Options

pop ups

please help me remove these pop ups, its slowing down my computer

Logfile of HijackThis v1.98.2
Scan saved at 9:54:51 PM, on 11/7/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\windows\temp\6O6.exe
C:\Program Files\Winamp\winampa.exe
C:\windows\temp\2atCjgeA.exe
C:\Program Files\Common files\updater\wupdater.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ltkphbk.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\WINDOWS\system32\stemIdle.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Documents and Settings\Ariel R\Application Data\ttuh.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
C:\WINDOWS\system32\settapi.exe
C:\WINDOWS\system32\stemIdle.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\system32\winupdt.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmiracle.com/sp.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.averatec.com/
R3 - URLSearchHook: IncrediFindBHO Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteBar\ELITEB~2.DLL
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Ariel R\Local Settings\Temp\mP.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\oloiwnod.exe
O4 - HKLM\..\Run: [Windows Compliant] dthuhp.exe
O4 - HKLM\..\Run: [$WindowsRegKey%update] IEXPLORE.EXE
O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\xmkidluh.exe
O4 - HKLM\..\Run: [Win32 System Spool] spoolsvc.exe
O4 - HKLM\..\Run: [6O6] C:\windows\temp\6O6.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [2atCjgeA] C:\windows\temp\2atCjgeA.exe
O4 - HKLM\..\Run: [Windows System Serivce] winserv.exe
O4 - HKLM\..\Run: [Auto updat] SysDebug.exe
O4 - HKLM\..\Run: [Win32 Configuration] videosd32.exe
O4 - HKLM\..\Run: [msjava service] xpcd.exe
O4 - HKLM\..\Run: [Microsoft Firewall] firewallsp2.exe
O4 - HKLM\..\Run: [MicrosoftUpdate] syshelper.exe
O4 - HKLM\..\Run: [MicrosoftUpdates] syshelped.exe
O4 - HKLM\..\Run: [SYSTRAY] C:\UNMT.EXE
O4 - HKLM\..\Run: [Windows Debugger] windbg.exe
O4 - HKLM\..\Run: [MSNMaSRR5] MSNMaSGRS.exe
O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winaxk32.exe
O4 - HKLM\..\Run: [stcloader] C:\WINDOWS\System32\stcloader.exe
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdtl.exe
O4 - HKLM\..\Run: [xsoO37O] ltkphbk.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\RunServices: [Windows Compliant] dthuhp.exe
O4 - HKLM\..\RunServices: [$WindowsRegKey%update] IEXPLORE.EXE
O4 - HKLM\..\RunServices: [systemidle] stemIdle.exe
O4 - HKLM\..\RunServices: [Win32 System Spool] spoolsvc.exe
O4 - HKLM\..\RunServices: [Windows System Serivce] winserv.exe
O4 - HKLM\..\RunServices: [Auto updat] SysDebug.exe
O4 - HKLM\..\RunServices: [Win32 Configuration] videosd32.exe
O4 - HKLM\..\RunServices: [msjava service] xpcd.exe
O4 - HKLM\..\RunServices: [Microsoft Firewall] firewallsp2.exe
O4 - HKLM\..\RunServices: [MicrosoftUpdate] syshelper.exe
O4 - HKLM\..\RunServices: [MicrosoftUpdates] syshelped.exe
O4 - HKLM\..\RunServices: [Windows Debugger] windbg.exe
O4 - HKLM\..\RunServices: [MSNMaSRR5] MSNMaSGRS.exe
O4 - HKLM\..\RunOnce: [systemidle] stemIdle.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Windows Compliant] dthuhp.exe
O4 - HKCU\..\Run: [$WindowsRegKey%update] IEXPLORE.EXE
O4 - HKCU\..\Run: [systemidle] stemIdle.exe
O4 - HKCU\..\Run: [Win32 System Spool] spoolsvc.exe
O4 - HKCU\..\Run: [Auto updat] SysDebug.exe
O4 - HKCU\..\Run: [Windows System Serivce] winserv.exe
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Ariel R\Application Data\ttuh.exe
O4 - HKCU\..\Run: [Win32 Configuration] videosd32.exe
O4 - HKCU\..\Run: [MicrosoftUpdate] syshelper.exe
O4 - HKCU\..\Run: [MicrosoftUpdates] syshelped.exe
O4 - HKCU\..\Run: [Windows Debugger] windbg.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [olethk32] C:\WINDOWS\System32\olethk32.exe
O4 - HKCU\..\Run: [Wqa] C:\WINDOWS\System32\??rvices.exe
O4 - HKCU\..\Run: [gB7ERXiqS] settapi.exe
O4 - HKCU\..\RunOnce: [systemidle] stemIdle.exe
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O16 - DPF: v2cab - http://searchmiracle.com/cab/v2cab.cab
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} (F1 Organizer Class) - http://www.addictivetechnologies.net/DM0/cab/60wu82rd.cab
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44297DA} - http://bannerfarm.ace.advertising.com/bannerfarm/47041/WrapperOuter1155.EXE
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildApp.cab

which should i remove?

Comments

  • SpywareShooterSpywareShooter 127.0.0.1
    edited November 2004
    You have a lot of crap on your computer, so we'll take it one step at a time, starting with the easy stuff.

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchmiracle.com/sp.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmiracle.com/sp.php
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.averatec.com/
    R3 - URLSearchHook: IncrediFindBHO Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL
    O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
    O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteBar\ELITEB~2.DLL
    O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Ariel R\Local Settings\Temp\mP.dll
    O16 - DPF: v2cab - http://searchmiracle.com/cab/v2cab.cab
    O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} (F1 Organizer Class) - http://www.addictivetechnologies.ne...ab/60wu82rd.cab
    O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44297DA} - http://bannerfarm.ace.advertising.c...erOuter1155.EXE
    O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
    O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
    O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildApp.cab


    Fix those entries then find and delete teh following files:
    C:\PROGRAM FILES\INCREDIFIND\
    C:\WINDOWS\EliteBar\
    C:\Documents and Settings\Ariel R\Local Settings\Temp\mP.dll

    Then reboot and post a new log.
  • edited November 2004
    hey thanks for the help man i followed your instruction it seems to work im not getting any pop ups yet! thanks a bunch realy appreciate it
  • SpywareShooterSpywareShooter 127.0.0.1
    edited November 2004
    Please post a new log.
  • edited November 2004
    heres my new log, im still getting pop ups , thanks for helping

    Logfile of HijackThis v1.98.2
    Scan saved at 5:01:23 PM, on 11/8/2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Winamp\winampa.exe
    C:\windows\temp\2atCjgeA.exe
    C:\Program Files\Common files\updater\wupdater.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\ltkphbk.exe
    C:\Program Files\AutoUpdate\AutoUpdate.exe
    C:\WINDOWS\system32\stemIdle.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\AIM\aim.exe
    C:\Documents and Settings\Ariel R\Application Data\ttuh.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
    C:\WINDOWS\System32\??rvices.exe
    C:\WINDOWS\system32\settapi.exe
    C:\Program Files\Winamp\winamp.exe
    C:\WINDOWS\system32\winupdt.exe
    C:\WINDOWS\system32\RUNDLL32.exe
    C:\WINDOWS\system32\winupdt.exe
    C:\Program Files\Digital Asphyxia\Y!TunnelPro 2.0\YTPro.exe
    C:\Program Files\Yahoo!\Messenger\ypager.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\unzipped\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Ariel R\Local Settings\Temp\bM4Zz7.dll
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\oloiwnod.exe
    O4 - HKLM\..\Run: [Windows Compliant] dthuhp.exe
    O4 - HKLM\..\Run: [$WindowsRegKey%update] IEXPLORE.EXE
    O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\xmkidluh.exe
    O4 - HKLM\..\Run: [Win32 System Spool] spoolsvc.exe
    O4 - HKLM\..\Run: [6O6] C:\windows\temp\6O6.exe
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [2atCjgeA] C:\windows\temp\2atCjgeA.exe
    O4 - HKLM\..\Run: [Windows System Serivce] winserv.exe
    O4 - HKLM\..\Run: [Auto updat] SysDebug.exe
    O4 - HKLM\..\Run: [Win32 Configuration] videosd32.exe
    O4 - HKLM\..\Run: [msjava service] xpcd.exe
    O4 - HKLM\..\Run: [Microsoft Firewall] firewallsp2.exe
    O4 - HKLM\..\Run: [MicrosoftUpdate] syshelper.exe
    O4 - HKLM\..\Run: [MicrosoftUpdates] syshelped.exe
    O4 - HKLM\..\Run: [SYSTRAY] C:\UNMT.EXE
    O4 - HKLM\..\Run: [Windows Debugger] windbg.exe
    O4 - HKLM\..\Run: [MSNMaSRR5] MSNMaSGRS.exe
    O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winaxk32.exe
    O4 - HKLM\..\Run: [stcloader] C:\WINDOWS\System32\stcloader.exe
    O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
    O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdtl.exe
    O4 - HKLM\..\Run: [xsoO37O] ltkphbk.exe
    O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
    O4 - HKLM\..\Run: [systemidle] stemIdle.exe
    O4 - HKLM\..\RunServices: [Windows Compliant] dthuhp.exe
    O4 - HKLM\..\RunServices: [$WindowsRegKey%update] IEXPLORE.EXE
    O4 - HKLM\..\RunServices: [systemidle] stemIdle.exe
    O4 - HKLM\..\RunServices: [Win32 System Spool] spoolsvc.exe
    O4 - HKLM\..\RunServices: [Windows System Serivce] winserv.exe
    O4 - HKLM\..\RunServices: [Auto updat] SysDebug.exe
    O4 - HKLM\..\RunServices: [Win32 Configuration] videosd32.exe
    O4 - HKLM\..\RunServices: [msjava service] xpcd.exe
    O4 - HKLM\..\RunServices: [Microsoft Firewall] firewallsp2.exe
    O4 - HKLM\..\RunServices: [MicrosoftUpdate] syshelper.exe
    O4 - HKLM\..\RunServices: [MicrosoftUpdates] syshelped.exe
    O4 - HKLM\..\RunServices: [Windows Debugger] windbg.exe
    O4 - HKLM\..\RunServices: [MSNMaSRR5] MSNMaSGRS.exe
    O4 - HKLM\..\RunOnce: [systemidle] stemIdle.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [Windows Compliant] dthuhp.exe
    O4 - HKCU\..\Run: [$WindowsRegKey%update] IEXPLORE.EXE
    O4 - HKCU\..\Run: [systemidle] stemIdle.exe
    O4 - HKCU\..\Run: [Win32 System Spool] spoolsvc.exe
    O4 - HKCU\..\Run: [Auto updat] SysDebug.exe
    O4 - HKCU\..\Run: [Windows System Serivce] winserv.exe
    O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Ariel R\Application Data\ttuh.exe
    O4 - HKCU\..\Run: [Win32 Configuration] videosd32.exe
    O4 - HKCU\..\Run: [MicrosoftUpdate] syshelper.exe
    O4 - HKCU\..\Run: [MicrosoftUpdates] syshelped.exe
    O4 - HKCU\..\Run: [Windows Debugger] windbg.exe
    O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
    O4 - HKCU\..\Run: [olethk32] C:\WINDOWS\System32\olethk32.exe
    O4 - HKCU\..\Run: [Wqa] C:\WINDOWS\System32\??rvices.exe
    O4 - HKCU\..\Run: [gB7ERXiqS] settapi.exe
    O4 - HKCU\..\RunOnce: [systemidle] stemIdle.exe
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
  • SpywareShooterSpywareShooter 127.0.0.1
    edited November 2004
    O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Ariel R\Local Settings\Temp\bM4Zz7.dll
    O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\oloiwnod.exe
    O4 - HKLM\..\Run: [Windows Compliant] dthuhp.exe
    O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\xmkidluh.exe
    O4 - HKLM\..\Run: [Win32 System Spool] spoolsvc.exe
    O4 - HKLM\..\Run: [6O6] C:\windows\temp\6O6.exe
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [2atCjgeA] C:\windows\temp\2atCjgeA.exe
    O4 - HKLM\..\Run: [Windows System Serivce] winserv.exe
    O4 - HKLM\..\Run: [Auto updat] SysDebug.exe
    O4 - HKLM\..\Run: [Win32 Configuration] videosd32.exe
    O4 - HKLM\..\Run: [msjava service] xpcd.exe
    O4 - HKLM\..\Run: [Microsoft Firewall] firewallsp2.exe
    O4 - HKLM\..\Run: [MicrosoftUpdate] syshelper.exe
    O4 - HKLM\..\Run: [MicrosoftUpdates] syshelped.exe
    O4 - HKLM\..\Run: [SYSTRAY] C:\UNMT.EXE
    O4 - HKLM\..\Run: [Windows Debugger] windbg.exe
    O4 - HKLM\..\Run: [MSNMaSRR5] MSNMaSGRS.exe
    O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winaxk32.exe
    O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
    O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdtl.exe
    O4 - HKLM\..\Run: [xsoO37O] ltkphbk.exe
    O4 - HKLM\..\Run: [systemidle] stemIdle.exe
    O4 - HKLM\..\RunServices: [Windows Compliant] dthuhp.exe
    O4 - HKLM\..\RunServices: [systemidle] stemIdle.exe
    O4 - HKLM\..\RunServices: [Windows System Serivce] winserv.exe
    O4 - HKLM\..\RunServices: [Auto updat] SysDebug.exe
    O4 - HKLM\..\RunServices: [Win32 Configuration] videosd32.exe
    O4 - HKLM\..\RunServices: [msjava service] xpcd.exe
    O4 - HKLM\..\RunServices: [Microsoft Firewall] firewallsp2.exe
    O4 - HKLM\..\RunServices: [MicrosoftUpdate] syshelper.exe
    O4 - HKLM\..\RunServices: [MicrosoftUpdates] syshelped.exe
    O4 - HKLM\..\RunServices: [Windows Debugger] windbg.exe
    O4 - HKLM\..\RunServices: [MSNMaSRR5] MSNMaSGRS.exe
    O4 - HKLM\..\RunOnce: [systemidle] stemIdle.exe
    O4 - HKCU\..\Run: [Windows Compliant] dthuhp.exe
    O4 - HKCU\..\Run: [systemidle] stemIdle.exe
    O4 - HKCU\..\Run: [Win32 System Spool] spoolsvc.exe
    O4 - HKCU\..\Run: [Auto updat] SysDebug.exe
    O4 - HKCU\..\Run: [Windows System Serivce] winserv.exe
    O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Ariel R\Application Data\ttuh.exe
    O4 - HKCU\..\Run: [Win32 Configuration] videosd32.exe
    O4 - HKCU\..\Run: [MicrosoftUpdate] syshelper.exe
    O4 - HKCU\..\Run: [MicrosoftUpdates] syshelped.exe
    O4 - HKCU\..\Run: [Windows Debugger] windbg.exe
    O4 - HKCU\..\Run: [olethk32] C:\WINDOWS\System32\olethk32.exe
    O4 - HKCU\..\Run: [Wqa] C:\WINDOWS\System32\??rvices.exe
    O4 - HKCU\..\Run: [gB7ERXiqS] settapi.exe
    O4 - HKCU\..\RunOnce: [systemidle] stemIdle.exe
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net

    Fix those entries then find and delete the files listed above, reboot and post a new log.
Sign In or Register to comment.