400.dll ",cdaEngineMain
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
    Files\Java\j2re1.4.2_06\bin\jusched.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
    Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [eBayToolbar] C:\Program
    Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
    O4 - HKLM\..\Run: [dla]
    C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [VSOCheckTask]
    "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online]
    "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe "
    O4 - HKLM\..\Run: [MimBoot]
    C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
    O4 - HKLM\..\Run: [etbrun]
    C:\windows\system32\elitencn32.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell
    Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [Mozilla Quick Launch]
    "C:\PROGRA~1\NETSCAPE\NETSCAPE\NETSCP.EXE" -turbo
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program
    Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program
    Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Spyware Remover] C:\Program
    Files\PAL SPYREM\spyrem.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program
    Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - Startup: Webshots.lnk = C:\Program
    Files\Webshots\Launcher.exe
    O4 - Global Startup: HPAiODevice(hp psc 700 series) -
    1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc
    700 series\Bin\hpobrt07.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program
    Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Symantec Fax Starter Edition
    Port.lnk = C:\Program Files\Microsoft
    Office\Office\1033\OLFSNT40.EXE
    O8 - Extra context menu item: &eBay Search -
    res://C:\Program Files\eBay\eBay
    Toolbar2\eBayTb.dll/RCSearch.html
    O8 - Extra context menu item: &Search -
    http://bar.mywebsearch.com/menusearch.html?p=ZN
    O8 - Extra context menu item: &Yahoo! Search -
    file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Yahoo! &Dictionary -
    file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps -
    file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O9 - Extra button: (no name) -
    {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
    Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console -
    {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
    Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
    O9 - Extra button: Real.com -
    {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
    C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger -
    {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
    Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger -
    {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
    Files\Messenger\msmsgs.exe
    O9 - Extra button: WeatherBug -
    {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program
    Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
    (Java Runtime Environment 1.4.2) -
    O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}
    (Java Runtime Environment 1.4.1_02) -
    O20 - Winlogon Notify: igfxcui -
    C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O23 - Service: Lexar SG20 (LxrSG20s) - Unknown owner -
    C:\WINDOWS\SYSTEM32\LxrSG20s.exe
    O23 - Service: McAfee.com McShield (McShield) -
    Unknown owner -
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee SecurityCenter Update Manager
    (mcupdmgr.exe) - McAfee, Inc -
    C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee.com VirusScan Online Realtime
    Engine (MCVSRte) - Networks Associates Technology, Inc
    - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    O23 - Service: McAfee Personal Firewall Service
    (MpfService) - McAfee Corporation -
    C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
    O23 - Service: Intel NCS NetService (NetSvc) -
    Intel(R) Corporation - C:\Program
    Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
     
    jbh,
    #1
  2. 2005/03/29
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    use hjt to FIX:

    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe
    "C:\Program
    Files\WildTangent\Apps\CDA\cdaEngine0400.dll ",cdaEngineMain

    O4 - HKLM\..\Run: [etbrun]
    C:\windows\system32\elitencn32.exe

    O4 - Startup: Webshots.lnk = C:\Program
    Files\Webshots\Launcher.exe

    O8 - Extra context menu item: &Search -
    http://bar.mywebsearch.com/menusearch.html?p=ZN

    O9 - Extra button: WeatherBug -
    {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program
    Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
     

  3. to hide this advert.

Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.