Hi there,
I got a problem. I posted about a few months ago but nobody answered, and now I think it is starting to get severe. I am now nocticing that one of the SVCHOST.EXE processes is not using too much cpu but it is using between 50MB-100MB of ram. Then about 12:30 am this morning, Jan 2, 07, explorer.exe shot-up to 100% cpu and about 110MB ram. This would happen sparaticoly, if that is how you spell it. What I mean is that this would go on for about 2 minutes then go back down to 30% and then back up to 100%. This was doing this for about 45 minutes. As of right now, and I just got back on my computer, my SVCHOST.EXE ram as avg. 52MB of ram, and explorer is back down to 42MB of ram. I also did a virus scan, and McAfee only found 9 minor cookies.
In addition, I first posted in the "Computer problems" forum asking about the SVCHOST.exe problem, but then after I did some research, I found one topic of another guy who sounded like I am having the same problem, and here his topic was that the tech asked him to run some sort of rootkit finder, and here it was the lzx32.sys rootkit. Now I am affraid of running a rootkit finder because McAfee told me not to have too many tools installed because they might conflict with McAfee, and the other reason is I do not know which one to use thinking what if it is a rootkit installer instead of a finder. So to make a long story short, I did a *.sys search on my hard-drive. I did not thankfully find the lzx32.sys rootkit, but I did find 2 other weird files. They are 1731a9bc94.sys and sabprocenum.sys.
Furthermore, I cannot run most of my startup files so I appoligize if this makes things more complicated for you guys when reading my HJT log. However, with what is just running in the background now, I only have about 100 MB of ram left, which if I did run the other stuff it would bring my system down to a craw. So here is my HJT log…
Logfile of HijackThis v1.99.1
Scan saved at 10:06:07 AM, on 1/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
You have a clean log Svchost manages your desktop and uses some resources.
not according to this, and I can't run rootkitRevealer. I did some research, and found a topic about using a tool called smitfraudfx.exe. So this is my scan down below using smitfraudfx.exe
SmitFraudFix v2.132
Scan done at 14:25:54.85, Fri 01/05/2007
Run from C:\Documents and Settings\backupAccount\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
C:\WINDOWS\alxie328.dll FOUND !
C:\WINDOWS\alxtb1.dll FOUND !
C:\WINDOWS\blue-bg.gif FOUND !
C:\WINDOWS\box_1.gif FOUND !
C:\WINDOWS\box_2.gif FOUND !
C:\WINDOWS\box_3.gif FOUND !
C:\WINDOWS\BTGrab.dll FOUND !
C:\WINDOWS\close-bar.gif FOUND !
C:\WINDOWS\dlmax.dll FOUND !
C:\WINDOWS\footer_back.gif FOUND !
C:\WINDOWS\header_1.gif FOUND !
C:\WINDOWS\main_back.gif FOUND !
C:\WINDOWS\Pynix.dll FOUND !
C:\WINDOWS\remove-spyware-btn.gif FOUND !
C:\WINDOWS\sep_hor.gif FOUND !
C:\WINDOWS\sep_vert.gif FOUND !
C:\WINDOWS\spacer.gif FOUND !
C:\WINDOWS\warning-bar-ico.gif FOUND !
C:\WINDOWS\win-sec-center-logo.gif FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
C:\WINDOWS\system32\jao.dll FOUND !
C:\WINDOWS\system32\questmod.dll FOUND !
C:\WINDOWS\system32\tcpservice2.exe FOUND !
C:\WINDOWS\system32\txfdb32.dll FOUND !
C:\WINDOWS\system32\udpmod.dll FOUND !
C:\WINDOWS\system32\winapi32.dll FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\backupAccount
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\backupAccount\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\BACKUP~1\FAVORI~1
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="\\\\?\\C:\\WINDOWS\\system32\\com5.ale"
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"system"="cszvu.exe"
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32
»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
You did indeed have an infection called Smitfraud, What I meant by a clean log is that nothing on HJT looks bad.
It looks like you ran option 1 that gave you the report, lets run Option 2
You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.
In case you need it again
Download SmitfraudFix
Extract the content (a folder named SmitfraudFix) to your Desktop.
Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop.
Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
Once the setup is complete you will need run Ewido and update the definition files.
On the main screen select the icon Update then select the Update now link.
Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
Once in the Settings screen click on Recommended actions and then select Quarantine<– Dont forget this
Under Reports
Select Automatically generate report after every scan
Un-Select Only if threats were found
Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.
Boot your computer into Safemode
Go to Start> Shut Off your Computer> Restart
As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
This will bring up a menu.
Use the Up and Down Arrow Keys to scroll up to SAFEMODE
Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode
Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.
The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".
The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart into normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new HijackThis log.
The report can also be found at the root of the system drive, usually at C:\rapport.txt
Clean out your Temporary Internet files. Proceed like this:
Quit Internet Explorer and quit any instances of Windows Explorer.
Click Start> Control Panel and then double-click Internet Options.
On the General tab, click Delete Files under Temporary Internet Files.
In the Delete Files dialog box, tick the Delete Offline content check box , and then click OK.
On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
Click on the Programs tab then click the Reset Web Settings button.
Click Apply then OK.
Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
Ewido will now begin the scanning process, be patient this may take a little time.
Once the scan is complete do the following:
If you have any infections you will prompted, then select Apply all actions
Next select the Reports icon at the top.
Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
make sure to remember where you saved that file, this is important
Close AVG Anti-Spyware 7.5
IMPORTANT: Do not open any other windows or programs while AVG is scanning, it may interfere with the scanning process:
Post the log from Smitfraud fix, the AVG Spyware log and a New HJT log please
Ok, one thing you are going to shoot me is that I missed your message that I should of cleaned out my tempory internet files. So basically what I did was this in the exact order
1. already had Smitfraud.cmd so I did not need to download that.
2. downloaded AVG Anit-spyware 7.5
3. set the settings in AVG
4. rebooted to safe mode
5. used Smithfraud.cmd option 2 and saved the report
6. rebooted the computer to normal mode
7 ran AVG and saved report
8 Did a HJT log
9. post my logs here which here they are as followed….
HJT…
Logfile of HijackThis v1.99.1
Scan saved at 12:32:32 AM, on 1/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Scan done at 23:06:04.82, Fri 01/05/2007
Run from C:\Documents and Settings\backupAccount\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
C:\WINDOWS\system32\rfscanax.dll -> Adware.AdwareSheriff : No action taken.
D:\owner d drive\AOL Downloads\gozilla.exe -> Adware.EZula : No action taken.
C:\WINDOWS\ho5.exe -> Dropper.Delf.ux : No action taken.
:mozilla.48:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.10:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@sonycorporate.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
:mozilla.30:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.52:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Clickbank : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.54:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.49:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.50:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.51:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\backupAccount\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\backupAccount\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\backupAccount\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.29:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@overture[2].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@edge.ru4[2].txt -> TrackingCookie.Ru4 : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.24:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.25:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.26:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\WINDOWS\system32\csynb.exe -> Trojan.Small.fb : No action taken.
[972] VM_01C30000 -> Trojan.Small.fb : No action taken.
You are doing well, you had no markers in your original HJT for Smithfraud so I am glad you posted the log from it, it looks like that infection is gone.
Look at your AVG log, when you set it up, you have it at No Action Taken you should have changed it to Quarantine or Delete as there are entries in there that are part of smitfraud. I would change it and run AVG again.
You can run this tool to clean you up real well after you run AVG.
Hphmon06.exe
This program is not required to start automatically as you can run it when you need to. It is advised that you disable this program so that it does not take up necessary resources.
You can remove this with HJT. O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
Look at your AVG log, when you set it up, you have it at No Action Taken you should have changed it to Quarantine or Delete as there are entries in there that are part of smitfraud. I would change it and run AVG again.
/quote]
I did changed it to quarantine. I can't look at it now because I got a warning "MALEWARE FOUND" in big red letters which I like to take care of first.
Also I am concerend about my other windows account. I only ran smitFraudFix.cmd through one account called "backupAccount", which I noticed that it only scanned that account. If you look at my first smitFraudFix.cmd report, you will see that the folder C:\documents and settings\backupAccount and subfolders where scanned, but I also have c:\ducuments and settings\owner and sub folders. Would this matter?
Last, as to about the first HJT log, I really appoligize for for not running in normal mode. But like said I could not boot in normal mode because my ram was so low, even without all my startup files running. Also because it took awhile to get help, I had more serious problems that where getting worst to the point that I coudd only boot into safe mode with networking. If you have a second, and this might help you diagnosing with future logs of mine, the last post of the following thread… http://forums.tomcoyote.org/index.php?showtopic=74501&hl descripes the problems that I was having while waiting for someone to post in here. I did this because I did not know what to do since you have this 5 day waiting policy and we should not to reply in your threads before a specialist post back first, and I needed to get through sombody to let you guys know.
Anyways to make a long story short, I will need to fix this warning first and then I will do another AVG scan and post back. Also, with the hphmon06.exe, even though it is not important to have logged on, still it should not be taking 260MB of ram.
Ok, first, like I said when I booted my computer up this morning, I got an AVG warning saying "MALEWARE FOUND!" in Big red letters. After posting the above reply, I went to take care of that warning first by choosing "clean and quarintine (recomended)", and clicked on OK. The warning box went away, and then I right clicked on the AVG icon on the systray, and selected open Main Window. I then double checked to make sure that the settings said "Quarintine". It did. Then I did another scan. After the scan, it reported more medium maleware, and the files from previously that said "take no action" was found again, but would you beleive that the darn same files said "take no action" again. I do not know what I am doing wrong, but AVG is not killing the files. So here is that report…
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 11:22:46 AM 1/6/2007
+ Scan result:
C:\WINDOWS\system32\rfscanax.dll -> Adware.AdwareSheriff : No action taken.
D:\owner d drive\AOL Downloads\gozilla.exe -> Adware.EZula : No action taken.
HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-59D4-4008-9058-080011001200} -> Adware.TitanShieldAntispyware : No action taken.
HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-C1EC-0345-6EC2-4D0300000000} -> Adware.TitanShieldAntispyware : No action taken.
HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-F09C-02B4-6EC2-AD0300000000} -> Adware.TitanShieldAntispyware : No action taken.
HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CEFF6CD-6F08-4E4D-BCCD-FF7415288C3B} -> Adware.TitanShieldAntispyware : No action taken.
HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7B55BB05-0B4D-44FD-81A6-B136188F5DEB} -> Adware.TitanShieldAntispyware : No action taken.
HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8333C319-0669-4893-A418-F56D9249FCA6} -> Adware.TitanShieldAntispyware : No action taken.
HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9C691A33-7DDA-4C2F-BE4C-C176083F35CF} -> Adware.TitanShieldAntispyware : No action taken.
HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E52DEDBB-D168-4BDB-B229-C48160800E81} -> Adware.TitanShieldAntispyware : No action taken.
HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFD2825E-0785-40C5-9A41-518F53A8261F} -> Adware.TitanShieldAntispyware : No action taken.
C:\WINDOWS\ho5.exe -> Dropper.Delf.ux : No action taken.
C:\WINDOWS\system32\csynb.exe -> Trojan.Small.fb : No action taken.
C:\WINDOWS\system32\dmgsv.exe -> Trojan.Small.fb : No action taken.
[264] VM_00B40000 -> Trojan.Small.fb : No action taken.
::Report end
next my HJT program said I do not have write access to this folder. please select another location.
I wonder if the reason is because I logged on as my other account which does not have adminivstrative rights? Could this be possible?
BTW… I atleast got my taskbar back to the way it suppose to look like.
All of the spyware forums have to many posters posting with malware problems to have more than one person helping you, decide which forum you want to stay with and have the courtesy to let us know which forum you want to help you. We all work together and makes no difference to me which one you choose.
All of the spyware forums have to many posters posting with malware problems to have more than one person helping you, decide which forum you want to stay with and have the courtesy to let us know which forum you want to help you. We all work together and makes no difference to me which one you choose.
Ok, I posted there because like I said, my computer was getting worse, and no one had said anything for 4 days. I really did not mean to take 2 people to help me and did not know you guys work together. I thought that maybe another site would of replied faster. Then again, why I posted here was because you directly told me what to do, where the specialist at spyware warrior just asked me if I wanted to format the hardrive, or I will try my best on cleaning the files, not too promising to me. But in any event I would like to stay with tomcoyote if you do not mind since you have aleardy cleaned some of the files.
Also, not to sound cruel or sacrastict or how ever you might take it, and just as a suggestion, maybe you guys could lower the after 5 day no reply policy to maybe after 3 days? It is just a suggestion, and I understand you guys get really swamp, and you are volenteers, but to me it I thought you guys where just ignoring me especially when I kept on seeing the "Views" part was increasing, ut still said 0 replies. I think it would be better if the users would be notified, even if it is a message saying, "I see your message, and someone will get to you as soon as possible. This way the user knows you aknolwede them, and the user can keep on reporting new problems. Or stop using the "we look at the 0 replies first" and instead, let the users reply new updates of what is happening to our computer while we are waiting for a specialist.
As you can see, when I first posted here, my HJT did not look so bad, and I think this was why some of you overlooked at my post because you know that other people have more serious threats. However, in the long run, I had the most threatening virus or maleware or what ever smitfraud is considered as. Also, rembering that I have seen some of these files previously and looking at the dates of the files, some of them have been on my computer since May of 2005 when my Desktop was Hijacked. So in otherwords who knows what this hacker or hackers had or has done to me for almost 2 years now.
Also, I forgot to mention, since I would like to choose this forum, what would you like me to do with why AVG will not kill those certain files? I have set my settings to "Quarentine" but for some reason, AVG will not kill them. And just as a reminder, I also asked about why HJT will not save a report. How would you like me to fix that? It is in the "c:\HijackThis\" directory and I could save logs before.
Ken, do you understand I am sticking with this forum?
Bob, like you said , we are all volunteers and do this whenever we get a spare moment , we all don't just sit in front of our computer 24 hours aday waiting for replies. I understand how frustrating this all is, you just have to use a little patience and we will try to clean you up best we can.
One of the infections you have may be interferring with AVG ??????
Do this and we can procede with some other infections that you have. Log into windows normally as you would when you want to use your computer.
You may want to print out these instructions for reference, since you will have to restart your computer during the fix.
Please download FixWareout from one of these sites: FixWareout Subratam FixWareout Lonny
Save it to your desktop and run it.
Click Next, then Install,
Then make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
You will be asked to reboot your computer; please do so.
Your system may take longer than usual to load; this is normal.
At the end of the fix, you may need to restart your computer again.
Save the contents of the logfile C:\fixwareout\report.txt and post it into your next reply.
Now lets check some settings on your system. For (2000/XP) Only)
Go to Start > control panel.
If you are using Windows XP's Category View, select the Networkand Internet Connections category otherwise double click on Network Connections.
Then right click on your default connection, usually local area connection for cable and dsl.
Left click on properties.
Click the Networking tab.
Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically
Press OK twice to get out of the properties screen and reboot if it asks. That option might not be available on some systems
Next Go start> Run type cmd and hit OK
Type in ipconfig /flushdns then hit enter (that space between g and / is needed)
Type exit hit enter
All the info that Blender gave you over at SpywareWarrior was true and up to date. We may clean your system but its possible that it has been badly compromised so I would refrain from any online transactions that involve personal information.
After you run FixWareout, reboot and run this tool.
Save the tool to your desktop.
Disconnect from internet and shut down any unecessary applications and your antivirus to prevent conflicts.
Double click the tool you just saved.
It may or may not find anything. It should ask if you want to continue regardless. If something is found you will be told to reboot.
Hit OK to continue.
Machine will be rebooted.
The removal tool will start its second phase of scan
Let it finish.
Press exit.
At this time you will be asked if you want to download/install Prevx1. Your choice whether or not to install this. Click no if you don't want it.
I would say no for now at least till we figure out what else is going on.
Log should be in c:\gromozon_removal.log. I will need this later.
Use the link in my signature to download and install a fresh copy of HJT, it will by default install in C:\Program Files\Hijackthis
Post the log from Fix Wareout , Gromozon and a New HJT log.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI