Please do not delete anything unless instructed to.
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab. Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders." Clear "Hide protected operating system files."
Click Apply, and then click OK.
Even if you've already run these, make SURE they're up-to-date and run per instructions.
Make sure you have the up-to-date versions of Spybot V 1.4 and Ad-aware SE Build 1.06 . All are free and available below.
Download Spybot, install and update. Then download Ad-aware, install, and update.
Spybot:
Install the program and launch it.
Go to Start > Programs >Spybot > Search & Destroy and choose Spybot S&D
Close ALL windows except Spybot S&D
Click the button to "Search for Updates" and download and install the Updates.
Next click the button "Check for Problems"
When Spybot is complete, it will be showing "RED" (RED) entries "BLACK" entries and "GREEN" (GREEN) entries in the window
Put a check mark beside the RED (RED) entries ONLY.
Choose "Fix Selected Problems" and allow Spybot to fix the RED (RED) entries.
Ad-Aware FULL SCAN:
Install the program and launch it.
1. Launch Ad-Aware SE and run the WebUpdate feature. (Click on the Globe icon > Click connect > Click OK > Click Finish.)
2. Set up the Configurations as follows:
– Click the Gear wheel at the top of the Ad-Aware window
– Click General > Safety & Settings: Check (Green) all three.
– Click Tweak > Cleaning Engine > UNcheck "Always try to unload modules before deletion".
3. Click "Proceed"
4. Click "Scan Now"
5. Deselect "Search for negligible risk entries" as negligible risk entries (MRU's) are not considered to be a threat.
6. Select "Search for low-risk threats"
7. Run the scanner using the Full Scan (Perform full system scan) mode.
8. When the scan has completed, select Next.
9. In the Scanning Results window, select the "Scan Summary" tab.
10. Check the box next to each "target family" you wish to remove.
11. Click next > Click OK.
Next:
Please download the trial version of ewido anti-malware 3.5 here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files. Do NOT run a scan yet.
Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.
Then please run Ewido, click on the Scanner run a full scan and let it clean everything it finds. Save the logfile from the scan.
Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
Also please describe how your computer behaves at the moment.
Please use the [external image: Posted Image] Button below to reply. Thanks
You still have a number of nasty infections, but we'll work on them
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab. Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders." Clear "Hide protected operating system files."
Click Apply, and then click OK.
Please do not delete anything unless instructed to.
Download the trial version of Spy Sweeper from Here
Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)
You will be prompted to check for updated definitions, please do so.
(This may take several minutes)
Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.
Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!
When the sweep has finished, click Remove. Click Select All and then Next
From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.
Exit Spy Sweeper.
Empty Recycle Bin
Reboot and "copy/paste" a new HJT log as well as the Resullts from Spy Sweeper file into this thread.
Also please describe how your computer behaves at the moment.
My computer seems fine right now, no poppups so far..
Here is my HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 3:50:48 PM, on 3/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
********
3:12 PM: | Start of Session, Thursday, March 16, 2006 |
3:12 PM: Spy Sweeper started
3:12 PM: Sweep initiated using definitions version 635
3:12 PM: Found Adware: surfsidekick
3:12 PM: HKLM\software\microsoft\windows\currentversion\run\ || surfsidekick 3 (ID = 1055336)
3:12 PM: Ssk.exe (ID = 1055336)
3:12 PM: HKCR\clsid\{02ee5b04-f144-47bb-83fb-a60bd91b74a9}\inprocserver32\ (2 subtraces) (ID = 1055337)
3:12 PM: SskBho.dll (ID = 1055337)
3:12 PM: Found Adware: internetoptimizer
3:12 PM: HKLM\software\avenue media\internet optimizer\browser helper\ || modulefilename (ID = 1187895)
3:12 PM: nem220.dll (ID = 1187895)
3:12 PM: HKU\S-1-5-21-1177238915-362288127-725345543-1003\software\microsoft\windows\currentversion\run\ || surfsidekick 3 (ID = 1055335)
3:12 PM: Ssk.exe (ID = 1055335)
3:12 PM: Starting Memory Sweep
3:13 PM: Found Adware: webhancer
3:13 PM: Detected running threat: C:\Program Files\webHancer\programs\whiehlpr.dll (ID = 83838)
3:13 PM: Found Adware: quicklink search toolbar
3:13 PM: Detected running threat: C:\windows\system32\w9seq.dll (ID = 259795)
3:14 PM: Found Adware: command
3:14 PM: Detected running threat: C:\WINDOWS\TWFj\asappsrv.dll (ID = 144945)
3:14 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:14 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:15 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:15 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:15 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:15 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:15 PM: Detected running threat: C:\WINDOWS\system32\slk8x2peu.exe (ID = 259744)
3:16 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:18 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:18 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:18 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:18 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:18 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:18 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:18 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:18 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:19 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:19 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:19 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:19 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:19 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:19 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:19 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:19 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:20 PM: Found Adware: dollarrevenue
3:20 PM: Detected running threat: C:\mousepad2.exe (ID = 260103)
3:20 PM: Detected running threat: C:\Program Files\webHancer\Programs\webhdll.dll (ID = 83813)
3:20 PM: Detected running threat: C:\Program Files\Common Files\VCClient\SS1001.exe (ID = 215896)
3:20 PM: Detected running threat: C:\Program Files\Common Files\VCClient\VCClient.exe (ID = 212828)
3:20 PM: HKU\S-1-5-21-1177238915-362288127-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run || CU1 (ID = 0)
3:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:20 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:20 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:20 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:20 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:20 PM: Detected running threat: C:\Program Files\Common Files\VCClient\VCMain.exe (ID = 212830)
3:20 PM: HKU\S-1-5-21-1177238915-362288127-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run || CU2 (ID = 0)
3:20 PM: Found Adware: look2me
3:20 PM: Detected running threat: C:\WINDOWS\system32\gwedit.dll (ID = 163672)
3:21 PM: Detected running threat: C:\WINDOWS\system32\iYsrad.dll (ID = 163672)
3:21 PM: Detected running threat: C:\Program Files\Network Monitor\netmon.exe (ID = 231443)
3:21 PM: Detected running threat: C:\WINDOWS\TWFj\command.exe (ID = 144946)
3:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
Logfile of HijackThis v1.99.1
Scan saved at 3:50:48 PM, on 3/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
In case you loose your internet connection you'll need to run this.
Get a copy of winsockxpfix.exe You just run it and
things should work OK after it reboots your system.
Please do not delete anything unless instructed to.
1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed: newDotNet
Spysweeper
Ewido
Note: Spysweeper and Ewiod are only 14 day trial versions.
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:
Close ALL windows and browsers except HijackThis and click "Fix checked"
delete these files if listed: repairs303169545.dll
C:\Win32\dll\Win32k.exe
C:\Win32\dll\Win32.exe
C:\\keyboard3.exe
C:\\newname3.exe
C:\windows\ms045170341017.exe
C:\windows\upmlqemA.exe
C:\WINDOWS\system32\i4lo0e33eh.dll
C:\windows\system32\gwedit.dll
C:\Program Files\Network Monitor\netmon.exe
C:\windows\upmlqem.exe
Open C:\Windows\Prefetch\ Delete ALL files in this folder.
Do this also if these Temp Folders are part of your OS.
Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.
Next navigate to the C:\Documents and Settings\(EVERY LISTED PROFILE USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.
Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.
Empty the Recycle Bin
Reboot and "copy/paste" a new HijackThis log file into this thread.
Also please describe how your computer behaves at the moment.
Logfile of HijackThis v1.99.1
Scan saved at 10:44:26 PM, on 3/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
no i dont ever use Outlook, although i do have Outlook installed, the closest thing i have matching that file path is: C:\Program Files\Outlook Express, but i dont have C:\Program Files\Outlook\
Start Killbox and click on Tools->Delete Temp Files.
Then select the option labeled Delete on reboot.
Do not close killbox, and open notepad, by clicking on Start, then Run, and typing notepad.exe and pressing the OK button.
When notepad is open, copy and paste the following bolded text into the notepad screen. You do this by highlighting each of the below bolded filenames and then pressing Control-C on your keyboard. Then click on the open notepad windows and press Control-V to paste the contents into the notepad.
C:\windows\system32\repairs303169545.dll
C:\Program Files\outlook\outlook.exe
Return to Killbox, go to the File menu and select Paste from Clipboard.
Still in Killbox, click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click No at the Pending Operations prompt.
If your computer does not restart automatically, please restart it manually