Computer A
These are "Nasty":
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmiracle.com/sp.php
R3 - Default URLSearchHook is missing
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINNT\EliteToolBar\EliteToolBar version 59.dll
O2 - BHO: &EliteSideBar - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - C:\WINNT\EliteSideBar\EliteSideBar 08.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINNT\EliteToolBar\EliteToolBar version 59.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINNT\EliteToolBar\EliteToolBar version 59.dll
O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
O16 - DPF: v3cab - http://searchmiracle.com/cab/v3cab.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/D...e/bridge-c7.cab
Do you know the IP or Domain '209.12.79.2,63.84.206.2,67.103.22.222'?
Caperjack didnt mention this I don't think. But for the O4 files you have to delete those files by going to that file.
Also CaperJack Microsoft AntiSpyware works just as well as Ad-Aware.
A lot more in baddies computer A than that ,thats why i got them to run the programs in my post, first and then post a new log !:)
I agree about microsofts program but its Beta and i don't recomend Beta program ,but if anyone wants to use please do ,I do !!
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
anyway this is what i find bad in computer A ,if any of this remains after running recomended program fix it .
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
Have Hijack This fix the following by placing a check in the appropriate boxes and selecting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.
You might want to print out or copy & paste to notePad , these instructions as you will need to close this browser window to fix with hijackthis !
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmiracle.com/sp.php
R3 - Default URLSearchHook is missing
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINNT\EliteToolBar\EliteToolBar version 59.dll
O2 - BHO: &EliteSideBar - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - C:\WINNT\EliteSideBar\EliteSideBar 08.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINNT\EliteToolBar\EliteToolBar version 59.dll
O4 - HKLM\..\Run: [alter service] hub132.exe
O4 - HKLM\..\Run: [element furth] c:\winnt\system32\vert\repcale.exe c:\winnt\system32\vert\palsp.exe
O4 - HKLM\..\Run: [mark the service] xxtra32.exe
O4 - HKLM\..\Run: [antiware] C:\winnt\system32\elitehwl32.exe
O4 - HKLM\..\Run: [clfmon] C:\WINNT\clfmon.exe
O4 - HKLM\..\Run: [SvcH0st] C:\WINNT\shch.exe /i
O4 - HKLM\..\Run: [Preview AdService] C:\Program Files\Preview AdService\PrevAdServ.exe
O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
O4 - HKLM\..\RunServices: [alter service] hub132.exe
O4 - HKLM\..\RunServices: [mark the service] xxtra32.exe
O4 - HKCU\..\Run: [alter service] hub132.exe
O4 - HKCU\..\Run: [mark the service] xxtra32.exe
O4 - HKCU\..\Run: [IBvpRhZti] serogmsg.exe
again this is optional.
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
Same here as in computer B, one is bad for sure but fix all to be safe .
O16 - DPF: v3cab - http://searchmiracle.com/cab/v3cab.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/pcpitstop.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/D...e/bridge-c7.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - http://www.ysbweb.com/ist/softwares...ysb_regular.cab
Now reboot into safe mode and delete the following files and folders if found .
hub132.exe,,,,,,,delete file
c:\winnt\system32\vert\,,,,,,,delete Folder
xxtra32.exe,,,,,,,delete file
C:\winnt\system32\elitehwl32.exe
C:\WINNT\clfmon.exe,,,,,,,delete file
C:\WINNT\shch.exe ,,,,,,,delete file
C:\Program Files\Preview AdService\,,,,,,,delete Folder
c:\temp\salm.exe,,,,,,,delete file
serogmsg.exe,,,,,,,delete file
to delete the above files and folder you will need to do the following
go to
Show hidden files & folders
"Fix Checked"...Reboot to SAFE mode to delete files
How to start computer in safe mode
reboot computer and post a new log