• Announcements

    • Budfred

      IE 11 copy/paste problem

      It has come to our attention that people using Internet Explorer 11 (IE 11) are having trouble with copy/paste to the forum. If you encounter this problem, using a different browser like Firefox or Chrome seems to get around the problem. We do not know what the problem is, but it seems to be specific to IE 11 and we are hopeful that Microsoft will eventually fix it.
    • Budfred

      PLEASE READ - Reversing upgrade   02/23/2017

      We have found that this new upgrade is somewhat of a disaster.  We are finding lots of glitches in being able to post and administer the forum.  Additionally, there are new costs associated with the upgrade that we simply cannot afford.  As a result, we have decided to reverse course and go back to the previous version of our software.  Since this will involve restoring it from a backup, we will lose posts that have been added since January 30 or possibly even some before that.    If you started a topic during that time, we urge you to make backups of your posts and you will need to start the topics over again after the change.  You can simply paste the copies of your posts that you created at that point.    If you joined the forum this month, you will need to re-register since your membership will be lost along with the posts.  Since you have a concealed password, we cannot simply restore your membership for you.   We are going to backup as much as we can so that it will reduce inconvenience for our members.  Unfortunately we cannot back everything up since much will be incompatible with the old version of our software.  We apologize for the confusion and regret the need to do this even though it is not viable to continue with this version of the software.   We plan to begin the process tomorrow evening and, if it goes smoothly, we shouldn't be offline for very long.  However, since we have not done this before, we are not sure how smoothly it will go.  We ask your patience as we proceed.
Sign in to follow this  
Followers 0
ashwilkinson

Please Help

26 posts in this topic

I think i have a trojan called 'Trojan.Ecure'. I have been trying for a week to manually remove the trojan but i just dont know how. I have read numerous web pages about this trojan and how to defeat it but i just cant seem to do it. Could somebody please help me?

 

 

my hijack this log is:

 

Logfile of HijackThis v1.97.7

Scan saved at 14:25:43, on 24/07/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\system32\crmn32.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\RunDll32.exe

C:\WINDOWS\System32\sm56hlpr.exe

C:\WINDOWS\system32\msmd32.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\System32\RUNDLL32.EXE

C:\WINDOWS\System32\gxyd.exe

C:\Program Files\WinZip\WZQKPICK.EXE

C:\Program Files\Internet Explorer\iexplore.exe

C:\Documents and Settings\Ashley\My Documents\hijack this\HijackThis.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://yfwhf.dll/index.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {5DA69830-91DD-A25B-F3C5-BD9CDB0ADEE7} - C:\WINDOWS\system32\msis32.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"

O4 - HKLM\..\Run: [sM56ACL] sm56hlpr.exe

O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"

O4 - HKLM\..\Run: [msmd32.exe] C:\WINDOWS\system32\msmd32.exe

O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [Wocb] C:\Documents and Settings\Ashley\Application Data\raau.exe

O4 - HKCU\..\Run: [Xqavolax] C:\WINDOWS\System32\gxyd.exe

O4 - HKLM\..\RunOnce: [msiv32.exe] C:\WINDOWS\system32\msiv32.exe

O4 - HKLM\..\RunOnce: [ipil.exe] C:\WINDOWS\ipil.exe

O4 - HKLM\..\RunOnce: [addxb.exe] C:\WINDOWS\system32\addxb.exe

O4 - HKLM\..\RunOnce: [crcf.exe] C:\WINDOWS\system32\crcf.exe

O4 - HKLM\..\RunOnce: [ntoc.exe] C:\WINDOWS\ntoc.exe

O4 - HKLM\..\RunOnce: [syscn32.exe] C:\WINDOWS\syscn32.exe

O4 - HKLM\..\RunOnce: [msuk.exe] C:\WINDOWS\system32\msuk.exe

O4 - HKLM\..\RunOnce: [sdkup32.exe] C:\WINDOWS\system32\sdkup32.exe

O4 - HKLM\..\RunOnce: [winbo32.exe] C:\WINDOWS\system32\winbo32.exe

O4 - HKLM\..\RunOnce: [javaof.exe] C:\WINDOWS\system32\javaof.exe

O4 - HKLM\..\RunOnce: [atlyc.exe] C:\WINDOWS\system32\atlyc.exe

O4 - HKLM\..\RunOnce: [msrm32.exe] C:\WINDOWS\msrm32.exe

O4 - HKLM\..\RunOnce: [sysfh.exe] C:\WINDOWS\sysfh.exe

O4 - HKLM\..\RunOnce: [netnb.exe] C:\WINDOWS\system32\netnb.exe

O4 - HKLM\..\RunOnce: [atlfn.exe] C:\WINDOWS\system32\atlfn.exe

O4 - HKLM\..\RunOnce: [addws.exe] C:\WINDOWS\system32\addws.exe

O4 - HKLM\..\RunOnce: [crtt.exe] C:\WINDOWS\system32\crtt.exe

O4 - HKLM\..\RunOnce: [msbf32.exe] C:\WINDOWS\msbf32.exe

O4 - HKLM\..\RunOnce: [ntmo32.exe] C:\WINDOWS\ntmo32.exe

O4 - HKLM\..\RunOnce: [ipgu32.exe] C:\WINDOWS\system32\ipgu32.exe

O4 - HKLM\..\RunOnce: [msrq32.exe] C:\WINDOWS\msrq32.exe

O4 - HKLM\..\RunOnce: [sysbd.exe] C:\WINDOWS\sysbd.exe

O4 - HKLM\..\RunOnce: [d3yi.exe] C:\WINDOWS\system32\d3yi.exe

O4 - HKLM\..\RunOnce: [addfu.exe] C:\WINDOWS\addfu.exe

O4 - HKLM\..\RunOnce: [winpk.exe] C:\WINDOWS\winpk.exe

O4 - HKLM\..\RunOnce: [sysvu.exe] C:\WINDOWS\sysvu.exe

O4 - HKLM\..\RunOnce: [sysrj.exe] C:\WINDOWS\system32\sysrj.exe

O4 - HKLM\..\RunOnce: [mfccf.exe] C:\WINDOWS\system32\mfccf.exe

O4 - HKLM\..\RunOnce: [ntit32.exe] C:\WINDOWS\system32\ntit32.exe

O4 - HKLM\..\RunOnce: [msxn32.exe] C:\WINDOWS\system32\msxn32.exe

O4 - HKLM\..\RunOnce: [mfcmc.exe] C:\WINDOWS\mfcmc.exe

O4 - HKLM\..\RunOnce: [ipmn32.exe] C:\WINDOWS\system32\ipmn32.exe

O4 - HKLM\..\RunOnce: [ntig32.exe] C:\WINDOWS\ntig32.exe

O4 - HKLM\..\RunOnce: [sysfp32.exe] C:\WINDOWS\system32\sysfp32.exe

O4 - HKLM\..\RunOnce: [d3vw32.exe] C:\WINDOWS\d3vw32.exe

O4 - HKLM\..\RunOnce: [apiae32.exe] C:\WINDOWS\system32\apiae32.exe

O4 - HKLM\..\RunOnce: [ntzl.exe] C:\WINDOWS\system32\ntzl.exe

O4 - HKLM\..\RunOnce: [addky.exe] C:\WINDOWS\system32\addky.exe

O4 - HKLM\..\RunOnce: [netuv32.exe] C:\WINDOWS\netuv32.exe

O4 - HKLM\..\RunOnce: [iecw.exe] C:\WINDOWS\iecw.exe

O4 - HKLM\..\RunOnce: [apigk32.exe] C:\WINDOWS\system32\apigk32.exe

O4 - HKLM\..\RunOnce: [atlhk.exe] C:\WINDOWS\system32\atlhk.exe

O4 - HKLM\..\RunOnce: [appat.exe] C:\WINDOWS\appat.exe

O4 - HKLM\..\RunOnce: [d3qy.exe] C:\WINDOWS\system32\d3qy.exe

O4 - HKLM\..\RunOnce: [netdn32.exe] C:\WINDOWS\netdn32.exe

O4 - HKLM\..\RunOnce: [netgc.exe] C:\WINDOWS\system32\netgc.exe

O4 - HKLM\..\RunOnce: [crfm32.exe] C:\WINDOWS\crfm32.exe

O4 - HKLM\..\RunOnce: [javatb.exe] C:\WINDOWS\javatb.exe

O4 - HKLM\..\RunOnce: [sysar.exe] C:\WINDOWS\system32\sysar.exe

O4 - HKLM\..\RunOnce: [apinn32.exe] C:\WINDOWS\system32\apinn32.exe

O4 - HKLM\..\RunOnce: [crjo.exe] C:\WINDOWS\crjo.exe

O4 - HKLM\..\RunOnce: [winig32.exe] C:\WINDOWS\system32\winig32.exe

O4 - HKLM\..\RunOnce: [ieoz.exe] C:\WINDOWS\system32\ieoz.exe

O4 - HKLM\..\RunOnce: [ieqc32.exe] C:\WINDOWS\system32\ieqc32.exe

O4 - HKLM\..\RunOnce: [ipyg32.exe] C:\WINDOWS\ipyg32.exe

O4 - HKLM\..\RunOnce: [mskg32.exe] C:\WINDOWS\system32\mskg32.exe

O4 - HKLM\..\RunOnce: [javawb.exe] C:\WINDOWS\system32\javawb.exe

O4 - HKLM\..\RunOnce: [sysxo.exe] C:\WINDOWS\system32\sysxo.exe

O4 - HKLM\..\RunOnce: [sdkkd.exe] C:\WINDOWS\sdkkd.exe

O4 - HKLM\..\RunOnce: [appoy32.exe] C:\WINDOWS\system32\appoy32.exe

O4 - HKLM\..\RunOnce: [javace.exe] C:\WINDOWS\javace.exe

O4 - HKLM\..\RunOnce: [msgx32.exe] C:\WINDOWS\msgx32.exe

O4 - HKLM\..\RunOnce: [atlgr32.exe] C:\WINDOWS\atlgr32.exe

O4 - HKLM\..\RunOnce: [atlzr32.exe] C:\WINDOWS\atlzr32.exe

O4 - HKLM\..\RunOnce: [winpy32.exe] C:\WINDOWS\winpy32.exe

O4 - HKLM\..\RunOnce: [javaqi.exe] C:\WINDOWS\system32\javaqi.exe

O4 - HKLM\..\RunOnce: [crqg32.exe] C:\WINDOWS\crqg32.exe

O4 - HKLM\..\RunOnce: [javazk32.exe] C:\WINDOWS\javazk32.exe

O4 - HKLM\..\RunOnce: [netkw32.exe] C:\WINDOWS\netkw32.exe

O4 - HKLM\..\RunOnce: [iehp.exe] C:\WINDOWS\system32\iehp.exe

O4 - HKLM\..\RunOnce: [apiob32.exe] C:\WINDOWS\system32\apiob32.exe

O4 - HKLM\..\RunOnce: [sdkmi.exe] C:\WINDOWS\system32\sdkmi.exe

O4 - HKLM\..\RunOnce: [sysmc.exe] C:\WINDOWS\system32\sysmc.exe

O4 - HKLM\..\RunOnce: [ipse32.exe] C:\WINDOWS\system32\ipse32.exe

O4 - HKLM\..\RunOnce: [netgt32.exe] C:\WINDOWS\netgt32.exe

O4 - HKLM\..\RunOnce: [d3qh.exe] C:\WINDOWS\system32\d3qh.exe

O4 - HKLM\..\RunOnce: [netpp32.exe] C:\WINDOWS\system32\netpp32.exe

O4 - HKLM\..\RunOnce: [crzn.exe] C:\WINDOWS\crzn.exe

O4 - HKLM\..\RunOnce: [appid32.exe] C:\WINDOWS\appid32.exe

O4 - HKLM\..\RunOnce: [ipzq32.exe] C:\WINDOWS\ipzq32.exe

O4 - HKLM\..\RunOnce: [d3km32.exe] C:\WINDOWS\system32\d3km32.exe

O4 - HKLM\..\RunOnce: [d3ob.exe] C:\WINDOWS\d3ob.exe

O4 - HKLM\..\RunOnce: [ieyj32.exe] C:\WINDOWS\ieyj32.exe

O4 - HKLM\..\RunOnce: [apidb.exe] C:\WINDOWS\apidb.exe

O4 - HKLM\..\RunOnce: [crxd32.exe] C:\WINDOWS\crxd32.exe

O4 - HKLM\..\RunOnce: [sysnq.exe] C:\WINDOWS\sysnq.exe

O4 - HKLM\..\RunOnce: [atlfd32.exe] C:\WINDOWS\system32\atlfd32.exe

O4 - HKLM\..\RunOnce: [ntun.exe] C:\WINDOWS\ntun.exe

O4 - HKLM\..\RunOnce: [crgk32.exe] C:\WINDOWS\system32\crgk32.exe

O4 - HKLM\..\RunOnce: [apivk.exe] C:\WINDOWS\apivk.exe

O4 - HKLM\..\RunOnce: [sdkbv32.exe] C:\WINDOWS\system32\sdkbv32.exe

O4 - HKLM\..\RunOnce: [ipfl32.exe] C:\WINDOWS\ipfl32.exe

O4 - HKLM\..\RunOnce: [javauo32.exe] C:\WINDOWS\system32\javauo32.exe

O4 - HKLM\..\RunOnce: [netmq.exe] C:\WINDOWS\system32\netmq.exe

O4 - HKLM\..\RunOnce: [apiuy32.exe] C:\WINDOWS\system32\apiuy32.exe

O4 - HKLM\..\RunOnce: [sysdt32.exe] C:\WINDOWS\sysdt32.exe

O4 - HKLM\..\RunOnce: [nthr.exe] C:\WINDOWS\system32\nthr.exe

O4 - HKLM\..\RunOnce: [sdkal.exe] C:\WINDOWS\system32\sdkal.exe

O4 - HKLM\..\RunOnce: [d3do32.exe] C:\WINDOWS\system32\d3do32.exe

O4 - HKLM\..\RunOnce: [apist.exe] C:\WINDOWS\system32\apist.exe

O4 - HKLM\..\RunOnce: [msoj.exe] C:\WINDOWS\msoj.exe

O4 - HKLM\..\RunOnce: [crmn32.exe] C:\WINDOWS\system32\crmn32.exe

O4 - HKLM\..\RunOnce: [sdkth.exe] C:\WINDOWS\system32\sdkth.exe

O4 - HKLM\..\RunOnce: [netiq.exe] C:\WINDOWS\system32\netiq.exe

O4 - HKLM\..\RunOnce: [sdkgd.exe] C:\WINDOWS\system32\sdkgd.exe

O4 - HKLM\..\RunOnce: [apiiz32.exe] C:\WINDOWS\system32\apiiz32.exe

O4 - HKLM\..\RunOnce: [crzy32.exe] C:\WINDOWS\system32\crzy32.exe

O4 - HKLM\..\RunOnce: [ntiu.exe] C:\WINDOWS\system32\ntiu.exe

O4 - HKLM\..\RunOnce: [d3xp.exe] C:\WINDOWS\system32\d3xp.exe

O4 - HKLM\..\RunOnce: [appvi.exe] C:\WINDOWS\appvi.exe

O4 - HKLM\..\RunOnce: [addrp32.exe] C:\WINDOWS\addrp32.exe

O4 - HKLM\..\RunOnce: [ntaz32.exe] C:\WINDOWS\system32\ntaz32.exe

O4 - HKLM\..\RunOnce: [mfcls32.exe] C:\WINDOWS\system32\mfcls32.exe

O4 - HKLM\..\RunOnce: [apife32.exe] C:\WINDOWS\system32\apife32.exe

O4 - HKLM\..\RunOnce: [apihj32.exe] C:\WINDOWS\apihj32.exe

O4 - HKLM\..\RunOnce: [craw.exe] C:\WINDOWS\system32\craw.exe

O4 - HKLM\..\RunOnce: [mfcdw32.exe] C:\WINDOWS\system32\mfcdw32.exe

O4 - HKLM\..\RunOnce: [d3xg.exe] C:\WINDOWS\system32\d3xg.exe

O4 - HKLM\..\RunOnce: [apiei.exe] C:\WINDOWS\system32\apiei.exe

O4 - HKLM\..\RunOnce: [ipgx32.exe] C:\WINDOWS\system32\ipgx32.exe

O4 - HKLM\..\RunOnce: [sysbg.exe] C:\WINDOWS\sysbg.exe

O4 - HKLM\..\RunOnce: [iesc32.exe] C:\WINDOWS\system32\iesc32.exe

O4 - HKLM\..\RunOnce: [sysnq32.exe] C:\WINDOWS\sysnq32.exe

O4 - HKLM\..\RunOnce: [iehf.exe] C:\WINDOWS\system32\iehf.exe

O4 - HKLM\..\RunOnce: [sdkkj32.exe] C:\WINDOWS\sdkkj32.exe

O4 - HKLM\..\RunOnce: [cryo.exe] C:\WINDOWS\cryo.exe

O4 - HKLM\..\RunOnce: [ipvy32.exe] C:\WINDOWS\system32\ipvy32.exe

O4 - HKLM\..\RunOnce: [crsj.exe] C:\WINDOWS\system32\crsj.exe

O4 - HKLM\..\RunOnce: [sdkzj.exe] C:\WINDOWS\sdkzj.exe

O4 - HKLM\..\RunOnce: [apimk32.exe] C:\WINDOWS\system32\apimk32.exe

O4 - HKLM\..\RunOnce: [sysnt.exe] C:\WINDOWS\sysnt.exe

O4 - HKLM\..\RunOnce: [atlql.exe] C:\WINDOWS\atlql.exe

O4 - HKLM\..\RunOnce: [d3bz.exe] C:\WINDOWS\d3bz.exe

O4 - HKLM\..\RunOnce: [crua32.exe] C:\WINDOWS\system32\crua32.exe

O4 - HKLM\..\RunOnce: [sysud.exe] C:\WINDOWS\system32\sysud.exe

O4 - HKLM\..\RunOnce: [apicp.exe] C:\WINDOWS\system32\apicp.exe

O4 - HKLM\..\RunOnce: [adddz.exe] C:\WINDOWS\system32\adddz.exe

O4 - HKLM\..\RunOnce: [addrn.exe] C:\WINDOWS\addrn.exe

O4 - HKLM\..\RunOnce: [mfcxi32.exe] C:\WINDOWS\system32\mfcxi32.exe

O4 - HKLM\..\RunOnce: [nethq.exe] C:\WINDOWS\nethq.exe

O4 - HKLM\..\RunOnce: [crbx32.exe] C:\WINDOWS\crbx32.exe

O4 - HKLM\..\RunOnce: [ntms.exe] C:\WINDOWS\ntms.exe

O4 - HKLM\..\RunOnce: [d3up.exe] C:\WINDOWS\d3up.exe

O4 - Startup: PowerReg Scheduler V3.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

O9 - Extra button: Related (HKLM)

O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)

O9 - Extra button: Money Viewer (HKLM)

O9 - Extra button: Messenger (HKLM)

O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O15 - Trusted Zone: *.blazefind.com

O15 - Trusted Zone: *.clickspring.net

O15 - Trusted Zone: *.flingstone.com

O15 - Trusted Zone: *.mt-download.com

O15 - Trusted Zone: *.my-internet.info

O15 - Trusted Zone: *.searchbarcash.com

O15 - Trusted Zone: *.searchmiracle.com

O15 - Trusted Zone: *.skoobidoo.com

O15 - Trusted Zone: *.slotch.com

O15 - Trusted Zone: *.xxxtoolbar.com

O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\wsluoiro.exe

O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://195.225.177.13/551/online.chm::/on-line.exe

O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://213.159.117.133/legal/x.chm::/load.exe

O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab

O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab

O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...38188.580787037

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab

Share this post


Link to post
Share on other sites

First disconnect your computer from the Internet.

Now do a Ctrl-Alt-Delete in order to bring up Task Manager and, on the Processes tab, end task on these processes:

 

msmd32.exe

gxyd.exe

 

Now find the following files, and delete them:

 

C:\WINDOWS\system32\msmd32.exe

C:\WINDOWS\System32\gxyd.exe

 

NOTE: To avoid the risk of the files not being found due to them having the 'Hidden' attribute, first make sure that in Folder Options > View hidden and operating system files are set to show.

 

Now run Hijack This again, and check and have it fix the following items:

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://yfwhf.dll/index.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

 

O2 - BHO: (no name) - {5DA69830-91DD-A25B-F3C5-BD9CDB0ADEE7} - C:\WINDOWS\system32\msis32.dll

 

O4 - HKLM\..\Run: [msmd32.exe] C:\WINDOWS\system32\msmd32.exe

 

O4 - HKCU\..\Run: [Wocb] C:\Documents and Settings\Ashley\Application Data\raau.exe

O4 - HKCU\..\Run: [Xqavolax] C:\WINDOWS\System32\gxyd.exe

O4 - HKLM\..\RunOnce: [msiv32.exe] C:\WINDOWS\system32\msiv32.exe

O4 - HKLM\..\RunOnce: [ipil.exe] C:\WINDOWS\ipil.exe

O4 - HKLM\..\RunOnce: [addxb.exe] C:\WINDOWS\system32\addxb.exe

O4 - HKLM\..\RunOnce: [crcf.exe] C:\WINDOWS\system32\crcf.exe

O4 - HKLM\..\RunOnce: [ntoc.exe] C:\WINDOWS\ntoc.exe

O4 - HKLM\..\RunOnce: [syscn32.exe] C:\WINDOWS\syscn32.exe

O4 - HKLM\..\RunOnce: [msuk.exe] C:\WINDOWS\system32\msuk.exe

O4 - HKLM\..\RunOnce: [sdkup32.exe] C:\WINDOWS\system32\sdkup32.exe

O4 - HKLM\..\RunOnce: [winbo32.exe] C:\WINDOWS\system32\winbo32.exe

O4 - HKLM\..\RunOnce: [javaof.exe] C:\WINDOWS\system32\javaof.exe

O4 - HKLM\..\RunOnce: [atlyc.exe] C:\WINDOWS\system32\atlyc.exe

O4 - HKLM\..\RunOnce: [msrm32.exe] C:\WINDOWS\msrm32.exe

O4 - HKLM\..\RunOnce: [sysfh.exe] C:\WINDOWS\sysfh.exe

O4 - HKLM\..\RunOnce: [netnb.exe] C:\WINDOWS\system32\netnb.exe

O4 - HKLM\..\RunOnce: [atlfn.exe] C:\WINDOWS\system32\atlfn.exe

O4 - HKLM\..\RunOnce: [addws.exe] C:\WINDOWS\system32\addws.exe

O4 - HKLM\..\RunOnce: [crtt.exe] C:\WINDOWS\system32\crtt.exe

O4 - HKLM\..\RunOnce: [msbf32.exe] C:\WINDOWS\msbf32.exe

O4 - HKLM\..\RunOnce: [ntmo32.exe] C:\WINDOWS\ntmo32.exe

O4 - HKLM\..\RunOnce: [ipgu32.exe] C:\WINDOWS\system32\ipgu32.exe

O4 - HKLM\..\RunOnce: [msrq32.exe] C:\WINDOWS\msrq32.exe

O4 - HKLM\..\RunOnce: [sysbd.exe] C:\WINDOWS\sysbd.exe

O4 - HKLM\..\RunOnce: [d3yi.exe] C:\WINDOWS\system32\d3yi.exe

O4 - HKLM\..\RunOnce: [addfu.exe] C:\WINDOWS\addfu.exe

O4 - HKLM\..\RunOnce: [winpk.exe] C:\WINDOWS\winpk.exe

O4 - HKLM\..\RunOnce: [sysvu.exe] C:\WINDOWS\sysvu.exe

O4 - HKLM\..\RunOnce: [sysrj.exe] C:\WINDOWS\system32\sysrj.exe

O4 - HKLM\..\RunOnce: [mfccf.exe] C:\WINDOWS\system32\mfccf.exe

O4 - HKLM\..\RunOnce: [ntit32.exe] C:\WINDOWS\system32\ntit32.exe

O4 - HKLM\..\RunOnce: [msxn32.exe] C:\WINDOWS\system32\msxn32.exe

O4 - HKLM\..\RunOnce: [mfcmc.exe] C:\WINDOWS\mfcmc.exe

O4 - HKLM\..\RunOnce: [ipmn32.exe] C:\WINDOWS\system32\ipmn32.exe

O4 - HKLM\..\RunOnce: [ntig32.exe] C:\WINDOWS\ntig32.exe

O4 - HKLM\..\RunOnce: [sysfp32.exe] C:\WINDOWS\system32\sysfp32.exe

O4 - HKLM\..\RunOnce: [d3vw32.exe] C:\WINDOWS\d3vw32.exe

O4 - HKLM\..\RunOnce: [apiae32.exe] C:\WINDOWS\system32\apiae32.exe

O4 - HKLM\..\RunOnce: [ntzl.exe] C:\WINDOWS\system32\ntzl.exe

O4 - HKLM\..\RunOnce: [addky.exe] C:\WINDOWS\system32\addky.exe

O4 - HKLM\..\RunOnce: [netuv32.exe] C:\WINDOWS\netuv32.exe

O4 - HKLM\..\RunOnce: [iecw.exe] C:\WINDOWS\iecw.exe

O4 - HKLM\..\RunOnce: [apigk32.exe] C:\WINDOWS\system32\apigk32.exe

O4 - HKLM\..\RunOnce: [atlhk.exe] C:\WINDOWS\system32\atlhk.exe

O4 - HKLM\..\RunOnce: [appat.exe] C:\WINDOWS\appat.exe

O4 - HKLM\..\RunOnce: [d3qy.exe] C:\WINDOWS\system32\d3qy.exe

O4 - HKLM\..\RunOnce: [netdn32.exe] C:\WINDOWS\netdn32.exe

O4 - HKLM\..\RunOnce: [netgc.exe] C:\WINDOWS\system32\netgc.exe

O4 - HKLM\..\RunOnce: [crfm32.exe] C:\WINDOWS\crfm32.exe

O4 - HKLM\..\RunOnce: [javatb.exe] C:\WINDOWS\javatb.exe

O4 - HKLM\..\RunOnce: [sysar.exe] C:\WINDOWS\system32\sysar.exe

O4 - HKLM\..\RunOnce: [apinn32.exe] C:\WINDOWS\system32\apinn32.exe

O4 - HKLM\..\RunOnce: [crjo.exe] C:\WINDOWS\crjo.exe

O4 - HKLM\..\RunOnce: [winig32.exe] C:\WINDOWS\system32\winig32.exe

O4 - HKLM\..\RunOnce: [ieoz.exe] C:\WINDOWS\system32\ieoz.exe

O4 - HKLM\..\RunOnce: [ieqc32.exe] C:\WINDOWS\system32\ieqc32.exe

O4 - HKLM\..\RunOnce: [ipyg32.exe] C:\WINDOWS\ipyg32.exe

O4 - HKLM\..\RunOnce: [mskg32.exe] C:\WINDOWS\system32\mskg32.exe

O4 - HKLM\..\RunOnce: [javawb.exe] C:\WINDOWS\system32\javawb.exe

O4 - HKLM\..\RunOnce: [sysxo.exe] C:\WINDOWS\system32\sysxo.exe

O4 - HKLM\..\RunOnce: [sdkkd.exe] C:\WINDOWS\sdkkd.exe

O4 - HKLM\..\RunOnce: [appoy32.exe] C:\WINDOWS\system32\appoy32.exe

O4 - HKLM\..\RunOnce: [javace.exe] C:\WINDOWS\javace.exe

O4 - HKLM\..\RunOnce: [msgx32.exe] C:\WINDOWS\msgx32.exe

O4 - HKLM\..\RunOnce: [atlgr32.exe] C:\WINDOWS\atlgr32.exe

O4 - HKLM\..\RunOnce: [atlzr32.exe] C:\WINDOWS\atlzr32.exe

O4 - HKLM\..\RunOnce: [winpy32.exe] C:\WINDOWS\winpy32.exe

O4 - HKLM\..\RunOnce: [javaqi.exe] C:\WINDOWS\system32\javaqi.exe

O4 - HKLM\..\RunOnce: [crqg32.exe] C:\WINDOWS\crqg32.exe

O4 - HKLM\..\RunOnce: [javazk32.exe] C:\WINDOWS\javazk32.exe

O4 - HKLM\..\RunOnce: [netkw32.exe] C:\WINDOWS\netkw32.exe

O4 - HKLM\..\RunOnce: [iehp.exe] C:\WINDOWS\system32\iehp.exe

O4 - HKLM\..\RunOnce: [apiob32.exe] C:\WINDOWS\system32\apiob32.exe

O4 - HKLM\..\RunOnce: [sdkmi.exe] C:\WINDOWS\system32\sdkmi.exe

O4 - HKLM\..\RunOnce: [sysmc.exe] C:\WINDOWS\system32\sysmc.exe

O4 - HKLM\..\RunOnce: [ipse32.exe] C:\WINDOWS\system32\ipse32.exe

O4 - HKLM\..\RunOnce: [netgt32.exe] C:\WINDOWS\netgt32.exe

O4 - HKLM\..\RunOnce: [d3qh.exe] C:\WINDOWS\system32\d3qh.exe

O4 - HKLM\..\RunOnce: [netpp32.exe] C:\WINDOWS\system32\netpp32.exe

O4 - HKLM\..\RunOnce: [crzn.exe] C:\WINDOWS\crzn.exe

O4 - HKLM\..\RunOnce: [appid32.exe] C:\WINDOWS\appid32.exe

O4 - HKLM\..\RunOnce: [ipzq32.exe] C:\WINDOWS\ipzq32.exe

O4 - HKLM\..\RunOnce: [d3km32.exe] C:\WINDOWS\system32\d3km32.exe

O4 - HKLM\..\RunOnce: [d3ob.exe] C:\WINDOWS\d3ob.exe

O4 - HKLM\..\RunOnce: [ieyj32.exe] C:\WINDOWS\ieyj32.exe

O4 - HKLM\..\RunOnce: [apidb.exe] C:\WINDOWS\apidb.exe

O4 - HKLM\..\RunOnce: [crxd32.exe] C:\WINDOWS\crxd32.exe

O4 - HKLM\..\RunOnce: [sysnq.exe] C:\WINDOWS\sysnq.exe

O4 - HKLM\..\RunOnce: [atlfd32.exe] C:\WINDOWS\system32\atlfd32.exe

O4 - HKLM\..\RunOnce: [ntun.exe] C:\WINDOWS\ntun.exe

O4 - HKLM\..\RunOnce: [crgk32.exe] C:\WINDOWS\system32\crgk32.exe

O4 - HKLM\..\RunOnce: [apivk.exe] C:\WINDOWS\apivk.exe

O4 - HKLM\..\RunOnce: [sdkbv32.exe] C:\WINDOWS\system32\sdkbv32.exe

O4 - HKLM\..\RunOnce: [ipfl32.exe] C:\WINDOWS\ipfl32.exe

O4 - HKLM\..\RunOnce: [javauo32.exe] C:\WINDOWS\system32\javauo32.exe

O4 - HKLM\..\RunOnce: [netmq.exe] C:\WINDOWS\system32\netmq.exe

O4 - HKLM\..\RunOnce: [apiuy32.exe] C:\WINDOWS\system32\apiuy32.exe

O4 - HKLM\..\RunOnce: [sysdt32.exe] C:\WINDOWS\sysdt32.exe

O4 - HKLM\..\RunOnce: [nthr.exe] C:\WINDOWS\system32\nthr.exe

O4 - HKLM\..\RunOnce: [sdkal.exe] C:\WINDOWS\system32\sdkal.exe

O4 - HKLM\..\RunOnce: [d3do32.exe] C:\WINDOWS\system32\d3do32.exe

O4 - HKLM\..\RunOnce: [apist.exe] C:\WINDOWS\system32\apist.exe

O4 - HKLM\..\RunOnce: [msoj.exe] C:\WINDOWS\msoj.exe

O4 - HKLM\..\RunOnce: [crmn32.exe] C:\WINDOWS\system32\crmn32.exe

O4 - HKLM\..\RunOnce: [sdkth.exe] C:\WINDOWS\system32\sdkth.exe

O4 - HKLM\..\RunOnce: [netiq.exe] C:\WINDOWS\system32\netiq.exe

O4 - HKLM\..\RunOnce: [sdkgd.exe] C:\WINDOWS\system32\sdkgd.exe

O4 - HKLM\..\RunOnce: [apiiz32.exe] C:\WINDOWS\system32\apiiz32.exe

O4 - HKLM\..\RunOnce: [crzy32.exe] C:\WINDOWS\system32\crzy32.exe

O4 - HKLM\..\RunOnce: [ntiu.exe] C:\WINDOWS\system32\ntiu.exe

O4 - HKLM\..\RunOnce: [d3xp.exe] C:\WINDOWS\system32\d3xp.exe

O4 - HKLM\..\RunOnce: [appvi.exe] C:\WINDOWS\appvi.exe

O4 - HKLM\..\RunOnce: [addrp32.exe] C:\WINDOWS\addrp32.exe

O4 - HKLM\..\RunOnce: [ntaz32.exe] C:\WINDOWS\system32\ntaz32.exe

O4 - HKLM\..\RunOnce: [mfcls32.exe] C:\WINDOWS\system32\mfcls32.exe

O4 - HKLM\..\RunOnce: [apife32.exe] C:\WINDOWS\system32\apife32.exe

O4 - HKLM\..\RunOnce: [apihj32.exe] C:\WINDOWS\apihj32.exe

O4 - HKLM\..\RunOnce: [craw.exe] C:\WINDOWS\system32\craw.exe

O4 - HKLM\..\RunOnce: [mfcdw32.exe] C:\WINDOWS\system32\mfcdw32.exe

O4 - HKLM\..\RunOnce: [d3xg.exe] C:\WINDOWS\system32\d3xg.exe

O4 - HKLM\..\RunOnce: [apiei.exe] C:\WINDOWS\system32\apiei.exe

O4 - HKLM\..\RunOnce: [ipgx32.exe] C:\WINDOWS\system32\ipgx32.exe

O4 - HKLM\..\RunOnce: [sysbg.exe] C:\WINDOWS\sysbg.exe

O4 - HKLM\..\RunOnce: [iesc32.exe] C:\WINDOWS\system32\iesc32.exe

O4 - HKLM\..\RunOnce: [sysnq32.exe] C:\WINDOWS\sysnq32.exe

O4 - HKLM\..\RunOnce: [iehf.exe] C:\WINDOWS\system32\iehf.exe

O4 - HKLM\..\RunOnce: [sdkkj32.exe] C:\WINDOWS\sdkkj32.exe

O4 - HKLM\..\RunOnce: [cryo.exe] C:\WINDOWS\cryo.exe

O4 - HKLM\..\RunOnce: [ipvy32.exe] C:\WINDOWS\system32\ipvy32.exe

O4 - HKLM\..\RunOnce: [crsj.exe] C:\WINDOWS\system32\crsj.exe

O4 - HKLM\..\RunOnce: [sdkzj.exe] C:\WINDOWS\sdkzj.exe

O4 - HKLM\..\RunOnce: [apimk32.exe] C:\WINDOWS\system32\apimk32.exe

O4 - HKLM\..\RunOnce: [sysnt.exe] C:\WINDOWS\sysnt.exe

O4 - HKLM\..\RunOnce: [atlql.exe] C:\WINDOWS\atlql.exe

O4 - HKLM\..\RunOnce: [d3bz.exe] C:\WINDOWS\d3bz.exe

O4 - HKLM\..\RunOnce: [crua32.exe] C:\WINDOWS\system32\crua32.exe

O4 - HKLM\..\RunOnce: [sysud.exe] C:\WINDOWS\system32\sysud.exe

O4 - HKLM\..\RunOnce: [apicp.exe] C:\WINDOWS\system32\apicp.exe

O4 - HKLM\..\RunOnce: [adddz.exe] C:\WINDOWS\system32\adddz.exe

O4 - HKLM\..\RunOnce: [addrn.exe] C:\WINDOWS\addrn.exe

O4 - HKLM\..\RunOnce: [mfcxi32.exe] C:\WINDOWS\system32\mfcxi32.exe

O4 - HKLM\..\RunOnce: [nethq.exe] C:\WINDOWS\nethq.exe

O4 - HKLM\..\RunOnce: [crbx32.exe] C:\WINDOWS\crbx32.exe

O4 - HKLM\..\RunOnce: [ntms.exe] C:\WINDOWS\ntms.exe

O4 - HKLM\..\RunOnce: [d3up.exe] C:\WINDOWS\d3up.exe

 

O15 - Trusted Zone: *.blazefind.com

O15 - Trusted Zone: *.clickspring.net

O15 - Trusted Zone: *.flingstone.com

O15 - Trusted Zone: *.mt-download.com

O15 - Trusted Zone: *.my-internet.info

O15 - Trusted Zone: *.searchbarcash.com

O15 - Trusted Zone: *.searchmiracle.com

O15 - Trusted Zone: *.skoobidoo.com

O15 - Trusted Zone: *.slotch.com

 

O15 - Trusted Zone: *.xxxtoolbar.com

O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\wsluoiro.exe

O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://195.225.177.13/551/online.chm::/on-line.exe

O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://213.159.117.133/legal/x.chm::/load.exe

O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab

 

Next, download About:Buster from here

 

http://www.downloads.subratam.org/AboutBuster.zip

 

Now start your computer in Safe Mode.

 

Unzip About:Buster to your desktop. Double click it and hit Ok, then Start, then Ok to start the scan. The scan should take a few seconds. Once it is done save the report.

 

Reboot normally, and run an online virus scan at http://housecall.antivirus.com/

 

When done, post the About: Buster report and a new Hijack this log here.

Share this post


Link to post
Share on other sites

hi. I searched and deleted the 'gxyd.exe' but i couldn't find 'msmd32.exe'. I then ran Hijack This and began scanning through your list and checking boxes when i noticed this difference:

 

You had told me to check and fix the following;

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049

 

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049

 

However in my Hijack This scan my two files were different, mine looked like this;

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\secure.html

 

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\secure.html

 

 

At this point i stopped and i would like to know if you feel this difference is significant before continuing.

 

 

To help you, i have updated my hijack this log.

 

Logfile of HijackThis v1.97.7

Scan saved at 19:18:19, on 25/07/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\system32\crmn32.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\System32\RunDll32.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\WINDOWS\System32\sm56hlpr.exe

C:\WINDOWS\System32\RUNDLL32.EXE

C:\Program Files\WinZip\WZQKPICK.EXE

C:\WINDOWS\system32\msmd32.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Microsoft Office\Office\WINWORD.EXE

C:\Documents and Settings\Ashley\My Documents\hijack this\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\secure.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\secure.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {5DA69830-91DD-A25B-F3C5-BD9CDB0ADEE7} - C:\WINDOWS\system32\msis32.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"

O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"

O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [msmd32.exe] C:\WINDOWS\system32\msmd32.exe

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [sM56ACL] sm56hlpr.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit

O4 - HKCU\..\Run: [Wocb] C:\Documents and Settings\Ashley\Application Data\raau.exe

O4 - HKCU\..\Run: [Xqavolax] C:\WINDOWS\System32\gxyd.exe

O4 - HKLM\..\RunOnce: [mfcxi32.exe] C:\WINDOWS\system32\mfcxi32.exe

O4 - HKLM\..\RunOnce: [ieyj32.exe] C:\WINDOWS\ieyj32.exe

O4 - HKLM\..\RunOnce: [apiob32.exe] C:\WINDOWS\system32\apiob32.exe

O4 - HKLM\..\RunOnce: [apidb.exe] C:\WINDOWS\apidb.exe

O4 - HKLM\..\RunOnce: [msxn32.exe] C:\WINDOWS\system32\msxn32.exe

O4 - HKLM\..\RunOnce: [crfm32.exe] C:\WINDOWS\crfm32.exe

O4 - HKLM\..\RunOnce: [crbx32.exe] C:\WINDOWS\crbx32.exe

O4 - HKLM\..\RunOnce: [adddz.exe] C:\WINDOWS\system32\adddz.exe

O4 - HKLM\..\RunOnce: [winpy32.exe] C:\WINDOWS\winpy32.exe

O4 - HKLM\..\RunOnce: [d3ob.exe] C:\WINDOWS\d3ob.exe

O4 - HKLM\..\RunOnce: [mskg32.exe] C:\WINDOWS\system32\mskg32.exe

O4 - HKLM\..\RunOnce: [javaqi.exe] C:\WINDOWS\system32\javaqi.exe

O4 - HKLM\..\RunOnce: [netgc.exe] C:\WINDOWS\system32\netgc.exe

O4 - HKLM\..\RunOnce: [addfu.exe] C:\WINDOWS\addfu.exe

O4 - HKLM\..\RunOnce: [addrp32.exe] C:\WINDOWS\addrp32.exe

O4 - HKLM\..\RunOnce: [d3bz.exe] C:\WINDOWS\d3bz.exe

O4 - HKLM\..\RunOnce: [crua32.exe] C:\WINDOWS\system32\crua32.exe

O4 - HKLM\..\RunOnce: [crjo.exe] C:\WINDOWS\crjo.exe

O4 - HKLM\..\RunOnce: [mfcdw32.exe] C:\WINDOWS\system32\mfcdw32.exe

O4 - HKLM\..\RunOnce: [sdkkd.exe] C:\WINDOWS\sdkkd.exe

O4 - HKLM\..\RunOnce: [appid32.exe] C:\WINDOWS\appid32.exe

O4 - HKLM\..\RunOnce: [netgt32.exe] C:\WINDOWS\netgt32.exe

O4 - HKLM\..\RunOnce: [ipil.exe] C:\WINDOWS\ipil.exe

O4 - HKLM\..\RunOnce: [mfcmc.exe] C:\WINDOWS\mfcmc.exe

O4 - HKLM\..\RunOnce: [javace.exe] C:\WINDOWS\javace.exe

O4 - HKLM\..\RunOnce: [msrq32.exe] C:\WINDOWS\msrq32.exe

O4 - HKLM\..\RunOnce: [apiiz32.exe] C:\WINDOWS\system32\apiiz32.exe

O4 - HKLM\..\RunOnce: [ipgx32.exe] C:\WINDOWS\system32\ipgx32.exe

O4 - HKLM\..\RunOnce: [atlfn.exe] C:\WINDOWS\system32\atlfn.exe

O4 - HKLM\..\RunOnce: [crgk32.exe] C:\WINDOWS\system32\crgk32.exe

O4 - HKLM\..\RunOnce: [javawb.exe] C:\WINDOWS\system32\javawb.exe

O4 - HKLM\..\RunOnce: [msuk.exe] C:\WINDOWS\system32\msuk.exe

O4 - HKLM\..\RunOnce: [ipvy32.exe] C:\WINDOWS\system32\ipvy32.exe

O4 - HKLM\..\RunOnce: [ieoz.exe] C:\WINDOWS\system32\ieoz.exe

O4 - HKLM\..\RunOnce: [apinn32.exe] C:\WINDOWS\system32\apinn32.exe

O4 - HKLM\..\RunOnce: [apiae32.exe] C:\WINDOWS\system32\apiae32.exe

O4 - HKLM\..\RunOnce: [netpp32.exe] C:\WINDOWS\system32\netpp32.exe

O4 - HKLM\..\RunOnce: [ipyg32.exe] C:\WINDOWS\ipyg32.exe

O4 - HKLM\..\RunOnce: [d3vw32.exe] C:\WINDOWS\d3vw32.exe

O4 - HKLM\..\RunOnce: [msgx32.exe] C:\WINDOWS\msgx32.exe

O4 - HKLM\..\RunOnce: [sdkgd.exe] C:\WINDOWS\system32\sdkgd.exe

O4 - HKLM\..\RunOnce: [iesc32.exe] C:\WINDOWS\system32\iesc32.exe

O4 - HKLM\..\RunOnce: [sysfp32.exe] C:\WINDOWS\system32\sysfp32.exe

O4 - HKLM\..\RunOnce: [atlql.exe] C:\WINDOWS\atlql.exe

O4 - HKLM\..\RunOnce: [ntms.exe] C:\WINDOWS\ntms.exe

O4 - HKLM\..\RunOnce: [atlfy.exe] C:\WINDOWS\atlfy.exe

O4 - HKLM\..\RunOnce: [javatb.exe] C:\WINDOWS\javatb.exe

O4 - HKLM\..\RunOnce: [apihj32.exe] C:\WINDOWS\apihj32.exe

O4 - HKLM\..\RunOnce: [sysnq32.exe] C:\WINDOWS\sysnq32.exe

O4 - HKLM\..\RunOnce: [d3xg.exe] C:\WINDOWS\system32\d3xg.exe

O4 - HKLM\..\RunOnce: [mfcls32.exe] C:\WINDOWS\system32\mfcls32.exe

O4 - HKLM\..\RunOnce: [apife32.exe] C:\WINDOWS\system32\apife32.exe

O4 - HKLM\..\RunOnce: [winbo32.exe] C:\WINDOWS\system32\winbo32.exe

O4 - HKLM\..\RunOnce: [sysnq.exe] C:\WINDOWS\sysnq.exe

O4 - HKLM\..\RunOnce: [d3xp.exe] C:\WINDOWS\system32\d3xp.exe

O4 - HKLM\..\RunOnce: [sdkzj.exe] C:\WINDOWS\sdkzj.exe

O4 - HKLM\..\RunOnce: [crtt.exe] C:\WINDOWS\system32\crtt.exe

O4 - HKLM\..\RunOnce: [atlgr32.exe] C:\WINDOWS\atlgr32.exe

O4 - HKLM\..\RunOnce: [cryo.exe] C:\WINDOWS\cryo.exe

O4 - HKLM\..\RunOnce: [sysdt32.exe] C:\WINDOWS\sysdt32.exe

O4 - HKLM\..\RunOnce: [craw.exe] C:\WINDOWS\system32\craw.exe

O4 - HKLM\..\RunOnce: [crxd32.exe] C:\WINDOWS\crxd32.exe

O4 - HKLM\..\RunOnce: [ipse32.exe] C:\WINDOWS\system32\ipse32.exe

O4 - HKLM\..\RunOnce: [ntaz32.exe] C:\WINDOWS\system32\ntaz32.exe

O4 - HKLM\..\RunOnce: [sysfh.exe] C:\WINDOWS\sysfh.exe

O4 - HKLM\..\RunOnce: [crmn32.exe] C:\WINDOWS\system32\crmn32.exe

O4 - HKLM\..\RunOnce: [sysbg.exe] C:\WINDOWS\sysbg.exe

O4 - HKLM\..\RunOnce: [nethq.exe] C:\WINDOWS\nethq.exe

O4 - HKLM\..\RunOnce: [apimk32.exe] C:\WINDOWS\system32\apimk32.exe

O4 - HKLM\..\RunOnce: [appvi.exe] C:\WINDOWS\appvi.exe

O4 - HKLM\..\RunOnce: [addrn.exe] C:\WINDOWS\addrn.exe

O4 - HKLM\..\RunOnce: [addxb.exe] C:\WINDOWS\system32\addxb.exe

O4 - HKLM\..\RunOnce: [iehp.exe] C:\WINDOWS\system32\iehp.exe

O4 - HKLM\..\RunOnce: [d3up.exe] C:\WINDOWS\d3up.exe

O4 - HKLM\..\RunOnce: [apigk32.exe] C:\WINDOWS\system32\apigk32.exe

O4 - HKLM\..\RunOnce: [ipmn32.exe] C:\WINDOWS\system32\ipmn32.exe

O4 - HKLM\..\RunOnce: [appat.exe] C:\WINDOWS\appat.exe

O4 - HKLM\..\RunOnce: [ntig32.exe] C:\WINDOWS\ntig32.exe

O4 - HKLM\..\RunOnce: [sysud.exe] C:\WINDOWS\system32\sysud.exe

O4 - HKLM\..\RunOnce: [mfccf.exe] C:\WINDOWS\system32\mfccf.exe

O4 - HKLM\..\RunOnce: [msrm32.exe] C:\WINDOWS\msrm32.exe

O4 - HKLM\..\RunOnce: [netnb.exe] C:\WINDOWS\system32\netnb.exe

O4 - HKLM\..\RunOnce: [crsj.exe] C:\WINDOWS\system32\crsj.exe

O4 - HKLM\..\RunOnce: [sdkth.exe] C:\WINDOWS\system32\sdkth.exe

O4 - HKLM\..\RunOnce: [netiq.exe] C:\WINDOWS\system32\netiq.exe

O4 - HKLM\..\RunOnce: [sysnt.exe] C:\WINDOWS\sysnt.exe

O4 - HKLM\..\RunOnce: [nthr.exe] C:\WINDOWS\system32\nthr.exe

O4 - HKLM\..\RunOnce: [iehf.exe] C:\WINDOWS\system32\iehf.exe

O4 - HKLM\..\RunOnce: [winpk.exe] C:\WINDOWS\winpk.exe

O4 - HKLM\..\RunOnce: [apiei.exe] C:\WINDOWS\system32\apiei.exe

O4 - HKLM\..\RunOnce: [apivk.exe] C:\WINDOWS\apivk.exe

O4 - HKLM\..\RunOnce: [d3do32.exe] C:\WINDOWS\system32\d3do32.exe

O4 - HKLM\..\RunOnce: [ipgu32.exe] C:\WINDOWS\system32\ipgu32.exe

O4 - HKLM\..\RunOnce: [sysvu.exe] C:\WINDOWS\sysvu.exe

O4 - HKLM\..\RunOnce: [msbf32.exe] C:\WINDOWS\msbf32.exe

O4 - HKLM\..\RunOnce: [javazk32.exe] C:\WINDOWS\javazk32.exe

O4 - HKLM\..\RunOnce: [crzy32.exe] C:\WINDOWS\system32\crzy32.exe

O4 - HKLM\..\RunOnce: [apicp.exe] C:\WINDOWS\system32\apicp.exe

O4 - HKLM\..\RunOnce: [sysar.exe] C:\WINDOWS\system32\sysar.exe

O4 - HKLM\..\RunOnce: [apiuy32.exe] C:\WINDOWS\system32\apiuy32.exe

O4 - HKLM\..\RunOnce: [sdkal.exe] C:\WINDOWS\system32\sdkal.exe

O4 - HKLM\..\RunOnce: [ntzl.exe] C:\WINDOWS\system32\ntzl.exe

O4 - HKLM\..\RunOnce: [sdkkj32.exe] C:\WINDOWS\sdkkj32.exe

O4 - HKLM\..\RunOnce: [ntiu.exe] C:\WINDOWS\system32\ntiu.exe

O4 - HKLM\..\RunOnce: [d3qy.exe] C:\WINDOWS\d3qy.exe

O4 - HKLM\..\RunOnce: [crzn.exe] C:\WINDOWS\crzn.exe

O4 - HKLM\..\RunOnce: [ntoc.exe] C:\WINDOWS\ntoc.exe

O4 - HKLM\..\RunOnce: [d3qh.exe] C:\WINDOWS\system32\d3qh.exe

O4 - HKLM\..\RunOnce: [ntmo32.exe] C:\WINDOWS\ntmo32.exe

O4 - Startup: PowerReg Scheduler V3.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

O9 - Extra button: Related (HKLM)

O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)

O9 - Extra button: Money Viewer (HKLM)

O9 - Extra button: Messenger (HKLM)

O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\wsluoiro.exe

O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://195.225.177.13/551/online.chm::/on-line.exe

O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://213.159.117.133/legal/x.chm::/load.exe

O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab

O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab

O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...38188.580787037

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab

Share this post


Link to post
Share on other sites

Did you run About-Buster at all? It doesnt look as if you did...

 

Would you please do this first:

 

Copy the contents of the 'QUOTE' box to Notepad, and save as GetServices.vbs (make sure you save as type: 'all files' )

 

Doubleclick GetServices.vbs (a script by Mosaic1), and it will produce a list of all active services on your computer; please post that list in your reply.

 

set objIdDictionary = CreateObject("Scripting.Dictionary")

strComputer = "."

Set objWMIService = GetObject("winmgmts:" _

    & "{impersonationLevel=impersonate}!\\" & strComputer & "\root\cimv2")

Set colServices = objWMIService.ExecQuery _

    ("Select * from Win32_Service Where State <> 'Stopped'")

For Each objService in colServices

    If objIdDictionary.Exists(objService.ProcessID) Then

    Else

        objIdDictionary.Add objService.ProcessID, objService.ProcessID

    End If

Next

colProcessIDs = objIdDictionary.Items

For i = 0 to objIdDictionary.Count - 1

    Set colServices = objWMIService.ExecQuery _

        ("Select * from Win32_Service Where ProcessID = '" & _

            colProcessIDs(i) & "'")

 

    For Each objService in colServices

        msg = msg & vbcrlf &  " " & Ucase(objService.DisplayName) & ":" & " " &  objService.Name & vbcrlf & objService.PathName &  vbcrlf

 

    Next

Next

Dim fso, Services,Wshshell

Set Wshshell = Wscript.CreateObject("Wscript.Shell")

Set fso = Wscript.CreateObject("Scripting.FileSystemObject")

Set Services = fso.CreateTextFile("Active.txt",true)

Services.Write "These are the Current Active Services:"

Services.WriteLine

Services.Write msg

Services.Close

Wshshell.Run "Active.txt"

 

 

If you have script blocking installed, you will get a warning when you try to run the script. Please allow it to run. It is only collecting information so we can help you.

Share this post


Link to post
Share on other sites

sorry about the problems but unfortunatly i have never heard of a program called 'About Buster'. I copied the quote into notepad and followed your instructions but when i double clicked it, the following error message appeared:

 

Script:  C:\WINDOWS\GetServices.vbs

Line:  32

Char:  1

Error:  The System Cannot Find The File Specified

 

Code:  80070002

Source:  (Null)

 

 

I had recieved some other advice but the moderator closed the topic so i couldnt reply. The advice from somebody else is shown below and im just wondering what you make of it because it is a very different approach.

 

 

You have a couple of different infections here. So let´s do it step by step.

 

Hello please download About:Buster and unzip it to your desktop. Don´t run it yet.

 

How to use Ad-Aware to remove Spyware <= Please check this link for instructions on how to download, install and then use adaware. Don´t use it yet.

1 You already have Adaware installed. Make sure it's up to date. Just open Adaware and click on *Check for Updates Now* and then *Connect*. It will find a new reference-file. Click *ok* and let it download and install the updates by clicking on *Finish* .This will return you to the main screen. You should now see Reference File # : 01R333 18.07.2004 or higher listed.

 

2 Print out these instructions so you have them handy as most of the steps need to be done in safe mode and you may not be able to go online.

 

3. Next, go to Start->Run and type "Services.msc" (without quotes) then hit Ok

Scroll down and find the service called "Network Security Service". When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. This service is installed by the malware. If this service is not listed go ahead with the next step.

 

4. Reboot to Safe Mode

How to start the computer in

Safe mode

 

 

5. Make sure your PC is configured to show hidden files

 

Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked.

Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"

Click "Apply" then "OK"

 

6.CLOSE ALL WINDOWS AND BROWSERS Scan with Hijack This and put checks next to all the following, then click "Fix Checked"

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://yfwhf.dll/index.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

O2 - BHO: (no name) - {5DA69830-91DD-A25B-F3C5-BD9CDB0ADEE7} - C:\WINDOWS\system32\msis32.dll

O4 - HKLM\..\Run: [msmd32.exe] C:\WINDOWS\system32\msmd32.exe

O4 - HKCU\..\Run: [Wocb] C:\Documents and Settings\Ashley\Application Data\raau.exe

O4 - HKCU\..\Run: [Xqavolax] C:\WINDOWS\System32\gxyd.exe

O4 - HKLM\..\RunOnce: [msiv32.exe] C:\WINDOWS\system32\msiv32.exe

O4 - HKLM\..\RunOnce: [ipil.exe] C:\WINDOWS\ipil.exe

O4 - HKLM\..\RunOnce: [addxb.exe] C:\WINDOWS\system32\addxb.exe

O4 - HKLM\..\RunOnce: [crcf.exe] C:\WINDOWS\system32\crcf.exe

O4 - HKLM\..\RunOnce: [ntoc.exe] C:\WINDOWS\ntoc.exe

O4 - HKLM\..\RunOnce: [syscn32.exe] C:\WINDOWS\syscn32.exe

O4 - HKLM\..\RunOnce: [msuk.exe] C:\WINDOWS\system32\msuk.exe

O4 - HKLM\..\RunOnce: [sdkup32.exe] C:\WINDOWS\system32\sdkup32.exe

O4 - HKLM\..\RunOnce: [winbo32.exe] C:\WINDOWS\system32\winbo32.exe

O4 - HKLM\..\RunOnce: [javaof.exe] C:\WINDOWS\system32\javaof.exe

O4 - HKLM\..\RunOnce: [atlyc.exe] C:\WINDOWS\system32\atlyc.exe

O4 - HKLM\..\RunOnce: [msrm32.exe] C:\WINDOWS\msrm32.exe

O4 - HKLM\..\RunOnce: [sysfh.exe] C:\WINDOWS\sysfh.exe

O4 - HKLM\..\RunOnce: [netnb.exe] C:\WINDOWS\system32\netnb.exe

O4 - HKLM\..\RunOnce: [atlfn.exe] C:\WINDOWS\system32\atlfn.exe

O4 - HKLM\..\RunOnce: [addws.exe] C:\WINDOWS\system32\addws.exe

O4 - HKLM\..\RunOnce: [crtt.exe] C:\WINDOWS\system32\crtt.exe

O4 - HKLM\..\RunOnce: [msbf32.exe] C:\WINDOWS\msbf32.exe

O4 - HKLM\..\RunOnce: [ntmo32.exe] C:\WINDOWS\ntmo32.exe

O4 - HKLM\..\RunOnce: [ipgu32.exe] C:\WINDOWS\system32\ipgu32.exe

O4 - HKLM\..\RunOnce: [msrq32.exe] C:\WINDOWS\msrq32.exe

O4 - HKLM\..\RunOnce: [sysbd.exe] C:\WINDOWS\sysbd.exe

O4 - HKLM\..\RunOnce: [d3yi.exe] C:\WINDOWS\system32\d3yi.exe

O4 - HKLM\..\RunOnce: [addfu.exe] C:\WINDOWS\addfu.exe

O4 - HKLM\..\RunOnce: [winpk.exe] C:\WINDOWS\winpk.exe

O4 - HKLM\..\RunOnce: [sysvu.exe] C:\WINDOWS\sysvu.exe

O4 - HKLM\..\RunOnce: [sysrj.exe] C:\WINDOWS\system32\sysrj.exe

O4 - HKLM\..\RunOnce: [mfccf.exe] C:\WINDOWS\system32\mfccf.exe

O4 - HKLM\..\RunOnce: [ntit32.exe] C:\WINDOWS\system32\ntit32.exe

O4 - HKLM\..\RunOnce: [msxn32.exe] C:\WINDOWS\system32\msxn32.exe

O4 - HKLM\..\RunOnce: [mfcmc.exe] C:\WINDOWS\mfcmc.exe

O4 - HKLM\..\RunOnce: [ipmn32.exe] C:\WINDOWS\system32\ipmn32.exe

O4 - HKLM\..\RunOnce: [ntig32.exe] C:\WINDOWS\ntig32.exe

O4 - HKLM\..\RunOnce: [sysfp32.exe] C:\WINDOWS\system32\sysfp32.exe

O4 - HKLM\..\RunOnce: [d3vw32.exe] C:\WINDOWS\d3vw32.exe

O4 - HKLM\..\RunOnce: [apiae32.exe] C:\WINDOWS\system32\apiae32.exe

O4 - HKLM\..\RunOnce: [ntzl.exe] C:\WINDOWS\system32\ntzl.exe

O4 - HKLM\..\RunOnce: [addky.exe] C:\WINDOWS\system32\addky.exe

O4 - HKLM\..\RunOnce: [netuv32.exe] C:\WINDOWS\netuv32.exe

O4 - HKLM\..\RunOnce: [iecw.exe] C:\WINDOWS\iecw.exe

O4 - HKLM\..\RunOnce: [apigk32.exe] C:\WINDOWS\system32\apigk32.exe

O4 - HKLM\..\RunOnce: [atlhk.exe] C:\WINDOWS\system32\atlhk.exe

O4 - HKLM\..\RunOnce: [appat.exe] C:\WINDOWS\appat.exe

O4 - HKLM\..\RunOnce: [d3qy.exe] C:\WINDOWS\system32\d3qy.exe

O4 - HKLM\..\RunOnce: [netdn32.exe] C:\WINDOWS\netdn32.exe

O4 - HKLM\..\RunOnce: [netgc.exe] C:\WINDOWS\system32\netgc.exe

O4 - HKLM\..\RunOnce: [crfm32.exe] C:\WINDOWS\crfm32.exe

O4 - HKLM\..\RunOnce: [javatb.exe] C:\WINDOWS\javatb.exe

O4 - HKLM\..\RunOnce: [sysar.exe] C:\WINDOWS\system32\sysar.exe

O4 - HKLM\..\RunOnce: [apinn32.exe] C:\WINDOWS\system32\apinn32.exe

O4 - HKLM\..\RunOnce: [crjo.exe] C:\WINDOWS\crjo.exe

O4 - HKLM\..\RunOnce: [winig32.exe] C:\WINDOWS\system32\winig32.exe

O4 - HKLM\..\RunOnce: [ieoz.exe] C:\WINDOWS\system32\ieoz.exe

O4 - HKLM\..\RunOnce: [ieqc32.exe] C:\WINDOWS\system32\ieqc32.exe

O4 - HKLM\..\RunOnce: [ipyg32.exe] C:\WINDOWS\ipyg32.exe

O4 - HKLM\..\RunOnce: [mskg32.exe] C:\WINDOWS\system32\mskg32.exe

O4 - HKLM\..\RunOnce: [javawb.exe] C:\WINDOWS\system32\javawb.exe

O4 - HKLM\..\RunOnce: [sysxo.exe] C:\WINDOWS\system32\sysxo.exe

O4 - HKLM\..\RunOnce: [sdkkd.exe] C:\WINDOWS\sdkkd.exe

O4 - HKLM\..\RunOnce: [appoy32.exe] C:\WINDOWS\system32\appoy32.exe

O4 - HKLM\..\RunOnce: [javace.exe] C:\WINDOWS\javace.exe

O4 - HKLM\..\RunOnce: [msgx32.exe] C:\WINDOWS\msgx32.exe

O4 - HKLM\..\RunOnce: [atlgr32.exe] C:\WINDOWS\atlgr32.exe

O4 - HKLM\..\RunOnce: [atlzr32.exe] C:\WINDOWS\atlzr32.exe

O4 - HKLM\..\RunOnce: [winpy32.exe] C:\WINDOWS\winpy32.exe

O4 - HKLM\..\RunOnce: [javaqi.exe] C:\WINDOWS\system32\javaqi.exe

O4 - HKLM\..\RunOnce: [crqg32.exe] C:\WINDOWS\crqg32.exe

O4 - HKLM\..\RunOnce: [javazk32.exe] C:\WINDOWS\javazk32.exe

O4 - HKLM\..\RunOnce: [netkw32.exe] C:\WINDOWS\netkw32.exe

O4 - HKLM\..\RunOnce: [iehp.exe] C:\WINDOWS\system32\iehp.exe

O4 - HKLM\..\RunOnce: [apiob32.exe] C:\WINDOWS\system32\apiob32.exe

O4 - HKLM\..\RunOnce: [sdkmi.exe] C:\WINDOWS\system32\sdkmi.exe

O4 - HKLM\..\RunOnce: [sysmc.exe] C:\WINDOWS\system32\sysmc.exe

O4 - HKLM\..\RunOnce: [ipse32.exe] C:\WINDOWS\system32\ipse32.exe

O4 - HKLM\..\RunOnce: [netgt32.exe] C:\WINDOWS\netgt32.exe

O4 - HKLM\..\RunOnce: [d3qh.exe] C:\WINDOWS\system32\d3qh.exe

O4 - HKLM\..\RunOnce: [netpp32.exe] C:\WINDOWS\system32\netpp32.exe

O4 - HKLM\..\RunOnce: [crzn.exe] C:\WINDOWS\crzn.exe

O4 - HKLM\..\RunOnce: [appid32.exe] C:\WINDOWS\appid32.exe

O4 - HKLM\..\RunOnce: [ipzq32.exe] C:\WINDOWS\ipzq32.exe

O4 - HKLM\..\RunOnce: [d3km32.exe] C:\WINDOWS\system32\d3km32.exe

O4 - HKLM\..\RunOnce: [d3ob.exe] C:\WINDOWS\d3ob.exe

O4 - HKLM\..\RunOnce: [ieyj32.exe] C:\WINDOWS\ieyj32.exe

O4 - HKLM\..\RunOnce: [apidb.exe] C:\WINDOWS\apidb.exe

O4 - HKLM\..\RunOnce: [crxd32.exe] C:\WINDOWS\crxd32.exe

O4 - HKLM\..\RunOnce: [sysnq.exe] C:\WINDOWS\sysnq.exe

O4 - HKLM\..\RunOnce: [atlfd32.exe] C:\WINDOWS\system32\atlfd32.exe

O4 - HKLM\..\RunOnce: [ntun.exe] C:\WINDOWS\ntun.exe

O4 - HKLM\..\RunOnce: [crgk32.exe] C:\WINDOWS\system32\crgk32.exe

O4 - HKLM\..\RunOnce: [apivk.exe] C:\WINDOWS\apivk.exe

O4 - HKLM\..\RunOnce: [sdkbv32.exe] C:\WINDOWS\system32\sdkbv32.exe

O4 - HKLM\..\RunOnce: [ipfl32.exe] C:\WINDOWS\ipfl32.exe

O4 - HKLM\..\RunOnce: [javauo32.exe] C:\WINDOWS\system32\javauo32.exe

O4 - HKLM\..\RunOnce: [netmq.exe] C:\WINDOWS\system32\netmq.exe

O4 - HKLM\..\RunOnce: [apiuy32.exe] C:\WINDOWS\system32\apiuy32.exe

O4 - HKLM\..\RunOnce: [sysdt32.exe] C:\WINDOWS\sysdt32.exe

O4 - HKLM\..\RunOnce: [nthr.exe] C:\WINDOWS\system32\nthr.exe

O4 - HKLM\..\RunOnce: [sdkal.exe] C:\WINDOWS\system32\sdkal.exe

O4 - HKLM\..\RunOnce: [d3do32.exe] C:\WINDOWS\system32\d3do32.exe

O4 - HKLM\..\RunOnce: [apist.exe] C:\WINDOWS\system32\apist.exe

O4 - HKLM\..\RunOnce: [msoj.exe] C:\WINDOWS\msoj.exe

O4 - HKLM\..\RunOnce: [crmn32.exe] C:\WINDOWS\system32\crmn32.exe

O4 - HKLM\..\RunOnce: [sdkth.exe] C:\WINDOWS\system32\sdkth.exe

O4 - HKLM\..\RunOnce: [netiq.exe] C:\WINDOWS\system32\netiq.exe

O4 - HKLM\..\RunOnce: [sdkgd.exe] C:\WINDOWS\system32\sdkgd.exe

O4 - HKLM\..\RunOnce: [apiiz32.exe] C:\WINDOWS\system32\apiiz32.exe

O4 - HKLM\..\RunOnce: [crzy32.exe] C:\WINDOWS\system32\crzy32.exe

O4 - HKLM\..\RunOnce: [ntiu.exe] C:\WINDOWS\system32\ntiu.exe

O4 - HKLM\..\RunOnce: [d3xp.exe] C:\WINDOWS\system32\d3xp.exe

O4 - HKLM\..\RunOnce: [appvi.exe] C:\WINDOWS\appvi.exe

O4 - HKLM\..\RunOnce: [addrp32.exe] C:\WINDOWS\addrp32.exe

O4 - HKLM\..\RunOnce: [ntaz32.exe] C:\WINDOWS\system32\ntaz32.exe

O4 - HKLM\..\RunOnce: [mfcls32.exe] C:\WINDOWS\system32\mfcls32.exe

O4 - HKLM\..\RunOnce: [apife32.exe] C:\WINDOWS\system32\apife32.exe

O4 - HKLM\..\RunOnce: [apihj32.exe] C:\WINDOWS\apihj32.exe

O4 - HKLM\..\RunOnce: [craw.exe] C:\WINDOWS\system32\craw.exe

O4 - HKLM\..\RunOnce: [mfcdw32.exe] C:\WINDOWS\system32\mfcdw32.exe

O4 - HKLM\..\RunOnce: [d3xg.exe] C:\WINDOWS\system32\d3xg.exe

O4 - HKLM\..\RunOnce: [apiei.exe] C:\WINDOWS\system32\apiei.exe

O4 - HKLM\..\RunOnce: [ipgx32.exe] C:\WINDOWS\system32\ipgx32.exe

O4 - HKLM\..\RunOnce: [sysbg.exe] C:\WINDOWS\sysbg.exe

O4 - HKLM\..\RunOnce: [iesc32.exe] C:\WINDOWS\system32\iesc32.exe

O4 - HKLM\..\RunOnce: [sysnq32.exe] C:\WINDOWS\sysnq32.exe

O4 - HKLM\..\RunOnce: [iehf.exe] C:\WINDOWS\system32\iehf.exe

O4 - HKLM\..\RunOnce: [sdkkj32.exe] C:\WINDOWS\sdkkj32.exe

O4 - HKLM\..\RunOnce: [cryo.exe] C:\WINDOWS\cryo.exe

O4 - HKLM\..\RunOnce: [ipvy32.exe] C:\WINDOWS\system32\ipvy32.exe

O4 - HKLM\..\RunOnce: [crsj.exe] C:\WINDOWS\system32\crsj.exe

O4 - HKLM\..\RunOnce: [sdkzj.exe] C:\WINDOWS\sdkzj.exe

O4 - HKLM\..\RunOnce: [apimk32.exe] C:\WINDOWS\system32\apimk32.exe

O4 - HKLM\..\RunOnce: [sysnt.exe] C:\WINDOWS\sysnt.exe

O4 - HKLM\..\RunOnce: [atlql.exe] C:\WINDOWS\atlql.exe

O4 - HKLM\..\RunOnce: [d3bz.exe] C:\WINDOWS\d3bz.exe

O4 - HKLM\..\RunOnce: [crua32.exe] C:\WINDOWS\system32\crua32.exe

O4 - HKLM\..\RunOnce: [sysud.exe] C:\WINDOWS\system32\sysud.exe

O4 - HKLM\..\RunOnce: [apicp.exe] C:\WINDOWS\system32\apicp.exe

O4 - HKLM\..\RunOnce: [adddz.exe] C:\WINDOWS\system32\adddz.exe

 

O4 - HKLM\..\RunOnce: [addrn.exe] C:\WINDOWS\addrn.exe

O4 - HKLM\..\RunOnce: [mfcxi32.exe] C:\WINDOWS\system32\mfcxi32.exe

O4 - HKLM\..\RunOnce: [nethq.exe] C:\WINDOWS\nethq.exe

O4 - HKLM\..\RunOnce: [crbx32.exe] C:\WINDOWS\crbx32.exe

O4 - HKLM\..\RunOnce: [ntms.exe] C:\WINDOWS\ntms.exe

O4 - HKLM\..\RunOnce: [d3up.exe] C:\WINDOWS\d3up.exe

 

 

 

 

7. Delete the following files if present.

 

C:\WINDOWS\sysdt32.exe

C:\WINDOWS\msoj.exe

C:\WINDOWS\ipfl32.exe

C:\WINDOWS\apivk.exe

C:\WINDOWS\ntun.exe

C:\WINDOWS\appvi.exe

C:\WINDOWS\addrp32.exe

C:\WINDOWS\apihj32.exe

C:\WINDOWS\sysnq32.exe

C:\WINDOWS\sdkkj32.exe

C:\WINDOWS\nethq.exe

C:\WINDOWS\cryo.exe

C:\WINDOWS\crbx32.exe

C:\WINDOWS\ntms.exe

C:\WINDOWS\d3up.exe

C:\WINDOWS\addrn.exe

C:\WINDOWS\sysnt.exe

C:\WINDOWS\atlql.exe

C:\WINDOWS\d3bz.exe

C:\WINDOWS\sdkzj.exe

C:\WINDOWS\sysbg.exe

C:\WINDOWS\msbf32.exe

C:\WINDOWS\ntmo32.exe

C:\WINDOWS\msrq32.exe

C:\WINDOWS\sysbd.exe

C:\WINDOWS\msrm32.exe

C:\WINDOWS\sysfh.exe

C:\WINDOWS\syscn32.exe

C:\WINDOWS\mfcmc.exe

C:\WINDOWS\ntig32.exe

C:\WINDOWS\d3vw32.exe

C:\WINDOWS\netuv32.exe

C:\WINDOWS\iecw.exe

C:\WINDOWS\addfu.exe

C:\WINDOWS\winpk.exe

C:\WINDOWS\sysvu.exe

C:\WINDOWS\ipil.exe

C:\WINDOWS\ntoc.exe

C:\WINDOWS\sdkkd.exe

C:\WINDOWS\ipyg32.exe

C:\WINDOWS\javace.exe

C:\WINDOWS\msgx32.exe

C:\WINDOWS\atlgr32.exe

C:\WINDOWS\atlzr32.exe

C:\WINDOWS\winpy32.exe

C:\WINDOWS\crjo.exe

C:\WINDOWS\crqg32.exe

C:\WINDOWS\javazk32.exe

C:\WINDOWS\netkw32.exe

C:\WINDOWS\crfm32.exe

C:\WINDOWS\javatb.exe

C:\WINDOWS\netgt32.exe

C:\WINDOWS\netdn32.exe

C:\WINDOWS\crzn.exe

C:\WINDOWS\appid32.exe

C:\WINDOWS\ipzq32.exe

C:\WINDOWS\appat.exe

C:\WINDOWS\d3ob.exe

C:\WINDOWS\ieyj32.exe

C:\WINDOWS\apidb.exe

C:\WINDOWS\crxd32.exe

C:\WINDOWS\sysnq.exe

C:\WINDOWS\system32\yfwhf.dll

C:\WINDOWS\system32\msis32.dll

C:\WINDOWS\system32\msmd32.exe

C:\WINDOWS\System32\gxyd.exe

C:\WINDOWS\system32\msiv32.exe

C:\WINDOWS\system32\addxb.exe

C:\WINDOWS\system32\crcf.exe

C:\WINDOWS\system32\msuk.exe

C:\WINDOWS\system32\sdkup32.exe

C:\WINDOWS\system32\winbo32.exe

C:\WINDOWS\system32\javaof.exe

C:\WINDOWS\system32\atlyc.exe

C:\WINDOWS\system32\netnb.exe

C:\WINDOWS\system32\atlfn.exe

C:\WINDOWS\system32\addws.exe

C:\WINDOWS\system32\crtt.exe

C:\WINDOWS\system32\d3yi.exe

C:\WINDOWS\system32\sysrj.exe

C:\WINDOWS\system32\mfccf.exe

C:\WINDOWS\system32\ntit32.exe

C:\WINDOWS\system32\msxn32.exe

C:\WINDOWS\system32\ipgu32.exe

C:\WINDOWS\system32\ipmn32.exe

C:\WINDOWS\system32\sysfp32.exe

C:\WINDOWS\system32\apiae32.exe

C:\WINDOWS\system32\ntzl.exe

C:\WINDOWS\system32\addky.exe

C:\WINDOWS\system32\apigk32.exe

C:\WINDOWS\system32\atlhk.exe

C:\WINDOWS\system32\d3qy.exe

C:\WINDOWS\system32\netgc.exe

C:\WINDOWS\system32\sysar.exe

C:\WINDOWS\system32\apinn32.exe

C:\WINDOWS\system32\winig32.exe

C:\WINDOWS\system32\ieoz.exe

C:\WINDOWS\system32\ieqc32.exe

C:\WINDOWS\system32\mskg32.exe

C:\WINDOWS\system32\javawb.exe

C:\WINDOWS\system32\sysxo.exe

C:\WINDOWS\system32\atlfd32.exe

C:\WINDOWS\system32\appoy32.exe

C:\WINDOWS\system32\crgk32.exe

C:\WINDOWS\system32\javaqi.exe

C:\WINDOWS\system32\sdkbv32.exe

C:\WINDOWS\system32\d3qh.exe

C:\WINDOWS\system32\netpp32.exe

C:\WINDOWS\system32\javauo32.exe

C:\WINDOWS\system32\netmq.exe

C:\WINDOWS\system32\apiuy32.exe

C:\WINDOWS\system32\iehp.exe

C:\WINDOWS\system32\apiob32.exe

C:\WINDOWS\system32\sdkmi.exe

C:\WINDOWS\system32\sysmc.exe

C:\WINDOWS\system32\ipse32.exe

C:\WINDOWS\system32\nthr.exe

C:\WINDOWS\system32\sdkal.exe

C:\WINDOWS\system32\d3do32.exe

C:\WINDOWS\system32\apist.exe

C:\WINDOWS\system32\d3km32.exe

C:\WINDOWS\system32\crmn32.exe

C:\WINDOWS\system32\sdkth.exe

C:\WINDOWS\system32\netiq.exe

C:\WINDOWS\system32\sdkgd.exe

C:\WINDOWS\system32\apiiz32.exe

C:\WINDOWS\system32\crzy32.exe

C:\WINDOWS\system32\ntiu.exe

C:\WINDOWS\system32\d3xp.exe

C:\WINDOWS\system32\ntaz32.exe

C:\WINDOWS\system32\mfcls32.exe

C:\WINDOWS\system32\apife32.exe

C:\WINDOWS\system32\craw.exe

C:\WINDOWS\system32\mfcdw32.exe

C:\WINDOWS\system32\d3xg.exe

C:\WINDOWS\system32\apiei.exe

C:\WINDOWS\system32\ipgx32.exe

C:\WINDOWS\system32\iesc32.exe

C:\WINDOWS\system32\iehf.exe

C:\WINDOWS\system32\ipvy32.exe

C:\WINDOWS\system32\crsj.exe

C:\WINDOWS\system32\apimk32.exe

C:\WINDOWS\system32\crua32.exe

C:\WINDOWS\system32\sysud.exe

C:\WINDOWS\system32\apicp.exe

C:\WINDOWS\system32\adddz.exe

C:\WINDOWS\system32\mfcxi32.exe

C:\Documents and Settings\Ashley\Application Data\raau.exe

 

 

 

8. Double click AboutBuster.exe that you downloaded earlier. Click OK, click Start, then click OK. This will scan your computer for the bad files and delete them. Save the report(copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

 

9. Scan with Adaware and let it remove any bad files found.

 

10. Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

 

Temporary Files

Temporary Internet Files

Recycle Bin

 

11. Reboot to normal mode, scan again with Hijack This and post a new log here.

 

12. Finally, do an online scan HERE. Let it remove any infected files found.

 

 

Post a fresh HijackThis log and the AboutBuster report back here please.

 

Still there is way to go

 

 

--------------------

 

::mmxx66::

Share this post


Link to post
Share on other sites
sorry about the problems but unfortunatly i have never heard of a program called 'About Buster'.

You should really read what I write...

 

In my first response I said:

 

Next, download About:Buster from here

 

http://www.downloads.subratam.org/AboutBuster.zip

 

 

As for what someone else advised you to do....

If you don't mind I'd like to do it one way only, or we're never going to get you fixed....

 

As for the script, it ought to run, providing you saved it correctly...

However, I suggest we forget about it; please follow the directions exacrly the way I gave them to you in my first reply:

 

end task on and delete files > run Hijack This to fix the items I rendered in bold.

 

Download About:Buster > Safe Mode, run it, CoolWebShredder, etcetera...

 

Providing you follow directions carefully I promise we'll get this fixed.

Edited by TonyKlein

Share this post


Link to post
Share on other sites

ok mate, i will follow your instructions. But i dont have the files 'R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049' and 'R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049'. So i cant fix them before i run auto-buster. My main page is 'C:\Windows\Secure'.

Share this post


Link to post
Share on other sites

I'm quoting from the log you posted; those are the lines exacly the way they are rendered in Hijack This. I figure that if I can see them, you should be able to as well; unless the situation has changed of course...

 

- HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://yfwhf.dll/index.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

 

But never mind, run About:buster nevertheless....

Edited by TonyKlein

Share this post


Link to post
Share on other sites

hi. I encountered 1 problem during my process. Nevertheless my homepage trojan has now gone and it only takes seconds to log my acount into windows unlike before where it took about 5 minutes.

 

The problem that i faced is whenever i clicked 'free virus scan' at http://housecall.trendmicro.com a windows error message appeared. The message is familier to me as it is the one that says 'Send error report' or 'Dont send error report'. So because of this i am unable to scan my computer from this location.

 

My new hijack this log is:

 

Logfile of HijackThis v1.97.7

Scan saved at 14:09:47, on 26/07/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\System32\RunDll32.exe

C:\WINDOWS\System32\sm56hlpr.exe

C:\Program Files\MSN Messenger\MsnMsgr.Exe

C:\WINDOWS\System32\RUNDLL32.EXE

C:\Program Files\WinZip\WZQKPICK.EXE

C:\WINDOWS\System32\nvsvc32.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\WINDOWS\System32\imapi.exe

C:\WINDOWS\explorer.exe

C:\Documents and Settings\Ashley\My Documents\hijack this\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html

O2 - BHO: (no name) - {5DA69830-91DD-A25B-F3C5-BD9CDB0ADEE7} - C:\WINDOWS\system32\msis32.dll (file missing)

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"

O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"

O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [msmd32.exe] C:\WINDOWS\system32\msmd32.exe

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [sM56ACL] sm56hlpr.exe

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit

O4 - Startup: PowerReg Scheduler V3.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

O9 - Extra button: Related (HKLM)

O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)

O9 - Extra button: Money Viewer (HKLM)

O9 - Extra button: Messenger (HKLM)

O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab

O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...38188.580787037

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab

 

 

Even though i can now reset my IE homepage the hijack this log still says my default and local page is C:\WINDOWS\secure.html. Also this quote is quite bizzarre as i have deleted the file:

 

O4 - HKLM\..\Run: [msmd32.exe] C:\WINDOWS\system32\msmd32.exe

 

 

Thank you very much for your help and patience so far.

Share this post


Link to post
Share on other sites

I think we're getting there; with all browser windows closed, have Hijack This fix the following items:

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html

 

O2 - BHO: (no name) - {5DA69830-91DD-A25B-F3C5-BD9CDB0ADEE7} - C:\WINDOWS\system32\msis32.dll (file missing)

 

O4 - HKLM\..\Run: [msmd32.exe] C:\WINDOWS\system32\msmd32.exe

 

Now restart your computer, and post a fresh log

Share this post


Link to post
Share on other sites

here is my new log.

 

 

Logfile of HijackThis v1.97.7

Scan saved at 15:32:01, on 26/07/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\System32\RunDll32.exe

C:\WINDOWS\System32\sm56hlpr.exe

C:\WINDOWS\System32\RUNDLL32.EXE

C:\Program Files\WinZip\WZQKPICK.EXE

C:\WINDOWS\System32\nvsvc32.exe

C:\Documents and Settings\Ashley\My Documents\hijack this\HijackThis.exe

C:\Program Files\iPod\bin\iPodService.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

O2 - BHO: (no name) - {C52F1B4D-A771-445D-A3D8-3F1E4B7B11F8} - C:\WINDOWS\System32\mff.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"

O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [sM56ACL] sm56hlpr.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit

O4 - Startup: PowerReg Scheduler V3.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

O9 - Extra button: Related (HKLM)

O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)

O9 - Extra button: Messenger (HKLM)

O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab

O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...38188.580787037

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab

Share this post


Link to post
Share on other sites

I was expecting a reply so now i understand that it is fixed i would like to let you know that i am very grateful and thankful. Its good to know that people like you are giving up your time to help others. Best wishes mate.

Share this post


Link to post
Share on other sites

I'm afraid you're now infected by another CoolWebSearch variant, that's isn't easy to remove either....

 

Click here to download FindnFix.exe by Freeatlast.

 

Double-click on the FINDnFIX.exe and it will install a folder called FINDnFIX on your system. Go to that folder and double-click on !LOG!.bat. The program will take a few minutes to collect the necessary information. When done post the contents of Log.txt in this thread.

Share this post


Link to post
Share on other sites

Here is my FindFix log:

 

 

»»»»»»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»»»»»»

»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»

 

Microsoft Windows XP [Version 5.1.2600]

»»»IE build and last SP(s)

6.0.2800.1106 SP1-Q823353-Q832894

The type of the file system is NTFS.

C: is not dirty.

 

Fri 30 Jul 04 11:03:14

11:03am up 0 days, 0:33

 

»»»»»»»»»»»»»»»»»»*** Note! ***»»»»»»»»»»»»»»»»

The list will produce a small database of files that will match certain criteria.

You must know how to ID the file based on the filters provided in

the scan, as not all the files flagged are bad.

Ex: read only files, s/h files, last modified date. size, etc.

The filters provided should help narrow down the list, and hopefully

pinpoint the culprit.

Along with that,registry scan logged at the end should match the

corresponding file(s) listed.

»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Unless the file match the entire criteria, it should not be pointed to remove

without attempting to confirm it's nature!

»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

At times there could be several (legit) files flagged, and/or duplicate culprit file(s)!

If in doubt, always search the file(s) and properties according to criteria!

 

The file(s) found should be moved to \FINDnFIX\"junkxxx" Subfolder

»»»»»»»»»»»»»»»»»»***LOG!***(*updated 7/27)»»»»»»»»»»»»»»»»

 

»»»*»»»*Use at your own risk!»»»*»»»*

 

Scanning for file(s)...

»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»

»»»»» (*1*) »»»»» .........

»»Locked or 'Suspect' file(s) found...

 

C:\WINDOWS\System32\CTLC.DLL +++ File read error

\\?\C:\WINDOWS\System32\CTLC.DLL +++ File read error

 

»»»»» (*2*) »»»»»........

CTLC.DLL Can't Open!

 

»»»»» (*3*) »»»»»........

 

C:\WINDOWS\SYSTEM32\

ctlc.dll Tue 20 Jul 2004 20:59:02 A...R 57,344 56.00 K

 

1 item found: 1 file, 0 directories.

Total of file sizes: 57,344 bytes 56.00 K

 

unknown/hidden files...

 

No matches found.

 

»»»»» (*4*) »»»»».........

Sniffing..........

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

Sniffed -> C:\WINDOWS\SYSTEM32\CTLC.DLL

 

»»»»»(*5*)»»»»»

¯ Access denied ® ..................... CTLC.DLL .....57344 20.07.2004

 

»»»»»(*6*)»»»»»

fgrep: can't open input C:\WINDOWS\SYSTEM32\CTLC.DLL

 

»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»

»»»»»Search by size...

 

 

C:\WINDOWS\SYSTEM32\

ctlc.dll Tue 20 Jul 2004 20:59:02 A...R 57,344 56.00 K

 

1 item found: 1 file, 0 directories.

Total of file sizes: 57,344 bytes 56.00 K

 

No matches found.

 

No matches found.

 

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

Sniffed -> C:\WINDOWS\SYSTEM32\CTLC.DLL

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

 

»»Size of Windows key:

(*Default-450 *No AppInit-398 *fake(infected)-448,504,512...)

 

Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 448

 

»»Dumping Values........

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

DeviceNotSelectedTimeout = 15

GDIProcessHandleQuota = REG_DWORD 0x00002710

Spooler = yes

swapdisk =

TransmissionRetryTimeout = 90

USERProcessHandleQuota = REG_DWORD 0x00002710

AppInit_DLLs = (*** MISSING TRAILING NULL CHARACTER ***)

 

»»Security settings for 'Windows' key:

 

 

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above

Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)

This program is Freeware, use it on your own risk!

 

Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:

(NI) ALLOW Read BUILTIN\Users

(IO) ALLOW Read BUILTIN\Users

(NI) ALLOW Read BUILTIN\Power Users

(IO) ALLOW Read BUILTIN\Power Users

(NI) ALLOW Full access BUILTIN\Administrators

(IO) ALLOW Full access BUILTIN\Administrators

(NI) ALLOW Full access NT AUTHORITY\SYSTEM

(IO) ALLOW Full access NT AUTHORITY\SYSTEM

(NI) ALLOW Full access BUILTIN\Administrators

(IO) ALLOW Full access CREATOR OWNER

 

Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:

Read BUILTIN\Users

Read BUILTIN\Power Users

Full access BUILTIN\Administrators

Full access NT AUTHORITY\SYSTEM

 

 

»»Member of...: (Admin logon required!)

User is a member of group WILKINSON\None.

User is a member of group \Everyone.

User is a member of group BUILTIN\Administrators.

User is a member of group BUILTIN\Users.

User is a member of group \LOCAL.

User is a member of group NT AUTHORITY\INTERACTIVE.

User is a member of group NT AUTHORITY\Authenticated Users.

 

 

»»»»»»Backups created...»»»»»»

11:04am up 0 days, 0:34

Fri 30 Jul 04 11:04:17

 

A C:\FINDnFIX\keyback.hiv

--a-- - - - - - 8,192 07-30-2004 keyback.hiv

A C:\FINDnFIX\keys1\winkey.reg

--a-- - - - - - 287 07-30-2004 winkey.reg

*Temp backups...

.

..

keyback2.hi_

winkey2.re_

 

 

C:\FINDNFIX\

JUNKXXX Fri 30 Jul 2004 11:03:14 .D... <Dir>

 

1 item found: 0 files, 1 directory.

 

»»Performing string scan....

00001150: ?

00001190: vk UDeviceNo

000011D0:tSelectedTimeout 1 5 @ vk ' z

00001210:GDIProcessHandleQuota" 9 0 | vk X

00001250:Spooler2 y e s n vk =pswapdisk

00001290: 8 h vk ( R TransmissionRetryTimeout

000012D0: vk ' n USERProcessHandleQuotai 8

00001310:h vk : H [ AppInit_DLLsvk C :

00001350:\ W I N D O W S \ S y s t e m 3 2 \ c t l c . d l l d x

00001390:

000013D0:

00001410:

00001450:

00001490:

000014D0:

00001510:

00001550:

00001590:

000015D0:

 

---------- WIN.TXT

AppInit_DLLsvk

--------------

--------------

$011C7: UDeviceNotSelectedTimeout

$0120F: zGDIProcessHandleQuota

$012B8: TransmissionRetryTimeout

$012E8: USERProcessHandleQuotai

$01338: AppInit_DLLsvk

--------------

--------------

C:\WINDOWS\System32\ctlc.dll

--------------

--------------

REGEDIT4

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"DeviceNotSelectedTimeout"="15"

"GDIProcessHandleQuota"=dword:00002710

"Spooler"="yes"

"swapdisk"=""

"TransmissionRetryTimeout"="90"

"USERProcessHandleQuota"=dword:00002710

"AppInit_DLLs"=""

 

A handle was successfully obtained for the

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows key.

This key has 0 subkeys.

The AppInitDLLs value exists and reports as 58 bytes, including the 2 for string termination.

 

[AppInitDLLs]

Ansi string : "C:\WINDOWS\System32\ctlc.dll"

0000 43 00 3a 00 5c 00 57 00 49 00 4e 00 44 00 4f 00 | C.:.\.W.I.N.D.O.

0010 57 00 53 00 5c 00 53 00 79 00 73 00 74 00 65 00 | W.S.\.S.y.s.t.e.

0020 6d 00 33 00 32 00 5c 00 63 00 74 00 6c 00 63 00 | m.3.2.\.c.t.l.c.

0030 2e 00 64 00 6c 00 6c 00 00 00 | ..d.l.l...

Share this post


Link to post
Share on other sites

Here is my findfix log:

 

 

»»»»»»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»»»»»»

»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»

 

Microsoft Windows XP [Version 5.1.2600]

»»»IE build and last SP(s)

6.0.2800.1106 SP1-Q823353-Q832894

The type of the file system is NTFS.

C: is not dirty.

 

Fri 30 Jul 04 11:03:14

11:03am up 0 days, 0:33

 

»»»»»»»»»»»»»»»»»»*** Note! ***»»»»»»»»»»»»»»»»

The list will produce a small database of files that will match certain criteria.

You must know how to ID the file based on the filters provided in

the scan, as not all the files flagged are bad.

Ex: read only files, s/h files, last modified date. size, etc.

The filters provided should help narrow down the list, and hopefully

pinpoint the culprit.

Along with that,registry scan logged at the end should match the

corresponding file(s) listed.

»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Unless the file match the entire criteria, it should not be pointed to remove

without attempting to confirm it's nature!

»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

At times there could be several (legit) files flagged, and/or duplicate culprit file(s)!

If in doubt, always search the file(s) and properties according to criteria!

 

The file(s) found should be moved to \FINDnFIX\"junkxxx" Subfolder

»»»»»»»»»»»»»»»»»»***LOG!***(*updated 7/27)»»»»»»»»»»»»»»»»

 

»»»*»»»*Use at your own risk!»»»*»»»*

 

Scanning for file(s)...

»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»

»»»»» (*1*) »»»»» .........

»»Locked or 'Suspect' file(s) found...

 

C:\WINDOWS\System32\CTLC.DLL +++ File read error

\\?\C:\WINDOWS\System32\CTLC.DLL +++ File read error

 

»»»»» (*2*) »»»»»........

CTLC.DLL Can't Open!

 

»»»»» (*3*) »»»»»........

 

C:\WINDOWS\SYSTEM32\

ctlc.dll Tue 20 Jul 2004 20:59:02 A...R 57,344 56.00 K

 

1 item found: 1 file, 0 directories.

Total of file sizes: 57,344 bytes 56.00 K

 

unknown/hidden files...

 

No matches found.

 

»»»»» (*4*) »»»»».........

Sniffing..........

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

Sniffed -> C:\WINDOWS\SYSTEM32\CTLC.DLL

 

»»»»»(*5*)»»»»»

¯ Access denied ® ..................... CTLC.DLL .....57344 20.07.2004

 

»»»»»(*6*)»»»»»

fgrep: can't open input C:\WINDOWS\SYSTEM32\CTLC.DLL

 

»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»

»»»»»Search by size...

 

 

C:\WINDOWS\SYSTEM32\

ctlc.dll Tue 20 Jul 2004 20:59:02 A...R 57,344 56.00 K

 

1 item found: 1 file, 0 directories.

Total of file sizes: 57,344 bytes 56.00 K

 

No matches found.

 

No matches found.

 

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

Sniffed -> C:\WINDOWS\SYSTEM32\CTLC.DLL

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

 

»»Size of Windows key:

(*Default-450 *No AppInit-398 *fake(infected)-448,504,512...)

 

Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 448

 

»»Dumping Values........

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

DeviceNotSelectedTimeout = 15

GDIProcessHandleQuota = REG_DWORD 0x00002710

Spooler = yes

swapdisk =

TransmissionRetryTimeout = 90

USERProcessHandleQuota = REG_DWORD 0x00002710

AppInit_DLLs = (*** MISSING TRAILING NULL CHARACTER ***)

 

»»Security settings for 'Windows' key:

 

 

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above

Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)

This program is Freeware, use it on your own risk!

 

Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:

(NI) ALLOW Read BUILTIN\Users

(IO) ALLOW Read BUILTIN\Users

(NI) ALLOW Read BUILTIN\Power Users

(IO) ALLOW Read BUILTIN\Power Users

(NI) ALLOW Full access BUILTIN\Administrators

(IO) ALLOW Full access BUILTIN\Administrators

(NI) ALLOW Full access NT AUTHORITY\SYSTEM

(IO) ALLOW Full access NT AUTHORITY\SYSTEM

(NI) ALLOW Full access BUILTIN\Administrators

(IO) ALLOW Full access CREATOR OWNER

 

Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:

Read BUILTIN\Users

Read BUILTIN\Power Users

Full access BUILTIN\Administrators

Full access NT AUTHORITY\SYSTEM

 

 

»»Member of...: (Admin logon required!)

User is a member of group WILKINSON\None.

User is a member of group \Everyone.

User is a member of group BUILTIN\Administrators.

User is a member of group BUILTIN\Users.

User is a member of group \LOCAL.

User is a member of group NT AUTHORITY\INTERACTIVE.

User is a member of group NT AUTHORITY\Authenticated Users.

 

 

»»»»»»Backups created...»»»»»»

11:04am up 0 days, 0:34

Fri 30 Jul 04 11:04:17

 

A C:\FINDnFIX\keyback.hiv

--a-- - - - - - 8,192 07-30-2004 keyback.hiv

A C:\FINDnFIX\keys1\winkey.reg

--a-- - - - - - 287 07-30-2004 winkey.reg

*Temp backups...

.

..

keyback2.hi_

winkey2.re_

 

 

C:\FINDNFIX\

JUNKXXX Fri 30 Jul 2004 11:03:14 .D... <Dir>

 

1 item found: 0 files, 1 directory.

 

»»Performing string scan....

00001150: ?

00001190: vk UDeviceNo

000011D0:tSelectedTimeout 1 5 @ vk ' z

00001210:GDIProcessHandleQuota" 9 0 | vk X

00001250:Spooler2 y e s n vk =pswapdisk

00001290: 8 h vk ( R TransmissionRetryTimeout

000012D0: vk ' n USERProcessHandleQuotai 8

00001310:h vk : H [ AppInit_DLLsvk C :

00001350:\ W I N D O W S \ S y s t e m 3 2 \ c t l c . d l l d x

00001390:

000013D0:

00001410:

00001450:

00001490:

000014D0:

00001510:

00001550:

00001590:

000015D0:

 

---------- WIN.TXT

AppInit_DLLsvk

--------------

--------------

$011C7: UDeviceNotSelectedTimeout

$0120F: zGDIProcessHandleQuota

$012B8: TransmissionRetryTimeout

$012E8: USERProcessHandleQuotai

$01338: AppInit_DLLsvk

--------------

--------------

C:\WINDOWS\System32\ctlc.dll

--------------

--------------

REGEDIT4

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"DeviceNotSelectedTimeout"="15"

"GDIProcessHandleQuota"=dword:00002710

"Spooler"="yes"

"swapdisk"=""

"TransmissionRetryTimeout"="90"

"USERProcessHandleQuota"=dword:00002710

"AppInit_DLLs"=""

 

A handle was successfully obtained for the

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows key.

This key has 0 subkeys.

The AppInitDLLs value exists and reports as 58 bytes, including the 2 for string termination.

 

[AppInitDLLs]

Ansi string : "C:\WINDOWS\System32\ctlc.dll"

0000 43 00 3a 00 5c 00 57 00 49 00 4e 00 44 00 4f 00 | C.:.\.W.I.N.D.O.

0010 57 00 53 00 5c 00 53 00 79 00 73 00 74 00 65 00 | W.S.\.S.y.s.t.e.

0020 6d 00 33 00 32 00 5c 00 63 00 74 00 6c 00 63 00 | m.3.2.\.c.t.l.c.

0030 2e 00 64 00 6c 00 6c 00 00 00 | ..d.l.l...

Share this post


Link to post
Share on other sites

OK, C:\Windows\System32\ctlc.dll is the super-hidden installer that will keep restoring this hijack at boot unless it's removed.

 

As the next step, DISABLE your antivirus and keep it disabled untill we've finished removing this one; if you do not, it may interfere.

 

Now in the FindnFix 'keys1' folder, double click on FIX.bat. You will get an alert of about 15 seconds before reboot - allow it to reboot.

 

On restart, open Explorer and navigate to C:\Windows\System32 folder, find the ctlc.dll file (it should be visible now). RightClick on ctlc.dll , and select -> Cut from the menu.

 

Immediately Open the C:\FINDnFIX\junkxxx subfolder.

RightClick inside it and select 'Paste' from the menu; hit 'ok' when/if asked on 'read only' file move prompt.

 

- Make sure the file is now indeed in that Junkxxx subfolder

 

Open the FINDnFIX folder again and run the "Restore.bat" file.

It will run and generate a log (log2.txt) . Post the contents of that log in your reply.

Share this post


Link to post
Share on other sites

»»»»»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»»»»

 

Sun 01 Aug 04 18:33:11

6:33pm up 0 days, 0:02

 

Microsoft Windows XP [Version 5.1.2600]

»»»IE build and last SP(s)

6.0.2800.1106 SP1-Q823353-Q832894

The type of the file system is NTFS.

C: is not dirty.

 

»»»»»»»»»»»»»»»»»»***LOG2!(*updated 7/27)***»»»»»»»»»»»»»»»»

 

This log will confirm if the file was successfully moved, and/or

the right file was selected...

 

Scanning for file(s) in System32...

 

»»»»»»» (1) »»»»»»»

 

»»»»»»» (2) »»»»»»»

 

»»»»»»» (3) »»»»»»»

 

No matches found.

Unknown/hidden files...

 

No matches found.

 

»»»»»»» (4) »»»»»»»

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

 

»»»»»(5)»»»»»

 

»»»»»(6)»»»»»

 

»»»»»»» Search by size...

 

 

No matches found.

 

No matches found.

 

No matches found.

 

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

 

»»»*»»» Scanning for moved file... »»»*»»»

 

* result\\?\C:\FINDnFIX\junkxxx\CTLC.222

 

 

C:\FINDNFIX\JUNKXXX\

ctlc.222 Tue 20 Jul 2004 20:59:02 A.... 57,344 56.00 K

 

1 item found: 1 file, 0 directories.

Total of file sizes: 57,344 bytes 56.00 K

 

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

Sniffed -> C:\FINDNFIX\JUNKXXX\CTLC.222

 

**File C:\FINDNFIX\JUNKXXX\CTLC.222

0000DEBE: 67 44 65 76 69 63 65 00 . 00 53 74 72 65 61 6D 69 gDevice. .Streami

0000DED3: 63 65 53 65 74 75 70 00 . 32 00 00 00 00 00 E0 01 ceSetup. 2.....à.

 

A----- CTLC .222 0000E000 20:59.02 20/07/2004

 

--a-- W32i - - - - 57,344 07-20-2004 ctlc.222

A C:\FINDnFIX\junkxxx\ctlc.222

 

CHK-SAFE.EXE Ver 2.51 by Bill Lambdin Don Peters and Robert Bullock.

MD5 Message Digest Algorithm by RSA Data Security, Inc.

 

File name Size Date Time MD5 Hash

________________________________________________________________________

CTLC.222 57344 07-20-104 20:59 c185b36f9969d3a6d2122ba7cbc02249

 

CRC-Cyclic Redundancy Checker, Version 1.20, 08-Feb-92, rtk

 

C:\FINDNFIX\JUNKXXX

CTLC.222 : crc16=3138 crc32=D5C9FB2E

 

 

File: <C:\FINDnFIX\junkxxx\ctlc.222>

 

CRC-32 : D5C9FB2E

 

MD5 : C185B36F 9969D3A6 D2122BA7 CBC02249

 

 

 

 

#######################################################

*Known files are...

--------------------

File: ((56k; (57,344 bytes)

CRC16 : 3138

CRC-32 : D5C9FB2E

MD5 : C185B36F 9969D3A6 D2122BA7 CBC02249

--------------------

File: ((35k; (35,840 bytes)

CRC16 : EEB1

CRC-32 : 33081C8B

MD5 : 1DE9A8E2 4C826006 7A479B09 577D9CAE

--------------------

File: ((21k; (21,504 bytes)

CRC16 : 90A5

CRC-32 : 2258F59E

MD5 : EFEE2CB3 B342A351 51802356 9637F8E6

#######################################################

»»Permissions:

C:\FINDnFIX\junkxxx\ctlc.222 Everyone:F

BUILTIN\Administrators:F

BUILTIN\Administrators:F

BUILTIN\Administrators:F

BUILTIN\Administrators:F

NT AUTHORITY\SYSTEM:F

WILKINSON\Ashley:F

BUILTIN\Users:R

 

Directory "C:\FINDnFIX\junkxxx\."

Permissions:

Type Flags Inh. Mask Gen. Std. File Group or User

======= ======== ==== ======== ==== ==== ==== ================

Allow 00000003 tco- 001F01FF ---- DSPO rw+x BUILTIN\Administrators

Allow 00000002 tc-- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM

Allow 00000009 --o- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM

Allow 00000002 tc-- 001F01FF ---- DSPO rw+x BUILTIN\Administrators

Allow 00000009 --o- 001F01FF ---- DSPO rw+x BUILTIN\Administrators

Allow 00000013 tco- 001F01FF ---- DSPO rw+x BUILTIN\Administrators

Allow 00000013 tco- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM

Allow 00000010 t--- 001F01FF ---- DSPO rw+x WILKINSON\Ashley

Allow 0000001B -co- 10000000 ---A ---- ---- \CREATOR OWNER

Allow 00000013 tco- 001200A9 ---- -S-- r--x BUILTIN\Users

Allow 00000012 tc-- 00000004 ---- ---- --+- BUILTIN\Users

Allow 00000012 tc-- 00000002 ---- ---- -w-- BUILTIN\Users

 

Owner: WILKINSON\Ashley

 

Primary Group: WILKINSON\None

 

Directory "C:\FINDnFIX\junkxxx\.."

Permissions:

Type Flags Inh. Mask Gen. Std. File Group or User

======= ======== ==== ======== ==== ==== ==== ================

Allow 00000003 tco- 001F01FF ---- DSPO rw+x BUILTIN\Administrators

Allow 00000003 tco- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM

Allow 00000000 t--- 001F01FF ---- DSPO rw+x WILKINSON\Ashley

Allow 0000000B -co- 10000000 ---A ---- ---- \CREATOR OWNER

Allow 00000003 tco- 001200A9 ---- -S-- r--x BUILTIN\Users

Allow 00000002 tc-- 00000004 ---- ---- --+- BUILTIN\Users

Allow 00000002 tc-- 00000002 ---- ---- -w-- BUILTIN\Users

 

Owner: WILKINSON\Ashley

 

Primary Group: WILKINSON\None

 

File "C:\FINDnFIX\junkxxx\ctlc.222"

Permissions:

Type Flags Inh. Mask Gen. Std. File Group or User

======= ======== ==== ======== ==== ==== ==== ================

Allow 00000000 t--- 001F01FF ---- DSPO rw+x \Everyone

Allow 00000000 t--- 001F01FF ---- DSPO rw+x BUILTIN\Administrators

Allow 00000000 t--- 001F01FF ---- DSPO rw+x BUILTIN\Administrators

Allow 00000000 t--- 001F01FF ---- DSPO rw+x BUILTIN\Administrators

Allow 00000010 t--- 001F01FF ---- DSPO rw+x BUILTIN\Administrators

Allow 00000010 t--- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM

Allow 00000010 t--- 001F01FF ---- DSPO rw+x WILKINSON\Ashley

Allow 00000010 t--- 001200A9 ---- -S-- r--x BUILTIN\Users

 

Owner: WILKINSON\Ashley

 

Primary Group: WILKINSON\None

 

C:\FINDnFIX\junkxxx\ctlc.222;Everyone:RrRaRepWwAWaWePXDDcO

C:\FINDnFIX\junkxxx\ctlc.222;BUILTIN\Administrators:RrRaRepWwAWaWePXDDcO

C:\FINDnFIX\junkxxx\ctlc.222;BUILTIN\Administrators:RrRaRepWwAWaWePXDDcO

C:\FINDnFIX\junkxxx\ctlc.222;BUILTIN\Administrators:RrRaRepWwAWaWePXDDcO

C:\FINDnFIX\junkxxx\ctlc.222;BUILTIN\Administrators:RrRaRepWwAWaWePXDDcO

C:\FINDnFIX\junkxxx\ctlc.222;NT AUTHORITY\SYSTEM:RrRaRepWwAWaWePXDDcO

C:\FINDnFIX\junkxxx\ctlc.222;WILKINSON\Ashley:RrRaRepWwAWaWePXDDcO

C:\FINDnFIX\junkxxx\ctlc.222;BUILTIN\Users:RrRaRepX

 

 

 

»»Size of Windows key:

(*Default-450 *No AppInit-398 *fake(infected)-448,504,512...)

 

Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 450

 

»»Dumping Values:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

DeviceNotSelectedTimeout = 15

GDIProcessHandleQuota = REG_DWORD 0x00002710

Spooler = yes

swapdisk =

TransmissionRetryTimeout = 90

USERProcessHandleQuota = REG_DWORD 0x00002710

AppInit_DLLs =

 

»»Security settings for 'Windows' key:

 

 

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above

Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)

This program is Freeware, use it on your own risk!

 

Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:

(ID-NI) ALLOW Read BUILTIN\Users

(ID-IO) ALLOW Read BUILTIN\Users

(ID-NI) ALLOW QWCEN-DS-- BUILTIN\Power Users

(ID-IO) ALLOW QWCEN-DS-- BUILTIN\Power Users

(ID-NI) ALLOW Full access BUILTIN\Administrators

(ID-IO) ALLOW Full access BUILTIN\Administrators

(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM

(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM

(ID-NI) ALLOW Full access WILKINSON\Ashley

(ID-IO) ALLOW Full access CREATOR OWNER

 

Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:

Read BUILTIN\Users

QWCEN-DS-- BUILTIN\Power Users

Full access BUILTIN\Administrators

Full access NT AUTHORITY\SYSTEM

Full access WILKINSON\Ashley

 

 

 

00001150: $ ? 1 <w#_ck

00001190: 1 <w#_ck 1 <w#_ck

000011D0: vk S DeviceNotSelectedTimeout 1 5

00001210: l d vk ' UGDIProcessHandleQuotaout

00001250: 9 0 | vk zSpoolere y e s @

00001290: vk swapdisk ` vk

000012D0: P TransmissionRetryTimeout vk ' is

00001310:USERProcessHandleQuota~ ` H vk

00001350: j AppInit_DLLs m~

00001390:

000013D0:

00001410:

00001450:

00001490:

000014D0:

00001510:

00001550:

 

---------- NEWWIN.TXT

AppInit_DLLsˆm~

--------------

--------------

$011F0: DeviceNotSelectedTimeout

$01237: UGDIProcessHandleQuotaout

$012E0: TransmissionRetryTimeout

$0130E: isUSERProcessHandleQuota

$01360: AppInit_DLLs

--------------

--------------

No strings found.

 

 

d.... 0 Jul 30 11:03 .

d.... 0 Jul 30 11:03 ..

....a 57344 Jul 20 20:59 ctlc.222

 

3 files found occupying 55296 bytes

 

-------- C:\FINDNFIX\JUNKXXX\CTLC.222

InstallStreamingDeviceStreamingDeviceSetupStreamingDeviceSetup2

===============================================================================

57,344 bytes 5,734,400 cps

Files: 1 Records: 13,139 Matches: 3 Elapsed Time: 00:00:00.01

 

VDIR v1.00

Path: C:\FINDNFIX\JUNKXXX\*.*

---------------------------------------+---------------------------------------

. <dir> 07-30-:4 11:03|CTLC 222 57344 A 07-20-:4 20:59

.. <dir> 07-30-:4 11:03|

---------------------------------------+---------------------------------------

3 files totaling 57344 bytes consuming 65024 bytes of disk space.

17299968 bytes available on Drive C: No volume label

 

...File dump...

 

56880 00000000 4b45524e 454c3332 2e444c4c |....KERNEL32.DLL| 0de30

56896 00004c6f 61644c69 62726172 79410000 |..LoadLibraryA..| 0de40

56912 47657450 726f6341 64647265 73730000 |GetProcAddress..| 0de50

56928 00000000 00000000 00000000 a6f00100 |................| 0de60

56944 01000000 03000000 03000000 88f00100 |................| 0de70

56960 94f00100 a0f00100 05270000 9a230000 |.........'...#..| 0de80

56976 242a0000 a7f00100 bef00100 d3f00100 |$*..............| 0de90

56992 00000100 02000049 6e737461 6c6c5374 |.......InstallSt| 0dea0

57008 7265616d 696e6744 65766963 65005374 |reamingDevice.St| 0deb0

57024 7265616d 696e6744 65766963 65536574 |reamingDeviceSet| 0dec0

57040 75700053 74726561 6d696e67 44657669 |up.StreamingDevi| 0ded0

57056 63655365 74757032 |ceSetup2 | 0dee0

 

Detecting...

 

C:\FINDnFIX\junkxxx

ctlc.222 ACL has 8 ACE(s)

SID = /Everyone S-1-1-0

ACE 0 is an ACCESS_ALLOWED_ACE_TYPE

ACE 0 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN

SID = BUILTIN/Administrators S-1-5-32-544

ACE 1 is an ACCESS_ALLOWED_ACE_TYPE

ACE 1 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN

SID = BUILTIN/Administrators S-1-5-32-544

ACE 2 is an ACCESS_ALLOWED_ACE_TYPE

ACE 2 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN

SID = BUILTIN/Administrators S-1-5-32-544

ACE 3 is an ACCESS_ALLOWED_ACE_TYPE

ACE 3 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN

SID = BUILTIN/Administrators S-1-5-32-544

ACE 4 is an ACCESS_ALLOWED_ACE_TYPE

ACE 4 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN

SID = NT AUTHORITY/SYSTEM S-1-5-18

ACE 5 is an ACCESS_ALLOWED_ACE_TYPE

ACE 5 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN

SID = WILKINSON/Ashley S-1-5-21-823518204-2000478354-1801674531-1003

ACE 6 is an ACCESS_ALLOWED_ACE_TYPE

ACE 6 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN

SID = BUILTIN/Users S-1-5-32-545

ACE 7 is an ACCESS_ALLOWED_ACE_TYPE

ACE 7 mask = 0x001200a9 -R -X

ACL done...

 

 

Finished Detecting...

Share this post


Link to post
Share on other sites

Well done! :)

 

Open the FINDnFIX folder again and open the Files2 folder. Double-click on the ZIPZAP.bat. It will quickly clean the rest and will make a copy of the bad file(s) in the same folder (junkxxx.zip) and open your email client with instructions.

 

Simply drag and drop the junkxxx.zip file from the folder into the mail message and submit to the specified addresses.

Please be sure to include a link to this thread in the body of your email. Reboot when done, then delete the entire FINDnFIX folder.

 

Now click here to download CWShredder by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'.

If you already have CWShredder, click 'Check for update' and make sure you are running version 1.59.1 .Reboot when done. Rescan with Hijack This, and post a new log in your next reply.

Share this post


Link to post
Share on other sites

:-) we are getting there!

 

Logfile of HijackThis v1.97.7

Scan saved at 22:14:06, on 01/08/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\System32\RunDll32.exe

C:\WINDOWS\System32\sm56hlpr.exe

C:\WINDOWS\System32\RUNDLL32.EXE

C:\Program Files\WinZip\WZQKPICK.EXE

C:\WINDOWS\System32\nvsvc32.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Documents and Settings\Ashley\My Documents\hijack this\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"

O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [sM56ACL] sm56hlpr.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit

O4 - Startup: PowerReg Scheduler V3.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

O9 - Extra button: Related (HKLM)

O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)

O9 - Extra button: Messenger (HKLM)

O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...director/sw.cab

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab

O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...38188.580787037

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab

O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B23E0CC} - http://direct.data-line.us/gbn298.exe

Share this post


Link to post
Share on other sites

With all Browser Windows closed, have Hijack This fix these items:

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank

 

O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B23E0CC} - http://direct.data-line.us/gbn298.exe

 

Go to Control Panel > Internet (Options)

 

In the General Tab > Temporary Internet Files section, hit "delete files". Make sure the 'delete all offline content' box is checked as well.

 

Now go to the 'Programs' tab, and click 'reset Web Settings'. In the dialog box, make sure 'Also reset my home page' check box is ticked.

Then click Yes , then OK, and OK once more in order to apply the settings.

 

Restart your computer, run Hijack This again, and post a fresh log.

Share this post


Link to post
Share on other sites

here is my new log:

 

 

Logfile of HijackThis v1.97.7

Scan saved at 14:05:33, on 02/08/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\System32\RunDll32.exe

C:\WINDOWS\System32\sm56hlpr.exe

C:\Program Files\MSN Messenger\MsnMsgr.Exe

C:\WINDOWS\System32\RUNDLL32.EXE

C:\Program Files\WinZip\WZQKPICK.EXE

C:\Program Files\iPod\bin\iPodService.exe

C:\Documents and Settings\Ashley\My Documents\hijack this\HijackThis.exe

 

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"

O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [sM56ACL] sm56hlpr.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit

O4 - Startup: PowerReg Scheduler V3.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

O9 - Extra button: Related (HKLM)

O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)

O9 - Extra button: Messenger (HKLM)

O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...director/sw.cab

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab

O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...38188.580787037

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab

Share this post


Link to post
Share on other sites

Glad we could help!

 

If you need this topic reopened, please request this by sending the moderating team an email with the address of the thread. This applies only to the original topic starter. Everyone else please begin a New Topic.

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.
Sign in to follow this  
Followers 0