This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

About:blank hijack

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hmmph! It happened to me :(. Below is my hijackthis log, but first a little background.

XP Pro w/automatic updates, Norton AV, Zonealarm, Ad-Aware, Spybot S&D, and occassional trips to Trendmicro's Housecall didn't protect me.

AdAware & Spybot keep finding similar items (including coolwebsearch and about:blank) and I delete them, but they don't clean the real culprit. I'm pretty up to date on files that should be in registry/startup/etc., but every time I delete what shouldn't be there, it comes back so there's something there that I can't figure out. Anyways, any help would be appreciated, so here's my log:

Logfile of HijackThis v1.99.1
Scan saved at 9:18:53 PM, on 6/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Folding@Home\fah502-console.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\Program Files\Folding@Home\FahCore_78.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\javavk.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\SYSTEM32\DRIVERS\etc\service.exe
C:\WINDOWS\SYSTEM32\DRIVERS\etc\system.exe
C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe
C:\Program Files\SOYO\HW Monitor\Itesmart.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Navnt\navapw32.exe
C:\WINDOWS\system32\windj.exe
C:\PROGRA~1\Navnt\alertsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Miket\Desktop\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ukbkg.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ukbkg.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ukbkg.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ukbkg.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ukbkg.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ukbkg.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {8D24EEA0-CCFD-2662-E69E-084B8B29DD85} - C:\WINDOWS\sdkvc.dll
O2 - BHO: Class - {C35AADB0-FE0C-8B29-3DF2-80B00335B70D} - C:\WINDOWS\cryy32.dll
O2 - BHO: Class - {E4EDC898-7094-9C0B-426A-F49CDE0BAD64} - C:\WINDOWS\msbx32.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [javavk.exe] C:\WINDOWS\javavk.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [h3yb0y] C:\WINDOWS\SYSTEM32\DRIVERS\etc\LSASS.exe C:\WINDOWS\SYSTEM32\DRIVERS\etc\service.exe C:\WINDOWS\SYSTEM32\DRIVERS\etc\conf.dll
O4 - HKLM\..\Run: [h3yb0y1] C:\WINDOWS\SYSTEM32\DRIVERS\etc\LSASS.exe C:\WINDOWS\SYSTEM32\DRIVERS\etc\system.exe C:\WINDOWS\SYSTEM32\DRIVERS\etc\serv-u.ini
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VGAUtil] C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe
O4 - HKLM\..\Run: [SmartGuardian] C:\Program Files\SOYO\HW Monitor\Itesmart.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097722582796
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\windj.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: FAH@C:+Program Files+Folding@Home+fah502-console - Unknown owner - C:\Program.exe (file missing)
O23 - Service: NAV Alert - Symantec Corporation - C:\PROGRA~1\Navnt\alertsvc.exe
O23 - Service: NAV Auto-Protect - Symantec Corporation - C:\PROGRA~1\Navnt\navapsvc.exe
O23 - Service: Norton Program Scheduler - Symantec Corporation - C:\PROGRA~1\Navnt\npssvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Thanks.

Mike.
EuroStyle, please don't post in other's HJT logs :thumbup:


Hello fishmahn, welcome to the TC.

Please save these instructions to a text file in Wordpad or print them out because we will be restarting in Safe Mode and you will have no Internet Connection
  • Download CWShredder.
  • Save CWShredder.exe to a convenient location.
  • Please Do Not Use It Yet.
  • Download AboutBuster.
  • Unzip AboutBuster.zip and it will install in it's own folder.
  • Double-click on AboutBuster.exe and then click 'OK' then 'Update'
  • Click "Check For Update" and then "Download Update".
  • Click "Exit"
  • Please Do Not Use It Yet.
Disconnect From The Internet

Boot into Safe Mode:
Restart your computer and tap F8 repeatedly while booting up and choose Safe Mode at the menu.

In Safe Mode Please Clean with CWShredder
  • Please Double-click on CWShredder.exe.
  • Click "Fix ->" and click "OK" at the prompt.
  • CWShredder will scan and clean your system of CWS files.
  • Click "Next->" and then "Exit".
In Safe Mode Please Use AboutBuster
  • Please Double-click on AboutBuster.exe.
  • Click "OK" then "Start" and then "OK" to allow AboutBuster to scan for all bad files.
  • Click "Yes" when About Buster asks if you will allow it to shutdown explorer.exe.
  • Allow AboutBuster to scan for all malicious files.
  • Repeat the scan if it asks to do another.
  • After the scan, click "Save Log". Post the log in your next post as it is necessary to make sure all has been cleaned
  • Then Click "Exit"
This infection often deletes necessary system files.
Reboot your computer back into normal mode so that we can see if any files need to be restored.
  • This infection deletes the windows file, shell.dll.

    If you are using XP,2000, or NT please download shell.dll from here: shell-dll.zip. Once the file is downloaded uncompress the zip file and copy shell.dll to the following locations:
    C:\Windows\system32
    C:\Windows\system


    If you are using Windows 98/ME please download shell.dll from here: shell98-dll.zip. Once the file is downloaded uncompress the zip file and copy shell.dll to the following locations
    C:\Windows\system
  • Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original deleted Hosts file.
  • If you have Spybot S&D installed you will also need to replace one file. Go here: Merijn's Files (sdhelper) and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy). Then click Start > Run > regsvr32 "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" and press the OK button
  • If you are using Windows 95, 98, or ME it is possible that the malware deleted your control.exe. Please check for the existence of this file by going to to Merijn Files control.exe and examine where the file should be for your operating system. If the file is missing then download the appropriate file and place it in the proper place according to this information.
  • There are several other files that are not targeted as often as the above, but new copies of them can be downloaded from
    Merijn Files
Online Antivirus Scan
  • Please go to The TrendMicro Housecall website.
  • Allow it to scan and fix anything that it finds.
  • Please Clean out temporary files:
  • Start> Run> then type cleanmgr and click enter
  • Please put a check mark beside Temporary Files, Temporary Internet Files, and Recycle Bin
  • Let cleanmgr scan your system and remove the files indicated
Reboot and Post a New HijackThis Log and your About Buster Log in this thread, using Add Reply to see what is left to clean.
I did all that was posted, but:

Shell.dll already existed in both locations, with a date of 3/31/2003, just like the rest of the WinXP system files, so I made the (hopefully correct) assumption that it was a good copy.

Merjin's site didn't have a copy of SDHelper.dll (or at least I didn't see it), and I know it doesn't exist in the SpybotS&D folder. Should I reinstall, or just search out a copy via google?

Here's the aboutbuster log:

AboutBuster 5.0 reference file 30
Scan started on [7/1/2005] at [6:05:42 PM]
————————————————
Removed Stream! C:\WINDOWS\abiuninst.htm:afxawq
Removed Stream! C:\WINDOWS\abiuninst.htm:vfpolu
Removed Stream! C:\WINDOWS\abiuninst.htm:ybhpyn
Removed Stream! C:\WINDOWS\Blue Lace 16.bmp:iytcut
Removed Stream! C:\WINDOWS\bootstat.dat:sfhora
Removed Stream! C:\WINDOWS\clock.avi:ziwurw
Removed Stream! C:\WINDOWS\control.ini:sboztg
Removed Stream! C:\WINDOWS\DirectX.log:mhsimz
Removed Stream! C:\WINDOWS\DUMP40f1.tmp:wbncvn
Removed Stream! C:\WINDOWS\DUMP4b22.tmp:ebiffb
Removed Stream! C:\WINDOWS\DUMP4b22.tmp:wilnob
Removed Stream! C:\WINDOWS\EAConfigInfo.txt:jsdrtz
Removed Stream! C:\WINDOWS\ehcco.log:kalms
Removed Stream! C:\WINDOWS\FaxSetup.log:btnwnk
Removed Stream! C:\WINDOWS\iis6.log:kztbgd
Removed Stream! C:\WINDOWS\imsins.BAK:bogmxq
Removed Stream! C:\WINDOWS\KB823182.log:sbmoxp
Removed Stream! C:\WINDOWS\KB824105.log:hawtdd
Removed Stream! C:\WINDOWS\KB828035.log:djeuve
Removed Stream! C:\WINDOWS\KB828741.log:cpkoes
Removed Stream! C:\WINDOWS\KB833998.log:ntmtu
Removed Stream! C:\WINDOWS\KB833998.log:urdslo
Removed Stream! C:\WINDOWS\KB834707.log:yvuvdb
Removed Stream! C:\WINDOWS\KB835732.log:iawget
Removed Stream! C:\WINDOWS\KB837001.log:uqctgd
Removed Stream! C:\WINDOWS\KB840374.log:bbplyw
Removed Stream! C:\WINDOWS\KB842773.log:iwmzvw
Removed Stream! C:\WINDOWS\kwv2.dat:yupmq
Removed Stream! C:\WINDOWS\mfyon.dat:ggyasj
Removed Stream! C:\WINDOWS\NeroDigital.ini:qihqcu
Removed Stream! C:\WINDOWS\netdet.ini:hvqbby
Removed Stream! C:\WINDOWS\netdet.ini:wfmnhi
Removed Stream! C:\WINDOWS\ntbtlog.txt:nzqsal
Removed Stream! C:\WINDOWS\ocgen.log:dkmpmc
Removed Stream! C:\WINDOWS\ocgen.log:ogcti
Removed Stream! C:\WINDOWS\ocmsn.log:sdizqn
Removed Stream! C:\WINDOWS\ODBC.INI:gqnaaa
Removed Stream! C:\WINDOWS\ODBCINST.INI:hhuykc
Removed Stream! C:\WINDOWS\OEWABLog.txt:nuona
Removed Stream! C:\WINDOWS\ogcti.dat:zrffcc
Removed Stream! C:\WINDOWS\oobeact.log:qtaeru
Removed Stream! C:\WINDOWS\Prairie Wind.bmp:zhfmfm
Removed Stream! C:\WINDOWS\Q327979.log:busrmf
Removed Stream! C:\WINDOWS\Q814995.log:yvsyw
Removed Stream! C:\WINDOWS\Q828026.log:prjrsi
Removed Stream! C:\WINDOWS\Q828026.log:wcuero
Removed Stream! C:\WINDOWS\Quicktools.INI:nusrp
Removed Stream! C:\WINDOWS\regopt.log:ivgryy
Removed Stream! C:\WINDOWS\regopt.log:pdqvve
Removed Stream! C:\WINDOWS\Rhododendron.bmp:ewohkc
Removed Stream! C:\WINDOWS\River Sumida.bmp:gkmbhl
Removed Stream! C:\WINDOWS\River Sumida.bmp:icjyku
Removed Stream! C:\WINDOWS\River Sumida.bmp:mlwmop
Removed Stream! C:\WINDOWS\rjxmr.txt:dsjxfu
Removed Stream! C:\WINDOWS\rjxmr.txt:vdyqyd
Removed Stream! C:\WINDOWS\roegk.log:wxhuem
Removed Stream! C:\WINDOWS\Santa Fe Stucco.bmp:mlywnf
Removed Stream! C:\WINDOWS\Santa Fe Stucco.bmp:qpglhs
Removed Stream! C:\WINDOWS\Santa Fe Stucco.bmp:tzmdtr
Removed Stream! C:\WINDOWS\sbnqg.log:pxrzyp
Removed Stream! C:\WINDOWS\SchedLgU.Txt:ylfgcn
Removed Stream! C:\WINDOWS\schedule.ini:adulee
Removed Stream! C:\WINDOWS\schedule.ini:jqyybc
Removed Stream! C:\WINDOWS\setupact.log:gtniup
Removed Stream! C:\WINDOWS\setupapi.log.0.old:vymsgj
Removed Stream! C:\WINDOWS\setupapi.log.0.old:wxfgya
Removed Stream! C:\WINDOWS\setuperr.log:igkqhx
Removed Stream! C:\WINDOWS\SIERRA.INI:uvktbh
Removed Stream! C:\WINDOWS\Soap Bubbles.bmp:hzyhmw
Removed Stream! C:\WINDOWS\spupdsvc.log:knqftd
Removed Stream! C:\WINDOWS\Sti_Trace.log:nwvywr
Removed Stream! C:\WINDOWS\svcpack.log:cfikvg
Removed Stream! C:\WINDOWS\SYMEVENT.LOG:jviglm
Removed Stream! C:\WINDOWS\SYSTEM.001:oasomj
Removed Stream! C:\WINDOWS\tabletoc.log:mgbqpq
Removed Stream! C:\WINDOWS\tmp.hta:rwezal
Removed Stream! C:\WINDOWS\tsoc.log:fhldsb
Removed Stream! C:\WINDOWS\vbaddin.ini:ehdig
Removed Stream! C:\WINDOWS\vbaddin.ini:jctbtt
Removed Stream! C:\WINDOWS\vbaddin.ini:kwwfdv
Removed Stream! C:\WINDOWS\Windows Update.log:jrjboz
Removed Stream! C:\WINDOWS\wininit.ini:xgchdb
Removed Stream! C:\WINDOWS\winnt.bmp:tzltpc
Removed Stream! C:\WINDOWS\winnt.bmp:vzwxck
Removed Stream! C:\WINDOWS\winnt256.bmp:idpuah
Removed Stream! C:\WINDOWS\wmsetup.log:lzspys
Removed Stream! C:\WINDOWS\wmsetup10.log:lavyjm
Removed Stream! C:\WINDOWS\WMSysPr9.prx:jigccl
Removed Stream! C:\WINDOWS\WMSysPr9.prx:teydpe
Removed Stream! C:\WINDOWS\xpsp1hfm.log:ezkusc
Removed Stream! C:\WINDOWS\xpsp1hfm.log:gazpyw
Removed Stream! C:\WINDOWS\_default.pif:citgpx
Removed Stream! C:\WINDOWS\_default.pif:dauviq
Removed Stream! C:\WINDOWS\_default.pif:ehcco
Removed Stream! C:\WINDOWS\_default.pif:eiklep
Removed Stream! C:\WINDOWS\_default.pif:eoocif
Removed Stream! C:\WINDOWS\_default.pif:gurwik
————————————————
Removed File! : C:\Windows\apppc.exe
Removed File! : C:\Windows\atlci.dll
Removed File! : C:\Windows\atlev32.dll
Removed File! : C:\Windows\cryy32.dll
Removed File! : C:\Windows\idtpt.dll
Removed File! : C:\Windows\ipfv.dll
Removed File! : C:\Windows\ipqq32.dll
Removed File! : C:\Windows\javavk.exe
Removed File! : C:\Windows\javayt32.exe
Removed File! : C:\Windows\ktvfa.dll
Removed File! : C:\Windows\lgatl.dat
Removed File! : C:\Windows\mizyi.dll
Removed File! : C:\Windows\mlpcq.dll
Removed File! : C:\Windows\msbx32.dll
Removed File! : C:\Windows\msls.exe
Removed File! : C:\Windows\netip.exe
Removed File! : C:\Windows\netps32.dll
Removed File! : C:\Windows\rgecq.dll
Removed File! : C:\Windows\sdkvc.dll
Removed File! : C:\Windows\sysel32.exe
Removed File! : C:\Windows\sysgy32.dll
Removed File! : C:\Windows\uqctg.dat
Removed File! : C:\Windows\vwtpn.dll
Removed File! : C:\Windows\winrk32.exe
Removed File! : C:\Windows\System32\addso.exe
Removed File! : C:\Windows\System32\apico.exe
Removed File! : C:\Windows\System32\apipn.dll
Removed File! : C:\Windows\System32\appfo.dll
Removed File! : C:\Windows\System32\d3wq32.exe
Removed File! : C:\Windows\System32\ieaj32.dll
Removed File! : C:\Windows\System32\ieti32.exe
Removed File! : C:\Windows\System32\javafj32.dll
Removed File! : C:\Windows\System32\javakt32.exe
Removed File! : C:\Windows\System32\javaxk.dll
Removed File! : C:\Windows\System32\mfcwi32.exe
Removed File! : C:\Windows\System32\mswo32.exe
Removed File! : C:\Windows\System32\netru32.dll
Removed File! : C:\Windows\System32\netut32.dll
Removed File! : C:\Windows\System32\windj.exe
Removed File! : C:\Windows\System32\winvl.exe
————————————————
Scan was COMPLETED SUCCESSFULLY at 6:06:07 PM

And here's a new Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 12:27:47 AM, on 7/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Folding@Home\fah502-console.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\Program Files\Folding@Home\FahCore_78.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\Navnt\alertsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\SYSTEM32\DRIVERS\etc\service.exe
C:\WINDOWS\SYSTEM32\DRIVERS\etc\system.exe
C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe
C:\Program Files\SOYO\HW Monitor\Itesmart.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Navnt\navapw32.exe
C:\WINDOWS\system32\userinit.exe
C:\Documents and Settings\Miket\Desktop\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\hsynn.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\hsynn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {EFF8EC3A-C0B2-A458-9B50-41DC660D3D07} - C:\WINDOWS\sysgy32.dll (file missing)
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [h3yb0y] C:\WINDOWS\SYSTEM32\DRIVERS\etc\LSASS.exe C:\WINDOWS\SYSTEM32\DRIVERS\etc\service.exe C:\WINDOWS\SYSTEM32\DRIVERS\etc\conf.dll
O4 - HKLM\..\Run: [h3yb0y1] C:\WINDOWS\SYSTEM32\DRIVERS\etc\LSASS.exe C:\WINDOWS\SYSTEM32\DRIVERS\etc\system.exe C:\WINDOWS\SYSTEM32\DRIVERS\etc\serv-u.ini
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VGAUtil] C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe
O4 - HKLM\..\Run: [SmartGuardian] C:\Program Files\SOYO\HW Monitor\Itesmart.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097722582796
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\windj.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: FAH@C:+Program Files+Folding@Home+fah502-console - Unknown owner - C:\Program.exe (file missing)
O23 - Service: NAV Alert - Symantec Corporation - C:\PROGRA~1\Navnt\alertsvc.exe
O23 - Service: NAV Auto-Protect - Symantec Corporation - C:\PROGRA~1\Navnt\navapsvc.exe
O23 - Service: Norton Program Scheduler - Symantec Corporation - C:\PROGRA~1\Navnt\npssvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Thanks again for your help.

Mike.
I suggest you do this:



Step 1:
Run AboutBuster once again
-Click OK to the Read dialogue
-Click the Update button, and then select: Check for Update
Exit from the program, and do not run AboutBuster yet.

Step 2:
Click Start>Run and type in: services.msc
-Click OK
-In the Services window find: Remote Procedure Call (RPC) Helper
-Select/highlight and right click the entry, and choose: Properties
-On the General tab, under Service Status click the Stop button
-Beside: Startup Type, in the drop menu, select: Disabled
-Click Apply, then OK

Do not select the following Services, they are legit!!
Remote Procedure Call (RPC)
Remote Procedure Call (RPC) Locator

Step 3:
Next, open HijackThis
Click on: Config
Click on: Misc Tools
Click on: Delete an NT Service
In the prompt: Delete an NT Service copy/paste: 11Fßä#·ºÄÖ`I
Press: Enter
Press: OK

If entering: 11Fßä#·ºÄÖ`I does not work, then copy/paste: Remote Procedure Call (RPC) Helper

Step 4:
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\hsynn.dll/sp.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\hsynn.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R3 - Default URLSearchHook is missing

O2 - BHO: Class - {EFF8EC3A-C0B2-A458-9B50-41DC660D3D07} - C:\WINDOWS\sysgy32.dll (file missing)

O4 - HKLM\..\Run: [h3yb0y] C:\WINDOWS\SYSTEM32\DRIVERS\etc\LSASS.exe C:\WINDOWS\SYSTEM32\DRIVERS\etc\service.exe C:\WINDOWS\SYSTEM32\DRIVERS\etc\conf.dll

O4 - HKLM\..\Run: [h3yb0y1] C:\WINDOWS\SYSTEM32\DRIVERS\etc\LSASS.exe C:\WINDOWS\SYSTEM32\DRIVERS\etc\system.exe C:\WINDOWS\SYSTEM32\DRIVERS\etc\serv-u.ini

O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\windj.exe (file missing)


Close ALL windows and browsers except HijackThis and click "Fix checked"


Step 5:
Reboot to Safe Mode

Step 6:
Search for, and if found, delete the following file (bold):
C:\WINDOWS\system32\windj.exe
C:\WINDOWS\sysgy32.dll
C:\WINDOWS\SYSTEM32\DRIVERS\etc\LSASS.exe


Step 7:
Now, go back to AboutBuster once again
-Click Start to begin the process
-Click OK on the Buster Report dialogue box to start the scan

AboutBuster scans the computer for malicious files and deletes them.
Save the report (copy and paste into Notepad and save as a .txt file) to post a copy for review.

When done with the above, also post a new HijackThis log for review.
Ok, I did as requested:

RPC helper wasn't running (but it was a service), and the service deleter couldn't find either spelling I copy/pasted from your earlier post.

I fixed the entries in Hijackthis, but the O23 entry (windj.exe) wasn't on the scan this time, so I couldn't remove it.

There were 3 copies of LSASS.exe, but none in the system32\drivers\etc folder. They were:

C:\windows\prefecth\LSASS.exe-2E7B5183.pf
C:\system32\LSASS.exe
C:\serivcepackfiles\i386\LSASS.exe

I'm assuming you did not want those deleted. Let me know if I was wrong.

Here's the new aboutbuster log:

AboutBuster 5.0 reference file 30
Scan started on [7/2/2005] at [12:45:14 PM]
————————————————
Removed Stream! C:\WINDOWS\svcpack.log:csdbol
Removed Stream! C:\WINDOWS\svcpack.log:zzjmoh
Removed Stream! C:\WINDOWS\tabletoc.log:sabsir
Removed Stream! C:\WINDOWS\tsoc.log:kbuxkt
Removed Stream! C:\WINDOWS\_default.pif:gxjbno
Removed Stream! C:\WINDOWS\_default.pif:itrnyt
Removed Stream! C:\WINDOWS\_default.pif:jjzvef
Removed Stream! C:\WINDOWS\_default.pif:labqon
Removed Stream! C:\WINDOWS\_default.pif:lisgcf
Removed Stream! C:\WINDOWS\_default.pif:mbjgiy
Removed Stream! C:\WINDOWS\_default.pif:ocxoel
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 12:45:30 PM


and here's a fresh hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 1:16:49 PM, on 7/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Folding@Home\fah502-console.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\Program Files\Folding@Home\FahCore_78.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe
C:\Program Files\SOYO\HW Monitor\Itesmart.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Navnt\navapw32.exe
C:\PROGRA~1\Navnt\alertsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Miket\Desktop\Hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VGAUtil] C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe
O4 - HKLM\..\Run: [SmartGuardian] C:\Program Files\SOYO\HW Monitor\Itesmart.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097722582796
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: FAH@C:+Program Files+Folding@Home+fah502-console - Unknown owner - C:\Program.exe (file missing)
O23 - Service: NAV Alert - Symantec Corporation - C:\PROGRA~1\Navnt\alertsvc.exe
O23 - Service: NAV Auto-Protect - Symantec Corporation - C:\PROGRA~1\Navnt\navapsvc.exe
O23 - Service: Norton Program Scheduler - Symantec Corporation - C:\PROGRA~1\Navnt\npssvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Looks much cleaner this time :)

Mike.
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI