Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
O1 - Hosts: ch.com
O1 - Hosts: 207.36.196.189 auto.search.msn.com
O1 - Hosts: 207.36.196.189 search.netscape.com
O1 - Hosts: 207.36.196.189 ieautosearch
O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file)
O3 - Toolbar: Pop Intra - {8E9AEE61-61F6-F8E6-114F-A7565A89F99E} - C:\PROGRA~1\SIZEAC~1\The Trans.dll (file missing)
O4 - HKLM\..\Run: [fash] C:\WINDOWS\fash.exe
If you cannot vouch for the following entry, fix it too;
O4 - HKLM\..\Run: [managereq] C:\PROGRA~1\OPENLE~1\WaitMp3.exe
Reboot into safe mode following the instructions here & navigate to & delete the following if found:
C:\WINDOWS\fash.exe< file
C:\PROGRA~1\OPENLE~1< folder, noting my query above.
Reboot normally after doing the above then post a fresh log plz.
Can you download the following app & run it, making sure to have one internet exploder window open. Save the log & paste the results back here.
VX2Finder
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Run Vx2Finder.exe again and click the Click to Find Vx2.BetterInternet button again. Place check marks next to each file and click the Delete these Files button. Click OK to each confirmation message.
Click the Open regedit button. Look for a Guardian... line in the left column. Right click it and choose Security/permissions. You'll get another window with advanced. Uncheck the lower box with inheritable permissions. Click ok and then choose remove on the following security prompt. Restart computer.
After a restart, double click VX2Finder.exe again, click the Click to Find Vx2.BetterInternet button again. Place a checkmark next to the remaining file(s) and click the Delete these Files button. Then, click the User Agent$ button to remove the registry entry.
Click the Open regedit button again. Highlight the Guardian... line in the left column, right click it and choose Security/permissions. You'll get another window with advanced. Place a check mark in the lower box with inheritable permissions. Close the registry editor.
Click the Guardian.reg key and Yes to the confirmation. This deletes that Guardian Key in the registry.
Click the Click to Find Vx2.BetterInternet button again and you should get a clean log of blank values. If it looks different than this, then click the Make Log button and post the contents:
Files Found---
Guardian Key--- is called:
User Agent String---
Then click the Restore Policy button to restore the Debug policy altered in the look2Me installation. Reboot your computer when prompted to.
Finally, post a fresh hijackthis log to make sure your all cleaned up.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
1st one is reported as being spyware. 2nd one from Purity = baddy. Try the PurityScan uninstaller.
I was concentrating on Look2Me as that is by far the worst.
Am off to bed now, early start for work, so will catch up tomorrow & see how you go with the removal.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Beautiful. I see nothing bad there now. Check my Sig for how you got infected.
Seriously, thanx for the offer of repayment but I do this solely for the pleasure of cleaning out the trash & getting control back to the user. If you are happy, me too :)
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Hey, you guys do all the work, I do the easy stuff :)
Your thanx are appreciated. Marking this thread solved. Anyone else with similar problems, please start your own thread. Thank you.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985