Thread: Fixwareout
View Single Post
Old 05-01-2007, 03:21 AM   #3 (permalink)
LonnyRJones
Expert Analyst, Moderator, Security Team
 
Join Date: Sep 2006
Posts: 1,646
OS: xp


Re: Fixwareout

Welcome to the forum

Delete fixwareout and its folder c:\fixwareout as it is not needed here

Start Hijackthis and place a check next to these items If there.

F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe
O2 - BHO: (no name) - {1051EA48-133B-4078-A70D-81DA6A6706B2} - C:\WINDOWS\System32\lcghda.dll (file missing)
O2 - BHO: SDWin32 Class - {13A57A6A-58F5-4727-B8AF-0735BD73A296} - C:\WINDOWS\System32\thzcf.dll (file missing)
O2 - BHO: (no name) - {4729922E-FB54-52C6-9276-020C40ACA671} - C:\WINDOWS\system32\zsizbsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [ICcontrol] C:\WINDOWS\iccontrol.exe
O4 - HKLM\..\Run: [oevywn.dll] "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\oevywn.dll,eeidstd
O4 - HKLM\..\Run: [msnsyslog] C:\WINDOWS\msnlogm.exe
O4 - HKLM\..\Run: [{28106F82-0AF0-2057-0923-03030403002c}] "C:\Program Files\Common Files\{28106F82-0AF0-2057-0923-03030403002c}\Update.exe" mc-110-12-0001032
O4 - HKCU\..\Run: [ad2240dc.exe] C:\Documents and Settings\Owner\Local Settings\Application Data\ad2240dc.exe
O16 - DPF: {FAFF0003-0A01-121A-A1C9-08032B23E0CC} - http://uk.global-acces.com/bc/nat3.exe
O16 - DPF: {FDE6B956-B80A-4578-9A10-4C24609412F1} - http://access.gamezdump.com/output/0.../fullgames.exe
O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/dba2106.exe

====================================
Hit fix checked and close Hijackthis.

Fallow the instructions here using Option to clean while your PC is in safe mode. afterwards once back in normal mode post its report and a new hijackthis log
http://siri.urz.free.fr/Fix/SmitfraudFix_En.php
LonnyRJones is offline