This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

About:blank Isn't

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Symptom: AOL email downloaded, but WWW aborted AOL. Moved computer to Verizon DSL environment and changed to IE. After running updated versions of SpyBot, SpywareBlaster, SpywareGuard, CWShredder, MiniRemoval CWS, finally saw the hijacked home page–plus millions of SpyBot and SpywareGuard messages!. Ran HiJackThis, and trying unsuccessfully to strip HJT myself, but must now bother you for help. :blink: THANKS! Logfile of HijackThis v1.98.2 Scan saved at 1:01:21 PM, on 10/20/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\WINDOWS\system32\sdkbh.exe C:\Program Files\SMART Board Software\SMARTBoardService.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\Common Files\WinTools\WToolsS.exe C:\WINDOWS\System32\hkcmd.exe C:\WINDOWS\BCMSMMSG.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\system32\ntbc.exe C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Common Files\WinTools\WSup.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\explorer.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\HiJackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://xuywg.dll/index.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://xuywg.dll/index.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\xuywg.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\xuywg.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\xuywg.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://xuywg.dll/index.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank R3 - Default URLSearchHook is missing O2 - BHO: (no name) - {B088F432-4905-C3A4-63E7-29CAC50E2E71} - C:\WINDOWS\appbx32.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [NAV CfgWiz] "C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT" O4 - HKLM\..\Run: [ntbc.exe] C:\WINDOWS\system32\ntbc.exe O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe O16 - DPF: {10003000-1000-0000-1000-000000000000} - O16 - DPF: {11111111-1111-1111-1111-111111111123} - O16 - DPF: {11311111-1111-1111-1111-111111111157} -
I don't want to "bump" this, but after two days I must ask: Since the HJT log I posted was after I followed the HJT tutorial and cleaned it up–more or less–would it help get help if I posted the original? I really appreciate your help. :unsure:
Click here to download CWShredder by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'. Reboot when done.

Click here to download Spybot Search & Destroy - install, update, scan and fix all RED items it finds. Reboot when done.

Click here to download Ad-Aware and install. Before scanning click on "check for updates now" to make sure you have the latest reference file. Then click the gear wheel at the top and check these options:

General> activate these: "Automatically save log-file" and "Automatically quarantine objects prior to removal"

Scanning > activate these: "Scan within archives", "Scan active processes", "Scan registry", "Deep scan registry", "Scan my IE Favorites for banned sites" and "Scan my Hosts file"

Tweaks > Scanning Engine> activate this: "Unload recognized processes during scanning."

Tweaks > Cleaning Engine: activate these: "Automatically try to unregister objects prior to deletion" and "Let Windows remove files in use after reboot."

Click "Proceed" to save your settings, then click "Start", make sure "Activate in-depth scan" is ticked green then scan your system. When the scan is finished, the screen will tell you if anything has been found, click "Next". The bad files will be listed, right click the pane and click "Select all objects" - this will put a check mark in the box at the side, click "Next" again and click "OK" at the prompt "# objects will be removed. Continue?".

Reboot when done. Rescan with HJT and post a new log here.

Also, click here to download a little script by Mosaic1 that reveals all running services in your system. Download, unzip and double-click getactiveservices.vbs (you may need to enable your antivirus program to run the file). This script will create and open a text file named Active.txt in the same folder as the script itself has been saved. It will then open Active.txt for you. Active text will list all active Services - copy and paste the contents of Active.txt in your next reply here.
I stopped running AdAware in tandem with SpyBot, SWBlaster, SWGuard, et al a couple of months ago because it wasn't finding anything–but I am DEFINITELY IMPRESSED with the new version. It even found COs on the two computers which have been protected!! (I am running it again on the infected one, just out of curiousity, and it is finding a bunch AGAIN even as we speak. Sigh… I will wait for your reply before I "fix" anything else.) Logfile of HijackThis v1.98.2 Scan saved at 7:16:08 PM, on 10/22/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\BCMSMMSG.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\syswi.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\SpywareGuard\sgmain.exe C:\WINDOWS\n_iyalee.dat:nfwlf C:\WINDOWS\explorer.exe C:\Documents and Settings\tom\My Documents\HiJackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ikwyt.dll/index.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ikwyt.dll/index.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\xuywg.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\xuywg.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ikwyt.dll/index.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R3 - Default URLSearchHook is missing O2 - BHO: (no name) - {B088F432-4905-C3A4-63E7-29CAC50E2E71} - C:\WINDOWS\appbx32.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing) O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [ipwc32.exe] C:\WINDOWS\ipwc32.exe O4 - HKLM\..\Run: [syswi.exe] C:\WINDOWS\syswi.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {10003000-1000-0000-1000-000000000000} - O16 - DPF: {11111111-1111-1111-1111-111111111123} - O16 - DPF: {11311111-1111-1111-1111-111111111157} - These are the Current Active Services: APPLICATION LAYER GATEWAY SERVICE: ALG C:\WINDOWS\System32\alg.exe AOL CONNECTIVITY SERVICE: AOL ACS C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe WINDOWS AUDIO: AudioSrv C:\WINDOWS\System32\svchost.exe -k netsvcs COMPUTER BROWSER: Browser C:\WINDOWS\System32\svchost.exe -k netsvcs CRYPTOGRAPHIC SERVICES: CryptSvc C:\WINDOWS\system32\svchost.exe -k netsvcs DHCP CLIENT: Dhcp C:\WINDOWS\System32\svchost.exe -k netsvcs ERROR REPORTING SERVICE: ERSvc C:\WINDOWS\System32\svchost.exe -k netsvcs COM+ EVENT SYSTEM: EventSystem C:\WINDOWS\System32\svchost.exe -k netsvcs FAST USER SWITCHING COMPATIBILITY: FastUserSwitchingCompatibility C:\WINDOWS\System32\svchost.exe -k netsvcs HELP AND SUPPORT: helpsvc C:\WINDOWS\System32\svchost.exe -k netsvcs SERVER: lanmanserver C:\WINDOWS\System32\svchost.exe -k netsvcs WORKSTATION: lanmanworkstation C:\WINDOWS\System32\svchost.exe -k netsvcs NETWORK CONNECTIONS: Netman C:\WINDOWS\System32\svchost.exe -k netsvcs NETWORK LOCATION AWARENESS (NLA): Nla C:\WINDOWS\System32\svchost.exe -k netsvcs DCOM SERVER PROCESS LAUNCHER: DcomLaunch C:\WINDOWS\system32\svchost -k DcomLaunch DNS CLIENT: Dnscache C:\WINDOWS\System32\svchost.exe -k NetworkService EVENT LOG: Eventlog C:\WINDOWS\system32\services.exe TCP/IP NETBIOS HELPER: LmHosts C:\WINDOWS\System32\svchost.exe -k LocalService MCAFEE.COM VIRUSSCAN ONLINE REALTIME ENGINE: MCVSRte c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe /Embedding MACHINE DEBUG MANAGER: MDM "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
That doesn't look like the full active.txt file - could you repost it. In the meantime, open Spybot S&D, click Mode>Advanced>Tools>Resident and remove the check from the Tea Timer box. You can reinstate it later but we don't want it interfering with what we need to do. Reboot when done and post another HJT log.
The only dif between the first Active.txt and this one might be the AOL– I had disabled the startup on it, but renabled everything for this log. (I have been trying unsuccessfully to install NAV 2005, and now that I see the frags of McAfee, even after a painful uninstall, I understand why. That will be one of the first things I get rid of–from SERVICES, yet, not even Startup, after we get done.) These are the Current Active Services: APPLICATION LAYER GATEWAY SERVICE: ALG C:\WINDOWS\System32\alg.exe AOL CONNECTIVITY SERVICE: AOL ACS C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe WINDOWS AUDIO: AudioSrv C:\WINDOWS\System32\svchost.exe -k netsvcs COMPUTER BROWSER: Browser C:\WINDOWS\System32\svchost.exe -k netsvcs CRYPTOGRAPHIC SERVICES: CryptSvc C:\WINDOWS\system32\svchost.exe -k netsvcs DHCP CLIENT: Dhcp C:\WINDOWS\System32\svchost.exe -k netsvcs ERROR REPORTING SERVICE: ERSvc C:\WINDOWS\System32\svchost.exe -k netsvcs COM+ EVENT SYSTEM: EventSystem C:\WINDOWS\System32\svchost.exe -k netsvcs FAST USER SWITCHING COMPATIBILITY: FastUserSwitchingCompatibility C:\WINDOWS\System32\svchost.exe -k netsvcs HELP AND SUPPORT: helpsvc C:\WINDOWS\System32\svchost.exe -k netsvcs SERVER: lanmanserver C:\WINDOWS\System32\svchost.exe -k netsvcs WORKSTATION: lanmanworkstation C:\WINDOWS\System32\svchost.exe -k netsvcs NETWORK CONNECTIONS: Netman C:\WINDOWS\System32\svchost.exe -k netsvcs NETWORK LOCATION AWARENESS (NLA): Nla C:\WINDOWS\System32\svchost.exe -k netsvcs DCOM SERVER PROCESS LAUNCHER: DcomLaunch C:\WINDOWS\system32\svchost -k DcomLaunch DNS CLIENT: Dnscache C:\WINDOWS\System32\svchost.exe -k NetworkService EVENT LOG: Eventlog C:\WINDOWS\system32\services.exe TCP/IP NETBIOS HELPER: LmHosts C:\WINDOWS\System32\svchost.exe -k LocalService MCAFEE.COM VIRUSSCAN ONLINE REALTIME ENGINE: MCVSRte c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe /Embedding MACHINE DEBUG MANAGER: MDM "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" Logfile of HijackThis v1.98.2 Scan saved at 9:19:17 AM, on 10/23/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\n_iyalee.dat:nfwlf C:\WINDOWS\BCMSMMSG.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\system32\ntbc.exe C:\Program Files\SpywareGuard\sgmain.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\explorer.exe C:\Documents and Settings\tom\My Documents\HiJackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ikwyt.dll/index.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ikwyt.dll/index.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ikwyt.dll/index.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R3 - Default URLSearchHook is missing O2 - BHO: (no name) - {B088F432-4905-C3A4-63E7-29CAC50E2E71} - C:\WINDOWS\appbx32.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing) O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [ntbc.exe] C:\WINDOWS\system32\ntbc.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {10003000-1000-0000-1000-000000000000} - O16 - DPF: {11111111-1111-1111-1111-111111111123} - O16 - DPF: {11311111-1111-1111-1111-111111111157} -
Hmmm.. OK. Print out these instructions as most of the steps need to be done in Safe Mode and you won't be able to go online.

Do this so you can see hidden files and folders - click here to download xphidden.zip. Extract xphidden.reg from the zip file and save it to the desktop. When done, double-click the xphidden.reg and when asked to merge say yes. Click here to download About:Buster and unzip it to your desktop. Don´t run it yet. Also, click here to download System Security Suite. Extract it from the zip file into a folder.

Reboot into Safe Mode by tapping F8 after the BIOS has loaded.

Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ikwyt.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ikwyt.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ikwyt.dll/index.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ikwyt.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {B088F432-4905-C3A4-63E7-29CAC50E2E71} - C:\WINDOWS\appbx32.dll
O4 - HKLM\..\Run: [ntbc.exe] C:\WINDOWS\system32\ntbc.exe
O16 - DPF: {10003000-1000-0000-1000-000000000000} -
O16 - DPF: {11111111-1111-1111-1111-111111111123} -
O16 - DPF: {11311111-1111-1111-1111-111111111157} -

Find and delete the following:

C:\WINDOWS\system32\ntbc.exe

Now double click AboutBuster.exe that you downloaded earlier. Click start then click OK. This will scan your computer for the bad files and delete them. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

Rescan with Adaware and let it remove any bad files found.

Reboot back into Normal Mode. Open System Security Suite - doubleclick on sss.exe. Check the boxes under the 'Items to Clear' tab and click 'Clear Selected Items'. You will be prompted to reboot, do so. Repeat for all log-in accounts on your computer.

Two files (possibly three) were also deleted from your computer by this malware and need to be replaced.

control.exe - go here and download the version of control.exe for your operating system - copy it to c:\windows\system32\.

Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program.

If you have Spybot S&D installed you will also need to replace one file. Go here here and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program.

Rescan with HijackThis and post a new log here.
Good news: AdAware and SpyBot are clear, and I rebooted and the HJT log hasn't reverted to the ugly search pages. I was finally able to get NAV 2005 sort of installed–still getting "AXWIN Frame Ordinal 233 Not Found in shdocvw.dll" messages when the cfgwiz.exe tries to start, so I haven't yet done a scan, and can't use the online ones, either. Bad news: Win Explorer and Internet Explorer continue to abort, which is the main symptom we were having. (All my downloading has been from this machine and saved over the network to the infected one.) I can find several error report files about it, if that would help. :thumbup: Good news: AboutBuster did a FINE job cleaning up. :thumbdown: Bad news: the keyboard and mouse froze as I was trying to save the file. I wrote as much as I could see down before I rebooted, and the second run was all clear. What I could see to write down: Version 3.0 Reference List 15 No ADS found on system Removed 2 random Key Entries Deleted 1 service key successfully! Removed: C:\Windows\appq032.exe C:\Windows\bvogv.dat C:\Windows\downloaded,bak C:\Windows\ipwc32.exe C:\Windows\ptysg.dat C:\Windows\syswi.exe C:\Windows\system32\aeafa.dat C:\Windows\system32\fcocy.dat C:\Windows\system32\msxmlpp.dll $$$ These are the Current Active Services: APPLICATION LAYER GATEWAY SERVICE: ALG C:\WINDOWS\System32\alg.exe AOL CONNECTIVITY SERVICE: AOL ACS C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe WINDOWS AUDIO: AudioSrv C:\WINDOWS\System32\svchost.exe -k netsvcs COMPUTER BROWSER: Browser C:\WINDOWS\System32\svchost.exe -k netsvcs CRYPTOGRAPHIC SERVICES: CryptSvc C:\WINDOWS\system32\svchost.exe -k netsvcs DHCP CLIENT: Dhcp C:\WINDOWS\System32\svchost.exe -k netsvcs ERROR REPORTING SERVICE: ERSvc C:\WINDOWS\System32\svchost.exe -k netsvcs COM+ EVENT SYSTEM: EventSystem C:\WINDOWS\System32\svchost.exe -k netsvcs FAST USER SWITCHING COMPATIBILITY: FastUserSwitchingCompatibility C:\WINDOWS\System32\svchost.exe -k netsvcs HELP AND SUPPORT: helpsvc C:\WINDOWS\System32\svchost.exe -k netsvcs SERVER: lanmanserver C:\WINDOWS\System32\svchost.exe -k netsvcs WORKSTATION: lanmanworkstation C:\WINDOWS\System32\svchost.exe -k netsvcs NETWORK CONNECTIONS: Netman C:\WINDOWS\System32\svchost.exe -k netsvcs NETWORK LOCATION AWARENESS (NLA): Nla C:\WINDOWS\System32\svchost.exe -k netsvcs REMOTE ACCESS CONNECTION MANAGER: RasMan C:\WINDOWS\System32\svchost.exe -k netsvcs TASK SCHEDULER: Schedule C:\WINDOWS\System32\svchost.exe -k netsvcs SECONDARY LOGON: seclogon C:\WINDOWS\System32\svchost.exe -k netsvcs SYSTEM EVENT NOTIFICATION: SENS C:\WINDOWS\system32\svchost.exe -k netsvcs WINDOWS FIREWALL/INTERNET CONNECTION SHARING (ICS): SharedAccess C:\WINDOWS\System32\svchost.exe -k netsvcs SHELL HARDWARE DETECTION: ShellHWDetection C:\WINDOWS\System32\svchost.exe -k netsvcs SYSTEM RESTORE SERVICE: srservice C:\WINDOWS\System32\svchost.exe -k netsvcs TELEPHONY: TapiSrv C:\WINDOWS\System32\svchost.exe -k netsvcs THEMES: Themes C:\WINDOWS\System32\svchost.exe -k netsvcs DISTRIBUTED LINK TRACKING CLIENT: TrkWks C:\WINDOWS\system32\svchost.exe -k netsvcs WINDOWS TIME: w32time C:\WINDOWS\system32\svchost.exe -k netsvcs WINDOWS MANAGEMENT INSTRUMENTATION: winmgmt C:\WINDOWS\system32\svchost.exe -k netsvcs SECURITY CENTER: wscsvc C:\WINDOWS\System32\svchost.exe -k netsvcs AUTOMATIC UPDATES: wuauserv C:\WINDOWS\system32\svchost.exe -k netsvcs WIRELESS ZERO CONFIGURATION: WZCSVC C:\WINDOWS\System32\svchost.exe -k netsvcs SYMANTEC EVENT MANAGER: ccEvtMgr "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" SYMANTEC SETTINGS MANAGER: ccSetMgr "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" DCOM SERVER PROCESS LAUNCHER: DcomLaunch C:\WINDOWS\system32\svchost -k DcomLaunch TERMINAL SERVICES: TermService C:\WINDOWS\System32\svchost -k DComLaunch DNS CLIENT: Dnscache C:\WINDOWS\System32\svchost.exe -k NetworkService EVENT LOG: Eventlog C:\WINDOWS\system32\services.exe PLUG AND PLAY: PlugPlay C:\WINDOWS\system32\services.exe TCP/IP NETBIOS HELPER: LmHosts C:\WINDOWS\System32\svchost.exe -k LocalService SSDP DISCOVERY SERVICE: SSDPSRV C:\WINDOWS\System32\svchost.exe -k LocalService WEBCLIENT: WebClient C:\WINDOWS\System32\svchost.exe -k LocalService NORTON ANTIVIRUS AUTO-PROTECT SERVICE: navapsvc "C:\Program Files\Norton AntiVirus\navapsvc.exe" NORTON ANTIVIRUS FIREWALL MONITOR SERVICE: NPFMntor "C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe" IPSEC SERVICES: PolicyAgent C:\WINDOWS\System32\lsass.exe PROTECTED STORAGE: ProtectedStorage C:\WINDOWS\system32\lsass.exe SECURITY ACCOUNTS MANAGER: SamSs C:\WINDOWS\system32\lsass.exe REMOTE PROCEDURE CALL (RPC): RpcSs C:\WINDOWS\system32\svchost -k rpcss PRINT SPOOLER: Spooler C:\WINDOWS\system32\spoolsv.exe SYMANTEC CORE LC: Symantec Core LC C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe WAN MINIPORT (ATW) SERVICE: WANMiniportService "C:\WINDOWS\wanmpsvc.exe" Logfile of HijackThis v1.98.2 Scan saved at 10:44:28 PM, on 10/23/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\BCMSMMSG.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe C:\Program Files\SpywareGuard\sgmain.exe C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Documents and Settings\tom\My Documents\Malware\HiJackThis\HijackThis.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\explorer.exe O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - (no file) O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [NAV CfgWiz] "C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
That's why I was trying to get NAV 2005 installed–no browser. I can update with the apps that do not open the browser, but I don't know how to get to the sites for scans without one. Ideas? When I open IE, things look OK. I can go to a web site, MSN, for example, but then before it does anything else it goes into "not responding" and hangs. Win Explorer, on the other hand, aborts with a "send/don't send" error report every time I double-click on one of the .log or .txt files to open them from within the WE, and at other times it just closes without a message. NAV gives me "AXWIN Frame Ordinal 233 Not Found in shdocvw.dll" messages when the cfgwiz.exe tries to start.
Well, I did SFC, and WE still aborting. Tried to do ie.inf, but it asked for the ieexplorer on the SP2 CD, and there is none that I could see. I can't perform searches because WE keeps aborting. But when I opened IE, there was a bogus search page again–just not porn this time. I thought you might like to see the logs that are here as I will fdisk when they are done, just for the possibility that someone else can be helped. (Doing them in normal mode.) I truly appreciate your help, but I have run out of time. THis baby needs to be up and running in the am.
Here is my organ donation (we can call this death by Solitaire…): Buster was fine–even ran it in Safe just for the hell of it. When I opened IE to test it, I got a popup called "http://vv6.s13.topx.cc Welcome to System Performance Wizard", and shutting it down apparently put "junk" back in… :rant2: :rant: Logfile of HijackThis v1.98.2 Scan saved at 12:45:52 PM, on 10/24/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\BCMSMMSG.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\Messenger\msmsgs.exe C:\Documents and Settings\tom\My Documents\Malware\HiJackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank O2 - BHO: Windows Resources - {2D38A51A-23C9-48a1-A33C-48675AA2B494} - C:\WINDOWS\winres.dll O2 - BHO: (no name) - {8A0F57A5-033E-47DE-992E-23CADE2D67F1} - C:\WINDOWS\system32\idaj.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: *.flingstone.com O15 - Trusted Zone: *.i-lookup.com O15 - Trusted Zone: *.offshoreclicks.com O15 - Trusted Zone: *.teensguru.com O15 - Trusted Zone: *.xxxtoolbar.com O18 - Filter: text/html - {AC5E8EC4-B5C0-44CE-A246-87E0729CB30C} - C:\WINDOWS\system32\idaj.dll O18 - Filter: text/plain - {AC5E8EC4-B5C0-44CE-A246-87E0729CB30C} - C:\WINDOWS\system32\idaj.dll These are the Current Active Services: APPLICATION LAYER GATEWAY SERVICE: ALG C:\WINDOWS\System32\alg.exe AOL CONNECTIVITY SERVICE: AOL ACS C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe WINDOWS AUDIO: AudioSrv C:\WINDOWS\System32\svchost.exe -k netsvcs COMPUTER BROWSER: Browser C:\WINDOWS\System32\svchost.exe -k netsvcs CRYPTOGRAPHIC SERVICES: CryptSvc C:\WINDOWS\system32\svchost.exe -k netsvcs DHCP CLIENT: Dhcp C:\WINDOWS\System32\svchost.exe -k netsvcs ERROR REPORTING SERVICE: ERSvc C:\WINDOWS\System32\svchost.exe -k netsvcs COM+ EVENT SYSTEM: EventSystem C:\WINDOWS\System32\svchost.exe -k netsvcs FAST USER SWITCHING COMPATIBILITY: FastUserSwitchingCompatibility C:\WINDOWS\System32\svchost.exe -k netsvcs HELP AND SUPPORT: helpsvc C:\WINDOWS\System32\svchost.exe -k netsvcs SERVER: lanmanserver C:\WINDOWS\System32\svchost.exe -k netsvcs WORKSTATION: lanmanworkstation C:\WINDOWS\System32\svchost.exe -k netsvcs NETWORK CONNECTIONS: Netman C:\WINDOWS\System32\svchost.exe -k netsvcs NETWORK LOCATION AWARENESS (NLA): Nla C:\WINDOWS\System32\svchost.exe -k netsvcs REMOTE ACCESS CONNECTION MANAGER: RasMan C:\WINDOWS\System32\svchost.exe -k netsvcs TASK SCHEDULER: Schedule C:\WINDOWS\System32\svchost.exe -k netsvcs SECONDARY LOGON: seclogon C:\WINDOWS\System32\svchost.exe -k netsvcs SYSTEM EVENT NOTIFICATION: SENS C:\WINDOWS\system32\svchost.exe -k netsvcs WINDOWS FIREWALL/INTERNET CONNECTION SHARING (ICS): SharedAccess C:\WINDOWS\System32\svchost.exe -k netsvcs SHELL HARDWARE DETECTION: ShellHWDetection C:\WINDOWS\System32\svchost.exe -k netsvcs SYSTEM RESTORE SERVICE: srservice C:\WINDOWS\System32\svchost.exe -k netsvcs TELEPHONY: TapiSrv C:\WINDOWS\System32\svchost.exe -k netsvcs THEMES: Themes C:\WINDOWS\System32\svchost.exe -k netsvcs DISTRIBUTED LINK TRACKING CLIENT: TrkWks C:\WINDOWS\system32\svchost.exe -k netsvcs WINDOWS TIME: w32time C:\WINDOWS\system32\svchost.exe -k netsvcs WINDOWS MANAGEMENT INSTRUMENTATION: winmgmt C:\WINDOWS\system32\svchost.exe -k netsvcs SECURITY CENTER: wscsvc C:\WINDOWS\System32\svchost.exe -k netsvcs AUTOMATIC UPDATES: wuauserv C:\WINDOWS\system32\svchost.exe -k netsvcs WIRELESS ZERO CONFIGURATION: WZCSVC C:\WINDOWS\System32\svchost.exe -k netsvcs SYMANTEC EVENT MANAGER: ccEvtMgr "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" SYMANTEC SETTINGS MANAGER: ccSetMgr "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" DCOM SERVER PROCESS LAUNCHER: DcomLaunch C:\WINDOWS\system32\svchost -k DcomLaunch TERMINAL SERVICES: TermService C:\WINDOWS\System32\svchost -k DComLaunch DNS CLIENT: Dnscache C:\WINDOWS\System32\svchost.exe -k NetworkService EVENT LOG: Eventlog C:\WINDOWS\system32\services.exe PLUG AND PLAY: PlugPlay C:\WINDOWS\system32\services.exe TCP/IP NETBIOS HELPER: LmHosts C:\WINDOWS\System32\svchost.exe -k LocalService SSDP DISCOVERY SERVICE: SSDPSRV C:\WINDOWS\System32\svchost.exe -k LocalService WEBCLIENT: WebClient C:\WINDOWS\System32\svchost.exe -k LocalService NORTON ANTIVIRUS AUTO-PROTECT SERVICE: navapsvc "C:\Program Files\Norton AntiVirus\navapsvc.exe" NORTON ANTIVIRUS FIREWALL MONITOR SERVICE: NPFMntor "C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe" IPSEC SERVICES: PolicyAgent C:\WINDOWS\System32\lsass.exe PROTECTED STORAGE: ProtectedStorage C:\WINDOWS\system32\lsass.exe SECURITY ACCOUNTS MANAGER: SamSs C:\WINDOWS\system32\lsass.exe REMOTE PROCEDURE CALL (RPC): RpcSs C:\WINDOWS\system32\svchost -k rpcss PRINT SPOOLER: Spooler C:\WINDOWS\system32\spoolsv.exe WAN MINIPORT (ATW) SERVICE: WANMiniportService "C:\WINDOWS\wanmpsvc.exe" :thumbup: Good luck with the fine service you provide here–too bad I couldn't work this one out to the end with you.
Different variant. If you still want to try, download FxAgentB.exe from here and save it to your desktop. After downloading, double-click the FxAgentB file to run it and the program will scan your entire hard drive - this may take a while. When it is done, it will generate a log file called FxAgentB.log - save that information as you will need to paste it here later. Reboot when done.

Next rescan with CWShredder and AAW.

Reboot when done, rescan with HijackThis and post a new log here, together with the FxAgentB log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI