Hello and Welcome. Please subscribe to this thread to get immediate notification of replies as soon as they are posted.
Before we do anything else, please ensure that you have already patch your system against the recent WMF exploit. Please refer to my sig. No point we fix anything only for it to return tomorrow.
Please read this post completely before begining the fix. If there's anything that you do not understand, kindly ask your questions before proceeding. Please ensure that there aren't any any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this webpage would not be available when you're carrying out the fix.
* * * * * *
Let's try this first..
Download and unzip -
bfu.zip
Run the program and click the Web button located on the top right corner
Copy/Paste this url into the address bar of the Download script window:
http://metallica.geekstogo.com/p2pnetwork.bfu
Checkmark the following boxes:
- Use settings specified in script for the above option
- Show log after script ends
Execute the script by clicking the
Execute button.
When it finishes running, click the Save button for a copy of the log
Post the log created by the script when you have completed the fix
If you have any questions about the use of BFU please click here
* * * * * * ADDITIONAL DOWNLOADS * * * * * * * * * * * * * *
Download & install
CleanUp.exe (not recommended for WinXP64)
Download the file attached -
Purity.zip
Save it on your desktop. We shall be needing it in Safe Mode
Download
KillBox v2.0.0.175.exe (it's important that you get version v2.0.0.175)
Download and install
Ewido Security Suite- When installing, under "Additional Options",
- uncheck - Install background guard
- Have Ewido update itself & then exit the program.
If you are having problems with the updater, you can use this link to
manually update Ewido
'UNPLUG'/DISCONNECT your computer from the Internet when you have finished downlaoding.
It is IMPORTANT that you don't miss a step & perform everything in the correct order.
* * * * * * FIXING ENTRIES WITH HIJACKTHIS * * * * * * * * * *
Do a HijackThis scan & place a check next to these items and select "Fix checked":
O2 - BHO: (no name) - {C5AF2622-8C75-4dfb-9693-23AB7686A456} - C:\WINDOWS\DH.dll (file missing)
O4 - HKLM\..\Run: [Network] C:\Program Files\Network\network.exe
O4 - HKLM\..\Run: [wmplayer] C:\Program Files\wmplayer\wmplayer.exe /auto
O4 - HKLM\..\Run: [drsmartloadb] c:\\drsmartloadb.exe
O4 - HKLM\..\Run: [xp] p2pnetworking.exe
O4 - HKLM\..\RunServices: [ms-update] scvhost.exe
O4 - HKLM\..\RunServices: [xp] p2pnetworking.exe
O4 - HKCU\..\Run: [Lakftp] C:\WINDOWS\system32\?hkntfs.exe
O4 - HKCU\..\Run: [SpyBlocs] C:\Program Files\eBlocs\SpyBlocs\GLF4D.exe
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://sib1.od2.com/common/Member/Cl.../OCI/setup.exe
O16 - DPF: {C56CE781-A6FC-4706-8B32-6EB4622155DF} (MediaConnect Control) - http://plugin.euro-infomedia.com/mpv0.cab
* * * * * * KILLBOX * * * * * * * * * * * * * * * * * * * * * * *
Launch KillBox.exe & select the following options:
- delete on Reboot
- All files (if available)
Use your mouse to select all the filenames highlighted in
blue & then right-click & select Copy
- C:\Program Files\Network\network.exe
C:\Program Files\wmplayer\wmplayer.exe
C:\WINDOWS\DH.dll
c:\drsmartloadb.exe
C:\WINDOWS\system32\scvhost.exe
C:\WINDOWS\scvhost.exe
* Go to the File menu, and choose
Paste from Clipboard
* Click the
RED X button.
* Click Yes at the Delete on Reboot prompt.
* Click Yes at the 'Pending Operations prompt'.
If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, download and run missingfilesetup.exe. Then try Killbox again.
* * * * * * RESTART WINDOWS IN SAFE MODE * * * * * * * * * *
1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the option to run Windows in Safe Mode.
* * * * * * UN-INSTALLING PROGRAMS * * * * * * * * * * * * * *
Go to Start -> Control Panel -> Add or Remove Programs and uninstall the following programs:
Please note any other programs that you dont recognize in that list in your next response
* * * * * * DELETING FILES/FOLDERS * * * * * * * * * * * * * * *
If you have not done so already, please enable the viewing of Hidden files
From Windows Explorer, go to Tools -> Folder Options -> View tab.
- Tick - 'Show hidden files and folder'
- Untick - 'Hide file extensions for known types'
- Untick - 'Hide protected operating system files'
- Click Yes to confirm & then click OK
Locate and delete the following files/folders: (let me know if you fail to find/delete any)
- C:\Program Files\eBlocs\
C:\Program Files\Network\
C:\Program Files\wmplayer\
* * * * * * PURGING TEMP FOLDERS * * * * * * * * * * * * * * *
Run
Cleanup! using the following configuration:
1. Click Options...
2. Set the slider initially to
Standard CleanUp!
3.
Uncheck the following:
- Delete Newsgroup cache
- Delete Newsgroup Subscriptions
- Scan local drives for temporary files
4. Click OK
5. Press the CleanUp! button to start the program.
6. Do NOT reboot/logoff if prompted.
* CleanUp! will not create any backups!!
* * * * * * RUNNING ADDITIONAL SCANNERS * * * * * * * * * * *
From within Purity.zip, double click
purity.bat & allow it to run
It shall produce a log (C:\G_Purity.txt) to post back here
* * * *
Run
Ewido with it's updated definitions:(...it's important that all windows must be closed)
- Click Scanner
- Click Complete System Scan to begin scanning.
- Click OK when prompted to clean files
With the first file it prompts to clean, select the option:
- "Perform action on all infections"
- .Choose clean and click OK.
Once finished, click the
Save report button & save the report to your desktop
** Ewido scan would require at least an hour. I suggest that you go grab a cup of coffee & do something else while you wait for it to complete.
* * * * * * REBOOT TO NORMAL MODE * * * * * * * * * * * * * *
Establish an internet connection & perform an online scan with Internet Explorer at
Kaspersky Online Scanner
Answer Yes, when prompted to install an ActiveX component.
- The program will then begin downloading the latest definition files.
- Once the files have been downloaded click on NEXT
- Locate the Scan Settings button & configure to:
- Scan using the following Anti-Virus database:
- Scan Options:
- Scan Archives
- Scan Mail Bases
- Click OK & have it scan My Computer
- Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
- Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
* * * * * * CHECK LIST * * * * * * * * * * * * * * * * * * * * *
In your next post, please include fresh logs from:
- HiJackThis log
- Bfu's log
- C:\G_Purity.txt
- Online Scan
- Ewido
Please provide details of any problems you encountered whilst performing the above steps & update us on how the computer behaves now