|
Search
|
||||||
Spyware HelpInternet Anything that has to do with the Internet; dial-up, DSL, cable and any browser issue. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
||||
|
||||
|
Spyware Help
My computer has been acting really weird for the past week....it freezes, mad pop-ups, etc. I'm pretty sure it's spyware. There's also a lot of processes running that i don't even know about, and a couple of folders on my computer that I can't delete (like Comet Systems and Wild Tangent). I used AdAware but it's not helping. I downloaded Hijack This but they told me that I need to show the log to someone who knows what to delete...so I was wondering if you guys could help me. I'll post the long in a couple of minutes. Thanks
|
| Advertisement |
|
#2
|
||||
|
||||
|
Logfile of HijackThis v1.97.7
Scan saved at 12:50:44 PM, on 7/1/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe C:\WINDOWS\system32\gearsec.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\ABBYY FineReader 5.0 Sprint\CAgent.exe C:\Program Files\Lexmark X74-X75\lxbbbmon.exe C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\Dpi\dpi.exe C:\WINDOWS\system32\pcs\pcsvc.exe C:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe C:\WINDOWS\System32\RUNDLL32.exe C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe C:\Documents and Settings\Chris\Application Data\iptl.exe C:\WINDOWS\System32\NDrv.exe C:\Program Files\Sony\VAIO Action Setup\VAServ.exe C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe C:\WINDOWS\System32\Ler6.exe C:\WINDOWS\System32\Ler6.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Chris\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.i--search.com/ie/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.i--search.com/ie/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\SearchBar.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.webcrawler.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.i--search.com/ie/ R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.i--search.com/ie/ R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/cust...//my.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...ch/search.html R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file) R3 - URLSearchHook: IncrediFindBHO Class - {4FC95EDD-4796-4966-9049-29649C80111D} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing) O1 - Hosts file is located at: C:\WINDOWS\help\hosts O1 - Hosts: 209.66.114.130 sitefinder.verisign.com O1 - Hosts: 88.88.88.88 elite O1 - Hosts: 207.44.220.30 www.google.akadns.net O1 - Hosts: 207.44.220.30 www.google.com O1 - Hosts: 207.44.220.30 google.com O1 - Hosts: 207.44.220.30 www.altavista.com O1 - Hosts: 207.44.220.30 altavista.com O1 - Hosts: 207.44.220.30 search.yahoo.com O1 - Hosts: 207.44.220.30 uk.search.yahoo.com O1 - Hosts: 207.44.220.30 ca.search.yahoo.com O1 - Hosts: 207.44.220.30 jp.search.yahoo.com O1 - Hosts: 207.44.220.30 au.search.yahoo.com O1 - Hosts: 207.44.220.30 de.search.yahoo.com O1 - Hosts: 207.44.220.30 search.yahoo.co.jp O1 - Hosts: 207.44.220.30 www.lycos.de O1 - Hosts: 207.44.220.30 www.lycos.ca O1 - Hosts: 207.44.220.30 www.lycos.jp O1 - Hosts: 207.44.220.30 www.lycos.co.jp O1 - Hosts: 207.44.220.30 alltheweb.com O1 - Hosts: 207.44.220.30 web.ask.com O1 - Hosts: 207.44.220.30 ask.com O1 - Hosts: 207.44.220.30 www.ask.com O1 - Hosts: 207.44.220.30 www.teoma.com O1 - Hosts: 207.44.220.30 search.aol.com O1 - Hosts: 207.44.220.30 www.looksmart.com O1 - Hosts: 207.44.220.30 auto.search.msn.com O1 - Hosts: 207.44.220.30 search.msn.com O1 - Hosts: 207.44.220.30 ca.search.msn.com O1 - Hosts: 207.44.220.30 fr.ca.search.msn.com O1 - Hosts: 207.44.220.30 search.fr.msn.be O1 - Hosts: 207.44.220.30 search.fr.msn.ch O1 - Hosts: 207.44.220.30 search.latam.yupimsn.com O1 - Hosts: 207.44.220.30 search.msn.at O1 - Hosts: 207.44.220.30 search.msn.be O1 - Hosts: 207.44.220.30 search.msn.ch O1 - Hosts: 207.44.220.30 search.msn.co.in O1 - Hosts: 207.44.220.30 search.msn.co.jp O1 - Hosts: 207.44.220.30 search.msn.co.kr O1 - Hosts: 207.44.220.30 search.msn.com.br O1 - Hosts: 207.44.220.30 search.msn.com.hk O1 - Hosts: 207.44.220.30 search.msn.com.my O1 - Hosts: 207.44.220.30 search.msn.com.sg O1 - Hosts: 207.44.220.30 search.msn.com.tw O1 - Hosts: 207.44.220.30 search.msn.co.za O1 - Hosts: 207.44.220.30 search.msn.de O1 - Hosts: 207.44.220.30 search.msn.dk O1 - Hosts: 207.44.220.30 search.msn.es O1 - Hosts: 207.44.220.30 search.msn.fi O1 - Hosts: 207.44.220.30 search.msn.fr O1 - Hosts: 207.44.220.30 search.msn.it O1 - Hosts: 207.44.220.30 search.msn.nl O1 - Hosts: 207.44.220.30 search.msn.no O1 - Hosts: 207.44.220.30 search.msn.se O1 - Hosts: 207.44.220.30 search.ninemsn.com.au O1 - Hosts: 207.44.220.30 search.t1msn.com.mx O1 - Hosts: 207.44.220.30 search.xtramsn.co.nz O1 - Hosts: 207.44.220.30 search.yupimsn.com O1 - Hosts: 207.44.220.30 uk.search.msn.com O1 - Hosts: 207.44.220.30 search.lycos.com O1 - Hosts: 207.44.220.30 www.lycos.com O1 - Hosts: 207.44.220.30 www.google.ca O1 - Hosts: 207.44.220.30 google.ca O1 - Hosts: 207.44.220.30 www.google.uk O1 - Hosts: 207.44.220.30 www.google.co.uk O1 - Hosts: 207.44.220.30 www.google.com.au O1 - Hosts: 207.44.220.30 www.google.co.jp O1 - Hosts: 207.44.220.30 www.google.jp O1 - Hosts: 207.44.220.30 www.google.at O1 - Hosts: 207.44.220.30 www.google.be O1 - Hosts: 207.44.220.30 www.google.ch O1 - Hosts: 207.44.220.30 www.google.de O1 - Hosts: 207.44.220.30 www.google.se O1 - Hosts: 207.44.220.30 www.google.dk O1 - Hosts: 207.44.220.30 www.google.fi O1 - Hosts: 207.44.220.30 www.google.fr O1 - Hosts: 207.44.220.30 www.google.com.gr O1 - Hosts: 207.44.220.30 www.google.com.hk O1 - Hosts: 207.44.220.30 www.google.ie O1 - Hosts: 207.44.220.30 www.google.co.il O1 - Hosts: 207.44.220.30 www.google.it O1 - Hosts: 207.44.220.30 www.google.co.kr O1 - Hosts: 207.44.220.30 www.google.com.mx O1 - Hosts: 207.44.220.30 www.google.nl O1 - Hosts: 207.44.220.30 www.google.co.nz O1 - Hosts: 207.44.220.30 www.google.pl O1 - Hosts: 207.44.220.30 www.google.pt O1 - Hosts: 207.44.220.30 www.google.com.ru O1 - Hosts: 207.44.220.30 www.google.com.sg O1 - Hosts: 207.44.220.30 www.google.co.th O1 - Hosts: 207.44.220.30 www.google.com.tr O1 - Hosts: 207.44.220.30 www.google.com.tw O1 - Hosts: 207.44.220.30 go.google.com O1 - Hosts: 207.44.220.30 google.at O1 - Hosts: 207.44.220.30 google.be O1 - Hosts: 207.44.220.30 google.de O1 - Hosts: 207.44.220.30 google.dk O1 - Hosts: 207.44.220.30 google.fi O1 - Hosts: 207.44.220.30 google.fr O1 - Hosts: 207.44.220.30 google.com.hk O1 - Hosts: 207.44.220.30 google.ie O1 - Hosts: 207.44.220.30 google.co.il O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\Program Files\ClearSearch\CSIE.DLL (file missing) O2 - BHO: (no name) - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\Program Files\DAP\DAPBHO.dll O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\adobe\acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {1B7D753B-1981-4bd2-91F3-6D055EE113A0} - C:\WINDOWS\System32\NDrv.dll O2 - BHO: NavErrRedir Class - {4FC95EDD-4796-4966-9049-29649C80111D} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing) O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll O2 - BHO: (no name) - {96DA5BEE-4ACC-476C-B3EC-54C6730C4293} - C:\PROGRA~1\Comet\Install\Temp\brbho.dll (file missing) O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll (file missing) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\DAP\DAPIEBar.dll O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll (file missing) O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE" O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe" O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot O4 - HKLM\..\Run: [ABBYY Community Agent] C:\Program Files\ABBYY FineReader 5.0 Sprint\CAgent.exe O4 - HKLM\..\Run: [Launcher] "C:\Program Files\KFH\cl\launcher.exe" /P O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A O4 - HKLM\..\Run: [LVCOMS] C:\WINDOWS\System32\LVCOMS.EXE O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe O4 - HKLM\..\Run: [Image] rundll32 C:\WINDOWS\image.dll,Install O4 - HKLM\..\Run: [haZMVLtPk] C:\documents and settings\chris\local settings\temp\haZMVLtPk.exe O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe" O4 - HKLM\..\Run: [Dpi] C:\Program Files\Common Files\Dpi\dpi.exe O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe O4 - HKLM\..\Run: [VZUKc87bu] C:\documents and settings\chris\local settings\temp\VZUKc87bu.exe O4 - HKLM\..\Run: [Prein] C:\DOCUME~1\Chris\LOCALS~1\Temp\app1.tmp O4 - HKLM\..\Run: [Pcsv] C:\WINDOWS\system32\pcs\pcsvc.exe O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaE ngineMain O4 - HKLM\..\Run: [4X@95ME57C5BM8] C:\WINDOWS\SYSTEM32\QEP78K13.EXE O4 - HKCU\..\Run: [IM] C:\PROGRA~1\RRIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - HKCU\..\Run: [Iinl] C:\Documents and Settings\Chris\Application Data\iptl.exe O4 - HKCU\..\Run: [NDrv] C:\WINDOWS\System32\NDrv.exe O4 - HKCU\..\RunServices: [Image] rundll32 C:\WINDOWS\image.dll,Install O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: VAIO Action Setup (Server).lnk = ? O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm O9 - Extra button: Run DAP (HKLM) O9 - Extra button: AIM (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.rr.com O16 - DPF: ConferenceRoom Java Client - http://chat.colombia.com/java/cr.cab O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg.com/us.yimg.com...45/yacscom.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/Activ...veLauncher.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...tatsClient.cab O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} (WMService Class) - http://download.overpro.com/WildApp.cab |
|
#3
|
||||
|
||||
|
I am truly impressed that your machine manages to run with so much bloat on it.
Check C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Common Files\Dpi\dpi.exe C:\WINDOWS\system32\pcs\pcsvc.exe C:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.i--search.com/ie/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.i--search.com/ie/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\SearchBar.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.webcrawler.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.i--search.com/ie/ R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.i--search.com/ie/ R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/cus...://my.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...rch/search.html R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cus...//www.yahoo.com R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file) R3 - URLSearchHook: IncrediFindBHO Class - {4FC95EDD-4796-4966-9049-29649C80111D} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing) O1 - Hosts file is located at: C:\WINDOWS\help\hosts O1 - Hosts: 209.66.114.130 sitefinder.verisign.com O1 - Hosts: 88.88.88.88 elite O1 - Hosts: 207.44.220.30 www.google.akadns.net O1 - Hosts: 207.44.220.30 www.google.com O1 - Hosts: 207.44.220.30 google.com O1 - Hosts: 207.44.220.30 www.altavista.com O1 - Hosts: 207.44.220.30 altavista.com O1 - Hosts: 207.44.220.30 search.yahoo.com O1 - Hosts: 207.44.220.30 uk.search.yahoo.com O1 - Hosts: 207.44.220.30 ca.search.yahoo.com O1 - Hosts: 207.44.220.30 jp.search.yahoo.com O1 - Hosts: 207.44.220.30 au.search.yahoo.com O1 - Hosts: 207.44.220.30 de.search.yahoo.com O1 - Hosts: 207.44.220.30 search.yahoo.co.jp O1 - Hosts: 207.44.220.30 www.lycos.de O1 - Hosts: 207.44.220.30 www.lycos.ca O1 - Hosts: 207.44.220.30 www.lycos.jp O1 - Hosts: 207.44.220.30 www.lycos.co.jp O1 - Hosts: 207.44.220.30 alltheweb.com O1 - Hosts: 207.44.220.30 web.ask.com O1 - Hosts: 207.44.220.30 ask.com O1 - Hosts: 207.44.220.30 www.ask.com O1 - Hosts: 207.44.220.30 www.teoma.com O1 - Hosts: 207.44.220.30 search.aol.com O1 - Hosts: 207.44.220.30 www.looksmart.com O1 - Hosts: 207.44.220.30 auto.search.msn.com O1 - Hosts: 207.44.220.30 search.msn.com O1 - Hosts: 207.44.220.30 ca.search.msn.com O1 - Hosts: 207.44.220.30 fr.ca.search.msn.com O1 - Hosts: 207.44.220.30 search.fr.msn.be O1 - Hosts: 207.44.220.30 search.fr.msn.ch O1 - Hosts: 207.44.220.30 search.latam.yupimsn.com O1 - Hosts: 207.44.220.30 search.msn.at O1 - Hosts: 207.44.220.30 search.msn.be O1 - Hosts: 207.44.220.30 search.msn.ch O1 - Hosts: 207.44.220.30 search.msn.co.in O1 - Hosts: 207.44.220.30 search.msn.co.jp O1 - Hosts: 207.44.220.30 search.msn.co.kr O1 - Hosts: 207.44.220.30 search.msn.com.br O1 - Hosts: 207.44.220.30 search.msn.com.hk O1 - Hosts: 207.44.220.30 search.msn.com.my O1 - Hosts: 207.44.220.30 search.msn.com.sg O1 - Hosts: 207.44.220.30 search.msn.com.tw O1 - Hosts: 207.44.220.30 search.msn.co.za O1 - Hosts: 207.44.220.30 search.msn.de O1 - Hosts: 207.44.220.30 search.msn.dk O1 - Hosts: 207.44.220.30 search.msn.es O1 - Hosts: 207.44.220.30 search.msn.fi O1 - Hosts: 207.44.220.30 search.msn.fr O1 - Hosts: 207.44.220.30 search.msn.it O1 - Hosts: 207.44.220.30 search.msn.nl O1 - Hosts: 207.44.220.30 search.msn.no O1 - Hosts: 207.44.220.30 search.msn.se O1 - Hosts: 207.44.220.30 search.ninemsn.com.au O1 - Hosts: 207.44.220.30 search.t1msn.com.mx O1 - Hosts: 207.44.220.30 search.xtramsn.co.nz O1 - Hosts: 207.44.220.30 search.yupimsn.com O1 - Hosts: 207.44.220.30 uk.search.msn.com O1 - Hosts: 207.44.220.30 search.lycos.com O1 - Hosts: 207.44.220.30 www.lycos.com O1 - Hosts: 207.44.220.30 www.google.ca O1 - Hosts: 207.44.220.30 google.ca O1 - Hosts: 207.44.220.30 www.google.uk O1 - Hosts: 207.44.220.30 www.google.co.uk O1 - Hosts: 207.44.220.30 www.google.com.au O1 - Hosts: 207.44.220.30 www.google.co.jp O1 - Hosts: 207.44.220.30 www.google.jp O1 - Hosts: 207.44.220.30 www.google.at O1 - Hosts: 207.44.220.30 www.google.be O1 - Hosts: 207.44.220.30 www.google.ch O1 - Hosts: 207.44.220.30 www.google.de O1 - Hosts: 207.44.220.30 www.google.se O1 - Hosts: 207.44.220.30 www.google.dk O1 - Hosts: 207.44.220.30 www.google.fi O1 - Hosts: 207.44.220.30 www.google.fr O1 - Hosts: 207.44.220.30 www.google.com.gr O1 - Hosts: 207.44.220.30 www.google.com.hk O1 - Hosts: 207.44.220.30 www.google.ie O1 - Hosts: 207.44.220.30 www.google.co.il O1 - Hosts: 207.44.220.30 www.google.it O1 - Hosts: 207.44.220.30 www.google.co.kr O1 - Hosts: 207.44.220.30 www.google.com.mx O1 - Hosts: 207.44.220.30 www.google.nl O1 - Hosts: 207.44.220.30 www.google.co.nz O1 - Hosts: 207.44.220.30 www.google.pl O1 - Hosts: 207.44.220.30 www.google.pt O1 - Hosts: 207.44.220.30 www.google.com.ru O1 - Hosts: 207.44.220.30 www.google.com.sg O1 - Hosts: 207.44.220.30 www.google.co.th O1 - Hosts: 207.44.220.30 www.google.com.tr O1 - Hosts: 207.44.220.30 www.google.com.tw O1 - Hosts: 207.44.220.30 go.google.com O1 - Hosts: 207.44.220.30 google.at O1 - Hosts: 207.44.220.30 google.be O1 - Hosts: 207.44.220.30 google.de O1 - Hosts: 207.44.220.30 google.dk O1 - Hosts: 207.44.220.30 google.fi O1 - Hosts: 207.44.220.30 google.fr O1 - Hosts: 207.44.220.30 google.com.hk O1 - Hosts: 207.44.220.30 google.ie O1 - Hosts: 207.44.220.30 google.co.il O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\Program Files\ClearSearch\CSIE.DLL (file missing) O2 - BHO: (no name) - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\Program Files\DAP\DAPBHO.dll O2 - BHO: NavErrRedir Class - {4FC95EDD-4796-4966-9049-29649C80111D} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing) O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll O2 - BHO: (no name) - {96DA5BEE-4ACC-476C-B3EC-54C6730C4293} - C:\PROGRA~1\Comet\Install\Temp\brbho.dll (file missing) O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll (file missing) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\DAP\DAPIEBar.dll O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll (file missing) O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100. O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot O4 - HKLM\..\Run: [ABBYY Community Agent] C:\Program Files\ABBYY FineReader 5.0 Sprint\CAgent.exe O4 - HKLM\..\Run: [Launcher] "C:\Program Files\KFH\cl\launcher.exe" /P O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A O4 - HKLM\..\Run: [LVCOMS] C:\WINDOWS\System32\LVCOMS.EXE O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe O4 - HKLM\..\Run: [Image] rundll32 C:\WINDOWS\image.dll,Install O4 - HKLM\..\Run: [haZMVLtPk] C:\documents and settings\chris\local settings\temp\haZMVLtPk.exe O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe" O4 - HKLM\..\Run: [Dpi] C:\Program Files\Common Files\Dpi\dpi.exe O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe O4 - HKLM\..\Run: [VZUKc87bu] C:\documents and settings\chris\local settings\temp\VZUKc87bu.exe O4 - HKLM\..\Run: [Prein] C:\DOCUME~1\Chris\LOCALS~1\Temp\app1.tmp O4 - HKLM\..\Run: [Pcsv] C:\WINDOWS\system32\pcs\pcsvc.exe O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaE ngineMain O4 - HKLM\..\Run: [4X@95ME57C5BM8] C:\WINDOWS\SYSTEM32\QEP78K13.EXE O4 - HKCU\..\Run: [IM] C:\PROGRA~1\RRIM\aim.exe -cnetwait.odl O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A O4 - HKLM\..\Run: [LVCOMS] C:\WINDOWS\System32\LVCOMS.EXE O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe O4 - HKLM\..\Run: [Image] rundll32 C:\WINDOWS\image.dll,Install O4 - HKLM\..\Run: [haZMVLtPk] C:\documents and settings\chris\local settings\temp\haZMVLtPk.exe O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe" O4 - HKLM\..\Run: [Dpi] C:\Program Files\Common Files\Dpi\dpi.exe O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe O4 - HKLM\..\Run: [VZUKc87bu] C:\documents and settings\chris\local settings\temp\VZUKc87bu.exe O4 - HKLM\..\Run: [Prein] C:\DOCUME~1\Chris\LOCALS~1\Temp\app1.tmp O4 - HKLM\..\Run: [Pcsv] C:\WINDOWS\system32\pcs\pcsvc.exe O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaE ngineMain O4 - HKLM\..\Run: [4X@95ME57C5BM8] C:\WINDOWS\SYSTEM32\QEP78K13.EXE O4 - HKCU\..\Run: [IM] C:\PROGRA~1\RRIM\aim.exe -cnetwait.odl O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg.com/us.yimg.co...v45/yacscom.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/Acti...iveLauncher.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binar...StatsClient.cab O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/...ash/swflash.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} (WMService Class) - http://download.overpro.com/WildApp.cab |
|
#4
|
||||
|
||||
|
Also, go to c:\windows(or WINNT if you're using 2000)\system32\drivers\etc and open the hosts file. It doesn't have an extension, but you can open it with any text editor. Either delete the whole file (don't worry, it will be recreated the next time you open up any internet enabled application) or open the file and delete all the contents. It appears as if the spyware is using this file to redirect information from common websites to their own.
|
|
#5
|
||||
|
||||
|
OK thanks....I deleted all the hijack this stuff....I'm trying to delete the hosts file, but there are a couple of them called host in that folder:
hosts hosts.bho lmhosts Which ones should I delete? |
|
#6
|
||||
|
||||
|
Oh and another thing.....after deleting the hijack this files.....I got a bunch of icons on my desktop thats said 'backup....and a number' should i delete those or put them in a folder?
|
|
#7
|
||||
|
||||
|
Those are the files hijack this made for backup... id put them in a folder in case you deleted something that you needed... when your comppy is running all good than you can delete them. Im guessing you put hijackthis.exe on your desktop
__________________
www.llamamaster.com |
|
#8
|
||||
|
||||
|
Put them in a folder
delete both hosts files, leave lmhosts |
|
#9
|
||||
|
||||
|
You guys have been really helpful.....Now I can go back to google and other sites I was not able to go before. I just have one more question. How do I get rid of the stupid WildTangent folder on my computer? That was never there and now that I'm trying to delete it it says to make sure the disk is not full or write protected...etc. I think that's the reason why i'm still getting pop-ups. And for some reason that thing is also on my Control panel.....the icon says 'Web Drivel Control Panel'
|
|
#10
|
||||
|
||||
|
Wild Tangent isn't spyware per say. Its kinda like flash. It used to come with WinAmp, it was a way to play games online and play mini games that could be streamed to your computer on demand.
The reason you can't delete it is because the program is running, and loaded into memory. Heres intstructions on removal (assuming you haven't deleted files needed to remove the whole program) http://wildtangent.custhelp.com/cgi-...cGFnZT0x&p_li= |
![]() |
| Tags |
| spyware |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Spyware...Help me get rid of it | demuthp | System Infection Support | 8 | Feb 24th, 05 12:32 PM |
| spyware | Supra | Internet | 3 | Feb 13th, 05 9:59 AM |
| Help Me Please - Spyware | javierito | System Infection Support | 4 | Sep 16th, 04 4:59 AM |
| Help with spyware!!!!!!!! | mike m | System Infection Support | 3 | Jul 21st, 04 6:53 PM |
| Spyware Help | karansaraf | Software Support | 7 | Jul 14th, 04 12:05 AM |