This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My Computer Log @ Work [<ab>]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

IE Homepage HiJacked Please Help.

Logfile of HijackThis v1.99.0
Scan saved at 12:19:59 PM, on 12/17/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINDOWS\crjn32.exe
C:\Tss2000\Tss2000.exe
C:\WINDOWS\SETUPLOG.TXT:lhujp
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\bqkdh.dll/sp.html#32777
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\bqkdh.dll/sp.html#32777
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\bqkdh.dll/sp.html#32777
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\bqkdh.dll/sp.html#32777
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\bqkdh.dll/sp.html#32777
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\bqkdh.dll/sp.html#32777
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\bqkdh.dll/sp.html#32777
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {6EE4E0AD-CA47-9A72-7C18-9CF62AD4C96C} - C:\WINDOWS\system32\crle32.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [crjn32.exe] C:\WINDOWS\crjn32.exe
O4 - HKLM\..\RunOnce: [lhujp] C:\WINDOWS\SETUPLOG.TXT:lhujp
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\TED\Application Data\ttuh.exe
O4 - HKCU\..\Run: [Ruiz] C:\WINDOWS\system32\?hkntfs.exe
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted IP range: (HKLM)
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Macromedia Licensing Service - Unknown - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Workstation NetLogon Service - Unknown - C:\WINDOWS\system32\apitx.exe (file missing)

Thanx
Click here to download CWShredder and run it, hit 'fix' as opposed to 'scan only'. Reboot when done.

Click here to download Spybot Search & Destroy - install, update, scan and fix all RED items it finds. Reboot when done.

Click here to download Ad-Aware SE and install. Before scanning click on "check for updates now" to make sure you have the latest reference file. Click "Start", select "Perform Full System scan" and "Next" to start the scan. When the scan is finished, the screen will tell you if anything has been found, click "Next". The bad files will be listed, right click the pane and click "Select all objects" - this will put a check mark in the box at the side, click "Next" again and click "OK" at the prompt "# objects will be removed. Continue?".

Reboot when done. Rescan with HJT and post a new log here so that any remnants can be removed manually.
Here is my new scan

Logfile of HijackThis v1.99.0
Scan saved at 10:05:56 AM, on 12/20/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\ieqh32.dll:mudvb
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINDOWS\system32\javagh.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {241DEE3C-B08A-3388-53C6-B2DB4CC5C2A6} - C:\WINDOWS\system32\sdkmf.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [javagh.exe] C:\WINDOWS\system32\javagh.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\TED\Application Data\ttuh.exe
O4 - HKCU\..\Run: [Ruiz] C:\WINDOWS\system32\?hkntfs.exe
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted IP range: (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Macromedia Licensing Service - Unknown - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Network Security Service (NSS) - Unknown - C:\WINDOWS\ieqh32.dll:mudvb.exe (file missing)

Thanx
Print out these instructions as most of the steps need to be done in Safe Mode and you won't be able to go online.

Do this so you can see hidden files and folders - click here to download xphidden.zip. Extract xphidden.reg from the zip file and save it to the desktop. When done, double-click the xphidden.reg and when asked to merge say yes. Click here to download About:Buster and unzip it to your desktop. Don´t run it yet. Also, click here to download System Security Suite. Extract it from the zip file into a folder.

Next, go to Start->Run and type Services.msc then hit Ok. Scroll down and find the service called "Network Security Service". When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows.

Reboot into Safe Mode by tapping F8 after the BIOS has loaded.

Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {241DEE3C-B08A-3388-53C6-B2DB4CC5C2A6} - C:\WINDOWS\system32\sdkmf.dll
O4 - HKLM\..\Run: [javagh.exe] C:\WINDOWS\system32\javagh.exe
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\TED\Application Data\ttuh.exe
O4 - HKCU\..\Run: [Ruiz] C:\WINDOWS\system32\?hkntfs.exe
O15 - Trusted IP range: (HKLM)
O23 - Service: Network Security Service (NSS) - Unknown - C:\WINDOWS\ieqh32.dll:mudvb.exe (file missing)

Find and delete the following:

C:\WINDOWS\system32\javagh.exe
C:\WINDOWS\ieqh32.dll:mudvb.exe

Now double click AboutBuster.exe that you downloaded earlier. Click Start then click OK. This will scan your computer for the bad files and delete them. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

Rescan with Adaware and let it remove any bad files found.

Reboot back into Normal Mode. Click here to download cwsuninst.zip. Extract cwsuninst.reg from the zip file and save it to the desktop. When done, double-click the cwsuninst.reg and when asked to merge say yes. Open System Security Suite and doubleclick on sss.exe. Check the boxes under the 'Items to Clear' tab and click 'Clear Selected Items'. You will be prompted to reboot, do so. Repeat for all log-in accounts on your computer.

Rescan with HijackThis and post a new log here.
OK for some reason it would not let me use the User on my comp in Safe mode. It would let me use another one but not the one we normally use. That user is marked as Admin too. IDK

I also could not remove javagh.exe nor could I find the ieqh32.dll:mudvb.exe

so here is the txt file from about buster:

Scanned at: 1:53:01 PM on: 12/20/2004


– Scan 1 —————————
About:Buster Version 4.0
Reference List : 19


Removed Data Streams:
C:\WINDOWS\apiet32.dll:lbred
C:\WINDOWS\appim.exe:uumcl
C:\WINDOWS\BJCFDins.log:utagb
C:\WINDOWS\cmsetacl.log:gefhv
C:\WINDOWS\crcx32.dll:myqwn
C:\WINDOWS\d3qd.dll:czqun
C:\WINDOWS\DELL.BMP:rzufn
C:\WINDOWS\dscew.txt:fblsl
C:\WINDOWS\iun6002.exe:qdmwa
C:\WINDOWS\KB826959.log:eytzt
C:\WINDOWS\OEWABLog.txt:rmbhv
C:\WINDOWS\Q328213.LOG:robaj
C:\WINDOWS\Q329909.LOG:wvtbt
C:\WINDOWS\Q331060.LOG:fjbny
C:\WINDOWS\Q816981.LOG:catxg
C:\WINDOWS\REGLOCS.OLD:xjaiw
C:\WINDOWS\SchedLgU.Txt:iprxl
C:\WINDOWS\sessmgr.setup.log:bmksf
C:\WINDOWS\SETUPERR.LOG:lkekv
C:\WINDOWS\smscfg.ini:dlxpp
C:\WINDOWS\TWAIN.DLL:ephjd
C:\WINDOWS\uninst.exe:xpzox
C:\WINDOWS\vclbde50.bpl:csxjh
C:\WINDOWS\Windows Update.log:yquut
C:\WINDOWS\WINHELP.EXE:jqnhn
C:\WINDOWS\wmsetup.log:rcndw
C:\WINDOWS\xcdunz32.dll:ezvol
C:\WINDOWS\xcdzip32.dll:xxepr


Removed 5 Random Key Entries
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset… Done!

– Scan 2 —————————
About:Buster Version 4.0
Reference List : 19


Removed Data Streams:
C:\WINDOWS\apiet32.dll:lbred
C:\WINDOWS\appim.exe:uumcl
C:\WINDOWS\BJCFDins.log:utagb
C:\WINDOWS\cmsetacl.log:gefhv
C:\WINDOWS\crcx32.dll:myqwn
C:\WINDOWS\d3qd.dll:czqun
C:\WINDOWS\DELL.BMP:rzufn
C:\WINDOWS\dscew.txt:fblsl
C:\WINDOWS\iun6002.exe:qdmwa
C:\WINDOWS\KB826959.log:eytzt
C:\WINDOWS\OEWABLog.txt:rmbhv
C:\WINDOWS\Q328213.LOG:robaj
C:\WINDOWS\Q329909.LOG:wvtbt
C:\WINDOWS\Q331060.LOG:fjbny
C:\WINDOWS\Q816981.LOG:catxg
C:\WINDOWS\REGLOCS.OLD:xjaiw
C:\WINDOWS\SchedLgU.Txt:iprxl
C:\WINDOWS\sessmgr.setup.log:bmksf
C:\WINDOWS\SETUPERR.LOG:lkekv
C:\WINDOWS\smscfg.ini:dlxpp
C:\WINDOWS\TWAIN.DLL:ephjd
C:\WINDOWS\uninst.exe:xpzox
C:\WINDOWS\vclbde50.bpl:csxjh
C:\WINDOWS\Windows Update.log:yquut
C:\WINDOWS\WINHELP.EXE:jqnhn
C:\WINDOWS\wmsetup.log:rcndw
C:\WINDOWS\xcdunz32.dll:ezvol
C:\WINDOWS\xcdzip32.dll:xxepr


Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset… Done!

– Scan 3 —————————
About:Buster Version 4.0
Reference List : 19

No ADS found on system
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset… Done!






Scanned at: 1:53:46 PM on: 12/20/2004


– Scan 1 —————————
About:Buster Version 4.0
Reference List : 19


Removed Data Streams:
C:\WINDOWS\apiet32.dll:lbred
C:\WINDOWS\appim.exe:uumcl
C:\WINDOWS\BJCFDins.log:utagb
C:\WINDOWS\cmsetacl.log:gefhv
C:\WINDOWS\crcx32.dll:myqwn
C:\WINDOWS\d3qd.dll:czqun
C:\WINDOWS\DELL.BMP:rzufn
C:\WINDOWS\dscew.txt:fblsl
C:\WINDOWS\iun6002.exe:qdmwa
C:\WINDOWS\KB826959.log:eytzt
C:\WINDOWS\OEWABLog.txt:rmbhv
C:\WINDOWS\Q328213.LOG:robaj
C:\WINDOWS\Q329909.LOG:wvtbt
C:\WINDOWS\Q331060.LOG:fjbny
C:\WINDOWS\Q816981.LOG:catxg
C:\WINDOWS\REGLOCS.OLD:xjaiw
C:\WINDOWS\SchedLgU.Txt:iprxl
C:\WINDOWS\sessmgr.setup.log:bmksf
C:\WINDOWS\SETUPERR.LOG:lkekv
C:\WINDOWS\smscfg.ini:dlxpp
C:\WINDOWS\TWAIN.DLL:ephjd
C:\WINDOWS\uninst.exe:xpzox
C:\WINDOWS\vclbde50.bpl:csxjh
C:\WINDOWS\Windows Update.log:yquut
C:\WINDOWS\WINHELP.EXE:jqnhn
C:\WINDOWS\wmsetup.log:rcndw
C:\WINDOWS\xcdunz32.dll:ezvol
C:\WINDOWS\xcdzip32.dll:xxepr


Removed 5 Random Key Entries
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset… Done!

– Scan 2 —————————
About:Buster Version 4.0
Reference List : 19


Removed Data Streams:
C:\WINDOWS\apiet32.dll:lbred
C:\WINDOWS\appim.exe:uumcl
C:\WINDOWS\BJCFDins.log:utagb
C:\WINDOWS\cmsetacl.log:gefhv
C:\WINDOWS\crcx32.dll:myqwn
C:\WINDOWS\d3qd.dll:czqun
C:\WINDOWS\DELL.BMP:rzufn
C:\WINDOWS\dscew.txt:fblsl
C:\WINDOWS\iun6002.exe:qdmwa
C:\WINDOWS\KB826959.log:eytzt
C:\WINDOWS\OEWABLog.txt:rmbhv
C:\WINDOWS\Q328213.LOG:robaj
C:\WINDOWS\Q329909.LOG:wvtbt
C:\WINDOWS\Q331060.LOG:fjbny
C:\WINDOWS\Q816981.LOG:catxg
C:\WINDOWS\REGLOCS.OLD:xjaiw
C:\WINDOWS\SchedLgU.Txt:iprxl
C:\WINDOWS\sessmgr.setup.log:bmksf
C:\WINDOWS\SETUPERR.LOG:lkekv
C:\WINDOWS\smscfg.ini:dlxpp
C:\WINDOWS\TWAIN.DLL:ephjd
C:\WINDOWS\uninst.exe:xpzox
C:\WINDOWS\vclbde50.bpl:csxjh
C:\WINDOWS\Windows Update.log:yquut
C:\WINDOWS\WINHELP.EXE:jqnhn
C:\WINDOWS\wmsetup.log:rcndw
C:\WINDOWS\xcdunz32.dll:ezvol
C:\WINDOWS\xcdzip32.dll:xxepr


Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset… Done!

And here is the HijackThis File:

Logfile of HijackThis v1.99.0
Scan saved at 3:40:17 PM, on 12/20/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINDOWS\sysxt32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\ieqh32.dll:mudvb
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {372EF314-6508-92AB-732E-258B08992A73} - C:\WINDOWS\d3tk.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [sysxt32.exe] C:\WINDOWS\sysxt32.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Macromedia Licensing Service - Unknown - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Network Security Service (NSS) - Unknown - C:\WINDOWS\ieqh32.dll:mudvb.exe (file missing)

Thanx
Cory
Still infected - this is a work computer, right? Can you talk to someone in your IT support about getting into Safe Mode and I will post another fix.
I can get into safe mode but the particular user that I saved the other prog. on my desktop. is not on the screen for me to choose form. and I can choose the admin. but those saved items are not on the desktop. IDK.
See we have 3 users on the comp. but only use the one that we are having the problem with. IDK if the others are having problems since we never use them. they are also password protected. So when the comp goes into safe mode then I have to choose a user, the one we are having problems with is not a choice.
Scanned at: 5:23:24 PM on: 12/20/2004


– Scan 1 —————————
About:Buster Version 4.0
Reference List : 19


Removed Data Streams:
C:\WINDOWS\DELL.BMP:rzufn


Removed 4 Random Key Entries
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset… Done!

– Scan 2 —————————
About:Buster Version 4.0
Reference List : 19


Removed Data Streams:
C:\WINDOWS\DELL.BMP:rzufn


Attempted Clean Of Temp folder.
Pages Reset… Done!

– Scan 3 —————————
About:Buster Version 4.0
Reference List : 19

No ADS found on system
Attempted Clean Of Temp folder.
Pages Reset… Done!


Logfile of HijackThis v1.99.0
Scan saved at 5:44:48 PM, on 12/20/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINDOWS\system32\sysog32.exe
C:\WINDOWS\ieqh32.dll:mudvb
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {372EF314-6508-92AB-732E-258B08992A73} - C:\WINDOWS\d3tk.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [sysog32.exe] C:\WINDOWS\system32\sysog32.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Macromedia Licensing Service - Unknown - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Network Security Service (NSS) - Unknown - C:\WINDOWS\ieqh32.dll:mudvb.exe (file missing)
Print out these instructions.

Next, go to Start->Run and type Services.msc then hit Ok. Scroll down and find the service called "Network Security Service". When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows.

Reboot into Safe Mode by tapping F8 after the BIOS has loaded.

Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {372EF314-6508-92AB-732E-258B08992A73} - C:\WINDOWS\d3tk.dll
O4 - HKLM\..\Run: [sysog32.exe] C:\WINDOWS\system32\sysog32.exe
O23 - Service: Network Security Service (NSS) - Unknown - C:\WINDOWS\ieqh32.dll:mudvb.exe (file missing)

Find and delete the following:

C:\WINDOWS\system32\sysog32.exe
C:\WINDOWS\ieqh32.dll:mudvb.exe

Double click AboutBuster.exe. Click Start then click OK. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

Rescan with Adaware and let it remove any bad files found.

Reboot back into Normal Mode. Double-click the cwsuninst.reg and when asked to merge say yes. Open System Security Suite and doubleclick on sss.exe. Check the boxes under the 'Items to Clear' tab and click 'Clear Selected Items'. You will be prompted to reboot, do so. Repeat for all log-in accounts on your computer.

Rescan with HijackThis and post a new log here.
Scanned at: 10:26:23 AM on: 12/22/2004


– Scan 1 —————————
About:Buster Version 4.0
Reference List : 19


Removed Data Streams:
C:\WINDOWS\DELL.BMP:rzufn


Removed 4 Random Key Entries
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset… Done!

– Scan 2 —————————
About:Buster Version 4.0
Reference List : 19


Removed Data Streams:
C:\WINDOWS\DELL.BMP:rzufn


Attempted Clean Of Temp folder.
Pages Reset… Done!

———————————————————————————————–
Logfile of HijackThis v1.99.0
Scan saved at 11:07:55 AM, on 12/22/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lywdl.dll/sp.html#32777
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Macromedia Licensing Service - Unknown - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI