Originally posted by: mechBgon
How about starting in Safe Mode? You will probably want to also disable System Restore, or the stuff may get put right back by Windows itself Could you also post what their network connection is (cable, DSL, whatever), what their firewall is (a router, a software firewall, none), and what their antivirus software is (include what generation, such as "Norton Antivirus
2003" or whatever). What OS does the computer run and has it been kept up-to-date on its patches?
Also:
- Download Hijack This!
- Save it in C:\HJT or another folder of your own making
- Run it from that folder and hit Save Log
- Post the log's contents here, so the anti-spyware gurus can analyze it for you
Or you can take what Yoda calls "the easy path" and just Drop The Bomb On It :evil: WinXP Setup baby... works every time. Temporarily, at least... still gotta educate those relatives about their risky behavior. :roll: And cure world hunger while you're at it, the two jobs will be roughly equal in difficulty, right?
I put together some recommendations for preventing spyware and junk
here under the
Ongoing prevention part down the page a ways. If you can get the system cleaned up, and get the relatives to stop shooting themselves in the foot, then those measures will do a good job for them. The tough one to sell to a home user is giving up the Administrator privileges and using a Limited / Restricted-User account, but it works.
The computer is running Windows XP Pro with all the latest updates (now that installed them) It's connected through a wireless router which is using Cable Modem connection. They have the latest version of AVG antivirus running, but suspiciously no firewall running (since remmodied with Kerio Personal Firewall)
Here is the log. I would prefer a quick fix as opposed to the entire Windows XP format. I got adaware 6.0 to work, but still can't get task manager to stay open, or msconfig. Again, does anyone know why I get the "windows security" pop-up when i hit ctrl-alt-del rather than the usual task manager?
LOG:
Scan saved at 4:06:51 AM, on 11/24/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\Explorer.EXE
H:\PROGRA~1\Grisoft\AVG6\avgserv.exe
H:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
H:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
H:\WINDOWS\System32\nvsvc32.exe
H:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
H:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
H:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
H:\WINDOWS\System32\P2P Networking\P2P Networking.exe
H:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
H:\Program Files\QuickTime\qttask.exe
H:\WINDOWS\system32\AIMMSNGR.EXE
H:\WINDOWS\system32\RYAOMJRC.EXE
H:\WINDOWS\system32\REAIPLAY.EXE
H:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
H:\WINDOWS\system32\RUNDLL32.EXE
H:\WINDOWS\system32\ctfmon.exe
H:\Program Files\AIM\aim.exe
H:\WINDOWS\System32\ouxynj.exe
H:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
H:\Program Files\Internet Explorer\iexplore.exe
H:\Program Files\Internet Explorer\iexplore.exe
H:\DOCUME~1\BRIANS~1\LOCALS~1\Temp\Temporary Directory 1 for hjt.zip\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {10DB3155-EE1F-69F1-8F59-655579AE281A} - H:\WINDOWS\System32\esmxkre.dll (file missing)
O2 - BHO: (no name) - {12803A51-ED4C-39AA-8359-655579AE2919} - H:\WINDOWS\System32\xcdq.dll (file missing)
O2 - BHO: (no name) - {18DC3A58-E946-39A1-815F-655579AF2C1F} - H:\WINDOWS\System32\qrk.dll (file missing)
O2 - BHO: (no name) - {19D83606-EC12-3CA9-845B-655579AE7E19} - H:\WINDOWS\System32\wmm.dll (file missing)
O2 - BHO: (no name) - {19DF3B09-EC15-6FFC-D75B-655579AE7B4E} - H:\WINDOWS\System32\nkaa.dll (file missing)
O2 - BHO: (no name) - {1C8C6F58-EC13-60FF-820A-655579AF2B49} - H:\WINDOWS\System32\benubv.dll (file missing)
O2 - BHO: (no name) - {1DDF3304-E74E-6AF0-D35F-655579AE2E1D} - H:\WINDOWS\System32\dbppt.dll (file missing)
O2 - BHO: (no name) - {1ED86F0B-BB4E-3EA5-D25F-655579AE7B4A} - H:\WINDOWS\System32\qknwjaf.dll (file missing)
O2 - BHO: (no name) - {1F826B0E-E819-6FF0-D65F-655579AF2E16} - H:\WINDOWS\System32\deoane.dll (file missing)
O2 - BHO: (no name) - {41813701-BD19-65AC-D459-655579AE2F15} - H:\WINDOWS\System32\fixor.dll (file missing)
O2 - BHO: (no name) - {438E3351-E040-3DAB-825F-655579AE2C4D} - H:\WINDOWS\System32\uehjrdul.dll (file missing)
O2 - BHO: (no name) - {488C6E0D-BD19-31F7-D50A-655579AF2840} - H:\WINDOWS\System32\bls.dll (file missing)
O2 - BHO: (no name) - {488F6300-B14D-6DFF-825F-655579AE2D19} - H:\WINDOWS\System32\ieso.dll (file missing)
O2 - BHO: (no name) - {4C88325D-EC12-3CFC-865B-655579AE274D} - H:\WINDOWS\System32\dkldeq.dll (file missing)
O2 - BHO: (no name) - {4E8E6D09-EF4B-68A4-D05F-655579AF2F1F} - H:\WINDOWS\System32\hfen.dll (file missing)
O2 - BHO: (no name) - {4F8F300B-ED40-38FF-845B-655579AE291C} - H:\WINDOWS\System32\omwby.dll (file missing)
O2 - BHO: Curl - {A78CC2FF-6E4E-4556-B27C-D7C3A70D7A50} - H:\WINDOWS\System32\NDrv.dll (file missing)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - h:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - h:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] H:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] H:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] H:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE H:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AVG_CC] H:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [P2P Networking] H:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [SunJavaUpdateSched] H:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AIM Messenger] AIMMSNGR.EXE
O4 - HKLM\..\Run: [AOL Instent Messenger] RYAOMJRC.EXE
O4 - HKLM\..\Run: [WhenUSearchWHSE] H:\PROGRA~1\WHENUS~1\whse.exe
O4 - HKLM\..\Run: [Real Internet Player] REAIPLAY.EXE
O4 - HKLM\..\Run: [ViewMgr] H:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE H:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] H:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Ebla] H:\Documents and Settings\Brian Sanders\Application Data\aoro.exe
O4 - HKCU\..\Run: [Tryrpzjn] H:\WINDOWS\System32\ouxynj.exe
O4 - HKCU\..\RunOnce: [AIM Messenger] AIMMSNGR.EXE
O4 - HKCU\..\RunOnce: [Real Internet Player] REAIPLAY.EXE
O4 - HKCU\..\RunOnce: [AOL Instent Messenger] RYAOMJRC.EXE
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: RollerCoaster Tycoon 3 Registration.lnk = H:\Documents and Settings\Brian Sanders\Local Settings\Temp\{A9AE1C47-EC5B-466B-A904-4B990021420C}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe
O4 - Global Startup: MA111 Configuration Utility.lnk = H:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe
O8 - Extra context menu item: &Google Search - res://h:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://h:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://h:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://h:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://h:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
http://download.microsoft.com/...901338C922/wmv9VCM.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} -
http://v4.windowsupdate.micros...l.CAB?37993.8598958333
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com...cabs/flash/swflash.cab