Yuhmee.com Which ones do I Delete?

Discussion in 'adware, spyware & hijack cleaning' started by Pete M, Feb 22, 2004.

Thread Status:
Not open for further replies.
  1. Pete M

    Pete M Guest

    Hi there,

    I got the annoying username/password from yuhmee.com popping up every time I load an IE page. Which ones do I delete to get rid of it??


    Logfile of HijackThis v1.97.7
    Scan saved at 18:35:09, on 22/02/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\Logitech\iTouch\iTouch.exe
    C:\Program Files\Messenger Plus! 2\MsgPlus.exe
    C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
    C:\Program Files\Steam\Steam.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\mIRC\mirc.exe
    C:\Program Files\Microsoft ActiveSync\WCESMgr.exe
    C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
    C:\Program Files\Winamp\winamp.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O1 - Hosts: 06272002-dbase.hitcountz.net
    O1 - Hosts: 1ca.cqcounter.com
    O1 - Hosts: 2001-007.com
    O1 - Hosts: ad-logics.com
    O1 - Hosts: ad.trafficmp.com
    O1 - Hosts: adclient.rottentomatoes.com
    O1 - Hosts: adcounter.globeandmail.com
    O1 - Hosts: adcounter.theglobeandmail.com
    O1 - Hosts: adlog.com.com
    O1 - Hosts: admanmail.com
    O1 - Hosts: ads.specificpop.com
    O1 - Hosts: adtech.de
    O1 - Hosts: askmen.thruport.com
    O1 - Hosts: banner.0catch.com
    O1 - Hosts: bilbo.counted.com
    O1 - Hosts: c1.statcounter.com
    O1 - Hosts: c1.thecounter.com
    O1 - Hosts: c2.gostats.com
    O1 - Hosts: c2.thecounter.com
    O1 - Hosts: c3.thecounter.com
    O1 - Hosts: c3.xxxcounter.com
    O1 - Hosts: cashcounter.com
    O1 - Hosts: cgi.hotstat.nl
    O1 - Hosts: clit6.sextracker.com
    O1 - Hosts: clit8.sextracker.com
    O1 - Hosts: cookies.cmpnet.com
    O1 - Hosts: counter.aaddzz.com
    O1 - Hosts: counter.bloke.com
    O1 - Hosts: counter.hitslink.com
    O1 - Hosts: counter.yadro.ru
    O1 - Hosts: counter14.sextracker.com
    O1 - Hosts: counter16.bravenet.com
    O1 - Hosts: counter17.bravenet.com
    O1 - Hosts: counter2.hitslink.com
    O1 - Hosts: counter26.bravenet.com
    O1 - Hosts: counter32.bravenet.com
    O1 - Hosts: counter34.breavenet.com
    O1 - Hosts: counter41.bravenet.com
    O1 - Hosts: counter47.bravenet.com
    O1 - Hosts: counter6.sextracker.com
    O1 - Hosts: counter8.bravenet.com
    O1 - Hosts: data.coremetrics.com
    O1 - Hosts: delivery.loopingclick.com
    O1 - Hosts: dwclick.com
    O1 - Hosts: ebay.doubleclick.net
    O1 - Hosts: ehg-amerix.hitbox.com
    O1 - Hosts: ehg-bestbuy.hitbox.com
    O1 - Hosts: ehg-crain.hitbox.com
    O1 - Hosts: ehg-dig.hitbox.com
    O1 - Hosts: ehg-eckounlimited.hitbox.com
    O1 - Hosts: ehg-espn.hitbox.com
    O1 - Hosts: ehg-idg.hitbox.com
    O1 - Hosts: ehg-liveperson.hitbox.com
    O1 - Hosts: ehg-oreilley.hitbox.com
    O1 - Hosts: ehg-space.hitbox.com
    O1 - Hosts: ehg-sportsline.hitbox.com
    O1 - Hosts: ehg-techtarget.hitbox.com
    O1 - Hosts: ehg-tigerdirect.hitbox.com
    O1 - Hosts: ehg-uniontrib.hitbox.com
    O1 - Hosts: ehg-viacom.hitbox.com
    O1 - Hosts: ehg.commjun.hitbox.com
    O1 - Hosts: ehg.hitbox.com
    O1 - Hosts: fastclick.net
    O1 - Hosts: fcstats.bcentral.com
    O1 - Hosts: flycast.com
    O1 - Hosts: g-wizzads.net
    O1 - Hosts: gostats.com
    O1 - Hosts: gtcc1.acecounter.com
    O1 - Hosts: hc2.humanclick.com
    O1 - Hosts: hit2.hotlog.ru
    O1 - Hosts: hit37.chark.dk
    O1 - Hosts: hitbox.com
    O1 - Hosts: hits.webstat.com
    O1 - Hosts: images.dailydiscounts.com
    O1 - Hosts: imp.clickability.com
    O1 - Hosts: impacts.alliancehub.com
    O1 - Hosts: insightfirst.com
    O1 - Hosts: int.sitestat.com
    O1 - Hosts: jkearns.freestats.com
    O1 - Hosts: linktrack.bravenet.com
    O1 - Hosts: logs.comics.com
    O1 - Hosts: m1.nedstatbasic.net
    O1 - Hosts: media101.sitebrand.com
    O1 - Hosts: mediatrack.revenue.net
    O1 - Hosts: mt122.mtree.com
    O1 - Hosts: nedstat.s0.nl
    O1 - Hosts: nl.sitestat.com
    O1 - Hosts: partner.alerts.aol.com
    O1 - Hosts: paxito.sitetracker.com
    O1 - Hosts: perso.estat.com
    O1 - Hosts: pmg.ad-logics.com
    O1 - Hosts: postclick.adcentriconline.com
    O1 - Hosts: prof.estat.com
    O1 - Hosts: s10.sitemeter.com
    O1 - Hosts: s11.sitemeter.com
    O1 - Hosts: s12.sitemeter.com
    O1 - Hosts: s13.sitemeter.com
    O1 - Hosts: s14.sitemeter.com
    O1 - Hosts: s15.sitemeter.com
    O1 - Hosts: s16.sitemeter.com
    O1 - Hosts: s2.statcounter.com
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SB-Live-2003\PROGRAM\ADGJDet.exe"
    O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
    O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [Steam] C:\Program Files\Steam\Steam.exe -silent
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra button: Create Mobile Favorite (HKLM)
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
    O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://pete/tsweb/msrdp.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37863.3865625
    O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab
    O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.telewest.co.uk/motive/files/MotivePreQual.cab
    O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} - http://download.rfwnad.com/cab/dlaccell.CAB
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{58317AF4-E00D-4AB5-9013-C0E805B5E05B}: NameServer =,
  2. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Apr 27, 2002
    Hi Pete,

    Check the following items in HijackThis.
    Close all windows except HijackThis and click Fix checked:

    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    All the O1 entries

    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -

    O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab

    O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} - http://download.rfwnad.com/cab/dlaccell.CAB

    Then reboot.


Thread Status:
Not open for further replies.