HijackThis! log please help!

Discussion in 'adware, spyware & hijack cleaning' started by Crag, Jul 3, 2004.

Thread Status:
Not open for further replies.
  1. Crag

    Crag Registered Member

    Joined:
    Jul 3, 2004
    Posts:
    4
    The inetkw.dll error is haunting me. Plus i get popups from time to time throught he blocker. Please help!

    Logfile of HijackThis v1.98.0
    Scan saved at 1:32:57 PM, on 7/3/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\runservice.exe
    c:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\d3wg32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\crlv.exe
    C:\windows\system\hpsysdrv.exe
    C:\HP\KBD\KBD.EXE
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\System32\S3apphk.exe
    C:\PROGRA~1\NORTON~1\navapw32.exe
    C:\PROGRA~1\INTERN~2\inetmgr.exe
    C:\Program Files\VVSN\VVSN.exe
    C:\PROGRA~1\INTERN~2\inetsvc.exe
    C:\WINDOWS\system32\mscb.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\AIM\aim.exe
    C:\WINDOWS\System32\xsext32f.exe
    C:\Program Files\Web_Rebates\WebRebates1.exe
    C:\Program Files\Web_Rebates\WebRebates0.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\Documents and Settings\Owner\My Documents\filelib\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hkcu
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\eclnj.dll/sp.html#96676
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://eclnj.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://eclnj.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\eclnj.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hklm
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\eclnj.dll/sp.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://eclnj.dll/index.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R3 - Default URLSearchHook is missing
    F0 - system.ini: Shell=
    F2 - REG:system.ini: UserInit=C:\Windows\System32\wsaupdater.exe,
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {8BF78BA5-0335-1C52-EC09-AEBCEBC0D548} - C:\WINDOWS\system32\ntiv32.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background
    O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [NAV Agent] c:\PROGRA~1\NORTON~1\navapw32.exe
    O4 - HKLM\..\Run: [wmplayer] C:\Program Files\Windows Media Player\wmplayer.exe -invisible
    O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe
    O4 - HKLM\..\Run: [inetmgr] C:\PROGRA~1\INTERN~2\inetmgr.exe
    O4 - HKLM\..\Run: [kqodiijzvk] C:\WINDOWS\System32\snztai.exe
    O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\bxxs5.dll,DllRun
    O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient.exe
    O4 - HKLM\..\Run: [mt1lbWzcq] C:\documents and settings\connie\local settings\temp\mt1lbWzcq.exe
    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
    O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe
    O4 - HKLM\..\Run: [mscb.exe] C:\WINDOWS\system32\mscb.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MediaPeek] C:\Documents and Settings\Owner\mediapeek\mptrial.exe
    O4 - HKLM\..\Run: [xsext32f] C:\WINDOWS\System32\xsext32f.exe
    O4 - HKLM\..\RunOnce: [crlv.exe] C:\WINDOWS\system32\crlv.exe
    O4 - HKLM\..\RunOnce: [iplw32.exe] C:\WINDOWS\system32\iplw32.exe
    O4 - HKLM\..\RunOnce: [d3kh32.exe] C:\WINDOWS\system32\d3kh32.exe
    O4 - HKLM\..\RunOnce: [sdkqw.exe] C:\WINDOWS\sdkqw.exe
    O4 - HKLM\..\RunOnce: [winbu.exe] C:\WINDOWS\winbu.exe
    O4 - HKLM\..\RunOnce: [appwk32.exe] C:\WINDOWS\system32\appwk32.exe
    O4 - HKLM\..\RunOnce: [addma.exe] C:\WINDOWS\addma.exe
    O4 - HKLM\..\RunOnce: [d3wg32.exe] C:\WINDOWS\system32\d3wg32.exe
    O4 - HKLM\..\RunOnce: [sdkvr.exe] C:\WINDOWS\sdkvr.exe
    O4 - HKLM\..\RunOnce: [atlxa32.exe] C:\WINDOWS\system32\atlxa32.exe
    O4 - HKLM\..\RunOnce: [appig.exe] C:\WINDOWS\appig.exe
    O4 - HKLM\..\RunOnce: [sysno32.exe] C:\WINDOWS\sysno32.exe
    O4 - HKLM\..\RunOnce: [mfcgk32.exe] C:\WINDOWS\mfcgk32.exe
    O4 - HKLM\..\RunOnce: [ntds32.exe] C:\WINDOWS\ntds32.exe
    O4 - HKLM\..\RunOnce: [syshz.exe] C:\WINDOWS\system32\syshz.exe
    O4 - HKLM\..\RunOnce: [appgp32.exe] C:\WINDOWS\system32\appgp32.exe
    O4 - HKLM\..\RunOnce: [crps32.exe] C:\WINDOWS\crps32.exe
    O4 - HKLM\..\RunOnce: [javasc.exe] C:\WINDOWS\system32\javasc.exe
    O4 - HKLM\..\RunOnce: [sdkxd32.exe] C:\WINDOWS\sdkxd32.exe
    O4 - HKLM\..\RunOnce: [netkf.exe] C:\WINDOWS\system32\netkf.exe
    O4 - HKLM\..\RunOnce: [javaid.exe] C:\WINDOWS\system32\javaid.exe
    O4 - HKLM\..\RunOnce: [d3kd32.exe] C:\WINDOWS\system32\d3kd32.exe
    O4 - HKLM\..\RunOnce: [winjs.exe] C:\WINDOWS\system32\winjs.exe
    O4 - HKLM\..\RunOnce: [addts32.exe] C:\WINDOWS\system32\addts32.exe
    O4 - HKLM\..\RunOnce: [sysup.exe] C:\WINDOWS\system32\sysup.exe
    O4 - HKLM\..\RunOnce: [javahj.exe] C:\WINDOWS\system32\javahj.exe
    O4 - HKLM\..\RunOnce: [ntaj.exe] C:\WINDOWS\system32\ntaj.exe
    O4 - HKLM\..\RunOnce: [ipmp32.exe] C:\WINDOWS\system32\ipmp32.exe
    O4 - HKLM\..\RunOnce: [appcl.exe] C:\WINDOWS\appcl.exe
    O4 - HKLM\..\RunOnce: [addor32.exe] C:\WINDOWS\addor32.exe
    O4 - HKLM\..\RunOnce: [sdkhf32.exe] C:\WINDOWS\sdkhf32.exe
    O4 - HKLM\..\RunOnce: [sdkmg32.exe] C:\WINDOWS\system32\sdkmg32.exe
    O4 - HKLM\..\RunOnce: [atlvc32.exe] C:\WINDOWS\system32\atlvc32.exe
    O4 - HKLM\..\RunOnce: [addoe.exe] C:\WINDOWS\system32\addoe.exe
    O4 - HKLM\..\RunOnce: [javabt.exe] C:\WINDOWS\system32\javabt.exe
    O4 - HKLM\..\RunOnce: [crdz32.exe] C:\WINDOWS\system32\crdz32.exe
    O4 - HKLM\..\RunOnce: [ntob32.exe] C:\WINDOWS\ntob32.exe
    O4 - HKLM\..\RunOnce: [iptm.exe] C:\WINDOWS\system32\iptm.exe
    O4 - HKLM\..\RunOnce: [sdkik32.exe] C:\WINDOWS\sdkik32.exe
    O4 - HKLM\..\RunOnce: [sdkgz32.exe] C:\WINDOWS\system32\sdkgz32.exe
    O4 - HKLM\..\RunOnce: [winlm.exe] C:\WINDOWS\system32\winlm.exe
    O4 - HKLM\..\RunOnce: [ntvm.exe] C:\WINDOWS\system32\ntvm.exe
    O4 - HKLM\..\RunOnce: [nette32.exe] C:\WINDOWS\system32\nette32.exe
    O4 - HKLM\..\RunOnce: [ntvy.exe] C:\WINDOWS\ntvy.exe
    O4 - HKLM\..\RunOnce: [sdkuh.exe] C:\WINDOWS\sdkuh.exe
    O4 - HKLM\..\RunOnce: [mfczn32.exe] C:\WINDOWS\system32\mfczn32.exe
    O4 - HKLM\..\RunOnce: [mfcbb32.exe] C:\WINDOWS\system32\mfcbb32.exe
    O4 - HKLM\..\RunOnce: [d3wn32.exe] C:\WINDOWS\d3wn32.exe
    O4 - HKLM\..\RunOnce: [appxe32.exe] C:\WINDOWS\system32\appxe32.exe
    O4 - HKLM\..\RunOnce: [atlsi32.exe] C:\WINDOWS\system32\atlsi32.exe
    O4 - HKLM\..\RunOnce: [mfcdr.exe] C:\WINDOWS\mfcdr.exe
    O4 - HKLM\..\RunOnce: [iplc.exe] C:\WINDOWS\iplc.exe
    O4 - HKLM\..\RunOnce: [mfcyk.exe] C:\WINDOWS\system32\mfcyk.exe
    O4 - HKLM\..\RunOnce: [sdkjg.exe] C:\WINDOWS\system32\sdkjg.exe
    O4 - HKLM\..\RunOnce: [appex.exe] C:\WINDOWS\appex.exe
    O4 - HKLM\..\RunOnce: [appcd32.exe] C:\WINDOWS\appcd32.exe
    O4 - HKLM\..\RunOnce: [javaxn.exe] C:\WINDOWS\system32\javaxn.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
    O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEUP~1\SNDMon.EXE
    O8 - Extra context menu item: MyPoints - file://C:\Program Files\MyPointsPointAlert\System\Temp\mypoints_script0.htm
    O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\msopt.dll
     
  2. illukka

    illukka Spyware Fighter

    Joined:
    Jun 23, 2003
    Posts:
    633
    Location:
    S.A.V.O
    hi
    omg you're really INFECTED!!!

    first do an online scan http://www.pandasoftware.com/activescan/com/activescan_principal.htm

    let it clean what it finds.

    then
    1. Download and install Adaware (free edition) . (Click on "Adaware" in the left-hand column near the top at their website to download the free edition.)

    2. Go to Start > Programs > Lavasoft and click on AdAware 6 to open the program

    3. Look at the icons on the top right of the page and click on the ‘world’ and let AdAware update the spyware reference list

    4. Once the update is finished click on the ‘Gear’ icon (second from the left) to access the preferences/settings window

    1. In the ‘General’ window make sure the following are selected:
    · Automatically save log-file
    · Automatically quarantine objects prior to removal
    · Safe Mode (always request confirmation)

    2. Click on the ‘Scanning’ button on the left and select :
    · Scan Within Archives
    · Scan Active Processes
    · Scan Registry
    · Deep Scan Registry
    · Scan my IE favorites for banned URL’s
    · Scan my Hosts file
    · Under ‘Click here to select drives + folders’, choose:
    · All of your hard drives

    3. Click on the ‘Advanced’ button on the left and select:
    · Include additional process information
    · Include additional file information
    · Include environment information
    · Include additional object details

    4. Click the ‘Tweak’ button and select:
    · Under the ‘Scanning Engine’:
    · Unload recognized processes during scanning
    · Include basic Ad-aware settings in logfile
    · Include additional Ad-aware settings in logfile
    · Under the ‘Cleaning Engine’:
    · Let Windows remove files in use at next reboot

    5. Click on ‘Proceed’ to save the settings.

    6. Click ‘Start’ and on the next screen choose ‘Activate in-depth Scan’ at the bottom of the page and then choose:
    · Use Custom Scanning Options

    7. Click ‘Next’ and AdAware will scan your hard drive(s) with the options you have selected.

    8. Save the log file when it asks and then click ‘finish’

    9. REBOOT
    ----------------------------------------------------------
    SPYBOT SEARCH & DESTROY

    1. Next, download and install Spybot Search and Destroy .

    2. Go to Start > Programs >Spybot - Search & Destroy and choose ‘Spybot S&D - easy mode’

    3. Close ALL windows except Spybot S&D

    4. Click the button to ‘Search for Updates’ and download and install the Updates.

    5. Next click the button ‘Check for Problems’

    6. When Spybot is complete, it will be showing ‘RED’ entries ‘BLACK’ entries and ‘GREEN’ entries in the window

    7. Put a check mark beside the RED entries ONLY.

    8. Choose ‘Fix Selected Problems’ and allow Spybot to fix the RED entries.

    9. REBOOT

    download and install a firewall like zone alarm free



    and last but not least go to windowsupdate and install all available patches.
    your log shows no updates installed so updating the operation system is FIRST PRIORITY


    post a fresh hijacthis log when done
     
  3. Crag

    Crag Registered Member

    Joined:
    Jul 3, 2004
    Posts:
    4
    I did all of the things you said, here is my fresh log.

    An Logfile of HijackThis v1.98.0
    Scan saved at 4:32:24 PM, on 7/4/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\runservice.exe
    c:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\apiel32.exe
    C:\WINDOWS\Explorer.EXE
    C:\windows\system\hpsysdrv.exe
    C:\HP\KBD\KBD.EXE
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\System32\S3apphk.exe
    C:\PROGRA~1\NORTON~1\navapw32.exe
    C:\PROGRA~1\INTERN~2\inetmgr.exe
    C:\WINDOWS\system32\mscb.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\System32\automove.exe
    C:\WINDOWS\System32\snztai.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\AIM\aim.exe
    C:\PROGRA~1\INTERN~2\inetsvc.exe
    C:\WINDOWS\System32\RUNDLL32.exe
    C:\Program Files\Web_Rebates\WebRebates1.exe
    C:\Program Files\Web_Rebates\WebRebates0.exe
    C:\Program Files\MYIE2\MyIE.exe
    C:\Documents and Settings\Owner\My Documents\filelib\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.shopnav.com/9908/snsearch/search.html?cid=shnv9908&PCID=20040704133918241975833
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\qyaiy.dll/sp.html#96676
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://qyaiy.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://qyaiy.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\qyaiy.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\qyaiy.dll/sp.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://qyaiy.dll/index.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.shopnav.com/9908/snsearch/search.html?cid=shnv9908&PCID=20040704133918241975833
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R3 - Default URLSearchHook is missing
    F0 - system.ini: Shell=
    F2 - REG:system.ini: UserInit=C:\Windows\System32\wsaupdater.exe,
    O2 - BHO: TwaintecObj Class - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {8BF78BA5-0335-1C52-EC09-AEBCEBC0D548} - C:\WINDOWS\system32\ntiv32.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background
    O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [NAV Agent] c:\PROGRA~1\NORTON~1\navapw32.exe
    O4 - HKLM\..\Run: [wmplayer] C:\Program Files\Windows Media Player\wmplayer.exe -invisible
    O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe
    O4 - HKLM\..\Run: [inetmgr] C:\PROGRA~1\INTERN~2\inetmgr.exe
    O4 - HKLM\..\Run: [mt1lbWzcq] C:\documents and settings\connie\local settings\temp\mt1lbWzcq.exe
    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
    O4 - HKLM\..\Run: [mscb.exe] C:\WINDOWS\system32\mscb.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MediaPeek] C:\Documents and Settings\Owner\mediapeek\mptrial.exe
    O4 - HKLM\..\Run: [leaut32o] C:\WINDOWS\System32\leaut32o.exe
    O4 - HKLM\..\Run: [stcloader] C:\WINDOWS\System32\stcloader.exe
    O4 - HKLM\..\Run: [ClrSchLoader] C:\Program Files\ClearSearch\Loader.exe
    O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\automove.exe
    O4 - HKLM\..\Run: [Srng] \Program Files\Srng\Srng.exe
    O4 - HKLM\..\Run: [ttdaldavgbhbo] C:\WINDOWS\System32\snztai.exe
    O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
    O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEUP~1\SNDMon.EXE
    O8 - Extra context menu item: MyPoints - file://C:\Program Files\MyPointsPointAlert\System\Temp\mypoints_script0.htm
    O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
    O9 - Extra button: Sidesearch - {000007C6-17DF-4438-92A4-DE5537471BA3} - C:\Program Files\Lycos\Sidesearch\sidesearch1400.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
     
  4. illukka

    illukka Spyware Fighter

    Joined:
    Jun 23, 2003
    Posts:
    633
    Location:
    S.A.V.O
    yes the log is now much shorter, but there are some things left to fix in it.
    first lets get rid of the startpage hijacker:
    Make sure your settings allow you to view "Hidden files". Open up any explorer windows and click on "Tools" => "Folder Options" => "View" and be sure to check off "Show Hidden Files and Folders".
    # Press Ctrl+Alt+Delete once => Click Task Manager => Click the Processes tab => Double-click the Image Name column header to alphabetically sort the processes => Scroll through the list and look for
    apiel32.exe
    mscb.exe
    snztai.exe
    automove.exe
    C:\WINDOWS\runservice.exe
    If you find the files, click on them, and then click End Process => Exit the Task Manager.
    # Next, go to Start->Run and type "Services.msc" (without quotes) then hit OK.
    # Scroll down and find the service called "Network Security Service".
    # When you find it, double-click on it. In the next window that opens, click the Stop button, then change the Startup Type to Disabled. Now hit Apply and then OK and close any open windows.
    # Run HijackThis, click on "Scan" and then place a check mark in the following boxes, And click on "Fix Checked":

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.shopnav.com/9908/snse...133918241975833

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\qyaiy.dll/sp.html#96676

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://qyaiy.dll/index.html#96676

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://qyaiy.dll/index.html#96676

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\qyaiy.dll/sp.html#96676

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\qyaiy.dll/sp.html#96676

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://qyaiy.dll/index.html#96676

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    http://search.shopnav.com/9908/snse...133918241975833

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R3 - Default URLSearchHook is missing

    F2 - REG:system.ini: UserInit=C:\Windows\System32\wsaupdater.exe,

    O2 - BHO: TwaintecObj Class - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll

    O2 - BHO: (no name) - {8BF78BA5-0335-1C52-EC09-AEBCEBC0D548} - C:\WINDOWS\system32\ntiv32.dll

    O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background

    O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot

    O4 - HKLM\..\Run: [wmplayer] C:\Program Files\Windows Media Player\wmplayer.exe -invisible

    O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe

    O4 - HKLM\..\Run: [inetmgr] C:\PROGRA~1\INTERN~2\inetmgr.exe

    O4 - HKLM\..\Run: [mt1lbWzcq] C:\documents and settings\connie\local settings\temp\mt1lbWzcq.exe

    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"

    O4 - HKLM\..\Run: [mscb.exe] C:\WINDOWS\system32\mscb.exe

    O4 - HKLM\..\Run: [MediaPeek] C:\Documents and Settings\Owner\mediapeek\mptrial.exe

    O4 - HKLM\..\Run: [leaut32o] C:\WINDOWS\System32\leaut32o.exe

    O4 - HKLM\..\Run: [stcloader] C:\WINDOWS\System32\stcloader.exe

    O4 - HKLM\..\Run: [ClrSchLoader] C:\Program Files\ClearSearch\Loader.exe

    O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\automove.exe

    O4 - HKLM\..\Run: [Srng] \Program Files\Srng\Srng.exe

    O4 - HKLM\..\Run: [ttdaldavgbhbo] C:\WINDOWS\System32\snztai.exe

    O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"

    O8 - Extra context menu item: MyPoints - file://C:\Program Files\MyPointsPointAlert\System\Temp\mypoints_script0.htm

    O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm

    O9 - Extra button: Sidesearch - {000007C6-17DF-4438-92A4-DE5537471BA3} - C:\Program Files\Lycos\Sidesearch\sidesearch1400.dll


    then reboot into safe mode and delete the following files:

    c\WINDOWS\System32\snztai.exe
    C:\WINDOWS\System32\automove.exe
    C:\WINDOWS\System32\leaut32o.exe
    c:\installer\id53.exe
    C:\WINDOWS\system32\mscb.exe
    C:\documents and settings\connie\local settings\temp\mt1lbWzcq.exe
    C:\WINDOWS\twaintec.dll
    C:\Windows\System32\wsaupdater.exe
    C:\WINDOWS\system32\ntiv32.dll
    C:\WINDOWS\system32\qyaiy.dll
    C:\WINDOWS\System32\stcloader.exe


    then open up notepad, copy/paste the text in the box below into it and save the file as cwsuninstall.reg.
    make sure you select all files as the saving format, not txt
    Code:
    REGEDIT4
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY___NS_SERVICE_3]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\__NS_Service_3]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY___NS_SERVICE_3]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\__NS_Service_3]
    
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA]
    
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE]
    
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW]
    
    
    doubleclick the file, and press ok when prompted and confirm you want to merge it with the registry.

    reboot

    rescan with hijackthis and post a fresh log
     
  5. Crag

    Crag Registered Member

    Joined:
    Jul 3, 2004
    Posts:
    4
    Here is the new log. I couldnt find a couple fo the files you wanted to delete. leaut320.exe, ntiv32.dll, and qyaiy.dll other thatn that i did the rest.

    Logfile of HijackThis v1.98.0
    Scan saved at 6:32:16 PM, on 7/5/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\runservice.exe
    c:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\mslw.exe
    C:\windows\system\hpsysdrv.exe
    C:\HP\KBD\KBD.EXE
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\System32\S3apphk.exe
    C:\PROGRA~1\NORTON~1\navapw32.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\PROGRA~1\INTERN~2\inetmgr.exe
    C:\Program Files\Web_Rebates\WebRebates0.exe
    C:\WINDOWS\system32\iemw.exe
    C:\Program Files\AIM\aim.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\PROGRA~1\INTERN~2\inetsvc.exe
    C:\Program Files\Web_Rebates\WebRebates1.exe
    C:\Documents and Settings\Owner\My Documents\filelib\HijackThis.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\daeqh.dll/sp.html#96676
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://daeqh.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://daeqh.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\daeqh.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\daeqh.dll/sp.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://daeqh.dll/index.html#96676
    R3 - Default URLSearchHook is missing
    F0 - system.ini: Shell=
    F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {8F7588D6-7A8B-1766-6205-203FDF6F7347} - C:\WINDOWS\system32\nttg32.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [NAV Agent] c:\PROGRA~1\NORTON~1\navapw32.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [inetmgr] C:\PROGRA~1\INTERN~2\inetmgr.exe
    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
    O4 - HKLM\..\Run: [mscb.exe] C:\WINDOWS\system32\mscb.exe
    O4 - HKLM\..\Run: [iemw.exe] C:\WINDOWS\system32\iemw.exe
    O4 - HKLM\..\RunOnce: [appxe32.exe] C:\WINDOWS\system32\appxe32.exe
    O4 - HKLM\..\RunOnce: [winvl32.exe] C:\WINDOWS\winvl32.exe
    O4 - HKLM\..\RunOnce: [sysjs32.exe] C:\WINDOWS\system32\sysjs32.exe
    O4 - HKLM\..\RunOnce: [ipsy32.exe] C:\WINDOWS\ipsy32.exe
    O4 - HKLM\..\RunOnce: [addcn32.exe] C:\WINDOWS\addcn32.exe
    O4 - HKLM\..\RunOnce: [addae32.exe] C:\WINDOWS\system32\addae32.exe
    O4 - HKLM\..\RunOnce: [javant32.exe] C:\WINDOWS\javant32.exe
    O4 - HKLM\..\RunOnce: [d3fq.exe] C:\WINDOWS\d3fq.exe
    O4 - HKLM\..\RunOnce: [apiel32.exe] C:\WINDOWS\apiel32.exe
    O4 - HKLM\..\RunOnce: [addio.exe] C:\WINDOWS\addio.exe
    O4 - HKLM\..\RunOnce: [winsk32.exe] C:\WINDOWS\system32\winsk32.exe
    O4 - HKLM\..\RunOnce: [mfcwo32.exe] C:\WINDOWS\system32\mfcwo32.exe
    O4 - HKLM\..\RunOnce: [sdkaq32.exe] C:\WINDOWS\system32\sdkaq32.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
    O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEUP~1\SNDMon.EXE
    O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
     
  6. illukka

    illukka Spyware Fighter

    Joined:
    Jun 23, 2003
    Posts:
    633
    Location:
    S.A.V.O
    ok looks like the fix failed because you could not find and delete those files.


    they're probably hidden, so here is how to show them:

    * Click Start.
    * Open My Computer.
    * Select the Tools menu and click Folder Options.
    * Select the View Tab.
    * Under the Hidden files and folders heading select Show hidden files and folders.
    * Uncheck the Hide protected operating system files (recommended) option.
    * Click Yes to confirm.
    * Click OK.

    also here is something to show superhidden files:
    copy/paste the text in the box below into notepad and save the file as unhide.reg. be sure to select 'all files' as the saving format, not txt files!

    Code:
    
    Windows Registry Editor Version 5.00
    
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer]
    "SearchSystemDirs"=dword:00000001
    "SearchHidden"=dword:00000001
    "IncludeSubFolders"=dword:00000001
    
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
    "Hidden"=dword:00000001
    "ShowSuperHidden"=dword:00000001
    
    
    after saving doubleclick unhide.reg and answer 'yes' when prompted to add its contents to the Registry, then restart your computer


    then repeat the steps in my above post,
    it might help you to print this before proceeding

    Press Ctrl+Alt+Delete once => Click Task Manager => Click the Processes tab => Double-click the Image Name column header to alphabetically sort the processes => Scroll through the list and look for:

    C:\WINDOWS\runservice.exe

    C:\WINDOWS\system32\mslw.exe

    C:\WINDOWS\system32\iemw.exe


    If you find the files, click on them to highlight, and then click End Process, then confirm it by pressing OK. do this to all processes in the above list, then => Exit the Task Manager

    Next, go to Start->Run and type "Services.msc" (without quotes) then hit OK.
    # Scroll down and find the service called "Network Security Service".
    # When you find it, double-click on it. In the next window that opens, click the Stop button, then change the Startup Type to Disabled. Now hit Apply and then OK and close any open windows.


    Run HijackThis, click on "Scan" and then place a check mark in the following boxes, And click on "Fix Checked"( you will have to close all other program and explorer windows{ including the one you're reading now} before proceeding, it is essential for the fix to work):

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\daeqh.dll/sp.html#96676

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://daeqh.dll/index.html#96676

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://daeqh.dll/index.html#96676

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\daeqh.dll/sp.html#96676

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\daeqh.dll/sp.html#96676

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://daeqh.dll/index.html#96676

    R3 - Default URLSearchHook is missing

    O2 - BHO: (no name) - {8F7588D6-7A8B-1766-6205-203FDF6F7347} - C:\WINDOWS\system32\nttg32.dll

    O4 - HKLM\..\Run: [inetmgr] C:\PROGRA~1\INTERN~2\inetmgr.exe

    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"

    O4 - HKLM\..\Run: [mscb.exe] C:\WINDOWS\system32\mscb.exe

    O4 - HKLM\..\Run: [iemw.exe] C:\WINDOWS\system32\iemw.exe

    O4 - HKLM\..\RunOnce: [appxe32.exe] C:\WINDOWS\system32\appxe32.exe

    O4 - HKLM\..\RunOnce: [winvl32.exe] C:\WINDOWS\winvl32.exe

    O4 - HKLM\..\RunOnce: [sysjs32.exe] C:\WINDOWS\system32\sysjs32.exe

    O4 - HKLM\..\RunOnce: [ipsy32.exe] C:\WINDOWS\ipsy32.exe

    O4 - HKLM\..\RunOnce: [addcn32.exe] C:\WINDOWS\addcn32.exe

    O4 - HKLM\..\RunOnce: [addae32.exe] C:\WINDOWS\system32\addae32.exe

    O4 - HKLM\..\RunOnce: [javant32.exe] C:\WINDOWS\javant32.exe

    O4 - HKLM\..\RunOnce: [d3fq.exe] C:\WINDOWS\d3fq.exe

    O4 - HKLM\..\RunOnce: [apiel32.exe] C:\WINDOWS\apiel32.exe

    O4 - HKLM\..\RunOnce: [addio.exe] C:\WINDOWS\addio.exe

    O4 - HKLM\..\RunOnce: [winsk32.exe] C:\WINDOWS\system32\winsk32.exe

    O4 - HKLM\..\RunOnce: [mfcwo32.exe] C:\WINDOWS\system32\mfcwo32.exe

    O4 - HKLM\..\RunOnce: [sdkaq32.exe] C:\WINDOWS\system32\sdkaq32.exe


    then reboot into safe mode and delete the following files:


    C:\WINDOWS\daeqh.dll

    C:\WINDOWS\system32\nttg32.dll

    C:\WINDOWS\system32\mscb.exe

    WINDOWS\system32\iemw.exe

    C:\Program Files\Web_Rebates entire folder
    check control panel, add/remove programs for possible uninstaller

    then reboot back to normal mode,open up notepad, copy/paste the text in the box below into it and save the file as cwsuninstall.reg.
    make sure you select all files as the saving format, not txt

    Code:
    
    REGEDIT4
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY___NS_SERVICE_3]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\__NS_Service_3]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY___NS_SERVICE_3]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\__NS_Service_3]
    
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA]
    
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE]
    
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW]
    
    
    doubleclick the file, and press ok when prompted and confirm you want to merge it with the registry.

    reboot and post a fresh hjt log
     
  7. Crag

    Crag Registered Member

    Joined:
    Jul 3, 2004
    Posts:
    4
    I cannot get into Safe Mode now. When I try it freesez up each time at the same spot. C:windows/system32/drivers/agp40.sys is the last thing on the screen.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.