Unsolved

This post is more than 5 years old

8 Posts

1389

January 2nd, 2011 04:00

Homepage locked

Hi, I have downloaded a Chinese software and installed it.  Unfortunately, it appeared to have spyware and locked my IE homepage to  .  I have tried many times to remove it through Internet Options and reset homepage.  But it doesn't work.  Here's the log from the HJT, please help.

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 20:27:03, on 2/1/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\eBoostr\eBoostrCP.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\eBoostr\EBstrSvc.exe

C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\srvany.exe

C:\Program Files\MacroData Inc\NetDrive\ndsvc.exe

C:\WINDOWS\KMService.exe

C:\WINDOWS\system32\conime.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

 

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: NaverToolbar Helper - {67C41E9E-2EBF-4F2B-AF74-314F0D793172} - C:\Program Files\naver\NaverToolbar\NaverTB_3_5_5_49.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL

O2 - BHO: TSWebMon - {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL

O2 - BHO: Veoh Web Player Toolbar - {cd90bf73-20f6-44ef-993d-bb920303bd2e} - C:\Program Files\Veoh_Web_Player\tbVeo2.dll

O2 - BHO: Thunder ToolbarBrowserHelper - {D2F8A635-8B0F-47BF-915E-6F456767A300} - C:\Program Files\Thunder Network\MiniThunder\ToolBarNow.dll

O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Veoh Web Player Toolbar - {cd90bf73-20f6-44ef-993d-bb920303bd2e} - C:\Program Files\Veoh_Web_Player\tbVeo2.dll

O3 - Toolbar: ??? ??(&N) - {D09CFF09-A42A-4EDC-9804-E61224F59CA1} - C:\Program Files\naver\NaverToolbar\NaverTB_3_5_5_49.dll

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [ctfmon] ctfmon.exe

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O15 - ESC Trusted Zone: http://*.update.microsoft.com

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1284193081031

O16 - DPF: {6CE20149-ABE3-462E-A1B4-5B549971AA38} (XecureCKKB Class) - 

O16 - DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} (HanSetupCtrl1010 Class) - https://members.hangame.com/common/HanSetup1040.cab

O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

O22 - SharedTaskScheduler: Browseui 啎樓婥最唗 - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: 郪璃濬梗遣湔最唗 - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: eBoostr Service (EBOOSTRSVC) - eBoostr.com - C:\Program Files\eBoostr\EBstrSvc.exe

O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: KMService - Unknown owner - C:\WINDOWS\system32\srvany.exe

O23 - Service: NetDrive Service (ndsvc) - MacroData Inc. - C:\Program Files\MacroData Inc\NetDrive\ndsvc.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: Virtual PDF Printer (Service1) - Unknown owner - C:\Program Files\Virtual PDF Printer\VirtualPrinting.exe

 

--

End of file - 8938 bytes

8 Posts

January 2nd, 2011 04:00

Srry forgot to say the locked homepage is http://hao.g3456.com/?91

2 Intern

 • 

1.1K Posts

January 2nd, 2011 08:00

I'm kevinf80 and I will be helping with any malware issues you may have with your system.

  • Please be aware that some of the logs I may ask for can be very complex and can take a long time to decipher. I am a volunteer here with a job and family so I ask that you be patient when waiting for replies.
  • Please DO NOT run any scans/tools/fixes on your own as this will conflict with the tools we are going to use.
  • Either print or Save to Notepad all instructions and please follow them carefully, if there's something you don't understand or that will not work please let me know and we will go through it together.
  • Malware is often buggy and can be very unstable, with that in mind it is advisable to backup any important data before we begin.
  • If you do not reply within 72 hours the thread will be closed, if you need more time let me know. Likewise if I do not respond within 48 hours feel free to PM me.
  • If you have any P2P applications installed such as BitTorrent, uTorrent, Limewire etc etc, please uninstall them before we begin.
  • If you are using Cracked or Illegal software your thread will be locked and all help will cease.



Please proceed as follows :-

Step 1

Please re-open HiJackThis and scan only.  Check the boxes next to all the entries listed below.

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: NaverToolbar Helper - {67C41E9E-2EBF-4F2B-AF74-314F0D793172} - C:\Program Files\naver\NaverToolbar\NaverTB_3_5_5_49.dll
O2 - BHO: TSWebMon - {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} - (no file)
O2 - BHO: Thunder ToolbarBrowserHelper - {D2F8A635-8B0F-47BF-915E-6F456767A300} - C:\Program Files\Thunder Network\MiniThunder\ToolBarNow.dll
O3 - Toolbar: ??? ??(&N) - {D09CFF09-A42A-4EDC-9804-E61224F59CA1} - C:\Program Files\naver\NaverToolbar\NaverTB_3_5_5_49.dll


Now close all windows other than HiJackThis, then click Fix Checked.  Close HiJackThis.  Reboot

Step 2

Please go to Start > Control Panel > Add/Remove Programs and remove the following (if present):

naver
Thunder Network


Step 3

Download user posted image TFC to your desktop, from either of the following links
Link 1
Link 2

  • Make sure any open work is saved. TFC will close all open application windows.
  • Double-click TFC.exe to run the program.
  • If prompted, click "Yes" to reboot.


TFC will automatically close any open programs, let it run uninterrupted. It shouldn't take longer take a couple of minutes, and may only take a few seconds. Only if needed will you be prompted to reboot.

Step 4

user posted image Please download Malwarebytes Anti-Malware and save it to your desktop.
Alernative D/L mirror
Alternative D/L mirror

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.



Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

Post back with the log from Malwarebytes, let me know if the issue remains.

Kevin

8 Posts

January 3rd, 2011 04:00

Malwarebytes' Anti-Malware 1.50.1.1100

www.malwarebytes.org

 

Database version: 5447

 

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

 

3/1/2011 20:00:06

mbam-log-2011-01-03 (20-00-06).txt

 

Scan type: Quick scan

Objects scanned: 154145

Time elapsed: 7 minute(s), 18 second(s)

 

Memory Processes Infected: 1

Memory Modules Infected: 0

Registry Keys Infected: 22

Registry Values Infected: 0

Registry Data Items Infected: 6

Folders Infected: 9

Files Infected: 133

 

Memory Processes Infected:

c:\WINDOWS\kmservice.exe (RiskWare.Tool.CK) -> 700 -> Unloaded 

 

process successfully.

 

Memory Modules Infected:

(No malicious items detected)

 

Registry Keys Infected:

HKEY_CLASSES_ROOT\CLSID\{FDAEAB93-6DC0-4A63-81C6-95C88ED36F6A} 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\TypeLib\{95DF3A30-BC7B-47C5-8AEF-BCD149142217} 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{131F521B-9A5D-466C-9049-

 

37EE2B354E6D} (Adware.Sogou) -> Quarantined and deleted 

 

successfully.

HKEY_CLASSES_ROOT\SEapi.SEInterface.1 (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\SEapi.SEInterface (Adware.Sogou) -> Quarantined 

 

and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\

 

PreApproved\{FDAEAB93-6DC0-4A63-81C6-95C88ED36F6A} (Adware.Sogou) 

 

-> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\SogouExplorer.AssocFile.HTM (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\HTTP\shell\SogouExplorer (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\InternetShortcut\shell\SogouExplorer 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\file\shell\SogouExplorer (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\htmlfile\shell\SogouExplorer (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\https\shell\SogouExplorer (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\mhtmlfile\shell\SogouExplorer (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\xmlfile\shell\SogouExplorer (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\OTGV1DNWQQ (Trojan.FakeAlert) -> 

 

Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\YXE7DXCQ37 (Trojan.FakeAlert) -> 

 

Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> 

 

Quarantined and deleted successfully.

HKEY_CURRENT_USER\Software\SogouExplorer (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\SogouExplor

 

er.exe (Adware.Sogou) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\Software\SogouExplorer (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Unin

 

stall\SogouExplorer (Adware.Sogou) -> Quarantined and deleted 

 

successfully.

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS 

 

(Trojan.Renos) -> Quarantined and deleted successfully.

 

Registry Values Infected:

(No malicious items detected)

 

Registry Data Items Infected:

HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}

 

\shell\OpenHomePage\Command\(default) (Hijack.HomePage) -> Bad: 

 

("C:\Program Files\Internet Explorer\IEXPLORE.EXE" 

 

"http://hao.g3456.com/?zm") Good: (iexplore.exe) -> Quarantined 

 

and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explo

 

rer\Advanced\Start_ShowHelp (PUM.Hijack.StartMenu) -> Bad: (0) 

 

Good: (1) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Polic

 

ies\Explorer\NoSMHelp (PUM.Hijack.Help) -> Bad: (1) Good: (0) -> 

 

Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security 

 

Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> 

 

Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security 

 

Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> 

 

Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security 

 

Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: 

 

(1) Good: (0) -> Quarantined and deleted successfully.

 

Folders Infected:

c:\program files\sogouexplorer (Adware.Sogou) -> Quarantined and 

 

deleted successfully.

c:\program files\sogouexplorer\startpage (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Selector (Adware.Sogou) 

 

-> Quarantined and deleted successfully.

c:\program files\sogouexplorer\userinstruct (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\userinstruct\laan (Adware.Sogou) 

 

-> Quarantined and deleted successfully.

c:\program files\sogouexplorer\userinstruct\laan\smart 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\userinstruct\laan\smart\tween 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\Skin (Adware.Sogou) -> Quarantined 

 

and deleted successfully.

 

Files Infected:

c:\WINDOWS\kmservice.exe (RiskWare.Tool.CK) -> Quarantined and 

 

deleted successfully.

c:\program files\sogouexplorer\seapi.dll (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\WINDOWS\system32\find.exe (Malware.Tool) -> Quarantined and 

 

deleted successfully.

c:\WINDOWS\reset.exe (Trojan.Agent.CK) -> Quarantined and deleted 

 

successfully.

c:\documents and settings\jackweiqi\favorites\4399小游戏.url 

 

(Hijack.Trace) -> Quarantined and deleted successfully.

c:\documents and settings\administrator\「开始」菜单\程序\启动

 

\3113068.lnk (Malware.Trace) -> Quarantined and deleted 

 

successfully.

c:\documents and settings\jackweiqi\「开始」菜单\程序\启动

 

\3113068.lnk (Malware.Trace) -> Quarantined and deleted 

 

successfully.

c:\program files\sogouexplorer\SoDaLib.dll (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\sogouexplorer.exe (Adware.Sogou) 

 

-> Quarantined and deleted successfully.

c:\program files\sogouexplorer\sogounet.dll (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\tridentcore.dll (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\uninstall.exe (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\video_acc.dll (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\webkitcore.dll (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\webkit_plugins_file.xml 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\adbrule.dat (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\browser.conf (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\cap.se (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\changelog.txt (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\checkrange.dll (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\cmdlineparser.dll (Adware.Sogou) 

 

-> Quarantined and deleted successfully.

c:\program files\sogouexplorer\config.se (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\crashrpt.exe (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\Dialog.dll (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\dialogcore.dll (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\flashicon.ico (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\install_flash_player.exe 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\LICENSE (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\p2pclient.dll (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\p4pshare.dll (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\pxpnet.dll (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\seacc.dll (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\shareclient.dll (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\site.url (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\snapshoter.dll (Adware.Sogou) -> 

 

Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\help.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\ie.css 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\ie.js 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\iframe.html 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\iframe_wk.html 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\index1.html 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\index2.html 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\logo.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\none.jpg 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\q1.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\q2.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\rbg.jpg 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\rbg0.jpg 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\rbg2.jpg 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\rbg3.jpg 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\reset.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\sb.jpg 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\selmenu.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\set.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\setcancel.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\setok.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\shadow1.jpg 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\shadow2.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\sogou.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\sogouc.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\space.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\tran1.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\tran2.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\tran3.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\wk.css 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\wk.js 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\baidu.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\baiduc.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\checkbox.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\checkbox1.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\checkbox2.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\close.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\close.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\default.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\default.jpg 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\default_page.ico 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\fenge.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\google.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\googlec.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\guding1.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Local\guding2.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Selector\sogou_logo.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_btn_queding_hover.pn

 

g (Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_stage_arrow_zuiai.pn

 

g (Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_stage_main.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_text_1.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_zidingyi_dizhikuang.

 

gif (Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_zidingyi_icon.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_zidingyi_text.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\s_baidu_logo.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\s_google_logo.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\s_sogou_logo.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Selector\baidu_logo.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Selector\google_logo.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Selector\index.html 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Selector\pic_daohang.jpg 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Selector\pic_kongbai.jpg 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Selector\pic_sousuo.jpg 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Selector\pic_zuiai.jpg 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Selector\pic_zuiai_1.jpg 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\startpage\Selector\pic_zuiai_2.jpg 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_body_bg.jpg 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_btn_daohang.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_btn_daohang_hit.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_btn_kongbai.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_btn_kongbai_hit.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_btn_light.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_btn_qita.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_btn_queding.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_btn_queding_hit.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_btn_sousuo.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_btn_sousuo_hit.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_btn_zidingyi.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_btn_zidingyi_hit.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_btn_zuiai.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_btn_zuiai_hit.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_checkbox_checked.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_checkbox_hover.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_checkbox_normal.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_daohang_logo_bg.png 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_ico_home.gif 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_stage_arrow_daohang.

 

png (Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_stage_arrow_kongbai.

 

png (Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_stage_arrow_sousuo.p

 

ng (Adware.Sogou) -> Quarantined and deleted successfully.

c:\program 

 

files\sogouexplorer\startpage\Selector\start_stage_arrow_zidingyi

 

.png (Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\userinstruct\download.swf 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\userinstruct\passport.swf 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\userinstruct\passport_20.swf 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\userinstruct\swichcore.swf 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\userinstruct\tabscroll.swf 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\userinstruct\videoextract.swf 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\userinstruct\videoontop.swf 

 

(Adware.Sogou) -> Quarantined and deleted successfully.

c:\program files\sogouexplorer\Skin\搜狗浏览器 2010.seskin 

 

(Adware.Sogou) -> Quarantined

8 Posts

January 3rd, 2011 04:00

I have followed ur steps.  But the IE homepage is still locked to a Chinese website stated in the first post :(

2 Intern

 • 

1.1K Posts

January 3rd, 2011 05:00

Malwarebytes has removed quite a lot of Malware for us. See if you can reset the Home page in IE as follows :-

Open Internet Explorer > Select > Tools > Internet Options > With the General Tab selected delete the address of the current Home page. Next type in Google.com > Select > apply > then OK. Tap the home icon on the tool bar (little house) Has the homepage changed OK.

Next, run the following scan and post the two produced logs :-

We need to see some additional information about what is happening in your machine. 
Please perform the following scan:

  • Download DDS by sUBs from one of the following links.  Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool.   
  • When done, DDS will open two (2) logs         1. DDS.txt
             2. Attach.txt
  • Save both reports to your desktop.
  • The instructions here ask you to attach the Attach.txt.user posted image
     
  • Instead of attaching, please copy/past both logs into your next reply.
  • Close the program window, and delete the program from your desktop.


Please note:  You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet. 
Information on A/V control HERE

What i`d like in your reply :-

  • Both logs from DDS
  • Did you change home page ok.
  • Any remaining issues or concerns



Kevin

8 Posts

January 4th, 2011 01:00

I can't perform DDS, even with all my antivirus protection disabled.

8 Posts

January 4th, 2011 01:00

and homepage not changed as well

2 Intern

 • 

1.1K Posts

January 4th, 2011 02:00

Hiya kulkiz,

Obviously still some malware/infection running on your system. Proceed as follows please :-

Step 1

Please download Rkill and save to your Desktop.
  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use Link 1 from the following list and so on in sequencial order until one runs successfully.

Link 1

Link 2

Link 3

Link 4

Link 5

Link 6


  • A log pops up at the end of the run. This log file is also located at C:\rkill.log. Please post this log in your reply.
  • If you get an alert from your own Security Program, accept it and allow Rkill to run, it is very safe and will not harm your system.
  • If the tool does not run from any of the links provided, please let me know.


Do not re-boot after a successful run of RKill

Step 2

We will continue with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

Combofix

Don`t forget Combofix must be saved to your desktop. <--Very important

Before saving Combofix to your Desktop rename it to Gotcha.exe as follows:

user posted image

Ensure you have disabledyour Firewall and all anti virus and anti malware programs so they do not interfere with the running of ComboFix. <---Very important

Please include the C:\ComboFix.txt in your next reply for further review.

Examples of how to disable realtime protection available at the following link :-

Disable realtime protection


Note: Do not click combofix's window with your mouse while it's running. That action may cause it to stall.

*EXTRA NOTES*
  • If Combofix detects any Rootkit/Bootkit activity on your system it will give a warning and prompt for a reboot, you must allow it to do so.
  • If Combofix reboot's due to a rootkit, the screen may stay black for several minutes on reboot, this is normal
  • If after running Combofix you receive any type of warning message about registry key's being listed for deletion when trying to open certain items, reboot the system and this will fix the issue (Those items will not be deleted)


Post log in reply please..

Kevin






















































8 Posts

January 4th, 2011 06:00

There's sth wrong with Combofix, will reply to you tomorrow Keviin

8 Posts

January 4th, 2011 06:00

This is for Rkill log, will post the next log after it's done

 

This log file is located at C:\rkill.log. 

Please post this only if requested to by the person helping you. 

Otherwise you can close this log when you wish. 

 

Rkill was run on 1/2011 Tue at 22:10:41. 

Operating System: Microsoft Windows XP 

 

 

Processes terminated by Rkill or while it was running: 

 

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

 

 

Rkill completed on 1/2011 Tue at 22:10:47. 

2 Intern

 • 

1.1K Posts

January 4th, 2011 10:00

OK, anytime you`re ready...

No Events found!

Top