Seite 1 von 2 1 2 LetzteLetzte
Zeige Ergebnis 1 bis 10 von 12

Thema: Cant remove QSearch toolbar

  1. #1
    Einsteiger
    Registriert seit
    23.04.2005
    Beiträge
    10

    Cant remove QSearch toolbar

    Hi,

    I'm helping a friend with some malware problems. I've installed Spy-bot, Ad-Aware, Spyward, AVG Virus. But cant get rid of the Qsearch bar in IE.

    Here is the log:
    Code:
    Logfile of HijackThis v1.99.0
    Scan saved at 9:32:52 AM, on 4/26/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Nhksrv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINDOWS\System32\CTsvcCDA.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE
    C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Ares\Ares.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    C:\Program Files\Reality Fusion\Reality Fusion GameCam SE\Program\RFTRay.exe
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\DOCUME~1\LUISMA~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis_199.zip\HijackThis.exe
    
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_38.dll
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: QuickSearch Search Bar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll
    O3 - Toolbar: QuickSearch Search Bar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [DIAGENT] C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE startup
    O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: Camio Viewer 2000.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
    O4 - Global Startup: Reality Fusion GameCam SE.lnk = ?
    O4 - Global Startup: winlogin.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe
    O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.gocyberlink.com/winxp/CheckDVD.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/097fe4716bada1900b21/netzip/RdxIE601.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1107663112857
    O23 - Service: .NET Framework Service - Unknown - C:\WINDOWS\svchost.exe (file missing)
    O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
    O23 - Service: IMAPI CD-Burning COM Service - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
    O23 - Service: Netropa NHK Server - Unknown - C:\WINDOWS\Nhksrv.exe
    Thanks for your help,

    Tulio

  2. #2
    Supermod a.D. Benutzerbild von Ruby
    Registriert seit
    25.01.2005
    Ort
    The Netherlands
    Beiträge
    20.042

    AW: Cant remove QSearch toolbar

    Hello Tuliothx

    Youre friend is running a very dangerous worm at his system: W32/Agobot-IX:

    W32/Agobot-IX is an IRC backdoor Trojan and network worm. W32/Agobot-IX copies itself to network shares protected by weak passwords. When first run W32/Agobot-IX copies itself to the Windows system folder as winlogin.exe and sets the following registry entries to ensure it is run at system logon. Each time W32/Agobot-IX is run it attempts to connect to a remote IRC server and join a specific channel. The worm then runs in the background allowing a remote intruder to issue commands which control the computer. W32/Agobot-IX can be instructed to download and install other programs on the system as well as to flood other computers with network packets. W32/Agobot-IX will terminate and disable various anti-virus and security related programs. W32/Agobot-IX will write to the hosts file so that various security related internet sites can no longer be accessed.

    -----------------------
    There is a very dangerous worm at the system.
    Online-banking, file-sharing, mailing, messaging,
    up and downloads behalve to security sites untill the system is clean
    are not allowed.
    Take a look to "Security Tips" in my signature.

    -----------------------


    Please follow these steps:

    1
    Turn off System Restore during the whole time we are working at your system.

    2
    Make sure you set windows to see the hidden files and folders.

    3
    Load down RegistryProt, read the instructions and follow the instructions!

    4
    Load down Registrar Lite, a tool to edit the registry.

    5
    For the greatest safety, Symantec recommends that if you edit the registry, you back up the entire registry: Backing up the Windows registry.

    6
    # Open Windows Task Manager.
    » press CTRL+SHIFT+ESC, then click the Processes tab.
    # In the list of running programs, locate the malware file(s) detected earlier.
    # Select one of the detected files, then press either the End Task or the End Process button, depending on the version of Windows on your system.
    # Do the same for all detected malware files in the list of running processes.
    # To check if the malware process has been terminated, close Task Manager, and then open it again.
    # Close Task Manager:

    winlogin.exe

    7
    START > RUN > (type) REGEDIT [enter] (of use 'Registrar Lite')

    Locate the HKEY_LOCAL_MACHINE entries:

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\

    delete
    WinLogin = winlogin.exe

    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\

    delete
    WinLogin = winlogin.exe

    Close the registry editor.

    8
    You will want to copy the text from this post and save it as a text file (*.txt) or print it because you will be working offline (in safemode) to resolve your problem and not have access to this forum.

    Follow these STEPS.

    STEP 1
    You must turn off System Restore during this process. You will keep it off until we are done fixing your system.

    STEP 2
    1. Download mwavscan (It is free), if you don't have a zip-tool we suggest zipgenius (It is free).
    2. You MUST Unzip mwavscan to 'C:\bases' (case sensitive, any other folder and it won't work properly)
    3. After installing some systems automatically start up the program, if this happens close it, you don't want to run it now.
    4. Open 'My Computer'
    5. Double click on 'C:'
    6. Double click on the folder 'bases'
    7. Now in that root folder look for 'kavupd.exe' and double click on it. (We are updating mwavscan to the latest definitions.)
    8. NOTE: Occasionally users receive an error that 'signatures are more then 30 days old'. If you receive this keep trying to run kavupd.exe, it means the definition server is busy, but you will eventually get through.

    CleanUp312.

    If after or during the cleaning process you find that your internet connection has been broken, please run lspfix, so please download it now.

    STEP 3
    Doubleclick the file cleanup312.exe

    Go to the option
    Select ‘custom’
    Put a checkmark to:

    * Cookies
    * Prefetch
    * Temp
    * All users.

    Press the 'cleanup' button

    STEP 4
    1. Now turn off your computer and remove the network cable/phone line from your machine.
    2. Reboot your computer in Safe Mode

    STEP 5
    1. Open 'My Computer'
    2. Double click on 'C:'
    3. Double click on the folder 'bases'
    4. Double click on 'mwavscan.com'
    5. Now close all other windows, browsers, and programs other then Mwavscan before continuing
    6. Checkmark: Memory, StartUp-Folders, Drives, All Local Drives, Registry and INI Files, System Folders, Services
    7. Now select 'Scan All Files'
    8. Finally, click on 'Scan Clean' (The program will take several hours to run)
    9. When the scan is complete, click 'View Log' and Save it!

    STEP 6
    1. Reconnect your network cable/phone line
    2. Reboot your system into normal mode.

    STEP 7
    1. Open 'My Computer'
    2. Double click on 'C:'
    3. Double click on the folder 'bases'
    4. Find the log file in the directory.
    5. Open it with an editor (Notepad will do fine)
    6. Look for the files which are tagged as "virus" or "infected"
    7. Copy&paste all these files tagged as "virus" or "infected" in a new document and save to your desktop

    STEP 8
    Run Hijackthis again and have it save a new log file.

    Step 9
    Come back to the site and post every file mwavscan tagged as "virus" and the names of the viruses in this thread.

    (It looks like this: File C:\WINDOWS\sssasasb32.exe infected by "Trojan-Downloader.Win32.Agent.ig" Virus. Action Taken)

    Also post the total results:

    =>Total Number of Files Scanned:
    =>Total Number of Virus(es) Found:
    =>Total Number of Disinfected Files:
    =>Total Number of Files Renamed:
    =>Total Number of Deleted Files:
    =>Total Number of Errors:
    ***** Scanning complete. *****

    Finally, post the new Hijackthis logfile!

  3. #3
    Einsteiger
    Registriert seit
    23.04.2005
    Beiträge
    10

    Re: Cant remove QSearch toolbar

    Hi,

    Thanks for your help. While doing the last part of Step 2, the link to CleanUp312 "The page cannot be found". Also, there seems to be a new version CleanUp40.exe but it also can not be found in the http://downloads.stevengould.org site.

    Should I continue without running this part of Step 2?

    Again, Thanks for all of your help.

    Tulio

  4. #4
    Supermod a.D. Benutzerbild von Ruby
    Registriert seit
    25.01.2005
    Ort
    The Netherlands
    Beiträge
    20.042

    AW: Cant remove QSearch toolbar

    Hello Tuliothx

    I don't have no problems to get the CleanUp-Tool per Direct-Link to CleanUp312.
    Please try it once more. Go on with the other numbers.

    Run HijackThis once more and have it save a new HijackThis-Logfile.
    Post it please. Thx.

  5. #5
    Einsteiger
    Registriert seit
    23.04.2005
    Beiträge
    10

    Re: Cant remove QSearch toolbar

    Hi,

    I had to burn CleanUp312.exe into a CD from my computer as my friend's computer was not able to get the link (Perhaps the virus was interfering?).

    Here are the tagged virus lines from mwavscan:

    Wed May 04 08:13:04 2005 => File C:\WINDOWS\default.css infected by "Trojan-Clicker.Win32.Qhost.a" Virus. Action Taken: File Deleted.
    Wed May 04 08:13:08 2005 => File C:\WINDOWS\NDNuninstall5_64.exe tagged as not-a-virus:AdWare.NewDotNet. No Action Taken.
    Wed May 04 08:13:12 2005 => File C:\WINDOWS\***Downloader.cab infected by "Trojan-Downloader.Win32.Pornet.c" Virus. Action Taken: File Deleted.
    Wed May 04 08:13:21 2005 => File C:\WINDOWS\system32\c38y5r07ew.dll infected by "Trojan.Win32.Krepper.v" Virus. Action Taken: File Deleted.
    Wed May 04 08:13:47 2005 => File C:\WINDOWS\system32\g1g3eb6f1msgl5.dll infected by "Trojan.Win32.Krepper.r" Virus. Action Taken: File Deleted.
    Wed May 04 08:15:06 2005 => File C:\WINDOWS\system32\utfnj8yld8.dll infected by "Trojan.Win32.Krepper.v" Virus. Action Taken: File Deleted.
    Wed May 04 08:15:07 2005 => File C:\WINDOWS\system32\v4ss968g88.dll infected by "Trojan.Win32.Krepper.r" Virus. Action Taken: File Deleted.
    Wed May 04 08:16:16 2005 => File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchXPlugin1.zip infected by "Password-protected-EXE" Virus. Action Taken: File Renamed.
    Wed May 04 08:16:53 2005 => File C:\Documents and Settings\luismateo\Application Data\sysupd.exe infected by "Trojan-Spy.Win32.Agent.l" Virus. Action Taken: File Deleted.
    Wed May 04 09:01:21 2005 => File C:\Program Files\Windows Media Player\wmplayer.exe.tmp infected by "Trojan.Win32.Small.q" Virus. Action Taken: File Deleted.


    Here are the Total Results:

    Wed May 04 09:21:23 2005 => Total Number of Files Scanned: 48451
    Wed May 04 09:21:23 2005 => Total Number of Virus(es) Found: 24
    Wed May 04 09:21:23 2005 => Total Number of Disinfected Files: 0
    Wed May 04 09:21:23 2005 => Total Number of Files Renamed: 1
    Wed May 04 09:21:23 2005 => Total Number of Deleted Files: 8
    Wed May 04 09:21:23 2005 => Total Number of Errors: 1
    Wed May 04 09:21:23 2005 => Time Elapsed: 01:08:29
    Wed May 04 09:21:23 2005 => Virus Database Date: 2005/04/29
    Wed May 04 09:21:23 2005 => Virus Database Count: 127678

    Wed May 04 09:21:23 2005 => Scan Completed.



    Here is the new log:
    Code:
    Logfile of HijackThis v1.99.0
    Scan saved at 8:46:53 AM, on 5/5/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE
    C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
    C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    C:\program files\registryprot\regprot.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\Nhksrv.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Reality Fusion\Reality Fusion GameCam SE\Program\RFTRay.exe
    C:\WINDOWS\System32\CTsvcCDA.EXE
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\MusicMatch\MusicMatch Jukebox\MMJB.EXE
    C:\Program Files\Hijackthis\HijackThis.exe
    
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_38.dll
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [DIAGENT] C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE startup
    O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [RegProt] c:\program files\registryprot\regprot.exe /start
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: Camio Viewer 2000.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
    O4 - Global Startup: Reality Fusion GameCam SE.lnk = ?
    O4 - Global Startup: winlogin.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe
    O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.gocyberlink.com/winxp/CheckDVD.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/097fe4716bada1900b21/netzip/RdxIE601.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1107663112857
    O23 - Service: .NET Framework Service - Unknown - C:\WINDOWS\svchost.exe (file missing)
    O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
    O23 - Service: IMAPI CD-Burning COM Service - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
    O23 - Service: Netropa NHK Server - Unknown - C:\WINDOWS\Nhksrv.exe

    Thanks for all of your help.


    Tulio

  6. #6
    Supermod a.D. Benutzerbild von Ruby
    Registriert seit
    25.01.2005
    Ort
    The Netherlands
    Beiträge
    20.042

    AW: Cant remove QSearch toolbar

    Hello Tuliothx

    There is nothing changed on your friends system.
    Why didn't you follow my instructions in the posting of 26.04.2005 05:00?
    Your friend is running a very dangerous worm at his system. If you of he isn't able to free the system from this worm you of he should better formate this system. If you don't follow my instructions - why do you ask me to help you? It's lost time.

    Please load down RegistryProt, read the instructions and follow the instructions.

    I'll try once more to make you know how to clean up this system. If you don't follow my instructions and I will get the same HijackThis Logfile once more, I will stop to help you.

    So let's go:

    Please read this instructions first and then print out this instructions or save it as a textfile (*.txt)
    since we will ask you to work offline in safe mode.


    Turn off System Restore.

    Follow the numbers.

    1
    # Open Windows Task Manager.
    » press CTRL+SHIFT+ESC, then click the Processes tab.
    # In the list of running programs, locate the malware file(s) detected earlier.
    # Select one of the detected files, then press either the End Task or the End Process button, depending on the version of Windows on your system.
    # Do the same for all detected malware files in the list of running processes.
    # To check if the malware process has been terminated, close Task Manager, and then open it again.
    # Close Task Manager:

    winlogin.exe

    2
    START > RUN > (type) REGEDIT [enter] (of use 'Registrar Lite')

    Locate the HKEY_LOCAL_MACHINE entries:

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run \

    delete
    WinLogin = winlogin.exe

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run Services\

    delete
    WinLogin = winlogin.exe

    Close the registry editor.

    3
    Download for free:
    Once more:
    If after or during the cleaning process you find that your internet connection has been broken, please run lspfix, so please download it now.

    4
    Disconnect to the Internet.

    5
    Turn to safe mode.

    6
    Close all windows including Internet Explorer.
    Run Hijackthis, click scan, and put a checkmark next to each of these items.
    Then click the Fix Checked button:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = hzzp://search.yahoo.com/search?p=%s
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
    O4 - Global Startup: Reality Fusion GameCam SE.lnk = ?
    O4 - Global Startup: winlogin.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - hzzp://www.gocyberlink.com/winxp/CheckDVD.cab

    Click on Fix Checked and exit HijackThis.

    7
    Delete by lspfix:

    Set a checkmark to "I know what I'm doing".
    Move the following files from the left side to the right side and click the "finished-button":

    C:\WINDOWS\NDNuninstall5_64.exe
    C:\Program Files\NewDotNet\newdotnet6_38.dll
    C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup
    O10 - Hijacked Internet access by New.Net

    8
    Delete the content of the temporary folders:

    8-1
    Go to START > run and type: cleanmgr and click ok.
    Let it scan your system for files to remove.
    Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked. Press OK to remove them.

    8-2
    Go to START> run> type %temp% and press [enter]. Do this for every account.

    8-3
    Go to START>Control Panel>Internet Options>tab programs> and click restore websettings.

    8-4
    1) Open Control Panel
    2) Click on Internet Options
    3) On the General Tab, in the middle of the screen, click on Delete Files
    4) You may also want to check the box "Delete all offline content"
    5) Click on OK and wait for the hourglass icon to stop after it deletes the temporary internet files
    6) You can now click on Delete Cookies and click OK to delete cookies that websites have placed on your hard drive

    8-5
    Delete the whole content of C:\Documents and Settings\Your Name\Local Settings\Temp <== this folder.

    9
    Using Windows Explorer delete the following file:

    C:\WINDOWS\system32\winlogin.exe

    10
    Reboot the system into normal mode.

    11
    Doubleclick the file cleanup312.exe.

    Go to the option
    Select ‘custom’
    Put a checkmark to:

    * Cookies
    * Prefetch
    * Temp
    * All users.

    Press the 'cleanup' button

    12
    Run an actual version of HijackThis once more, have it save a logfile.

    Post the new HJT-Logfile.

  7. #7
    Einsteiger
    Registriert seit
    23.04.2005
    Beiträge
    10

    Re: Cant remove QSearch toolbar

    Hi Ruby,

    First, thanks very much for your help. Believe me, I've been following the instructions very closely so I'm not sure why the log is the same. I will try again today to apply your instructions.

    One question: on step 1 it says "# In the list of running programs, locate the malware file(s) detected earlier." I'm not sure what you want mean by "detected earlier". The only earlier step is the installation of "RegistryProt" but I don't think that gives me a list of malware files.

    Again, your help is very valuable so thanks very much for your time.

    Tulio

  8. #8
    Supermod a.D. Benutzerbild von Ruby
    Registriert seit
    25.01.2005
    Ort
    The Netherlands
    Beiträge
    20.042

    AW: Cant remove QSearch toolbar

    @ Tuliothx

    that means that you will want to delete "winlogin.exe" by using Windows Taskmanager. It would be great if you could delete "winlogin.exe" want it is a worm with backdoor functionality: W32/Agobot-IX

    Read more about it in my postings. It should be better that you formate this system.

  9. #9
    Supermod a.D. Benutzerbild von Ruby
    Registriert seit
    25.01.2005
    Ort
    The Netherlands
    Beiträge
    20.042

    AW: Cant remove QSearch toolbar

    @ Tuliothx

    1
    Download
    the KillBox

    2
    Run the Killbox

    o browse this file into the killbox:

    C:\WINDOWS\system32\winlogin.exe

    o activate "Replace on Reboot"
    o activate "Use dummy" - then click at the red X
    o "YES"
    o "YES" by the question if you want to reboot ...

    3
    Run HijackThis once more and have it save a new Logfile.
    Post it please.

  10. #10
    Einsteiger
    Registriert seit
    23.04.2005
    Beiträge
    10

    Re: Cant remove QSearch toolbar

    Hi Ruby,

    I rerun with the updated steps. Hijackthis can not remove C:\Windows\system32\winlogin.exe and the file dos not exists anywhere in the registry, TAKS MANAGER, or the C: drive. Not sure why Hijackthis picks it up.

    Here is the log:
    Code:
    Logfile of HijackThis v1.99.1
    Scan saved at 8:03:46 AM, on 5/7/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Microsoft Shared\Works 
    
    Shared\WkUFind.exe
    C:\Program Files\Creative\SBLive\Creative Diagnostics 
    
    2.0\DIAGENT.EXE
    C:\Program Files\Adaptec\Easy CD Creator 
    
    5\DirectCD\DirectCD.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
    C:\WINDOWS\Nhksrv.exe
    C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    C:\program files\registryprot\regprot.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINDOWS\System32\CTsvcCDA.EXE
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
    C:\Program Files\Hijackthis\HijackThis.exe
    
    O2 - BHO: URLLink Class - 
    
    {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program 
    
    Files\NewDotNet\newdotnet6_38.dll
    O2 - BHO: SpywareGuard Download Protection - 
    
    {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program 
    
    Files\SpywareGuard\dlprotect.dll
    O2 - BHO: (no name) - 
    
    {53707962-6F74-2D53-2644-206D7942484F} - 
    
    C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program 
    
    Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] 
    
    C:\Program Files\Common Files\Microsoft Shared\Works 
    
    Shared\WkUFind.exe
    O4 - HKLM\..\Run: [DIAGENT] C:\Program 
    
    Files\Creative\SBLive\Creative Diagnostics 
    
    2.0\DIAGENT.EXE startup
    O4 - HKLM\..\Run: [AHQInit] C:\Program 
    
    Files\Creative\SBLive\Program\AHQInit.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program 
    
    Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [AVG7_CC] 
    
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [EPSON Stylus CX5400] 
    
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE 
    
    /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus 
    
    CX5400"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE 
    
    NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [mmtask] C:\Program 
    
    Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [RegProt] c:\program 
    
    files\registryprot\regprot.exe /start
    O4 - HKLM\..\Run: [New.net Startup] rundll32 
    
    C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program 
    
    Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - Startup: SpywareGuard.lnk = C:\Program 
    
    Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: Camio Viewer 2000.lnk = C:\Program 
    
    Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
    O4 - Global Startup: winlogin.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program 
    
    Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel 
    
    - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - 
    
    {92780B25-18CC-41C8-B9BE-3C9C571A8263} - 
    
    C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - 
    
    {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program 
    
    Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - 
    
    {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program 
    
    Files\Messenger\msmsgs.exe
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} 
    
    (YInstStarter Class) - 
    
    http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yin
    
    st0401.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - 
    
    http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.in
    
    fo.apple.com/mickey/us/win/QuickTimeInstaller.exe
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE 
    
    Class) - 
    
    http://software-dl.real.com/097fe4716bada1900b21/netzip/R
    
    dxIE601.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} 
    
    (WUWebControl Class) - 
    
    http://v5.windowsupdate.microsoft.com/v5consumer/V5Contro
    
    ls/en/x86/client/wuweb_site.cab?1107663112857
    O23 - Service: .NET Framework Service (.NET Connection 
    
    Service) - Unknown owner - C:\WINDOWS\svchost.exe (file 
    
    missing)
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - 
    
    GRISOFT, s.r.o. - 
    
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - 
    
    GRISOFT, s.r.o. - 
    
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Creative Service for CDROM Access - 
    
    Creative Technology Ltd - 
    
    C:\WINDOWS\System32\CTsvcCDA.EXE
    O23 - Service: IMAPI CD-Burning COM Service 
    
    (ImapiService) - Roxio Inc. - 
    
    C:\WINDOWS\System32\ImapiRox.exe
    O23 - Service: Netropa NHK Server (Nhksrv) - Unknown 
    
    owner - C:\WINDOWS\Nhksrv.exe

    Thanks Ruby,

    Tulio

Seite 1 von 2 1 2 LetzteLetzte

Aktive Benutzer

Aktive Benutzer

Aktive Benutzer in diesem Thema: 1 (Registrierte Benutzer: 0, Gäste: 1)

     

Ähnliche Themen

  1. can't remove ad popups
    Von barb1 im Forum Archiv
    Antworten: 1
    Letzter Beitrag: 14.03.2005, 23:23
  2. please help my log to remove SAHAgent
    Von Ben im Forum Archiv
    Antworten: 1
    Letzter Beitrag: 11.03.2005, 18:27
  3. Remove AZESEARCH Toolbar
    Von gutguy im Forum Archiv
    Antworten: 1
    Letzter Beitrag: 02.03.2005, 19:50
  4. Can't open taskmanager and other programs
    Von dekmar im Forum Archiv
    Antworten: 6
    Letzter Beitrag: 09.02.2005, 01:04
  5. Can't remove 015 trusted zone
    Von turk im Forum Archiv
    Antworten: 3
    Letzter Beitrag: 27.01.2005, 03:45

Forumregeln

  • Es ist Ihnen nicht erlaubt, neue Themen zu verfassen.
  • Es ist Ihnen nicht erlaubt, auf Beiträge zu antworten.
  • Es ist Ihnen nicht erlaubt, Anhänge hochzuladen.
  • Es ist Ihnen nicht erlaubt, Ihre Beiträge zu bearbeiten.