This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] System Error !

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi To all

I need HELP please, i am running XP pro and have now got a System error box appering on screen when using explorer. Saying

System Error!
Your system is infected with Dangerous Virus !
Note Strongly recommend to install Antispyware program to clean your system and avoid total crash of your computer
Click OK to download Antispyware (Recommended)

Attached is my What the Teck log.

Your help will be much appriceatted
Dave

Logfile of HijackThis v1.99.1
Scan saved at 11:32:41, on 26/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\WINDOWS\system32\atwtusb.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\btbb_wcm\McciTrayApp.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\system32\sol.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.co.uk/iesearch/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Video - {DA40137D-AE41-4148-BFEC-916B326D5BBD} - C:\WINDOWS\psoplu.dll
O2 - BHO: (no name) - {E75E99C8-3A9D-50CA-416B-423BF325D19F} - C:\WINDOWS\vgaujhso.dll
O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O3 - Toolbar: (no name) - {8B68564D-53FD-4293-B80C-993A9F3988EE} - (no file)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [desktop] C:\WINDOWS\system32\idemlog.exe
O4 - HKCU\..\Run: [iesetupdll] mozilla-text.exe
O4 - HKCU\..\Run: [Brong32] driver32.exe
O4 - HKCU\..\Run: [dialer423] PasswdMon.exe
O4 - HKCU\..\Run: [Ncao] "C:\WINDOWS\system32\DOBE~1\csrss.exe" -vt yazb
O4 - HKCU\..\Run: [PECarlin] "C:\Program Files\PECarlin\PECarlin.exe"
O4 - HKCU\..\Run: [Jni] C:\WINDOWS\system32\??curity\javaw.exe
O4 - HKCU\..\Run: [AXVenore] "C:\Program Files\AXVenore\AXVenore.exe"
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O8 - Extra context menu item: Search with Freeserve - res://C:\PROGRA~1\FREESE~1\FSBAR\FSBAR.DLL/VSearch.htm
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk/
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200707…ex/qtplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1126739499953
O16 - DPF: {AAD17958-DBDD-423C-AB51-61483DB7B23B} (UKChatroomsClient.client) - http://www.ukchatrooms.net/UKChatroomsClientv2_40.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/bingame/hsol/default/SCEWebLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://msnuk.oberon-media.com/online2/MSN_…ader_v10_en.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{11CB6771-2B47-49DA-B2E7-3C363AE0D327}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{31A04117-1D9B-4495-A643-F2D0BA47FBEA}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{3ED6E991-D768-44FF-98E8-BFBA4506E2DD}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{51448B6A-2FCB-4582-A131-3FD33F202194}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{57B8DB28-1A77-4BC6-B33A-A75315DEAAD0}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{73CD0DFC-4B8E-478F-AF4A-3D9CA0935662}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{8960BB38-BB0D-4C11-81BF-8A34D6F8EF2E}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{9AF193AD-A01A-4576-B426-2FAB265D1F7C}: NameServer = 85.255.113.123 85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{A90C5EEC-9FC0-4CCD-A429-32BDA0782A8E}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABF55655-EC01-4D0B-804B-8F5114DF104A}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{CDD28562-3ED0-4E09-AF8C-8FCAE514014E}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{FC051CE7-7BCA-494F-BF6C-11E40C5A86F6}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.123 85.255.112.186
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.123 85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.123 85.255.112.186
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter hijack: Class Install Handler - (no CLSID) - (no file)
O18 - Filter hijack: lzdhtml - (no CLSID) - (no file)
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE77-738B1E346E99} - (no file)
O18 - Filter: text/plain - {520A7042-8AC4-4991-B4BD-050C1841F405} - (no file)
O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Unknown owner - C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE (file missing)
O23 - Service: Speed Disk service - Unknown owner - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE (file missing)
Hi Dave Copper,

Download FixWareout from here:
http://download.bleepingcomputer.com/lonny/Fixwareout.exe
  • Save it to your desktop and run it. Click Next, then Install, make sure Run fixit is checked and click Finish
  • The fix will begin, follow the prompts
  • You will be asked to reboot your computer, please do so
  • Your system may take longer than usual to load, this is normal
  • Once the desktop loads a file will open called report.txt, post the contents of this in your next response
  • Then click Start->Control Panel->Network Connections
  • Right click your default connection, usually Local Area Connection (or Dial-up Connection if you are using dial-up) and select Properties
  • Under This connection uses the following items, select Internet Protocol (TCP/IP) item and press the Properties button
  • Select the radio button that says Obtain DNS servers automatically and then click OK twice

Then check to see if you have internet access. If it appears you have lost access, please follow these steps in Olive to restore it:
  • Select Start->Control Panel->Network Connections
  • Right click your default connection, usually Local Area Connection (or Dial-up Connection if you are using dial-up) and select Properties
  • Under This connection uses the following items, select Internet Protocol (TCP/IP) item and press the Properties button
  • Select the radio button that says Use the following DNS server addresses:
  • Then enter the following IP addresses into the Preferred and Alternate IP address boxes: 208.67.222.222 and 208.67.220.220
  • Then click OK twice



Then, open HijackThis, choose Do a system scan only and place a checkmark next to the following lines:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Video - {DA40137D-AE41-4148-BFEC-916B326D5BBD} - C:\WINDOWS\psoplu.dll
O2 - BHO: (no name) - {E75E99C8-3A9D-50CA-416B-423BF325D19F} - C:\WINDOWS\vgaujhso.dll
O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O3 - Toolbar: (no name) - {8B68564D-53FD-4293-B80C-993A9F3988EE} - (no file)
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [desktop] C:\WINDOWS\system32\idemlog.exe
O4 - HKCU\..\Run: [iesetupdll] mozilla-text.exe
O4 - HKCU\..\Run: [Brong32] driver32.exe
O4 - HKCU\..\Run: [dialer423] PasswdMon.exe
O4 - HKCU\..\Run: [Ncao] "C:\WINDOWS\system32\DOBE~1\csrss.exe" -vt yazb
O4 - HKCU\..\Run: [PECarlin] "C:\Program Files\PECarlin\PECarlin.exe"
O4 - HKCU\..\Run: [Jni] C:\WINDOWS\system32\??curity\javaw.exe
O4 - HKCU\..\Run: [AXVenore] "C:\Program Files\AXVenore\AXVenore.exe"
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://msnuk.oberon-media.com/online2/MSN_…ader_v10_en.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{11CB6771-2B47-49DA-B2E7-3C363AE0D327}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{31A04117-1D9B-4495-A643-F2D0BA47FBEA}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{3ED6E991-D768-44FF-98E8-BFBA4506E2DD}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{51448B6A-2FCB-4582-A131-3FD33F202194}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{57B8DB28-1A77-4BC6-B33A-A75315DEAAD0}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{73CD0DFC-4B8E-478F-AF4A-3D9CA0935662}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{8960BB38-BB0D-4C11-81BF-8A34D6F8EF2E}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{9AF193AD-A01A-4576-B426-2FAB265D1F7C}: NameServer = 85.255.113.123 85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{A90C5EEC-9FC0-4CCD-A429-32BDA0782A8E}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABF55655-EC01-4D0B-804B-8F5114DF104A}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{CDD28562-3ED0-4E09-AF8C-8FCAE514014E}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{FC051CE7-7BCA-494F-BF6C-11E40C5A86F6}: NameServer = 85.255.113.123,85.255.112.186
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.123 85.255.112.186
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.123 85.255.112.186
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.123 85.255.112.186
O18 - Filter hijack: Class Install Handler - (no CLSID) - (no file)
O18 - Filter hijack: lzdhtml - (no CLSID) - (no file)
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE77-738B1E346E99} - (no file)
O18 - Filter: text/plain - {520A7042-8AC4-4991-B4BD-050C1841F405} - (no file)
O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)

Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.


Download Deckard's System Scanner (DSS) to your Desktop (right-click the link, select Save Target As…, select your Desktop and press Save)
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Make sure Format->Word Wrap is unchecked
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your reply

Once complete, please post the FixWareout report and both DSS logs, you won't need to produce a new HijackThis log as DSS produces one for you.
Do you still need help with your machine? If the instructions are unclear or something isn't working, please let me know before proceeding.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI