I have a virus or viruses. Two error messages pop up on screen every few minutes, also a taskbar error pops up. An internet explorer window also pops and tries to goto a site. The hijack this is below. I need a way to fix this.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:19:11 AM, on 3/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exendy
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\ZoneLa
bs\vsmon.e
xe
C:\WINDOWS\system32\spools
v.exe
C:\PROGRA~1\Grisoft\AVG7\a
vgamsvr.ex
e
C:\PROGRA~1\Grisoft\AVG7\a
vgupsvc.ex
e
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\System32\wltrys
vc.exe
C:\WINDOWS\System32\bcmwlt
ry.exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\System32\WLTRAY
.exe
C:\Program Files\Lexmark 3300 Series\lxccmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
e
C:\DOCUME~1\ADMINI~1\LOCAL
S~1\Temp\2
0083109557
_mcinfo.ex
e
C:\PROGRA~1\Grisoft\AVG7\a
vgcc.exe
C:\Program Files\XP Tools\xptools.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\XP Tools\xptools.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\WINDOWS\system32\lxccco
ms.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.e
xe
C:\PROGRA~1\MICROS~4\rapim
gr.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\PROGRA~1\Grisoft\AVG7\a
vgw.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
4DAF1D92D4
3} - C:\Program Files\Java\jre1.6.0_03\bin
\ssv.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-D
FEE4931A4A
A} - C:\Program Files\ZoneAlarmSB\bar\1.bi
n\SPYBLOCK
.DLL
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-A
EFAF26AB26
3} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\
VeohToolba
r.dll
O3 - Toolbar: enlfxgw - {A133882E-2F89-47A3-A01C-8
FA1D04B8E5
7} - C:\WINDOWS\enlfxgw.dll (file missing)
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-D
FEE4931A4A
A} - C:\Program Files\ZoneAlarmSB\bar\1.bi
n\SPYBLOCK
.DLL
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\System32\WLTRAY
.exe
O4 - HKLM\..\Run: [lxccmon.exe] "C:\Program Files\Lexmark 3300 Series\lxccmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [LXCCCATS] rundll32 C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\LXC
Ctime.dll,
_RunDLLEnt
ry@16
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
e"
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\ADMINI~1\LOCAL
S~1\Temp\2
0083109557
_mcinfo.ex
e /insfin
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\a
vgcc.exe /STARTUP
O4 - HKCU\..\Run: [XP Tools] C:\Program Files\XP Tools\xptools.exe /min
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.e
xe" /VeohHide
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\a
vgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\a
vgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\a
vgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\a
vgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_03\bin
\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_03\bin
\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-0
0C04FAE2D4
F} - C:\PROGRA~1\MICROS~4\INetR
epl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-0
0C04FAE2D4
F} - C:\PROGRA~1\MICROS~4\INetR
epl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-0
0C04FAE2D4
F} - C:\PROGRA~1\MICROS~4\INetR
epl.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-1
2A255F085E
1} - C:\Program Files\PartyGaming\PartyPok
er\RunApp.
exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-1
2A255F085E
1} - C:\Program Files\PartyGaming\PartyPok
er\RunApp.
exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D
00330E511D
3} (StagingUI Object) -
http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cabO16 - DPF: {1A1F56AA-3401-46F9-B277-D
57F3421F82
1} (FunGamesLoader Object) -
http://www.worldwinner.com/games/v46/shared/FunGamesLoader.cabO16 - DPF: {215B8138-A3CF-44C5-803F-8
226143CFC0
A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
0105AA9B6A
E} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cabO16 - DPF: {33E54F7F-561C-49E6-929B-D
7E76D3AFEB
1} (Pool Control) -
http://www.worldwinner.com/games/v48/pool/pool.cabO16 - DPF: {3BB54395-5982-4788-8AF4-B
5388FFDD0D
8} (MSN Games Buddy Invite) -
http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5
A1EDB1D8A2
1} -
http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cabO16 - DPF: {56336BCB-3D8A-11D6-A00B-0
050DA18DE7
1} -
http://software-dl.real.com/128b4e176c8f62cc4c16/netzip/RdxIE2.cabO16 - DPF: {5736C456-EA94-4AAC-BB08-9
17ABDD035B
3} (ZonePAChat Object) -
http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cabO16 - DPF: {58FC4C77-71C2-4972-A8CD-7
8691AD8515
8} (BJA Control) -
http://www.worldwinner.com/games/v49/bjattack/bjattack.cabO16 - DPF: {5F8469B4-B055-49DD-83F7-6
2B522420EC
C} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cabO16 - DPF: {615F158E-D5CA-422F-A8E7-F
6A5EED7063
B} (Bejeweled Control) -
http://www.worldwinner.com/games/v45/bejeweled/bejeweled.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E
099162EEEC
5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {67DABFBF-D0AB-41FA-9C46-C
C0F2172161
6} (DivXBrowserPlugin Object) -
http://download.divx.com/player/DivXBrowserPlugin.cabO16 - DPF: {85D1F3B2-2A21-11D7-97B9-0
010DC2A624
3} (SecureLogin class) -
http://secure2.comned.com/signuptemplates/securelogin-devel.cabO16 - DPF: {8A94C905-FF9D-43B6-8708-F
0F22D22B1C
B} (Wwlaunch Control) -
http://www.worldwinner.com/games/shared/wwlaunch.cabO16 - DPF: {97438FE9-D361-4279-BA82-9
8CC0877A71
7} (Cubis Control) -
http://www.worldwinner.com/games/v55/cubis/cubis.cabO16 - DPF: {A4110378-789B-455F-AE86-3
A1BFC40285
3} (ZPA_SHVL Object) -
http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cabO16 - DPF: {A91FB93D-7561-4524-8484-5
C27C8FA8D4
2} (WwLuxor Control) -
http://www.worldwinner.com/games/v49/luxor/luxor.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-2
2031317559
2} (MSN Games - Installer) -
http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cabO16 - DPF: {C5326A4D-E9AA-40AD-A09A-E
74304D86B4
7} (DinerDash Control) -
http://www.worldwinner.com/games/v50/dinerdash/dinerdash.cabO16 - DPF: {C86FF4B0-AA1D-46D4-8612-0
25FB86583C
7} (AstoundLauncher Control) -
http://zone.msn.com/bingame/jobo/default/AstoundLauncher.cab#version=1,0,0,10O16 - DPF: {C93C1C34-CEA9-49B1-9046-0
40F59E0E0D
8} (Paint Control) -
http://www.worldwinner.com/games/v42/paint/paint.cabO16 - DPF: {CAC181B0-4D70-402D-B571-C
596A47D0CE
0} (CBankshotZoneCtrl Class) -
http://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cabO16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C
771BB36993
7} (MSN Games Game Communicator) -
http://zone.msn.com/binframework/v10/StProxy.cab55579.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-7
3DB16A1543
A} (PopCapLoader Object) -
http://zone.msn.com/bingame/popcaploader_v10.cabO16 - DPF: {FAE74270-E5EE-49C3-B816-E
A8B4D55F38
F} (H2hPool Control) -
http://www.worldwinner.com/games/v53/h2hpool/h2hpool.cabO16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F
3C737E37BC
4} (CPlayFirstSweetopiaContro
l Object) -
http://zone.msn.com/bingame/swet/default/Sweetopia.1.0.0.46.cabO21 - SSODL: btrklfr - {B5D1DC7B-99A1-4FB6-B0A7-3
5300297AF9
D} - C:\WINDOWS\btrklfr.dll
O21 - SSODL: apdqnxp - {48118BF7-285C-456C-AB61-0
6A8B88E7D2
B} - C:\WINDOWS\apdqnxp.dll (file missing)
O21 - SSODL: MonChk - {ac0e89e8-1825-4153-8658-6
37705601f6
7} - C:\WINDOWS\Installer\{ac0e
89e8-1825-
4153-8658-
637705601f
67}\MonChk
.dll (file missing)
O21 - SSODL: zip - {e693ff39-fcb6-48ab-9985-d
123d71c986
7} - C:\WINDOWS\Installer\{e693
ff39-fcb6-
48ab-9985-
d123d71c98
67}\zip.dl
l (file missing)
O21 - SSODL: ChkVolume - {f91ac192-3dd3-4406-9c4e-9
d0cc6ebcad
4} - C:\WINDOWS\Installer\{f91a
c192-3dd3-
4406-9c4e-
9d0cc6ebca
d4}\ChkVol
ume.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev
xx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\a
vgamsvr.ex
e
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\a
vgupsvc.ex
e
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxccco
ms.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLa
bs\vsmon.e
xe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrys
vc.exe
--
End of file - 11878 bytes
Start Free Trial