This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HiJack issue

41 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sorry for the late reply, caught up again…
Here's a new HJT log after doing the fixing with SReng
but from what i gather, nothing's changed coz those file/folder still come back.


Logfile of HijackThis v1.99.1
Scan saved at 10:43:09 PM, on 5/10/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\WordWeb\wweb32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsgSys.EXE
c:\windows\system32\wbem\winlogon.exe
C:\Documents and Settings\Patrick\Desktop\Hihack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.7322.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://client.jogo.cn/cdn/browser/sidesear…esearch-en.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://client.jogo.cn/cdn/browser/customse…msearch-en.html
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SYM - {36BF6929-DCBC-4CCD-A620-C5E3BBA77B95} - C:\WINDOWS\System32\usercrd.dll
O2 - BHO: (no name) - {3D898C55-74CC-4B7C-B5F1-45913F368388} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINDOWS\System32\xenroer.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [UnlockerAssistant] ; C:\Program Files\Unlocker\UnlockerAssistant.exe
O4 - HKLM\..\Run: [QuickTime Task] ; "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [WinampAgent] ; C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HP Software Update] ; C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] ; C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [NeroFilterCheck] ; C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [SunJavaUpdateSched] ; "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [vptray] ; C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [VTTimer] ; VTTimer.exe
O4 - HKLM\..\Run: [YhooUapdates] ; C:\WINDOWS\system32\ymssmsgs.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Internet Download Accelerator] ; C:\Program Files\IDA\ida.exe -autorun
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O8 - Extra context menu item: >>²ÊÐÅ·¢ËÍ<< - res://C:\PROGRA~1\MMSASS~1\mmsass~1.dll/mms.htm
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - Extra 'Tools' menuitem: ²ÊE¾«ÁéÉèÖà - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O21 - SSODL: webwork - {4C611512-2C1D-44b2-A044-872AD2AD5A61} - C:\WINDOWS\webwork\webwork.dll
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
splat

We are going to alter the instructions a bit

We need to create another batch fille

First Copy and paste the following into NotePad (Not Wordpad)taskkill /PID 1324
taskkill /PID 1380
taskkill /PID 684
taskkill /PID 1748
taskkill /PID 1780
taskkill /PID 2196
taskkill /PID 2096

Click File ->>Save as ->>type in stop.batUnder "Save as type" Select "all files" ->>Save it to your Desktop
Close Notepad
The stop.bat file should now appear on your Desktop
Double Click that file (It will appear that nothing has happened, but that's o.k.)
Now following the instructions from the previous post

Next Using Windows Search (Click Start->>Search) Making sure your search includes looking in hidden files and Folders)
Locate and delete the following Folders (if found)C:\WINDOWS\System32\MsServices
C:\Program Files\CNNIC
C:\Program Files\Common Files\UPDATE2
C:\PROGRA~1\MMSASS~1
<<-The folder will start with MMSASS->>
C:\Program Files\coolsign
Locate and delete the following files (if found)c:\windows\system32\netwindde.dll
C:\WINDOWS\System32\usercrd.dll
C:\WINDOWS\System32\xenroer.dll
mysvcc.exe
mssvcc.exe
winystems.exe

Next Rerun SREng2
At the main Window and in the Left pane Select "Boot Items"
In the Right pane Click the registry tab
In the List of items listed
Locate the items listed below->>Hilite the items one at a time->>Then Select the Delete ButtonCdnCtr->>C:\Program Files\CNNIC\Cdn\cdnup.exe><<-There will be 2 of these->>
Update->>C:\Program Files\Common Files\UPDATE2\Update.exe>
mysvcig38->>mysvcc.exe><<-There will be 3 of these->>
msconfig38->>; mssvcc.exe>
winystems25->>; winystems.exe>
Then In the left Pane Select System repair
In the right pane Click the Browser Add-ons Tab
Locate the CLSID Numbers below->>Hilite the items one at a time_>>Select the Delete Selected Button
(Note: if you cannot see enough of the CLSID number, place your mouse between CLSID and CLSID1, a divider bar will appear, left click and slide the columb over untill the CLSID is visable){36BF6929-DCBC-4CCD-A620-C5E3BBA77B95}->>C:\WINDOWS\System32\usercrd.dll,
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108}->>C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC
{6671A431-5C3D-463d-A7CF-5587F9B7E191}->>C:\PROGRA~1\MMSASS~1\mmsass~1.dll,
{A64E86D2-203D-4145-AA9B-2425BAF568E9}->>C:\WINDOWS\System32\xenroer.dll,
{1D901067-2529-4A9B-9B6B-7A1DB3A44CB5}->>C:\Program Files\coolsign\coolsign.dll
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108}->>C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll,
{6671A433-5C3D-463d-A7CF-5587F9B7E191}->>C:\PROGRA~1\MMSASS~1\mmsass~1.dll,

Close SREng->>Reboot your PC->>Rerun Hijackthis and post a fresh log
before i continue…i just want to check with you in regards to your first instructions: taskkill /PID 1324 taskkill /PID 1380 taskkill /PID 684 taskkill /PID 1748 taskkill /PID 1780 taskkill /PID 2196 taskkill /PID 2096 i was able to screenshot the process and i get an error message for each one; something like this: taskkill /PID 1324 ERROR: the process "1324" not found should i continue with your other instructions and ignore the errors?
2006-10-10,12:18:18 System Repair Engineer 2.2.6.605 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 1 (Build 2600) - Administrative User - Completed Functions Allowed Follow item(s) have been choosed: All Boot Items (Including Registry, Startup Folders, Services and so on) Browser Add-ons Runing Processes (Including process model information) File Associations Winsock Provider Autorun.Inf HOSTS File Boot Items Registry [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Corporation] <; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [Microsoft Corporation] <; C:\Program Files\IDA\ida.exe -autorun> [N/A] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <; C:\Program Files\Unlocker\UnlockerAssistant.exe> [N/A] <; "C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.] <"C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized> [Anti-Malware Development a.s.] <; C:\Program Files\Winamp\winampa.exe> [N/A] <; C:\Program Files\HP\HP Software Update\HPWuSchd2.exe> [Hewlett-Packard Co.] <; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation] <; C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC> [(Verified)N/A] <; C:\WINDOWS\system32\NeroCheck.exe> [Ahead Software Gmbh] <; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation] <; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation] <; "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"> [Sun Microsystems, Inc.] <; C:\Program Files\NavNT\vptray.exe> [Symantec Corporation] <; VTTimer.exe> [(Verified)S3 Graphics, Inc.] <; C:\WINDOWS\system32\ymssmsgs.exe> [N/A] [N/A] <"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"> [Cyberlink Corp.] <"C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices] [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Corporation] [(Verified)Microsoft Corporation] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{57B86673-276A-48B2-BAE7-C6DBB3020EB8}> [Anti-Malware Development a.s.] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] [MSWebwork Cop.] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon] [N/A] ================================== Startup Folders [WordWeb] C:\PROGRA~1\WordWeb\wweb32.exe [Antony Lewis]> ================================== Services [ASP.NET Work State Service / aspwstate] c:\windows\system32\aspwswin.dll> [Remote Route Service / AtWork] C:\WINDOWS\System32\mssapi.dll> [CA License Client / CA_LIC_CLNT] [COM+ Event System Helper / COMEventHelper] c:\windows\system32\comeventhelper.dll> [DefWatch / DefWatch] [Distributed Logical Disks Manager / DistriDiskMan] c:\windows\system32\wuwebldsv.dll> [ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard] [Human Interface Device Access / HidServ] %SystemRoot%\System32\hidserv.dll> [JMediaService / JMediaService] [Event Log Watch / LogWatch] [MessageService / MessageService] C:\WINDOWS\System32\MsServices\svchost.dll> [WinDDE Service / NetDisDDE] c:\windows\system32\netwindde.dll> [NetFrame Wireless Configuration / NFSWZCSVC] c:\windows\system32\nfswzwin32.dll> [Norton AntiVirus Client / Norton AntiVirus Server] [Pml Driver HPZ12 / Pml Driver HPZ12] ================================== Drivers [Albus / Albus] <\SystemRoot\System32\drivers\Albus.SYS> [ewido anti-spyware 4.0 driver / ewido anti-spyware 4.0 driver] <\??\C:\Program Files\ewido anti-spyware 4.0\guard.sys> [GMSIPCI / GMSIPCI] <\??\D:\INSTALL\GMSIPCI.SYS> [IEEE-1284.4 Driver HPZid412 / HPZid412] [Print Class Driver for IEEE-1284.4 HPZipr12 / HPZipr12] [USB to IEEE-1284.4 Translation Driver HPZius12 / HPZius12] [NAVAP / NAVAP] <\??\C:\Program Files\NavNT\NAVAP.sys> [NAVAPEL / NAVAPEL] <\??\C:\Program Files\NavNT\NAVAPEL.SYS> [NAVENG / NAVENG] <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061004.009\NAVENG.sys> [NAVEX15 / NAVEX15] <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061004.009\NAVEX15.sys> [nwlnksipx / nwlnksipx] <\??\C:\WINDOWS\System32\drivers\nwlnksipx.sys> [nwupspx / nwupspx] <\SystemRoot\System32\drivers\nwupspx.sys> [ProcServ / ProcServ] <\??\C:\WINDOWS\System32\drivers\ProcServ.sys> [Direct Parallel Link Driver / Ptilink] [PxHelp20 / PxHelp20] <\SystemRoot\System32\Drivers\PxHelp20.sys> [RegGuard / RegGuard] <\??\C:\WINDOWS\System32\Drivers\regguard.sys> [Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver / RTL8023xp] [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139] [Secdrv / Secdrv] [SymEvent / SymEvent] <\??\C:\Program Files\Symantec\SYMEVENT.SYS> [VIA AGP Filter / viaagp1] <\SystemRoot\System32\DRIVERS\viaagp1.sys> [viagfx / viagfx] ================================== Browser Add-ons [HelperObject Class] {00C6482D-C502-44C8-8409-FCE54AD9C208} [Adobe PDF Reader Link Helper] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [SYM] {36BF6929-DCBC-4CCD-A620-C5E3BBA77B95} [] {53707962-6F74-2D53-2644-206D7942484F} [Vision] {6671A431-5C3D-463d-A7CF-5587F9B7E191} [SSVHelper Class] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [DDOC] {A64E86D2-203D-4145-AA9B-2425BAF568E9} [Java Plug-in 1.5.0_08] {08B0E5C0-4FCB-11CF-AAA5-00401C608501} [MMSAssistMenu] {6671A433-5C3D-463d-A7CF-5587F9B7E191} [&Research] {92780B25-18CC-41C8-B9BE-3C9C571A8263} [@shdoclc.dll,-866] {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A> [&Radio] {8E718888-423F-11D2-876E-00A0C9082467} [FlashGet Bar] {E0E899AB-F487-11D5-8D29-0050BA6940E3} [SnagIt] {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} [QuickTime Object] {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} [CKAVWebScan Object] {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} [Shockwave ActiveX Control] {166B1BCA-3F9C-11CF-8075-444553540000} [Windows Genuine Advantage Validation Tool] {17492023-C23A-453E-A040-C7C580BBF700} [Java Plug-in 1.5.0_08] {8AD9C840-044E-11D1-B3E9-00805F499D93} [Java Plug-in 1.5.0_08] {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} [Java Plug-in 1.5.0_08] {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [>>²ÊÐÅ·¢ËÍ<<] [Download All by FlashGet] [Download using FlashGet] ================================== Running Processes [PID: 436][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)] [PID: 492][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 516][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)] [C:\WINDOWS\System32\NavLogon.dll] [N/A, N/A] [PID: 568][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 580][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)] [PID: 748][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 800][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 884][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 900][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 1224][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)] [C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll] [Anti-Malware Development a.s., 4, 0, 0, 172] [C:\WINDOWS\webwork\webwork.nls] [MSWebwork Cop., 1, 0, 0, 1] [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0] [C:\WINDOWS\System32\usercrd.dll] [, 1, 0, 0, 1] [C:\PROGRA~1\SPYBOT~1\SDHelper.dll] [Safer Networking Limited, 1, 4, 0, 0] [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.7.2006011200] [C:\PROGRA~1\MMSASS~1\mmsass~1.dll] [, 1, 2, 0, 6] [C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll] [Sun Microsystems, Inc., 5.0.80.3] [PID: 1232][C:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)] [PID: 1276][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)] [C:\WINDOWS\system32\HpTcpMon.dll] [Hewlett Packard, 5.01.00.011] [C:\WINDOWS\system32\hpzjrd01.dll] [Hewlett Packard, 2.01.00.001] [C:\WINDOWS\system32\HPTcpMUI.dll] [Microsoft Corporation, 5.01.00.011] [C:\WINDOWS\system32\hptcpmib.dll] [Hewlett Packard, 5.01.00.011] [C:\WINDOWS\system32\hpz3l3xu.dll] [Hewlett-Packard Company, 60.051.644.00] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\hpzpp3xu.dll] [Hewlett-Packard Corporation, 60.051.644.00] [PID: 1388][C:\Program Files\ewido anti-spyware 4.0\ewido.exe] [Anti-Malware Development a.s., 4, 0, 0, 172] [C:\Program Files\ewido anti-spyware 4.0\engine.dll] [Anti-Malware Development a.s., 4, 0, 0, 172] [PID: 1400][C:\WINDOWS\System32\mysvcc.exe] [N/A, N/A] [PID: 1428][C:\Program Files\WordWeb\wweb32.exe] [Antony Lewis, 4.0.0.0] [C:\WINDOWS\wweb32.dll] [Antony Lewis, 4.0.0.0] [PID: 1668][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 1684][C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe] [Computer Associates International Inc., 0, 1, 3, 1] [C:\Program Files\CA\SharedComponents\CA_LIC\licdscvr.dll] [Computer Associates International Inc., 0, 0, 1, 7] [C:\Program Files\CA\SharedComponents\CA_LIC\licencrypt.dll] [Computer Associates International Inc., 0, 0, 1, 7] [C:\Program Files\CA\SharedComponents\CA_LIC\lic98.dll] [Computer Associates, 01.61.0] [PID: 1716][C:\Program Files\NavNT\defwatch.exe] [Symantec Corporation, 7.60.00.926] [PID: 1756][C:\Program Files\ewido anti-spyware 4.0\guard.exe] [Anti-Malware Development a.s., 4, 0, 0, 172] [C:\Program Files\ewido anti-spyware 4.0\engine.dll] [Anti-Malware Development a.s., 4, 0, 0, 172] [PID: 1776][C:\WINDOWS\System32\rundll32.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\PROGRA~1\MMSASS~1\MMSSVER.DLL] [, 1, 2, 0, 6] [PID: 1796][C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe] [Computer Associates, 1.52] [C:\Program Files\CA\SharedComponents\CA_LIC\lic98.dll] [Computer Associates, 01.61.0] [PID: 1964][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 1976][C:\Program Files\NavNT\rtvscan.exe] [Symantec Corporation, 7.60.00.926] [C:\Program Files\NavNT\Dec2.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2ARJ.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2ID.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2LHA.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\SymLHA.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2LZ.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2MIME.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2Zip.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2AMG.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\SYMAMG32.DLL] [Symantec Corporation with portions by FUJITSU DEVICES INC., 2.50.31.52] [C:\Program Files\NavNT\Dec2UUE.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2SS.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2RTF.dll] [Symantec Corporation, 2.50.31.52] [C:\WINDOWS\System32\CBA.DLL] [Intel Corporation, 6.0.201.0940 E] [C:\WINDOWS\System32\MsgSys.dll] [Intel Corporation, 6.0.201.0940 E] [C:\WINDOWS\System32\NTS.dll] [Intel Corporation, 6.0.201.0940 E] [C:\WINDOWS\System32\PDS.DLL] [Intel Corporation, 6.0.201.0940 E] [C:\Program Files\NavNT\NAVLU.dll] [Symantec Corporation, 7.60.00.926] [C:\Program Files\NavNT\NAVNTUTL.DLL] [Symantec/Peter Norton Group, 1, 0, 0, 1] [C:\Program Files\NavNT\i2ldvp3.dll] [Symantec Corporation, 7.60.00.926] [C:\Program Files\NavNT\NAVAPI32.DLL] [Symantec Corp., 4.1.0.15] [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061004.009\NAVEX32a.DLL] [Symantec Corporation, 20061.3.0.12] [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061004.009\NAVENG32.DLL] [Symantec Corporation, 20061.3.0.12] [C:\Program Files\NavNT\NAVAP32.DLL] [Symantec Corporation, 5.3.1.39] [C:\WINDOWS\System32\amslib.dll] [Intel Corporation, 6.0.201.0940 E] [C:\WINDOWS\System32\loc32vc0.dll] [Intel, 3, 0, 0, 2] [C:\PROGRA~1\COMMON~1\SYMANT~1\SSC\scandlgs.dll] [Symantec Corporation, 7.60.00.926] [C:\PROGRA~1\COMMON~1\SYMANT~1\SSC\LDVPCtls.ocx] [Symantec Corporation, 7.60.00.926] [PID: 2000][C:\WINDOWS\system32\HPZipm12.exe] [HP, 9, 0, 0, 0] [PID: 2036][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\WINDOWS\System32\hpowiamd.dll] [Hewlett-Packard, 3.2.2.905] [PID: 1460][C:\WINDOWS\System32\MsgSys.EXE] [Intel Corporation, 6.0.201.0940 E] [C:\WINDOWS\System32\NTS.dll] [Intel Corporation, 6.0.201.0940 E] [C:\WINDOWS\System32\CBA.DLL] [Intel Corporation, 6.0.201.0940 E] [C:\WINDOWS\System32\MsgSys.dll] [Intel Corporation, 6.0.201.0940 E] [C:\WINDOWS\System32\PDS.DLL] [Intel Corporation, 6.0.201.0940 E] [PID: 2080][c:\windows\system32\wbem\winlogon.exe] [Microsoft, 1.0.0.0] [PID: 2676][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 3848][C:\Program Files\CyberLink\Shared files\RichVideo.exe] [, 1.1.0808 ] [PID: 3484][C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe] [Cyberlink Corp., 5.00.0910] [C:\Program Files\CyberLink\PowerDVD\CLRCEngine3.dll] [CyberLink Corp., 4, 5, 0, 1711] [PID: 3336][C:\Documents and Settings\Patrick\Desktop\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605] ================================== File Associations .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock Provider N/A ================================== Autorun.Inf N/A ================================== HOSTS File 127.0.0.1 localhost ==================================
splat

Sorry for the delay, have been doing research on this infection. It does look like the Cinnic folder is gone. :)

Please download Boran Remover from one of the following places and save it to your Desktop:

http://download.bleepingcomputer.com/sUBs/boran-remover.exe

http://www.techsupportforum.com/sectools/boran-remover.exe
Close all open windows.
Double-click boran-remover.exe to start the tool.
Your computer will reboot if an infection is found.
If the tool is unable to neutralize the infection, it will reboot again for another attempt.
When the tool is finished, it will save a log called boran.log in the boran-remover folder on your Desktop.
Copy and paste that log as a reply

thanks bamajim
Boran Remover :: 2006-10-06 :: 18 —————————————————————- Run by [removed] Found C:\WINDOWS\system32\drivers\albus.sys Found C:\WINDOWS\system32\stdup.dll Found C:\WINDOWS\system32\stdsver.dll Found C:\Program Files\MMSAssist\mmsass~1.dll Found C:\Program Files\MMSAssist\mmssver.dll Rebooting… Attempting to disable albus.sys… Successful! Attempting to remove files and directories: C:\WINDOWS\system32\almms.dat C:\WINDOWS\system32\alpst.dat C:\WINDOWS\system32\extern.ini C:\WINDOWS\system32\std.ini C:\WINDOWS\system32\stdd.ini C:\WINDOWS\system32\STDSVER.DLL C:\WINDOWS\system32\stdup.dll C:\WINDOWS\system32\updadini.ini C:\WINDOWS\system32\updstdex.ini C:\WINDOWS\system32\updstdup.ini C:\Program Files\MMSAssist C:\WINDOWS\system32\exuppsh C:\WINDOWS\system32\stdcache C:\WINDOWS\system32\updadini C:\WINDOWS\system32\updstdex C:\WINDOWS\system32\updstdup C:\WINDOWS\Temp\exuppsh C:\WINDOWS\Temp\insmms5 C:\WINDOWS\Temp\inspst Cleaning Registry… Done!
Bamajim.. can you check if there's a new infection on my HJT log because i've started getting new popups that constantly show up every few seconds.

it seems to do with C:\WINDOWS\system32\wldll.dll

Splat

Logfile of HijackThis v1.99.1
Scan saved at 9:14:13 PM, on 15/10/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Patrick\Desktop\Hihack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.7322.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://client.jogo.cn/cdn/browser/customse…msearch-en.html
F3 - REG:win.ini: load=C:\WINDOWS\rundl132.exe
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5025.dll
O2 - BHO: SYM - {36BF6929-DCBC-4CCD-A620-C5E3BBA77B95} - C:\WINDOWS\System32\usercrd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [UnlockerAssistant] ; C:\Program Files\Unlocker\UnlockerAssistant.exe
O4 - HKLM\..\Run: [QuickTime Task] ; "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [WinampAgent] ; C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HP Software Update] ; C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] ; C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [NeroFilterCheck] ; C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [SunJavaUpdateSched] ; "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [VTTimer] ; VTTimer.exe
O4 - HKLM\..\Run: [mysvcig38] mysvcc.exe
O4 - HKLM\..\Run: [realtpsk] C:\WINDOWS\system\realsched.exe
O4 - HKLM\..\Run: [Tray] C:\WINDOWS\command\rundll32.exe
O4 - HKLM\..\Run: [rzt] C:\WINDOWS\Intel\rundll32.exe
O4 - HKLM\..\Run: [ms] C:\Program Files\Microsoft\svhost32.exe
O4 - HKLM\..\Run: [wl] C:\WINDOWS\Download\svhost32.exe
O4 - HKLM\..\RunServices: [mysvcig38] mysvcc.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Internet Download Accelerator] ; C:\Program Files\IDA\ida.exe -autorun
O4 - HKCU\..\Run: [updatereal] C:\WINDOWS\realupdate.exe other
O4 - HKCU\..\Run: [msnnt] C:\WINDOWS\winampe.exe
O4 - HKCU\..\Run: [SaveMail] C:\WINDOWS\System32\MSSOFT\winampe.exe
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Chinese Navigation - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Chinese Navigation - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Network Logons (NetWorkLogons) - Unknown owner - rundll32.exe (file missing)
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
splat

Sure, it looks like the tool worked for the one infection

First Copy and paste the following into NotePad (Not Wordpad)sc stop NetWorkLogons
sc delete NetWorkLogons

Click File ->>Save as ->>type in net.batUnder "Save as type" Select "all files" ->>Save it to your Desktop
Close Notepad
The net.bat file should now appear on your Desktop
Double Click that file (It will appear that nothing has happened, but that's o.k.)
1. Please download Brute Force Uninstaller to your desktop.
  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk (C:) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
2. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS Remover.

Save it in the same folder you made earlier (c:\BFU).

Reboot your PC into Safe Mode
This can be done byRestart your PC, and after it starts, but before you see the Windows Splash screen
Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
Use your arrow keys and select Safe Mode and then Enter
3. Then ReRun Ewido (in safe mode)

4. Then, please go to Start > My Computer and navigate to the C:\BFU folder.
  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • Behind the scriptline to execute field click the folder icon [external image: Posted Image] and select alcanshorty.bfu
  • Press Execute and let the program do it’s job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Press exit to terminate the BFU program.
Reboot into normal windows and post the contents of Ewido text report that you saved and a new HiJackThis log.

Your reply should includeyour new repost_scan.txt from Ewido
a fresh Hijackthis log
Thanks bamajim
——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 6:53:01 PM 16/10/2006 + Scan result: C:\Program Files\MMSAssist\albus.dll -> Adware.Baidu : Cleaned with backup (quarantined). C:\WINDOWS\system32\alsmt.exe -> Adware.Baidu : Cleaned with backup (quarantined). C:\WINDOWS\system32\drivers\Albus.SYS -> Adware.Baidu : Cleaned with backup (quarantined). C:\Program Files\MMSAssist\mmsass~1.dll -> Adware.Boran : Cleaned with backup (quarantined). C:\Program Files\MMSAssist\mmssver.dll -> Adware.Boran : Cleaned with backup (quarantined). C:\WINDOWS\system32\STDSVER.DLL -> Adware.Boran : Cleaned with backup (quarantined). C:\WINDOWS\system32\stdup.dll -> Adware.Boran : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\SearchHook.URLSearchHook -> Adware.CrackedEarth : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\SearchHook.URLSearchHook.1 -> Adware.CrackedEarth : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\SearchHook.URLSearchHook\CLSID -> Adware.CrackedEarth : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\SearchHook.URLSearchHook\CurVer -> Adware.CrackedEarth : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\CLSID\{6671A431-5C3D-463d-A7CF-5587F9B7E191} -> Adware.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\CLSID\{6A512BF7-EC78-4e8d-9841-6C02E8FA9838} -> Adware.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\TypeLib\{2511DE40-34A3-4C6A-B1B2-C5C92A2F00BE} -> Adware.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6671A431-5C3D-463d-A7CF-5587F9B7E191} -> Adware.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A512BF7-EC78-4e8d-9841-6C02E8FA9838} -> Adware.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6A512BF7-EC78-4e8d-9841-6C02E8FA9838} -> Adware.Generic : Cleaned with backup (quarantined). C:\winla\winla.exe -> Downloader.Small.dtt : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\SearchHook.SrchHook -> Hijacker.ShopNav : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\SearchHook.SrchHook.1 -> Hijacker.ShopNav : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\SearchHook.SrchHook\CLSID -> Hijacker.ShopNav : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\SearchHook.SrchHook\CurVer -> Hijacker.ShopNav : Cleaned with backup (quarantined). C:\WINDOWS\system32\dllwm.dll -> Trojan.Lineage.ahq : Cleaned with backup (quarantined). C:\WINDOWS\system32\360safe.exe -> Trojan.WOW.el : Cleaned with backup (quarantined). ::Report end
i have a slight problem…can't open hjthis program…double click and it doesn't open tried reinstalling but that didn't do anything. any suggestion? splat
bamajim… my pc has gone haywire… it resets alot and started coming out with a lot of errors; i must've done something wrong during the process. I'm going to save all my stuff and format my harddrive.. i think that's the best way of clearing all the problem. Very sorry to have bothered you with all this and wasted your time. i just have one last request. can you tell me how i can protect my computer from future infections? splat
splat

I'm sorry you are having this kind of problem, and you have not wasted my time at all :)

I would be glad to. However before you reformat and you have your OS (operating system) disk, there is something I'd like you to try first.

Click Start->>Run->> and type in sfc /scannow (there is a space between sfc and /) ->>Then O.k.

This will check the condition of the system files,. you may be prompted to install your OS disk if there are some corrupted files.

If thats a no go, then after the reformat post another Hijackthis log for me, to make sure it's clean and I will post prevention measures.

thanks bamajim

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI