brokencomputer
New member
I am getting that same yahabags problem i have seen among other users; when i click a link from google, i will often get routed to yahabags and then to some other site. if i hit back enough to get back to google and re-select the link, it works just fine.
I have followed the precedures and run S & D in safe mode, i tried to do the panda search but after over an hour, it was only a quarter done so i gave up, is this normal? If it is necessary, i will go back and complete that. below is my log from hijack this.
Also (and i'm not sure if this problem is related or not), when i boot up my computer, i will go to Internet Explorer and the program will open, but within 5 seconds or so (perhaps on mouse movement, it's hard to tell), it will automatically close with no error message or anything. This does not always happen, but does often. Other times, it will freeze. If i keep restarting the computer, after several tries, i can eventually get it to work.
Logfile of HijackThis v1.99.1
Scan saved at 10:32:04 PM, on 12/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\system32\dvdupgrd.exe
C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\gabe\Desktop\hijack\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify2?.done=http://fantasysports.yahoo.com&.src=spt&.intl=us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: CIEPl Object - {6BB18EFE-F2C7-457C-81FE-705757171FA0} - C:\WINDOWS\System32\bin32.dll
O2 - BHO: (no name) - {E9E581B8-AC6A-4C56-A779-A8BEA2C651D6} - C:\WINDOWS\system32\nedblrbs.dll
O2 - BHO: (no name) - {FA641CC3-C739-427C-A624-49273628CB57} - C:\WINDOWS\system32\cjayspfu.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DVDUpgrade] DVDUpgrd.exe /async9x
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Smart Wizard Wireless Settings.lnk = C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Gabe\IM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Fleet - http://download2.games.yahoo.com/games/clients/y/fltt3_x.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MT...ehicles/2005/prius/key_features/pc/index.html
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/103p/html/gtdownlr.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1153440767407
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153440759525
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B2FCED61-570E-11D3-B160-00A0C9E70E84} (OmniForm Form Control) - https://www4.lsac.org/LSACD_XMLWebServices/Http/OIFActiveX/ofmctl.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/games/web_games/tikgames/cinematycoon/cinematycoon.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O20 - Winlogon Notify: bin32 - C:\WINDOWS\SYSTEM32\bin32.dll
O20 - Winlogon Notify: bwebnkfe - bwebnkfe.dll (file missing)
O20 - Winlogon Notify: eevbamom - eevbamom.dll (file missing)
O20 - Winlogon Notify: fjbpgdpq - fjbpgdpq.dll (file missing)
O20 - Winlogon Notify: insagqvy - insagqvy.dll (file missing)
O20 - Winlogon Notify: mecawykn - mecawykn.dll (file missing)
O20 - Winlogon Notify: ojuqplxh - ojuqplxh.dll (file missing)
O20 - Winlogon Notify: pymqaylr - pymqaylr.dll (file missing)
O20 - Winlogon Notify: qrpqpaxq - qrpqpaxq.dll (file missing)
O20 - Winlogon Notify: shmqklbo - shmqklbo.dll (file missing)
O20 - Winlogon Notify: skwhusyc - skwhusyc.dll (file missing)
O20 - Winlogon Notify: tqrjtnyv - tqrjtnyv.dll (file missing)
O20 - Winlogon Notify: ttggmmxr - ttggmmxr.dll (file missing)
O20 - Winlogon Notify: urixtnqp - urixtnqp.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: wrendghf - wrendghf.dll (file missing)
O20 - Winlogon Notify: wvuyvnke - wvuyvnke.dll (file missing)
O20 - Winlogon Notify: xqyrrwxu - xqyrrwxu.dll (file missing)
O20 - Winlogon Notify: xxjsymgb - xxjsymgb.dll (file missing)
O20 - Winlogon Notify: ympbrtue - ympbrtue.dll (file missing)
O21 - SSODL: IEFilter - {8BE61E77-3194-48AC-B0EF-51F23432C67C} - C:\WINDOWS\system32\IEFilter.dll (file missing)
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
Thanks in advance for your help. I am eager to follow the steps necessary to remove this nasty bug.
I have followed the precedures and run S & D in safe mode, i tried to do the panda search but after over an hour, it was only a quarter done so i gave up, is this normal? If it is necessary, i will go back and complete that. below is my log from hijack this.
Also (and i'm not sure if this problem is related or not), when i boot up my computer, i will go to Internet Explorer and the program will open, but within 5 seconds or so (perhaps on mouse movement, it's hard to tell), it will automatically close with no error message or anything. This does not always happen, but does often. Other times, it will freeze. If i keep restarting the computer, after several tries, i can eventually get it to work.
Logfile of HijackThis v1.99.1
Scan saved at 10:32:04 PM, on 12/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\system32\dvdupgrd.exe
C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\gabe\Desktop\hijack\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify2?.done=http://fantasysports.yahoo.com&.src=spt&.intl=us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: CIEPl Object - {6BB18EFE-F2C7-457C-81FE-705757171FA0} - C:\WINDOWS\System32\bin32.dll
O2 - BHO: (no name) - {E9E581B8-AC6A-4C56-A779-A8BEA2C651D6} - C:\WINDOWS\system32\nedblrbs.dll
O2 - BHO: (no name) - {FA641CC3-C739-427C-A624-49273628CB57} - C:\WINDOWS\system32\cjayspfu.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DVDUpgrade] DVDUpgrd.exe /async9x
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Smart Wizard Wireless Settings.lnk = C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Gabe\IM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Fleet - http://download2.games.yahoo.com/games/clients/y/fltt3_x.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MT...ehicles/2005/prius/key_features/pc/index.html
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/103p/html/gtdownlr.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1153440767407
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153440759525
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B2FCED61-570E-11D3-B160-00A0C9E70E84} (OmniForm Form Control) - https://www4.lsac.org/LSACD_XMLWebServices/Http/OIFActiveX/ofmctl.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/games/web_games/tikgames/cinematycoon/cinematycoon.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O20 - Winlogon Notify: bin32 - C:\WINDOWS\SYSTEM32\bin32.dll
O20 - Winlogon Notify: bwebnkfe - bwebnkfe.dll (file missing)
O20 - Winlogon Notify: eevbamom - eevbamom.dll (file missing)
O20 - Winlogon Notify: fjbpgdpq - fjbpgdpq.dll (file missing)
O20 - Winlogon Notify: insagqvy - insagqvy.dll (file missing)
O20 - Winlogon Notify: mecawykn - mecawykn.dll (file missing)
O20 - Winlogon Notify: ojuqplxh - ojuqplxh.dll (file missing)
O20 - Winlogon Notify: pymqaylr - pymqaylr.dll (file missing)
O20 - Winlogon Notify: qrpqpaxq - qrpqpaxq.dll (file missing)
O20 - Winlogon Notify: shmqklbo - shmqklbo.dll (file missing)
O20 - Winlogon Notify: skwhusyc - skwhusyc.dll (file missing)
O20 - Winlogon Notify: tqrjtnyv - tqrjtnyv.dll (file missing)
O20 - Winlogon Notify: ttggmmxr - ttggmmxr.dll (file missing)
O20 - Winlogon Notify: urixtnqp - urixtnqp.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: wrendghf - wrendghf.dll (file missing)
O20 - Winlogon Notify: wvuyvnke - wvuyvnke.dll (file missing)
O20 - Winlogon Notify: xqyrrwxu - xqyrrwxu.dll (file missing)
O20 - Winlogon Notify: xxjsymgb - xxjsymgb.dll (file missing)
O20 - Winlogon Notify: ympbrtue - ympbrtue.dll (file missing)
O21 - SSODL: IEFilter - {8BE61E77-3194-48AC-B0EF-51F23432C67C} - C:\WINDOWS\system32\IEFilter.dll (file missing)
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
Thanks in advance for your help. I am eager to follow the steps necessary to remove this nasty bug.