CoolWebSearch, BetterInternet, and Iefeats (adware)
I have read many of the postings from this site before joining and posting this and I really thought I could beat it as a former network administrator, but I'm giving in as I burned out several years ago. My frustration in identifying the malignant files and removing them from the registry and the OS is not working. I have already downloaded the CWShredder, Fixiefts (Norton Utility for removing Iefeats), Ad-aware, HiJackThis, Spybot S&D, Swat-it, REGBlock, and Norton Internet Security 2005.
As a note, before posting, I have updated everything in Spybot S&D, Ad-aware, and NIS2005.
Please give me advice as my brain is fried. Thanks in advance for any posts.
Here is the latest HijackThis log.
Logfile of HijackThis v1.99.1
Scan saved at 10:04:17 AM, on 5/3/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Be sure and put a check in the box by "Auto Clean" before you do the scan. If it finds anything that it cannot clean have it delete it or make a note of the file location so you can delete it yourself.
I couldn't run the Trend Micro scanner. My IE kept dying when I tried that. The Panda scan is downright scarry. You will see that I have Ad-Aware, NIS 2005, AND SpyBot S&D running, and yet, Panda found all kinds of viruses and spyware. NEED HELP!
I am going to attach both files below before taking any steps.
Copy all my instructions into wordpad and save to your desktop. You can't have any open browser windows.
Go to Start->Run and type "Services.msc" (without quotes) then hit OK
Scroll down and find the service called.
Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I)
Make sure it is selected in color. Right click on the service and click on stop. Right click on it again and go to Properties. In the Properties screen and under the General Tab, change the Startup Type to Disabled in the dropdown box. Click on Apply. Then OK. If the service isn't listed go ahead with the rest of these instructions anyway.
* Updating Ad-aware:
Double-Click the Desktop Icon > Click 'Check For Updates Now' > Click 'Connect'
* Updating Spybot:
Double-Click the Desktop Icon > Click Update > Drop-Down Box UniDo(Europe) > Select Pure-Elite(USA) or EON (AU) > Click 'Search for Updates' > Click 'Download Updates'
Please Copy ALL My Notes Below Into Notepad and Save the File to Your Desktop. You Need to be Offline and In Safe Mode to Remove Everything in your Log
Now rebooot into safe mode (press f8 during reboot, select safe mode) and DON'T reconnect to the net. You MUST be in safe mode to remove the About:Blank Bug on your system.
Run Hijackthis and place a check next to the following
This one here are you using
O23 - Service: WMP54GSVC - Unknown owner - C:\Program Files\WMPCI54G WLAN Monitor\WLService.exe" "WMP54G.exe (file missing)
and click fix.
Remain in safe mode for the next part of the removal.
- First Run the Cleanit! Program
- Next, Unzip the About:Buster Program to your desktop > Double-Click the Folder > Double-Click About:Buster > Click 'OK' > Click 'Start' >
now the program will start to run, it will take a few minutes, once the program is complete go ahead and run the program again.
- Double-Click CWShredder and click 'Fix'
* Close CWShredder, open Ad-aware and make the following changes to the settings in Ad-aware.
o Under Ad-aware 6 > Settings (Gear at the top) > Tweak > Scanning Engine:
check: "Unload recognized processes during scanning."
o Under Ad-aware 6 > Settings (Gear at the top) > Tweak > Cleaning Engine:
Check: "Let Windows remove files in use at next reboot."
Press 'Proceed'
Press 'Start'
* Select option 'Use Custom scanning options'
* Click 'Activate in-depth scan'
* Press 'Select drives\folders to scan' Select the active partition which is usually C:
Click 'Customize'
* Make sure the following are all are Checked:
o 'Scan Within Archives'
o 'Scan Active Processes'
o 'Scan Registry'
o 'Deep Scan Registry'
o 'Scan My IE Favorites For Banned URL'S
o 'Scan My Hosts File'
Click 'Proceed'
* Now press "Next" to let Ad-aware scan your drives.
* Once Ad-aware has completed its scan click 'Next' > Now Click 'Scan Summary' > Click All the Boxes with a Green Check Mark
* Now Click 'Next' and Finally Click 'OK'
Close Out Ad-aware
Open Spybot.
* Click 'Search & Destroy'
* Click 'Check for problems' (the program will now search your HDD)
* Make sure all finding are checked and click 'Fix Selected Problems'
Close SpyBot!
Now Delete the following Files.
Files:
C:\WINNT\javaaz32.exe << This file
C:\WINNT\system32\d3nm.exe << This file
C:\WINNT\system32\javaki32.exe << This file
C:\WINNT\system32\apiba.dll << This file
C:\WINNT\appqo.dll << This file
Okay. That took a while, but I got through it all. Here is the new log file.
Also, I have three questions...
1.) is it possible that everytime I reboot, these files are multiplying and worse, still, renaming themselves? Everytime I think I've got it, I am finding new files that are trying to start. I had to change a couple of your instructions to include almost 10 d3*.dll, .exe. and .cfg files, and the executables changed names also in other cases. That has been my trouble with fighting these.
2.) I'm surprised there isn't more talk about Webroot Spy Sweeper. That is the program I've had installed for a while that told me there was a problem in the first place. It didn't do much to remove it, but it kept me aware that there was a problem. What do you think?
3.) Is it possible that something on my system was/is preventing the NISShExt.dll file from installing? That is part of the Norton Adware Prevention file system. Just wondering if you knew off the top of your head.
Anyway, I'm waiting around to see what you think of the log file, so let me know if there is something else I need to do. Thanks for your help in this.
tE
Logfile of HijackThis v1.99.1
Scan saved at 10:03:57 AM, on 5/4/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Wow that is some great work you did there my friend
1.)Yes it is possible these things have gone mad.
2.)Yes i have heard of this program but have not used it
but it did let you know something was up. & that made you do
something about it
3.)Yes anything is possible with this type of stuff there is someone
somewhere right now saying hmmmm what if
but thanks to sites like this one we try to stay on top of problems
now here are some other progs that you should not be without.
SpywareGuard - An anti-virus program scans files before you open them and prevents execution if a virus is detected - SpywareGuard does the same thing, but for spyware! http://www.javacoolsoftware.com/spywareguard.html
IE-SPYAD is a Registry file (IE-ADS.REG) that adds a long list of sites and domains associated with known advertisers, marketers, and crapware pushers to the Restricted sites zone of Internet Explorer. https://netfiles.uiuc.edu/ehowes/www/resource.htm
Okay, the problem is fixed and I've made the additional changes that were suggested. I am not using NIS2005, but now I am using the programs recommended from this site, and my computer is working better than ever. In fact, the whole wireless network in my house is. I never knew this wireless printer could print so fast and the firewall catches everything.
My compliments to HGD for his impressive troubleshooting and concise advice. It makes me think that every computer needs to go through some amount of checking to make sure that it's running at its top performance.