Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

FRUSTRATED


  • Please log in to reply
10 replies to this topic

#1 jlinton

jlinton

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:56 PM

Posted 19 February 2005 - 05:37 AM

Have been infected with Home Search Assistant. ARGHHHHHH!!!!!! Followed instructions on how to remove with no success, little sucker is so stubborn. Running Windows 98, so am I missing something somewhere. Can't seem to find the .exe file. This is not my computer, it's just a loaner...alot of stuff is on it and don't know what everything is for, a little hesitant to start deleting stuff. Also on dialup, so you can imagine how slow the internet has become. Any help would be greatly appreciated. Thanks

Logfile of HijackThis v1.99.1
Scan saved at 5:38:41 AM, on 2/19/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\USBMONIT.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\SYMPATICO STARTER KIT\BIN\CONFSVR.EXE
C:\WINDOWS\SYSSG.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\SYMPATICO STARTER KIT\BIN\GBCONMON.EXE
C:\PROGRAM FILES\SYMPATICO STARTER KIT\BIN\GBTASK.EXE
C:\WINDOWS\SYSTEM\D3IP32.EXE
C:\WINDOWS\SYSTEM\D3IP32.EXE
C:\WINDOWS\ATLXZ.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\SYMPATICO STARTER KIT\BIN\GBDASH.EXE
C:\WINDOWS\ATLXZ.EXE
C:\WINDOWS\SYSAY.EXE
C:\WINDOWS\SYSTEM\JAVAOA32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\ATLXZ.EXE
C:\WINDOWS\SYSTEM\IECD32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\JAVAOA32.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\wvqgv.dll/sp.html#44768
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\wvqgv.dll/sp.html#44768
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\wvqgv.dll/sp.html#44768
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\wvqgv.dll/sp.html#44768
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\wvqgv.dll/sp.html#44768
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\wvqgv.dll/sp.html#44768
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\wvqgv.dll/sp.html#44768
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>
R3 - Default URLSearchHook is missing
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Class - {C5E4D61E-DD51-7B29-414B-CAEAD1ADA5D6} - C:\WINDOWS\SYSTEM\SDKHU.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINDOWS\SYSTEM\USBMonit.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [Gearbox] "C:\Program Files\Sympatico Starter Kit\bin\confsvr.exe"
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\Run: [SYSSG.EXE] C:\WINDOWS\SYSSG.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [Gearbox Deferal Check] C:\Program Files\Sympatico Starter Kit\bin\gbdefer.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ADDZU.EXE] C:\WINDOWS\ADDZU.EXE
O4 - HKLM\..\RunServices: [ADDCX.EXE] C:\WINDOWS\ADDCX.EXE
O4 - HKLM\..\RunServices: [D3IP32.EXE] C:\WINDOWS\SYSTEM\D3IP32.EXE
O4 - HKLM\..\RunServices: [IEFW32.EXE] C:\WINDOWS\SYSTEM\IEFW32.EXE
O4 - HKLM\..\RunServices: [ATLTC.EXE] C:\WINDOWS\ATLTC.EXE
O4 - HKLM\..\RunServices: [SYSOC.EXE] C:\WINDOWS\SYSTEM\SYSOC.EXE
O4 - HKLM\..\RunServices: [NETSJ32.EXE] C:\WINDOWS\NETSJ32.EXE
O4 - HKLM\..\RunServices: [APPWY32.EXE] C:\WINDOWS\SYSTEM\APPWY32.EXE
O4 - HKLM\..\RunServices: [ATLXZ.EXE] C:\WINDOWS\ATLXZ.EXE
O4 - HKLM\..\RunServices: [SYSAY.EXE] C:\WINDOWS\SYSAY.EXE
O4 - HKLM\..\RunServices: [JAVAOA32.EXE] C:\WINDOWS\SYSTEM\JAVAOA32.EXE
O4 - HKLM\..\RunServices: [IECD32.EXE] C:\WINDOWS\SYSTEM\IECD32.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Corel MEDIA FOLDERS INDEXER 8.LNK = C:\Corel\Graphics8\Programs\MFIndexer.exe
O4 - Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\SYSTEM\E_SRCV03.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.static.topconverting.com
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.static.topconverting.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O15 - Trusted IP range: 206.161.125.149 (HKLM)
O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by1fd.bay1.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://static.topconverting.com/activex/loader2.ocx
O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} (InstallX Class) - http://www.20x2p.com/262095de/enter.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab

BC AdBot (Login to Remove)

 


m

#2 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,389 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:12:56 PM

Posted 20 February 2005 - 11:38 AM

Download the attached zip file and unzip it to your desktop.

http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click on the deldomains.inf file and select 'Install'

Download cwshredder 2.12 from here:

http://cwshredder.net/bin/CWShredder.exe

Run the file after it is downloaded and click on the fix button. Let it do its thing and when its done, even if it crashes.

When its done run hijackthis again post a new log

#3 jlinton

jlinton
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:56 PM

Posted 20 February 2005 - 08:17 PM

Sorry Grinler couldn't find before, posted another, but I'll do here too. Followed instructions, shredder (ver 2.13) says not there. Here's new hjt log. Thanks

Logfile of HijackThis v1.99.1
Scan saved at 7:48:09 PM, on 2/20/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Class - {F4564785-092A-07FF-1B06-149E3520576B} - C:\WINDOWS\SYSTEM\NTKW32.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINDOWS\SYSTEM\USBMonit.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [Gearbox] "C:\Program Files\Sympatico Starter Kit\bin\confsvr.exe"
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\Run: [NTWP32.EXE] C:\WINDOWS\SYSTEM\NTWP32.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [Gearbox Deferal Check] C:\Program Files\Sympatico Starter Kit\bin\gbdefer.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ADDZU.EXE] C:\WINDOWS\ADDZU.EXE
O4 - HKLM\..\RunServices: [ADDCX.EXE] C:\WINDOWS\ADDCX.EXE
O4 - HKLM\..\RunServices: [D3IP32.EXE] C:\WINDOWS\SYSTEM\D3IP32.EXE
O4 - HKLM\..\RunServices: [IEFW32.EXE] C:\WINDOWS\SYSTEM\IEFW32.EXE
O4 - HKLM\..\RunServices: [ATLTC.EXE] C:\WINDOWS\ATLTC.EXE
O4 - HKLM\..\RunServices: [SYSOC.EXE] C:\WINDOWS\SYSTEM\SYSOC.EXE
O4 - HKLM\..\RunServices: [NETSJ32.EXE] C:\WINDOWS\NETSJ32.EXE
O4 - HKLM\..\RunServices: [APPWY32.EXE] C:\WINDOWS\SYSTEM\APPWY32.EXE
O4 - HKLM\..\RunServices: [ATLXZ.EXE] C:\WINDOWS\ATLXZ.EXE
O4 - HKLM\..\RunServices: [SYSAY.EXE] C:\WINDOWS\SYSAY.EXE
O4 - HKLM\..\RunServices: [JAVAOA32.EXE] C:\WINDOWS\SYSTEM\JAVAOA32.EXE
O4 - HKLM\..\RunServices: [IECD32.EXE] C:\WINDOWS\SYSTEM\IECD32.EXE
O4 - HKLM\..\RunServices: [SYSQY32.EXE] C:\WINDOWS\SYSQY32.EXE
O4 - HKLM\..\RunServices: [IEDB.EXE] C:\WINDOWS\SYSTEM\IEDB.EXE
O4 - HKLM\..\RunServices: [CRHV.EXE] C:\WINDOWS\SYSTEM\CRHV.EXE
O4 - HKLM\..\RunServices: [MFCDL32.EXE] C:\WINDOWS\MFCDL32.EXE
O4 - HKLM\..\RunServices: [SDKHX.EXE] C:\WINDOWS\SYSTEM\SDKHX.EXE
O4 - HKLM\..\RunServices: [APPQB.EXE] C:\WINDOWS\APPQB.EXE
O4 - HKLM\..\RunServices: [WINLD.EXE] C:\WINDOWS\SYSTEM\WINLD.EXE
O4 - HKLM\..\RunServices: [NETBQ32.EXE] C:\WINDOWS\NETBQ32.EXE
O4 - HKLM\..\RunServices: [JAVAWA32.EXE] C:\WINDOWS\SYSTEM\JAVAWA32.EXE
O4 - HKLM\..\RunServices: [SYSUA.EXE] C:\WINDOWS\SYSUA.EXE
O4 - HKLM\..\RunServices: [NTTG32.EXE] C:\WINDOWS\SYSTEM\NTTG32.EXE
O4 - HKLM\..\RunServices: [WINET32.EXE] C:\WINDOWS\SYSTEM\WINET32.EXE
O4 - HKLM\..\RunServices: [IEYZ32.EXE] C:\WINDOWS\SYSTEM\IEYZ32.EXE
O4 - HKLM\..\RunServices: [D3LH.EXE] C:\WINDOWS\D3LH.EXE
O4 - HKLM\..\RunServices: [MSPS32.EXE] C:\WINDOWS\MSPS32.EXE
O4 - HKLM\..\RunServices: [IPZN.EXE] C:\WINDOWS\IPZN.EXE
O4 - HKLM\..\RunServices: [MFCDR32.EXE] C:\WINDOWS\SYSTEM\MFCDR32.EXE
O4 - HKLM\..\RunServices: [ATLUS32.EXE] C:\WINDOWS\ATLUS32.EXE
O4 - HKLM\..\RunServices: [IEDZ.EXE] C:\WINDOWS\SYSTEM\IEDZ.EXE
O4 - HKLM\..\RunServices: [ADDLA32.EXE] C:\WINDOWS\SYSTEM\ADDLA32.EXE
O4 - HKLM\..\RunServices: [JAVAJW.EXE] C:\WINDOWS\SYSTEM\JAVAJW.EXE
O4 - HKLM\..\RunServices: [MFCUH.EXE] C:\WINDOWS\SYSTEM\MFCUH.EXE
O4 - HKLM\..\RunServices: [D3BU32.EXE] C:\WINDOWS\D3BU32.EXE
O4 - HKLM\..\RunServices: [APPBQ.EXE] C:\WINDOWS\APPBQ.EXE
O4 - HKLM\..\RunServices: [JAVAYR.EXE] C:\WINDOWS\JAVAYR.EXE
O4 - HKLM\..\RunServices: [NTFY32.EXE] C:\WINDOWS\NTFY32.EXE
O4 - HKLM\..\RunServices: [ADDKY.EXE] C:\WINDOWS\ADDKY.EXE
O4 - HKLM\..\RunServices: [JAVAYQ32.EXE] C:\WINDOWS\SYSTEM\JAVAYQ32.EXE
O4 - HKLM\..\RunServices: [ADDEJ32.EXE] C:\WINDOWS\SYSTEM\ADDEJ32.EXE
O4 - HKLM\..\RunServices: [SYSUE.EXE] C:\WINDOWS\SYSUE.EXE
O4 - HKLM\..\RunServices: [CRFJ.EXE] C:\WINDOWS\SYSTEM\CRFJ.EXE
O4 - HKLM\..\RunServices: [ADDRW.EXE] C:\WINDOWS\ADDRW.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\RunServices: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Corel MEDIA FOLDERS INDEXER 8.LNK = C:\Corel\Graphics8\Programs\MFIndexer.exe
O4 - Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\SYSTEM\E_SRCV03.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by1fd.bay1.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} (InstallX Class) - http://www.20x2p.com/262095de/enter.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab

#4 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,389 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:12:56 PM

Posted 20 February 2005 - 11:13 PM

1. Please down About:Buster from here: http://tools.zerosrealm.com/AboutBuster.zip

2. Once it is download, please run the tool. When the tool is open press ok and then start. In the field labeled "Input in here..." enter the following:

<substitue res:// part from the R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = line in HJT>

3. Then press the OK button. The program will start to delete the various elements of this malware.

4. After the tool is completed please run hijackthis again and fix the following entries:

<substitute for entries from Hijackthis>

5. Then press control-alt-delete and click on the processes tab. Please make sure the following processes are ended:

<substitute for any of the processes found in the Hijackthis process portion of the log>

6. Manually delete the following files:

<substitute for the files whose processes you ended in step 5.

#5 jlinton

jlinton
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:56 PM

Posted 21 February 2005 - 01:01 AM

Grinler,
Tried download but zerosrealm no longer available, got from another site.
When I run aboutbuster only get the scan start page, no place to enter "input in here". Did I miss something?
I'm attaching new HJT log, damn things changed again. Seems everytime I restart it changes itelf. HELP!!!!!! This log created without going into safe mode.
Appreciate all your patience. Thanks

Logfile of HijackThis v1.99.1
Scan saved at 12:48:17 AM, on 2/21/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\ADDCX.EXE
C:\WINDOWS\ADDZU.EXE
C:\WINDOWS\SYSTEM\D3IP32.EXE
C:\WINDOWS\SYSTEM\SYSOC.EXE
C:\WINDOWS\SYSTEM\IEFW32.EXE
C:\WINDOWS\ATLTC.EXE
C:\WINDOWS\NETSJ32.EXE
C:\WINDOWS\SYSTEM\APPWY32.EXE
C:\WINDOWS\ATLXZ.EXE
C:\WINDOWS\SYSTEM\JAVAOA32.EXE
C:\WINDOWS\SYSAY.EXE
C:\WINDOWS\SYSQY32.EXE
C:\WINDOWS\SYSTEM\IEDB.EXE
C:\WINDOWS\SYSTEM\CRHV.EXE
C:\WINDOWS\MFCDL32.EXE
C:\WINDOWS\SYSTEM\IECD32.EXE
C:\WINDOWS\SYSTEM\SDKHX.EXE
C:\WINDOWS\APPQB.EXE
C:\WINDOWS\SYSTEM\WINLD.EXE
C:\WINDOWS\SYSTEM\NTTG32.EXE
C:\WINDOWS\SYSUA.EXE
C:\WINDOWS\NETBQ32.EXE
C:\WINDOWS\SYSTEM\JAVAWA32.EXE
C:\WINDOWS\SYSTEM\WINET32.EXE
C:\WINDOWS\SYSTEM\IEYZ32.EXE
C:\WINDOWS\D3LH.EXE
C:\WINDOWS\MSPS32.EXE
C:\WINDOWS\IPZN.EXE
C:\WINDOWS\SYSTEM\MFCDR32.EXE
C:\WINDOWS\ATLUS32.EXE
C:\WINDOWS\SYSTEM\IEDZ.EXE
C:\WINDOWS\MFCLL.EXE
C:\WINDOWS\SYSTEM\ADDLA32.EXE
C:\WINDOWS\SYSTEM\JAVAJW.EXE
C:\WINDOWS\SYSTEM\MFCUH.EXE
C:\WINDOWS\D3BU32.EXE
C:\WINDOWS\APPBQ.EXE
C:\WINDOWS\JAVAYR.EXE
C:\WINDOWS\NTFY32.EXE
C:\WINDOWS\ADDKY.EXE
C:\WINDOWS\SYSTEM\JAVAYQ32.EXE
C:\WINDOWS\SYSTEM\ADDEJ32.EXE
C:\WINDOWS\SYSUE.EXE
C:\WINDOWS\SYSTEM\CRFJ.EXE
C:\WINDOWS\ADDRW.EXE
C:\WINDOWS\NETBQ32.EXE
C:\WINDOWS\NETBQ32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\NTMH32.EXE
C:\WINDOWS\SYSTEM\D3KG.EXE
C:\WINDOWS\MSBI32.EXE
C:\WINDOWS\SYSTEM\NTSG32.EXE
C:\WINDOWS\SYSTEM\IPXL32.EXE
C:\WINDOWS\NTVX.EXE
C:\WINDOWS\SYSTEM\SYSZE32.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\USBMONIT.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\SYMPATICO STARTER KIT\BIN\CONFSVR.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\IEFW32.EXE
C:\PROGRAM FILES\SYMPATICO STARTER KIT\BIN\GBCONMON.EXE
C:\PROGRAM FILES\SYMPATICO STARTER KIT\BIN\GBTASK.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wawtn.dll/sp.html#44768
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wawtn.dll/sp.html#44768
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\wawtn.dll/sp.html#44768
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wawtn.dll/sp.html#44768
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wawtn.dll/sp.html#44768
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\wawtn.dll/sp.html#44768
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\wawtn.dll/sp.html#44768
R3 - Default URLSearchHook is missing
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Class - {0DD6C7B1-4C89-ACE1-1449-E89B2C259103} - C:\WINDOWS\SYSEA.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINDOWS\SYSTEM\USBMonit.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [Gearbox] "C:\Program Files\Sympatico Starter Kit\bin\confsvr.exe"
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [Gearbox Deferal Check] C:\Program Files\Sympatico Starter Kit\bin\gbdefer.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ADDZU.EXE] C:\WINDOWS\ADDZU.EXE
O4 - HKLM\..\RunServices: [ADDCX.EXE] C:\WINDOWS\ADDCX.EXE
O4 - HKLM\..\RunServices: [D3IP32.EXE] C:\WINDOWS\SYSTEM\D3IP32.EXE
O4 - HKLM\..\RunServices: [IEFW32.EXE] C:\WINDOWS\SYSTEM\IEFW32.EXE
O4 - HKLM\..\RunServices: [ATLTC.EXE] C:\WINDOWS\ATLTC.EXE
O4 - HKLM\..\RunServices: [SYSOC.EXE] C:\WINDOWS\SYSTEM\SYSOC.EXE
O4 - HKLM\..\RunServices: [NETSJ32.EXE] C:\WINDOWS\NETSJ32.EXE
O4 - HKLM\..\RunServices: [APPWY32.EXE] C:\WINDOWS\SYSTEM\APPWY32.EXE
O4 - HKLM\..\RunServices: [ATLXZ.EXE] C:\WINDOWS\ATLXZ.EXE
O4 - HKLM\..\RunServices: [SYSAY.EXE] C:\WINDOWS\SYSAY.EXE
O4 - HKLM\..\RunServices: [JAVAOA32.EXE] C:\WINDOWS\SYSTEM\JAVAOA32.EXE
O4 - HKLM\..\RunServices: [IECD32.EXE] C:\WINDOWS\SYSTEM\IECD32.EXE
O4 - HKLM\..\RunServices: [SYSQY32.EXE] C:\WINDOWS\SYSQY32.EXE
O4 - HKLM\..\RunServices: [IEDB.EXE] C:\WINDOWS\SYSTEM\IEDB.EXE
O4 - HKLM\..\RunServices: [CRHV.EXE] C:\WINDOWS\SYSTEM\CRHV.EXE
O4 - HKLM\..\RunServices: [MFCDL32.EXE] C:\WINDOWS\MFCDL32.EXE
O4 - HKLM\..\RunServices: [SDKHX.EXE] C:\WINDOWS\SYSTEM\SDKHX.EXE
O4 - HKLM\..\RunServices: [APPQB.EXE] C:\WINDOWS\APPQB.EXE
O4 - HKLM\..\RunServices: [WINLD.EXE] C:\WINDOWS\SYSTEM\WINLD.EXE
O4 - HKLM\..\RunServices: [NETBQ32.EXE] C:\WINDOWS\NETBQ32.EXE
O4 - HKLM\..\RunServices: [JAVAWA32.EXE] C:\WINDOWS\SYSTEM\JAVAWA32.EXE
O4 - HKLM\..\RunServices: [SYSUA.EXE] C:\WINDOWS\SYSUA.EXE
O4 - HKLM\..\RunServices: [NTTG32.EXE] C:\WINDOWS\SYSTEM\NTTG32.EXE
O4 - HKLM\..\RunServices: [WINET32.EXE] C:\WINDOWS\SYSTEM\WINET32.EXE
O4 - HKLM\..\RunServices: [IEYZ32.EXE] C:\WINDOWS\SYSTEM\IEYZ32.EXE
O4 - HKLM\..\RunServices: [D3LH.EXE] C:\WINDOWS\D3LH.EXE
O4 - HKLM\..\RunServices: [MSPS32.EXE] C:\WINDOWS\MSPS32.EXE
O4 - HKLM\..\RunServices: [IPZN.EXE] C:\WINDOWS\IPZN.EXE
O4 - HKLM\..\RunServices: [MFCDR32.EXE] C:\WINDOWS\SYSTEM\MFCDR32.EXE
O4 - HKLM\..\RunServices: [ATLUS32.EXE] C:\WINDOWS\ATLUS32.EXE
O4 - HKLM\..\RunServices: [IEDZ.EXE] C:\WINDOWS\SYSTEM\IEDZ.EXE
O4 - HKLM\..\RunServices: [ADDLA32.EXE] C:\WINDOWS\SYSTEM\ADDLA32.EXE
O4 - HKLM\..\RunServices: [JAVAJW.EXE] C:\WINDOWS\SYSTEM\JAVAJW.EXE
O4 - HKLM\..\RunServices: [MFCUH.EXE] C:\WINDOWS\SYSTEM\MFCUH.EXE
O4 - HKLM\..\RunServices: [D3BU32.EXE] C:\WINDOWS\D3BU32.EXE
O4 - HKLM\..\RunServices: [APPBQ.EXE] C:\WINDOWS\APPBQ.EXE
O4 - HKLM\..\RunServices: [JAVAYR.EXE] C:\WINDOWS\JAVAYR.EXE
O4 - HKLM\..\RunServices: [NTFY32.EXE] C:\WINDOWS\NTFY32.EXE
O4 - HKLM\..\RunServices: [ADDKY.EXE] C:\WINDOWS\ADDKY.EXE
O4 - HKLM\..\RunServices: [JAVAYQ32.EXE] C:\WINDOWS\SYSTEM\JAVAYQ32.EXE
O4 - HKLM\..\RunServices: [ADDEJ32.EXE] C:\WINDOWS\SYSTEM\ADDEJ32.EXE
O4 - HKLM\..\RunServices: [SYSUE.EXE] C:\WINDOWS\SYSUE.EXE
O4 - HKLM\..\RunServices: [CRFJ.EXE] C:\WINDOWS\SYSTEM\CRFJ.EXE
O4 - HKLM\..\RunServices: [ADDRW.EXE] C:\WINDOWS\ADDRW.EXE
O4 - HKLM\..\RunServices: [MSBI32.EXE] C:\WINDOWS\MSBI32.EXE
O4 - HKLM\..\RunServices: [NTMH32.EXE] C:\WINDOWS\NTMH32.EXE
O4 - HKLM\..\RunServices: [NTSG32.EXE] C:\WINDOWS\SYSTEM\NTSG32.EXE
O4 - HKLM\..\RunServices: [D3KG.EXE] C:\WINDOWS\SYSTEM\D3KG.EXE
O4 - HKLM\..\RunServices: [IPXL32.EXE] C:\WINDOWS\SYSTEM\IPXL32.EXE
O4 - HKLM\..\RunServices: [NTVX.EXE] C:\WINDOWS\NTVX.EXE
O4 - HKLM\..\RunServices: [SYSZE32.EXE] C:\WINDOWS\SYSTEM\SYSZE32.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Corel MEDIA FOLDERS INDEXER 8.LNK = C:\Corel\Graphics8\Programs\MFIndexer.exe
O4 - Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\SYSTEM\E_SRCV03.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by1fd.bay1.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} (InstallX Class) - http://www.20x2p.com/262095de/enter.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab

#6 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,389 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:12:56 PM

Posted 21 February 2005 - 10:27 AM

Ok redownload it from here:

http://www.downloads.subratam.org/AboutBuster.zip

Start it, click on the start button, then press the OK button. Let it scan twice if its asks. When it is done, do not reboot and post a new log

#7 jlinton

jlinton
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:56 PM

Posted 21 February 2005 - 12:28 PM

Did as you requested.

Logfile of HijackThis v1.99.1
Scan saved at 12:23:32 PM, on 2/21/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\D3IP32.EXE
C:\WINDOWS\ADDZU.EXE
C:\WINDOWS\SYSTEM\SYSOC.EXE
C:\WINDOWS\ADDCX.EXE
C:\WINDOWS\NETSJ32.EXE
C:\WINDOWS\SYSTEM\IEFW32.EXE
C:\WINDOWS\SYSTEM\APPWY32.EXE
C:\WINDOWS\ATLTC.EXE
C:\WINDOWS\SYSAY.EXE
C:\WINDOWS\ATLXZ.EXE
C:\WINDOWS\SYSTEM\JAVAOA32.EXE
C:\WINDOWS\SYSTEM\IECD32.EXE
C:\WINDOWS\SYSQY32.EXE
C:\WINDOWS\SYSTEM\CRHV.EXE
C:\WINDOWS\SYSTEM\IEDB.EXE
C:\WINDOWS\MFCDL32.EXE
C:\WINDOWS\SYSTEM\SDKHX.EXE
C:\WINDOWS\SYSTEM\WINLD.EXE
C:\WINDOWS\APPQB.EXE
C:\WINDOWS\NETBQ32.EXE
C:\WINDOWS\SYSTEM\JAVAWA32.EXE
C:\WINDOWS\SYSUA.EXE
C:\WINDOWS\SYSTEM\NTTG32.EXE
C:\WINDOWS\SYSTEM\WINET32.EXE
C:\WINDOWS\SYSTEM\IEYZ32.EXE
C:\WINDOWS\IPZN.EXE
C:\WINDOWS\MSPS32.EXE
C:\WINDOWS\D3LH.EXE
C:\WINDOWS\SYSTEM\MFCDR32.EXE
C:\WINDOWS\SYSTEM\ADDLA32.EXE
C:\WINDOWS\SYSTEM\IEDZ.EXE
C:\WINDOWS\ATLUS32.EXE
C:\WINDOWS\SYSTEM\JAVAJW.EXE
C:\WINDOWS\SYSTEM\MFCUH.EXE
C:\WINDOWS\D3BU32.EXE
C:\WINDOWS\APPBQ.EXE
C:\WINDOWS\JAVAYR.EXE
C:\WINDOWS\NTFY32.EXE
C:\WINDOWS\ADDKY.EXE
C:\WINDOWS\SYSTEM\JAVAYQ32.EXE
C:\WINDOWS\SYSTEM\ADDEJ32.EXE
C:\WINDOWS\SYSUE.EXE
C:\WINDOWS\ADDRW.EXE
C:\WINDOWS\SYSTEM\CRFJ.EXE
C:\WINDOWS\MSBI32.EXE
C:\WINDOWS\NTMH32.EXE
C:\WINDOWS\SYSTEM\NTSG32.EXE
C:\WINDOWS\SYSTEM\D3KG.EXE
C:\WINDOWS\SYSTEM\SYSZE32.EXE
C:\WINDOWS\SYSTEM\IPXL32.EXE
C:\WINDOWS\NTVX.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\USBMONIT.EXE
C:\PROGRAM FILES\SYMPATICO STARTER KIT\BIN\CONFSVR.EXE
C:\WINDOWS\SYSTEM\D3KG.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\SYMPATICO STARTER KIT\BIN\GBCONMON.EXE
C:\PROGRAM FILES\SYMPATICO STARTER KIT\BIN\GBTASK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\D3IP32.EXE
C:\WINDOWS\MSFQ.EXE
C:\WINDOWS\SYSTEM\D3IP32.EXE
C:\WINDOWS\SYSTEM\IPLA.EXE
C:\WINDOWS\ADDMJ32.EXE
C:\WINDOWS\SYSTEM\D3IP32.EXE
C:\WINDOWS\SYSTEM\WINIJ.EXE
C:\WINDOWS\SYSTEM\D3IP32.EXE
C:\WINDOWS\SYSTEM\D3IP32.EXE
C:\WINDOWS\SYSTEM\MSEX32.EXE
C:\WINDOWS\SYSTEM\D3KG.EXE
C:\WINDOWS\SYSTEM\SYSBD32.EXE
C:\WINDOWS\SYSTEM\D3IP32.EXE
C:\WINDOWS\SYSTEM\JAVAPJ32.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\hnvoi.dll/sp.html#44768
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\hnvoi.dll/sp.html#44768
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\hnvoi.dll/sp.html#44768
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\hnvoi.dll/sp.html#44768
R3 - Default URLSearchHook is missing
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Class - {4B4EE737-2D47-E126-DFBD-035B9EF1BE06} - C:\WINDOWS\APPRP.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINDOWS\SYSTEM\USBMonit.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [Gearbox] "C:\Program Files\Sympatico Starter Kit\bin\confsvr.exe"
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\Run: [ADDMJ32.EXE] C:\WINDOWS\ADDMJ32.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [Gearbox Deferal Check] C:\Program Files\Sympatico Starter Kit\bin\gbdefer.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ADDZU.EXE] C:\WINDOWS\ADDZU.EXE
O4 - HKLM\..\RunServices: [ADDCX.EXE] C:\WINDOWS\ADDCX.EXE
O4 - HKLM\..\RunServices: [D3IP32.EXE] C:\WINDOWS\SYSTEM\D3IP32.EXE
O4 - HKLM\..\RunServices: [IEFW32.EXE] C:\WINDOWS\SYSTEM\IEFW32.EXE
O4 - HKLM\..\RunServices: [ATLTC.EXE] C:\WINDOWS\ATLTC.EXE
O4 - HKLM\..\RunServices: [SYSOC.EXE] C:\WINDOWS\SYSTEM\SYSOC.EXE
O4 - HKLM\..\RunServices: [NETSJ32.EXE] C:\WINDOWS\NETSJ32.EXE
O4 - HKLM\..\RunServices: [APPWY32.EXE] C:\WINDOWS\SYSTEM\APPWY32.EXE
O4 - HKLM\..\RunServices: [ATLXZ.EXE] C:\WINDOWS\ATLXZ.EXE
O4 - HKLM\..\RunServices: [SYSAY.EXE] C:\WINDOWS\SYSAY.EXE
O4 - HKLM\..\RunServices: [JAVAOA32.EXE] C:\WINDOWS\SYSTEM\JAVAOA32.EXE
O4 - HKLM\..\RunServices: [IECD32.EXE] C:\WINDOWS\SYSTEM\IECD32.EXE
O4 - HKLM\..\RunServices: [SYSQY32.EXE] C:\WINDOWS\SYSQY32.EXE
O4 - HKLM\..\RunServices: [IEDB.EXE] C:\WINDOWS\SYSTEM\IEDB.EXE
O4 - HKLM\..\RunServices: [CRHV.EXE] C:\WINDOWS\SYSTEM\CRHV.EXE
O4 - HKLM\..\RunServices: [MFCDL32.EXE] C:\WINDOWS\MFCDL32.EXE
O4 - HKLM\..\RunServices: [SDKHX.EXE] C:\WINDOWS\SYSTEM\SDKHX.EXE
O4 - HKLM\..\RunServices: [APPQB.EXE] C:\WINDOWS\APPQB.EXE
O4 - HKLM\..\RunServices: [WINLD.EXE] C:\WINDOWS\SYSTEM\WINLD.EXE
O4 - HKLM\..\RunServices: [NETBQ32.EXE] C:\WINDOWS\NETBQ32.EXE
O4 - HKLM\..\RunServices: [JAVAWA32.EXE] C:\WINDOWS\SYSTEM\JAVAWA32.EXE
O4 - HKLM\..\RunServices: [SYSUA.EXE] C:\WINDOWS\SYSUA.EXE
O4 - HKLM\..\RunServices: [NTTG32.EXE] C:\WINDOWS\SYSTEM\NTTG32.EXE
O4 - HKLM\..\RunServices: [WINET32.EXE] C:\WINDOWS\SYSTEM\WINET32.EXE
O4 - HKLM\..\RunServices: [IEYZ32.EXE] C:\WINDOWS\SYSTEM\IEYZ32.EXE
O4 - HKLM\..\RunServices: [D3LH.EXE] C:\WINDOWS\D3LH.EXE
O4 - HKLM\..\RunServices: [MSPS32.EXE] C:\WINDOWS\MSPS32.EXE
O4 - HKLM\..\RunServices: [IPZN.EXE] C:\WINDOWS\IPZN.EXE
O4 - HKLM\..\RunServices: [MFCDR32.EXE] C:\WINDOWS\SYSTEM\MFCDR32.EXE
O4 - HKLM\..\RunServices: [ATLUS32.EXE] C:\WINDOWS\ATLUS32.EXE
O4 - HKLM\..\RunServices: [IEDZ.EXE] C:\WINDOWS\SYSTEM\IEDZ.EXE
O4 - HKLM\..\RunServices: [ADDLA32.EXE] C:\WINDOWS\SYSTEM\ADDLA32.EXE
O4 - HKLM\..\RunServices: [JAVAJW.EXE] C:\WINDOWS\SYSTEM\JAVAJW.EXE
O4 - HKLM\..\RunServices: [MFCUH.EXE] C:\WINDOWS\SYSTEM\MFCUH.EXE
O4 - HKLM\..\RunServices: [D3BU32.EXE] C:\WINDOWS\D3BU32.EXE
O4 - HKLM\..\RunServices: [APPBQ.EXE] C:\WINDOWS\APPBQ.EXE
O4 - HKLM\..\RunServices: [JAVAYR.EXE] C:\WINDOWS\JAVAYR.EXE
O4 - HKLM\..\RunServices: [NTFY32.EXE] C:\WINDOWS\NTFY32.EXE
O4 - HKLM\..\RunServices: [ADDKY.EXE] C:\WINDOWS\ADDKY.EXE
O4 - HKLM\..\RunServices: [JAVAYQ32.EXE] C:\WINDOWS\SYSTEM\JAVAYQ32.EXE
O4 - HKLM\..\RunServices: [ADDEJ32.EXE] C:\WINDOWS\SYSTEM\ADDEJ32.EXE
O4 - HKLM\..\RunServices: [SYSUE.EXE] C:\WINDOWS\SYSUE.EXE
O4 - HKLM\..\RunServices: [CRFJ.EXE] C:\WINDOWS\SYSTEM\CRFJ.EXE
O4 - HKLM\..\RunServices: [ADDRW.EXE] C:\WINDOWS\ADDRW.EXE
O4 - HKLM\..\RunServices: [MSBI32.EXE] C:\WINDOWS\MSBI32.EXE
O4 - HKLM\..\RunServices: [NTMH32.EXE] C:\WINDOWS\NTMH32.EXE
O4 - HKLM\..\RunServices: [NTSG32.EXE] C:\WINDOWS\SYSTEM\NTSG32.EXE
O4 - HKLM\..\RunServices: [D3KG.EXE] C:\WINDOWS\SYSTEM\D3KG.EXE
O4 - HKLM\..\RunServices: [IPXL32.EXE] C:\WINDOWS\SYSTEM\IPXL32.EXE
O4 - HKLM\..\RunServices: [NTVX.EXE] C:\WINDOWS\NTVX.EXE
O4 - HKLM\..\RunServices: [SYSZE32.EXE] C:\WINDOWS\SYSTEM\SYSZE32.EXE
O4 - HKLM\..\RunServices: [MSFQ.EXE] C:\WINDOWS\MSFQ.EXE
O4 - HKLM\..\RunServices: [IPLA.EXE] C:\WINDOWS\SYSTEM\IPLA.EXE
O4 - HKLM\..\RunServices: [WINIJ.EXE] C:\WINDOWS\SYSTEM\WINIJ.EXE
O4 - HKLM\..\RunServices: [MSEX32.EXE] C:\WINDOWS\SYSTEM\MSEX32.EXE
O4 - HKLM\..\RunServices: [SYSBD32.EXE] C:\WINDOWS\SYSTEM\SYSBD32.EXE
O4 - HKLM\..\RunServices: [JAVAPJ32.EXE] C:\WINDOWS\SYSTEM\JAVAPJ32.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Corel MEDIA FOLDERS INDEXER 8.LNK = C:\Corel\Graphics8\Programs\MFIndexer.exe
O4 - Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\SYSTEM\E_SRCV03.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by1fd.bay1.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} (InstallX Class) - http://www.20x2p.com/262095de/enter.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab

#8 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,389 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:12:56 PM

Posted 21 February 2005 - 04:34 PM

You may want to print out these directions as the Internet will not be available. Please continue with the next step if you run into a problem with the current one. Just be sure to let us know what the problem was when you reply.

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Please download About:Buster from here: About:Buster Download. Once it is downloaded extract it to
c:\aboutbuster. We will use that program later in this process.

Reboot your computer into Safe Mode and follow these steps:

Step 1:
Then close all programs and windows and run hijackthis. Put a checkmark next to each of these entries and press the fix button when ready:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\hnvoi.dll/sp.html#44768
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\hnvoi.dll/sp.html#44768
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\hnvoi.dll/sp.html#44768
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\hnvoi.dll/sp.html#44768
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {4B4EE737-2D47-E126-DFBD-035B9EF1BE06} - C:\WINDOWS\APPRP.DLL
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\Run: [ADDMJ32.EXE] C:\WINDOWS\ADDMJ32.EXE
O4 - HKLM\..\RunServices: [ADDZU.EXE] C:\WINDOWS\ADDZU.EXE
O4 - HKLM\..\RunServices: [ADDCX.EXE] C:\WINDOWS\ADDCX.EXE
O4 - HKLM\..\RunServices: [D3IP32.EXE] C:\WINDOWS\SYSTEM\D3IP32.EXE
O4 - HKLM\..\RunServices: [IEFW32.EXE] C:\WINDOWS\SYSTEM\IEFW32.EXE
O4 - HKLM\..\RunServices: [ATLTC.EXE] C:\WINDOWS\ATLTC.EXE
O4 - HKLM\..\RunServices: [SYSOC.EXE] C:\WINDOWS\SYSTEM\SYSOC.EXE
O4 - HKLM\..\RunServices: [NETSJ32.EXE] C:\WINDOWS\NETSJ32.EXE
O4 - HKLM\..\RunServices: [APPWY32.EXE] C:\WINDOWS\SYSTEM\APPWY32.EXE
O4 - HKLM\..\RunServices: [ATLXZ.EXE] C:\WINDOWS\ATLXZ.EXE
O4 - HKLM\..\RunServices: [SYSAY.EXE] C:\WINDOWS\SYSAY.EXE
O4 - HKLM\..\RunServices: [JAVAOA32.EXE] C:\WINDOWS\SYSTEM\JAVAOA32.EXE
O4 - HKLM\..\RunServices: [IECD32.EXE] C:\WINDOWS\SYSTEM\IECD32.EXE
O4 - HKLM\..\RunServices: [SYSQY32.EXE] C:\WINDOWS\SYSQY32.EXE
O4 - HKLM\..\RunServices: [IEDB.EXE] C:\WINDOWS\SYSTEM\IEDB.EXE
O4 - HKLM\..\RunServices: [CRHV.EXE] C:\WINDOWS\SYSTEM\CRHV.EXE
O4 - HKLM\..\RunServices: [MFCDL32.EXE] C:\WINDOWS\MFCDL32.EXE
O4 - HKLM\..\RunServices: [SDKHX.EXE] C:\WINDOWS\SYSTEM\SDKHX.EXE
O4 - HKLM\..\RunServices: [APPQB.EXE] C:\WINDOWS\APPQB.EXE
O4 - HKLM\..\RunServices: [WINLD.EXE] C:\WINDOWS\SYSTEM\WINLD.EXE
O4 - HKLM\..\RunServices: [NETBQ32.EXE] C:\WINDOWS\NETBQ32.EXE
O4 - HKLM\..\RunServices: [JAVAWA32.EXE] C:\WINDOWS\SYSTEM\JAVAWA32.EXE
O4 - HKLM\..\RunServices: [SYSUA.EXE] C:\WINDOWS\SYSUA.EXE
O4 - HKLM\..\RunServices: [NTTG32.EXE] C:\WINDOWS\SYSTEM\NTTG32.EXE
O4 - HKLM\..\RunServices: [WINET32.EXE] C:\WINDOWS\SYSTEM\WINET32.EXE
O4 - HKLM\..\RunServices: [IEYZ32.EXE] C:\WINDOWS\SYSTEM\IEYZ32.EXE
O4 - HKLM\..\RunServices: [D3LH.EXE] C:\WINDOWS\D3LH.EXE
O4 - HKLM\..\RunServices: [MSPS32.EXE] C:\WINDOWS\MSPS32.EXE
O4 - HKLM\..\RunServices: [IPZN.EXE] C:\WINDOWS\IPZN.EXE
O4 - HKLM\..\RunServices: [MFCDR32.EXE] C:\WINDOWS\SYSTEM\MFCDR32.EXE
O4 - HKLM\..\RunServices: [ATLUS32.EXE] C:\WINDOWS\ATLUS32.EXE
O4 - HKLM\..\RunServices: [IEDZ.EXE] C:\WINDOWS\SYSTEM\IEDZ.EXE
O4 - HKLM\..\RunServices: [ADDLA32.EXE] C:\WINDOWS\SYSTEM\ADDLA32.EXE
O4 - HKLM\..\RunServices: [JAVAJW.EXE] C:\WINDOWS\SYSTEM\JAVAJW.EXE
O4 - HKLM\..\RunServices: [MFCUH.EXE] C:\WINDOWS\SYSTEM\MFCUH.EXE
O4 - HKLM\..\RunServices: [D3BU32.EXE] C:\WINDOWS\D3BU32.EXE
O4 - HKLM\..\RunServices: [APPBQ.EXE] C:\WINDOWS\APPBQ.EXE
O4 - HKLM\..\RunServices: [JAVAYR.EXE] C:\WINDOWS\JAVAYR.EXE
O4 - HKLM\..\RunServices: [NTFY32.EXE] C:\WINDOWS\NTFY32.EXE
O4 - HKLM\..\RunServices: [ADDKY.EXE] C:\WINDOWS\ADDKY.EXE
O4 - HKLM\..\RunServices: [JAVAYQ32.EXE] C:\WINDOWS\SYSTEM\JAVAYQ32.EXE
O4 - HKLM\..\RunServices: [ADDEJ32.EXE] C:\WINDOWS\SYSTEM\ADDEJ32.EXE
O4 - HKLM\..\RunServices: [SYSUE.EXE] C:\WINDOWS\SYSUE.EXE
O4 - HKLM\..\RunServices: [CRFJ.EXE] C:\WINDOWS\SYSTEM\CRFJ.EXE
O4 - HKLM\..\RunServices: [ADDRW.EXE] C:\WINDOWS\ADDRW.EXE
O4 - HKLM\..\RunServices: [MSBI32.EXE] C:\WINDOWS\MSBI32.EXE
O4 - HKLM\..\RunServices: [NTMH32.EXE] C:\WINDOWS\NTMH32.EXE
O4 - HKLM\..\RunServices: [NTSG32.EXE] C:\WINDOWS\SYSTEM\NTSG32.EXE
O4 - HKLM\..\RunServices: [D3KG.EXE] C:\WINDOWS\SYSTEM\D3KG.EXE
O4 - HKLM\..\RunServices: [IPXL32.EXE] C:\WINDOWS\SYSTEM\IPXL32.EXE
O4 - HKLM\..\RunServices: [NTVX.EXE] C:\WINDOWS\NTVX.EXE
O4 - HKLM\..\RunServices: [SYSZE32.EXE] C:\WINDOWS\SYSTEM\SYSZE32.EXE
O4 - HKLM\..\RunServices: [MSFQ.EXE] C:\WINDOWS\MSFQ.EXE
O4 - HKLM\..\RunServices: [IPLA.EXE] C:\WINDOWS\SYSTEM\IPLA.EXE
O4 - HKLM\..\RunServices: [WINIJ.EXE] C:\WINDOWS\SYSTEM\WINIJ.EXE
O4 - HKLM\..\RunServices: [MSEX32.EXE] C:\WINDOWS\SYSTEM\MSEX32.EXE
O4 - HKLM\..\RunServices: [SYSBD32.EXE] C:\WINDOWS\SYSTEM\SYSBD32.EXE
O4 - HKLM\..\RunServices: [JAVAPJ32.EXE] C:\WINDOWS\SYSTEM\JAVAPJ32.EXE
O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} (InstallX Class) - http://www.20x2p.com/262095de/enter.cab




Step 2:
I now need you to delete the following files:


C:\WINDOWS\hnvoi.dll
C:\WINDOWS\APPRP.DLL
C:\WINDOWS\ADDMJ32.EXE
C:\WINDOWS\ADDZU.EXE
C:\WINDOWS\ADDCX.EXE
C:\WINDOWS\SYSTEM\D3IP32.EXE
C:\WINDOWS\SYSTEM\IEFW32.EXE
C:\WINDOWS\ATLTC.EXE
C:\WINDOWS\SYSTEM\SYSOC.EXE
C:\WINDOWS\NETSJ32.EXE
C:\WINDOWS\SYSTEM\APPWY32.EXE
C:\WINDOWS\ATLXZ.EXE
C:\WINDOWS\SYSAY.EXE
C:\WINDOWS\SYSTEM\JAVAOA32.EXE
C:\WINDOWS\SYSTEM\IECD32.EXE
C:\WINDOWS\SYSQY32.EXE
C:\WINDOWS\SYSTEM\IEDB.EXE
C:\WINDOWS\SYSTEM\CRHV.EXE
C:\WINDOWS\MFCDL32.EXE
C:\WINDOWS\SYSTEM\SDKHX.EXE
C:\WINDOWS\APPQB.EXE
C:\WINDOWS\SYSTEM\WINLD.EXE
C:\WINDOWS\NETBQ32.EXE
C:\WINDOWS\SYSTEM\JAVAWA32.EXE
C:\WINDOWS\SYSUA.EXE
C:\WINDOWS\SYSTEM\NTTG32.EXE
C:\WINDOWS\SYSTEM\WINET32.EXE
C:\WINDOWS\SYSTEM\IEYZ32.EXE
C:\WINDOWS\D3LH.EXE
C:\WINDOWS\MSPS32.EXE
C:\WINDOWS\IPZN.EXE
C:\WINDOWS\SYSTEM\MFCDR32.EXE
C:\WINDOWS\ATLUS32.EXE
C:\WINDOWS\SYSTEM\IEDZ.EXE
C:\WINDOWS\SYSTEM\ADDLA32.EXE
C:\WINDOWS\SYSTEM\JAVAJW.EXE
C:\WINDOWS\SYSTEM\MFCUH.EXE
C:\WINDOWS\D3BU32.EXE
C:\WINDOWS\APPBQ.EXE
C:\WINDOWS\JAVAYR.EXE
C:\WINDOWS\NTFY32.EXE
C:\WINDOWS\ADDKY.EXE
C:\WINDOWS\SYSTEM\JAVAYQ32.EXE
C:\WINDOWS\SYSTEM\ADDEJ32.EXE
C:\WINDOWS\SYSUE.EXE
C:\WINDOWS\SYSTEM\CRFJ.EXE
C:\WINDOWS\ADDRW.EXE
C:\WINDOWS\MSBI32.EXE
C:\WINDOWS\NTMH32.EXE
C:\WINDOWS\SYSTEM\NTSG32.EXE
C:\WINDOWS\SYSTEM\D3KG.EXE
C:\WINDOWS\SYSTEM\IPXL32.EXE
C:\WINDOWS\NTVX.EXE
C:\WINDOWS\SYSTEM\SYSZE32.EXE
C:\WINDOWS\MSFQ.EXE
C:\WINDOWS\SYSTEM\IPLA.EXE
C:\WINDOWS\SYSTEM\WINIJ.EXE
C:\WINDOWS\SYSTEM\MSEX32.EXE
C:\WINDOWS\SYSTEM\SYSBD32.EXE
C:\WINDOWS\SYSTEM\JAVAPJ32.EXE
If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.

Step 3:

Copy the contents of the Quote Box below to Notepad.
Name the file as fix.reg
Change the Save as Type to All Files
Save this file on the desktop

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW]


Then double-click on the fix.reg file, and when it prompts to merge say yes, and this will clear some registry entries left behind by the process.

Step 4:

This is the step where we will use About:Buster that you had downloaded previously.

Navigate to the c:\aboutbuster directory and double-click on aboutbuster.exe When the tool is open press the OK button, then the Start button, then the OK button, and then finally the Yes button. It will start scanning your computer for files. If it asks if you would like to do a second pass, allow it to do so.

When it completed move on to step 5.


Step 5:
Reboot your computer back to normal mode so that we can restore files that were deleted by this infection:
  • This infection deletes the windows file, shell.dll.

    If you are using XP,2000, or NT please download shell.dll from here: shell-dll.zip. Once the file is downloaded uncompress the zip file and copy shell.dll to the following locations (%windir% being the windows or winnt directory):

    %windir%\system32
    %windir%\system

    If you are using Windows 98 please download shell.dll from here: shell-dll98.zip. Once the file is downloaded uncompress the zip file and copy shell.dll to the following locations (%windir% being the windows or winnt directory):

    %windir%\system

    If you are using Windows ME please download shell.dll from here: shell-dll98.zip. Once the file is downloaded uncompress the zip file and copy shell.dll to the following locations (%windir% being the windows or winnt directory):

    %windir%\system

  • Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original deleted Hosts file.

  • If you have Spybot S&D installed you will also need to replace one file. Go here: SDHelper.zip and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy). Then click Start > Run > regsvr32 "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" and press the OK button

  • If you are using Windows 95, 98, or ME it is possible that the malware deleted your control.exe. Please check for the existence of this file by going to to Merijn Files control.exe and examine where the file should be for your operating system. If the file is missing then download the appropriate file and place it in the proper place according to this information.
Step 6:

Run an online antivirus scan at:

http://housecall.antivirus.com/

Reboot and post a last log

#9 jlinton

jlinton
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:56 PM

Posted 21 February 2005 - 11:32 PM

Grinler;
Ok, that was a whole lot of fun...NOT!!!!! It had changed again since last posting, so cleaned those extras out as well. Kinda got the gist of how it works and pretty sure I got them all. Been holding my breath....1st time in days computer has started without that damn page! Does this mean it's really gone, or am I just foolin myself?
Ran the online scan and there's still trojan files that it couldn't delete. Should I go ahead and delete these manualy?
Anyhoo, here's the latest HJT log. Thanks

Logfile of HijackThis v1.99.1
Scan saved at 11:17:45 PM, on 2/21/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\USBMONIT.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\SYMPATICO STARTER KIT\BIN\CONFSVR.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\SYMPATICO STARTER KIT\BIN\GBCONMON.EXE
C:\PROGRAM FILES\SYMPATICO STARTER KIT\BIN\GBTASK.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS\HIJACKTHIS.EXE

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINDOWS\SYSTEM\USBMonit.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [Gearbox] "C:\Program Files\Sympatico Starter Kit\bin\confsvr.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [Gearbox Deferal Check] C:\Program Files\Sympatico Starter Kit\bin\gbdefer.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Corel MEDIA FOLDERS INDEXER 8.LNK = C:\Corel\Graphics8\Programs\MFIndexer.exe
O4 - Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\SYSTEM\E_SRCV03.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by1fd.bay1.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab

#10 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,389 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:12:56 PM

Posted 22 February 2005 - 11:24 AM

Log looks clean...great job!

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and reenable system restore to make sure there are no infected files found in a restore point.

    You can find instructions on how to enable and reenable system restore here:

    Managing Windows Millenium System Restore

    or

    Windows XP System Restore Guide

    Renable system restore with instructions from tutorial above

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Commercial Spyware Removal/Protection Programs - If you feel more comfortable installing a commercial Spyware removal program then we recommend WebRoot's Spysweeper or Lavasoft's Ad-Aware Professional. There are many commercial products on the market, but unfortunately most are misleading and substandard. Both of the products we recommend here are proven to be excellent products and a worthy addition to the arsenal of software protecting your computer.

    Spysweeper Product Information
    Ad-Aware Pro Production Information


  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help.

#11 jlinton

jlinton
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:56 PM

Posted 22 February 2005 - 01:45 PM

Grinler,
Many, many thanks for all the guidance, couldn't have done it without your expertise! Kudos to an awesome site!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users