Download
About:Buster.zipby RubbeR Ducky
UNZIP the contents to desktop, a folder will be placed on your desktop
Open it and run About:buster.exe
Click the Update Button and check for updates, if any, download them
Then close it for now, we'll need this later
==Download and UNZIP to desktop
Cwserviceremove.zip so you now have cwserviceremove.reg extracted to desktop
We'll need it later
==Download and Install this small program
to help clean your temp folders,cookies, etc...
Windows CleanupGive the link time to load or try it twice, it may be busy
Alternate Download linkWe'll need this later
==Download and save too desktop
winsockxpfix.exeWe'll need this later
==From my signature below, download and save to Desktop CWShredder.exe
Don't run it yet
Set Windows To Show Hidden Files and Folders
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Uncheck the Hide Extensions for known file types
* Click Yes to confirm.
* Click OK.
==Please Print this out or save these instructions to a Notepad file and save it to your Desktop
RESTART your Computer in
SAFE MODEYou can do this by tapping the F8 key as the system is restarting, right before Windows loads, or use the link
I supplied for a more detailed explanation
==Go to START>>>RUN>>>type in
services.msc and hit Enter
In the next window, look on the right hand side for this service
name----
Network Security Service (NSS) Double click on it--- STOP the service-- If running
In the drop down menu, change the startup type to
DisabledAccess your Add/Remove programs and remove
Viewpoint Media PlayerIf you didn't intentionally install Secret Smileys
Remove it too
==Using Windows Explore, navigate to these files and delete them if found and if you can, carry on if you can't find or remove them
FILES
C:\WINDOWS\
crle.exeC:\WINDOWS\system32\
atlzk32.dllC:\WINDOWS\system32\
sdkog.exeC:\WINDOWS\system32\
appvr32.exeFOLDERS
C:\Program Files\
Security iGuardC:\Program Files\
ViewpointC:\Program Files\
Enigma Software Group==Open Windows CleanUp!>>START>>programs>>Cleanup!
Click on the CleanUp button, let it finish scanning for files, when it's done
Decline to Log off
==Start About:Buster and hit ok. Now for the scanning part. Hit Start and then Ok. The program should start scanning.Scan a Second time. Save the log... Then hit exit
You may have to scan more than twice, try 3 or 4 times until no files or Data Streams are found
==Do another scan with Hijackthis and put a check next to these entries:
Not all may exist, but fix what appears
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\qsnwl.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\qsnwl.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\qsnwl.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\qsnwl.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\qsnwl.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\qsnwl.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\qsnwl.dll/sp.html#37049
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Class - {F521300B-AC38-427A-A225-491396604012} - C:\WINDOWS\system32\atlzk32.dll
O4 - HKLM\..\Run: [JVM0.12] C:\WINDOWS\System32\uvnmjaox.exe
O4 - HKLM\..\Run: [JVM0.14] C:\WINDOWS\System32\cynjs.exe
O4 - HKLM\..\Run: [FILE] C:\WINDOWS\abcdefg.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\Program Files\Internet Explorer\IEXPLORE.EXE
O4 - HKLM\..\Run: [sdkog.exe] C:\WINDOWS\system32\sdkog.exe
O4 - HKLM\..\RunOnce: [appvr32.exe] C:\WINDOWS\system32\appvr32.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\crle.exe (file missing)
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\\aolserv.exe (file missing)After you have ticked the above entries, close
All other open windows,
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis
==Double click on
cwsserviceremove.reg and allow it to add or merge to the registry
==Run CWShredder.exe, click the FIX button and let it fix what it finds
===RESTART the computer back to Normal mode
Back in Windows
*If prompted by Microsoft Anti-Spyware about a change
ALLOW them so it won't interfere with any fixes we are trying
===Look for a file called
shell.dll in your C:\Windows\system32 folder
If it is not there, Go into System32\dllcache folder
Find shell.dll
Right click on shell.dll and choose copy from the menu. Then paste it into the
system32 folder
Access Internet Options via Control Panel
Under the Programs tab "Reset Web Settings"
Under the Security tab | Custom Level
Check ActiveX security settings:
Make sure that the following settings are correct:
o Download signed ActiveX controls (Prompt)
o Download unsigned ActiveX controls (Disable)
o Initialize and script ActiveX controls not marked as safe (Disable)
o Run ActiveX controls and plug-ins (Enabled)
o Script ActiveX controls marked safe for scripting (Prompt)
I'm going to ask that you post back a number of logs
Try and supply them all, thanks
Post back with a fresh Hijackthis log
Also, post the logs from About:Buster
I want to check to see if your hosts file was edited
Could you do the following
==Open Hijackthis>>Open Misc tools section>>Open Hosts file manager
Click the "Open in Notepad"
Copy and paste back the whole contents of this notepad file too
*Note, if at any time you lose Internet connection
Open Winsockfix.exe and run the FIX button with all other windows closed
It should restart your computer
If not restart anyways