Start a Conversation

Unsolved

This post is more than 5 years old

489

August 2nd, 2005 20:00

AZE search Toolbar

​ Hi all! I just recently got the Aze Toolbar virus-- I was able to get rid of the toolbar as well as the links to the websites- but one thing I was not able to get rid of is the the fact that my homepage has been changed and its locked so I cant change it back-- also I now cant get on the msn homepage- heres my Hijack this log-- any help would be great! thanks ​
​ jim ​
​ ​
​ ​
​ C:\WINDOWS\System32\smss.exe ​
​C:\WINDOWS\system32\winlogon.exe ​
​C:\WINDOWS\system32\services.exe ​
​C:\WINDOWS\system32\lsass.exe ​
​C:\WINDOWS\System32\Ati2evxx.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\WINDOWS\system32\spoolsv.exe ​
​C:\WINDOWS\Explorer.EXE ​
​C:\WINDOWS\System32\drivers\CDAC11BA.EXE ​
​C:\Program Files\NavNT\defwatch.exe ​
​C:\Program Files\NavNT\rtvscan.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\WINDOWS\System32\Tablet.exe ​
​C:\WINDOWS\System32\MsgSys.EXE ​
​C:\WINDOWS\BCMSMMSG.exe ​
​C:\Program Files\Synaptics\SynTP\SynTPLpr.exe ​
​C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ​
​C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe ​
​C:\Program Files\Dell\AccessDirect\dadapp.exe ​
​C:\WINDOWS\system32\dla\tfswctrl.exe ​
​C:\WINDOWS\System32\DSentry.exe ​
​C:\Program Files\Dell\Media Experience\PCMService.exe ​
​C:\Program Files\Common Files\Real\Update_OB\realsched.exe ​
​C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe ​
​C:\Program Files\Common Files\Dell\EUSW\Support.exe ​
​C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe ​
​C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe ​
​C:\WINDOWS\System32\MMTrayLSI.exe ​
​C:\WINDOWS\System32\MMTray2k.exe ​
​C:\Program Files\NavNT\vptray.exe ​
​C:\Program Files\ScanSoft\OmniPageSE\opware32.exe ​
​C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe ​
​C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE ​
​C:\Program Files\Logitech\ImageStudio\LogiTray.exe ​
​C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe ​
​C:\WINDOWS\System32\P2P Networking\P2P Networking.exe ​
​C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe ​
​C:\Program Files\MSN Messenger\msnmsgr.exe ​
​C:\Program Files\Yahoo!\Messenger\ypager.exe ​
​C:\WINDOWS\System32\196_150_ni.exe ​
​C:\WINDOWS\System32\wbem\wmiapsrv.exe ​
​C:\Program Files\Handspring\HOTSYNC.EXE ​
​C:\Program Files\Walpaper\jlpaper.exe ​
​C:\Program Files\hijackthis\HijackThis.exe ​
​ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = ​​http://www.dell4me.com/myway​​ ​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = ​​http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html​​ ​
​R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = ​​http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com​​ ​
​R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = ​​http://www.dell4me.com/myway​​ ​
​R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost ​
​O1 - Hosts: 213.219.251.78 google.com ​
​O1 - Hosts: 213.219.251.78 ​​www.google.co.uk​​ ​
​O1 - Hosts: 213.219.251.78 google.co.uk ​
​O1 - Hosts: 213.219.251.78 ​​www.google.ca​​ ​
​O1 - Hosts: 213.219.251.78 google.ca ​
​O1 - Hosts: 213.219.251.78 ​​www.google.es​​ ​
​O1 - Hosts: 213.219.251.78 google.es ​
​O1 - Hosts: 213.219.251.78 ​​www.google.de​​ ​
​O1 - Hosts: 213.219.251.78 google.de ​
​O1 - Hosts: 213.219.251.78 ​​www.google.fr​​ ​
​O1 - Hosts: 213.219.251.78 google.fr ​
​O1 - Hosts: 213.219.251.78 ​​www.google.com.au​​ ​
​O1 - Hosts: 213.219.251.78 google.com.au ​
​O1 - Hosts: 213.219.251.79 ​​www.yahoo.com​​ ​
​O1 - Hosts: 213.219.251.79 yahoo.com ​
​O1 - Hosts: 66.218.75.184 mail.yahoo.com ​
​O1 - Hosts: 213.219.251.80 ​​www.msn.com​​ ​
​O1 - Hosts: 213.219.251.80 msn.com ​
​O1 - Hosts: 213.219.251.80 search.msn.com ​
​O1 - Hosts: 213.219.251.80 ​​www.search.msn.com​​ ​
​O1 - Hosts: 213.219.251.80 go.com ​
​O1 - Hosts: 213.219.251.80 ​​www.go.com​​ ​
​O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_19_0.dll ​
​O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ​
​O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll ​
​O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll ​
​O2 - BHO: (no name) - {7A1693A1-AFAF-4F1E-9B05-EEC38A85FBF3} - C:\WINDOWS\SYSTEM32\313ch56.dll ​
​O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx ​
​O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_19_0.dll ​
​O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe ​
​O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe ​
​O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe ​
​O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ​
​O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe ​
​O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe ​
​O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe ​
​O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r ​
​O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe ​
​O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" ​
​O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime ​
​O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot ​
​O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe ​
​O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe ​
​O4 - HKLM\..\Run: [hplampc] C:\WINDOWS\system32\hplampc.exe ​
​O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe ​
​O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe ​
​O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe ​
​O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe ​
​O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe ​
​O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe ​
​O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE ​
​O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe ​
​O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe ​
​O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe ​
​O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART ​
​O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe ​
​O4 - HKLM\..\RunOnce: [6n01949.exe] C:\WINDOWS\System32\6n01949.exe /k ​
​O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background ​
​O4 - HKCU\..\Run: [isrdbg32] C:\WINDOWS\System32\isrdbg32.exe ​
​O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet ​
​O4 - HKCU\..\Run: [LDM] \Program\ ​
​O4 - HKCU\..\Run: [196_150_ni] C:\WINDOWS\System32\196_150_ni.exe ​
​O4 - HKCU\..\RunOnce: [6n01949.exe] C:\WINDOWS\System32\6n01949.exe /k ​
​O4 - Startup: HotSync Manager.lnk = C:\Program Files\Handspring\HOTSYNC.EXE ​
​O4 - Startup: PowerReg Scheduler V3.exe ​
​O4 - Startup: Wallpaper Changer.lnk = C:\Program Files\Walpaper\jlpaper.exe ​
​O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe ​
​O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe ​
​O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present ​
​O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 ​
​O8 - Extra context menu item: &Search - ​​http://ka.bar.need2find.com/KA/menusearch.html?p=KA​ ​
​O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll ​
​O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll ​
​O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll ​
​O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll ​
​O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm ​
​O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm ​
​O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll ​
​O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE ​
​O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE ​
​O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll ​
​O15 - Trusted Zone: *.musicmatch.com ​
​O15 - Trusted Zone: *.musicmatch.com (HKLM) ​
​O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - ​​file://c:\counter.cab​​ ​
​O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) - ​
​O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - ​​http://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab​​ ​
​O16 - DPF: {874DF68E-711C-43E3-855D-5A1949FAB109} (The Faces.com Friend Finder v1.8) - ​​https://www.faces.com/Scripts/FAddrImp.cab​​ ​
​O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - ​​http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab​​ ​
​O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - ​​http://zone.msn.com/bingame/shpo/default/shapo.cab​​ ​
​O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - ​​http://utu.popcap.com/games/popcaploader_v5.cab​​ ​
​O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll ​
​O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe ​
​O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe ​
​O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe ​
​O23 - Service: Alias Wavefront Help Server (AWHelpServer) - Unknown owner - C:\Program Files\AliasWavefront\Maya5.0\docs\Wrapper.exe" -s "C:\Program Files\AliasWavefront\Maya5.0\docs/Wrapper.conf (file missing) ​
​O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE ​
​O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe ​
​O23 - Service: Ndiatw - Unknown owner - (no file) ​
​O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe ​
​O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\System32\Tablet.exe ​
​ ​

5.9K Posts

August 3rd, 2005 00:00

Next time please do the System Scan and Save a Log File option then copy the whole text from the notepad file that comes up.
 

Download the Hoster from:
Unpack to your desktop and run it.  If you see green text then press the Restore Original Hosts button and OK.
If you see red text then press the Make Hosts Writable button then the Restore Original Hosts button and OK.


Also download and install ccleaner.exe from http://www.ccleaner.com. Don't let
it clean anything yet.
 

Shutdown and Restart and Boot into Safe Mode by tapping the F8 key when you see the PC
maker's logo.
Keep tapping until it tells you it is going to Safe Mode or you see the Safe
Mode menu. Select the top option.
Do a HijackThis Scan and check the following (if still there) then Fix Checked.
 
O1 - Hosts: 213.219.251.78 google.com
O1 - Hosts: 213.219.251.78 www.google.co.uk
O1 - Hosts: 213.219.251.78 google.co.uk
O1 - Hosts: 213.219.251.78 www.google.ca
O1 - Hosts: 213.219.251.78 google.ca
O1 - Hosts: 213.219.251.78 www.google.es
O1 - Hosts: 213.219.251.78 google.es
O1 - Hosts: 213.219.251.78 www.google.de
O1 - Hosts: 213.219.251.78 google.de
O1 - Hosts: 213.219.251.78 www.google.fr
O1 - Hosts: 213.219.251.78 google.fr
O1 - Hosts: 213.219.251.78 www.google.com.au
O1 - Hosts: 213.219.251.78 google.com.au
O1 - Hosts: 213.219.251.79 www.yahoo.com
O1 - Hosts: 213.219.251.79 yahoo.com
O1 - Hosts: 66.218.75.184 mail.yahoo.com
O1 - Hosts: 213.219.251.80 www.msn.com
O1 - Hosts: 213.219.251.80 msn.com
O1 - Hosts: 213.219.251.80 search.msn.com
O1 - Hosts: 213.219.251.80 www.search.msn.com
O1 - Hosts: 213.219.251.80 go.com
O1 - Hosts: 213.219.251.80 www.go.com
O2 - BHO: (no name) - {7A1693A1-AFAF-4F1E-9B05-EEC38A85FBF3} - C:\WINDOWS\SYSTEM32\313ch56.dll
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\RunOnce: [6n01949.exe] C:\WINDOWS\System32\6n01949.exe /k
O4 - HKCU\..\Run: [isrdbg32] C:\WINDOWS\System32\isrdbg32.exe
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [196_150_ni] C:\WINDOWS\System32\196_150_ni.exe
O4 - HKCU\..\RunOnce: [6n01949.exe] C:\WINDOWS\System32\6n01949.exe /k
O4 - Startup: Wallpaper Changer.lnk = C:\Program Files\Walpaper\jlpaper.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Search - http://ka.bar.need2find.com/KA/menusearch.html?p=KA
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O23 - Service: Ndiatw - Unknown owner - (no file)
 
 

Run ccleaner.exe, uncheck everything on the first page except the two entries
with Temporary and then Run Cleaner.

Rerun the hoster just to be sure.
 
Reboot into regular mode, run a new HijackThis scan and save log and post the log as a reply.
 
Ron

 
No Events found!

Top