Discussion in 'adware, spyware & hijack cleaning' started by Elise Hesselink, Feb 29, 2004.

Thread Status:
Not open for further replies.
  1. I have spyware from Yuhmee.com and can't delete it. My system is very slow.

    I made the next Hijack.log. I also ran Ad-Aware and it doesn't find spyware.
    Can you help me?

    Logfile of HijackThis v1.97.7
    Scan saved at 10:47:21, on 29-2-2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
    C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
    C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
    C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
    C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
    C:\Program Files\Logitech\iTouch\iTouch.exe
    C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Logitech\MouseWare\system\em_exec.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\Program Files\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
    C:\WINDOWS\twain_32\Trust\Direct Webscan\WATCH.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Hampsink.HAMPSINK1\Local Settings\Temp\Tijdelijke map 2 voor hijackthis1977.zip\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    R3 - Default URLSearchHook is missing
    O1 - Hosts: 06272002-dbase.hitcountz.net
    O1 - Hosts: 1ca.cqcounter.com
    O1 - Hosts: 2001-007.com
    O1 - Hosts: ad-logics.com
    O1 - Hosts: ad.trafficmp.com
    O1 - Hosts: adclient.rottentomatoes.com
    O1 - Hosts: adcounter.globeandmail.com
    O1 - Hosts: adcounter.theglobeandmail.com
    O1 - Hosts: adlog.com.com
    O1 - Hosts: admanmail.com
    O1 - Hosts: ads.specificpop.com
    O1 - Hosts: adtech.de
    O1 - Hosts: askmen.thruport.com
    O1 - Hosts: banner.0catch.com
    O1 - Hosts: bilbo.counted.com
    O1 - Hosts: c1.statcounter.com
    O1 - Hosts: c1.thecounter.com
    O1 - Hosts: c2.gostats.com
    O1 - Hosts: c2.thecounter.com
    O1 - Hosts: c3.thecounter.com
    O1 - Hosts: c3.xxxcounter.com
    O1 - Hosts: cashcounter.com
    O1 - Hosts: cgi.hotstat.nl
    O1 - Hosts: clit6.sextracker.com
    O1 - Hosts: clit8.sextracker.com
    O1 - Hosts: cookies.cmpnet.com
    O1 - Hosts: counter.aaddzz.com
    O1 - Hosts: counter.bloke.com
    O1 - Hosts: counter.hitslink.com
    O1 - Hosts: counter.yadro.ru
    O1 - Hosts: counter14.sextracker.com
    O1 - Hosts: counter16.bravenet.com
    O1 - Hosts: counter17.bravenet.com
    O1 - Hosts: counter2.hitslink.com
    O1 - Hosts: counter26.bravenet.com
    O1 - Hosts: counter32.bravenet.com
    O1 - Hosts: counter34.breavenet.com
    O1 - Hosts: counter41.bravenet.com
    O1 - Hosts: counter47.bravenet.com
    O1 - Hosts: counter6.sextracker.com
    O1 - Hosts: counter8.bravenet.com
    O1 - Hosts: data.coremetrics.com
    O1 - Hosts: delivery.loopingclick.com
    O1 - Hosts: dwclick.com
    O1 - Hosts: ebay.doubleclick.net
    O1 - Hosts: ehg-amerix.hitbox.com
    O1 - Hosts: ehg-bestbuy.hitbox.com
    O1 - Hosts: ehg-crain.hitbox.com
    O1 - Hosts: ehg-dig.hitbox.com
    O1 - Hosts: ehg-eckounlimited.hitbox.com
    O1 - Hosts: ehg-espn.hitbox.com
    O1 - Hosts: ehg-idg.hitbox.com
    O1 - Hosts: ehg-liveperson.hitbox.com
    O1 - Hosts: ehg-oreilley.hitbox.com
    O1 - Hosts: ehg-space.hitbox.com
    O1 - Hosts: ehg-sportsline.hitbox.com
    O1 - Hosts: ehg-techtarget.hitbox.com
    O1 - Hosts: ehg-tigerdirect.hitbox.com
    O1 - Hosts: ehg-uniontrib.hitbox.com
    O1 - Hosts: ehg-viacom.hitbox.com
    O1 - Hosts: ehg.commjun.hitbox.com
    O1 - Hosts: ehg.hitbox.com
    O1 - Hosts: fastclick.net
    O1 - Hosts: fcstats.bcentral.com
    O1 - Hosts: flycast.com
    O1 - Hosts: g-wizzads.net
    O1 - Hosts: gostats.com
    O1 - Hosts: gtcc1.acecounter.com
    O1 - Hosts: hc2.humanclick.com
    O1 - Hosts: hit2.hotlog.ru
    O1 - Hosts: hit37.chark.dk
    O1 - Hosts: hitbox.com
    O1 - Hosts: hits.webstat.com
    O1 - Hosts: images.dailydiscounts.com
    O1 - Hosts: imp.clickability.com
    O1 - Hosts: impacts.alliancehub.com
    O1 - Hosts: insightfirst.com
    O1 - Hosts: int.sitestat.com
    O1 - Hosts: jkearns.freestats.com
    O1 - Hosts: linktrack.bravenet.com
    O1 - Hosts: logs.comics.com
    O1 - Hosts: m1.nedstatbasic.net
    O1 - Hosts: media101.sitebrand.com
    O1 - Hosts: mediatrack.revenue.net
    O1 - Hosts: mt122.mtree.com
    O1 - Hosts: nedstat.s0.nl
    O1 - Hosts: nl.sitestat.com
    O1 - Hosts: partner.alerts.aol.com
    O1 - Hosts: paxito.sitetracker.com
    O1 - Hosts: perso.estat.com
    O1 - Hosts: pmg.ad-logics.com
    O1 - Hosts: postclick.adcentriconline.com
    O1 - Hosts: prof.estat.com
    O1 - Hosts: s10.sitemeter.com
    O1 - Hosts: s11.sitemeter.com
    O1 - Hosts: s12.sitemeter.com
    O1 - Hosts: s13.sitemeter.com
    O1 - Hosts: s14.sitemeter.com
    O1 - Hosts: s15.sitemeter.com
    O1 - Hosts: s16.sitemeter.com
    O1 - Hosts: s2.statcounter.com
    O2 - BHO: (no name) - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\Program Files\DAP\DAPBHO.dll
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG.exe -on
    O4 - HKLM\..\Run: [Gainward] C:\WINDOWS\TBPanel.exe /A
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zapro.exe
    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [Dit] Dit.exe
    O4 - HKLM\..\Run: [Realtime Audio Engine] mmrtkrnl.exe
    O4 - HKLM\..\Run: [ElbyCheckElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
    O4 - HKLM\..\Run: [Gtwatch] C:\WINDOWS\gtwatch.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\Downloaded Program Files\bridge.dll",Load
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Pinnacle Scheduler.lnk = ?
    O4 - Global Startup: Watch.lnk = C:\WINDOWS\twain_32\Trust\Direct Webscan\WATCH.exe
    O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O9 - Extra button: Run DAP (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
    O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - https://extranet.nijmegen.nl/Citrix/ICAWEB/en/ica32/ica32t.exe
    O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/nl/big/1.1.62-big/GoogleNav.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
    O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.bibliotheekmillingen.nl/catalogus/msrdp.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://webcam.enschede.nl:48250/activex/AxisCamControl.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37933.1262384259
    O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} - http://download.rfwnad.com/cab/dlaccell.CAB
  2. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Apr 27, 2002
    Hoi Elise,

    Before you start please unzip hijackthis.exe to a folder of it´s own. The program creates backups in the folder it is in. In a Temp folder they easily disappear.

    Check the following items in HijackThis.
    Close all windows except HijackThis and click Fix checked:

    All the O1 entries

    O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\Downloaded Program Files\bridge.dll",Load

    O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} - http://download.rfwnad.com/cab/dlaccell.CAB

    Then reboot.
    There are some more things we can disable from starting at boot, but let's see how it goes without spyware first. ;)


  3. Hoi Pieter,

    Thank you very much for your quick help. And it helped. The spyware is gone and the computer now is very fast again.
    What did you mean with this: There are some more things we can disable from starting at boot, but let's see how it goes without spyware first"o_O??

    Regards, Elise
  4. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Apr 27, 2002
    Hi Elise,

    You have some unnecessary programs starting up IMO, but if your computer is acting like you want it to now, it's better not to mess with those.

    Glad we could help. :)


  5. Hoi Pieter,

    OK, thanks very much for your good help! Keep up the good work!

    Groeten, Elise ;)
Thread Status:
Not open for further replies.