I don't see anything else in your log, are you still having problems?
I don't see anything else in your log, are you still having problems?
Ok, I did that, but how do I know if it worked?
I also DLed HJT b/c when I got a new computer 6 months ago it was lost.
Should I run it & send you the code?
I don't even remember how after all this time LOL
Thanks
Michelle
That would probably help; make sure you have the latest version of HijackThis (1.99.1).
Close any open browser windows, press the Scan and save log button, and then copy the contents of the log that comes up and paste it here.
Glad we could help. Be careful how you use your computer, especially your work computer! You don't need to be getting fired over something stupid like this.
Go to Start, Run, type regedit in the box, and hit Enter.
At the top of the Registry Editor window, click on File, and then Export. In the Export range panel (at the bottom), click All, give the file a name, and then Save your registry as a backup to a location where you will be able to locate it easily if necessary.
Navigate to and delete the following subkeys:
HKEY_LOCAL_MACHINE\Software\Classes\CLSID
\{081669BA-EFC4-48C2-A8F4-874052D02553}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID
\{145E6FB1-1256-44ED-A336-8BBA43373BE6}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID
\{1D27320E-2DA2-41E2-A103-B5FD9D6A798B}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID
\{B599C57E-113A-4488-A5E9-BC552C4F1152}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID
\{D56A1203-1452-EBA1-7294-EE3377770000}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID
\{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}
HKEY_LOCAL_MACHINE\Software\Classes\Interface
\{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}
HKEY_LOCAL_MACHINE\Software\Classes\Typelib
\{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}
HKEY_LOCAL_MACHINE\Software\Classes\Serch_hook.transURL
HKEY_LOCAL_MACHINE\Software\Classes\Serch_hook.transURL.1
HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database
\Distribution Units\{11120607-1001-1111-1000-110199901123}
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer
\Extensions\{081669BA-EFC4-48C2-A8F4-874052D02553}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Current Version
\Uninstall\Internet Connection Update and HomeP KB234087
HKEY_USERS\Software\Microsoft\Internet Explorer\Extensions
\{081669BA-EFC4-48C2-A8F4-874052D02553}
HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Ext
\Stats\{081669BA-EFC4-48C2-A8F4-874052D02553}
HKEY_USERS\Software\Microsoft\Windows\CurrentVersion
\Policies\System
Navigate to the subkey HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, and in the right pane, delete the value: "WindowsFY" = "C:\wp.exe"
Navigate to the subkey HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Current Version
\Explorer\SharedTaskScheduler, and in the right pane, delete the value: "{D56A1203-1452-EBA1-7294-EE3377770000}" = "Interlinking Memory Support"
Navigate to the subkey HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks, and in the right pane, delete the value: "{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}" = ""
Exit the Registry Editor.
Please read this thread:
http://www.daniweb.com/techtalkforums/thread27519.html
In order to view some of the files and folders mentioned here, you will need to set your system to show hidden files and folders. Open Windows Explorer, go to Tools, and in Folder Options, select Show hidden files and folders, and uncheck Hide protected operating system files.
Get the Pocket Killbox from here:
http://bleepingcomputer.com/files/spyware/KillBox.zip
Unzip the file to your desktop.
Go offline until this is completed (you may wish to print these instructions).
Reboot into Safe Mode.
Do a search for these files and delete any instances found:
param32.dll
guninst.exe
popup_bl.dll
systr.dll
svrhost.exe
If any could not be deleted, (most likely param32.dll), run Pocket Killbox and paste the full file path of file in the box and click on Delete on Reboot. Click on the button with the red circle and an X in the middle; you will get a message saying File will be deleted on next reboot, Process and Reboot now?, Click Yes to reboot. (Note: the 'file path' will be something like C:\WINDOWS\System32\param32.dll)
Scan with hijackthis, and have it fix this entry:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotoffers.info/ad0278/
Empty your Recycle Bin and reboot normally.
Delete any unwanted icons from your desktop and empty your Recycle Bin.
Close any open browser windows, scan with HijackThis, and post a new log please.
PC seems fine now. HC did the trick - Is their virus software worth buying?
If you're looking for the best antivirus, I would recommend Nod32; I don't think it costs any more then the others. You can do a search here on DaniWeb, or on the net, for other opinions and comparisions.
By the way I am looking at building a new PC, what motherboard would you recommend for around 100 to 150 euros? and should I go for AMD or Pentium? (Iwould like at least 2.5 gig)
There will probably be a lot of varying opinions on MB's and CPU's, you may find what you're looking for in the Hardware section (http://www.daniweb.com/techtalkforums/forum7.html). If not, post your own question there. If I were building a PC, I would probably get an ASUS MB and Pentium CPU, but that's just me.
Happy to hear your PC is working properly again :)
Please follow the instructions in this thread:
http://www.daniweb.com/techtalkforums/thread13362.html
Get the Pocket Killbox from here:
http://bleepingcomputer.com/files/spyware/KillBox.zip
Unzip the file to your desktop.
Boot into Safe Mode and do a search for lqfax12n.dll, and delete any instances found.
If any could not be deleted, run Pocket Killbox and paste the full file path in the box and click on Delete on Reboot. Click on the button with the red circle and an X in the middle; you will get a message saying File will be deleted on next reboot, Process and Reboot now?, Click Yes to reboot. (Note: the 'file path' will be something like C:\WINDOWS\system32\lqfax12n.dll)
Empty your Recycle Bin, reboot normally, and search for the file again to make sure it's gone.
Then, right-click in an open area of your desktop, select New, Folder; give the new folder a name (something like HJT or HijackThis), and drag the hijackthis.exe icon that is on your desktop into the new folder.
Close any open browser windows, scan with HJT, and post a new log please.
Open NotePad (or WordPad), copy the contents of the 'Code' below , and paste it into NotePad:
cd System32
attrib -s -r -h MSplg7.dll
del MSplg7.dll
Go to File, Save As and type the filename as Remove.bat, save it to your Desktop, and then close NotePad.
Reboot into Safe Mode.
Scan with Hijackthis and have it fix the following entry:
O20 - Winlogon Notify: f3dsl - C:\WINDOWS\SYSTEM32\MSplg7.dll
Close any open windows and hit Fix checked.
Double-click on the file Remove.bat, and a DOS-type window should open and close quickly, this is normal. (If the window does not close by itslef, you can close it after few seconds.)
Go to C:\WINDOWS\SYSTEM32 and delete MSplg7.dll.
Do a search for MSplg7.dll and delete any instances found.
Empty your Recycle Bin and reboot normally.
Close any open browser windows, scan with HJT, and post a new log please.
Check this thread:
http://www.daniweb.com/techtalkforums/thread27924.html
Slightly different problem, but the same fixes should be tried. There is also a link to reinstalling IE.
thanks so much!!but i still cant get rid of A0059569.exe..it doesn't matter right?what does this virus do?it will appear during the ad-adware scan.Only the exe file.thanks alot!!
Did you have A0059569.exe scanned at Jotti? What were the results?
Glad to hear it :D
Happy computing!
thank you so much =) no im not having any more problems! i really appreciate your help! thanks tons! :mrgreen:
Great! Glad to hear it :)
Happy computing!
Your log looks good to me, are you still having any problems? If so, can you give us the details please?
Thanks VERY, VERY much. Things seem clean now.
I haven't had any bad-looking behavior for the last 24 hours - since even before these last couple of fixes - so I THINK things are clean.Eric
Great! Glad to hear it :)
Let us know if anything else comes up.
Log on to her account, scan with hijackthis, and post the log please.
I would also suggest removing Viewpoint Manager (using Add/Remove Programs), and then go to C:\Program Files and delete the Viewpoint folder.
Hope you don't mind if I cut in...
Why are you trying to remove this? It's the driver for you video card.
You now need to reinstall your video card drivers either with the CD that came with your computer, the CD that came with the card (if you added it seperately), or you can download them from the manufacturers (NVIDIA) website.
2. Followed HJT instructions
During FIX, MS AntiSpyware popped up saying CWS was trying to install.
MS claims to have blocked and fixed. (Although I ran CW Shredder the
other day and IT thought it had fixed everything, too).
Ran MS Scan - clean (but it was this a.m., too, before this)3. On reboot, McAfee says it is broken and wants me to reinstall - I suspect that's because of one of the HJT removals... was that an error? (Not a big deal, but I probably should reinstall).
A question - I read somewhere that AWS is better behaved these days - is it OK to reinstall or is it still considered spyware?
Download, install, and update CWShredder 2.15 --http://www.intermute.com/products/cwshredder.html. Run it, and press Fix (not scan). Close any open windows, other then CWS, before hitting the Fix button.
Nothing you fixed with HJT should have hurt McAfee, but it is possible one of the malicious files on your system corrupted it. McAfee may have a 'Repair' option, if it does, try that first. If not, then reinstall it.
I've also heard that the Weatherbug is not much of a pest anymore. Myself, I wouldn't trust it, but if you like it, and can put up with it's ads (if it still does that), then go ahead and reinstall it).
Also, you may wish to consider disabling CTHELPER.EXE -- quote from sysinfo:
"CTHELPER is a background task that is …
Go to Add/Remove Programs in your Control Panel and remove WeatherBug (or AWS), if present.
Download LSPfix from http://www.computercops.biz/downloads-file-334.html. On the opening screen, click the I know what I'm doing checkbox. Then click Finish.
Scan with hijackthis and have it fix the following entries:
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - Default URLSearchHook is missing
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\topMoxie\TEMP\limeshop_script.htm
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O10 - Broken Internet access because of LSP provider 'connwsp1.dll' missing
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {02466323-75ED-11CF-A267-0020AF2546EA} (VivoActive Control) - http://player.vivo.com/ie/vvweb.cab
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.bitstream.com/wfplayer/tdserver.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (WficaCtl Object) - http://www.genisar.com/files/genplug60.cab
O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} (RdxIE Class) - http://207.188.7.150/201f2d97d5c479...etzip/RdxIE.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1408.g.akamai.net/7/1408/99...iTunesSetup.exe
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared...72/mcinsctl.cab
O16 - DPF: {71CA4411-45EC-4608-B9D7-6D4B6A9D1BB4} (Attenza System Profiler) - http://service.dell.com/dell/SystemProfiler.cab
…
Go to Add/Remove Programs in your Control Panel and remove (if present):
180SearchAssistant
Eecpj
Media Gateway
PartyPoker
Viewpoint (may be Viewpoint Manager, ViewMgr, or something similar)
WeatherBug (or AWS)
WildTangent
Scan with hijackthis and have it fix the following entries:
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O2 - BHO: SABHO - {21B4ACC4-8874-4AEC-AEAC-F567A249B4D4} - c:\program files\180searchassistant\salmhook.dll
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [Hevosxn] C:\Program Files\Eecpj\Qmzwulj.exe
O4 - HKLM\..\Run: [Media Gateway] C:\Program Files\Media Gateway\MediaGateway.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/M...e/bridge-c8.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JA...loadManager.ocx
Close any open windows, other then hijackthis, before hitting Fix checked.
Go to the following locations and delete the highlighted folders:
C:\program files\180searchassistant
C:\Program Files\AWS
C:\Program Files\Eecpj
C:\Program Files\Media Gateway
C:\Program Files\PartyPoker
C:\Program Files\Viewpoint
C:\Program Files\WildTangent
Empty your Recycle Bin and reboot.
Close any open browser …
I don't see anything else, are you still having problems? If so, please give us specific details :)
Your log looks okay to me, are you still having problems?
Hi Helpmerhonda, welcome to DaniWeb :D
I've merged your threads so anyone looking at this will have all the relevant information available. For future refrence, instead of starting a new thread, simply making a new post in the existing one will bring the thread back to the top of the forum where it will have a better chance of getting spotted.
Get Ewido from here:
http://www.download.com/Ewido-Security-Suite/3000-8022_4-10326287.html?tag=lst-0-1
Boot into Safe Mode, scan with Ewido, allowing it to clean whatever it finds.
Reboot normally, close any open browser windows, scan with hijackthis, and post a new log please.
Hi shmay, welcome to DaniWeb :D
Please follow the suggestions in the following threads:
http://www.daniweb.com/techtalkforums/thread27519.html
http://www.daniweb.com/techtalkforums/thread27570.html
Include Ewido in that list of suggestions, and scan with it in Safe Mode.
Empty your Recycle Bin and reboot normally.
Close any open browser windows, scan with HJT, and post a new log please.
You will need to disconnect from the internet so you may wish to print these instructions.
Go to Add/Remove Programs in your Control Panel and remove WildTangent (or WT), if present.
Download Nailfix from here:
http://www.noidea.us/easyfile/file.php?download=20050515010747824
Unzip it to your desktop, but do not run it yet.
Download, install, update, and run these tools:
CWShredder -- http://www.intermute.com/spysubtract/cwshredder_download.html
about:Buster -- http://www.majorgeeks.com/download4289.html
HSRemove -- http://www.majorgeeks.com/download4286.html
PurityScan uninstaller -- http://www.purityscan.com/uninstall.html
Disconnect from the net and reboot into Safe Mode.
Double-click on the Nailfix.cmd that is on your desktop. Your desktop and icons will disappear and reappear, and a window should open and close very quickly -- this is normal.
Then run a full system scan with Ewido (note: you will be posting the log from this scan in your next reply).
Still in Safe Mode, scan with hijackthis and have it fix the following entries:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus9.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus9.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus9.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
…
Getting better, just look at all the stuff Ewido cleaned for you :)
You should follow the instructions here (again):
http://www.daniweb.com/techtalkforums/thread27570.html
Update your antivirus program and allow it to fix whatever it finds.
Scan with HJT and have it fix the following entries:
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [xbnsrhy] c:\windows\system32\avaxrc.exe r
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
Remember to close any open window before hitting Fix checked.
Go to the following locations and delete the highlighted files:
C:\WINDOWS\wupdt.exe
C:\windows\system32\avaxrc.exe
Do a search for the following files and delete any instances found:
Systb.dll
Winobject.dll
Winserv.exe
Wupdt.exe
If any of files cannot be deleted in normal mode, try Safe Mode.
Configure your email server to block or remove email that contains file attachments that are commonly used to spread viruses, such as .vbs, .bat, .exe, .pif and .scr files.
Empty your Recycle Bin and reboot.
Close any open browser windows, scan with HJT, and post a new log please.
Please follow the recommendations in these threads to help protect and start the cleanup process of your system:
http://www.daniweb.com/techtalkforums/thread27519.html
http://www.daniweb.com/techtalkforums/thread27570.html
Then close any open broswer windows, scan with hijackthis, and post a new log and wait for instructions on removing anything else remaining.
When you post your new HJT log, please paste the entire log. Your last one was missing the header info (Operating System, date scanned, etc.).
The recommendations here should resolve the problem with System Volume Information:
http://www.daniweb.com/techtalkforums/thread13362.html
You should have A0059569.exe scanned here:
Yes, you should go ahead and delete it; I doubt if there is anything in that .dll that your system will want :)
Glad to hear it; thanks for letting us know.
You will need to disconnect from the internet so you may wish to print these instructions.
Download Ewido Security Suite from here:
http://fileforum.betanews.com/detail/ewido_security_suite/1098736486/1
Install and update it, and then close the program (don't scan yet).
Download Nailfix from here:
http://www.noidea.us/easyfile/file.php?download=20050515010747824
Unzip it to your desktop, but do not run it yet.
Remove Newdotnet either from Add/Remove Programs, or by following the instructions here:
http://www.newdotnet.com/removal.html
Also in Add/Remove Programs, remove quickbar, if present.
Download, install, update, and run these tools:
CWShredder -- http://www.intermute.com/spysubtract/cwshredder_download.html
about:Buster -- http://www.majorgeeks.com/download4289.html
HSRemove -- http://www.majorgeeks.com/download4286.html
PurityScan uninstaller -- http://www.purityscan.com/uninstall.html
Disconnect from the net and reboot into Safe Mode.
Double-click on the Nailfix.cmd that is on your desktop. Your desktop and icons will disappear and reappear, and a window should open and close very quickly -- this is normal.
Then run a full system scan with Ewido (note: you will be posting the log from this scan in your next reply).
Still in Safe Mode, scan with hijackthis and have it fix the following entries:
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://approvedlinks.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Quick! - {4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} - C:\PROGRA~1\quickbar\quickbar.dll
O3 - Toolbar: …
I'll let DMR finish this up; I just have a couple of things to throw in here...
There's some info on protecting your computer in this thread:
http://www.daniweb.com/techtalkforums/thread27519.html
And see if this will help with that file you're trying to get rid of:
Download, install, and update CWShredder 2.15 --http://www.intermute.com/products/cwshredder.html. Run it, and press Fix (not scan). Close any open windows, other then CWS, before hitting the Fix button.
First you should have the file scanned here:
If it comes up clean, you can try to get some info on it by going to the file and right-clicking on it. Then go to Properties and get whatever info you can (Company, Version, etc.). After that, right-click on it again, and chose Open With...; you may get a warning message, if you do, click on the Open With... button. Choose Notepad (or Wordpad) to open it with. Most likely you will just see a bunch of gibberish characters, but keep looking through it -- sometimes some tell-tale information is provided.
Let us know what you find out :)
Hi Jessykah, welcome to DaniWeb :D
Yes, it's okay to 'bump' but please wait a bit longer before doing so. I realize you'r anxious to get your computer fixed, but there are only a few of us here trying to resolve dozens of users problems, and we can't be here all the time. I'd say that if you don't get a response within 24 hrs to go ahead and give it a bump to make sure it isn't being overlooked.
Please follow the recommendations in these threads to help protect and start the cleanup process of your system:
http://www.daniweb.com/techtalkforums/thread27519.html
http://www.daniweb.com/techtalkforums/thread27570.html
Then close any open broswer windows, scan with hijackthis, and post a new log and wait for instructions on removing the Aurora infection and anything else remaining.
Go to each of these highlighted files and right-click on it; go to properties and give us whatever info you can on them (Company, version, etc.) in your next post:
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDll32.exe
Go to Start, Run, type regedit in the box, and hit Enter.
At the top of the Registry Editor window, click on File, and then Export. In the Export range panel (at the bottom), click All, give the file a name, and then Save your registry as a backup to a location where you will be able to locate it easily if necessary.
Then click on Edit, Find; in the box, type or paste SideFind, and then click on Find Next
Right-click on any entries found and click on Delete.
Continue using the Find Next option until you get the Finished searching through registry message.
Close the Registry Editor.
Speaking of which- I know that definitely meant that I was up too late, but does it also mean that you got up at some unholy early hour just to sneak in a few posts here before work? :cheesy:
No, I did it during my lunch break while at work, that's why they were so short -- I saw how far behind we were and wanted get as many answered as I could.
Before posting a new log, please follow the suggestions in these threads:
Check here first to see if it offers any assistance:
http://forum.grisoft.cz/freeforum/read.php?4,23563,23585
Then follow the recommendations here to help prevent future infections:
http://www.daniweb.com/techtalkforums/thread27519.html
After that, follow the instructions here (this will clean up some of your problems, but not all):
http://www.daniweb.com/techtalkforums/thread27570.html
Close any open browser windows, scan with HJT, and post a new log please.
I can't help with this, just giving it a 'bump' so DMR doesn't overlook it :)
(I know how much he needs more to do)
Dave, I deleted my post because yours had more info included, mine was just links to similar info. :)
I saw your name reviewing this thread just as I hit the Post button.
Follow the suggestions in these threads:
http://www.daniweb.com/techtalkforums/thread27519.html
http://www.daniweb.com/techtalkforums/thread27570.html
Then, right-click in an open area of your desktop, select New, Folder; give the new folder a name (something like HJT or HijackThis), and drag the hijackthis.exe icon that is on your desktop into the new folder.
Close any open browser windows, scan with HJT, and post a new log please.
norton does create some of the weirdest problems i've ever seen.
That's one of the reasons I suggested replacing it :)
Glad you got it figured out!
You should first follow the recommendations in this thread on the problem computer to help prevent further occurrences:
http://www.daniweb.com/techtalkforums/thread27519.html
Try uninstalling Norton, and then reinstalling it (or consider replacing it :) )
Note: Hijackthis should be in it's own folder, like G:\programs\Hijackthis\HijackThis.exe (instead of G:\programs\HijackThis.exe)
Spybot and Adaware come up clean, but downloaded and ran "Adware Spy" today and it presented me with over 400 registry items mainly in Local Machine, IE, ActiveX Compatibility, that read like a who's who of every malware signature ever invented. Couldn't use it to fix the issues though as you have to buy before they do that.. And I was a little suspicous that such a huge number had bypassed the other adware checkers.. Not sure if it's just a sales gimmick?
It is most likely a gimmick; Adware Spy is identified as 'Rogue/suspect antispyware' here:
http://www.spywarewarrior.com/rogue_anti-spyware.htm
Where you can find this statement regarding Adware Spy (and other products in this 'family'):
"... the dubious distinction of generating the most false positives on a "spyware free" system -- flagging hundreds of items as "spyware," including completely legitimate programs like Nero, Adobe Acrobat, and AdShield, among others."
You might want to give these a try:
CounterSpy (http://www.download.com/3000-8022_4-10337358.html)
Ewido Security Suite (http://www.download.com/Ewido-Security-Suite/3000-8022_4-10326287.html?tag=lst-0-1)
And if that doesn't clean it up, download and run Silent Runners.vbs -- http://www.silentrunners.org/.
Post the information from the log it generates in this thread.
Yes i did system restore 3 weeks ago as soon as this thing appeared again. The system restore was successful but it made no difference. Do you think that repair would fix it? & if so, why do you think folk do a full format when there is a repair option on the windows disk that come with PC's.
Other than that, have you ant more ideas?
I don't know if the repair will correct your problem because I don't know what the problem is.
Many people, I believe, do a full format because they don't know the Repair option exists, or they don't know how to use it. Also, as far as I know, the Repair will not remove any malware, it will only fix and replace corrupted and missing Windows files.
I do have one other suggestion, but since I don't know a lot about it, I can only get you started, and then turn this over to one of our other members who is more familiar with it.
Please do the following:
Open the Event Viewer utility in your Administrative Tools control panel.
In the Event Viewer, look through the System and Application logs for entries flagged as Warning or Error; double-clicking on any of those entries will open a "details" window with more information about the error/warning. If you find any entries that seem to relate to program hangs/crashes or anything else related to the problems you're having, post the full …
Glad you posted that other hijackthis log, the first one scared me!
Go to Add/Remove Programs in your Control Panel and remove (if present):
Viewpoint (may be called Viewpoint Manager, ViewMgr or something similar)
Scan with hijackthis and have it fix the following entries:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
Close any open windows and hit Fix checked.
Go to C:\Program Files and delete the Viewpoint folder.
For every User listed under C:\Documents and Settings, delete the entire contents of these folders (not the folders themselves):
Local Settings\Temp
Cookies
History
Local Settings\Temporary Internet Files\Content.IE5
Delete the entire contents of your C:\Windows\Temp folder.
Delete the entire contents of your C:\Temp folder (if you have one).
Do a search for *.tmp and delete all entries found.
Open Firefox, go to Tools, Options, and click on Privacy (padlock icon on the left); click on the Clear All button.
Go to Start, Run, and type in cleanmgr, and then click OK. Select the drive XP is on, and check the boxes for Downloaded Program Files (move any files you wish to keep out of this folder first), Temporary Internet Files, Recycle Bin, …
Just wondering, there is a 'repair' option on the windows disk. Don't know if i chose that after putting it in the drawer or if you go through bios & boot up with the Windows disk, but could that solve it? & would we lose all our files & settings using this option?
What you are referring to is an in-place upgrade (aka repair installation); instructions can be found here:
http://support.microsoft.com/default.aspx?scid=kb;en-us;315341&Product=winxp
You shouldn't lose any files or setting but, as always, it's best to have everything backed up just in case. It's possible that could resolve your problem without having to reinstall Windows.
However, before you try that, have you tried using System Restore to return your system to a point prior to when you started having this problem? If you do this, you may need to remove the things we just cleaned off again because they could be a part of your restoration.
Hi Rhonda, welcome to DaniWeb :D
You will need to disconnect from the internet so you may wish to print these instructions.
Download Ewido Security Suite from here:
http://fileforum.betanews.com/detail/ewido_security_suite/1098736486/1
Install and update it, and then close the program (don't scan yet).
Download Nailfix from here:
http://www.noidea.us/easyfile/file.php?download=20050515010747824
Unzip it to your desktop, but do not run it yet.
Disconnect from the net and reboot into Safe Mode.
Double-click on the Nailfix.cmd that is on your desktop. Your desktop and icons will disappear and reappear, and a window should open and close very quickly -- this is normal.
Then run a full system scan with Ewido (note: you will be posting the log from this scan when back in normal mode).
Still in Safe Mode, scan with hijackthis and have it fix the following entries:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50249
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50249
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50249
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - …
Thanks DMR, a lot of good info there :)
But unless yikyang mistyped, he doesn't have msdirectx.sys, he has msdiretx.sys; do you know if it's related or if the MS fix will work for it?
Get the Pocket Killbox from here:
http://bleepingcomputer.com/files/spyware/KillBox.zip
Unzip the file to your desktop.
Go offline until this is completed (you may wish to print these instructions).
Boot into Safe Mode and do a search for jiorzm.exe and delete any instances found.
If any could not be deleted, run Pocket Killbox and paste the full file path in the box and click on Delete on Reboot. Click on the button with the red circle and an X in the middle; you will get a message saying File will be deleted on next reboot, Process and Reboot now?, Click Yes to reboot. (Note: the 'file path' will be something like C:\windows\system32\jiorzm.exe or C\windows\prefetch\jiorzm.exe)
Reboot (normally), empty your Recycle Bin and search for the file again to make sure it's gone.
O16 entries are safe to be fixed with hijackthis, they will be removed, but any legit ones will be restored next time you visit the site; it's just easier (and cleans up the log more) if they are all fixed rather then researching each one to seperate the good from the bad.
The easiest way to find out about the O17 entry is to contact your ISP and ask if that IP address is theirs.
Post a new log after the Norton scan and fixing the noted HJT entries :)