Discussion in 'adware, spyware & hijack cleaning' started by Armen Vahe, Feb 22, 2004.

Thread Status:
Not open for further replies.
  1. Armen Vahe

    Armen Vahe Guest

    Logfile of HijackThis v1.97.7
    Scan saved at 4:26:11 AM, on 2/23/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
    C:\Program Files\Copy Handler\Copy Handler.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Winamp\winamp.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Armen Vahe\Local Settings\Temp\HijackThis.exe

    O1 - Hosts: 06272002-dbase.hitcountz.net
    O1 - Hosts: 1ca.cqcounter.com
    O1 - Hosts: 2001-007.com
    O1 - Hosts: ad-logics.com
    O1 - Hosts: ad.trafficmp.com
    O1 - Hosts: adclient.rottentomatoes.com
    O1 - Hosts: adcounter.globeandmail.com
    O1 - Hosts: adcounter.theglobeandmail.com
    O1 - Hosts: adlog.com.com
    O1 - Hosts: admanmail.com
    O1 - Hosts: ads.specificpop.com
    O1 - Hosts: adtech.de
    O1 - Hosts: askmen.thruport.com
    O1 - Hosts: banner.0catch.com
    O1 - Hosts: bilbo.counted.com
    O1 - Hosts: c1.statcounter.com
    O1 - Hosts: c1.thecounter.com
    O1 - Hosts: c2.gostats.com
    O1 - Hosts: c2.thecounter.com
    O1 - Hosts: c3.thecounter.com
    O1 - Hosts: c3.xxxcounter.com
    O1 - Hosts: cashcounter.com
    O1 - Hosts: cgi.hotstat.nl
    O1 - Hosts: clit6.sextracker.com
    O1 - Hosts: clit8.sextracker.com
    O1 - Hosts: cookies.cmpnet.com
    O1 - Hosts: counter.aaddzz.com
    O1 - Hosts: counter.bloke.com
    O1 - Hosts: counter.hitslink.com
    O1 - Hosts: counter.yadro.ru
    O1 - Hosts: counter14.sextracker.com
    O1 - Hosts: counter16.bravenet.com
    O1 - Hosts: counter17.bravenet.com
    O1 - Hosts: counter2.hitslink.com
    O1 - Hosts: counter26.bravenet.com
    O1 - Hosts: counter32.bravenet.com
    O1 - Hosts: counter34.breavenet.com
    O1 - Hosts: counter41.bravenet.com
    O1 - Hosts: counter47.bravenet.com
    O1 - Hosts: counter6.sextracker.com
    O1 - Hosts: counter8.bravenet.com
    O1 - Hosts: data.coremetrics.com
    O1 - Hosts: delivery.loopingclick.com
    O1 - Hosts: dwclick.com
    O1 - Hosts: ebay.doubleclick.net
    O1 - Hosts: ehg-amerix.hitbox.com
    O1 - Hosts: ehg-bestbuy.hitbox.com
    O1 - Hosts: ehg-crain.hitbox.com
    O1 - Hosts: ehg-dig.hitbox.com
    O1 - Hosts: ehg-eckounlimited.hitbox.com
    O1 - Hosts: ehg-espn.hitbox.com
    O1 - Hosts: ehg-idg.hitbox.com
    O1 - Hosts: ehg-liveperson.hitbox.com
    O1 - Hosts: ehg-oreilley.hitbox.com
    O1 - Hosts: ehg-space.hitbox.com
    O1 - Hosts: ehg-sportsline.hitbox.com
    O1 - Hosts: ehg-techtarget.hitbox.com
    O1 - Hosts: ehg-tigerdirect.hitbox.com
    O1 - Hosts: ehg-uniontrib.hitbox.com
    O1 - Hosts: ehg-viacom.hitbox.com
    O1 - Hosts: ehg.commjun.hitbox.com
    O1 - Hosts: ehg.hitbox.com
    O1 - Hosts: fastclick.net
    O1 - Hosts: fcstats.bcentral.com
    O1 - Hosts: flycast.com
    O1 - Hosts: g-wizzads.net
    O1 - Hosts: gostats.com
    O1 - Hosts: gtcc1.acecounter.com
    O1 - Hosts: hc2.humanclick.com
    O1 - Hosts: hit2.hotlog.ru
    O1 - Hosts: hit37.chark.dk
    O1 - Hosts: hitbox.com
    O1 - Hosts: hits.webstat.com
    O1 - Hosts: images.dailydiscounts.com
    O1 - Hosts: imp.clickability.com
    O1 - Hosts: impacts.alliancehub.com
    O1 - Hosts: insightfirst.com
    O1 - Hosts: int.sitestat.com
    O1 - Hosts: jkearns.freestats.com
    O1 - Hosts: linktrack.bravenet.com
    O1 - Hosts: logs.comics.com
    O1 - Hosts: m1.nedstatbasic.net
    O1 - Hosts: media101.sitebrand.com
    O1 - Hosts: mediatrack.revenue.net
    O1 - Hosts: mt122.mtree.com
    O1 - Hosts: nedstat.s0.nl
    O1 - Hosts: nl.sitestat.com
    O1 - Hosts: partner.alerts.aol.com
    O1 - Hosts: paxito.sitetracker.com
    O1 - Hosts: perso.estat.com
    O1 - Hosts: pmg.ad-logics.com
    O1 - Hosts: postclick.adcentriconline.com
    O1 - Hosts: prof.estat.com
    O1 - Hosts: s10.sitemeter.com
    O1 - Hosts: s11.sitemeter.com
    O1 - Hosts: s12.sitemeter.com
    O1 - Hosts: s13.sitemeter.com
    O1 - Hosts: s14.sitemeter.com
    O1 - Hosts: s15.sitemeter.com
    O1 - Hosts: s16.sitemeter.com
    O1 - Hosts: s2.statcounter.com
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Copy handler] C:\Program Files\Copy Handler\Copy Handler.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
    O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
    O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
    O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra button: Yahoo! Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38012.7546759259
    O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} - http://download.rfwnad.com/cab/dlaccell.CAB
    O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} - http://download.redswoosh.net/Installer/104/rsinstaller.cab
  2. snowbound

    snowbound Retired Moderator

    Feb 18, 2003
    The Big Smoke
    Hi Armen Vahe :)

    Welcome to Wilders.

    First thing u need to do is unzip highjackthis.exe to a folder of it's own. It will create backups in the folder that it is in.

    Iam not an expert but i know these entries can be fixed.

    Check the following items in HijackThis.

    Close all windows except HijackThis and click Fix checked:

    All the 01 entries

    Then reboot and post a fresh HJT log.

    After wait for one of the experts to give u recommendations on the rest of your log.

  3. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Apr 27, 2002
    Fix these as well:
    O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} - http://download.rfwnad.com/cab/dlaccell.CAB
    O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} - http://download.redswoosh.net/Installer/104/rsinstaller.cab

    and you should be fine.


Thread Status:
Not open for further replies.