[Newbie] Webrebates1.exe Help!!

Hello,

as you can tell im new here, if i tell you my background it might help...

i got a week to go to GERMANY and the pc was fine before o left, as i was away, one of my family members was using my pc, as i arrived back i found the pc to be slow but didnt take much notice since i was downloading some movies via BT.

after a couple of days the pc slowed even more down so i check the C DRIVE capacity to see if i had reached my quota but it still had 50% free... i also realised some pop ups appearing even though the pop-up stopper was running...

i eventually did a AD-AWARE scan and a SPYBOT scan which picked up quite a few bugs which i got rid off....but the problem still remained a BLUE POP-up bar keeps appearing at the bottom of the screen also which has links such as MAKE MONEY, MUSIC, CASINO and makes it appear itself as a XP product maybe because of the design...

i finally did a CTRL+ALT_DEL and found sumik called WEB REBATES.exe ive read a few threads and im scared as i used my financial details to purchase a few items and hoping it was not tracked....

i have a program HIJACKTHIS. can you please advise me on what i should do next??

thank you very much!!
4.JPG 14.4K
5.JPG 58.6K

Comments

  • edited September 2004
    here is my HiJackThis log..im sorry if i was ment to ask first but a thread advise me to post it up and wait..

    Logfile of HijackThis v1.97.7
    Scan saved at 13:40:08, on 23/09/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\CTSvcCDA.EXE
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\INTEL\DSLSetup\ProDsl.exe
    C:\WINDOWS\System32\msawindows.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Winad Client\Winad.exe
    C:\WINDOWS\System32\dqxlgvs.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Winad Client\WinClt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Web_Rebates\WebRebates1.exe
    C:\Program Files\Web_Rebates\WebRebates0.exe
    C:\Program Files\HJT\HijackThis.exe

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.jqeekjugfmnninrbxrpnoicl.net/PLcer/Q/8tHo/tS9PVrtZz2dIfgA4BNyRSyB8RuwkqM1orggzjA4S1ZNKyp9iJBZ.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BT Openworld Business 500 P&G
    R3 - URLSearchHook: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
    O2 - BHO: (no name) - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\localNRD.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
    O2 - BHO: (no name) - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
    O2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [DSL Connection Manager] C:\Program Files\INTEL\DSLSetup\ProDsl.exe
    O4 - HKLM\..\Run: [Microsoft Wininit (System33r)] system33r.exe
    O4 - HKLM\..\Run: [Microsoft Update] msawindows.exe
    O4 - HKLM\..\Run: [Shellapi32] mcvsrte.exe
    O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB002" /M "Stylus Photo R300"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [Managerpiledatewait] C:\Documents and Settings\All Users\Application Data\BrowseSixthManagerPile\clock audio.exe
    O4 - HKLM\..\Run: [InfoPenMSN] C:\Program Files\InfoKing\InfoPenMSN\Pro\InfoPenIM.exe
    O4 - HKLM\..\Run: [Winad Client] C:\Program Files\Winad Client\Winad.exe
    O4 - HKLM\..\Run: [mmmzxeojgipqv] C:\WINDOWS\System32\dqxlgvs.exe
    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
    O4 - HKLM\..\RunServices: [Microsoft Update] msawindows.exe
    O4 - HKLM\..\RunServices: [Shellapi32] mcvsrte.exe
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
    O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O9 - Extra button: Homepage (HKCU)
    O9 - Extra button: Help (HKCU)
    O9 - Extra button: BT (HKCU)
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=0b0da3f84b3b3c05ed7fa392e3efe1fab333c9ea44adda07004f3ee6d4c9d4ad75385cfe976fa93d83e232e0b165175db52f3fd8:a2c609657aedc26a0559c58055eaf1e3
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - http://toolbar.isearch.com/general/drm.cab
    O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78D} (DoomCln Object) - http://www.microsoft.com/security/controls/DoomCln.CAB
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{E922F035-C63D-4B62-9DFF-DA44D5127E5A}: NameServer = 213.1.119.103 213.1.119.104
  • edited September 2004
    after some re-searching i have finally been able to remove the blue toolbar with the help of omegakiller....

    but i am not able to solve my webrebates.exe problem

    :(
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited September 2004
    Hello, welcome to short-media.

    This is a multi-step process, so don't get discouraged. I will be able to help you remove this from your system.

    First things first. Please close all internet explorer windows. Make sure HJT is the only program running.
    Now, hit CTRL-ALT-DELETE to get to the task manager. Go to the PROCESSES tab.

    END ALL IEXPLORE.EXE processess. There should be at least two. Make sure all of them are stopped.

    Now, end all web rebates processes.

    Also, end these processes:

    C:\WINDOWS\System32\dqxlgvs.exe
    C:\WINDOWS\System32\msawindows.exe
    C:\Program Files\Winad Client\WinClt.exe

    Now, go to C:\PROGRAM FILES\ and DELETE the Web_Rebates and WinAd Client folders.

    Then, go to C:\WINDOWS\SYSTEM32\ and DELETE dqxlgvs.exe

    Now, go to C:\Documents and Settings\All Users\Application Data\ and delete the folder called BrowseSixthManagerPile

    After you do these things, go into HJT and fix the following items:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.jqeekjugfmnninrbxrpnoicl...Kyp9iJB Z.html

    R3 - URLSearchHook: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
    O2 - BHO: (no name) - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\localNRD.dll

    O2 - BHO: (no name) - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
    O2 - BHO: (no name) - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
    O2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll

    O4 - HKLM\..\Run: [Microsoft Wininit (System33r)] system33r.exe
    O4 - HKLM\..\Run: [Microsoft Update] msawindows.exe
    O4 - HKLM\..\Run: [Shellapi32] mcvsrte.exe

    O4 - HKLM\..\Run: [Managerpiledatewait] C:\Documents and Settings\All Users\Application Data\BrowseSixthManagerPile\clock audio.exe
    O4 - HKLM\..\Run: [InfoPenMSN] C:\Program Files\InfoKing\InfoPenMSN\Pro\InfoPenIM.exe
    O4 - HKLM\..\Run: [Winad Client] C:\Program Files\Winad Client\Winad.exe
    O4 - HKLM\..\Run: [mmmzxeojgipqv] C:\WINDOWS\System32\dqxlgvs.exe
    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
    O4 - HKLM\..\RunServices: [Microsoft Update] msawindows.exe
    O4 - HKLM\..\RunServices: [Shellapi32] mcvsrte.exe

    O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\toolbar.dll/SEARCH.HTML

    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_f...559c58055eaf1e3

    O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - http://toolbar.isearch.com/general/drm.cab

    Then, close HJT and PULL THE PLUG on your computer - DO NOT CLICK START-->SHUT DOWN.

    When you plug it back in, download the latest version of HJT (1.98.2), which is available on our security downloads page (link in my sig). Post a new log with that version.
  • edited September 2004
    i have followed your instructions and here is the new log....

    Logfile of HijackThis v1.98.2
    Scan saved at 15:29:01, on 23/09/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\CTSvcCDA.EXE
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\INTEL\DSLSetup\ProDsl.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Winad Client\Winad.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
    C:\Program Files\Winad Client\WinClt.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BT Openworld Business 500 P&G
    O1 - Hosts: 127.0.0.41 active-max.com
    O1 - Hosts: 127.0.0.238 www.active-max.com
    O1 - Hosts: 127.0.0.84 allaboutsearching.com
    O1 - Hosts: 127.0.0.230 amazingautossearch.com
    O1 - Hosts: 127.0.0.48 www.amazingautossearch.com
    O1 - Hosts: 127.0.0.38 www.contexualsearch.com
    O1 - Hosts: 127.0.0.80 crap2.com
    O1 - Hosts: 127.0.0.205 www.dialup2.com
    O1 - Hosts: 127.0.0.63 www.ecpm.com
    O1 - Hosts: 127.0.0.55 find-quick.com
    O1 - Hosts: 127.0.0.237 www.find-quick.com
    O1 - Hosts: 127.0.0.201 lop.com
    O1 - Hosts: 127.0.0.4 ao.lop.com
    O1 - Hosts: 127.0.0.92 srch.lop.com
    O1 - Hosts: 127.0.0.38 www.lop2.com
    O1 - Hosts: 127.0.0.83 search200.com
    O1 - Hosts: 127.0.0.39 www.mysearchnow.com
    O1 - Hosts: 127.0.0.91 www.netsearchsoft.com
    O1 - Hosts: 127.0.0.242 www.rub.to
    O1 - Hosts: 127.0.0.80 searchexe.com
    O1 - Hosts: 127.0.0.92 www.searchweb2.com
    O1 - Hosts: 127.0.0.91 www.spawnet.com
    O1 - Hosts: 127.0.0.59 tdmy.com
    O1 - Hosts: 127.0.0.212 www.tfil.com
    O1 - Hosts: 127.0.0.245 www.tdko.com
    O1 - Hosts: 127.0.0.225 wrn.net
    O1 - Hosts: 127.0.0.87 www.wrn.net
    O1 - Hosts: 127.0.0.89 www.mp3search.com
    O1 - Hosts: 127.0.0.97 www.lyricsdomain.com
    O1 - Hosts: 127.0.0.241 omega-search.com
    O1 - Hosts: 127.0.0.92 www.omega-search.com
    O1 - Hosts: 127.0.0.72 trinityacquisitions.com
    O1 - Hosts: 127.0.0.36 www.trinityacquisitions.com
    O1 - Hosts: 127.0.0.253 wethere.com
    O1 - Hosts: 127.0.0.88 asearchforyou.org
    O1 - Hosts: 127.0.0.37 www.asearchforyou.org
    O1 - Hosts: 127.0.0.24 intelesearch.com
    O1 - Hosts: 127.0.0.205 www.intelesearch.com
    O1 - Hosts: 127.0.0.83 www.isearchhere.com
    O1 - Hosts: 127.0.0.80 www.iwantosearch.com
    O1 - Hosts: 127.0.0.236 opensearch.org
    O1 - Hosts: 127.0.0.7 searchbee.net
    O1 - Hosts: 127.0.0.227 searchhotsex.com
    O1 - Hosts: 127.0.0.50 www.searchhotsex.com
    O1 - Hosts: 127.0.0.221 ifsearch.com
    O1 - Hosts: 127.0.0.35 www.ifsearch.com
    O1 - Hosts: 127.0.0.203 mastersearcher.com
    O1 - Hosts: 127.0.0.40 look-today.com
    O1 - Hosts: 127.0.0.250 aavc.com
    O1 - Hosts: 127.0.0.247 www.aavc.com
    O1 - Hosts: 127.0.0.56 acjp.com
    O1 - Hosts: 127.0.0.86 www.acjp.com
    O1 - Hosts: 127.0.0.225 www.ecmh.com
    O1 - Hosts: 127.0.0.34 wabu.com
    O1 - Hosts: 127.0.0.59 wabq.com
    O1 - Hosts: 127.0.0.97 maximumexperience.com
    O1 - Hosts: 127.0.0.27 www.maximumexperience.com
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [DSL Connection Manager] C:\Program Files\INTEL\DSLSetup\ProDsl.exe
    O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB002" /M "Stylus Photo R300"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [Winad Client] C:\Program Files\Winad Client\Winad.exe
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
    O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
    O9 - Extra button: Homepage - {297C8DF7-7EE2-49E7-A0E7-4DC19481FE07} - http://www.btopenworld.com/businesshome (file missing) (HKCU)
    O9 - Extra button: Help - {7D7A7C1A-C4A3-4917-84A5-2F505D0255B5} - http://www.btopenworld.com/helpbb (file missing) (HKCU)
    O9 - Extra button: BT - {7F5C31F9-8C95-40B4-803F-CC54D2FECEAB} - http://www.bt.com (file missing) (HKCU)
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{E922F035-C63D-4B62-9DFF-DA44D5127E5A}: NameServer = 213.1.119.103 213.1.119.104
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited September 2004
    Still have to get rid of that WinAd client.


    O4 - HKLM\..\Run: [Winad Client] C:\Program Files\Winad Client\Winad.exe

    Do the same thing again: End this process:

    C:\Program Files\Winad Client\Winad.exe
    and then go to C:\PROGRAM FILES\ and DELETE WinAd Client.

    If you cannot delete it, try renaming it.

    After you delete or rename it, pull the plug.

    Plug back in, turn it on, and post a new log.
  • edited September 2004
    everytime i end the explorer.exe process my whole desktop goes blank and i cant access anything...so wot i did was end the winad client process and try deleting the folder but was unsucessful...

    even renaming will not work...
  • edited September 2004
    i finally sorted it....i apprently missed one of the proccesses...

    heres my new log...

    Logfile of HijackThis v1.98.2
    Scan saved at 16:05:25, on 23/09/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\CTSvcCDA.EXE
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\INTEL\DSLSetup\ProDsl.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\Winamp\winampa.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\System32\taskmgr.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BT Openworld Business 500 P&G
    O1 - Hosts: 127.0.0.41 active-max.com
    O1 - Hosts: 127.0.0.238 www.active-max.com
    O1 - Hosts: 127.0.0.84 allaboutsearching.com
    O1 - Hosts: 127.0.0.230 amazingautossearch.com
    O1 - Hosts: 127.0.0.48 www.amazingautossearch.com
    O1 - Hosts: 127.0.0.38 www.contexualsearch.com
    O1 - Hosts: 127.0.0.80 crap2.com
    O1 - Hosts: 127.0.0.205 www.dialup2.com
    O1 - Hosts: 127.0.0.63 www.ecpm.com
    O1 - Hosts: 127.0.0.55 find-quick.com
    O1 - Hosts: 127.0.0.237 www.find-quick.com
    O1 - Hosts: 127.0.0.201 lop.com
    O1 - Hosts: 127.0.0.4 ao.lop.com
    O1 - Hosts: 127.0.0.92 srch.lop.com
    O1 - Hosts: 127.0.0.38 www.lop2.com
    O1 - Hosts: 127.0.0.83 search200.com
    O1 - Hosts: 127.0.0.39 www.mysearchnow.com
    O1 - Hosts: 127.0.0.91 www.netsearchsoft.com
    O1 - Hosts: 127.0.0.242 www.rub.to
    O1 - Hosts: 127.0.0.80 searchexe.com
    O1 - Hosts: 127.0.0.92 www.searchweb2.com
    O1 - Hosts: 127.0.0.91 www.spawnet.com
    O1 - Hosts: 127.0.0.59 tdmy.com
    O1 - Hosts: 127.0.0.212 www.tfil.com
    O1 - Hosts: 127.0.0.245 www.tdko.com
    O1 - Hosts: 127.0.0.225 wrn.net
    O1 - Hosts: 127.0.0.87 www.wrn.net
    O1 - Hosts: 127.0.0.89 www.mp3search.com
    O1 - Hosts: 127.0.0.97 www.lyricsdomain.com
    O1 - Hosts: 127.0.0.241 omega-search.com
    O1 - Hosts: 127.0.0.92 www.omega-search.com
    O1 - Hosts: 127.0.0.72 trinityacquisitions.com
    O1 - Hosts: 127.0.0.36 www.trinityacquisitions.com
    O1 - Hosts: 127.0.0.253 wethere.com
    O1 - Hosts: 127.0.0.88 asearchforyou.org
    O1 - Hosts: 127.0.0.37 www.asearchforyou.org
    O1 - Hosts: 127.0.0.24 intelesearch.com
    O1 - Hosts: 127.0.0.205 www.intelesearch.com
    O1 - Hosts: 127.0.0.83 www.isearchhere.com
    O1 - Hosts: 127.0.0.80 www.iwantosearch.com
    O1 - Hosts: 127.0.0.236 opensearch.org
    O1 - Hosts: 127.0.0.7 searchbee.net
    O1 - Hosts: 127.0.0.227 searchhotsex.com
    O1 - Hosts: 127.0.0.50 www.searchhotsex.com
    O1 - Hosts: 127.0.0.221 ifsearch.com
    O1 - Hosts: 127.0.0.35 www.ifsearch.com
    O1 - Hosts: 127.0.0.203 mastersearcher.com
    O1 - Hosts: 127.0.0.40 look-today.com
    O1 - Hosts: 127.0.0.250 aavc.com
    O1 - Hosts: 127.0.0.247 www.aavc.com
    O1 - Hosts: 127.0.0.56 acjp.com
    O1 - Hosts: 127.0.0.86 www.acjp.com
    O1 - Hosts: 127.0.0.225 www.ecmh.com
    O1 - Hosts: 127.0.0.34 wabu.com
    O1 - Hosts: 127.0.0.59 wabq.com
    O1 - Hosts: 127.0.0.97 maximumexperience.com
    O1 - Hosts: 127.0.0.27 www.maximumexperience.com
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [DSL Connection Manager] C:\Program Files\INTEL\DSLSetup\ProDsl.exe
    O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB002" /M "Stylus Photo R300"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
    O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
    O9 - Extra button: Homepage - {297C8DF7-7EE2-49E7-A0E7-4DC19481FE07} - http://www.btopenworld.com/businesshome (file missing) (HKCU)
    O9 - Extra button: Help - {7D7A7C1A-C4A3-4917-84A5-2F505D0255B5} - http://www.btopenworld.com/helpbb (file missing) (HKCU)
    O9 - Extra button: BT - {7F5C31F9-8C95-40B4-803F-CC54D2FECEAB} - http://www.bt.com (file missing) (HKCU)
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{E922F035-C63D-4B62-9DFF-DA44D5127E5A}: NameServer = 213.1.119.102 213.1.119.103
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited September 2004
    okay, don't end EXPLORER.EXE.... End IEXPLORE.EXE - they are differnet.

    Secondly, make sure you delete the folder, not the files within the folder.

    If you can't delete the folder, try renaming it.

    If you can't delete it, then perhaps the process is respawning very quickly after you stop it. try right clicking on the winad process and clicking "END PROCESS TREE"

    Or, "race" it --- end the process and then VERY QUICKLY delete the folder before it has a chance to respawn. It's a race! :D
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited September 2004
    Oh, okay. cool. Final cleanup run now, get rid of the following:

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
    O9 - Extra button: Homepage - {297C8DF7-7EE2-49E7-A0E7-4DC19481FE07} - http://www.btopenworld.com/businesshome (file missing) (HKCU)
    O9 - Extra button: Help - {7D7A7C1A-C4A3-4917-84A5-2F505D0255B5} - http://www.btopenworld.com/helpbb (file missing) (HKCU)
    O9 - Extra button: BT - {7F5C31F9-8C95-40B4-803F-CC54D2FECEAB} - http://www.bt.com (file missing) (HKCU)

    Then, my friend, you are done.

    Check out the article in my sig about "how you got infected".... I would highly recommend switching to FireFox - it is a better browser.

    Also, be sure to check out our folding team. We would love to have you join. Link is in my sig.
  • edited September 2004
    lol...okay ive done it please have a look at my new log

    Logfile of HijackThis v1.98.2
    Scan saved at 16:08:28, on 23/09/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\CTSvcCDA.EXE
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\INTEL\DSLSetup\ProDsl.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\Winamp\winampa.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
    C:\Program Files\HJT\HijackThis.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\System32\wuauclt.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BT Openworld Business 500 P&G
    O1 - Hosts: 127.0.0.41 active-max.com
    O1 - Hosts: 127.0.0.238 www.active-max.com
    O1 - Hosts: 127.0.0.84 allaboutsearching.com
    O1 - Hosts: 127.0.0.230 amazingautossearch.com
    O1 - Hosts: 127.0.0.48 www.amazingautossearch.com
    O1 - Hosts: 127.0.0.38 www.contexualsearch.com
    O1 - Hosts: 127.0.0.80 crap2.com
    O1 - Hosts: 127.0.0.205 www.dialup2.com
    O1 - Hosts: 127.0.0.63 www.ecpm.com
    O1 - Hosts: 127.0.0.55 find-quick.com
    O1 - Hosts: 127.0.0.237 www.find-quick.com
    O1 - Hosts: 127.0.0.201 lop.com
    O1 - Hosts: 127.0.0.4 ao.lop.com
    O1 - Hosts: 127.0.0.92 srch.lop.com
    O1 - Hosts: 127.0.0.38 www.lop2.com
    O1 - Hosts: 127.0.0.83 search200.com
    O1 - Hosts: 127.0.0.39 www.mysearchnow.com
    O1 - Hosts: 127.0.0.91 www.netsearchsoft.com
    O1 - Hosts: 127.0.0.242 www.rub.to
    O1 - Hosts: 127.0.0.80 searchexe.com
    O1 - Hosts: 127.0.0.92 www.searchweb2.com
    O1 - Hosts: 127.0.0.91 www.spawnet.com
    O1 - Hosts: 127.0.0.59 tdmy.com
    O1 - Hosts: 127.0.0.212 www.tfil.com
    O1 - Hosts: 127.0.0.245 www.tdko.com
    O1 - Hosts: 127.0.0.225 wrn.net
    O1 - Hosts: 127.0.0.87 www.wrn.net
    O1 - Hosts: 127.0.0.89 www.mp3search.com
    O1 - Hosts: 127.0.0.97 www.lyricsdomain.com
    O1 - Hosts: 127.0.0.241 omega-search.com
    O1 - Hosts: 127.0.0.92 www.omega-search.com
    O1 - Hosts: 127.0.0.72 trinityacquisitions.com
    O1 - Hosts: 127.0.0.36 www.trinityacquisitions.com
    O1 - Hosts: 127.0.0.253 wethere.com
    O1 - Hosts: 127.0.0.88 asearchforyou.org
    O1 - Hosts: 127.0.0.37 www.asearchforyou.org
    O1 - Hosts: 127.0.0.24 intelesearch.com
    O1 - Hosts: 127.0.0.205 www.intelesearch.com
    O1 - Hosts: 127.0.0.83 www.isearchhere.com
    O1 - Hosts: 127.0.0.80 www.iwantosearch.com
    O1 - Hosts: 127.0.0.236 opensearch.org
    O1 - Hosts: 127.0.0.7 searchbee.net
    O1 - Hosts: 127.0.0.227 searchhotsex.com
    O1 - Hosts: 127.0.0.50 www.searchhotsex.com
    O1 - Hosts: 127.0.0.221 ifsearch.com
    O1 - Hosts: 127.0.0.35 www.ifsearch.com
    O1 - Hosts: 127.0.0.203 mastersearcher.com
    O1 - Hosts: 127.0.0.40 look-today.com
    O1 - Hosts: 127.0.0.250 aavc.com
    O1 - Hosts: 127.0.0.247 www.aavc.com
    O1 - Hosts: 127.0.0.56 acjp.com
    O1 - Hosts: 127.0.0.86 www.acjp.com
    O1 - Hosts: 127.0.0.225 www.ecmh.com
    O1 - Hosts: 127.0.0.34 wabu.com
    O1 - Hosts: 127.0.0.59 wabq.com
    O1 - Hosts: 127.0.0.97 maximumexperience.com
    O1 - Hosts: 127.0.0.27 www.maximumexperience.com
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [DSL Connection Manager] C:\Program Files\INTEL\DSLSetup\ProDsl.exe
    O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB002" /M "Stylus Photo R300"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
    O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
    O9 - Extra button: Homepage - {297C8DF7-7EE2-49E7-A0E7-4DC19481FE07} - http://www.btopenworld.com/businesshome (file missing) (HKCU)
    O9 - Extra button: Help - {7D7A7C1A-C4A3-4917-84A5-2F505D0255B5} - http://www.btopenworld.com/helpbb (file missing) (HKCU)
    O9 - Extra button: BT - {7F5C31F9-8C95-40B4-803F-CC54D2FECEAB} - http://www.bt.com (file missing) (HKCU)
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
  • edited September 2004
    ive reviewed ur posts and seems like i missed a few steps...

    here is my new revised log...

    Logfile of HijackThis v1.98.2
    Scan saved at 17:18:15, on 23/09/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\CTSvcCDA.EXE
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\INTEL\DSLSetup\ProDsl.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\Winamp\winampa.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BT Openworld Business 500 P&G
    O1 - Hosts: 127.0.0.41 active-max.com
    O1 - Hosts: 127.0.0.238 www.active-max.com
    O1 - Hosts: 127.0.0.84 allaboutsearching.com
    O1 - Hosts: 127.0.0.230 amazingautossearch.com
    O1 - Hosts: 127.0.0.48 www.amazingautossearch.com
    O1 - Hosts: 127.0.0.38 www.contexualsearch.com
    O1 - Hosts: 127.0.0.80 crap2.com
    O1 - Hosts: 127.0.0.205 www.dialup2.com
    O1 - Hosts: 127.0.0.63 www.ecpm.com
    O1 - Hosts: 127.0.0.55 find-quick.com
    O1 - Hosts: 127.0.0.237 www.find-quick.com
    O1 - Hosts: 127.0.0.201 lop.com
    O1 - Hosts: 127.0.0.4 ao.lop.com
    O1 - Hosts: 127.0.0.92 srch.lop.com
    O1 - Hosts: 127.0.0.38 www.lop2.com
    O1 - Hosts: 127.0.0.83 search200.com
    O1 - Hosts: 127.0.0.39 www.mysearchnow.com
    O1 - Hosts: 127.0.0.91 www.netsearchsoft.com
    O1 - Hosts: 127.0.0.242 www.rub.to
    O1 - Hosts: 127.0.0.80 searchexe.com
    O1 - Hosts: 127.0.0.92 www.searchweb2.com
    O1 - Hosts: 127.0.0.91 www.spawnet.com
    O1 - Hosts: 127.0.0.59 tdmy.com
    O1 - Hosts: 127.0.0.212 www.tfil.com
    O1 - Hosts: 127.0.0.245 www.tdko.com
    O1 - Hosts: 127.0.0.225 wrn.net
    O1 - Hosts: 127.0.0.87 www.wrn.net
    O1 - Hosts: 127.0.0.89 www.mp3search.com
    O1 - Hosts: 127.0.0.97 www.lyricsdomain.com
    O1 - Hosts: 127.0.0.241 omega-search.com
    O1 - Hosts: 127.0.0.92 www.omega-search.com
    O1 - Hosts: 127.0.0.72 trinityacquisitions.com
    O1 - Hosts: 127.0.0.36 www.trinityacquisitions.com
    O1 - Hosts: 127.0.0.253 wethere.com
    O1 - Hosts: 127.0.0.88 asearchforyou.org
    O1 - Hosts: 127.0.0.37 www.asearchforyou.org
    O1 - Hosts: 127.0.0.24 intelesearch.com
    O1 - Hosts: 127.0.0.205 www.intelesearch.com
    O1 - Hosts: 127.0.0.83 www.isearchhere.com
    O1 - Hosts: 127.0.0.80 www.iwantosearch.com
    O1 - Hosts: 127.0.0.236 opensearch.org
    O1 - Hosts: 127.0.0.7 searchbee.net
    O1 - Hosts: 127.0.0.227 searchhotsex.com
    O1 - Hosts: 127.0.0.50 www.searchhotsex.com
    O1 - Hosts: 127.0.0.221 ifsearch.com
    O1 - Hosts: 127.0.0.35 www.ifsearch.com
    O1 - Hosts: 127.0.0.203 mastersearcher.com
    O1 - Hosts: 127.0.0.40 look-today.com
    O1 - Hosts: 127.0.0.250 aavc.com
    O1 - Hosts: 127.0.0.247 www.aavc.com
    O1 - Hosts: 127.0.0.56 acjp.com
    O1 - Hosts: 127.0.0.86 www.acjp.com
    O1 - Hosts: 127.0.0.225 www.ecmh.com
    O1 - Hosts: 127.0.0.34 wabu.com
    O1 - Hosts: 127.0.0.59 wabq.com
    O1 - Hosts: 127.0.0.97 maximumexperience.com
    O1 - Hosts: 127.0.0.27 www.maximumexperience.com
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [DSL Connection Manager] C:\Program Files\INTEL\DSLSetup\ProDsl.exe
    O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB002" /M "Stylus Photo R300"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
    O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{E922F035-C63D-4B62-9DFF-DA44D5127E5A}: NameServer = 213.1.119.102 213.1.119.103
  • edited September 2004
    after doing all the scans and fixes my notepad doesnt work now :(

    everythin else is sorted....
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited September 2004
    A lot of spyware breaks notepad, in an attempt to prevent removal.

    See Dexter's post about this.
  • edited September 2004
    thank you for all your help!!!
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited September 2004
    No problem :)
This discussion has been closed.