My Log

Status
Not open for further replies.

triplej_38118

Solid State Member
Messages
10
I just completed the steps of the Spyware Removal Guide. Here is my log. . .

Logfile of HijackThis v1.99.1
Scan saved at 11:05:09 AM, on 8/12/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\System32\wuauclt.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\TPT Registry_Cleaner (Trial)\RegClean.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.711.1664\GoogleToolbarNotifier.exe
C:\Documents and Settings\Joshua Jefferies\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {009057E0-E644-7B31-F576-A66A75B760A4} - (no file)
O2 - BHO: (no name) - {0283E400-BF96-1C65-2C3F-9441F31430C2} - (no file)
O2 - BHO: (no name) - {0315E8BF-CB9F-4795-F013-258F5F05C8F7} - (no file)
O2 - BHO: (no name) - {055AF2EF-F0B2-A80F-927D-4E428A7707D6} - (no file)
O2 - BHO: (no name) - {05DDF3D2-6A66-0B87-40D6-F21D101758C7} - (no file)
O2 - BHO: (no name) - {0FF735ED-18CB-AF19-21F7-AC40587668DD} - (no file)
O2 - BHO: (no name) - {11432651-A087-8D4D-B7F1-E0B7E38F5E5D} - (no file)
O2 - BHO: (no name) - {212369CB-F3F6-8742-D3D1-58CD02D51232} - (no file)
O2 - BHO: (no name) - {2876779C-5E73-7B62-FEEB-18D1F3BA6422} - (no file)
O2 - BHO: (no name) - {2F698176-3020-6710-0AB8-CB9B1DEB7AEF} - (no file)
O2 - BHO: (no name) - {337E0629-2148-2599-602E-569DE2D76764} - (no file)
O2 - BHO: (no name) - {33A49432-E399-EC6E-1569-941A0DB59717} - (no file)
O2 - BHO: (no name) - {33AC5F10-1C95-86A7-25C4-F0E4BD5677F2} - (no file)
O2 - BHO: (no name) - {341F535C-9E0C-261C-AEDC-D7DD7B74CC80} - (no file)
O2 - BHO: (no name) - {48785F27-22B3-8233-44D2-64CF0F0060B0} - (no file)
O2 - BHO: (no name) - {4D7C2D84-2B00-146D-CAF2-38E8743204A2} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {55E7FCAD-77C1-35FF-8206-D7405C6CDFAB} - (no file)
O2 - BHO: (no name) - {55F20EFF-2F9C-BDB0-B7CF-8E85DA740089} - (no file)
O2 - BHO: (no name) - {5C0FEC2D-DA98-9458-4F80-5D030ABD600A} - (no file)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {5FF7BB31-38C8-9368-5FEE-A72B4BCC8B6A} - (no file)
O2 - BHO: (no name) - {64B286CD-6CF2-30B4-802B-348460FA3ED2} - (no file)
O2 - BHO: (no name) - {655963E8-0F03-5868-828A-091DBC963461} - (no file)
O2 - BHO: (no name) - {6736D543-9459-D61F-8FA7-A53653949C0D} - (no file)
O2 - BHO: (no name) - {6A0B4E0C-174C-0B4A-A49C-433AF3B7AF78} - (no file)
O2 - BHO: (no name) - {7675940E-2E8F-CC66-3F3E-33734232EC19} - (no file)
O2 - BHO: (no name) - {7CDC4EAB-426C-E934-1759-2CFC38EB81BE} - (no file)
O2 - BHO: (no name) - {846E0BB2-4B7E-3DCA-BD80-7211A3EE88C4} - (no file)
O2 - BHO: (no name) - {8B10E5C2-6029-0876-04F6-786D53DF4AD3} - (no file)
O2 - BHO: (no name) - {9070ABC0-F5FE-FB2B-7B28-6729FA764BEA} - (no file)
O2 - BHO: (no name) - {90920AC0-CE70-911A-27A7-D53EDA3B6DED} - (no file)
O2 - BHO: (no name) - {9A986B13-A3F2-264C-9C18-9E42C205AF6A} - (no file)
O2 - BHO: (no name) - {9AB0AEAF-5C00-97B4-67EB-26FA674D4DA9} - (no file)
O2 - BHO: (no name) - {A2D7908D-E877-6C8D-8534-BE5DA802D24F} - (no file)
O2 - BHO: (no name) - {A2F74E18-58FA-8D05-B8CE-91DE2E079D51} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {AD979EF0-4E2D-0151-5E87-CC0ABDB1DFA2} - (no file)
O2 - BHO: (no name) - {BCB07B6E-BEFE-ADD4-7CEB-728FF235B841} - (no file)
O2 - BHO: (no name) - {C94CA15C-484C-57B3-630A-615B55BB4FE0} - (no file)
O2 - BHO: (no name) - {D197A0E1-57CF-5D1D-AB6B-C7313C71B514} - (no file)
O2 - BHO: (no name) - {D3176F21-DA2F-61E8-97B6-26C992DA4F51} - (no file)
O2 - BHO: (no name) - {D6FB4062-6BF9-178C-68C4-0DA115E430B5} - (no file)
O2 - BHO: (no name) - {D77CC508-D635-4696-3365-3202DB071395} - (no file)
O2 - BHO: (no name) - {DC0E40FD-D633-7594-A016-624F4172C934} - (no file)
O2 - BHO: (no name) - {E0529D79-7C19-A6FA-AAB9-F02E449A707C} - (no file)
O2 - BHO: (no name) - {E655DD60-AB14-D8EA-6258-0B4A7FC5B627} - (no file)
O2 - BHO: (no name) - {E89AC3C6-AF51-4EAC-DF55-2D8493591F9A} - (no file)
O2 - BHO: (no name) - {E8A21F6F-CE35-C5F4-D125-77B47648F1A3} - (no file)
O2 - BHO: (no name) - {EA1AF1C9-4CDD-24D5-6EFC-0661A1A20252} - (no file)
O2 - BHO: (no name) - {EF02D695-F38A-DE2E-1FF2-A228263D2819} - (no file)
O2 - BHO: (no name) - {F735A94E-3DD7-5936-2156-A36605F56680} - (no file)
O2 - BHO: (no name) - {FEDBC933-9884-74C8-1988-83E8B42CE43F} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [COALSOFTWARE] C:\DOCUME~1\JOSHUA~1\APPLIC~1\COMPBA~1\pure aim settings.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\TPT Registry_Cleaner (Trial)\RegClean.exe"
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0191ABF4-9421-435E-9FFD-CD827A2A82D8} - http://ultimateplugin.com/tl7000.dll
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540013} - http://adserver.sharewareonline.com/adserver/Install.cab
O16 - DPF: {342999A3-728D-4DF6-BB81-CDD1A743096A} (MRActivXUI Class) - http://comp.mediaring.com/consumer/pcphone/ver5.4.4.0/wbaxuiph544.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1128877478062
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} - https://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: STOPzilla Local Service - Unknown owner - C:\Program Files\STOPzilla!\szntsvc.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
 
Remove these entries, then rescan to see if they came back. If they did come back, boot into safemode, rescan and then remove the entries and then post a new log

Uninstall this as it is junk and remove it from hijackthis C:\Program Files\TPT Registry_Cleaner (Trial)\RegClean.exe


R3 - Default URLSearchHook is missing

Remove all the 02 entries, I didnt post them all because there are to many

O2 - BHO: (no name) - {009057E0-E644-7B31-F576-A66A75B760A4} - (no file)

O2 - BHO: (no name) - {0283E400-BF96-1C65-2C3F-9441F31430C2} - (no file)

O2 - BHO: (no name) - {0315E8BF-CB9F-4795-F013-258F5F05C8F7} - (no file)


O2 - BHO: (no name) - {055AF2EF-F0B2-A80F-927D-4E428A7707D6} - (no file)

O2 - BHO: (no name) - {05DDF3D2-6A66-0B87-40D6-F21D101758C7} - (no file)

O2 - BHO: (no name) - {0FF735ED-18CB-AF19-21F7-AC40587668DD} - (no file)

O2 - BHO: (no name) - {11432651-A087-8D4D-B7F1-E0B7E38F5E5D} - (no file)

O2 - BHO: (no name) - {212369CB-F3F6-8742-D3D1-58CD02D51232} - (no file)

O2 - BHO: (no name) - {2876779C-5E73-7B62-FEEB-18D1F3BA6422} - (no file)


O2 - BHO: (no name) - {2F698176-3020-6710-0AB8-CB9B1DEB7AEF} - (no file)

O2 - BHO: (no name) - {337E0629-2148-2599-602E-569DE2D76764} - (no file)

O2 - BHO: (no name) - {33A49432-E399-EC6E-1569-941A0DB59717} - (no file)

O2 - BHO: (no name) - {33AC5F10-1C95-86A7-25C4-F0E4BD5677F2} - (no file)


O2 - BHO: (no name) - {341F535C-9E0C-261C-AEDC-D7DD7B74CC80} - (no file)


O2 - BHO: (no name) - {48785F27-22B3-8233-44D2-64CF0F0060B0} - (no file)

O2 - BHO: (no name) - {4D7C2D84-2B00-146D-CAF2-38E8743204A2} - (no file)

O2 - BHO: (no name) - {55E7FCAD-77C1-35FF-8206-D7405C6CDFAB} - (no file)

O2 - BHO: (no name) - {FEDBC933-9884-74C8-1988-83E8B42CE43F} - (no file)

O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\TPT Registry_Cleaner (Trial)\RegClean.exe"

O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

O16 - DPF: {0191ABF4-9421-435E-9FFD-CD827A2A82D8} - http://ultimateplugin.com/tl7000.dll

O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540013} - http://adserver.sharewareonline.com...ver/Install.cab

O16 - DPF: {342999A3-728D-4DF6-BB81-CDD1A743096A} (MRActivXUI Class) - http://comp.mediaring.com/consumer/...wbaxuiph544.cab

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe

O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} - https://www.stopzilla.com/_download...ller/dwnldr.cab
 
Status
Not open for further replies.
Back
Top Bottom