|  | 
 
															
															
	
			
			
				| ulwindowseek & ulwindowURL & Virus Alert Icon |  |  
					
					
				 
						| TommieMUCNewbie 
   | 6. June 2006 @ 07:45 |  Link to this message   |  
						| 
							
							Hi,
every five minutes 2 windows with "ulwindowseek & ulwindowURL" open. & on my toolbar there is Virus Alert Icon & Virus Alert Popup that tells me that my computer is infected and when I click on it, there is a website for a free spyware remover... but i think its better not to download it..
 I tried to do my very best, reading in forums and so on, but I have to give up. Can somebody help me? ... please!
 
 Thanks.
 
 This is my HighJack Logfile:
 Logfile of HijackThis v1.99.1
 Scan saved at 17:42:57, on 06.06.2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
 C:\Programme\Norton Internet Security\ISSVC.exe
 C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe
 C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\system32\brsvc01a.exe
 C:\WINDOWS\system32\brss01a.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
 c:\Programme\LRZ VPN Client\cvpnd.exe
 C:\Programme\Norton Internet Security\Norton AntiVirus\navapsvc.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe
 C:\Programme\Java\jre1.5.0_05\bin\jusched.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Programme\QuickTime\qttask.exe
 C:\Programme\Power Manager\PM.exe
 C:\Programme\ScanSoft\PaperPort\pptd40nt.exe
 C:\WINDOWS\system32\igfxtray.exe
 C:\Programme\ICQLite\ICQLite.exe
 C:\WINDOWS\system32\hkcmd.exe
 C:\Programme\Brother\ControlCenter2\brctrcen.exe
 C:\Programme\Apoint2K\Apoint.exe
 C:\WINDOWS\AGRSMMSG.exe
 C:\Programme\Messenger\msmsgs.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programme\Apoint2K\Apntex.exe
 C:\Programme\GetRight\getright.exe
 C:\Programme\GetRight\getright.exe
 C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 C:\Programme\Internet Explorer\IEXPLORE.EXE
 C:\Programme\Mozilla Firefox\firefox.exe
 C:\Dokumente und Einstellungen\Thomas\Desktop\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
 F2 - REG:system.ini: UserInit=userinit.exe
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Programme\GetRight\xx2gr.dll
 O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programme\Gemeinsame Dateien\Symantec Shared\AdBlocking\NISShExt.dll
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programme\Norton Internet Security\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programme\Gemeinsame Dateien\Symantec Shared\AdBlocking\NISShExt.dll
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton Internet Security\Norton AntiVirus\NavShExt.dll
 O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
 O4 - HKLM\..\Run: [Zone Labs Client] "C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe"
 O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Programme\Norton Internet Security\UrlLstCk.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\jre1.5.0_05\bin\jusched.exe
 O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [SetDefPrt] C:\Programme\Brother\Brmfl05a\BrStDvPt.exe
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [PowerManager] C:\Programme\Power Manager\PM.exe
 O4 - HKLM\..\Run: [PaperPort PTD] C:\Programme\ScanSoft\PaperPort\pptd40nt.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [IndexSearch] C:\Programme\ScanSoft\PaperPort\IndexSearch.exe
 O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
 O4 - HKLM\..\Run: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -minimize
 O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
 O4 - HKLM\..\Run: [Google Desktop Search] "C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe" /startup
 O4 - HKLM\..\Run: [ControlCenter2.0] C:\Programme\Brother\ControlCenter2\brctrcen.exe /autorun
 O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [Apoint] C:\Programme\Apoint2K\Apoint.exe
 O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Programme\GetRight\getright.exe
 O4 - Global Startup: LRZ VPN Client.lnk = C:\Programme\LRZ VPN Client\vpngui.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE
 O4 - Global Startup: Status Monitor.lnk = C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe
 O8 - Extra context menu item: Download with GetRight - C:\Programme\GetRight\GRdownload.htm
 O8 - Extra context menu item: Open with GetRight Browser - C:\Programme\GetRight\GRbrowse.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_05\bin\npjpi150_05.dll
 O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_05\bin\npjpi150_05.dll
 O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
 O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
 O9 - Extra button: @C:\Programme\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: @C:\Programme\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
 O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
 O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccProxy.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
 O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Programme\LRZ VPN Client\cvpnd.exe
 O23 - Service: AVM FRITZ!web Routing Service (de_serv) - Unknown owner - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe (file missing)
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Programme\Norton Internet Security\ISSVC.exe
 O23 - Service: Norton AntiVirus Auto-Protect-Dienst (navapsvc) - Symantec Corporation - C:\Programme\Norton Internet Security\Norton AntiVirus\navapsvc.exe
 O23 - Service: PACSPTISVR - Sony Corporation - C:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\PACSPTISVR.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Programme\Norton Internet Security\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\GEMEIN~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\SPTISRV.exe
 
 
 Thanks, Thomas |  
						| Advertisement   |   |  
						|  |  
						| Johnny_JNewbie 
   | 6. June 2006 @ 08:18 |  Link to this message   |  
						| 
							
							^ i've got the same and maybe some more spyware if someone could help me too please.
 Logfile of HijackThis v1.99.1
 Scan saved at 17:16:05, on 06/06/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\LEXBCES.EXE
 C:\WINDOWS\system32\LEXPPS.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\System32\CTSvcCDA.EXE
 C:\mysql\bin\mysqld-nt.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\System32\MsPMSPSv.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\wscntfy.exe
 C:\WINDOWS\system32\gsicon.exe
 C:\WINDOWS\system32\dslagent.exe
 C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
 C:\WINDOWS\vsnpstd.exe
 C:\Program Files\Microsoft IntelliType Pro\type32.exe
 C:\Program Files\MessengerPlus! 3\MsgPlus.exe
 C:\Program Files\Winamp\winampa.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 C:\program files\valve\steam\steam.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\DOCUME~1\Alex\APPLIC~1\CROSOF~1\javaw.exe
 C:\WINDOWS\SMANTE~1\fast.exe
 C:\Program Files\Microsoft Office\Office\OSA.EXE
 C:\Program Files\MSN Messenger\msnmsgr.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 C:\Documents and Settings\Alex\Desktop\tool.com
 C:\Program Files\mIRC\mirc.exe
 C:\WINDOWS\TEMP\win1A3.tmp.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Documents and Settings\Alex\Desktop\hijackthis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.btbroadbandstart.com/
 R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
 F2 - REG:system.ini: UserInit=userinit.exe
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
 O3 - Toolbar: PowerSearch - {4E7BD74F-2B8D-469E-C6ED-ED6AA787AD2D} - C:\PROGRA~1\POWERS~1\Toolbar\pwrsfrst.dll (file missing)
 O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll (file missing)
 O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll (file missing)
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O4 - HKLM\..\Run: [SUPASTATUS] C:\Program Files\Internet Explorer\Connection Wizard\Status.exe
 O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
 O4 - HKLM\..\Run: [GSICONEXE] gsicon.exe
 O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
 O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
 O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
 O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
 O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
 O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
 O4 - HKLM\..\Run: [Registry Toolkit] C:\Program Files\Registry Toolkit\RegToolkit.exe /scan
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
 O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
 O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
 O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
 O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
 O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [GoldenFTPserver] "C:\Program Files\Golden FTP Server\GFTP.exe"
 O4 - HKCU\..\Run: [Hoow] "C:\DOCUME~1\Alex\APPLIC~1\CROSOF~1\javaw.exe" -vt yazb
 O4 - HKCU\..\Run: [Klkdn] C:\WINDOWS\SMANTE~1\fast.exe
 O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
 O4 - Global Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband\Help\bin\matcli.exe
 O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
 O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
 O8 - Extra context menu item: Download Using &BitSpirit - D:\BitSpirit\bsurl.htm
 O8 - Extra context menu item: Save Flash - res://C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/210
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
 O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
 O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra button: Flash - {43CF38F3-5AEC-45a3-AD31-04EB06E9C6CA} - C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll (HKCU)
 O10 - Broken Internet access because of LSP provider 'xfire_lsp_10650.dll' missing
 O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/SU/ocx/12119/CTSUEng.cab
 O16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\ied_s7.cab
 O16 - DPF: {11111111-1111-1111-1111-511111113457} - file://c:\x.cab
 O16 - DPF: {11111111-1111-1111-1111-511111113458} - file://c:\x.cab
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
 O16 - DPF: {2B36F775-8CF5-4489-B454-2D1B80984CF2} (FXPluginCtl Object) - http://www.powerflasher.de/plugin/powerres.cab
 O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.2.76.cab
 O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple...
 O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x8...
 O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
 O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
 O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
 O16 - DPF: {D3D83E08-54D1-4E9D-8EAF-9F979D139294} (MaxisSimCityScapeTeleX Control) - http://simcity.ea.com/scape/teleport/MaxisSimCityScapeTeleX.cab
 O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
 O16 - DPF: {F2A84794-EE6D-447B-8C21-3BA1DC77C5B4} (SDKInstall Class) - http://activex.microsoft.com/activex/controls/sdkupdate/sdkinst.cab
 O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
 O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/SU/ocx/12119/CTPID.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{F675233E-CA41-46CD-B208-6CF871678202}: NameServer = 62.6.40.178 194.72.9.38
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O20 - AppInit_DLLs:    C:\WINDOWS\system32\netdde.dll
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O20 - Winlogon Notify: winjyp32 - C:\WINDOWS\SYSTEM32\winjyp32.dll
 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
 O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
 O23 - Service: MySQL - Unknown owner - C:\mysql\bin\mysqld-nt.exe
 O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
 O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
 |  
						| Senior Member 
   | 6. June 2006 @ 10:35 |  Link to this message   |  
						| 
							
							@TommieMUC
 Hi, you got a smitfraud infection...
 
 Download SmitfraudFix.zip to your desktop -> http://siri.urz.free.fr/Fix/SmitfraudFix.zip
 
 Unzip it (folder named SmitFraudFix) to your desktop:
 
 Open the folder SmitfraudFix and doubleclick smitfraudfix.cmd
 Choose option #1 - Search by typing 1 and pressing "Enter"; a textfile opens and lists the infected files (if those exist)
 
 Post the contents of this textfile to here.
 
 (Some antiviruses recognises process.exe as a malware. It is not malware, it is a program that stops processes)
 
 @Johnny_J
 
 Hi, you got more than one infections there...
 
 Download SmitfraudFix.zip to your desktop -> http://siri.urz.free.fr/Fix/SmitfraudFix.zip
 
 Unzip it (folder named SmitFraudFix) to your desktop:
 
 Open the folder SmitfraudFix and doubleclick smitfraudfix.cmd
 Choose option #1 - Search by typing 1 and pressing "Enter"; a textfile opens and lists the infected files (if those exist)
 
 Post the contents of this textfile to here.
 
 (Some antiviruses recognises process.exe as a malware. It is not malware, it is a program that stops processes)
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| Johnny_JNewbie 
   | 6. June 2006 @ 13:28 |  Link to this message   |  
						| 
							
							SmitFraudFix v2.55
 Scan done at 22:27:26.01, 06/06/2006
 Run from C:\Documents and Settings\Alex\Desktop\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
 Fix ran in normal mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Alex\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»»
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="My Current Home Page"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 ------------------------
 Thankyou in advance!
 |  
						| Advertisement   |   |  
						| 
 |  
						| Senior Member 
   | 7. June 2006 @ 07:51 |  Link to this message   |  
						| 
							
							@Johnny_J
 You have two firewalls running at the same time, Sygate and ZoneAlarm, this is not recommended and you should remove one of them.
 
 Go to Control Panel -> Add/Remove programs -> Remove Sygate or ZoneAlarm
 
 Cleaning instructions:
 
 Move HijackThis into its own folder C:\HJT
 
 Download and install Ewido anti-malware -> http://www.ewido.net/en/download
 Update it, but do NOT run a scan yet. We'll use it later.
 
 Download ATF Cleaner by Atribune to your desktop -> http://www.atribune.org/ccount/click.php?id=1
 Do NOT run yet.
 
 Go to Control Panel -> Add/Remove programs -> Remove PowerSearch, PuritySCAN By OIN, OuterInfo, OIN  or similar ,
 
 If PuritySCAN By OIN, OuterInfo, OIN  aren't not listed, download and run this uninstaller:
 http://www.outerinfo.com/OiUninstaller.exe
 
 Tutorial for the uninstaller if needed -> http://www.outerinfo.com/howto.html
 
 Run HijackThis. Press Do a system scan only, then close all other windows, checkmark the following entries and press Fix checked
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
 R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
 O3 - Toolbar: PowerSearch - {4E7BD74F-2B8D-469E-C6ED-ED6AA787AD2D} - C:\PROGRA~1\POWERS~1\Toolbar\pwrsfrst.dll (file missing)
 O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll (file missing)
 O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll (file missing)
 O16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\ied_s7.cab
 O16 - DPF: {11111111-1111-1111-1111-511111113457} - file://c:\x.cab
 O16 - DPF: {11111111-1111-1111-1111-511111113458} - file://c:\x.cab
 O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
 O20 - AppInit_DLLs: C:\WINDOWS\system32\netdde.dll
 O20 - Winlogon Notify: winjyp32 - C:\WINDOWS\SYSTEM32\winjyp32.dll
 
 Make your hidden files visible -> http://www.bleepingcomputer.com/tutorials/tutorial62.html
 Restart your computer to the safemode -> http://www.pchell.com/support/safemode.shtml
 
 Delete these folders (if found):
 C:\Program Files\PurityScan
 C:\Program Files\PowerSearch
 
 Delete these files (if found):
 C:\WINDOWS\system32\netdde.dll
 C:\WINDOWS\SYSTEM32\winjyp32.dll
 
 Run ATF Cleaner -> Check select all -> Press Empty selected
 
 Scan and clean your computer with Ewido and save the report.
 
 Clean the Recycle bin and make your hidden files visible again.
 
 Restart your computer normally.
 
 Post the following logs to here:
 -> a fresh HijackThis log
 -> Ewido's log
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  |