This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

A Lot Of Problems, Please Help

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Control panel, apperances and themes, change the desktop background, desktop, customize desktop, web If that security website has a checkmark beside it uncheck it then delete it.
HMMMMMMMMMMM let me ask a few people and I will hopefully have an answer soon.

In the meantime please do an scan with MicroWorld scanner. Make sure that you choose all directories and files. The scan will take a long time and will not fix any files it finds. When the scan is complete hilight the lower box with the lines in it then ctrl + c and paste them in the thread.

>>>> http://www.mwti.net/antivirus/mwav.asp
File C:\PROGRA~1\mIRC\mirc.exe tagged as not-a-virus:RiskWare.mIRC.6.16. No Action Taken. File C:\WINDOWS\BTGrab.dll infected by "not-a-virus:AdWare.BiSpy.t" Virus. Action Taken: No Action Taken. File C:\WINDOWS\dlmax.dll infected by "not-a-virus:AdWare.BiSpy.t" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\akcore.dll infected by "not-a-virus:AdWare.Coreak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\dsktrf.dll infected by "not-a-virus:AdWare.ToolBar.HotSearchBar.b" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\dsmanager.dll infected by "not-a-virus:AdWare.ToolBar.BHO.j" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\dsmanager32.dll infected by "not-a-virus:AdWare.ToolBar.BHO.j" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\dun.exe infected by "not-a-virus:AdWare.DealHelper.x" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\eitsi.dll infected by "not-a-virus:AdWare.Adstart.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\eitsid.exe infected by "not-a-virus:AdWare.Adstart.i" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\eitsif.exe infected by "not-a-virus:AdWare.Adstart.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\hokqw.dll infected by "not-a-virus:AdWare.Adstart.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\hokqwd.exe infected by "not-a-virus:AdWare.Adstart.b" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\hokqwf.exe infected by "not-a-virus:AdWare.Adstart.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\randreco.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\rk.bin tagged as not-a-virus:RiskWare.Proxy.MarketScore.k. No Action Taken. File C:\WINDOWS\System32\rk.exe tagged as not-a-virus:RiskWare.Proxy.MarketScore.k. No Action Taken. File C:\WINDOWS\System32\wincibk32.exe infected by "not-a-virus:AdWare.ZenoSearch.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\Ydajld.exe infected by "not-a-virus:AdWare.DealHelper.z" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\Temp\adlinstallwin32.exe infected by "not-a-virus:AdWare.Adstart.c" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\Temp\akcore.dll infected by "not-a-virus:AdWare.Coreak" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\Temp\DrTemp\thnall1b.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\Temp\DrTemp\thnall2r.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\Temp\DrTemp\wupdsnff.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\Temp\i48.tmp infected by "not-a-virus:AdWare.SurfSide.a" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\Temp\idcs50202.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\Temp\SskUpdater.exe infected by "not-a-virus:AdWare.TotalVelocity.af" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\Temp\suicidetb.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.z" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\Temp\temp.fr85A4 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\Temp\THI3AC2.tmp\dlmax.cab infected by "not-a-virus:AdWare.BiSpy.t" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\Temp\THI3AC2.tmp\dlmax.dll infected by "not-a-virus:AdWare.BiSpy.t" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\Temp\THI6A3C.tmp\dlmax.cab infected by "not-a-virus:AdWare.BiSpy.t" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\Temp\THI6A3C.tmp\dlmax.dll infected by "not-a-virus:AdWare.BiSpy.t" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\TEMPOR~1\Content.IE5\0K8EXJOD\videox[1].cab infected by "not-a-virus:AdWare.BHO.RedHotNet.a" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\TEMPOR~1\Content.IE5\4Z0X2ZOD\BHO[2].dll infected by "not-a-virus:AdWare.ToolBar.BHO.j" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\TEMPOR~1\Content.IE5\4Z0X2ZOD\Installer[1].exe infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\TEMPOR~1\Content.IE5\4Z0X2ZOD\thnall2r[1].exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\TEMPOR~1\Content.IE5\QVE5IBQV\crazywinningsgame[1].exe infected by "not-a-virus:AdWare.WinShow.f" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\TEMPOR~1\Content.IE5\QVE5IBQV\l2mfix[1].exe tagged as not-a-virus:RiskWare.Tool.Processor.20. No Action Taken. File C:\DOCUME~1\William\LOCALS~1\TEMPOR~1\Content.IE5\WP834Z0D\124488[1].exe infected by "not-a-virus:Porn-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\TEMPOR~1\Content.IE5\WP834Z0D\ddfs[1].chm infected by "Exploit.HTML.CodeBaseExec" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\TEMPOR~1\Content.IE5\WP834Z0D\IEMenuExtension[1].exe infected by "not-a-virus:AdWare.ToolBar.Ucmore.a" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\William\LOCALS~1\TEMPOR~1\Content.IE5\WP834Z0D\MediaTicketsInstaller[1].cab infected by "not-a-virus:AdWare.MediaTickets.f" Virus. Action Taken: No Action Taken.
Download CCleaner from here >>>> http://www.majorgeeks.com/download4191.html

Then open it and click on "run cleaner".

Also empty your recycle bin.

Boot to safe mode and delete these files

C:\WINDOWS\BTGrab.dll
File C:\WINDOWS\dlmax.dll
File C:\WINDOWS\System32\akcore.dll
File C:\WINDOWS\System32\dsktrf.dll
File C:\WINDOWS\System32\dsmanager.dll
File C:\WINDOWS\System32\dsmanager32.dll
File C:\WINDOWS\System32\dun.exe
File C:\WINDOWS\System32\eitsi.dll
File C:\WINDOWS\System32\eitsid.exe
File C:\WINDOWS\System32\eitsif.exe
File C:\WINDOWS\System32\hokqw.dll
File C:\WINDOWS\System32\hokqwd.exe .
File C:\WINDOWS\System32\hokqwf.exe
File C:\WINDOWS\System32\randreco.exe
File C:\WINDOWS\System32\rk.bin
File C:\WINDOWS\System32\rk.exe .
File C:\WINDOWS\System32\wincibk32.exe
File C:\WINDOWS\System32\Ydajld.exe

Then reboot and post a new log.
Logfile of HijackThis v1.99.1
Scan saved at 12:26:46 AM, on 2/24/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\mIRC\mirc.exe
C:\DOCUME~1\William\LOCALS~1\Temp\Rar$EX00.922\HijackThis.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {1C955F3B-5B32-4393-A05D-24B4970CD2A1} (Video Class) - http://streamp.babenet.com/cabs/videox.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/3048786d87f3af…ip/RdxIE601.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
One moer time Go to Start-> Settings -> Control Panel -> Display. Click on the Desktop tab, then the Customize Desktop button. Choose the Web tab. Under the Web Pages listing, there should be an entry named "Security". Highlight that entry then click the Delete button. Click Ok then the Apply button and the Ok button. Then a new microworld scan please.
No, it was still blinking, but what you told me to do with the "Customize Desktop" worked! And yes is working perfect now, thanks for all of your help!
You really need to update both IE & XP.

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI