Trying to Clean A computer...Help(HJT LOG included)

  1. #1
    EnochCain is offline Newbie

    Trying to Clean A computer...Help(HJT LOG included)

    Hey First off thanks a ton for helping me out my friend...I am sure it takes a boat load of patience to do what you guys do...WOW! thanks in advance
    Anyway i am trying to fix my parents computer and i know that HJT really works so heres the log...I am clicking off like a million popups as i type this lol.
    Thanks again,

    Chris


    C:\Documents and Settings\June\Application Data\cppo.exe
    C:\WINNT\System32\chknetbs.exe
    C:\WINNT\System32\t?skmgr.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    C:\WINNT\System32\RUNDLL32.exe
    C:\Program Files\Microsoft Money\System\urlmap.exe
    C:\PROGRA~1\WINZIP\wzqkpick.exe
    C:\WINNT\Explorer.exe
    C:\Documents and Settings\June\Local Settings\Temp\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - (no file)
    O2 - BHO: (no name) - {1AE53918-C791-403B-AFF9-34C5CC42DA55} - (no file)
    O2 - BHO: (no name) - {498F3D7A-954A-25B3-D106-62557CF22E65} - C:\WINNT\System32\ortvyi.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
    O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
    O4 - HKLM\..\Run: [o3ng34j] ir5ssvc.exe
    O4 - HKLM\..\RunOnce: [AAW] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Aware.exe" "+b1"
    O4 - HKLM\..\RunOnce: [SideStepDllDelete] cmd.exe /q /c del /f /q "C:\WINNT\DOWNLO~1\SbCIe028.dll" "C:\WINNT\DOWNLO~1\SbCIe028.inf"
    O4 - HKCU\..\Run: [Tbta] C:\Documents and Settings\June\Application Data\cppo.exe
    O4 - HKCU\..\Run: [Z04mRQHmi] chknetbs.exe
    O4 - HKCU\..\Run: [Eqtome] C:\WINNT\System32\t?skmgr.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://download.sidestep.com/get/k42039/sb028.cab
    O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.comp...io5_3_16_0.cab

    *edit* i did clean the computer with CCleaner and Ad aware b/f this log was posted... Also am using Spyblaster... Just thought you might find that helpful...


  2. #2
    owen is offline D-A-L Team Member (UK)
    Save 20% on AVG Internet Security 2012 Suite!
    Could you please post a new log and ensure that you include the entire log.

+ Reply to Thread