User Name Password Register
DaniWeb IT Discussion Community
All
What is DaniWeb IT Discussion Community?
You're currently browsing the Viruses, Spyware and other Nasties section within the Tech Talk category of DaniWeb, a massive community of 397,886 software developers, web developers, Internet marketers, and tech gurus who are all enthusiastic about making contacts, networking, and learning from each other. In fact, there are 2,610 IT professionals currently interacting right now! Registration is free, only takes a minute and lets you enjoy all of the interactive features of the site.
Please support our Viruses, Spyware and other Nasties advertiser:

Hijack this log Re: desktop background

Join Date: Jul 2005
Location: FL.
Posts: 1,536
Reputation: tayspen is on a distinguished road 
Rep Power: 7
Solved Threads: 98
Colleague
tayspen's Avatar
tayspen tayspen is offline Offline
<Insert title here>

Re: Hijack this log Re: desktop background

  #3  
Mar 26th, 2006
Hi and welcome to DaniWeb. First I think your Internet eplorer is out of date. You can run Windows Update to fix that.

Ok, you have a fair amount of nasties on your system. Lets boot into safe mode, and have windows show hidden files or folders. To do this:


1 Click the Start Button

2 In the Start menu click Control Panel

3 In the Control panel Window click the Folder Options Icon

4 The folder Options Window will now Open

5 Click the View Tab

6 In the view tab window look down the list for a section marked Hidden Files and Folders

7 Enable the option Show Hidden Files and Folders by left clicking the radio button on the left of the option with your mouse. Then uncheck Hide protected operating system files. CLick yes to the dialog.

8 Press the Apply button

9 On the next screen press OK to exit

10 You should now be able to view the hidden files and folders.

------------------------

1. If the computer is running, shut down Windows, and then turn off the power
2. Wait 30 seconds, and then turn the computer on.
3. When you see the black-and-white Starting Windows bar at the bottom of the screen, start tapping the F8 key. The Windows 2000 Advanced Options Menu appears.
4. Ensure that the Safe mode option is selected. In most cases, it is the first item in the list and is selected by default.
5. Press Enter. The computer then begins to start in Safe mode.


Then while in safe mode Run HJT again and put a check next to the following items.


O4 - HKLM\..\Run: [bauggva] c:\windows\system32\hjsawed.exe

O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe

O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe

O4 - HKLM\..\Run: [wuozsrr] C:\WINDOWS\System32\pzegua.exe r


O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe


O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE

O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE

O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearc...p=ZUxdm082YYUS

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_98.dll' missing

O13 - DefaultPrefix: http://103.nowfind.biz/gall.php?url=

O13 - WWW Prefix: http://103.nowfind.biz/gall.php?url=

O13 - WWW Prefix: http://103.nowfind.biz/gall.php?url=

O13 - WWW Prefix: http://103.nowfind.biz/gall.php?url=

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache...WBInitialSetup 1.0.0.15.cab


Click Fix Checked


Then please Uninstall the following (Start>Control Panel>Add/Remove Programs)


Newdotnet

My Web Search

Also if you see any of these, uninstall them as well

My Web Search

My Way Speedbar

My Way Speedbar

My Way Speedbar

Search Assistant - My Way



Then please go to Start>My Computer>Program Files

Delete the following folders

FunWebProducts

MyWebSearch

Then while your still in safe mode, delete the following files.

C:\WINDOWS\System32\pzegua.exe

c:\windows\system32\hjsawed.exe

C:\WINDOWS\dinst.exe

----------------------------------------------------------------
Reboot Computer Normally

Then please download ewido - www.ewido.net - Install. Update. Scan. Remove anything it finds.

Post a new HJT log, and the ewido log


EDIT: Do what Demented said, quicker and probally more effective
Firefox
Ewido
Tune up windows
Get detailed system information
My Fixes

Member - Alliance of Security Analysis Professionals - Since 2006
Reply With Quote  
All times are GMT -4. The time now is 9:47 am.
Forum system based on vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
©2003 - 2008 DaniWeb® LLC