pinaldave
asked on
highjackthis log :(
okey,
I have spyware which is not able to caught by ad-aware. it says there are none but actually this offeroptimizer.com pop up is always there when I open my IE. This is my highjackthis log.
Regards,
---Pinal
Logfile of HijackThis v1.97.7
Scan saved at 7:04:14 AM, on 11/2/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e xe
C:\WINDOWS\system32\winlog on.exe
C:\WINDOWS\system32\servic es.exe
C:\WINDOWS\system32\lsass. exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\System32\brsvc0 1a.exe
C:\WINDOWS\system32\spools v.exe
C:\WINDOWS\System32\brss01 a.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\PROGRA~1\SYMANT~1\SYMAN T~1\DefWat ch.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2. exe
C:\WINDOWS\System32\inetsr v\inetinfo .exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL$INSTANCENAME\ Binn\sqlse rvr.exe
C:\PROGRA~1\SYMANT~1\SYMAN T~1\Rtvsca n.exe
C:\WINDOWS\System32\nvsvc3 2.exe
C:\WINDOWS\System32\tcpsvc s.exe
C:\WINDOWS\System32\snmp.e xe
C:\WINDOWS\System32\svchos t.exe
C:\PROGRA~1\SYMANT~1\SYMAN T~1\vptray .exe
C:\Program Files\Common Files\Real\Update_OB\reals ched.exe
C:\WINDOWS\system32\ixwzcf r.exe
C:\WINDOWS\system32\ctfmon .exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma ngr.exe
C:\Program Files\Yahoo!\Messenger\YPa ger.exe
C:\WINDOWS\system32\DllHos t.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Pinal.RUDRA.000\D esktop\dow nload\Hija ckThis.exe
R0 - HKLM\Software\Microsoft\In ternet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
R0 - HKLM\Software\Microsoft\In ternet Explorer\Main,Local Page =
O2 - BHO: (no name) - {00320615-B6C2-40A6-8F99-F 1C52D674FA D} - C:\WINDOWS\localNRD.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7 84B7D6BE0B 3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIE Helper.ocx
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-C F10577473F 7} - c:\program files\google\googletoolbar 1.dll
O2 - BHO: (no name) - {CD209A08-98B5-4669-AF9F-4 47AC525335 6} - C:\WINDOWS\System32\CSapp. dll
O2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-E D6A80FD66D A} - C:\WINDOWS\system32\msbe.d ll
O3 - Toolbar: SuperBar - {C15187C0-7992-4BC9-A174-1 B1E05A2114 9} - C:\Program Files\_SUPERBAR\_SUPERBAR. dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0 09027A5CD4 F} - c:\program files\google\googletoolbar 1.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E 1B4C16F92E B} - (no file)
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMAN T~1\vptray .exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals ched.exe" -osboot
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\system32\bridg e.dll",Loa d
O4 - HKLM\..\Run: [zhjkqpdpt] C:\WINDOWS\system32\ixwzcf r.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon .exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma ngr.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar 1.dll/cmse arch.html
O8 - Extra context menu item: Add to AD Black List - C:\Program Files\Avant Browser\AddToADBlackList.h tm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar 1.dll/cmba cklinks.ht ml
O8 - Extra context menu item: Block All Images from the Same Server - C:\Program Files\Avant Browser\AddAllToADBlackLis t.htm
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar 1.dll/cmca che.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3 \OFFICE11\ EXCEL.EXE/ 3000
O8 - Extra context menu item: Highlight - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open All Links in This Page... - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Search - C:\Program Files\Avant Browser\Search.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar 1.dll/cmsi milar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar 1.dll/cmtr ans.html
O9 - Extra button: Research (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox. dll
O16 - DPF: {0246ECA8-996F-11D1-BE2F-0 0A0C9037DF E} (TDServer Control) - http://www.chitralekha.com/wfplayer/tdserver.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1 E41684E07B B} - http://ak.imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {33564D57-0000-0010-8000-0 0AA00389B7 1} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {963BE66B-121D-4E6C-BF9F-1 A774D9A2E4 1} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupdate.exe
O16 - DPF: {BF628973-1E86-4D0E-B42C-E DDECFFABDB C} (Bugs AoD Class) - http://player.bugs.co.kr/install/bugsLoader20041018.cab
I have spyware which is not able to caught by ad-aware. it says there are none but actually this offeroptimizer.com pop up is always there when I open my IE. This is my highjackthis log.
Regards,
---Pinal
Logfile of HijackThis v1.97.7
Scan saved at 7:04:14 AM, on 11/2/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\System32\brsvc0
C:\WINDOWS\system32\spools
C:\WINDOWS\System32\brss01
C:\WINDOWS\Explorer.EXE
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\PROGRA~1\SYMANT~1\SYMAN
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.
C:\WINDOWS\System32\inetsr
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL$INSTANCENAME\
C:\PROGRA~1\SYMANT~1\SYMAN
C:\WINDOWS\System32\nvsvc3
C:\WINDOWS\System32\tcpsvc
C:\WINDOWS\System32\snmp.e
C:\WINDOWS\System32\svchos
C:\PROGRA~1\SYMANT~1\SYMAN
C:\Program Files\Common Files\Real\Update_OB\reals
C:\WINDOWS\system32\ixwzcf
C:\WINDOWS\system32\ctfmon
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma
C:\Program Files\Yahoo!\Messenger\YPa
C:\WINDOWS\system32\DllHos
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Pinal.RUDRA.000\D
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
O2 - BHO: (no name) - {00320615-B6C2-40A6-8F99-F
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-C
O2 - BHO: (no name) - {CD209A08-98B5-4669-AF9F-4
O2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-E
O3 - Toolbar: SuperBar - {C15187C0-7992-4BC9-A174-1
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMAN
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\system32\bridg
O4 - HKLM\..\Run: [zhjkqpdpt] C:\WINDOWS\system32\ixwzcf
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Add to AD Black List - C:\Program Files\Avant Browser\AddToADBlackList.h
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Block All Images from the Same Server - C:\Program Files\Avant Browser\AddAllToADBlackLis
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3
O8 - Extra context menu item: Highlight - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open All Links in This Page... - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Search - C:\Program Files\Avant Browser\Search.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
O9 - Extra button: Research (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
O16 - DPF: {0246ECA8-996F-11D1-BE2F-0
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1
O16 - DPF: {33564D57-0000-0010-8000-0
O16 - DPF: {963BE66B-121D-4E6C-BF9F-1
O16 - DPF: {BF628973-1E86-4D0E-B42C-E
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
And then Download these tools and install them:
========================== ========== ========== ==========
AdAware ==> http://www.spychecker.com/program/adaware.html
SpyBot ==> http://www.spychecker.com/program/spybot.html
CoolWebShredder ==> http://www.softpedia.com/public/cat/10/17/10-17-150.shtml
Stinger ==> http://vil.nai.com/vil/stinger
========================== ========== ========== ==========
Turn off ur System Restore >> http://www.pchell.com/virus/systemrestore.shtml
Then Disable ur Messenger Service if its running >> http://www.itc.virginia.edu/desktop/docs/messagepopup/
After that here are some "canned" Instructions of mine, If u want u can follow them to check if they can work for u or not :)
1. Restart ur machine in safemode and Login as Administrator
2. Run the AntiVirus tool and delete all viruses it found
3. Run the Spyware Removal tools and delete everything they detect
4. Then goto My Computer>Tools>Folder Options>View and turn on the feature of Show Hidden Files
5. Goto C:\Documents and Settings\ur usernmae\Local Settings\Temp and delete all files present here
6. Goto C:\Documents and Settings\ur usernmae\Local Settings\Temporary Internet Files, and delete the folder of ContentIE
7. Goto C:\Documents and Settings\ur usernmae\Cookies, and delete all cookies present here
(ofcourse im assuming that u have already saved all the login passwords for ur websites :)
8. Goto C:\Windows\Temp and delete all files present here
9. Reboot back in Normal Mode and check if problems are gone or not
10.Post Back and Good Luck :)
==========================
AdAware ==> http://www.spychecker.com/program/adaware.html
SpyBot ==> http://www.spychecker.com/program/spybot.html
CoolWebShredder ==> http://www.softpedia.com/public/cat/10/17/10-17-150.shtml
Stinger ==> http://vil.nai.com/vil/stinger
==========================
Turn off ur System Restore >> http://www.pchell.com/virus/systemrestore.shtml
Then Disable ur Messenger Service if its running >> http://www.itc.virginia.edu/desktop/docs/messagepopup/
After that here are some "canned" Instructions of mine, If u want u can follow them to check if they can work for u or not :)
1. Restart ur machine in safemode and Login as Administrator
2. Run the AntiVirus tool and delete all viruses it found
3. Run the Spyware Removal tools and delete everything they detect
4. Then goto My Computer>Tools>Folder Options>View and turn on the feature of Show Hidden Files
5. Goto C:\Documents and Settings\ur usernmae\Local Settings\Temp and delete all files present here
6. Goto C:\Documents and Settings\ur usernmae\Local Settings\Temporary Internet Files, and delete the folder of ContentIE
7. Goto C:\Documents and Settings\ur usernmae\Cookies, and delete all cookies present here
(ofcourse im assuming that u have already saved all the login passwords for ur websites :)
8. Goto C:\Windows\Temp and delete all files present here
9. Reboot back in Normal Mode and check if problems are gone or not
10.Post Back and Good Luck :)
ASKER
this is wonderful. My two best online friend replied to me. Thank you Shehar and Thank you Ashwin.
I will try right away.
Regards,
---Pinal
I will try right away.
Regards,
---Pinal
sure mate.... just post back if u get stuck somewhere :)
ASKER
With a lot of respect I will say both of you are just magic. Thank you thank you. Being Sr. Web Programmer and MS in Comp Network. I was very much stuck.
Once does not need MS to fix the computer, a right knowledge is enough to real genious.
Summery: Fixed!!!! =)
As both the answer are same and same min I will go for equal split. Thank you again.
---Pinal
Btw, everytime whenever I have seen this question, I have laughed on them (today I was stuck since five in the morning!)
Once does not need MS to fix the computer, a right knowledge is enough to real genious.
Summery: Fixed!!!! =)
As both the answer are same and same min I will go for equal split. Thank you again.
---Pinal
Btw, everytime whenever I have seen this question, I have laughed on them (today I was stuck since five in the morning!)
great, it was fast.... but just make sure that it has really gone,,,, coz malwares are not easy sometimes to kick out from the system :)
pinaldave,
Thanks for the nice words. It has been a custom (more like a rule) to direct users towards that analyzer website
than solving the issue ourselves.. Actually , you would learn more from that cos of that tutorial.
Also did you restart your computer and open the browser to see if that would still happen.
if it happens then go to start > run > msconfig
go to startup tab and disable all applications except Anti-virus .
restart and check ..
Thanks for the nice words. It has been a custom (more like a rule) to direct users towards that analyzer website
than solving the issue ourselves.. Actually , you would learn more from that cos of that tutorial.
Also did you restart your computer and open the browser to see if that would still happen.
if it happens then go to start > run > msconfig
go to startup tab and disable all applications except Anti-virus .
restart and check ..
ASKER
thank you for extra advise. I will make sure now.
Seems like it is not happening again. Worked great!
will go to office peacefully now!
---Pinal
Seems like it is not happening again. Worked great!
will go to office peacefully now!
---Pinal
ASKER
this is okey.