Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
search bars, maybe a virus.
   
BullGuard Antivirus Forum > General Security > Spyware > search bars, maybe a virus.  
Forum Quick Jump
 
New Topic Post reply to : search bars, maybe a virus. Printable version of : search bars, maybe a virus.
[ << Previous Thread | Next Thread >> ]

willie148
New Member


Date Joined Sep 2004
Total Posts : 4
 
   Posted 9-20-2004 12:19 (GMT +1)    Quote: search bars, maybe a virus.Alert an admin about: search bars, maybe a virus.
Hellow i've got a big problem my startup page is only about: blank and it's a page with only links for gambling and ....  I've allready ran ad-aware. and i can change the startup page butt every time restart the pc i've got the same problem.  Here's my hijack log i've allready deleted everything with the search bar butt it returns.  Who can help me?
 
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSTEM\JAVABF32.EXE
C:\WINDOWS\SYSTEM\IPKB.EXE
C:\WINDOWS\IEAY.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\CMMPU.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MOBILE DISK O21\MDTOOLS.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSTEM\IPUL32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSTEM\WINFZ32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSTEM\CRPR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSTEM\IPKB.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSTEM\WINFZ32.EXE
C:\WINDOWS\SYSTEM\WINFZ32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSTEM\CRHG.EXE
C:\WINDOWS\SYSTEM\CRHG.EXE
C:\WINDOWS\SYSTEM\IPZF32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSTEM\IPVC32.EXE
C:\WINDOWS\SYSTEM\JAVABF32.EXE
C:\WINDOWS\SYSTEM\JAVABF32.EXE
C:\WINDOWS\SYSTEM\MFCKJ32.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSTEM\CRKG.EXE
C:\WINDOWS\SYSTEM\JAVABF32.EXE
C:\WINDOWS\CRLT32.EXE
C:\WINDOWS\CRLT32.EXE
C:\WINDOWS\SYSTEM\JAVAXZ32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\SYSSL32.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\enipr.dll/sp.html#37794
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\enipr.dll/sp.html#37794
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\enipr.dll/sp.html#37794
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\enipr.dll/sp.html#37794
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\enipr.dll/sp.html#37794
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\enipr.dll/sp.html#37794
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\enipr.dll/sp.html#37794
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.pandora.be:8080
F1 - win.ini: run=C:\WINDOWS\SYSTEM\cmmpu.exe
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {56CC0A27-27B4-C934-2722-3683C7345708} - C:\WINDOWS\MSJS32.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MDTOOL] c:\program files\mobile disk o21\mdtools.exe sys_auto_run C:\PROGRAM FILES\MOBILE DISK O21
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\RunServices: [IPKB.EXE] C:\WINDOWS\SYSTEM\IPKB.EXE
O4 - HKLM\..\RunServices: [SYSSL32.EXE] C:\WINDOWS\SYSSL32.EXE
O4 - HKLM\..\RunServices: [IEAY.EXE] C:\WINDOWS\IEAY.EXE
O4 - HKLM\..\RunServices: [JAVABF32.EXE] C:\WINDOWS\SYSTEM\JAVABF32.EXE
O4 - HKLM\..\RunServices: [IPUL32.EXE] C:\WINDOWS\SYSTEM\IPUL32.EXE
O4 - HKLM\..\RunServices: [WINFZ32.EXE] C:\WINDOWS\SYSTEM\WINFZ32.EXE
O4 - HKLM\..\RunServices: [CRPR.EXE] C:\WINDOWS\SYSTEM\CRPR.EXE
O4 - HKLM\..\RunServices: [CRHG.EXE] C:\WINDOWS\SYSTEM\CRHG.EXE
O4 - HKLM\..\RunServices: [IPZF32.EXE] C:\WINDOWS\SYSTEM\IPZF32.EXE
O4 - HKLM\..\RunServices: [IPVC32.EXE] C:\WINDOWS\SYSTEM\IPVC32.EXE
O4 - HKLM\..\RunServices: [MFCKJ32.EXE] C:\WINDOWS\SYSTEM\MFCKJ32.EXE
O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mpg: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin4.dll
O16 - DPF: {22D6F312-B0F6-11D0-94AB-0080C74C7E95} (Windows Media Player) - http://activex.microsoft.com/activex/controls/mplayer/en/nsmp2inf.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - http://download.microsoft.com/download/PowerPoint2002/Install/10.0.2609/WIN98MeXP/EN-US/msorun.cab
 
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13599
 
   Posted 9-20-2004 12:52 (GMT +1)    Quote: search bars, maybe a virus.Alert an admin about: search bars, maybe a virus.
Hey willie148smilewinkgrin
Please download AboutBuster: http://tools.zerosrealm.com/AboutBuster.zip
Just unzip to Desktop.
Scanner  http://www.mwti.net/antivirus/free_utilities.asp
Take one of the first seven links.
 
Leave the programs.
 
 
Please print out the remainder of these directions, as you'll have to proceed in Safe Mode.  Now, disconnect to the net.
 
Go to Taskmanager ctrl+alt+del Processes, find:
IPKB.EXE
SYSSL32.EXE
IEAY.EXE
JAVABF32.EXE
IPUL32.EXE
WINFZ32.EXE
CRPR.EXE
CRHG.EXE
IPZF32.EXE
IPVC32.EXE
MFCKJ32.EXE
Rightclick on them-end proces
 
Start-run, type:regedit
Find- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
check for a key called-HOMEOldsp, if present- delete it.
And if you have some files in searchpage/searchbar which end with …\sp delete them
Go to Edit in registry and type - HOMEOldsp. Click-Find Next, delete it-if present.
Use F3 for search more, if you find more- delete them.
Same procedure with-About:blank
Close Registry.
 
Reboot to Safe Mode - F8

Scan with HijackThis , close all other windows and browsers, and place a checkmark next to these items, and fix:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\enipr.dll/sp.html#37794
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\enipr.dll/sp.html#37794
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\enipr.dll/sp.html#37794
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\enipr.dll/sp.html#37794
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\enipr.dll/sp.html#37794
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\enipr.dll/sp.html#37794
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\enipr.dll/sp.html#37794
O2 - BHO: (no name) - {56CC0A27-27B4-C934-2722-3683C7345708} - C:\WINDOWS\MSJS32.DLL
O4 - HKLM\..\RunServices: [IPKB.EXE] C:\WINDOWS\SYSTEM\IPKB.EXE
O4 - HKLM\..\RunServices: [SYSSL32.EXE] C:\WINDOWS\SYSSL32.EXE
O4 - HKLM\..\RunServices: [IEAY.EXE] C:\WINDOWS\IEAY.EXE
O4 - HKLM\..\RunServices: [JAVABF32.EXE] C:\WINDOWS\SYSTEM\JAVABF32.EXE
O4 - HKLM\..\RunServices: [IPUL32.EXE] C:\WINDOWS\SYSTEM\IPUL32.EXE
O4 - HKLM\..\RunServices: [WINFZ32.EXE] C:\WINDOWS\SYSTEM\WINFZ32.EXE
O4 - HKLM\..\RunServices: [CRPR.EXE] C:\WINDOWS\SYSTEM\CRPR.EXE
O4 - HKLM\..\RunServices: [CRHG.EXE] C:\WINDOWS\SYSTEM\CRHG.EXE
O4 - HKLM\..\RunServices: [IPZF32.EXE] C:\WINDOWS\SYSTEM\IPZF32.EXE
O4 - HKLM\..\RunServices: [IPVC32.EXE] C:\WINDOWS\SYSTEM\IPVC32.EXE
O4 - HKLM\..\RunServices: [MFCKJ32.EXE] C:\WINDOWS\SYSTEM\MFCKJ32.EXE

 
find and delete these files:
C:\WINDOWS\enipr.dll
C:\WINDOWS\MSJS32.DLL
C:\WINDOWS\SYSTEM\IPKB.EXE
C:\WINDOWS\SYSSL32.EXE
C:\WINDOWS\IEAY.EXE
C:\WINDOWS\SYSTEM\JAVABF32.EXE
C:\WINDOWS\SYSTEM\IPUL32.EXE
C:\WINDOWS\SYSTEM\WINFZ32.EXE
C:\WINDOWS\SYSTEM\CRPR.EXE
C:\WINDOWS\SYSTEM\CRHG.EXE
C:\WINDOWS\SYSTEM\IPZF32.EXE
C:\WINDOWS\SYSTEM\IPVC32.EXE
C:\WINDOWS\SYSTEM\MFCKJ32.EXE



 Double click the AboutBuster.exe file. Click OK, then click Start, then click OK.
 This will scan your computer for the bad files and delete them. Save the report it creates (copy and paste it into notepad  and save as a .txt file).
 
Run Ccleaner, put a checkmark to Temporary internet files, cookies.
 
Empty Recycle Bin.
 
Start-Run Type: %temp% delete all files
 
Now run the Scanner, you downloaded from Microworld.
Activate all, in settings
 
Reboot,this should be your first reboot! post new log, with AboutBuster log
---------------------------------------------------------------------------

Download and (gem) save to:
C\Windows\System32 :
http://home8.inet.tele.dk/fbj/SHELL.DLL  If you get error message about missing –Shell dll





     Touch
 
 

Back to Top
 

willie148
New Member


Date Joined Sep 2004
Total Posts : 4
 
   Posted 9-20-2004 1:41 (GMT +1)    Quote: search bars, maybe a virus.Alert an admin about: search bars, maybe a virus.
Thank you very much. I'm gonna put some files on a cd and then I'm gonna start with all these steps. Butt I allready hav a problem, I can't download blockbuster. I've got a notice: corrupt database. the database is either corrupted or missing. and I've searched on google and downloaded from an other location and it's the same problem.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13599
 
   Posted 9-20-2004 2:37 (GMT +1)    Quote: search bars, maybe a virus.Alert an admin about: search bars, maybe a virus.
Try download this:  http://www.mwti.net/antivirus/free_utilities.asp
It is an exe file, if you can, let me know;-)


     Touch
 
 

Back to Top
 

willie148
New Member


Date Joined Sep 2004
Total Posts : 4
 
   Posted 9-20-2004 6:57 (GMT +1)    Quote: search bars, maybe a virus.Alert an admin about: search bars, maybe a virus.
Ive done all the processes and scans I think everything looks good. I only doubt about d3xw32.
here's the hijack log:
Logfile of HijackThis v1.97.7
Scan saved at 19:50:46, on 20/09/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\CMMPU.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MOBILE DISK O21\MDTOOLS.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start.be/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.pandora.be:8080
F1 - win.ini: run=C:\WINDOWS\SYSTEM\cmmpu.exe
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MDTOOL] c:\program files\mobile disk o21\mdtools.exe sys_auto_run C:\PROGRAM FILES\MOBILE DISK O21
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [D3XW32.EXE] C:\WINDOWS\SYSTEM\D3XW32.EXE
O16 - DPF: {22D6F312-B0F6-11D0-94AB-0080C74C7E95} (Windows Media Player) - http://activex.microsoft.com/activex/controls/mplayer/en/nsmp2inf.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - http://download.microsoft.com/download/PowerPoint2002/Install/10.0.2609/WIN98MeXP/EN-US/msorun.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
Here's the scanner log
-- Scan 1 ---------------------------
About:Buster Version 3.0
Reference List : 15

ADS not scanned System(FAT)
Removed! : C:\WINDOWS\ltdmk.dat
Removed! : C:\WINDOWS\ahdhy.dat
Removed! : C:\WINDOWS\encos.dat
Removed! : C:\WINDOWS\cmlddx.dat
Removed! : C:\WINDOWS\vmwifh.dat
Removed! : C:\WINDOWS\fnsqv.dat
Removed! : C:\WINDOWS\ipvis.dat
Removed! : C:\WINDOWS\SYSTEM\rnsue.dat
Removed! : C:\WINDOWS\SYSTEM\xokvq.dat
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset... Done!
-- Scan 2 ---------------------------
About:Buster Version 3.0
Reference List : 15

ADS not scanned System(FAT)
Attempted Clean Of Temp folder.
Pages Reset... Done!
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13599
 
   Posted 9-20-2004 7:34 (GMT +1)    Quote: search bars, maybe a virus.Alert an admin about: search bars, maybe a virus.
You have done a good jobyeah
We take second  step:
You´re right about this
Scan with Hijackthis again, same procedure, and fix:
O4 - HKLM\..\RunServices: [D3XW32.EXE] C:\WINDOWS\SYSTEM\D3XW32.EXE
Delete:
C:\WINDOWS\SYSTEM\D3XW32.EXE
I don´t need more log´s. Just tell how it works;-)


     Touch
 
Proud member of:
Back to Top
 

willie148
New Member


Date Joined Sep 2004
Total Posts : 4
 
   Posted 9-20-2004 9:02 (GMT +1)    Quote: search bars, maybe a virus.Alert an admin about: search bars, maybe a virus.
Thank you very very very much for you're help.
 
The file was allready gone at one moment. Do I have to install all those things I have allready Norton antivirus, zone alert. I scan with ad aware.  Now also with ccleaner, aboutbuster and e scan
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13599
 
   Posted 9-21-2004 8:32 (GMT +1)    Quote: search bars, maybe a virus.Alert an admin about: search bars, maybe a virus.
You decide, but please read this;-)


     Touch
 
Proud member of:
Back to Top
 
New Topic Post reply to : search bars, maybe a virus. Printable version of : search bars, maybe a virus.
 
Forum Information
Currently it is Friday, November 21, 2008 12:42 AM (GMT +1)
There are a total of 63.950 posts in 15.824 threads.
In the last 3 days there were 33 new threads and 166 reply posts. View Active Threads
Who's Online
This forum has 27181 registered members. Please welcome our newest member, DilbertCube.
35 Guest(s), 1 Registered Member(s) are currently online.  Details
bizzaro
5 Latest Threads
Help please!!! (7)20-11-2008 23:03:58 (paytons place)
Win 32-trojan-gen (14)20-11-2008 22:20:55 (RAYJAY)
Generic Host processor for Win32 services (0)20-11-2008 21:28:28 (gio)
Trojan horse SHeur2.FO help :( (3)20-11-2008 21:23:39 (bizzaro)
Bullguard quits scanning after 6200 files (0)20-11-2008 19:59:07 (Ruud Smit)