Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Hi
I still have Hijackthis reporting R0 and R1 registry values set to www.2020search.com
as well as015 trusted zone lines set to:
*.i-lookup.com
*.teensguru.com
*.offshoreclicks.com
*.xxxtoolbar.comI ran spywareblastersetup, Cwschredder, ad-awar6, Spybots, xtracer, and finally highjackthis with the lastest updates (with reboot between different executions and at computer startup and offline) but I still have My IExplorer home page highjack and VIPru.com favorite added illegaly as well as shortcuts (loans sex etc) on my desktops.
I have done a lot of researches on the net to find a solution without any sucess. Any idea??
Thank you for your help
Talk to you soon

There's an uninstaller on their web site.
Uninstall 2020search
So far as the 015's, have HJT fix them.

Hi Blender,
Here it is:
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\Pavsrv50.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.exe
C:\Program Files\Winamp\Winampa.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\APVXDWIN.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\WebProxy.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\AVENGINE.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WebSiteViewer\122691.dlr
C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
C:\Downloads\VirusDefense\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Windows Resources - {2D38A51A-23C9-48a1-A33C-48675AA2B494} - C:\WINNT\winres.dll
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\APVXDWIN.exe" /s
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Evidence Eliminator] C:\Program Files\Evidence Eliminator\ee.exe /m
O4 - HKCU\..\Run: [sp] C:\WINNT\sp.exe
O4 - Global Startup: hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
O4 - Global Startup: hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O15 - Trusted Zone: *.i-lookup.com
O15 - Trusted Zone: *.offshoreclicks.com
O15 - Trusted Zone: *.teensguru.com
O15 - Trusted Zone: *.xxxtoolbar.com
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by8fd.bay8.hotmail.msn.com/activex/HMAtchmt.ocx
Thanks for your help

cahuet
While offline check the following in hijack:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blankO2 - BHO: Windows Resources - {2D38A51A-23C9-48a1-A33C-48675AA2B494} - C:\WINNT\winres.dll
O4 - HKCU\..\Run: [sp] C:\WINNT\sp.exe
O15 - Trusted Zone: *.i-lookup.com
O15 - Trusted Zone: *.offshoreclicks.com
O15 - Trusted Zone: *.teensguru.com
O15 - Trusted Zone: *.xxxtoolbar.comClose any open windows and click "fix checked"
Reboot to safe mode, offline and delete the following if still present:
c:\winnt\winres.dll <-file
c:\winnt\sp.exe <-fileRerun your ad-aware and spybot (while in safe mode to remove what they find)
Reboot to normal windows and go here for virus scan:
http://housecall.trendmicro.com/housecall/start_corp.asp
You will need to disable your own av to prevent conflicts.
Post new log when done.
______________________________
I never give up!

cahuet
Before removing the 04 for:
O4 - HKCU\..\Run: [sp] C:\WINNT\sp.exe
Or deleting the file sp.exe....can you check its properties please?
I am not sure on that one....more research shows it may be valid...
Let me know what it is....thanks...sorry for confusion.
__________________________I never give up!

I have the same problem with this HJ, i want to know if doing that things you could solve the problem, so as to follow the same steps...
ty
jp

I can't get rid of this Golden Palace Casino that keeps downloading or the XXX toolbar....I ran hijack this, but I don't know what to delete...can somebody help me?

Cassandra
I had golden palace and xxxtoolbar on my 98 machine...I removed most of it by going to add/remove programs and removing:
CasProg
xxxtoolbar
CSync...comes with the toolbar and is spyware
n-case
ncase ads delivery...comes with xxx crap and is adware...you will be taken to a website to download the uninstaller.
IST
ISTsvc...part of the xxxtoolbar
Internet optimiser...comes with that toolbar
Active alert..comes with the toolbar***note***
All those programs I listed may not be there but do remove any of the ones that are in my list above.After you removed what you can with add/rem...reboot when it tells you, and you need to be online for most because the site that installed it will uninstall it.
Download these 3 programs for both protection and removal of what is left.Once installed update all 3 programs.
Spywareblaster...once updated click the select all button, click the "protect from checked items button.Spybot...after updating run its scan (turn off your antivirus to prevent conflicts) remove all in red.
Ad-aware...after updating, close it and restart the program, set up the following:Click the gear icon on top of window
click scanning button on left...check everything you can there...green=on
Click tweak on left...
click the+ beside scanning engine, make sure this is green:
unload recognized processes during scanning
Click the+ beside cleaning engine
Make sure this is green:
Let windows remove files in use at next reboot
Click proceed at botom of window
click start
check use custom scanning options
Make sure Activate in depth scan is green
Click next
Let it remove all found.Make sure you have all your windows updates, there has been many security related issues fixed that will help prevent re-infection.
And if you havn't already...wouldnt hurt to do a full system scan with antivirus.
Here is an online scanner if you need it:
If ou use the online scanner...turn off your antivirus to prevent conflicts.
Once you have done all that...start your own new thread if you want to post hijack log...but do say you used spybot, ad-aware to clean up first. (there will still be a few things to remove (fix))
All the above programs are free.
Jp
Follow same advise as I gave Cassandra
_________________________________
I never give up!

Hi,
I think I have the similar problem: about:blank page was highjacked with some internet search. The only thing I could do was to remove links to a file "winres.dll" from the registry. It helped but I wonder if is it an original Windows file or some trojan created it. One more thing: is it possible that trojan is still there?
Lamers everywhere!

Hey Jp, I did everything you said, and Golden Palace Casino is still downloading. Here is my hijackthis log...thanks so much!!! ~Cassandra
Logfile of HijackThis v1.97.7
Scan saved at 4:24:37 PM, on 2/27/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\WINDOWS\System32\uvtqaxhq.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\iPod\bin\iPodManager.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Ares\ares.exe
C:\Program Files\AOL Companion\companion.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\CASSANDRA\My Documents\HijackThis.exeR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.globalcomputer.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://ucf.proxy.fcla.edu:8888
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {C048B794-38AE-C293-FEFE-81DF7AD8FE08} - C:\WINDOWS\system32\vykulgti.dll
O2 - BHO: (no name) - {EFBDCDCC-BC0A-F92F-96CA-833D8BFD563C} - C:\WINDOWS\system32\poibtyab.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [onlhidhd] C:\WINDOWS\eydcnpsm.exe
O4 - HKLM\..\Run: [WinFavorites] C:\Program Files\WinFavorites\WinFavorites.exe1
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [xgnvkyza] C:\WINDOWS\System32\uvtqaxhq.exe
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\KaZaA Lite\Kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [] c:\WINDOWS\System32\
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [iPodManager] C:\Program Files\iPod\bin\iPodManager.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [zzb] c:\WINDOWS\System32\zzb.exe
O4 - HKLM\..\Run: [nvid] C:\WINDOWS\System32\tpsaqfgv.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKCU\..\Run: [] c:\WINDOWS\System32\
O4 - HKCU\..\Run: [zzb] c:\WINDOWS\System32\zzb.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\ares.exe" -h
O4 - HKLM\..\RunOnce: [RealPlayer_update] C:\Program Files\America Online 9.0\Jiti\Real9_codec_upd.exe restart
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.globalcomputer.com
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab

mmmiha
That winres.dll is one of the cool web search trojan varients...
Link to CWShredder...removal tool. Second one in the list.
Run the tool while offline, with all windows closed except for cwshredder.http://www.lurkhere.com/~nicefiles/
The tool will check for and remove any other varients and remains of the one you have (had).
To prevent it from happening again....Visit windows update, install all critical updates and service packs for both windows and for internet explorer.
_________________________________I never give up!

Cassandra
Just so I dont confuse you...I was giving Jp pretty much the same advise.
First place hijack in its own folder in your "my documents" folder...the program makes backups and will make a mess of your documents folder.
Start hijackthis and check all the following:
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {C048B794-38AE-C293-FEFE-81DF7AD8FE08} - C:\WINDOWS\system32\vykulgti.dll
O2 - BHO: (no name) - {EFBDCDCC-BC0A-F92F-96CA-833D8BFD563C} - C:\WINDOWS\system32\poibtyab.dllO4 - HKLM\..\Run: [onlhidhd] C:\WINDOWS\eydcnpsm.exe
O4 - HKLM\..\Run: [WinFavorites] C:\Program Files\WinFavorites\WinFavorites.exe1O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [xgnvkyza] C:\WINDOWS\System32\uvtqaxhq.exeO4 - HKLM\..\Run: [] c:\WINDOWS\System32\
O4 - HKLM\..\Run: [nvid] C:\WINDOWS\System32\tpsaqfgv.exe
O4 - HKCU\..\Run: [] c:\WINDOWS\System32\
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
Close all windows except hijack and click "fix checked"
Reboot the computer to SAFE mode (tap f8 while booting)
Show hidden and system files:Start> settings> control panel> folder options> View> Check "show hidden files and folders"> click apply> click ok.
Search for and delete the following files/folders:
C:\WINDOWS\eydcnpsm.exe <- file
C:\Program Files\WinFavorites <- folder
C:\WINDOWS\System32\P2P Networking <- folder
C:\WINDOWS\System32\uvtqaxhq.exe <-file
C:\WINDOWS\System32\tpsaqfgv.exe <-file
c:\program files\WebsavingsFromEbates <- folderReboot to normal windows, visit windows update, install all updates listed including sp1; there are many for both windows and internet explorer.
That should take care of most of the baddies but I do have a couple questions..
Is globalcomputer.com your homepage?Can you go to c:\windows\system32\zzb.exe, right click the file> properties> and tell me whatever info you get from the properties box please?
Also for this one unless you can tell me...
c:\program files\ares\ares.exe <-this fileI am particularly interested in who made them and date created..(when installed on your computer)
Can you also post a fresh log too please?
Thanks!
_________________________________
I never give up!

Hi,I think I solved the problem,it seems that my pc had a CWS.Googlemsn.
I used the Hijackthis, the Cwssrhedder and also i deleted the file winres.dll, which i think was the file that install the problem everytime the pc was reboot, then i had also a file call svshost similar to svchost , but the first is a kind of hj or similar,
well ty for the help and suggestions
byesorry for my poor english
jp..

JP
Hi..Glad you got it fixed up.
You are right the file winres.dll is one of the CWS varients.
The file svshost is a result of a virus. You may want to do an online scan or make sure your own antivirus is up to date and run a scan with it.
If you had the googlems cws hijack; you might want to check to see if your windows media player works ok. Sometimes the hijacker will replace the windows media player with its trojan.
If you find your windows media player does not work...you can re-instal it here:For windows 95/me/nt4/2000/xp:
http://www.microsoft.com/windows/windowsmedia/9series/player.aspx
Make sure you check for updates when done installing it...there has been updates since media player 9 came out.
For windows 98 gold:
http://www.microsoft.com/windows/windowsmedia/software/playerV7.aspx
Online scans:
Turn off your own antivirus to run any of those scans.
If they report clean as well as your own...you are ok.Good luck
_____________________________________I never give up!

![]() |
bridge.dll/system 32
|
Trojan found
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |