0

hey...my i have 2 hard drives right now just so i had something in case something happens...like right now for example. my main hard drive...which has everything i actually need on it is infected with something. windows says its spyware or adware, but it wont let me install programs...it will just shut off. it used to not boot up at all. now it DOES boot up but i dont have a desktop background anymore. alot of times i cant click icons on it either, and its going extremely slow. i used lavasoft's ad-aware professional AND spy sweeper about 18 times now and ive deleted EVERYTHING that has come up (adware, trojan downloaders) but more just keeps coming, and now my windows says something is missing from it. i wanted to try and repair windows....but after i select which OS i want to fix it asks for the administrator password...i dont have one, so i just press enter...then it says something like E:\windows (my hard drive is on E, not C) and it doesnt go any further...it wants me to type something...im just really confused right now....here is my hijack this log file.


Logfile of HijackThis v1.99.1
Scan saved at 12:46:54 PM, on 4/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
E:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
E:\Program Files\M-Audio\Fast Track USB\MAUSBFTInst.exe
E:\WINDOWS\SVCHOST.EXE
E:\WINDOWS\Explorer.EXE
E:\Program Files\PowerISO\PWRISOVM.EXE
E:\WINDOWS\system32\ctfmon.exe
E:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
E:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
E:\Program Files\Real\RealPlayer\RealPlay.exe
E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
E:\windows\system32\uvnx.exe
E:\WINDOWS\updater.exe
E:\WINDOWS\ms054841610871.exe
E:\WINDOWS\ms041484161087.exe
E:\WINDOWS\system32\spoolsvv.exe
E:\Program Files\America Online 9.0d\waol.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Ipwindows\ipwins.exe
E:\Program Files\11g USB adapter\Wifiusb.exe
E:\WINDOWS\system32\wuauclt.exe
E:\Program Files\America Online 9.0d\shellmon.exe
E:\WINDOWS\system32\wuauclt.exe
e:\program files\internet explorer\iexplore.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Documents and Settings\Gilbert\Desktop\HijackThis.exe
R3 - Default URLSearchHook is missing
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - E:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - E:\WINDOWS\cfg32s.dll (file missing)
O4 - HKLM\..\Run: [PWRISOVM.EXE] E:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [HostManager] E:\Program Files\Common Files\AOL\1170194214\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] E:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "E:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] E:\WINDOWS\System32\M-AudioTaskBarIcon.exe
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Lexmark_X79-55] E:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [RealTray] E:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [GrooveMonitor] "E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [DeluxeCommunications] E:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [uvnx] e:\windows\system32\uvnx.exe
O4 - HKLM\..\Run: [runner1] E:\WINDOWS\updater.exe 61A847B5BBF72810329B385576F901F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKLM\..\Run: [{C9-91-18-80-ZN}] e:\windows\system32\vdsreg.exe SKY001
O4 - HKLM\..\Run: [Configuration Manager] E:\WINDOWS\cfg32.exe
O4 - HKLM\..\Run: [ms054841610871] E:\WINDOWS\ms054841610871.exe
O4 - HKLM\..\Run: [ms041484161087] E:\WINDOWS\ms041484161087.exe
O4 - HKLM\..\Run: [SoundService] rundll32.exe "E:\WINDOWS\system32\__c00DC98A.dat",setvm
O4 - HKLM\..\Run: [System] E:\WINDOWS\system32\kernels32.exe
O4 - HKLM\..\Run: [WindowsHive] E:\WINDOWS\system32\rpcc.exe
O4 - HKLM\..\Run: [spoolsvv] E:\WINDOWS\system32\spoolsvv.exe
O4 - HKCU\..\Run: [Elus] "E:\PROGRA~1\COMMON~1\SCURIT~1\nopdb.exe" -vt yazb
O4 - HKCU\..\Run: [Gbf] "E:\Program Files\Common Files\W?nSxS\w?nword.exe" 99001275
O4 - HKCU\..\Run: [DAEMON Tools] "E:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [MySpaceIM] E:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [MsnMsgr] "E:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AOL Fast Start] "E:\Program Files\America Online 9.0d\AOL.EXE" -b
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WebBuying] E:\Program Files\Web Buying\v1.6.8\webbuying.exe
O4 - HKCU\..\Run: [DeluxeCommunications] E:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [A00F23328F.exe] E:\DOCUME~1\Gilbert\LOCALS~1\Temp\_A00F23328F.exe
O4 - HKCU\..\Run: [A00F244854.exe] E:\DOCUME~1\Gilbert\LOCALS~1\Temp\_A00F244854.exe
O4 - HKCU\..\Run: [A00F247FCF.exe] E:\DOCUME~1\Gilbert\LOCALS~1\Temp\_A00F247FCF.exe
O4 - HKCU\..\Run: [A00F250F1F.exe] E:\DOCUME~1\Gilbert\LOCALS~1\Temp\_A00F250F1F.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [IpWins] E:\Program Files\Ipwindows\ipwins.exe
O4 - Global Startup: 802.11g USB adapter.lnk = E:\Program Files\11g USB adapter\Wifiusb.exe
O8 - Extra context menu item: &AOL Toolbar search - res://E:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - E:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - E:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - E:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - E:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: e:\windows\system32\thqwamausyw.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\thqwamausyw.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\thqwamausyw.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\thqwamausyw.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\thqwamausyw.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\thqwamausyw.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\thqwamausyw.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\thqwamausyw.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\thqwamausyw.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\thqwamausyw.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{440A0F21-ABB4-4701-B9EA-24FA14D02710}: NameServer = 63.226.12.96
O17 - HKLM\System\CCS\Services\Tcpip\..\{9A4716F9-F9A8-4F73-B82C-6158ACCBF285}: NameServer = 63.226.12.96
O17 - HKLM\System\CS1\Services\Tcpip\..\{440A0F21-ABB4-4701-B9EA-24FA14D02710}: NameServer = 63.226.12.96
O17 - HKLM\System\CS2\Services\Tcpip\..\{440A0F21-ABB4-4701-B9EA-24FA14D02710}: NameServer = 63.226.12.96
O17 - HKLM\System\CS3\Services\Tcpip\..\{440A0F21-ABB4-4701-B9EA-24FA14D02710}: NameServer = 63.226.12.96
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - E:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - E:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - E:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - E:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: dxclib303562752.dll
O21 - SSODL: OtpeegYpOn - {40CC9181-EA66-3B2B-CB88-5DD269FC4B92} - E:\WINDOWS\system32\leh.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - E:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - E:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: M-Audio Fast Track Installer (FastTrackInstallerService) - Avid Technology, Inc. - E:\Program Files\M-Audio\Fast Track USB\MAUSBFTInst.exe
O23 - Service: General Socket Service - Unknown owner - E:\WINDOWS\SVCHOST.EXE

2
Contributors
1
Reply
2
Views
10 Years
Discussion Span
Last Post by gerbil
0

Wow.... a great collection of malware. Are you serious that Adaware did not remove some of this??? Ri-ight...
Don't try a Repair with all this bad gear, you will face certain disappointment. In fact, a reinstall is called for.... but it is fixable without that if you wish to try - I look on it as an exercise for me... A reinstall will destroy any files you have in the same folder as the OS.

This topic has been dead for over six months. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.