You have the Xabot virus.
Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. (Not a temporary folder or the desktop & not directly on your hard drive). Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/cus...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [SysInit] wininit32.exe -services
O4 - HKLM\..\Run: [cdupodgr] C:\WINDOWS\cdupodgr.exe
O4 - HKLM\..\RunServices: [SysInit] wininit32.exe -services
O4 - HKCU\..\Run: [SysInit] wininit32.exe -drivers
O4 - HKCU\..\Run: [WINT] C:\WINDOWS\cdupodgr.exe
Reboot into safe mode following the instructions here & navigate to & delete
C:\WINDOWS\cdupodgr.exe< this one
Boot into normal.
P2P networking should be uninstalled.
Go here for an on-line scan & set it to autoclean for you.
Get back with the results plz.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
condorcanqui
Junior Poster in Training
51 posts since Nov 2003
Reputation Points: 10
Solved Threads: 6
you missed this one .
O4 - HKCU\..\Run: [WINT] C:\WINDOWS\System32\wcpsvit.exe>>>> bad
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
Moving to the new Security forum, as this is spyware-related. :)
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
alright for the moving but that doesn't help me.
Perhaps not, but itdoes help us keep all of these spyware/adware/malware posts in one place.
Also- patience is key here, and please remember that we do this on a volunteer basis.
caperjack and crunchie are very helpful and knowledgeable in this area; if the answers they've given you haven't solved your problems yet, don't worry- they'll be back to help soon. :)
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
Have Hijack This fix the following by placing a check in the appropriate boxes and selecting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.
O4 - HKCU\..\Run: [WINT] C:\WINDOWS\System32\wcpsvit.exe
Now reboot into safe mode and delete the following files and folders .
C:\WINDOWS\System32\wcpsvit.exe>> delete file if found
to delete the above files and folder you will need to do the following
go to Show hidden files & folders
"Fix Checked"...Reboot to SAFE mode to delete files
How to start computer in safe mode
reboot computer and post a new log
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
Can you download the following app & run it, making sure to have one internet exploder window open. Save the log & paste the results back here.
VX2Finder
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Download Killbox from http://download.broadbandmedic.com/VbStuff/KillBox.zip
Unzip to your desktop.
Run Killbox.exe. From the menu click “Fix L2M then click “Kill VX2.BetterInternet"
Restart your system
Next, type javascript:navigator.userAgent or just copy and paste it in your IE Address bar then hit enter.
Post the complete result again. (That is, VX2finder log + the IE results)
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Log for VX2.BetterInternet File Finder
Files Found---
C:\WINDOWS\System32\6go4svc.dll
C:\WINDOWS\System32\abd.dll
C:\WINDOWS\System32\afmparse.dll
C:\WINDOWS\System32\agd.dll
C:\WINDOWS\System32\aolui.dll
C:\WINDOWS\System32\aqlui.dll
C:\WINDOWS\System32\asaamon.dll
C:\WINDOWS\System32\Ay3API.DLL
Guardian Key---
User Agent String---
{8539157C-3407-41F9-A686-1B84A0407626}
This is the log after m reboot of VX2 Finder it seems worst!
Run Killbox.exe. From the menu click “Fix L2M then click “Kill VX2.BetterInternet"
Restart your system
Run Killbox.exe again.
From the menu click “Fix L2M then click “Import L2M.reg.
Click OK when you asked to “Import Registry Script?
Then from the menu again, click “Find. Click “User Agent String.
Select the entry {8539157C-3407-41F9-A686-1B84A0407626} then click “Action.
Click “Delete User Agent String. Close Killbox.
Reboot.
Run VX2 finder once more & the IE Javascript search. Post the Log for VX2.Finder and result of javascript:navigator.userAgent.
Also include a fresh hijackthis log plz.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Try this instead. Download the VX2 fix here.
You must run it three times in a row to completely remove the files registry keys.
Then post another VX2 log plz.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985