Author Topic: I need help, daosearch.com problems  (Read 1019 times)

Offline DAkinOS

  • Newbie
  • *
  • Posts: 3
  • Karma: +0/-0
    • View Profile
I need help, daosearch.com problems
« on: March 27, 2005, 11:12:38 PM »
I've been having a lot of problems with mozilla and IE where there are links for words like "free" and "auto", that send me to http://daosearch.com . Also, when I google something, the sites that come up have nothing to do with what I searched for, and also go to daosearch.com . I'm also having problems with Security iGuard where it will install and run by itself. I've tried uninstalling it but it keeps coming back. Below is my HijackThis log. Please help me, thank you.



Logfile of HijackThis v1.99.1
Scan saved at 10:47:31 PM, on 3/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Rscmpt.exe
C:\WINDOWS\system32\BSPLAYER.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
C:\WINDOWS\system32\vmss\vmss.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\Services\{118110F7-B489-4AE5-A74F-9721C8661C4D}\SVCHOST.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AIM2\aim.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Dennis\My Documents\HIJACK\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://daosearch.com/index.php?id=32994&said=261
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.makemesearch.com/?said=338
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: Cls - {CF021F40-3E14-23A5-CBA2-7173706D1316} - C:\WINDOWS\system32\spm1316.dll (file missing)
O4 - HKLM\..\Run: [Rscmpt] C:\WINDOWS\system32\Rscmpt.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BS Player] BSPLAYER.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\system32\tibs3.exe
O4 - HKLM\..\Run: [mediamotor.exe] C:\WINDOWS\mmups.exe
O4 - HKLM\..\Run: [gwbbjg] c:\windows\system32\gwbbjg.exe
O4 - HKLM\..\Run: [Dvx] C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [vmss] C:\WINDOWS\system32\vmss\vmss.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Disk Keeper] C:\DOCUME~1\Dennis\LOCALS~1\Temp\keep.exe
O4 - HKLM\..\Run: [Service Host] C:\WINDOWS\system32\Services\{118110F7-B489-4AE5-A74F-9721C8661C4D}\SVCHOST.EXE
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\RunOnce: [Local runole service] C:\WINDOWS\System32\srvc32.exe
O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - HKCU\..\Run: [Steam] "c:\progra~1\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - HKCU\..\RunOnce: [Local runole service] C:\WINDOWS\System32\srvc32.exe
O4 - HKCU\..\RunOnce: [BS Player] BSPLAYER.EXE
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM2\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Microsoft AntiSpyware helper - {293DC1F7-A65C-4778-83F0-2195282AD32A} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {293DC1F7-A65C-4778-83F0-2195282AD32A} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {A324E949-ABBA-4E07-8549-29B2B8AD2D1B} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {A324E949-ABBA-4E07-8549-29B2B8AD2D1B} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {A32F8DC0-8A1A-4425-BA80-941C042729DA} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {A32F8DC0-8A1A-4425-BA80-941C042729DA} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {CFCEFF52-C429-439A-B419-0E80C65FE62F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {CFCEFF52-C429-439A-B419-0E80C65FE62F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {F832401B-C927-4159-9CF1-D6D6B9310C30} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {F832401B-C927-4159-9CF1-D6D6B9310C30} - (no file) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

firecar

  • Guest
I need help, daosearch.com problems
« Reply #1 on: April 05, 2005, 05:43:33 PM »
The following is obtained from mcafee.com.

This is a trojan that modifies Web Browser settings and contents.  The trojan comes with a dropper file.  When the dropper is run, the following files are created:

%WinSys%\Services\{clsid}\svchost.dll (126,976)
%WinSys%\Services\{clsid}\svchost.exe (45,056)
%WinSys%\Services\{clsid}\svchost32.dll (57,344)
where %WinSys% is the Windows system32 directory.  {clsid} is a random generated class id used as directory name, such as {F67221AA-C5A4-4D1A-B39A-9AAF48CA084B}.

The following registry keys are created:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"Service Host" = %WinSys%\Services\{clsid}\svchost.exe
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
"Start Page" =  http://daosearch.com
svchost32.dll installs a system wide message hook.  The dll is loaded with every running processes.  It monitors processes running on the system, if a web browser is launched, such as Internet Explorer, Netscap, Firefox, Mozilla or Opera, the dll can perform various tasks:


I have resolved the problem by doing the following;

1) Using regedit, delete
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"Service Host" = %WinSys%\Services\{clsid}\svchost.exe

2) Reboot the system

3) Delete 3 files in
%WinSys%\Services\{clsid}\svchost.dll (126,976)
%WinSys%\Services\{clsid}\svchost.exe (45,056)
%WinSys%\Services\{clsid}\svchost32.dll (57,344)

where %WinSys% is the Windows system32 directory.  {clsid} is a random generated class id used as directory name, such as {F67221AA-C5A4-4D1A-B39A-9AAF48CA084B}.

The file sizes are different from the above in my case.

Good luck..

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
I need help, daosearch.com problems
« Reply #2 on: April 05, 2005, 05:51:37 PM »
C:\WINDOWS\System32\wldr.dll
Thanks for the info firecar, I've seen that link to McAfee's
Good information
Unfortunately that doesn't remove all the bad files and registry keys
DAkinOS, if you still need a hand with your log can you please supply a fresh Hijackthis log, sorry thay we missed you
« Last Edit: April 05, 2005, 09:11:39 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline DAkinOS

  • Newbie
  • *
  • Posts: 3
  • Karma: +0/-0
    • View Profile
I need help, daosearch.com problems
« Reply #3 on: April 05, 2005, 08:02:54 PM »
Ok so I tried to use regedit by the run command but the second it opens up it just closes. The same thing happens with msconfig. Is there any other way to access regedit? And here is an updated HJT scan. Thanks for the help.


Logfile of HijackThis v1.99.1
Scan saved at 9:01:10 PM, on 4/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Rscmpt.exe
C:\WINDOWS\system32\BSPLAYER.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\Services\{2FAF450C-6003-4795-8D7E-F3EEC6324385}\SVCHOST.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
C:\WINDOWS\system32\picsvr\picsvr.exe
C:\Program Files\AIM2\aim.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\system32\ospitray.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Dennis\My Documents\HIJACK\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://daosearch.com/index.php?id=11258
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: Cls - {CF021F40-3E14-23A5-CBA2-7173706D1316} - C:\WINDOWS\system32\spm1316.dll (file missing)
O4 - HKLM\..\Run: [Rscmpt] C:\WINDOWS\system32\Rscmpt.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BS Player] BSPLAYER.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\system32\tibs3.exe
O4 - HKLM\..\Run: [mediamotor.exe] C:\WINDOWS\mmups.exe
O4 - HKLM\..\Run: [gwbbjg] c:\windows\system32\gwbbjg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Disk Keeper] C:\DOCUME~1\Dennis\LOCALS~1\Temp\keep.exe
O4 - HKLM\..\Run: [Service Host] C:\WINDOWS\system32\Services\{2FAF450C-6003-4795-8D7E-F3EEC6324385}\SVCHOST.EXE
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\system32\picsvr\picsvr.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\RunOnce: [Local runole service] C:\WINDOWS\System32\srvc32.exe
O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - HKCU\..\Run: [Steam] "c:\progra~1\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\RunOnce: [Local runole service] C:\WINDOWS\System32\srvc32.exe
O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - HKCU\..\RunOnce: [BS Player] BSPLAYER.EXE
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM2\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Microsoft AntiSpyware helper - {0ABCDF09-B6CF-4BCC-BABD-16717E055D0D} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {0ABCDF09-B6CF-4BCC-BABD-16717E055D0D} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {1997D0B8-F9FB-41B9-8882-551E220E2657} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {1997D0B8-F9FB-41B9-8882-551E220E2657} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {293DC1F7-A65C-4778-83F0-2195282AD32A} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {293DC1F7-A65C-4778-83F0-2195282AD32A} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {A324E949-ABBA-4E07-8549-29B2B8AD2D1B} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {A324E949-ABBA-4E07-8549-29B2B8AD2D1B} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {A32F8DC0-8A1A-4425-BA80-941C042729DA} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {A32F8DC0-8A1A-4425-BA80-941C042729DA} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {CFCEFF52-C429-439A-B419-0E80C65FE62F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {CFCEFF52-C429-439A-B419-0E80C65FE62F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {DFE7EC09-A962-4108-904D-CBDA5E74EEF2} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {DFE7EC09-A962-4108-904D-CBDA5E74EEF2} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {E8BF62EF-FDDE-497F-849F-A007D165ECF5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {E8BF62EF-FDDE-497F-849F-A007D165ECF5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {F832401B-C927-4159-9CF1-D6D6B9310C30} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {F832401B-C927-4159-9CF1-D6D6B9310C30} - (no file) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
I need help, daosearch.com problems
« Reply #4 on: April 05, 2005, 08:22:33 PM »
===Download and Install this small program
to help clean your temp folders,cookies,prefetch folder, recylebin
Windows Cleanup
Install for now, don't run a scan yet

Download and save to desktop
HSFIX.zip
Unzip the contents of HSFix.zip and an HSFix directory will be created
We'll need this later

Please Print this out or save these instructions to a Notepad file and save it to your Desktop
RESTART your Computer in SAFE MODE

Find and delete these files or folders if found
C:\WINDOWS\system32\BSPLAYER.EXE <-file
C:\WINDOWS\system32\tibs3.exe
C:\WINDOWS\mmups.exe
C:\WINDOWS\desktop.html
C:\WINDOWS\Web\desktop.html
c:\windows\system32\gwbbjg.exe
C:\WINDOWS\System32\srvc32.exe
C:\WINDOWS\System32\spoolsrv32.exe <-file, don't delete anything else because it looks similiar

C:\WINDOWS\system32\nsvsvc <-folder
C:\WINDOWS\system32\picsvr <-folder
C:\Program Files\Security iGuard <-folder
C:\WINDOWS\system32\Services\{2FAF450C-6003-4795-8D7E-F3EEC6324385} <-folder

Stay in safe mode

Do another scan with Hijackthis and put a check next to these entries:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://daosearch.com/index.php?id=11258 <--may just show Start Page= in safe mode
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - (no file)

O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: Cls - {CF021F40-3E14-23A5-CBA2-7173706D1316} - C:\WINDOWS\system32\spm1316.dll (file missing)

O4 - HKLM\..\Run: [BS Player] BSPLAYER.EXE

O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\system32\tibs3.exe
O4 - HKLM\..\Run: [mediamotor.exe] C:\WINDOWS\mmups.exe
O4 - HKLM\..\Run: [gwbbjg] c:\windows\system32\gwbbjg.exe

O4 - HKLM\..\Run: [Disk Keeper] C:\DOCUME~1\Dennis\LOCALS~1\Temp\keep.exe
O4 - HKLM\..\Run: [Service Host] C:\WINDOWS\system32\Services\{2FAF450C-6003-4795-8D7E-F3EEC6324385}\SVCHOST.EXE
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\system32\picsvr\picsvr.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\RunOnce: [Local runole service] C:\WINDOWS\System32\srvc32.exe
O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe

O4 - HKCU\..\RunOnce: [Local runole service] C:\WINDOWS\System32\srvc32.exe
O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - HKCU\..\RunOnce: [BS Player] BSPLAYER.EXE

O9 - Extra button: Microsoft AntiSpyware helper - {0ABCDF09-B6CF-4BCC-BABD-16717E055D0D} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {0ABCDF09-B6CF-4BCC-BABD-16717E055D0D} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {1997D0B8-F9FB-41B9-8882-551E220E2657} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {1997D0B8-F9FB-41B9-8882-551E220E2657} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {293DC1F7-A65C-4778-83F0-2195282AD32A} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {293DC1F7-A65C-4778-83F0-2195282AD32A} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {A324E949-ABBA-4E07-8549-29B2B8AD2D1B} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {A324E949-ABBA-4E07-8549-29B2B8AD2D1B} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {A32F8DC0-8A1A-4425-BA80-941C042729DA} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {A32F8DC0-8A1A-4425-BA80-941C042729DA} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {CFCEFF52-C429-439A-B419-0E80C65FE62F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {CFCEFF52-C429-439A-B419-0E80C65FE62F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {DFE7EC09-A962-4108-904D-CBDA5E74EEF2} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {DFE7EC09-A962-4108-904D-CBDA5E74EEF2} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {E8BF62EF-FDDE-497F-849F-A007D165ECF5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {E8BF62EF-FDDE-497F-849F-A007D165ECF5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {F832401B-C927-4159-9CF1-D6D6B9310C30} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {F832401B-C927-4159-9CF1-D6D6B9310C30} - (no file) (HKCU)


After you have ticked the above entries, close All other open windows, including this one
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis

Open Windows CleanUp!>>START>>All programs>>Cleanup!
Click on the CleanUp button, let it finish scanning for files, when it's done
Don't log off or restart yet

Navigate to the HSFix directory and double-click on HSFix.bat.
* It will produce a log file, located here: C:\hslog.txt. <--we'll need this later

RESTART your computer back to Normal mode

Do the following
1. Open the Control Panel.
2. Open Display Properties.
3. Click the Desktop tab.
4. Click the Customize Desktop button.
5. Click the Web tab in the Desktop Items window.
6. Make sure all checkboxes in this window are un-checked.
OK your way out
Log off your user account and log back on again if anything unchecked

Post back a fresh Hijackthis log and the log from HSfix.bat>>C:\hslog.txt

Also let me know what other files or folders you see in this folder
C:\WINDOWS\system32\Services

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here