Archived from groups: microsoft.public.windowsxp.help_and_support (
More info?)
Bullguard is installed by P2P software right along with spyware. You should
remove it and use Zone Alarm for your firewall and Avast for your Antivirus
http://www.avast.com . Letting hjt fix the files below will disable it not
uninstall it. It's your choice, I don't trust it. Use add/remove programs to
uninstall it. ZA is all you need. The BHO listed below is a remnant of the
CWS Coolwebsearch malware at it should be removed/fixed by HJT. The same for
R3.
R3 - Default URLSearchHook is missing
O2 - BHO: Local Spool Net support DLL -
{4E7BD750-2C8E-469B-C1E2-F063C081BF33} - c:\windows\system32\localsplnet.dll
O4 - HKCU\..\Run: [BullGuard] "C:\Program Files\BullGuard
Software\BullGuard\BullGuard.exe"
O23 - Service: BullGuard LiveUpdate Service (BGLiveSvc) - BullGuard, Ltd. -
C:\Program Files\BullGuard Software\BullGuard\BgUpdSvc.exe
--
The best live web video on the internet
http://www.seedsv.com/webdemo.htm
NEW Embedded system W/Linux. We now sell DVR cards.
See it all at
http://www.seedsv.com/products.htm
Sharpvision simply the best
http://www.seedsv.com
"Boat Dr" <BoatDr@discussions.microsoft.com> wrote in message
news:6135287D-6916-4A04-BD6F-6F9E1095CECA@microsoft.com...
>
>
> "pcbutts1" wrote:
>
>> Download, install, update and run all of the following.
>>
>> Ad-Aware
>>
http://www.pcbutts1.com/downloads/aawsepersonal.exe
>>
>> Spybot search and destroy
>>
http://www.pcbutts1.com/downloads/spybotsd14.exe
>>
>> Ewido Security Suite Trial version
>>
http://www.pcbutts1.com/downloads/ewidosetup.exe
>>
>> Microsoft Windows AntiSpyware (Beta1)
>>
http://www.microsoft.com/downloads/details.aspx?FamilyId=321CD7A2-6A57-4C57-A8BD-DBF62EDA9671&displaylang=en
>>
>> If none of the above fixes the issue then download Hijack this, run it,
>> save
>> a copy of the log file and cut and paste it back here to this group so
>> that
>> I can analyze it. Ignore anyone who tells you to post it elsewhere. I
>> need
>> to see it not them.
>>
>>
>> HijackThis
>>
http://www.pcbutts1.com/downloads/HijackThis.zip
>
> What does this logfile tell you, Please?
>
> Logfile of HijackThis v1.99.1
> Scan saved at 3:42:33 PM, on 8/31/2005
> Platform: Windows XP SP2 (WinNT 5.01.2600)
> MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
>
> Running processes:
> C:\WINDOWS\System32\smss.exe
> C:\WINDOWS\system32\winlogon.exe
> C:\WINDOWS\system32\services.exe
> C:\WINDOWS\system32\lsass.exe
> C:\WINDOWS\system32\svchost.exe
> C:\WINDOWS\System32\svchost.exe
> C:\WINDOWS\system32\spoolsv.exe
> C:\Program Files\BullGuard Software\BullGuard\BgUpdSvc.exe
> C:\WINDOWS\System32\svchost.exe
> C:\WINDOWS\System32\svchost.exe
> C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
> C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
> C:\WINDOWS\System32\svchost.exe
> C:\WINDOWS\Explorer.EXE
> C:\Program Files\Startup Mechanic\StartupMonitor.exe
> C:\Program Files\Acesoft\Tracks Eraser Pro\te.exe
> C:\Program Files\BullGuard Software\BullGuard\BullGuard.exe
> C:\Program Files\AT&T Worldnet Accelerator\PropelAC.exe
> C:\Program Files\Hewlett-Packard\HP OfficeJet T Series\Bin\HPOstr05.exe
> C:\PROGRA~1\Webshots\webshots.scr
> C:\WINDOWS\system32\rundll32.exe
> C:\Program Files\Hewlett-Packard\HP OfficeJet T Series\bin\HPOVDX05.EXE
> C:\WINDOWS\system32\hpoipm07.exe
> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10MT2.EXE
> C:\Program Files\AT&T\WnClient\Programs\WNConnect.exe
> C:\PROGRA~1\AT&T\WnClient\Programs\WNCSMS~1.EXE
> C:\Program Files\Internet Explorer\iexplore.exe
> C:\WINDOWS\system32\wuauclt.exe
> C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\IEExec.exe
> C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\IEExec.exe
> C:\WINDOWS\system32\taskmgr.exe
> C:\HJT\hijackthis.exe
>
> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
>
http://www.att.net
> R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title =
> Microsoft
> Internet Explorer provided by AT&T Worldnet Service
> R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
> Settings,ProxyServer = http=localhost:8080
> R3 - Default URLSearchHook is missing
> O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
> C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
> O2 - BHO: Local Spool Net support DLL -
> {4E7BD750-2C8E-469B-C1E2-F063C081BF33} -
> c:\windows\system32\localsplnet.dll
> O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
> C:\PROGRA~1\SPYBOT~1\SDHelper.dll
> O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program
> Files\MSN
> Apps\ST\01.03.0000.1005\en-xu\stmain.dll
> O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} -
> C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
> O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program
> Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
> O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} -
> C:\Program Files\ICQToolbar\toolbaru.dll
> O4 - HKLM\..\Run: [Startup Manager Scanner] C:\Program Files\Startup
> Mechanic\StartupMonitor.exe
> O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\AT&T Worldnet
> Accelerator\trayctl.exe" /STARTUPLAUNCH
> O4 - HKCU\..\Run: [Tracks Eraser Pro] C:\Program Files\Acesoft\Tracks
> Eraser
> Pro\te.exe min
> O4 - HKCU\..\Run: [BullGuard] "C:\Program Files\BullGuard
> Software\BullGuard\BullGuard.exe"
> O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
> O4 - Startup: Swebexec.lnk = F:\Program Files\Webshots\Swebexec.exe
> O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
> O4 - Global Startup: HP OfficeJet T Series Startup.lnk = C:\Program
> Files\Hewlett-Packard\HP OfficeJet T Series\Bin\HPOstr05.exe
> O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
> Office\Office10\OSA.EXE
> O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program
> Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
> O8 - Extra context menu item: E&xport to Microsoft Excel -
> res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
> O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program
> Files\AT&T Worldnet Accelerator\pac-page.html
> O8 - Extra context menu item: Refresh Pi&cture with Full Quality -
> C:\Program Files\AT&T Worldnet Accelerator\pac-image.html
> O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
> C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
> O9 - Extra 'Tools' menuitem: Sun Java Console -
> {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
> Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
> O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} -
> C:\Program Files\ICQ\ICQ.exe
> O9 - Extra 'Tools' menuitem: ICQ -
> {6224f700-cba3-4071-b251-47cb894244cd} -
> C:\Program Files\ICQ\ICQ.exe
> O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} -
> C:\Program Files\ICQLite\ICQLite.exe
> O9 - Extra 'Tools' menuitem: ICQ Lite -
> {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program
> Files\ICQLite\ICQLite.exe
> O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 -
> {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
> Files\Messenger\msmsgs.exe
> O9 - Extra 'Tools' menuitem: @C:\Program
> Files\Messenger\Msgslang.dll,-61144
> - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
> Files\Messenger\msmsgs.exe
> O12 - Plugin for .mid: C:\Program Files\Internet
> Explorer\PLUGINS\npqtplugin.dll
> O12 - Plugin for .spop: C:\Program Files\Internet
> Explorer\Plugins\NPDocBox.dll
> O12 - Plugin for .tif: C:\Program Files\Internet
> Explorer\PLUGINS\npqtplugin3.dll
> O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload
> Tool) -
>
http://www.msnusers.com/controls/PhotoUC/MsnPUpld.cab
> O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
>
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1125322866162
> O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) -
>
http://www.gamespot.com/KDX/download/kdx.cab
> O17 -
> HKLM\System\CCS\Services\Tcpip\..\{904177BF-5785-4D59-886D-BC3912283139}:
> NameServer = 12.102.244.1 204.127.129.3
> O23 - Service: AutoComplete Service (Autocomplete) - Acesoft - C:\Program
> Files\Acesoft\Tracks Eraser Pro\autocomp.exe
> O23 - Service: BullGuard LiveUpdate Service (BGLiveSvc) - BullGuard,
> Ltd. -
> C:\Program Files\BullGuard Software\BullGuard\BgUpdSvc.exe
> O23 - Service: EpsonBidirectionalAgent - SEIKO EPSON CORPORATION -
> C:\Program Files\Common Files\EPSON\EBAPI\eEBAgent.exe
> O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program
> Files\Common Files\EPSON\EBAPI\eEBSVC.exe
> O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO
> EPSON
> CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
> O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. -
> C:\WINDOWS\system32\ZoneLabs\vsmon.exe
>
>