Problem changing homepage and deleting a virus

intrikate

OSNN One Post Wonder
Joined
Nov 15, 2006
Messages
1
#1
Hi i just want to know if anyone can help me fix my IE6 - it won't let me change my homepage.. everytime i open IE6 it keeps going to this chinese search page "www.my123.com". I think it has something to do with this file i've been trying to delete - mguyyy70.dll. it says that that file is a virus known as "Downloader.Agent.bbc". Anyway here is my hijackthis logfile:

Logfile of HijackThis v1.99.1
Scan saved at 2:54:52 PM, on 15/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\Explorer.EXE
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Ringz Studio\Storm Codec\qttask.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\BricoPacks\Longhorn Inspirat\ObjectDock\ObjectDock.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
D:\My Documents\Loi\files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,Start Page = http://www.my123.com/
R1 - HKLM\Software\Microsoft\Internet Explorer,Start Page = http://www.my123.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my123.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my123.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IExpress - {27E96DE0-8211-42CF-9A1E-FA6246A95B77} - C:\WINDOWS\system32\iexpress.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\Ringz Studio\Storm Codec\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [isDeleteMe] "C:\WINDOWS\system32\cmd.exe" /c "C:\DOCUME~1\MALIBI~1.OIC\LOCALS~1\Temp\isDel.bat"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Longhorn Inspirat\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://cable.optusnet.com.au
O15 - Trusted Zone: http://www.google.com.au
O15 - Trusted Zone: http://www.netbank.com.au
O15 - Trusted Zone: http://www.nettex.com.au
O15 - Trusted Zone: http://www.hotmail.com
O15 - Trusted Zone: http://login.live.com
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} (MMCPlayer Class) - http://p3p.sogou.com/MMCShell.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Unknown owner - C:\Program Files\Norton Internet Security\ccPwdSvc.exe (file missing)
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe




=================================================​

This is my Ewido Anti-Malware [AVG Anti-Spyware 7.5] scan report:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 4:45:44 AM 14/11/2006

+ Scan result:



C:\WINDOWS\system32\iexpress.dll -> Adware.Baidu : No action taken.
C:\WINDOWS\system32\AdCache -> Adware.Cydoor : No action taken.
C:\WINDOWS\system32\AdCache\B_434_0_0_445800.htm -> Adware.Cydoor : No action taken.
C:\WINDOWS\system32\AdCache\B_434_0_0_445900.htm -> Adware.Cydoor : No action taken.
C:\WINDOWS\system32\AdCache\B_434_0_0_446000.htm -> Adware.Cydoor : No action taken.
C:\WINDOWS\system32\AdCache\B_434_1_0_448500.gif -> Adware.Cydoor : No action taken.
C:\WINDOWS\system32\AdCache\B_434_1_0_448600.gif -> Adware.Cydoor : No action taken.
C:\WINDOWS\system32\AdCache\B_434_2_0_814200.htm -> Adware.Cydoor : No action taken.
C:\WINDOWS\system32\AdCache\B_434_2_0_815600.htm -> Adware.Cydoor : No action taken.
C:\WINDOWS\system32\AdCache\B_434_2_0_815900.htm -> Adware.Cydoor : No action taken.
HKLM\SOFTWARE\WinAntiVirus Pro 2006 -> Adware.WinAntiVirus : No action taken.
C:\System Volume Information\_restore{F017CD5D-529D-42AE-B414-0D72CDE41B6D}\RP2\A0000139.exe -> Backdoor.Ifinst : No action taken.
C:\WINDOWS\system32\mguyyy70.dll -> Downloader.Agent.bbc : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4HIBCDIN\popup[1].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4HIBCDIN\popup[2].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4HIBCDIN\popup[3].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4HIBCDIN\popup[4].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4HYFWHYF\popup[1].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4HYFWHYF\popup[2].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4HYFWHYF\popup[3].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4HYFWHYF\popup[4].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\4XERGP67\popup[1].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\OL6RK9IF\popup[1].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\OL6RK9IF\popup[2].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\OL6RK9IF\popup[3].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\OL6RK9IF\popup[4].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\OXLBJMMH\popup[1].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\OXLBJMMH\popup[2].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\SDIJO96Z\popup[1].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Malibiran.OIC\Local Settings\Temporary Internet Files\Content.IE5\SDIJO96Z\popup[2].htm -> Hijacker.Agent.a : No action taken.
C:\WINDOWS\system32\drivers\mguyyy70.sys -> Hijacker.StartPage.amg : No action taken.
C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N68M2301NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : No action taken.
C:\WINDOWS\Downloaded Program Files\UDC6_0001_D19M1908NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.m : No action taken.
C:\WINDOWS\Downloaded Program Files\UERS_9999_N91S2507NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\Documents and Settings\Malibiran.OIC\Cookies\malibiran@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
F:\Documents and Settings\Malibiran\Cookies\malibiran@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
F:\Documents and Settings\Malibiran\Cookies\malibiran@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Malibiran\Cookies\malibiran@adbrite[1].txt -> TrackingCookie.Adbrite : No action taken.
F:\Documents and Settings\Malibiran\Cookies\malibiran@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Malibiran.OIC\Cookies\malibiran@casalemedia[1].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Malibiran.OIC\Cookies\malibiran@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Malibiran\Cookies\malibiran@ehg-globalgamingleague.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Malibiran\Cookies\malibiran@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
F:\Documents and Settings\Malibiran\Cookies\malibiran@yadro[1].txt -> TrackingCookie.Yadro : No action taken.
C:\Documents and Settings\Malibiran.OIC\Cookies\malibiran@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : No action taken.
D:\System Volume Information\_restore{C5BFF694-5781-46CF-93C2-D57DCF1CB1EC}\RP89\A0025826.dll -> Trojan.Zapchast : No action taken.


::Report end



=================================================​

pls help.
 

Members online

No members online now.

Latest posts

Latest profile posts

Perris Calderon wrote on Electronic Punk's profile.
Ep, glad to see you come back and tidy up...did want to ask a one day favor, I want to enhance my resume , was hoping you could make me administrator for a day, if so, take me right off since I won't be here to do anything, and don't know the slightest about the board, but it would be nice putting "served administrator osnn", if can do, THANKS

Been running around Quora lately, luv it there https://tinyurl.com/ycpxl
Electronic Punk wrote on Perris Calderon's profile.
All good still mate?
Hello, is there anybody in there? Just nod if you can hear me ...
Xie
What a long strange trip it's been. =)

Forum statistics

Threads
62,000
Messages
673,427
Members
89,025
Latest member
Haniew