OMFG THANK U SO MUCH! YOUR A GODSEND! HAHAAH SO HAPPY ^^
n e ways here are the logs:
Logfile of HijackThis v1.98.2
Scan saved at 4:04:36 PM, on 9/12/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\System32\Ati2evxx.exe
E:\WINDOWS\system32\pctspk.exe
E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
E:\Program Files\Common Files\WinTools\WToolsS.exe
E:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
E:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe
E:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe
E:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe
E:\Program Files\Analog Devices\SoundMAX\SMTray.exe
E:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
E:\Program Files\iTunes\iTunesHelper.exe
E:\Program Files\iPod\bin\iPodService.exe
E:\Program Files\QuickTime\qttask.exe
E:\Program Files\Messenger\msmsgs.exe
E:\Program Files\Yahoo!\Messenger\ypager.exe
E:\WINDOWS\system32\winmm64.exe
E:\Program Files\WinMX\WinMX.exe
E:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\E-Color\True Internet Color\TICIcon.exe
E:\Documents and Settings\Sampson & Staz\Desktop\AboutBuster\AboutBuster.exe
E:\Program Files\Windows Media Player\wmplayer.exe
C:\hjt\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://s-redirect.com/?a=2&b=n-noname
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL =
http://s-redirect.com/?a=2&b=n-noname
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://s-redirect.com/?a=2&b=n-noname
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://s-redirect.com/?a=2&b=n-noname
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://s-redirect.com/?a=2&b=n-noname
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://s-redirect.com/?a=2&b=n-noname
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL =
http://s-redirect.com/?a=2&b=n-noname
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL =
http://s-redirect.com/?a=2&b=n-noname
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIPTA] E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [pccguide.exe] "E:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "E:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "E:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\Run: [Smapp] E:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] E:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] E:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [WebRebates0] "E:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKCU\..\Run: [MSMSGS] "E:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] C:\Valve\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [Yahoo! Pager] E:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [SpywareGuardPlus] E:\WINDOWS\system32\winmm64.exe
O4 - HKCU\..\Run: [WinMX] E:\Program Files\WinMX\WinMX.exe -m
O4 - HKCU\..\Run: [msnmsgr] "E:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: True Internet Color Icon.lnk = C:\Program Files\E-Color\True Internet Color\TICIcon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download by NetAnts - E:\PROGRA~1\NetAnts\NAGet.htm
O8 - Extra context menu item: &Yahoo! Search -
file:///E:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Download &All by NetAnts - E:\PROGRA~1\NetAnts\NAGetAll.htm
O8 - Extra context menu item: Yahoo! &Dictionary -
file:///E:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps -
file:///E:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - E:\PROGRA~1\NetAnts\NetAnts.exe
O9 - Extra 'Tools' menuitem: &NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - E:\PROGRA~1\NetAnts\NetAnts.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) -
http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) -
http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} (Personal System Administrator Control) -
http://206.65.172.231/check/netset//install/gtdowngc.cab
Scanned at: 2:55:40 PM on: 9/12/2004
-- Scan 1 ---------------------------
About:Buster Version 3.0
Reference List : 15
No ADS found on system
Removed 3 Random Key Entries
Deleted 1 Service Keys Successfully!
Removed! : E:\WINDOWS\agtkz.dat
Removed! : E:\WINDOWS\aoyig.dat
Removed! : E:\WINDOWS\appex32.exe
Removed! : E:\WINDOWS\aybzm.dat
Removed! : E:\WINDOWS\bcpba.dat
Removed! : E:\WINDOWS\bqrcu.dat
Removed! : E:\WINDOWS\crpk.exe
Removed! : E:\WINDOWS\dfjhm.dat
Removed! : E:\WINDOWS\dhuoo.dat
Removed! : E:\WINDOWS\dsojv.dat
Removed! : E:\WINDOWS\ggdqp.dat
Removed! : E:\WINDOWS\ibdda.dat
Removed! : E:\WINDOWS\javayn32.exe
Removed! : E:\WINDOWS\lbzkz.dat
Removed! : E:\WINDOWS\ltjji.dat
Removed! : E:\WINDOWS\lubxl.dat
Removed! : E:\WINDOWS\mjymg.dat
Removed! : E:\WINDOWS\ntdo32.exe
Removed! : E:\WINDOWS\nycvk.dat
Removed! : E:\WINDOWS\onrrw.dat
Removed! : E:\WINDOWS\psaju.dat
Removed! : E:\WINDOWS\QuickBrowser.exe.$$$
Removed! : E:\WINDOWS\qxngu.dat
Removed! : E:\WINDOWS\rwjaf.dat
Removed! : E:\WINDOWS\sbgpd.dat
Removed! : E:\WINDOWS\sdkeq32.exe
Removed! : E:\WINDOWS\sysde32.exe
Removed! : E:\WINDOWS\sysjf.exe
Removed! : E:\WINDOWS\sysoa.exe.bak
Removed! : E:\WINDOWS\tmyoo.dat
Removed! : E:\WINDOWS\tywpu.dat
Removed! : E:\WINDOWS\ueiqm.dat
Removed! : E:\WINDOWS\vlont.dat
Removed! : E:\WINDOWS\wsacx.dat
Removed! : E:\WINDOWS\xwefp.dat
Removed! : E:\WINDOWS\yjklc.dat
Removed! : E:\WINDOWS\zsvyr.dat
Removed! : E:\WINDOWS\System32\acrhm.dat
Removed! : E:\WINDOWS\System32\apiuh32.exe
Removed! : E:\WINDOWS\System32\appeg32.exe
Removed! : E:\WINDOWS\System32\atlls.exe
Removed! : E:\WINDOWS\System32\bdqkk.dat
Removed! : E:\WINDOWS\System32\chcox.dat
Removed! : E:\WINDOWS\System32\crnb32.exe
Removed! : E:\WINDOWS\System32\czcyi.dat
Removed! : E:\WINDOWS\System32\fmato.dat
Removed! : E:\WINDOWS\System32\gmdiw.dat
Removed! : E:\WINDOWS\System32\gubyv.dat
Removed! : E:\WINDOWS\System32\gvztq.dat
Removed! : E:\WINDOWS\System32\ipnw.exe
Removed! : E:\WINDOWS\System32\ixxdw.dat
Removed! : E:\WINDOWS\System32\javacw.exe
Removed! : E:\WINDOWS\System32\jtudy.dat
Removed! : E:\WINDOWS\System32\lgmau.dat
Removed! : E:\WINDOWS\System32\ljhva.dat
Removed! : E:\WINDOWS\System32\mfcwu32.exe
Removed! : E:\WINDOWS\System32\mswua.dat
Removed! : E:\WINDOWS\System32\mszw32.exe
Removed! : E:\WINDOWS\System32\netcq.exe
Removed! : E:\WINDOWS\System32\nettf.exe
Removed! : E:\WINDOWS\System32\netxo32.exe
Removed! : E:\WINDOWS\System32\noqpj.dat
Removed! : E:\WINDOWS\System32\nthz32.exe
Removed! : E:\WINDOWS\System32\ohknh.dat
Removed! : E:\WINDOWS\System32\pnrjw.dat
Removed! : E:\WINDOWS\System32\sdkqq.exe
Removed! : E:\WINDOWS\System32\sysuk32.exe
Removed! : E:\WINDOWS\System32\tgtur.dat
Removed! : E:\WINDOWS\System32\ttqym.dat
Removed! : E:\WINDOWS\System32\ueagn.dat
Removed! : E:\WINDOWS\System32\vrgbh.dat
Removed! : E:\WINDOWS\System32\vskgo.dat
Removed! : E:\WINDOWS\System32\wgbsg.dat
Removed! : E:\WINDOWS\System32\winaz.exe
Removed! : E:\WINDOWS\System32\ztoca.dat
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset... Done!
-- Scan 2 ---------------------------
About:Buster Version 3.0
Reference List : 15
No ADS found on system
Removed 3 Random Key Entries
Attempted Clean Of Temp folder.
Pages Reset... Done!
Scanned at: 3:21:34 PM on: 9/12/2004
-- Scan 1 ---------------------------
About:Buster Version 3.0
Reference List : 15
No ADS found on system
Removed 3 Random Key Entries
Attempted Clean Of Temp folder.
Pages Reset... Done!
-- Scan 2 ---------------------------
About:Buster Version 3.0
Reference List : 15
No ADS found on system
Removed 3 Random Key Entries
Attempted Clean Of Temp folder.
Pages Reset... Done!
Scanned at: 4:04:10 PM on: 9/12/2004
-- Scan 1 ---------------------------
About:Buster Version 3.0
Reference List : 15
No ADS found on system
Removed 6 Random Key Entries
Attempted Clean Of Temp folder.
Pages Reset... Done!
-- Scan 2 ---------------------------
About:Buster Version 3.0
Reference List : 15
No ADS found on system
Removed 6 Random Key Entries
Attempted Clean Of Temp folder.
Pages Reset... Done!
Umm one more thing....uhhh do u have any idea why i cant sign into msn messanger?