TV Media
primesuspect
Beepin n' BoopinDetroit, MI Icrontian
I'm stumped. TV Media keeps showing up in the registry, and keeps trying to load after reboot. I've tried everything that I can think of (and you know I'm no slouch at this)....
I can't find anything relating to the about:_blank trojan, there aren't any appInit problems in the registry, but one thing I've noticed is that CWS crashes on the CWS.Smartserach variants.. I have the latest versions of everything (CWS, defs for spybot and adaware), I've tried all the current methods (safe mode, PV, killbox, etc.) and I cannot kill this thing.
Any suggestions?
I can't find anything relating to the about:_blank trojan, there aren't any appInit problems in the registry, but one thing I've noticed is that CWS crashes on the CWS.Smartserach variants.. I have the latest versions of everything (CWS, defs for spybot and adaware), I've tried all the current methods (safe mode, PV, killbox, etc.) and I cannot kill this thing.
Any suggestions?
0
Comments
1) Restart in Safe Mode
2) Enable Hidden Files
Locate and delete the following:
C:\Program Files\TV Media <--this folder
C:\WINDOWS\twaintec.dll <--this file
C:\WINDOWS\twaintec.ini <--this file
C:\WINDOWS\bxxs5.dll <--this file
C:\WINDOWS\xqfkbqd.exe <--this file
C:\WINDOWS\System32\sxcggasj.exe <--this file
C:\Program Files\whInstall <--this folder
While still in Safe Mode:
Close all open windows, rescan with HijackThis and "Fix checked" the following:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\Program Files\TV Media\TvmBho.dll
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll
O2 - BHO: (no name) - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\bxxs5.dll
O4 - HKLM\..\Run: [xqfkbqd] C:\WINDOWS\xqfkbqd.exe
O4 - HKLM\..\Run: [webHancer Survey Companion] C:\Program Files\whInstall\WhSurvey.exe
O4 - HKLM\..\Run: [ofkqefx] C:\WINDOWS\System32\sxcggasj.exe
O4 - HKLM\..\Run: [mswspl] C:\WINDOWS\System32\sxcggasj.exe
O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\bxxs5.dll,DllRun
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
Restart normally, update and rescan with SpyBot, reboot and post a fresh log ...
MediaMan, since when did you start making appearances here in the SVT forum??
Dexter...
The log looks clean, and that scares me.
DON'T install the registry entries! These are for viewing purposes!
When I have 2c...I give it. Of course my 2c is Canadian so it's not worth that much.
You might also want to add www.delfinproject.com to your hosts file.
can you please post a STARTUP log. Not a regular HJT log, but a STARTUP log.
Dexter...
///EDIT: Did you find this: http://vil.nai.com/vil/content/v_100534.htm