need help removing trust cleaner files! please

Discussion in 'Windows - Virus and spyware problems' started by groomjac, Feb 6, 2007.

Thread Status:
Not open for further replies.
  1. groomjac

    groomjac Member

    Joined:
    Feb 6, 2007
    Messages:
    6
    Likes Received:
    0
    Trophy Points:
    11
    hi guys im new to the boards so hello everyone. im at work and when i try to do a google search sometimes this trust cleaner ad pops up and when i search on ebay. any help is apprecciated i included a log file from hijack this thanks.


    Logfile of HijackThis v1.99.1
    Scan saved at 4:13:22 PM, on 2/6/2007
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\PROGRA~1\NavNT\DefWatch.exe
    C:\PROGRA~1\NavNT\rtvscan.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\System32\wm.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\system32\NWTRAY.EXE
    C:\PROGRA~1\NavNT\vptray.exe
    C:\WINNT\Downloaded Program Files\UWAS6_0001_N69M0903NetInstaller.exe
    C:\WINNT\system32\iprntctl.exe
    S:\WinSPC\pub\Autocodedater\AutoCodeDate.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\WINNT\system32\proquota.exe
    C:\Program Files\dqs\WinSPC\WinSPC32.exe
    C:\Documents and Settings\MCDEPOSIT1\Desktop\HijackThis_v1.99.1.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.home.mars/search
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.masterfoodsusa.mars/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://WWW.CLV.NA.MARS
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.masterfoodsusa.mars/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SDS
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: ChangerBHO Class - {0edc6c20-a31c-11db-8ab9-0800200c9a66} - C:\WINNT\system32\COMCATb.dll
    O2 - BHO: ContextualAds Class - {3AAC4C68-AFC8-11DB-80EF-8AF955D89593} - C:\Program Files\TrustIn Contextual\trustincontext.dll (file missing)
    O2 - BHO: Clicker Class - {631f7200-642e-11db-bd13-0800200c9a66} - C:\WINNT\system32\mscoriezb.dll
    O2 - BHO: WeeklyExecuter Class - {f015f320-ab08-11db-abbd-0800200c9a66} - (no file)
    O2 - BHO: SpoofBHO Class - {F67EEB12-AB09-11DB-A6F1-260856D89593} - (no file)
    O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [msmc] C:\WINNT\system32\msmc.exe
    O4 - HKLM\..\Run: [NI.UWAS6_0001_N69M0903] "C:\WINNT\Downloaded Program Files\UWAS6_0001_N69M0903NetInstaller.exe" -nag
    O4 - HKLM\..\Run: [iPrint Tray] C:\WINNT\system32\iprntctl.exe TRAY_ICON
    O4 - Global Startup: Shortcut to AutoCodeDate.lnk = WinSPC\pub\Autocodedater\AutoCodeDate.exe
    O4 - Global Startup: WinZIP Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.home.mars/ie4.asp
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.co...ivex/hcImpl.cab
    O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://clvsn1.clv.na.mars/iNotes6.cab
    O16 - DPF: {4F021AE3-9E98-11D0-A808-00C04FDCD94A} (Novell Directory Control) - http://www.home.mars/ActiveX/nwdir.cab
    O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab
    O16 - DPF: {D27CDB6E-0000-0000-0000-000000000000} - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = CLV.NA.MARS
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = CLV.NA.MARS
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = clv.na.mars,na.mars,mars,sa.mars,eu.mars,ap.mars,cds.mars
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = CLV.NA.MARS
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = clv.na.mars,na.mars,mars,sa.mars,eu.mars,ap.mars,cds.mars
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = clv.na.mars,na.mars,mars,sa.mars,eu.mars,ap.mars,cds.mars
    O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
    O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINNT\system32\cusrvc.exe
    O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\NavNT\DefWatch.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\NavNT\rtvscan.exe
    O23 - Service: OracleOracle_871ClientCache - Unknown owner - (no file)
    O23 - Service: User Profile Hive Cleanup (UPHClean) - Unknown owner - C:\Program Files\UPHClean\uphclean.exe (file missing)
    O23 - Service: Novell Workstation Manager (WM) - Novell, Inc. - C:\WINNT\System32\wm.exe
     
  2. ireland

    ireland Active member

    Joined:
    Nov 28, 2002
    Messages:
    3,451
    Likes Received:
    15
    Trophy Points:
    68
  3. ddp

    ddp Moderator Staff Member

    Joined:
    Oct 15, 2004
    Messages:
    39,169
    Likes Received:
    137
    Trophy Points:
    143
    moved to correct forum
     
Thread Status:
Not open for further replies.

Share This Page