View Single Post
Old 04-14-2004, 02:55 AM   #4 (permalink)
Lobos
Ultra Techie
 
Join Date: Apr 2004
Posts: 617
Default

first put hjt into its own folder and unzip all its contentsinto the folder

C:\Program Files\highjackthis

reason it makes backup


run hjt close put a check next to these . close all browsers and hit fixall browsers




C:\PROGRA~1\free manager\Defy once more.exe

C:\Program Files\SysAI\SysAI.exe



R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mdg.ca
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: (no name) - {4FC95EDD-4796-4966-9049-29649C80111D} - C:\PROGRA~1\INCRED~2\BHO\INCFIN~1.DLL
O2 - BHO: (no name) - {820545D4-1200-31E9-206E-E74401BE5CF2} - C:\PROGRA~1\THUNKG~1\NewCash.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: UploadCdrom - {F825940E-3120-3A0E-9848-8DAEAC05B176} - C:\PROGRA~1\THUNKG~1\NewCash.dll
O4 - HKLM\..\Run: [1f3cb4a51eaac270bd4cab0fd85b737b] C:\Program Files\Internet Explorer\1f3cb4a51eaac270bd4cab0fd85b737b.exe
O4 - HKLM\..\Run: [second funk] C:\PROGRA~1\free manager\Defy once more.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"

O4 - HKCU\..\Run: [Instant Access] rundll32.exe EGCOMLIB_1034.dll,InstantAccess
O4 - Startup: BJ Status Monitor Canon i470D.lnk = C:\Documents and Settings\Jeff\cnmss Canon i470D (Local).exe

O16 - DPF: {093F9CF8-0DE1-491C-95D5-5EC257BD4CA3} - http://akamai.downloadv3.com/binari...dtc32_EN_XP.cab
O16 - DPF: {0D4312E2-5E4D-4A27-A9D8-043E43904277} - http://www.warezoracle.com/xdownloader.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocach...etup1.0.0.8.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://64.124.45.181/downloads/ccpm_0237.cab
O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} - http://download.rfwnad.com/cab/download.CAB

reboot into safe mode and delete

C:\PROGRA~1\free manager\Defy once more.exe
C:\Program Files\SysAI\SysAI.exe

then comback and post a fresh log please
__________________
AdAware | Spybot S&D 1.4 | spyware guard & spyware blaster |

How did I get infected in the first place By Tony Klein

If you use IE I suggest using thes two programs IE Hosts & IE-SPYAD


Lobos is offline   Reply With Quote