peterofware Posted October 26, 2004 Posted October 26, 2004 Hi, over the last few days i have been plagued by a series of programs trying to access the internet - stopped by ZoneAlarm. This is happening usually when I open Internet explorer. The programs appear to be random although lately they all seem to be Z5bf08.I have also noticed a series of ".LGC" files in APPLOG and within the the IE PLUGINS folder there is a series of ddl files starting with npqtplugin.dll, then nq...2.dll through to ..7.dll. I assume because all seem to have happened on 21st Oct and these are dated same then this is relevent.Can anyone advise as to how to get rid of this, can I just delete these files? I have tried using Spybot and ran a Norton AV scan (which is kept up to date) to no avail. Ideas please.Cheers, Peter
TomcaT Posted October 26, 2004 Posted October 26, 2004 It does sound like spyware....... get spybot and adware and also download Hi-jack this, run it and post your log up on here and will try and say which ones to delete.
Schadenfroh Posted October 28, 2004 Posted October 28, 2004 take a look at my Spyware Removal Guidei dont believe that npqtplugin.dll is malicious, but i will have to read up a little more
FuneralofShadows Posted November 13, 2004 Posted November 13, 2004 ok, i have the same issue, umm, as for adware, it keeps freezing in the middle of a scan, so the logfile for that is out of the question, spybot, i scanned and deleted everything, but as for hijack this, this is my log file:Logfile of HijackThis v1.98.2Scan saved at 3:10:58 PM, on 11/13/2004Platform: Windows ME (Win9x 4.90.3000)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\SYSTEM\KERNEL32.DLLC:\WINDOWS\SYSTEM\MSGSRV32.EXEC:\WINDOWS\SYSTEM\MPREXE.EXEC:\WINDOWS\SYSTEM\MSTASK.EXEC:\WINDOWS\SYSTEM\STIMON.EXEC:\PROGRAM FILES\MESSENGER PLUS! 3\MSGPLUS.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXEC:\PROGRAM FILES\NORTON ANTIVIRUS\IWP\NPFMNTOR.EXEC:\WINDOWS\SYSTEM\mmtask.tskC:\WINDOWS\SYSTEM\RESTORE\STMGR.EXEC:\WINDOWS\EXPLORER.EXEC:\WINDOWS\TASKMON.EXEC:\WINDOWS\SYSTEM\SYSTRAY.EXEC:\WINDOWS\LOADQM.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXEC:\TOOLS_95\IMGICON.EXEC:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXEC:\TOOLS_95\IOWATCH.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXEC:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXEC:\WINDOWS\SYSTEM\DDHELP.EXEC:\MY DOCUMENTS\DOCUMENTS\HIJACKTHIS.EXEC:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXER1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.zrlsqoforutytdxgbjlmc.us/cwCut0...TRbSndiuIi.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cnn.com/O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dllO2 - BHO: (no name) - {8F59277D-8B7B-B43E-D41E-DB5E22D20BC0} - C:\WINDOWS\APPLICATION DATA\MAILDASH\HOLEINSIDE.EXEO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLLO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCXO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dllO4 - HKLM\..\Run: [scanRegistry] C:\WINDOWS\scanregw.exe /autorunO4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exeO4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -sO4 - HKLM\..\Run: [systemTray] SysTray.ExeO4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrSchemeO4 - HKLM\..\Run: [LoadQM] loadqm.exeO4 - HKLM\..\Run: [symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe startO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [MEAL SEND OKAY INTERNET] C:\WINDOWS\All Users\Application Data\boldstopmealsend\seek that.exeO4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXEO4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrSchemeO4 - HKLM\..\RunServices: [schedulingAgent] mstask.exeO4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exeO4 - HKLM\..\RunServices: [stillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXEO4 - HKLM\..\RunServices: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"O4 - HKLM\..\RunServices: [NPFMonitor] C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exeO4 - HKLM\..\RunServices: [scriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -regO4 - HKCU\..\Run: [find open] C:\WINDOWS\APPLIC~1\PLAYBO~1\Knob Admin.exeO4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO4 - Startup: Zip Disk Icons.lnk = C:\Tools_95\IMGICON.EXEO4 - Startup: AdSubtract.lnk = C:\Program Files\AdSubtract\adsub.exeO4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXEO4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXEO4 - Startup: Event Reminder.lnk = C:\Program Files\Mindscape\PrintMaster\PMREMIND.EXEO4 - Startup: Iomega Startup Options.lnk = C:\Tools_95\IMGSTART.EXEO4 - Startup: Iomega Watch.lnk = C:\Tools_95\IOWATCH.EXEO9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLLO9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLLO9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htmO9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htmO16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cabO16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cabO16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cabO16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cabO16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cabO16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/...utocomplete.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cabcould you please tell me what to get rid of?
gamehead200 Posted November 13, 2004 Posted November 13, 2004 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.zrlsqoforutytdxgbjlmc.us/cwCut0...TRbSndiuIi.htmO2 - BHO: (no name) - {8F59277D-8B7B-B43E-D41E-DB5E22D20BC0} - C:\WINDOWS\APPLICATION DATA\MAILDASH\HOLEINSIDE.EXEO4 - HKLM\..\Run: [MEAL SEND OKAY INTERNET] C:\WINDOWS\All Users\Application Data\boldstopmealsend\seek that.exeO4 - HKLM\..\RunServices: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" (Yes, MessengerPlus3, full of adware/spyware)O4 - HKCU\..\Run: [find open] C:\WINDOWS\APPLIC~1\PLAYBO~1\Knob Admin.exeThere might be more... Run Ad-Aware and Spybot S&D like crazy! Also, if you end some tasks and see that something else starts up after ending a program, I would suggest searching for it on your computer and deleting it... I've had that problem on several of my friends' computers and they were, in fact, adware or spyware! Good luck!
tguy Posted December 29, 2004 Posted December 29, 2004 You might also need:XoftSpyHiJackThisAnti-Virus scanner
DigeratiPrime Posted December 30, 2004 Posted December 30, 2004 i hate to sound trollish, but all I 'want' to say is "Firefox perhaps"?
10forcash Posted December 30, 2004 Posted December 30, 2004 npqtplugin.dll is used by Opera... and others, it's a quicktime plugin extensionCheers,10forcash
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now