Hello,
Now a day my avast anti virus program drives me crazy!!!
I am using a loptop with Windows XP SP2. When i connect to internet using firefox, some exe files with trojan horse downloading to my Temp directory. Even if delete, this happens again when i restart my system.
I have scanned with HijackThis in safe mode, but i need help to fix them.
Logfile of HijackThis v1.98.2
Scan saved at 21:06:30, on 31.03.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\Dokumente und Einstellungen\Raju\Desktop
\hijackthi
s\HijackTh
is.exe
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.comR3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Programme\Adobe\Acrobat
6.0\Acrobat\ActiveX\AcroIE
Helper.dll
O2 - BHO: Explorer Class - {962F12AE-2773-4BEB-99EA-B
5C3AB9A660
6} - C:\WINDOWS\system32\DSMANA
~1.DLL
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0
445EE16191
0} - C:\Programme\Adobe\Acrobat
6.0\Acrobat\AcroIEFavClien
t.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - (no file)
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-0
0D0B743919
D} - C:\WINDOWS\System32\Stopzi
llaBHO.dll
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
819E2EAAC9
3} - C:\Programme\Adobe\Acrobat
6.0\Acrobat\AcroIEFavClien
t.dll
O3 - Toolbar: Systran40premi.IEPlugIn - {D3919E1A-D6A5-11D6-AC3E-0
0B0D094B57
6} - C:\Programme\Systran\4_0\P
remium\IEP
lugIn.dll
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [Msgchm] C:\WINDOWS\System32\MSGCHM
.EXE
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\stopzilla\Stopzilla.
exe" /autorun
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooke
r.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCh
eck.exe
O4 - HKLM\..\Run: [WLANSTA.EXE] WLANSTA.EXE START
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\j2re1.4.
2_04\bin\j
usched.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast
4\ashDisp.
exe
O4 - HKLM\..\Run: [8NZOj] C:\WINDOWS\qhcvxv.exe
O4 - HKLM\..\Run: [Á³# L"h'þ9Óð3rÅWC:\Programme
\ISTsvc\is
tsvc.exe] C:\WINDOWS\qhcvxv.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCt
r\Binaries
\MSConfig.
exe /auto
O4 - HKCU\..\Run: [Internet Download Accelerator] C:\Programme\IDA\ida.exe -autorun
O4 - Startup: Webshots.lnk = C:\Programme\Webshots\Laun
cher.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.h
tm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.
htm
O8 - Extra context menu item: Download All Files by HiDownload - C:\PROGRA~1\HIDOWN~1\HDGet
All.htm
O8 - Extra context menu item: Download by HiDownload - C:\PROGRA~1\HIDOWN~1\HDGet
.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\WINDOWS\System32\msjava
.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\WINDOWS\System32\msjava
.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-A
FF36D6C704
0} - C:\Programme\WinHTTrack\Wi
nHTTrackIE
Bar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-A
FF36D6C704
0} - C:\Programme\WinHTTrack\Wi
nHTTrackIE
Bar.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-0
0010333D0A
D} - (no file)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-0
0010333D0A
D} - (no file)
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2
C66DA43AC6
C} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0
050045C3C9
6} - C:\PROGRA~1\Yahoo!\MESSEN~
1\YPager.e
xe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0
050045C3C9
6} - C:\PROGRA~1\Yahoo!\MESSEN~
1\YPager.e
xe
O9 - Extra button: HiDownload - {F4FBA929-A891-492C-A0F6-5
C79CC4F174
2} - C:\PROGRA~1\HIDOWN~1\hidow
nload.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Programme\Messenger\msm
sgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Programme\Messenger\msm
sgs.exe
O12 - Plugin for .avi: C:\Programme\Internet Explorer\PLUGINS\npqtplugi
n.dll
O16 - DPF: {001EE746-A1F9-460E-80AD-2
69E088D6A0
1} (Infotl Control) -
http://site.ebrary.com/support/plugins/ebraryRdr.cabO16 - DPF: {0246ECA8-996F-11D1-BE2F-0
0A0C9037DF
E} (TDServer Control) -
http://www.truedoc.com/activex/tdserver.cabO16 - DPF: {17492023-C23A-453E-A040-C
7C580BBF70
0} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1
E41684E07B
B} -
http://ak.imgfarm.com/images/nocache/funwebproducts/ei/PopularScreenSaversInitialSetup1.0.0.8.cabO16 - DPF: {2B96D5CC-C5B5-49A5-A69D-C
C0A30F9028
C} (MiniBugTransporterX Class) -
http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?O16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093964564204O16 - DPF: {771A1334-6B08-4A6B-AEDC-C
F994BA2CEB
E} (Installer Class) -
http://static.35mb.com/applet/applet_y.cabO16 - DPF: {C606BA60-AB76-48B6-96A7-2
C4D5C386F7
0} (PreQualifier Class) -
http://www.sc-server1.bt.com/broadband/MotivePreQual.cabO16 - DPF: {CA034DCC-A580-4333-B52F-1
5F98C42E04
C} (Downloader Class) -
https://www.stopzilla.com/_download/Auto_Installer/dwnldr.cabO16 - DPF: {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} -
http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cabO17 - HKLM\System\CCS\Services\T
cpip\..\{B
B3A9181-49
B9-4D83-95
8D-309064F
70A26}: NameServer = 192.168.2.1
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8
E447D12930
0} - C:\Programme\HP\hpcoretech
\comp\hpui
prot.dll
Thank you...