Options
Dizkiderock-hijack this log *msblank internet explorer*
Asking help on solving my situation Username: Dizkiderock
problem:I ran ad-aware and it still didnt solve the problem, When i open my internet explorer it opens in a msblank and wont let me go anywhere from there, keeps opening searh pages. Any help would be very much appreciated, Thank You-Dizkiderock
Logfile of HijackThis v1.99.1
Scan saved at 8:30:32 PM, on 10/3/2005
Platform: Windows 2000 SP1 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\Explorer.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\System32\popcorn72.exe
C:\Program Files\Warez P2P Client\warez.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\DESKTOP\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINNT\System32\msblank.html
R3 - URLSearchHook: (no name) - {08E540E1-9218-1A4D-8AA1-8C42F3712956} - SetupExeDll.dll (file missing)
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINNT\System32\wlswf.dll
O2 - BHO: ActiveX Control - {3D8F0A3E-48AC-4967-93F5-E2CACAFB5B3B} - blank (file missing)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: IE SP2 AddOn - {ABBA349B-7F75-4A38-8CF9-E7932CE09B62} - blank (file missing)
O2 - BHO: ActiveX Control - {DB1D0922-E0FE-4491-B6B2-3DBF1876B785} - blank (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINNT\System32\wlswf.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [dnsquerx] C:\Program Files\Merak\dnsquerx.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ControlPanel] C:\WINNT\System32\popcorn72.exe rundll.dll,LoadMouseProfile
O4 - HKCU\..\Run: [warez] "C:\Program Files\Warez P2P Client\warez.exe" -h
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: RaptisoftGameLoader - http://miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1125445706615
O16 - DPF: {EC51659D-721F-4CBF-9CEA-5E776D89CEA9} - http://www.pacimedia.com/install/pcs_0007.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{7E61CEFA-9498-4F81-B2A9-06BC26B96F52}: NameServer = 85.255.113.108,85.255.112.25
O17 - HKLM\System\CCS\Services\Tcpip\..\{7EDA5757-4FFF-499B-89E1-FF6D215B8B57}: NameServer = 85.255.113.108,85.255.112.25
O17 - HKLM\System\CS1\Services\VxD\MSTCP: NameServer = 69.50.188.180,85.255.112.5
O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 69.50.188.180,85.255.112.5
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.50.188.180,85.255.112.5
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
problem:I ran ad-aware and it still didnt solve the problem, When i open my internet explorer it opens in a msblank and wont let me go anywhere from there, keeps opening searh pages. Any help would be very much appreciated, Thank You-Dizkiderock
Logfile of HijackThis v1.99.1
Scan saved at 8:30:32 PM, on 10/3/2005
Platform: Windows 2000 SP1 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\Explorer.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\System32\popcorn72.exe
C:\Program Files\Warez P2P Client\warez.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\DESKTOP\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINNT\System32\msblank.html
R3 - URLSearchHook: (no name) - {08E540E1-9218-1A4D-8AA1-8C42F3712956} - SetupExeDll.dll (file missing)
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINNT\System32\wlswf.dll
O2 - BHO: ActiveX Control - {3D8F0A3E-48AC-4967-93F5-E2CACAFB5B3B} - blank (file missing)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: IE SP2 AddOn - {ABBA349B-7F75-4A38-8CF9-E7932CE09B62} - blank (file missing)
O2 - BHO: ActiveX Control - {DB1D0922-E0FE-4491-B6B2-3DBF1876B785} - blank (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINNT\System32\wlswf.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [dnsquerx] C:\Program Files\Merak\dnsquerx.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ControlPanel] C:\WINNT\System32\popcorn72.exe rundll.dll,LoadMouseProfile
O4 - HKCU\..\Run: [warez] "C:\Program Files\Warez P2P Client\warez.exe" -h
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: RaptisoftGameLoader - http://miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1125445706615
O16 - DPF: {EC51659D-721F-4CBF-9CEA-5E776D89CEA9} - http://www.pacimedia.com/install/pcs_0007.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{7E61CEFA-9498-4F81-B2A9-06BC26B96F52}: NameServer = 85.255.113.108,85.255.112.25
O17 - HKLM\System\CCS\Services\Tcpip\..\{7EDA5757-4FFF-499B-89E1-FF6D215B8B57}: NameServer = 85.255.113.108,85.255.112.25
O17 - HKLM\System\CS1\Services\VxD\MSTCP: NameServer = 69.50.188.180,85.255.112.5
O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 69.50.188.180,85.255.112.5
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.50.188.180,85.255.112.5
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
0
Comments
You'll see a list of all the items it found. There will also be a log on your desktop with the name fsbl.xxxxxxx.log (where xxxxxxx represents numbers). The application finds both bad files and legitimate ones such as "wbemtest.exe", so don't choose the rename option yet! Copy and paste the log it generated in your next reply.
this is the log they gave me, where do i go from here thanks, dizkiderock
10/04/05 19:59:30 [Info]: BlackLight Engine 1.0.23 initialized
10/04/05 19:59:30 [Info]: OS: 5.0 build 2195 (Service Pack 1)
10/04/05 19:59:31 [Note]: 4019 4
10/04/05 19:59:31 [Note]: 4005 0
10/04/05 20:00:02 [Note]: 4006 0
10/04/05 20:00:02 [Note]: 4011 796
10/04/05 20:00:04 [Note]: FSRAW library version 1.7.1011
10/04/05 20:00:45 [Info]: Hidden file: C:\WINNT\system32\wbem\wbemtest.exe
10/04/05 20:00:45 [Note]: 10002 1
10/04/05 20:00:47 [Info]: Hidden file: C:\WINNT\system32\bndmod.exe
10/04/05 20:00:47 [Note]: 10002 1
10/04/05 20:00:49 [Info]: Hidden file: C:\WINNT\system32\cseyf.exe
10/04/05 20:00:49 [Note]: 4002 32
10/04/05 20:00:49 [Note]: 4003 1
10/04/05 20:00:49 [Note]: 10002 1
10/04/05 20:00:49 [Info]: Hidden file: C:\WINNT\system32\dmrev.exe
10/04/05 20:00:49 [Note]: 4002 32
10/04/05 20:00:49 [Note]: 4003 1
10/04/05 20:00:49 [Note]: 10002 1
10/04/05 20:00:51 [Info]: Hidden file: C:\WINNT\system32\hclean32.exe
10/04/05 20:00:51 [Note]: 10002 1
10/04/05 20:00:51 [Info]: Hidden file: C:\WINNT\system32\hlmicro.exe
10/04/05 20:00:51 [Note]: 10002 1
10/04/05 20:00:52 [Info]: Hidden file: C:\WINNT\system32\loadctr32.exe
10/04/05 20:00:52 [Note]: 10002 1
10/04/05 20:00:53 [Info]: Hidden file: C:\WINNT\system32\loodctr32.exe
10/04/05 20:00:53 [Note]: 10002 1
10/04/05 20:01:01 [Info]: Hidden file: C:\WINNT\system32\hwiper.exe
10/04/05 20:01:01 [Note]: 10002 1
10/04/05 20:02:29 [Note]: 4007 0
Select these items in blacklite and choose rename:
C:\WINNT\system32\bndmod.exe
C:\WINNT\system32\cseyf.exe
C:\WINNT\system32\dmrev.exe
C:\WINNT\system32\hclean32.exe
C:\WINNT\system32\hlmicro.exe
C:\WINNT\system32\loadctr32.exe
C:\WINNT\system32\loodctr32.exe
C:\WINNT\system32\hwiper.exe
The tool will ask if you want to reboot (restart) choose yes.
Please download FixWareout from one of these sites:
http://forums.subratam.org/index.php?act=Attach&type=post&id=43811
http://swandog46.geekstogo.com/Fixwareout.exe
Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINNT\System32\msblank.html
R3 - URLSearchHook: (no name) - {08E540E1-9218-1A4D-8AA1-8C42F3712956} - SetupExeDll.dll (file missing)
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: ActiveX Control - {3D8F0A3E-48AC-4967-93F5-E2CACAFB5B3B} - blank (file missing)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: IE SP2 AddOn - {ABBA349B-7F75-4A38-8CF9-E7932CE09B62} - blank (file missing)
O2 - BHO: ActiveX Control - {DB1D0922-E0FE-4491-B6B2-3DBF1876B785} - blank (file missing)
Click Fix Checked. Close HijackThis, and click OK to proceed.
At the end of the fix, you may need to restart your computer again.
Finally, please post the contents of the logfile C:\fixwareout\report.txt, along with a new HijackThis log.