Hello,
Please could you download and unzip About
:Buster from
AboutBuster. Leave it for now, we'll use it later. Also download and install Ad-aware from
here.
Once you have installed Ad-aware, run the program and in the bottom right hand corner click Check For Updates. Update Ad-aware following the prompts and then close the program, we will use it later.
Then boot into
Safe Mode and ensure that you are showing
Hidden Files and Folders beforehand.
Go to Start> Run and type
services.msc.
Locate
Network Security Service (NSS). Double click it and click the Stop button in the Properties window. Select Disabled from the drop down menu next to Startup Type. Click Ok and exit Services.
Press Ctrl+Alt+Del to get into Task Manager. Once in Task Manager, end the following processes (if they exist):
ntzv32.exe
Restart Hijack This and put a checkmark next to these entries and click Fix Checked:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ggmsv.dll/sp.html#35273
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about
:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\ggmsv.dll/sp.html#35273
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ggmsv.dll/sp.html#35273
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ggmsv.dll/sp.html#35273
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\ggmsv.dll/sp.html#35273
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System\blank.htm
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {1FF3C680-15C2-D623-5DC8-97AEC3A3E57C} - C:\WINDOWS\system32\crji32.dll
O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\System32\tibs3.exe
O23 - Service: Network Security Service (NSS) ( 6Q'8) - Unknown owner - C:\WINDOWS\system32\ntzv32.exe
Delete the following files and folders:
C:\WINDOWS\System\
blank.htm
C:\WINDOWS\system32\
crji32.dll
C:\WINDOWS\System32\
tibs3.exe
C:\WINDOWS\system32\
ntzv32.exe
Now run the file aboutbuster.exe that we downloaded earlier. When the tool is open press the
Ok button, then the
Start button, then the
Ok button, and then finally the
Yes button. If it asks if you would like to do a second pass, allow it to do so.When finished, press the "Save log" button. I will want a copy of that log after all steps are completed here.
Copy the contents of this quote box to Notepad:
Quote:
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\HSA]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\SE]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\SW]
|
Click File> Save As. Click the drop down arrow next to Save as type: and select all files. In the filename box type fix.reg. Save it to a convenient location. Once saved, double click it and confirm that you want it to merge with the registry.
Now Start Ad-aware
We need to configure Ad-aware for a full scan.

Click on the
Gear icon (second from the left) to access the preferences/settings window
1. In the
General window make sure the following are selected:
- Automatically save log-file
- Automatically quarantine objects prior to removal
- Safe Mode (always request confirmation)
2. Click on the
Scanning button on the left and select :
- Scan Within Archives
- Scan Active Processes
- Scan Registry
- Deep Scan Registry
- Scan my IE favorites for banned URLs
- Scan my Hosts file
- Under Click here to select drives + folders, choose:
- All of your hard drives

Click on the
Advanced button on the left and select:
- Include additional process information
- Include additional file information
- Include environment information

Click the
Tweak button and select:
- Under the Scanning Engine:
- Unload recognized processes & modules during scan
- Include additional Ad-aware settings in logfile
- Under the Cleaning Engine:
- Let Windows remove files in use at next reboot

Click on
Proceed to save the settings.

Click
Start and on the next screen choose
Activate in-depth Scan at the bottom of the page and then choose:
- Use Custom Scanning Options

Click
Next and
Ad-aware will scan your hard drive(s) with the options you have selected.

Save the log file when it asks and then click
Finish

When finished, mark everything for removal and get rid of it. (Right-click the window and choose
Select All from the drop down menu and click
Next).
Then go to Start> Run and type
cleanmgr.
Put a checkmark next to:
Temporary Files
Temporary Internet Files
Recycle Bin
Click Ok
Reboot into Normal Mode.
Note: Two, possibly three files may have been deleted from your computer by the hijacker and may need to be replaced:
Control.exe. If control.exe is missing go to
merijn and download the version of control.exe for your operating system. If you are running Windows 2000, copy it to c:\winnt\system32\. For Windows XP, copy it to c:\windows\system32\.
hosts (with no extension). Download the
Hoster. Press "Restore Original Hosts" and press "OK". Exit Program. Note: if you were using a custom Hosts file you will need to replace any of those entries yourself
SDHelper.dll (if you are using Spybot Search & Destroy). If you have Spybot S&D installed and SDHelper.dll is missing, replace it
with this one. Copy the file to the folder containing your Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy)
Additionally, Please check your ActiveX security settings. They may have been changed by this CWS variant to allow all ActiveX. In IE, click Tools> Internet Options and then click the Security tab. Click on
Custom Level and make sure that the following settings are correct:
Download signed ActiveX controls (Prompt)
Download unsigned ActiveX controls (Disable)
Initialize and script ActiveX controls not marked as safe (Disable)
Run ActiveX controls and plug-ins (Enabled) (This actually refers to Java and Flash, not ActiveX)
Script ActiveX controls marked safe for scripting (Prompt)
Pay a visit to
http://housecall.trendmicro.com and let it scan for and remove any viruses, worms or trojans you may have.
Then post a fresh Hijack This log and your About
:Buster log here.