Author Topic: Please look at my hijack this log (2nd thought)  (Read 740 times)

Guest_John

  • Guest
Please look at my hijack this log (2nd thought)
« on: December 20, 2004, 01:10:16 PM »
here is my hijack this log

Logfile of HijackThis v1.97.7
Scan saved at 12:06:28 PM, on 12/20/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\afbyroq.exe
C:\DOCUME~1\Mary\LOCALS~1\Temp\ICD3.tmp\svcmm32.exe
C:\WINDOWS\System32\SahAgent.exe
C:\Program Files\Bcpc\bcpc.exe
C:\WINDOWS\System32\ykxwdru\jgeyuqlk.exe
C:\WINDOWS\System32\gikbix\rpwv.exe
C:\WINDOWS\System32\sersg.exe
C:\WINDOWS\System32\txwdc\uabfsatf.exe
C:\WINDOWS\System32\cbijv\xwfnqaym.exe
C:\Program Files\CSBB\CSV7P070.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\CSBB\csAOLldr.exe
C:\Program Files\America Online 8.0a\aoltray.exe
C:\WINDOWS\System32\winupdt.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\WINDOWS\System32\winupdt.exe
C:\Program Files\America Online 8.0a\Email Removedexe
C:\Program Files\America Online 8.0a\wEmail Removedexe
C:\Program Files\America Online 8.0a\aolwbspd.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Will\My Documents\help\HijackThis.exe

R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll
O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000002230} - C:\Program Files\CSBB\CSBB.DLL
O2 - BHO: (no name) - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\bxxs5.dll
O2 - BHO: (no name) - {002EB272-2590-4693-B166-FBD5D9B6FEA6} - C:\WINDOWS\multimpp.dll
O2 - BHO: (no name) - {7CD20E91-1F31-41da-8379-479EA31DF969} - c:\Program Files\XML\XML.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll (file missing)
O3 - Toolbar: (no name) - {BDF6CE3D-F5C5-4462-9814-3C8EAC330CA8} - (no file)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\ScanSoft\NaturallySpeaking\Program\Ereg.exe" -r "C:\Program Files\ScanSoft\NaturallySpeaking\Program\ereg.ini"
O4 - HKLM\..\Run: [stcloader] C:\WINDOWS\System32\stcloader.exe
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdtl.exe
O4 - HKLM\..\Run: [egxjbc] C:\WINDOWS\System32\egxjbc.exe
O4 - HKLM\..\Run: [ignhmnpuoy] C:\WINDOWS\System32\afbyroq.exe
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [conscorr] C:\WINDOWS\conscorr.exe
O4 - HKLM\..\Run: [kdlkoc] C:\WINDOWS\System32\kdlkoc.exe
O4 - HKLM\..\Run: [jwqlsxhr] C:\WINDOWS\System32\cusp\jwqlsxhr.exe
O4 - HKLM\..\Run: [sgkh] C:\WINDOWS\System32\elxv\sgkh.exe
O4 - HKLM\..\Run: [evqxlfe] C:\WINDOWS\System32\qargng\evqxlfe.exe
O4 - HKLM\..\Run: [USB controller] "C:\DOCUME~1\Mary\LOCALS~1\Temp\ICD3.tmp\svcmm32.exe" /startup
O4 - HKLM\..\Run: [SAHAgent] C:\WINDOWS\System32\SahAgent.exe
O4 - HKLM\..\Run: [BCPC] "C:\Program Files\Bcpc\bcpc.exe"
O4 - HKLM\..\Run: [Breg] "C:\Program Files\Common Files\Java\bcre.exe"
O4 - HKLM\..\Run: [Xcpy1] "C:\Program Files\Common Files\Java\Xcpy1.exe"
O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\bxxs5.dll,DllRun
O4 - HKLM\..\Run: [doftllrl] C:\WINDOWS\System32\hcqanadi\doftllrl.exe
O4 - HKLM\..\Run: [xqmf] C:\WINDOWS\System32\vxbhbxs\xqmf.exe
O4 - HKLM\..\Run: [sxmjhkj] C:\WINDOWS\System32\oeghwxhx\sxmjhkj.exe
O4 - HKLM\..\Run: [fjoy] C:\WINDOWS\System32\qtapux\fjoy.exe
O4 - HKLM\..\Run: [osnS37g] sersg.exe
O4 - HKLM\..\Run: [rpwv] C:\WINDOWS\System32\gikbix\rpwv.exe
O4 - HKLM\..\Run: [jgeyuqlk] C:\WINDOWS\System32\ykxwdru\jgeyuqlk.exe
O4 - HKLM\..\Run: [uabfsatf] C:\WINDOWS\System32\txwdc\uabfsatf.exe
O4 - HKLM\..\Run: [xwfnqaym] C:\WINDOWS\System32\cbijv\xwfnqaym.exe
O4 - HKLM\..\Run: [ryvrfc] C:\WINDOWS\System32\ryvrfc.exe
O4 - HKLM\..\Run: [AdRoarUpdate] C:\WINDOWS\ARUpdate.exe
O4 - HKLM\..\Run: [olblscc] C:\WINDOWS\System32\ttukgw\olblscc.exe
O4 - HKLM\..\Run: [wpbkym] C:\WINDOWS\System32\nxjin\wpbkym.exe
O4 - HKLM\..\Run: [xplwf] C:\WINDOWS\System32\xeobovj\xplwf.exe
O4 - HKLM\..\Run: [sgcm] C:\WINDOWS\System32\dvssg\sgcm.exe
O4 - HKLM\..\Run: [CSV7P70] C:\Program Files\CSBB\CSV7P070.exe
O4 - HKLM\..\Run: [wbatktc] C:\WINDOWS\System32\xxomewy\wbatktc.exe
O4 - HKLM\..\Run: [qgktst] C:\WINDOWS\System32\uhfy\qgktst.exe
O4 - HKLM\..\Run: [vpsxauih] C:\WINDOWS\System32\ewdjf\vpsxauih.exe
O4 - HKLM\..\Run: [myhjlc] C:\WINDOWS\System32\myhjlc.exe
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [TB_setup] C:\DOCUME~1\Will\LOCALS~1\Temp\tb_setup.exe /dcheck
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0a\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: AIM (HKLM)
O17 - HKLM\System\CCS\Services\Tcpip\..\{8B7AE6D7-7579-46F1-93A5-D3E33802FCAA}: NameServer = 205.188.146.146

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Please look at my hijack this log (2nd thought)
« Reply #1 on: December 20, 2004, 08:21:04 PM »
You have a bit of malware to cleanup, with some tools and manual cleanup we can get your computer running clean again

First--Go into your add/remove programs and remove if found
TV MEDIA
ShopatHome
MSIETS
Internet 404
Tools for Internet Explorer
Search Toolbar
Web Search Toolbar
Win-Tools Easy Installer


RESTART your computer if anything is Removed
If TVMEDIA is not totally removed can you download the Uninstaller from Microsoft
http://www.microsoft.com/downloads/details...&displaylang=en
Run it and follow the prompts
Restart your computer

Could you download a couple free tools that you can hang onto, as I said, yours for free, no reason to be without them

First: Download and Install the free version of Ad-Aware SE Personal 1.05
Ensure you have this version
If you don't have this verision,install this one
Open Ad-Aware, ensure to click the check for updates online link and Connect to download the latest updates
Perform a Full system scan
When it's finished scanning
At this point you should either right click on the screen and and choose the "Select All" Objects option or individually put a checkmark in each objects checkbox
click on the Next button. Ad-Aware SE will now present you with a confirmation box as to whether or not you would like to remove the objects you have just selected. Press the "OK" button

RESTART your computer again to finish the cleaning process

Download and Install Spybot S&D 1.3
While installing please do not enable TEA TIMER, it's a very good addon but can get in the way of any fixes we will manually try on your log
After installation--SEARCH FOR UPDATES
Download all updates and then close and Restart the program
Click the Search & Destroy Button on the left
Check for Problems---Let it Finish Scanning---Check and FIX everything in RED
RESTART your computer to finish the cleaning

I would also recommend that you do a Free online Virus scan at Trend Micro's Housecall's---Set to Autoclean
http://housecall.trendmicro.com/
and/or Panda's Active Scan
http://www.pandasoftware.com/activescan/co...n_principal.htm

When you have finished the above, could you please update your version of Hijackthis
Open Hijackthis>>Config>>Misc tools>>Check for updates online
If for some reason it won't update
Redownload Hijackthis from HERE or HERE
 and save it to your C:\Documents and Settings\Will\My Documents\help folder
allowing it to overwrite your old version

Please post back with a fresh log from Hijackthis 1.99

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here