Unread postby martin_uk » December 6th, 2008, 8:34 am

Hi All got hijacked by this annoying thing!! hope you can help

Logfile of HijackThis v1.99.1
Scan saved at 12:21:15, on 06/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)

Running processes:
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\russ\My Documents\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: http://www.yahoo.com
O1 - Hosts: http://www.google.com
O1 - Hosts: http://www.google.co.uk
O1 - Hosts: http://www.myspace.com
O1 - Hosts: http://www.youtube.com
O1 - Hosts: http://www.facebook.com
O1 - Hosts: http://www.antispy.com
O1 - Hosts: http://www.yahoo.com
O1 - Hosts: http://www.yahoo.co.uk
O1 - Hosts: http://www.antispyware.com
O1 - Hosts: antispyware.com
O1 - Hosts: antispy.com
O1 - Hosts: http://www.msn.com
O1 - Hosts: http://www.asdfasdfd.com
O1 - Hosts: http://www.gg.com
O1 - Hosts: http://www.ghfhj.com
O1 - Hosts: http://www.cvnbcvnb.com
O1 - Hosts: http://www.1.com
O1 - Hosts: http://www.3.com
O1 - Hosts: http://www.asdf4asdfd.com
O1 - Hosts: http://www.asdfawsdfd.com
O1 - Hosts: http://www.asdfatsdfd.com
O1 - Hosts: http://www.asdfasdfd.com
O1 - Hosts: http://www.asdfadsdfd.com
O1 - Hosts: http://www.asdfasdfd.com
O1 - Hosts: http://www.asdfafsdfd.com
O1 - Hosts: http://www.asdfasdfd.com
O1 - Hosts: http://www.asdfagsdfd.com
O1 - Hosts: http://www.asdfasgdfd.com
O1 - Hosts: http://www.asdfasdhfd.com
O1 - Hosts: http://www.asdfasdfjd.com
O1 - Hosts: http://www.asdfasdfkd.com
O1 - Hosts: http://www.asdfasdfld.com
O1 - Hosts: http://www.asdfasdf,d.com
O1 - Hosts: http://www.asxdfasdfd.com
O1 - Hosts: http://www.asdzfasdfd.com
O1 - Hosts: http://www.asdcfasdfd.com
O1 - Hosts: http://www.asdfvasdfd.com
O1 - Hosts: http://www.asdfabsdfd.com
O1 - Hosts: http://www.asdfasndfd.com
O1 - Hosts: http://www.asdfasdmfd.com
O1 - Hosts: http://www.asdfasdfd.com
O1 - Hosts: http://www.11asdfasdfd.com
O1 - Hosts: http://www.as222dfasdfd.com
O1 - Hosts: http://www.asdfa33sdfd.com
O1 - Hosts: http://www.asdfasd44fd.com
O1 - Hosts: http://www.asdfasdfd5.com
O1 - Hosts: http://www.as66dfasdfd.com
O1 - Hosts: http://www.asdf77asdfd.com
O1 - Hosts: http://www.asdf8asdfd.com
O1 - Hosts: http://www.asdf9asdfd.com
O1 - Hosts: http://www.asdf0asdfd.com
O1 - Hosts: http://www.asdf-asdfd.com
O1 - Hosts: http://www.aqqsdfasdfd.com
O1 - Hosts: http://www.aswwdfasdfd.com
O1 - Hosts: http://www.asdhhfasdfdyy.com
O1 - Hosts: http://www.live.com
O1 - Hosts: http://www.asdwwwfasdfd.com
O1 - Hosts: http://www.asdfeasdfd.com
O1 - Hosts: http://www.asdfrrasdfd.com
O1 - Hosts: http://www.asdfttasdfd.com
O1 - Hosts: http://www.asdfyyasdfd.com
O1 - Hosts: http://www.asdfuuuasdfd.com
O1 - Hosts: http://www.asdfaiisdfd.com
O1 - Hosts: http://www.asdfaoosdfd.com
O1 - Hosts: http://www.asdfappsdfd.com
O1 - Hosts: http://www.asdfasssdfd.com
O1 - Hosts: http://www.aswwdfasdfd.com
O1 - Hosts: http://www.asdeefasdfd.com
O1 - Hosts: http://www.asdfffasdfd.com
O1 - Hosts: http://www.asdfavvvsdfd.com
O1 - Hosts: http://www.asnnndfasdfd.com
O1 - Hosts: http://www.asdmmmfasdfd.com
O1 - Hosts: http://www.asdfaffsdfd.com
O1 - Hosts: http://www.asdhhfasdfd.com
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\System32\bcmntray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [explore] C:\WINDOWS\system32\explore.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/s ... DEXAXO.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/i ... ection.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/ ... leId=26688
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

Hope this helps

Just finished this too......

Malwarebytes' Anti-Malware 1.31
Database version: 1466
Windows 5.1.2600 Service Pack 2

06/12/2008 13:08:29
mbam-log-2008-12-06 (13-08-23).txt

Scan type: Quick Scan
Objects scanned: 52900
Time elapsed: 12 minute(s), 49 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 8

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Explore (Trojan.Agent) -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\explore.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\ian russell\Application Data\Microsoft\Internet Explorer\Quick Launch\VirusHeat 4.3.lnk (Rogue.VirusHeat) -> No action taken.
C:\Documents and Settings\ian russell\Local Settings\Temp\wrdwn3 (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\ian russell\Local Settings\Temp\TDSSed81.tmp (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\ian russell\Local Settings\Temp\TDSSedb0.tmp (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\ian russell\Favorites\Error Cleaner.url (Rogue.Link) -> No action taken.
C:\Documents and Settings\ian russell\Favorites\Privacy Protector.url (Rogue.Link) -> No action taken.
C:\Documents and Settings\ian russell\Favorites\Spyware&Malware Protection.url (Rogue.Link) -> No action taken.
Posts: 1
Joined: December 6th, 2008, 8:31 am
Re: intervalhehehe

Unread postby chryssi2001 » December 17th, 2008, 2:05 pm

Hello martin_uk,

I will be assisting you with your malware issues.

  • Whatever repairs we make, are for fixing your computer problems only and by no means should be used on another computer.
  • Continue to respond to this thread until I give you the All Clean! If you have any question or you're stuck in there please reply it to me. I will try my best to help you!
  • Please bookmark or favourite this page. In case you need it as reference or etc.
  • Open HijackThis.
  • Click on Open the Misc Tools section.
  • Click on the Open Uninstall Manager... button.
  • Click on the Save list... button.
  • It will prompt you to save. Save this log in a convenient location. By default it's named uninstall_list.txt.
  • Notepad will open. Please copy and paste the contents of this log in your next reply.
See in this link details.
Also post a new HijackThis log.
Posts: 14395
Joined: September 24th, 2006, 2:11 am
Location: far away

Re: intervalhehehe

Unread postby Gary R » December 22nd, 2008, 12:20 pm

Due to lack of response, this topic is now closed.

If you still require help, please open a new thread in the Infected? Virus, malware, adware, ransomware, oh my! forum, include a fresh FRST log, and wait for a new helper.
Posts: 21809
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire

