Options

HJT(first timer)

:scratch: HI My name is John and this is my first time using HJT, so I really dont know what to do. I have AntiVir Guard installed and Spybot aswell. My main concern is that I cannot remove Search Assitant from my Add/Remove list and BIG problem is when I use IE a big list of sites come up. It happens on every site I visit. Dont know how to fix. Please help...Well heres my Log:
Thnx in advance

Logfile of HijackThis v1.98.2
Scan saved at 10:24:49 PM, on 11/20/2004
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\scagent.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\RALPH~2.OLI\LOCALS~1\Temp\Rar$EX00.578\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://search123.biz/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://0ml.net/cat
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINNT\_s.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://0ml.net/cat
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://0ml.net/cat
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINNT\_s.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = C:\WINNT\_sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = http://0ml.net/searchasst.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = http://0ml.net/searchasst.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://0ml.net/cat
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *new-search.net*;*x-google.net*
R3 - URLSearchHook: (no name) - {C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_7_0.dll
O2 - BHO: BL Class - {28F65FCB-D130-11D8-BA48-8BE0C49AF370} - C:\DOCUME~1\RALPH~2.OLI\LOCALS~1\Temp\20041009\popup_bl.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: sr - {5742F79A-1D91-42c4-990C-B46CF55A6478} - C:\WINNT\System32\setfgi.dll
O2 - BHO: (no name) - {BFFEE2FC-95D3-40AB-AEB0-04618B53F399} - C:\WINNT\System32\hgpcbaa.dll (file missing)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Games toolbar - {02ffc86e-283e-4faa-95d6-addca024f30a} - C:\Program Files\Games\tbGame.dll
O3 - Toolbar: (no name) - {815A82AE-CDEF-11D8-BA48-A6D245798277} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [mswspl] C:\Documents and Settings\Ralph.OLIVAS-SE9K1IZ0\Desktop\ploint.exe
O4 - HKLM\..\Run: [MSUpdSrv] msupdsrv.exe
O4 - HKLM\..\Run: [ControlPanel] C:\WINNT\System32\twink64.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [Create A Monster] "C:\Program Files\Kudd.com\createAMonster.exe" -run
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKCU\..\Run: [winltmpv] c:\documents and settings\ralph.olivas-se9k1iz0\desktop\winln.exe
O4 - HKCU\..\Run: [cmsound] c:\documents and settings\ralph.olivas-se9k1iz0\desktop\vcsystem.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O13 - DefaultPrefix:
O16 - DPF: {01463AD4-3879-0F1D-ABB7-64BB4D65ED0E} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {018E333F-6A77-027E-C167-26692FCA2477} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {03D74C59-957A-23F8-D6EF-4B631519C094} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {04740C99-C8EE-7A84-EFD8-043E41E310AF} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {074E9E2B-B877-4FCD-F4EF-19EE66CAD72C} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {07A9A988-CC2C-0BC0-D31E-2E8A487A0034} - http://205.252.249.254/1/rdgUS1077.exe
O16 - DPF: {09438437-B785-1D22-0735-286F33447A9F} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {0A3E7B78-4860-3D17-AD3A-7ABA36EA8369} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {0D825A4E-741F-217D-B404-53A22C1BDC68} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {10DAC47F-D9A5-0FE4-E315-5FB26306861C} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {11111111-1111-1111-1111-222222222222} - ms-its:mhtml:file://d:\foo.mht!http://v73.us/count//x.chm::/open.exe
O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:\foo.mht!http://82.179.166.145/x19.chm::/trs19.exe
O16 - DPF: {267C355E-F153-126C-511A-3C3C674B52B8} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {27AAD006-1223-54E0-065D-5C553F74B279} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {29BA0A0C-C971-568F-677F-379217002B1E} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {2A853B64-7C55-55C8-4B70-20C8163F7D46} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {2B42961B-E012-5022-A98F-2F6C24867323} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {2E2A35D1-4136-08C1-C69B-18B5282E3E99} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {356EF9DA-6257-6526-9653-1FB72BA4802E} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {3630E02D-C7AC-7D38-C8F2-0FCE655FEBD2} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {3A5AF16E-6DE7-7F9B-A684-17290DEE550E} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {4005DDC8-6108-6C23-3F38-043C66DF803D} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {42D696C4-9CAD-4E95-026A-741C7CE84C50} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {48D7AC27-9F8F-225A-3984-4CCB3384EF53} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {5551238E-4BB8-03AC-783A-2D131D1A5ABC} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {5E2467C5-FC4A-2E54-C521-435611DF8085} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {643AA4CF-DB55-3C20-4D1C-1CD239A60EAF} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {64449F81-A956-17B1-0AA7-237E6AA352B9} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {70C71108-3F13-38E5-002D-283E665A165A} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {74EDCC49-0B86-12EE-F8EA-6DED35A547DD} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {76F60E1C-8D99-3407-D95F-12A72A0A8376} - http://213.159.117.150/1/rdgUS10.exe
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://static.topconverting.com/activex/loader2.ocx
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildtangent.com/bgn/partners/aolim/install.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINNT\httpfilter.dll

Comments

  • SpywareShooterSpywareShooter 127.0.0.1
    edited November 2004
    Well, the first thing I'm going to have you do is fix ALL of the O16, R1 and R0 entries. Once you've done that, reboot and post a new log. That will clear most of hte crap out of your log, and we'll get rid of the malicious files from there.
  • edited November 2004
    First I want to say Im very sorry spyshooter for making you wait And more importantly Thank You for what youve done already . I just got caught up in the whole holiday and didnt get a chane to post. Ok well if you still want to help heres my new log:

    Logfile of HijackThis v1.98.2
    Scan saved at 6:05:08 PM, on 11/29/2004
    Platform: Windows 2000 (WinNT 5.00.2195)
    MSIE: Internet Explorer v5.00 (5.00.2920.0000)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\SYSTEM32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\AVPersonal\AVWUPSRV.EXE
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\scagent.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\Explorer.exe
    C:\WINNT\ploint.exe
    C:\winnt\winln.exe
    C:\winnt\vcsystem.exe
    C:\Program Files\WinRAR\WinRAR.exe
    C:\DOCUME~1\RALPH~2.OLI\LOCALS~1\Temp\Rar$EX00.917\HijackThis.exe

    R3 - URLSearchHook: (no name) - {C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70} - (no file)
    O1 - Hosts: 3466709097 com.org
    O1 - Hosts: 3466690378 view.atdmt.com
    O1 - Hosts: 3466690378 click.atdmt.com
    O1 - Hosts: 3466690378 leader.linkexchange.com
    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_7_0.dll
    O2 - BHO: BL Class - {28F65FCB-D130-11D8-BA48-8BE0C49AF370} - C:\DOCUME~1\RALPH~2.OLI\LOCALS~1\Temp\20041009\popup_bl.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: sr - {5742F79A-1D91-42c4-990C-B46CF55A6478} - C:\WINNT\setfgi.dll
    O2 - BHO: (no name) - {B72F75B8-93F3-429D-B13E-660B206D897A} - C:\WINNT\System32\porynt.dll
    O2 - BHO: (no name) - {BFFEE2FC-95D3-40AB-AEB0-04618B53F399} - C:\WINNT\System32\hgpcbaa.dll (file missing)
    O3 - Toolbar: Games toolbar - {02ffc86e-283e-4faa-95d6-addca024f30a} - C:\Program Files\Games\tbGame.dll
    O3 - Toolbar: (no name) - {815A82AE-CDEF-11D8-BA48-A6D245798277} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_7_0.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [mswspl] C:\WINNT\ploint.exe
    O4 - HKLM\..\Run: [MSUpdSrv] msupdsrv.exe
    O4 - HKLM\..\Run: [ControlPanel] C:\WINNT\System32\twink64.exe internat.dll,LoadKeyboardProfile
    O4 - HKLM\..\Run: [Create A Monster] "C:\Program Files\Kudd.com\createAMonster.exe" -run
    O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
    O4 - HKCU\..\Run: [winltmpv] c:\winnt\winln.exe
    O4 - HKCU\..\Run: [cmsound] c:\winnt\vcsystem.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O13 - DefaultPrefix:
    O15 - Trusted Zone: *.clickspring.net
    O15 - Trusted Zone: *.crazywinnings.com
    O15 - Trusted Zone: *.flingstone.com
    O15 - Trusted Zone: *.mt-download.com
    O15 - Trusted Zone: *.my-internet.info
    O15 - Trusted Zone: *.searchbarcash.com
    O15 - Trusted Zone: *.searchmiracle.com
    O15 - Trusted Zone: *.skoobidoo.com
    O15 - Trusted Zone: *.topconverting.com
    O15 - Trusted Zone: *.windupdates.com
    O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINNT\httpfilter.dll
    O19 - User stylesheet: (file missing)
Sign In or Register to comment.