|
|
|||||||||
|
|||||||||
| |||||||||
|
|
|
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
#1
|
|||
|
|||
|
Antivirus Gold hijacker: popups, homepage, desktop, taskbar, slowness
I don't think it's anything lethal, but my computer came down with a bug today that's rendered using it nearly impossible. Popups, phoney search page, a hijacked desktop image, and a weird little icon on my taskbar are the main problems. If it helps to identify itself, I'm seeing plenty of stuff related to something called "Gold Antivirus"/"Antivirus Gold", which is probably a hoax. I've tried hard to weed this out, with my usual systems (Adaware and PestPatrol), a new virus scanner that I downloaded after the infection (BitDefender), and my best guesses at the sources of the problem in Hijackthis, run in regular and safe modes. Here's the logfile from Hijackthis, run under safe mode:
Logfile of HijackThis v1.99.1 Scan saved at 5:21:47 PM, on 7/5/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - Default URLSearchHook is missing F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe, O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Class - {D04B13F5-0E39-EE4E-D33A-14F3941F8539} - C:\WINDOWS\system32\d3ms.dll O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe O4 - HKLM\..\RunOnce: [addwq32.exe] C:\WINDOWS\addwq32.exe O4 - HKLM\..\RunOnce: [addiw32.exe] C:\WINDOWS\addiw32.exe O4 - HKLM\..\RunOnce: [apiwz32.exe] C:\WINDOWS\system32\apiwz32.exe O4 - HKLM\..\RunOnce: [sysru32.exe] C:\WINDOWS\sysru32.exe O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook O4 - HKCU\..\Run: [PopUpStopperProfessional] "C:\PROGRA~1\PANICW~1\POP-UP~1\POPUPS~1.EXE" O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\appzb32.exe O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing) O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender8\vsserv.exe" /service (file missing) O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing) I hope someone can help. Thanks! |
|
#2
|
||||
|
||||
|
hi anansi000,
if you still need help please post a fresh log sorry for the delay .. ![]()
__________________
Nigel ..Seeking code free nirvana... Nigel Fernandes Blog Never argue with fools. They will bring you down to their level and beat you with experience. ![]() Manchester United Forever ![]() |
|
#3
|
|||
|
|||
|
This is the log, run under safe mode. Let me know if there's any other information you require.
Also, in my earlier post, I neglected to mention the live links that popped up on words in regular text ("New York", "travel", "diamonds", etc.). I'm not sure if it matters at all, but I figured it can't hurt to say it. Logfile of HijackThis v1.99.1 Scan saved at 11:24:35 AM, on 7/10/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe C:\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - Default URLSearchHook is missing F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe, O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Class - {D04B13F5-0E39-EE4E-D33A-14F3941F8539} - C:\WINDOWS\system32\d3ms.dll O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe O4 - HKLM\..\RunOnce: [addwq32.exe] C:\WINDOWS\addwq32.exe O4 - HKLM\..\RunOnce: [addzr32.exe] C:\WINDOWS\system32\addzr32.exe O4 - HKLM\..\RunOnce: [addxq.exe] C:\WINDOWS\addxq.exe O4 - HKLM\..\RunOnce: [apizi.exe] C:\WINDOWS\apizi.exe O4 - HKLM\..\RunOnce: [atlhd32.exe] C:\WINDOWS\atlhd32.exe O4 - HKLM\..\RunOnce: [sdksz.exe] C:\WINDOWS\sdksz.exe O4 - HKLM\..\RunOnce: [msus32.exe] C:\WINDOWS\msus32.exe O4 - HKLM\..\RunOnce: [appno.exe] C:\WINDOWS\system32\appno.exe O4 - HKLM\..\RunOnce: [ntgw.exe] C:\WINDOWS\ntgw.exe O4 - HKLM\..\RunOnce: [appmq32.exe] C:\WINDOWS\appmq32.exe O4 - HKLM\..\RunOnce: [winex32.exe] C:\WINDOWS\winex32.exe O4 - HKLM\..\RunOnce: [winwz.exe] C:\WINDOWS\winwz.exe O4 - HKLM\..\RunOnce: [apieu.exe] C:\WINDOWS\apieu.exe O4 - HKLM\..\RunOnce: [ipwh.exe] C:\WINDOWS\ipwh.exe O4 - HKLM\..\RunOnce: [nettc32.exe] C:\WINDOWS\system32\nettc32.exe O4 - HKLM\..\RunOnce: [msaz32.exe] C:\WINDOWS\msaz32.exe O4 - HKLM\..\RunOnce: [msxr.exe] C:\WINDOWS\system32\msxr.exe O4 - HKLM\..\RunOnce: [sdkze32.exe] C:\WINDOWS\system32\sdkze32.exe O4 - HKLM\..\RunOnce: [sysrq.exe] C:\WINDOWS\system32\sysrq.exe O4 - HKLM\..\RunOnce: [mfcws.exe] C:\WINDOWS\mfcws.exe O4 - HKLM\..\RunOnce: [sdkef.exe] C:\WINDOWS\sdkef.exe O4 - HKLM\..\RunOnce: [appvh.exe] C:\WINDOWS\appvh.exe O4 - HKLM\..\RunOnce: [d3sf.exe] C:\WINDOWS\system32\d3sf.exe O4 - HKLM\..\RunOnce: [sysgl32.exe] C:\WINDOWS\sysgl32.exe O4 - HKLM\..\RunOnce: [atlno32.exe] C:\WINDOWS\atlno32.exe O4 - HKLM\..\RunOnce: [d3vs32.exe] C:\WINDOWS\system32\d3vs32.exe O4 - HKLM\..\RunOnce: [d3lt.exe] C:\WINDOWS\d3lt.exe O4 - HKLM\..\RunOnce: [addeh.exe] C:\WINDOWS\system32\addeh.exe O4 - HKLM\..\RunOnce: [apiir.exe] C:\WINDOWS\system32\apiir.exe O4 - HKLM\..\RunOnce: [syslc32.exe] C:\WINDOWS\system32\syslc32.exe O4 - HKLM\..\RunOnce: [sdkaa.exe] C:\WINDOWS\sdkaa.exe O4 - HKLM\..\RunOnce: [ntuf32.exe] C:\WINDOWS\ntuf32.exe O4 - HKLM\..\RunOnce: [apiva.exe] C:\WINDOWS\system32\apiva.exe O4 - HKLM\..\RunOnce: [atlzk32.exe] C:\WINDOWS\atlzk32.exe O4 - HKLM\..\RunOnce: [ipix32.exe] C:\WINDOWS\ipix32.exe O4 - HKLM\..\RunOnce: [apizn.exe] C:\WINDOWS\system32\apizn.exe O4 - HKLM\..\RunOnce: [d3mb.exe] C:\WINDOWS\d3mb.exe O4 - HKLM\..\RunOnce: [appoe.exe] C:\WINDOWS\system32\appoe.exe O4 - HKLM\..\RunOnce: [iecn32.exe] C:\WINDOWS\system32\iecn32.exe O4 - HKLM\..\RunOnce: [nthh.exe] C:\WINDOWS\nthh.exe O4 - HKLM\..\RunOnce: [msqu32.exe] C:\WINDOWS\msqu32.exe O4 - HKLM\..\RunOnce: [d3lj.exe] C:\WINDOWS\d3lj.exe O4 - HKLM\..\RunOnce: [addsu.exe] C:\WINDOWS\system32\addsu.exe O4 - HKLM\..\RunOnce: [crvh.exe] C:\WINDOWS\system32\crvh.exe O4 - HKLM\..\RunOnce: [winfd32.exe] C:\WINDOWS\winfd32.exe O4 - HKLM\..\RunOnce: [atlnr.exe] C:\WINDOWS\system32\atlnr.exe O4 - HKLM\..\RunOnce: [apinu.exe] C:\WINDOWS\apinu.exe O4 - HKLM\..\RunOnce: [crje.exe] C:\WINDOWS\crje.exe O4 - HKLM\..\RunOnce: [ntde.exe] C:\WINDOWS\ntde.exe O4 - HKLM\..\RunOnce: [sysrt32.exe] C:\WINDOWS\sysrt32.exe O4 - HKLM\..\RunOnce: [ntrb.exe] C:\WINDOWS\system32\ntrb.exe O4 - HKLM\..\RunOnce: [appwv32.exe] C:\WINDOWS\appwv32.exe O4 - HKLM\..\RunOnce: [d3qu32.exe] C:\WINDOWS\system32\d3qu32.exe O4 - HKLM\..\RunOnce: [ipvq.exe] C:\WINDOWS\ipvq.exe O4 - HKLM\..\RunOnce: [atlzc.exe] C:\WINDOWS\system32\atlzc.exe O4 - HKLM\..\RunOnce: [mfcul32.exe] C:\WINDOWS\mfcul32.exe O4 - HKLM\..\RunOnce: [d3wl.exe] C:\WINDOWS\system32\d3wl.exe O4 - HKLM\..\RunOnce: [adddo.exe] C:\WINDOWS\adddo.exe O4 - HKLM\..\RunOnce: [msza.exe] C:\WINDOWS\msza.exe O4 - HKLM\..\RunOnce: [atlvr.exe] C:\WINDOWS\atlvr.exe O4 - HKLM\..\RunOnce: [iebu32.exe] C:\WINDOWS\system32\iebu32.exe O4 - HKLM\..\RunOnce: [addni.exe] C:\WINDOWS\system32\addni.exe O4 - HKLM\..\RunOnce: [mfcfz.exe] C:\WINDOWS\mfcfz.exe O4 - HKLM\..\RunOnce: [systb32.exe] C:\WINDOWS\system32\systb32.exe O4 - HKLM\..\RunOnce: [ntiz32.exe] C:\WINDOWS\ntiz32.exe O4 - HKLM\..\RunOnce: [crmw.exe] C:\WINDOWS\system32\crmw.exe O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook O4 - HKCU\..\Run: [PopUpStopperProfessional] "C:\PROGRA~1\PANICW~1\POP-UP~1\POPUPS~1.EXE" O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\appzb32.exe O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing) O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender8\vsserv.exe" /service (file missing) O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing) |
|
#4
|
|||
|
|||
|
You might want to print these instructions for reference or copy and paste them into notepad and save them on your desktop, as you will be off the internet while using HijackThis.
If you have any questions before starting the fix, please don't hesitate to ask! Please download CCleaner: http://www.ccleaner.com Install the program but do Not run it yet! Next... Please download CWShredder: http://cwshredder.net/bin/CWShredder.exe Save it to the desktop but do NOT run it yet. Next... Please download about:Buster from here: http://www.malwarebytes.biz/AboutBuster5.zip Unzip it to the desktop, run it, Check for Updates, and update the files, but do NOT run a scan yet. Next... Please download the trial version of Ewido Security Suite here: http://www.ewido.net/en/download/ Install it, and update the definitions to the newest files. Do NOT run a scan yet. Next... Boot into Safe Mode. Restart your computer, start tapping F8 when your computer first starts booting, there will be a menu displayed > select Safe Mode. Go to Start > Run > type “services.msc” (without the quotes) Locate Network Security Service, right-click on it, and choose Properties. Click Stop, and set the "Startup Type" to Disabled. Next... please run CWShredder, and click Fix. Next... Then please run about:Buster and click Start to begin the scan. If prompted to end the Explorer.exe process, click Yes. Your desktop may disappear --- this is normal. Allow the program to scan twice, and when complete click "Save Log". This will create a text file called "AB Logfile.txt" in the folder where about:Buster is saved. I will want to see this logfile later. Then please run Ewido, and run a full scan. Save the log from the scan for me. Run HijackThis, click scan, place a checkmark next to the following items. Close all browsers and any other windows or the fix may not work! Click "fix checked". R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\nswzf.dll/sp.html#14044 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - Default URLSearchHook is missing F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe, O2 - BHO: Class - {D04B13F5-0E39-EE4E-D33A-14F3941F8539} - C:\WINDOWS\system32\d3ms.dll O4 - HKLM\..\RunOnce: [addwq32.exe] C:\WINDOWS\addwq32.exe O4 - HKLM\..\RunOnce: [addzr32.exe] C:\WINDOWS\system32\addzr32.exe O4 - HKLM\..\RunOnce: [addxq.exe] C:\WINDOWS\addxq.exe O4 - HKLM\..\RunOnce: [apizi.exe] C:\WINDOWS\apizi.exe O4 - HKLM\..\RunOnce: [atlhd32.exe] C:\WINDOWS\atlhd32.exe O4 - HKLM\..\RunOnce: [sdksz.exe] C:\WINDOWS\sdksz.exe O4 - HKLM\..\RunOnce: [msus32.exe] C:\WINDOWS\msus32.exe O4 - HKLM\..\RunOnce: [appno.exe] C:\WINDOWS\system32\appno.exe O4 - HKLM\..\RunOnce: [ntgw.exe] C:\WINDOWS\ntgw.exe O4 - HKLM\..\RunOnce: [appmq32.exe] C:\WINDOWS\appmq32.exe O4 - HKLM\..\RunOnce: [winex32.exe] C:\WINDOWS\winex32.exe O4 - HKLM\..\RunOnce: [winwz.exe] C:\WINDOWS\winwz.exe O4 - HKLM\..\RunOnce: [apieu.exe] C:\WINDOWS\apieu.exe O4 - HKLM\..\RunOnce: [ipwh.exe] C:\WINDOWS\ipwh.exe O4 - HKLM\..\RunOnce: [nettc32.exe] C:\WINDOWS\system32\nettc32.exe O4 - HKLM\..\RunOnce: [msaz32.exe] C:\WINDOWS\msaz32.exe O4 - HKLM\..\RunOnce: [msxr.exe] C:\WINDOWS\system32\msxr.exe O4 - HKLM\..\RunOnce: [sdkze32.exe] C:\WINDOWS\system32\sdkze32.exe O4 - HKLM\..\RunOnce: [sysrq.exe] C:\WINDOWS\system32\sysrq.exe O4 - HKLM\..\RunOnce: [mfcws.exe] C:\WINDOWS\mfcws.exe O4 - HKLM\..\RunOnce: [sdkef.exe] C:\WINDOWS\sdkef.exe O4 - HKLM\..\RunOnce: [appvh.exe] C:\WINDOWS\appvh.exe O4 - HKLM\..\RunOnce: [d3sf.exe] C:\WINDOWS\system32\d3sf.exe O4 - HKLM\..\RunOnce: [sysgl32.exe] C:\WINDOWS\sysgl32.exe O4 - HKLM\..\RunOnce: [atlno32.exe] C:\WINDOWS\atlno32.exe O4 - HKLM\..\RunOnce: [d3vs32.exe] C:\WINDOWS\system32\d3vs32.exe O4 - HKLM\..\RunOnce: [d3lt.exe] C:\WINDOWS\d3lt.exe O4 - HKLM\..\RunOnce: [addeh.exe] C:\WINDOWS\system32\addeh.exe O4 - HKLM\..\RunOnce: [apiir.exe] C:\WINDOWS\system32\apiir.exe O4 - HKLM\..\RunOnce: [syslc32.exe] C:\WINDOWS\system32\syslc32.exe O4 - HKLM\..\RunOnce: [sdkaa.exe] C:\WINDOWS\sdkaa.exe O4 - HKLM\..\RunOnce: [ntuf32.exe] C:\WINDOWS\ntuf32.exe O4 - HKLM\..\RunOnce: [apiva.exe] C:\WINDOWS\system32\apiva.exe O4 - HKLM\..\RunOnce: [atlzk32.exe] C:\WINDOWS\atlzk32.exe O4 - HKLM\..\RunOnce: [ipix32.exe] C:\WINDOWS\ipix32.exe O4 - HKLM\..\RunOnce: [apizn.exe] C:\WINDOWS\system32\apizn.exe O4 - HKLM\..\RunOnce: [d3mb.exe] C:\WINDOWS\d3mb.exe O4 - HKLM\..\RunOnce: [appoe.exe] C:\WINDOWS\system32\appoe.exe O4 - HKLM\..\RunOnce: [iecn32.exe] C:\WINDOWS\system32\iecn32.exe O4 - HKLM\..\RunOnce: [nthh.exe] C:\WINDOWS\nthh.exe O4 - HKLM\..\RunOnce: [msqu32.exe] C:\WINDOWS\msqu32.exe O4 - HKLM\..\RunOnce: [d3lj.exe] C:\WINDOWS\d3lj.exe O4 - HKLM\..\RunOnce: [addsu.exe] C:\WINDOWS\system32\addsu.exe O4 - HKLM\..\RunOnce: [crvh.exe] C:\WINDOWS\system32\crvh.exe O4 - HKLM\..\RunOnce: [winfd32.exe] C:\WINDOWS\winfd32.exe O4 - HKLM\..\RunOnce: [atlnr.exe] C:\WINDOWS\system32\atlnr.exe O4 - HKLM\..\RunOnce: [apinu.exe] C:\WINDOWS\apinu.exe O4 - HKLM\..\RunOnce: [crje.exe] C:\WINDOWS\crje.exe O4 - HKLM\..\RunOnce: [ntde.exe] C:\WINDOWS\ntde.exe O4 - HKLM\..\RunOnce: [sysrt32.exe] C:\WINDOWS\sysrt32.exe O4 - HKLM\..\RunOnce: [ntrb.exe] C:\WINDOWS\system32\ntrb.exe O4 - HKLM\..\RunOnce: [appwv32.exe] C:\WINDOWS\appwv32.exe O4 - HKLM\..\RunOnce: [d3qu32.exe] C:\WINDOWS\system32\d3qu32.exe O4 - HKLM\..\RunOnce: [ipvq.exe] C:\WINDOWS\ipvq.exe O4 - HKLM\..\RunOnce: [atlzc.exe] C:\WINDOWS\system32\atlzc.exe O4 - HKLM\..\RunOnce: [mfcul32.exe] C:\WINDOWS\mfcul32.exe O4 - HKLM\..\RunOnce: [d3wl.exe] C:\WINDOWS\system32\d3wl.exe O4 - HKLM\..\RunOnce: [adddo.exe] C:\WINDOWS\adddo.exe O4 - HKLM\..\RunOnce: [msza.exe] C:\WINDOWS\msza.exe O4 - HKLM\..\RunOnce: [atlvr.exe] C:\WINDOWS\atlvr.exe O4 - HKLM\..\RunOnce: [iebu32.exe] C:\WINDOWS\system32\iebu32.exe O4 - HKLM\..\RunOnce: [addni.exe] C:\WINDOWS\system32\addni.exe O4 - HKLM\..\RunOnce: [mfcfz.exe] C:\WINDOWS\mfcfz.exe O4 - HKLM\..\RunOnce: [systb32.exe] C:\WINDOWS\system32\systb32.exe O4 - HKLM\..\RunOnce: [ntiz32.exe] C:\WINDOWS\ntiz32.exe O4 - HKLM\..\RunOnce: [crmw.exe] C:\WINDOWS\system32\crmw.exe O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\appzb32.exe Please run CCleaner: On the Windows tab, click Run cleaner. On the Applications tab, click Run Cleaner. Reboot normally. Please post a fresh HijackThis log., and post a new HijackThis log, as well as the logs from AboutBuster and Ewido. Tom
__________________
HijackThis Ad-aware Spybot Search & Destroy SpywareBlaster SpywareGuard Housecall Online A/V Scan Please read the stickys at the top of the forum before posting! |
|
#5
|
|||
|
|||
|
I followed all the procedures you listed. Unfortunately, at least some of the bugs seem to have survived the purge. I am putting all of the logs on here as attached files, just for brevity's sake, since you can always post them in their entirety if you deem it worthwhile.
|
|
#6
|
|||
|
|||
|
Hi anansi000,
Sorry about the delay. Some nice guy pulled in front of me with his car and kind of messed both me and my car up a couple of weeks ago. Please post a fresh HijackThis log. Tom |
![]() |
| Viewing: Dev Shed Forums > System Administration > Antivirus Protection > My computer seems to have the plague |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
|
|