A) Remove Spyware Begone- the program is bogus. See the following link for an explanation:
http://www.spywarewarrior.com/rogue_anti-spyware.htm
B) You should download and run Ad Aware and SpyBot, as well as do an online virus scan; that will clear up a lot of your problems. Instructions for doing so, as well as other solutions which address some of your exact problems, can be found in the link below:
http://forums.thatcomputerguy.us/index.php?showtopic=4703
C) Once you've done the above:
- create a new, separate folder for HijackThis somewhere on your hard drive that is not inside a Temp/Temporary/Temporary Internet folder (C:\HijackThis, for example). Move HJT to that folder and run it from there from now on.
- close all open programs, especially Internet Explorer; HJT cannot perform all of its fixes if IE is running.
- run HJT again and post a fresh log.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
*Both before and after performing "spyware" removal procedures, it is a very good idea to delete the contents of all Cookies, Temp, and Temporary Internet Files folders and then empty your Recycle Bin. Rebooting after doing so is also a good idea.
1. To start with, you are infected by a WinTools variant. Carefully follow the instructions in the link below to remove it:
http://www.pchell.com/support/wintools.shtml
2. Have HJT fix the following:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.piyovwjyalldzh.info/yJQs...PLraVt7Sf8G.cgi
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: CnfSearch Class - {D7CD08F0-D691-11D8-9669-0800200C9A66} - c:\winnt\system32\ConfuSearch.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common Files\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [ObjBiasSeekDumb] C:\Documents and Settings\All Users\Application Data\4 heck obj bias\Axis Heart.exe
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - HKCU\..\Run: [Spyware Begone] c:\freescan\freescan.exe -FastScan
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/c...DC_1_0_0_44.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/0100131...ip/RdxIE601.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/sof...nch/alaunch.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4...21/cpbrkpie.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {E123BED4-B8C7-42BB-958F-F13CA77EF95D} (Anark Client ActiveX Control) - http://install.anark.com/client/ver...en/AMClient.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
I don't recognize the entries below, but if you can't verify that they're legitiamate I'd have HJT fix them as well:
O4 - HKLM\..\Run: [drv fast] C:\PROGRA~1\HOPEVI~1\Data Bits Ante.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
3. Reboot into safe mode and delete:
- the enitre "Web Offer" folder.
- the "Heart.exe" file. Judging from the name of the folder the file appears to live in, the entire folder should probably be deleted, but I can't be certain.
- If you've had HJT fix the "Ante.exe" and "SED.exe" entries, delete the files. Again, the entire folders should probably be deleted, but I can't be certain.
4. I already mentioned this, but: remove the Spyware Begone program.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370