[Moderator's note: this post has been split from this previous thread]


hey,i've already read the other postas form this errors,and done the proceders that MDr said.
there ir the log,hoping for a reply
chears :D

Logfile of HijackThis v1.99.1
Scan saved at 21:46:39, on 27-05-2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAMAS\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAMAS\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAMAS\FICHEIROS COMUNS\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\MY DOCUMENTS\HIJACKTHIS.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.specialgoods.info/ad/ad0415/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\system32\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
R3 - Default URLSearchHook is missing
O2 - BHO: DownloadRedirect Class - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - C:\PROGRAMAS\IMESH\IMESH5\IMESHBHO.DLL
O2 - BHO: (no name) - {8A5F6488-6D79-44CF-BDD6-CAA77E44A620} - (no file)
O2 - BHO: (no name) - {C79D197D-F6EC-BF69-9D5F-DAC81E8A789A} - (no file)
O2 - BHO: (no name) - {E7506B66-F19E-4EED-82EF-DA4EF9AF92FF} - C:\WINDOWS\SYSTEM\CMF.DLL (file missing)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Symantec Core LC] C:\Programas\Ficheiros comuns\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programas\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Programas\Webroot\Spy Sweeper\SPYSWEEPER.EXE" /0
O4 - Startup: Spy Sweeper Fix.pif = C:\PROGRA~1\WEBROOT\SPYSWE~1\SPYSWE~1.BAT
O9 - Extra button: Microsoft AntiSpyware helper - {8742F5BA-7D50-4985-AA06-E949DF1CBFF2} - (no file)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {8742F5BA-7D50-4985-AA06-E949DF1CBFF2} - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Microsoft AntiSpyware helper - {2A42603A-808F-4FA8-BCEC-7C5CF24B745B} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {2A42603A-808F-4FA8-BCEC-7C5CF24B745B} - (no file) (HKCU)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4463/mcfscan.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by15fd.bay15.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {697E51CB-6BBF-492E-8580-C204AFD30976} (isInstallCAB.ucInstallCab) - http://www.barrita.com/ISINSTALLCAB.CAB

Hi maynd,

Judging fom your log, it looks like the work you've already done may have cleaned up most of the problems. The log isn't entirely clean yet though, so...


1. Run HijackThis again and have it fix:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.specialgoods.info/ad/ad0415/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\system32\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
R3 - Default URLSearchHook is missing
O2 - BHO: DownloadRedirect Class - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - C:\PROGRAMAS\IMESH\IMESH5\IMESHBHO.DLL
O2 - BHO: (no name) - {8A5F6488-6D79-44CF-BDD6-CAA77E44A620} - (no file)
O2 - BHO: (no name) - {C79D197D-F6EC-BF69-9D5F-DAC81E8A789A} - (no file)
O2 - BHO: (no name) - {E7506B66-F19E-4EED-82EF-DA4EF9AF92FF} - C:\WINDOWS\SYSTEM\CMF.DLL (file missing)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O9 - Extra button: Microsoft AntiSpyware helper - {8742F5BA-7D50-4985-AA06-E949DF1CBFF2} - (no file)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {8742F5BA-7D50-4985-AA06-E949DF1CBFF2} - (no file)
O9 - Extra button: Microsoft AntiSpyware helper - {2A42603A-808F-4FA8-BCEC-7C5CF24B745B} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {2A42603A-808F-4FA8-BCEC-7C5CF24B745B} - (no file) (HKCU)


After doing the above fixes:

- Reboot into safe mode (you get to the safe mode boot option by hitting the F8 key as your computer is starting up)

- Open Windows Explorer, and:

- Locate and delete the following file:
c:\windows\system32\blank.htm

- Locate and delete the following folder entirely:
C:\PROGRAMAS\IMESH

- Empty your Recycle Bin and reboot normally.


3. Run HijackThis again and post a fresh log. Also give us details of any symptoms you may still be experiencing.

Hi Maynd, welcome to DaniWeb :D

If you haven't done so already, follow these instructions as well (be sure your system is set to show Hidden files and folders first) --

Get the Pocket Killbox from here:
http://bleepingcomputer.com/files/spyware/KillBox.zip

Unzip the file to your desktop.

Go offline until this is completed (you may wish to print these instructions).

Boot into Safe Mode and do a search for these files and delete any instances found:

param32.dll
guninst.exe
popup_bl.dll
systr.dll
svrhost.exe

If any could not be deleted, (most likely param32.dll), run Pocket Killbox and paste the full file path of file in the box and click on Delete on Reboot. Click on the button with the red circle and an X in the middle; you will get a message saying File will be deleted on next reboot, Process and Reboot now?, Click Yes to reboot (normally). Note: the 'file path' will be something like C:\WINDOWS\System32\param32.dll

After you reboot, delete any icons from your desktop that you did not put there yourself and empty your recycle bin.

tks very much,my problem is solved thaks to you
you guys rock
:D

Glad we could help, but could you post a new log to make sure everything is as it should be?

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.