Need help!

Discussion in 'adware, spyware & hijack cleaning' started by Mikko, Apr 21, 2004.

Thread Status:
Not open for further replies.
  1. Mikko

    Mikko Registered Member

    Joined:
    Apr 4, 2004
    Posts:
    6
    browser changing homepage....

    hijackthislog

    Logfile of HijackThis v1.97.7
    Scan saved at 0:09:39, on 22.4.2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\PFShared\UmxCfg.exe
    C:\Program Files\Common Files\PFShared\UmxPol.exe
    C:\Program Files\Tiny Personal Firewall\UmxAgent.exe
    C:\Program Files\Tiny Personal Firewall\UmxTray.exe
    C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
    C:\Program Files\NavNT\defwatch.exe
    C:\WINDOWS\System32\inetsrv\inetinfo.exe
    C:\Program Files\No-IP\DUC20.exe
    C:\Program Files\NavNT\rtvscan.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\PFShared\umxlu.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\System32\MsgSys.EXE
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\GSICON.EXE
    C:\WINDOWS\System32\dslagent.exe
    C:\program files\powerstrip\pstrip.exe
    C:\Program Files\NavNT\vptray.exe
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\Program Files\Messenger Plus! 2\MsgPlus.exe
    C:\Program Files\Internet Optimizer\optimize.exe
    C:\Program Files\Internet Optimizer\actalert.exe
    C:\program files\180solutions\msbb.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\ClockSync\Sync.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\No-IP\DUC20.exe
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\Program Files\steam\Steam.exe
    C:\Program Files\mIRC614\mirc.exe
    D:\programs\hijackthis1977\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.suomi24.fi/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=132156
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Sonera Plaza Ltd
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.suomi24.fi/
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O1 - Hosts file is located at: C:\WINDOWS\nsdb\hosts
    O1 - Hosts: 81.211.105.69 lender-search.com
    O1 - Hosts: 81.211.105.68 hot-searches.com
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
    O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
    O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
    O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
    O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
    O4 - HKLM\..\Run: [Locks Grid] C:\PROGRA~1\BAGSOP~1\filmslow.exe
    O4 - HKLM\..\Run: [SAHBundle] C:\DOCUME~1\Mikko\LOCALS~1\Temp\bundle.exe
    O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
    O4 - HKLM\..\Run: [msbb] c:\program files\180solutions\msbb.exe
    O4 - HKLM\..\Run: [cbmrwxov] C:\WINDOWS\cbmrwxov.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [ClockSync] C:\Program Files\ClockSync\Sync.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Startup: No-IP DUC.lnk = C:\Program Files\No-IP\DUC20.exe
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra button: Hello from Picasa Capture (HKLM)
    O9 - Extra 'Tools' menuitem: Share in &Hello from Picasa (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38035.4826388889
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {EF86873F-04C2-4A95-A373-5703C08EFC7B} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
     
  2. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    4,449
    Location:
    North Carolina, USA
    Hi Mikko,

    Welcome to Wilder's!!!!!

    First download Ad-Aware and double-click to install.
    Then follow the following steps:

    1.) Start Ad-Aware by double-clicking on its desktop icon.
    2.) Update Ad-aware by using its Globe icon.
    3.) After updating, close all IE windows, then close and restart Ad-aware.
    4.) Be sure the following items are checked under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Scanning Engine:
    "Unload recognized processes during scanning".
    5.) Be sure the following items are checked under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Cleaning Engine:
    "Automatically mark all objects in result list".
    "Automatically try to unregister objects prior to deletion".
    "XP/2000: Allow unloading explorer to unload shell extensions prior deletion" <-- Check only if you have Windows XP or 2000.
    "Let Windows remove files in use after reboot".
    6.) Press "Scan Now".
    7.) Check option "Use Custom scanning options".
    8.) Check option "Activate In-Depth Scan".
    9.) Press "Select drives\folders to scan".
    10.) Select the active partition which is usually C:
    11.) Press "Next" to let Ad-aware scan your drives...
    12.) If it finds "bad" files and registry keys, press "Next" again.
    13.) All items should be checked. if not right-click in that pane and choose "select all".
    14.) Press "next".
    15.) When it asks to remove all checked items, Press "OK".
    16.) You may now exit out of Ad-Aware and reboot your system. Then go to the next section for SpyBot S&D.

    Now download Spybot S&D and install by double-clicking on the downloaded file.
    Then follow the following steps:

    1.) Run Spybot S&D from desktop icon or Start menu.
    2.) Press "Search for updates" button to get list of updates available.
    3.) Press "Download updates" button.
    4.) Close all IE windows, then close and restart Spybot S&D.
    5.) Press "Check for problems" button.
    6.) Have SpyBot remove all it marks in red by pressing "Fix selected problems".
    7.) You may now exit out of SpyBot and reboot your system. Then go to the next section for CWShredder.

    Please download the latest copy of CWShredder and run by double-clicking the icon of the file you just downloaded.
    Click FIX and follow the instructions given.

    Now reboot your system and post a new HJT log.

    Regards,
    Kent
     
Thread Status:
Not open for further replies.