Hi Everyone,
All of a sudden, my computer started coming up with all sort of problems...I really need your urgent help...
Firstly, my IE homepage has been hijacked by an about:blank page (some sort of search engine called Home Search), and whenever I open
a new IE window a new window is opened with the same "Home Search" page.
Secondly, the Ad-watch utility that comes with Ad-aware 6 keeps informing me of attempts to change a registry value...wether I accept
it or block it, the same wornings keep coming...the most common worning is:
Root: HKEY_LOCAL_MACHINE
Key: Software\Microsoft\Windows
\CurrentVe
rsion\Run
Value: 2QA68XP4C66PNY
Data: c;\WINDOWS\System32\Pvbl73
1.exe
New Data: C:\WINDOWS\System32\SInt.e
xe
also, sometimes SInt.exe is replaced with UdbkLS.exe
Additionally, when surfing the internet I get some popups (Ironically about Adwares), this wasn't the case before!!.
I tried many things so far..none of which have worked..
I scanned my computer using Norton Antivirus and found 1 virus called W32.Spybot.Worm, I deleted it by following the advised
procedures, and manually deleted a file called spoolsvc.exe which was infected by the virus.
Then I tried CWshredder, Ad-Aware, Spybot..and none had fixed the problem.
I also tried a program called Tracks Eraser Pro which deletes cookies, temp files, History...etc
I even tried to use Hijackthis, and used a website that automatically analyses the log. and fixed all the "nasty" entries.
but then realised that some of the entries keep coming back after I've fixed them
anyway here is the latest Hijackthis log:
Logfile of HijackThis v1.97.7
Scan saved at 11:07:11, on 21/09/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTEC
T.EXE
C:\WINDOWS\System32\nvsvc3
2.exe
C:\WINDOWS\system32\sdkpw.
exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\Program Files\Pinnacle\InstantCDDV
D\InstantW
rite\iwctr
l.exe
C:\Program Files\iTunes\iTunesHelper.
exe
C:\WINDOWS\System32\RUNDLL
32.EXE
C:\WINDOWS\system32\mfcnl.
exe
C:\DOCUMENTS AND SETTINGS\GHASSAN\MY DOCUMENTS\MY PROGRAMS\Qtime\qttask.exe
C:\windows\temp\a0536B.exe
C:\Program Files\iPod\bin\iPodService
.exe
C:\WINDOWS\system32\pcs\pc
svc.exe
C:\Program Files\Common Files\Dpi\dpi.exe
C:\WINDOWS\System32\rundll
32.exe
C:\WINDOWS\System32\IEHost
.exe
C:\WINDOWS\System32\rundll
32.exe
C:\WINDOWS\System32\ctfmon
.exe
C:\Program Files\Sony Handheld\HOTSYNC.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPA
D.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\UdbkLS
.exe
C:\Documents and Settings\Ghassan\Desktop\B
ackup\Hija
ckThis.exe
C:\WINDOWS\System32\Viu995
2.exe
C:\WINDOWS\System32\CkgQ5y
5o.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\
zrmbm.dll/
sp.html#29
126
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINDOWS\system32\
zrmbm.dll/
sp.html#29
126
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant = res://C:\WINDOWS\system32\
zrmbm.dll/
sp.html#29
126
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\
zrmbm.dll/
sp.html#29
126
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINDOWS\system32\
zrmbm.dll/
sp.html#29
126
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = about:blank
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL = res://C:\WINDOWS\system32\
zrmbm.dll/
sp.html#29
126
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant = res://C:\WINDOWS\system32\
zrmbm.dll/
sp.html#29
126
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title = supanet Internet Explorer
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = *hot-searches.com*;*lender
-search.co
m*
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page_bak = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIE
Helper.ocx
O2 - BHO: (no name) - {913DFA36-9040-F4DA-2372-4
54F96C8DF8
B} - C:\WINDOWS\system32\winai.
dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-6
4B5B4FF55D
0} - C:\Program Files\MSN Toolbar\01.01.1601.0\msgr.
en-us.en-
gb\msntb.dll
O4 - HKLM\..\Run: [SUPASTATUS] C:\Program Files\Internet Explorer\Connection Wizard\status.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTo
ols\ADVCHK
.EXE
O4 - HKLM\..\Run: [Ad-watch] C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [IW_ControlCenter] C:\Program Files\Pinnacle\InstantCDDV
D\InstantW
rite\iwctr
l.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.
exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCh
eck.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCh
eck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTr
ay.dll,NvT
askbarInit
O4 - HKLM\..\Run: [mfcnl.exe] C:\WINDOWS\system32\mfcnl.
exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\DOCUMENTS AND SETTINGS\GHASSAN\MY DOCUMENTS\MY PROGRAMS\Qtime\qttask.exe"
-atboottime
O4 - HKLM\..\Run: [a0536B] C:\windows\temp\a0536B.exe
O4 - HKLM\..\Run: [2QA68XP4C66PNY] C:\WINDOWS\System32\Slnt.e
xe
O4 - HKLM\..\Run: [Pcsv] C:\WINDOWS\system32\pcs\pc
svc.exe
O4 - HKLM\..\Run: [Dpi] C:\Program Files\Common Files\Dpi\dpi.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDO
T~2.DLL,Ne
wDotNetSta
rtup -s
O4 - HKLM\..\Run: [Winad Client] C:\Program Files\Winad Client\Winad.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebat
es0.exe"
O4 - HKLM\..\Run: [Win32 System Spool] spoolsvc.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [Bakra] C:\WINDOWS\System32\IEHost
.exe
O4 - HKLM\..\Run: [{2CF0B992-5EEB-4143-99C0-
5297EF71F4
44}] rundll32.exe C:\WINDOWS\System32\stlbdi
st.DLL,Dll
RunMain
O4 - HKLM\..\RunServices: [Win32 System Spool] spoolsvc.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon
.exe
O4 - HKCU\..\Run: [Win32 System Spool] spoolsvc.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Ad
obe Gamma Loader.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3
\Office10\
EXCEL.EXE/
3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.h
tm
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\T
p1150\scri
1150a.htm
O9 - Extra button: SideFind (HKLM)
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: SWF Catcher (HKLM)
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O14 - IERESET.INF: START_PAGE_URL=
http://www.supanet.com/O16 - DPF: ppctlcab -
http://69.44.122.156/scanner/ppctlcab.cabO16 - DPF: {02BCC737-B171-4746-94C9-0
D8A0B2C008
9} (Microsoft Office Template and Media Control) -
http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-4
4455354000
0} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3
DEA45B69CB
F} (Web P2P Installer) -
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-0
0A0CC6651A
8} (Cult3D ActiveX Player) -
http://www.cult3d.com/download/cult.cabO16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-0
0105AA9B6A
E} (Symantec RuFSI Registry Information Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/c
absa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F
5C6AF4DE1B
D} -
http://www.smgradio.com/core/player/abasetup141.cabO16 - DPF: {EFB22865-F3BC-4309-ADFA-C
8E078A7F76
2} (SysWebTelecomInt Class) -
http://www.sponsoradulto.com/en/SysWebTelecom.cabThe "O10 - Hijacked Internet access by New.Net" entries were suppose to be deleted by spybot, but after I used Spybot they are
still there :( .
Finaly, as this is urgent to me, I'm gonna give it maximum points 500
Thank you