OMEGASEARCH - dude2

Help me!

Logfile of HijackThis v1.97.7
Scan saved at 5:57:51 PM, on 5/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Win XP\Desktop\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.the-exit.com/search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://omegasearch.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://omegasearch.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://omegasearch.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://omegasearch.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://omegasearch.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://omegasearch.com/searchbar.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = t
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.attbb.net;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts file is located at: C:\WINDOWS\help\hosts
O1 - Hosts: 127.127.127.127 elite
O1 - Hosts: 64.191.59.85 www.google.com
O1 - Hosts: 64.191.59.85 google.com
O1 - Hosts: 64.191.59.85 www.altavista.com
O1 - Hosts: 64.191.59.85 altavista.com
O1 - Hosts: 64.191.59.85 search.yahoo.com
O1 - Hosts: 64.191.59.85 uk.search.yahoo.com
O1 - Hosts: 64.191.59.85 ca.search.yahoo.com
O1 - Hosts: 64.191.59.85 jp.search.yahoo.com
O1 - Hosts: 64.191.59.85 au.search.yahoo.com
O1 - Hosts: 64.191.59.85 de.search.yahoo.com
O1 - Hosts: 64.191.59.85 search.yahoo.co.jp
O1 - Hosts: 64.191.59.85 www.lycos.de
O1 - Hosts: 64.191.59.85 www.lycos.ca
O1 - Hosts: 64.191.59.85 www.lycos.jp
O1 - Hosts: 64.191.59.85 www.lycos.co.jp
O1 - Hosts: 64.191.59.85 alltheweb.com
O1 - Hosts: 64.191.59.85 web.ask.com
O1 - Hosts: 64.191.59.85 ask.com
O1 - Hosts: 64.191.59.85 www.ask.com
O1 - Hosts: 64.191.59.85 www.teoma.com
O1 - Hosts: 64.191.59.85 search.aol.com
O1 - Hosts: 64.191.59.85 www.looksmart.com
O1 - Hosts: 64.191.59.85 ca.search.msn.com
O1 - Hosts: 64.191.59.85 fr.ca.search.msn.com
O1 - Hosts: 64.191.59.85 search.fr.msn.be
O1 - Hosts: 64.191.59.85 search.fr.msn.ch
O1 - Hosts: 64.191.59.85 search.latam.yupimsn.com
O1 - Hosts: 64.191.59.85 search.msn.at
O1 - Hosts: 64.191.59.85 search.msn.be
O1 - Hosts: 64.191.59.85 search.msn.ch
O1 - Hosts: 64.191.59.85 search.msn.co.in
O1 - Hosts: 64.191.59.85 search.msn.co.jp
O1 - Hosts: 64.191.59.85 search.msn.co.kr
O1 - Hosts: 64.191.59.85 search.msn.com.br
O1 - Hosts: 64.191.59.85 search.msn.com.hk
O1 - Hosts: 64.191.59.85 search.msn.com.my
O1 - Hosts: 64.191.59.85 search.msn.com.sg
O1 - Hosts: 64.191.59.85 search.msn.com.tw
O1 - Hosts: 64.191.59.85 search.msn.co.za
O1 - Hosts: 64.191.59.85 search.msn.de
O1 - Hosts: 64.191.59.85 search.msn.dk
O1 - Hosts: 64.191.59.85 search.msn.es
O1 - Hosts: 64.191.59.85 search.msn.fi
O1 - Hosts: 64.191.59.85 search.msn.fr
O1 - Hosts: 64.191.59.85 search.msn.it
O1 - Hosts: 64.191.59.85 search.msn.nl
O1 - Hosts: 64.191.59.85 search.msn.no
O1 - Hosts: 64.191.59.85 search.msn.se
O1 - Hosts: 64.191.59.85 search.ninemsn.com.au
O1 - Hosts: 64.191.59.85 search.t1msn.com.mx
O1 - Hosts: 64.191.59.85 search.xtramsn.co.nz
O1 - Hosts: 64.191.59.85 search.yupimsn.com
O1 - Hosts: 64.191.59.85 uk.search.msn.com
O1 - Hosts: 64.191.59.85 search.lycos.com
O1 - Hosts: 64.191.59.85 www.lycos.com
O1 - Hosts: 64.191.59.85 www.google.ca
O1 - Hosts: 64.191.59.85 google.ca
O1 - Hosts: 64.191.59.85 www.google.uk
O1 - Hosts: 64.191.59.85 www.google.co.uk
O1 - Hosts: 64.191.59.85 www.google.com.au
O1 - Hosts: 64.191.59.85 www.google.co.jp
O1 - Hosts: 64.191.59.85 www.google.jp
O1 - Hosts: 64.191.59.85 www.google.at
O1 - Hosts: 64.191.59.85 www.google.be
O1 - Hosts: 64.191.59.85 www.google.ch
O1 - Hosts: 64.191.59.85 www.google.de
O1 - Hosts: 64.191.59.85 www.google.dk
O1 - Hosts: 64.191.59.85 www.google.fi
O1 - Hosts: 64.191.59.85 www.google.fr
O1 - Hosts: 64.191.59.85 www.google.com.gr
O1 - Hosts: 64.191.59.85 www.google.com.hk
O1 - Hosts: 64.191.59.85 www.google.ie
O1 - Hosts: 64.191.59.85 www.google.co.il
O1 - Hosts: 64.191.59.85 www.google.it
O1 - Hosts: 64.191.59.85 www.google.co.kr
O1 - Hosts: 64.191.59.85 www.google.com.mx
O1 - Hosts: 64.191.59.85 www.google.nl
O1 - Hosts: 64.191.59.85 www.google.co.nz
O1 - Hosts: 64.191.59.85 www.google.pl
O1 - Hosts: 64.191.59.85 www.google.pt
O1 - Hosts: 64.191.59.85 www.google.com.ru
O1 - Hosts: 64.191.59.85 www.google.com.sg
O1 - Hosts: 64.191.59.85 www.google.co.th
O1 - Hosts: 64.191.59.85 www.google.com.tr
O1 - Hosts: 64.191.59.85 www.google.com.tw
O1 - Hosts: 64.191.59.85 google.at
O1 - Hosts: 64.191.59.85 google.be
O1 - Hosts: 64.191.59.85 google.de
O1 - Hosts: 64.191.59.85 google.dk
O1 - Hosts: 64.191.59.85 google.fi
O1 - Hosts: 64.191.59.85 google.fr
O1 - Hosts: 64.191.59.85 google.com.hk
O1 - Hosts: 64.191.59.85 google.ie
O1 - Hosts: 64.191.59.85 google.co.il
O1 - Hosts: 64.191.59.85 google.it
O1 - Hosts: 64.191.59.85 google.co.kr
O1 - Hosts: 64.191.59.85 google.com.mx
O1 - Hosts: 64.191.59.85 google.nl
O1 - Hosts: 64.191.59.85 google.co.nz
O1 - Hosts: 64.191.59.85 google.pl
O2 - BHO: Clear Search - {00000000-0000-0000-0000-000000000240} - C:\Program Files\ClearSearch\IE_ClrSch.DLL
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {46AE04C0-BCFA-4728-90E7-00EB4A8B3863} - (no file)
O3 - Toolbar: (no name) - {4CC0FAF8-6048-421C-9FE2-261A9ECE5F80} - (no file)
O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O3 - Toolbar: (no name) - {CC90CDA0-74A0-45b4-80EF-D89CA8C249B8} - (no file)
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Launcher] "C:\Program Files\KFH\cl\launcher.exe" /P
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] c:\program files\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\Updater\wupdater.exe
O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe
O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe
O4 - HKLM\..\Run: [MMTray] MMTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DM_Server] C:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe /onreboot
O4 - HKLM\..\Run: [Open Site] C:\Program Files\Open Site\opnste.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [Else Tick] C:\PROGRA~1\BALLTY~1\gridregs.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpyBlast] C:\Program Files\SpyBlast\SpyBlast.exe /autorun
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - Startup: iMesh.lnk = C:\Program Files\iMesh\Client\iMeshClient.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: hp instant support.lnk = C:\Program Files\Hewlett-Packard\AiO\HPis\bin\matcli.exe
O4 - Global Startup: HPAiODevice(hp officejet v series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: updater.lnk = C:\Program Files\Common Files\updater\wupdater.exe
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1078703564316
O16 - DPF: {1EB17D1C-141D-4D9D-91CB-24D99215851D} - http://akamai.downloadv3.com/binaries/IA/netia32_EN_XP.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {3B02AAA2-327C-40ED-A849-4BE819AE5385} (ImgSizer Control) - file://C:\Documents and Settings\Win XP\Local Settings\Temp\~DlfnTmp0\imgSizer.ocx
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,64/mcinsctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/31adfcafa22dbec6d100/netzip/RdxIE601.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37641.7534027778
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78D} (DoomCln Object) - http://www.microsoft.com/security/controls/DoomCln.CAB
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,13/mcgdmgr.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = mydomain.com
O17 - HKLM\System\CS1\Services\VxD\MSTCP: Domain = mydomain.com
O17 - HKLM\System\CS1\Services\VxD\MSTCP: NameServer = 69.57.146.14
O17 - HKLM\System\CS2\Services\VxD\MSTCP: Domain = mydomain.com
O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 69.57.146.14
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.57.146.14

Comments

  • shwaipshwaip bluffin' with my muffin Icrontian
    edited May 2004
    welcome to s-m

    holy poop you've got a lot of problems!

    reboot into safe mode, remove the following using <strike>omegasearch</strike> Hijackthis:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.the-exit.com/search
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://omegasearch.com/searchbar.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://omegasearch.com/searchbar.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://omegasearch.com/searchbar.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://omegasearch.com/searchbar.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://omegasearch.com/searchbar.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://omegasearch.com/searchbar.html
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = t
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.attbb.net;
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts file is located at: C:\WINDOWS\help\hosts
    O1 - Hosts: 127.127.127.127 elite
    O1 - Hosts: 64.191.59.85 www.google.com
    O1 - Hosts: 64.191.59.85 google.com
    O1 - Hosts: 64.191.59.85 www.altavista.com
    O1 - Hosts: 64.191.59.85 altavista.com
    O1 - Hosts: 64.191.59.85 search.yahoo.com
    O1 - Hosts: 64.191.59.85 uk.search.yahoo.com
    O1 - Hosts: 64.191.59.85 ca.search.yahoo.com
    O1 - Hosts: 64.191.59.85 jp.search.yahoo.com
    O1 - Hosts: 64.191.59.85 au.search.yahoo.com
    O1 - Hosts: 64.191.59.85 de.search.yahoo.com
    O1 - Hosts: 64.191.59.85 search.yahoo.co.jp
    O1 - Hosts: 64.191.59.85 www.lycos.de
    O1 - Hosts: 64.191.59.85 www.lycos.ca
    O1 - Hosts: 64.191.59.85 www.lycos.jp
    O1 - Hosts: 64.191.59.85 www.lycos.co.jp
    O1 - Hosts: 64.191.59.85 alltheweb.com
    O1 - Hosts: 64.191.59.85 web.ask.com
    O1 - Hosts: 64.191.59.85 ask.com
    O1 - Hosts: 64.191.59.85 www.ask.com
    O1 - Hosts: 64.191.59.85 www.teoma.com
    O1 - Hosts: 64.191.59.85 search.aol.com
    O1 - Hosts: 64.191.59.85 www.looksmart.com
    O1 - Hosts: 64.191.59.85 ca.search.msn.com
    O1 - Hosts: 64.191.59.85 fr.ca.search.msn.com
    O1 - Hosts: 64.191.59.85 search.fr.msn.be
    O1 - Hosts: 64.191.59.85 search.fr.msn.ch
    O1 - Hosts: 64.191.59.85 search.latam.yupimsn.com
    O1 - Hosts: 64.191.59.85 search.msn.at
    O1 - Hosts: 64.191.59.85 search.msn.be
    O1 - Hosts: 64.191.59.85 search.msn.ch
    O1 - Hosts: 64.191.59.85 search.msn.co.in
    O1 - Hosts: 64.191.59.85 search.msn.co.jp
    O1 - Hosts: 64.191.59.85 search.msn.co.kr
    O1 - Hosts: 64.191.59.85 search.msn.com.br
    O1 - Hosts: 64.191.59.85 search.msn.com.hk
    O1 - Hosts: 64.191.59.85 search.msn.com.my
    O1 - Hosts: 64.191.59.85 search.msn.com.sg
    O1 - Hosts: 64.191.59.85 search.msn.com.tw
    O1 - Hosts: 64.191.59.85 search.msn.co.za
    O1 - Hosts: 64.191.59.85 search.msn.de
    O1 - Hosts: 64.191.59.85 search.msn.dk
    O1 - Hosts: 64.191.59.85 search.msn.es
    O1 - Hosts: 64.191.59.85 search.msn.fi
    O1 - Hosts: 64.191.59.85 search.msn.fr
    O1 - Hosts: 64.191.59.85 search.msn.it
    O1 - Hosts: 64.191.59.85 search.msn.nl
    O1 - Hosts: 64.191.59.85 search.msn.no
    O1 - Hosts: 64.191.59.85 search.msn.se
    O1 - Hosts: 64.191.59.85 search.ninemsn.com.au
    O1 - Hosts: 64.191.59.85 search.t1msn.com.mx
    O1 - Hosts: 64.191.59.85 search.xtramsn.co.nz
    O1 - Hosts: 64.191.59.85 search.yupimsn.com
    O1 - Hosts: 64.191.59.85 uk.search.msn.com
    O1 - Hosts: 64.191.59.85 search.lycos.com
    O1 - Hosts: 64.191.59.85 www.lycos.com
    O1 - Hosts: 64.191.59.85 www.google.ca
    O1 - Hosts: 64.191.59.85 google.ca
    O1 - Hosts: 64.191.59.85 www.google.uk
    O1 - Hosts: 64.191.59.85 www.google.co.uk
    O1 - Hosts: 64.191.59.85 www.google.com.au
    O1 - Hosts: 64.191.59.85 www.google.co.jp
    O1 - Hosts: 64.191.59.85 www.google.jp
    O1 - Hosts: 64.191.59.85 www.google.at
    O1 - Hosts: 64.191.59.85 www.google.be
    O1 - Hosts: 64.191.59.85 www.google.ch
    O1 - Hosts: 64.191.59.85 www.google.de
    O1 - Hosts: 64.191.59.85 www.google.dk
    O1 - Hosts: 64.191.59.85 www.google.fi
    O1 - Hosts: 64.191.59.85 www.google.fr
    O1 - Hosts: 64.191.59.85 www.google.com.gr
    O1 - Hosts: 64.191.59.85 www.google.com.hk
    O1 - Hosts: 64.191.59.85 www.google.ie
    O1 - Hosts: 64.191.59.85 www.google.co.il
    O1 - Hosts: 64.191.59.85 www.google.it
    O1 - Hosts: 64.191.59.85 www.google.co.kr
    O1 - Hosts: 64.191.59.85 www.google.com.mx
    O1 - Hosts: 64.191.59.85 www.google.nl
    O1 - Hosts: 64.191.59.85 www.google.co.nz
    O1 - Hosts: 64.191.59.85 www.google.pl
    O1 - Hosts: 64.191.59.85 www.google.pt
    O1 - Hosts: 64.191.59.85 www.google.com.ru
    O1 - Hosts: 64.191.59.85 www.google.com.sg
    O1 - Hosts: 64.191.59.85 www.google.co.th
    O1 - Hosts: 64.191.59.85 www.google.com.tr
    O1 - Hosts: 64.191.59.85 www.google.com.tw
    O1 - Hosts: 64.191.59.85 google.at
    O1 - Hosts: 64.191.59.85 google.be
    O1 - Hosts: 64.191.59.85 google.de
    O1 - Hosts: 64.191.59.85 google.dk
    O1 - Hosts: 64.191.59.85 google.fi
    O1 - Hosts: 64.191.59.85 google.fr
    O1 - Hosts: 64.191.59.85 google.com.hk
    O1 - Hosts: 64.191.59.85 google.ie
    O1 - Hosts: 64.191.59.85 google.co.il
    O1 - Hosts: 64.191.59.85 google.it
    O1 - Hosts: 64.191.59.85 google.co.kr
    O1 - Hosts: 64.191.59.85 google.com.mx
    O1 - Hosts: 64.191.59.85 google.nl
    O1 - Hosts: 64.191.59.85 google.co.nz
    O1 - Hosts: 64.191.59.85 google.pl
    O2 - BHO: Clear Search - {00000000-0000-0000-0000-000000000240} - C:\Program Files\ClearSearch\IE_ClrSch.DLL
    O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
    O3 - Toolbar: (no name) - {46AE04C0-BCFA-4728-90E7-00EB4A8B3863} - (no file)
    O3 - Toolbar: (no name) - {4CC0FAF8-6048-421C-9FE2-261A9ECE5F80} - (no file)
    O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
    O3 - Toolbar: (no name) - {CC90CDA0-74A0-45b4-80EF-D89CA8C249B8} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\Updater\wupdater.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [DM_Server] C:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe /onreboot
    O4 - HKLM\..\Run: [Open Site] C:\Program Files\Open Site\opnste.exe
    O4 - HKLM\..\Run: [Else Tick] C:\PROGRA~1\BALLTY~1\gridregs.exe
    O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
    O16 - DPF: {1EB17D1C-141D-4D9D-91CB-24D99215851D} - http://akamai.downloadv3.com/binari...tia32_EN_XP.cab
    O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
    O16 - DPF: {3B02AAA2-327C-40ED-A849-4BE819AE5385} (ImgSizer Control) - file://C:\Documents and Settings\Win XP\Local Settings\Temp\~DlfnTmp0\imgSizer.ocx
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/31adfcafa22dbe...ip/RdxIE601.cab
    O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
    These are all "downloaded program files". A couple may not be problems, but if they're needed, they'll just get re-downloaded from the site if you visit it again, so remove them

    then manually delete the folder:
    c:\PROGRAM FILES\BALLTY~1\ (it's a folder that starts with ballty)

    finally, reboot into "normal" mode, download and install adaware and spybot S&D from the link in my sig, update and run them, and repost a new (hopefully clean) log.
  • shwaipshwaip bluffin' with my muffin Icrontian
    edited May 2004
    I don't know what to do about these, perhaps someone could pop in and help out:

    O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = mydomain.com
    O17 - HKLM\System\CS1\Services\VxD\MSTCP: Domain = mydomain.com
    O17 - HKLM\System\CS1\Services\VxD\MSTCP: NameServer = 69.57.146.14
    O17 - HKLM\System\CS2\Services\VxD\MSTCP: Domain = mydomain.com
    O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 69.57.146.14
    O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.57.146.14


    edit:

    after some research, I found that if these aren't from your ISP or other known source, remove them.
  • GuyuteGuyute Gamehenge
    edited May 2004
    if in doubt, try inputting the IP into Google---it will start to open the site if it is exact, I think, then you get a quick glimpse of the title of the site before closing the window. This may be risky, but I know of no other way...
  • shwaipshwaip bluffin' with my muffin Icrontian
    edited May 2004
    I actually already tried that :D

    /me shakes fist at Leo

    (yea, I've actually done that before, but I usually catch it before I submit)
  • LeonardoLeonardo Wake up and smell the glaciers Eagle River, Alaska Icrontian
    edited May 2004
    ;D;D Priceless!
  • shwaipshwaip bluffin' with my muffin Icrontian
    edited May 2004
    I r h8 u.
  • edited May 2004
    thank you for taking the time to read my log omegasearch is gone so thank shwaip
This discussion has been closed.