Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HijackThis Log: Please help Diagnose


  • Please log in to reply
9 replies to this topic

#1 muellertime

muellertime

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:17 AM

Posted 17 March 2005 - 10:35 AM

I have been trying for several days to get rid of this "about:blank" variant, and need some help, please. I have gone through the detailed instructions found in the tutorial section so many times I have lost track, and it just keeps coming back. I have installed and run all the sugessted spyware programs, and they find this bug, remove it and then it comes back.
The program "WinPatrol" keeps giving me a pop-up that warns me of the new bug, "se.dll" and I keep deleting it and it continues to re-name itself and come back with a vengance.
Here is the current status:
I have turned off all of the spyware programs to let the "bug" run wild. I have saved the HJT log and posted it below. I am running Win 98SE and have restarted in SafeMode and run HJT and deleted (fixed) all of the R0 and R1 lines, all of the 02 lines, the 04 line that has the "se.dll" command and the last 2 018 lines.
I then go back and delete the files that it finds, and run CWShredder (2.12), which finds nothing. Then I run "Cleanup" and "AboutBuster" and then scan with the latest version of Ad-AwareSE and Webroot's Spy Sweeper.
when I reboot in normal mode. Spy Sweeper finds "CWS" and the whole thing starts again.
Here is the HJT log before:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {5050A3A3-B067-4EB5-8687-756A96D2453E} - C:\WINDOWS\SYSTEM\EKPMFA.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN0\YCOMP5_6_0_0.DLL (file missing)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\winpatrol.exe
O4 - HKLM\..\Run: [pccguide.exe] C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SPYSWEEPER.EXE /1
O4 - HKCU\..\RunServices: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SPYSWEEPER.EXE /1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O8 - Extra context menu item: Convert for CLIÉ - C:\Program Files\Sony\Image Converter\menu.htm
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {3EB4F9EA-51A6-48DA-846A-0D69DCBA39EF} (DownloadManager Control) - http://download.akamaitools.com.edgesuite....loadManager.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/...tterInstall.cab
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/US/install.cab
O18 - Filter: text/html - {AE47EBE9-3227-4FEA-8597-5984DFF56095} - C:\WINDOWS\SYSTEM\EKPMFA.DLL
O18 - Filter: text/plain - {AE47EBE9-3227-4FEA-8597-5984DFF56095} - C:\WINDOWS\SYSTEM\EKPMFA.DLL

Please help me determine what it is that I am missing, or not finding, so that I can have my computer back.....Please!

Thank you!!

BC AdBot (Login to Remove)

 


#2 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,618 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:02:17 AM

Posted 17 March 2005 - 12:34 PM

Please post a complete HJT log. This log is not complete.

#3 muellertime

muellertime
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:17 AM

Posted 21 March 2005 - 02:44 PM

OK, sorry about that....here is the current log. I have read the other posts, removed everything, even re-installed Windows and Internet Explorer. After a period of time, usually a couple of hours, it comes back.
It always runs in the "rundll32" file and the "se.dll" somehow, and CounterSpy finds it as the "Spooner-A" if that helps at all.
Please Help me, this thing is driving me NUTS!!



Logfile of HijackThis v1.99.1
Scan saved at 12:22:36 PM, on 3/21/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\MY DOWNLOAD FILES\PROTECTION\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {E0498660-9A01-11D9-9E8E-0060DBE9B6ED} - C:\WINDOWS\SYSTEM\HCCKF.DLL
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\winpatrol.exe
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O8 - Extra context menu item: Convert for CLIÉ - C:\Program Files\Sony\Image Converter\menu.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {3EB4F9EA-51A6-48DA-846A-0D69DCBA39EF} (DownloadManager Control) - http://download.akamaitools.com.edgesuite....loadManager.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/...tterInstall.cab
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/US/install.cab
O18 - Filter: text/html - {565CAFE1-9A01-11D9-9E8E-0060BD88FC11} - C:\WINDOWS\SYSTEM\HCCKF.DLL
O18 - Filter: text/plain - {565CAFE1-9A01-11D9-9E8E-0060BD88FC11} - C:\WINDOWS\SYSTEM\HCCKF.DLL

#4 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,618 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:02:17 AM

Posted 21 March 2005 - 02:57 PM

Please follow these steps:


1. Download: "StartDreck" from:

http://www.niksoft.at/download/startdreck.htm

2. Extract the file into c:\startdreck.

3. Navigate to c:\startdreck and double-click on Startdreck.exe

4. When the program opens click on the Config button.

5. Then click on the unmark all button.

6. Then put checkmarks in the following checkboxes:

Under Registry put a checkmark in the Run Keys checkbox.

Under System/Drivers put a check in the Running Proccess checkbox.

7. Press the OK button.

8. Press the Save button. Type in the location you want to save the log to, or use the defaults which will save the log into the directory you are running the program from. If you choose the defaults the filename for the log will be StartDreck.log.

9. Post a copy of the log as a reply to this post.

#5 muellertime

muellertime
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:17 AM

Posted 21 March 2005 - 03:16 PM

Startdreck log below....

StartDreck (build 2.1.7 public stable) - 2005-03-21 @ 13:10:11 (GMT -07:00)
Platform: Windows 98 SE (Win 4.10.2222 A)
Internet Explorer: 6.0.2800.1106
Logged in as Scott at MUELLERTIME

»Registry
»Run Keys
»Current User
»Run
»RunOnce
»Default User
»Run
»RunOnce
»Local Machine
»Run
*SystemTray=SysTray.Exe
*ATIPTA=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
*WinPatrol=C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\winpatrol.exe
*ScanRegistry=c:\windows\scanregw.exe /autorun
*TaskMonitor=c:\windows\taskmon.exe
*sp=rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
+OptionalComponents
+IMAIL
*Installed=1
+MAPI
*NoChange=1
*Installed=1
+MAPI
*NoChange=1
*Installed=1
»RunOnce
»RunServices
»RunServicesOnce
**lwf=rundll32 C:\WINDOWS\NETWOLK.TXT,DllGetClassObject
»RunOnceEx
»RunServicesOnceEx
»Files
»System/Drivers
»Running Processes
+FF8F25F9=C:\WINDOWS\SYSTEM\KERNEL32.DLL
+FFFFE1AD=C:\WINDOWS\SYSTEM\MSGSRV32.EXE
+FFFFFE39=C:\WINDOWS\SYSTEM\MPREXE.EXE
+FFFFA40D=C:\WINDOWS\SYSTEM\mmtask.tsk
+FFFC76A5=C:\WINDOWS\EXPLORER.EXE
+FFFC7915=C:\WINDOWS\RUNDLL32.EXE
+FFFCA1B1=C:\WINDOWS\SYSTEM\SYSTRAY.EXE
+FFFD5001=C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
+FFFD03A5=C:\WINDOWS\TASKMON.EXE
+FFFD1659=C:\WINDOWS\RUNDLL32.EXE
+FFFD8F29=C:\WINDOWS\SYSTEM\DDHELP.EXE
+FFF25615=C:\WINDOWS\SYSTEM\WMIEXE.EXE
+FFFF9B35=C:\WINDOWS\NOTEPAD.EXE
+FFF22FB1=C:\STARTDRECK\STARTDRECK.EXE
»Application specific

#6 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,618 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:02:17 AM

Posted 21 March 2005 - 03:21 PM

Download the following file:

http://www.derbilk.de/SpSeHjfix_Beta9.zip

Extract it and run and then post the resulting log along with a new startdreck log

#7 muellertime

muellertime
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:17 AM

Posted 21 March 2005 - 04:29 PM

When this new program ran, it actually saved 2 files. The first was a log:



(3/21/05 2:12:02 PM) SPSeHjFix started v1.09
(3/21/05 2:12:02 PM) OS: Win98SE A (4.10.67766446)
(3/21/05 2:12:02 PM) Language: english
(3/21/05 2:12:17 PM) Disinfect started
(3/21/05 2:12:17 PM) Bad-Dll(IEP): se.dll
(3/21/05 2:12:17 PM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\SYSTEM\HCCKF.DLL
(3/21/05 2:12:17 PM) Searchassistant Uninstaller - Keys Deleted
(3/21/05 2:12:17 PM) UBF: 6
(3/21/05 2:12:17 PM) UBB: 0
(3/21/05 2:12:17 PM) FilterKey: HKCR\text/html (deleted)
(3/21/05 2:12:17 PM) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(3/21/05 2:12:17 PM) FilterKey: HKCR\CLSID\{565CAFE1-9A01-11D9-9E8E-0060BD88FC11} (deleted)
(3/21/05 2:12:17 PM) FilterKey: HKCR\text/plain (deleted)
(3/21/05 2:12:17 PM) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(3/21/05 2:12:17 PM) FilterKey: HKCR\CLSID\{565CAFE1-9A01-11D9-9E8E-0060BD88FC11} (error while deleting)
(3/21/05 2:12:17 PM) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1B9C0320-9A0A-11D9-9E8E-0060EAC2922B} (deleted)
(3/21/05 2:12:17 PM) BHO-Key: HKCR\CLSID\{1B9C0320-9A0A-11D9-9E8E-0060EAC2922B} (deleted)
(3/21/05 2:12:17 PM) UBR: 6
(3/21/05 2:12:17 PM) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall (deleted)
(3/21/05 2:12:17 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\TEMP\se.dll/sp.html
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\TEMP\se.dll/sp.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(3/21/05 2:12:17 PM) Stealth-String found: C:\WINDOWS\NETWOLK.TXT
(3/21/05 2:12:17 PM) File added to delete: c:\windows\system\hcckf.dll
(3/21/05 2:12:17 PM) File added to delete: c:\windows\system\hcckf.dll
(3/21/05 2:12:17 PM) File added to delete: c:\windows\temp\se.dll
(3/21/05 2:12:17 PM) File added to delete: c:\windows\netwolk.txt
(3/21/05 2:12:17 PM) Reboot


Then it gave me a text file called "bad_dll" which contained only one line:

C:\WINDOWS\NETWOLK.TXT

The computer then re-booted, and I ran startdreck, which produced the following log file:

StartDreck (build 2.1.7 public stable) - 2005-03-21 @ 14:20:39 (GMT -07:00)
Platform: Windows 98 SE (Win 4.10.2222 A)
Internet Explorer: 6.0.2800.1106
Logged in as Scott at MUELLERTIME

»Registry
»Run Keys
»Current User
»Run
»RunOnce
»Default User
»Run
»RunOnce
»Local Machine
»Run
*SystemTray=SysTray.Exe
*ATIPTA=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
*WinPatrol=C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\winpatrol.exe
*ScanRegistry=c:\windows\scanregw.exe /autorun
*TaskMonitor=c:\windows\taskmon.exe
*sp=rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
+OptionalComponents
+IMAIL
*Installed=1
+MAPI
*NoChange=1
*Installed=1
+MAPI
*NoChange=1
*Installed=1
»RunOnce
»RunServices
»RunServicesOnce
»RunOnceEx
»RunServicesOnceEx
»Files
»System/Drivers
»Running Processes
+FF8F244B=C:\WINDOWS\SYSTEM\KERNEL32.DLL
+FFFFE01F=C:\WINDOWS\SYSTEM\MSGSRV32.EXE
+FFFFFF8B=C:\WINDOWS\SYSTEM\MPREXE.EXE
+FFFFA5BF=C:\WINDOWS\SYSTEM\mmtask.tsk
+FFFC2E93=C:\WINDOWS\EXPLORER.EXE
+FFFCD5BF=C:\WINDOWS\SYSTEM\SYSTRAY.EXE
+FFFC82AB=C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
+FFFC8A9B=C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\WINPATROL.EXE
+FFFCB52B=C:\WINDOWS\TASKMON.EXE
+FFFD17B3=C:\WINDOWS\SYSTEM\DDHELP.EXE
+FFFFAF27=C:\WINDOWS\SYSTEM\WMIEXE.EXE
+FFF26153=C:\STARTDRECK\STARTDRECK.EXE
»Application specific


HOWEVER, when I re-booted, it says that the computer has been dis-infected but WinPatrol tells me that se.dll keeps wanting to open.....

#8 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,618 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:02:17 AM

Posted 21 March 2005 - 10:07 PM

I know...we will fix that quickly. POst a new hjt log

#9 muellertime

muellertime
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:17 AM

Posted 22 March 2005 - 09:10 AM

It looks like it may be gone...finally!

Logfile of HijackThis v1.99.1
Scan saved at 6:51:58 AM, on 3/22/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\WINPATROL.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\MY DOWNLOAD FILES\PROTECTION\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN2\YCOMP5_6_0_0.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN2\YCOMP5_6_0_0.DLL
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\winpatrol.exe
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O8 - Extra context menu item: Convert for CLIÉ - C:\Program Files\Sony\Image Converter\menu.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {3EB4F9EA-51A6-48DA-846A-0D69DCBA39EF} (DownloadManager Control) - http://download.akamaitools.com.edgesuite....loadManager.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/...tterInstall.cab
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/US/install.cab

#10 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,618 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:02:17 AM

Posted 22 March 2005 - 11:17 AM

Fix these and your clean:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/...tterInstall.cab


Log looks clean...great job!

Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and reenable system restore to make sure there are no infected files found in a restore point.

You can find instructions on how to enable and reenable system restore here:

Managing Windows Millenium System Restore

or

Windows XP System Restore Guide

Renable system restore with instructions from tutorial above


Next,

This process will clean out your Temp files and your Temporary Internet Files. Please do both steps:

Step 1:Delete Temp Files
To clean out your temp files, click on Start and then run, and type %temp% and press the ok button.

This should open up the temp directory that your machine uses. Please delete all files that are found there. If you get an error when deleting a file, skip that file and delete all the others. If you had trouble deleting a file, reboot into Safe Mode and follow this step again. You should now be able to delete all the files.

Step 2: Delete Temporary Internet Files
Now I want you to open up Internet Explorer, and click on the Tools menu and then Internet Options. At the General tab, which should be the first tab you are currently on, click on the Delete Files button and put a checkmark in Delete offline content. Then press the OK button. This may take quite a while, so do not be alarmed with how long it takes. When it is done, your Temporary Internet Files will now be deleted.

Finally, and definitely the MOST IMPORTANT step, click on the following tutorial and follow each step listed there:

Simple and easy ways to keep your computer safe and secure on the Internet


Glad I was able to help.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users