|
|
jimbo1046
new user
Reg'd: Fri
Posts: 4
|
|
Hi, First time I've used this so bear with me. Everytime I start up my computer, a Russian website appears. Plus a click me!!! internet explorer comes on the desktop. Everytime I delete them and start my computer agin, they reappear. It's so unbelievably annoying. I'm using Windows ME. Don't know if this helps but I've noticed other users post it, so here's my hijackthis report.
Logfile of HijackThis v1.98.0 Scan saved at 16:40:59, on 13/08/2004 Platform: Windows ME (Win9x 4.90.3000) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\MSTASK.EXE C:\WINDOWS\SYSTEM\MDM.EXE C:\WINDOWS\SYSTEM\STIMON.EXE C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.EXE C:\WINDOWS\SYSTEM\SYSTRAY.EXE C:\WINDOWS\LOADQM.EXE C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE C:\WINDOWS\START MENU\PROGRAMS\STARTUP\WINUPDATE.EXE C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE C:\PROGRAM FILES\COMMON FILES\GMT\GMT.EXE C:\WINDOWS\SYSTEM\RNAAPP.EXE C:\WINDOWS\SYSTEM\TAPISRV.EXE C:\WINDOWS\SYSTEM\WMIEXE.EXE C:\MY DOCUMENTS\HJTLOG.EXE C:\HIJACKTHIS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.searchdirs.com/panel/?aff=1020&exp=4 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchdirs.com/?aff=1020&exp=4 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchdirs.com/panel/?aff=1020&exp=4 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchdirs.com/?aff=1020&exp=4 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost O1 - Hosts: 88.88.88.88 elite O1 - Hosts: 207.44.194.56 www.google.akadns.net O1 - Hosts: 207.44.194.56 www.google.com O1 - Hosts: 207.44.194.56 google.com O1 - Hosts: 207.44.194.56 www.altavista.com O1 - Hosts: 207.44.194.56 altavista.com O1 - Hosts: 207.44.194.56 search.yahoo.com O1 - Hosts: 207.44.194.56 uk.search.yahoo.com O1 - Hosts: 207.44.194.56 ca.search.yahoo.com O1 - Hosts: 207.44.194.56 jp.search.yahoo.com O1 - Hosts: 207.44.194.56 au.search.yahoo.com O1 - Hosts: 207.44.194.56 de.search.yahoo.com O1 - Hosts: 207.44.194.56 search.yahoo.co.jp O1 - Hosts: 207.44.194.56 www.lycos.de O1 - Hosts: 207.44.194.56 www.lycos.ca O1 - Hosts: 207.44.194.56 www.lycos.jp O1 - Hosts: 207.44.194.56 www.lycos.co.jp O1 - Hosts: 207.44.194.56 alltheweb.com O1 - Hosts: 207.44.194.56 web.ask.com O1 - Hosts: 207.44.194.56 ask.com O1 - Hosts: 207.44.194.56 www.ask.com O1 - Hosts: 207.44.194.56 www.teoma.com O1 - Hosts: 207.44.194.56 search.aol.com O1 - Hosts: 207.44.194.56 www.looksmart.com O1 - Hosts: 207.44.194.56 auto.search.msn.com O1 - Hosts: 207.44.194.56 search.msn.com O1 - Hosts: 207.44.194.56 ca.search.msn.com O1 - Hosts: 207.44.194.56 fr.ca.search.msn.com O1 - Hosts: 207.44.194.56 search.fr.msn.be O1 - Hosts: 207.44.194.56 search.fr.msn.ch O1 - Hosts: 207.44.194.56 search.latam.yupimsn.com O1 - Hosts: 207.44.194.56 search.msn.at O1 - Hosts: 207.44.194.56 search.msn.be O1 - Hosts: 207.44.194.56 search.msn.ch O1 - Hosts: 207.44.194.56 search.msn.co.in O1 - Hosts: 207.44.194.56 search.msn.co.jp O1 - Hosts: 207.44.194.56 search.msn.co.kr O1 - Hosts: 207.44.194.56 search.msn.com.br O1 - Hosts: 207.44.194.56 search.msn.com.hk O1 - Hosts: 207.44.194.56 search.msn.com.my O1 - Hosts: 207.44.194.56 search.msn.com.sg O1 - Hosts: 207.44.194.56 search.msn.com.tw O1 - Hosts: 207.44.194.56 search.msn.co.za O1 - Hosts: 207.44.194.56 search.msn.de O1 - Hosts: 207.44.194.56 search.msn.dk O1 - Hosts: 207.44.194.56 search.msn.es O1 - Hosts: 207.44.194.56 search.msn.fi O1 - Hosts: 207.44.194.56 search.msn.fr O1 - Hosts: 207.44.194.56 search.msn.it O1 - Hosts: 207.44.194.56 search.msn.nl O1 - Hosts: 207.44.194.56 search.msn.no O1 - Hosts: 207.44.194.56 search.msn.se O1 - Hosts: 207.44.194.56 search.ninemsn.com.au O1 - Hosts: 207.44.194.56 search.t1msn.com.mx O1 - Hosts: 207.44.194.56 search.xtramsn.co.nz O1 - Hosts: 207.44.194.56 search.yupimsn.com O1 - Hosts: 207.44.194.56 uk.search.msn.com O1 - Hosts: 207.44.194.56 search.lycos.com O1 - Hosts: 207.44.194.56 www.lycos.com O1 - Hosts: 207.44.194.56 www.google.ca O1 - Hosts: 207.44.194.56 google.ca O1 - Hosts: 207.44.194.56 www.google.uk O1 - Hosts: 207.44.194.56 www.google.co.uk O1 - Hosts: 207.44.194.56 www.google.com.au O1 - Hosts: 207.44.194.56 www.google.co.jp O1 - Hosts: 207.44.194.56 www.google.jp O1 - Hosts: 207.44.194.56 www.google.at O1 - Hosts: 207.44.194.56 www.google.be O1 - Hosts: 207.44.194.56 www.google.ch O1 - Hosts: 207.44.194.56 www.google.de O1 - Hosts: 207.44.194.56 www.google.se O1 - Hosts: 207.44.194.56 www.google.dk O1 - Hosts: 207.44.194.56 www.google.fi O1 - Hosts: 207.44.194.56 www.google.fr O1 - Hosts: 207.44.194.56 www.google.com.gr O1 - Hosts: 207.44.194.56 www.google.com.hk O1 - Hosts: 207.44.194.56 www.google.ie O1 - Hosts: 207.44.194.56 www.google.co.il O1 - Hosts: 207.44.194.56 www.google.it O1 - Hosts: 207.44.194.56 www.google.co.kr O1 - Hosts: 207.44.194.56 www.google.com.mx O1 - Hosts: 207.44.194.56 www.google.nl O1 - Hosts: 207.44.194.56 www.google.co.nz O1 - Hosts: 207.44.194.56 www.google.pl O1 - Hosts: 207.44.194.56 www.google.pt O1 - Hosts: 207.44.194.56 www.google.com.ru O1 - Hosts: 207.44.194.56 www.google.com.sg O1 - Hosts: 207.44.194.56 www.google.co.th O1 - Hosts: 207.44.194.56 www.google.com.tr O1 - Hosts: 207.44.194.56 www.google.com.tw O1 - Hosts: 207.44.194.56 go.google.com O1 - Hosts: 207.44.194.56 google.at O1 - Hosts: 207.44.194.56 google.be O1 - Hosts: 207.44.194.56 google.de O1 - Hosts: 207.44.194.56 google.dk O1 - Hosts: 207.44.194.56 google.fi O1 - Hosts: 207.44.194.56 google.fr O1 - Hosts: 207.44.194.56 google.com.hk O1 - Hosts: 207.44.194.56 google.ie O1 - Hosts: 207.44.194.56 google.co.il O1 - Hosts: 207.44.194.56 google.it O2 - BHO: IEHlprObj Class - {CD4C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRAM FILES\GO!ZILLA\GOIEHLP.DLL (file missing) O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\PROGRAM FILES\MEDIALOADS ENHANCED\ME2.DLL O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX O4 - HKLM\..\Run: [CMESys] "C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.EXE" O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\Run: [LoadQM] loadqm.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Startup: WinUpdate.exe O8 - Extra context menu item: Download with Go!Zilla - file://C:\PROGRAM FILES\GO!ZILLA\download-with-gozilla.html O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O16 - DPF: {F08555B1-9CC3-11D2-AA8E-000000000000} - http://www.freshgirls.com/download/freshgirls.cab O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://mirror.worldwinner.com/games/v51/h2hpool/h2hpool.cab O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://mirror.worldwinner.com/games/shared/wwlaunch.cab O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=ba9e5852dc980b986fee61c992c908c8c4aec16057356878cb33e09dd16b4cf022ee4f03b5e10bcc02ba107b27ceffe90e 3fd70ec204a8ea059f9bce3429:7de6395213b713f896a76337b174f90e O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = mydomain.com O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.57.146.14 O21 - SSODL: AUHook - {BCBCD383-3E06-11D3-91A9-00C04F68105C} - C:\WINDOWS\SYSTEM\AUHOOK.DLL
I'd be eternally grateful if someone could help me.
James
Edited by greysts on 13/08/2004 17:23 (server time).
|
|
bricat
HijackThis Helper
Reg'd: Wed
Posts: 28633
Loc: belfast
|
|
Download and then check for updates and run COOLWEBSHREDDER Click Fix, don't just scan. Let it fix everything it asks about.
Then :- reboot your computer.
Close all windows,rerun HJT, put a tick beside these and click FIX CHECKED
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.searchdirs.com/panel/?aff=1020&exp=4 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchdirs.com/?aff=1020&exp=4 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchdirs.com/panel/?aff=1020&exp=4 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchdirs.com/?aff=1020&exp=4
O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\PROGRAM FILES\MEDIALOADS ENHANCED\ME2.DLL O4 - HKLM\..\Run: [CMESys] "C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.EXE" O4 - HKLM\..\Run: [LoadQM] loadqm.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Startup: WinUpdate.exe O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O16 - DPF: {F08555B1-9CC3-11D2-AA8E-000000000000} - http://www.freshgirls.com/download/freshgirls.cab O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://mirror.worldwinner.com/games/v51/h2hpool/h2hpool.cab O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://mirror.worldwinner.com/games/shared/wwlaunch.cab O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=ba9e5852dc980b986fee61c992c908c8c4aec16057356878cb33e09dd16b4cf022ee4f03b5e10bcc02ba107b27ceffe90e 3fd70ec204a8ea059f9bce3429:7de6395213b713f896a76337b174f90e O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = mydomain.com O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.57.146.14
then go to C:\PROGRAM FILES and delete MEDIALOADS ENHANCED<----folder
then go to C:\PROGRAM FILES\COMMON FILES and delete CMEII <----folder and GMT
then go to C:\WINDOWS\START MENU\PROGRAMS\STARTUP and delete WINUPDATE.EXE
then reboot and post a fresh log.
AVG ANTIVIRUS..AVG email scanner..SYGATE FIREWALL..ADAWARE..SPYWAREBLASTER..HIJACK THIS..WINDOWS UPDATE..COOLWEBSHREDDER.. SPYWARE GUARD..WINZIP.. DISKEEPERLITE BARNEYS PLACE
Sic biscuitus disintegratum
|
jimbo1046
new user
Reg'd: Fri
Posts: 4
|
|
Cheers mate, that did the trick, that bloody russian website has gone, as have the click me icons. That was a great help. Thanks again. James
|
greysts
regular
Reg'd: Thu
Posts: 17983
Loc: Colchester
|
|
The job is not yet complete. Please post another log as requested.

Do you know that we're all in line for succession to the throne? Really? Well, if forty-eight million, two hundred thousand, seven hundred and one people died I'd be Queen.
|
jimbo1046
new user
Reg'd: Fri
Posts: 4
|
|
Oh right sorry, well here it is.
Logfile of HijackThis v1.97.7 Scan saved at 14:32:46, on 15/08/2004 Platform: Windows ME (Win9x 4.90.3000) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\MSTASK.EXE C:\WINDOWS\SYSTEM\STIMON.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\SYSTEM\SYSTRAY.EXE C:\WINDOWS\SYSTEM\WMIEXE.EXE C:\WINDOWS\SYSTEM\PSTORES.EXE C:\WINDOWS\SYSTEM\DDHELP.EXE C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost O2 - BHO: (no name) - {CD4C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRAM FILES\GO!ZILLA\GOIEHLP.DLL (file missing) O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE O8 - Extra context menu item: Download with Go!Zilla - file://C:\PROGRAM FILES\GO!ZILLA\download-with-gozilla.html O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37899.337337963
|
|
|