Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Bloodhound.w32.ep problem + IE not working [RESOLVED]


  • This topic is locked This topic is locked

#61
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Lets try this instead -

Run Hijack This. Click on Config ---> Misc Tools ---> Open Process Manager.
Kill each of the following processes, if found -

Hardware Clock Driver / (hwclock) / C:\WINDOWS\System32\hwclock.exe
Network DDE Client / (NetDDEclnt) / C:\WINDOWS\System32\netddeclnt.exe

C:\WINDOWS\System32\Fmspdy.exe
C:\WINDOWS\System32\Twypai.exe
C:\WINDOWS\System32\oif6ak25.exe
C:\Program Files\Wflumn\Fdgyzs.exe
winhost.exe
Logitech.exe
ntguard32.exe
winupdater.exe


Run Hijack This again. Click on config ---> Misc Tools ----> Delete an NT service. Enter the following item - hwclock - and hit enter. Repeat the process with NetDDEclnt.

Run Hijack This and click on scan. The following items need to be fixed -

O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C:\Program Files\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL (file missing)
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL (file missing)
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem303.dll (file missing)
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho.dll (file missing)
O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL (file missing)
O3 - Toolbar: ISTbar - {FAA356E4-D317-42a6-AB41-A3021C6E7D52} - C:\Program Files\ISTbar\istbarcm.dll (file missing)
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll (file missing)
O4 - HKLM\..\Run: [Logitech] Logitech.exe
O4 - HKLM\..\Run: [WSAConfiguration] ntguard32.exe
O4 - HKLM\..\Run: [Microsoft Update] winupdater.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\Fmspdy.exe
O4 - HKLM\..\Run: [secure] C:\WINDOWS\System32\Twypai.exe
O4 - HKLM\..\Run: [oif6ak25] C:\WINDOWS\System32\oif6ak25.exe
O4 - HKLM\..\Run: [Vrbteswr] C:\Program Files\Wflumn\Fdgyzs.exe
O4 - HKLM\..\RunServices: [win32] winhost.exe
O4 - HKLM\..\RunServices: [Logitech] Logitech.exe
O4 - HKLM\..\RunServices: [WSAConfiguration] ntguard32.exe
O4 - HKLM\..\RunServices: [Microsoft Update] winupdater.exe

Close all windows other than Hijack This. Check the boxes next to above items and click on Fix checked.

Connect back the PC and modem.

Reboot the PC in Safe Mode.

Locate and delete the files -

C:\WINDOWS\System32\Fmspdy.exe
C:\WINDOWS\System32\Twypai.exe
C:\WINDOWS\System32\oif6ak25.exe
C:\Program Files\Wflumn\Fdgyzs.exe
winhost.exe
Logitech.exe
ntguard32.exe
winupdater.exe

Reboot the PC and post a fresh HJT log
  • 0

Advertisements


#62
Souss

Souss

    Member

  • Topic Starter
  • Member
  • PipPip
  • 51 posts

Lets try this instead -

Run Hijack This. Click on Config ---> Misc Tools ---> Open Process Manager.
Kill each of the following processes, if found -

Hardware Clock Driver  /  (hwclock)  /  C:\WINDOWS\System32\hwclock.exe
Network DDE Client    /    (NetDDEclnt)    /  C:\WINDOWS\System32\netddeclnt.exe

C:\WINDOWS\System32\Fmspdy.exe
C:\WINDOWS\System32\Twypai.exe
C:\WINDOWS\System32\oif6ak25.exe
C:\Program Files\Wflumn\Fdgyzs.exe
winhost.exe
Logitech.exe
ntguard32.exe
winupdater.exe



none of these are in the list

Run Hijack This again. Click on config ---> Misc Tools ----> Delete an NT service. Enter the following item - hwclock - and hit enter. Repeat the process with NetDDEclnt.


got the same message: they are running and need to disabled.

Run Hijack This and click on scan. The following items need to be fixed -

O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C:\Program Files\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL (file missing)
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL (file missing)
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem303.dll (file missing)
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho.dll (file missing)
O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL (file missing)
O3 - Toolbar: ISTbar - {FAA356E4-D317-42a6-AB41-A3021C6E7D52} - C:\Program Files\ISTbar\istbarcm.dll (file missing)
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll (file missing)
O4 - HKLM\..\Run: [Logitech] Logitech.exe
O4 - HKLM\..\Run: [WSAConfiguration] ntguard32.exe
O4 - HKLM\..\Run: [Microsoft Update] winupdater.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\Fmspdy.exe
O4 - HKLM\..\Run: [secure] C:\WINDOWS\System32\Twypai.exe
O4 - HKLM\..\Run: [oif6ak25] C:\WINDOWS\System32\oif6ak25.exe
O4 - HKLM\..\Run: [Vrbteswr] C:\Program Files\Wflumn\Fdgyzs.exe
O4 - HKLM\..\RunServices: [win32] winhost.exe
O4 - HKLM\..\RunServices: [Logitech] Logitech.exe
O4 - HKLM\..\RunServices: [WSAConfiguration] ntguard32.exe
O4 - HKLM\..\RunServices: [Microsoft Update] winupdater.exe

Close all windows other than Hijack This. Check the boxes next to above items and click on Fix checked.

Connect back the PC and modem.

Reboot the PC in Safe Mode.

Locate and delete the files -

C:\WINDOWS\System32\Fmspdy.exe
C:\WINDOWS\System32\Twypai.exe
C:\WINDOWS\System32\oif6ak25.exe
C:\Program Files\Wflumn\Fdgyzs.exe
winhost.exe
Logitech.exe
ntguard32.exe
winupdater.exe

Reboot the PC and post a fresh HJT log

View Post


  • 0

#63
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
ok, proceed with the rest of the fix i.e. fixing the entries in HJT and then deleting them !!!
  • 0

#64
Souss

Souss

    Member

  • Topic Starter
  • Member
  • PipPip
  • 51 posts
I couldn't find any of the files you asked to delete.

here is the new log
thanks

Attached Files


  • 0

#65
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
The HJT log looks much better !!!

Has your PC improved in any perceptible way ???
  • 0

#66
Souss

Souss

    Member

  • Topic Starter
  • Member
  • PipPip
  • 51 posts
there is slight improvement, I have less popups.

but the wallpaper is still gone, so as the start bar, my internet explorer is still weird and I can't run most programs.

Edited by Souss, 29 June 2005 - 12:30 PM.

  • 0

#67
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Hi Souss,

Can you visit this site - http://www3.ca.com/s...sinfo/scan.aspx and do an online scan ??

Let it fix any itmes that it finds and save the scan report for posting here
  • 0

#68
Souss

Souss

    Member

  • Topic Starter
  • Member
  • PipPip
  • 51 posts
Here is the report. All viruses could not be cured so they were deleted, except for the last one.

Scan Results: 33335 files scanned. 10 viruses were detected.

prompt[1].htm
JS.SillyDlScript.H
deleted
C:\Documents and Settings\Souss\Local Settings\Temporary Internet Files\Content.IE5\6MN07HCS\

Fdgyzs.exe
Win32.Dyfuca.B
deleted
C:\RECYCLER\S-1-5-21-2176965470-3732937156-2088241414-1005\Dc24\

actalert.exe
Win32.Dyfuca.L
deleted
C:\RECYCLER\S-1-5-21-2176965470-3732937156-2088241414-1005\Dc26\

optimize.exe
Win32.Dyfuca.P
deleted
C:\RECYCLER\S-1-5-21-2176965470-3732937156-2088241414-1005\Dc26\

actalert.exe
Win32.Dyfuca.L
deleted
C:\RECYCLER\S-1-5-21-2176965470-3732937156-2088241414-1005\Dc26\update\

rogue.exe
Win32.Dyfuca.B
deleted
C:\RECYCLER\S-1-5-21-2176965470-3732937156-2088241414-1005\Dc26\update\

Dc30.dll
Win32.Dyfuca.F
deleted
C:\RECYCLER\S-1-5-21-2176965470-3732937156-2088241414-1005\

A0038157.dll
Win32.Dyfuca.D
deleted
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP5\

A0038158.exe
Win32.SillyDl.JC
deleted
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP5\

wininet.dll
Win32.Alemod.A
cannot delete
C:\WINDOWS\system32\

Edited by Souss, 29 June 2005 - 01:11 PM.

  • 0

#69
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Copy this into a text file and name it as locate.bat -

dir %Systemdrive%\wininet.dll /a h /s > files.txt

Run locate.bat

Attach the files.txt in your next reply
  • 0

#70
Souss

Souss

    Member

  • Topic Starter
  • Member
  • PipPip
  • 51 posts
here it is

Attached Files


  • 0

Advertisements


#71
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Hi Souss,

looks like all the available and latest copies of wininet.dll are infected !!!!

I want you to edit the registry now !!! You have to be very careful as modifying any key other than the one specified can seriously effect your PC !!!!

If you are not comfortable, then I will figure out another way !!!!

Run regedit. Locate the following keys -

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=dword:00000000

For each of the keys, make sure that the DisableRegistryTools dword is set to 0.

Please try it and report back
  • 0

#72
Souss

Souss

    Member

  • Topic Starter
  • Member
  • PipPip
  • 51 posts
again, I can't run regedit. error message.
  • 0

#73
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Can you save the text -

REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=dword:00000000


as a text file and rename it as 1.reg. Double click on it and let it merge with the registry.

Let me know how it goes
  • 0

#74
Souss

Souss

    Member

  • Topic Starter
  • Member
  • PipPip
  • 51 posts
same error message when I double click the file
  • 0

#75
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Souss,

I need to get more ideas !!!!!!!!!

I will check with others and get back
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP