Hi,
I have a tenacious little virus, bot, spy, worm, malware, ad thing that won't go away. The symptom is that I can't change IE to start with any other URL but D:\WINDOWS\secure.html.
I ran Ad-Aware 6.0 and got no hits.
I ran Spybot S&D 1.3 and got:
Error During Check!
XABOT (Ungultiger Datentyp fur ")
and 5 DSO Exploits.
I tried to fix the DSO Exploits and they would come back everytime I scanned with Spybot S&D. I read that this was a bug and that I should either adjust Spybot to ignore the DSOs in the security tab or fake the registry so Spybot doesn't see them. I chose to let Spybot ignore them since I didn't want to deal with regedit.
I ran Hijack This 1.97.7 in normal mode, the ROs and R1s you see in the log file below did not delete, and IE booted with D:\WINDOWS\secure.html as it's startup page.
When I ran HJT in safe mode, the ROs and R1s did delete, and IE booted with
www.yahoo.com as it's startup page.
But as soon as I rebooted in normal mode, the R0s and R1s reappeared.
BTW, I have Windows 98 (factory-loaded from Sony on a VAIO) on the C volume and boot from D using XP.
I am very frustrated and just want to get rid of this nasty bug. Please find my HTJ log below. Can someone help me please?Thanks,
Darrell
Logfile of HijackThis v1.97.7
Scan saved at 11:07:45 PM, on 7/22/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
D:\WINDOWS\System32\smss.e
xe
D:\WINDOWS\system32\winlog
on.exe
D:\WINDOWS\system32\servic
es.exe
D:\WINDOWS\system32\lsass.
exe
D:\WINDOWS\system32\svchos
t.exe
D:\WINDOWS\System32\svchos
t.exe
D:\WINDOWS\system32\spools
v.exe
D:\WINDOWS\System32\driver
s\CDAC11BA
.EXE
D:\WINDOWS\wanmpsvc.exe
D:\WINDOWS\system32\fxssvc
.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\WLANST
A.EXE
D:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
D:\Program Files\iTunes\iTunesHelper.
exe
D:\Program Files\QuickTime\qttask.exe
D:\WINDOWS\system.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\The Weather Channel\The Weather Channel.exe
D:\Program Files\Express ClickYes\ClickYes.exe
D:\Program Files\iPod\bin\iPodService
.exe
D:\WINDOWS\System32\smtaqm
n.exe
D:\Program Files\eNetBot\eNetBot Mail\enetbot.exe
D:\Program Files\Handspring\GoSync.ex
e
D:\Program Files\D-Link AirPlus Xtreme G\AirPlus.exe
D:\Program Files\Handspring\HOTSYNC.E
XE
D:\Documents and Settings\Darrell\Desktop\H
ijackThis.
exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page = D:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = D:\WINDOWS\secure.html
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page = D:\WINDOWS\secure.html
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = D:\WINDOWS\secure.html
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Local Page = D:\WINDOWS\secure.html
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Local Page = D:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\In
ternet Explorer,SearchAssistant = ,
R1 - HKCU\Software\Microsoft\In
ternet Explorer,CustomizeSearch = ,
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7
695ECA0567
0} - D:\WINDOWS\Downloaded Program Files\ycomp5_1_5_0.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - D:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: (no name) - {69FA6A0B-E130-2CB0-8727-6
0550FA27A3
E} - D:\WINDOWS\System32\ygkst.
dll
O2 - BHO: (no name) - {9CB29894-AA3C-4262-8CB3-2
9C3BBBC3A0
7} - D:\WINDOWS\1090380940.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - D:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - D:\WINDOWS\Downloaded Program Files\ycomp5_1_5_0.dll
O4 - HKLM\..\Run: [WLANSTA.EXE] WLANSTA.EXE START
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] D:\Program Files\iTunes\iTunesHelper.
exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [System32] D:\WINDOWS\system.exe
O4 - HKCU\..\Run: [Yahoo! Pager] D:\Program Files\Messenger\ypager.exe
-quiet
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [Desktop Weather 3] D:\Program Files\The Weather Channel\The Weather Channel.exe
O4 - HKCU\..\Run: [Express ClickYes] D:\Program Files\Express ClickYes\ClickYes.exe
O4 - HKCU\..\Run: [Aeom] D:\Documents and Settings\Darrell\Applicati
on Data\oosp.exe
O4 - HKCU\..\Run: [Bbzd] D:\WINDOWS\System32\smtaqm
n.exe
O4 - HKCU\..\Run: [X-Cleaner Freeware] "D:\PROGRA~1\X-CLEA~1\XCle
aner_free.
exe" -turbo -autostart -NOREBOOT
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Startup: HotSync Manager.lnk = D:\Program Files\Handspring\HOTSYNC.E
XE
O4 - Global Startup: Quicken Scheduled Updates.lnk = D:\Program Files\Quicken\bagent.exe
O4 - Global Startup: ItsDeductiblePopUp.lnk = D:\Program Files\ItsDeductible\ItsDed
uctible.ex
e
O4 - Global Startup: eNetBot Mail.lnk = D:\Program Files\eNetBot\eNetBot Mail\enetbot.exe
O4 - Global Startup: Billminder.lnk = D:\Program Files\Quicken\billmind.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = D:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: GoSync v1.0.lnk = ?
O4 - Global Startup: D-Link AirPlus Xtreme G Configuration Utility.lnk = ?
O4 - Global Startup: D-Link REG Utility.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O16 - DPF: {02BCC737-B171-4746-94C9-0
D8A0B2C008
9} (Microsoft Office Template and Media Control) -
http://office.microsoft.com/templates/ieawsdc.cabO16 - DPF: {166B1BCA-3F9C-11CF-8075-4
4455354000
0} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cabO16 - DPF: {26CBF141-7D0F-46E1-AA06-7
18958B6E4D
2} -
http://download.ebay.com/turbo_lister/US/install.cabO16 - DPF: {298BFFEE-662D-11D5-ADAF-0
0E0810232D
7} (lgbplay Class) -
https://video.manheim.com/lib/LiveSound.dllO16 - DPF: {41F17733-B041-4099-A042-B
518BB6A408
C} -
http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exeO16 - DPF: {74D05D43-3236-11D4-BDCD-0
0C04F9A3B6
1} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} (Yahoo! Companion) -
http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/yiebio5_1_5_0.cabStart Free Trial