It's got mie this time

First, you guys are awsome and provide an amazing service, especialy to us not so literate computer users.
We are not able to access IE or Mozilla, I am only able to communicate with you through Netscape. The kids told me that it started with IE first although they could not search some sites such as ebay with Mozilla, eventually it blocked Mozilla also. I have run AVG scanner, Spybot, Kaspersky, and A-Squared but only came up with "Double Click Cookie". I have included the hijack Log. Thanks again for your help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:59:30 AM, on 11/2/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
c:\program files\a-squared free\a2service.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Documents and Settings\fred\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dogpile.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:80
O1 - Hosts: 7.0.0.1 www.google.cn
O1 - Hosts: 127.ogle.ms
O1 - Hosts: se
O1 - Hosts: .com
O1 - Hosts: 0
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [WindowsRegKey update] winupdate.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [WindowsRegKey update] winupdate.exe (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1201659040718
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

--
End of file - 3932 bytes

Comments

  • VekaVeka Finland
    edited November 2008
    Hello snowcat.

    I must warn you right away: Your computer is infected with a worm that have backdoor capabilities. This means that it has a built-in IRC client engine, which enables it to connect to a remote IRC server and channel. It then listens for commands from the remote user.

    More information about the infection from here

    In situations like this, I always recommend formatting the entire hard drive. It's the best way to get rid of it and make sure the computer is safe. Of course it might be possible to clean out the infection, but there is no any guarantee of it. Neither we can't be sure that your computer will be safe and secure again.

    Please let me know about your decision.
  • edited November 2008
    vekarppe wrote:
    Hello snowcat.

    I must warn you right away: Your computer is infected with a worm that have backdoor capabilities. This means that it has a built-in IRC client engine, which enables it to connect to a remote IRC server and channel. It then listens for commands from the remote user.

    More information about the infection from here

    In situations like this, I always recommend formatting the entire hard drive. It's the best way to get rid of it and make sure the computer is safe. Of course it might be possible to clean out the infection, but there is no any guarantee of it. Neither we can't be sure that your computer will be safe and secure again.

    Please let me know about your decision.

    I default to your expertise, if we reformat the hard drive, we would loose every thing that is not backed up, correct? I admit I have been lax.
  • VekaVeka Finland
    edited November 2008
    Yea, that's correct. Backup all important data before formating.
  • edited November 2008
    vekarppe wrote:
    Yea, that's correct. Backup all important data before formating.

    Every thing is backed up.
  • VekaVeka Finland
    edited November 2008
    Hi snowcat. How is your computer running? :)
  • VekaVeka Finland
    edited December 2008
    Glad we could be of assistance! The help you received here was free.

    This topic is now closed. If you wish it reopened, please send a Private Message to Trogan with a link to your thread.

    If you are not the user who started this thread, you must start your own Thread instead :)
    _______________________________
    Have we helped you with any issues you have had with your PCs or other items? If so, you can now help us by Joining Team 93 and fold for a cure.
Sign In or Register to comment.