This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Frustrated with StartPage-DU and About:Blank

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please help me remove this StartPage-DU.dll

I posted two days ago. Now I can't find my post. I no longer have internet access because my browser keeps crashing and several spy-ware detection tools keep shutting down before I can use them, so I am not able to get online anymore. I am using another computer, so I cannot send another HJT log.

Please help me with this.

I am desperate!

Logfile of HijackThis v1.99.1
Scan saved at 10:52:23 PM, on 7/8/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\LEXBCES.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\LEXPPS.EXE
D:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
D:\WINDOWS\system32\HPZipm12.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\SOUNDMAN.EXE
D:\PROGRA~1\mcafee.com\agent\McAgent.exe
d:\progra~1\mcafee.com\vso\mcvsescn.exe
D:\WINDOWS\system32\LXSUPMON.EXE
D:\WINDOWS\system32\netrm32.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\system32\NOTEPAD.EXE
F:\Downloads\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://D:\WINDOWS\system32\mxbpn.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://D:\WINDOWS\system32\mxbpn.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://D:\WINDOWS\system32\mxbpn.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://D:\WINDOWS\system32\mxbpn.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://D:\WINDOWS\system32\mxbpn.dll/sp.html#93256
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://D:\WINDOWS\system32\mxbpn.dll/sp.html#93256
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {0B4DACA1-181A-DBF9-29CD-2BF9C12D5462} - D:\WINDOWS\ieir32.dll
O2 - BHO: Class - {2C3B82F9-8957-B27D-C371-5070E7E07D84} - D:\WINDOWS\system32\sdkpv32.dll
O2 - BHO: Class - {5646BC95-0DCD-80B6-C388-AE901E5A2066} - D:\WINDOWS\system32\mfchi.dll
O2 - BHO: Class - {686FC7CE-9850-E8AF-9F8D-C905B7852E27} - D:\WINDOWS\system32\atlto.dll
O2 - BHO: Class - {8F2290B4-A233-0040-1A53-2FD0032E2B49} - D:\WINDOWS\system32\iemc.dll
O2 - BHO: Class - {9E32CABC-9B79-F6F5-7841-91BDA440AF47} - D:\WINDOWS\system32\iekb32.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar3.dll
O2 - BHO: Class - {B6EEBD98-DCC8-A9AD-3E92-1F6A9907E2CB} - D:\WINDOWS\atlvx.dll
O2 - BHO: Class - {B8542646-AFF5-94ED-2255-DD8481388BCE} - D:\WINDOWS\system32\sdkcg32.dll
O2 - BHO: Class - {BCF0F99E-6ABF-F983-2E19-BF8289ADC738} - D:\WINDOWS\ntnm.dll
O2 - BHO: Class - {D74D00C3-EB52-A0FF-0E67-45BE41EF3E73} - D:\WINDOWS\sdkre32.dll
O2 - BHO: Class - {EA2270C0-1898-881C-E2E3-E9930A02FC7E} - D:\WINDOWS\sysom.dll
O2 - BHO: Class - {F5515DA6-6F6A-8984-2D4A-E409679E2F80} - D:\WINDOWS\system32\mfcww.dll
O2 - BHO: Class - {FB2B869A-3707-C933-19E7-B30E8BFBB10E} - D:\WINDOWS\mfcfz.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - d:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_7_1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VirusScan Online] "d:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCUpdateExe] D:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] d:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [WM_LOGIN] C:\Program Files\McAfee\McAfee Firewall\MSGLOGIN.EXE
O4 - HKLM\..\Run: [LXSUPMON] D:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [netrm32.exe] D:\WINDOWS\system32\netrm32.exe
O4 - HKLM\..\RunOnce: [d3dq32.exe] D:\WINDOWS\system32\d3dq32.exe
O4 - HKLM\..\RunOnce: [winkz.exe] D:\WINDOWS\winkz.exe
O4 - HKLM\..\RunOnce: [d3dd32.exe] D:\WINDOWS\system32\d3dd32.exe
O4 - HKLM\..\RunOnce: [msll32.exe] D:\WINDOWS\system32\msll32.exe
O4 - HKLM\..\RunOnce: [addle.exe] D:\WINDOWS\addle.exe
O4 - HKLM\..\RunOnce: [sdkwu32.exe] D:\WINDOWS\system32\sdkwu32.exe
O4 - HKLM\..\RunOnce: [msnf32.exe] D:\WINDOWS\msnf32.exe
O4 - HKLM\..\RunOnce: [javand32.exe] D:\WINDOWS\system32\javand32.exe
O4 - HKLM\..\RunOnce: [apisy.exe] D:\WINDOWS\apisy.exe
O4 - HKLM\..\RunOnce: [javacy.exe] D:\WINDOWS\javacy.exe
O4 - HKLM\..\RunOnce: [msha32.exe] D:\WINDOWS\msha32.exe
O4 - HKLM\..\RunOnce: [d3wx.exe] D:\WINDOWS\system32\d3wx.exe
O4 - HKLM\..\RunOnce: [sysvd.exe] D:\WINDOWS\sysvd.exe
O4 - HKLM\..\RunOnce: [ipvl32.exe] D:\WINDOWS\system32\ipvl32.exe
O4 - HKLM\..\RunOnce: [sdkow32.exe] D:\WINDOWS\system32\sdkow32.exe
O4 - HKLM\..\RunOnce: [ntgj32.exe] D:\WINDOWS\system32\ntgj32.exe
O4 - HKLM\..\RunOnce: [atlqe.exe] D:\WINDOWS\atlqe.exe
O4 - HKLM\..\RunOnce: [javaio.exe] D:\WINDOWS\javaio.exe
O4 - HKLM\..\RunOnce: [sdkks.exe] D:\WINDOWS\system32\sdkks.exe
O4 - HKLM\..\RunOnce: [adduw32.exe] D:\WINDOWS\system32\adduw32.exe
O4 - HKLM\..\RunOnce: [d3zy.exe] D:\WINDOWS\system32\d3zy.exe
O4 - HKLM\..\RunOnce: [mspw.exe] D:\WINDOWS\mspw.exe
O4 - HKLM\..\RunOnce: [ntur32.exe] D:\WINDOWS\system32\ntur32.exe
O4 - HKLM\..\RunOnce: [windu32.exe] D:\WINDOWS\windu32.exe
O4 - HKLM\..\RunOnce: [sysge.exe] D:\WINDOWS\system32\sysge.exe
O4 - HKLM\..\RunOnce: [iejl.exe] D:\WINDOWS\system32\iejl.exe
O4 - HKLM\..\RunOnce: [ntxn32.exe] D:\WINDOWS\ntxn32.exe
O4 - HKLM\..\RunOnce: [apphl32.exe] D:\WINDOWS\apphl32.exe
O4 - HKLM\..\RunOnce: [d3py.exe] D:\WINDOWS\system32\d3py.exe
O4 - HKLM\..\RunOnce: [mfcgf.exe] D:\WINDOWS\system32\mfcgf.exe
O4 - HKLM\..\RunOnce: [sdkrl32.exe] D:\WINDOWS\system32\sdkrl32.exe
O4 - HKLM\..\RunOnce: [winvy32.exe] D:\WINDOWS\winvy32.exe
O4 - HKLM\..\RunOnce: [javaat32.exe] D:\WINDOWS\system32\javaat32.exe
O4 - HKLM\..\RunOnce: [d3wn32.exe] D:\WINDOWS\d3wn32.exe
O4 - HKLM\..\RunOnce: [ipcv.exe] D:\WINDOWS\system32\ipcv.exe
O4 - HKLM\..\RunOnce: [addip32.exe] D:\WINDOWS\addip32.exe
O4 - HKLM\..\RunOnce: [apptv.exe] D:\WINDOWS\system32\apptv.exe
O4 - HKLM\..\RunOnce: [ipez32.exe] D:\WINDOWS\ipez32.exe
O4 - HKLM\..\RunOnce: [mfcmu32.exe] D:\WINDOWS\system32\mfcmu32.exe
O4 - HKLM\..\RunOnce: [sysaw.exe] D:\WINDOWS\system32\sysaw.exe
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://d:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://d:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://d:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://d:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://d:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1118891304406
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - D:\WINDOWS\system32\d3dq32.exe" /s (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - D:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - d:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - D:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - d:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - D:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SpywareCleanerService - Unknown owner - D:\Program Files\Spyware Cleaner\SCService.exe (file missing)
Welcome to the forum.

Heres You're First Post

You have a mess here - but we'll get it.


Please read through the instructions before you start (you may want to print this out).

Please download and install these programs - don't run them yet!!

Please download and unzip
AboutBuster to a folder.
AboutBuster MUST be updated before you use it.
Check the AboutBuster Tutorial for instructions.
Don't run it yet.

Download and unzip cwsserviceremove to your desktop. use link below:
DownloadItHere

The above Registry file was written specifically for this infection and is not to be used on any other infection as it could damage a person's PC



Download CW-Shredder at the link below:
http://cwshredder.net/bin/CWShredder.exe

Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked.
Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

Reboot into SafeMode. <—MAKE SURE YOU KNOW HOW TO DO THIS!!

+++++++++++++++++++++++++++++++++++++++++++++++++

Here's the fix:

Important Step
1. Go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called:
Workstation NetLogon Service

When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.

2. Reboot into Safe Mode

3. Press Ctrl+Alt+Delete once => Click Task Manager => Click the Processes tab => Double-click the Image Name column header to alphabetically sort the processes => Scroll through the list and look for:

netrm32.exe

If you find the files, click on them, and then click End Process => Exit the Task Manager.

4. CLOSE ALL WINDOWS AND BROWSERS Scan with Hijack This and put checks next to all the following, then click "Fix Checked"

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://D:\WINDOWS\system32\mxbpn.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://D:\WINDOWS\system32\mxbpn.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://D:\WINDOWS\system32\mxbpn.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://D:\WINDOWS\system32\mxbpn.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://D:\WINDOWS\system32\mxbpn.dll/sp.html#93256
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://D:\WINDOWS\system32\mxbpn.dll/sp.html#93256
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {0B4DACA1-181A-DBF9-29CD-2BF9C12D5462} - D:\WINDOWS\ieir32.dll
O2 - BHO: Class - {2C3B82F9-8957-B27D-C371-5070E7E07D84} - D:\WINDOWS\system32\sdkpv32.dll
O2 - BHO: Class - {5646BC95-0DCD-80B6-C388-AE901E5A2066} - D:\WINDOWS\system32\mfchi.dll
O2 - BHO: Class - {686FC7CE-9850-E8AF-9F8D-C905B7852E27} - D:\WINDOWS\system32\atlto.dll
O2 - BHO: Class - {8F2290B4-A233-0040-1A53-2FD0032E2B49} - D:\WINDOWS\system32\iemc.dll
O2 - BHO: Class - {9E32CABC-9B79-F6F5-7841-91BDA440AF47} - D:\WINDOWS\system32\iekb32.dll
O2 - BHO: Class - {B6EEBD98-DCC8-A9AD-3E92-1F6A9907E2CB} - D:\WINDOWS\atlvx.dll
O2 - BHO: Class - {B8542646-AFF5-94ED-2255-DD8481388BCE} - D:\WINDOWS\system32\sdkcg32.dll
O2 - BHO: Class - {BCF0F99E-6ABF-F983-2E19-BF8289ADC738} - D:\WINDOWS\ntnm.dll
O2 - BHO: Class - {D74D00C3-EB52-A0FF-0E67-45BE41EF3E73} - D:\WINDOWS\sdkre32.dll
O2 - BHO: Class - {EA2270C0-1898-881C-E2E3-E9930A02FC7E} - D:\WINDOWS\sysom.dll
O2 - BHO: Class - {F5515DA6-6F6A-8984-2D4A-E409679E2F80} - D:\WINDOWS\system32\mfcww.dll
O2 - BHO: Class - {FB2B869A-3707-C933-19E7-B30E8BFBB10E} - D:\WINDOWS\mfcfz.dll
O4 - HKLM\..\Run: [netrm32.exe] D:\WINDOWS\system32\netrm32.exe
O4 - HKLM\..\RunOnce: [d3dq32.exe] D:\WINDOWS\system32\d3dq32.exe
O4 - HKLM\..\RunOnce: [winkz.exe] D:\WINDOWS\winkz.exe
O4 - HKLM\..\RunOnce: [d3dd32.exe] D:\WINDOWS\system32\d3dd32.exe
O4 - HKLM\..\RunOnce: [msll32.exe] D:\WINDOWS\system32\msll32.exe
O4 - HKLM\..\RunOnce: [addle.exe] D:\WINDOWS\addle.exe
O4 - HKLM\..\RunOnce: [sdkwu32.exe] D:\WINDOWS\system32\sdkwu32.exe
O4 - HKLM\..\RunOnce: [msnf32.exe] D:\WINDOWS\msnf32.exe
O4 - HKLM\..\RunOnce: [javand32.exe] D:\WINDOWS\system32\javand32.exe
O4 - HKLM\..\RunOnce: [apisy.exe] D:\WINDOWS\apisy.exe
O4 - HKLM\..\RunOnce: [javacy.exe] D:\WINDOWS\javacy.exe
O4 - HKLM\..\RunOnce: [msha32.exe] D:\WINDOWS\msha32.exe
O4 - HKLM\..\RunOnce: [d3wx.exe] D:\WINDOWS\system32\d3wx.exe
O4 - HKLM\..\RunOnce: [sysvd.exe] D:\WINDOWS\sysvd.exe
O4 - HKLM\..\RunOnce: [ipvl32.exe] D:\WINDOWS\system32\ipvl32.exe
O4 - HKLM\..\RunOnce: [sdkow32.exe] D:\WINDOWS\system32\sdkow32.exe
O4 - HKLM\..\RunOnce: [ntgj32.exe] D:\WINDOWS\system32\ntgj32.exe
O4 - HKLM\..\RunOnce: [atlqe.exe] D:\WINDOWS\atlqe.exe
O4 - HKLM\..\RunOnce: [javaio.exe] D:\WINDOWS\javaio.exe
O4 - HKLM\..\RunOnce: [sdkks.exe] D:\WINDOWS\system32\sdkks.exe
O4 - HKLM\..\RunOnce: [adduw32.exe] D:\WINDOWS\system32\adduw32.exe
O4 - HKLM\..\RunOnce: [d3zy.exe] D:\WINDOWS\system32\d3zy.exe
O4 - HKLM\..\RunOnce: [mspw.exe] D:\WINDOWS\mspw.exe
O4 - HKLM\..\RunOnce: [ntur32.exe] D:\WINDOWS\system32\ntur32.exe
O4 - HKLM\..\RunOnce: [windu32.exe] D:\WINDOWS\windu32.exe
O4 - HKLM\..\RunOnce: [sysge.exe] D:\WINDOWS\system32\sysge.exe
O4 - HKLM\..\RunOnce: [iejl.exe] D:\WINDOWS\system32\iejl.exe
O4 - HKLM\..\RunOnce: [ntxn32.exe] D:\WINDOWS\ntxn32.exe
O4 - HKLM\..\RunOnce: [apphl32.exe] D:\WINDOWS\apphl32.exe
O4 - HKLM\..\RunOnce: [d3py.exe] D:\WINDOWS\system32\d3py.exe
O4 - HKLM\..\RunOnce: [mfcgf.exe] D:\WINDOWS\system32\mfcgf.exe
O4 - HKLM\..\RunOnce: [sdkrl32.exe] D:\WINDOWS\system32\sdkrl32.exe
O4 - HKLM\..\RunOnce: [winvy32.exe] D:\WINDOWS\winvy32.exe
O4 - HKLM\..\RunOnce: [javaat32.exe] D:\WINDOWS\system32\javaat32.exe
O4 - HKLM\..\RunOnce: [d3wn32.exe] D:\WINDOWS\d3wn32.exe
O4 - HKLM\..\RunOnce: [ipcv.exe] D:\WINDOWS\system32\ipcv.exe
O4 - HKLM\..\RunOnce: [addip32.exe] D:\WINDOWS\addip32.exe
O4 - HKLM\..\RunOnce: [apptv.exe] D:\WINDOWS\system32\apptv.exe
O4 - HKLM\..\RunOnce: [ipez32.exe] D:\WINDOWS\ipez32.exe
O4 - HKLM\..\RunOnce: [mfcmu32.exe] D:\WINDOWS\system32\mfcmu32.exe
O4 - HKLM\..\RunOnce: [sysaw.exe] D:\WINDOWS\system32\sysaw.exe
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - D:\WINDOWS\system32\d3dq32.exe" /s (file missing)

Click on Fix Checked and exit HijackThis.


5. Delete the following files if present:

SKIP THIS STEP - ABOUTBUSTER WILL DELETE THEM

(and any other files with the same name that end in .dll, .exe or .dat, you may find them right next to each other, example - appsw.exe, appsw.dll, appsw.dat)
If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.


6. Run AboutBuster . This will scan your computer for the bad files and delete them. It will ask to scan the system again, let it. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

7. Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin

8. Double click on the cwsserviceremove and when asked to merge say yes.

9. Run CW-Shredder - Hit the FIX button - let it run and fix what it finds.

10. Reboot into normal mode.

11. Download and run this online virus scan:<—Important
http://housecall.trendmicro.com/housecall/start_corp.asp
Make sure you check "AutoClean"

12. Reboot and post a fresh HJT log back here by using the add reply button below, and lets see how we did, MrC
Thanks for getting back. Right now I am unable to open the ie browser and I don't have another one. I am using a second computer at home. Second, whenever I try to run Trend Micro, it shuts right down, but I have CWS Shredder as part of that and it was updated last Saturday before the browser quit. I just can't run it. What should I do in this case? By the way, I currently have system restore turned off…
Why don't you download AboutBuster and cwsserviceremove on your good computer, unzip them then copy them to a floppy.
Put the floppy in the infected computer and copy the two programs on the computer.
Now you should be able to reboot the computer into safe mode and follow my instructions, don't worry about the anti virus scan for now - the main programs to run would be AboutBuster, CW-Shredder and cwsserviceremove.
Don't forget to run HJT and fix what I have listed first.

Good Luck, MrC
Thanks :thumbup: . AboutBuster crashed after the OK screen. I tried it twice. So I can't give you the report from that, but here is the final HJT output. I now have internet access :)

BTW, I still have SystemRestore turned off.

Logfile of HijackThis v1.99.1
Scan saved at 11:53:34 PM, on 7/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\LEXBCES.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\LEXPPS.EXE
d:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
D:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
D:\WINDOWS\system32\HPZipm12.exe
D:\WINDOWS\System32\svchost.exe
d:\PROGRA~1\mcafee.com\vso\mcshield.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\SOUNDMAN.EXE
D:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
D:\PROGRA~1\mcafee.com\agent\McAgent.exe
D:\WINDOWS\system32\ctfmon.exe
d:\progra~1\mcafee.com\vso\mcvsescn.exe
D:\WINDOWS\system32\wuauclt.exe
F:\Downloads\HiJackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar3.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - d:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_7_1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VirusScan Online] "d:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCUpdateExe] D:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] d:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [WM_LOGIN] C:\Program Files\McAfee\McAfee Firewall\MSGLOGIN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://d:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://d:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://d:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://d:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://d:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1118891304406
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - D:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - d:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - D:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - d:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - D:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SpywareCleanerService - Unknown owner - D:\Program Files\Spyware Cleaner\SCService.exe (file missing)
Well Done!

Close ALL programs down, leaving ONLY HijackThis running.
Place a check against the following items:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R3 - Default URLSearchHook is missing

Fix this one only if you don't have Spyware Cleaner on the system
O23 - Service: SpywareCleanerService - Unknown owner - D:\Program Files\Spyware Cleaner\SCService.exe (file missing)

Click on Fix Checked and exit HijackThis.

Open up Internet Explorer , Tools, General Tab, reset your home page to what you want, now the Programs Tab, click Reset Web Settings
That will change everything back to the default settings.


Reboot and post a fresh HijackThis log and we'll take another look. MrC
Here is the latest HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 9:38:25 AM, on 7/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\LEXBCES.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\LEXPPS.EXE
d:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
D:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
D:\WINDOWS\system32\HPZipm12.exe
D:\WINDOWS\System32\svchost.exe
d:\PROGRA~1\mcafee.com\vso\mcshield.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\SOUNDMAN.EXE
D:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
D:\PROGRA~1\mcafee.com\agent\McAgent.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\WINDOWS\system32\ctfmon.exe
d:\progra~1\mcafee.com\vso\mcvsescn.exe
F:\Downloads\HiJackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar3.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - d:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_7_1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VirusScan Online] "d:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCUpdateExe] D:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] d:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [WM_LOGIN] C:\Program Files\McAfee\McAfee Firewall\MSGLOGIN.EXE
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://d:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://d:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://d:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://d:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://d:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1118891304406
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - D:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - d:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - D:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - d:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - D:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
Looks Good!

It should be running OK now, let me know if you have any questions.

I'll leave you with……..

Some preventive maintenance:

——————Must have or do:—————–

Now that you're clean: <—-Important Step!!!!
Delete your system restore files and create a new restore point:
(ME and XP users only)

XP system restore

ME system restore


Visit Windows Update and install all the lastest critical updates.

Install these two free programs, they sit in the backround and protect your system from spy and adware being installed on your system, also from your browser being hijacked. Check for updates weekly.

SpywareBlaster

SpywareGuard


IE-SPYAD
Puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
IE-SPYAD

SpyBot has some protection benefits - use them.

Need a free anti virus?
AVG*free
(check for updates - daily)

How about a firewall? The front door to your computer.
ZoneAlarm*free



———-Free malware removal programs:———-

SpyBot
AD-Aware
CW-Shredder

Free Online Trojan Scan

A SQUARED FREE TROJAN SCANNER

Trojan Hunter
TrojanHunter - free trial

Please consider using FireFox instead of Internet Explorer

Replace Java with SunJava

Pop-up stoppers:
GoogleToolBar
Pop-upStopperFree

Disable Windows MessengerXP - 2K (stops pop-up ads -etc):
Disabling Messenger Service in Windows XP
How to Remove Windows Messenger on Windows XP
How to Remove Windows Messenger on Windows XP
Shoot The Messenger


Don't open e-mail attachments without first scanning them with an up-to-date
anti virus program, even after doing that I would be very careful. Don't click on any executables in e-mails or any other links that you're not sure of.
Watch your surfing habits, don't click on or download anything you're not sure of. Don't install a program that hasn't been recommended by a reputable organization.

Good luck and thanks for using the forum - MrC
:wavey:
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI