|
|
#1 |
|
The WWYD Jerk
(Forum King) Join Date: Jan 2002
Location: Shanghai
Posts: 2,385
|
WToolsA.exe
Winamp doesn't have a computing/general tech support forum, but I figure that GD has the smartest people around.
Noticed some bad stuff happening on my computer. It's not in my Add/Remove Programs list and I can't delete or end the processes - access is denied. I ran HijackThis. Here's my log. Logfile of HijackThis v1.97.7 Scan saved at 5:00:50 PM, on 01/06/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common files\WinTools\WToolsS.exe C:\WINDOWS\System32\BRMFRSMG.EXE C:\WINDOWS\Explorer.EXE C:\Program Files\Messenger Plus! 2\MsgPlus.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe C:\WINDOWS\System32\RUNDLL32.EXE C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Common files\WinTools\WSup.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common files\WinTools\WToolsA.exe D:\Documents and Settings\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://allaboutsearching.com/passthr...redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file) O1 - Hosts: 207.36.196.189 auto.search.msn.com O1 - Hosts: 207.36.196.189 search.netscape.com O1 - Hosts: 207.36.196.189 ieautosearch O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: proxy bike shim - {AB0DE5A1-18C2-B6F4-A3B5-A358EA961AE5} - C:\PROGRA~1\KNOBMA~1\PEAK HOLD.dll O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\Downloaded Program Files\bridge.dll",Load O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common files\WinTools\WToolsA.exe O4 - HKLM\..\Run: [gsdyfm] C:\WINDOWS\System32\qjbdesvf.exe O4 - HKLM\..\Run: [Tick Curb] C:\PROGRA~1\PollGreyLong\Safe Mfcd.exe O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: Research (HKLM) O9 - Extra button: FlashGet (HKLM) O9 - Extra 'Tools' menuitem: &FlashGet (HKLM) O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} (ZingBatchAXDwnl Class) - http://www.imagestation.com/common/c...on=4,3,2,20802 O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...978.6802777778 O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/co...20/SassCln.CAB O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Instal...sinstaller.cab Help me, please! How can I get rid of this ugly shpoo? |
|
|
|
|
|
#2 |
|
Sawg 2.0
Major Dude Join Date: Mar 2004
Posts: 5,917
|
http://forums.spywareinfo.com/index....ic=2703&st=0&#
http://forums.techguy.org/showpost.p...13&postcount=4 Plus run Spybot and AdAware |
|
|
|
|
|
#3 | |
|
rules all things
Join Date: Jan 2001
Posts: 3,148
|
Re: WToolsA.exe
Quote:
|
|
|
|
|
|
|
#4 |
|
not fucked, not quite.
(Forum King) |
Cleanup, looks like Germ proved you wrong.
|
|
|
|
|
|
#5 |
|
rules all things
Join Date: Jan 2001
Posts: 3,148
|
Help! I'M BEING FLAMED
|
|
|
|
|
|
#6 |
|
Techorator
Winamp Team Join Date: Jun 2000
Posts: 35,125
|
Yup, you've got some nasty malware and browser hijackers there.
I'm the resident HJT log analyzer in the Winamp Tech forum (I also post at TSG and Computercops.biz forums, as The_Egg). WinTools is a trojan / hijacker, and appears to be a new variant of the IBIS Toolbar bridge.dll = WinFavorites / Loud Marketing Flingstone.com browser hijacker fgiebar.dll = FlashGet BHO hijack. Did you knowingly install this spyware p.o.s.? alchem.exe = ClickAlchemy (new Transponder variant) There's also a few entries there with no info from a google search, or from any of my usual resource sites, so I'm going to assume they're bad. If you know for sure that any of the entries I tell you to fix are kosher, then leave "as is". Namely: Toolbar: proxy bike shim (peak hold.dll) [Tick Curb]: PollGreyLong\Safe Mfcd.exe First, download and install the following programs: (note, I recommend all of these). CWShredder (CoolWebSearch Shredder) Spybot Search & Destroy [direct download] SpywareBlaster Additional/optional scan/protection: Adaware6 SpywareGuard Now print out this page, and close ALL browser and Explorer windows, and as many other apps as possible (if not all). Run CWShredder first. Note, the download is the executable, so save it to eg. C:\Program Files\CWShredder -or- Desktop Click the "Fix" button. When done, you can now close CWShredder. Next, go to the Services Control Panel (Control Panel > Admin Tools) and "stop" the "WinTools For IE Service" (WToolsS.exe) and then set it to "disabled" (c/o right click > properties) Open Task Manager End process for all of: WToolsA.exe WSup.exe (WToolsS.exe should already be disabled) Now have HJT fix the following entries: (checkmark them, and click "fix checked") R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://allaboutsearching.com/passth.../redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file) O1 - Hosts: 207.36.196.189 auto.search.msn.com O1 - Hosts: 207.36.196.189 search.netscape.com O1 - Hosts: 207.36.196.189 ieautosearch O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll O3 - Toolbar: proxy bike shim - {AB0DE5A1-18C2-B6F4-A3B5-A358EA961AE5} - C:\PROGRA~1\KNOBMA~1\PEAK HOLD.dll O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\Downloaded Program Files\bridge.dll",Load O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common files\WinTools\WToolsA.exe O4 - HKLM\..\Run: [gsdyfm] C:\WINDOWS\System32\qjbdesvf.exe O4 - HKLM\..\Run: [Tick Curb] C:\PROGRA~1\PollGreyLong\Safe Mfcd.exe O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm O9 - Extra button: FlashGet (HKLM) O9 - Extra 'Tools' menuitem: &FlashGet (HKLM) O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} (ZingBatchAXDwnl Class) - http://www.imagestation.com/common/classes/batchdwnl.cab?version=4,3,2,20802 O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Installer/104/rsinstaller.cab Now the delete the following files and folders: C:\Program Files\Common files\WinTools C:\Program Files\Flashget C:\WINDOWS\System32\qjbdesvf.exe C:\WINDOWS\alchem.exe C:\WINDOWS\Downloaded Program Files\bridge.dll C:\Program Files\KNOBMA~1\PEAK HOLD.dll (wtf is this?) C:\Program Files\PollGreyLong\Safe Mfcd.exe (wtf is this?) Next... Run Spywareblaster Install all updates Protect your system against further attacks (program usage is straightforward). You can also add the following c/o Tools > Custom Blocking: Name = WinTools CLSID = {87766247-311C-43B4-8499-3D5FEC94A183} Now run SpybotSD Check for updates first Immunize your system Run the scan Fix all Reboot. If you wish, post a new HJT log when done. Note to others: Please do not post HJT logs here. There's plenty of forums on the net which deal with these issues. http://computercops******forumx67-0-50.html http://forums.spywareinfo.com http://forums.techguy.org etc etc. |
|
|
|
|
|
#7 | |
|
The WWYD Jerk
(Forum King) Join Date: Jan 2002
Location: Shanghai
Posts: 2,385
|
Well, I cleaned out some of the stuff. I believe WinTools is gone, and so is the bridge.dll stuffs. But of course, I'm still getting some random pop-ups and decreased performance. So, I'll go through DJ Egg's instructions, and see how I do.
For fun, here's my current HJT log. Logfile of HijackThis v1.97.7 Scan saved at 8:18:23 PM, on 01/06/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\System32\BRMFRSMG.EXE C:\WINDOWS\Explorer.EXE C:\Program Files\Messenger Plus! 2\MsgPlus.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe C:\WINDOWS\System32\RUNDLL32.EXE C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Canon\MultiPASS4\MPDBMgr.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Internet Explorer\iexplore.exe D:\Documents and Settings\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: 207.36.196.189 auto.search.msn.com O1 - Hosts: 207.36.196.189 search.netscape.com O1 - Hosts: 207.36.196.189 ieautosearch O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: Research (HKLM) O9 - Extra button: FlashGet (HKLM) O9 - Extra 'Tools' menuitem: &FlashGet (HKLM) O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...978.6802777778 O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/co...20/SassCln.CAB O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Instal...sinstaller.cab Notably, I see msn and netscape search stuff, and Flashget. I never knew Flashget was linked to adware. [Edit:] Quote:
|
|
|
|
|
|
|
#8 |
|
Ninja Master!
(Forum King) |
egg for president of tech support.
oh wait. he already is now that sawg is gone. |
|
|
|
|
|
#9 |
|
Techorator
Winamp Team Join Date: Jun 2000
Posts: 35,125
|
Yeah, you've still got a few things left (Flashget, alchemy, the hosts hijackers, and the DPF's).
Follow my instructions implicitly ![]() After you've got rid of all the evil crap from above, if decreased performance is still an issue, although they're not malware, you can disable the following (useless?) startup items: O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe MS Japanese/Oriental Language Support O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName Hopefully you've not got the msconfig virus there. There has been known to be a virus which replaces the standard msconfig. You'll know for sure if you go to start -> run -> msconfig and no msconfig window appears. Also, good luck with disabling msoffice language bar ctfmon.exe and QuickTime qttask.exe, because they have a nasty habit of auto re-enabling themselves. Both are known resource hoggers. |
|
|
|
|
|
#10 |
|
The WWYD Jerk
(Forum King) Join Date: Jan 2002
Location: Shanghai
Posts: 2,385
|
HJT Log:
Logfile of HijackThis v1.97.7 Scan saved at 4:41:26 PM, on 04/06/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Messenger Plus! 2\MsgPlus.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe C:\WINDOWS\System32\RUNDLL32.EXE C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\BRMFRSMG.EXE D:\Documents and Settings\Desktop\Anti-Spyware\HijackThis.exe O1 - Hosts: 207.36.196.189 auto.search.msn.com O1 - Hosts: 207.36.196.189 search.netscape.com O1 - Hosts: 207.36.196.189 ieautosearch O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: Research (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Messenger (HKLM) O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...978.6802777778 O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/co...20/SassCln.CAB O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab I used SpybotSD before... I didn't really figure it did anything.. hopefully, this time, it works. As long as I have it installed, it'll prevent known spyware from installing on my computer? Edit: Also, what's C:\WINDOWS\System32\BRMFRSMG.EXE? And I can't seem to get rid of the netscape/msn/ieautosearch lines. |
|
|
|
|
|
#11 |
|
The WWYD Jerk
(Forum King) Join Date: Jan 2002
Location: Shanghai
Posts: 2,385
|
I'm still getting pop-ups - ones I've gotten before. Is there anything else suspicious in my log? BRMFRSMG.EXE is a thing for my printer.
|
|
|
|
|
|
#12 |
|
The WWYD Jerk
(Forum King) Join Date: Jan 2002
Location: Shanghai
Posts: 2,385
|
Wow, um, as soon as I closed my browser, three shortcuts appeared on my desktop: Instant Love Alert, Free Games - Cash Prizes, and Discount Travel Specials. I've seen the last one before, but I thought I removed it.
This isn't cool. |
|
|
|
|
|
#13 |
|
Moderator Alumni
Join Date: Jun 2000
Location: the MANCANNON!
Posts: 22,430
|
EDIT your posts, rather than post multiple times at once.
|
|
|
|
|
|
#14 |
|
Moderator Alumni
Join Date: Jun 2000
Location: the MANCANNON!
Posts: 22,430
|
Please
|
|
|
|
|
|
#15 |
|
The WWYD Jerk
(Forum King) Join Date: Jan 2002
Location: Shanghai
Posts: 2,385
|
Hehe. It's easier to use the quick reply than click edit.
[Edit:] Note, those three shortcuts I just deleted linked to webpages, nothing on my computer. But something in my computer must be creating them. |
|
|
|
|
|
#16 |
|
Moderator Alumni
Join Date: Jun 2000
Location: the MANCANNON!
Posts: 22,430
|
Easy and right are two different thingees.
|
|
|
|
|
|
#17 |
|
Forum King
|
EWW!!
"C:\WINDOWS\Downloaded Program Files\bridge.dll" Had that slip into my comp last month. Spybot S&D killed that with a startup scan.
Webmaster @Order Of The Mists [OOM] |
|
|
|
|
|
#18 |
|
The Forum Slut
Join Date: Jun 2002
Location: A place that invites a post pumping whore from NY
Posts: 15,579
|
I just ran SpybotSD, which I just dowloaded from here,
thankyouverymuch! I had downloaded Shareaza and after found about 27 "tracking" things ..Great program! Computer seems a little faster..still trying to find a good p2p that won't confuse me, and is fast...... |
|
|
|
|
|
#19 |
|
The WWYD Jerk
(Forum King) Join Date: Jan 2002
Location: Shanghai
Posts: 2,385
|
Widdy: You can always get an illegal copy of KaZaA Gold. Yummy.
I'm still getting random pop-ups... Where's DJ and his tech-knowledge? |
|
|
|
|
|
#20 |
|
The Forum Slut
Join Date: Jun 2002
Location: A place that invites a post pumping whore from NY
Posts: 15,579
|
(out of side of mouth)... pm me with that please
DJ is probably in tech forum or asleep or out shopping or in the backyard or...what?
|
|
|
|
![]() |
|
|||||||
| Thread Tools | Search this Thread |
| Display Modes | |
|
|