This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

CWS INFESTATION?

37 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My machine has been attacked by what looks like CWS. It started with the desktop being replaced with a spyware warning, and Display settings were disabled to prevent it being changed back. Subsequent symptoms include hijacking of homepage to "about:blank", pop ups labelled "Only the best", google searches being hijacked to "Looking for [searchtext]" popup screens, and occasional warnings appearing about spyware, along with a button to click to get advice - but the screen doesn't look genuine to me. Spyware infection star symbols appear in the bottom right toolbar from time to time - a Windows update seemed to get rid of these for a while.

Ad-Aware SE Personal and various other spyware fixes find problems and fix them, but it all reappears even before rebooting.

I run Windows 2000 Professional. I updated to SP4 after the infection but it still continues.

Any advice appreciated ….


HijackThis log reads:

Logfile of HijackThis v1.97.7
Scan saved at 20:00:42, on 20/09/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\iezm32.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\addtw32.exe
C:\Program Files\LINKSYS\Configuration Utility\config.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Documents and Settings\leo.quigley\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\ntutq.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\ntutq.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\ntutq.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\ntutq.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\ntutq.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\system32\ntutq.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\ntutq.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTopenworld
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {B01F6005-F9D6-AF30-3500-0C47DB24CB55} - C:\WINNT\system32\addge32.dll
O2 - BHO: (no name) - {D3547B4B-C739-5087-709F-ECF270ADE92A} - C:\WINNT\appow.dll
O2 - BHO: (no name) - {FED29B04-D6C8-9AC6-BFD2-869A828A72AA} - C:\WINNT\system32\netkw32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vmcleaner] gxlib.exe
O4 - HKLM\..\Run: [sysup.exe] C:\WINNT\sysup.exe
O4 - HKLM\..\Run: [sdkar32.exe] C:\WINNT\sdkar32.exe
O4 - HKLM\..\Run: [netjr.exe] C:\WINNT\netjr.exe
O4 - HKLM\..\Run: [addtw32.exe] C:\WINNT\system32\addtw32.exe
O4 - HKLM\..\Run: [d3gd32.exe] C:\WINNT\system32\d3gd32.exe
O4 - HKLM\..\Run: [winxz32.exe] C:\WINNT\system32\winxz32.exe
O4 - HKCU\..\Run: [SNInstall] C:\winstall.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Configuration Utility.lnk = C:\Program Files\LINKSYS\Configuration Utility\config.exe
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
O4 - Global Startup: winlogin.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.btopenworld.com/
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1127235282831
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1) -
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = gatesh-tr.northy.nhs.uk,xghnt
O17 - HKLM\System\CS1\Services\Tcpip\..\{3216F52D-8BB1-4C30-A975-DB1DDBFDD405}: NameServer = 194.101.13.2,194.101.13.40
You are using an outdated version of HijackThis. Please download HijackThis version 1.99.1 from here. Please delete your current version and extract the new version into its own folder. Once that is done, please post a new HJT log.
OK, thanks, 1.99.1 dowloaded and run. Here is the new Hijack log:


Logfile of HijackThis v1.99.1
Scan saved at 18:05:48, on 30/09/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\iezm32.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\addtw32.exe
C:\Program Files\LINKSYS\Configuration Utility\config.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\Program Files\Common Files\System\MAPI\1033\nt\MAPISP32.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\WINNT\explorer.exe
C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\ntutq.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\ntutq.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\system32\ntutq.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\ntutq.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\ntutq.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\ntutq.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\ntutq.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTopenworld
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {8191B8E8-A679-923E-550D-26C5DEDC71E6} - C:\WINNT\system32\winbp32.dll
O2 - BHO: Class - {9B630CC6-396F-7B7E-A1A0-564D91182A03} - C:\WINNT\system32\crbt32.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Class - {B01F6005-F9D6-AF30-3500-0C47DB24CB55} - C:\WINNT\system32\addge32.dll
O2 - BHO: Class - {B6A3E8CC-EC52-30B1-6CC6-92B377FCB99B} - C:\WINNT\system32\javapc.dll
O2 - BHO: Class - {D3547B4B-C739-5087-709F-ECF270ADE92A} - C:\WINNT\appow.dll
O2 - BHO: Class - {FED29B04-D6C8-9AC6-BFD2-869A828A72AA} - C:\WINNT\system32\netkw32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vmcleaner] gxlib.exe
O4 - HKLM\..\Run: [sysup.exe] C:\WINNT\sysup.exe
O4 - HKLM\..\Run: [sdkar32.exe] C:\WINNT\sdkar32.exe
O4 - HKLM\..\Run: [netjr.exe] C:\WINNT\netjr.exe
O4 - HKLM\..\Run: [addtw32.exe] C:\WINNT\system32\addtw32.exe
O4 - HKLM\..\Run: [d3gd32.exe] C:\WINNT\system32\d3gd32.exe
O4 - HKLM\..\Run: [winxz32.exe] C:\WINNT\system32\winxz32.exe
O4 - HKCU\..\Run: [SNInstall] C:\winstall.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Configuration Utility.lnk = C:\Program Files\LINKSYS\Configuration Utility\config.exe
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
O4 - Global Startup: winlogin.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.btopenworld.com/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1127235282831
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1) -
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = gatesh-tr.northy.nhs.uk,xghnt
O17 - HKLM\System\CS1\Services\Tcpip\..\{3216F52D-8BB1-4C30-A975-DB1DDBFDD405}: NameServer = 194.101.13.2,194.101.13.40
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\iezm32.exe" /s (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe (file missing)
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\ORL\VNC\WinVNC.exe" -service (file missing)
Please download Intermute's CWShredder from here:
http://cwshredder.net/bin/CWShredder.exe
Save it to the desktop and run it, and click "Fix" to remove the CWS infection.

Then please download About:Buster from here:
http://www.malwarebytes.biz/AboutBuster5.zip
Unzip the files to a convenient location such as C:\AboutBuster, and run AboutBuster.exe. Read the instructions then click OK to proceed. Then click Start to begin the scan. If prompted to end the Explorer.exe process, click Yes. Your desktop may disappear — this is normal. Allow the program to scan twice, and when complete click "Save Log". This will create a text file called "AB Logfile.txt" in the folder where About:Buster is saved. Please post the entire contents of that logfile here for me. Please also restart your computer and post a new HijackThis log.
Succeeded in downloading and unzipping About Buster, but when trying to run it I get Run-time error '5' - invalid procedure, call or argument.
OK, it was clicking on 'update' that gave the error, so I haven;t been able to do an update. However, I've run About Buster twice as requested and here is the log file: AboutBuster 5.0 reference file 31 Scan started on [30/09/2005] at [22:23:04] ———————————————— Streams(ADS) not scanned: System not NTFS ———————————————— No Files Found! ———————————————— Scan was COMPLETED SUCCESSFULLY at 22:23:04 AboutBuster 5.0 reference file 31 Scan started on [30/09/2005] at [22:25:49] ———————————————— Streams(ADS) not scanned: System not NTFS ———————————————— No Files Found! ———————————————— Scan was COMPLETED SUCCESSFULLY at 22:25:49 Hijackthis log follows in five minutes.
Here's the new HIjackthis log after running AboutBuster:

Logfile of HijackThis v1.99.1
Scan saved at 22:33:31, on 30/09/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\iezm32.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\d3gd32.exe
C:\Program Files\LINKSYS\Configuration Utility\config.exe
C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\WINNT\explorer.exe
C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\ctffw.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTopenworld
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {5DBCB797-3A02-97C1-14B5-81C44EE99410} - C:\WINNT\msup32.dll
O2 - BHO: Class - {8191B8E8-A679-923E-550D-26C5DEDC71E6} - C:\WINNT\system32\winbp32.dll
O2 - BHO: Class - {9B630CC6-396F-7B7E-A1A0-564D91182A03} - C:\WINNT\system32\crbt32.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Class - {B01F6005-F9D6-AF30-3500-0C47DB24CB55} - C:\WINNT\system32\addge32.dll
O2 - BHO: Class - {B6A3E8CC-EC52-30B1-6CC6-92B377FCB99B} - C:\WINNT\system32\javapc.dll
O2 - BHO: Class - {D3547B4B-C739-5087-709F-ECF270ADE92A} - C:\WINNT\appow.dll
O2 - BHO: Class - {FED29B04-D6C8-9AC6-BFD2-869A828A72AA} - C:\WINNT\system32\netkw32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vmcleaner] gxlib.exe
O4 - HKLM\..\Run: [sysup.exe] C:\WINNT\sysup.exe
O4 - HKLM\..\Run: [sdkar32.exe] C:\WINNT\sdkar32.exe
O4 - HKLM\..\Run: [netjr.exe] C:\WINNT\netjr.exe
O4 - HKLM\..\Run: [d3gd32.exe] C:\WINNT\system32\d3gd32.exe
O4 - HKLM\..\Run: [winlh32.exe] C:\WINNT\system32\winlh32.exe
O4 - HKCU\..\Run: [SNInstall] C:\winstall.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Configuration Utility.lnk = C:\Program Files\LINKSYS\Configuration Utility\config.exe
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
O4 - Global Startup: winlogin.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.btopenworld.com/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1127235282831
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1) -
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = gatesh-tr.northy.nhs.uk,xghnt
O17 - HKLM\System\CS1\Services\Tcpip\..\{3216F52D-8BB1-4C30-A975-DB1DDBFDD405}: NameServer = 194.101.13.2,194.101.13.40
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\iezm32.exe" /s (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe (file missing)
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\ORL\VNC\WinVNC.exe" -service (file missing)
Ok, can you updated Ewido, then boot into Safe Mode and scan with Ewido and let it remove what it finds? Then, reboot into normal mode and post a new HJT log.
OK, done as instructed. New HJL log:

Logfile of HijackThis v1.99.1
Scan saved at 00:52:19, on 01/10/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\iezm32.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\explorer.exe
C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\ctffw.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTopenworld
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {5DBCB797-3A02-97C1-14B5-81C44EE99410} - C:\WINNT\msup32.dll
O2 - BHO: Class - {8191B8E8-A679-923E-550D-26C5DEDC71E6} - C:\WINNT\system32\winbp32.dll
O2 - BHO: Class - {9B630CC6-396F-7B7E-A1A0-564D91182A03} - C:\WINNT\system32\crbt32.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Class - {B01F6005-F9D6-AF30-3500-0C47DB24CB55} - C:\WINNT\system32\addge32.dll
O2 - BHO: Class - {B6A3E8CC-EC52-30B1-6CC6-92B377FCB99B} - C:\WINNT\system32\javapc.dll
O2 - BHO: Class - {D3547B4B-C739-5087-709F-ECF270ADE92A} - C:\WINNT\appow.dll
O2 - BHO: Class - {FD7D04A3-0B7C-2DAC-A169-EE97CF53C6B5} - C:\WINNT\system32\msqm.dll
O2 - BHO: Class - {FED29B04-D6C8-9AC6-BFD2-869A828A72AA} - C:\WINNT\system32\netkw32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vmcleaner] gxlib.exe
O4 - HKLM\..\Run: [sysup.exe] C:\WINNT\sysup.exe
O4 - HKLM\..\Run: [sdkar32.exe] C:\WINNT\sdkar32.exe
O4 - HKLM\..\Run: [netjr.exe] C:\WINNT\netjr.exe
O4 - HKCU\..\Run: [SNInstall] C:\winstall.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Configuration Utility.lnk = C:\Program Files\LINKSYS\Configuration Utility\config.exe
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
O4 - Global Startup: winlogin.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.btopenworld.com/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1127235282831
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1) -
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = gatesh-tr.northy.nhs.uk,xghnt
O17 - HKLM\System\CS1\Services\Tcpip\..\{3216F52D-8BB1-4C30-A975-DB1DDBFDD405}: NameServer = 194.101.13.2,194.101.13.40
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\iezm32.exe" /s (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe (file missing)
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\ORL\VNC\WinVNC.exe" -service (file missing)
Ok, you have a pretty serious infection there, so it will take some work. You may want to print out or make a copy of these instructions before starting, because you will not be able to connect to the internet during most of this fix.

Download smitRem.exe and save the file to your desktop.
Double click on the file to extract it to it's own folder on the desktop.

If you do not already have Ad-Aware SE 1.06 installed, follow these download and setup instructions. Also check for updates:
Ad-Aware SE Setup
Again, do NOT run a scan yet.


Next, please reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
Now scan with HJT and place a checkmark next to each of the following items:

===================================================
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\ctffw.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\ctffw.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\ctffw.dll/sp.html#28129
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {5DBCB797-3A02-97C1-14B5-81C44EE99410} - C:\WINNT\msup32.dll
O2 - BHO: Class - {8191B8E8-A679-923E-550D-26C5DEDC71E6} - C:\WINNT\system32\winbp32.dll
O2 - BHO: Class - {9B630CC6-396F-7B7E-A1A0-564D91182A03} - C:\WINNT\system32\crbt32.dll
O2 - BHO: Class - {B01F6005-F9D6-AF30-3500-0C47DB24CB55} - C:\WINNT\system32\addge32.dll
O2 - BHO: Class - {B6A3E8CC-EC52-30B1-6CC6-92B377FCB99B} - C:\WINNT\system32\javapc.dll
O2 - BHO: Class - {D3547B4B-C739-5087-709F-ECF270ADE92A} - C:\WINNT\appow.dll
O2 - BHO: Class - {FD7D04A3-0B7C-2DAC-A169-EE97CF53C6B5} - C:\WINNT\system32\msqm.dll
O2 - BHO: Class - {FED29B04-D6C8-9AC6-BFD2-869A828A72AA} - C:\WINNT\system32\netkw32.dll
O4 - HKLM\..\Run: [vmcleaner] gxlib.exe
O4 - HKLM\..\Run: [sysup.exe] C:\WINNT\sysup.exe
O4 - HKLM\..\Run: [sdkar32.exe] C:\WINNT\sdkar32.exe
O4 - HKLM\..\Run: [netjr.exe] C:\WINNT\netjr.exe
O4 - HKCU\..\Run: [SNInstall] C:\winstall.exe
O4 - Global Startup: winlogin.exe
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\iezm32.exe" /s (file missing)

===================================================

Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Your desktop and icons will disappear and then reappear again — this is normal.
Wait for the tool to complete and Disk Cleanup to finish — this may take a while; please be patient.

Next, run Ad-aware and perform a full scan. Remove everything found.

Now open Ewido Security Suite
  • Click on Scanner
  • Click on Complete System Scan and the scan will begin.
  • NOTE: During some scans with ewido it is finding cases of false positives. You will need to step through the process of cleaning files one-by-one. If ewido detects a file you KNOW to be legitimate, select none as the action.
  • DO NOT select "Perform action on all infections"
  • When the scan is finished, click the Save report button at the bottom of the screen.
  • Save the report to your desktop
  • Close Ewido
Next go to Start -> Control Panel, click Display -> Desktop -> Customize Desktop -> Web -> Uncheck "Security Info" if present.


Restart your computer in normal mode.

Run Panda's online virus scan and perform a full system scan. Make sure the Autoclean box is checked!

Next, please enable viewing of hidden files as follows:
  • Go to My Computer, and click on the "Tools" menu
  • Click "Folder options"
  • Select the "View" tab
  • Make sure "Show hidden files and folders" is selected
  • Make sure "Hide extensions for known file types" is unchecked
  • Make sure "Hide protected operating system files (recommended)" is unchecked
Delete the following files and folders (if found):
C:\WINNT\msup32.dll <–This file
C:\WINNT\system32\winbp32.dll <–This file
C:\WINNT\system32\crbt32.dll <–This file
C:\WINNT\system32\addge32.dll <–This file
C:\WINNT\system32\javapc.dll <–This file
C:\WINNT\appow.dll <–This file
C:\WINNT\system32\msqm.dll <–This file
C:\WINNT\system32\netkw32.dll <–This file
gxlib.exe <–This file. It is probably in C:\WINNT or C:\WINNT\system32, but you will have to search for it.
C:\WINNT\sysup.exe <–This file
C:\WINNT\sysup.exe <–This file
C:\WINNT\msmpatch.exe <–This file
C:\WINNT\svosm.exe <–This file
C:\WINNT\msmpatch.exe <–This file
C:\WINNT\dsm.exe <–This file
C:\WINNT\system32\One Eye Granny pic!.pif <–This file
C:\WINNT\system32\Me drunk at The Sea!.pif <–This file
C:\WINNT\system32\Punk Lives! lol.pif <–This file
C:\WINNT\system32\Me Love You Long Time.pif <–This file
C:\WINNT\system32\Me pic.pif <–This file
C:\WINNT\system32\HillBilly Chick lol.pif <–This file
C:\WINNT\system32\Dumb Looking Goth Chick.pif <–This file
C:\WINNT\system32\Hot Blonde!.pif <–This file
C:\WINNT\system32\Modelling Her New Bikini.pif <–This file
C:\WINNT\system32\Crazy Japanese man kicks crazy frog!.pif <–This file
C:\WINNT\system32\Funny Hitler parody!.pif <–This file
C:\WINNT\system32\My birthday pic!.pif <–This file
C:\WINNT\system32\Funny Hitler parody.pif <–This file
C:\Documents and Settings\\Local Settings\Application Data\Microsoft\CD Burning\autorun.exe <–This file, where "Current User" is the name of the currently logged in user.
C:\WINNT\sdkar32.exe <–This file
C:\WINNT\netjr.exe <–This file

Finally, restart your computer once more, and please post a new HijackThis log as well as the log from the Ewido scan and the log from the smitRem tool, which will be located at C:\smitfiles.txt.
Let us know if any problems persist.
OK, a few issues to let you know about while I was carrying out the instructions.

1. The HJT log files that previously included cffw.dll/sp.html#28129 had all morphed into wnorc.dll/sp.html#28129. I fixed them anyway.
2. HJT wouldn't fix O4 - Global Startup: winlogin.exe. It said it was still running and I should use Taskmanager to close it first. I couldn't find it in Taskmanager, either in applications or processes, there was only a process called winlogon.exe, which looked important so I left it alone.
3. The disk cleanup tool from Smitrem ran for only ten seconds or so before shutting down, leaving the Mydocuments window open. I couldn't tell whether it was still operating, left it for fifteen minutes and when nothing had happened by then carried on to the Adaware scan.
4. I coudn't find "web" or "security info" in customise desktop. so couldnt check how it was set.
5. I ran the Panda scan for "local disks" rather than "My computer". There wasn;t an autoclean box to check. The instructions said it would clean viruses anyway, but it found lots of other things and either couldn;t or wouldn't disinfect them. I've added the Panda log for information.

Finally, I didn't find any of the files you said to delete - I'm pretty sure I had the settings and locations right, they just weren't there.

I am still getting browser hijacking and popups as before.

Here are the various logs:


Logfile of HijackThis v1.99.1
Scan saved at 12:30:34, on 01/10/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\iezm32.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\system32\appuv32.exe
C:\WINNT\explorer.exe
C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\sbuow.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\sbuow.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\sbuow.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\sbuow.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\sbuow.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\sbuow.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\sbuow.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTopenworld
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {55C43446-D6EF-FEAE-8151-BCA92481B35C} - C:\WINNT\system32\addne32.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [appuv32.exe] C:\WINNT\system32\appuv32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Configuration Utility.lnk = C:\Program Files\LINKSYS\Configuration Utility\config.exe
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
O4 - Global Startup: winlogin.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.btopenworld.com/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1127235282831
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1) -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = gatesh-tr.northy.nhs.uk,xghnt
O17 - HKLM\System\CS1\Services\Tcpip\..\{3216F52D-8BB1-4C30-A975-DB1DDBFDD405}: NameServer = 194.101.13.2,194.101.13.40
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\iezm32.exe" /s (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe (file missing)
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\ORL\VNC\WinVNC.exe" -service (file missing)


———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 10:29:25, 01/10/2005
+ Report-Checksum: CFE0338F

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{9E590345-2CAF-3710-CEAE-2B56767589B6} -> Spyware.CoolWebSearch : Cleaned with backup


::Report End




smitRem log file
version 2.5

by noahdfear

The current date is: Sat 01/10/2005
The current time is: 9:52:41.86

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run Files Present


~~~ Program Files ~~~



~~~ Shortcuts ~~~

Install.dat


~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~


shudder global limited


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



Post-run Files Present


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~



~~~ Miscellaneous Files/folders ~~~




~~~ Wininet.dll ~~~

CLEAN! :)



Incident Status Location

Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\SYSTEM32\ieek.exe
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\SYSTEM32\msly.exe
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\SYSTEM32\addne32.dll
Adware:adware/navipromo No disinfected C:\WINNT\SYSTEM32\sdkjn32.exe
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\SYSTEM32\mfcnt.exe
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\SYSTEM32\appcf32.exe
Adware:Adware/WinTools No disinfected C:\WINNT\SYSTEM32\msietn.dll
Adware:Adware/NetPals No disinfected C:\WINNT\SYSTEM32\netpals.dll
Adware:Adware/BrowsePal No disinfected C:\WINNT\SYSTEM32\ctbv2.dll
Virus:W32/Smitfraud.E Disinfected C:\WINNT\SYSTEM32\wininet.old
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\SYSTEM32\ntwg32.exe
Adware:Adware/eZula No disinfected C:\WINNT\SYSTEM32\ezStubi.dll
Virus:Trj/W32.Delf Disinfected C:\WINNT\SYSTEM32\installer_im.dll
Adware:Adware/Comet No disinfected C:\WINNT\SYSTEM32\CometTB.dll
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\SYSTEM32\winqv32.exe
Adware:adware/twain-tech No disinfected C:\WINNT\INF\multimpp.inf
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\nvbjyf.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\ysqjly.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\ylvlnc.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\yoeztw.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\tncmcs.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\dljihs.txt
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\applc32.exe
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\javamk32.exe
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\threaz.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\vwtpzx.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\leudgz.log
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\sfgdtr.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\xzntvs.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\yrsnxw.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\vpyjkb.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\wizjfr.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\xbfmpu.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\osxepl.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\xkfdzq.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\lucvsh.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\wjwtgl.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\jldgwb.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\okcgzo.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\ofpdai.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\iezm32.exe
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\sdusmb.log
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\wprppn.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\aapfdh.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\dvzodp.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\tylxdu.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\clabqn.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\vwhwka.log
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\vxqqky.dat
Adware:Adware/Startpage.VQ No disinfected C:\WINNT\sbuow.dll
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\znkpuz.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\meppdk.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\agpred.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\rokanb.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\fkywan.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\gddykq.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\hnvnbe.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\cllilv.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\dercvy.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\syqdqe.dat
Adware:Adware/Startpage.VQ No disinfected C:\WINNT\jdsiux.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\boioek.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\cqplra.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\hzosyo.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\ikumjs.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\cbufte.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\xjgjur.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\xcldwu.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\najwmi.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\otoqwl.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\swayaz.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\sgfakd.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\ntnvwa.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\odaphd.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\ydtaxl.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\fwfcen.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\gpkxgr.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\zogdio.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\eoxjfj.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\fycdpm.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\nmqijj.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\kdcjsr.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\loqdcu.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\nfwclm.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\ndvgzi.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\gvaacl.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\umjhlj.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\vfpbvm.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\qjwvhj.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\qccqkm.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\ppvvbq.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\qibxmt.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\pnaxoa.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\iyfzyd.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\lknuka.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\dvsond.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\xflsbo.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\gpvowx.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\giaiza.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\yqquer.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\sksnnl.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\tcypyo.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\ohfkkl.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\pzlemp.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\fxjxbc.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\xqwrmg.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\elxuvh.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\yytpce.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\lkisig.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\muousj.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\vsituv.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\hjrnsw.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\ibwhcz.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\wlnvfy.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\zkcfxd.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\auhhhg.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\eyjwza.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\zvesva.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\agjnyd.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\wklhwa.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\pdybye.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\talyve.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\pxynre.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\hidhuh.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\hvrnxl.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\aowpzo.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\surdrq.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\seextt.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\mtxmoh.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\nldoqk.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\yojtzv.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\ygowcy.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\dsecel.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\icfljh.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\bukfll.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\ziwtdo.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\blphxv.dat
Adware:Adware/Startpage.AIX No disinfected C:\WINNT\xxlhdp.dat
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected C:\WINNT\ppqcns.dat
Adware:adware/gator No disinfected C:\GatorPatch.log
Adware:Adware/Startpage.AIX No disinfected C:\unzipped\hijackthis\backups\backup-20051001-094658-659.dll
Adware:Adware/Startpage.AIX No disinfected C:\unzipped\hijackthis\backups\backup-20051001-094658-362.dll
Adware:Adware/Startpage.AIX No disinfected C:\unzipped\hijackthis\backups\backup-20051001-094658-255.dll
Adware:Adware/Startpage.AIX No disinfected C:\unzipped\hijackthis\backups\backup-20051001-094658-371.dll
Adware:Adware/Startpage.AIX No disinfected C:\unzipped\hijackthis\backups\backup-20051001-094658-661.dll
Adware:Adware/Startpage.AIX No disinfected C:\unzipped\hijackthis\backups\backup-20051001-094658-615.dll
Adware:Adware/Startpage.AIX No disinfected C:\unzipped\hijackthis\backups\backup-20051001-094658-628.dll
Adware:Adware/Startpage.AIX No disinfected C:\unzipped\hijackthis\backups\backup-20051001-094658-180.dll
Adware:adware/searchaid No disinfected C:\Documents and Settings\leo.quigley\Favorites\Search the web.url
Dialer:Dialer.B No disinfected C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
Adware:adware/superspider No disinfected C:\Program Files\q330994.exe
Adware:adware/startpage.id No disinfected C:\msdos.exe
Virus:W32/FunLove.4096 No disinfected C:\transfer\Utils\SonyCMD\setup.exe[Setup.exe]
Please save these instructions to WordPad so that you have them accessible while following the steps. You also may want to print out these directions as the Internet will not be available. You must disconnect from the internet totally, as staying connected while fixing will prevent the fix from working. Also please keep Internet Explorer closed throughout as opening it will reinstall the infection. Read through all the instructions so that you can ask any questions now, before you disconnect from the Internet.

Please download and install Firefox and use it
exclusively throughout the entire fix to prevent more malware from being downloaded before you are cleaned:

http://www.mozilla.org/products/firefox/

Please download and install a newer version of Visual Basic 6.0: Run-Time Redistribution Pack from here:
http://www.microsoft.com/downloads/details…&displaylang=en

Please delete the copy of AboutBuster you currently have, and download it from here:
http://www.bleepingcomputer.com/files/aboutbuster.php
Once it is downloaded extract it to C:\aboutbuster. Do NOT use it yet. When you do use it later on in this fix, as trying to update is causing a problem, do NOT use the Update button.

Now download cwsserviceremove.zip from http://lineofire.geekstogo.com/cwsserviceremove.zip.
Unzip the contents of cwsserviceremove.zip (cwsserviceremove.reg) to your desktop.
Do NOT run the program yet.

Reconfigure Windows XP to show hidden files:
Click Start. Open My Computer.
Select the Tools menu and click Folder Options. Select the View Tab.
Under the Hidden files and folders heading select "Show hidden files and folders".
Uncheck the "Hide protected operating system files (recommended)" option.
Uncheck the "Hide file extensions for known file types" option.

Please disconnect from the Internet and unplug your modem for the duration of this fix

Reboot your computer into Safe Mode by tapping F8 while booting up and continue for the rest of the fix in SAFE MODE

Go to Start > Run and type in Services.msc then click OK
Click the Extended tab.
Scroll down until you find the service Network Security Service
Click once on the service to highlight it.
Click Stop
Right-Click on the service Network Security Service
Click on 'Properties'
Select the 'General' tab
Click the Arrow-down tab on the right-hand side on the 'Start-up Type' box
From the drop-down menu, click on 'Disabled'
Click the 'Apply' tab, then click 'OK'


Now run HijackThis, click “Open the Misc Tools section”, and then click “Delete an NT service”.
In the “Delete a Windows NT Service” window that opens, type:
Network Security Service and hit OK.
Close HijackThis.

Press control-alt-delete to open the Task Manager and end the following processes if they exist:

C:\WINNT\iezm32.exe
C:\WINNT\system32\appuv32.exe
winlogin (winlogon is a valid process, so don't end that one, only winlogin)



Now you need to run HijackThis and click "Do a system scan only." Place a check next to the following entries (if they are still there):

The R1/R0 lines may look slightly different as the hijacker changes filenames.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\sbuow.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\sbuow.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\sbuow.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\sbuow.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\sbuow.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\sbuow.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\sbuow.dll/sp.html#28129
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {55C43446-D6EF-FEAE-8151-BCA92481B35C} - C:\WINNT\system32\addne32.dll
O4 - HKLM\..\Run: [appuv32.exe] C:\WINNT\system32\appuv32.exe
O4 - Global Startup: winlogin.exe
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\iezm32.exe" /s (file missing)


Now close all browser and other windows except for HijackThis, and click "Fix Checked" to have HijackThis fix the entries you checked.

Now, delete the following files:

C:\WINNT\system32\addne32.dll
C:\WINNT\system32\appuv32.exe

If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.


Double-click on cwsserviceremove.reg that you downloaded earlier.
When it asks you to merge the information to the registry click "Yes".

Navigate to the c:\aboutbuster directory and double-click on aboutbuster.exe. As trying to update is causing a problem, do NOT use the Update button.
When the tool is open press the OK button, then the Start button, then the OK button, and then finally the Yes button. It will start scanning your computer for files. If it asks if you would like to do a second pass, allow it to do so. Post the log file in your next reply.

Please restart your system and post a new HijackThis log and the log from AboutBuster (AB Logfile.txt).

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI