UNSOLVED

Frostilicus

updated

21 years ago

F

Frostilicus

16 Posts

0

2019

July 12th, 2005 06:00

StartPage-DU.dll Trojan

Alright, I got this StartPage-DU.dll thing today, and I'm having NO luck getting rid of it. I've tried & tried to get rid of the virus, but can't. I don't know if it's even what I am supposed to do, but I ran ewido and hijackthis and will post both logfiles. If anyone can help me, PLEASE do. I also realize that this might belong in the virus/spyware section, however since I've got the hijackthis log to go with it, I figured it would be alright here. Any help you can offer will be appreciated. Another note: McAfee and Ewido bring up warnings saying that the files infected are in the system32 folder. I don't know what this means, but when I tried to reboot my computer just now, I got a bunch of messages saying that several files could not be found in the system32 folder. I'm sorry if this is too much info, but I really need help. (I'm not sure if it's normal, but my ewido logfile is like, 57,000 characters. I can't really post that on here, so I don't know what to do. What are the important parts I can single out?)

Logfile of HijackThis v1.99.0
Scan saved at 11:38:20 PM, on 7/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Josh\My Documents\HijackThis\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\aqnar.dll/sp.html#55135
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\aqnar.dll/sp.html#55135
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\aqnar.dll/sp.html#55135
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\aqnar.dll/sp.html#55135
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\aqnar.dll/sp.html#55135
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\aqnar.dll/sp.html#55135
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: Class - {7085B7F3-6735-6A89-5650-95D1C3942B93} - C:\WINDOWS\syspw.dll
O2 - BHO: Class - {ABD21B9C-E941-0D73-3CFC-DA88CA3C766E} - C:\WINDOWS\system32\atlyb32.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr__.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [apifv.exe] C:\WINDOWS\system32\apifv.exe
O4 - HKLM\..\RunOnce: [addyy.exe] C:\WINDOWS\system32\addyy.exe
O4 - HKLM\..\RunOnce: [apiqu32.exe] C:\WINDOWS\apiqu32.exe
O4 - HKLM\..\RunOnce: [mfczv.exe] C:\WINDOWS\system32\mfczv.exe
O4 - HKLM\..\RunOnce: [addyq.exe] C:\WINDOWS\addyq.exe
O4 - HKLM\..\RunOnce: [d3rp32.exe] C:\WINDOWS\system32\d3rp32.exe
O4 - HKLM\..\RunOnce: [crug.exe] C:\WINDOWS\system32\crug.exe
O4 - HKLM\..\RunOnce: [winkt.exe] C:\WINDOWS\winkt.exe
O4 - HKLM\..\RunOnce: [netzi32.exe] C:\WINDOWS\system32\netzi32.exe
O4 - HKLM\..\RunOnce: [atlpy32.exe] C:\WINDOWS\system32\atlpy32.exe
O4 - HKLM\..\RunOnce: [appak32.exe] C:\WINDOWS\appak32.exe
O4 - HKLM\..\RunOnce: [crmb.exe] C:\WINDOWS\system32\crmb.exe
O4 - HKLM\..\RunOnce: [javaqs32.exe] C:\WINDOWS\system32\javaqs32.exe
O4 - HKLM\..\RunOnce: [javaep.exe] C:\WINDOWS\javaep.exe
O4 - HKLM\..\RunOnce: [mfcjt.exe] C:\WINDOWS\mfcjt.exe
O4 - HKLM\..\RunOnce: [sdkzj.exe] C:\WINDOWS\sdkzj.exe
O4 - HKLM\..\RunOnce: [sysds.exe] C:\WINDOWS\sysds.exe
O4 - HKLM\..\RunOnce: [netvc32.exe] C:\WINDOWS\netvc32.exe
O4 - HKLM\..\RunOnce: [sysgi.exe] C:\WINDOWS\system32\sysgi.exe
O4 - HKLM\..\RunOnce: [syseg32.exe] C:\WINDOWS\system32\syseg32.exe
O4 - HKLM\..\RunOnce: [crry.exe] C:\WINDOWS\crry.exe
O4 - HKLM\..\RunOnce: [iepg32.exe] C:\WINDOWS\iepg32.exe
O4 - HKLM\..\RunOnce: [d3jg.exe] C:\WINDOWS\d3jg.exe
O4 - HKLM\..\RunOnce: [netzq32.exe] C:\WINDOWS\netzq32.exe
O4 - HKLM\..\RunOnce: [ipvi32.exe] C:\WINDOWS\system32\ipvi32.exe
O4 - HKLM\..\RunOnce: [crrg.exe] C:\WINDOWS\system32\crrg.exe
O4 - HKLM\..\RunOnce: [apilx32.exe] C:\WINDOWS\apilx32.exe
O4 - HKLM\..\RunOnce: [javauq32.exe] C:\WINDOWS\javauq32.exe
O4 - HKLM\..\RunOnce: [ntya.exe] C:\WINDOWS\system32\ntya.exe
O4 - HKLM\..\RunOnce: [syseo.exe] C:\WINDOWS\system32\syseo.exe
O4 - HKLM\..\RunOnce: [javaxf32.exe] C:\WINDOWS\javaxf32.exe
O4 - HKLM\..\RunOnce: [cria.exe] C:\WINDOWS\system32\cria.exe
O4 - HKLM\..\RunOnce: [ipbr32.exe] C:\WINDOWS\system32\ipbr32.exe
O4 - HKLM\..\RunOnce: [sysmw32.exe] C:\WINDOWS\system32\sysmw32.exe
O4 - HKLM\..\RunOnce: [javavm32.exe] C:\WINDOWS\system32\javavm32.exe
O4 - HKLM\..\RunOnce: [iekx.exe] C:\WINDOWS\system32\iekx.exe
O4 - HKLM\..\RunOnce: [mswd32.exe] C:\WINDOWS\system32\mswd32.exe
O4 - HKLM\..\RunOnce: [ntnk32.exe] C:\WINDOWS\system32\ntnk32.exe
O4 - HKLM\..\RunOnce: [d3ly.exe] C:\WINDOWS\d3ly.exe
O4 - HKLM\..\RunOnce: [atlam32.exe] C:\WINDOWS\atlam32.exe
O4 - HKLM\..\RunOnce: [ipcf.exe] C:\WINDOWS\ipcf.exe
O4 - HKLM\..\RunOnce: [ipqu.exe] C:\WINDOWS\ipqu.exe
O4 - HKLM\..\RunOnce: [netzs.exe] C:\WINDOWS\system32\netzs.exe
O4 - HKLM\..\RunOnce: [wincn.exe] C:\WINDOWS\system32\wincn.exe
O4 - HKLM\..\RunOnce: [ntcv32.exe] C:\WINDOWS\ntcv32.exe
O4 - HKLM\..\RunOnce: [d3en32.exe] C:\WINDOWS\system32\d3en32.exe
O4 - HKLM\..\RunOnce: [ipig.exe] C:\WINDOWS\system32\ipig.exe
O4 - HKLM\..\RunOnce: [atljb32.exe] C:\WINDOWS\system32\atljb32.exe
O4 - HKLM\..\RunOnce: [addkb32.exe] C:\WINDOWS\addkb32.exe
O4 - HKLM\..\RunOnce: [crol.exe] C:\WINDOWS\crol.exe
O4 - HKLM\..\RunOnce: [apire32.exe] C:\WINDOWS\apire32.exe
O4 - HKLM\..\RunOnce: [atlke.exe] C:\WINDOWS\system32\atlke.exe
O4 - HKLM\..\RunOnce: [msox32.exe] C:\WINDOWS\system32\msox32.exe
O4 - HKLM\..\RunOnce: [crpx32.exe] C:\WINDOWS\system32\crpx32.exe
O4 - HKLM\..\RunOnce: [javaxs.exe] C:\WINDOWS\system32\javaxs.exe
O4 - HKLM\..\RunOnce: [atlyv.exe] C:\WINDOWS\atlyv.exe
O4 - HKLM\..\RunOnce: [syshi32.exe] C:\WINDOWS\syshi32.exe
O4 - HKLM\..\RunOnce: [iepd.exe] C:\WINDOWS\iepd.exe
O4 - HKLM\..\RunOnce: [atlzb.exe] C:\WINDOWS\system32\atlzb.exe
O4 - HKLM\..\RunOnce: [atlaf.exe] C:\WINDOWS\system32\atlaf.exe
O4 - HKLM\..\RunOnce: [d3lu32.exe] C:\WINDOWS\system32\d3lu32.exe
O4 - HKLM\..\RunOnce: [netjc.exe] C:\WINDOWS\netjc.exe
O4 - HKLM\..\RunOnce: [mfcav32.exe] C:\WINDOWS\system32\mfcav32.exe
O4 - HKLM\..\RunOnce: [ntri32.exe] C:\WINDOWS\system32\ntri32.exe
O4 - HKLM\..\RunOnce: [ipmr.exe] C:\WINDOWS\ipmr.exe
O4 - HKLM\..\RunOnce: [sdkat.exe] C:\WINDOWS\system32\sdkat.exe
O4 - HKLM\..\RunOnce: [sdkgq.exe] C:\WINDOWS\sdkgq.exe
O4 - HKLM\..\RunOnce: [crow32.exe] C:\WINDOWS\system32\crow32.exe
O4 - HKLM\..\RunOnce: [ipej32.exe] C:\WINDOWS\ipej32.exe
O4 - HKLM\..\RunOnce: [d3xi.exe] C:\WINDOWS\system32\d3xi.exe
O4 - HKLM\..\RunOnce: [javagi32.exe] C:\WINDOWS\system32\javagi32.exe
O4 - HKLM\..\RunOnce: [craz32.exe] C:\WINDOWS\system32\craz32.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://courses.mindleaders.com/dpec/shared/cabs/awswaxf.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,74/mcinsctl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,16/mcgdmgr.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.15.36/ttinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v5.cab
O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)
O23 - Service: Network Security Service - Unknown - C:\WINDOWS\system32\addyy.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
  • ALgal

    1188 Posts

    895

    0

    Posted July 12th, 2005 16:00

    Hello Frosticilus,

    I will be posting a fixes shortly but please help us out! 

    You have a number of files that we would like copies of - to check out and play with.

    1. Using Windows Explorer, go to My Computer =>C =>Windows. Please note that many files are in C:\Windows\system32 so you will have to go to the system32 folder to locate them. Locate the first file you want to zip.

    C:\WINDOWS\syspw.dll
    2. Right click on the file and select "Send To" and "Compressed (zipped) Folder".

    3. Then locate and right click on
    C:\WINDOWS\system32\addyy.exe
     

    4. Select "Copy".

    5. Right click on the compressed folder and select "Paste". The copied files will be compressed and pasted in.

    6. Repeat steps 3. to 5. for the following files
    C:\WINDOWS\system32\aqnar.dll
    C:\WINDOWS\apiqu32.exe

    C:\WINDOWS\system32\mfczv.exe
    C:\WINDOWS\system32\d3rp32.exe
    Note that the folder should have 6 files in it if you found them all.

    7. Right click on the zipped folder and select "Explore".

    8. In "File" menu select "Add a Password". Enter the password infected and confirm the password.

    9. Please email to  cjwd-subAThostingatessex.com (Please replace the 'AT' with an '@' )
    Please copy the following to the email  and attach the zipped file(s) :

    The password is "infected".
    The thread is found here. [URL=http://forums.us.dell.com/supportforums/board/post?board.id=si_hijack&message.reply_to_id=8605]
    Paste it in the text field and send please.

     

    If you could do this, we  would be very appreciative!

     

     

  • ALgal

    1188 Posts

    895

    0

    Posted July 12th, 2005 17:00

    Hello Frosticilus,

     

    First of all I need you to download some programs for use later.

    Download this file and unzip it to your desktop

    Download About:Buster from here. Once it is downloaded extract it to c:\aboutbuster and check for updates. Do NOT use it yet

    Download CWShredder from here, install it, check for updates but again, don't use it yet.

    Then, Download Ad-aware Second Edition here and install it. If you already have Ad-aware Second Edition skip to the next step.

    Open adaware and Click the "Check for updates now" line on the main screen. CLick the "Connect" button on the webupdate screen.

    If an update is available download it and install it. Click the "Finish" button to go back to the main screen.

    Click on the "Settings" button (gear symbol in the upper right corner of the main status screen) in the quick launch toolbar to open the General settings screen. Check the "Automatically quarantine objects prior to removal" setting and then click "Proceed" to save your changes

    Click the "Scan now" button in the main menu on the left side of the main status screen or use the "Start" button in lower right corner. This will open the Preparing System Scan screen. Please deselect "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat. Then select "Use custom scanning options" and click "CUstomize". This will open the "Scan Settings Page. Make sure all of the following are On with a "green" checkmark:

    Scan within archives
    Scan active processes
    Scan Registry
    Deep-scan Registry
    Scan my IE Favorites for banned URLs
    Scan my Hosts File

    Then click on the "Tweak" Button to open up the tweak settings.

    Open up the Scanning Engine section and make sure all of the following are On with a "green" checkmark:

    Scan registry for all users instead of current user only

    Make sure the following is unchecked with a "red" X:

    Unload recognized processes & modules during scan.

    Open up the Cleaning Engine section and make sure all of the following are On with a "green" checkmark:

    Always try to unload modules before deletion
    During Removal, unload Explorer and IE if necessary
    Let Windows remove files in use at next reboot.

    Click the "Proceed" button to save settings.

    Don't scan yet. We will do it in safe mode.

    Ensure hidden files and folders are set to show;

     

    • Click Start.
    • Open My Computer.
    • Select the Tools menu and click Folder Options.
    • Select the View Tab.
    • Under the Hidden files and folders heading select Show hidden files and folders.
    • Uncheck the Hide protected operating system files (recommended) option.
    • Click Yes to confirm.
    • Click OK.


    Next, go to Start->Run and type "Services.msc" (without quotes) then hit Ok

    Scroll down and find the service called . When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows.

    Please disconnect from the Internet and unplug your modem for the duration of this fix You may want to print the rest of these instructions.

    Reboot your computer into Safe Mode by tapping F8 while booting up and continue for the rest of the fix in SAFE MODE

    While in safe mode, double click on the cwsserviceemove.reg file you downloaded at the beginning. Grant it permission to add the registry items.

    Then Open cwshredder that you downloaded in the first step. Close all browser windows and click on the fix/next button.

    Bring up task manager Ctrl-Alt-Del and end these processes if they are present

    addyy.exe
    apiqu32.exe
    mfczv.exe

    addyq.exe
    d3rp32.exe
    crug.exe
    winkt.exe

    netzi32.exe
    atlpy32.exe

    appak32.exe
    crmb.exe
    javaqs32.exe
    javaep.exe
    mfcjt.exe
    sdkzj.exe
    sysds.exe

    netvc32.exe
    sysgi.exe
    syseg32.exe
    crry.exe

    iepg32.exe
    d3jg.exe
    netzq32.exe
    ipvi32.exe
    crrg.exe
    apilx32.exe
    javauq32.exe
    ntya.exe
    syseo.exe
    javaxf32.exe
    cria.exe
    ipbr32.exe
    sysmw32.exe
    javavm32.exe
    iekx.exe
    mswd32.exe
    ntnk32.exe
    d3ly.exe
    atlam32.exe
    ipcf.exe
    ipqu.exe
    netzs.exe
    wincn.exe
    ntcv32.exe
    d3en32.exe
    ipig.exe
    atljb32.exe
    addkb32.exe
    crol.exe

    apire32.exe
    atlke.exe
    msox32.exe
    crpx32.exe
    javaxs.exe
    atlyv.exe

    syshi32.exe
    iepd.exe
    atlzb.exe
    atlaf.exe
    d3lu32.exe
    netjc.exe
    mfcav32.exe
    ntri32.exe
    ipmr.exe
    sdkat.exe
    sdkgq.exe
    crow32.exe
    ipej32.exe
    d3xi.exe
    javagi32.exe
    craz32.exe

    I am continuing the fix in the next reply so don't stop here.

  • ALgal

    1188 Posts

    895

    0

    Posted July 12th, 2005 17:00

    Now find and delete these files, if you can't find one then don't worry.. just move on to the next one.

     

    C:\WINDOWS\system32\aqnar.dll

    C:\WINDOWS\syspw.dll

    C:\WINDOWS\system32\atlyb32.dll

    C:\WINDOWS\system32\addyy.exe
    C:\WINDOWS\apiqu32.exe
    C:\WINDOWS\system32\mfczv.exe

    C:\WINDOWS\addyq.exe
    C:\WINDOWS\system32\d3rp32.exe
    C:\WINDOWS\system32\crug.exe
    C:\WINDOWS\winkt.exe

    C:\WINDOWS\system32\netzi32.exe
    C:\WINDOWS\system32\atlpy32.exe

    C:\WINDOWS\appak32.exe
    C:\WINDOWS\system32\crmb.exe
    C:\WINDOWS\system32\javaqs32.exe
    C:\WINDOWS\javaep.exe
    C:\WINDOWS\mfcjt.exe
    C:\WINDOWS\sdkzj.exe
    C:\WINDOWS\sysds.exe

    C:\WINDOWS\netvc32.exe
    C:\WINDOWS\system32\sysgi.exe
    C:\WINDOWS\system32\syseg32.exe
    C:\WINDOWS\crry.exe

    C:\WINDOWS\iepg32.exe
    C:\WINDOWS\d3jg.exe
    C:\WINDOWS\netzq32.exe
    C:\WINDOWS\system32\ipvi32.exe
    C:\WINDOWS\system32\crrg.exe
    C:\WINDOWS\apilx32.exe
    C:\WINDOWS\javauq32.exe
    C:\WINDOWS\system32\ntya.exe
    C:\WINDOWS\system32\syseo.exe
    C:\WINDOWS\javaxf32.exe
    C:\WINDOWS\system32\cria.exe
    C:\WINDOWS\system32\ipbr32.exe
    C:\WINDOWS\system32\sysmw32.exe
    C:\WINDOWS\system32\javavm32.exe
    C:\WINDOWS\system32\iekx.exe
    C:\WINDOWS\system32\mswd32.exe
    C:\WINDOWS\system32\ntnk32.exe
    C:\WINDOWS\d3ly.exe
    C:\WINDOWS\atlam32.exe
    C:\WINDOWS\ipcf.exe
    C:\WINDOWS\ipqu.exe
    C:\WINDOWS\system32\netzs.exe
    C:\WINDOWS\system32\wincn.exe
    C:\WINDOWS\ntcv32.exe
    C:\WINDOWS\system32\d3en32.exe
    C:\WINDOWS\system32\ipig.exe
    C:\WINDOWS\system32\atljb32.exe
    C:\WINDOWS\addkb32.exe
    C:\WINDOWS\crol.exe

    C:\WINDOWS\apire32.exe
    C:\WINDOWS\system32\atlke.exe
    C:\WINDOWS\system32\msox32.exe
    C:\WINDOWS\system32\crpx32.exe
    C:\WINDOWS\system32\javaxs.exe
    C:\WINDOWS\atlyv.exe

    C:\WINDOWS\syshi32.exe
    C:\WINDOWS\iepd.exe
    C:\WINDOWS\system32\atlzb.exe
    C:\WINDOWS\system32\atlaf.exe
    C:\WINDOWS\system32\d3lu32.exe
    C:\WINDOWS\netjc.exe
    C:\WINDOWS\system32\mfcav32.exe
    C:\WINDOWS\system32\ntri32.exe
    C:\WINDOWS\ipmr.exe
    C:\WINDOWS\system32\sdkat.exe
    C:\WINDOWS\sdkgq.exe
    C:\WINDOWS\system32\crow32.exe
    C:\WINDOWS\ipej32.exe
    C:\WINDOWS\system32\d3xi.exe
    C:\WINDOWS\system32\javagi32.exe
    C:\WINDOWS\system32\craz32.exe

    C:\WINDOWS\system32\addyy.exe


    Now run hijackthis and click the scan button, when it has finished scanning put a check against the following and click 'fix checked'

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\aqnar.dll/sp.html#55135
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\aqnar.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\aqnar.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\aqnar.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\aqnar.dll/sp.html#55135
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\aqnar.dll/sp.html#55135

    R3 - Default URLSearchHook is missing

    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: Class - {7085B7F3-6735-6A89-5650-95D1C3942B93} - C:\WINDOWS\syspw.dll
    O2 - BHO: Class - {ABD21B9C-E941-0D73-3CFC-DA88CA3C766E} - C:\WINDOWS\system32\atlyb32.dll

    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr__.exe
    O4 - HKLM\..\Run: [apifv.exe] C:\WINDOWS\system32\apifv.exe
    O4 - HKLM\..\RunOnce: [addyy.exe] C:\WINDOWS\system32\addyy.exe
    O4 - HKLM\..\RunOnce: [apiqu32.exe] C:\WINDOWS\apiqu32.exe
    O4 - HKLM\..\RunOnce: [mfczv.exe] C:\WINDOWS\system32\mfczv.exe
    O4 - HKLM\..\RunOnce: [addyq.exe] C:\WINDOWS\addyq.exe
    O4 - HKLM\..\RunOnce: [d3rp32.exe] C:\WINDOWS\system32\d3rp32.exe
    O4 - HKLM\..\RunOnce: [crug.exe] C:\WINDOWS\system32\crug.exe
    O4 - HKLM\..\RunOnce: [winkt.exe] C:\WINDOWS\winkt.exe
    O4 - HKLM\..\RunOnce: [netzi32.exe] C:\WINDOWS\system32\netzi32.exe
    O4 - HKLM\..\RunOnce: [atlpy32.exe] C:\WINDOWS\system32\atlpy32.exe
    O4 - HKLM\..\RunOnce: [appak32.exe] C:\WINDOWS\appak32.exe
    O4 - HKLM\..\RunOnce: [crmb.exe] C:\WINDOWS\system32\crmb.exe
    O4 - HKLM\..\RunOnce: [javaqs32.exe] C:\WINDOWS\system32\javaqs32.exe
    O4 - HKLM\..\RunOnce: [javaep.exe] C:\WINDOWS\javaep.exe
    O4 - HKLM\..\RunOnce: [mfcjt.exe] C:\WINDOWS\mfcjt.exe
    O4 - HKLM\..\RunOnce: [sdkzj.exe] C:\WINDOWS\sdkzj.exe
    O4 - HKLM\..\RunOnce: [sysds.exe] C:\WINDOWS\sysds.exe
    O4 - HKLM\..\RunOnce: [netvc32.exe] C:\WINDOWS\netvc32.exe
    O4 - HKLM\..\RunOnce: [sysgi.exe] C:\WINDOWS\system32\sysgi.exe
    O4 - HKLM\..\RunOnce: [syseg32.exe] C:\WINDOWS\system32\syseg32.exe
    O4 - HKLM\..\RunOnce: [crry.exe] C:\WINDOWS\crry.exe
    O4 - HKLM\..\RunOnce: [iepg32.exe] C:\WINDOWS\iepg32.exe
    O4 - HKLM\..\RunOnce: [d3jg.exe] C:\WINDOWS\d3jg.exe
    O4 - HKLM\..\RunOnce: [netzq32.exe] C:\WINDOWS\netzq32.exe
    O4 - HKLM\..\RunOnce: [ipvi32.exe] C:\WINDOWS\system32\ipvi32.exe
    O4 - HKLM\..\RunOnce: [crrg.exe] C:\WINDOWS\system32\crrg.exe
    O4 - HKLM\..\RunOnce: [apilx32.exe] C:\WINDOWS\apilx32.exe
    O4 - HKLM\..\RunOnce: [javauq32.exe] C:\WINDOWS\javauq32.exe
    O4 - HKLM\..\RunOnce: [ntya.exe] C:\WINDOWS\system32\ntya.exe
    O4 - HKLM\..\RunOnce: [syseo.exe] C:\WINDOWS\system32\syseo.exe
    O4 - HKLM\..\RunOnce: [javaxf32.exe] C:\WINDOWS\javaxf32.exe
    O4 - HKLM\..\RunOnce: [cria.exe] C:\WINDOWS\system32\cria.exe
    O4 - HKLM\..\RunOnce: [ipbr32.exe] C:\WINDOWS\system32\ipbr32.exe
    O4 - HKLM\..\RunOnce: [sysmw32.exe] C:\WINDOWS\system32\sysmw32.exe
    O4 - HKLM\..\RunOnce: [javavm32.exe] C:\WINDOWS\system32\javavm32.exe
    O4 - HKLM\..\RunOnce: [iekx.exe] C:\WINDOWS\system32\iekx.exe
    O4 - HKLM\..\RunOnce: [mswd32.exe] C:\WINDOWS\system32\mswd32.exe
    O4 - HKLM\..\RunOnce: [ntnk32.exe] C:\WINDOWS\system32\ntnk32.exe
    O4 - HKLM\..\RunOnce: [d3ly.exe] C:\WINDOWS\d3ly.exe
    O4 - HKLM\..\RunOnce: [atlam32.exe] C:\WINDOWS\atlam32.exe
    O4 - HKLM\..\RunOnce: [ipcf.exe] C:\WINDOWS\ipcf.exe
    O4 - HKLM\..\RunOnce: [ipqu.exe] C:\WINDOWS\ipqu.exe
    O4 - HKLM\..\RunOnce: [netzs.exe] C:\WINDOWS\system32\netzs.exe
    O4 - HKLM\..\RunOnce: [wincn.exe] C:\WINDOWS\system32\wincn.exe
    O4 - HKLM\..\RunOnce: [ntcv32.exe] C:\WINDOWS\ntcv32.exe
    O4 - HKLM\..\RunOnce: [d3en32.exe] C:\WINDOWS\system32\d3en32.exe
    O4 - HKLM\..\RunOnce: [ipig.exe] C:\WINDOWS\system32\ipig.exe
    O4 - HKLM\..\RunOnce: [atljb32.exe] C:\WINDOWS\system32\atljb32.exe
    O4 - HKLM\..\RunOnce: [addkb32.exe] C:\WINDOWS\addkb32.exe
    O4 - HKLM\..\RunOnce: [crol.exe] C:\WINDOWS\crol.exe
    O4 - HKLM\..\RunOnce: [apire32.exe] C:\WINDOWS\apire32.exe
    O4 - HKLM\..\RunOnce: [atlke.exe] C:\WINDOWS\system32\atlke.exe
    O4 - HKLM\..\RunOnce: [msox32.exe] C:\WINDOWS\system32\msox32.exe
    O4 - HKLM\..\RunOnce: [crpx32.exe] C:\WINDOWS\system32\crpx32.exe
    O4 - HKLM\..\RunOnce: [javaxs.exe] C:\WINDOWS\system32\javaxs.exe
    O4 - HKLM\..\RunOnce: [atlyv.exe] C:\WINDOWS\atlyv.exe
    O4 - HKLM\..\RunOnce: [syshi32.exe] C:\WINDOWS\syshi32.exe
    O4 - HKLM\..\RunOnce: [iepd.exe] C:\WINDOWS\iepd.exe
    O4 - HKLM\..\RunOnce: [atlzb.exe] C:\WINDOWS\system32\atlzb.exe
    O4 - HKLM\..\RunOnce: [atlaf.exe] C:\WINDOWS\system32\atlaf.exe
    O4 - HKLM\..\RunOnce: [d3lu32.exe] C:\WINDOWS\system32\d3lu32.exe
    O4 - HKLM\..\RunOnce: [netjc.exe] C:\WINDOWS\netjc.exe
    O4 - HKLM\..\RunOnce: [mfcav32.exe] C:\WINDOWS\system32\mfcav32.exe
    O4 - HKLM\..\RunOnce: [ntri32.exe] C:\WINDOWS\system32\ntri32.exe
    O4 - HKLM\..\RunOnce: [ipmr.exe] C:\WINDOWS\ipmr.exe
    O4 - HKLM\..\RunOnce: [sdkat.exe] C:\WINDOWS\system32\sdkat.exe
    O4 - HKLM\..\RunOnce: [sdkgq.exe] C:\WINDOWS\sdkgq.exe
    O4 - HKLM\..\RunOnce: [crow32.exe] C:\WINDOWS\system32\crow32.exe
    O4 - HKLM\..\RunOnce: [ipej32.exe] C:\WINDOWS\ipej32.exe
    O4 - HKLM\..\RunOnce: [d3xi.exe] C:\WINDOWS\system32\d3xi.exe
    O4 - HKLM\..\RunOnce: [javagi32.exe] C:\WINDOWS\system32\javagi32.exe
    O4 - HKLM\..\RunOnce: [craz32.exe] C:\WINDOWS\system32\craz32.exe

    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.15.36/ttinst.cab

    O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)

    O23 - Service: Network Security Service - Unknown - C:\WINDOWS\system32\addyy.exe (file missing)


    The following step is important as you may have several malware files in your temp directories.

    Then browse to the C:\documents and settings\Your User Name (repeat for all other user names in documents and settings)\local settings\temp folder and delete all files and folders in it. Then browse to the C:\Window\Temp folder and delete all files and folders in it. Then in internet explore click tools>internet Options>General. Click on Delete Files make sure you get all offline content as well.

    Now navigate to the c:\aboutbuster directory and double-click on AboutBuster.exe. Click Begin Removal to allow AboutBuster to scan. When it has finished, AboutBuster will open a 'Scan Completed' window. Click OK. Another information window will open. Click on Exit. AboutBuster will inform you that a log has been created. Click OK. I will need you to post that log later.

    Scan with Adaware by opening it and clicking the "Next" button to start the scan.

    When the scan is completed the Performing System Scan screen will change name to "Scan Complete".

    Click the "Next" button to get to the Scanning Results screens where more information about the objects detected during the scan is available.

    Click the Critical Objects Tab. In general all of the items listed will be bad. Be carefull with the Hosts file entries. Malware uses the hosts file to redirect you websites. However you can use the hosts file as a way to prevent malware. If the object has 127.0.0.1 in it, it should most likely not be deleted as it is protecting against unwanted sites. For more information on how to use a host file to protect yourself read here. So in short, you may or may not want to fix the hosts file entries.

    To fix all the bad critical objects do the following:

    Right click on one of them to open up the selection screen. Click the "Select All" button to select all entries. In general all should be selected with the exception of the good hosts file entries.

    When all are selected Click "Next" and then "OK" in the pop-up window to confirm the removal.

    Now reboot,and run hijackthis again and post a fresh log along with the about buster log.

  • Frostilicus

    16 Posts

    895

    0

    Posted July 12th, 2005 20:00

    Thank you very much for your quick and comprehensive response, ALgal. I tried to find those files that you said you would like copies of, without any success. I couldn't locate a single one of the 6 files. I followed the instructions that followed, and the various programs seemed to find a good deal of things related to CWS. I know hardly anything about hijackthis, but it seemed that when I ran the scan for the last time after rebooting, some of the files that I had previously deleted had returned. Anyway, here is the fresh log, along with the about buster log. Thank you again for your help.




    Logfile of HijackThis v1.99.0
    Scan saved at 2:50:13 PM, on 7/12/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\Program Files\ewido\security suite\ewidoctrl.exe
    C:\Program Files\ewido\security suite\ewidoguard.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\system32\svchost.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    C:\Program Files\DIGStream\digstream.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr__.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Documents and Settings\Josh\My Documents\HijackThis\hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
    R3 - Default URLSearchHook is missing
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Class - {67A010F1-25BF-4EAD-A31C-3E5DD32D913A} - C:\WINDOWS\ipst32.dll (file missing)
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
    O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
    O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr__.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
    O4 - HKLM\..\Run: [apifv.exe] C:\WINDOWS\system32\apifv.exe
    O4 - HKLM\..\Run: [sdkbu32.exe] C:\WINDOWS\sdkbu32.exe
    O4 - HKLM\..\Run: [sdktx32.exe] C:\WINDOWS\sdktx32.exe
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
    O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://courses.mindleaders.com/dpec/shared/cabs/awswaxf.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,74/mcinsctl.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
    O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,16/mcgdmgr.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v5.cab
    O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
    O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee.com VirusScan Online Realtime Engine - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    O23 - Service: Intel NCS NetService - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe





    AboutBuster 5.0 reference file 28
    Scan started on [7/12/2005] at [2:35:49 PM]
    ------------------------------------------------
    Removed Stream! C:\WINDOWS\002326_.tmp:tghevu
    Removed Stream! C:\WINDOWS\CTDVAUDY.CDF:tlbtos
    Removed Stream! C:\WINDOWS\CTWave32.ini:wewzea
    Removed Stream! C:\WINDOWS\disney.ini:xpkgvr
    Removed Stream! C:\WINDOWS\ODBCINST.INI:suiypd
    Removed Stream! C:\WINDOWS\orun32.isu:wuhrtb
    Removed Stream! C:\WINDOWS\SETUP32.INI:cqgzfl
    Removed Stream! C:\WINDOWS\SYSTEM.INI:jhmpkg
    Removed Stream! C:\WINDOWS\WININI.QTW:sdrssr
    Removed Stream! C:\WINDOWS\WMSysPr9.prx:wdqzhe
    ------------------------------------------------
    Removed File! : C:\Windows\qzyig.dat
    Removed File! : C:\Windows\xychc.dat
    Removed File! : C:\Windows\xygyy.dat
    Removed File! : C:\Windows\ylocu.dat
    Removed File! : C:\Windows\System32\avosw.dat
    Removed File! : C:\Windows\System32\peeym.dat
    ------------------------------------------------
    Scan was COMPLETED SUCCESSFULLY at 2:36:12 PM
  • Frostilicus

    16 Posts

    895

    0

    Posted July 12th, 2005 21:00

    Apparantly, my version of hijackthis is out of date, and the newest log that I posted is incorrect. Here is the log file created from the updated hijackthis. Sorry about that.


    Logfile of HijackThis v1.99.1
    Scan saved at 3:18:56 PM, on 7/12/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\Program Files\ewido\security suite\ewidoctrl.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\system32\svchost.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    C:\Program Files\DIGStream\digstream.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr__.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\Program Files\ewido\security suite\ewidoguard.exe
    C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exe
    C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
    C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpHost.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Documents and Settings\Josh\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
    R3 - Default URLSearchHook is missing
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Class - {67A010F1-25BF-4EAD-A31C-3E5DD32D913A} - C:\WINDOWS\ipst32.dll (file missing)
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
    O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
    O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr__.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
    O4 - HKLM\..\Run: [apifv.exe] C:\WINDOWS\system32\apifv.exe
    O4 - HKLM\..\Run: [sdkbu32.exe] C:\WINDOWS\sdkbu32.exe
    O4 - HKLM\..\Run: [sdktx32.exe] C:\WINDOWS\sdktx32.exe
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
    O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://courses.mindleaders.com/dpec/shared/cabs/awswaxf.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,74/mcinsctl.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
    O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,16/mcgdmgr.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v5.cab
    O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
    O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
  • ALgal

    1188 Posts

    895

    0

    Posted July 13th, 2005 00:00

    Hi Frostilicus,

    Sorry about that! The version slipped by but now you have hijackthis on your desktop.
    C:\Documents and Settings\Josh\Desktop\HijackThis.exe
    You need to move it off the desktop to a folder for example C:\HJT so that we have backups.   

  • Frostilicus

    16 Posts

    895

    0

    Posted July 13th, 2005 01:00

    Ok, hijackthis has been moved off of the desktop. Also, apparantly something that you suggested worked, because internet explorer is working normally again. I was able to set my homepage back to yahoo without it being reverted back to about:blank. It would seem that about:blank has been taken care of. Spybot and Adaware haven't picked up anything having to do with CoolWWWSearch or StartPage-DU either, so I can only assume that they are gone as well. However, I don't trust my ability to determine whether or not my system is clean, so I will run hijackthis right now and post the log. Thanks for taking the time to help me out.


    Logfile of HijackThis v1.99.1
    Scan saved at 7:07:03 PM, on 7/12/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\Program Files\ewido\security suite\ewidoctrl.exe
    C:\Program Files\ewido\security suite\ewidoguard.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\system32\svchost.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    C:\Program Files\DIGStream\digstream.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr__.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
    R3 - Default URLSearchHook is missing
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Class - {67A010F1-25BF-4EAD-A31C-3E5DD32D913A} - C:\WINDOWS\ipst32.dll (file missing)
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
    O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
    O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr__.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
    O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://courses.mindleaders.com/dpec/shared/cabs/awswaxf.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,74/mcinsctl.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
    O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,16/mcgdmgr.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v5.cab
    O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
    O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
  • ALgal

    1188 Posts

    895

    0

    Posted July 13th, 2005 03:00

    Let's continue the fix.



    Run HiJackThis and click " Scan", then check(tick) the following, if present:


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\fpfts.dll/sp.html#55135
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = 
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\fpfts.dll/sp.html#55135

    R3 - Default URLSearchHook is missing

    O2 - BHO: Class - {67A010F1-25BF-4EAD-A31C-3E5DD32D913A} - C:\WINDOWS\ipst32.dll (file missing)

    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr__.exe

    O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)


    Now, with all windows closed except HiJackThis, click "Fix checked".



    Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:

    folders...

        C:\Program Files\Viewpoint

    files...

        C:\WINDOWS\fpfts.dll

    -

    Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them from "Safe Mode".



    Let's clear out everything in the ' prefetch' folder, to prevent anything we're fixing and deleting, from starting back up when your system is rebooted. To do that, let's:

    1)  Click "Start", then "My Computer"
    2)  Double-click "Local disk" or your current system drive.
    3)  Double-click "Windows"
    4)  Double-click "Prefetch"

    Now we're ready to clear out everything in this folder.

    5)  Scroll down to the last available file, and while holding down the SHIFT key, click on the last available file. That should select all files in that folder.
    6)  Right-click anywhere on the selected files, then select "Delete".
    7)  Close the window.



    Post back a new log, and let me know how everything goes.

     

  • Frostilicus

    16 Posts

    895

    0

    Posted July 13th, 2005 04:00

    Well, I ran hijackthis and had it fix those files you mentioned, all of which were present. I then went and deleted both of the other files you stated. After rebooting, I ran hijackthis and here is the log file. Near as I can tell, those things you told me to delete stopped showing up.


    Logfile of HijackThis v1.99.1
    Scan saved at 10:18:23 PM, on 7/12/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\Program Files\ewido\security suite\ewidoctrl.exe
    C:\Program Files\ewido\security suite\ewidoguard.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\system32\svchost.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\Program Files\DIGStream\digstream.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\webshots.scr
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
    O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
    O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
    O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://courses.mindleaders.com/dpec/shared/cabs/awswaxf.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,74/mcinsctl.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
    O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,16/mcgdmgr.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v5.cab
    O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
    O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
  • ALgal

    1188 Posts

    315

    0

    Posted July 13th, 2005 11:00

    You are doing great!:smileyhappy:Let's continue the fix.

    Now we need to see if we need to restore some deleted files:
    Please check for the following files using the Windows Search Engine:

    control.exe
    rundll32.exe
    wmplayer.exe
    msconfig.exe
    notepad.exe
    shell.dll
    SDHelper.dll

    If any are missing or not working properly then you can download new copies from Merijn's Files and follow the instructions at that site to installthem where they belong for your OS.

    Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original deleted Hosts file.

    Run an online antivirus scan at:

    Trend Micro
    Reboot

    Finally, scan again with HijackThis once more and post your logfile just to make sure that there is nothing left to fix