Options

Help me fix adware and spyware

I have trouble with adware that creates virus arler and lead Internet Exporer browser to some website. This website surgest to pay them for remove virus.
Here is HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 10:15:41 AM, on 6/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\atievxx.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\libusbd-nt.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\dcomcfg.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\Bkav2006\Bkav2006.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\AcroDist.exe
C:\PROGRA~1\FONEVN~1\FoneVNN Dialer.exe
C:\Program Files\Wireless LAN\WLAN CardBus Utility\WLAN_UI.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\DOCUME~1\KHANHN~1\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\WINDOWS\system32\atmclk.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\khanh ngoc\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Nothing - {686a161d-5bd1-4999-8832-6393f41e564c} - C:\WINDOWS\system32\hp100.tmp
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [TradeManager] C:\PROGRA~1\ALIBABA\TRADEM~1\TradeManager -hideframe
O4 - HKLM\..\Run: [BkavFw] C:\Program Files\Bkav2006\Bkav2006.exe TASKBAR
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [] C:\PROGRA~1\FONEVN~1\FoneVNN Dialer.exe -auto
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [b8ce8d9f.exe] C:\Documents and Settings\khanh ngoc\Local Settings\Application Data\b8ce8d9f.exe
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: WLAN CardBus Utility.lnk = C:\Program Files\Wireless LAN\WLAN CardBus Utility\WLAN_UI.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Add to &Teleport - C:\Program Files\Teleport Pro\teleport.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download all by Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.offshoreclicks.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {77AAD261-A84E-4564-BEC2-C51FF6A7187F} (MRActivXUI Class) - http://202.8.40.133/comp/partner/pcphone/ver6.1.2.0/wbaxuiph612.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: winyoc32 - winyoc32.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - http://libusb-win32.sourceforge.net - C:\WINDOWS\system32\libusbd-nt.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe

And bellow is:
ewido anti-malware - Scan report

+ Created on: 2:25:52 AM, 6/14/2006
+ Report-Checksum: 1E32BE9

+ Scan result:

[220] C:\WINDOWS\system32\winyoc32.dll -> Trojan.Agent.vg : Cleaned with backup
C:\WINDOWS\system32\winyoc32.dll -> Trojan.Agent.vg : Cleaned with backup
C:\WINDOWS\system32\b8ce8d9f.exe -> Downloader.Obfuscated.a : Cleaned with backup
C:\WINDOWS\system32\1024 -> Trojan.Small : Cleaned with backup
C:\WINDOWS\system32\1024\ldDA87.tmp -> Trojan.Small : Cleaned with backup
C:\WINDOWS\system32\1024\ld1BDD.tmp -> Trojan.Small : Cleaned with backup
C:\WINDOWS\system32\atmclk.exe -> Trojan.Small : Cleaned with backup
C:\WINDOWS\Temp\win48.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup
C:\WINDOWS\Temp\win4B.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup
C:\WINDOWS\Temp\win54.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Local Settings\Temp\cli78.tmp -> Trojan.Agent.vg : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Local Settings\Temp\win7A.tmp.exe -> Downloader.Obfuscated.a : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Local Settings\Temp\win7C.tmp.exe -> Hijacker.Small : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Local Settings\Temp\win81.tmp.exe -> Downloader.IstBar.eq : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Local Settings\Temp\win86.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Local Settings\Temp\OA.exe -> Downloader.PurityScan.cq : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Local Settings\Temporary Internet Files\Content.IE5\1MNHQ0SW\wlzip32[1].exe -> Downloader.Obfuscated.a : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Local Settings\Temporary Internet Files\Content.IE5\1MNHQ0SW\wizp32[1].exe -> Downloader.IstBar.eq : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Local Settings\Temporary Internet Files\Content.IE5\1MNHQ0SW\srvfny[1].exe -> Trojan.Dialer.oy : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Local Settings\Temporary Internet Files\Content.IE5\1MNHQ0SW\srvlqu[1].exe -> Trojan.Dialer.oy : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Local Settings\Temporary Internet Files\Content.IE5\9I4CEBVD\srvbua[1].exe -> Trojan.Dialer.oy : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Local Settings\Temporary Internet Files\Content.IE5\1223PIMG\mulbin32[1].exe -> Hijacker.Small : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Local Settings\Temporary Internet Files\Content.IE5\1223PIMG\srvrdg[1].exe -> Trojan.Dialer.oy : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Local Settings\Temporary Internet Files\Content.IE5\1223PIMG\wizip32[1].exe -> Hijacker.Small.kx : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Local Settings\Application Data\b8ce8d9f.exe -> Downloader.Obfuscated.a : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Cookies\khanh [email]ngoc@www.myaffiliateprogram[1].txt[/email] -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Cookies\khanh [email]ngoc@weborama[2].txt[/email] -> TrackingCookie.Weborama : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Cookies\khanh [email]ngoc@adopt.euroclick[1].txt[/email] -> TrackingCookie.Euroclick : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Cookies\khanh [email]ngoc@clickbank[1].txt[/email] -> TrackingCookie.Clickbank : Cleaned with backup
C:\Documents and Settings\khanh ngoc\Cookies\khanh [email]ngoc@rotator.adjuggler[1].txt[/email] -> TrackingCookie.Adjuggler : Cleaned with backup
C:\Program Files\Common Files\Y1123OA.exe -> Downloader.PurityScan.cq : Cleaned with backup
D:\Documents and Settings\Thanh Van\My Skype Received Files\FlashGet.v1.71 Final.CR.zip/CR/twk-flashget171patch_ttdown.com.exe -> Downloader.Harnig.bq : Cleaned with backup


::Report End
Thank you in advance.
Vietguy

Comments

  • airbornflghtairbornflght Houston, TX Icrontian
    edited June 2006
    Which website is it. is it Spyfalcon? I have taken that off of 3 peoples computers in the lst 2 weeks, that thing is a major pita.
Sign In or Register to comment.