Hello and Welcome. Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.
Before beginning the fix, read this post completely. If there's anything that you do not understand, kindly ask your questions before proceeding. Ensure that there aren't any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this webpage would not be available when you're carrying out the fix.
It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence.
---------------------------------------------------------------------------------------------
Download combofix.exe to your desktop. We'll use this later.
---------------------------------------------------------------------------------------------
Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe
Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
Once the desktop loads a text file will open (report.txt), you can close it - the file has already been saved.
Run HijackThis. Click "Do a System Scan Only", and place a check next to the following items (if found):
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O3 - Toolbar: (no name) - {5CBE2611-C31B-401F-89BC-4CBB25E853D7} - (no file)
O4 - HKLM\..\Run: [lnwin.exe] C:\WINNT\system32\lnwin.exe
O4 - HKCU\..\Run: [Brct] "C:\DOCUME~1\ADMINI~1\APPLIC~1\APPATC~1\msdtc.exe" -vt wnew
O4 - HKCU\..\Run: [Kmzbro] C:\Documents and Settings\Administrator\Application Data\a?sembly\?explore.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.118 85.255.112.205
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.118 85.255.112.205
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.116.118 85.255.112.205
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.118 85.255.112.205 <<<<Note!!! Only these O17 entries I have listed. There is one legit O17 entry in your log.
Click FIX CHECKED. Close HijackThis.
At the end of this fix, please post the contents of the text file that opened earlier (you can find it at C:\fixwareout\report.txt ).
**If you receive an error message while trying to run FixWareout, copy autoexec.nt from the C:\WINDOWS\repair folder to C:\WINDOWS\system32 folder, and run FixWareout again.
----------------------------------------------------------------------------------------------------------
Run ComboFix
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
---------------------------------------------------------------------------------------------
Please go to: VirusTotal
---------------------------------------------------------------------------------------------
Before beginning the fix, read this post completely. If there's anything that you do not understand, kindly ask your questions before proceeding. Ensure that there aren't any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this webpage would not be available when you're carrying out the fix.
It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence.
---------------------------------------------------------------------------------------------
Download combofix.exe to your desktop. We'll use this later.
---------------------------------------------------------------------------------------------
Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe
Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
Once the desktop loads a text file will open (report.txt), you can close it - the file has already been saved.
Run HijackThis. Click "Do a System Scan Only", and place a check next to the following items (if found):
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O3 - Toolbar: (no name) - {5CBE2611-C31B-401F-89BC-4CBB25E853D7} - (no file)
O4 - HKLM\..\Run: [lnwin.exe] C:\WINNT\system32\lnwin.exe
O4 - HKCU\..\Run: [Brct] "C:\DOCUME~1\ADMINI~1\APPLIC~1\APPATC~1\msdtc.exe" -vt wnew
O4 - HKCU\..\Run: [Kmzbro] C:\Documents and Settings\Administrator\Application Data\a?sembly\?explore.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.118 85.255.112.205
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.118 85.255.112.205
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.116.118 85.255.112.205
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.118 85.255.112.205 <<<<Note!!! Only these O17 entries I have listed. There is one legit O17 entry in your log.
Click FIX CHECKED. Close HijackThis.
At the end of this fix, please post the contents of the text file that opened earlier (you can find it at C:\fixwareout\report.txt ).
**If you receive an error message while trying to run FixWareout, copy autoexec.nt from the C:\WINDOWS\repair folder to C:\WINDOWS\system32 folder, and run FixWareout again.
----------------------------------------------------------------------------------------------------------
Run ComboFix
- Double click on combofix.exe & follow the prompts.
- When finished, it shall produce a log for you. Post that log in your next reply.
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
---------------------------------------------------------------------------------------------
Please go to: VirusTotal
- At the top of the page you'll find a "Browse" button. Click the "Browse" button and browse to this file in BOLD:
C:\WINNT\system32\lnwin.exe (or simply copy/paste the file path into the box next to the Browse button, then Click Send.)
- Click "Open".
- Then click the "Send" button at the top of the VirusTotal page.
- This will scan the file. Please be patient.
- Once scanned, copy and paste the results in your next reply together with a new HijackThis log, the results from combofix, located at C:\ComboFix.txt, and the results from FixWareout, located at C:\FixWareout\report.txt.
---------------------------------------------------------------------------------------------