Discussion in 'adware, spyware & hijack cleaning' started by Hamlet, Mar 30, 2004.

Thread Status:
Not open for further replies.
  1. Hamlet

    Hamlet Guest

    Hello folks, I was told you might be able to help me out.

    Something called Yuhmee Search Companion is ruining my Internet experience. Spybot can't find it, and I can't delete it, even though it shows up on my Add/Remove llist (it sends me to a broken link).

    Here's my HijackThis file. Any advice you could give me would be much appreciated.

    Logfile of HijackThis v1.97.7
    Scan saved at 9:03:15 AM, on 3/30/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    D:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
    C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
    D:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton Utilities\NPROTECT.EXE
    D:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\DIGStream\digstream.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Messenger\msmsgs.exe
    D:\Program Files\adobe\Acrobat 6.0\Distillr\acrotray.exe
    C:\Program Files\Norton Utilities\SYSDOC32.EXE
    D:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    D:\Program Files\Netscape\Netscape\Netscp.exe
    C:\Documents and Settings\Hamlet Nalbandyan\Local Settings\Temp\HijackThis.exe

    N3 - Netscape 7: user_pref("browser.startup.homepage", "latimes.com"); (C:\Documents and Settings\Hamlet Nalbandyan\Application Data\Mozilla\Profiles\default\ozfdnv1s.slt\prefs.js)
    N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://D%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Hamlet Nalbandyan\Application Data\Mozilla\Profiles\default\ozfdnv1s.slt\prefs.js)
    O1 - Hosts: 06272002-dbase.hitcountz.net
    O1 - Hosts: 1ca.cqcounter.com
    O1 - Hosts: 2001-007.com
    O1 - Hosts: ad-logics.com
    O1 - Hosts: ad.trafficmp.com
    O1 - Hosts: adclient.rottentomatoes.com
    O1 - Hosts: adcounter.globeandmail.com
    O1 - Hosts: adcounter.theglobeandmail.com
    O1 - Hosts: adlog.com.com
    O1 - Hosts: admanmail.com
    O1 - Hosts: ads.specificpop.com
    O1 - Hosts: adtech.de
    O1 - Hosts: askmen.thruport.com
    O1 - Hosts: banner.0catch.com
    O1 - Hosts: bilbo.counted.com
    O1 - Hosts: c1.statcounter.com
    O1 - Hosts: c1.thecounter.com
    O1 - Hosts: c2.gostats.com
    O1 - Hosts: c2.thecounter.com
    O1 - Hosts: c3.thecounter.com
    O1 - Hosts: c3.xxxcounter.com
    O1 - Hosts: cashcounter.com
    O1 - Hosts: cgi.hotstat.nl
    O1 - Hosts: clit6.sextracker.com
    O1 - Hosts: clit8.sextracker.com
    O1 - Hosts: cookies.cmpnet.com
    O1 - Hosts: counter.aaddzz.com
    O1 - Hosts: counter.bloke.com
    O1 - Hosts: counter.hitslink.com
    O1 - Hosts: counter.yadro.ru
    O1 - Hosts: counter14.sextracker.com
    O1 - Hosts: counter16.bravenet.com
    O1 - Hosts: counter17.bravenet.com
    O1 - Hosts: counter2.hitslink.com
    O1 - Hosts: counter26.bravenet.com
    O1 - Hosts: counter32.bravenet.com
    O1 - Hosts: counter34.breavenet.com
    O1 - Hosts: counter41.bravenet.com
    O1 - Hosts: counter47.bravenet.com
    O1 - Hosts: counter6.sextracker.com
    O1 - Hosts: counter8.bravenet.com
    O1 - Hosts: data.coremetrics.com
    O1 - Hosts: delivery.loopingclick.com
    O1 - Hosts: dwclick.com
    O1 - Hosts: ehg-amerix.hitbox.com
    O1 - Hosts: ehg-bestbuy.hitbox.com
    O1 - Hosts: ehg-crain.hitbox.com
    O1 - Hosts: ehg-dig.hitbox.com
    O1 - Hosts: ehg-eckounlimited.hitbox.com
    O1 - Hosts: ehg-espn.hitbox.com
    O1 - Hosts: ehg-idg.hitbox.com
    O1 - Hosts: ehg-liveperson.hitbox.com
    O1 - Hosts: ehg-oreilley.hitbox.com
    O1 - Hosts: ehg-space.hitbox.com
    O1 - Hosts: ehg-sportsline.hitbox.com
    O1 - Hosts: ehg-techtarget.hitbox.com
    O1 - Hosts: ehg-tigerdirect.hitbox.com
    O1 - Hosts: ehg-uniontrib.hitbox.com
    O1 - Hosts: ehg-viacom.hitbox.com
    O1 - Hosts: ehg.commjun.hitbox.com
    O1 - Hosts: ehg.hitbox.com
    O1 - Hosts: fastclick.net
    O1 - Hosts: fcstats.bcentral.com
    O1 - Hosts: flycast.com
    O1 - Hosts: g-wizzads.net
    O1 - Hosts: gostats.com
    O1 - Hosts: gtcc1.acecounter.com
    O1 - Hosts: hc2.humanclick.com
    O1 - Hosts: hit2.hotlog.ru
    O1 - Hosts: hit37.chark.dk
    O1 - Hosts: hitbox.com
    O1 - Hosts: hits.webstat.com
    O1 - Hosts: images.dailydiscounts.com
    O1 - Hosts: imp.clickability.com
    O1 - Hosts: impacts.alliancehub.com
    O1 - Hosts: insightfirst.com
    O1 - Hosts: int.sitestat.com
    O1 - Hosts: jkearns.freestats.com
    O1 - Hosts: linktrack.bravenet.com
    O1 - Hosts: logs.comics.com
    O1 - Hosts: m1.nedstatbasic.net
    O1 - Hosts: media101.sitebrand.com
    O1 - Hosts: mediatrack.revenue.net
    O1 - Hosts: mt122.mtree.com
    O1 - Hosts: nedstat.s0.nl
    O1 - Hosts: nl.sitestat.com
    O1 - Hosts: partner.alerts.aol.com
    O1 - Hosts: paxito.sitetracker.com
    O1 - Hosts: perso.estat.com
    O1 - Hosts: pmg.ad-logics.com
    O1 - Hosts: postclick.adcentriconline.com
    O1 - Hosts: prof.estat.com
    O1 - Hosts: s10.sitemeter.com
    O1 - Hosts: s11.sitemeter.com
    O1 - Hosts: s12.sitemeter.com
    O1 - Hosts: s13.sitemeter.com
    O1 - Hosts: s14.sitemeter.com
    O1 - Hosts: s15.sitemeter.com
    O1 - Hosts: s16.sitemeter.com
    O1 - Hosts: s2.statcounter.com
    O1 - Hosts: sm1.sitemeter.com
    O2 - BHO: (no name) - {9819C369-5F62-4D37-9A42-44043A742C1E} - c:\progra~1\ddm\9219\redirect.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
    O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [QD FastAndSafe] C:\Program Files\Norton CleanSweep\QDCSFS.exe /scheduler
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [URLLSTCK.exe] D:\Program Files\UrlLstCk.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [IWE] C:\WINDOWS\IWE.exe
    O4 - HKLM\..\Run: [QuickTime Task] "D:\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [sysu] "C:\progra~1\ddm\sysu.exe"
    O4 - HKLM\..\Run: [SAHBundle] C:\DOCUME~1\HAMLET~1\LOCALS~1\Temp\bundle.exe
    O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] D:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=041304 serial=DR12WTX-9999998-YSP lang=EN
    O4 - HKLM\..\Run: [WDNJ] C:\WINDOWS\WDNJ.exe
    O4 - HKLM\..\Run: [P2encM] C:\WINDOWS\System32\P2encM.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Startup: Norton System Doctor.LNK = C:\Program Files\Norton Utilities\SYSDOC32.EXE
    O4 - Global Startup: Acrobat Assistant.lnk = D:\Program Files\adobe\Acrobat 6.0\Distillr\acrotray.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
    O9 - Extra button: Researcher (HKLM)
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O16 - DPF: Yahoo! NBA StatTracker - http://aud5.sports.yahoo.com/java/y/nbast8264_x.cab
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
    O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
    O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab
    O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe
    O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) -
    O16 - DPF: {73F0FD85-BD47-4A95-86D1-DE38860462C1} (PremiumHTML Class) - http://www.accesoplugin.com/dialercab/IberoDialerHTML.cab
    O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/i486/NTANSI/retail/DASAct.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
    O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://encarta.msn.com/encnet/external/MSSurVid.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control) - http://download.rfwnad.com/cab/crack.CAB
    O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) -
    O16 - DPF: {FF054BED-D972-4215-897E-726C3488DDBB} (sonyctl.sonycm) - http://supportcentral4.sel.sony.com/sdccommon/download/sonyctl.CAB
  2. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Apr 27, 2002
    Hi Hamlet,

    <insert your own joke about yuhmee or not ....>

    Before you start please unzip hijackthis.exe to a folder of it´s own. The program creates backups in the folder it is in. In a Temp folder they easily disappear.

    Check the following items in HijackThis.
    Close all windows except HijackThis and click Fix checked:

    All the O1 - Hosts: entries
    O2 - BHO: (no name) - {9819C369-5F62-4D37-9A42-44043A742C1E} - c:\progra~1\ddm\9219\redirect.dll

    O4 - HKLM\..\Run: [IWE] C:\WINDOWS\IWE.exe
    O4 - HKLM\..\Run: [QuickTime Task] "D:\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [sysu] "C:\progra~1\ddm\sysu.exe"
    O4 - HKLM\..\Run: [SAHBundle] C:\DOCUME~1\HAMLET~1\LOCALS~1\Temp\bundle.exe

    O4 - HKLM\..\Run: [WDNJ] C:\WINDOWS\WDNJ.exe
    O4 - HKLM\..\Run: [P2encM] C:\WINDOWS\System32\P2encM.exe

    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -

    O16 - DPF: {73F0FD85-BD47-4A95-86D1-DE38860462C1} (PremiumHTML Class) - http://www.accesoplugin.com/dialercab/IberoDialerHTML.cab

    O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control) - http://download.rfwnad.com/cab/crack.CAB

    Then reboot and delete:
    C:\program files\ddm <= the entire folder<

    And could you please mail these files to the address in my profile:

    Then run HijackThis again and post the new log.


Thread Status:
Not open for further replies.