Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
NEED HELP!
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > NEED HELP!  
Forum Quick Jump
 
New Topic Locked Topic Printable version of : NEED HELP!
[ << Previous Thread | Next Thread >> ]

imatrickha
New Member


Date Joined Jun 2004
Total Posts : 7
 
   Posted 7-28-2004 1:50 (GMT +2)    Quote: NEED HELP!Alert an admin about: NEED HELP!
First of all I am running Windows ME, yes I know it's trash. Anyhow.... I some how now cannot use IE because everytime I try and open it, it crashes. I seem to have a lot of MSIE BHO's i have Hijackthis.exe software along with registry mechanic and cwshredder which no longer detects anything but Hijackthis is constantly deleting them and then they come right back the same ones minutes later when i another scan. Registry Mechanic at first found 800+ errors fixed them all and now will find 110 delete them but if i scan again they're back. I tried some tool called BHOremover with no success as well. I'm stuck....what's next? My homepage keeps getting changed to some crap on IE res:// something or other I can change it from IE properties but when i open IE and try to go to a page it still crashes. What can I do to remove this crap? here's the log from hijack this
 
Logfile of HijackThis v1.97.7
Scan saved at 6:37:42 PM, on 7/27/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\APIWP32.EXE
C:\WINDOWS\SYSTEM\NETHJ32.EXE
C:\WINDOWS\SYSTEM\MFCYJ32.EXE
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\SYSTEM\NETHJ32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\AMERICA ONLINE 9.0\WAOL.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE
C:\PROGRAM FILES\AMERICA ONLINE 9.0\SHELLMON.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\AMERICA ONLINE 9.0\AOLWBSPD.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\APIUW32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\REGISTRY MECHANIC\REGMECH.EXE
C:\WINDOWS\SYSTEM\NETHJ32.EXE
C:\WINDOWS\SYSTEM\NETHJ32.EXE
C:\WINDOWS\SYSTEM\IEAU.EXE
C:\WINDOWS\D3FN32.EXE
C:\WINDOWS\APIWP32.EXE
C:\WINDOWS\APIWP32.EXE
C:\WINDOWS\APIWP32.EXE
C:\WINDOWS\SYSTEM\D3HR.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\SYSTEM\MFCBA32.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\IEDJ.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\APIWP32.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\SYSTEM\D3HR.EXE
C:\WINDOWS\SYSTEM\D3HR.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\SYSTEM\D3HR.EXE
C:\WINDOWS\SYSTEM\APIUW32.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\SYSTEM\D3HR.EXE
C:\WINDOWS\SYSTEM\APIUW32.EXE
C:\WINDOWS\SYSTEM\IEAU.EXE
C:\WINDOWS\TEMP\TD_0003.DIR\HIJACKTHIS.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\SYSTEM\APIUW32.EXE
C:\WINDOWS\SYSTEM\IEAU.EXE
C:\WINDOWS\APIWP32.EXE
O2 - BHO: (no name) - {14CF1741-1536-6D1D-8C45-53936B2AC35B} - C:\WINDOWS\SYSTEM\NTFA.DLL (file missing)
O2 - BHO: (no name) - {F74A5390-42AD-D680-DFCE-850A678681CD} - C:\WINDOWS\SYSTEM\APPEH32.DLL (file missing)
O2 - BHO: (no name) - {6BE5C394-AA25-266E-D794-88256569CD9D} - C:\WINDOWS\D3RO32.DLL
O2 - BHO: (no name) - {CF3F3E61-9595-B4D3-EC0A-2911D33AF9CA} - C:\WINDOWS\NETWX.DLL
O2 - BHO: (no name) - {D8DD2012-1BEC-74D3-2065-8D04FFA52092} - C:\WINDOWS\IPAC.DLL (file missing)
O2 - BHO: (no name) - {43E92535-41C0-42A6-6DD1-EC22B7AA19CC} - C:\WINDOWS\MSDZ32.DLL (file missing)
O2 - BHO: (no name) - {1258EF1B-3DEF-334F-DB40-B3E344FFB374} - C:\WINDOWS\SYSTEM\APIWA32.DLL
O2 - BHO: (no name) - {877E32FD-53A0-0D73-8770-3C53B7A199C8} - C:\WINDOWS\CRSP32.DLL
O2 - BHO: (no name) - {D1BFA6A7-7A01-DE0C-1BB3-A5E88C3429FE} - C:\WINDOWS\SYSTEM\IPPV.DLL
 
Back to Top
 

imatrickha
New Member


Date Joined Jun 2004
Total Posts : 7
 
   Posted 7-28-2004 2:04 (GMT +2)    Quote: NEED HELP!Alert an admin about: NEED HELP!
NEW Hijack Scan with all the files returning
Logfile of HijackThis v1.97.7
Scan saved at 7:02:32 PM, on 7/27/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\APIWP32.EXE
C:\WINDOWS\SYSTEM\NETHJ32.EXE
C:\WINDOWS\SYSTEM\MFCYJ32.EXE
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\SYSTEM\NETHJ32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\AMERICA ONLINE 9.0\WAOL.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE
C:\PROGRAM FILES\AMERICA ONLINE 9.0\SHELLMON.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\AMERICA ONLINE 9.0\AOLWBSPD.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\APIUW32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\REGISTRY MECHANIC\REGMECH.EXE
C:\WINDOWS\SYSTEM\NETHJ32.EXE
C:\WINDOWS\SYSTEM\NETHJ32.EXE
C:\WINDOWS\SYSTEM\IEAU.EXE
C:\WINDOWS\D3FN32.EXE
C:\WINDOWS\APIWP32.EXE
C:\WINDOWS\APIWP32.EXE
C:\WINDOWS\APIWP32.EXE
C:\WINDOWS\SYSTEM\D3HR.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\SYSTEM\MFCBA32.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\IEDJ.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\APIWP32.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\SYSTEM\D3HR.EXE
C:\WINDOWS\SYSTEM\D3HR.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\SYSTEM\D3HR.EXE
C:\WINDOWS\SYSTEM\APIUW32.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\SYSTEM\D3HR.EXE
C:\WINDOWS\SYSTEM\APIUW32.EXE
C:\WINDOWS\SYSTEM\IEAU.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\SYSTEM\APIUW32.EXE
C:\WINDOWS\SYSTEM\IEAU.EXE
C:\WINDOWS\APIWP32.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\IEMI32.EXE
C:\WINDOWS\SYSTEM\SDKRO32.EXE
C:\WINDOWS\SYSTEM\D3HR.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\SYSTEM\APIUW32.EXE
C:\WINDOWS\SYSTEM\IEAU.EXE
C:\WINDOWS\IEDJ.EXE
C:\WINDOWS\TEMP\TD_0005.DIR\HIJACKTHIS.EXE
C:\WINDOWS\SYSTEM\APIUW32.EXE
C:\WINDOWS\IPBL32.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\dnbwg.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://dnbwg.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://dnbwg.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\dnbwg.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://dnbwg.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\dnbwg.dll/sp.html#96676
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
O2 - BHO: (no name) - {14CF1741-1536-6D1D-8C45-53936B2AC35B} - C:\WINDOWS\SYSTEM\NTFA.DLL (file missing)
O2 - BHO: (no name) - {F74A5390-42AD-D680-DFCE-850A678681CD} - C:\WINDOWS\SYSTEM\APPEH32.DLL
O2 - BHO: (no name) - {6BE5C394-AA25-266E-D794-88256569CD9D} - C:\WINDOWS\D3RO32.DLL
O2 - BHO: (no name) - {CF3F3E61-9595-B4D3-EC0A-2911D33AF9CA} - C:\WINDOWS\NETWX.DLL (file missing)
O2 - BHO: (no name) - {D8DD2012-1BEC-74D3-2065-8D04FFA52092} - C:\WINDOWS\IPAC.DLL (file missing)
O2 - BHO: (no name) - {43E92535-41C0-42A6-6DD1-EC22B7AA19CC} - C:\WINDOWS\MSDZ32.DLL
O2 - BHO: (no name) - {1258EF1B-3DEF-334F-DB40-B3E344FFB374} - C:\WINDOWS\SYSTEM\APIWA32.DLL
O2 - BHO: (no name) - {877E32FD-53A0-0D73-8770-3C53B7A199C8} - C:\WINDOWS\CRSP32.DLL
O2 - BHO: (no name) - {D1BFA6A7-7A01-DE0C-1BB3-A5E88C3429FE} - C:\WINDOWS\SYSTEM\IPPV.DLL
O4 - HKLM\..\Run: [SDKRO32.EXE] C:\WINDOWS\SYSTEM\SDKRO32.EXE
O4 - HKLM\..\RunServices: [APIUU.EXE] C:\WINDOWS\SYSTEM\APIUU.EXE
O4 - HKLM\..\RunServices: [APISE.EXE] C:\WINDOWS\APISE.EXE
O4 - HKLM\..\RunServices: [IEMI32.EXE] C:\WINDOWS\IEMI32.EXE
O4 - HKLM\..\RunServices: [D3HR.EXE] C:\WINDOWS\SYSTEM\D3HR.EXE
O4 - HKLM\..\RunServices: [APIUW32.EXE] C:\WINDOWS\SYSTEM\APIUW32.EXE
O4 - HKLM\..\RunServices: [IEAU.EXE] C:\WINDOWS\SYSTEM\IEAU.EXE
O4 - HKLM\..\RunServices: [IEDJ.EXE] C:\WINDOWS\IEDJ.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\dnbwg.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://dnbwg.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://dnbwg.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\dnbwg.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://dnbwg.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\dnbwg.dll/sp.html#96676
O2 - BHO: (no name) - {14CF1741-1536-6D1D-8C45-53936B2AC35B} - C:\WINDOWS\SYSTEM\NTFA.DLL (file missing)
O2 - BHO: (no name) - {F74A5390-42AD-D680-DFCE-850A678681CD} - C:\WINDOWS\SYSTEM\APPEH32.DLL
O2 - BHO: (no name) - {6BE5C394-AA25-266E-D794-88256569CD9D} - C:\WINDOWS\D3RO32.DLL
O2 - BHO: (no name) - {CF3F3E61-9595-B4D3-EC0A-2911D33AF9CA} - C:\WINDOWS\NETWX.DLL (file missing)
O2 - BHO: (no name) - {D8DD2012-1BEC-74D3-2065-8D04FFA52092} - C:\WINDOWS\IPAC.DLL (file missing)
O2 - BHO: (no name) - {43E92535-41C0-42A6-6DD1-EC22B7AA19CC} - C:\WINDOWS\MSDZ32.DLL
O2 - BHO: (no name) - {1258EF1B-3DEF-334F-DB40-B3E344FFB374} - C:\WINDOWS\SYSTEM\APIWA32.DLL
O2 - BHO: (no name) - {877E32FD-53A0-0D73-8770-3C53B7A199C8} - C:\WINDOWS\CRSP32.DLL
O2 - BHO: (no name) - {D1BFA6A7-7A01-DE0C-1BB3-A5E88C3429FE} - C:\WINDOWS\SYSTEM\IPPV.DLL
O4 - HKLM\..\Run: [SDKRO32.EXE] C:\WINDOWS\SYSTEM\SDKRO32.EXE
O4 - HKLM\..\RunServices: [APIUU.EXE] C:\WINDOWS\SYSTEM\APIUU.EXE
O4 - HKLM\..\RunServices: [APISE.EXE] C:\WINDOWS\APISE.EXE
O4 - HKLM\..\RunServices: [IEMI32.EXE] C:\WINDOWS\IEMI32.EXE
O4 - HKLM\..\RunServices: [D3HR.EXE] C:\WINDOWS\SYSTEM\D3HR.EXE
O4 - HKLM\..\RunServices: [APIUW32.EXE] C:\WINDOWS\SYSTEM\APIUW32.EXE
O4 - HKLM\..\RunServices: [IEAU.EXE] C:\WINDOWS\SYSTEM\IEAU.EXE
O4 - HKLM\..\RunServices: [IEDJ.EXE] C:\WINDOWS\IEDJ.EXE
Back to Top
 

imatrickha
New Member


Date Joined Jun 2004
Total Posts : 7
 
   Posted 7-28-2004 3:34 (GMT +2)    Quote: NEED HELP!Alert an admin about: NEED HELP!
anyone???
Back to Top
 

imatrickha
New Member


Date Joined Jun 2004
Total Posts : 7
 
   Posted 7-28-2004 4:15 (GMT +2)    Quote: NEED HELP!Alert an admin about: NEED HELP!
ok update ran bullguard got 6 viruses removed one called demiser ever heard of it? now here's what the log looks like
Logfile of HijackThis v1.97.7
Scan saved at 9:18:01 PM, on 7/27/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\IEDJ.EXE
C:\WINDOWS\IPBL32.EXE
C:\WINDOWS\SYSTEM\D3HR.EXE
C:\WINDOWS\SYSTEM\IEAU.EXE
C:\WINDOWS\SYSTEM\APIUW32.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\IEMI32.EXE
C:\WINDOWS\APISE.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\IEAU.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSIMPL.EXE
C:\PROGRAM FILES\REGISTRY MECHANIC\REGMECH.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\TEMP\TD_0001.DIR\HIJACKTHIS.EXE
C:\WINDOWS\SYSTEM\APIUW32.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\WINDOWS\D3RO32.EXE
C:\WINDOWS\SYSTEM\APIUU.EXE
C:\PROGRAM FILES\WINAMP3\STUDIO.EXE
C:\PROGRAM FILES\AMERICA ONLINE 9.0\WAOL.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE
C:\PROGRAM FILES\AMERICA ONLINE 9.0\SHELLMON.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHCHEST.EXE
C:\PROGRAM FILES\AMERICA ONLINE 9.0\AOLWBSPD.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YUPDATER.EXE
C:\WINDOWS\SYSTEM\WINPE32.EXE
C:\PROGRAM FILES\AIM\AIM.EXE

O2 - BHO: (no name) - {6BE5C394-AA25-266E-D794-88256569CD9D} - C:\WINDOWS\D3RO32.DLL
O2 - BHO: (no name) - {1258EF1B-3DEF-334F-DB40-B3E344FFB374} - C:\WINDOWS\SYSTEM\APIWA32.DLL
O2 - BHO: (no name) - {7A23E735-EC07-BB26-5CF0-DCDEBB6EADC9} - C:\WINDOWS\SDKWN.DLL (file missing)
O2 - BHO: (no name) - {F74A5390-42AD-D680-DFCE-850A678681CD} - C:\WINDOWS\SYSTEM\APPEH32.DLL (file missing)
O2 - BHO: (no name) - {D1BFA6A7-7A01-DE0C-1BB3-A5E88C3429FE} - C:\WINDOWS\SYSTEM\IPPV.DLL (file missing)
O2 - BHO: (no name) - {F4A41C9A-A713-9C96-601E-1966003429F8} - C:\WINDOWS\ADDKE.DLL (file missing)
O2 - BHO: (no name) - {3EE94CC3-A0CC-8BC2-F84A-9FBD535910A6} - C:\WINDOWS\SYSTEM\D3AT.DLL
O4 - HKLM\..\RunServices: [WINPE32.EXE] C:\WINDOWS\SYSTEM\WINPE32.EXE
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM\aim.exe -cnetwait.odl
O9 - Extra button: AIM (HKLM)
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 18005
 
   Posted 7-28-2004 5:07 (GMT +2)    Quote: NEED HELP!Alert an admin about: NEED HELP!
Hi imatrickha
 
The last log file, looks a bit short!
 
Please scan again with HJT, scan button change to save log, post this file:-)
 
If i am wrong, sorryrolleyes
Back to Top
 

imatrickha
New Member


Date Joined Jun 2004
Total Posts : 7
 
   Posted 7-29-2004 12:55 (GMT +2)    Quote: NEED HELP!Alert an admin about: NEED HELP!
Logfile of HijackThis v1.97.7
Scan saved at 5:47:54 PM, on 7/28/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\SYSKW.EXE
C:\WINDOWS\SYSTEM\APILW.EXE
C:\WINDOWS\SYSTEM\WINCY.EXE
C:\WINDOWS\SDKUY.EXE
C:\WINDOWS\NETEJ.EXE
C:\WINDOWS\SYSTEM\SDKCQ.EXE
C:\WINDOWS\CRRR.EXE
C:\WINDOWS\IEMI32.EXE
C:\WINDOWS\SYSTEM\APPVC32.EXE
C:\WINDOWS\SYSTEM\WINPE32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\D3RO32.EXE
C:\WINDOWS\SYSTEM\SYSKW.EXE
C:\WINDOWS\CRRR.EXE
C:\WINDOWS\CRRR.EXE
C:\WINDOWS\NETEJ.EXE
C:\WINDOWS\SYSTEM\APPVC32.EXE
C:\WINDOWS\CRRR.EXE
C:\WINDOWS\SYSTEM\SYSKW.EXE
C:\WINDOWS\SYSTEM\APPVC32.EXE
C:\WINDOWS\NETEJ.EXE
C:\WINDOWS\TEMP\TD_0001.DIR\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\nrlfq.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://nrlfq.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://nrlfq.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\nrlfq.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://nrlfq.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\nrlfq.dll/sp.html#96676
O2 - BHO: (no name) - {6BE5C394-AA25-266E-D794-88256569CD9D} - C:\WINDOWS\D3RO32.DLL (file missing)
O2 - BHO: (no name) - {F4A41C9A-A713-9C96-601E-1966003429F8} - C:\WINDOWS\ADDKE.DLL (file missing)
O2 - BHO: (no name) - {B368DFA6-172D-988C-124B-8A24C7FBA651} - C:\WINDOWS\SYSTEM\SYSYP32.DLL (file missing)
O2 - BHO: (no name) - {8F30B32A-F793-7B48-2B17-6EB4E169E8EB} - C:\WINDOWS\SDKHQ32.DLL (file missing)
O2 - BHO: (no name) - {2B86B621-D1DC-1979-E5BC-338CC5E8A0CD} - C:\WINDOWS\ATLKC.DLL (file missing)
O2 - BHO: (no name) - {1258EF1B-3DEF-334F-DB40-B3E344FFB374} - C:\WINDOWS\SYSTEM\APIWA32.DLL (file missing)
O2 - BHO: (no name) - {1DE16B10-FCB7-8977-CAF4-0AEB7D77FC72} - C:\WINDOWS\SYSTEM\MSZU32.DLL (file missing)
O2 - BHO: (no name) - {FB2785DC-6C8E-B839-61C8-3F6127DC95AB} - C:\WINDOWS\SYSTEM\NTPN.DLL (file missing)
O2 - BHO: (no name) - {4EB6319E-49FF-C8C6-FBBF-07BAC7CCFC75} - C:\WINDOWS\CRIC32.DLL (file missing)
O2 - BHO: (no name) - {697A7FE2-3B55-05DE-6F30-2EE710E7FFB2} - C:\WINDOWS\SYSTEM\ATLRT32.DLL (file missing)
O2 - BHO: (no name) - {F604D27D-2FA1-6463-FBD6-675B3EA2615B} - C:\WINDOWS\NETDB.DLL (file missing)
O2 - BHO: (no name) - {2CDF515F-066F-CDC9-46C7-30B30CE880BF} - C:\WINDOWS\SYSTEM\D3UK32.DLL (file missing)
O2 - BHO: (no name) - {8005338C-F6C8-1567-B7F1-510AA773BCF3} - C:\WINDOWS\JAVAUE32.DLL (file missing)
O2 - BHO: (no name) - {EF3E880A-AE91-DB11-D009-D00B6A0E94A7} - C:\WINDOWS\SYSTEM\IPGP32.DLL (file missing)
O2 - BHO: (no name) - {2F5D99FB-9063-BAAC-95E7-FEC0C3AF7BAB} - C:\WINDOWS\SDKVW32.DLL (file missing)
O2 - BHO: (no name) - {3EC51367-FA39-1261-3090-522B4BFA5214} - C:\WINDOWS\MFCML32.DLL (file missing)
O2 - BHO: (no name) - {4A741325-E903-BE06-381E-B35E597E3C6A} - C:\WINDOWS\D3VG.DLL (file missing)
O2 - BHO: (no name) - {FBC662AC-AA0D-1389-1431-40872CBDACA2} - C:\WINDOWS\MFCPW.DLL
O2 - BHO: (no name) - {BB60F1BB-CF25-D241-18BC-E21E7E46195C} - C:\WINDOWS\SYSTEM\SYSIP32.DLL
O2 - BHO: (no name) - {EFBC894E-C716-CF6F-30F0-1F1AE60E2401} - C:\WINDOWS\MFCAA.DLL
O2 - BHO: (no name) - {0F8EC515-3766-9410-E291-53457B589DCC} - C:\WINDOWS\SYSTEM\APIXZ32.DLL (file missing)
O2 - BHO: (no name) - {4A5122FD-E216-E8D5-D6CA-0AD5A2315D68} - C:\WINDOWS\SYSTEM\APIXR32.DLL (file missing)
O2 - BHO: (no name) - {B05401ED-FDEB-8A21-A5DA-21D057B7FF3C} - C:\WINDOWS\SYSTEM\IEUU32.DLL (file missing)
O2 - BHO: (no name) - {53EB571E-DF9B-C0FE-846E-402B5896036A} - C:\WINDOWS\MSJM.DLL
O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe
O4 - HKLM\..\RunServices: [WINPE32.EXE] C:\WINDOWS\SYSTEM\WINPE32.EXE
O4 - HKLM\..\RunServices: [SYSKW.EXE] C:\WINDOWS\SYSTEM\SYSKW.EXE
O4 - HKLM\..\RunServices: [APPVC32.EXE] C:\WINDOWS\SYSTEM\APPVC32.EXE
O4 - HKLM\..\RunServices: [APILW.EXE] C:\WINDOWS\SYSTEM\APILW.EXE
O4 - HKLM\..\RunServices: [CRRR.EXE] C:\WINDOWS\CRRR.EXE
O4 - HKLM\..\RunServices: [IEMI32.EXE] C:\WINDOWS\IEMI32.EXE
O4 - HKLM\..\RunServices: [WINCY.EXE] C:\WINDOWS\SYSTEM\WINCY.EXE
O4 - HKLM\..\RunServices: [NETEJ.EXE] C:\WINDOWS\NETEJ.EXE
O4 - HKLM\..\RunServices: [SDKUY.EXE] C:\WINDOWS\SDKUY.EXE
O4 - HKLM\..\RunServices: [SDKCQ.EXE] C:\WINDOWS\SYSTEM\SDKCQ.EXE
O4 - HKLM\..\RunOnce: [*Restore] C:\WINDOWS\SYSTEM\RESTORE\RSTRUI.EXE /f
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net
Back to Top
 

imatrickha
New Member


Date Joined Jun 2004
Total Posts : 7
 
   Posted 7-29-2004 11:54 (GMT +2)    Quote: NEED HELP!Alert an admin about: NEED HELP!
can someone help me? it's getting progessively worse and worse.
Back to Top
 

imatrickha
New Member


Date Joined Jun 2004
Total Posts : 7
 
   Posted 8-2-2004 5:25 (GMT +2)    Quote: NEED HELP!Alert an admin about: NEED HELP!
?????
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 18005
 
   Posted 8-2-2004 6:46 (GMT +2)    Quote: NEED HELP!Alert an admin about: NEED HELP!
I look to ityeah
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 18005
 
   Posted 8-2-2004 8:21 (GMT +2)    Quote: NEED HELP!Alert an admin about: NEED HELP!
Please move Hjt to a permanent folder.
And i suggest you print this file.
Open your task manager (CTRL+ALT+DEL) and click the process tab. Highlight and 'END Process' on these items:
SYSKW.EXE
APILW.EXE
WINCY.EXE
SDKUY.EXE
NETEJ.EXE
SDKCQ.EXE
CRRR.EXE
IEMI32.EXE
APPVC32.EXE
WINPE32.EXE
D3RO32.EXE
 
Now navigate to and delete these files:
C:\WINDOWS\SYSTEM\SYSKW.EXE
C:\WINDOWS\SYSTEM\APILW.EXE
C:\WINDOWS\SYSTEM\WINCY.EXE
C:\WINDOWS\SDKUY.EXE
C:\WINDOWS\NETEJ.EXE
C:\WINDOWS\SYSTEM\SDKCQ.EXE
C:\WINDOWS\CRRR.EXE
C:\WINDOWS\IEMI32.EXE
C:\WINDOWS\SYSTEM\APPVC32.EXE
C:\WINDOWS\SYSTEM\WINPE32.EXE
C:\WINDOWS\D3RO32.EXE
If you can´t delete them, we´ll get them later.
 
Scan with HijackThis again, close all other windows and browsers, and place a checkmark next to these items:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\nrlfq.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://nrlfq.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://nrlfq.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\nrlfq.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://nrlfq.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\nrlfq.dll/sp.html#96676
O2 - BHO: (no name) - {6BE5C394-AA25-266E-D794-88256569CD9D} - C:\WINDOWS\D3RO32.DLL (file missing)
O2 - BHO: (no name) - {F4A41C9A-A713-9C96-601E-1966003429F8} - C:\WINDOWS\ADDKE.DLL (file missing)
O2 - BHO: (no name) - {B368DFA6-172D-988C-124B-8A24C7FBA651} - C:\WINDOWS\SYSTEM\SYSYP32.DLL (file missing)
O2 - BHO: (no name) - {8F30B32A-F793-7B48-2B17-6EB4E169E8EB} - C:\WINDOWS\SDKHQ32.DLL (file missing)
O2 - BHO: (no name) - {2B86B621-D1DC-1979-E5BC-338CC5E8A0CD} - C:\WINDOWS\ATLKC.DLL (file missing)
O2 - BHO: (no name) - {1258EF1B-3DEF-334F-DB40-B3E344FFB374} - C:\WINDOWS\SYSTEM\APIWA32.DLL (file missing)
O2 - BHO: (no name) - {1DE16B10-FCB7-8977-CAF4-0AEB7D77FC72} - C:\WINDOWS\SYSTEM\MSZU32.DLL (file missing)
O2 - BHO: (no name) - {FB2785DC-6C8E-B839-61C8-3F6127DC95AB} - C:\WINDOWS\SYSTEM\NTPN.DLL (file missing)
O2 - BHO: (no name) - {4EB6319E-49FF-C8C6-FBBF-07BAC7CCFC75} - C:\WINDOWS\CRIC32.DLL (file missing)
O2 - BHO: (no name) - {697A7FE2-3B55-05DE-6F30-2EE710E7FFB2} - C:\WINDOWS\SYSTEM\ATLRT32.DLL (file missing)
O2 - BHO: (no name) - {F604D27D-2FA1-6463-FBD6-675B3EA2615B} - C:\WINDOWS\NETDB.DLL (file missing)
O2 - BHO: (no name) - {2CDF515F-066F-CDC9-46C7-30B30CE880BF} - C:\WINDOWS\SYSTEM\D3UK32.DLL (file missing)
O2 - BHO: (no name) - {8005338C-F6C8-1567-B7F1-510AA773BCF3} - C:\WINDOWS\JAVAUE32.DLL (file missing)
O2 - BHO: (no name) - {EF3E880A-AE91-DB11-D009-D00B6A0E94A7} - C:\WINDOWS\SYSTEM\IPGP32.DLL (file missing)
O2 - BHO: (no name) - {2F5D99FB-9063-BAAC-95E7-FEC0C3AF7BAB} - C:\WINDOWS\SDKVW32.DLL (file missing)
O2 - BHO: (no name) - {3EC51367-FA39-1261-3090-522B4BFA5214} - C:\WINDOWS\MFCML32.DLL (file missing)
O2 - BHO: (no name) - {4A741325-E903-BE06-381E-B35E597E3C6A} - C:\WINDOWS\D3VG.DLL (file missing)
O2 - BHO: (no name) - {FBC662AC-AA0D-1389-1431-40872CBDACA2} - C:\WINDOWS\MFCPW.DLL
O2 - BHO: (no name) - {BB60F1BB-CF25-D241-18BC-E21E7E46195C} - C:\WINDOWS\SYSTEM\SYSIP32.DLL
O2 - BHO: (no name) - {EFBC894E-C716-CF6F-30F0-1F1AE60E2401} - C:\WINDOWS\MFCAA.DLL
O2 - BHO: (no name) - {0F8EC515-3766-9410-E291-53457B589DCC} - C:\WINDOWS\SYSTEM\APIXZ32.DLL (file missing)
O2 - BHO: (no name) - {4A5122FD-E216-E8D5-D6CA-0AD5A2315D68} - C:\WINDOWS\SYSTEM\APIXR32.DLL (file missing)
O2 - BHO: (no name) - {B05401ED-FDEB-8A21-A5DA-21D057B7FF3C} - C:\WINDOWS\SYSTEM\IEUU32.DLL (file missing)
O2 - BHO: (no name) - {53EB571E-DF9B-C0FE-846E-402B5896036A} - C:\WINDOWS\MSJM.DLL
O4 - HKLM\..\RunServices: [WINPE32.EXE] C:\WINDOWS\SYSTEM\WINPE32.EXE
O4 - HKLM\..\RunServices: [SYSKW.EXE] C:\WINDOWS\SYSTEM\SYSKW.EXE
O4 - HKLM\..\RunServices: [APPVC32.EXE] C:\WINDOWS\SYSTEM\APPVC32.EXE
O4 - HKLM\..\RunServices: [APILW.EXE] C:\WINDOWS\SYSTEM\APILW.EXE
O4 - HKLM\..\RunServices: [CRRR.EXE] C:\WINDOWS\CRRR.EXE
O4 - HKLM\..\RunServices: [IEMI32.EXE] C:\WINDOWS\IEMI32.EXE
O4 - HKLM\..\RunServices: [WINCY.EXE] C:\WINDOWS\SYSTEM\WINCY.EXE
O4 - HKLM\..\RunServices: [NETEJ.EXE] C:\WINDOWS\NETEJ.EXE
O4 - HKLM\..\RunServices: [SDKUY.EXE] C:\WINDOWS\SDKUY.EXE
O4 - HKLM\..\RunServices: [SDKCQ.EXE] C:\WINDOWS\SYSTEM\SDKCQ.EXE
 
Boot into safe mode by tapping the F8 key and delete:
C:\WINDOWS\SYSTEM\WINPE32.EXE
C:\WINDOWS\SYSTEM\SYSKW.EXE
C:\WINDOWS\SYSTEM\APPVC32.EXE
C:\WINDOWS\SYSTEM\APILW.EXE
C:\WINDOWS\CRRR.EXE
C:\WINDOWS\IEMI32.EXE
C:\WINDOWS\SYSTEM\WINCY.EXE
C:\WINDOWS\NETEJ.EXE
C:\WINDOWS\SDKUY.EXE
C:\WINDOWS\SYSTEM\SDKCQ.EXE
 
Run Adware.
o to Start > Programs > Lavasoft and click on AdAware 6 to open the program
 Look at the icons on the top right of the page and click on the ‘world’ and let AdAware update the spyware reference list
 Once the update is finished click on the ‘Gear’ icon (second from the left) to access the preferences/settings window
 In the "General" window make sure the following are selected:
 Automatically save log-file
 Automatically quarantine objects prior to removal
 Safe Mode (always request confirmation)
 Click on the "Scanning" button on the left and select :
 Scan Within Archives
 Scan Active Processes
 Scan Registry
 Deep Scan Registry
 Scan my IE favorites for banned URL’s
 Scan my Hosts file
 Under ‘Click here to select drives + folders, choose:
 All of your hard drives
 Click on the "Advanced" button on the left and select:
 Include additional process information
 Include additional file information
 Include environment information
 Include additional object details
 Click the "Tweak" button and select:
 Under the "Scanning Engine":
 Unload recognized processes during scanning
 Include basic Ad-aware settings in logfile
 Include additional Ad-aware settings in logfile
 Under the ‘Cleaning Engine’:
 Let Windows remove files in use at next reboot
 Click on "Proceed" to save the settings.
 Click -Start- and on the next screen choose "Activate in-depth Scan" at the bottom of the page and then choose:
 Use Custom Scanning Options
Click -Next- and AdAware will scan your hard drive(s) with the options you have selected.
After scan,put a checkmark to all what it find, then click "finish"
 
Run regcleaner
 
Reboot, and run Ccleaner, post new log
 
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 18005
 
   Posted 11-9-2005 6:41 (GMT +2)    Quote: NEED HELP!Alert an admin about: NEED HELP!
I've locked this thread since the issue is old


Regards - Touch
 
Do not post your log file in a thread started by someone else.
Duplicate posts will be deleted.

Back to Top
 
New Topic Locked Topic Printable version of : NEED HELP!
 
Forum Information
Currently it is Monday, May 21, 2012 10:29 PM (GMT +2)
There are a total of 82.921 posts in 18.688 threads.
In the last 3 days there were 2 new threads and 3 reply posts. View Active Threads
Who's Online
This forum has 33970 registered members. Please welcome our newest member, JohnKWagner.
32 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
BullGuard Support Hijacked :) (0)21-05-2012 19:36:34 (Andreea-Luciana Ostache)
Empty tmp folders (14)21-05-2012 19:31:13 (Andreea-Luciana Ostache)
Bogus BullGuard Websites (0)21-05-2012 14:37:08 (Robert Mateescu)
Multiple Virus Issues (7)19-05-2012 15:44:59 (Touch)