robbob
2006-07-14, 13:52
Hi Gang,
After following your instructions I can now produce the following logs:
Hijack this:
Logfile of HijackThis v1.99.1
Scan saved at 8:46:50 PM, on 14/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Utils\D-Tools\daemon.exe
C:\WINDOWS\system32\6e9f40f1.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Games\Valve\Steam\Steam.exe
C:\PROGRA~1\FNTS~1\dexplore.exe
C:\Program Files\Xfire\Xfire.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\HijackThis\hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {01007648-CDD5-BF06-AB14-9B1C819DB692} - C:\WINDOWS\system32\boch.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {53DF202C-99E6-EB30-CCE9-91FC5FF0E090} - C:\WINDOWS\system32\izla.dll
O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - C:\WINDOWS\system32\ixt0.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Utils\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [6e9f40f1.exe] C:\WINDOWS\system32\6e9f40f1.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [Steam] C:\Games\Valve\Steam\\Steam.exe -silent
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Acmp] "C:\PROGRA~1\FNTS~1\dexplore.exe" -vt yazr
O4 - HKCU\..\Run: [6e9f40f1.exe] C:\Documents and Settings\Administrator\Local Settings\Application Data\6e9f40f1.exe
O4 - HKCU\..\Run: [zfuf] C:\PROGRA~1\COMMON~1\zfuf\zfufm.exe
O4 - HKCU\..\Run: [Qgo] C:\Program Files\Common Files\??sembly\n?tepad.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: winhdn32 - C:\WINDOWS\SYSTEM32\winhdn32.dll
O21 - SSODL: cinnamomum - {93ac7c30-3878-4eaa-9420-7977285df5b1} - C:\WINDOWS\system32\pmnqguh.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Online scan log:
Incident Status Location
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\4hev7qb2.default\cookies.txt[.atdmt.com/]
Adware:adware/securityerror Not disinfected C:\Documents and Settings\Administrator\Favorites\Antivirus Test Online.url
Adware:Adware/SystemDoctor Not disinfected C:\Documents and Settings\Administrator\Local Settings\Application Data\6e9f40f1.exe
Spyware:spyware/surfsidekick Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Ssk.log
Adware:Adware/PurityScan Not disinfected C:\Program Files\F?nts\dexplore.exe
Adware:Adware/SystemDoctor Not disinfected C:\WINDOWS\system32\6e9f40f1.exe
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\system32\bjrrzcz.dll
Adware:Adware/SpywareQuake Not disinfected C:\WINDOWS\system32\components\flx5.dll
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\system32\izla.dll
Adware:adware/mediatickets Not disinfected C:\WINDOWS\system32\oins.exe
Adware:Adware/YazzleSudoku Not disinfected C:\WINDOWS\system32\winhdn32.dll
Virus:Trj/DNSChanger.GG Disinfected C:\WINDOWS\temp\win1B6.tmp.exe
Adware:Adware/CommAd Not disinfected C:\WINDOWS\Um9iZXJ0bw\asappsrv.dll
Adware:Adware/CommAd Not disinfected C:\WINDOWS\Um9iZXJ0bw\command.exe
Adware:Adware/CommAd Not disinfected C:\WINDOWS\Um9iZXJ0bw\oA62trLXvT.vbs
Adware:Adware/IST.ISTBar Not disinfected C:\WINDOWS\winres.dll
Potentially unwanted tool:Application/Processor Not disinfected E:\Essentials\Tools\virus removal\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected E:\Essentials\Tools\virus removal\smitRem.exe[smitRem/Process.exe]
Thanks a bunch for your help!:bigthumb:
After following your instructions I can now produce the following logs:
Hijack this:
Logfile of HijackThis v1.99.1
Scan saved at 8:46:50 PM, on 14/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Utils\D-Tools\daemon.exe
C:\WINDOWS\system32\6e9f40f1.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Games\Valve\Steam\Steam.exe
C:\PROGRA~1\FNTS~1\dexplore.exe
C:\Program Files\Xfire\Xfire.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\HijackThis\hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {01007648-CDD5-BF06-AB14-9B1C819DB692} - C:\WINDOWS\system32\boch.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {53DF202C-99E6-EB30-CCE9-91FC5FF0E090} - C:\WINDOWS\system32\izla.dll
O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - C:\WINDOWS\system32\ixt0.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Utils\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [6e9f40f1.exe] C:\WINDOWS\system32\6e9f40f1.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [Steam] C:\Games\Valve\Steam\\Steam.exe -silent
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Acmp] "C:\PROGRA~1\FNTS~1\dexplore.exe" -vt yazr
O4 - HKCU\..\Run: [6e9f40f1.exe] C:\Documents and Settings\Administrator\Local Settings\Application Data\6e9f40f1.exe
O4 - HKCU\..\Run: [zfuf] C:\PROGRA~1\COMMON~1\zfuf\zfufm.exe
O4 - HKCU\..\Run: [Qgo] C:\Program Files\Common Files\??sembly\n?tepad.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: winhdn32 - C:\WINDOWS\SYSTEM32\winhdn32.dll
O21 - SSODL: cinnamomum - {93ac7c30-3878-4eaa-9420-7977285df5b1} - C:\WINDOWS\system32\pmnqguh.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Online scan log:
Incident Status Location
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\4hev7qb2.default\cookies.txt[.atdmt.com/]
Adware:adware/securityerror Not disinfected C:\Documents and Settings\Administrator\Favorites\Antivirus Test Online.url
Adware:Adware/SystemDoctor Not disinfected C:\Documents and Settings\Administrator\Local Settings\Application Data\6e9f40f1.exe
Spyware:spyware/surfsidekick Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Ssk.log
Adware:Adware/PurityScan Not disinfected C:\Program Files\F?nts\dexplore.exe
Adware:Adware/SystemDoctor Not disinfected C:\WINDOWS\system32\6e9f40f1.exe
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\system32\bjrrzcz.dll
Adware:Adware/SpywareQuake Not disinfected C:\WINDOWS\system32\components\flx5.dll
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\system32\izla.dll
Adware:adware/mediatickets Not disinfected C:\WINDOWS\system32\oins.exe
Adware:Adware/YazzleSudoku Not disinfected C:\WINDOWS\system32\winhdn32.dll
Virus:Trj/DNSChanger.GG Disinfected C:\WINDOWS\temp\win1B6.tmp.exe
Adware:Adware/CommAd Not disinfected C:\WINDOWS\Um9iZXJ0bw\asappsrv.dll
Adware:Adware/CommAd Not disinfected C:\WINDOWS\Um9iZXJ0bw\command.exe
Adware:Adware/CommAd Not disinfected C:\WINDOWS\Um9iZXJ0bw\oA62trLXvT.vbs
Adware:Adware/IST.ISTBar Not disinfected C:\WINDOWS\winres.dll
Potentially unwanted tool:Application/Processor Not disinfected E:\Essentials\Tools\virus removal\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected E:\Essentials\Tools\virus removal\smitRem.exe[smitRem/Process.exe]
Thanks a bunch for your help!:bigthumb: