This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My Son's Computer

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

4th time I've re-installed after MaximOnline gave me CoolWebSearch and About:Blank. This time I'd like to get rid of it. I notice that I don't even HAVE a hosts file now… I ran Ad Aware, SpyBot and Trend Sys Cleaner in safe mode. Then Hijack This: Any Ideas??? Logfile of HijackThis v1.98.2 Scan saved at 11:03:26 PM, on 12/25/2004 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT4\System32\smss.exe C:\WINNT4\system32\winlogon.exe C:\WINNT4\system32\services.exe C:\WINNT4\system32\lsass.exe C:\WINNT4\system32\svchost.exe C:\WINNT4\system32\spoolsv.exe C:\WINNT4\System32\svchost.exe C:\WINNT4\system32\regsvc.exe C:\WINNT4\system32\MSTask.exe C:\WINNT4\System32\WBEM\WinMgmt.exe C:\WINNT4\system32\svchost.exe C:\WINNT4\Explorer.EXE C:\WINNT4\Mixer.exe C:\Program Files\Windows ServeAd\WinServAd.exe C:\Program Files\Windows ServeAd\WinServSuit.exe C:\WINNT4\system32\wuauclt.exe C:\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT4\fbplx.dll/sp.html#28129 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT4\fbplx.dll/sp.html#28129 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT4\fbplx.dll/sp.html#28129 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT4\fbplx.dll/sp.html#28129 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT4\fbplx.dll/sp.html#28129 R3 - Default URLSearchHook is missing O2 - BHO: (no name) - {17E09133-131D-E930-C436-4CE8F9E5D2AC} - C:\WINNT4\javawc32.dll O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT4\System32\msdxm.ocx O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup O4 - HKLM\..\Run: [Windows ServeAd] C:\Program Files\Windows ServeAd\WinServAd.exe O15 - Trusted Zone: *.awmdabest.com Thanks in advance!
Click here to download CWShredder and run it, hit 'fix' as opposed to 'scan only'. Reboot when done.

Click here to download ServiceFilter, a little script by rand1038 that reveals potential unauthorised running services in your system. Download, unzip and double-click ServiceFilter.vbs (you may need to enable your antivirus program to run the file). This script will create a text file named Post_This.txt in the same folder as the script itself has been saved - copy and paste the contents of Post_This.txt in your next reply here.
CW Shredder did not find anything. Service filter reported this: The script did not recognize the services listed below. This does not mean that they are a problem. To copy the entire contents of this document for posting: At the top of this window click "Edit" then "Select All" Next click "Edit" again then "Copy" Now right click in the forum post box then click "Paste" ######################################## ServiceFilter 1.1 by rand1038 Microsoft Windows 2000 Professional Version: 5.0.2195 Service Pack 4 Dec 26, 2004 7:43:26 PM —> Begin Service Listing <— Unknown Service # 1 Service Name: %AF夶À¨ Display Name: Remote Procedure Call (RPC) Helper Start Mode: Auto Start Name: LocalSystem Description: Remote Procedure Call (RPC) … Service Type: Share Process Path: c:\winnt4\system32\msze.exe /s State: Stopped Process ID: 0 Started: False Exit Code: 0 Accept Pause: False Accept Stop: False —> End Service Listing <— There are 56 Win32 services on this machine. 1 were unrecognized. Script Execution Time: 1.007813 seconds. Thanks for helping :wavey:
Print out these instructions as most of the steps need to be done in Safe Mode and you won't be able to go online.

Do this so you can see hidden files and folders - click here to download xphidden.zip. Extract xphidden.reg from the zip file and save it to the desktop. When done, double-click the xphidden.reg and when asked to merge say yes. Click here to download About:Buster and unzip it to your desktop. Don´t run it yet. Also, click here to download System Security Suite. Extract it from the zip file into a folder.

Next, go to Start->Run and type Services.msc then hit Ok. Scroll down and find the service called "Remote Procedure Call (RPC) Helper". When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows.

Reboot into Safe Mode by tapping F8 after the BIOS has loaded.

Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT4\fbplx.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT4\fbplx.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT4\fbplx.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT4\fbplx.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT4\fbplx.dll/sp.html#28129
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {17E09133-131D-E930-C436-4CE8F9E5D2AC} - C:\WINNT4\javawc32.dll
O4 - HKLM\..\Run: [Windows ServeAd] C:\Program Files\Windows ServeAd\WinServAd.exe
O15 - Trusted Zone: *.awmdabest.com


Find and delete the following:

C:\Program Files\Windows ServeAd\ <– folder
c:\winnt4\system32\msze.exe

Now double click AboutBuster.exe that you downloaded earlier. Click Start then click OK. This will scan your computer for the bad files and delete them. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

Rescan with Adaware and let it remove any bad files found.

Reboot back into Normal Mode. Click here to download cwsuninst.zip. Extract cwsuninst.reg from the zip file and save it to the desktop. When done, double-click the cwsuninst.reg and when asked to merge say yes. Open System Security Suite and doubleclick on sss.exe. Check the boxes under the 'Items to Clear' tab and click 'Clear Selected Items'. You will be prompted to reboot, do so. Repeat for all log-in accounts on your computer.

Rescan with HijackThis and post a new log here.
:thumbup: Awesome!!! AboutBuster LogFile: Scanned at: 8:15:14 PM on: 12/30/2004 – Scan 1 ————————— About:Buster Version 4.0 Reference List : 19 Removed Data Streams: C:\WINNT4\cmuninst.dat:sqzqr C:\WINNT4\imsins.BAK:iolke C:\WINNT4\twain.dll:grrkp C:\WINNT4\_default.pif:ewdel Attempted Clean Of Temp folder. Pages Reset… Done! – Scan 2 ————————— About:Buster Version 4.0 Reference List : 19 Removed Data Streams: C:\WINNT4\cmuninst.dat:sqzqr C:\WINNT4\imsins.BAK:iolke C:\WINNT4\twain.dll:grrkp C:\WINNT4\_default.pif:ewdel Attempted Clean Of Temp folder. Pages Reset… Done! ************************************************************** Logfile of HijackThis v1.98.2 Scan saved at 8:31:50 PM, on 12/30/2004 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT4\System32\smss.exe C:\WINNT4\system32\winlogon.exe C:\WINNT4\system32\services.exe C:\WINNT4\system32\lsass.exe C:\WINNT4\system32\svchost.exe C:\WINNT4\system32\spoolsv.exe C:\WINNT4\System32\svchost.exe C:\WINNT4\system32\regsvc.exe C:\WINNT4\system32\MSTask.exe C:\WINNT4\System32\WBEM\WinMgmt.exe C:\WINNT4\system32\svchost.exe C:\WINNT4\Explorer.EXE C:\WINNT4\Mixer.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\WINNT4\system32\wuauclt.exe C:\HijackThis\HijackThis.exe O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT4\System32\msdxm.ocx O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
You're welcome - glad to help :D

To help keep you clean follow the recommendations in Tony's article here:

So how did I get infected in the first place?



As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI