Unsolved
This post is more than 5 years old
22 Posts
0
3544
July 13th, 2005 23:00
HELP please - About:blank has taken over
Hi:
I have that annoying about:blank problem. I've installed and run ad aware and cwshredder. The latter "removed" cws.HomeSearch, then I rebooted and reran cwshredder. Again it found and removed cws.HomeSearch. I did this 3 times. Any input would be appreciated. Thank you.
Jim
Logfile of HijackThis v1.99.1
Scan saved at 8:43:13 PM, on 7/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Scan saved at 8:43:13 PM, on 7/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spupdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spnpinst.exe
C:\WINDOWS\system32\Sysocmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\mfcjt32.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\TWAIN_32\S6U12BX\WATCH.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\DOCUME~1\Amy\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spupdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spnpinst.exe
C:\WINDOWS\system32\Sysocmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\mfcjt32.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\TWAIN_32\S6U12BX\WATCH.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\DOCUME~1\Amy\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\vvcoe.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vvcoe.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\vvcoe.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\vvcoe.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vvcoe.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vvcoe.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://shell.windows.com/fileassoc/0409/xml/redir.asp?Ext=pdf
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {A8ED1EB9-4DCD-9FEF-5087-1F9CDCCE6B2B} - C:\WINDOWS\ntff.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [mfcjt32.exe] C:\WINDOWS\system32\mfcjt32.exe
O4 - HKLM\..\RunOnce: [d3zg.exe] C:\WINDOWS\system32\d3zg.exe
O4 - HKLM\..\RunOnce: [addis.exe] C:\WINDOWS\addis.exe
O4 - HKLM\..\RunOnce: [sysxm.exe] C:\WINDOWS\system32\sysxm.exe
O4 - HKLM\..\RunOnce: [addou32.exe] C:\WINDOWS\system32\addou32.exe
O4 - HKLM\..\RunOnce: [winew32.exe] C:\WINDOWS\winew32.exe
O4 - HKLM\..\RunOnce: [d3um32.exe] C:\WINDOWS\system32\d3um32.exe
O4 - HKLM\..\RunOnce: [winoi.exe] C:\WINDOWS\system32\winoi.exe
O4 - HKLM\..\RunOnce: [ntaa32.exe] C:\WINDOWS\ntaa32.exe
O4 - HKLM\..\RunOnce: [atlsz32.exe] C:\WINDOWS\system32\atlsz32.exe
O4 - HKLM\..\RunOnce: [atllh32.exe] C:\WINDOWS\atllh32.exe
O4 - HKLM\..\RunOnce: [sdkpm32.exe] C:\WINDOWS\sdkpm32.exe
O4 - HKLM\..\RunOnce: [syspp.exe] C:\WINDOWS\syspp.exe
O4 - HKLM\..\RunOnce: [mfclv32.exe] C:\WINDOWS\system32\mfclv32.exe
O4 - HKLM\..\RunOnce: [sdkwt.exe] C:\WINDOWS\system32\sdkwt.exe
O4 - HKLM\..\RunOnce: [syszf32.exe] C:\WINDOWS\system32\syszf32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Watch.lnk = C:\WINDOWS\TWAIN_32\S6U12BX\WATCH.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://www.support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - http://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\d3zg.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vvcoe.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\vvcoe.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\vvcoe.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vvcoe.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vvcoe.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://shell.windows.com/fileassoc/0409/xml/redir.asp?Ext=pdf
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {A8ED1EB9-4DCD-9FEF-5087-1F9CDCCE6B2B} - C:\WINDOWS\ntff.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [mfcjt32.exe] C:\WINDOWS\system32\mfcjt32.exe
O4 - HKLM\..\RunOnce: [d3zg.exe] C:\WINDOWS\system32\d3zg.exe
O4 - HKLM\..\RunOnce: [addis.exe] C:\WINDOWS\addis.exe
O4 - HKLM\..\RunOnce: [sysxm.exe] C:\WINDOWS\system32\sysxm.exe
O4 - HKLM\..\RunOnce: [addou32.exe] C:\WINDOWS\system32\addou32.exe
O4 - HKLM\..\RunOnce: [winew32.exe] C:\WINDOWS\winew32.exe
O4 - HKLM\..\RunOnce: [d3um32.exe] C:\WINDOWS\system32\d3um32.exe
O4 - HKLM\..\RunOnce: [winoi.exe] C:\WINDOWS\system32\winoi.exe
O4 - HKLM\..\RunOnce: [ntaa32.exe] C:\WINDOWS\ntaa32.exe
O4 - HKLM\..\RunOnce: [atlsz32.exe] C:\WINDOWS\system32\atlsz32.exe
O4 - HKLM\..\RunOnce: [atllh32.exe] C:\WINDOWS\atllh32.exe
O4 - HKLM\..\RunOnce: [sdkpm32.exe] C:\WINDOWS\sdkpm32.exe
O4 - HKLM\..\RunOnce: [syspp.exe] C:\WINDOWS\syspp.exe
O4 - HKLM\..\RunOnce: [mfclv32.exe] C:\WINDOWS\system32\mfclv32.exe
O4 - HKLM\..\RunOnce: [sdkwt.exe] C:\WINDOWS\system32\sdkwt.exe
O4 - HKLM\..\RunOnce: [syszf32.exe] C:\WINDOWS\system32\syszf32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Watch.lnk = C:\WINDOWS\TWAIN_32\S6U12BX\WATCH.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://www.support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - http://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\d3zg.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
No Events found!


ALgal
1.2K Posts
0
July 14th, 2005 00:00
Before we begin, let's move HiJackThis to it's own folder; like c:\HJT. When we're done ' cleaning' off your system, we're going to ' flush' the temporary folders which, with HiJackThis in it's current location, we'll lose both the program and the backups it creates. These backups are important in case we need to restore any 'fixed' entry(s) later.
You have a number of files that we would like copies of - to check out and play with.
1. Using Windows Explorer, go to C:\Windows\system32 . Locate the first file you want to zip.
C:\WINDOWS\system32\d3zg.exe
2. Right click on the file and select "Send To" and "Compressed (zipped) Folder".
3. Then locate and right click on
C:\WINDOWS\system32\vvcoe.dll
4. Select "Copy".
5. Right click on the compressed folder and select "Paste". The copied files will be compressed and pasted in.
6. Repeat steps 3. to 5. for the following files
C:\WINDOWS\ntff.dll
C:\WINDOWS\system32\mfcjt32.exe
C:\WINDOWS\system32\d3zg.exe
C:\WINDOWS\addis.exe
C:\WINDOWS\system32\sysxm.exe
Note that the folder should have 7 files in it if you found them all.
7. Right click on the zipped folder and select "Explore".
8. In "File" menu select "Add a Password". Enter the password infected and confirm the password.
9. Please email to cjwd-subAThostingatessex.com (Please replace the 'AT' with an '@' )
Please copy the following to the email and attach the zipped file(s) :
The password is "infected".
The thread is found here
http://forums.us.dell.com/supportforums/board/post?board.id=si_hijack&message.reply_to_id=8760
Paste it in the text field.
and send please.
Claymen77
22 Posts
0
July 14th, 2005 11:00
Thanks for your help. I plan on getting back into the battle vs. about:blank late this evening and will do the things you've indicated. A few quick questions:
1. I have Norton antivirus running on my PC (Dimension 2400). Should I temporarily turn this off before running HijackThis, Ad aware, CWShredder, Spybot, etc.?
2. Should all of these cleaner-uppers be run in safe mode? I know at least some recommend it. Does safe mode take care of keeping Norton Antivirus from interfering? This stuff has my head spinning, but I think I did not use safe mode for running hijackthis.
3. When I downloaded HijackThis, I opened "My Computer", selected the C: drive, created a new folder called HJT and then (I think) downloaded hijackthis.exe into this new folder. The utility warned me that my file was in a temp folder, recommending I put it in C:\program files\hijackthis... but I thought I had taken care of this satisfactorily by making a folder within C. Based upon your note, I must have not done it correctly - maybe I made the new folder, but somehow dumped the file into a different folder. Does making a new folder C:\HJT the way I described work? I'll check this evening to see where hijackthis.exe ended up.
Again, thanks for your help.
Jim
PS - doesn't the "community" know who's putting out all this bad stuff? Can't we go beat them up, or at least TP a tree on their lawn??
Claymen77
22 Posts
0
July 14th, 2005 12:00
Gotcha - by the way, I read your above note several times, and regarding the HJT files & folders, I believe there may be a subtlety many people overlook. You mentioned you do not want the hijackthis.exe file in the zipped folder. After I downloaded the zipped hijackthis.exe and put it somewhere (?), I couldn't find an un-zipper but did something like right-click and open to get it to run. I never put the unzipped file in a different folder from the zipped. I'll redo that part tonight. If I have trouble unzipping, I read in a posting by Community Assistant ky331 that I can download the already unzipped file at http://downloads.malewareremoval.com/HijackThis.exe and will try that (then put in a separate folder).
I'm starting to enjoy this. Is that bad??
ALgal
1.2K Posts
0
July 14th, 2005 12:00
Hello Claymen,
Do not turn off your anti-virus. Sometimes we have to have people temporarily disable anti-spyware as Teatimer, Ad-Watch, etc. to allow the fixes we require to take place using hijackthis but never their anti-virus.
Generally things are easier to delete in while in safe mode. Less things are running and therefore the items to be deleted may not be in use. If items are in use, deletion may be difficult without taking other steps.
Check your hijackthis folder. We don't want it in a temp folder and do not want it in the zipped hijackthis folder and do not have it on the desktop. If you need more help just post.
Dr. Lawrence Ho
2 Intern
•
2K Posts
0
July 14th, 2005 19:00
cghost
302 Posts
0
July 14th, 2005 19:00
< Kibbitz >
If nobody enjoyed this you wouldn't be getting any help !
If you start having fun, check out the link in Algal's signature.
cg
< end Kibbitz >
ALgal
1.2K Posts
0
July 14th, 2005 21:00
Claymen,
I have to ask you to ignore paindoc's response. He is breaking the rules of the forum which ChrisM (Dell) has made. Blocking a server is not going to clean malware off your computer. Please post the hijackthis like I requested and we will get to work cleaning up the malware.
Dr. Lawrence Ho
2 Intern
•
2K Posts
0
July 14th, 2005 22:00
Claymen77
22 Posts
0
July 15th, 2005 11:00
OK - I started checking things out late last night. I managed to unzip hijackthis.exe and put in a separate folder. My PC locked up a few minutes later and I was too tired to think straight - so I gave up for the evening.
I have run ad aware, spybot and Cwshredder on my PC and still have my homepage hijacked to about:blank. As indicated a few postings ago, Cwshredder continues to find and "remove" CWS.homesearch, then I reboot and do it again...and again. I assume CWS and about:blank are closely related - like a disease and a symptom. A coworker suggested I should literally unplug my Comcast digital line from the back of my PC and run everything that way also. For what its worth, I never saw or heard of about:blank until 5 minutes after switching from aol & dialup to Comcast high speed internet. Perhaps it was always there, but not able to redirect the aol homepage feature.
Anyway, tonight I hope to rerun and post a hijackthis report and send copies of the 7 noted files to the address you supplied.
Thanks much for your patience and help.
Jim
ChrisRLG
2 Intern
•
3.9K Posts
0
July 15th, 2005 13:00
Claymen77 (Jim)
I am sorry that lots of others have started jumping in to give advise.
They should all read this topic :-
http://forums.us.dell.com/supportforums/board/message?board.id=si_hijack&message.id=7392
The standard rules of the Dell Community Forum do not apply to the posts in this room for VERY good reasons.
Those rules DO give a way to provide suggestions from others to the expert assisting you, and if they have concerns or other methods that they believe will work, they should use those methods to advise your Expert instead.
I will state that ALgal is a respected member of the anti-malware forums who is in contact with others for advise when ever she has any problems. She has been through and graduated from my anti-malware school at www.malwareremoval.com
Please ignor ALL other posters to this topic.
Claymen77
22 Posts
0
July 15th, 2005 22:00
Hi ALgal et. al.:
Below is a new & (hopefully) improved log from hijackthis. I emailed the zipped file with 5 of the 7 files you listed. I could not find C:\windows\system32\mfcjt32.exe. I used the search function and checked the entire c: drive - no luck. Maybe it got "cleaned up" somewhere along the line. The other missing file is not really missing. Your note had C:\windows\system32\d3zg.exe listed as the first, then again as the 5th file.
Thanks again for all your help.
Jim (Claymen)
Logfile of HijackThis v1.99.1
Scan saved at 6:53:01 PM, on 7/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://shell.windows.com/fileassoc/0409/xml/redir.asp?Ext=pdf
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {2B3FC2B5-8EC5-0AC5-D56B-8208A144A487} - C:\WINDOWS\atlkt.dll
O2 - BHO: Class - {4B2B7AB1-27B5-D55B-0C12-16D5280C1A80} - C:\WINDOWS\ntrw.dll
O2 - BHO: Class - {794F43DD-B7AC-6EC0-A5F6-521F6ED11C88} - C:\WINDOWS\system32\appsf32.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\RunOnce: [d3zg.exe] C:\WINDOWS\system32\d3zg.exe
O4 - HKLM\..\RunOnce: [addis.exe] C:\WINDOWS\addis.exe
O4 - HKLM\..\RunOnce: [sdksh32.exe] C:\WINDOWS\system32\sdksh32.exe
O4 - HKLM\..\RunOnce: [addhw32.exe] C:\WINDOWS\system32\addhw32.exe
O4 - HKLM\..\RunOnce: [javaou.exe] C:\WINDOWS\system32\javaou.exe
O4 - HKLM\..\RunOnce: [mfceq.exe] C:\WINDOWS\mfceq.exe
O4 - HKLM\..\RunOnce: [netqr32.exe] C:\WINDOWS\netqr32.exe
O4 - HKLM\..\RunOnce: [syspp.exe] C:\WINDOWS\syspp.exe
O4 - HKLM\..\RunOnce: [appdh.exe] C:\WINDOWS\appdh.exe
O4 - HKLM\..\RunOnce: [apidm32.exe] C:\WINDOWS\system32\apidm32.exe
O4 - HKLM\..\RunOnce: [appbn.exe] C:\WINDOWS\system32\appbn.exe
O4 - HKLM\..\RunOnce: [atlbc.exe] C:\WINDOWS\atlbc.exe
O4 - HKLM\..\RunOnce: [sdksc.exe] C:\WINDOWS\sdksc.exe
O4 - HKLM\..\RunOnce: [winvo.exe] C:\WINDOWS\winvo.exe
O4 - HKLM\..\RunOnce: [winbl.exe] C:\WINDOWS\winbl.exe
O4 - HKLM\..\RunOnce: [d3zf.exe] C:\WINDOWS\d3zf.exe
O4 - HKLM\..\RunOnce: [ntfy.exe] C:\WINDOWS\ntfy.exe
O4 - HKLM\..\RunOnce: [apijk.exe] C:\WINDOWS\system32\apijk.exe
O4 - HKLM\..\RunOnce: [winxk32.exe] C:\WINDOWS\system32\winxk32.exe
O4 - HKLM\..\RunOnce: [javaav32.exe] C:\WINDOWS\javaav32.exe
O4 - HKLM\..\RunOnce: [mfcmy.exe] C:\WINDOWS\mfcmy.exe
O4 - HKLM\..\RunOnce: [ntfd32.exe] C:\WINDOWS\system32\ntfd32.exe
O4 - HKLM\..\RunOnce: [apikf.exe] C:\WINDOWS\apikf.exe
O4 - HKLM\..\RunOnce: [iekf32.exe] C:\WINDOWS\system32\iekf32.exe
O4 - HKLM\..\RunOnce: [crum32.exe] C:\WINDOWS\system32\crum32.exe
O4 - HKLM\..\RunOnce: [atlgp.exe] C:\WINDOWS\atlgp.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Watch.lnk = C:\WINDOWS\TWAIN_32\S6U12BX\WATCH.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://www.support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - http://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
ALgal
1.2K Posts
0
July 16th, 2005 02:00
Hello Claymen,
Let's do the first part of the fix.
First of all I need you to download some programs for use later.
Cwsserviceremove
Download cwsserviceremove from http://ralphcaddell.com/Uploads/cwsserviceremove.zip
and unzip it to your desktop Do NOT use it yet
About:Buster
Download About:Buster from http://downloads.malwareremoval.com/AboutBuster.zip
Once it is downloaded extract it to c:\aboutbuster and check for updates. Do NOT use it yet
CWShredder
Download CWShredder from
http://www.intermute.com/spysubtract/cwshredder_download.html
install it, check for updates but again. Do NOT use it yet
Ad-aware Second Edition
Download Ad-aware Second Edition from
http://lavasoft.element5.com/support/download/
Open adaware and Click the "Check for updates now" line on the main screen. CLick the "Connect" button on the webupdate screen.
If an update is available download it and install it. Click the "Finish" button to go back to the main screen.
Click on the "Settings" button (gear symbol in the upper right corner of the main status screen) in the quick launch toolbar to open the General settings screen. Check the "Automatically quarantine objects prior to removal" setting and then click "Proceed" to save your changes
Click the "Scan now" button in the main menu on the left side of the main status screen or use the "Start" button in lower right corner. This will open the Preparing System Scan screen. Please deselect "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat. Then select "Use custom scanning options" and click "CUstomize". This will open the "Scan Settings Page. Make sure all of the following are On with a "green" checkmark:
Scan within archives
Scan active processes
Scan Registry
Deep-scan Registry
Scan my IE Favorites for banned URLs
Scan my Hosts File
Then click on the "Tweak" Button to open up the tweak settings.
Open up the Scanning Engine section and make sure all of the following are On with a "green" checkmark:
Scan registry for all users instead of current user only
Make sure the following is unchecked with a "red" X:
Unload recognized processes & modules during scan.
Open up the Cleaning Engine section and make sure all of the following are On with a "green" checkmark:
Always try to unload modules before deletion
During Removal, unload Explorer and IE if necessary
Let Windows remove files in use at next reboot.
Click the "Proceed" button to save settings.
Don't scan yet. We will do it in safe mode.
Ensure hidden files and folders are set to show;
Please disconnect from the Internet and unplug your modem for the duration of this fix You may want to print the rest of these instructions.
Reboot your computer into Safe Mode by tapping F8 while booting up and continue for the rest of the fix in SAFE MODE
While in safe mode, double click on the cwsserviceemove.reg file you downloaded at the beginning. Grant it permission to add the registry items.
Then Open cwshredder that you downloaded in the first step. Close all browser windows and click on the fix/next button.
Bring up task manager Ctrl-Alt-Del and end these processes if they are present
d3zg.exe
addis.exe
sdksh32.exe
addhw32.exe
javaou.exe
mfceq.exe
netqr32.exe
syspp.exe
appdh.exe
apidm32.exe
appbn.exe
atlbc.exe
sdksc.exe
winvo.exe
winbl.exe
d3zf.exe
ntfy.exe
apijk.exe
winxk32.exe
javaav32.exe
mfcmy.exe
ntfd32.exe
apikf.exe
iekf32.exe
crum32.exe
atlgp.exe
Now find and delete these files, if you can't find one then don't worry.. just move on to the next one.
C:\WINDOWS\atlkt.dll
C:\WINDOWS\ntrw.dll
C:\WINDOWS\system32\appsf32.dll
C:\WINDOWS\system32\d3zg.exe
C:\WINDOWS\addis.exe
C:\WINDOWS\system32\sdksh32.exe
C:\WINDOWS\system32\addhw32.exe
C:\WINDOWS\system32\javaou.exe
C:\WINDOWS\mfceq.exe
C:\WINDOWS\netqr32.exe
C:\WINDOWS\syspp.exe
C:\WINDOWS\appdh.exe
C:\WINDOWS\system32\apidm32.exe
C:\WINDOWS\system32\appbn.exe
C:\WINDOWS\atlbc.exe
C:\WINDOWS\sdksc.exe
C:\WINDOWS\winvo.exe
C:\WINDOWS\winbl.exe
C:\WINDOWS\d3zf.exe
C:\WINDOWS\ntfy.exe
C:\WINDOWS\system32\apijk.exe
C:\WINDOWS\system32\winxk32.exe
C:\WINDOWS\javaav32.exe
C:\WINDOWS\mfcmy.exe
C:\WINDOWS\system32\ntfd32.exe
C:\WINDOWS\apikf.exe
C:\WINDOWS\system32\iekf32.exe
C:\WINDOWS\system32\crum32.exe
C:\WINDOWS\atlgp.exe
Now run hijackthis and click the scan button, when it has finished scanning put a check against the following and click 'fix checked'
Run HiJackThis and click "Scan", then check(tick) the following, if present:
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://shell.windows.com/fileassoc/0409/xml/redir.asp?Ext=pdf
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {2B3FC2B5-8EC5-0AC5-D56B-8208A144A487} - C:\WINDOWS\atlkt.dll
O2 - BHO: Class - {4B2B7AB1-27B5-D55B-0C12-16D5280C1A80} - C:\WINDOWS\ntrw.dll
O2 - BHO: Class - {794F43DD-B7AC-6EC0-A5F6-521F6ED11C88} - C:\WINDOWS\system32\appsf32.dll
O4 - HKLM\..\RunOnce: [d3zg.exe] C:\WINDOWS\system32\d3zg.exe
O4 - HKLM\..\RunOnce: [addis.exe] C:\WINDOWS\addis.exe
O4 - HKLM\..\RunOnce: [sdksh32.exe] C:\WINDOWS\system32\sdksh32.exe
O4 - HKLM\..\RunOnce: [addhw32.exe] C:\WINDOWS\system32\addhw32.exe
O4 - HKLM\..\RunOnce: [javaou.exe] C:\WINDOWS\system32\javaou.exe
O4 - HKLM\..\RunOnce: [mfceq.exe] C:\WINDOWS\mfceq.exe
O4 - HKLM\..\RunOnce: [netqr32.exe] C:\WINDOWS\netqr32.exe
O4 - HKLM\..\RunOnce: [syspp.exe] C:\WINDOWS\syspp.exe
O4 - HKLM\..\RunOnce: [appdh.exe] C:\WINDOWS\appdh.exe
O4 - HKLM\..\RunOnce: [apidm32.exe] C:\WINDOWS\system32\apidm32.exe
O4 - HKLM\..\RunOnce: [appbn.exe] C:\WINDOWS\system32\appbn.exe
O4 - HKLM\..\RunOnce: [atlbc.exe] C:\WINDOWS\atlbc.exe
O4 - HKLM\..\RunOnce: [sdksc.exe] C:\WINDOWS\sdksc.exe
O4 - HKLM\..\RunOnce: [winvo.exe] C:\WINDOWS\winvo.exe
O4 - HKLM\..\RunOnce: [winbl.exe] C:\WINDOWS\winbl.exe
O4 - HKLM\..\RunOnce: [d3zf.exe] C:\WINDOWS\d3zf.exe
O4 - HKLM\..\RunOnce: [ntfy.exe] C:\WINDOWS\ntfy.exe
O4 - HKLM\..\RunOnce: [apijk.exe] C:\WINDOWS\system32\apijk.exe
O4 - HKLM\..\RunOnce: [winxk32.exe] C:\WINDOWS\system32\winxk32.exe
O4 - HKLM\..\RunOnce: [javaav32.exe] C:\WINDOWS\javaav32.exe
O4 - HKLM\..\RunOnce: [mfcmy.exe] C:\WINDOWS\mfcmy.exe
O4 - HKLM\..\RunOnce: [ntfd32.exe] C:\WINDOWS\system32\ntfd32.exe
O4 - HKLM\..\RunOnce: [apikf.exe] C:\WINDOWS\apikf.exe
O4 - HKLM\..\RunOnce: [iekf32.exe] C:\WINDOWS\system32\iekf32.exe
O4 - HKLM\..\RunOnce: [crum32.exe] C:\WINDOWS\system32\crum32.exe
O4 - HKLM\..\RunOnce: [atlgp.exe] C:\WINDOWS\atlgp.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
Now, with all windows closed except HiJackThis, click "Fix checked".
The following step is important as you may have several malware files in your temp directories.
Then browse to the C:\documents and settings\Your User Name (repeat for all other user names in documents and settings)\local settings\temp folder and delete all files and folders in it. Then browse to the C:\Window\Temp folder and delete all files and folders in it. Then in internet explore click tools>internet Options>General. Click on Delete Files make sure you get all offline content as well.
Now navigate to the c:\aboutbuster directory and double-click on AboutBuster.exe. Click Begin Removal to allow AboutBuster to scan. When it has finished, AboutBuster will open a 'Scan Completed' window. Click OK. Another information window will open. Click on Exit. AboutBuster will inform you that a log has been created. Click OK. I will need you to post that log later.
Scan with Adaware by opening it and clicking the "Next" button to start the scan.
When the scan is completed the Performing System Scan screen will change name to "Scan Complete".
Click the "Next" button to get to the Scanning Results screens where more information about the objects detected during the scan is available.
Click the Critical Objects Tab. In general all of the items listed will be bad. Be carefull with the Hosts file entries. Malware uses the hosts file to redirect you websites. However you can use the hosts file as a way to prevent malware. If the object has 127.0.0.1 in it, it should most likely not be deleted as it is protecting against unwanted sites. For more information on how to use a host file to protect yourself read here. So in short, you may or may not want to fix the hosts file entries.
To fix all the bad critical objects do the following:
Right click on one of them to open up the selection screen. Click the "Select All" button to select all entries. In general all should be selected with the exception of the good hosts file entries.
When all are selected Click "Next" and then "OK" in the pop-up window to confirm the removal.
Now reboot,and run hijackthis again and post a fresh log along with the about buster log.
Claymen77
22 Posts
0
July 16th, 2005 18:00
OK my pal Algal:
I am cautiously optimistic that improvements have been made. When I reconnected to the internet (to make this posting) I was NOT directed to about:blank for the first time in months.
Here is the latest HJT log. My message became too big to post, so I'll try to post the aboutbuster log separately .
2 quick notes:
1. To download aboutbuster, download.malwareremoval.com was "unavailable", so I searched on-line and used the free download from bleepingcomputer.com
2. HJT encountered one error "Error #52 - bad file name or number in sub GetLongPath(?.exe)" and asked that I send a report to merijn@spywareinfo.com (I will.)
Thanks again for your help.
Jim/Claymen
Logfile of HijackThis v1.99.1
Scan saved at 3:12:46 PM, on 7/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spupdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spnpinst.exe
C:\WINDOWS\system32\Sysocmgr.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\winyx32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\TWAIN_32\S6U12BX\WATCH.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {56602600-9335-D10F-A0C5-C6602AA24FD3} - C:\WINDOWS\netgo.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {FB118E8B-875C-AD27-289B-C22A5B4AA454} - C:\WINDOWS\apptk32.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Watch.lnk = C:\WINDOWS\TWAIN_32\S6U12BX\WATCH.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://www.support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - http://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\winyx32.exe" /s (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
End of HJT Log>>>>>>>>>>>>
Claymen77
22 Posts
0
July 16th, 2005 18:00
Message Edited by Claymen77 on 07-16-2005 03:02 PM
ChrisRLG
2 Intern
•
3.9K Posts
0
July 16th, 2005 19:00