Go Back   Winamp Forums > Community Center > General Discussions

Reply
Thread Tools Search this Thread Display Modes
Old 1st June 2004, 20:58   #1
Cleanup
The WWYD Jerk
(Forum King)
 
Cleanup's Avatar
 
Join Date: Jan 2002
Location: Shanghai
Posts: 2,385
WToolsA.exe

Winamp doesn't have a computing/general tech support forum, but I figure that GD has the smartest people around.

Noticed some bad stuff happening on my computer. It's not in my Add/Remove Programs list and I can't delete or end the processes - access is denied. I ran HijackThis. Here's my log.

Logfile of HijackThis v1.97.7
Scan saved at 5:00:50 PM, on 01/06/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common files\WinTools\WToolsS.exe
C:\WINDOWS\System32\BRMFRSMG.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Common files\WinTools\WSup.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common files\WinTools\WToolsA.exe
D:\Documents and Settings\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://allaboutsearching.com/passthr...redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
O1 - Hosts: 207.36.196.189 auto.search.msn.com
O1 - Hosts: 207.36.196.189 search.netscape.com
O1 - Hosts: 207.36.196.189 ieautosearch
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: proxy bike shim - {AB0DE5A1-18C2-B6F4-A3B5-A358EA961AE5} - C:\PROGRA~1\KNOBMA~1\PEAK HOLD.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\Downloaded Program Files\bridge.dll",Load
O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common files\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [gsdyfm] C:\WINDOWS\System32\qjbdesvf.exe
O4 - HKLM\..\Run: [Tick Curb] C:\PROGRA~1\PollGreyLong\Safe Mfcd.exe
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research (HKLM)
O9 - Extra button: FlashGet (HKLM)
O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} (ZingBatchAXDwnl Class) - http://www.imagestation.com/common/c...on=4,3,2,20802
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...978.6802777778
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/co...20/SassCln.CAB
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Instal...sinstaller.cab

Help me, please! How can I get rid of this ugly shpoo?
Cleanup is offline   Reply With Quote
Old 1st June 2004, 21:03   #2
drewbar
Sawg 2.0
Major Dude
 
Join Date: Mar 2004
Posts: 5,917
http://forums.spywareinfo.com/index....ic=2703&st=0&#
http://forums.techguy.org/showpost.p...13&postcount=4

Plus run Spybot and AdAware

Count with us!
Jan 1st, 12AM (PST, GMT -8) 2010 - 282,246
drewbar is offline   Reply With Quote
Old 1st June 2004, 21:04   #3
Germ
rules all things
 
Germ's Avatar
 
Join Date: Jan 2001
Posts: 3,148
Re: WToolsA.exe

Quote:
Originally posted by Cleanup
Winamp doesn't have a computing/general tech support forum, but I figure that GD has the smartest people around.
HAHAHAHAHHAHAHAHHAHA
Germ is offline   Reply With Quote
Old 1st June 2004, 22:01   #4
ryan
not fucked, not quite.
(Forum King)
 
ryan's Avatar
 
Join Date: Feb 2002
Location: Tn
Posts: 8,755
Send a message via AIM to ryan
Cleanup, looks like Germ proved you wrong.
ryan is offline   Reply With Quote
Old 1st June 2004, 23:18   #5
Germ
rules all things
 
Germ's Avatar
 
Join Date: Jan 2001
Posts: 3,148
Help! I'M BEING FLAMED
Germ is offline   Reply With Quote
Old 1st June 2004, 23:51   #6
DJ Egg
Techorator
Winamp Team
 
Join Date: Jun 2000
Posts: 35,125
Yup, you've got some nasty malware and browser hijackers there.

I'm the resident HJT log analyzer in the Winamp Tech forum
(I also post at TSG and Computercops.biz forums, as The_Egg).

WinTools is a trojan / hijacker, and appears to be a new variant of the IBIS Toolbar

bridge.dll = WinFavorites / Loud Marketing Flingstone.com browser hijacker

fgiebar.dll = FlashGet BHO hijack.
Did you knowingly install this spyware p.o.s.?

alchem.exe = ClickAlchemy (new Transponder variant)


There's also a few entries there with no info from a google search,
or from any of my usual resource sites, so I'm going to assume they're bad.
If you know for sure that any of the entries I tell you to fix are kosher, then leave "as is".
Namely:
Toolbar: proxy bike shim (peak hold.dll)
[Tick Curb]: PollGreyLong\Safe Mfcd.exe


First, download and install the following programs:
(note, I recommend all of these).

CWShredder (CoolWebSearch Shredder)
Spybot Search & Destroy [direct download]
SpywareBlaster

Additional/optional scan/protection:
Adaware6
SpywareGuard


Now print out this page, and close ALL browser and Explorer windows,
and as many other apps as possible (if not all).


Run CWShredder first.
Note, the download is the executable,
so save it to eg. C:\Program Files\CWShredder -or- Desktop

Click the "Fix" button.
When done, you can now close CWShredder.


Next, go to the Services Control Panel (Control Panel > Admin Tools)
and "stop" the "WinTools For IE Service" (WToolsS.exe)
and then set it to "disabled" (c/o right click > properties)

Open Task Manager
End process for all of:
WToolsA.exe
WSup.exe
(WToolsS.exe should already be disabled)


Now have HJT fix the following entries:
(checkmark them, and click "fix checked")

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://allaboutsearching.com/passth.../redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)

O1 - Hosts: 207.36.196.189 auto.search.msn.com

O1 - Hosts: 207.36.196.189 search.netscape.com

O1 - Hosts: 207.36.196.189 ieautosearch

O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll

O3 - Toolbar: proxy bike shim - {AB0DE5A1-18C2-B6F4-A3B5-A358EA961AE5} - C:\PROGRA~1\KNOBMA~1\PEAK HOLD.dll

O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\Downloaded Program Files\bridge.dll",Load

O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common files\WinTools\WToolsA.exe

O4 - HKLM\..\Run: [gsdyfm] C:\WINDOWS\System32\qjbdesvf.exe

O4 - HKLM\..\Run: [Tick Curb] C:\PROGRA~1\PollGreyLong\Safe Mfcd.exe

O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe

O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm

O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm

O9 - Extra button: FlashGet (HKLM)

O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)

O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} (ZingBatchAXDwnl Class) - http://www.imagestation.com/common/classes/batchdwnl.cab?version=4,3,2,20802

O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab

O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Installer/104/rsinstaller.cab


Now the delete the following files and folders:

C:\Program Files\Common files\WinTools
C:\Program Files\Flashget
C:\WINDOWS\System32\qjbdesvf.exe
C:\WINDOWS\alchem.exe
C:\WINDOWS\Downloaded Program Files\bridge.dll
C:\Program Files\KNOBMA~1\PEAK HOLD.dll (wtf is this?)
C:\Program Files\PollGreyLong\Safe Mfcd.exe (wtf is this?)


Next...

Run Spywareblaster
Install all updates
Protect your system against further attacks
(program usage is straightforward).

You can also add the following c/o Tools > Custom Blocking:
Name = WinTools
CLSID = {87766247-311C-43B4-8499-3D5FEC94A183}


Now run SpybotSD
Check for updates first
Immunize your system
Run the scan
Fix all
Reboot.

If you wish, post a new HJT log when done.


Note to others:
Please do not post HJT logs here.
There's plenty of forums on the net which deal with these issues.
http://computercops******forumx67-0-50.html
http://forums.spywareinfo.com
http://forums.techguy.org
etc etc.
DJ Egg is online now   Reply With Quote
Old 2nd June 2004, 00:10   #7
Cleanup
The WWYD Jerk
(Forum King)
 
Cleanup's Avatar
 
Join Date: Jan 2002
Location: Shanghai
Posts: 2,385
Well, I cleaned out some of the stuff. I believe WinTools is gone, and so is the bridge.dll stuffs. But of course, I'm still getting some random pop-ups and decreased performance. So, I'll go through DJ Egg's instructions, and see how I do.

For fun, here's my current HJT log.

Logfile of HijackThis v1.97.7
Scan saved at 8:18:23 PM, on 01/06/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\BRMFRSMG.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Canon\MultiPASS4\MPDBMgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Documents and Settings\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 207.36.196.189 auto.search.msn.com
O1 - Hosts: 207.36.196.189 search.netscape.com
O1 - Hosts: 207.36.196.189 ieautosearch
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research (HKLM)
O9 - Extra button: FlashGet (HKLM)
O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...978.6802777778
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/co...20/SassCln.CAB
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Instal...sinstaller.cab

Notably, I see msn and netscape search stuff, and Flashget. I never knew Flashget was linked to adware.

[Edit:]

Quote:
HAHAHAHAHAHAHAHAHA...
I don't post in GD much. I started that What Do You Do crap, but that was it. I think I was either being a kiss-ass or sarcastic.
Cleanup is offline   Reply With Quote
Old 2nd June 2004, 00:17   #8
InvisableMan
Ninja Master!
(Forum King)
 
InvisableMan's Avatar
 
Join Date: Mar 2001
Location: Hotel California
Posts: 4,325
Send a message via AIM to InvisableMan
egg for president of tech support.

oh wait. he already is now that sawg is gone.
InvisableMan is offline   Reply With Quote
Old 2nd June 2004, 00:27   #9
DJ Egg
Techorator
Winamp Team
 
Join Date: Jun 2000
Posts: 35,125
Yeah, you've still got a few things left (Flashget, alchemy, the hosts hijackers, and the DPF's).

Follow my instructions implicitly


After you've got rid of all the evil crap from above,
if decreased performance is still an issue, although they're not malware,
you can disable the following (useless?) startup items:

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

MS Japanese/Oriental Language Support
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName

Hopefully you've not got the msconfig virus there.
There has been known to be a virus which replaces the standard msconfig.
You'll know for sure if you go to start -> run -> msconfig
and no msconfig window appears.

Also, good luck with disabling msoffice language bar ctfmon.exe and QuickTime qttask.exe,
because they have a nasty habit of auto re-enabling themselves.
Both are known resource hoggers.
DJ Egg is online now   Reply With Quote
Old 4th June 2004, 20:34   #10
Cleanup
The WWYD Jerk
(Forum King)
 
Cleanup's Avatar
 
Join Date: Jan 2002
Location: Shanghai
Posts: 2,385
HJT Log:

Logfile of HijackThis v1.97.7
Scan saved at 4:41:26 PM, on 04/06/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\BRMFRSMG.EXE
D:\Documents and Settings\Desktop\Anti-Spyware\HijackThis.exe

O1 - Hosts: 207.36.196.189 auto.search.msn.com
O1 - Hosts: 207.36.196.189 search.netscape.com
O1 - Hosts: 207.36.196.189 ieautosearch
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...978.6802777778
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/co...20/SassCln.CAB
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab

I used SpybotSD before... I didn't really figure it did anything.. hopefully, this time, it works.

As long as I have it installed, it'll prevent known spyware from installing on my computer?

Edit:

Also, what's C:\WINDOWS\System32\BRMFRSMG.EXE?

And I can't seem to get rid of the netscape/msn/ieautosearch lines.
Cleanup is offline   Reply With Quote
Old 4th June 2004, 20:36   #11
Cleanup
The WWYD Jerk
(Forum King)
 
Cleanup's Avatar
 
Join Date: Jan 2002
Location: Shanghai
Posts: 2,385
I'm still getting pop-ups - ones I've gotten before. Is there anything else suspicious in my log? BRMFRSMG.EXE is a thing for my printer.
Cleanup is offline   Reply With Quote
Old 4th June 2004, 20:38   #12
Cleanup
The WWYD Jerk
(Forum King)
 
Cleanup's Avatar
 
Join Date: Jan 2002
Location: Shanghai
Posts: 2,385
Wow, um, as soon as I closed my browser, three shortcuts appeared on my desktop: Instant Love Alert, Free Games - Cash Prizes, and Discount Travel Specials. I've seen the last one before, but I thought I removed it.

This isn't cool.
Cleanup is offline   Reply With Quote
Old 4th June 2004, 20:38   #13
ElChevelle
Moderator Alumni
 
ElChevelle's Avatar
 
Join Date: Jun 2000
Location: the MANCANNON!
Posts: 22,430
EDIT your posts, rather than post multiple times at once.
ElChevelle is offline   Reply With Quote
Old 4th June 2004, 20:39   #14
ElChevelle
Moderator Alumni
 
ElChevelle's Avatar
 
Join Date: Jun 2000
Location: the MANCANNON!
Posts: 22,430
Please
ElChevelle is offline   Reply With Quote
Old 4th June 2004, 20:44   #15
Cleanup
The WWYD Jerk
(Forum King)
 
Cleanup's Avatar
 
Join Date: Jan 2002
Location: Shanghai
Posts: 2,385
Hehe. It's easier to use the quick reply than click edit.

[Edit:] Note, those three shortcuts I just deleted linked to webpages, nothing on my computer. But something in my computer must be creating them.
Cleanup is offline   Reply With Quote
Old 4th June 2004, 20:45   #16
ElChevelle
Moderator Alumni
 
ElChevelle's Avatar
 
Join Date: Jun 2000
Location: the MANCANNON!
Posts: 22,430
Easy and right are two different thingees.
ElChevelle is offline   Reply With Quote
Old 5th June 2004, 11:51   #17
Omega X
Forum King
 
Omega X's Avatar
 
Join Date: Feb 2003
Location: A Parallel Dimension
Posts: 2,233
Send a message via AIM to Omega X Send a message via Yahoo to Omega X
EWW!!
"C:\WINDOWS\Downloaded Program Files\bridge.dll"

Had that slip into my comp last month. Spybot S&D killed that with a startup scan.
Omega X is offline   Reply With Quote
Old 5th June 2004, 12:22   #18
Widdykats
The Forum Slut
 
Widdykats's Avatar
 
Join Date: Jun 2002
Location: A place that invites a post pumping whore from NY
Posts: 15,579
I just ran SpybotSD, which I just dowloaded from here,
thankyouverymuch!
I had downloaded Shareaza and after found about 27 "tracking" things ..Great program! Computer seems a little faster..still trying to find a good p2p that won't confuse me, and is fast......
Widdykats is offline   Reply With Quote
Old 5th June 2004, 13:37   #19
Cleanup
The WWYD Jerk
(Forum King)
 
Cleanup's Avatar
 
Join Date: Jan 2002
Location: Shanghai
Posts: 2,385
Widdy: You can always get an illegal copy of KaZaA Gold. Yummy.

I'm still getting random pop-ups... Where's DJ and his tech-knowledge?
Cleanup is offline   Reply With Quote
Old 5th June 2004, 13:46   #20
Widdykats
The Forum Slut
 
Widdykats's Avatar
 
Join Date: Jun 2002
Location: A place that invites a post pumping whore from NY
Posts: 15,579
(out of side of mouth)... pm me with that please
DJ is probably in tech forum or asleep or out shopping
or in the backyard or...what?
Widdykats is offline   Reply With Quote
Reply
Go Back   Winamp Forums > Community Center > General Discussions

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump