Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stop making mediocre tutorials.The best tutorials are video! Camtasia Studio makes it easy to create engaging, buzz-building screen videos at any size, in any popular format. Download the free trial!
  #1  
Old June 15th, 2004, 11:45 PM
okudazilla okudazilla is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2004
Posts: 1 okudazilla User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
mshp.dll variations

After attempting to fix similar mshp.dll problems to those found in this forum i found that although mshp.dll disappeared identical websites with different *.dll names started appearing. I attempted to fix the problems in the same way that those who conquered mshp.dll did, but new versions kept popping up. I will post my hjt log in the hopes that someone has an idea of something to do.
Thanks in advance...
EmiC:\WINDOWS.000\SYSTEM\KERNEL32.DLL
C:\WINDOWS.000\SYSTEM\MSGSRV32.EXE
C:\WINDOWS.000\SYSTEM\MPREXE.EXE
C:\WINDOWS.000\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\AVSYNMGR.EXE
C:\WINDOWS.000\JAVAMA32.EXE
C:\WINDOWS.000\SYSTEM\mmtask.tsk
C:\WINDOWS.000\SYSTEM\NTFK.EXE
C:\WINDOWS.000\APPKY.EXE
C:\WINDOWS.000\SYSTEM\MFCKE32.EXE
C:\WINDOWS.000\SDKUC.EXE
C:\WINDOWS.000\SYSTEM\IPWC.EXE
C:\WINDOWS.000\SYSTEM\D3TI32.EXE
C:\WINDOWS.000\ATLMS32.EXE
C:\WINDOWS.000\SYSMH32.EXE
C:\WINDOWS.000\SDKTH32.EXE
C:\WINDOWS.000\SYSTEM\MSEF32.EXE
C:\WINDOWS.000\WINVS.EXE
C:\WINDOWS.000\SYSTEM\NTSN.EXE
C:\WINDOWS.000\SYSTEM\IPOV.EXE
C:\WINDOWS.000\MFCMA32.EXE
C:\WINDOWS.000\ATLNI.EXE
C:\WINDOWS.000\ADDSG.EXE
C:\WINDOWS.000\SYSTEM\WINFO.EXE
C:\WINDOWS.000\SYSTEM\JAVAND32.EXE
C:\WINDOWS.000\MFCGB32.EXE
C:\WINDOWS.000\SYSTEM\IESF32.EXE
C:\WINDOWS.000\JAVAQS32.EXE
C:\WINDOWS.000\ATLHW32.EXE
C:\WINDOWS.000\D3EU.EXE
C:\WINDOWS.000\SYSTEM\IPUW32.EXE
C:\WINDOWS.000\JAVACQ.EXE
C:\WINDOWS.000\SYSTEM\APING.EXE
C:\WINDOWS.000\SYSTEM\SYSPF32.EXE
C:\WINDOWS.000\SYSTEM\NTSS32.EXE
C:\WINDOWS.000\IPHN32.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\VSSTAT.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\VSHWIN32.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\AVCONSOL.EXE
C:\WINDOWS.000\EXPLORER.EXE
C:\WINDOWS.000\SYSTEM\SYSTRAY.EXE
C:\WINDOWS.000\SYSTEM\QTTASK.EXE
C:\WINDOWS.000\NTOG32.EXE
C:\WINDOWS.000\JAVAMA32.EXE
C:\WINDOWS.000\SYSTEM\DDHELP.EXE
C:\WINDOWS.000\SYSTEM\MSHE.EXE
C:\WINDOWS.000\SYSTEM\WMIEXE.EXE
C:\WINDOWS.000\SYSTEM\INTERNAT.EXE
C:\WINDOWS.000\SYSTEM\JAVAND32.EXE
C:\WINDOWS.000\SYSTEM\NTQL.EXE
C:\WINDOWS.000\JAVAMA32.EXE
C:\WINDOWS.000\SYSTEM\WINLV32.EXE
C:\WINDOWS.000\D3EU.EXE
C:\WINDOWS.000\SYSTEM\D3UP.EXE
C:\WINDOWS.000\SYSTEM\JAVAND32.EXE
C:\WINDOWS.000\SYSTEM\ADDIB32.EXE
C:\WINDOWS.000\SYSTEM\IESF32.EXE
C:\WINDOWS.000\IPVN32.EXE
C:\WINDOWS.000\JAVAMA32.EXE
C:\WINDOWS.000\SYSTEM\JAVASK.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS.000\SYSTEM\D3UP.EXE
C:\WINDOWS.000\ADDWY32.EXE
C:\WINDOWS.000\D3EU.EXE
C:\WINDOWS.000\SYSTEM\SDKDS.EXE
C:\WINDOWS.000\JAVAMA32.EXE
C:\WINDOWS.000\SYSTEM\CRBU.EXE
C:\WINDOWS.000\SYSTEM\JAVAND32.EXE
C:\WINDOWS.000\SYSTEM\NETKJ32.EXE
C:\WINDOWS.000\JAVAMA32.EXE
C:\WINDOWS.000\SYSTEM\IEDJ.EXE
C:\WINDOWS.000\JAVAMA32.EXE
C:\WINDOWS.000\SYSTEM\IPOE.EXE
C:\WINDOWS.000\IPVN32.EXE
C:\WINDOWS.000\SYSTEM\ADDKD32.EXE
C:\WINDOWS.000\JAVAMA32.EXE
C:\WINDOWS.000\WINUZ.EXE
C:\WINDOWS.000\JAVAMA32.EXE
C:\WINDOWS.000\JAVAOY32.EXE
C:\WINDOWS.000\JAVAMA32.EXE
C:\WINDOWS.000\APPIJ32.EXE
C:\WINDOWS.000\JAVAMA32.EXE
C:\WINDOWS.000\SYSTEM\IPAA.EXE
C:\WINDOWS.000\JAVAMA32.EXE
C:\WINDOWS.000\D3PJ.EXE
C:\WINDOWS.000\DESKTOP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS.000\hlusy.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://hlusy.dll/index.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://hlusy.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS.000\hlusy.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://hlusy.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS.000\hlusy.dll/sp.html#37049
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: . - {D34F08C5-4F18-477c-86CB-1A9BEECFE37B} - C:\WINDOWS.000\APPLICATION DATA\IEKC\IEKC32.DLL (file missing)
O2 - BHO: (no name) - {117FE238-928F-624F-E203-E4F4600A8E24} - C:\WINDOWS.000\SYSTEM\MFCKW32.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS.000\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS.000\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [NTOG32.EXE] C:\WINDOWS.000\NTOG32.EXE
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [McAfeeVirusScanService] C:\Program Files\Network Associates\VirusScan\AVSYNMGR.EXE
O4 - HKLM\..\RunServices: [D3TI32.EXE] C:\WINDOWS.000\SYSTEM\D3TI32.EXE
O4 - HKLM\..\RunServices: [JAVAMA32.EXE] C:\WINDOWS.000\JAVAMA32.EXE
O4 - HKLM\..\RunServices: [APPKY.EXE] C:\WINDOWS.000\APPKY.EXE
O4 - HKLM\..\RunServices: [MFCKE32.EXE] C:\WINDOWS.000\SYSTEM\MFCKE32.EXE
O4 - HKLM\..\RunServices: [SDKUC.EXE] C:\WINDOWS.000\SDKUC.EXE
O4 - HKLM\..\RunServices: [IPWC.EXE] C:\WINDOWS.000\SYSTEM\IPWC.EXE
O4 - HKLM\..\RunServices: [NTFK.EXE] C:\WINDOWS.000\SYSTEM\NTFK.EXE
O4 - HKLM\..\RunServices: [SDKTH32.EXE] C:\WINDOWS.000\SDKTH32.EXE
O4 - HKLM\..\RunServices: [ATLMS32.EXE] C:\WINDOWS.000\ATLMS32.EXE
O4 - HKLM\..\RunServices: [SYSMH32.EXE] C:\WINDOWS.000\SYSMH32.EXE
O4 - HKLM\..\RunServices: [MSEF32.EXE] C:\WINDOWS.000\SYSTEM\MSEF32.EXE
O4 - HKLM\..\RunServices: [WINVS.EXE] C:\WINDOWS.000\WINVS.EXE
O4 - HKLM\..\RunServices: [MFCMA32.EXE] C:\WINDOWS.000\MFCMA32.EXE
O4 - HKLM\..\RunServices: [NTSN.EXE] C:\WINDOWS.000\SYSTEM\NTSN.EXE
O4 - HKLM\..\RunServices: [IPOV.EXE] C:\WINDOWS.000\SYSTEM\IPOV.EXE
O4 - HKLM\..\RunServices: [ATLNI.EXE] C:\WINDOWS.000\ATLNI.EXE
O4 - HKLM\..\RunServices: [MFCGB32.EXE] C:\WINDOWS.000\MFCGB32.EXE
O4 - HKLM\..\RunServices: [WINFO.EXE] C:\WINDOWS.000\SYSTEM\WINFO.EXE
O4 - HKLM\..\RunServices: [ADDSG.EXE] C:\WINDOWS.000\ADDSG.EXE
O4 - HKLM\..\RunServices: [JAVAND32.EXE] C:\WINDOWS.000\SYSTEM\JAVAND32.EXE
O4 - HKLM\..\RunServices: [IESF32.EXE] C:\WINDOWS.000\SYSTEM\IESF32.EXE
O4 - HKLM\..\RunServices: [JAVAQS32.EXE] C:\WINDOWS.000\JAVAQS32.EXE
O4 - HKLM\..\RunServices: [ATLHW32.EXE] C:\WINDOWS.000\ATLHW32.EXE
O4 - HKLM\..\RunServices: [IPUW32.EXE] C:\WINDOWS.000\SYSTEM\IPUW32.EXE
O4 - HKLM\..\RunServices: [D3EU.EXE] C:\WINDOWS.000\D3EU.EXE
O4 - HKLM\..\RunServices: [JAVACQ.EXE] C:\WINDOWS.000\JAVACQ.EXE
O4 - HKLM\..\RunServices: [APING.EXE] C:\WINDOWS.000\SYSTEM\APING.EXE
O4 - HKLM\..\RunServices: [SYSPF32.EXE] C:\WINDOWS.000\SYSTEM\SYSPF32.EXE
O4 - HKLM\..\RunServices: [NTSS32.EXE] C:\WINDOWS.000\SYSTEM\NTSS32.EXE
O4 - HKLM\..\RunServices: [IPHN32.EXE] C:\WINDOWS.000\IPHN32.EXE
O4 - HKLM\..\RunServices: [MSHE.EXE] C:\WINDOWS.000\SYSTEM\MSHE.EXE
O4 - HKLM\..\RunServices: [NTQL.EXE] C:\WINDOWS.000\SYSTEM\NTQL.EXE
O4 - HKLM\..\RunServices: [WINLV32.EXE] C:\WINDOWS.000\SYSTEM\WINLV32.EXE
O4 - HKLM\..\RunServices: [D3UP.EXE] C:\WINDOWS.000\SYSTEM\D3UP.EXE
O4 - HKLM\..\RunServices: [ADDIB32.EXE] C:\WINDOWS.000\SYSTEM\ADDIB32.EXE
O4 - HKLM\..\RunServices: [IPVN32.EXE] C:\WINDOWS.000\IPVN32.EXE
O4 - HKLM\..\RunServices: [JAVASK.EXE] C:\WINDOWS.000\SYSTEM\JAVASK.EXE
O4 - HKLM\..\RunServices: [ADDWY32.EXE] C:\WINDOWS.000\ADDWY32.EXE
O4 - HKLM\..\RunServices: [SDKDS.EXE] C:\WINDOWS.000\SYSTEM\SDKDS.EXE
O4 - HKLM\..\RunServices: [CRBU.EXE] C:\WINDOWS.000\SYSTEM\CRBU.EXE
O4 - HKLM\..\RunServices: [NETKJ32.EXE] C:\WINDOWS.000\SYSTEM\NETKJ32.EXE
O4 - HKLM\..\RunServices: [IEDJ.EXE] C:\WINDOWS.000\SYSTEM\IEDJ.EXE
O4 - HKLM\..\RunServices: [IPOE.EXE] C:\WINDOWS.000\SYSTEM\IPOE.EXE
O4 - HKLM\..\RunServices: [ADDKD32.EXE] C:\WINDOWS.000\SYSTEM\ADDKD32.EXE
O4 - HKLM\..\RunServices: [WINUZ.EXE] C:\WINDOWS.000\WINUZ.EXE
O4 - HKLM\..\RunServices: [JAVAOY32.EXE] C:\WINDOWS.000\JAVAOY32.EXE
O4 - HKLM\..\RunServices: [APPIJ32.EXE] C:\WINDOWS.000\APPIJ32.EXE
O4 - HKLM\..\RunServices: [IPAA.EXE] C:\WINDOWS.000\SYSTEM\IPAA.EXE
O4 - HKLM\..\RunServices: [D3PJ.EXE] C:\WINDOWS.000\D3PJ.EXE
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: AIM (HKLM)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - URL
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - URL
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - URL
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - URL
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - URL

Reply With Quote
  #2  
Old June 16th, 2004, 01:02 AM
edwinbrains's Avatar
edwinbrains edwinbrains is offline
Retired Moderator
Dev Shed God 4th Plane (6500 - 6999 posts)
 
Join Date: Jan 2004
Location: London, UK
Posts: 6,670 edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)  Folding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced Folder
Time spent in forums: 1 Week 6 Days 23 h 36 m 40 sec
Reputation Power: 92
moved...
__________________
- Edwin -

The General Rules Thread | The General FAQ Thread

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > mshp.dll variations


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 6 hosted by Hostway