Jump to content


680180.net & Others

  • Please log in to reply
1 reply to this topic

#1 rpmrmp



  • New Member
  • Pip
  • 1 posts

Posted 29 July 2004 - 10:49 AM

Hello everybody.
I really, really need help, as i'm getting desperate with this one.
For the last couple of days, popups to the 680180.net site are appearing in my computer. I have tried everything i saw in this and other forums (Search & Destroy, Ad-Aware, Windows critical updates, etc). When i think i got it solved... they come back again. Worst : now i also get popups from http://adlogix.com/z...go/without.html and 'Transfer files' of SHDOCVW.dll from a source i can't identify (wich i refuse to download, of course). So, i'm letting you my Hijackthis log, to see if anyone can find anything i should do to solve this. Thank you in advance for any feedback :

Logfile of HijackThis v1.98.0
Scan saved at 16:43:33, on 29-07-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
d:\Programas\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\Programas\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
D:\Programas\McAfee\McAfee VirusScan\alogserv.exe
D:\Programas\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\Programas\Analog Devices\SoundMAX\SMTray.exe
C:\Programas\MSN Messenger\MsnMsgr.Exe
d:\Programas\McAfee\McAfee VirusScan\VsStat.exe
d:\Programas\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Programas\Ficheiros comuns\Network Associates\McShield\Mcshield.exe
d:\Programas\McAfee\McAfee VirusScan\Avconsol.exe
d:\Programas\McAfee\McAfee VirusScan\Webscanx.exe
C:\Documents and Settings\Rui\Ambiente de trabalho\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programas\Adobe\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SDWin32 Class - {0C55191B-5C9B-4671-9999-A6F74306ADBA} - C:\WINDOWS\System32\frjhs.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - d:\Programas\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Alogserv] d:\Programas\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programas\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programas\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Programas\Ficheiros comuns\Nokia\NCLTools\NclTray.exe
O4 - HKLM\..\Run: [DataLayer] D:\Programas\Nokia\Nokia PC Suite 5\DataLayer.exe
O4 - HKLM\..\Run: [Ad-watch] "D:\Programas\Lavasoft\Ad-aware 6\Ad-watch.exe"
O4 - HKLM\..\Run: [Smapp] C:\Programas\Analog Devices\SoundMAX\SMTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programas\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Microsoft Office.lnk = D:\Programas\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Download with GetRight - D:\Programas\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - D:\Programas\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\MSMSGS.EXE
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups...plorer1_8us.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab28578.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.co...wnload/cult.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://geo.sapo.pt/i...gi/mgaxctrl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab28578.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...381/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = saudexxi.local
O17 - HKLM\Software\..\Telephony: DomainName = saudexxi.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{B7F5452E-3656-4F8F-88AF-5CA0D4E0B57F}: NameServer =,
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = saudexxi.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = saudexxi.local

#2 grinler



  • Expert
  • PipPipPipPipPip
  • 530 posts

Posted 29 July 2004 - 12:41 PM

Fix this entry with hijackthis:

O2 - BHO: SDWin32 Class - {0C55191B-5C9B-4671-9999-A6F74306ADBA} - C:\WINDOWS\System32\frjhs.dll

Reboot and post a new log. Also tell me if the popups are gone

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of

Support SpywareInfo Forum - click the button
PayPal - The safer, easier way to pay online!