(1) Unwanted Web Page on Desktop
"Warning You're In Danger All you do with computer is stored forever ..."
Properties shows the following file on my system: C:\Windows\desktop.html. When deleted it returns on startup.
(2) Unwanted popups and processes, couple examples of many:
a. "Computer Perforamance Software Advertisement System Performance Info"
http://adserver.sharewareonline.com/AdServer/MemTurbo/Adm/ad080504.htmb. "Would you like to install the free trial version of the CPURocket . . . "
(3) Unwanted processes: see report below
WHAT I'VE TRIED:
a. HiJackThis
b. Ad-Aware
c. CW Shredder
d. Stinger
e. Spybot
f. SpywareBlaster
HIJACK THIS REPORT:
Logfile of HijackThis v1.98.2
Scan saved at 7:33:34 PM, on 11/27/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\System32\Ati2ev
xx.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\system32\rundll
32.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\System32\Tablet
.exe
C:\WINDOWS\System32\wltrys
vc.exe
C:\WINDOWS\System32\bcmwlt
ry.exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tf
swctrl.exe
C:\WINDOWS\tppaldr.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\twink6
4.exe
C:\WINDOWS\System32\ezykah
v.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Steve\Application
Data\osoa.exe
C:\WINDOWS\System32\r?ndll
32.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\windos
.exe
C:\Program Files\WebSiteViewer\124424
.dlr
C:\Program Files\AutoUpdate\AutoUpdat
e.exe
C:\WINDOWS\System32\taskmg
r.exe
C:\WINDOWS\System32\wuaucl
t.exe
C:\Program Files\Web_Rebates\WebRebat
es1.exe
C:\Program Files\Web_Rebates\WebRebat
es0.exe
C:\PROGRA~1\eZula\mmod.exe
C:\WINDOWS\System32\brods.
exe
C:\WINDOWS\System32\q_emyd
.exe
C:\PROGRA~1\WEBOFF~1\wo.ex
e
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\CxtPls\CxtPls.exe
C:\Documents and Settings\Steve\My Documents\Backed Up\Computer\Hijack Help\HijackThis.exe
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
swctrl.exe
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobs
ync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\twink6
4.exe internat.dll,LoadKeyboardP
rofile
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [kwgekpdlnbgjx] C:\WINDOWS\System32\ezykah
v.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdat
e.exe"
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebat
es0.exe"
O4 - HKLM\..\Run: [t7oV3EP] q_emyd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [Ncao] C:\Documents and Settings\Steve\Application
Data\osoa.exe
O4 - HKCU\..\Run: [Sqtqvtl] C:\WINDOWS\System32\r?ndll
32.exe
O4 - HKCU\..\Run: [SurfSideKick 2] C:\Program Files\SurfSideKick 2\Ssk.exe
O4 - HKCU\..\Run: [cw79ROjEQ] brods.exe
O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\T
p1150\scri
1150a.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.
dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.
dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.
dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.
dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.
dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.
dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.
dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.
dll
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.crazywinnings.com
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.topconverting.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.xxxtoolbar.com
O15 - Trusted Zone: *.ysbweb.com
O16 - DPF: ppctlcab -
http://ppupdates.ca.com/downloads/scanner/ppctlcab.cabO16 - DPF: {205FF73B-CA67-11D5-99DD-4
4455354000
6} (CInstall Class) -
http://www.errorguard.com/installation/Install.cabO16 - DPF: {2FC9A21E-2069-4E47-8235-3
6318989DB1
3} (PPSDKActiveXScanner.MainS
creen) -
http://ppupdates.ca.com/downloads/scanner/axscanner.cabO16 - DPF: {41F17733-B041-4099-A042-B
518BB6A408
C} -
http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exeO16 - DPF: {79849612-A98F-45B8-95E9-4
D13C7B6B35
C} (Loader2 Control) -
http://static.topconverting.com/activex/loader2.ocxO16 - DPF: {A93D84FD-641F-43AE-B963-E
6FA84BE7FE
7} (LinkSys Content Update) -
http://www.linksysfix.com/netcheck/24/install/gtdownls.cabO16 - DPF: {DBA230D1-8467-4e69-987E-5
FAE815A3B4
5} -
Appreciate any help you have to offer
-Tigershark
Start Free Trial