Desktop Hijack. What do I remove?
7 min read
welcome back to the TC Forums.
I am in the USA isn't this great?
I have read your log. Let me suggest you copy and paste these instructions into word pad, and print it out so you can follow the steps in order and have a reference, since you will have to restart your computer during the fix
Please read through this post since I am asking you to download specific software to assist you.
This fix of yours may take more than a couple of posts.
good luck
mschroe919
Lets go to work:
FIRST:
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.
Please do not delete anything unless instructed to.
Read this:
I see you have (Piolet) installed .
There have been some pretty nasty infections being spread via "peer to peer file sharing" recently.
Be afraid… Be very, VERY, afraid….
===========================================
As a second thought read this:
http://p2p.malwareremoval.com/
Your Piolet could be why your pc ill?
You dicision however if you want to remove it?
NEXT:
1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed: Removing this is your call:
Again I say optional and your call.
Piolet
NEXT:
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: winapi32.MyBHO - {86A0607D-6126-45AE-8A29-46C181AFF4D6} - C:\WINDOWS\system32\winapi32.dll (file missing)
O2 - BHO: (no name) - {8702d9e1-890b-4bf2-a233-fa44e582b2de} - (no file)
O2 - BHO: (no name) - {9EAC0102-5E61-2312-BC2D-000000000000} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-716d74632608} - (no file)
O2 - BHO: (no name) - {d53b810f-6219-11d4-95b6-0040950375e7} - (no file)
O2 - BHO: (no name) - {dd6f50c0-9f8f-a41c-291e-7b3fb818ef18} - (no file)
O2 - BHO: (no name) - {f21bd77e-0cce-c6cd-4f85-aa3b7895988e} - (no file)
O2 - BHO: (no name) - {ff731508-cd28-e0b0-3e85-0cf55fde9fba} - (no file)
*O4 - HKLM\..\Run: [Piolet] C:\Program Files\Piolet\Piolet.exe SILENT >>>>optional and your call. (See*)
O4 - HKLM\..\Run: [dmqww.exe] C:\WINDOWS\system32\dmqww.exe
O4 - HKLM\..\Run: [yanou.exe] C:\WINDOWS\system32\yanou.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{3C0A1EB3-0053-4389-B68A-F3D6A4164903}: NameServer = 85.255.116.72,85.255.112.140
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E33D33F-CD38-4F1B-8410-6A3DB395DFB1}: NameServer = 85.255.116.72,85.255.112.140
O17 - HKLM\System\CCS\Services\Tcpip\..\{A4057B07-A398-4CA5-95C7-F1C0378AC557}: NameServer = 85.255.116.72 85.255.112.140
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.72 85.255.112.140
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.72 85.255.112.140
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.72 85.255.112.140
O21 - SSODL: SysTray.Exiv - {2963ECFC-4E5C-2f3b-B334-D67434FC72E0} - C:\WINDOWS\system32\aaoejcap.dll (file missing)
Close ALL windows and browsers except HijackThis and click "Fix checked"
Delete these Files in RED if listed: not to worry if not there
C:\WINDOWS\system32\winapi32.dll
C:\Program Files\Piolet\Piolet.exe
C:\WINDOWS\system32\dmqww.exe
C:\WINDOWS\system32\yanou.exe
C:\WINDOWS\system32\aaoejcap.dll
NEXT:
Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe
Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
You will be asked to reboot your computer; please do so.
Your system may take longer than usual to load; this is normal.
Once the desktop loads a text that will open (report.txt) Please save this file, you'll need to post it with a new HijackThis log.
NEXT:
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)
It's normal after running ATF cleaner that the PC will be slower to boot the first time or two
Reboot and "copy/paste" the text file (report.txt) and a new Hijackthis log
Also please describe how your computer behaves at the moment.
There will be more to do after I see the new log and (report.txt)
Good luck mschroe919
=================================================================
welcome back to the TC Forums.
We have more work here.
Some of these infections along with being difficult, they are sneeky.
Please GreatGuy we need to run Fixwareout again, post the log it creates, and also post a new HijackThis! log.
THEN LEAVE THE MACHINE ON AND DON'T REBOOT.
If it reboots, the infections changes names and the fix won't work.
We have to run the program again
Something like this:
So lets do it this way
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!
Browse to c:\fixwareout click and Fixit.bat
This will start Fixwareout again.
After the reboot, post:
1. The fixwareout report
2. A new HijackThis! log
Into this thread.
THEN DO NOT REBOOT UNTIL INSTRUCTED TO DO SO
The infection changes names with each reboot.
After posting shut off monitor and leave PC on till I read the log and fixwareout report,
and get back to you as your next step.
Good luck
mschroe919
welcome back to the TC Forums.
Copy the text in the following quote box into Notepad:
attrib -r -s -h C:\WINDOWS\system32\exsms.exe
attrib -r -s -h C:\WINDOWS\SYSTEM32\DMIMF.EXE
attrib -r -s -h C:\WINDOWS\SYSTEM32\DMJVF.EXE
attrib -r -s -h C:\WINDOWS\SYSTEM32\DMQFU.EXE
attrib -r -s -h C:\WINDOWS\SYSTEM32\DMZTF.EXE
attrib -r -s -h C:\WINDOWS\system32\{F7236E95-42B0-4961-969B-8BBD3593E4AF}.dll
attrib -r -s -h C:\WINDOWS\system32\{0C407C2E-63F2-4EF2-8CAE-2AB82B1FA7BA}.exe
attrib -r -s -h C:\WINDOWS\system32\{345A1913-19A6-471B-B484-404155236499}.exe
attrib -r -s -h C:\WINDOWS\system32\{F44EAD2F-EE34-41AC-AC97-E717C676C710}.exe
attrib -r -s -h C:\WINDOWS\system32\{C4258437-5A76-4DF5-907D-657C60D34AE2}.exe
attrib -r -s -h C:\WINDOWS\system32\{A0255106-2A8D-4F9D-9D99-C7FECB0B64F3}.exe
attrib -r -s -h C:\WINDOWS\system32\{284ACE27-2338-45D8-B5E1-CC58643A1B6C}.exe
attrib -r -s -h C:\WINDOWS\system32\{479F7D2A-5093-46A4-9C7B-5DFABF3D7E1E}.exe
attrib -r -s -h C:\WINDOWS\system32\{BA2B0DAE-A610-4250-8F76-787AAF7CC389}.exe
attrib -r -s -h C:\WINDOWS\system32\{C94F3F1D-EB66-43A6-90DD-FE0329C5BBAC}.exe
attrib -r -s -h C:\WINDOWS\system32\{88CE3C69-B5DB-4197-B9F7-A0DA82F58A1F}.exe
del C:\WINDOWS\system32\exsms.exe
del C:\WINDOWS\SYSTEM32\DMIMF.EXE
del C:\WINDOWS\SYSTEM32\DMJVF.EXE
del C:\WINDOWS\SYSTEM32\DMQFU.EXE
del C:\WINDOWS\SYSTEM32\DMZTF.EXE
del C:\WINDOWS\system32\{F7236E95-42B0-4961-969B-8BBD3593E4AF}.dll
del C:\WINDOWS\system32\{0C407C2E-63F2-4EF2-8CAE-2AB82B1FA7BA}.exe
del C:\WINDOWS\system32\{345A1913-19A6-471B-B484-404155236499}.exe
del C:\WINDOWS\system32\{F44EAD2F-EE34-41AC-AC97-E717C676C710}.exe
del C:\WINDOWS\system32\{C4258437-5A76-4DF5-907D-657C60D34AE2}.exe
del C:\WINDOWS\system32\{A0255106-2A8D-4F9D-9D99-C7FECB0B64F3}.exe
del C:\WINDOWS\system32\{284ACE27-2338-45D8-B5E1-CC58643A1B6C}.exe
del C:\WINDOWS\system32\{479F7D2A-5093-46A4-9C7B-5DFABF3D7E1E}.exe
del C:\WINDOWS\system32\{BA2B0DAE-A610-4250-8F76-787AAF7CC389}.exe
del C:\WINDOWS\system32\{C94F3F1D-EB66-43A6-90DD-FE0329C5BBAC}.exe
del C:\WINDOWS\system32\{88CE3C69-B5DB-4197-B9F7-A0DA82F58A1F}.exe
Save it to your desktop as ff.bat
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!
Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):
O4 - HKLM\..\Run: [exsms.exe] C:\WINDOWS\system32\exsms.exe
Then click "Fix checked".
Now in HijackThis! click on Config –> Misc Tools –> Open Process Manager
In the list of processes, find explorer.exe
Click to highlight, then click "Kill Process". OK any prompts.
Your desktop will disappear, but that is normal. It will come back when you reboot.
Now, in HijackThis!, click:
Run –> browse
Browse to your desktop and click ff.bat –> open –> OK
Browse to c:\fixwareout and click Fixit.bat –> open –> OK
This will start Fixwareout again.
After the reboot, post:
1. The fixwareout report
2. A new HijackThis! log
welcome back to the TC Forums.
A little more work here…getting better.
Please Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:
O17 - HKLM\System\CCS\Services\Tcpip\..\{3C0A1EB3-0053-4389-B68A-F3D6A4164903}: NameServer = 85.255.116.72,85.255.112.140
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E33D33F-CD38-4F1B-8410-6A3DB395DFB1}: NameServer = 85.255.116.72,85.255.112.140
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.72 85.255.112.140
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.72 85.255.112.140
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.72 85.255.112.140
Close ALL windows and browsers except HijackThis and click "Fix checked"
Reboot and post a new log file.
I'll have something ready to fix the desktop in a bit.
Good luck mschroe919
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI