Alrighty - got something nasty the other day when my brother was on my machine (I think.) Bought Webroot's Spy Sweeper - good friend owns the company, I got it cheap!! Highly Recommend!!
Anyhew- almost everything cleaned up - EXCEPT the damn recurrings. Hijack log to follow..
/begin transmission
Logfile of HijackThis v1.99.0
Scan saved at 12:06:56 AM, on 2/3/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\cidaemon.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Documents and Settings\Josh.BAHAMUT\Desktop\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.slashdot.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O15 - Trusted Zone: *.addictivetechnologies.com
O15 - Trusted Zone: *.addictivetechnologies.net
O15 - Trusted Zone: *.admin2cash.biz
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.bettersearch.biz
O15 - Trusted Zone: *.c4tdownload.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.f1organizer.com
O15 - Trusted Zone: *.finefind.nettraffic2cash.biz
O15 - Trusted Zone: *.iframe.biz
O15 - Trusted Zone: *.megapornix.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.newiframe.biz
O15 - Trusted Zone: *.overpro.com
O15 - Trusted Zone: *.pizdato.biz
O15 - Trusted Zone: *.private-dialer.biz
O15 - Trusted Zone: *.private-iframe.biz
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.sp2admin.biz
O15 - Trusted Zone: *.sp2****ed.biz
O15 - Trusted Zone: *.vse-moe.biz
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.xxxtoolbar.com
O15 - Trusted Zone: *.ysbweb.com
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
Here are the detected ADS
C:\WINDOWS\KB839645.log : xugoub (11592 bytes)
C:\WINDOWS\KB840987.log : hvytol (7305 bytes)
C:\WINDOWS\Q307869.log : fuemji (9728 bytes)
C:\WINDOWS\Q311967.log : qwqffv (29184 bytes)
C:\WINDOWS\Q329834.log : apxeyf (9728 bytes)
C:\WINDOWS\Q811630.log : spijtp (29184 bytes)
C:\WINDOWS\River Sumida.bmp : nsdhjm (7305 bytes)
C:\WINDOWS\ScUnin.exe : gswnlp (3547 bytes)
C:\WINDOWS\sessmgr.setup.log : ylpsfz (68096 bytes)
C:\WINDOWS\vminst.log : bsmgat (7305 bytes)
C:\WINDOWS\War3Unin.pif : ulfuuv (3547 bytes)
/end transmission
A few notes to help you along...
even if i can get everything else cleaned up,
O15 - Trusted Zone: *.finefind.nettraffic2cash.biz
dosent seem to die. I check, fix, and re scan - still there. No reg entry, so I dont know what to do.
I had a nasty case of isrvs (Desktop search) but it APPEARS to have gone into remission.
jitcfji - this keeps showing up, I can't find anything about it on google. I think I have it gone.
Something i have keeps droping the same 5 shortcuts on my desktop at specific intervals - data eraser, spam blocker, and I know the last one was a credit card offer.
Thx in advance for your help - should you choose to accept this mission, yada yada yada.