afterdawn.com > forums > consoles > sony psp - mod and firmware discussion > dear jesus someone please help me!!!!
DEAR JESUS SOMEONE PLEASE HELP ME!!!!
chriskarl
Newbie
24. July 2006 @ 15:03
Link to this message
Okay folks i need some help. Every time i go to log on my internet explorer i get a error message. w32.myzor.fk@yf The only option is ok. It tells me that the virus attempts to steal private information. When i click okay it takes me to a web page that wants me to buy software to get rid of it. I've been around the block with that mess before and I don't want to buy yet another program to get rid of something i dont need. i scanned my computer with highjack this.
> here is my log. someone please help me!! ASAP
>
> Logfile of HijackThis v1.99.1
> Scan saved at 9:55:25 PM, on 7/22/2006
> Platform: Windows XP SP2 (WinNT 5.01.2600)
> MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
>
> Running processes:
> C:\WINDOWS\System32\smss.exe
> C:\WINDOWS\system32\winlogon.exe
> C:\WINDOWS\system32\services.exe
> C:\WINDOWS\system32\lsass.exe
> C:\WINDOWS\system32\svchost.exe
> C:\WINDOWS\System32\svchost.exe
> C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
> C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
> C:\WINDOWS\system32\spoolsv.exe
> C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
> C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
> C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
> C:\WINDOWS\system32\DVDRAMSV.exe
> C:\WINDOWS\eHome\ehRecvr.exe
> C:\WINDOWS\eHome\ehSched.exe
> c:\program files\mcafee.com\agent\mcdetect.exe
> c:\PROGRA~1\mcafee.com\vso\mcshield.exe
> c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
> C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
> c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
> C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
> C:\WINDOWS\Explorer.EXE
> C:\WINDOWS\system32\dcomcfg.exe
> C:\WINDOWS\system32\atmclk.exe
> C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
> C:\WINDOWS\system32\TDispVol.exe
> C:\PROGRA~1\mcafee.com\agent\mcagent.exe
> C:\WINDOWS\system32\igfxtray.exe
> C:\WINDOWS\system32\hkcmd.exe
> C:\WINDOWS\system32\igfxpers.exe
> C:\WINDOWS\ehome\ehtray.exe
> C:\Program Files\Protector Suite QL\psqltray.exe
> C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
> C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
> C:\Program Files\ltmoh\Ltmoh.exe
> C:\Program Files\Synaptics\SynTP\Toshiba.exe
> C:\WINDOWS\AGRSMMSG.exe
> C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
> C:\Program Files\Toshiba\Tvs\TvsTray.exe
> C:\WINDOWS\system32\TPSMain.exe
> C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
> C:\WINDOWS\system32\dla\DLACTRLW.exe
> C:\toshiba\ivp\ism\pinger.exe
> C:\WINDOWS\system32\dllhost.exe
> C:\WINDOWS\system32\TPSBattM.exe
> C:\Program Files\McAfee.com\VSO\oasclnt.exe
> C:\WINDOWS\eHome\ehmsas.exe
> c:\program files\mcafee.com\vso\mcvsshld.exe
> C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
> C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
> C:\Program Files\Common Files\AOL\1140083713\ee\AOLSoftware.exe
> C:\Program Files\iTunes\iTunesHelper.exe
> C:\Program Files\QuickTime\qttask.exe
> C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
> C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
> C:\Program Files\iPod\bin\iPodService.exe
> C:\WINDOWS\system32\ctfmon.exe
> C:\Program Files\Messenger\msmsgs.exe
> C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
> C:\WINDOWS\system32\wscntfy.exe
> C:\Program Files\Metamail Inc\Metamail Tray\Metamail Trust Manager.exe
> C:\WINDOWS\system32\RAMASST.exe
> C:\PROGRA~1\METAMA~1\METAMA~1\METAMA~2.EXE
> C:\WINDOWS\system32\svchost.exe
> C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
> C:\WINDOWS\system32\wuauclt.exe
> C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
> C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
> C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
> C:\Program Files\Grisoft\AVG Free\avgcc.exe
> C:\Program Files\SpyHeal\SpyHeal.exe
> C:\Program Files\SpyHeal\SpyHeal.exe
> C:\Program Files\Internet Explorer\iexplore.exe
> C:\Documents and Settings\Chris lewellyan\Local Settings\Temporary Internet
> Files\Content.IE5\8RB3AW55\HijackThis_v1.99.1[2].exe
>
> R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
> http://g.msn.com/0SEENUS/SAOS01 > R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
> http://www.toshibadirect.com/dpdstart > R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D}
> - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
> O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
> C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
> O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} -
> C:\WINDOWS\System32\DLA\DLASHX_W.DLL
> O2 - BHO: (no name) - {5f4c3d09-b3b9-4f88-aa82-31332fee1c08} -
> C:\WINDOWS\system32\hp100.tmp
> O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} -
> C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
> O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN
> Apps\ST\01.03.0000.1005\en-xu\stmain.dll
> O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
> c:\program files\google\googletoolbar2.dll
> O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program
> Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
> O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} -
> c:\progra~1\mcafee.com\vso\mcvsshl.dll
> O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} -
> C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
> O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program
> Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
> O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
> files\google\googletoolbar2.dll
> O3 - Toolbar: SecurityToolbar - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} -
> C:\Program Files\Security Toolbar\Security Toolbar.dll
> O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
> O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
> O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
> O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
> O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
> O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
> O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
> O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite
> QL\launcher.exe" /startup
> O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
> O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba
> Applet\thotkey.exe
> O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
> O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
> O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
> O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
> O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
> O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
> O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
> O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and
> Launch\PadExe.exe
> O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming
> Utility\SmoothView.exe
> O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\DLACTRLW.exe
> O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
> O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe"
> /checktask
> O4 - HKLM\..\Run: [VirusScan Online] C:\Program
> Files\McAfee.com\VSO\mcvsshld.exe
> O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
> O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program
> Files\Intel\Wireless\bin\ZCfgSvc.exe"
> O4 - HKLM\..\Run: [IntelWireless] "C:\Program
> Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
> O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common
> Files\AOL\1140083713\ee\AOLSoftware.exe
> O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common
> Files\AOL\IPHSend\IPHSend.exe
> O4 - HKLM\..\Run: [Pure Networks Port Magic]
> "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
> O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
> O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
> O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"
> -atboottime
> O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
> O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
> O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone
> Labs\ZoneAlarm\zlclient.exe
> O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
> O4 - HKLM\..\Run: [SpyHeal] C:\Program Files\SpyHeal\SpyHeal.exe /h
> O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
> O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
> O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
> O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe"
> /background
> O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common
> Files\AOL\Launch\AOLLaunch.exe" /d locale=en-us ee://aol/imApp
> O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common
> Files\Adobe\Calibration\Adobe Gamma Loader.exe
> O4 - Global Startup: Metamail Trust Manager.lnk = C:\Program Files\Metamail
> Inc\Metamail Tray\Metamail Trust Manager.exe
> O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
> O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol
> toolbar 3.1\resources\en-US\local\search.html
> O8 - Extra context menu item: &Google Search - res://c:\program
> files\google\GoogleToolbar2.dll/cmsearch.html
> O8 - Extra context menu item: &Translate English Word - res://c:\program
> files\google\GoogleToolbar2.dll/cmwordtrans.html
> O8 - Extra context menu item: Backward Links - res://c:\program
> files\google\GoogleToolbar2.dll/cmbacklinks.html
> O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program
> files\google\GoogleToolbar2.dll/cmcache.html
> O8 - Extra context menu item: E&xport to Microsoft Excel -
> res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
> O8 - Extra context menu item: Similar Pages - res://c:\program
> files\google\GoogleToolbar2.dll/cmsimilar.html
> O8 - Extra context menu item: Translate Page into English - res://c:\program
> files\google\GoogleToolbar2.dll/cmtrans.html
> O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
> C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
> O9 - Extra 'Tools' menuitem: Sun Java Console -
> {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
> Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
> O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} -
> C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
> O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
> C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
> O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
> C:\WINDOWS\system32\Shdocvw.dll
> O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
> C:\Program Files\Messenger\msmsgs.exe
> O9 - Extra 'Tools' menuitem: Windows Messenger -
> {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
> O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart > O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} -
> "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
> O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
> O20 - Winlogon Notify: psfus - C:\WINDOWS\SYSTEM32\psqlpwd.dll
> O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
> O21 - SSODL: altmannsberger - {210b4043-35ca-4aa0-8796-191f9663dfb3} -
> C:\WINDOWS\system32\vpxnk.dll (file missing)
> O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common
> Files\Adobe Systems Shared\Service\Adobelmsvc.exe
> O23 - Service: AOL Connectivity Service (AOL ACS) - America Online -
> C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
> O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online,
> Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
> O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner -
> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
> O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -
> C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
> O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -
> C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
> O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. -
> C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
> O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. -
> C:\WINDOWS\system32\ZoneLabs\isafe.exe
> O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program
> Files\TOSHIBA\ConfigFree\CFSvcs.exe
> O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. -
> C:\WINDOWS\system32\DVDRAMSV.exe
> O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation
> - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
> O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision
> Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel
> 32\IDriverT.exe
> O23 - Service: iPodService - Apple Computer, Inc. - C:\Program
> Files\iPod\bin\iPodService.exe
> O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc -
> c:\program files\mcafee.com\agent\mcdetect.exe
> O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. -
> c:\PROGRA~1\mcafee.com\vso\mcshield.exe
> O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc -
> c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
> O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee,
> Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
> O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel
> Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
> O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel
> Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
> O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
> O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. -
> C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
> O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC -
> C:\WINDOWS\system32\ZoneLabs\vsmon.exe
>
>
>
>
Karl
Advertisement
Senior Member
24. July 2006 @ 15:06
Link to this message
y is this in a psp forum
if it tells you the path to the vires just find the folder and delete it!
it works for me wen i use mc,cafee.
-re-install windows (save important stuff and reinstall)
AfterDawn Addict
24. July 2006 @ 15:07
Link to this message
you should try the windows forums man, sounds like your in a real mess :(
Senior Member
24. July 2006 @ 15:12
Link to this message
poor guy.
man go termanator on that virus and just destroy every file and everthing that it has been through.
then get a better virus protection,
or scaner. i use spyware doctor, takes off everthing, from bad cookies to the trojan virus.
Senior Member
24. July 2006 @ 15:18
Link to this message
i hate trojan, i get them all the time. but they r easy 2 delete, u just find the path (many times in internet temp. files) and delete it :P
Senior Member
24. July 2006 @ 17:30
Link to this message
yeah but mine were imbeded.
so they wouldn't come out so easy.
AfterDawn Addict
24. July 2006 @ 18:06
Link to this message
you guys still use IE? wow.............wow.
Tips for this guy.
1.Virus Scanner
2.Spyware Scanner
3.Firewall
4.Download Firefox for Web Browser
5.Try reinstalling XP
Member
2 product reviews
24. July 2006 @ 18:51
Link to this message
check these and delete them in hijack this
--C:\Program Files\SpyHeal\SpyHeal.exe
-- C:\Program Files\SpyHeal\SpyHeal.exe
--C:\Documents and Settings\Chris lewellyan\Local Settings\Temporary Internet:<this just to be safe delete
--O4 - HKLM\..\Run: [SpyHeal] C:\Program Files\SpyHeal\SpyHeal.exe /h
--O2 - BHO: (no name) - {5f4c3d09-b3b9-4f88-aa82-31332fee1c08} -
> C:\WINDOWS\system32\hp100.tmp
download Spybot search and destroy here:
update them both and immunize:
http://www.safer-networking.org/en/download/index.html then download adawarehere:http://www.lavasoftusa.com/support/download/ run them both fix problems.
Finally download cccleaner here :http://www.ccleaner.com/download/ run that hit cleaner> then analyze then run cleaner again when done analyzing. Also hit issues analyze then fix issues.
Run hijack this again and save log file and then post again. HERE http://forums.afterdawn.com/forum_view.cfm/166
This message has been edited since posting. Last time this message was edited on 24. July 2006 @ 19:22
AfterDawn Addict
24. July 2006 @ 19:04
Link to this message
can you please finish this in the windows forums.
Advertisement
Senior Member
24. July 2006 @ 19:16
Link to this message
Ya man post this in the windows virus forum there are great people there who will guide u step by step to get every single piece of crap off ur pc.
In fact I think we would be fooling our selves if we have a community this large, and did not realize that there are some enemies present.
afterdawn.com > forums > consoles > sony psp - mod and firmware discussion > dear jesus someone please help me!!!!