This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help! Cannot get my computer clean

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 7:47:39 PM, on 5/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Picasa\PicasaMediaDetector.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\atlft32.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\npqzh.dll/sp.html#45052
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\npqzh.dll/sp.html#45052
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\npqzh.dll/sp.html#45052
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\npqzh.dll/sp.html#45052
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\npqzh.dll/sp.html#45052
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\npqzh.dll/sp.html#45052
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\System32\blank.htm
R3 - Default URLSearchHook is missing
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Class - {B6F39436-B55A-8D4D-6E92-1B81D55EBAEF} - C:\WINDOWS\msyx.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [LifeScape Media Detector] C:\Program Files\Picasa\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\mobile PhoneTools\WatchDog.exe
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [FTFTdJ0j3] C:\WINDOWS\bicrotvw.exe
O4 - HKLM\..\Run: [apiwg.exe] C:\WINDOWS\apiwg.exe
O4 - HKLM\..\Run: [appan.exe] C:\WINDOWS\appan.exe
O4 - HKLM\..\Run: [syssy32.exe] C:\WINDOWS\syssy32.exe
O4 - HKLM\..\Run: [addwb.exe] C:\WINDOWS\addwb.exe
O4 - HKLM\..\Run: [addau32.exe] C:\WINDOWS\addau32.exe
O4 - HKLM\..\Run: [apphm32.exe] C:\WINDOWS\system32\apphm32.exe
O4 - HKLM\..\Run: [atlft32.exe] C:\WINDOWS\atlft32.exe
O4 - HKLM\..\RunOnce: [mfcbg32.exe] C:\WINDOWS\system32\mfcbg32.exe
O4 - HKLM\..\RunOnce: [javalo.exe] C:\WINDOWS\javalo.exe
O4 - HKLM\..\RunOnce: [appcb.exe] C:\WINDOWS\appcb.exe
O4 - HKLM\..\RunOnce: [ieyp32.exe] C:\WINDOWS\ieyp32.exe
O4 - HKLM\..\RunOnce: [msil.exe] C:\WINDOWS\system32\msil.exe
O4 - HKLM\..\RunOnce: [ntpf.exe] C:\WINDOWS\system32\ntpf.exe
O4 - HKLM\..\RunOnce: [msup.exe] C:\WINDOWS\system32\msup.exe
O4 - HKLM\..\RunOnce: [XoftSpy] "C:\Program Files\XoftSpy\XoftSpy.exe" -b
O4 - HKLM\..\RunOnce: [netmm32.exe] C:\WINDOWS\netmm32.exe
O4 - HKLM\..\RunOnce: [d3zb.exe] C:\WINDOWS\d3zb.exe
O4 - HKLM\..\RunOnce: [sysss.exe] C:\WINDOWS\system32\sysss.exe
O4 - HKLM\..\RunOnce: [sdkyv.exe] C:\WINDOWS\system32\sdkyv.exe
O4 - HKLM\..\RunOnce: [msoa.exe] C:\WINDOWS\system32\msoa.exe
O4 - HKLM\..\RunOnce: [winfp32.exe] C:\WINDOWS\winfp32.exe
O4 - HKLM\..\RunOnce: [winuk.exe] C:\WINDOWS\system32\winuk.exe
O4 - HKLM\..\RunOnce: [winpb32.exe] C:\WINDOWS\system32\winpb32.exe
O4 - HKLM\..\RunOnce: [ntqp.exe] C:\WINDOWS\ntqp.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: PowerReg Scheduler.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~5\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~5\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1116727646269
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\ntxm32.exe (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
Hello Erikkt, welcome to the forum

Download CW-Shredder at the link below: (don't run it yet)
http://cwshredder.net/bin/CWShredder.exe

Download 'SpSeHjfix'. into a folder. (don't run it yet)

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin


Make sure you know how to boot into - SafeMode

NOTE: This needs to be run twice. It will not work unless you do.
Reboot into safe mode.

Disconnect from the net and Close ALL OPEN PROGRAMS.
Run 'SpSeHjfix'. and click on "Start Disinfection".
When it's finished it will reboot your machine to finish the cleaning process.
The tool creates a log of the fix which will appear in the folder.

Now run the Shredder - Hit The FIX button!

Reboot and repeat the process above.

Reboot and post a fresh HJT log and the log that was created by 'SpSeHjfix'.
Here are the two logs The first one is SpSeHjfix.



(6/4/05 9:01:34 PM) SPSeHjFix started v1.1.2
(6/4/05 9:01:34 PM) OS: WinXP Service Pack 2 (5.1.2600)
(6/4/05 9:01:34 PM) Language: english
(6/4/05 9:01:34 PM) Win-Path: C:\WINDOWS
(6/4/05 9:01:34 PM) System-Path: C:\WINDOWS\system32
(6/4/05 9:01:34 PM) Temp-Path: C:\DOCUME~2\ADMINI~1.000\LOCALS~1\Temp\
(6/4/05 9:01:42 PM) Disinfection started
(6/4/05 9:01:42 PM) Bad-Dll(IEP): c:\windows\scgcy.dll
(6/4/05 9:01:42 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:01:42 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:01:42 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page:
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\scgcy.dll/sp.html#37049
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: res://c:\windows\scgcy.dll/sp.html#37049
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Page_URL: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Search_URL: res://c:\windows\scgcy.dll/sp.html#37049
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: res://c:\windows\scgcy.dll/sp.html#37049
(6/4/05 9:01:42 PM) Stealth-String not found
(6/4/05 9:01:42 PM) No locked Files to delete. End without Reboot
(6/4/05 9:01:59 PM) Disinfection started
(6/4/05 9:01:59 PM) Bad-Dll(IEP): c:\windows\scgcy.dll
(6/4/05 9:01:59 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:01:59 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:01:59 PM) Bad IE-pages: (none)
(6/4/05 9:01:59 PM) Stealth-String not found
(6/4/05 9:01:59 PM) No locked Files to delete. End without Reboot
(6/4/05 9:02:18 PM) Disinfection started
(6/4/05 9:02:18 PM) Bad-Dll(IEP): c:\windows\scgcy.dll
(6/4/05 9:02:18 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:02:18 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:02:18 PM) Bad IE-pages: (none)
(6/4/05 9:02:18 PM) Stealth-String not found
(6/4/05 9:02:18 PM) No locked Files to delete. End without Reboot
(6/4/05 9:02:19 PM) Disinfection started
(6/4/05 9:02:19 PM) Bad-Dll(IEP): c:\windows\scgcy.dll
(6/4/05 9:02:19 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:02:19 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:02:19 PM) Bad IE-pages: (none)
(6/4/05 9:02:19 PM) Stealth-String not found
(6/4/05 9:02:19 PM) No locked Files to delete. End without Reboot
(6/4/05 9:03:47 PM) Disinfection started
(6/4/05 9:03:47 PM) Bad-Dll(IEP): c:\windows\scgcy.dll
(6/4/05 9:03:47 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:03:47 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:03:47 PM) Bad IE-pages: (none)
(6/4/05 9:03:47 PM) Stealth-String not found
(6/4/05 9:03:47 PM) No locked Files to delete. End without Reboot
(6/4/05 9:03:48 PM) Disinfection started
(6/4/05 9:03:48 PM) Bad-Dll(IEP): c:\windows\scgcy.dll
(6/4/05 9:03:48 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:03:48 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:03:48 PM) Bad IE-pages: (none)
(6/4/05 9:03:48 PM) Stealth-String not found
(6/4/05 9:03:48 PM) No locked Files to delete. End without Reboot
(6/4/05 9:03:48 PM) Disinfection started
(6/4/05 9:03:48 PM) Bad-Dll(IEP): c:\windows\scgcy.dll
(6/4/05 9:03:48 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:03:48 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:03:48 PM) Bad IE-pages: (none)
(6/4/05 9:03:48 PM) Stealth-String not found
(6/4/05 9:03:48 PM) No locked Files to delete. End without Reboot
(6/4/05 9:03:49 PM) Disinfection started
(6/4/05 9:03:49 PM) Bad-Dll(IEP): c:\windows\scgcy.dll
(6/4/05 9:03:49 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:03:49 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:03:49 PM) Bad IE-pages: (none)
(6/4/05 9:03:49 PM) Stealth-String not found
(6/4/05 9:03:49 PM) No locked Files to delete. End without Reboot


(6/4/05 9:05:44 PM) SPSeHjFix started v1.1.2
(6/4/05 9:05:44 PM) OS: WinXP Service Pack 2 (5.1.2600)
(6/4/05 9:05:44 PM) Language: english
(6/4/05 9:05:44 PM) Win-Path: C:\WINDOWS
(6/4/05 9:05:44 PM) System-Path: C:\WINDOWS\system32
(6/4/05 9:05:44 PM) Temp-Path: C:\DOCUME~2\ADMINI~1.000\LOCALS~1\Temp\
(6/4/05 9:05:48 PM) Disinfection started
(6/4/05 9:05:48 PM) Bad-Dll(IEP): (not found)
(6/4/05 9:05:48 PM) Bad-Dll(IEP) in BHO: (not found)
(6/4/05 9:05:48 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:05:48 PM) UBF: 5 - UBB: 0 - UBR: 5
(6/4/05 9:05:48 PM) Bad IE-pages: (none)
(6/4/05 9:05:48 PM) Stealth-String not found
(6/4/05 9:05:48 PM) Not infected->END


(6/4/05 9:10:21 PM) SPSeHjFix started v1.1.2
(6/4/05 9:10:21 PM) OS: WinXP Service Pack 2 (5.1.2600)
(6/4/05 9:10:21 PM) Language: english
(6/4/05 9:10:21 PM) Win-Path: C:\WINDOWS
(6/4/05 9:10:21 PM) System-Path: C:\WINDOWS\system32
(6/4/05 9:10:21 PM) Temp-Path: C:\DOCUME~2\ADMINI~1.000\LOCALS~1\Temp\
(6/4/05 9:10:23 PM) Disinfection started
(6/4/05 9:10:23 PM) Bad-Dll(IEP): (not found)
(6/4/05 9:10:23 PM) Bad-Dll(IEP) in BHO: (not found)
(6/4/05 9:10:23 PM) UBF: 5 - UBB: 1 - UBR: 5
(6/4/05 9:10:23 PM) UBF: 5 - UBB: 1 - UBR: 5
(6/4/05 9:10:23 PM) Bad IE-pages: (none)
(6/4/05 9:10:23 PM) Stealth-String not found
(6/4/05 9:10:23 PM) Not infected->END


(6/4/05 9:18:22 PM) SPSeHjFix started v1.1.2
(6/4/05 9:18:22 PM) OS: WinXP Service Pack 2 (5.1.2600)
(6/4/05 9:18:22 PM) Language: english
(6/4/05 9:18:22 PM) Win-Path: C:\WINDOWS
(6/4/05 9:18:22 PM) System-Path: C:\WINDOWS\system32
(6/4/05 9:18:22 PM) Temp-Path: C:\DOCUME~2\Erik.JIM\LOCALS~1\Temp\
(6/4/05 9:18:25 PM) Disinfection started
(6/4/05 9:18:25 PM) Bad-Dll(IEP): c:\windows\scgcy.dll
(6/4/05 9:18:25 PM) UBF: 5 - UBB: 0 - UBR: 4
(6/4/05 9:18:25 PM) UBF: 5 - UBB: 0 - UBR: 4
(6/4/05 9:18:25 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\scgcy.dll/sp.html#37049
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: res://c:\windows\scgcy.dll/sp.html#37049
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
(6/4/05 9:18:25 PM) Stealth-String not found
(6/4/05 9:18:25 PM) No locked Files to delete. End without Reboot
(6/4/05 9:18:30 PM) Disinfection started
(6/4/05 9:18:30 PM) Bad-Dll(IEP): c:\windows\scgcy.dll
(6/4/05 9:18:30 PM) UBF: 5 - UBB: 0 - UBR: 4
(6/4/05 9:18:30 PM) UBF: 5 - UBB: 0 - UBR: 4
(6/4/05 9:18:30 PM) Bad IE-pages: (none)
(6/4/05 9:18:30 PM) Stealth-String not found
(6/4/05 9:18:30 PM) No locked Files to delete. End without Reboot
(6/4/05 9:18:30 PM) Disinfection started
(6/4/05 9:18:30 PM) Bad-Dll(IEP): c:\windows\scgcy.dll
(6/4/05 9:18:30 PM) UBF: 5 - UBB: 0 - UBR: 4
(6/4/05 9:18:30 PM) UBF: 5 - UBB: 0 - UBR: 4
(6/4/05 9:18:30 PM) Bad IE-pages: (none)
(6/4/05 9:18:30 PM) Stealth-String not found
(6/4/05 9:18:30 PM) No locked Files to delete. End without Reboot


(6/4/05 9:19:05 PM) SPSeHjFix started v1.1.2
(6/4/05 9:19:05 PM) OS: WinXP Service Pack 2 (5.1.2600)
(6/4/05 9:19:05 PM) Language: english
(6/4/05 9:19:05 PM) Win-Path: C:\WINDOWS
(6/4/05 9:19:05 PM) System-Path: C:\WINDOWS\system32
(6/4/05 9:19:05 PM) Temp-Path: C:\DOCUME~2\Erik.JIM\LOCALS~1\Temp\
(6/4/05 9:19:08 PM) Disinfection started
(6/4/05 9:19:08 PM) Bad-Dll(IEP): (not found)
(6/4/05 9:19:08 PM) Bad-Dll(IEP) in BHO: (not found)
(6/4/05 9:19:08 PM) UBF: 5 - UBB: 0 - UBR: 4
(6/4/05 9:19:08 PM) UBF: 5 - UBB: 0 - UBR: 4
(6/4/05 9:19:08 PM) Bad IE-pages: (none)
(6/4/05 9:19:08 PM) Stealth-String not found
(6/4/05 9:19:08 PM) Not infected->END

Here is HJT Log
Logfile of HijackThis v1.99.1
Scan saved at 9:20:06 PM, on 6/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\sdkgp.exe
C:\Program Files\Picasa\PicasaMediaDetector.exe
C:\WINDOWS\system32\winud32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\scgcy.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\scgcy.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\scgcy.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\scgcy.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\scgcy.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\scgcy.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {FFB59007-30E2-88D1-986B-566D8510B4B3} - C:\WINDOWS\ieba.dll
O4 - HKLM\..\Run: [LifeScape Media Detector] C:\Program Files\Picasa\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [FTFTdJ0j3] C:\WINDOWS\bicrotvw.exe
O4 - HKLM\..\Run: [winud32.exe] C:\WINDOWS\system32\winud32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: PowerReg Scheduler.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~5\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~5\OFFICE11\REFIEBAR.DLL
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1116727646269
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\sdkgp.exe" /s (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
1.click Start> Run> type in CMD tap enter. Copy/Paste the following into command prompt:

sc delete 11Fßä#·ºÄÖ`I

At the command prompt: type exit.


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\scgcy.dll/sp.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\scgcy.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\scgcy.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\scgcy.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\scgcy.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\scgcy.dll/sp.html#37049

R3 - Default URLSearchHook is missing

O2 - BHO: Class - {FFB59007-30E2-88D1-986B-566D8510B4B3} - C:\WINDOWS\ieba.dll

O4 - HKLM\..\Run: [FTFTdJ0j3] C:\WINDOWS\bicrotvw.exe

O4 - HKLM\..\Run: [winud32.exe] C:\WINDOWS\system32\winud32.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - Startup: PowerReg Scheduler.exe

O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\sdkgp.exe" /s (file missing)


Close ALL windows and browsers except HijackThis and click "Fix checked"



Restart in Safe Mode:
Restart your computer.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.


Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.




Search for and delete these files if listed:
C:\WINDOWS\bicrotvw.exe
C:\WINDOWS\system32\winud32.exe


Open C:\Windows\Prefetch\ Delete ALL files in this folder.


Do this also if these Temp Folders are part of your OS.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


Next navigate to the C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty the Recycle Bin

Reboot

Click the link. Save, Install, Update and do a Full Scan.
http://free.grisoft.com/softw/70free/setup…ree_323a539.exe



Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Homepage still getting hijacked. Downloaded AVG ran it found 127 trojan horses! This is the log after ran AVG and rebooted.

Logfile of HijackThis v1.99.1
Scan saved at 12:32:12 AM, on 6/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Picasa\PicasaMediaDetector.exe
C:\WINDOWS\system32\winud32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\sdkgp.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\system32\devldr32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\tlfsf.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\tlfsf.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\tlfsf.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\tlfsf.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\tlfsf.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\tlfsf.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {67A172FD-EC42-BB28-B86A-BCD05A1CA484} - C:\WINDOWS\system32\mssy32.dll
O4 - HKLM\..\Run: [LifeScape Media Detector] C:\Program Files\Picasa\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [winud32.exe] C:\WINDOWS\system32\winud32.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~5\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~5\OFFICE11\REFIEBAR.DLL
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1116727646269
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\sdkgp.exe" /s (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
First of all I need you to download some programs for use later.

Download this file and unzip it to your desktop

Download About:Buster from here. Once it is downloaded extract it to c:\aboutbuster and check for updates. Do NOT use it yet

Download CWShredder from here, install it, check for updates but again, don't use it yet.

Then, Download Ad-aware Second Edition here and install it. If you already have Ad-aware Second Edition skip to the next step.

Open adaware and Click the "Check for updates now" line on the main screen. CLick the "Connect" button on the webupdate screen.

If an update is available download it and install it. Click the "Finish" button to go back to the main screen.

Click on the "Settings" button (gear symbol in the upper right corner of the main status screen) in the quick launch toolbar to open the General settings screen. Check the "Automatically quarantine objects prior to removal" setting and then click "Proceed" to save your changes

Click the "Scan now" button in the main menu on the left side of the main status screen or use the "Start" button in lower right corner. This will open the Preparing System Scan screen. Please deselect "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat. Then select "Use custom scanning options" and click "CUstomize". This will open the "Scan Settings Page. Make sure all of the following are On with a "green" checkmark:

Scan within archives
Scan active processes
Scan Registry
Deep-scan Registry
Scan my IE Favorites for banned URLs
Scan my Hosts File

Then click on the "Tweak" Button to open up the tweak settings.

Open up the Scanning Engine section and make sure all of the following are On with a "green" checkmark:

Scan registry for all users instead of current user only

Make sure the following is unchecked with a "red" X:

Unload recognized processes & modules during scan.

Open up the Cleaning Engine section and make sure all of the following are On with a "green" checkmark:

Always try to unload modules before deletion
During Removal, unload Explorer and IE if necessary
Let Windows remove files in use at next reboot.

Click the "Proceed" button to save settings.

Don't scan yet. We will do it in safe mode.

Ensure hidden files and folders are set to show;
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Next, go to Start->Run and type "Services.msc" (without quotes) then hit Ok

Scroll down and find the service called . When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows.

Please disconnect from the Internet and unplug your modem for the duration of this fix You may want to print the rest of these instructions.

Reboot your computer into Safe Mode by tapping F8 while booting up and continue for the rest of the fix in SAFE MODE

While in safe mode, double click on the cwsserviceemove.reg file you downloaded at the beginning. Grant it permission to add the registry items.

Then Open cwshredder that you downloaded in the first step. Close all browser windows and click on the fix/next button.

Bring up task manager Ctrl-Alt-Del and end these processes if they are present

winud32.exe


Now find and delete these files, if you can't find one then don't worry.. just move on to the next one.

C:\WINDOWS\system32\winud32.exe

Now run hijackthis and click the scan button, when it has finished scanning put a check against the following and click 'fix checked'

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\tlfsf.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\tlfsf.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\tlfsf.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\tlfsf.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\tlfsf.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\tlfsf.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {67A172FD-EC42-BB28-B86A-BCD05A1CA484} - C:\WINDOWS\system32\mssy32.dll
O4 - HKLM\..\Run: [winud32.exe] C:\WINDOWS\system32\winud32.exe
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\sdkgp.exe" /s (file missing


The following step is important as you may have several malware files in your temp directories.

Then browse to the C:\documents and settings\Your User Name (repeat for all other user names in documents and settings)\local settings\temp folder and delete all files and folders in it.
Then browse to the C:\Window\Temp folder and delete all files and folders in it.
Then in internet explore click tools>internet Options>General. Click on Delete Files make sure you get all offline content as well.

Now navigate to the c:\aboutbuster directory and double-click on aboutbuster.exe When the tool is open press the OK button, then the Start button, then the OK button, and then finally the Yes button. It will start scanning your computer for files. If it asks if you would like to do a second pass, allow it to do so. Post the log file in your next reply.

Scan with Adaware by opening it and clicking the "Next" button to start the scan.

When the scan is completed the Performing System Scan screen will change name to "Scan Complete".

Click the "Next" button to get to the Scanning Results screens where more information about the objects detected during the scan is available.

Click the Critical Objects Tab. In general all of the items listed will be bad. Be carefull with the Hosts file entries. Malware uses the hosts file to redirect you websites. However you can use the hosts file as a way to prevent malware. If the object has 127.0.0.1 in it, it should most likely not be deleted as it is protecting against unwanted sites. For more information on how to use a host file to protect yourself read here. So in short, you may or may not want to fix the hosts file entries.

To fix all the bad critical objects do the following:

Right click on one of them to open up the selection screen. Click the "Select All" button to select all entries. In general all should be selected with the exception of the good hosts file entries.

When all are selected Click "Next" and then "OK" in the pop-up window to confirm the removal.

Now reboot,and run hijackthis again and post a fresh log along with the about buster log. :)
Help i do not think this is right i cannot find this in services section (insert service name here) Next, go to Start->Run and type "Services.msc" (without quotes) then hit Ok Scroll down and find the service called . When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows.
Everything seems to be fast and smooth no popups no redirects explorer opens fast home page stays. I am very very grateful for all your help thank you!! Erikkt.
Here are the 2 logs
Logfile of HijackThis v1.99.1
Scan saved at 11:11:00 PM, on 6/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Picasa\PicasaMediaDetector.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ywibo.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ywibo.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [LifeScape Media Detector] C:\Program Files\Picasa\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~5\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~5\OFFICE11\REFIEBAR.DLL
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1116727646269
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe



Here is the Aboutbuster log


AboutBuster 5.0 reference file 28
Scan started on [6/5/2005] at [10:32:17 PM]
————————————————
Removed Stream! C:\WINDOWS\_default.pif:mqmvz
Removed Stream! C:\WINDOWS\_default.pif:muvicw
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 10:33:20 PM


AboutBuster 5.0 reference file 28
Scan started on [6/5/2005] at [10:34:22 PM]
————————————————
Removed Stream! C:\WINDOWS\_default.pif:mvkzs
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 10:35:08 PM


AboutBuster 5.0 reference file 28
Scan started on [6/5/2005] at [10:35:19 PM]
————————————————
Removed Stream! C:\WINDOWS\_default.pif:ncceri
Removed Stream! C:\WINDOWS\_default.pif:ncduq
Removed Stream! C:\WINDOWS\_default.pif:nyfnaq
Removed Stream! C:\WINDOWS\_default.pif:oqbfmg
Removed Stream! C:\WINDOWS\_default.pif:pcmiuk
Removed Stream! C:\WINDOWS\_default.pif:pdhsr
Removed Stream! C:\WINDOWS\_default.pif:pjdik
Removed Stream! C:\WINDOWS\_default.pif:pnlraq
Removed Stream! C:\WINDOWS\_default.pif:pzoqac
Removed Stream! C:\WINDOWS\_default.pif:reudqo
Removed Stream! C:\WINDOWS\_default.pif:reycqf
Removed Stream! C:\WINDOWS\_default.pif:tucdim
Removed Stream! C:\WINDOWS\_default.pif:tudfmo
Removed Stream! C:\WINDOWS\_default.pif:uwkscf
Removed Stream! C:\WINDOWS\_default.pif:vixnd
Removed Stream! C:\WINDOWS\_default.pif:vpfmrw
Removed Stream! C:\WINDOWS\_default.pif:wbbuaz
Removed Stream! C:\WINDOWS\_default.pif:wheydw
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 10:36:08 PM


AboutBuster 5.0 reference file 28
Scan started on [6/5/2005] at [10:36:21 PM]
————————————————
Removed Stream! C:\WINDOWS\_default.pif:xyvdya
Removed Stream! C:\WINDOWS\_default.pif:xyzhm
Removed Stream! C:\WINDOWS\_default.pif:ycrimg
Removed Stream! C:\WINDOWS\_default.pif:ydnwod
Removed Stream! C:\WINDOWS\_default.pif:yrhhwr
Removed Stream! C:\WINDOWS\_default.pif:yxgwj
Removed Stream! C:\WINDOWS\_default.pif:yzgfso
Removed Stream! C:\WINDOWS\_default.pif:zmzjyx
Removed Stream! C:\WINDOWS\_default.pif:zvadu
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 10:37:08 PM


AboutBuster 5.0 reference file 28
Scan started on [6/5/2005] at [10:37:18 PM]
————————————————
Removed Stream! C:\WINDOWS\_default.pif:zwfnh
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 10:38:05 PM


AboutBuster 5.0 reference file 28
Scan started on [6/5/2005] at [10:38:11 PM]
————————————————
No Ads Found!
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 10:38:58 PM


AboutBuster 5.0 reference file 28
Scan started on [6/5/2005] at [10:39:05 PM]
————————————————
No Ads Found!
————————————————
No Files Found!
————————————————
Scan was ABORTED at 10:39:08 PM


AboutBuster 5.0 reference file 28
Scan started on [6/5/2005] at [11:07:53 PM]
————————————————
No Ads Found!
————————————————
No Files Found!
————————————————
Scan was ABORTED at 11:07:58 PM
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ywibo.dll/sp.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ywibo.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

R3 - Default URLSearchHook is missing

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background


Close ALL windows and browsers except HijackThis and click "Fix checked"


Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Computer Starts up fast nothing funny seems to be going on explorer is back to normal. I do not know what happened I never had a problem like that. I use Symantec antivirus corporate edition and ad-aware and i don't think i ever had a virus/malware/adware problem now I had this I was going out of my mind! Thanks again very much Erikkt
Here is the latest log


Logfile of HijackThis v1.99.1
Scan saved at 10:14:39 PM, on 6/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Picasa\PicasaMediaDetector.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://woodtv.com/
O4 - HKLM\..\Run: [LifeScape Media Detector] C:\Program Files\Picasa\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~5\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~5\OFFICE11\REFIEBAR.DLL
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1116727646269
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

I do not know what happened I never had a problem like that. I use Symantec antivirus corporate edition and ad-aware and i don't think i ever had a virus/malware/adware problem now I had this I was going out of my mind!

We're all having problems keeping up with the bad guys, but we're trying :D

Good Job :thumbup:

Log looks good :D

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Click Start> My Computer, select the Tools menu and then Folder Options, after the new window appears select the View tab…]
This time select the: Restore Defaults
Select: Apply, and click OK




If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI