something odd i just realized- it is logging me into windows messenger without me typing in password, or ever even setting up the program...so i guess it stole my password from .NET (i use Email Removed)
so now i guess i have to change all my passwords, no biggie
anyway, also - symptoms- just so u know what we're dealing with...we have like, 5 new links on my desktop...spyware avenger, virus hunter security, popupblocker stops popups, evidence eraser, and your platinum visa card.... they all come up when i start up... i have this search bar above the date in the bottom right... there is NO memory, everythings damn slow, popups galore including java script ones that try to get me to click okay...
i found a program called ddddd.exe or something on my harddrive that had a pornographic icon, and it was in use and couldn't be deleted even in safe mode...
Do i need to get those cws and the other program again from you, because my computer lost them (unbelievable to me too- but the time i downloaded them it could not find my user profile, and it gave me a default desktop ....and now when i search my computer for them, it says they don't exist.)
so here's the diagnostic stuff. i am running nromal mode now
Okay, here we go-
Scanned at: 10:09:59 PM on: 2/7/2005
-- Scan 1 ---------------------------
About:Buster Version 4.0
Reference List : 23
No ADS found on system
Removed 4 Random Key Entries
Removed! : C:\WINDOWS\aeqxg.dll
Removed! : C:\WINDOWS\awtkw.dll
Removed! : C:\WINDOWS\cinkm.dll
Removed! : C:\WINDOWS\jydcf.dll
Removed! : C:\WINDOWS\ktekt.dll
Removed! : C:\WINDOWS\mogvb.dll
Removed! : C:\WINDOWS\mqjum.dll
Removed! : C:\WINDOWS\oajrh.dll
Removed! : C:\WINDOWS\oaxst.dll
Removed! : C:\WINDOWS\ofmef.dll
Removed! : C:\WINDOWS\rdiaf.dll
Removed! : C:\WINDOWS\sancr.dll
Removed! : C:\WINDOWS\tgtws.dll
Removed! : C:\WINDOWS\umora.dll
Removed! : C:\WINDOWS\vlkbd.dll
Removed! : C:\WINDOWS\wugzt.dll
Removed! : C:\WINDOWS\xqyhu.dll
Removed! : C:\WINDOWS\xtcfr.dll
Removed! : C:\WINDOWS\zhrpv.dll
Removed! : C:\WINDOWS\zkczj.dll
Removed! : C:\WINDOWS\znjom.dll
Removed! : C:\WINDOWS\System32\bukpc.dll
Removed! : C:\WINDOWS\System32\fnnhk.dat
Removed! : C:\WINDOWS\System32\itwnd.dll
Removed! : C:\WINDOWS\System32\jbfjt.dll
Removed! : C:\WINDOWS\System32\lqsad.dll
Removed! : C:\WINDOWS\System32\ojfsq.dll
Removed! : C:\WINDOWS\System32\owkrz.dll
Removed! : C:\WINDOWS\System32\pncfj.dll
Removed! : C:\WINDOWS\System32\qirdo.dll
Removed! : C:\WINDOWS\System32\qksza.dll
Removed! : C:\WINDOWS\System32\qpzhb.dll
Removed! : C:\WINDOWS\System32\qwjvr.dll
Removed! : C:\WINDOWS\System32\rntkk.dll
Removed! : C:\WINDOWS\System32\tvhqe.dll
Removed! : C:\WINDOWS\System32\vjbfj.dat
Removed! : C:\WINDOWS\System32\vpkqb.dll
Removed! : C:\WINDOWS\System32\vqpzh.dat
Removed! : C:\WINDOWS\System32\wzbft.dll
Removed! : C:\WINDOWS\System32\xwzbf.dat
Removed! : C:\WINDOWS\System32\yofme.dat
Removed! : C:\WINDOWS\System32\ypefs.dll
Removed! : C:\WINDOWS\System32\ysntc.dll
Removed! : C:\WINDOWS\System32\zomyp.dll
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset... Done!
-- Scan 2 ---------------------------
About:Buster Version 4.0
Reference List : 23
No ADS found on system
Attempted Clean Of Temp folder.
Pages Reset... Done!
Scanned at: 12:45:01 AM on: 2/8/2005
-- Scan 1 ---------------------------
About:Buster Version 4.0
Reference List : 23
No ADS found on system
Attempted Clean Of Temp folder.
Pages Reset... Done!
-- Scan 2 ---------------------------
About:Buster Version 4.0
Reference List : 23
No ADS found on system
Attempted Clean Of Temp folder.
Pages Reset... Done!
Logfile of HijackThis v1.97.7
Scan saved at 12:46:01 AM, on 2/8/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\System32\qbrurzrw5.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\isrvs\desktop.exe
C:\windows\system32\tvshdg.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\jordan\Application Data\eetu.exe
C:\WINDOWS\System32\m?iexec.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\windows\system32\packager.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Documents and Settings\jordan\Desktop\AboutBuster\AboutBuster\AboutBuster.exe
C:\Documents and Settings\jordan\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
www.msn.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
www.msn.comR1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\xqyhu.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext =
http://us.mcafee.com/root/landingpages/cd....ystempopup=true (obfuscated)
F1 - win.ini: run=C:\WINDOWS\System32\soft.exe
O2 - BHO: (no name) - {00000000-C1EC-0345-6EC2-4D0300000000} - C:\WINDOWS\ZServ.dll
O2 - BHO: (no name) - {4C6760DC-238D-9383-FB09-D1F471E71804} - (no file)
O2 - BHO: (no name) - {502B8893-05D5-1E4B-D4E1-6F514A11CDB7} - (no file)
O2 - BHO: (no name) - {79EF8DE9-C305-C8CC-6B87-1ED452FEAE42} - C:\WINDOWS\System32\gmapuiud.dll
O2 - BHO: (no name) - {F88F8875-03DC-4821-9D1E-193A135D0CF2} - C:\WINDOWS\System32\qlc.dll
O3 - Toolbar: (no name) - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe files\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [tvshdg] c:\windows\system32\tvshdg.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Web Service] C:\WINDOWS\System32\msxmidi.exe
O4 - HKCU\..\Run: [d0q8RkZ5R] offuk.exe
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\jordan\Application Data\eetu.exe
O4 - HKCU\..\Run: [Vlzxmfa] C:\WINDOWS\System32\m?iexec.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AOL Toolbar (HKLM)
O9 - Extra 'Tools' menuitem: AOL Toolbar (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O10 - Broken Internet access because of LSP provider 'imon.dll' missing
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.addictivetechnologies.com
O15 - Trusted Zone: *.addictivetechnologies.net
O15 - Trusted Zone: *.admin2cash.biz
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.bettersearch.biz
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.c4tdownload.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.crazywinnings.com
O15 - Trusted Zone: *.f1organizer.com
O15 - Trusted Zone: *.finefind.nettraffic2cash.biz
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.iframe.biz
O15 - Trusted Zone: *.megapornix.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.newiframe.biz
O15 - Trusted Zone: *.overpro.com
O15 - Trusted Zone: *.pizdato.biz
O15 - Trusted Zone: *.private-dialer.biz
O15 - Trusted Zone: *.private-iframe.biz
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.sp2admin.biz
O15 - Trusted Zone: *.sp2[censored]ed.biz
O15 - Trusted Zone: *.static.topconverting.com
O15 - Trusted Zone: *.topconverting.com
O15 - Trusted Zone: *.vse-moe.biz
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.xxxtoolbar.com
O15 - Trusted Zone: *.ysbweb.com
O16 - DPF: v3cab -
http://searchmiracle.com/cab/1.cabO16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cabO16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) -
http://www.musicnotes.com/download/mnviewer.cabO16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwa...director/sw.cabO16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
http://download.microsoft.com/download/F/6...922/wmv9VCM.CABO16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52/200312...meInstaller.exeO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://bin.mcafee.com/molbin/shared/mcinsc...76/mcinsctl.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5co...b?1107534934375O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cabO16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) -
http://www.bitdefender.com/scan/Msie/bitdefender.cabO16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) -
http://web1.shutterfly.com/downloads/Uploader.cabO16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) -
http://www.mt-download.com/MediaTicketsIns....cab?refid=4583O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://bin.mcafee.com/molbin/shared/mcgdmg...,16/mcgdmgr.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwa...ash/swflash.cabO16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) -
http://ax.phobos.apple.com.edgesuite.net/d.../ITDetector.cabO16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/bin/msnchat45.cab