madboy33 Posted December 6, 2003 Author Report Share Posted December 6, 2003 thanks nells Link to comment Share on other sites More sharing options...
mark2 Posted December 6, 2003 Report Share Posted December 6, 2003 Here goes, Madboy, have HJT fix the following by ticking their boxes,closing ALL browser and explorer windows, then click fixO1 - Hosts: 211.162.108.123 www.123buyviagra.comO1 - Hosts: 211.162.108.123 www.1-2-3-buy-viagra.comO1 - Hosts: 211.162.108.123 www.2-buy-cheap-viagra.comO1 - Hosts: 211.162.108.123 www.2-buy-viagra-cheap-online.comO1 - Hosts: 211.162.108.123 www.a1b2c3.comO1 - Hosts: 211.162.108.123 www.agingwithsuccess.comO1 - Hosts: 211.162.108.123 www.all-viagra.comO1 - Hosts: 211.162.108.123 www.amazingpills.netO1 - Hosts: 211.162.108.123 www.americanpharmacy.comO1 - Hosts: 211.162.108.123 www.a-zonlinedrugs.comO1 - Hosts: 211.162.108.123 www.bluecommunity.netO1 - Hosts: 211.162.108.123 www.buycheappills.netO1 - Hosts: 211.162.108.123 www.buy-cheap-rx.comO1 - Hosts: 211.162.108.123 www.buy-generic-viagra.comO1 - Hosts: 211.162.108.123 www.buy-generic-viagra-sildenafil-citrate.comO1 - Hosts: 211.162.108.123 www.buy-low-cost-viagra.comO1 - Hosts: 211.162.108.123 www.buy-order-viagra.comO1 - Hosts: 211.162.108.123 www.buy--viagra.comO1 - Hosts: 211.162.108.123 www.buy-viagra-4less.comO1 - Hosts: 211.162.108.123 www.buyviagra-direct.comO1 - Hosts: 211.162.108.123 www.buy-viagra-free-prescriptions.comO1 - Hosts: 211.162.108.123 www.buy-viagra-here.comO1 - Hosts: 211.162.108.123 www.buy-viagra-internet.netO1 - Hosts: 211.162.108.123 www.buy-viagra-now.netO1 - Hosts: 211.162.108.123 www.buy-viagra-now.tripod.comO1 - Hosts: 211.162.108.123 www.buy-viagra-online-cheap.netO1 - Hosts: 211.162.108.123 www.buyviagraonlineforless.comO1 - Hosts: 211.162.108.123 www.buy-viagra-online-sales.comO1 - Hosts: 211.162.108.123 www.buy-viagra-usa-prescription.comO1 - Hosts: 211.162.108.123 www.buy-viagra-viagara-online.comO1 - Hosts: 211.162.108.123 www.buyviagra-viagra.comO1 - Hosts: 211.162.108.123 www.canadaexpressrx.comO1 - Hosts: 211.162.108.123 www.cheap-viagra-4u.comO1 - Hosts: 211.162.108.123 www.cheap-viagra-pharmacy.comO1 - Hosts: 211.162.108.123 www.click-viagra.comO1 - Hosts: 211.162.108.123 www.cyberpillsnetwork.comO1 - Hosts: 211.162.108.123 www.discount-viagra-cheap.comO1 - Hosts: 211.162.108.123 www.doctorviagra.netO1 - Hosts: 211.162.108.123 www.drugstore.comO1 - Hosts: 211.162.108.123 www.ed-pharmacy.comO1 - Hosts: 211.162.108.123 www.ed-pills.comO1 - Hosts: 211.162.108.123 www.e-order-viagra.comO1 - Hosts: 211.162.108.123 www.epillz.comO1 - Hosts: 211.162.108.123 www.find-viagra.comO1 - Hosts: 211.162.108.123 www.free-viagra-sample.comO1 - Hosts: 211.162.108.123 www.genericviagra.infoO1 - Hosts: 211.162.108.123 www.generic-viagra.wsO1 - Hosts: 211.162.108.123 www.genuine-pfizer-viagra.comO1 - Hosts: 211.162.108.123 www.global-viagra.comO1 - Hosts: 211.162.108.123 www.horizondrugs.comO1 - Hosts: 211.162.108.123 www.howtogetviagra.comO1 - Hosts: 211.162.108.123 www.lmtc.netO1 - Hosts: 211.162.108.123 www.lowpricepills.comO1 - Hosts: 211.162.108.123 www.mailorderviagra.netO1 - Hosts: 211.162.108.123 www.menscripts.comO1 - Hosts: 211.162.108.123 www.mixpills.comO1 - Hosts: 211.162.108.123 www.moodmaniac.comO1 - Hosts: 211.162.108.123 www.myclinics.comO1 - Hosts: 211.162.108.123 www.myviagrasupplier.comO1 - Hosts: 211.162.108.123 www.overnightprescription.comO1 - Hosts: 211.162.108.123 www.pharmaviagra.comO1 - Hosts: 211.162.108.123 www.pillcraze.comO1 - Hosts: 211.162.108.123 www.pilldealfinder.comO1 - Hosts: 211.162.108.123 www.pillrange.comO1 - Hosts: 211.162.108.123 www.pilltip.comO1 - Hosts: 211.162.108.123 www.pillwatch.comO1 - Hosts: 211.162.108.123 www.planetarymed.comO1 - Hosts: 211.162.108.123 www.platinum-rx.comO1 - Hosts: 211.162.108.123 www.romance-tips.comO1 - Hosts: 211.162.108.123 www.shoprxonline.comO1 - Hosts: 211.162.108.123 www.starpills.comO1 - Hosts: 211.162.108.123 www.top-10-viagra-pharmacies-online.comO1 - Hosts: 211.162.108.123 www.top-pharmacy-guide.comO1 - Hosts: 211.162.108.123 www.usapills.netO1 - Hosts: 211.162.108.123 www.viagrabuyonline.netO1 - Hosts: 211.162.108.123 www.viagra-online--now.comO1 - Hosts: 211.162.108.123 www.viagraonlinepharmacy.comO1 - Hosts: 211.162.108.123 www.viagraprice.netO1 - Hosts: 211.162.108.123 www.viagra-price-guide.comO1 - Hosts: 211.162.108.123 www.viagraprices.netO1 - Hosts: 211.162.108.123 www.viagra-qs.comO1 - Hosts: 211.162.108.123 www.viagrastories.comO1 - Hosts: 211.162.108.123 www.v-viagra.comO1 - Hosts: 211.162.108.123 www.1000med.comO1 - Hosts: 211.162.108.123 www.123pill.comO1 - Hosts: 211.162.108.123 www.123prescriptionpills.comO1 - Hosts: 211.162.108.123 www.1soma.comO1 - Hosts: 211.162.108.123 www.24-7online-pharmacy.comO1 - Hosts: 211.162.108.123 www.247-pharmacy.comO1 - Hosts: 211.162.108.123 www.24hourpill.comO1 - Hosts: 211.162.108.123 www.abcweightloss.netO1 - Hosts: 211.162.108.123 www.alfadrugs.comO1 - Hosts: 211.162.108.123 www.alfaus.comO1 - Hosts: 211.162.108.123 www.ashevillelist.comO1 - Hosts: 211.162.108.123 www.bestprescription.comO1 - Hosts: 211.162.108.123 www.buy.affordable-prescriptions.comO1 - Hosts: 211.162.108.123 www.buyambienonline.comO1 - Hosts: 211.162.108.123 www.buy-carisoprodol.comO1 - Hosts: 211.162.108.123 www.buy-drugs-without-prescription.comO1 - Hosts: 211.162.108.123 www.buy-flexeril-00.bizO1 - Hosts: 211.162.108.123 www.buy-flexeril-i-a.bizO2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - C:\WINDOWS\bi.dllO4 - HKLM\..\Run: [belt] C:\WINDOWS\Belt.exeReboot into safe mode and delete Belt.exe from c:\Windows then rerun HJT and post the new resultsyou've been hijacked by A better internet :angry: Link to comment Share on other sites More sharing options...
madboy33 Posted December 6, 2003 Author Report Share Posted December 6, 2003 thanks markwill come back to you on this mate Link to comment Share on other sites More sharing options...
madboy33 Posted December 6, 2003 Author Report Share Posted December 6, 2003 here we go mark2 is that better?Logfile of HijackThis v1.97.7Scan saved at 20:15:24, on 06/12/2003Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Logitech\iTouch\iTouch.exeC:\WINDOWS\System32\sstray.exeC:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exeC:\Program Files\Iomega\AutoDisk\ADUserMon.exeC:\Program Files\Iomega\DriveIcons\ImgIcon.exeC:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exeC:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exeC:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exeC:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exeC:\Program Files\Logitech\MouseWare\system\em_exec.exeC:\WINDOWS\System32\cisvc.exeC:\PROGRA~1\Iomega\System32\AppServices.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exeC:\WINDOWS\system32\ZoneLabs\vsmon.exeC:\Program Files\Iomega\AutoDisk\ADService.exeC:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exeC:\Documents and Settings\Tony Dos Santos\My Documents\hijackthis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blueyonder.co.uk/blueyonder/index.jspR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {8C0DE7AF-38CF-ED1F-7EDD-81BB42DC45EE} - C:\WINDOWS\system32\culakkma.dllO2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dllO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.ExeO4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exeO4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /rO4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exeO4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exeO4 - HKLM\..\Run: [iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exeO4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTARTO4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -kO4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXEO4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXEO8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTMO8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTMO9 - Extra button: ieSpell (HKLM)O9 - Extra 'Tools' menuitem: ieSpell (HKLM)O9 - Extra 'Tools' menuitem: ieSpell Options (HKLM)O9 - Extra button: Messenger (HKLM)O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)O9 - Extra button: Messenger (HKLM)O9 - Extra 'Tools' menuitem: Messenger (HKLM)O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CABO16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...director/sw.cabO16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.trojanscan.com/trojanscan/TDECntrl.CABO16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cabO16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/d2c89f6...all/xscan53.cabO16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...7937.7888194444O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab Link to comment Share on other sites More sharing options...
madboy33 Posted December 6, 2003 Author Report Share Posted December 6, 2003 still got a problemwhen trying to do PC-PITSTOP full test, it gets to the hard disc test, says it is sending data and then for some reason internet explorer page just vanishes Link to comment Share on other sites More sharing options...
mark2 Posted December 6, 2003 Report Share Posted December 6, 2003 One item I can't find any information about (will google)O2 - BHO: (no name) - {8C0DE7AF-38CF-ED1F-7EDD-81BB42DC45EE} - C:\WINDOWS\system32\culakkma.dllbut other than that looks good.some optional fixes if you find things a little slowO4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exeO4 - HKLM\..\Run: [iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exeO4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTARTO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXEO4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.ExeFrom Pacmans StartupsLogitech UtilityLogi_MwX.exeLogitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled Link to comment Share on other sites More sharing options...
mark2 Posted December 6, 2003 Report Share Posted December 6, 2003 when trying to do PC-PITSTOP full test, it gets to the hard disc test, says it is sending data and then for some reason internet explorer page just vanishesThe pit may be the place to post regarding that problem madboy.Unless this O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cabhas become corrupted.Any other probs found ? Link to comment Share on other sites More sharing options...
mark2 Posted December 8, 2003 Report Share Posted December 8, 2003 This has been confirmed as an IEloader hijacker.O2 - BHO: (no name) - {8C0DE7AF-38CF-ED1F-7EDD-81BB42DC45EE} - C:\WINDOWS\system32\culakkma.dll Link to comment Share on other sites More sharing options...
madboy33 Posted December 8, 2003 Author Report Share Posted December 8, 2003 mark2deleted that itemhowever, windows would not start corectly without it and when loaded it took about 3 minutes to loadlooks like i am going to have to reformat and be done with itcould someone close this thread for mei am starting another thread about partitioning Link to comment Share on other sites More sharing options...
Recommended Posts