Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Major brower problem.  (Read 5474 times)

0 Members and 1 Guest are viewing this topic.

eswginger

  • Guest
Major brower problem.
« on: March 13, 2007, 07:31:52 PM »
all of my browers i have seem to do the same what ever i do to try and correct it
basicaly i can be randomly surfing the web and it changes to some random page like 888.com or this http://winantivirus.com/download/2007/
and along with about 20 different pages.
the 2nd thing that happenes is it starts ALOT of browers up, starting at 1 and keeps adding untill i end the iexplorer.exe in processes
had it up to 50 browers before now.

my hijack this log is too big to post on here so i uploaded for your convience
http://eswclan.net/images/hijackthis.log

this is seriously affecting my ability to do the stuff i normaly do like controll my gameservers.

Thanks for your help in Advance

Robin Mitchell

CBMatt

  • Mod & Malware Specialist


  • Prodigy

  • Sad and lonely...and loving every minute of it.
  • Thanked: 167
    • Yes
  • Experience: Experienced
  • OS: Windows 7
Re: Major brower problem.
« Reply #1 on: March 14, 2007, 12:24:19 AM »
Definitely sounds like you have some kind of adware/spyware.  What protection do you have?  Also, to be on the safe side, please scan with HijackThis again and post the results here instead of attaching them or linking to them.  It will take several posts, but that's alright.  We don't want to take the risk of spreading whatever infection(s) you might have.  Do that and someone will come along to help you out.

I would also advise downloading SiteAdvisor and SpywareBlaster, which will both make your internet browsing a lot safer.  However, I wouldn't do this until your log has been checked and you have been given a clean bill of health.
Quote
An undefined problem has an infinite number of solutions.
—Robert A. Humphrey

oddjob



    Hopeful

    Thanked: 4
    • Experience: Beginner
    • OS: Windows 7
    Re: Major brower problem.
    « Reply #2 on: March 14, 2007, 07:20:41 AM »
    Quote
    ..... it changes to some random page like .... http://winantivirus.com/download/2007/
    and along with about 20 different pages.
    My edit in bold is the key here.

    Winantivirus is malware and a definite unwanted program. Part of the Vundo/Virtuemonde scum.


    Download VundoFix.exe to your desktop from here ....

    http://www.atribune.org/ccount/click.php?id=4

        * Double-click VundoFix.exe to run it.
        * Click the Scan for Vundo button.
        * Once it's done scanning, click the Remove Vundo button.
        * You will receive a prompt asking if you want to remove the files, click YES
        * Once you click yes, your desktop will go blank as it starts removing Vundo.
        * When completed, it will prompt that it will reboot your computer, click OK.

    Note >>> It is possible that VundoFix encounters a file it could not remove.
    In this case, VundoFix will run on reboot; simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

    You may need to run it a few times to get rid of it fully.

    Post back and let us know how you get on.


    OJ

    eswginger

    • Guest
    Re: Major brower problem.
    « Reply #3 on: March 14, 2007, 07:49:36 AM »
    Logfile of HijackThis v1.99.1
    Scan saved at 13:47:50, on 14/03/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
    C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
    C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
    C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
    C:\WINDOWS\CTHELPER.EXE
    C:\WINDOWS\system32\CTXFIHLP.EXE
    C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
    C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe
    C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
    C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
    C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDPOP3.exe
    C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe
    C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
    C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    C:\Program Files\Schmads Inc\G15_TeamSpeak\G15_TeamSpeak.exe
    C:\Program Files\McAfee.com\VSO\oasclnt.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    c:\program files\mcafee.com\agent\mcagent.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
    C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    C:\Program Files\MSI\Live Update 3\LMonitor.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Download Manager\DLM.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
    C:\Program Files\MSI\Core Center\CoreCenter.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    c:\progra~1\mcafee.com\vso\mcvsftsn.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
    C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Documents and Settings\Robin\My Documents\VundoFix.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\HijackThis\HijackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
    O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
    O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
    O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
    O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe"
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
    O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"

    eswginger

    • Guest
    Re: Major brower problem.
    « Reply #4 on: March 14, 2007, 07:53:19 AM »
    O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\system32\sktjvkvo.dll",setvm
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
    O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
    O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h20264.www2.hp.com/ediags/dd/install/HPInstallMgr_v01_4.cab
    O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by135fd.bay135.hotmail.msn.com/activex/HMAtchmt.ocx
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
    O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    i use mcafee internet security (firewallplus, antivirus, antispam & privacy service)
    i have adaware personal, search and distroy and i also used trend micro's online scan
    vundofix picked up 9 files in my system32 folder....

    eswginger

    • Guest
    Re: Major brower problem.
    « Reply #5 on: March 14, 2007, 08:22:42 AM »
    vundo got rid of the files and i have done any scan i can find and it seems to have fixed it, if u can check my hijackthis log and see if theres anything left i would be greatfull

    oddjob



      Hopeful

      Thanked: 4
      • Experience: Beginner
      • OS: Windows 7
      Re: Major brower problem.
      « Reply #6 on: March 14, 2007, 08:56:54 AM »
      The log is clean of vundo but still a couple of things to sort out.

      Open HJT ... click on scan ... put a tick/check mark next to this entry IF it is still present ...

      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

      Remember to close ALL open browser windows before clicking on "Fix Checked" at the foot of the HJT window.

      ***************

      Now carry out a system-wide search for this file ...

      ALCMTR.EXE

      Delete it.

      ***************

      Empty your recycle bin.

      ***************

      Your Java is a little out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

      Updating Java:
      • Download the latest version of  Java Runtime Environment (JRE) 6.
      • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..

      • Click the "Download" button to the right.
      • Check the box that says: "Accept License Agreement".
      • The page will refresh.
      • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
      • Close any programs you may have running - especially your web browser.
      • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
      • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
      • Click the Remove or Change/Remove button.
      • Repeat as many times as necessary to remove each Java versions.
      • Reboot your computer once all Java components are removed.
      • Then from your desktop double-click on jre-6-windowsi586-p.exe to install the newest version.
      ****************

      If you are having no more problems please post back once more to confirm and I will let you have some final advice on PC protection.



      OJ
      « Last Edit: March 14, 2007, 08:57:39 AM by oddjob »

      eswginger

      • Guest
      Re: Major brower problem.
      « Reply #7 on: March 14, 2007, 09:21:59 AM »
      ok i did all what u said and everything seems great, except my printer problem but i will post in a diff topic for that.

      u said u have some advice for me?????

      i use mcafee as my main security

      oddjob



        Hopeful

        Thanked: 4
        • Experience: Beginner
        • OS: Windows 7
        Re: Major brower problem.
        « Reply #8 on: March 14, 2007, 10:11:59 AM »
        If you are certain you have no more trouble you should clear out all old System Restore points then immediately create a new one so you have something to fall back on should anything go awry again. Also remember to make SR points on a regular basis.

        More on System Restore ...

        http://www.microsoft.com/windowsxp/using/helpandsupport/getstarted/ballew_03may19.mspx


        What may have lead up to your infection and help keep your computer free of malware …

        http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html

        http://www.help2go.com/Tutorials/Protect_Your_PC/Avoid_Web_Browser_Hijackers.html

        There is a little duplication but these tutorials are both well worth reading.


        If you do suffer an infection again you should run first Ccleaner to clean out your system. Get Ccleaner here but ensure you install it WITHOUT the optional Yahoo Toolbar download (you must untick/uncheck the relevant box on download) …

        http://www.ccleaner.com/


        Also run through this before posting another HijackThis log …

        http://www.help2go.com/Tutorials/Protect_Your_PC/Get_Rid_of_Spyware%2C_Adware%2C_and_Web_Browser_Hijackers.html


        Best wishes.


        OJ

        eswginger

        • Guest
        Re: Major brower problem.
        « Reply #9 on: March 15, 2007, 11:01:48 AM »
        ok its kinda back, i did a vundofix and it didnt work, i have mcafee site adviser, ccleaner, spyblaster, adaware, search and distroy.

        it redirects me to this http://64.111.208.122/click.php?c=7acef945551a0b3da504&r=1

        helpppppppppp......

        oddjob



          Hopeful

          Thanked: 4
          • Experience: Beginner
          • OS: Windows 7
          Re: Major brower problem.
          « Reply #10 on: March 15, 2007, 11:16:13 AM »
          Please download FixwareOut from one of the following sites .....
           
          http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe
           
          http://downloads.subratam.org/Fixwareout.exe
           
           
          Save it to your desktop and run it.  
           
          Click Next, then Install, make sure "Run fixit" is checked and click Finish.
           
          The fix will begin; follow the prompts.  
           
          If your firewall gives an alert, (because this tool will download an additional file from the internet), please don't let your firewall block it, but allow it instead.
           
          Then you will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

          Once the desktop loads please save the text that will open report.txt.

           
          Note: ONLY if you have connection problems after performing above steps - go to Start > Control Panel choose work connections, right click on your default connection, usually Local Area Connection or Dial-up Connection if you are using Dial-up, and left click on properties. Double-click on the Internet Protocol (TCP/IP) and select the radio button that says obtain DNS servers automatically. Click OK twice and restart your computer.

          **************

          Now install Ccleaner from the link above and clear out your system with it.


          After all this please post back a fresh HJT log, the report.txt and an update on how the computer is operating now.


          OJ
          « Last Edit: March 15, 2007, 11:26:42 AM by oddjob »

          eswginger

          • Guest
          Re: Major brower problem.
          « Reply #11 on: March 15, 2007, 12:14:40 PM »
          didnt fix it

          Logfile of HijackThis v1.99.1
          Scan saved at 18:13:11, on 15/03/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Windows Defender\MsMpEng.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
          C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
          C:\WINDOWS\system32\CTsvcCDA.EXE
          c:\program files\mcafee.com\agent\mcdetect.exe
          c:\PROGRA~1\mcafee.com\vso\mcshield.exe
          c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
          C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
          C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\SiteAdvisor\5248\SAService.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\wanmpsvc.exe
          C:\WINDOWS\system32\notepad.exe
          C:\WINDOWS\RTHDCPL.EXE
          C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
          C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
          C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
          C:\WINDOWS\CTHELPER.EXE
          C:\WINDOWS\system32\CTXFIHLP.EXE
          C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
          C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
          C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe
          C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDPOP3.exe
          C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
          C:\Program Files\McAfee.com\VSO\mcvsshld.exe
          C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe
          C:\Program Files\McAfee.com\VSO\oasclnt.exe
          C:\Program Files\Schmads Inc\G15_TeamSpeak\G15_TeamSpeak.exe
          c:\progra~1\mcafee.com\vso\mcvsescn.exe
          c:\program files\mcafee.com\agent\mcagent.exe
          C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
          C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
          C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          C:\Program Files\MSI\Live Update 3\LMonitor.exe
          C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\SiteAdvisor\5248\SiteAdv.exe
          C:\Program Files\Java\jre1.6.0\bin\jusched.exe
          C:\Program Files\MSN Messenger\msnmsgr.exe
          C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
          C:\Program Files\MSI\Core Center\CoreCenter.exe
          c:\progra~1\mcafee.com\vso\mcvsftsn.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\Logitech\SetPoint\SetPoint.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
          C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
          C:\WINDOWS\system32\msiexec.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\Program Files\MSN Messenger\usnsvc.exe
          C:\Program Files\HijackThis\HijackThis.exe
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
          O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\5248\SiteAdv.dll
          O2 - BHO: (no name) - {15D1B0EB-0055-4F51-BE03-8A4DADA1B8D6} - C:\WINDOWS\system32\qgbvftac.dll
          O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\PROGRA~1\mcafee.com\mps\mcbrhlpr.dll
          O2 - BHO: (no name) - {36FDF945-9540-4823-A84A-AC43FA97A0E5} - (no file)
          O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
          O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: (no name) - {C3178C97-FE42-4A9F-8574-C9BF97524A17} - (no file)
          O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
          O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\5248\SiteAdv.dll

          eswginger

          • Guest
          Re: Major brower problem.
          « Reply #12 on: March 15, 2007, 12:15:41 PM »
          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
          O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
          O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
          O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
          O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
          O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
          O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
          O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
          O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
          O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe"
          O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
          O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
          O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
          O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
          O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
          O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
          O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
          O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
          O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
          O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
          O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
          O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\5248\SiteAdv.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
          O4 - Global Startup: Logitech SetPoint.lnk = ?
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
          O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
          O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h20264.www2.hp.com/ediags/dd/install/HPInstallMgr_v01_4.cab
          O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by135fd.bay135.hotmail.msn.com/activex/HMAtchmt.ocx
          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\5248\SiteAdv.dll
          O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
          O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
          O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
          O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
          O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe

          eswginger

          • Guest
          Re: Major brower problem.
          « Reply #13 on: March 15, 2007, 12:16:04 PM »
          O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
          O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
          O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
          O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\5248\SAService.exe
          O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

          report.txt

           
          Fixwareout Last edited 2/11/2007
          Post this report in the forums please
          ...
          »»»»»Prerun check

          »»»»» System restarted
           
          »»»»» Postrun check
          HKLM\SOFTWARE\~\Winlogon\ "System"=""
          ....
          ....
          »»»»» Misc files.
          ....
          »»»»» Checking for older varients.
          ....

          Search five digit cs, dm, kd, jb, other, files.
          The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.



          Click browse, find the file then click submit.
          http://www.virustotal.com/flash/index_en.html
          Or http://virusscan.jotti.org/

          »»»»» Other



          »»»»» Current runs
          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "RTHDCPL"="RTHDCPL.EXE"
          "CTDVDDET"="\"C:\\Program Files\\Creative\\Sound Blaster X-Fi\\DVDAudio\\CTDVDDET.EXE\""
          "RCSystem"="\"C:\\Program Files\\Creative\\Shared Files\\Module Loader\\DLLML.exe\" RCSystem * -Startup"
          "AudioDrvEmulator"="\"C:\\Program Files\\Creative\\Shared Files\\Module Loader\\DLLML.exe\" -1 AudioDrvEmulator \"C:\\Program Files\\Creative\\Shared Files\\Module Loader\\Audio Emulator\\AudDrvEm.dll\""
          "VolPanel"="\"C:\\Program Files\\Creative\\Sound Blaster X-Fi\\Volume Panel\\VolPanel.exe\" /r"
          "CTHelper"="CTHELPER.EXE"
          "CTxfiHlp"="CTXFIHLP.EXE"
          "UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
          "Launch LGDCore"="\"C:\\Program Files\\Common Files\\Logitech\\G-series Software\\LGDCore.exe\" /SHOWHIDE"
          "Launch LCDMon"="\"C:\\Program Files\\Common Files\\Logitech\\LCD Manager\\lcdmon.exe\""
          "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE"
          "VSOCheckTask"="\"C:\\PROGRA~1\\McAfee.com\\VSO\\mcmnhdlr.exe\" /checktask"
          "VirusScan Online"="C:\\Program Files\\McAfee.com\\VSO\\mcvsshld.exe"
          "OASClnt"="C:\\Program Files\\McAfee.com\\VSO\\oasclnt.exe"
          "MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe"
          "MCUpdateExe"="C:\\PROGRA~1\\mcafee.com\\agent\\mcupdate.exe"
          "MPFExe"="C:\\PROGRA~1\\McAfee.com\\PERSON~1\\MpfTray.exe"
          "MPSExe"="c:\\PROGRA~1\\mcafee.com\\mps\\mscifapp.exe /embedding"
          "MSKAGENTEXE"="C:\\PROGRA~1\\McAfee\\SPAMKI~1\\MskAgent.exe"
          "MSKDetectorExe"="C:\\PROGRA~1\\McAfee\\SPAMKI~1\\MSKDetct.exe /startup"
          "HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
          "ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\CLIStart.exe\""
          "LiveMonitor"="C:\\Program Files\\MSI\\Live Update 3\\LMonitor.exe"
          "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
          "Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
          "SiteAdvisor"="C:\\Program Files\\SiteAdvisor\\5248\\SiteAdv.exe"
          "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
          "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
          ....
          Hosts file was reset, If you use a custom hosts file please replace it
          »»»»» End report »»»»»

          oddjob



            Hopeful

            Thanked: 4
            • Experience: Beginner
            • OS: Windows 7
            Re: Major brower problem.
            « Reply #14 on: March 15, 2007, 12:51:22 PM »
            Please print out or copy this page to Notepad in order to assist you when carrying out the following instructions.

            ***************

            Go to My Computer >Tools >Folder Options >View tab and select Show hidden files and folders. Uncheck the Hide protected operating system files (recommended) option. Also make sure there is no checkmark beside Hide file extensions for known file types. Click OK.  

            ***************
              
            Restart your computer and boot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list).  In some systems, this may be the F5 key, so try that if F8 doesn't work.  Login on your usual account.  Make sure to close any open browsers.

            ***************

            Open HijackThis and click on 'Do a System Scan Only'. Check the following entries (If they still exist, make sure you do not miss any)

            O2 - BHO: (no name) - {15D1B0EB-0055-4F51-BE03-8A4DADA1B8D6} - C:\WINDOWS\system32\qgbvftac.dll

            O2 - BHO: (no name) - {36FDF945-9540-4823-A84A-AC43FA97A0E5} - (no file)

            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

            O2 - BHO: (no name) - {C3178C97-FE42-4A9F-8574-C9BF97524A17} - (no file)


            Please remember to close all other windows, including browsers then click Fix checked.

            ***************

            Delete the following File indicated in bold IF it still exists[/b] ......

            C:\WINDOWS\system32\qgbvftac.dll

            ***************

            Reboot your system in Normal Mode, use it as you would usually do and let us know how it's working now.

            Please also post back a fresh HJT log.


            OJ