Reboot into safe mode following the instructions here & navigate to & delete the following:
C:\WINDOWS\system32\crnm.exe< file
C:\WINDOWS\system32\windh.exe< file
C:\WINDOWS\jlxzg.dll< file
C:\WINDOWS\system32\winfi32.dll< file
Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\jlxzg.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://jlxzg.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://jlxzg.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\jlxzg.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://jlxzg.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\jlxzg.dll/sp.html#96676
O2 - BHO: (no name) - {55EA0424-DDA9-DB28-3D99-75C0B49E15FE} - C:\WINDOWS\system32\winfi32.dll
O4 - HKLM\..\Run: [crnm.exe] C:\WINDOWS\system32\crnm.exe
O4 - HKLM\..\RunOnce: [windh.exe] C:\WINDOWS\system32\windh.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/03634be...ip/RdxIE601.cab
Reboot normally after doing the above then post a fresh log plz.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Go here for an on-line scan & set it to autoclean for you.
Reboot & post another log plz.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
- Make sure your settings allow you to view "Hidden files". Open up any explorer windows and click on "Tools" => "Folder Options" => "View" and be sure to check off "Show Hidden Files and Folders".
- Press Ctrl+Alt+Delete once => Click Task Manager => Click the Processes tab => Double-click the Image Name column header to alphabetically sort the processes => Scroll through the list and look for "crhi.exe" & "msmy32.exe". If you find the files, click on them, and then click End Process => Exit the Task Manager.
- Next, go to Start->Run and type "Services.msc" (without quotes) then hit OK.
- Scroll down and find the service called "Network Security Service".
- When you find it, double-click on it. In the next window that opens, click the Stop button, then change the Startup Type to Disabled. Now hit Apply and then OK and close any open windows.
Run HijackThis, click on "Scan" and then place a check mark in the following boxes, And click on "Fix Checked":
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\cmotv.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://cmotv.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://cmotv.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\cmotv.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://cmotv.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\cmotv.dll/sp.html#96676
O2 - BHO: (no name) - {6EB6A56A-4BFC-3BA9-232B-8316BEE8CB76} - C:\WINDOWS\system32\javaun32.dll
O4 - HKLM\..\Run: [msmy32.exe] C:\WINDOWS\system32\msmy32.exe
O4 - HKLM\..\RunOnce: [crhi.exe] C:\WINDOWS\system32\crhi.exe
Reboot into Safe Mode - How do I boot into "Safe" mode? , and delete the following files:
C:\WINDOWS\cmotv.dll< file
C:\WINDOWS\system32\javaun32.dll< file
C:\WINDOWS\system32\msmy32.exe< file
C:\WINDOWS\system32\crhi.exe< file
- Go to Start => Run and type in "regedit" (without quotes) and press "Enter".
- One the registry opens, Navigate to: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\__NS_Service_3
If __NS_Service_3 exists , right click on it and choose delete from the menu.
- Still in the registry, navigate to: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY___NS_Service_3
If LEGACY___NS_Service_3 exists then right click on it and choose delete from the menu.
- Exit regedit and reboot in Normal Mode.
- Two files (Possibly three) were also deleted from your computer and need to be replaced.
- control.exe - Go to Merijn Files (control) and download the version of control.exe for your operating system. If you are running Windows 2000, copy it to c:\winnt\system32\. For Windows XP, copy it to c:\windows\system32\.
- Download the Hoster from here . Press "Restore Original Hosts" and press "OK". Exit Program.
- If you have Spybot S&D installed you will also need to replace one file. Go here: Merijn's Files (sdhelper) and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy)
- Run HiJackThis again and post a new log in this thread.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
That looks good now. Check out the *how you got infected* link in my sig.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
from: sgibbins--
Also, I do not know what to do once I have an adaware log.
First up, you need to start your own thread so that you recieve the helkp that you need. You also need to delete all that adaware finds.
Settings for Adaware :
In settings under 'scanning,' have it set to
'scan within archives,'
'scan active processes,'
'scan registry,'
'deepscan registry'
'scan my IE Favourites for banned URL's,'
'scan my host's file.'
In 'tweaks' under 'scanning engine' set it to 'unload recognised processes during scanning.'
Also in 'tweaks' under 'cleaning engine' set it to 'Automatically try to unregister objects prior to deletion' & 'let Windows remove files in use at next reboot.'
Select 'activate in-depth scan' before starting scan.
When the scan is finished select 'next.'
Remove what it finds by placing a check in the box to the left of the object.Reboot
Download & instal Spybot S&D from here Update it B4 scanning.
After the scan is complete, have spybot fix everything marked RED.
On the page that first opens when you start Spybot there is an option to immunise, you should do this. In the immunise section there is also a link to download Spywareblaster. This program will prevent the install of bad activex controls that it has knowledge of. Download that & you can keep it updated by selecting the same link that you use to download it. Reboot
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
I am having problems posting Topics, it doesn't work, but my homepage keeps changing back to res://jxusk.dll/index.html#37049. I did everything, norton ant virus scan, ad-aware, spybot, cwshredder. What is wrong need help.
bill786
Junior Poster in Training
52 posts since Jun 2004
Reputation Points: 11
Solved Threads: 1
I am having problems posting Topics, it doesn't work, but my homepage keeps changing back to res://jxusk.dll/index.html#37049. I did everything, norton ant virus scan, ad-aware, spybot, cwshredder. What is wrong need help.
At the top of the page almost, select *New thread* & post what the problem is, what you have done to fix it etc. I don't think (as you have found) that any of those programs will fix this particular hijack, so you will need to post a hijackthis log after you have rebooted your computer.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
At the top of the page almost, select *New thread* & post what the problem is, what you have done to fix it etc. I don't think (as you have found) that any of those programs will fix this particular hijack, so you will need to post a hijackthis log after you have rebooted your computer.
I can't post topics, it is not working, It doesn't post it after I finish typing the message. It goes back to the main screen of these forums.
bill786
Junior Poster in Training
52 posts since Jun 2004
Reputation Points: 11
Solved Threads: 1
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985