It is currently Tue Sep 01, 2026 4:23 pm


Help with Hijack Log

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Postby brad » Sun Jun 20, 2004 11:35 am

First, download:

Now, boot into "Safe Mode".


Turn off System Restore. (Turn it back on after this is repaired and you've rebooted.)
Run HiJackThis.
Close all other open Windows and have HiJackThis Fix:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
O2 - BHO: (no name) - {B9FF2C30-0BCC-40E8-8D63-6C99C495F013} - C:\WINDOWS\System32\aneop.dll

Now delete these Folders or Files that are Highlighted: (You may need enable "Show all Files" and disable "Hide System Files" in Windows Explorer / Tools / Folder Options / View Tab) (You may have to boot to "Safe Mode" in order to delete some Files/Folders)

C:\WINDOWS\System32\aneop.dll

Now Run the PeperFix tool you downloaded. Click the "Find and Fix" button.

Now, empty your TEMP Folder / Temporary Internet Files Folder and then empty your "Recycle Bin" and reboot.

Restart in "Normal Mode" and post a new HJT Log File.

brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Sunday June 20

Postby jerry » Sun Jun 20, 2004 3:10 pm

Okay I completed the task as you noted - The PeperFix program did not find any files to delete - the file C:\WINDOWS\system32\aneop.dll was not in that folder. When I clicked on IE Explorer to send the HJT files it went back to that search page, I ran HJT again and it hall all of the same old stuff in it and showed this file C:\WINDOWS\system32\homla.dll. So I rebotted back into safe mode and ran HJT and fixed all of that stuff and then looked for that strange dll file and could not find it. I ran PeperFix again and it found no files to delete. Both time I deleted all of the temp files and cleared the Recycle Bin. This Trojan or whatever it is seems to have something hidden very well----I have the PC set to show all files but I don't understand why I can never find that dll file that keeps changing.

When I just clicked on IE Explorer the home page that opened was "about blank" ----- hopefully it will stay on my desired home page when I select it and apply..............

This is the current HJT log:

Logfile of HijackThis v1.97.7
Scan saved at 8:56:37 AM, on 6/20/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Utilities\NProtect.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Jerry Thornton\Desktop\HJT\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.kansascity.com/mld/kansascitystar/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.kansascity.com/mld/kansascitystar/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [QOELOADER] C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O15 - Trusted Zone: www.pogo.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsup ... rtutil.CAB
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupda ... t/opuc.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... .718912037
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0C4D9B8-FE9B-42FF-B730-0958349C8CF5}: NameServer = 151.164.8.201,151.164.1.8

Jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Postby brad » Sun Jun 20, 2004 3:25 pm

Update and run Ad-aware / SpyBot / and your Norton.
Post back with the results and a new HJT Log File.
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Second Post for Sunday

Postby jerry » Sun Jun 20, 2004 3:27 pm

HeyBrad,,,,,,,,,,,,,I just ran my Norton WinDoctor and it found three Registry entrys that were a problem - it was all three of the dang dll files that have been a problem - including the aneop and homla and another - it wanted to put them back in the system and I told it NO - I guess I need to stop running that program or tell it to ignore these items. Wonder if those item are still in the registry somewhere?????????

so far everything is working just fine :)))

Jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Postby brad » Sun Jun 20, 2004 3:38 pm

As I said, Run a full AV Scan with Norton. Do full scans with Ad-aware and SpyBot, too.
You're getting there.
After all that, reboot and post a HJT Log File.
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Latest Post on Sunday

Postby jerry » Sun Jun 20, 2004 4:30 pm

I updated and ran SpyBot - it found one file "Doubleclick" and I told it to fix that entry. Updated Norton and ran it and it was clean. Updated Ad-Aware and ran it and the result was clean.

Rebooted and here is the HJT log:
Logfile of HijackThis v1.97.7
Scan saved at 10:23:37 AM, on 6/20/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Utilities\NProtect.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Jerry Thornton\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.kansascity.com/mld/kansascity/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.kansascity.com/mld/kansascitystar/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.kansascity.com/mld/kansascitystar/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [QOELOADER] C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O15 - Trusted Zone: www.pogo.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsup ... rtutil.CAB
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupda ... t/opuc.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... .718912037
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0C4D9B8-FE9B-42FF-B730-0958349C8CF5}: NameServer = 151.164.8.201,151.164.1.8

I did notice that a couple of files have been added to my F drive - one is called Recycler and the other is named System Volume Files - I tried to delete them in Safe Mode but it will not let me.

Jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Postby brad » Sun Jun 20, 2004 4:36 pm

Log looks excellent.
Those files are system Files. I don't know what your "F" drive is but I don't think I'd worry too much.
System Volume Files are your "System Restore" Files.

brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

THANKS

Postby jerry » Sun Jun 20, 2004 4:41 pm

Thanks Brad,,,,,,,,you are a very patient person - thanks you so much for your help - everything is working just fine :)

Jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Postby brad » Sun Jun 20, 2004 10:43 pm

You're very welcome. I commend you for "hanging in there".
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Another time - sheesh

Postby jerry » Mon Jun 21, 2004 12:42 am

Hi Brad,,,,,,,,,,,,well, everything was working perfectly and I closed all of the open windows and went to my daughters for dinner and was gone for about 5 hours and when I came back and clicked on IE to open my explorer it went to that dang search page again.

I booted into Safe Mode and had HJT fix the problem entries and completed all of the other tasks that you have taught me to do and now it is doing fine.

There is still something running in the background that does this but who knows what it might be. I thought for sure that we had it licked but it is like a bad penny, it keeps coming back hahahaha.

If you have any ideas please let me know..........

Thanks again for your help Jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Postby brad » Mon Jun 21, 2004 10:31 am

Download / Install / and Update: .
Make sure you update it.
TrojanRemover is a very good program. It has a free 30 day trial that is fully functional. Run it and email me a copy of the Log. The Log is too big to post here.

Also, Download / Install / and Update: .
This runs all the time and will protect you from most Hijacks.

brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Monday June 21

Postby jerry » Mon Jun 21, 2004 11:08 am

Good Morning Brad,,,,,,,,,,,,,when I download TrojanRemover and install it - then try to run it I get this popup - Cannot run - files damaged either by a bad sector of the harddrive or a virus..............

I have to go to work this morning but will check back to see your response this evening - have a great day............

Jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Post 2 for Monday June 21

Postby jerry » Mon Jun 21, 2004 6:35 pm

User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Postby brad » Mon Jun 21, 2004 7:38 pm

Thats' what a Peper Trojan does. It generates random exe's. It's controled by a .dll that stays hidden and generates fake .dll's to make it hard to find.
I'd still like for you to get Trojan Remover installed. Try installing in "Safe Mode". It's a clean download...it's on my ftp account.
See if you can get it running.
Also, when you start getting attacked again, reboot a couple of times without fixing anything. Then post a HJT Log File.
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Monday evening

Postby jerry » Tue Jun 22, 2004 12:48 am

Hi Brad, I tried to get TrojanRemover loaded in Safe Mode but it gives me the same message and it will not run :mad:

The dang thing just got me again and I rebooted twice and here is the HJT log:

Logfile of HijackThis v1.97.7
Scan saved at 6:40:51 PM, on 6/21/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Utilities\NProtect.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Documents and Settings\Jerry Thornton\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.kansascity.com/mld/kansascitystar/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.kansascity.com/mld/kansascitystar/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {24D00819-A6B4-4042-BE19-FAACB92CBF0E} - C:\WINDOWS\System32\bibfjb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [QOELOADER] C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O15 - Trusted Zone: www.pogo.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsup ... rtutil.CAB
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupda ... t/opuc.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... .718912037
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0C4D9B8-FE9B-42FF-B730-0958349C8CF5}: NameServer = 151.164.8.201,151.164.1.8

jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

PreviousNext

Return to Malware Support

Who is online

Users browsing this forum: No registered users and 0 guests

cron