TechSpot

url.cpvfeed popup virus!!!

By nblackst
Jun 12, 2007
  1. I need some help guys... I have been getting these popups like a lot of people have and I think the first step is for me to download hijackthis and give the log file... so here it is! I really hope somebody can help me!!! Thanks in advance!
     
  2. momok

    momok TS Rookie Posts: 2,265

    Hi nblackst and welcome to techspot. =)

    Note:Please do not copy and paste your logs. Instead, post the .log or .txt files as attachments.

    You are running an outdated version of HijackThis.
    You can obtain the latest version from the link in my signature. Also, please rename the HijackThis.exe to Analyze.exe.

    Important: Please read this thread HERE before you decide whether to clean or reformat your system.

    Should you decide to clean your computer, please do the following.

    You may wish to copy and paste these instructions on notepad for easier reference later.

    Boot into safe mode under your normal user name. See how HERE

    Next turn on "Show all files and folders, including hidden and system". See how HERE

    Go to start > run and type services.msc. Press the enter key.
    Search for the following services. Double click to select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

    ApachInc
    Cgtozku


    After that, run HijackThis and fix the following entries, if found (do this by placing a tick in the check boxes beside these entries and clicking "Fix checked"):

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {8A61098D-612B-4EF2-943D-64E920684061} - C:\WINDOWS\system32\xxyxwuv.dll (file missing)
    O2 - BHO: (no name) - {9D783D17-DBFE-8B26-8A0A-8DADA99072C2} - C:\WINDOWS\system32\qwn.dll
    O2 - BHO: (no name) - {AF2C54EB-0207-4477-BA59-80B187558247} - C:\WINDOWS\system32\jkkll.dll (file missing)
    O2 - BHO: (no name) - {E12BFF69-38A7-406e-A8EF-2738107A7831} - C:\WINDOWS\system32\jjforsqa.dll (file missing)
    O4 - HKLM\..\Run: [ApachInc] rundll32.exe "C:\WINDOWS\system32\wagqfimj.dll",realset
    O4 - HKCU\..\Run: [Cgtozku] "C:\Program Files\s?curity\winword.exe"
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} -
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab
    O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://mvnet.xlontech.net/qm/fox/061...ie06101001.cab
    O20 - Winlogon Notify: jkkll - C:\WINDOWS\system32\jkkll.dll (file missing)
    O20 - Winlogon Notify: xxyxwuv - xxyxwuv.dll (file missing)

    Close HJT.

    Navigate in Windows Explorer and delete the following files and folders in bold.

    C:\WINDOWS\system32\qwn.dll
    C:\WINDOWS\system32\wagqfimj.dll
    C:\Program Files\s?curity\ < There should be a folder which says "security" under Program Files. Delete the whole folder.

    Reboot into normal mode and rehide your protected OS files.

    Please go ahead to Viruses/Spyware/Malware, preliminary removal instructions and follow the steps given. Do follow all the instructions exactly. They will provide logs for analysis of your system so I will know how to instruct you to proceed.

    Thereafter, please post fresh HijackThis, AVG Antispyware and Combofix logs as attachments into this thread. Do not copy and paste your logs if not it will be ignored and/or removed.

    Also, please let me know the results of the AVG Antirootkit scan


    Regards,
    Your friendly momok =)

    This thread is for the use of nblackst only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...