~Sarah
DrWatson Postmortem Debugger error[CLOSED]
Started by
squeeker
, Apr 07 2005 07:16 PM
#1
Posted 07 April 2005 - 07:16 PM
~Sarah
#2
Guest_thatman_*
Posted 13 April 2005 - 05:10 AM
Hi squeeker
Let us take a closer look at what is running on your PC. We'll need you to use a free diagnostic tool (HiJackThis) and post a log back here with the results.
Click the HijackThis Guide in my signature, download it and follow the instructions in the guide.
Most of what it lists will be harmless or even essential, DO NOT delete or modify anything yet! Someone will be along to tell you what steps to take after you post the contents of the scan results.
Download the CCleaner unzip the file to install.
Open the ccleaner.
Place a check by everything in the Applications tab.
Place a check by Internet Explorer, Windows explorer, and System in the Windows tab.
Now click on Run Cleaner
Reboot your system.
Please run the following free, online virus scans.
http://www.pandasoft...n_principal.htm
http://housecall.tre.../start_corp.asp
Please post the logs From Panda virus scan and HJT.log we will need them to remove previous infections that have left files on your system.
Kc
Let us take a closer look at what is running on your PC. We'll need you to use a free diagnostic tool (HiJackThis) and post a log back here with the results.
Click the HijackThis Guide in my signature, download it and follow the instructions in the guide.
Most of what it lists will be harmless or even essential, DO NOT delete or modify anything yet! Someone will be along to tell you what steps to take after you post the contents of the scan results.
Download the CCleaner unzip the file to install.
Open the ccleaner.
Place a check by everything in the Applications tab.
Place a check by Internet Explorer, Windows explorer, and System in the Windows tab.
Now click on Run Cleaner
Reboot your system.
Please run the following free, online virus scans.
http://www.pandasoft...n_principal.htm
http://housecall.tre.../start_corp.asp
Please post the logs From Panda virus scan and HJT.log we will need them to remove previous infections that have left files on your system.
Kc
#3
Posted 13 April 2005 - 07:17 PM
ogfile of HijackThis v1.99.1
Scan saved at 8:12:28 PM, on 4/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ipok32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\ntfl.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Saker\Desktop\HijackThis-1.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {A3F6D56C-AE8E-1964-1EAA-D04BFBEF25A5} - C:\WINDOWS\system32\addtl.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ntfl.exe] C:\WINDOWS\ntfl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\RunOnce: [ipok32.exe] C:\WINDOWS\ipok32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Search - http://bar.mywebsear...earch.html?p=ZB
O9 - Extra button: (no name) - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PopStopper - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by14fd.bay14....es/MsnPUpld.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildt...stx/install.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.c...ropper1_4us.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/...aploader_v6.cab
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\atlzn32.exe (file missing)
Scan saved at 8:12:28 PM, on 4/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ipok32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\ntfl.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Saker\Desktop\HijackThis-1.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {A3F6D56C-AE8E-1964-1EAA-D04BFBEF25A5} - C:\WINDOWS\system32\addtl.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ntfl.exe] C:\WINDOWS\ntfl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\RunOnce: [ipok32.exe] C:\WINDOWS\ipok32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Search - http://bar.mywebsear...earch.html?p=ZB
O9 - Extra button: (no name) - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PopStopper - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by14fd.bay14....es/MsnPUpld.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildt...stx/install.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.c...ropper1_4us.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/...aploader_v6.cab
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\atlzn32.exe (file missing)
#4
Guest_thatman_*
Posted 14 April 2005 - 04:12 AM
Hi squeeker
Welcome
Please download all items to your desktop first.
Please read through the instructions before you start (you may want to print this out).
Please download and install these programs - don't run them yet!!
Download the CCleaner unzip the file to install.
Please download and unzip
About:Buster to a folder. Inside the folder is a readme file that has instructions on the use of the program.
AboutBuster MUST be updated before you use it.
Start AboutBuster, click the update button, check for update, drag the box to the side and hit download updates, close the box . Don't run it yet.
Please download and install AD-Aware.
Check Here on how setup and use it - please make sure you update it first.
Download and unzip cwsserviceremove to your desktop. use either link below:
cwsserviceremove
cwsserviceremove.zip
Download CW-Shredder at the link below:
CWShredder
Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked.
Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"
+++++++++++++++++++++++++++++++++++++++++++++++++
Here's the fix:
Important Step
1. Go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called:
Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I)
When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.
Use Windows add remove program file's ininstall the following:
C:\Program Files\LimeWire
C:\Program Files\MyWebSearch
2. Reboot into Safe Mode: Click here if you don't know how to do this.
3. Press Ctrl+Alt+Delete once -> Click Task Manager -> Click the Processes tab -> Double-click the Image Name column header to alphabetically sort the processes -> Scroll through the list and look for:
C:\WINDOWS\system32\tnano.dll
C:\WINDOWS\system32\addtl.dll
C:\WINDOWS\ntfl.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\WINDOWS\ipok32.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\WINDOWS\system32\atlzn32.exe
If you find the files, click on them, and then click End Process
Exit the Task Manager.
4. CLOSE ALL WINDOWS AND BROWSERS Scan with HijackThis and put checks next to all the following,
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {A3F6D56C-AE8E-1964-1EAA-D04BFBEF25A5} - C:\WINDOWS\system32\addtl.dll
O4 - HKLM\..\Run: [ntfl.exe] C:\WINDOWS\ntfl.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\RunOnce: [ipok32.exe] C:\WINDOWS\ipok32.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O8 - Extra context menu item: &Search - http://bar.mywebsear...earch.html?p=ZB
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\atlzn32.exe (file missing)
Then click on Fix Checked
5. Using Windows Explorer, locate the following files/folders, and delete them: If found
C:\WINDOWS\system32\tnano.dll<--Delete this file
C:\WINDOWS\system32\addtl.dll<--Delete this file
C:\WINDOWS\ntfl.exe<--Delete this file
C:\Program Files\MyWebSearch<--Delete the whole folder
C:\WINDOWS\ipok32.exe<--Delete this file
C:\Program Files\LimeWire<--Delete the whole folder
C:\WINDOWS\system32\atlzn32.exe<--Delete this file
(and any other files with the same name that end in .dll, .exe or .dat, you may find them right next to each other, example - appsw.exe, appsw.dll, appsw.dat)
Exit Explorer.
6. Run AboutBuster . This will scan your computer for the bad files and delete them. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.
7. Scan with AdAware and let it remove any bad files found.
8. Clean out temporary and TIF files. Go to Start > Run and type in the box: [b]cleanmgr. Let it scan your system for files to remove. Make sure all are checked and then press *ok* to remove:
9. Double click on the cwsserviceremove and when asked to merge say yes.
10. Run CW-Shredder - Hit the FIX button - let it run and fix what it finds.
11. Open the ccleaner.
Place a check by everything in the Applications tab.
Place a check by Internet Explorer, Windows explorer, and System in the Windows tab.
Now click on [b]Run Cleaner
Reboot into normal mode.
12. Download the Hoster from here Press "Restore Original Hosts. and press "OK". Exit Program.
Please run the following free, online virus scans.
http://www.pandasoft...n_principal.htm
http://housecall.tre.../start_corp.asp
[b]Please post the logs From Panda virus scan and HJT.log we will need them to remove previous infections that have left files on your system.
Kc
Welcome
Please download all items to your desktop first.
Please read through the instructions before you start (you may want to print this out).
Please download and install these programs - don't run them yet!!
Download the CCleaner unzip the file to install.
Please download and unzip
About:Buster to a folder. Inside the folder is a readme file that has instructions on the use of the program.
AboutBuster MUST be updated before you use it.
Start AboutBuster, click the update button, check for update, drag the box to the side and hit download updates, close the box . Don't run it yet.
Please download and install AD-Aware.
Check Here on how setup and use it - please make sure you update it first.
Download and unzip cwsserviceremove to your desktop. use either link below:
cwsserviceremove
cwsserviceremove.zip
Download CW-Shredder at the link below:
CWShredder
Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked.
Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"
+++++++++++++++++++++++++++++++++++++++++++++++++
Here's the fix:
Important Step
1. Go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called:
Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I)
When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.
Use Windows add remove program file's ininstall the following:
C:\Program Files\LimeWire
C:\Program Files\MyWebSearch
2. Reboot into Safe Mode: Click here if you don't know how to do this.
3. Press Ctrl+Alt+Delete once -> Click Task Manager -> Click the Processes tab -> Double-click the Image Name column header to alphabetically sort the processes -> Scroll through the list and look for:
C:\WINDOWS\system32\tnano.dll
C:\WINDOWS\system32\addtl.dll
C:\WINDOWS\ntfl.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\WINDOWS\ipok32.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\WINDOWS\system32\atlzn32.exe
If you find the files, click on them, and then click End Process
Exit the Task Manager.
4. CLOSE ALL WINDOWS AND BROWSERS Scan with HijackThis and put checks next to all the following,
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\tnano.dll/sp.html#28129
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {A3F6D56C-AE8E-1964-1EAA-D04BFBEF25A5} - C:\WINDOWS\system32\addtl.dll
O4 - HKLM\..\Run: [ntfl.exe] C:\WINDOWS\ntfl.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\RunOnce: [ipok32.exe] C:\WINDOWS\ipok32.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O8 - Extra context menu item: &Search - http://bar.mywebsear...earch.html?p=ZB
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\atlzn32.exe (file missing)
Then click on Fix Checked
5. Using Windows Explorer, locate the following files/folders, and delete them: If found
C:\WINDOWS\system32\tnano.dll<--Delete this file
C:\WINDOWS\system32\addtl.dll<--Delete this file
C:\WINDOWS\ntfl.exe<--Delete this file
C:\Program Files\MyWebSearch<--Delete the whole folder
C:\WINDOWS\ipok32.exe<--Delete this file
C:\Program Files\LimeWire<--Delete the whole folder
C:\WINDOWS\system32\atlzn32.exe<--Delete this file
(and any other files with the same name that end in .dll, .exe or .dat, you may find them right next to each other, example - appsw.exe, appsw.dll, appsw.dat)
Exit Explorer.
6. Run AboutBuster . This will scan your computer for the bad files and delete them. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.
7. Scan with AdAware and let it remove any bad files found.
8. Clean out temporary and TIF files. Go to Start > Run and type in the box: [b]cleanmgr. Let it scan your system for files to remove. Make sure all are checked and then press *ok* to remove:
9. Double click on the cwsserviceremove and when asked to merge say yes.
10. Run CW-Shredder - Hit the FIX button - let it run and fix what it finds.
11. Open the ccleaner.
Place a check by everything in the Applications tab.
Place a check by Internet Explorer, Windows explorer, and System in the Windows tab.
Now click on [b]Run Cleaner
Reboot into normal mode.
12. Download the Hoster from here Press "Restore Original Hosts. and press "OK". Exit Program.
Please run the following free, online virus scans.
http://www.pandasoft...n_principal.htm
http://housecall.tre.../start_corp.asp
[b]Please post the logs From Panda virus scan and HJT.log we will need them to remove previous infections that have left files on your system.
Kc
#5
Posted 15 April 2005 - 09:22 PM
THANK YOU SOOOOO MUCH!!!!!!!!!!!
but........i tryed to run 10. Run CW-Shredder - Hit the FIX button - let it run and fix what it finds. and it didnt work and then i tryed to run 12. Download the Hoster from here Press "Restore Original Hosts. and press "OK". Exit Program. and nothing showed up....what should i do?
but........i tryed to run 10. Run CW-Shredder - Hit the FIX button - let it run and fix what it finds. and it didnt work and then i tryed to run 12. Download the Hoster from here Press "Restore Original Hosts. and press "OK". Exit Program. and nothing showed up....what should i do?
#6
Posted 15 April 2005 - 09:23 PM
-- Scan 1 ---------------------------
About:Buster Version 4.0
Reference List : 26
Removed Data Streams:
C:\WINDOWS\crci32.exe:ttdvk
C:\WINDOWS\FaxSetup.log:ufwae
C:\WINDOWS\KB873339.log:wfkvs
C:\WINDOWS\n_hxhjmm.log:tpsxv
C:\WINDOWS\ocgen.log:sesac
C:\WINDOWS\sdkby32.exe:pjzwr
C:\WINDOWS\wmsetup10.log:dkzso
C:\WINDOWS\WMSysPrx.prx:lqjvt
Removed 2 Random Key Entries
Removed! : C:\WINDOWS\apphz32.exe
Removed! : C:\WINDOWS\balxh.dat
Removed! : C:\WINDOWS\crmy32.dll
Removed! : C:\WINDOWS\nppis.dat
Removed! : C:\WINDOWS\sntvp.dat
Removed! : C:\WINDOWS\txrpz.dat
Removed! : C:\WINDOWS\uazdv.dat
Removed! : C:\WINDOWS\yyokb.dat
Removed! : C:\WINDOWS\system32\appnm32.exe
Removed! : C:\WINDOWS\system32\fdino.dat
Removed! : C:\WINDOWS\system32\jnibl.dat
Removed! : C:\WINDOWS\system32\ophvt.dat
Removed! : C:\WINDOWS\system32\uowul.dat
Attempted Clean Of Temp folder.
Pages Reset... Done!
-- Scan 2 ---------------------------
About:Buster Version 4.0
Reference List : 26
Removed Data Streams:
C:\WINDOWS\crci32.exe:ttdvk
C:\WINDOWS\FaxSetup.log:ufwae
C:\WINDOWS\KB873339.log:wfkvs
C:\WINDOWS\n_hxhjmm.log:tpsxv
C:\WINDOWS\ocgen.log:sesac
C:\WINDOWS\sdkby32.exe:pjzwr
C:\WINDOWS\wmsetup10.log:dkzso
C:\WINDOWS\WMSysPrx.prx:lqjvt
About:Buster Version 4.0
Reference List : 26
Removed Data Streams:
C:\WINDOWS\crci32.exe:ttdvk
C:\WINDOWS\FaxSetup.log:ufwae
C:\WINDOWS\KB873339.log:wfkvs
C:\WINDOWS\n_hxhjmm.log:tpsxv
C:\WINDOWS\ocgen.log:sesac
C:\WINDOWS\sdkby32.exe:pjzwr
C:\WINDOWS\wmsetup10.log:dkzso
C:\WINDOWS\WMSysPrx.prx:lqjvt
Removed 2 Random Key Entries
Removed! : C:\WINDOWS\apphz32.exe
Removed! : C:\WINDOWS\balxh.dat
Removed! : C:\WINDOWS\crmy32.dll
Removed! : C:\WINDOWS\nppis.dat
Removed! : C:\WINDOWS\sntvp.dat
Removed! : C:\WINDOWS\txrpz.dat
Removed! : C:\WINDOWS\uazdv.dat
Removed! : C:\WINDOWS\yyokb.dat
Removed! : C:\WINDOWS\system32\appnm32.exe
Removed! : C:\WINDOWS\system32\fdino.dat
Removed! : C:\WINDOWS\system32\jnibl.dat
Removed! : C:\WINDOWS\system32\ophvt.dat
Removed! : C:\WINDOWS\system32\uowul.dat
Attempted Clean Of Temp folder.
Pages Reset... Done!
-- Scan 2 ---------------------------
About:Buster Version 4.0
Reference List : 26
Removed Data Streams:
C:\WINDOWS\crci32.exe:ttdvk
C:\WINDOWS\FaxSetup.log:ufwae
C:\WINDOWS\KB873339.log:wfkvs
C:\WINDOWS\n_hxhjmm.log:tpsxv
C:\WINDOWS\ocgen.log:sesac
C:\WINDOWS\sdkby32.exe:pjzwr
C:\WINDOWS\wmsetup10.log:dkzso
C:\WINDOWS\WMSysPrx.prx:lqjvt
#7
Guest_thatman_*
Posted 16 April 2005 - 03:51 AM
Hi squeeker
Did you run the virus scans we need the logs
Also post a new HJTLog
Kc
Did you run the virus scans we need the logs
Also post a new HJTLog
Kc
#8
Posted 16 April 2005 - 07:19 PM
i have mozilla firefox as my browser so the http://www.pandasoft...n_principal.htm dosent work for me.....and the other one....something just dosent work with it. are there any other virus scans i can get?
#9
Guest_thatman_*
Posted 16 April 2005 - 11:12 PM
Hi squeeker
You did not post a HJT.Log
Download the Microsoft Antispyware
Run Microsoft Antispyware
Download the CCleaner unzip the file to install.
Open CCleaner.
Place a check by everything in the Applications tab.
Place a check by Internet Explorer, Windows explorer, and System in the Windows tab.
Run the ccleaner
Lets see if this will find any hidden Trojan’s http://www.ewido.net/en/download/
Run ewido scanner
This setup contains the free as well as the plus-version of the ewido security suite. After the installation, a free 14-day test version containing all the extensions of the plus-version will be activated. At the end of the test phase, the extensions of the plus version are deactivated and the freeware version can be used unlimited times. The purchased license code of the plus version can be entered at any time.
Now run about buster.
Run CW-Shredder - Hit the FIX button - let it run and fix what it finds.
Post a new HJT.Log
Kc
You did not post a HJT.Log
Download the Microsoft Antispyware
Run Microsoft Antispyware
Download the CCleaner unzip the file to install.
Open CCleaner.
Place a check by everything in the Applications tab.
Place a check by Internet Explorer, Windows explorer, and System in the Windows tab.
Run the ccleaner
Lets see if this will find any hidden Trojan’s http://www.ewido.net/en/download/
Run ewido scanner
This setup contains the free as well as the plus-version of the ewido security suite. After the installation, a free 14-day test version containing all the extensions of the plus-version will be activated. At the end of the test phase, the extensions of the plus version are deactivated and the freeware version can be used unlimited times. The purchased license code of the plus version can be entered at any time.
Now run about buster.
Run CW-Shredder - Hit the FIX button - let it run and fix what it finds.
Post a new HJT.Log
Kc
#10
Posted 16 April 2005 - 11:26 PM
Incident Status Location
Adware:Adware/SaveNow No disinfected Windows Registry
Adware:Adware/nCase No disinfected C:\WINDOWS\system32\saie_*.dat
Adware:Adware/PortalScan No disinfected C:\WINDOWS\bundles
Adware:Adware/VirtualBouncer No disinfected C:\Documents and Settings\All Users\Application Data\VBouncer
Spyware:Spyware/TVMedia No disinfected C:\WINDOWS\Bundles
Adware:Adware/SideFind No disinfected Windows Registry
Adware:Adware/PowerSearch No disinfected C:\WINDOWS\system32\stlb2.xml
Adware:Adware/SearchRelevancy No disinfected Windows Registry
Spyware:Spyware/Search3 No disinfected C:\Program Files\Search3 Toolbar
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Saker\Favorites\Sites about\Ab scissor.url
Adware:Adware/SearchAid No disinfected C:\Documents and Settings\Saker\Desktop\backups\backup-20050413-201402-652.dll
Virus:VBS/Inor.AF Renamed C:\ntdetect.hta
Adware:Adware/Minibug No disinfected C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll
Adware:Adware/Gator No disinfected C:\Program Files\Common Files\clanteaf\crtrlcepjn\hanhelhnc.exe
Adware:Adware/Gator No disinfected C:\Program Files\Common Files\clanteaf\ejlrnpjd\pcnjepna.exe
Adware:Adware/WUpd No disinfected C:\Program Files\Windows AdStatus\WinStatComm.dll
Adware:Adware/AdLogix No disinfected C:\Program Files\Windows Media Player\wmplayer.exe.tmp
Adware:Adware/SearchAid No disinfected C:\WINDOWS\addcn.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\addkv.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\addte.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\addwy32.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\aobeo.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\apiin.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\apins32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\apinz32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\apitb.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\appft.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\appip32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\appmb32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\apppc.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\apppf32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\atlae.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\atlll32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\atlrh.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\bcnsj.dll
Virus:Trj/Delf.EB Disinfected C:\WINDOWS\bundles\HelperInstaller.exe.tmp
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\crax.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\crci32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\crlx32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\d3bv32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\d3dv.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\d3yt32.exe
Spyware:Spyware/Search3 No disinfected C:\WINDOWS\Downloaded Program Files\search3.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\etsqr.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\iexb.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\ipzr.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\javaso.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\javazw32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\mfcdf32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\mfckw.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\msja.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\mslv32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\msxd.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\msxz32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\netiz32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\netra.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ntcx32.exe
Virus:Trj/Downloader.AQN Disinfected C:\WINDOWS\ntfl.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ntga.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ntus32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sdkby32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sdkef.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sdkmn32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sysci.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\addcn32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\added.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\addth32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apidy.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apihc32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apilp32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\apimn.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apipi.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apivb32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apphn32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\appib32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\appvy32.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\asydj.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\atlqd32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\crkg.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\d3rd.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\d3ue32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\d3vr32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\d3zu.exe
Adware:Adware/DealHelper No disinfected C:\WINDOWS\system32\dun.exe
Adware:Adware/FunWeb No disinfected C:\WINDOWS\system32\f3PSSavr.scr
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\ibeda.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ieck32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\iegl32.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\ikfps.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ipjq.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\iplb.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\javako32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\mfcjz.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\mfcse32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\mfcye32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\msat32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\msgl.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\msyy.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\netew32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\ntdv32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ntlj.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\ntuf.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\olijm.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\phmif.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdkim32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdknk32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdkod32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdkyc.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\spbmh.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sysav.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sysjb.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sysqe32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sysuk32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\winah32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\winis32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\winnm32.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\zcinm.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\zgxdb.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\systu.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sysxb32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\winoi.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\winpa.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\winza32.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\ymtpv.dll
Adware:Adware/SaveNow No disinfected Windows Registry
Adware:Adware/nCase No disinfected C:\WINDOWS\system32\saie_*.dat
Adware:Adware/PortalScan No disinfected C:\WINDOWS\bundles
Adware:Adware/VirtualBouncer No disinfected C:\Documents and Settings\All Users\Application Data\VBouncer
Spyware:Spyware/TVMedia No disinfected C:\WINDOWS\Bundles
Adware:Adware/SideFind No disinfected Windows Registry
Adware:Adware/PowerSearch No disinfected C:\WINDOWS\system32\stlb2.xml
Adware:Adware/SearchRelevancy No disinfected Windows Registry
Spyware:Spyware/Search3 No disinfected C:\Program Files\Search3 Toolbar
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Saker\Favorites\Sites about\Ab scissor.url
Adware:Adware/SearchAid No disinfected C:\Documents and Settings\Saker\Desktop\backups\backup-20050413-201402-652.dll
Virus:VBS/Inor.AF Renamed C:\ntdetect.hta
Adware:Adware/Minibug No disinfected C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll
Adware:Adware/Gator No disinfected C:\Program Files\Common Files\clanteaf\crtrlcepjn\hanhelhnc.exe
Adware:Adware/Gator No disinfected C:\Program Files\Common Files\clanteaf\ejlrnpjd\pcnjepna.exe
Adware:Adware/WUpd No disinfected C:\Program Files\Windows AdStatus\WinStatComm.dll
Adware:Adware/AdLogix No disinfected C:\Program Files\Windows Media Player\wmplayer.exe.tmp
Adware:Adware/SearchAid No disinfected C:\WINDOWS\addcn.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\addkv.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\addte.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\addwy32.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\aobeo.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\apiin.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\apins32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\apinz32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\apitb.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\appft.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\appip32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\appmb32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\apppc.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\apppf32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\atlae.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\atlll32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\atlrh.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\bcnsj.dll
Virus:Trj/Delf.EB Disinfected C:\WINDOWS\bundles\HelperInstaller.exe.tmp
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\crax.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\crci32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\crlx32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\d3bv32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\d3dv.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\d3yt32.exe
Spyware:Spyware/Search3 No disinfected C:\WINDOWS\Downloaded Program Files\search3.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\etsqr.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\iexb.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\ipzr.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\javaso.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\javazw32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\mfcdf32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\mfckw.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\msja.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\mslv32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\msxd.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\msxz32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\netiz32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\netra.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ntcx32.exe
Virus:Trj/Downloader.AQN Disinfected C:\WINDOWS\ntfl.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ntga.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ntus32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sdkby32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sdkef.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sdkmn32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sysci.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\addcn32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\added.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\addth32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apidy.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apihc32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apilp32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\apimn.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apipi.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apivb32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apphn32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\appib32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\appvy32.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\asydj.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\atlqd32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\crkg.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\d3rd.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\d3ue32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\d3vr32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\d3zu.exe
Adware:Adware/DealHelper No disinfected C:\WINDOWS\system32\dun.exe
Adware:Adware/FunWeb No disinfected C:\WINDOWS\system32\f3PSSavr.scr
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\ibeda.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ieck32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\iegl32.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\ikfps.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ipjq.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\iplb.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\javako32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\mfcjz.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\mfcse32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\mfcye32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\msat32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\msgl.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\msyy.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\netew32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\ntdv32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ntlj.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\ntuf.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\olijm.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\phmif.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdkim32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdknk32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdkod32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdkyc.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\spbmh.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sysav.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sysjb.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sysqe32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sysuk32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\winah32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\winis32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\winnm32.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\zcinm.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\zgxdb.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\systu.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sysxb32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\winoi.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\winpa.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\winza32.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\ymtpv.dll
#11
Posted 16 April 2005 - 11:27 PM
^^^^^^^^^^^^^thats the panda scan
#12
Guest_thatman_*
Posted 16 April 2005 - 11:31 PM
Hi squeeker
I do need to see a Hijackhis scan log, to enable me to run a new fix for you
Kc
I do need to see a Hijackhis scan log, to enable me to run a new fix for you
Kc
#13
Guest_thatman_*
Posted 16 April 2005 - 11:56 PM
Hi squeeker
Download Pocket Killbox and unzip it; save it to your Desktop.
Please read through the instructions before you start (you may want to print this out).
Reboot into Safe Mode: Click here if you don't know how to do this.
Run killbox and click the radio button that says Delete a file on reboot.
Copy and Paste them one at a time into the full path of file to delete box and click the red circle with a white cross in it.
The program will ask you if you want to reboot; say No each time until the last one has been pasted in where upon you should answer Yes.
Let the system reboot.
C:\WINDOWS\system32\saie_*.dat
C:\WINDOWS\bundles
C:\WINDOWS\Bundles
C:\WINDOWS\system32\stlb2.xml
C:\ntdetect.hta
C:\WINDOWS\addcn.exe
C:\WINDOWS\addkv.exe
C:\WINDOWS\addte.exe
C:\WINDOWS\addwy32.exe
C:\WINDOWS\aobeo.dll
C:\WINDOWS\apiin.exe
C:\WINDOWS\apins32.exe
C:\WINDOWS\apinz32.exe
C:\WINDOWS\apitb.exe
C:\WINDOWS\appft.exe
C:\WINDOWS\appip32.exe
C:\WINDOWS\appmb32.exe
C:\WINDOWS\apppc.exe
C:\WINDOWS\apppf32.exe
C:\WINDOWS\atlae.exe
C:\WINDOWS\atlll32.exe
C:\WINDOWS\atlrh.exe
C:\WINDOWS\bcnsj.dll
C:\WINDOWS\bundles\HelperInstaller.exe.tmp
C:\WINDOWS\crax.exe
C:\WINDOWS\crci32.exe
C:\WINDOWS\crlx32.exe
C:\WINDOWS\d3bv32.exe
C:\WINDOWS\d3dv.exe
C:\WINDOWS\d3yt32.exe
C:\WINDOWS\Downloaded Program Files\search3.dll
C:\WINDOWS\etsqr.dll
C:\WINDOWS\iexb.exe
C:\WINDOWS\ipzr.exe
C:\WINDOWS\javaso.exe
C:\WINDOWS\javazw32.exe
C:\WINDOWS\mfcdf32.exe
C:\WINDOWS\mfckw.exe
C:\WINDOWS\msja.exe
C:\WINDOWS\mslv32.exe
C:\WINDOWS\msxd.exe
C:\WINDOWS\msxz32.exe
C:\WINDOWS\netiz32.exe
C:\WINDOWS\netra.exe
C:\WINDOWS\ntcx32.exe
C:\WINDOWS\ntfl.exe
C:\WINDOWS\ntga.exe
C:\WINDOWS\ntus32.exe
C:\WINDOWS\sdkby32.exe
C:\WINDOWS\sdkef.exe
C:\WINDOWS\sdkmn32.exe
C:\WINDOWS\sysci.exe
C:\WINDOWS\system32\addcn32.exe
C:\WINDOWS\system32\added.exe
C:\WINDOWS\system32\addth32.exe
C:\WINDOWS\system32\apidy.exe
C:\WINDOWS\system32\apihc32.exe
C:\WINDOWS\system32\apilp32.exe
C:\WINDOWS\system32\apimn.exe
C:\WINDOWS\system32\apipi.exe
C:\WINDOWS\system32\apivb32.exe
C:\WINDOWS\system32\apphn32.exe
C:\WINDOWS\system32\appib32.exe
C:\WINDOWS\system32\appvy32.exe
C:\WINDOWS\system32\asydj.dll
C:\WINDOWS\system32\atlqd32.exe
C:\WINDOWS\system32\crkg.exe
C:\WINDOWS\system32\d3rd.exe
C:\WINDOWS\system32\d3ue32.exe
C:\WINDOWS\system32\d3vr32.exe
C:\WINDOWS\system32\d3zu.exe
C:\WINDOWS\system32\dun.exe
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\system32\ibeda.dll
C:\WINDOWS\system32\ieck32.exe
C:\WINDOWS\system32\iegl32.exe
C:\WINDOWS\system32\ikfps.dll
C:\WINDOWS\system32\ipjq.exe
C:\WINDOWS\system32\iplb.exe
C:\WINDOWS\system32\javako32.exe
C:\WINDOWS\system32\mfcjz.exe
C:\WINDOWS\system32\mfcse32.exe
C:\WINDOWS\system32\mfcye32.exe
C:\WINDOWS\system32\msat32.exe
C:\WINDOWS\system32\msgl.exe
C:\WINDOWS\system32\msyy.exe
C:\WINDOWS\system32\netew32.exe
C:\WINDOWS\system32\ntdv32.exe
C:\WINDOWS\system32\ntlj.exe
C:\WINDOWS\system32\ntuf.exe
C:\WINDOWS\system32\olijm.dll
C:\WINDOWS\system32\phmif.dll
C:\WINDOWS\system32\sdkim32.exe
C:\WINDOWS\system32\sdknk32.exe
C:\WINDOWS\system32\sdkod32.exe
C:\WINDOWS\system32\sdkyc.exe
C:\WINDOWS\system32\spbmh.dll
C:\WINDOWS\system32\sysav.exe
C:\WINDOWS\system32\sysjb.exe
C:\WINDOWS\system32\sysqe32.exe
C:\WINDOWS\system32\sysuk32.exe
C:\WINDOWS\system32\winah32.exe
C:\WINDOWS\system32\winis32.exe
C:\WINDOWS\system32\winnm32.exe
C:\WINDOWS\system32\zcinm.dll
C:\WINDOWS\system32\zgxdb.dll
C:\WINDOWS\systu.exe
C:\WINDOWS\sysxb32.exe
C:\WINDOWS\winoi.exe
C:\WINDOWS\winpa.exe
C:\WINDOWS\winza32.exe
C:\WINDOWS\ymtpv.dll
End of killbox file's
Reboot into normal mode.
Post a new Panda.log and new HJT.Log
Kc
Download Pocket Killbox and unzip it; save it to your Desktop.
Please read through the instructions before you start (you may want to print this out).
Reboot into Safe Mode: Click here if you don't know how to do this.
Run killbox and click the radio button that says Delete a file on reboot.
Copy and Paste them one at a time into the full path of file to delete box and click the red circle with a white cross in it.
The program will ask you if you want to reboot; say No each time until the last one has been pasted in where upon you should answer Yes.
Let the system reboot.
C:\WINDOWS\system32\saie_*.dat
C:\WINDOWS\bundles
C:\WINDOWS\Bundles
C:\WINDOWS\system32\stlb2.xml
C:\ntdetect.hta
C:\WINDOWS\addcn.exe
C:\WINDOWS\addkv.exe
C:\WINDOWS\addte.exe
C:\WINDOWS\addwy32.exe
C:\WINDOWS\aobeo.dll
C:\WINDOWS\apiin.exe
C:\WINDOWS\apins32.exe
C:\WINDOWS\apinz32.exe
C:\WINDOWS\apitb.exe
C:\WINDOWS\appft.exe
C:\WINDOWS\appip32.exe
C:\WINDOWS\appmb32.exe
C:\WINDOWS\apppc.exe
C:\WINDOWS\apppf32.exe
C:\WINDOWS\atlae.exe
C:\WINDOWS\atlll32.exe
C:\WINDOWS\atlrh.exe
C:\WINDOWS\bcnsj.dll
C:\WINDOWS\bundles\HelperInstaller.exe.tmp
C:\WINDOWS\crax.exe
C:\WINDOWS\crci32.exe
C:\WINDOWS\crlx32.exe
C:\WINDOWS\d3bv32.exe
C:\WINDOWS\d3dv.exe
C:\WINDOWS\d3yt32.exe
C:\WINDOWS\Downloaded Program Files\search3.dll
C:\WINDOWS\etsqr.dll
C:\WINDOWS\iexb.exe
C:\WINDOWS\ipzr.exe
C:\WINDOWS\javaso.exe
C:\WINDOWS\javazw32.exe
C:\WINDOWS\mfcdf32.exe
C:\WINDOWS\mfckw.exe
C:\WINDOWS\msja.exe
C:\WINDOWS\mslv32.exe
C:\WINDOWS\msxd.exe
C:\WINDOWS\msxz32.exe
C:\WINDOWS\netiz32.exe
C:\WINDOWS\netra.exe
C:\WINDOWS\ntcx32.exe
C:\WINDOWS\ntfl.exe
C:\WINDOWS\ntga.exe
C:\WINDOWS\ntus32.exe
C:\WINDOWS\sdkby32.exe
C:\WINDOWS\sdkef.exe
C:\WINDOWS\sdkmn32.exe
C:\WINDOWS\sysci.exe
C:\WINDOWS\system32\addcn32.exe
C:\WINDOWS\system32\added.exe
C:\WINDOWS\system32\addth32.exe
C:\WINDOWS\system32\apidy.exe
C:\WINDOWS\system32\apihc32.exe
C:\WINDOWS\system32\apilp32.exe
C:\WINDOWS\system32\apimn.exe
C:\WINDOWS\system32\apipi.exe
C:\WINDOWS\system32\apivb32.exe
C:\WINDOWS\system32\apphn32.exe
C:\WINDOWS\system32\appib32.exe
C:\WINDOWS\system32\appvy32.exe
C:\WINDOWS\system32\asydj.dll
C:\WINDOWS\system32\atlqd32.exe
C:\WINDOWS\system32\crkg.exe
C:\WINDOWS\system32\d3rd.exe
C:\WINDOWS\system32\d3ue32.exe
C:\WINDOWS\system32\d3vr32.exe
C:\WINDOWS\system32\d3zu.exe
C:\WINDOWS\system32\dun.exe
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\system32\ibeda.dll
C:\WINDOWS\system32\ieck32.exe
C:\WINDOWS\system32\iegl32.exe
C:\WINDOWS\system32\ikfps.dll
C:\WINDOWS\system32\ipjq.exe
C:\WINDOWS\system32\iplb.exe
C:\WINDOWS\system32\javako32.exe
C:\WINDOWS\system32\mfcjz.exe
C:\WINDOWS\system32\mfcse32.exe
C:\WINDOWS\system32\mfcye32.exe
C:\WINDOWS\system32\msat32.exe
C:\WINDOWS\system32\msgl.exe
C:\WINDOWS\system32\msyy.exe
C:\WINDOWS\system32\netew32.exe
C:\WINDOWS\system32\ntdv32.exe
C:\WINDOWS\system32\ntlj.exe
C:\WINDOWS\system32\ntuf.exe
C:\WINDOWS\system32\olijm.dll
C:\WINDOWS\system32\phmif.dll
C:\WINDOWS\system32\sdkim32.exe
C:\WINDOWS\system32\sdknk32.exe
C:\WINDOWS\system32\sdkod32.exe
C:\WINDOWS\system32\sdkyc.exe
C:\WINDOWS\system32\spbmh.dll
C:\WINDOWS\system32\sysav.exe
C:\WINDOWS\system32\sysjb.exe
C:\WINDOWS\system32\sysqe32.exe
C:\WINDOWS\system32\sysuk32.exe
C:\WINDOWS\system32\winah32.exe
C:\WINDOWS\system32\winis32.exe
C:\WINDOWS\system32\winnm32.exe
C:\WINDOWS\system32\zcinm.dll
C:\WINDOWS\system32\zgxdb.dll
C:\WINDOWS\systu.exe
C:\WINDOWS\sysxb32.exe
C:\WINDOWS\winoi.exe
C:\WINDOWS\winpa.exe
C:\WINDOWS\winza32.exe
C:\WINDOWS\ymtpv.dll
End of killbox file's
Reboot into normal mode.
Post a new Panda.log and new HJT.Log
Kc
#14
Posted 18 April 2005 - 06:19 PM
Incident Status Location
Adware:Adware/SaveNow No disinfected Windows Registry
Adware:Adware/nCase No disinfected C:\WINDOWS\system32\saie_*.dat
Adware:Adware/PortalScan No disinfected C:\WINDOWS\system32\winupdt.bin
Adware:Adware/VirtualBouncer No disinfected C:\Documents and Settings\All Users\Application Data\VBouncer
Adware:Adware/SideFind No disinfected Windows Registry
Spyware:Spyware/Search3 No disinfected C:\Program Files\Search3 Toolbar
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Saker\Favorites\Sites about\Ab scissor.url
Adware:Adware/SearchAid No disinfected C:\Documents and Settings\Saker\Desktop\backups\backup-20050413-201402-652.dll
Virus:VBS/Inor.AF Renamed C:\ntdetect_hta.vir
Adware:Adware/Minibug No disinfected C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll
Adware:Adware/Gator No disinfected C:\Program Files\Common Files\clanteaf\crtrlcepjn\hanhelhnc.exe
Adware:Adware/Gator No disinfected C:\Program Files\Common Files\clanteaf\ejlrnpjd\pcnjepna.exe
Adware:Adware/WUpd No disinfected C:\Program Files\Windows AdStatus\WinStatComm.dll
Adware:Adware/AdLogix No disinfected C:\Program Files\Windows Media Player\wmplayer.exe.tmp
Adware:Adware/SaveNow No disinfected Windows Registry
Adware:Adware/nCase No disinfected C:\WINDOWS\system32\saie_*.dat
Adware:Adware/PortalScan No disinfected C:\WINDOWS\system32\winupdt.bin
Adware:Adware/VirtualBouncer No disinfected C:\Documents and Settings\All Users\Application Data\VBouncer
Adware:Adware/SideFind No disinfected Windows Registry
Spyware:Spyware/Search3 No disinfected C:\Program Files\Search3 Toolbar
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Saker\Favorites\Sites about\Ab scissor.url
Adware:Adware/SearchAid No disinfected C:\Documents and Settings\Saker\Desktop\backups\backup-20050413-201402-652.dll
Virus:VBS/Inor.AF Renamed C:\ntdetect_hta.vir
Adware:Adware/Minibug No disinfected C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll
Adware:Adware/Gator No disinfected C:\Program Files\Common Files\clanteaf\crtrlcepjn\hanhelhnc.exe
Adware:Adware/Gator No disinfected C:\Program Files\Common Files\clanteaf\ejlrnpjd\pcnjepna.exe
Adware:Adware/WUpd No disinfected C:\Program Files\Windows AdStatus\WinStatComm.dll
Adware:Adware/AdLogix No disinfected C:\Program Files\Windows Media Player\wmplayer.exe.tmp
#15
Posted 18 April 2005 - 06:20 PM
Logfile of HijackThis v1.99.1
Scan saved at 7:19:55 PM, on 4/18/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\Documents and Settings\Saker\Desktop\HijackThis-1.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
Scan saved at 7:19:55 PM, on 4/18/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\Documents and Settings\Saker\Desktop\HijackThis-1.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users