Options

Annoying AIM Virus on my computer!!! HELP

edited August 2005 in Spyware & Virus Removal
Here is my log from hijackthis.... PLEASE help us... our computer is slow as hell and has sooo many pop ups!!!!


Logfile of HijackThis v1.99.1
Scan saved at 10:52:49 PM, on 7/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\xmconfig.exe
C:\WINDOWS\system32\xrnfig.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\winusersystem32.exe
C:\WINDOWS\system32\palsp.exe
C:\WINDOWS\system32\palsp.exe
C:\Program Files\Netscape\Netscape Browser\netscape.exe
C:\Program Files\Messenger\msmsgs.exe
C:\DOCUME~1\Peindl\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [stratas] xmconfig.exe
O4 - HKLM\..\Run: [rcctratas] xrnfig.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [Microsoft Update Loaders 2006] winusersystem32.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\eliteicr32.exe
O4 - HKLM\..\RunServices: [stratas] xmconfig.exe
O4 - HKLM\..\RunServices: [rcctratas] xrnfig.exe
O4 - HKLM\..\RunServices: [Microsoft Update Loaders 2006] winusersystem32.exe
O4 - HKCU\..\Run: [stratas] xmconfig.exe
O4 - HKCU\..\Run: [rcctratas] xrnfig.exe
O4 - HKCU\..\Run: [PaperShredder] C:\Program Files\WinMeta\PaperShredder\PaperShredder.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Paper Shredder - {EB55A514-7BDA-407F-BB10-17C6962E8316} - C:\Program Files\WinMeta\PaperShredder\PaperShredder.shd
O9 - Extra 'Tools' menuitem: &Paper Shredder - {EB55A514-7BDA-407F-BB10-17C6962E8316} - C:\Program Files\WinMeta\PaperShredder\PaperShredder.shd
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1450/ftp.coupons.com/r3302/cpbrkpie.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Comments

  • Shadow2018Shadow2018 Northwest Missouri
    edited July 2005
    You are running Hijack This from a temp folder. Please move HJT to your C: directory and post a new log.
  • edited July 2005
    Here is the new log file. Not in temp anymore.

    Logfile of HijackThis v1.99.1
    Scan saved at 10:00:02 PM, on 7/23/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Norton Internet Security\ISSVC.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\xmconfig.exe
    C:\WINDOWS\system32\xrnfig.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\winusersystem32.exe
    C:\Program Files\WinMeta\PaperShredder\PaperShredder.exe
    C:\Program Files\AIM95\aim.exe
    C:\Program Files\WinMeta\PaperShredder\stopper.exe
    C:\PROGRA~1\NETSCAPE\NETSCA~1\NETSCAPE.EXE
    C:\WINDOWS\system32\palsp.exe
    C:\WINDOWS\system32\palsp.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\HijackThis.exe
    C:\Program Files\Messenger\msmsgs.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
    O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM95\\DeadAIM.ocm",ExportedCheckODLs
    O4 - HKLM\..\Run: [stratas] xmconfig.exe
    O4 - HKLM\..\Run: [rcctratas] xrnfig.exe
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
    O4 - HKLM\..\Run: [Microsoft Update Loaders 2006] winusersystem32.exe
    O4 - HKLM\..\Run: [checkrun] C:\windows\system32\eliteicr32.exe
    O4 - HKLM\..\RunServices: [stratas] xmconfig.exe
    O4 - HKLM\..\RunServices: [rcctratas] xrnfig.exe
    O4 - HKLM\..\RunServices: [Microsoft Update Loaders 2006] winusersystem32.exe
    O4 - HKCU\..\Run: [stratas] xmconfig.exe
    O4 - HKCU\..\Run: [rcctratas] xrnfig.exe
    O4 - HKCU\..\Run: [PaperShredder] C:\Program Files\WinMeta\PaperShredder\PaperShredder.exe
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Paper Shredder - {EB55A514-7BDA-407F-BB10-17C6962E8316} - C:\Program Files\WinMeta\PaperShredder\PaperShredder.shd
    O9 - Extra 'Tools' menuitem: &Paper Shredder - {EB55A514-7BDA-407F-BB10-17C6962E8316} - C:\Program Files\WinMeta\PaperShredder\PaperShredder.shd
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1450/ftp.coupons.com/r3302/cpbrkpie.cab
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • Shadow2018Shadow2018 Northwest Missouri
    edited July 2005
    Please download LSPFix and save the file to a convenient location. Open LSPFix and run the program.

    Open the start menu and navigate to the add/remove programs list. Uninstall these entries:

    EliteToolbar
    New.Net (may not let you uninstall this right now, if not that's ok)

    Download Ad-Aware SE 1.06 and save the setup file to a convenient location. Run the setup file and then update Ad-Aware SE with the latest definitions. Exit this for now.

    Download Spybot Search & Destroy. Follow the same steps as with Ad-Aware SE and then exit this program.

    Make sure hidden files all can be viewed.

    Boot into safe mode. To enter safe mode>reboot>tap the F8 button when the start up screen appears>select safe mode from the menu.

    Run Hijack This and place ace a checkmark next to these entries then click Fix Checked:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
    O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
    O4 - HKLM\..\Run: [stratas] xmconfig.exe
    O4 - HKLM\..\Run: [rcctratas] xrnfig.exe
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
    O4 - HKLM\..\Run: [Microsoft Update Loaders 2006] winusersystem32.exe
    O4 - HKLM\..\Run: [checkrun] C:\windows\system32\eliteicr32.exe
    O4 - HKLM\..\RunServices: [stratas] xmconfig.exe
    O4 - HKLM\..\RunServices: [rcctratas] xrnfig.exe
    O4 - HKLM\..\RunServices: [Microsoft Update Loaders 2006] winusersystem32.exe
    O4 - HKCU\..\Run: [stratas] xmconfig.exe
    O4 - HKCU\..\Run: [rcctratas] xrnfig.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll


    Now delete these files or directories if they exist:
    C:\WINDOWS\EliteToolBar
    C:\windows\system32\eliteicr32.exe
    C:\WINDOWS\system32\Shdocvw.dll

    Do a search for these files and delete them. Do not be alarmed if you don't find them:
    xmconfig.exe
    xrnfig.exe
    winusersystem32.exe
    Newdotnet

    Run a "full system scan" with Ad-Aware SE and Spybot S&D. Remove all objects found.

    Reboot your system and run these online scans:

    Activescan

    Bitdefender

    Please save and post the results of Activescan and a new hijack this log.
  • edited July 2005
    Seems to be working again! Thanks a ton... I really didnt want to have to re do the whole computer. Here is the activscan log


    Adware:adware/maxifiles No disinfected C:\PROGRAM FILES\MaxiFiles
    Adware:adware/wupd No disinfected C:\PROGRAM FILES\Media Access
    Adware:adware/elitebar No disinfected C:\DOCUMENTS AND SETTINGS\PEINDL\FAVORITES\Casino & Carrers
    Adware:adware/coolsavings No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\MODULEUSAGE\C:/WINDOWS/DOWNLOADED PROGRAM FILES/CPNMGR.DLL
    Adware:adware/myway No disinfected HKEY_CLASSES_ROOT\MYWAYSEARCHASSISTANTDE.AUXILIARY
    Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Peindl\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loader.jar-46c0219f-33f1bf45.zip[Dummy.class]
    Adware:Adware/EliteBar No disinfected C:\Documents and Settings\Peindl\Local Settings\Temp\262612_3476_3288_4268_62.41.tmp
    Adware:Adware/EliteBar No disinfected C:\Documents and Settings\Peindl\Local Settings\Temp\655642_1792_3288_5180_62.41.tmp
    Adware:Adware/EliteBar No disinfected C:\Documents and Settings\Peindl\Local Settings\Temp\66156_1260_1472_3056_62.41.tmp
    Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Peindl\Local Settings\Temp\jfghjfgudk.exe
    Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Peindl\Local Settings\Temporary Internet Files\Content.IE5\CDUJ0XEJ\casino[1].bmp
    Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Peindl\Local Settings\Temporary Internet Files\Content.IE5\O96B8LAJ\dating[1].bmp
    Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Peindl\Local Settings\Temporary Internet Files\Content.IE5\O96B8LAJ\fav[1].bmp
    Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Peindl\Local Settings\Temporary Internet Files\Content.IE5\O96B8LAJ\istdownload[1].exe
    Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Peindl\Local Settings\Temporary Internet Files\Content.IE5\XYZ0STCV\drugs[1].bmp
    Virus:W32/Gaobot.JFW.worm Disinfected C:\WINDOWS\SYSTEM32\poker3.exe
    Adware:Adware/EliteBar No disinfected C:\WINDOWS\SYSTEM32\temperror32.dat
    Virus:W32/Mytob.IG.worm Disinfected C:\WINDOWS\SYSTEM32\winusersystem32.exe
    Virus:W32/Gaobot.JFB.worm Disinfected C:\WINDOWS\SYSTEM32\xmconfig.exe
    Virus:W32/Sdbot.EKO.worm Disinfected C:\WINDOWS\SYSTEM32\xrnfig.exe
  • Shadow2018Shadow2018 Northwest Missouri
    edited August 2005
    Delete these files or directories if they exist:

    C:\PROGRAM FILES\MaxiFiles
    C:\PROGRAM FILES\Media Access
    C:\WINDOWS\SYSTEM32\temperror32.dat
    C:/WINDOWS/DOWNLOADED PROGRAM FILES/CPNMGR.DLL

    Download cleanup 4.0 and save the setup file to a convenient location. Run the setup file for cleanup and place a shortcut on your desktop. Open cleanup 4.0 and click the cleanup button. This will clean out your temp folders and free up some space on your HDD.

    For the registry entry it will need to be removed manually. Please proceed with caution and be sure you have located the correct file before deletion:

    Open the start menu>click run>(type) regedit>click ok>a menu will appear>double click this directory-HKEY_CLASSES_ROOT>right click on this entry and click delete:MYWAYSEARCHASSISTANTDE.AUXILIARY>exit out of the registry editor.

    Run activescan once more and post the results of that scan with a new HIJACK THIS LOG.
Sign In or Register to comment.