Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

DrWatson Postmortem Debugger error[CLOSED]


  • This topic is locked This topic is locked

#1
squeeker

squeeker

    Member

  • Member
  • PipPip
  • 12 posts
;) ok i keep getting this DrWatson Postmortem Debugger error every time i try to open up anything from my start menu. my pics, my music, my docs, control panel...ok you get the point. every time i try and open any of them, my computer freezes then 30 seconds later i get this error message that says "DrWatson Postmortem Debugger" has a problem blah blah blah. i have tried ad-aware, some other anit-spyware programs and an advanced registry optimizer program...and nothings worked. all thats left to do is totally erase everything :tazz: and see if that fixes it. i really dont want to do that. if anyone knows what to do PLEASE help me out.

~Sarah ;)
  • 0

Advertisements


#2
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi squeeker

Let us take a closer look at what is running on your PC. We'll need you to use a free diagnostic tool (HiJackThis) and post a log back here with the results.

Click the HijackThis Guide in my signature, download it and follow the instructions in the guide.

Most of what it lists will be harmless or even essential, DO NOT delete or modify anything yet! Someone will be along to tell you what steps to take after you post the contents of the scan results.

Download the CCleaner unzip the file to install.
Open the ccleaner.
Place a check by everything in the Applications tab.
Place a check by Internet Explorer, Windows explorer, and System in the Windows tab.
Now click on Run Cleaner

Reboot your system.

Please run the following free, online virus scans.
http://www.pandasoft...n_principal.htm
http://housecall.tre.../start_corp.asp
Please post the logs From Panda virus scan and HJT.log we will need them to remove previous infections that have left files on your system.

Kc :tazz:
  • 0

#3
squeeker

squeeker

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
ogfile of HijackThis v1.99.1
Scan saved at 8:12:28 PM, on 4/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ipok32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\ntfl.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Saker\Desktop\HijackThis-1.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {A3F6D56C-AE8E-1964-1EAA-D04BFBEF25A5} - C:\WINDOWS\system32\addtl.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ntfl.exe] C:\WINDOWS\ntfl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\RunOnce: [ipok32.exe] C:\WINDOWS\ipok32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Search - http://bar.mywebsear...earch.html?p=ZB
O9 - Extra button: (no name) - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PopStopper - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by14fd.bay14....es/MsnPUpld.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildt...stx/install.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.c...ropper1_4us.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/...aploader_v6.cab
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\atlzn32.exe (file missing)
  • 0

#4
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi squeeker

Welcome

Please download all items to your desktop first.

Please read through the instructions before you start (you may want to print this out).

Please download and install these programs - don't run them yet!!

Download the CCleaner unzip the file to install.

Please download and unzip
About:Buster to a folder. Inside the folder is a readme file that has instructions on the use of the program.
AboutBuster MUST be updated before you use it.
Start AboutBuster, click the update button, check for update, drag the box to the side and hit download updates, close the box . Don't run it yet.

Please download and install AD-Aware.
Check Here on how setup and use it - please make sure you update it first.

Download and unzip cwsserviceremove to your desktop. use either link below:
cwsserviceremove

cwsserviceremove.zip

Download CW-Shredder at the link below:
CWShredder

Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked.
Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

+++++++++++++++++++++++++++++++++++++++++++++++++

Here's the fix:

Important Step
1. Go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called:


Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I)

When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.

Use Windows add remove program file's ininstall the following:
C:\Program Files\LimeWire
C:\Program Files\MyWebSearch

2. Reboot into Safe Mode: Click here if you don't know how to do this.


3. Press Ctrl+Alt+Delete once -> Click Task Manager -> Click the Processes tab -> Double-click the Image Name column header to alphabetically sort the processes -> Scroll through the list and look for:
C:\WINDOWS\system32\tnano.dll
C:\WINDOWS\system32\addtl.dll
C:\WINDOWS\ntfl.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\WINDOWS\ipok32.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\WINDOWS\system32\atlzn32.exe
If you find the files, click on them, and then click End Process
Exit the Task Manager.

4. CLOSE ALL WINDOWS AND BROWSERS Scan with HijackThis and put checks next to all the following,
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {A3F6D56C-AE8E-1964-1EAA-D04BFBEF25A5} - C:\WINDOWS\system32\addtl.dll
O4 - HKLM\..\Run: [ntfl.exe] C:\WINDOWS\ntfl.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\RunOnce: [ipok32.exe] C:\WINDOWS\ipok32.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O8 - Extra context menu item: &Search - http://bar.mywebsear...earch.html?p=ZB
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\atlzn32.exe (file missing)

Then click on Fix Checked

5. Using Windows Explorer, locate the following files/folders, and delete them: If found
C:\WINDOWS\system32\tnano.dll<--Delete this file
C:\WINDOWS\system32\addtl.dll<--Delete this file
C:\WINDOWS\ntfl.exe<--Delete this file
C:\Program Files\MyWebSearch<--Delete the whole folder
C:\WINDOWS\ipok32.exe<--Delete this file
C:\Program Files\LimeWire<--Delete the whole folder
C:\WINDOWS\system32\atlzn32.exe<--Delete this file
(and any other files with the same name that end in .dll, .exe or .dat, you may find them right next to each other, example - appsw.exe, appsw.dll, appsw.dat)
Exit Explorer.

6. Run AboutBuster . This will scan your computer for the bad files and delete them. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

7. Scan with AdAware and let it remove any bad files found.

8. Clean out temporary and TIF files. Go to Start > Run and type in the box: [b]cleanmgr
. Let it scan your system for files to remove. Make sure all are checked and then press *ok* to remove:

9. Double click on the cwsserviceremove and when asked to merge say yes.

10. Run CW-Shredder - Hit the FIX button - let it run and fix what it finds.

11. Open the ccleaner.
Place a check by everything in the Applications tab.
Place a check by Internet Explorer, Windows explorer, and System in the Windows tab.
Now click on [b]Run Cleaner


Reboot into normal mode.

12. Download the Hoster from here Press "Restore Original Hosts. and press "OK". Exit Program.

Please run the following free, online virus scans.
http://www.pandasoft...n_principal.htm
http://housecall.tre.../start_corp.asp
[b]Please post the logs From Panda virus scan and HJT.log we will need them to remove previous infections that have left files on your system.

Kc :tazz:
  • 0

#5
squeeker

squeeker

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
THANK YOU SOOOOO MUCH!!!!!!!!!!! ;) :tazz:


but........i tryed to run 10. Run CW-Shredder - Hit the FIX button - let it run and fix what it finds. and it didnt work and then i tryed to run 12. Download the Hoster from here Press "Restore Original Hosts. and press "OK". Exit Program. and nothing showed up....what should i do?
  • 0

#6
squeeker

squeeker

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
-- Scan 1 ---------------------------
About:Buster Version 4.0
Reference List : 26


Removed Data Streams:
C:\WINDOWS\crci32.exe:ttdvk
C:\WINDOWS\FaxSetup.log:ufwae
C:\WINDOWS\KB873339.log:wfkvs
C:\WINDOWS\n_hxhjmm.log:tpsxv
C:\WINDOWS\ocgen.log:sesac
C:\WINDOWS\sdkby32.exe:pjzwr
C:\WINDOWS\wmsetup10.log:dkzso
C:\WINDOWS\WMSysPrx.prx:lqjvt


Removed 2 Random Key Entries
Removed! : C:\WINDOWS\apphz32.exe
Removed! : C:\WINDOWS\balxh.dat
Removed! : C:\WINDOWS\crmy32.dll
Removed! : C:\WINDOWS\nppis.dat
Removed! : C:\WINDOWS\sntvp.dat
Removed! : C:\WINDOWS\txrpz.dat
Removed! : C:\WINDOWS\uazdv.dat
Removed! : C:\WINDOWS\yyokb.dat
Removed! : C:\WINDOWS\system32\appnm32.exe
Removed! : C:\WINDOWS\system32\fdino.dat
Removed! : C:\WINDOWS\system32\jnibl.dat
Removed! : C:\WINDOWS\system32\ophvt.dat
Removed! : C:\WINDOWS\system32\uowul.dat
Attempted Clean Of Temp folder.
Pages Reset... Done!

-- Scan 2 ---------------------------
About:Buster Version 4.0
Reference List : 26


Removed Data Streams:
C:\WINDOWS\crci32.exe:ttdvk
C:\WINDOWS\FaxSetup.log:ufwae
C:\WINDOWS\KB873339.log:wfkvs
C:\WINDOWS\n_hxhjmm.log:tpsxv
C:\WINDOWS\ocgen.log:sesac
C:\WINDOWS\sdkby32.exe:pjzwr
C:\WINDOWS\wmsetup10.log:dkzso
C:\WINDOWS\WMSysPrx.prx:lqjvt
  • 0

#7
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi squeeker

Did you run the virus scans we need the logs

Also post a new HJTLog

Kc :tazz:
  • 0

#8
squeeker

squeeker

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
i have mozilla firefox as my browser so the http://www.pandasoft...n_principal.htm dosent work for me.....and the other one....something just dosent work with it. are there any other virus scans i can get?
  • 0

#9
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi squeeker

You did not post a HJT.Log

Download the Microsoft Antispyware
Run Microsoft Antispyware

Download the CCleaner unzip the file to install.
Open CCleaner.
Place a check by everything in the Applications tab.
Place a check by Internet Explorer, Windows explorer, and System in the Windows tab.
Run the ccleaner

Lets see if this will find any hidden Trojan’s http://www.ewido.net/en/download/
Run ewido scanner

This setup contains the free as well as the plus-version of the ewido security suite. After the installation, a free 14-day test version containing all the extensions of the plus-version will be activated. At the end of the test phase, the extensions of the plus version are deactivated and the freeware version can be used unlimited times. The purchased license code of the plus version can be entered at any time.

Now run about buster.

Run CW-Shredder - Hit the FIX button - let it run and fix what it finds.

Post a new HJT.Log

Kc :tazz:
  • 0

#10
squeeker

squeeker

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Incident Status Location

Adware:Adware/SaveNow No disinfected Windows Registry
Adware:Adware/nCase No disinfected C:\WINDOWS\system32\saie_*.dat
Adware:Adware/PortalScan No disinfected C:\WINDOWS\bundles
Adware:Adware/VirtualBouncer No disinfected C:\Documents and Settings\All Users\Application Data\VBouncer
Spyware:Spyware/TVMedia No disinfected C:\WINDOWS\Bundles
Adware:Adware/SideFind No disinfected Windows Registry
Adware:Adware/PowerSearch No disinfected C:\WINDOWS\system32\stlb2.xml
Adware:Adware/SearchRelevancy No disinfected Windows Registry
Spyware:Spyware/Search3 No disinfected C:\Program Files\Search3 Toolbar
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Saker\Favorites\Sites about\Ab scissor.url
Adware:Adware/SearchAid No disinfected C:\Documents and Settings\Saker\Desktop\backups\backup-20050413-201402-652.dll
Virus:VBS/Inor.AF Renamed C:\ntdetect.hta
Adware:Adware/Minibug No disinfected C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll
Adware:Adware/Gator No disinfected C:\Program Files\Common Files\clanteaf\crtrlcepjn\hanhelhnc.exe
Adware:Adware/Gator No disinfected C:\Program Files\Common Files\clanteaf\ejlrnpjd\pcnjepna.exe
Adware:Adware/WUpd No disinfected C:\Program Files\Windows AdStatus\WinStatComm.dll
Adware:Adware/AdLogix No disinfected C:\Program Files\Windows Media Player\wmplayer.exe.tmp
Adware:Adware/SearchAid No disinfected C:\WINDOWS\addcn.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\addkv.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\addte.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\addwy32.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\aobeo.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\apiin.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\apins32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\apinz32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\apitb.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\appft.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\appip32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\appmb32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\apppc.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\apppf32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\atlae.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\atlll32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\atlrh.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\bcnsj.dll
Virus:Trj/Delf.EB Disinfected C:\WINDOWS\bundles\HelperInstaller.exe.tmp
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\crax.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\crci32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\crlx32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\d3bv32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\d3dv.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\d3yt32.exe
Spyware:Spyware/Search3 No disinfected C:\WINDOWS\Downloaded Program Files\search3.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\etsqr.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\iexb.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\ipzr.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\javaso.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\javazw32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\mfcdf32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\mfckw.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\msja.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\mslv32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\msxd.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\msxz32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\netiz32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\netra.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ntcx32.exe
Virus:Trj/Downloader.AQN Disinfected C:\WINDOWS\ntfl.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ntga.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ntus32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sdkby32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sdkef.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sdkmn32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sysci.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\addcn32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\added.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\addth32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apidy.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apihc32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apilp32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\apimn.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apipi.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apivb32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apphn32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\appib32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\appvy32.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\asydj.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\atlqd32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\crkg.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\d3rd.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\d3ue32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\d3vr32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\d3zu.exe
Adware:Adware/DealHelper No disinfected C:\WINDOWS\system32\dun.exe
Adware:Adware/FunWeb No disinfected C:\WINDOWS\system32\f3PSSavr.scr
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\ibeda.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ieck32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\iegl32.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\ikfps.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ipjq.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\iplb.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\javako32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\mfcjz.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\mfcse32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\mfcye32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\msat32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\msgl.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\msyy.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\netew32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\ntdv32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ntlj.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\ntuf.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\olijm.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\phmif.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdkim32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdknk32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdkod32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdkyc.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\spbmh.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sysav.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sysjb.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sysqe32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sysuk32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\winah32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\winis32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\winnm32.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\zcinm.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\zgxdb.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\systu.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sysxb32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\winoi.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\winpa.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\winza32.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\ymtpv.dll
  • 0

Advertisements


#11
squeeker

squeeker

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
^^^^^^^^^^^^^thats the panda scan
  • 0

#12
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi squeeker

I do need to see a Hijackhis scan log, to enable me to run a new fix for you

Kc :tazz:
  • 0

#13
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi squeeker

Download Pocket Killbox and unzip it; save it to your Desktop.

Please read through the instructions before you start (you may want to print this out).

Reboot into Safe Mode: Click here if you don't know how to do this.

Run killbox and click the radio button that says Delete a file on reboot.
Copy and Paste them one at a time into the full path of file to delete box and click the red circle with a white cross in it.
The program will ask you if you want to reboot; say No each time until the last one has been pasted in where upon you should answer Yes.
Let the system reboot.
C:\WINDOWS\system32\saie_*.dat
C:\WINDOWS\bundles
C:\WINDOWS\Bundles
C:\WINDOWS\system32\stlb2.xml
C:\ntdetect.hta
C:\WINDOWS\addcn.exe
C:\WINDOWS\addkv.exe
C:\WINDOWS\addte.exe
C:\WINDOWS\addwy32.exe
C:\WINDOWS\aobeo.dll
C:\WINDOWS\apiin.exe
C:\WINDOWS\apins32.exe
C:\WINDOWS\apinz32.exe
C:\WINDOWS\apitb.exe
C:\WINDOWS\appft.exe
C:\WINDOWS\appip32.exe
C:\WINDOWS\appmb32.exe
C:\WINDOWS\apppc.exe
C:\WINDOWS\apppf32.exe
C:\WINDOWS\atlae.exe
C:\WINDOWS\atlll32.exe
C:\WINDOWS\atlrh.exe
C:\WINDOWS\bcnsj.dll
C:\WINDOWS\bundles\HelperInstaller.exe.tmp
C:\WINDOWS\crax.exe
C:\WINDOWS\crci32.exe
C:\WINDOWS\crlx32.exe
C:\WINDOWS\d3bv32.exe
C:\WINDOWS\d3dv.exe
C:\WINDOWS\d3yt32.exe
C:\WINDOWS\Downloaded Program Files\search3.dll
C:\WINDOWS\etsqr.dll
C:\WINDOWS\iexb.exe
C:\WINDOWS\ipzr.exe
C:\WINDOWS\javaso.exe
C:\WINDOWS\javazw32.exe
C:\WINDOWS\mfcdf32.exe
C:\WINDOWS\mfckw.exe
C:\WINDOWS\msja.exe
C:\WINDOWS\mslv32.exe
C:\WINDOWS\msxd.exe
C:\WINDOWS\msxz32.exe
C:\WINDOWS\netiz32.exe
C:\WINDOWS\netra.exe
C:\WINDOWS\ntcx32.exe
C:\WINDOWS\ntfl.exe
C:\WINDOWS\ntga.exe
C:\WINDOWS\ntus32.exe
C:\WINDOWS\sdkby32.exe
C:\WINDOWS\sdkef.exe
C:\WINDOWS\sdkmn32.exe
C:\WINDOWS\sysci.exe
C:\WINDOWS\system32\addcn32.exe
C:\WINDOWS\system32\added.exe
C:\WINDOWS\system32\addth32.exe
C:\WINDOWS\system32\apidy.exe
C:\WINDOWS\system32\apihc32.exe
C:\WINDOWS\system32\apilp32.exe
C:\WINDOWS\system32\apimn.exe
C:\WINDOWS\system32\apipi.exe
C:\WINDOWS\system32\apivb32.exe
C:\WINDOWS\system32\apphn32.exe
C:\WINDOWS\system32\appib32.exe
C:\WINDOWS\system32\appvy32.exe
C:\WINDOWS\system32\asydj.dll
C:\WINDOWS\system32\atlqd32.exe
C:\WINDOWS\system32\crkg.exe
C:\WINDOWS\system32\d3rd.exe
C:\WINDOWS\system32\d3ue32.exe
C:\WINDOWS\system32\d3vr32.exe
C:\WINDOWS\system32\d3zu.exe
C:\WINDOWS\system32\dun.exe
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\system32\ibeda.dll
C:\WINDOWS\system32\ieck32.exe
C:\WINDOWS\system32\iegl32.exe
C:\WINDOWS\system32\ikfps.dll
C:\WINDOWS\system32\ipjq.exe
C:\WINDOWS\system32\iplb.exe
C:\WINDOWS\system32\javako32.exe
C:\WINDOWS\system32\mfcjz.exe
C:\WINDOWS\system32\mfcse32.exe
C:\WINDOWS\system32\mfcye32.exe
C:\WINDOWS\system32\msat32.exe
C:\WINDOWS\system32\msgl.exe
C:\WINDOWS\system32\msyy.exe
C:\WINDOWS\system32\netew32.exe
C:\WINDOWS\system32\ntdv32.exe
C:\WINDOWS\system32\ntlj.exe
C:\WINDOWS\system32\ntuf.exe
C:\WINDOWS\system32\olijm.dll
C:\WINDOWS\system32\phmif.dll
C:\WINDOWS\system32\sdkim32.exe
C:\WINDOWS\system32\sdknk32.exe
C:\WINDOWS\system32\sdkod32.exe
C:\WINDOWS\system32\sdkyc.exe
C:\WINDOWS\system32\spbmh.dll
C:\WINDOWS\system32\sysav.exe
C:\WINDOWS\system32\sysjb.exe
C:\WINDOWS\system32\sysqe32.exe
C:\WINDOWS\system32\sysuk32.exe
C:\WINDOWS\system32\winah32.exe
C:\WINDOWS\system32\winis32.exe
C:\WINDOWS\system32\winnm32.exe
C:\WINDOWS\system32\zcinm.dll
C:\WINDOWS\system32\zgxdb.dll
C:\WINDOWS\systu.exe
C:\WINDOWS\sysxb32.exe
C:\WINDOWS\winoi.exe
C:\WINDOWS\winpa.exe
C:\WINDOWS\winza32.exe
C:\WINDOWS\ymtpv.dll

End of killbox file's

Reboot into normal mode.

Post a new Panda.log and new HJT.Log

Kc :tazz:
  • 0

#14
squeeker

squeeker

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Incident Status Location

Adware:Adware/SaveNow No disinfected Windows Registry
Adware:Adware/nCase No disinfected C:\WINDOWS\system32\saie_*.dat
Adware:Adware/PortalScan No disinfected C:\WINDOWS\system32\winupdt.bin
Adware:Adware/VirtualBouncer No disinfected C:\Documents and Settings\All Users\Application Data\VBouncer
Adware:Adware/SideFind No disinfected Windows Registry
Spyware:Spyware/Search3 No disinfected C:\Program Files\Search3 Toolbar
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Saker\Favorites\Sites about\Ab scissor.url
Adware:Adware/SearchAid No disinfected C:\Documents and Settings\Saker\Desktop\backups\backup-20050413-201402-652.dll
Virus:VBS/Inor.AF Renamed C:\ntdetect_hta.vir
Adware:Adware/Minibug No disinfected C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll
Adware:Adware/Gator No disinfected C:\Program Files\Common Files\clanteaf\crtrlcepjn\hanhelhnc.exe
Adware:Adware/Gator No disinfected C:\Program Files\Common Files\clanteaf\ejlrnpjd\pcnjepna.exe
Adware:Adware/WUpd No disinfected C:\Program Files\Windows AdStatus\WinStatComm.dll
Adware:Adware/AdLogix No disinfected C:\Program Files\Windows Media Player\wmplayer.exe.tmp
  • 0

#15
squeeker

squeeker

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Logfile of HijackThis v1.99.1
Scan saved at 7:19:55 PM, on 4/18/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\Documents and Settings\Saker\Desktop\HijackThis-1.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP