Unsolved

This post is more than 5 years old

10 Posts

669

September 25th, 2005 12:00

Winfixer help, please!!

Hello.  I need help getting rid of WinFixer also. Thanks and here are the results of my HJT log:
 
Logfile of HijackThis v1.99.1
Scan saved at 8:01:11 PM, on 9/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\SurfAccuracy\SAcc.exe
C:\WINDOWS\system32\grnnaak5.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\PeoplePC Online\bin\bartshel.exe
C:\PROGRA~1\PEOPLE~1\dialer\DIALER.EXE
C:\PROGRA~1\PEOPLE~1\bin\ppshared.exe
C:\Program Files\PeoplePC Online\bin\bartshel.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
c:\progra~1\intern~1\IEXPLORE.EXE
C:\DOCUME~1\MELANI~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_0_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PeoplePC FixedBandBHO - {3DE88907-3E38-11D4-BEB2-CBE76C0598DD} - C:\Program Files\PeoplePC Online\bin\BandObject.dll
O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_0_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Bart Station] C:\Program Files\PeoplePC Online\hta\station.sbrt
O4 - HKLM\..\Run: [PPCRunonce] C:\WINDOWS\system32\PPCRunOnce.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O4 - HKLM\..\Run: [grnnaak5] C:\WINDOWS\system32\grnnaak5.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [zfmi] C:\PROGRA~1\COMMON~1\zfmi\zfmim.exe
O4 - HKCU\..\Run: [MoxERVd2e] lodwapi.exe
O4 - HKCU\..\Run: [Spyware Begone] c:\freescan\freescan.exe -FastScan
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1125100159765
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4F4BA5AF-8A5C-42C9-BC46-1875FF9C137D}: NameServer = 209.244.0.3 209.244.0.4
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
 

10 Posts

September 25th, 2005 13:00

This is a repost of my thread I posted two days ago and no one has gotten back to me yet. Sorry to be a pain, I was just making sure that someone saw it and am so ready to get rid of it. Thanks

September 26th, 2005 19:00

Message Edited by Crossbones748 on 09-27-2005 07:42 PM

10 Posts

September 26th, 2005 23:00

Does this really work? Doesn't seem like it is very legit.

September 27th, 2005 01:00

Message Edited by Crossbones748 on 09-27-2005 07:42 PM

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 27th, 2005 14:00

*NOT* taking ownership of this thread:
 
Melanie,
 
first, a rather basic question:   on what basis are you saying that your specific problem is "winfixer"?   did you actually see a message with that name displayed on your PC?  or are you just assuming you have winfixer, because so many people have it at the moment?
 
i've glanced over your log, and while I make no claim to be an expert, and while I believe I see some items that do need further investigation, I do *not* see any classic/tell-tale signs of winfixer.  in particular, in your previous thread, you inquired about "follow[ing] atribunes instructions", but these are based on the presence of a particular O2 and O20 entry, neither of which is present in your log.
 
if your problem is a popup, that does NOT have to mean winfixer... there are many other sources of popups.

4 Apprentice

 • 

8.8K Posts

September 27th, 2005 18:00

Melanie,
As ky331's eagle eyes brought to your attention, you are not infected with Winfixer as per your log.

But you are infected with other rats.

Let's see if this helps the situation?


Be sure to look this solution over before you begin. There are a some item(s) i'm not familar with. If you recognze any, then just omit them from this fix.



Let's look for, and delete, any program segments( prefetches) that might be present, and are associated with the ' problems' we're trying to remove from this system. To do this, let's:

1) Click " Start | Search", then search for each of these program's base name(s), in all files and folders:

DIALER.EXE*

2) Then if any are found in the ' prefetch' folder, delete them.

Look closely, since the ' base' name will have a bunch of random numbers and letters attached to it.


Run HiJackThis then:

1. Click " Config..."
2. Click " Misc Tools"
3. Click " Open Process manager"

Next, while holding down the CTRL key, locate ( if present) and click on ( highlight) each of the following:

C:\Program Files\SurfAccuracy\SAcc.exe
C:\WINDOWS\system32\grnnaak5.exe
C:\PROGRA~1\PEOPLE~1\dialer\DIALER.EXE

Now double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.



Before we begin, let's move HiJackThis to it's own folder; like c:\HJT. When we're done ' cleaning' off your system, we're going to ' flush' the temporary folders which, with HiJackThis in it's current location, we'll lose both the program and the backups it creates. These backups are important in case we need to restore any 'fixed' entry(s) later.

Also move the " Backups" folder, for HiJackThis, if present.


Run HiJackThis and click " Scan", then check(tick) the following, if present:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com

R3 - Default URLSearchHook is missing

O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll (file missing)

O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll (file missing)

O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O4 - HKLM\..\Run: [grnnaak5] C:\WINDOWS\system32\grnnaak5.exe
O4 - HKCU\..\Run: [zfmi] C:\PROGRA~1\COMMON~1\zfmi\zfmim.exe
O4 - HKCU\..\Run: [MoxERVd2e] lodwapi.exe
O4 - HKCU\..\Run: [Spyware Begone] c:\freescan\freescan.exe -FastScan

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
... (Unless you've set these with a anti-spyware program like SpyBot's Immunize feature, have HiJackThis fix this.)

O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab

Now, with all windows closed except HiJackThis, click " Fix checked".


Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:

folders...
C:\Program Files\SurfAccuracy
C:\PROGRA~1\PEOPLE~1
C:\PROGRA~1\COMMON~1\zfmi
c:\freescan

files...
C:\WINDOWS\system32\grnnaak5.exe

Search for...

lodwapi.exe

...using " Start | Search...".

Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".


Reboot and post back a new log, and let me know how everything goes.
Steve
-

10 Posts

September 27th, 2005 21:00

Thanks for everyone's help. The problem I have been having is that the winfixer pop up happens and then it starts to automatically scan my system but I have to back out of it to get it to stop. Now I am confused on what to do since someone said according to my log, I don't have a winfixer problem. Should I continue with the instructions that were posted above? I just don't want to mess anything up, but that pop up is annoying me very much.

10 Posts

September 27th, 2005 22:00

Please ignore this message. Since it took so long for anyone to get back to me on this board,I went to another board, atribune.com and posted this exact same log and got the help I needed.  

4 Apprentice

 • 

8.8K Posts

September 28th, 2005 00:00

Melanie,

My hat's off to the person that managed to fix the system, clean the mess created by the trojans I saw in the log, and STILL give you enough time to check your email and post this last message.

Please have him contact me here and let ME know his secrets.

Regards,
Steve
No Events found!

Top