Cant proceed to the next step after deleting
I am a newbie and ive been reading threads all day. I think i have spyware problem,I am seeing msnbb, msnappau. My computer is way slower and some links I cannot proceed. I did Ad-aware about 10 times today and came with about 190 things I need to delete.
Problem is I can not proceed to the FINISHI step after it deltes these files. It freezes. So I think its incomplete. Please, I need help and I dont know what to delete at all, I broke my prevous computer like this. Should I download Hijackthis and post a log or is the one from Ad-aware OK? Thank you for your help.
Problem is I can not proceed to the FINISHI step after it deltes these files. It freezes. So I think its incomplete. Please, I need help and I dont know what to delete at all, I broke my prevous computer like this. Should I download Hijackthis and post a log or is the one from Ad-aware OK? Thank you for your help.
0
This discussion has been closed.
Comments
cant help you if no info here..
Thanks
ArchiveData(auto-quarantine- 2004-11-03 19-09-05.bckp)
Referencefile : SE1R16 28.10.2004
======================================================
WINDUPDATES
ササササササササササササササササササササササササササササササササササササササ
obj[0]=Process : C:\PROGRAM FILES\WINDOWS ADTOOLS\WINADTOOLS.EXE
obj[32]=Regkey : software\microsoft\code store database\distribution units\{15ad4789-cdb4-47e1-a9da-992ee8e6bad6}
obj[33]=RegValue : software\microsoft\code store database\distribution units\{15ad4789-cdb4-47e1-a9da-992ee8e6bad6} "SystemComponent"
obj[34]=RegValue : software\microsoft\code store database\distribution units\{15ad4789-cdb4-47e1-a9da-992ee8e6bad6} "Installer"
BOOKEDSPACE
ササササササササササササササササササササササササササササササササササササササ
obj[1]=Process : C:\WINDOWS\SYSTEM\JLYXREYP.EXE
obj[68]=Regkey : software\vendor\xml
obj[69]=RegValue : software\vendor\xml ""
obj[70]=Regkey : software\vendor
180SOLUTIONS
ササササササササササササササササササササササササササササササササササササササ
obj[2]=Regkey : software\180solutions\msbb
obj[3]=RegValue : software\180solutions\msbb "did"
obj[4]=RegValue : software\180solutions\msbb "duid"
obj[5]=RegValue : software\180solutions\msbb "partner_id"
obj[6]=RegValue : software\180solutions\msbb "product_id"
obj[7]=RegValue : software\180solutions\msbb "smt"
obj[8]=RegValue : software\180solutions\msbb "boom"
obj[9]=Regkey : .DEFAULT\software\180solutions
obj[10]=Regkey : software\180solutions
obj[45]=RegValue : software\msbb "partner_id"
obj[71]=Regkey : software\microsoft\internet explorer\explorer bars\{30d02401-6a81-11d0-8274-00c04fd5ae38}
obj[72]=RegValue : software\microsoft\internet explorer\explorer bars\{30d02401-6a81-11d0-8274-00c04fd5ae38} "BarSize"
obj[73]=Regkey : software\180solutions
obj[74]=Regkey : software\msbb
obj[75]=RegValue : software\msbb "last_conn_h"
obj[76]=RegValue : software\msbb "last_conn_l"
obj[77]=RegValue : software\msbb "we"
obj[78]=RegValue : software\msbb "cdata"
obj[79]=RegValue : software\msbb "TimeOffset"
obj[80]=RegValue : software\msbb "action_url_version"
obj[81]=RegValue : software\msbb "key_file"
obj[82]=RegValue : software\msbb "action_url_last_chunk"
obj[83]=RegValue : software\msbb "action_url_last_full_version"
obj[84]=RegValue : software\msbb "kw_last_chunk"
obj[85]=RegValue : software\msbb "keyword_file_last_full_version"
obj[86]=RegValue : software\msbb "recent_shown"
obj[87]=RegValue : software\msbb "key_int_high"
obj[88]=RegValue : software\msbb "key_int_low"
obj[89]=Regkey : software\msbb
obj[90]=RegValue : software\msbb "did"
obj[91]=RegValue : software\msbb "duid"
obj[92]=RegValue : software\msbb "product_id"
obj[93]=RegValue : software\msbb "mt1"
obj[94]=RegValue : software\msbb "mt2"
obj[95]=RegValue : software\msbb "mt3"
obj[96]=RegValue : software\msbb "gma"
obj[97]=RegValue : software\msbb "gvi"
obj[98]=RegValue : software\msbb "gpi"
obj[99]=RegValue : software\msbb "boom"
obj[100]=RegValue : software\msbb "boom_ver"
obj[175]=File : C:\WINDOWS\TEMP\Del5080.TMP
obj[183]=File : C:\temp\msbb.exe
obj[185]=File : C:\temp\msbbhook.dll
ALEXA
ササササササササササササササササササササササササササササササササササササササ
obj[11]=Regkey : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
obj[12]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "MenuText"
obj[13]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "MenuStatusBar"
obj[14]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "Script"
obj[15]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "clsid"
obj[16]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "Icon"
obj[17]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "HotIcon"
obj[18]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "ButtonText"
obj[46]=RegValue : .DEFAULT\software\microsoft\internet explorer\extensions\cmdmapping "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
BLAZEFIND
ササササササササササササササササササササササササササササササササササササササ
obj[19]=Regkey : clsid\{83de62e0-5805-11d8-9b25-00e04c60faf2}
obj[20]=RegValue : clsid\{83de62e0-5805-11d8-9b25-00e04c60faf2} ""
obj[21]=Regkey : software\classes\clsid\{15ad4789-cdb4-47e1-a9da-992ee8e6bad6}
obj[22]=Regkey : software\microsoft\windows\currentversion\explorer\browser helper objects\{83de62e0-5805-11d8-9b25-00e04c60faf2}
obj[23]=RegValue : software\microsoft\windows\currentversion\explorer\browser helper objects\{83de62e0-5805-11d8-9b25-00e04c60faf2} "KeyVersion"
obj[24]=RegValue : software\microsoft\windows\currentversion\explorer\browser helper objects\{83de62e0-5805-11d8-9b25-00e04c60faf2} "BHOVersion"
obj[25]=RegValue : software\microsoft\windows\currentversion\explorer\browser helper objects\{83de62e0-5805-11d8-9b25-00e04c60faf2} "BHONew"
obj[26]=RegValue : software\microsoft\windows\currentversion\explorer\browser helper objects\{83de62e0-5805-11d8-9b25-00e04c60faf2} "KeyNew"
obj[27]=RegValue : software\microsoft\windows\currentversion\explorer\browser helper objects\{83de62e0-5805-11d8-9b25-00e04c60faf2} "KeyNew_Url"
obj[28]=RegValue : software\microsoft\windows\currentversion\explorer\browser helper objects\{83de62e0-5805-11d8-9b25-00e04c60faf2} "BHONew_Url"
obj[29]=RegValue : software\microsoft\windows\currentversion\explorer\browser helper objects\{83de62e0-5805-11d8-9b25-00e04c60faf2} "KeyNew_Version"
obj[30]=RegValue : software\microsoft\windows\currentversion\explorer\browser helper objects\{83de62e0-5805-11d8-9b25-00e04c60faf2} "BHONew_Version"
obj[31]=RegValue : software\microsoft\windows\currentversion\explorer\browser helper objects\{83de62e0-5805-11d8-9b25-00e04c60faf2} "BHO_Path"
obj[101]=Regkey : software\microsoft\windows\currentversion\uninstall\windows sr 2.0
obj[102]=RegValue : software\microsoft\windows\currentversion\uninstall\windows sr 2.0 "DisplayName"
obj[103]=RegValue : software\microsoft\windows\currentversion\uninstall\windows sr 2.0 "UninstallString"
obj[179]=File : C:\WINDOWS\2_0_1browserhelper2.dll
obj[180]=File : C:\WINDOWS\Key2.txt
obj[181]=File : C:\WINDOWS\UnstSA2.exe
obj[182]=File : C:\temp\Installer2.exe
VX2
ササササササササササササササササササササササササササササササササササササササ
obj[35]=Regkey : typelib\{690bccb4-6b83-4203-ae77-038c116594ec}
obj[36]=Regkey : vx2.vx2obj
obj[37]=RegValue : vx2.vx2obj ""
obj[38]=Regkey : localnrddll.localnrddllobj.1
obj[39]=RegValue : localnrddll.localnrddllobj.1 ""
obj[40]=Regkey : clsid\{00320615-b6c2-40a6-8f99-f1c52d674fad}
obj[41]=RegValue : clsid\{00320615-b6c2-40a6-8f99-f1c52d674fad} ""
obj[42]=Regkey : interface\{4534cd6b-59d6-43fd-864b-06a0d843444a}
obj[43]=RegValue : interface\{4534cd6b-59d6-43fd-864b-06a0d843444a} ""
obj[44]=Regkey : software\microsoft\windows\currentversion\explorer\browser helper objects\{00320615-b6c2-40a6-8f99-f1c52d674fad}
obj[47]=RegValue : .DEFAULT\software\localnrd "LNI0d1OfSInst"
obj[48]=RegValue : software\microsoft\windows\currentversion\run "conscorr"
obj[49]=RegValue : Software\Microsoft\Windows\CurrentVersion\Run "yqslpzzk"
obj[104]=Regkey : software\localnrd
obj[105]=RegValue : software\localnrd "LNI0d1OfSInst"
obj[106]=RegValue : software\localnrd "LNI0d1OfSDist"
obj[107]=RegValue : software\localnrd "LNT0o1pListSPos"
obj[108]=RegValue : software\localnrd "LNI0n1ProgSCab"
obj[109]=RegValue : software\localnrd "LNI0n1ProgSEx"
obj[110]=RegValue : software\localnrd "LNI0n1ProgSLstest"
obj[111]=RegValue : software\localnrd "LNC0n1trSEvnt"
obj[112]=RegValue : software\localnrd "LNC0n1trMsgSDisp"
obj[113]=RegValue : software\localnrd "LNC0S1Insur"
obj[114]=RegValue : software\localnrd "LNT0h1rshSCheckSIn"
obj[115]=RegValue : software\localnrd "LN0C1ntrSTransac"
obj[116]=RegValue : software\localnrd "LNC0u1rrentSMode"
obj[117]=RegValue : software\localnrd "LNC0n1tFyl"
obj[118]=RegValue : software\localnrd "LNM0o1deSSync"
obj[119]=RegValue : software\localnrd "LNT0h1rshSBath"
obj[120]=RegValue : software\localnrd "LNT0h1rshSysSInf"
obj[121]=RegValue : software\localnrd "LNT0h1rshSMots"
obj[122]=RegValue : software\localnrd "LNI0g1noreS"
obj[123]=RegValue : software\localnrd "LNs0t1i2cky1S"
obj[124]=RegValue : software\localnrd "LNs0t1i2cky2S"
obj[125]=RegValue : software\localnrd "LNs0t1i2cky3S"
obj[126]=RegValue : software\localnrd "LNs0t1i2cky4S"
obj[127]=RegValue : software\localnrd "LN0N1a2tionSCode"
obj[128]=RegValue : software\localnrd "LND0s1tSSEnd"
obj[129]=RegValue : software\localnrd "LND0s1tSCHost"
obj[130]=RegValue : software\localnrd "LND0s1tSCPath"
obj[131]=RegValue : software\localnrd "LNL0a1stMotsSDay"
obj[132]=RegValue : software\localnrd "LNL0a1stSSChckin"
obj[133]=RegValue : software\localnrd "LNS0t1atusOfSInst"
obj[134]=RegValue : software\localnrd "LNC0o1d2eOfSFinalAd"
obj[135]=RegValue : software\localnrd "LNT0i1m2eOfSFinalAd"
obj[136]=Regkey : .default\software\localnrd
obj[137]=RegValue : .default\software\localnrd "LNI0d1OfSDist"
obj[138]=RegValue : .default\software\localnrd "LNT0o1pListSPos"
obj[139]=RegValue : .default\software\localnrd "LNI0n1ProgSCab"
obj[140]=RegValue : .default\software\localnrd "LNI0n1ProgSEx"
obj[141]=RegValue : .default\software\localnrd "LNI0n1ProgSLstest"
obj[142]=RegValue : .default\software\localnrd "LNC0n1trSEvnt"
obj[143]=RegValue : .default\software\localnrd "LNC0n1trMsgSDisp"
obj[144]=RegValue : .default\software\localnrd "LNC0S1Insur"
obj[145]=RegValue : .default\software\localnrd "LNT0h1rshSCheckSIn"
obj[146]=RegValue : .default\software\localnrd "LN0C1ntrSTransac"
obj[147]=RegValue : .default\software\localnrd "LNC0u1rrentSMode"
obj[148]=RegValue : .default\software\localnrd "LNC0n1tFyl"
obj[149]=RegValue : .default\software\localnrd "LNM0o1deSSync"
obj[150]=RegValue : .default\software\localnrd "LNT0h1rshSBath"
obj[151]=RegValue : .default\software\localnrd "LNT0h1rshSysSInf"
obj[152]=RegValue : .default\software\localnrd "LNT0h1rshSMots"
obj[153]=RegValue : .default\software\localnrd "LNI0g1noreS"
obj[154]=RegValue : .default\software\localnrd "LNs0t1i2cky1S"
obj[155]=RegValue : .default\software\localnrd "LNs0t1i2cky2S"
obj[156]=RegValue : .default\software\localnrd "LNs0t1i2cky3S"
obj[157]=RegValue : .default\software\localnrd "LNs0t1i2cky4S"
obj[158]=RegValue : .default\software\localnrd "LN0N1a2tionSCode"
obj[159]=RegValue : .default\software\localnrd "LND0s1tSSEnd"
obj[160]=RegValue : .default\software\localnrd "LND0s1tSCHost"
obj[161]=RegValue : .default\software\localnrd "LND0s1tSCPath"
obj[162]=RegValue : .default\software\localnrd "LNL0a1stMotsSDay"
obj[163]=RegValue : .default\software\localnrd "LNL0a1stSSChckin"
obj[164]=RegValue : .default\software\localnrd "LNS0t1atusOfSInst"
obj[165]=RegValue : .default\software\localnrd "LNC0o1d2eOfSFinalAd"
obj[166]=RegValue : .default\software\localnrd "LNT0i1m2eOfSFinalAd"
obj[167]=File : c:\windows\system\jlyxreyp.exe
obj[169]=File : C:\WINDOWS\TEMP\THI5404.TMP\localNrd.cab
obj[170]=File : C:\WINDOWS\TEMP\THI5404.TMP\localNRD.dll
obj[172]=File : C:\WINDOWS\TEMP\THI5404.TMP\polall1l.exe
obj[173]=File : C:\WINDOWS\TEMP\conscorr.cab
obj[174]=File : C:\WINDOWS\TEMP\conscorr.exe
obj[176]=File : C:\WINDOWS\LOCALNRD.DLL
obj[178]=File : C:\WINDOWS\CONSCORR.EXE
obj[184]=File : C:\temp\lc.exe
obj[186]=File : C:\windows\TEMP\dummy.htm
obj[187]=File : C:\WINDOWS\inf\LOCALNRD.INF
TRACKING COOKIE
ササササササササササササササササササササササササササササササササササササササ
obj[50]=IECache Entry : Cookie:vaio@j.2004cms.com/HTM/562/0
obj[51]=IECache Entry : Cookie:vaio@custom-click.com/cgi-bin/
obj[52]=IECache Entry : Cookie:vaio@serving-sys.com/
obj[53]=IECache Entry : Cookie:vaio@atdmt.com/
obj[54]=IECache Entry : Cookie:vaio@bs.serving-sys.com/
obj[55]=IECache Entry : Cookie:vaio@tripod.com/
obj[56]=IECache Entry : Cookie:vaio@valuecommerce.com/
obj[57]=IECache Entry : Cookie:vaio@a.as-eu.falkag.net/
obj[58]=IECache Entry : Cookie:vaio@zedo.com/
obj[59]=IECache Entry : Cookie:vaio@valueclick.ne.jp/
obj[60]=IECache Entry : Cookie:vaio@promo.match.com/
obj[61]=IECache Entry : Cookie:vaio@z1.adserver.com/
obj[62]=IECache Entry : Cookie:vaio@jdirect.cjt1.net/HTM/562/0
obj[63]=IECache Entry : Cookie:vaio@tribalfusion.com/
obj[64]=IECache Entry : Cookie:vaio@as-eu.falkag.net/
obj[65]=IECache Entry : Cookie:vaio@doubleclick.net/
obj[66]=IECache Entry : Cookie:vaio@2o7.net/
obj[67]=IECache Entry : Cookie:vaio@versiontracker.com/
WINAD
ササササササササササササササササササササササササササササササササササササササ
obj[168]=File : C:\WINDOWS\SYSTEM\ide21201.vxd
ELITUM.ELITEBARBHO
ササササササササササササササササササササササササササササササササササササササ
obj[171]=File : C:\WINDOWS\TEMP\THI5404.TMP\preInsln.exe
obj[177]=File : C:\WINDOWS\PREINSLN.EXE
Logfile of HijackThis v1.98.2
Scan saved at 10:05:51, on 04/11/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\IMEJPMGR.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\PRINTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\MSN APPS\UPDATER\01.02.3000.1001\JA\MSNAPPAU.EXE
C:\PROGRAM FILES\WINDOWS ADTOOLS\WINADTOOLS.EXE
C:\WINDOWS\SYSTEM\JLYXREYP.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\SONY\VAIO ACTION SETUP\VASERV.EXE
C:\PROGRAM FILES\WINDOWS ADTOOLS\WINRATCHET.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\TEMP\RAR$EX00.956\HIJACKTHIS.EXE
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\JA\MSNTB.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.02.3000.1002\EN-XU\STMAIN.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll
O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\LOCALNRD.DLL
O3 - Toolbar: ラジオ(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\JA\MSNTB.DLL
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [FujiXeroxPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [msnappau] "c:\program files\MSN Apps\Updater\01.02.3000.1001\ja\msnappau.exe"
O4 - HKLM\..\Run: [Windows AdTools] C:\PROGRAM FILES\WINDOWS ADTOOLS\WINADTOOLS.EXE
O4 - HKLM\..\Run: [yqslpzzk] C:\WINDOWS\SYSTEM\jlyxreyp.exe
O4 - HKLM\..\Run: [CONSCORR] C:\WINDOWS\CONSCORR.exe
O4 - HKLM\..\Run: [zqxkt] C:\WINDOWS\zqxkt.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [MsnMsgr] "c:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\PROGRAM FILES\SKYPE\PHONE\SKYPE.EXE" /nosplash /minimized
O4 - Startup: VAIO Action Setup (サーバー).lnk = C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: RealGuide - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O12 - Plugin for .wav: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab30149.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab30149.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab30149.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab30149.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab30149.cab
O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary/Upwords.cab30149.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab30149.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=dd8db6eae7b3654038237d0b84b1b7592a7c740cb737386283389eb86c385c56bc11960de953afc8b0f8ea2e3d3e128ba9221d51f15727809397a79e20e8b65ea7:ca217fc8f18ffa8896bcf1e0be69801e
O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\LOCALNRD.DLL
O4 - HKLM\..\Run: [Windows AdTools] C:\PROGRAM FILES\WINDOWS ADTOOLS\WINADTOOLS.EXE
O4 - HKLM\..\Run: [yqslpzzk] C:\WINDOWS\SYSTEM\jlyxreyp.exe
O4 - HKLM\..\Run: [CONSCORR] C:\WINDOWS\CONSCORR.exe
O4 - HKLM\..\Run: [zqxkt] C:\WINDOWS\zqxkt.exe
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_f...6bcf1e0be69801e
Fix those entries then find and delete the files listed above, reboot and post a new log.
Here is my new log. And I stil cant access my hotmail inbox, the page is still white and frozen.
Logfile of HijackThis v1.98.2
Scan saved at 15:41:03, on 04/11/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\IMEJPMGR.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\PRINTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\MSN APPS\UPDATER\01.02.3000.1001\JA\MSNAPPAU.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\SONY\VAIO ACTION SETUP\VASERV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\TEMP\RAR$EX00.273\HIJACKTHIS.EXE
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\JA\MSNTB.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.02.3000.1002\EN-XU\STMAIN.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll (file missing)
O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\LOCALNRD.DLL (file missing)
O3 - Toolbar: ラジオ(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\JA\MSNTB.DLL
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [FujiXeroxPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [msnappau] "c:\program files\MSN Apps\Updater\01.02.3000.1001\ja\msnappau.exe"
O4 - HKLM\..\Run: [Windows AdTools] C:\PROGRAM FILES\WINDOWS ADTOOLS\WINADTOOLS.EXE
O4 - HKLM\..\Run: [yqslpzzk] C:\WINDOWS\SYSTEM\jlyxreyp.exe
O4 - HKLM\..\Run: [CONSCORR] C:\WINDOWS\CONSCORR.exe
O4 - HKLM\..\Run: [zqxkt] C:\WINDOWS\zqxkt.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [MsnMsgr] "c:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\PROGRAM FILES\SKYPE\PHONE\SKYPE.EXE" /nosplash /minimized
O4 - Startup: VAIO Action Setup (サーバー).lnk = C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: RealGuide - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O12 - Plugin for .wav: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab30149.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab30149.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab30149.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab30149.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab30149.cab
O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary/Upwords.cab30149.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab30149.cab
O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\LOCALNRD.DLL (file missing)
O4 - HKLM\..\Run: [Windows AdTools] C:\PROGRAM FILES\WINDOWS ADTOOLS\WINADTOOLS.EXE
O4 - HKLM\..\Run: [yqslpzzk] C:\WINDOWS\SYSTEM\jlyxreyp.exe
O4 - HKLM\..\Run: [CONSCORR] C:\WINDOWS\CONSCORR.exe
O4 - HKLM\..\Run: [zqxkt] C:\WINDOWS\zqxkt.exe
Fix those entries then find and delete the files listed above, reboot and post a new log.
I have created a new folder in C file and tried to drag the suggested files in to Quarantine file but it did not work, it said WIndows is using this so I can not remove. Some I was able to delete. So, I went to Start-search-file and folder and just typed in the name and pressed delete.
What am I doing wrong? and where can O4 - HKLM\..\Run: [zqxkt] C:\WINDOWS\zqxkt.exe be found?
Logfile of HijackThis v1.98.2
Scan saved at 14:22:05, on 04/11/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\IMEJPMGR.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\PRINTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\MSN APPS\UPDATER\01.02.3000.1001\JA\MSNAPPAU.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\SONY\VAIO ACTION SETUP\VASERV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\WINRAR\WINRAR.EXE
C:\WINDOWS\TEMP\RAR$EX00.183\HIJACKTHIS.EXE
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\JA\MSNTB.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.02.3000.1002\EN-XU\STMAIN.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: ラジオ(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\JA\MSNTB.DLL
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [FujiXeroxPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [msnappau] "c:\program files\MSN Apps\Updater\01.02.3000.1001\ja\msnappau.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [MsnMsgr] "c:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\PROGRAM FILES\SKYPE\PHONE\SKYPE.EXE" /nosplash /minimized
O4 - Startup: VAIO Action Setup (サーバー).lnk = C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: RealGuide - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O12 - Plugin for .wav: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab30149.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab30149.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab30149.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab30149.cab
O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary/Upwords.cab30149.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab30149.cab