Options

spyware warning - desktop

HELP ME ANYONE, PLEASE.............

mY COMPUTER HAS BEEN HIJACKED.
many popups ocurres, my desktop has been frozen "SPYWARE WARNING"

I HAVE RUNNED THE PROGRAM hijackthis, AND SAVED A LOG. bUT I DONT KNOW WHAT TO DELETE AND NOT TO DELETE.

Can anyone help me???

im mot very in to computers... can anyone tell me what to do by stepping me through what to do??

here is my log:
Logfile of HijackThis v1.99.1
Scan saved at 23:40:47, on 25.10.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe
C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
C:\Progra~1\Launch Manager\LaunchAp.exe
C:\Progra~1\Launch Manager\PowerKey.exe
C:\Progra~1\Launch Manager\HotkeyApp.exe
C:\Progra~1\Launch Manager\CtrlVol.exe
C:\Progra~1\Launch Manager\Wbutton.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Programfiler\Telenor\ecc\ecc.exe
C:\windows\system32\mdms.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programfiler\Messenger\msmsgs.exe
C:\Programfiler\MSN Messenger\MsnMsgr.Exe
C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe
C:\Programfiler\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTSvcCDA.EXE
C:\Programfiler\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe
C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe
C:\Programfiler\BearShare\BearShare.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programfiler\Internet Explorer\iexplore.exe
C:\Programfiler\Internet Explorer\iexplore.exe
C:\PROGRAMFILER\INTERNET EXPLORER\IEXPLORE.EXE
C:\Documents and Settings\anette vågslid\Skrivebord\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.vg.no.no/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
O1 - Hosts: 127.0.0.4 n-glx.s-redirect.com
O1 - Hosts: 127.0.0.4 x.full-tgp.net
O1 - Hosts: 127.0.0.4 counter.sexmaniack.com
O1 - Hosts: 127.0.0.4 autoescrowpay.com
O1 - Hosts: 127.0.0.4 www.autoescrowpay.com
O1 - Hosts: 127.0.0.4 www.awmdabest.com
O1 - Hosts: 127.0.0.4 www.sexfiles.nu
O1 - Hosts: 127.0.0.4 awmdabest.com
O1 - Hosts: 127.0.0.4 sexfiles.nu
O1 - Hosts: 127.0.0.4 allforadult.com
O1 - Hosts: 127.0.0.4 www.allforadult.com
O1 - Hosts: 127.0.0.4 www.iframe.biz
O1 - Hosts: 127.0.0.4 iframe.biz
O1 - Hosts: 127.0.0.4 www.newiframe.biz
O1 - Hosts: 127.0.0.4 newiframe.biz
O1 - Hosts: 127.0.0.4 www.vesbiz.biz
O1 - Hosts: 127.0.0.4 vesbiz.biz
O1 - Hosts: 127.0.0.4 www.pizdato.biz
O1 - Hosts: 127.0.0.4 pizdato.biz
O1 - Hosts: 127.0.0.4 www.aaasexypics.com
O1 - Hosts: 127.0.0.4 aaasexypics.com
O1 - Hosts: 127.0.0.4 www.virgin-tgp.net
O1 - Hosts: 127.0.0.4 virgin-tgp.net
O1 - Hosts: 127.0.0.4 www.awmcash.biz
O1 - Hosts: 127.0.0.4 awmcash.biz
O1 - Hosts: 127.0.0.4 buldog-stats.com
O1 - Hosts: 127.0.0.4 www.buldog-stats.com
O1 - Hosts: 127.0.0.4 fregat.drocherway.com
O1 - Hosts: 127.0.0.4 slutmania.biz
O1 - Hosts: 127.0.0.4 www.slutmania.biz
O1 - Hosts: 127.0.0.4 toolbarpartner.com
O1 - Hosts: 127.0.0.4 www.toolbarpartner.com
O1 - Hosts: 127.0.0.4 www.megapornix.com
O1 - Hosts: 127.0.0.4 megapornix.com
O1 - Hosts: 127.0.0.4 www.sp2****ed.biz
O1 - Hosts: 127.0.0.4 sp2****ed.biz
O1 - Hosts: 127.0.0.4 greg-tut.com
O1 - Hosts: 127.0.0.4 www.greg-tut.com
O1 - Hosts: 127.0.0.4 nylonsexy.com
O1 - Hosts: 127.0.0.4 www.nylonsexy.com
O1 - Hosts: 127.0.0.4 vparivalka.com
O1 - Hosts: 127.0.0.4 www.vparivalka.com
O1 - Hosts: 127.0.0.4 iframeprofit.com
O1 - Hosts: 127.0.0.4 www.iframeprofit.com
O1 - Hosts: 127.0.0.4 topsearch10.com
O1 - Hosts: 127.0.0.4 www.topsearch10.com
O1 - Hosts: 127.0.0.4 statscash.biz
O1 - Hosts: 127.0.0.4 www.statscash.biz
O1 - Hosts: 127.0.0.4 vxiframe.biz
O1 - Hosts: 127.0.0.4 www.vxiframe.biz
O1 - Hosts: 127.0.0.4 crazy-toolbar.com
O1 - Hosts: 127.0.0.4 www.crazy-toolbar.com
O1 - Hosts: 127.0.0.4 topcash.biz
O1 - Hosts: 127.0.0.4 www.topcash.biz
O1 - Hosts: 127.0.0.4 loadcash.biz
O1 - Hosts: 127.0.0.4 www.loadcash.biz
O1 - Hosts: 127.0.0.4 txiframe.biz
O1 - Hosts: 127.0.0.4 www.txiframe.biz
O1 - Hosts: 127.0.0.4 procounter.biz
O1 - Hosts: 127.0.0.4 www.procounter.biz
O1 - Hosts: 127.0.0.4 advadmin.biz
O1 - Hosts: 127.0.0.4 www.advadmin.biz
O1 - Hosts: 127.0.0.4 trafficbest.net
O1 - Hosts: 127.0.0.4 www.trafficbest.net
O1 - Hosts: 127.0.0.4 besthvac.com
O1 - Hosts: 127.0.0.4 www.besthvac.com
O1 - Hosts: 127.0.0.4 traff4.com
O1 - Hosts: 127.0.0.4 www.traff4.com
O1 - Hosts: 127.0.0.4 ambush-script.com
O1 - Hosts: 127.0.0.4 www.ambush-script.com
O1 - Hosts: 127.0.0.4 beehappyy.biz
O1 - Hosts: 127.0.0.4 www.beehappyy.biz
O1 - Hosts: 127.0.0.4 tracktraff.cc
O1 - Hosts: 127.0.0.4 www.tracktraff.cc
O1 - Hosts: 127.0.0.4 allcount.net
O1 - Hosts: 127.0.0.4 www.allcount.net
O1 - Hosts: 127.0.0.4 onedayoffer.biz
O4 - HKLM\..\Run: [LaunchApp] LaunApp
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LaunchAp] C:\Progra~1\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [PowerKey] "C:\Progra~1\Launch Manager\PowerKey.exe"
O4 - HKLM\..\Run: [LManager] C:\Progra~1\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Progra~1\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Progra~1\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ecc] C:\Programfiler\Telenor\ecc\ecc.exe
O4 - HKLM\..\Run: [SysMemory manager] c:\windows\system32\mdms.exe
O4 - HKLM\..\Run: [IPVk] C:\WINDOWS\bjijc.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ChkMail] è<9
O4 - HKCU\..\Run: [LineOfSightVietnamSetup.exe] C:\DOCUME~1\ANETTE~1\SKRIVE~1\instl\LINEOF~1.EXE /r
O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe
O9 - Extra button: Expekt.com Poker - {3852AC86-965F-4abe-A75F-3DCB7E81A4B2} - C:\Programfiler\expektMPP\MPPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/M...pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: style32 - C:\WINDOWS\
O20 - Winlogon Notify: tcpG4T - tcpG4T.dll (file missing)
O20 - Winlogon Notify: WebCheck - C:\WINDOWS\system32\lvp0097me.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programfiler\Cisco Systems\VPN Client\cvpnd.exe

ANyone?? :)

Comments

  • TroganTrogan London, UK
    edited October 2005
    Please follow this guide:

    http://www.short-media.com/forum/showthread.php?t=32218


    Post a new HJT log after :)
  • edited October 2005
    done,
    here is my log now...


    Logfile of HijackThis v1.99.1
    Scan saved at 18:17:34, on 26.10.2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe
    C:\Programfiler\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\System32\CTSvcCDA.EXE
    C:\Programfiler\Cisco Systems\VPN Client\cvpnd.exe
    C:\WINDOWS\Explorer.EXE
    C:\Programfiler\ewido\security suite\ewidoctrl.exe
    C:\Programfiler\ewido\security suite\ewidoguard.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe
    C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
    C:\Progra~1\Launch Manager\LaunchAp.exe
    C:\Progra~1\Launch Manager\PowerKey.exe
    C:\Progra~1\Launch Manager\HotkeyApp.exe
    C:\Progra~1\Launch Manager\CtrlVol.exe
    C:\Progra~1\Launch Manager\Wbutton.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Programfiler\Telenor\ecc\ecc.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programfiler\Messenger\msmsgs.exe
    C:\Programfiler\MSN Messenger\MsnMsgr.Exe
    C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe
    C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Programfiler\Internet Explorer\iexplore.exe
    C:\Documents and Settings\anette vågslid\Skrivebord\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.vg.no.no/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
    O1 - Hosts: 127.0.0.4 n-glx.s-redirect.com
    O1 - Hosts: 127.0.0.4 x.full-tgp.net
    O1 - Hosts: 127.0.0.4 counter.sexmaniack.com
    O1 - Hosts: 127.0.0.4 autoescrowpay.com
    O1 - Hosts: 127.0.0.4 www.autoescrowpay.com
    O1 - Hosts: 127.0.0.4 www.awmdabest.com
    O1 - Hosts: 127.0.0.4 www.sexfiles.nu
    O1 - Hosts: 127.0.0.4 awmdabest.com
    O1 - Hosts: 127.0.0.4 sexfiles.nu
    O1 - Hosts: 127.0.0.4 allforadult.com
    O1 - Hosts: 127.0.0.4 www.allforadult.com
    O1 - Hosts: 127.0.0.4 www.iframe.biz
    O1 - Hosts: 127.0.0.4 iframe.biz
    O1 - Hosts: 127.0.0.4 www.newiframe.biz
    O1 - Hosts: 127.0.0.4 newiframe.biz
    O1 - Hosts: 127.0.0.4 www.vesbiz.biz
    O1 - Hosts: 127.0.0.4 vesbiz.biz
    O1 - Hosts: 127.0.0.4 www.pizdato.biz
    O1 - Hosts: 127.0.0.4 pizdato.biz
    O1 - Hosts: 127.0.0.4 www.aaasexypics.com
    O1 - Hosts: 127.0.0.4 aaasexypics.com
    O1 - Hosts: 127.0.0.4 www.virgin-tgp.net
    O1 - Hosts: 127.0.0.4 virgin-tgp.net
    O1 - Hosts: 127.0.0.4 www.awmcash.biz
    O1 - Hosts: 127.0.0.4 awmcash.biz
    O1 - Hosts: 127.0.0.4 buldog-stats.com
    O1 - Hosts: 127.0.0.4 www.buldog-stats.com
    O1 - Hosts: 127.0.0.4 fregat.drocherway.com
    O1 - Hosts: 127.0.0.4 slutmania.biz
    O1 - Hosts: 127.0.0.4 www.slutmania.biz
    O1 - Hosts: 127.0.0.4 toolbarpartner.com
    O1 - Hosts: 127.0.0.4 www.toolbarpartner.com
    O1 - Hosts: 127.0.0.4 www.megapornix.com
    O1 - Hosts: 127.0.0.4 megapornix.com
    O1 - Hosts: 127.0.0.4 www.sp2****ed.biz
    O1 - Hosts: 127.0.0.4 sp2****ed.biz
    O1 - Hosts: 127.0.0.4 greg-tut.com
    O1 - Hosts: 127.0.0.4 www.greg-tut.com
    O1 - Hosts: 127.0.0.4 nylonsexy.com
    O1 - Hosts: 127.0.0.4 www.nylonsexy.com
    O1 - Hosts: 127.0.0.4 vparivalka.com
    O1 - Hosts: 127.0.0.4 www.vparivalka.com
    O1 - Hosts: 127.0.0.4 iframeprofit.com
    O1 - Hosts: 127.0.0.4 www.iframeprofit.com
    O1 - Hosts: 127.0.0.4 topsearch10.com
    O1 - Hosts: 127.0.0.4 www.topsearch10.com
    O1 - Hosts: 127.0.0.4 statscash.biz
    O1 - Hosts: 127.0.0.4 www.statscash.biz
    O1 - Hosts: 127.0.0.4 vxiframe.biz
    O1 - Hosts: 127.0.0.4 www.vxiframe.biz
    O1 - Hosts: 127.0.0.4 crazy-toolbar.com
    O1 - Hosts: 127.0.0.4 www.crazy-toolbar.com
    O1 - Hosts: 127.0.0.4 topcash.biz
    O1 - Hosts: 127.0.0.4 www.topcash.biz
    O1 - Hosts: 127.0.0.4 loadcash.biz
    O1 - Hosts: 127.0.0.4 www.loadcash.biz
    O1 - Hosts: 127.0.0.4 txiframe.biz
    O1 - Hosts: 127.0.0.4 www.txiframe.biz
    O1 - Hosts: 127.0.0.4 procounter.biz
    O1 - Hosts: 127.0.0.4 www.procounter.biz
    O1 - Hosts: 127.0.0.4 advadmin.biz
    O1 - Hosts: 127.0.0.4 www.advadmin.biz
    O1 - Hosts: 127.0.0.4 trafficbest.net
    O1 - Hosts: 127.0.0.4 www.trafficbest.net
    O1 - Hosts: 127.0.0.4 besthvac.com
    O1 - Hosts: 127.0.0.4 www.besthvac.com
    O1 - Hosts: 127.0.0.4 traff4.com
    O1 - Hosts: 127.0.0.4 www.traff4.com
    O1 - Hosts: 127.0.0.4 ambush-script.com
    O1 - Hosts: 127.0.0.4 www.ambush-script.com
    O1 - Hosts: 127.0.0.4 beehappyy.biz
    O1 - Hosts: 127.0.0.4 www.beehappyy.biz
    O1 - Hosts: 127.0.0.4 tracktraff.cc
    O1 - Hosts: 127.0.0.4 www.tracktraff.cc
    O1 - Hosts: 127.0.0.4 allcount.net
    O1 - Hosts: 127.0.0.4 www.allcount.net
    O1 - Hosts: 127.0.0.4 onedayoffer.biz
    O4 - HKLM\..\Run: [LaunchApp] LaunApp
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [LaunchAp] C:\Progra~1\Launch Manager\LaunchAp.exe
    O4 - HKLM\..\Run: [PowerKey] "C:\Progra~1\Launch Manager\PowerKey.exe"
    O4 - HKLM\..\Run: [LManager] C:\Progra~1\Launch Manager\HotkeyApp.exe
    O4 - HKLM\..\Run: [CtrlVol] C:\Progra~1\Launch Manager\CtrlVol.exe
    O4 - HKLM\..\Run: [Wbutton] "C:\Progra~1\Launch Manager\Wbutton.exe"
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [ecc] C:\Programfiler\Telenor\ecc\ecc.exe
    O4 - HKLM\..\Run: [IPVk] C:\WINDOWS\bjijc.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ChkMail] è<9
    O4 - HKCU\..\Run: [LineOfSightVietnamSetup.exe] C:\DOCUME~1\ANETTE~1\SKRIVE~1\instl\LINEOF~1.EXE /r
    O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe
    O9 - Extra button: Expekt.com Poker - {3852AC86-965F-4abe-A75F-3DCB7E81A4B2} - C:\Programfiler\expektMPP\MPPoker.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: CSCSettings - C:\WINDOWS\system32\donmodem.dll
    O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\system32\n66qlgj516o.dll (file missing)
    O20 - Winlogon Notify: style32 - C:\WINDOWS\
    O20 - Winlogon Notify: tcpG4T - tcpG4T.dll (file missing)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programfiler\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Programfiler\ewido\security suite\ewidoctrl.exe
    O23 - Service: ewido security suite guard - ewido networks - C:\Programfiler\ewido\security suite\ewidoguard.exe
  • TroganTrogan London, UK
    edited October 2005
    Please move HJT to its own folder on your C: so backups can be created. Do this before continuing.
    ===

    Check the following in HJT and click 'Fix Checked'

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.vg.no.no/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

    O1 - Hosts: 127.0.0.4 n-glx.s-redirect.com
    O1 - Hosts: 127.0.0.4 x.full-tgp.net
    O1 - Hosts: 127.0.0.4 counter.sexmaniack.com
    O1 - Hosts: 127.0.0.4 autoescrowpay.com
    O1 - Hosts: 127.0.0.4 www.autoescrowpay.com
    O1 - Hosts: 127.0.0.4 www.awmdabest.com
    O1 - Hosts: 127.0.0.4 www.sexfiles.nu
    O1 - Hosts: 127.0.0.4 awmdabest.com
    O1 - Hosts: 127.0.0.4 sexfiles.nu
    O1 - Hosts: 127.0.0.4 allforadult.com
    O1 - Hosts: 127.0.0.4 www.allforadult.com
    O1 - Hosts: 127.0.0.4 www.iframe.biz
    O1 - Hosts: 127.0.0.4 iframe.biz
    O1 - Hosts: 127.0.0.4 www.newiframe.biz
    O1 - Hosts: 127.0.0.4 newiframe.biz
    O1 - Hosts: 127.0.0.4 www.vesbiz.biz
    O1 - Hosts: 127.0.0.4 vesbiz.biz
    O1 - Hosts: 127.0.0.4 www.pizdato.biz
    O1 - Hosts: 127.0.0.4 pizdato.biz
    O1 - Hosts: 127.0.0.4 www.aaasexypics.com
    O1 - Hosts: 127.0.0.4 aaasexypics.com
    O1 - Hosts: 127.0.0.4 www.virgin-tgp.net
    O1 - Hosts: 127.0.0.4 virgin-tgp.net
    O1 - Hosts: 127.0.0.4 www.awmcash.biz
    O1 - Hosts: 127.0.0.4 awmcash.biz
    O1 - Hosts: 127.0.0.4 buldog-stats.com
    O1 - Hosts: 127.0.0.4 www.buldog-stats.com
    O1 - Hosts: 127.0.0.4 fregat.drocherway.com
    O1 - Hosts: 127.0.0.4 slutmania.biz
    O1 - Hosts: 127.0.0.4 www.slutmania.biz
    O1 - Hosts: 127.0.0.4 toolbarpartner.com
    O1 - Hosts: 127.0.0.4 www.toolbarpartner.com
    O1 - Hosts: 127.0.0.4 www.megapornix.com
    O1 - Hosts: 127.0.0.4 megapornix.com
    O1 - Hosts: 127.0.0.4 www.sp2****ed.biz
    O1 - Hosts: 127.0.0.4 sp2****ed.biz
    O1 - Hosts: 127.0.0.4 greg-tut.com
    O1 - Hosts: 127.0.0.4 www.greg-tut.com
    O1 - Hosts: 127.0.0.4 nylonsexy.com
    O1 - Hosts: 127.0.0.4 www.nylonsexy.com
    O1 - Hosts: 127.0.0.4 vparivalka.com
    O1 - Hosts: 127.0.0.4 www.vparivalka.com
    O1 - Hosts: 127.0.0.4 iframeprofit.com
    O1 - Hosts: 127.0.0.4 www.iframeprofit.com
    O1 - Hosts: 127.0.0.4 topsearch10.com
    O1 - Hosts: 127.0.0.4 www.topsearch10.com
    O1 - Hosts: 127.0.0.4 statscash.biz
    O1 - Hosts: 127.0.0.4 www.statscash.biz
    O1 - Hosts: 127.0.0.4 vxiframe.biz
    O1 - Hosts: 127.0.0.4 www.vxiframe.biz
    O1 - Hosts: 127.0.0.4 crazy-toolbar.com
    O1 - Hosts: 127.0.0.4 www.crazy-toolbar.com
    O1 - Hosts: 127.0.0.4 topcash.biz
    O1 - Hosts: 127.0.0.4 www.topcash.biz
    O1 - Hosts: 127.0.0.4 loadcash.biz
    O1 - Hosts: 127.0.0.4 www.loadcash.biz
    O1 - Hosts: 127.0.0.4 txiframe.biz
    O1 - Hosts: 127.0.0.4 www.txiframe.biz
    O1 - Hosts: 127.0.0.4 procounter.biz
    O1 - Hosts: 127.0.0.4 www.procounter.biz
    O1 - Hosts: 127.0.0.4 advadmin.biz
    O1 - Hosts: 127.0.0.4 www.advadmin.biz
    O1 - Hosts: 127.0.0.4 trafficbest.net
    O1 - Hosts: 127.0.0.4 www.trafficbest.net
    O1 - Hosts: 127.0.0.4 besthvac.com
    O1 - Hosts: 127.0.0.4 www.besthvac.com
    O1 - Hosts: 127.0.0.4 traff4.com
    O1 - Hosts: 127.0.0.4 www.traff4.com
    O1 - Hosts: 127.0.0.4 ambush-script.com
    O1 - Hosts: 127.0.0.4 www.ambush-script.com
    O1 - Hosts: 127.0.0.4 beehappyy.biz
    O1 - Hosts: 127.0.0.4 www.beehappyy.biz
    O1 - Hosts: 127.0.0.4 tracktraff.cc
    O1 - Hosts: 127.0.0.4 www.tracktraff.cc
    O1 - Hosts: 127.0.0.4 allcount.net
    O1 - Hosts: 127.0.0.4 www.allcount.net
    O1 - Hosts: 127.0.0.4 onedayoffer.biz

    O4 - HKLM\..\Run: [LaunchApp] LaunApp
    ===

    Post a new HJT :)
  • edited October 2005
    Logfile of HijackThis v1.99.1
    Scan saved at 21:05:24, on 27.10.2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe
    C:\Programfiler\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\System32\CTSvcCDA.EXE
    C:\Programfiler\Cisco Systems\VPN Client\cvpnd.exe
    C:\Programfiler\ewido\security suite\ewidoctrl.exe
    C:\Programfiler\Spyware Doctor\sdhelp.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe
    C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
    C:\Progra~1\Launch Manager\LaunchAp.exe
    C:\Progra~1\Launch Manager\PowerKey.exe
    C:\Progra~1\Launch Manager\HotkeyApp.exe
    C:\Progra~1\Launch Manager\CtrlVol.exe
    C:\Progra~1\Launch Manager\Wbutton.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Programfiler\Telenor\ecc\ecc.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programfiler\Messenger\msmsgs.exe
    C:\Programfiler\MSN Messenger\MsnMsgr.Exe
    C:\Programfiler\Spyware Doctor\swdoctor.exe
    C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe
    C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe
    C:\Programfiler\Internet Explorer\iexplore.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRAMFILER\INTERNET EXPLORER\IEXPLORE.EXE
    C:\Programfiler\Azureus\Azureus.exe
    C:\Programfiler\Java\jre1.5.0_05\bin\javaw.exe
    C:\PROGRAMFILER\INTERNET EXPLORER\IEXPLORE.EXE
    C:\hijackthis\HijackThis.exe
    C:\WINDOWS\system32\NOTEPAD.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.vg.no
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [LaunchAp] C:\Progra~1\Launch Manager\LaunchAp.exe
    O4 - HKLM\..\Run: [PowerKey] "C:\Progra~1\Launch Manager\PowerKey.exe"
    O4 - HKLM\..\Run: [LManager] C:\Progra~1\Launch Manager\HotkeyApp.exe
    O4 - HKLM\..\Run: [CtrlVol] C:\Progra~1\Launch Manager\CtrlVol.exe
    O4 - HKLM\..\Run: [Wbutton] "C:\Progra~1\Launch Manager\Wbutton.exe"
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [ecc] C:\Programfiler\Telenor\ecc\ecc.exe
    O4 - HKLM\..\Run: [IPVk] C:\WINDOWS\bjijc.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programfiler\Java\jre1.5.0_05\bin\jusched.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ChkMail] è<9
    O4 - HKCU\..\Run: [LineOfSightVietnamSetup.exe] C:\DOCUME~1\ANETTE~1\SKRIVE~1\instl\LINEOF~1.EXE /r
    O4 - HKCU\..\Run: [Spyware Doctor] "C:\Programfiler\Spyware Doctor\swdoctor.exe" /Q
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O9 - Extra button: Expekt.com Poker - {3852AC86-965F-4abe-A75F-3DCB7E81A4B2} - C:\Programfiler\expektMPP\MPPoker.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Programfiler\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\system32\n66qlgj516o.dll (file missing)
    O20 - Winlogon Notify: SharedDLLs - C:\WINDOWS\system32\j60slgd7160.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programfiler\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Programfiler\ewido\security suite\ewidoctrl.exe
    O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Programfiler\Spyware Doctor\sdhelp.exe
  • TroganTrogan London, UK
    edited October 2005
    Follow this guide here and download Ad-Aware SE and SpyBot Search & Destroy. Check for updates on both and then do a full system scan.

    Post a new HJT log. How are things now?
Sign In or Register to comment.