PA
Mon Apr 21 10:26:53 PDT 2008
Repost:
**Post your log to
http://forums.spybot.info/forumdisplay.php?f=22,
http://castlecops.com/forum67.html,
http://forums.subratam.org/index.php?showforum=7,
http://aumha.net/viewforum.php?f=30, or other appropriate forums for review
by an expert in such matters, not here.**
PS: Uninstall Yahoo and Google toolbars and see if the behavior persists.
--
~PA Bear
dama1 wrote:
> Logfile of Trend Micro HijackThis v2.0.2
> Scan saved at 11:57:55 AM, on 4/21/2008
> Platform: Windows XP SP2 (WinNT 5.01.2600)
> MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
> Boot mode: Normal
>
> Running processes:
> C:\WINDOWS\System32\smss.exe
> C:\WINDOWS\system32\winlogon.exe
> C:\WINDOWS\system32\services.exe
> C:\WINDOWS\system32\lsass.exe
> C:\WINDOWS\System32\Ati2evxx.exe
> C:\WINDOWS\system32\svchost.exe
> C:\WINDOWS\System32\svchost.exe
> C:\WINDOWS\system32\svchost.exe
> C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
> C:\WINDOWS\system32\Ati2evxx.exe
> C:\WINDOWS\Explorer.EXE
> C:\WINDOWS\system32\spoolsv.exe
> C:\PROGRA~1\Yahoo!\YOP\yop.exe
> C:\Program Files\NavNT\vptray.exe
> C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
> C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
> C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
> C:\WINDOWS\system32\ctfmon.exe
> C:\PROGRA~1\Yahoo!\browser\ycommon.exe
> C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
> C:\Program Files\Isota\ABCSpell\ABCSpellService.exe
> C:\Program Files\NavNT\defwatch.exe
> C:\WINDOWS\system32\svchost.exe
> C:\WINDOWS\system32\svchost.exe
> C:\WINDOWS\System32\svchost.exe
> C:\Program Files\NavNT\rtvscan.exe
> C:\WINDOWS\System32\svchost.exe
> C:\WINDOWS\System32\svchost.exe
> C:\Program Files\Webroot\Washer\WasherSvc.exe
> C:\Program Files\Canon\CAL\CALMAIN.exe
> C:\WINDOWS\system32\MsgSys.EXE
> C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
> C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
> C:\Program Files\Yahoo!\browser\ybrwicon.exe
> C:\Program Files\Internet Explorer\iexplore.exe
> C:\Documents and Settings\Owner\Local Settings\Temporary Internet
> Files\Content.IE5\O3IQFMI0\hijackthis[1].exe
>
> R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
>
http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
> R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
>
http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
> R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
>
http://www.yahoo.com/
> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
>
http://yahoo.sbc.com/dsl
> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
>
http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
>
http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
>
http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
> R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
>
http://www.yahoo.com/
> R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL =
>
http://www.searchv.com/1/search.html
> R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Page_URL =
>
http://www.searchv.com/1/
> R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL =
>
http://www.searchv.com/1/
> R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
>
http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
> R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
> about:blank
> R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
> Settings,ProxyOverride = 127.0.0.1;<local>
> R3 - URLSearchHook: Yahoo! Toolbar -
> {EF99BD32-C1FB-11D2-892F-0090271D4F88}
> - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll
> O2 - BHO: &Yahoo! Toolbar Helper -
> {02478D38-C3F9-4EFB-9B51-7695ECA05670} -
> C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll
> O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} -
> C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
> O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} -
> C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
> O2 - BHO: Adobe PDF Reader Link Helper -
> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common
> Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
> O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
> C:\PROGRA~1\SPYBOT~1\SDHelper.dll
> O2 - BHO: Yahoo! IE Services Button -
> {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
> - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
> O2 - BHO: SidebarAutoLaunch Class -
> {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} -
> C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
> O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -
> C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll (file
> missing) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
> c:\program files\google\googletoolbar.dll
> O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
> C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll
> O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
> O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program
> Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
> O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
> O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search
> Protection\SearchProtection.exe"
> O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software
> Update\HPWuSchd2.exe
> O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft
> ActiveSync\WCESCOMM.EXE"
> O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
> O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search
> Protection\SearchProtection.exe
> O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program
> Files\HP\Digital Imaging\bin\hpqtra08.exe
> O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel
> present O8 - Extra context menu item: &Google Search - res://C:\Program
> Files\Google\googletoolbar.dll/cmsearch.html
> O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program
> Files\Yahoo!\Common/ycsrch.htm
> O8 - Extra context menu item: Backward &Links - res://C:\Program
> Files\Google\googletoolbar.dll/cmbacklinks.html
> O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program
> Files\Google\googletoolbar.dll/cmcache.html
> O8 - Extra context menu item: E&xport to Microsoft Excel -
> res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
> O8 - Extra context menu item: Si&milar Pages - res://C:\Program
> Files\Google\googletoolbar.dll/cmsimilar.html
> O8 - Extra context menu item: Translate into English - res://C:\Program
> Files\Google\googletoolbar.dll/cmtrans.html
> O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program
> Files\Yahoo!\Common/ycdict.htm
> O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program
> Files\Yahoo!\Common/ycdict.htm
> O9 - Extra button: (no name) - {06FE5D00-8F11-11d2-804F-00105A133818} -
>
http://jump.altavista.com/avie5/home (file missing)
> O9 - Extra 'Tools' menuitem: &AltaVista Home -
> {06FE5D00-8F11-11d2-804F-00105A133818} -
>
http://jump.altavista.com/avie5/home (file missing)
> O9 - Extra button: (no name) - {06FE5D02-8F11-11d2-804F-00105A133818} -
>
http://jump.altavista.com/avie5/linksearch (file missing)
> O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL -
> {06FE5D02-8F11-11d2-804F-00105A133818} -
>
http://jump.altavista.com/avie5/linksearch (file missing)
> O9 - Extra button: (no name) - {06FE5D03-8F11-11d2-804F-00105A133818} -
>
http://jump.altavista.com/avie5/hostsearch (file missing)
> O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host -
> {06FE5D03-8F11-11d2-804F-00105A133818} -
>
http://jump.altavista.com/avie5/hostsearch (file missing)
> O9 - Extra button: Translate - {06FE5D05-8F11-11d2-804F-00105A133818} -
>
http://jump.altavista.com/avie5/babelfish (file missing)
> O9 - Extra 'Tools' menuitem: AV &Translate -
> {06FE5D05-8F11-11d2-804F-00105A133818} -
>
http://jump.altavista.com/avie5/babelfish (file missing)
> O9 - Extra button: Create Mobile Favorite -
> {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft
> ActiveSync\inetrepl.dll
> O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -
> C:\Program Files\Microsoft ActiveSync\inetrepl.dll
> O9 - Extra 'Tools' menuitem: Create Mobile Favorite... -
> {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft
> ActiveSync\inetrepl.dll
> O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} -
> C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
> O9 - Extra button: AT&T Yahoo! Services -
> {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -
> C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll O9 - Extra button: HP Smart Select -
> {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web
> Printing\hpswp_extensions.dll
> O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
> C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
> O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} -
> c:\Program Files\Microsoft Money\System\mnyviewer.dll
> O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
> C:\Program Files\Messenger\msmsgs.exe
> O9 - Extra 'Tools' menuitem: Windows Messenger -
> {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
> Files\Messenger\msmsgs.exe O16 - DPF:
> {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage
> Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
> O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver
> Installation Control) -
>
http://inst.c-wss.com/n035p/EN/install/gtdownlr.cab
> O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus
> scanner) -
>
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab O16 -
> DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) -
> C:\Program Files\Yahoo!\Common\Yinsthelper.dll
> O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) -
> https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
> O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (CwlscInstall Object) -
> https://scan.safety.live.com/resource/download/scanner/en-us/wlscbase2213.cab
> O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility
> Class) -
>
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
> O16 -
> DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
>
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136935232484
> O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments
> Control) - https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
> O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
> (MsnMessengerSetupDownloadControl Class) -
>
http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
> O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) -
>
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
> O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -
> https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
> O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) -
> https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
> O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data
> Class)
> -
http://wwemail.support.hp.com/fd2/objects/SysQuery.cab
> O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program
> Files\Lavasoft\Ad-Aware 2007\aawservice.exe
> O23 - Service: ABCSpell Helper Service - Unknown owner - C:\Program
> Files\Isota\ABCSpell\ABCSpellService.exe
> O23 - Service: Ati HotKey Poller - Unknown owner -
> C:\WINDOWS\System32\Ati2evxx.exe
> O23 - Service: ATI Smart - Unknown owner -
> C:\WINDOWS\system32\ati2sgag.exe
> O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. -
> C:\Program Files\Canon\CAL\CALMAIN.exe
> O23 - Service: DefWatch - Symantec Corporation - C:\Program
> Files\NavNT\defwatch.exe
> O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision
> Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel
> 32\IDriverT.exe
> O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) -
> Symantec
> Corporation - C:\Program Files\NavNT\rtvscan.exe
> O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software,
> Inc. -
> C:\Program Files\Webroot\Washer\WasherSvc.exe
> O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
> O24 - Desktop Component 0: (no name) -
>
http://a1568.g.akamai.net/7/1568/1600/20051017001200/music.yahoo.com/common/resources/skins/us/LAUNCH_hdr_gradient_left.jpg
>
>
>> Despite your security applications, I'm afraid you've got a nasty
>> hijackware infection. Run a /thorough/ check for hijackware, including
>> posting your hijackthis log to an appropriate forum.
>>
>> Checking for/Help with Hijackware
>>
http://aumha.org/a/parasite.htm
>>
http://aumha.org/a/quickfix.htm
>>
http://aumha.net/viewtopic.php?t=5878
>>
http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction
>>
http://mvps.org/winhelp2002/unwanted.htm
>>
http://inetexplorer.mvps.org/data/prevention.htm
>>
http://inetexplorer.mvps.org/tshoot.html
>>
http://www.mvps.org/sramesh2k/Malware_Defence.htm
>>
http://defendingyourmachine2.blogspot.com/
>>
http://www.elephantboycomputers.com/page2.html#Removing_Malware
>>
>> When all else fails, HijackThis v2.0.2
>> (
http://aumha.org/downloads/hijackthis.exe) is the preferred tool to use.
>> It will help you to both identify and remove any hijackware/spyware with
>> assistance from an expert. **Post your log to
>>
http://forums.spybot.info/forumdisplay.php?f=22,
>>
http://castlecops.com/forum67.html,
>>
http://forums.subratam.org/index.php?showforum=7,
>>
http://aumha.net/viewforum.php?f=30, or other appropriate forums for
>> review
>> by an expert in such matters, not here.**
>>
>> If the procedures look too complex - and there is no shame in admitting
>> this isn't your cup of tea - take the machine to a local, reputable and
>> independent (i.e., not BigBoxStoreUSA) computer repair shop.
>> --
>> ~PA Bear
>>
>> dama1 wrote:
>> <paste>
>>> Yikes! It's getting worse. I can't even follow a link online without IE
>>> closing down with the same stupid message about "encountering a
>>> problem".
>>> I
>>> even looked for the download for IE6 on Microsoft downloads, thinking
>>> what
>>> I
>>> have may be corrupted, but there wasn't anything except updates
>>> available
>>> (which seems strange). Any suggestions????
>> </paste>
>>> P.S. I'm on "Automatic Updates" with Microsoft.
>>>
>>>> I have Norton Anti-Virus (Corporate Edition), Windows Firewall, plus
>>>> Ad-Aware, Trojan Scan, and SpyBot. They all have been installed and
>>>> functional for at least 4 years with no adverse effects. I'm running a
>>>> Compaq desk top with an AMD Athlon XP 2000+ @ 1.67 GHz. Just FYI, I've
>>>> already done a system restore to a day before this all started, without
>>>> any success. Thanks for the response.
>>>>
>>>> "PA Bear [MS MVP]" wrote:
>>>>> What anti-virus application or security suite is installed? What
>>>>> anti-spyware applications (other than Defender)? What third-party
>>>>> firewall (if any)?
>>>>>
>>>>> Is the machine fully patched at Windows Update?
>>>>> --
>>>>> ~Robear Dyer (PA Bear)
>>>>> MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
>>>>> AumHa VSOP & Admin
http://aumha.net
>>>>> DTS-L
http://dts-l.net/
>>>>>
>>>>> dama1 wrote:
>>>>>> My operating system is XP. I have IE 6. For the past several days,
>>>>>> every
>>>>>> time I launch my IE browser, and go to another web page then close
>>>>>> the
>>>>>> window (or click on "home"), I get the "IE has encountered a problem
>>>>>> and
>>>>>> needs to close......." popup. I send the error report but don't get
>>>>>> the
>>>>>> other message that explains the error. This is a real pain in the
>>>>>> #^&.
>>>>>> Any suggestions to resolve this would be appreciated.