Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Several Problems


  • Please log in to reply
5 replies to this topic

#1 wds

wds

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:06:26 AM

Posted 20 May 2005 - 05:32 PM

Windows 98 SE machine with several problems. Slow, lost connectivity to network printer.... Here is the HJT log.

WDS
Logfile of HijackThis v1.99.1
Scan saved at 4:27:05 PM, on 05/20/2005
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\RTVSCN95.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\DEFWATCH.EXE
C:\WINDOWS\SYSTEM\ATLWK.EXE
C:\WINDOWS\NETAD32.EXE
C:\WINDOWS\JAVATM.EXE
C:\WINDOWS\SYSTEM\WINFQ32.EXE
C:\WINDOWS\SYSTEM\APPTC32.EXE
C:\WINDOWS\SYSTEM\APPNI.EXE
C:\WINDOWS\CRYV.EXE
C:\WINDOWS\APPQV32.EXE
C:\WINDOWS\JAVAZV.EXE
C:\WINDOWS\SYSTEM\ATLED.EXE
C:\WINDOWS\SYSTEM\CRDY.EXE
C:\WINDOWS\MSTM.EXE
C:\WINDOWS\JAVADP32.EXE
C:\WINDOWS\SYSTEM\APPKI.EXE
C:\WINDOWS\ADDEN.EXE
C:\WINDOWS\SYSTEM\NETXR.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\SBMX.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\VPTRAY.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\IESB.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\ADDEN.EXE
C:\WINDOWS\SYSTEM\ATLWK.EXE
C:\WINDOWS\NETAD32.EXE
C:\WINDOWS\SYSTEM\ATLLL.EXE
C:\WINDOWS\MSTM.EXE
C:\WINDOWS\SYSTEM\NETXR.EXE
C:\WINDOWS\SYSTEM\CRDY.EXE
C:\WINDOWS\NETAD32.EXE
C:\WINDOWS\MSMU32.EXE
C:\WINDOWS\MSMU32.EXE
C:\WINDOWS\MSTM.EXE
C:\WINDOWS\ADDEN.EXE
C:\WINDOWS\JAVANP.EXE
C:\WINDOWS\SYSTEM\NETXR.EXE
C:\WINDOWS\SYSTEM\CRDY.EXE
C:\WINDOWS\NETAD32.EXE
C:\WINDOWS\ATLMX32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\NETXR.EXE
C:\WINDOWS\IPNW.EXE
C:\WINDOWS\IPNW.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\wqbqu.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\wqbqu.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\wqbqu.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\wqbqu.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\wqbqu.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\wqbqu.dll/sp.html#28129
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {3961D259-E678-4571-8985-CC45A0FEBCF4} - C:\WINDOWS\APPNS32.DLL
O2 - BHO: Class - {44B10FE2-CB48-98A4-AC3B-F7905A256627} - C:\WINDOWS\SYSTEM\D3OY32.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN0\YCOMP5_6_0_0.DLL (file missing)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SBMX] C:\WINDOWS\SYSTEM\sbmx.exe
O4 - HKLM\..\Run: [LexStart] LexStart.EXE
O4 - HKLM\..\Run: [vptray] c:\Program Files\Norton AntiVirus\vptray.exe
O4 - HKLM\..\Run: [Client Access Service] "C:\Program Files\IBM\Client Access\cwbsvstr.exe"
O4 - HKLM\..\Run: [Client Access Help Update] "C:\Program Files\IBM\Client Access\cwbinhlp.exe"
O4 - HKLM\..\Run: [Client Access Check Version] "C:\Program Files\IBM\Client Access\cwbckver.exe" LOGIN
O4 - HKLM\..\Run: [Client Access Express Welcome] "C:\Program Files\IBM\Client Access\cwbwlwiz.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IESB.EXE] C:\WINDOWS\SYSTEM\IESB.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [rtvscn95] c:\Program Files\Norton AntiVirus\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] c:\Program Files\Norton AntiVirus\defwatch.exe
O4 - HKLM\..\RunServices: [Client Access Start Incoming RC] ###C:\WINDOWS\command\start.exe /MINIMIZED C:\WINDOWS\cwbrxd.exe
O4 - HKLM\..\RunServices: [ATLWK.EXE] C:\WINDOWS\SYSTEM\ATLWK.EXE /s
O4 - HKLM\..\RunServices: [NETAD32.EXE] C:\WINDOWS\NETAD32.EXE /s
O4 - HKLM\..\RunServices: [JAVATM.EXE] C:\WINDOWS\JAVATM.EXE /s
O4 - HKLM\..\RunServices: [WINFQ32.EXE] C:\WINDOWS\SYSTEM\WINFQ32.EXE /s
O4 - HKLM\..\RunServices: [APPTC32.EXE] C:\WINDOWS\SYSTEM\APPTC32.EXE /s
O4 - HKLM\..\RunServices: [APPNI.EXE] C:\WINDOWS\SYSTEM\APPNI.EXE /s
O4 - HKLM\..\RunServices: [CRYV.EXE] C:\WINDOWS\CRYV.EXE /s
O4 - HKLM\..\RunServices: [APPQV32.EXE] C:\WINDOWS\APPQV32.EXE /s
O4 - HKLM\..\RunServices: [JAVAZV.EXE] C:\WINDOWS\JAVAZV.EXE /s
O4 - HKLM\..\RunServices: [ATLED.EXE] C:\WINDOWS\SYSTEM\ATLED.EXE /s
O4 - HKLM\..\RunServices: [CRDY.EXE] C:\WINDOWS\SYSTEM\CRDY.EXE /s
O4 - HKLM\..\RunServices: [MSTM.EXE] C:\WINDOWS\MSTM.EXE /s
O4 - HKLM\..\RunServices: [JAVADP32.EXE] C:\WINDOWS\JAVADP32.EXE /s
O4 - HKLM\..\RunServices: [APPKI.EXE] C:\WINDOWS\SYSTEM\APPKI.EXE /s
O4 - HKLM\..\RunServices: [ADDEN.EXE] C:\WINDOWS\ADDEN.EXE /s
O4 - HKLM\..\RunServices: [NETXR.EXE] C:\WINDOWS\SYSTEM\NETXR.EXE /s
O4 - HKLM\..\RunServices: [ATLLL.EXE] C:\WINDOWS\SYSTEM\ATLLL.EXE /s
O4 - HKLM\..\RunServices: [MSMU32.EXE] C:\WINDOWS\MSMU32.EXE /s
O4 - HKLM\..\RunServices: [JAVANP.EXE] C:\WINDOWS\JAVANP.EXE /s
O4 - HKLM\..\RunServices: [ATLMX32.EXE] C:\WINDOWS\ATLMX32.EXE /s
O4 - HKLM\..\RunServices: [IPNW.EXE] C:\WINDOWS\IPNW.EXE /s
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Sikeston Desktop Alert.lnk = C:\Program Files\Sikeston Desktop Alert\TrueWeather.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://carpoint.msn.com/Components/Ocx/Exterior/Outside.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://carpoint.msn.com/Components/Ocx/SurVid/MSSurVid.cab
O16 - DPF: {22D6F312-B0F6-11D0-94AB-0080C74C7E95} (Windows Media Player) - http://activex.microsoft.com/activex/contr...en/nsmp2inf.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...etup1.0.0.8.exe
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www5.incredimail.com/contents/setup...p1/imloader.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_...aploader_v6.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://66.35.183.172/activex/AxisCamControl.cab
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} (SbInstObj) - http://installs.spamblockerutility.com/ins...ckerutility.cab
O16 - DPF: {69FD62B1-0216-4C31-8D55-840ED86B7C8F} (HbInstObj) - http://installs.hotbar.com/installs/hotbar...rams/hotbar.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = sbmu.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.151.44.9,69.60.160.196

BC AdBot (Login to Remove)

 


#2 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:07:26 AM

Posted 20 May 2005 - 11:10 PM

Hello wds and welcome to the BC forums. After reviewing your log I see a few items that require our attention. Let's start with a CWS scan.

Download Cwshredder.exe and save it to a folder of its own. Start the program and click on the Check for Update button. If an update is available then download and install it.

Start in Safe Mode Using the F8 method:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until the boot menu appears.
  • Use the arrow keys to select the Safe Mode menu item.
  • Press the Enter key.
Run CWShredder
  • Double-click on CWShredder.exe.
  • Click "Fix ->" and click "OK" at the prompt.
  • CWShredder will scan and clean your system of CWS files.
  • Click "Next->" and then "Exit".
OK. Reboot your computer normally, start HijackThis and perform a new scan. Use the Add Reply button to post your new log file back here along with details of any problems you encountered performing the above steps and I will review it when it comes in.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#3 wds

wds
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:06:26 AM

Posted 21 May 2005 - 08:45 AM

OT
Here is the HJT Log after running CW Shredder. No problems encountered.
WDS

Logfile of HijackThis v1.99.1
Scan saved at 8:35:33 AM, on 05/21/2005
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\RTVSCN95.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\DEFWATCH.EXE
C:\WINDOWS\SYSTEM\ATLWK.EXE
C:\WINDOWS\NETAD32.EXE
C:\WINDOWS\JAVATM.EXE
C:\WINDOWS\SYSTEM\WINFQ32.EXE
C:\WINDOWS\SYSTEM\APPTC32.EXE
C:\WINDOWS\SYSTEM\APPNI.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\CRYV.EXE
C:\WINDOWS\APPQV32.EXE
C:\WINDOWS\JAVAZV.EXE
C:\WINDOWS\SYSTEM\ATLED.EXE
C:\WINDOWS\SYSTEM\CRDY.EXE
C:\WINDOWS\MSTM.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\JAVADP32.EXE
C:\WINDOWS\SYSTEM\APPKI.EXE
C:\WINDOWS\ADDEN.EXE
C:\WINDOWS\SYSTEM\NETXR.EXE
C:\WINDOWS\SYSTEM\ATLLL.EXE
C:\WINDOWS\MSMU32.EXE
C:\WINDOWS\JAVANP.EXE
C:\WINDOWS\ATLMX32.EXE
C:\WINDOWS\IPNW.EXE
C:\WINDOWS\NETIK32.EXE
C:\WINDOWS\WINSH.EXE
C:\WINDOWS\SYSQK.EXE
C:\WINDOWS\MFCZV32.EXE
C:\WINDOWS\JAVALL32.EXE
C:\WINDOWS\SYSTEM\NETOL.EXE
C:\WINDOWS\NETPP.EXE
C:\WINDOWS\SYSTEM\CRNC32.EXE
C:\WINDOWS\JAVABT.EXE
C:\WINDOWS\SYSTEM\NTYI.EXE
C:\WINDOWS\SYSTEM\WINLV32.EXE
C:\WINDOWS\APIRG.EXE
C:\WINDOWS\MSCU.EXE
C:\WINDOWS\NTLI.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\SBMX.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\VPTRAY.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\IESB.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\ATLMX32.EXE
C:\WINDOWS\SYSTEM\ATLWK.EXE
C:\WINDOWS\SYSTEM\NETXR.EXE
C:\WINDOWS\APPWN32.EXE
C:\HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\yzbhh.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\yzbhh.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\yzbhh.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\yzbhh.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\yzbhh.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\yzbhh.dll/sp.html#28129
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {8CB84857-78A5-7B94-ADC9-547BABDB5BC0} - C:\WINDOWS\ADDPO32.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN0\YCOMP5_6_0_0.DLL (file missing)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SBMX] C:\WINDOWS\SYSTEM\sbmx.exe
O4 - HKLM\..\Run: [LexStart] LexStart.EXE
O4 - HKLM\..\Run: [vptray] c:\Program Files\Norton AntiVirus\vptray.exe
O4 - HKLM\..\Run: [Client Access Service] "C:\Program Files\IBM\Client Access\cwbsvstr.exe"
O4 - HKLM\..\Run: [Client Access Help Update] "C:\Program Files\IBM\Client Access\cwbinhlp.exe"
O4 - HKLM\..\Run: [Client Access Check Version] "C:\Program Files\IBM\Client Access\cwbckver.exe" LOGIN
O4 - HKLM\..\Run: [Client Access Express Welcome] "C:\Program Files\IBM\Client Access\cwbwlwiz.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IESB.EXE] C:\WINDOWS\SYSTEM\IESB.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [rtvscn95] c:\Program Files\Norton AntiVirus\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] c:\Program Files\Norton AntiVirus\defwatch.exe
O4 - HKLM\..\RunServices: [Client Access Start Incoming RC] ###C:\WINDOWS\command\start.exe /MINIMIZED C:\WINDOWS\cwbrxd.exe
O4 - HKLM\..\RunServices: [ATLWK.EXE] C:\WINDOWS\SYSTEM\ATLWK.EXE /s
O4 - HKLM\..\RunServices: [NETAD32.EXE] C:\WINDOWS\NETAD32.EXE /s
O4 - HKLM\..\RunServices: [JAVATM.EXE] C:\WINDOWS\JAVATM.EXE /s
O4 - HKLM\..\RunServices: [WINFQ32.EXE] C:\WINDOWS\SYSTEM\WINFQ32.EXE /s
O4 - HKLM\..\RunServices: [APPTC32.EXE] C:\WINDOWS\SYSTEM\APPTC32.EXE /s
O4 - HKLM\..\RunServices: [APPNI.EXE] C:\WINDOWS\SYSTEM\APPNI.EXE /s
O4 - HKLM\..\RunServices: [CRYV.EXE] C:\WINDOWS\CRYV.EXE /s
O4 - HKLM\..\RunServices: [APPQV32.EXE] C:\WINDOWS\APPQV32.EXE /s
O4 - HKLM\..\RunServices: [JAVAZV.EXE] C:\WINDOWS\JAVAZV.EXE /s
O4 - HKLM\..\RunServices: [ATLED.EXE] C:\WINDOWS\SYSTEM\ATLED.EXE /s
O4 - HKLM\..\RunServices: [CRDY.EXE] C:\WINDOWS\SYSTEM\CRDY.EXE /s
O4 - HKLM\..\RunServices: [MSTM.EXE] C:\WINDOWS\MSTM.EXE /s
O4 - HKLM\..\RunServices: [JAVADP32.EXE] C:\WINDOWS\JAVADP32.EXE /s
O4 - HKLM\..\RunServices: [APPKI.EXE] C:\WINDOWS\SYSTEM\APPKI.EXE /s
O4 - HKLM\..\RunServices: [ADDEN.EXE] C:\WINDOWS\ADDEN.EXE /s
O4 - HKLM\..\RunServices: [NETXR.EXE] C:\WINDOWS\SYSTEM\NETXR.EXE /s
O4 - HKLM\..\RunServices: [ATLLL.EXE] C:\WINDOWS\SYSTEM\ATLLL.EXE /s
O4 - HKLM\..\RunServices: [MSMU32.EXE] C:\WINDOWS\MSMU32.EXE /s
O4 - HKLM\..\RunServices: [JAVANP.EXE] C:\WINDOWS\JAVANP.EXE /s
O4 - HKLM\..\RunServices: [ATLMX32.EXE] C:\WINDOWS\ATLMX32.EXE /s
O4 - HKLM\..\RunServices: [IPNW.EXE] C:\WINDOWS\IPNW.EXE /s
O4 - HKLM\..\RunServices: [NETIK32.EXE] C:\WINDOWS\NETIK32.EXE /s
O4 - HKLM\..\RunServices: [WINSH.EXE] C:\WINDOWS\WINSH.EXE /s
O4 - HKLM\..\RunServices: [SYSQK.EXE] C:\WINDOWS\SYSQK.EXE /s
O4 - HKLM\..\RunServices: [MFCZV32.EXE] C:\WINDOWS\MFCZV32.EXE /s
O4 - HKLM\..\RunServices: [JAVALL32.EXE] C:\WINDOWS\JAVALL32.EXE /s
O4 - HKLM\..\RunServices: [NETOL.EXE] C:\WINDOWS\SYSTEM\NETOL.EXE /s
O4 - HKLM\..\RunServices: [NETPP.EXE] C:\WINDOWS\NETPP.EXE /s
O4 - HKLM\..\RunServices: [CRNC32.EXE] C:\WINDOWS\SYSTEM\CRNC32.EXE /s
O4 - HKLM\..\RunServices: [JAVABT.EXE] C:\WINDOWS\JAVABT.EXE /s
O4 - HKLM\..\RunServices: [NTYI.EXE] C:\WINDOWS\SYSTEM\NTYI.EXE /s
O4 - HKLM\..\RunServices: [WINLV32.EXE] C:\WINDOWS\SYSTEM\WINLV32.EXE /s
O4 - HKLM\..\RunServices: [APIRG.EXE] C:\WINDOWS\APIRG.EXE /s
O4 - HKLM\..\RunServices: [MSCU.EXE] C:\WINDOWS\MSCU.EXE /s
O4 - HKLM\..\RunServices: [NTLI.EXE] C:\WINDOWS\NTLI.EXE /s
O4 - HKLM\..\RunServices: [APPWN32.EXE] C:\WINDOWS\APPWN32.EXE /s
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Sikeston Desktop Alert.lnk = C:\Program Files\Sikeston Desktop Alert\TrueWeather.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://carpoint.msn.com/Components/Ocx/Exterior/Outside.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://carpoint.msn.com/Components/Ocx/SurVid/MSSurVid.cab
O16 - DPF: {22D6F312-B0F6-11D0-94AB-0080C74C7E95} (Windows Media Player) - http://activex.microsoft.com/activex/contr...en/nsmp2inf.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...etup1.0.0.8.exe
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www5.incredimail.com/contents/setup...p1/imloader.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_...aploader_v6.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://66.35.183.172/activex/AxisCamControl.cab
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} (SbInstObj) - http://installs.spamblockerutility.com/ins...ckerutility.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = sbmu.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.151.44.9,69.60.160.196

#4 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:07:26 AM

Posted 21 May 2005 - 03:33 PM

Hi wds. Wow, that didn't even budge this thing. Let's try one more program before we have to do this all manually.

Step #1

Download About:Buster.zip and unzip it to its own directory.
Now run AboutBuster and save the logs:
  • Browse to where you saved AboutBuster and run AboutBuster.exe.
  • Click "OK" at the directions Read: Important! prompt.
  • Click the Update button to check for updates and install any that are available.
  • Click "Start" and then "OK" to allow AboutBuster to scan for Alternate Data Streams.
  • Click "Yes" at the About:Buster prompt to allow it to shutdown explorer.exe.
  • Please wait while AboutBuster scans your computer for malicious files. If it asks if you would like to do a second pass, allow it to do so.
  • When it has finished, click "Save Log...". Make sure you save it as I will need a copy of it.
  • Click "Exit" and "Exit" again to exit AboutBuster.
Step #2

Now start HijackThis and click the Scan button to perform a scan. Look for the following items and click in the checkbox in front of each item to select it:R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\yzbhh.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\yzbhh.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\yzbhh.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\yzbhh.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\yzbhh.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\yzbhh.dll/sp.html#28129
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {8CB84857-78A5-7B94-ADC9-547BABDB5BC0} - C:\WINDOWS\ADDPO32.DLL
O4 - HKLM\..\Run: [IESB.EXE] C:\WINDOWS\SYSTEM\IESB.EXE
O4 - HKLM\..\RunServices: [ATLWK.EXE] C:\WINDOWS\SYSTEM\ATLWK.EXE /s
O4 - HKLM\..\RunServices: [NETAD32.EXE] C:\WINDOWS\NETAD32.EXE /s
O4 - HKLM\..\RunServices: [JAVATM.EXE] C:\WINDOWS\JAVATM.EXE /s
O4 - HKLM\..\RunServices: [WINFQ32.EXE] C:\WINDOWS\SYSTEM\WINFQ32.EXE /s
O4 - HKLM\..\RunServices: [APPTC32.EXE] C:\WINDOWS\SYSTEM\APPTC32.EXE /s
O4 - HKLM\..\RunServices: [APPNI.EXE] C:\WINDOWS\SYSTEM\APPNI.EXE /s
O4 - HKLM\..\RunServices: [CRYV.EXE] C:\WINDOWS\CRYV.EXE /s
O4 - HKLM\..\RunServices: [APPQV32.EXE] C:\WINDOWS\APPQV32.EXE /s
O4 - HKLM\..\RunServices: [JAVAZV.EXE] C:\WINDOWS\JAVAZV.EXE /s
O4 - HKLM\..\RunServices: [ATLED.EXE] C:\WINDOWS\SYSTEM\ATLED.EXE /s
O4 - HKLM\..\RunServices: [CRDY.EXE] C:\WINDOWS\SYSTEM\CRDY.EXE /s
O4 - HKLM\..\RunServices: [MSTM.EXE] C:\WINDOWS\MSTM.EXE /s
O4 - HKLM\..\RunServices: [JAVADP32.EXE] C:\WINDOWS\JAVADP32.EXE /s
O4 - HKLM\..\RunServices: [APPKI.EXE] C:\WINDOWS\SYSTEM\APPKI.EXE /s
O4 - HKLM\..\RunServices: [ADDEN.EXE] C:\WINDOWS\ADDEN.EXE /s
O4 - HKLM\..\RunServices: [NETXR.EXE] C:\WINDOWS\SYSTEM\NETXR.EXE /s
O4 - HKLM\..\RunServices: [ATLLL.EXE] C:\WINDOWS\SYSTEM\ATLLL.EXE /s
O4 - HKLM\..\RunServices: [MSMU32.EXE] C:\WINDOWS\MSMU32.EXE /s
O4 - HKLM\..\RunServices: [JAVANP.EXE] C:\WINDOWS\JAVANP.EXE /s
O4 - HKLM\..\RunServices: [ATLMX32.EXE] C:\WINDOWS\ATLMX32.EXE /s
O4 - HKLM\..\RunServices: [IPNW.EXE] C:\WINDOWS\IPNW.EXE /s
O4 - HKLM\..\RunServices: [NETIK32.EXE] C:\WINDOWS\NETIK32.EXE /s
O4 - HKLM\..\RunServices: [WINSH.EXE] C:\WINDOWS\WINSH.EXE /s
O4 - HKLM\..\RunServices: [SYSQK.EXE] C:\WINDOWS\SYSQK.EXE /s
O4 - HKLM\..\RunServices: [MFCZV32.EXE] C:\WINDOWS\MFCZV32.EXE /s
O4 - HKLM\..\RunServices: [JAVALL32.EXE] C:\WINDOWS\JAVALL32.EXE /s
O4 - HKLM\..\RunServices: [NETOL.EXE] C:\WINDOWS\SYSTEM\NETOL.EXE /s
O4 - HKLM\..\RunServices: [NETPP.EXE] C:\WINDOWS\NETPP.EXE /s
O4 - HKLM\..\RunServices: [CRNC32.EXE] C:\WINDOWS\SYSTEM\CRNC32.EXE /s
O4 - HKLM\..\RunServices: [JAVABT.EXE] C:\WINDOWS\JAVABT.EXE /s
O4 - HKLM\..\RunServices: [NTYI.EXE] C:\WINDOWS\SYSTEM\NTYI.EXE /s
O4 - HKLM\..\RunServices: [WINLV32.EXE] C:\WINDOWS\SYSTEM\WINLV32.EXE /s
O4 - HKLM\..\RunServices: [APIRG.EXE] C:\WINDOWS\APIRG.EXE /s
O4 - HKLM\..\RunServices: [MSCU.EXE] C:\WINDOWS\MSCU.EXE /s
O4 - HKLM\..\RunServices: [NTLI.EXE] C:\WINDOWS\NTLI.EXE /s
O4 - HKLM\..\RunServices: [APPWN32.EXE] C:\WINDOWS\APPWN32.EXE /s
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...etup1.0.0.8.exe

Now close ALL open windows except HijackThis and click the Fix Checked button to finish the repair.

Step #3

Download CCleaner and install it. Start CCleaner and click on the Run Cleaner button in the lower right-hand corner. When it is finished close CCleaner.

Step #4

Please run at least 2 of the following on-line virus scans:Trend Micro Housecall
BitDefender On-Line Virus Scan
Panda ActiveScan
eTrust Antivirus Web Scanner
Make sure that you choose "fix" or "clean".

Step #5

AdAware SE

Download, install, update, configure and run a scan with Ad-aware SE:
  • Download and Install AdAware SE Personal, keeping the default options. However, some of the settings will need to be changed before your first scan.
  • Close ALL windows except Ad-Aware SE.
  • Click on the‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.
  • Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window:
    • In the ‘General’ window make sure the following are selected in green:
      • Under Safety:
        • Automatically save log-file
      • Automatically quarantine objects prior to removal
      • Safe Mode (always request confirmation)
    • Under Definitions:
      • Prompt to update outdated definitions - set the number of days
  • Click on the ‘Scanning’ button on the left and select in green:
    • Under Driver, Folders & Files:
      • Scan Within Archives
    • Under Select drives & folders to scan:
      • choose all hard drives
    • Under Memory & Registry: all green
      • Scan Active Processes
      • Scan Registry
      • Deep Scan Registry
      • Scan my IE favorites for banned URL’s
      • Scan my Hosts file
  • Click on the ‘Advanced’ button on the left and select in green:
    • Under Shell Integration:
      • Move deleted files to recycle bin
    • Under Logfile Detail Level: all green
      • include addtional object information
      • DESELECT - include negligible objects information
      • include environment information
    • Under Alternate Data Streams:
      • Don't log streams smaller than 0 bytes
      • Don't log ADS with the following names: CA_INOCULATEIT
  • Click the ‘Tweak’ button and select in green:
    • Under ‘Scanning Engine’:
      • Unload recognized processes during scanning
      • Scan registry for all users instead of current user only
    • Under ‘Cleaning Engine’:
      • Let Windows remove files in use at next reboot
    • Under Log Files:
      • Include basic Ad-aware SE settings in logfile
      • Include additional Ad-aware SE settings in logfile
      • Please do not check: Include Module list in logfile
  • Click on ‘Proceed’ to save the settings.
  • Click ‘Start’
  • Choose 'Perform Full System Scan'
  • DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.
  • Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.
  • If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window
  • Save the log file when it asks and then click ‘Finish’
  • REBOOT to complete the removal of what Ad-Aware SE found.
Step #6

OK. Reboot your computer normally, start HijackThis and perform a new scan. Use the Add Reply button to post your new log file and the log file from AboutBuster back here along with details of any problems you encountered performing the above steps and I will review it when it comes in.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#5 wds

wds
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:06:26 AM

Posted 26 May 2005 - 05:46 PM

OT
Sorry for the delay.....busy week. I did all the items you suggested. About Buster ran two scans but, for some reason, at the end of the second scan the machine rebooted itself so I was not able to get a log file. I ran an online virus scan at all three sites you suggested and cleaned up around 1600 trojans. I ran Ad-Aware and cleaned up several items. I'm not sure how much progress I have made though. About Blank still makes itself my homepage. I have several windows that pop up one after another and all that is in the window is a random series of numbers or alpha characters. Here is the latest HJT log. Thanks.
WDS

Logfile of HijackThis v1.99.1
Scan saved at 4:00:01 PM, on 05/24/2005
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\RTVSCN95.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\DEFWATCH.EXE
C:\WINDOWS\APICL32.EXE
C:\WINDOWS\ATLXX.EXE
C:\WINDOWS\SYSUZ32.EXE
C:\WINDOWS\SYSTEM\NETFG.EXE
C:\WINDOWS\SYSTEM\NTKV.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SDKLC32.EXE
C:\WINDOWS\SYSTEM\APIZH.EXE
C:\WINDOWS\NTSC.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\SBMX.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\VPTRAY.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\SIKESTON DESKTOP ALERT\TRUEWEATHER.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\IESB.EXE
C:\WINDOWS\NTSC.EXE
C:\WINDOWS\SYSTEM\WINTQ32.EXE
C:\WINDOWS\SDKLC32.EXE
C:\WINDOWS\SYSUZ32.EXE
C:\WINDOWS\NTSC.EXE
C:\WINDOWS\D3QS32.EXE
C:\WINDOWS\SYSTEM\WINTQ32.EXE
C:\WINDOWS\APPEB32.EXE
C:\WINDOWS\D3QS32.EXE
C:\WINDOWS\MFCVB.EXE
C:\WINDOWS\D3QS32.EXE
C:\WINDOWS\APPVD32.EXE
C:\WINDOWS\APPVD32.EXE
C:\HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\nokzr.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\nokzr.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\nokzr.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\nokzr.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\nokzr.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\nokzr.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {EAEDD2F7-A231-D258-2D9D-83929E38D040} - C:\WINDOWS\MFCBQ32.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN0\YCOMP5_6_0_0.DLL (file missing)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SBMX] C:\WINDOWS\SYSTEM\sbmx.exe
O4 - HKLM\..\Run: [LexStart] LexStart.EXE
O4 - HKLM\..\Run: [vptray] c:\Program Files\Norton AntiVirus\vptray.exe
O4 - HKLM\..\Run: [Client Access Service] "C:\Program Files\IBM\Client Access\cwbsvstr.exe"
O4 - HKLM\..\Run: [Client Access Help Update] "C:\Program Files\IBM\Client Access\cwbinhlp.exe"
O4 - HKLM\..\Run: [Client Access Check Version] "C:\Program Files\IBM\Client Access\cwbckver.exe" LOGIN
O4 - HKLM\..\Run: [Client Access Express Welcome] "C:\Program Files\IBM\Client Access\cwbwlwiz.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IESB.EXE] C:\WINDOWS\SYSTEM\IESB.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [rtvscn95] c:\Program Files\Norton AntiVirus\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] c:\Program Files\Norton AntiVirus\defwatch.exe
O4 - HKLM\..\RunServices: [Client Access Start Incoming RC] ###C:\WINDOWS\command\start.exe /MINIMIZED C:\WINDOWS\cwbrxd.exe
O4 - HKLM\..\RunServices: [APICL32.EXE] C:\WINDOWS\APICL32.EXE /s
O4 - HKLM\..\RunServices: [ATLXX.EXE] C:\WINDOWS\ATLXX.EXE /s
O4 - HKLM\..\RunServices: [SYSUZ32.EXE] C:\WINDOWS\SYSUZ32.EXE /s
O4 - HKLM\..\RunServices: [NETFG.EXE] C:\WINDOWS\SYSTEM\NETFG.EXE /s
O4 - HKLM\..\RunServices: [NTKV.EXE] C:\WINDOWS\SYSTEM\NTKV.EXE /s
O4 - HKLM\..\RunServices: [SDKLC32.EXE] C:\WINDOWS\SDKLC32.EXE /s
O4 - HKLM\..\RunServices: [APIZH.EXE] C:\WINDOWS\SYSTEM\APIZH.EXE /s
O4 - HKLM\..\RunServices: [NTSC.EXE] C:\WINDOWS\NTSC.EXE /s
O4 - HKLM\..\RunServices: [WINTQ32.EXE] C:\WINDOWS\SYSTEM\WINTQ32.EXE /s
O4 - HKLM\..\RunServices: [D3QS32.EXE] C:\WINDOWS\D3QS32.EXE /s
O4 - HKLM\..\RunServices: [APPEB32.EXE] C:\WINDOWS\APPEB32.EXE /s
O4 - HKLM\..\RunServices: [MFCVB.EXE] C:\WINDOWS\MFCVB.EXE /s
O4 - HKLM\..\RunServices: [APPVD32.EXE] C:\WINDOWS\APPVD32.EXE /s
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Sikeston Desktop Alert.lnk = C:\Program Files\Sikeston Desktop Alert\TrueWeather.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://carpoint.msn.com/Components/Ocx/Exterior/Outside.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://carpoint.msn.com/Components/Ocx/SurVid/MSSurVid.cab
O16 - DPF: {22D6F312-B0F6-11D0-94AB-0080C74C7E95} (Windows Media Player) - http://activex.microsoft.com/activex/contr...en/nsmp2inf.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www5.incredimail.com/contents/setup...p1/imloader.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_...aploader_v6.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://66.35.183.172/activex/AxisCamControl.cab
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} (SbInstObj) - http://installs.spamblockerutility.com/ins...ckerutility.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = sbmu.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.151.44.9,69.60.160.196

#6 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:07:26 AM

Posted 26 May 2005 - 06:48 PM

Hi wds. It's looking better but it is still infected. Let's have another go at it.

It also appears that you are running quite an old verison of Norton. Is that updated regulary? It should be picking these up unless it has been disabled or is out of date.

Step #1

Download Cwshredder.exe and save it to a folder of its own. Start the program and click on the Check for Update button. If an update is available then download and install it. Close the program (do not run it yet).

Download CCleaner and install it but do not run it yet.

Step #2

Restart in Safe Mode
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until the boot menu appears.
  • Use the arrow keys to select the Safe Mode menu item.
  • Press the Enter key.
Step #3

Start HijackThis and click the Scan button to perform a scan. Look for the following items and click in the checkbox in front of each item to select it:R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\nokzr.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\nokzr.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\nokzr.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\nokzr.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\nokzr.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\nokzr.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {EAEDD2F7-A231-D258-2D9D-83929E38D040} - C:\WINDOWS\MFCBQ32.DLL
O4 - HKLM\..\Run: [IESB.EXE] C:\WINDOWS\SYSTEM\IESB.EXE
O4 - HKLM\..\RunServices: [APICL32.EXE] C:\WINDOWS\APICL32.EXE /s
O4 - HKLM\..\RunServices: [ATLXX.EXE] C:\WINDOWS\ATLXX.EXE /s
O4 - HKLM\..\RunServices: [SYSUZ32.EXE] C:\WINDOWS\SYSUZ32.EXE /s
O4 - HKLM\..\RunServices: [NETFG.EXE] C:\WINDOWS\SYSTEM\NETFG.EXE /s
O4 - HKLM\..\RunServices: [NTKV.EXE] C:\WINDOWS\SYSTEM\NTKV.EXE /s
O4 - HKLM\..\RunServices: [SDKLC32.EXE] C:\WINDOWS\SDKLC32.EXE /s
O4 - HKLM\..\RunServices: [APIZH.EXE] C:\WINDOWS\SYSTEM\APIZH.EXE /s
O4 - HKLM\..\RunServices: [NTSC.EXE] C:\WINDOWS\NTSC.EXE /s
O4 - HKLM\..\RunServices: [WINTQ32.EXE] C:\WINDOWS\SYSTEM\WINTQ32.EXE /s
O4 - HKLM\..\RunServices: [D3QS32.EXE] C:\WINDOWS\D3QS32.EXE /s
O4 - HKLM\..\RunServices: [APPEB32.EXE] C:\WINDOWS\APPEB32.EXE /s
O4 - HKLM\..\RunServices: [MFCVB.EXE] C:\WINDOWS\MFCVB.EXE /s
O4 - HKLM\..\RunServices: [APPVD32.EXE] C:\WINDOWS\APPVD32.EXE /s

Now close ALL open windows except HijackThis and click the Fix Checked button to finish the repair.

Step #4

We need to make sure all hidden files are showing so please:
  • Open My Computer.
  • Select the View menu and click Folder Options.
  • Select the View tab.
  • In the Hidden files section select Show all files.
  • Click OK.
Find the following files/folders and delete them (don't worry if they are already gone):C:\WINDOWS\nokzr.dll
C:\WINDOWS\MFCBQ32.DLL
C:\WINDOWS\SYSTEM\IESB.EXE
C:\WINDOWS\APICL32.EXE
C:\WINDOWS\ATLXX.EXE
C:\WINDOWS\SYSUZ32.EXE
C:\WINDOWS\SYSTEM\NETFG.EXE
C:\WINDOWS\SYSTEM\NTKV.EXE
C:\WINDOWS\SDKLC32.EXE
C:\WINDOWS\SYSTEM\APIZH.EXE
C:\WINDOWS\NTSC.EXE
C:\WINDOWS\SYSTEM\WINTQ32.EXE
C:\WINDOWS\D3QS32.EXE
C:\WINDOWS\APPEB32.EXE
C:\WINDOWS\MFCVB.EXE
C:\WINDOWS\APPVD32.EXE

Step #5

Start CCleaner and click on the Run Cleaner button in the lower right-hand corner. When it is finished close CCleaner.

Step #6

Run CWShredder
  • Double-click on CWShredder.exe.
  • Click "Fix ->" and click "OK" at the prompt.
  • CWShredder will scan and clean your system of CWS files.
  • Click "Next->" and then "Exit".
Step #7

Reboot normally and run at least 2 of the following on-line virus scans:Trend Micro Housecall
BitDefender On-Line Virus Scan
Panda ActiveScan
eTrust Antivirus Web Scanner
Make sure that you choose "fix" or "clean".

Step #8

AdAware SE
  • Close ALL windows and start Ad-Aware SE.
  • Click ‘Start’
  • Choose 'Perform Full System Scan'
  • DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.
  • Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.
  • If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window
  • Save the log file when it asks and then click ‘Finish’
  • REBOOT to complete the removal of what Ad-Aware SE found.
Step #9

Let's do one more scan to lookfor any files that are not showing up in the HijackThis log.

Download PFind.zip and unzip the contents to its own permanent folder.

Important! Reboot in SAFE MODE !!

Start in Safe Mode Using the F8 method:
  • Restart the computer in Safe Mode.
  • As soon as the BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
  • Use the arrow keys to select the Safe Mode menu item.
  • Press the Enter key.
Locate the pfind.bat file and double-click it to run it. It will start scanning your computer and could take a little while so be patient. When the DOS window closes, reboot back to normal mode.

Post the contents of C:\pfind.txt back here and I will review it when it comes in.

Step #10

OK. Reboot your computer normally, start HijackThis and perform a new scan. Use the Add Reply button to post your new log file and the c:\pfind.txt file contents back here along with details of any problems you encountered performing the above steps and I will review it when it comes in.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users