
Signature
Glen Ventura, MS MVP W95/98 Systems
http://dts-l.org/goodpost.htm
Glen- lost my cable connection and lost everything. Ran
Hijackthis and CWShredder. Looked on forum and it didnt
post. Let me know what you think. Also, will send this
to Spywareinfo forum.
I am resending the new logfile from Hijackthis:
Logfile of HijackThis v1.97.3
Scan saved at 11:20:08 AM, on 10/30/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE
EDITION\PSFREE.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\WINZIP81\WINZIP32.EXE
C:\WINDOWS\TEMP\HIJACKTHIS.EXE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search
Bar = +s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window
Title = Microsoft Internet Explorer provided by AT&T
WorldNet Service
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-
784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0
\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {029CA12C-89C1-46a7-A3C7-
82F2F98635CB} - C:\PROGRAM FILES\KONTIKI\BIN\BH304181.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-
00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry]
C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6
\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM
FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -
cnetwait.odl
O4 - Startup: Office Startup.lnk = C:\Program
Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Find Fast.lnk = C:\Program
Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Event Reminder.lnk = C:\pmw\PMREMIND.EXE
O8 - Extra context menu item: Get It With Kontiki -
res://C:\PROGRAM FILES\KONTIKI\BIN\BH304181.DLL/201
O8 - Extra context menu item: &Add animation to
IncrediMail Style Box - C:\PROGRA~1\INCRED~1
\bin\WebMenuImg.htm
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Net2Phone (HKLM)
O9 - Extra 'Tools' menuitem: Net2Phone (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Dictionary (HKLM)
O9 - Extra 'Tools' menuitem: Dictionary (HKLM)
O9 - Extra button: Netnews (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1
\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: C:\Program Files\Internet
Explorer\Plugins\NPUPano.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
(Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swf
lash.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE}
(Microsoft Office Tools on the Web Control) -
http://officeupdate.microsoft.com/TemplateGallery/downloads
/outc.cab
O16 - DPF: {0D6451B3-FDDA-11D3-BFEC-00D0B725EB0B} (Yahoo!
Vision) - http://download.yahoo.com/dl/fv/yv.cab
O16 - DPF: {53A1630A-DB38-4316-B18F-911719E1F66E} (MSN
Money Ticker) -
http://fdl.msn.com/public/investor/v11/ticker.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68}
(InstallShield International Setup Player) -
http://www.installengine.com/engine/isetup.cab
O16 - DPF: {7160FB1B-3DE0-4C42-81F0-41B4269990B0} (MSN
Money Ticker) -
http://fdl.msn.com/public/investor/v12/ticker.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94}
(PCPitstop Utility) -
http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC
Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {78960E0E-0B0C-11D4-8997-00104BD12D94} (AV
Class) - http://www.pcpitstop.com/antivirus/PCPAV.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update
Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CA
B?37898.742025463
O16 - DPF: PlaceWare Console: PWS-CC2K-4-2-0-0-A-m7t8o4 -
http://www27.placeware.com/etc/pwf/test/lib/cc-full.cab
O16 - DPF: {1000026A-8230-4DD4-BE4F-6889D1E74167} -
http://207.246.124.105/cabs/ROOSTTD3001/TPS108.cab
O16 - DPF: {11111111-1111-1111-1111-111111111111} -
http://207.246.124.105/cabs/ROOSTER3001/TPS108.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE}
(Symantec RuFSI Registry Information Class) -
http://security.symantec.com/SSC/SharedContent/common/bin/c
absa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
(Symantec AntiVirus scanner) -
http://security.symantec.com/SSC/SharedContent/vc/bin/AvSni
ff.cab
-----------------end of file
>-----Original Message-----
>Uh-oh! super-spider.com AND MyWebSearch.....not good!
[quoted text clipped - 57 lines]
>> http://super-spider.com/main/sp.php
>> R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search
>> Bar = http://super-spider.com/main/sp.php
>> R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search
>> Page = http://super-spider.com/main/sp.php
>> R1 - HKCU\Software\Microsoft\Internet
[quoted text clipped - 7 lines]
>> Explorer\Search,SearchAssistant = +s
>> R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Window
>> Title = Microsoft Internet Explorer provided by AT&T
>> WorldNet Service
[quoted text clipped - 60 lines]
>> O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
>> (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swf
>> lash.cab
>> O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE}
>> (Microsoft Office Tools on the Web Control) -
http://officeupdate.microsoft.com/TemplateGallery/downloads
>> /outc.cab
>> O16 - DPF: {0D6451B3-FDDA-11D3-BFEC-00D0B725EB0B} (Yahoo!
[quoted text clipped - 17 lines]
>> O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update
>> Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CA
>> B?37898.742025463
>> O16 - DPF: PlaceWare Console: PWS-CC2K-4-2-0-0-A-m7t8o4 -
[quoted text clipped - 5 lines]
>> O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE}
>> (Symantec RuFSI Registry Information Class) -
http://security.symantec.com/SSC/SharedContent/common/bin/c
>> absa.cab
>> O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
>> (Symantec AntiVirus scanner) -
http://security.symantec.com/SSC/SharedContent/vc/bin/AvSni
>> ff.cab
>> O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Fun Web
>> Products Installer Start) -
http://imgfarm.com/images/nocache/funwebproducts/SmileyCent
>> ralInitialSetup1.0.0.5.cab
>>
[quoted text clipped - 164 lines]
>
>.
glee - 31 Oct 2003 05:03 GMT
More spyware....Transponder:
> O16 - DPF: {1000026A-8230-4DD4-BE4F-6889D1E74167} -
> http://207.246.124.105/cabs/ROOSTTD3001/TPS108.cab
> O16 - DPF: {11111111-1111-1111-1111-111111111111} -
> http://207.246.124.105/cabs/ROOSTER3001/TPS108.cab
Read here:
http://www.doxdesk.com/parasite/Transponder.html
and
http://www.cexx.org/vx2.htm
Install Ad-Aware 6 free edition:
http://www.lavasoftusa.com/support/download/
Then start Ad-Aware, click the 'Check for updates' link in the progranm and install updates.
Scan the system with Ad-Aware, and remove what it finds.
Reboot.
Post back with another Hijack This log after the reboot, and report whether the system is operating correctly.

Signature
Glen Ventura, MS MVP W95/98 Systems
http://dts-l.org/goodpost.htm
> Glen- lost my cable connection and lost everything. Ran
> Hijackthis and CWShredder. Looked on forum and it didnt
[quoted text clipped - 527 lines]
> >
> >.