hey its you again!
now i am try to clean up another computer of mine (my girlfriend's)
yes.. i do have spyware blaster installed
and of course.. i also have spybot.. 1.3.1
by the way.. thax for the prior post.. now i think my comp is runnin fine
and here is the spybot log for the second computer! (HJT log is the second computer not the first)
--- Search result list ---
ISearchTech.PowerScan: Settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\BandRest
Altnet: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Altnet
Altnet: Root class (Registry key, nothing done)
HKEY_CLASSES_ROOT\ADM25.ADM25
Altnet: Root class (Registry key, nothing done)
HKEY_CLASSES_ROOT\ADM4.ADM4
WildMedia: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{E8EAEB34-F7B5-4C55-87FF-720FAF53D841}
WildMedia: Root class (Registry key, nothing done)
HKEY_CLASSES_ROOT\SearchHelp
WildMedia: Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E8EAEB34-F7B5-4C55-87FF-720FAF53D841}
--- Spybot - Search & Destroy version: 1.3 .1TX (build: 20040801) ---
2004-05-12 blindman.exe (1.0.0.0)
2004-08-30 SpybotSD.exe (1.3.0.12)
2004-05-12 TeaTimer.exe (1.3.0.12)
2004-06-15 unins000.exe (51.15.0.0)
2004-05-12 Update.exe (1.3.0.0)
2004-10-04 advcheck.dll (1.0.1.0)
2004-05-12 borlndmm.dll (7.0.4.453)
2004-05-12 delphimm.dll (7.0.4.453)
2004-05-12 Tools.dll (2.0.0.0)
2004-05-12 UnzDll.dll (1.73.1.1)
2004-05-12 ZipDll.dll (1.73.2.0)
2004-11-29 Includes\Cookies.sbi
2005-01-04 Includes\Dialer.sbi
2005-01-04 Includes\Hijackers.sbi
2004-12-29 Includes\Keyloggers.sbi
2004-05-12 Includes\LSP.sbi
2005-01-04 Includes\Malware.sbi
2004-08-11 Includes\plugin-ignore.ini
2003-11-12 Includes\QA Tests.sbi
2004-11-29 Includes\Revision.sbi
2004-11-29 Includes\Security.sbi
2005-01-05 Includes\Spybots.sbi
2003-11-21 Includes\Temporary.sbi
2004-11-29 Includes\Tracks.uti
2005-01-04 Includes\Trojans.sbi
--- System information ---
Windows XP (Build: 2600) Service Pack 2
/ DataAccess: Microsoft Data Access Components KB870669
/ DataAccess: Security update for Microsoft Data Access Components
/ DataAccess: Security Update for Microsoft Data Access Components
/ DirectX: DirectX Update 819696
/ DirectX / DX9 / SP1: DirectX 9 Hotfix - KB839643
/ Windows Media Player / SP0: Windows Media Player Hotfix [See wm828026 for more information]
/ Windows Media Player: Windows Media Update 817787
/ Windows Media Player: Windows Media Update 819639
/ Windows Media Player: Windows Media Update 828026
/ Windows XP / SP2: Windows XP Service Pack 2
/ Windows XP / SP3: Windows XP Hotfix - KB834707
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB885884
/ Windows XP / SP3: Windows XP Hotfix - KB886185
/ Windows XP / SP3: Windows XP Hotfix - KB890175
--- Startup entries list ---
Located: HK_LM:Run, ccApp
command: "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
file: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
size: 66680
MD5: 371d2fa0dfeb9767b3cc7cae1ab21a5a
Located: HK_LM:Run, DwlClient
command: C:\Program Files\Common Files\Dell\EUSW\Support.exe
file: C:\Program Files\Common Files\Dell\EUSW\Support.exe
size: 245760
MD5: 58cd30203ddb67fad6a34aa624fa0141
Located: HK_LM:Run, E1K9H
command: C:\documents and settings\fish\local settings\temp\E1K9H.exe
file: C:\documents and settings\fish\local settings\temp\E1K9H.exe
size: 200770
MD5: 6b829bd4a420ba00794fe6f87cbfcd03
Located: HK_LM:Run, eNVzIb
command: C:\documents and settings\fish\local settings\temp\eNVzIb.exe
file: C:\documents and settings\fish\local settings\temp\eNVzIb.exe
size: 200908
MD5: cf1b6119a8d213702dbc6d754b85e81b
Located: HK_LM:Run, HotKeysCmds
command: C:\WINDOWS\System32\hkcmd.exe
file: C:\WINDOWS\System32\hkcmd.exe
size: 114688
MD5: 3a9978c5caec77771ff28eb7a3889639
Located: HK_LM:Run, hwlrwL
command: C:\windows\system32\hwlrwL.exe
file: C:\windows\system32\hwlrwL.exe
size: 233620
MD5: 837aff6886e55e5384e390bcaa6d0f9e
Located: HK_LM:Run, IgfxTray
command: C:\WINDOWS\System32\igfxtray.exe
file: C:\WINDOWS\System32\igfxtray.exe
size: 155648
MD5: 735486208c3a359cab624526e4467257
Located: HK_LM:Run, IMJPMIG8.1
command: "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
file: C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE
size: 208952
MD5: 7bbe4cf421aecc7f0226edd75f12079f
Located: HK_LM:Run, l
command: C:\documents and settings\fish\local settings\temp\l.exe
file: C:\documents and settings\fish\local settings\temp\l.exe
size: 172094
MD5: 1a0c22d0ef0785aed1030af41be32d83
Located: HK_LM:Run, MessengerPlus3
command: "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
file: C:\Program Files\Messenger Plus! 3\MsgPlus.exe
size: 169096
MD5: c39294d45e86155690266d05b2da6d77
Located: HK_LM:Run, mmtask
command: C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
file: C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
size: 53248
MD5: 6631470725d1c58a2b9c3ce1ce1929f9
Located: HK_LM:Run, MSPY2002
command: C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
file: C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe
size: 59392
MD5: 1b17e09c1223f6d17336d2dd7a1af4f4
Located: HK_LM:Run, MyPointsPointAlert0
command: "C:\Program Files\MyPoints_PointAlert\MyPointsPointAlert0.exe"
file: C:\Program Files\MyPoints_PointAlert\MyPointsPointAlert0.exe
size: 98304
MD5: a8e8e8d3507939c7b0626c67340f82ba
Located: HK_LM:Run, PHIME2002A
command: C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
file: C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE
size: 455168
MD5: 024dc0f68df5fd6ae9dd82dfbaf479d6
Located: HK_LM:Run, PHIME2002ASync
command: C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
file: C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE
size: 455168
MD5: 024dc0f68df5fd6ae9dd82dfbaf479d6
Located: HK_LM:Run, RVRgiIbY.exe
command: c:\windows\system32\RVRgiIbY.exe
file: c:\windows\system32\RVRgiIbY.exe
size: 176362
MD5: bb6b2e25a5506ea2a92ad583a5cf3313
Located: HK_LM:Run, TkBellExe
command: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
file: C:\Program Files\Common Files\Real\Update_OB\realsched.exe
size: 180269
MD5: 3cf6bff887af6f733473d81a8921a5c5
Located: HK_LM:Run, UdoLX8
command: C:\documents and settings\fish\local settings\temp\UdoLX8.exe
file: C:\documents and settings\fish\local settings\temp\UdoLX8.exe
size: 233656
MD5: bf22b6762024ca12fee0eab52f43f3fa
Located: HK_LM:Run, UZinV1
command: C:\documents and settings\fish\local settings\temp\UZinV1.exe
file: C:\documents and settings\fish\local settings\temp\UZinV1.exe
size: 172146
MD5: 22a337dd85a7857258e203841863d24a
Located: HK_LM:Run, vptray
command: C:\PROGRA~1\SYMANT~1\VPTray.exe
file: C:\PROGRA~1\SYMANT~1\VPTray.exe
size: 124128
MD5: 5972a3384ebceaeb99f4216e77ebed59
Located: HK_CU:Run, ctfmon.exe
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996a38c0b0cf151c2140ae29fc8
Located: HK_CU:Run, MessengerPlus3
command: "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
file: C:\Program Files\Messenger Plus! 3\MsgPlus.exe
size: 169096
MD5: c39294d45e86155690266d05b2da6d77
Located: HK_CU:Run, msnmsgr
command: "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
file: C:\Program Files\MSN Messenger\msnmsgr.exe
size: 4849664
MD5: 9c588e9844ba27135f0c4147d1b38c07
Located: HK_CU:Run, STYLEXP
command: C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
Located: Startup (user), AntiCrash.lnk
command: C:\Program Files\Dachshund Software\AntiCrash\AntiCrash.exe
file: C:\Program Files\Dachshund Software\AntiCrash\AntiCrash.exe
size: 2301798
MD5: d650e0bb24c1c4d796fd2e88e8fdfeff
Located: Startup (user), Hare.lnk
command: C:\Program Files\Dachshund Software\Hare\Hare.exe
file: C:\Program Files\Dachshund Software\Hare\Hare.exe
size: 1874381
MD5: a4df641cda8a91a844b1f069ca2daf4c
Located: Startup (user), Zoom.lnk
command: C:\Program Files\Dachshund Software\Zoom\Zoom.exe
file: C:\Program Files\Dachshund Software\Zoom\Zoom.exe
size: 1446302
MD5: 46852612f2d80b11517055eb208a2f15
Located: WinLogon, crypt32chain
command: crypt32.dll
Located: WinLogon, cryptnet
command: cryptnet.dll
Located: WinLogon, cscdll
command: cscdll.dll
Located: WinLogon, igfxcui
command: igfxsrvc.dll
Located: WinLogon, NavLogon
command: C:\WINDOWS\system32\NavLogon.dll
file: C:\WINDOWS\system32\NavLogon.dll
size: 83176
MD5: 55dc54c87fa324a4cd32b3b407307671
Located: WinLogon, ScCertProp
command: wlnotify.dll
Located: WinLogon, Schedule
command: wlnotify.dll
Located: WinLogon, sclgntfy
command: sclgntfy.dll
Located: WinLogon, SensLogn
command: WlNotify.dll
Located: WinLogon, termsrv
command: wlnotify.dll
Located: WinLogon, wlballoon
command: wlnotify.dll
--- Browser helper object list ---
{E8EAEB34-F7B5-4C55-87FF-720FAF53D841} (Search Help)
BHO name: Search Help
CLSID name: CSearchHelpIEExtension Object
Path: C:\Documents and Settings\Fish\Local Settings\Temp\
Long name: 36UFp.dll
Short name:
Date (created): 1/14/2005 1:32:14 PM
Date (last access): 1/15/2005 8:50:58 PM
Date (last write): 1/14/2005 1:37:16 PM
Filesize: 119057
Attributes: archive
MD5: 2FFB83A22D7DBC19A1039E84DF51FD59
CRC32: 8E321627
Version: 0.1.0.0
--- ActiveX list ---
Yahoo! Pool 2 (Yahoo! Pool 2)
DPF name: Yahoo! Pool 2
CLSID name:
Yahoo! Spades (Yahoo! Spades)
DPF name: Yahoo! Spades
CLSID name:
{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine)
DPF name:
CLSID name: Office Update Installation Engine
Path: C:\WINDOWS\
Long name: opuc.dll
Short name:
Date (created): 8/27/2003 3:10:30 AM
Date (last access): 1/15/2005 9:48:28 PM
Date (last write): 8/27/2003 3:10:30 AM
Filesize: 314368
Attributes: archive
MD5: 1E32EC4A8A17B19926B49EA5F6B79A76
CRC32: E98FC293
Version: 0.11.0.0
{4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class)
DPF name:
CLSID name: EPUImageControl Class
Path: C:\WINDOWS\Downloaded Program Files\
Long name: EPUWalcontrol.dll
Short name: EPUWAL~1.DLL
Date (created): 5/15/2004 2:14:18 PM
Date (last access): 1/15/2005 9:47:10 PM
Date (last write): 5/15/2004 2:14:18 PM
Filesize: 884736
Attributes: archive
MD5: ACBDA0F01F0A678AB5E6CC9080708C7D
CRC32: B21B099F
Version: 0.1.0.0
{D44C75D8-C827-473E-8F68-A77E42500782} (Uploader Class)
DPF name:
CLSID name: Uploader Class
Path: C:\WINDOWS\Downloaded Program Files\
Long name: WebUploadClient.dll
Short name: WEBUPL~1.DLL
Date (created): 10/25/2004 11:19:30 AM
Date (last access): 1/15/2005 9:47:10 PM
Date (last write): 10/25/2004 11:19:30 AM
Filesize: 3612672
Attributes: archive
MD5: 09A8259560E8342F8FB095399D3442F6
CRC32: 4A52C06A
Version: 0.2.0.0
{E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class)
DPF name:
CLSID name: EPSImageControl Class
Path: C:\WINDOWS\Downloaded Program Files\
Long name: EPScontrol.dll
Short name: EPSCON~1.DLL
Date (created): 1/12/2004 9:49:20 AM
Date (last access): 1/15/2005 9:47:10 PM
Date (last write): 1/12/2004 9:49:20 AM
Filesize: 885248
Attributes: archive
MD5: C69F7705F630B2204DBF13B1F30804AE
CRC32: 15BAE482
Version: 0.1.0.0
--- Process list ---
PID: 0 ( 0) [System]
PID: 4 ( 0) System
PID: 124 ( 700) C:\WINDOWS\System32\svchost.exe
PID: 160 ( 364) C:\documents and settings\fish\local settings\temp\E1K9H.exe
PID: 240 ( 364) C:\documents and settings\fish\local settings\temp\l.exe
PID: 312 ( 364) C:\documents and settings\fish\local settings\temp\UZinV1.exe
PID: 348 ( 364) C:\windows\system32\hwlrwL.exe
PID: 364 ( 328) C:\WINDOWS\Explorer.EXE
PID: 432 ( 700) C:\WINDOWS\system32\cisvc.exe
PID: 444 ( 700) C:\Program Files\Symantec AntiVirus\DefWatch.exe
PID: 460 ( 700) C:\Program Files\Executive Software\Diskeeper\DkService.exe
PID: 524 ( 700) C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
PID: 584 ( 4) \SystemRoot\System32\smss.exe
PID: 608 ( 700) C:\Program Files\Symantec AntiVirus\Rtvscan.exe
PID: 632 ( 584) csrss.exe
PID: 656 ( 584) \??\C:\WINDOWS\system32\winlogon.exe
PID: 700 ( 656) C:\WINDOWS\system32\services.exe
PID: 712 ( 656) C:\WINDOWS\system32\lsass.exe
PID: 716 ( 364) C:\windows\system32\RVRgiIbY.exe
PID: 868 ( 700) C:\WINDOWS\system32\svchost.exe
PID: 912 ( 904) C:\WINDOWS\SYSTEM32\RVRgiIbY.exe
PID: 952 ( 700) svchost.exe
PID: 1048 ( 364) C:\Program Files\Internet Explorer\iexplore.exe
PID: 1064 ( 700) C:\WINDOWS\System32\svchost.exe
PID: 1092 ( 700) C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
PID: 1176 ( 700) svchost.exe
PID: 1248 ( 964) C:\Program Files\MSN Messenger\msnmsgr.exe
PID: 1264 ( 364) C:\WINDOWS\system32\ctfmon.exe
PID: 1296 ( 364) C:\WINDOWS\System32\hkcmd.exe
PID: 1316 ( 700) svchost.exe
PID: 1388 ( 700) C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PID: 1420 ( 364) C:\Program Files\Common Files\Dell\EUSW\Support.exe
PID: 1424 ( 700) wdfmgr.exe
PID: 1448 ( 700) C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PID: 1612 ( 364) C:\Program Files\Messenger Plus! 3\MsgPlus.exe
PID: 1648 ( 364) C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PID: 1656 ( 364) C:\PROGRA~1\SYMANT~1\VPTray.exe
PID: 1700 ( 364) C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
PID: 1720 ( 364) C:\documents and settings\fish\local settings\temp\UdoLX8.exe
PID: 1728 ( 364) C:\documents and settings\fish\local settings\temp\eNVzIb.exe
PID: 2024 ( 700) C:\WINDOWS\system32\spoolsv.exe
PID: 2096 (1676) C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PID: 2296 (1668) C:\Program Files\MyPoints_PointAlert\MyPointsPointAlert1.exe
PID: 2308 ( 364) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
PID: 2348 (2296) C:\Program Files\MyPoints_PointAlert\MyPointsPointAlert0.exe
PID: 2460 ( 700) alg.exe
PID: 2664 (1584) C:\WINDOWS\Integrator.exe
PID: 3064 ( 432) C:\WINDOWS\system32\cidaemon.exe
PID: 3192 ( 700) C:\WINDOWS\System32\svchost.exe
PID: 3956 ( 364) C:\Program Files\Windows Media Player\wmplayer.exe
Spybot - Search && Destroy process list report, 1/15/2005 9:50:39 PM
--- Browser start & search pages list ---
Spybot - Search && Destroy browser pages report, 1/15/2005 9:50:39 PM
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://home.microsoft.com/access/allinone.aspHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
http://home.microsoft.com/search/lobby/search.aspHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
about:blank
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.dellnet.comHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
http://home.microsoft.com/access/autosearch.asp?p=%sHKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
%SystemRoot%\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?p...=ie&ar=iesearchHKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar
about:blank
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.dellnet.comHKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhomeHKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.microsoft.com/isapi/redir.dll?p...=ie&ar=iesearchHKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com/{SUB_RFC1766}/src...st/srchasst.htmHKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{SUB_RFC1766}/src...st/srchcust.htm--- Winsock Layered Service Provider list ---
mostly the most annoyin one is that i can't remove "CSearchHelpIEExtension Object" that i found with ToolBar Cop.. cause i would remove it but then next time i restart.. it would restart also and mess up my internet explorer..
and sometimes when i load a page on this computer it takes me to some ad234.com.. something like that..
hope this helps!