Discussion in 'adware, spyware & hijack cleaning' started by pandah, Mar 15, 2004.

Thread Status:
Not open for further replies.
  1. pandah

    pandah Guest

    -The original problem was spyware called "yuhmee", it redirects most of my Internet Explorer URLs to a search site full of advertisments.
    I've run the lastest updates of both 'spybot'-which didn't help and 'adaware'. At the moment I'm not sure if I still have the same problem, but I would like to get my registry checked just in case. There also seems to be a problem with my host file.

    Logfile of HijackThis v1.97.7
    Scan saved at 6:29:08 PM, on 15/03/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\Program Files\BlackICE\blackice.exe
    C:\Program Files\BlackICE\blackd.exe
    C:\Documents and Settings\Rob Hamilton\My Documents\Setup, cracks and zips\Setups\HijackThis.exe

    R3 - Default URLSearchHook is missing
    O1 - Hosts: 06272002-dbase.hitcountz.net
    O1 - Hosts: 1ca.cqcounter.com
    O1 - Hosts: 2001-007.com
    O1 - Hosts: ad-logics.com
    O1 - Hosts: ad.trafficmp.com
    O1 - Hosts: adclient.rottentomatoes.com
    O1 - Hosts: adcounter.globeandmail.com
    O1 - Hosts: adcounter.theglobeandmail.com
    O1 - Hosts: adlog.com.com
    O1 - Hosts: admanmail.com
    O1 - Hosts: ads.specificpop.com
    O1 - Hosts: adtech.de
    O1 - Hosts: askmen.thruport.com
    O1 - Hosts: banner.0catch.com
    O1 - Hosts: bilbo.counted.com
    O1 - Hosts: c1.statcounter.com
    O1 - Hosts: c1.thecounter.com
    O1 - Hosts: c2.gostats.com
    O1 - Hosts: c2.thecounter.com
    O1 - Hosts: c3.thecounter.com
    O1 - Hosts: c3.xxxcounter.com
    O1 - Hosts: cashcounter.com
    O1 - Hosts: cgi.hotstat.nl
    O1 - Hosts: clit6.sextracker.com
    O1 - Hosts: clit8.sextracker.com
    O1 - Hosts: cookies.cmpnet.com
    O1 - Hosts: counter.aaddzz.com
    O1 - Hosts: counter.bloke.com
    O1 - Hosts: counter.hitslink.com
    O1 - Hosts: counter.yadro.ru
    O1 - Hosts: counter14.sextracker.com
    O1 - Hosts: counter16.bravenet.com
    O1 - Hosts: counter17.bravenet.com
    O1 - Hosts: counter2.hitslink.com
    O1 - Hosts: counter26.bravenet.com
    O1 - Hosts: counter32.bravenet.com
    O1 - Hosts: counter34.breavenet.com
    O1 - Hosts: counter41.bravenet.com
    O1 - Hosts: counter47.bravenet.com
    O1 - Hosts: counter6.sextracker.com
    O1 - Hosts: counter8.bravenet.com
    O1 - Hosts: data.coremetrics.com
    O1 - Hosts: delivery.loopingclick.com
    O1 - Hosts: dwclick.com
    O1 - Hosts: ebay.doubleclick.net
    O1 - Hosts: ehg-amerix.hitbox.com
    O1 - Hosts: ehg-bestbuy.hitbox.com
    O1 - Hosts: ehg-crain.hitbox.com
    O1 - Hosts: ehg-dig.hitbox.com
    O1 - Hosts: ehg-eckounlimited.hitbox.com
    O1 - Hosts: ehg-espn.hitbox.com
    O1 - Hosts: ehg-idg.hitbox.com
    O1 - Hosts: ehg-liveperson.hitbox.com
    O1 - Hosts: ehg-oreilley.hitbox.com
    O1 - Hosts: ehg-space.hitbox.com
    O1 - Hosts: ehg-sportsline.hitbox.com
    O1 - Hosts: ehg-techtarget.hitbox.com
    O1 - Hosts: ehg-tigerdirect.hitbox.com
    O1 - Hosts: ehg-uniontrib.hitbox.com
    O1 - Hosts: ehg-viacom.hitbox.com
    O1 - Hosts: ehg.commjun.hitbox.com
    O1 - Hosts: ehg.hitbox.com
    O1 - Hosts: fastclick.net
    O1 - Hosts: fcstats.bcentral.com
    O1 - Hosts: flycast.com
    O1 - Hosts: g-wizzads.net
    O1 - Hosts: gostats.com
    O1 - Hosts: gtcc1.acecounter.com
    O1 - Hosts: hc2.humanclick.com
    O1 - Hosts: hit2.hotlog.ru
    O1 - Hosts: hit37.chark.dk
    O1 - Hosts: hitbox.com
    O1 - Hosts: hits.webstat.com
    O1 - Hosts: images.dailydiscounts.com
    O1 - Hosts: imp.clickability.com
    O1 - Hosts: impacts.alliancehub.com
    O1 - Hosts: insightfirst.com
    O1 - Hosts: int.sitestat.com
    O1 - Hosts: jkearns.freestats.com
    O1 - Hosts: linktrack.bravenet.com
    O1 - Hosts: logs.comics.com
    O1 - Hosts: m1.nedstatbasic.net
    O1 - Hosts: media101.sitebrand.com
    O1 - Hosts: mediatrack.revenue.net
    O1 - Hosts: mt122.mtree.com
    O1 - Hosts: nedstat.s0.nl
    O1 - Hosts: nl.sitestat.com
    O1 - Hosts: partner.alerts.aol.com
    O1 - Hosts: paxito.sitetracker.com
    O1 - Hosts: perso.estat.com
    O1 - Hosts: pmg.ad-logics.com
    O1 - Hosts: postclick.adcentriconline.com
    O1 - Hosts: prof.estat.com
    O1 - Hosts: s10.sitemeter.com
    O1 - Hosts: s11.sitemeter.com
    O1 - Hosts: s12.sitemeter.com
    O1 - Hosts: s13.sitemeter.com
    O1 - Hosts: s14.sitemeter.com
    O1 - Hosts: s15.sitemeter.com
    O1 - Hosts: s16.sitemeter.com
    O1 - Hosts: s2.statcounter.com
    O2 - BHO: (no name) - {9819C369-5F62-4D37-9A42-44043A742C1E} - c:\progra~1\ddm\5330\redirect.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [sysu] "C:\progra~1\ddm\sysu.exe"
    O4 - HKLM\..\Run: [CFIMP] C:\WINDOWS\CFIMP.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [RealUpdater] C:\WINDOWS\System32\realupd.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: BlackICE PC Protection.lnk = C:\Program Files\BlackICE\blackice.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} - http://download.rfwnad.com/cab/crack.CAB

  2. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Apr 27, 2002
    Hi pandah,

    Check the items listed below in HijackThis, close all windows except HijackThis and click Fix checked:

    R3 - Default URLSearchHook is missing
    All the O1 - Hosts: entries
    O2 - BHO: (no name) - {9819C369-5F62-4D37-9A42-44043A742C1E} - c:\progra~1\ddm\5330\redirect.dll

    O4 - HKLM\..\Run: [sysu] "C:\progra~1\ddm\sysu.exe"
    O4 - HKLM\..\Run: [CFIMP] C:\WINDOWS\CFIMP.exe

    O4 - HKCU\..\Run: [RealUpdater] C:\WINDOWS\System32\realupd.exe

    O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} - http://download.rfwnad.com/cab/crack.CAB

    Then reboot and delete:
    C:\program files\ddm <= entire folder


  3. pandah

    pandah Guest

    thankyou muchly
  4. slammer_JvA

    slammer_JvA Registered Member

    Feb 23, 2004
    Below sea-level. Safe and sound behind our dikes:
    Re: THANK YOU yuhmee

    Dear Pandah,

    As you noticed, you've come to the right place, with great people, great experts, and great advice.
    A month ago I also experienced simular problems with that nasty YUHMEE.
    Somehow I "stumbled" :rolleyes: onto this forum, and it has been one of the best lucky punches I had for years on the net :) !

    *** That's why I shout a firm: THANK YOU YUHMEE.com ! ;) :D :D :D ***


    Because if it wasn't for their :mad:annoying spyware activities :mad: I would never had been served with so much expert help and knowledge already; I would never had met these fantastic people here! :D *puppy*
    Besides that, this has given me a treasure of links on this -alas- very important subject /threat and all that comes with it.

    I'm still learning every day - and I love it! :-*

    As a bonus you'll meet new people, some of which I already consider new online friends.

    That is why I hope you return, so we can welcome you as a member. CU @ Wilders!
    Don't be shy...look around, ask whatever you want: We all have to start somewhere.
    You'll find your way - like we all did.

    ENJOY :): It's a feast.

    Take care Pandah.

    slammer ;)

    (Only downside may be....lack of sleep, and possible 'addiction'. But there's help for that too, here + plenty of other pleasant "nut-cases" around. :D)
Thread Status:
Not open for further replies.