Make sure to update spybot and ad-aware and norton before running them
Main Topics
Browse All TopicsHi,
Today's problem de jour would be some type of virus that keeps changing my home page to some sex-obcessed "search page" with a bunch of links; the url bar has just about:blank in it. Other symptoms include: NAV 2002 with the latest defs finds no virus, then I did an online scan with trend housecall and it found 31 viruses, could not delete them all. restart win xp to safe w/networking, now whatever it is prevents me from downloading the virus scan engine and pattern (.asp extension) so I can scan again, it shuts internet explorer down every time I try, ad-aware finds nothing, spybot finds always just 1 file; "redirected host-auto search.msn.com=213.159.117
I can't seem to delete this little redirector thing. And the popups keep coming. wWhatever this (or these) viruses is doing, it's getting past updated spybot & adaware & nav 2002. Seems that the viruses are getting worse. Anyone have any Ideas, or recommend a online scan/repair ?? thanks
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Check also with stinger:
http://vil.nai.com/vil/sti
Ok, Sunray, here's the log from hijack this:
Logfile of HijackThis v1.97.5
Scan saved at 7:51:58 AM, on 3/17/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCE
C:\WINDOWS\system32\spools
C:\WINDOWS\system32\LEXPPS
C:\PROGRA~1\COMMON~1\aol\A
C:\PROGRA~1\Grisoft\AVG7\a
C:\PROGRA~1\Grisoft\AVG7\a
C:\WINDOWS\system32\cisvc.
C:\WINDOWS\System32\CTsvcC
C:\WINDOWS\system32\driver
C:\Program Files\Common Files\Dell\EUSW\Support.ex
C:\Program Files\Yahoo!\Parental Controls\YPC.EXE
C:\Program Files\Yahoo!\browser\ybrwi
C:\WINDOWS\System32\nvsvc3
C:\program files\support.com\bin\tgcm
C:\WINDOWS\system32\pcs\pc
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\WINDOWS\System32\DSentr
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\Grisoft\AVG7\a
C:\PROGRA~1\Grisoft\AVG7\a
C:\WINDOWS\System32\ScsiAc
C:\WINDOWS\System32\svchos
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\WINDOWS\System32\MsPMSP
C:\PROGRA~1\Yahoo!\browser
C:\Program Files\Creative\SBLive\Diag
C:\WINDOWS\SYSTEM32\YPCSER
C:\PROGRA~1\Yahoo!\MESSEN~
C:\WINDOWS\system32\cidaem
C:\WINDOWS\system32\cidaem
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\delores cox\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackTh
R1 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\Wi
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-
O1 - Hosts: 213.159.117.235 auto.search.msn.com
O2 - BHO: Clear Search - {00000000-0000-0000-0000-0
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-C
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.ex
O4 - HKLM\..\Run: [YPC] C:\Program Files\Yahoo!\Parental Controls\YPC.EXE
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwi
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
O4 - HKLM\..\Run: [tgcmdprovidersbc] "c:\program files\support.com\bin\tgcm
O4 - HKLM\..\Run: [Soundmx] C:\WINDOWS\System32\soundm
O4 - HKLM\..\Run: [Pcsv] C:\WINDOWS\system32\pcs\pc
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Age
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mca
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentr
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diag
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\a
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\a
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [defragm_check] C:\WINDOWS\System32\defrag
O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch
O9 - Extra button: Yahoo! Login (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Login (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O10 - Broken Internet access because of LSP provider 'ypclsp.dll' missing
O16 - DPF: {01A88BB1-1174-41EC-ACCB-9
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2
O16 - DPF: {3E68E405-C6DE-49FF-83AE-4
O16 - DPF: {4F5E4276-C120-11D6-A1FD-0
O16 - DPF: {74D05D43-3236-11D4-BDCD-0
O16 - DPF: {94B82441-A413-4E43-8422-D
O16 - DPF: {A17E30C4-A9BA-11D4-8673-6
O16 - DPF: {B9191F79-5613-4C76-AA2A-3
O16 - DPF: {BAC01377-73DD-4796-854D-2
O16 - DPF: {D18F962A-3722-4B59-B08D-2
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
O18 - Protocol hijack: about - {53B95211-7D77-11D2-9F80-0
And thanks, juvz, but the stinger did not work.
I was able to remove the hdd and scan it as a slave. this allowed me to find and delete all the viruses. But this OE6 start page thing is driving me nuts!
Last response to you 03/16/2004 11:46PM PST so I'll give you this.
You want to run HijackThis again and put checkmarks beside these and remove them...
R1 - HKCU\Software\Microsoft\Wi
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-
O1 - Hosts: 213.159.117.235 auto.search.msn.com
O2 - BHO: Clear Search - {00000000-0000-0000-0000-0
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
O4 - HKLM\..\Run: [tgcmdprovidersbc] "c:\program files\support.com\bin\tgcm
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O18 - Protocol hijack: about - {53B95211-7D77-11D2-9F80-0
You want to email the Russians responsible for hacking your Internet Explorer and tell them
how you feel about their tactics?
person: Dmitry Kuzmenko
address: Malaja Morskaja 11, apt 216
address: Saint-Petersburg, Russia 191186
phone: +7 812 3157505
fax-no: +7 812 3157343
e-mail: djk@linkey.ru
nic-hdl: DK7445-RIPE
notify: admin@linkey.ru
notify: djk@linkey.ru
mnt-by: LINKEY-MNT
changed: djk@linkey.ru 20040212
source: RIPE
person: Sergey A Hripchenko
address: Malaja Morskaja 11, apt 216
address: Saint-Petersburg, Russia 191186
phone: +7 812 3157505
fax-no: +7 812 3157343
e-mail: hripchenko@linkey.ru
nic-hdl: SAH6-RIPE
notify: admin@linkey.ru
notify: hripchenko@linkey.ru
mnt-by: LINKEY-MNT
changed: djk@linkey.ru 20040212
source: RIPE
you may want to keep the latest CWShedder on hand.
This takes care of alot of the browser hijackers.
CWShredder
http://www.spywareinfo.com
OK, here's an update:
Tried directions from Sunray- didnt work.
Did all the stuff spiderfix said- (except tracck down the rusky)it's back
Sorry akboss- your shredder did remove some files, but it all comes back as soon as you reboot.
That url you see above next to hosts is where it goes.
The shredder removes the following files: CWS.Svchost32
CWS.Xmlmimefilter
CWS.Aboutblank
I'm going to put the xp firewall up and try again...I'll keep you posted
>>The shredder removes the following files: CWS.Svchost32<<
Svchost32.exe is the Gaobot virus.
There is a free Gaobot removal tool here...
http://securityresponse.sy
I'm confused on the accepted answer.
akboss>>you may want to keep the latest CWShedder on hand<<
hardstarburst>Sorry akboss- your shredder did remove some files, but it all comes back as soon as you reboot<<
So if CWShredder (Sh_r_edder not Shedder) didn't work why is it accepted?
This was the Gaobot virus was it not?
Spiderfix,
You seem to have a problem with accepting how I award the points. This is not the first time.
the fact of the matter is that YOU should have not gotten ANY points for this. If you will follow the thread, you will see that Sunray was the one who suggested hijackthis, and asked me to post the log. YOU came in AFTER hijackthis was suggested, made some comment about responding to me before, then issued instructions on what boxes you thought I should check. THIS did not work. THEN, akboss comes in with the idea to try the S_H_R_E_D_D_E_R_.
I couldn't care less how he spelled it, because I used the LINK he posted. After running the shredder unsucessfully, I posted comments to that effect. akboss immediately followed up( 11 minutes later) with the comment about sysrestore being off, and the scan being done in safe mode. I had run the scan without being in safe mode, and once I did the scan in safe mode, the issue was resolved BEFORE you even made your 756 pm cst comments. The SHREDDER is what cleared the issue, akboss both suggested it , and posted comments to make sure I had used it properly. Sunray got an assist because by having me post the log, the actual problem was Identified and exposed, so that others could see precisely the nature of the problem, and accurately suggest a fix (as akboss did). I awarded YOU the 100 points SPECIFICALLY so you wouldn't bitch. Now, do me a favor- when you see that hardstarburst has posted a question, DON'T REPLY
>>The SHREDDER is what cleared the issue<<
Why didn't you just post that instead of ranting like I stole your wife.
>>I awarded YOU the 100 points SPECIFICALLY so you wouldn't bitch<<
Now I can buy that third house I wanted with the 100 points. The 100 will be given away
in the lounge.
http://oldlook.experts-exc
http://oldlook.experts-exc
>>Now, do me a favor- when you see that hardstarburst has posted a question, DON'T REPLY<<
Too many user names here. Sorry, but I will not remember you. If you see me reply in the future
just rant again and I'll remember.
We have issues don't we.
Business Accounts
Answer for Membership
by: sunray_2003Posted on 2004-03-16 at 17:19:36ID: 10611778
Not sure if you tried this one
ownload/dl hijackthis .shtml
\Microsoft \Internet Explorer\Main\Search Bar \Microsoft \Internet Explorer\Main\Search Page \Microsoft \Internet Explorer\Main\Start Page ternet Explorer\SearchURL ternet Explorer\Main\Default_Page _URL ternet Explorer\Main\Default_Sear ch_URL ternet Explorer\Search\SearchAssi stant ternet Explorer\Search\CustomizeS earch e\Microsof t\Internet Explorer\Main\Search Bar
HijackThis : http://www.webattack.com/d
best tool around to check for URL changing by spywares. Post the log from here
Also check these registry entries and delete the culprit
HKEY_CURRENT_USER\Software
HKEY_CURRENT_USER\Software
HKEY_CURRENT_USER\Software
HKCU\Software\Microsoft\In
HKCU\Software\Microsoft\In
HKCU\Software\Microsoft\In
HKCU\Software\Microsoft\In
HKCU\Software\Microsoft\In
HKEY_LOCAL_MACHINE\Softwar