User User name Password  
   
Friday 29.8.2025 / 15:33
Search AfterDawn Forums:        In English   Suomeksi   På svenska
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > another "hijack" log that needs checking thanks
Show topics
 
Forums
Forums
Another "Hijack" log that needs checking THANKS
  Jump to:
 
Posted Message
Senior Member
_
13. January 2007 @ 01:21 _ Link to this message    Send private message to this user   
Actually, that report is wonderful. I was expecting the Zango and MyWebSearch reg keys to return, but they're gone now. :-)

Quote:
What do I do with the nasty little zip file called Avenger, back up zip.
Delete it, it's not needed.

Delete the KillBox backup folder:
C:\!KillBox

This cookie you will have to delete manually:
C:\Documents and Settings\LocalService\Cookies\system@mysearch[2].txt


Copy the following bold text into Notepad.

REGEDIT4

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{99410cde-6f16-42ce-9d49-3807f78f0287}]


Name the file Fix.reg
Change the "Save as Type" to All Files and save it on the desktop.
Open the Fix.reg file and click Yes when prompted to merge.


Quote:
I have traced the Hacking Tool/Rootkit to a file named
C:\Documents and Settings\nton\My Documents\desktop.ini
Open the desktop.ini with Notepad and post the contents here.

Advertisement
_
__
AfterDawn Addict
_
13. January 2007 @ 01:33 _ Link to this message    Send private message to this user   
Before I do anything, this scan has only just finished, looks like there's 2 Hacking and Rootkit now

cident Status Location

Potentially unwanted tool:application/zango Not disinfected HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{99410cde-6f16-42ce-9d49-3807f78f0287}
Spyware:Cookie/Mysearch Not disinfected C:\Documents and Settings\LocalService\Cookies\system@mysearch[2].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
Heres the .ini file contents

DeleteOnCopy]
Owner=nton
Personalized=5
PersonalizedName=My Documents



guide by ScubaPete http://www.dvdplusvideo.com/tutorial007.html Nero guide by alkohol http://www.dvdplusvideo.com/Guides/alkohol_guide3.html

New RipIt4Me + DVD Shrink + ImgBurn guid <==== Rip any DVDs http://forums.afterdawn.com/thread_view.cfm/422740 Guides by bbmayo..... http://webpages.charter.net/bacitup/
Senior Member
_
13. January 2007 @ 02:20 _ Link to this message    Send private message to this user   
Nothing to worry about. Just use the regfix and you'll be fine.

AfterDawn Addict
_
13. January 2007 @ 02:24 _ Link to this message    Send private message to this user   
Can I just delete the ini file and do I use reg.fix on

C:\WINDOWS\system32\Process.exe




guide by ScubaPete http://www.dvdplusvideo.com/tutorial007.html Nero guide by alkohol http://www.dvdplusvideo.com/Guides/alkohol_guide3.html

New RipIt4Me + DVD Shrink + ImgBurn guid <==== Rip any DVDs http://forums.afterdawn.com/thread_view.cfm/422740 Guides by bbmayo..... http://webpages.charter.net/bacitup/
bkf
Suspended due to non-functional email address
_
13. January 2007 @ 02:29 _ Link to this message    Send private message to this user   
You two put alot of time and super human effort into this system. And I know you want to beat this monster, but I question the stability and security of the system when you finish. Me I would have allready formatted or taken the drive to the back yard and shot it. I think you have used just about every program known to kill this but I have to think even those programs have holes. I know it's a matter of personal pride but Gwen you got something that just defies the rules of nature. These hackers are getting very good (bless their hearts I would like to take them all out and hang them) Niobis has the smarts for virus killing and Gwen you have the smarts to move all your important stuff to other drives in what appears to be a very largy system. I know it's a pain in the butt and for me a full reload would be atleast a week or more without a ghost image. I follow this thread everyday and would like to hear your thoughts. Bk

Gwen: After reading your last posts I rebuilt my ghost image just to keep it up to date. That was after runing every anti everything I could think of. My system shows no problems or issues at the moment but im sure my time is coming as well. The ghost image sits on 5 DVD's as well as another drive just to make sure. I only ghost the OS because all the other drives only contain data and they sit on a couple of hunderd DVD's. Ken

This message has been edited since posting. Last time this message was edited on 13. January 2007 @ 02:45

Senior Member
_
13. January 2007 @ 02:40 _ Link to this message    Send private message to this user   
@gwendolin, NO, do not delete the desktop.ini file. It is a necessary system file.
Quote:

do I use reg.fix on C:\WINDOWS\system32\Process.exe
No, process.exe belongs to SmitfraudFix. It's a process that stops process. AV's can't determine the difference between good and bad, so they're all flagged bad.

Use the regfix for the Zango registry entry.


@bkf,

Quote:
but I question the stability and security of the system when you finish.
You're right in thinking that. Haxdoor is a backdoor and usually with all backdoors the HD should be reformatted. But, Haxdoor is easily removed in most cases. This case in particular is very odd because Haxfix would not remove the rootkit hidden files. If you read back and follow the Haxfix log, you'll see that Haxdoor itself was removed early. The problem was removing the info files. Info files themselves are not really malicious, so there wasn't much to be worried about.

This message has been edited since posting. Last time this message was edited on 13. January 2007 @ 02:41

AfterDawn Addict
_
13. January 2007 @ 02:41 _ Link to this message    Send private message to this user   
@bkf, I am NOT very computer smart, nor am I rich so I think I will just "hang in there" with niobis and see if we can beat this thing. Already he has solved the Virus problem and I'm sure he'll find a way to get rid of the Hacking Tools and Rootkit (whatever they are)

So niobis if you're still there then so am I...lets kill the "beast"

Quote:
Use the regfix for the Zango registry entry.
Yep, done that



guide by ScubaPete http://www.dvdplusvideo.com/tutorial007.html Nero guide by alkohol http://www.dvdplusvideo.com/Guides/alkohol_guide3.html

New RipIt4Me + DVD Shrink + ImgBurn guid <==== Rip any DVDs http://forums.afterdawn.com/thread_view.cfm/422740 Guides by bbmayo..... http://webpages.charter.net/bacitup/

This message has been edited since posting. Last time this message was edited on 13. January 2007 @ 02:43

bkf
Suspended due to non-functional email address
_
13. January 2007 @ 02:48 _ Link to this message    Send private message to this user   
I agree! Kill the beast! But I had to ask. The best and ill keep reading. Again super human effort on both your parts :-)

"@bkf, I am NOT very computer smart"
I think you under estimate yourself. Very few in here could stay the course with what you have been working through.

This message has been edited since posting. Last time this message was edited on 13. January 2007 @ 03:02

Senior Member
_
13. January 2007 @ 02:55 _ Link to this message    Send private message to this user   
Quote:
So niobis if you're still there then so am I...lets kill the "beast"
Umm, I think we're done. You're computer is clean now.

AfterDawn Addict
_
13. January 2007 @ 03:00 _ Link to this message    Send private message to this user   
@niobis, Once again I would like to thank you for ALL your help, I'm so glad you persisted with the problem..as I said if ever I can return the favour then let me know.

AD should be PROUD that they have members such as yourself who give their time FREELY AND WILLINGLY to help others. Cheers.



guide by ScubaPete http://www.dvdplusvideo.com/tutorial007.html Nero guide by alkohol http://www.dvdplusvideo.com/Guides/alkohol_guide3.html

New RipIt4Me + DVD Shrink + ImgBurn guid <==== Rip any DVDs http://forums.afterdawn.com/thread_view.cfm/422740 Guides by bbmayo..... http://webpages.charter.net/bacitup/
Senior Member
_
13. January 2007 @ 07:17 _ Link to this message    Send private message to this user   
Double post.

This message has been edited since posting. Last time this message was edited on 13. January 2007 @ 07:19

Senior Member
_
13. January 2007 @ 07:17 _ Link to this message    Send private message to this user   
gwendolin, you need not return the favor. I'm the one returning the favor for your assistance last year.

You're very welcome. And again, if anything else comes up just let me know and I'll help where I can.

AfterDawn Addict
_
13. January 2007 @ 20:33 _ Link to this message    Send private message to this user   
I originally posted here as I thought I had a virus when my Nero 7, which I recently updated from filehippo, took several minutes to respond. After the cleaning of Virus etc I found Nero still was acting up, taking several minutes to respond so I decided to remove it from my comp....that was easier said than done, it took almost 45 minutes, it would just hang and refused to budge, tried Clean tool , same thing, kept trying and eventually managed to delete it from HD..d/l latest version, 7.5.9.0a directly from Nero.com and no more problems.
Question, could I have possibly got the "Nasties" from my Nero download through filehippo.



guide by ScubaPete http://www.dvdplusvideo.com/tutorial007.html Nero guide by alkohol http://www.dvdplusvideo.com/Guides/alkohol_guide3.html

New RipIt4Me + DVD Shrink + ImgBurn guid <==== Rip any DVDs http://forums.afterdawn.com/thread_view.cfm/422740 Guides by bbmayo..... http://webpages.charter.net/bacitup/
Senior Member
_
14. January 2007 @ 15:42 _ Link to this message    Send private message to this user   
Quote:
could I have possibly got the "Nasties" from my Nero download through filehippo.
Doubt it. FileHippo is a really good site and I've never known any file to be infected from them.

AfterDawn Addict
_
14. January 2007 @ 15:54 _ Link to this message    Send private message to this user   
I dont believe it, it appears to be back

Logfile of HijackThis v1.99.1
Scan saved at 10:45:53 AM, on 1/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\WINDOWS\vsnpstd2.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
c:\program files\internet explorer\iexplore.exe
C:\Documents and Settings\nton \Desktop\all my copying programs\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.69:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-au\msntb.dll
O3 - Toolbar: ninemsn - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-au\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner...can_unicode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Mes...nt.cab30149.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} - http://www.miniclip.com/bestfriends/miniclipGameLoader.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Share...bin/AvSniff.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared...01/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Share...n/bin/cabsa.cab
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://mvt.mcafee.com/mvt/bin/3,0,0,0/mvt.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Mes...nt.cab30149.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-lo...784/mcfscan.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Sol...wn.cab31267.cab
O18 - Protocol: bw+0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: offline-8876480 - {6C26BC7B-1D63-4DEA-A8D6-64507DD1A831} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe


Activescan Log

Incident Status Location

Potentially unwanted tool:application/zango Not disinfected HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{0AC49246-419B-4EE0-8917-8818DAAD6A4E}



guide by ScubaPete http://www.dvdplusvideo.com/tutorial007.html Nero guide by alkohol http://www.dvdplusvideo.com/Guides/alkohol_guide3.html

New RipIt4Me + DVD Shrink + ImgBurn guid <==== Rip any DVDs http://forums.afterdawn.com/thread_view.cfm/422740 Guides by bbmayo..... http://webpages.charter.net/bacitup/
Senior Member
_
14. January 2007 @ 17:51 _ Link to this message    Send private message to this user   
You had me really worried there for a moment, lol. I thought you meant Haxdoor was back.

No, it's a different registry entry, notice the different numbers. Any time a subkey like this one shows up, follow the same directions. All you do is add [-] around the entry. [] around the entire key and - after the first [ as in subtracting the key.

Copy the following bold text into Notepad.

REGEDIT4

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{0AC49246-419B-4EE0-8917-8818DAAD6A4E}]


Name the file Fix.reg
Change the "Save as Type" to All Files and save it on the desktop.
Open the Fix.reg file and click Yes when prompted to merge.

Edit: I hope I made that comprehendable. :-)

This message has been edited since posting. Last time this message was edited on 14. January 2007 @ 17:53

Advertisement
_
__
 
_
AfterDawn Addict
_
14. January 2007 @ 18:03 _ Link to this message    Send private message to this user   
Thanks again, I should be able to do that in my sleep by now. Will do ASAP, Cheers.



guide by ScubaPete http://www.dvdplusvideo.com/tutorial007.html Nero guide by alkohol http://www.dvdplusvideo.com/Guides/alkohol_guide3.html

New RipIt4Me + DVD Shrink + ImgBurn guid <==== Rip any DVDs http://forums.afterdawn.com/thread_view.cfm/422740 Guides by bbmayo..... http://webpages.charter.net/bacitup/
 
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > another "hijack" log that needs checking thanks
 

Digital video: AfterDawn.com | AfterDawn Forums
Music: MP3Lizard.com
Gaming: Blasteroids.com | Blasteroids Forums | Compare game prices
Software: Software downloads
Blogs: User profile pages
RSS feeds: AfterDawn.com News | Software updates | AfterDawn Forums
International: AfterDawn in Finnish | AfterDawn in Swedish | AfterDawn in Norwegian | download.fi
Navigate: Search | Site map
About us: About AfterDawn Ltd | Advertise on our sites | Rules, Restrictions, Legal disclaimer & Privacy policy
Contact us: Send feedback | Contact our media sales team
 
  © 1999-2025 by AfterDawn Ltd.

  IDG TechNetwork