Unsolved
This post is more than 5 years old
8 Posts
0
1389
January 2nd, 2011 04:00
Homepage locked
Hi, I have downloaded a Chinese software and installed it. Unfortunately, it appeared to have spyware and locked my IE homepage to . I have tried many times to remove it through Internet Options and reset homepage. But it doesn't work. Here's the log from the HJT, please help.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:27:03, on 2/1/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\eBoostr\eBoostrCP.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\eBoostr\EBstrSvc.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\srvany.exe
C:\Program Files\MacroData Inc\NetDrive\ndsvc.exe
C:\WINDOWS\KMService.exe
C:\WINDOWS\system32\conime.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: NaverToolbar Helper - {67C41E9E-2EBF-4F2B-AF74-314F0D793172} - C:\Program Files\naver\NaverToolbar\NaverTB_3_5_5_49.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: TSWebMon - {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Veoh Web Player Toolbar - {cd90bf73-20f6-44ef-993d-bb920303bd2e} - C:\Program Files\Veoh_Web_Player\tbVeo2.dll
O2 - BHO: Thunder ToolbarBrowserHelper - {D2F8A635-8B0F-47BF-915E-6F456767A300} - C:\Program Files\Thunder Network\MiniThunder\ToolBarNow.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Veoh Web Player Toolbar - {cd90bf73-20f6-44ef-993d-bb920303bd2e} - C:\Program Files\Veoh_Web_Player\tbVeo2.dll
O3 - Toolbar: ??? ??(&N) - {D09CFF09-A42A-4EDC-9804-E61224F59CA1} - C:\Program Files\naver\NaverToolbar\NaverTB_3_5_5_49.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ctfmon] ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1284193081031
O16 - DPF: {6CE20149-ABE3-462E-A1B4-5B549971AA38} (XecureCKKB Class) -
O16 - DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} (HanSetupCtrl1010 Class) - https://members.hangame.com/common/HanSetup1040.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui 啎樓婥最唗 - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: 郪璃濬梗遣湔最唗 - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: eBoostr Service (EBOOSTRSVC) - eBoostr.com - C:\Program Files\eBoostr\EBstrSvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KMService - Unknown owner - C:\WINDOWS\system32\srvany.exe
O23 - Service: NetDrive Service (ndsvc) - MacroData Inc. - C:\Program Files\MacroData Inc\NetDrive\ndsvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Virtual PDF Printer (Service1) - Unknown owner - C:\Program Files\Virtual PDF Printer\VirtualPrinting.exe
--
End of file - 8938 bytes


kulkiz
8 Posts
0
January 2nd, 2011 04:00
Srry forgot to say the locked homepage is http://hao.g3456.com/?91
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
January 2nd, 2011 08:00
I'm kevinf80 and I will be helping with any malware issues you may have with your system.
Please proceed as follows :-
Step 1
Please re-open HiJackThis and scan only. Check the boxes next to all the entries listed below.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: NaverToolbar Helper - {67C41E9E-2EBF-4F2B-AF74-314F0D793172} - C:\Program Files\naver\NaverToolbar\NaverTB_3_5_5_49.dll
O2 - BHO: TSWebMon - {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} - (no file)
O2 - BHO: Thunder ToolbarBrowserHelper - {D2F8A635-8B0F-47BF-915E-6F456767A300} - C:\Program Files\Thunder Network\MiniThunder\ToolBarNow.dll
O3 - Toolbar: ??? ??(&N) - {D09CFF09-A42A-4EDC-9804-E61224F59CA1} - C:\Program Files\naver\NaverToolbar\NaverTB_3_5_5_49.dll
Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. Reboot
Step 2
Please go to Start > Control Panel > Add/Remove Programs and remove the following (if present):
naver
Thunder Network
Step 3
Download
Link 1
Link 2
TFC will automatically close any open programs, let it run uninterrupted. It shouldn't take longer take a couple of minutes, and may only take a few seconds. Only if needed will you be prompted to reboot.
Step 4
Alernative D/L mirror
Alternative D/L mirror
Double Click mbam-setup.exe to install the application.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Post back with the log from Malwarebytes, let me know if the issue remains.
Kevin
kulkiz
8 Posts
0
January 3rd, 2011 04:00
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5447
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
3/1/2011 20:00:06
mbam-log-2011-01-03 (20-00-06).txt
Scan type: Quick scan
Objects scanned: 154145
Time elapsed: 7 minute(s), 18 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 22
Registry Values Infected: 0
Registry Data Items Infected: 6
Folders Infected: 9
Files Infected: 133
Memory Processes Infected:
c:\WINDOWS\kmservice.exe (RiskWare.Tool.CK) -> 700 -> Unloaded
process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{FDAEAB93-6DC0-4A63-81C6-95C88ED36F6A}
(Adware.Sogou) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{95DF3A30-BC7B-47C5-8AEF-BCD149142217}
(Adware.Sogou) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{131F521B-9A5D-466C-9049-
37EE2B354E6D} (Adware.Sogou) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\SEapi.SEInterface.1 (Adware.Sogou) ->
Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\SEapi.SEInterface (Adware.Sogou) -> Quarantined
and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\
PreApproved\{FDAEAB93-6DC0-4A63-81C6-95C88ED36F6A} (Adware.Sogou)
-> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\SogouExplorer.AssocFile.HTM (Adware.Sogou) ->
Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\HTTP\shell\SogouExplorer (Adware.Sogou) ->
Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\InternetShortcut\shell\SogouExplorer
(Adware.Sogou) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\file\shell\SogouExplorer (Adware.Sogou) ->
Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\htmlfile\shell\SogouExplorer (Adware.Sogou) ->
Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\https\shell\SogouExplorer (Adware.Sogou) ->
Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mhtmlfile\shell\SogouExplorer (Adware.Sogou) ->
Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\xmlfile\shell\SogouExplorer (Adware.Sogou) ->
Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\OTGV1DNWQQ (Trojan.FakeAlert) ->
Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\YXE7DXCQ37 (Trojan.FakeAlert) ->
Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) ->
Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\SogouExplorer (Adware.Sogou) ->
Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\SogouExplor
er.exe (Adware.Sogou) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\Software\SogouExplorer (Adware.Sogou) ->
Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Unin
stall\SogouExplorer (Adware.Sogou) -> Quarantined and deleted
successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS
(Trojan.Renos) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}
\shell\OpenHomePage\Command\(default) (Hijack.HomePage) -> Bad:
("C:\Program Files\Internet Explorer\IEXPLORE.EXE"
"http://hao.g3456.com/?zm") Good: (iexplore.exe) -> Quarantined
and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explo
rer\Advanced\Start_ShowHelp (PUM.Hijack.StartMenu) -> Bad: (0)
Good: (1) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Polic
ies\Explorer\NoSMHelp (PUM.Hijack.Help) -> Bad: (1) Good: (0) ->
Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) ->
Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) ->
Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad:
(1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
c:\program files\sogouexplorer (Adware.Sogou) -> Quarantined and
deleted successfully.
c:\program files\sogouexplorer\startpage (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Selector (Adware.Sogou)
-> Quarantined and deleted successfully.
c:\program files\sogouexplorer\userinstruct (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\userinstruct\laan (Adware.Sogou)
-> Quarantined and deleted successfully.
c:\program files\sogouexplorer\userinstruct\laan\smart
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\userinstruct\laan\smart\tween
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\Skin (Adware.Sogou) -> Quarantined
and deleted successfully.
Files Infected:
c:\WINDOWS\kmservice.exe (RiskWare.Tool.CK) -> Quarantined and
deleted successfully.
c:\program files\sogouexplorer\seapi.dll (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\WINDOWS\system32\find.exe (Malware.Tool) -> Quarantined and
deleted successfully.
c:\WINDOWS\reset.exe (Trojan.Agent.CK) -> Quarantined and deleted
successfully.
c:\documents and settings\jackweiqi\favorites\4399小游戏.url
(Hijack.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\「开始」菜单\程序\启动
\3113068.lnk (Malware.Trace) -> Quarantined and deleted
successfully.
c:\documents and settings\jackweiqi\「开始」菜单\程序\启动
\3113068.lnk (Malware.Trace) -> Quarantined and deleted
successfully.
c:\program files\sogouexplorer\SoDaLib.dll (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\sogouexplorer.exe (Adware.Sogou)
-> Quarantined and deleted successfully.
c:\program files\sogouexplorer\sogounet.dll (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\tridentcore.dll (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\uninstall.exe (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\video_acc.dll (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\webkitcore.dll (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\webkit_plugins_file.xml
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\adbrule.dat (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\browser.conf (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\cap.se (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\changelog.txt (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\checkrange.dll (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\cmdlineparser.dll (Adware.Sogou)
-> Quarantined and deleted successfully.
c:\program files\sogouexplorer\config.se (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\crashrpt.exe (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\Dialog.dll (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\dialogcore.dll (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\flashicon.ico (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\install_flash_player.exe
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\LICENSE (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\p2pclient.dll (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\p4pshare.dll (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\pxpnet.dll (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\seacc.dll (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\shareclient.dll (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\site.url (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\snapshoter.dll (Adware.Sogou) ->
Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\help.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\ie.css
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\ie.js
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\iframe.html
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\iframe_wk.html
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\index1.html
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\index2.html
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\logo.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\none.jpg
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\q1.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\q2.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\rbg.jpg
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\rbg0.jpg
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\rbg2.jpg
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\rbg3.jpg
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\reset.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\sb.jpg
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\selmenu.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\set.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\setcancel.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\setok.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\shadow1.jpg
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\shadow2.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\sogou.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\sogouc.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\space.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\tran1.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\tran2.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\tran3.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\wk.css
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\wk.js
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\baidu.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\baiduc.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\checkbox.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\checkbox1.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\checkbox2.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\close.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\close.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\default.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\default.jpg
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\default_page.ico
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\fenge.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\google.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\googlec.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\guding1.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Local\guding2.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Selector\sogou_logo.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_btn_queding_hover.pn
g (Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_stage_arrow_zuiai.pn
g (Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_stage_main.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_text_1.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_zidingyi_dizhikuang.
gif (Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_zidingyi_icon.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_zidingyi_text.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\s_baidu_logo.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\s_google_logo.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\s_sogou_logo.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Selector\baidu_logo.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Selector\google_logo.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Selector\index.html
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Selector\pic_daohang.jpg
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Selector\pic_kongbai.jpg
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Selector\pic_sousuo.jpg
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Selector\pic_zuiai.jpg
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Selector\pic_zuiai_1.jpg
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\startpage\Selector\pic_zuiai_2.jpg
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_body_bg.jpg
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_btn_daohang.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_btn_daohang_hit.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_btn_kongbai.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_btn_kongbai_hit.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_btn_light.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_btn_qita.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_btn_queding.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_btn_queding_hit.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_btn_sousuo.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_btn_sousuo_hit.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_btn_zidingyi.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_btn_zidingyi_hit.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_btn_zuiai.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_btn_zuiai_hit.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_checkbox_checked.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_checkbox_hover.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_checkbox_normal.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_daohang_logo_bg.png
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_ico_home.gif
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_stage_arrow_daohang.
png (Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_stage_arrow_kongbai.
png (Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_stage_arrow_sousuo.p
ng (Adware.Sogou) -> Quarantined and deleted successfully.
c:\program
files\sogouexplorer\startpage\Selector\start_stage_arrow_zidingyi
.png (Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\userinstruct\download.swf
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\userinstruct\passport.swf
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\userinstruct\passport_20.swf
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\userinstruct\swichcore.swf
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\userinstruct\tabscroll.swf
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\userinstruct\videoextract.swf
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\userinstruct\videoontop.swf
(Adware.Sogou) -> Quarantined and deleted successfully.
c:\program files\sogouexplorer\Skin\搜狗浏览器 2010.seskin
(Adware.Sogou) -> Quarantined
kulkiz
8 Posts
0
January 3rd, 2011 04:00
I have followed ur steps. But the IE homepage is still locked to a Chinese website stated in the first post :(
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
January 3rd, 2011 05:00
Malwarebytes has removed quite a lot of Malware for us. See if you can reset the Home page in IE as follows :-
Open Internet Explorer > Select > Tools > Internet Options > With the General Tab selected delete the address of the current Home page. Next type in Google.com > Select > apply > then OK. Tap the home icon on the tool bar (little house) Has the homepage changed OK.
Next, run the following scan and post the two produced logs :-
We need to see some additional information about what is happening in your machine.
Please perform the following scan:
2. Attach.txt
Please note: You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control HERE
What i`d like in your reply :-
Kevin
kulkiz
8 Posts
0
January 4th, 2011 01:00
I can't perform DDS, even with all my antivirus protection disabled.
kulkiz
8 Posts
0
January 4th, 2011 01:00
and homepage not changed as well
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
January 4th, 2011 02:00
Obviously still some malware/infection running on your system. Proceed as follows please :-
Step 1
Please download Rkill and save to your Desktop.
Link 1
Link 2
Link 3
Link 4
Link 5
Link 6
Do not re-boot after a successful run of RKill
Step 2
We will continue with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:
Combofix
Don`t forget Combofix must be saved to your desktop. <--Very important
Before saving Combofix to your Desktop rename it to Gotcha.exe as follows:
Ensure you have disabledyour Firewall and all anti virus and anti malware programs so they do not interfere with the running of ComboFix. <---Very important
Please include the C:\ComboFix.txt in your next reply for further review.
Examples of how to disable realtime protection available at the following link :-
Disable realtime protection
Note: Do not click combofix's window with your mouse while it's running. That action may cause it to stall.
*EXTRA NOTES*
Post log in reply please..
Kevin
kulkiz
8 Posts
0
January 4th, 2011 06:00
There's sth wrong with Combofix, will reply to you tomorrow Keviin
kulkiz
8 Posts
0
January 4th, 2011 06:00
This is for Rkill log, will post the next log after it's done
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 1/2011 Tue at 22:10:41.
Operating System: Microsoft Windows XP
Processes terminated by Rkill or while it was running:
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jackweiqi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
Rkill completed on 1/2011 Tue at 22:10:47.
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
January 4th, 2011 10:00
OK, anytime you`re ready...