The following page at Symantec/Norton's support site explains one of the infections you have:
http://sarc.com/avcenter/venc/data/pf/adware.easysearch.html
Since you already have Norton and SpyBot installed, also download and install Ad Aware and then do the following:
A) Run a full anti-virus scan, making sure that your anti-virus program is using the most current virus definition updates.
B) Follow these directions for configuring Ad Aware (directions courtesy of our member "crunchie"):
1. Download and Install Ad-Aware SE, keeping the default options. However, some of the settings will need to be changed before your first scan
2.Close ALL windows except Ad-Aware SE
3. Click on the‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.
4. Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window
1) In the ‘General’ window make sure the following are selected in green:
*Automatically save log-file
*Automatically quarantine objects prior to removal
*Safe Mode (always request confirmation)
Under Definitions:
*Prompt to udate outdated definitions - set the number of days
2) Click on the ‘Scanning’ button on the left and select in green :
Under Driver, Folders & Files:
*Scan Within Archives
Under Select drives & folders to scan -
*choose all hard drives
Under Memory & Registry: all green
*Scan Active Processes
*Scan Registry
*Deep Scan Registry
*Scan my IE favorites for banned URL’s
*Scan my Hosts file
3) Click on the ‘Advanced’ button on the left and select in green:
Under Shell Integration:
*Move deleted files to recycle bin
Under Logfile Detail Level: (all green)
*include addtional object information
*DESELECT - include negligible objects information
*include environment information
Under Alternate Data Streams:
*Don't log streams smaller than 0 bytes
*Don't log ADS with the following names: CA_INOCULATEIT
4) Click the ‘Tweak’ button and select in green:
Under the ‘Scanning Engine’:
*Unload recognized processes during scanning
*Scan registry for all users instead of current user only
Under the ‘Cleaning Engine’:
*Let Windows remove files in use at next reboot
Under the Log Files:
*Include basic Ad-aware SE settings in logfile
*Include additional Ad-aware SE settings in logfile
*Please do not check or make green: Include Module list in logfile
5. Click on ‘Proceed’ to save the settings.
6. Click ‘Start’
*Choose:'Perform Full System Scan'
*DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.
7. Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.
8. If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window
9. Save the log file when it asks and then click ‘finish’
10. REBOOT to complete the removal of what Ad-Aware SE found
* Run SpyBot.
When you first run SpyBot, it will walk you through a Wizard which will perform a few critical functions (making a registry backup, getting the latest updates, etc.).
1. Perform all of the Wizard's tasks.
2. Run the program. Once it completes, have it fix everything it finds.
3. Reboot.
C) Boot into Safe Mode (do this by hitting the F8 key as the computer is booting) and:
- Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files".
- For every user account listed under C:\Documents and Settings, delete everything inside the following folders (don't delete the folders themselves though):
1. Local Settings\Temp
2. Cookies
3. History
4. Local Settings\Temporary Internet Files\Content.IE5
- Delete the entire content of your C:\Windows\Temp folder.
(If you get any messages concerning the deletion of system files such as desktop.ini or index.dat, just choose to delete those files; they'll be automatically regenerated by Windows if needed.)
- Empty your Recycle Bin.
- Reboot normally.
D) Run HijackThis again and post a fresh log.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
Ok, now for the fun part...
We're probably not going to get all of the nasties on the first run, but let's start with this:
1) Have HijackThis fix the following entries:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = https://
F3 - REG:win.ini: run=C:\WINDOWS\inetdata\services.exe
O2 - BHO: (no name) - {2A29FA17-1BA9-6654-A58E-47C6F864C7B3} - C:\WINDOWS\System32\atkshaeg.dll (file missing)
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O2 - BHO: (no name) - {B8DADE78-4022-48BF-BE4F-521F4DE6452D} - C:\WINDOWS\System32\lnmg.dll (file missing)
O2 - BHO: Cls - {CF021F40-3E14-23A5-CBA2-716D61788264} - C:\WINDOWS\System32\max8264.dll
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inetdata\services.exe
O4 - HKLM\..\Run: [Microsoft Internet Acceleration Utility] iau.exe
O4 - HKLM\..\Run: [Internet Connection Wizard] stisvsq.exe
O4 - HKLM\..\Run: [Games Acceleration] svshost.exe
O4 - HKLM\..\Run: [Internet Mail and News] msqdevl.exe
O4 - HKLM\..\Run: [Microsoft Management Console] lssas.exe
O4 - HKLM\..\Run: [Multimedia extensions] mservice.exe
O4 - HKCU\..\Run: [Ooru] C:\Documents and Settings\Andrew Russon\Application Data\thha.exe
O4 - HKCU\..\Run: [Wbihgqvo] C:\WINDOWS\System32\?hkdsk.exe
O4 - HKCU\..\Run: [Microsoft Internet Acceleration Utility] iau.exe
O4 - HKCU\..\Run: [Internet Connection Wizard] stisvsq.exe
O4 - HKCU\..\Run: [Games Acceleration] svshost.exe
O4 - HKCU\..\Run: [Internet Mail and News] msqdevl.exe
O4 - HKCU\..\Run: [Microsoft Management Console] lssas.exe
O4 - HKCU\..\Run: [Multimedia extensions] mservice.exe
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inetdata\services.exe
O15 - Trusted IP range: 206.161.125.149
O15 - Trusted IP range: (HKLM)
O16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\ied_s7m.cab
O16 - DPF: {11111111-1111-1111-1111-511111113457} - file://c:\x.cab
O16 - DPF: {11111111-1111-1111-1111-511111113458} - file://c:\x.cab
* Note that although many of the above "04" entries appear to be duplicates, they are not; be sure to select all of them when you have HijackThis perform the fixes.
2. After HJT finishes the fixes, reboot into Safe Mode and do the following:
- Delete the entire C:\WINDOWS\inetdata folder.
- Find and delete all of the following files:
C:\ied_s7m.cab
C:\x.cab
C:\Documents and Settings\Andrew Russon\Application Data\thha.exe
C:\WINDOWS\inetdata\services.exe
iau.exe
stisvsq.exe
svshost.exe
msqdevl.exe
lssas.exe
mservice.exe
C:\WINDOWS\System32\?hkdsk.exe
- Empty your Recycle Bin and reboot.
- Post a fresh HijackThis log.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
Open Task Manager & end process on the following:
cmd32.exe
Go to C:\WINDOWS\System32 and delete the file manually. It is added by the TANKED WORM!
Scan with hijackthis and tick the boxes next to all the following entries, then close all browser and explorer windows, and hit the "Fix checked" button.
F3 - REG:win.ini: run=C:\WINDOWS\inetdata\services.exe
Reboot into safe mode following the instructions here and navigate to and delete the following if found:
C:\WINDOWS\inetdata\services.exe<----file
Reboot normally after doing the above, rescan with hijackthis, then post that log here please.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Open Task Manager & end process on the following:
cmd32.exe
Go to C:\WINDOWS\System32 and delete the file manually. It is added by the TANKED WORM!
Thanks for the catch crunchie- I totally missed that one... :o
sheff,
The entries referencing the missing googletoolbar2.dll file might mean that the toolbar took a hit in all of this, but other than that your log looks clean now. I'd like to wait for crunchie to give it the OK as well though, before we totally sign off on it.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
No worries DMR. Log looks good :).
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
You're welcome sheff, glad we could help. :)
Now that your system is clean, here are some things you can do to greatly minimize your chances of getting reinfected:
1. Use Windows Automatic Update function to keep your system as up-to-date as possible with the most current Microsoft security and bug fixes.
2. Stop using Internet Explorer as your web browser. Because IE is so closely tied into the Windows operating system itself and contains so many security flaws, switching to another browser such as Netscape, Firefox, or Opera will greatly reduce the avenues through which spyware/adware/hijackers/etc. can infect your computer.
3. Install preventative utilities such as SpywareBlaster and SpywareGuard (links are in my sig below), especially if you absolutely have to continue using Internet Exploder. These utilities protect areas of your system known to be vulnerable to malicious attacks.
4. Tighten up some of Internet Explorer's existing, default settings to make it more secure. Some info on that can be found here .
5. Obviously: install a good anti-virus program and enable its "auto-protect", "auto-update", and email-scanning features.
6. None of your utilities are of much good if you don't check for updates frequently; updates for anti-spyware/anti-virus programs can be released as often as ever two or three days, so make sure you do that for any of the utilities you use which don't have an "auto-update" feature.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
And again- you're welcome.
Norton has its "Live Update" feature. If you enable that, it wil get its updates without any intervention on your part.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370