Problem changing homepage and deleting a virus

  • Thread starter intrikate
  • https://www.osnn.net/admin.php?templates/thread_view.1970/delete&_xfRedirect=https%3A%2F%2Fwww.osnn.net%2Fadmin.php%3Ftemplates%2Foutdated Start date

intrikate

OSNN One Post Wonder
Joined
15 Nov 2006
Messages
1
Hi i just want to know if anyone can help me fix my IE6 - it won't let me change my homepage.. everytime i open IE6 it keeps going to this chinese search page "www.my123.com". I think it has something to do with this file i've been trying to delete - mguyyy70.dll. it says that that file is a virus known as "Downloader.Agent.bbc". Anyway here is my hijackthis logfile:

Logfile of HijackThis v1.99.1
Scan saved at 2:54:52 PM, on 15/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\Explorer.EXE
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Ringz Studio\Storm Codec\qttask.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\BricoPacks\Longhorn Inspirat\ObjectDock\ObjectDock.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
D:\My Documents\Loi\files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,Start Page = http://www.my123.com/
R1 - HKLM\Software\Microsoft\Internet Explorer,Start Page = http://www.my123.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my123.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my123.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IExpress - {27E96DE0-8211-42CF-9A1E-FA6246A95B77} - C:\WINDOWS\system32\iexpress.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\Ringz Studio\Storm Codec\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [isDeleteMe] "C:\WINDOWS\system32\cmd.exe" /c "C:\DOCUME~1\MALIBI~1.OIC\LOCALS~1\Temp\isDel.bat"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Longhorn Inspirat\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://cable.optusnet.com.au
O15 - Trusted Zone: http://www.google.com.au
O15 - Trusted Zone: http://www.netbank.com.au
O15 - Trusted Zone: http://www.nettex.com.au
O15 - Trusted Zone: http://www.hotmail.com
O15 - Trusted Zone: http://login.live.com
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} (MMCPlayer Class) - http://p3p.sogou.com/MMCShell.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Unknown owner - C:\Program Files\Norton Internet Security\ccPwdSvc.exe (file missing)
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe




=================================================​

This is my Ewido Anti-Malware [AVG Anti-Spyware 7.5] scan report:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 4:45:44 AM 14/11/2006

+ Scan result:



C:\WINDOWS\system32\iexpress.dll -> Adware.Baidu : No action taken.
C:\WINDOWS\system32\AdCache -> Adware.Cydoor : No action taken.
C:\WINDOWS\system32\AdCache\B_434_0_0_445800.htm -> Adware.Cydoor : No action taken.
C:\WINDOWS\system32\AdCache\B_434_0_0_445900.htm -> Adware.Cydoor : No action taken.
C:\WINDOWS\system32\AdCache\B_434_0_0_446000.htm -> Adware.Cydoor : No action taken.
C:\WINDOWS\system32\AdCache\B_434_1_0_448500.gif -> Adware.Cydoor : No action taken.
C:\WINDOWS\system32\AdCache\B_434_1_0_448600.gif -> Adware.Cydoor : No action taken.
C:\WINDOWS\system32\AdCache\B_434_2_0_814200.htm -> Adware.Cydoor : No action taken.
C:\WINDOWS\system32\AdCache\B_434_2_0_815600.htm -> Adware.Cydoor : No action taken.
C:\WINDOWS\system32\AdCache\B_434_2_0_815900.htm -> Adware.Cydoor : No action taken.
HKLM\SOFTWARE\WinAntiVirus Pro 2006 -> Adware.WinAntiVirus : No action taken.
C:\System Volume Information\_restore{F017CD5D-529D-42AE-B414-0D72CDE41B6D}\RP2\A0000139.exe -> Backdoor.Ifinst : No action taken.
C:\WINDOWS\system32\mguyyy70.dll -> Downloader.Agent.bbc : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4HIBCDIN\popup[1].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4HIBCDIN\popup[2].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4HIBCDIN\popup[3].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4HIBCDIN\popup[4].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4HYFWHYF\popup[1].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4HYFWHYF\popup[2].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4HYFWHYF\popup[3].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4HYFWHYF\popup[4].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4XERGP67\popup[1].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\OL6RK9IF\popup[1].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\OL6RK9IF\popup[2].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\OL6RK9IF\popup[3].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\OL6RK9IF\popup[4].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\OXLBJMMH\popup[1].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\OXLBJMMH\popup[2].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\SDIJO96Z\popup[1].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\SDIJO96Z\popup[2].htm -> Hijacker.Agent.a : No action taken.
C:\WINDOWS\system32\drivers\mguyyy70.sys -> Hijacker.StartPage.amg : No action taken.
C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N68M2301NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : No action taken.
C:\WINDOWS\Downloaded Program Files\UDC6_0001_D19M1908NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.m : No action taken.
C:\WINDOWS\Downloaded Program Files\UERS_9999_N91S2507NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\Documents and Settings\Malibiran.OIC\Cookies\malibiran@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
F:\Documents and Settings\Malibiran\Cookies\malibiran@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
F:\Documents and Settings\Malibiran\Cookies\malibiran@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Malibiran\Cookies\malibiran@adbrite[1].txt -> TrackingCookie.Adbrite : No action taken.
F:\Documents and Settings\Malibiran\Cookies\malibiran@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Malibiran.OIC\Cookies\malibiran@casalemedia[1].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Malibiran.OIC\Cookies\malibiran@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Malibiran\Cookies\malibiran@ehg-globalgamingleague.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Malibiran\Cookies\malibiran@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
F:\Documents and Settings\Malibiran\Cookies\malibiran@yadro[1].txt -> TrackingCookie.Yadro : No action taken.
C:\Documents and Settings\Malibiran.OIC\Cookies\malibiran@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : No action taken.
D:\System Volume Information\_restore{C5BFF694-5781-46CF-93C2-D57DCF1CB1EC}\RP89\A0025826.dll -> Trojan.Zapchast : No action taken.


::Report end



=================================================​

pls help.
 

Members online

No members online now.

Latest forum posts

Latest profile posts

Xie wrote on Electronic Punk's profile.
Impressed you have kept this alive this long EP! So many sites have come and gone. :(

Just did some crude math and I apparently joined almost 18yrs ago, how is that possible???
hello peeps... is been some time since i last came here.
Electronic Punk wrote on Sazar's profile.
Rest in peace my friend, been trying to find you and finally did in the worst way imaginable.
Terrahertz wrote on Electronic Punk's profile.
Yo fellas!
Electronic Punk wrote on Sazar's profile.
Where are you buddy?

Forum statistics

Threads
62,000
Messages
673,429
Members
5,596
Latest member
Joshua Liansky