This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Log Help

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here's my log; I would be grateful for any help. Scans in safe-mode won't help nor does anything else, it seems…


Logfile of HijackThis v1.98.0
Scan saved at 10:41:29 AM, on 7/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\PROGRA~1\Ontrack\Fix-It\mxtask.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\win.exe
C:\WINDOWS\simple1.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Corel\Graphics8\Programs\MFIndexer.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\inetsrv\winlogon.exe
C:\Program Files\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINDOWS\system32\searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchportal.info/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://searchportal.info/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Fix-It AV] C:\PROGRA~1\Ontrack\Fix-It\MemCheck.exe
O4 - HKLM\..\Run: [Remndr] "C:\Program Files\CasinoOnline\CsRemnd.exe"
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inetsrv\winlogon.exe
O4 - HKLM\..\Run: [Winhost] C:\WINDOWS\win.exe
O4 - HKLM\..\Run: [nuluyc] C:\WINDOWS\System32\yixjocm.exe
O4 - HKLM\..\Run: [ist service uninstall x] C:\WINDOWS\simple1.exe /u
O4 - HKCU\..\Run: [SP TimeSync] "C:\Program Files\SP TimeSync 1.4\SP TimeSync.exe"
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inetsrv\winlogon.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Corel MEDIA FOLDERS INDEXER 8.LNK = C:\Corel\Graphics8\Programs\MFIndexer.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\windows\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\windows\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://c:\windows\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\windows\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: www.mt-download.com
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8B25920A-3AFC-40CA-A217-354A02B68805}: NameServer = 209.244.0.3 209.244.0.4
O18 - Protocol hijack: about - {53B95211-7D77-11D2-9F81-00104B107C96}
O18 - Protocol: start - {53B95211-7D77-11D2-9F81-00104B107C96} - C:\WINDOWS\System32\msxword.dll
hello Seth,

ok here we go.

first look in add/remove panel and uninstall any web search tools, enhancers, helpers etc.

next download CWShredder (dont run it just yet)
here:http://www.spywareinfo.com/~merijn/downloads.html

next get Spybot Search and destroy here:http://www.safer-networking.org/ (dont run yet)
———————————————————————————————–
next make sure files are set to show, how:Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

next boot into safe mode: how: tap F5 or F8 key at start up, may take several minutes to get to desk top, chose safe mode or see this link first: http://service1.symantec.com/SUPPORT/tsgen…001052409420406
————————————————————————————————
Once in safe mode:

run CWshredder,
latest version is 1.59.1, click on fix and run it

next run HJT again and have it fix these items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINDOWS\system32\searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchportal.info/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://searchportal.info/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O4 - HKLM\..\Run: [Remndr] "C:\Program Files\CasinoOnline\CsRemnd.exe"
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inetsrv\winlogon.exe
O4 - HKLM\..\Run: [nuluyc] C:\WINDOWS\System32\yixjocm.exe
O15 - Trusted Zone: www.mt-download.com
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
O18 - Protocol hijack: about - {53B95211-7D77-11D2-9F81-00104B107C96}
O18 - Protocol: start - {53B95211-7D77-11D2-9F81-00104B107C96} - C:\WINDOWS\System32\msxword.dll

while still in safe mode find and delete these:

C:\WINDOWS\inetsrv\winlogon.exe

Do you know what these next two are? if not woudnt hurt to delete them
C:\WINDOWS\win.exe
C:\WINDOWS\simple1.exe

C:\Program Files\CasinoOnline\CsRemnd.exe
O4 - HKLM\..\Run: [nuluyc] C:\WINDOWS\System32\yixjocm.exe

ok still in safe mode run Spybot search and destroy
—————————————————————————————–
afterwards back in normal mode, update and run your resident Av scanner
and do a online scan here;

online trojan scan: http://scan.sygatetech.com/pretrojanscan.html


http://www.windowsecurity.com/trojanscan/

post back in this thread if needed……shelf life
hello Seth, One more thing (forgot) clean up your temp folder, how: Empty Temp folders. Go to Start > Run and type:cleanmgr. Windows will scan. When done check these 3 and press *ok* to remove: Temporary Files Temporary Internet Files Recycle Bin ———————————– shelf life
Hi, shelf life:

It was a valiant effort but, alas, I'm still hijacked. My browser still opens to "Search Portal" regardless of how many times I reset my Options to Google, online or off.

To confirm, here's what I did:
Downloded CWShredder and Spybot Search; updated both from their sites.
Ran HJT in Safe Mode and found that several of the items that I was supposed to have it fix (from the first scan) weren't there to remove:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINDOWS\system32\searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
C:\WINDOWS\inetsrv\winlogon.exe
O4 - HKLM\..\Run: [Remndr] "C:\Program Files\CasinoOnline\CsRemnd.exe"

And the scary part is that I would have it fix/remove this file:
O18 - Protocol: start - {53B95211-7D77-11D2-9F81-00104B107C96} - C:\WINDOWS\System32\msxword.dll
and it would be back again the next time I (immediately) did an HJT re-scan.

I tried to run the online scan from Sygatetech but after 10 minutes of scanning, I received the following mesage:

"You have blocked all of our probes! We still recommend running this test both with
and without Sygate Personal Firewall enabled… so turn it off and try the test again."

Since I don't have Sygate Personal Firewall, I don't know why I would get this message.

I also ran the Trojansacn at windowsecurity.com and it found nothing, though it couldn't access some files. This is a copy of the message after the scan:

Starting scan at 12:35:19:515…
Scan Memory
Memory not infected
Scan folder: 'C:\', recursive
Unable to scan C:\System Volume Information - Access is denied.
Finished scan at 12:55:40:390
Total number of files is 40194, number of infected files is 0
Average files per second is 33, average file size is 4984829

There was one thing I forgot to mention in my first posting. For the last month or so, when I boot up, a "Desktop.ini- Notepad "window shows up on my desktop with the following message:

[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787

I don't what this is or why I would get it.


Finally, here's a current HJT scan log:

Logfile of HijackThis v1.98.0
Scan saved at 1:56:01 PM, on 7/11/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\PROGRA~1\Ontrack\Fix-It\mxtask.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\inetsrv\winlogon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Corel\Graphics8\Programs\MFIndexer.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchportal.info/
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Fix-It AV] C:\PROGRA~1\Ontrack\Fix-It\MemCheck.exe
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [ist service uninstall x] C:\WINDOWS\simple1.exe /u
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inetsrv\winlogon.exe
O4 - HKCU\..\Run: [SP TimeSync] "C:\Program Files\SP TimeSync 1.4\SP TimeSync.exe"
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inetsrv\winlogon.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Corel MEDIA FOLDERS INDEXER 8.LNK = C:\Corel\Graphics8\Programs\MFIndexer.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\windows\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\windows\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://c:\windows\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\windows\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8B25920A-3AFC-40CA-A217-354A02B68805}: NameServer = 209.244.0.3 209.244.0.4
O18 - Protocol: start - {53B95211-7D77-11D2-9F81-00104B107C96} - C:\WINDOWS\System32\msxword.dll

You'll note that some of the files that I was supposed to find but couldn't the first time, are there now (in addition to the pesky 018 item). I tried to remove them in normal mode but it couldn't haven't tried it again in safe mode.

Thanks for your continued help. I'm ever grateful.

Seth
hello Seth,

We have some work to do, but i like a challenge. Lets try once more and if that dosnt clear it up then i will have to get some help on this one.
i would print this out
go out and get ad aware here: http://www.lavasoft.de/ and update it, also update Spybot while online

next make sure all files are set to show, reboot to safe mode again (select safe mode)

Run CWShredder once more in safe mode
now start ad-aware and configure it like this:

Under Ad-aware 6 > Settings (Gear at the top) > Tweak > Scanning Engine:
check: "Unload recognized processes during scanning."

- Under Ad-aware 6 > Settings (Gear at the top) > Tweak > Cleaning Engine:
Check: "Let Windows remove files in use at next reboot."

Press 'Proceed'

Press 'Start'

Select option 'Use Custom scanning options'
Click 'Activate in-depth scan'
Press 'Select drives\folders to scan' Select the active partition which is usually C:
Click Customize
Make the following are all are Checked
*'Scan Within Archives'
*'Scan Active Processes'
*'Scan Registry'
*'Deep Scan Registry'
*'Scan My IE Favorites For Banned URL'S
*'Scan My Hosts File'
Click Proceed

press "Next" to let Ad-aware scan your drives…

Let it fix what it finds, next run Spybot search and destroy in safe mode
next reboot normally, >>>dont get on the internet<<<

ok now:
Have Hijack This fix all of the following (if still there) by placing a check in the boxes and hitting fix checked. Make sure all browsers and all Windows Explorer windows are closed before fixing.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchportal.info/

O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)

O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [ist service uninstall x] C:\WINDOWS\simple1.exe /u
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inetsrv\winlogon.exe
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inetsrv\winlogon.exe
O18 - Protocol: start - {53B95211-7D77-11D2-9F81-00104B107C96} - C:\WINDOWS\System32\msxword.dll

Now reboot back into safe mode and see if any of the above are running by hitting ctrl-alt-delete at same time, if so end process.

ok still in safe mode you will have to search for the above 04 items and delete them and the .dll file, i would do this with explorer: right click on start and chose explore and drill down to the files.
also in safe mode clear temps again:
Start > Run and type:cleanmgr. Windows will scan. When done check these 3 and press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin

hope this works
will get the desktop .ini later………………shelf life
shelf life:

I'm glad you like a challenge. Believe me, I'm as frustrated as you, but I'm still hijacked: I can't seem to make Search Portal not my home page.

Did everything and it found a bunch of stuff which was removed.

In Hijack This, the file
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
wasn't there but curiously, I found the file,
C:\WINDOWS\alchem.ini
in Explorer, dated 7.11.04, however I did not delete it (just in case). Also, the file
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://searchportal.info/
that was removed previously was back; I removed it.

The files
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inetsrv\winlogon.exe
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inetsrv\winlogon.exe
were gone and were also not present in the Windows folder.

Of course, that nasty little bugger
O18 - Protocol: start - {53B95211-7D77-11D2-9F81-00104B107C96} - C:\WINDOWS\System32\msxword.dll
was deleted in HJT (along with the others I was told to delete), but it was right back, in a follow-up scan. To make matters worse, it was nowhere to be found in the Windows folder. It must be hiding somewhere.

I hope this doesn't mean wiping the hard drive clean and reloading everything. That's not fun. BTW, what country/time zone are you in?

Best,

Seth
hey Seth, no you wont have to wipe the hard drive, ive seen much worse than what you have. i really think that msxword.dll is the problem and maybe a .exe file somewhere that iam missing, one way to catch this crapware is with a firewall, at least it can be denied a connection until you can pin it down. I could come up with some more suggestions, but i know you must be ready to get rid of this thing, so iam going to ask someone else to help you, iam sure they could provide a fix quickly. Iam in the US- central time zone, usually on after 4 or 5pm (afterwork)…….shelf life
shelf life: Thanks, much. I appreciate your efforts. Seth PS: Any thoughts on that Notepad thing that appears when I boot up (or is that related to the hijacking?)?
Hi Seth…. could you make sure you are running the most up to date version of CWShredder, click on the update button to check. Then boot into safe mode and run CWShredder and hit fix as opposed to scan only, reboot into normal mode and post a fresh hijack log for review.
Hi, Nellie2.

Thanks for joining the fray. Veified that my CWShredder was current and ran it in in Safe Mode; all clear.

Here's the new log:

Logfile of HijackThis v1.98.0
Scan saved at 9:19:53 PM, on 7/13/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\PROGRA~1\Ontrack\Fix-It\mxtask.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\inetsrv\services.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Corel\Graphics8\Programs\MFIndexer.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchportal.info/
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Fix-It AV] C:\PROGRA~1\Ontrack\Fix-It\MemCheck.exe
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inetsrv\services.exe
O4 - HKCU\..\Run: [SP TimeSync] "C:\Program Files\SP TimeSync 1.4\SP TimeSync.exe"
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inetsrv\services.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Corel MEDIA FOLDERS INDEXER 8.LNK = C:\Corel\Graphics8\Programs\MFIndexer.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\windows\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\windows\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://c:\windows\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\windows\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: www.mt-download.com
O15 - Trusted Zone: install.xxxtoolbar.com
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O18 - Protocol: start - {53B95211-7D77-11D2-9F81-00104B107C96} - C:\WINDOWS\System32\msxword.dll

Whoever you masked men and women are, thank you for all of your efforts on the part of a total stranger. I am truly grateful.

shelf life: I'm off to the link you suggested, next.

Best,

Seth
Hi Seth

Bring up task manager (Ctrl-Alt-Del) and end this process services.exe

Then run hijackthis again and with all browsers and windows closed except for hijackthis, put a check against the following and click 'fix checked'

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchportal.info/

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)

O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inetsrv\services.exe
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inetsrv\services.exe

O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - (no file)

O15 - Trusted Zone: www.mt-download.com
O15 - Trusted Zone: install.xxxtoolbar.com

O18 - Protocol: start - {53B95211-7D77-11D2-9F81-00104B107C96} - C:\WINDOWS\System32\msxword.dll

Then reboot into safe mode, you may have to enable hidden files and folders and delete the following;

C:\WINDOWS\inetsrv <– folder
C:\WINDOWS\System32\msxword.dll <– file

Then reboot and post a fresh hijack log for review.
Hi, Nellie2:

First, Task Manager wouldn't let me end the process > services.exe. A window appeared that was titled UNABLE TO TERMINATE PROCESS, with the message, "This is a critical process. Task Manager cannot end this process." I tried the same thing again in Safe Mode and got the same message.

I still had HJT fix the files you indicated (while in Safe Mode) and then deleted the folder C:\WINDOWS\inetsrv. Once again, the file > C:\WINDOWS\System32\msxword.dll was nowhere to be found in Explorer.

I rebooted and got the folowing message:

Windows cannot find C:\WINDOWS\inetsrv.exe, Make sure you typed the name correctly and then try again." [this makes some sense since I deleted the folder it was probabaly in, however, I didn't type anything…]. After clicking OK, I then got another message, " Could not load or run C:\WINDOWS\inetsrv. exe specified in the registry. Make sure the file exists or remove it from the registry." I clicked OK and then it rebooted normally.

The good news is that "Search Portal" is not my home page anymore; "About:blank" came up in the search window. Also, Internet Explorer seemed to be working faster when connecting to this site (with56K dial-up service). My new log is below. Note that 018 just won't go away.

Thanks.

Seth


Logfile of HijackThis v1.98.0
Scan saved at 7:44:55 PM, on 7/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\PROGRA~1\Ontrack\Fix-It\mxtask.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Corel\Graphics8\Programs\MFIndexer.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hijack This\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Fix-It AV] C:\PROGRA~1\Ontrack\Fix-It\MemCheck.exe
O4 - HKCU\..\Run: [SP TimeSync] "C:\Program Files\SP TimeSync 1.4\SP TimeSync.exe"
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Corel MEDIA FOLDERS INDEXER 8.LNK = C:\Corel\Graphics8\Programs\MFIndexer.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\windows\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\windows\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://c:\windows\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\windows\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8B25920A-3AFC-40CA-A217-354A02B68805}: NameServer = 209.244.0.3 209.244.0.4
O18 - Protocol: start - {53B95211-7D77-11D2-9F81-00104B107C96} - C:\WINDOWS\System32\msxword.dll
Hi Seth……. let me know if you are still getting the error message on reboot!

For now, run hijackthis again and fix the following;

O18 - Protocol: start - {53B95211-7D77-11D2-9F81-00104B107C96} - C:\WINDOWS\System32\msxword.dll

then copy the contents of the quotebox into notepad and save as fixme.reg, make sure you save it as all file types to your desktop.

REGEDIT4

[-HKEY_CLASSES_ROOT\CLSID\{53B95211-7D77-11D2-9F81-00104B107C96}]
[-HKEY_CLASSES_ROOT\TypeLib\{53B95204-7D77-11D2-9F81-00104B107C96}]
[-HKEY_CLASSES_ROOT\Interface\{53B95210-7D77-11D2-9F81-00104B107C96}]

[-HKEY_CLASSES_ROOT\PROTOCOLS\Handler\about]
[HKEY_CLASSES_ROOT\PROTOCOLS\Handler\about]
"{3050F406-98B5-11CF-BB82-00AA00BDCE0B}"=""

[-HKEY_CLASSES_ROOT\PROTOCOLS\Handler\start]


Merge the fixme.reg file by double clicking.
You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".

search for and delete these files if found
C:\WINNT\system32\msxword.dll
C:\Windows\system\wmscrop.exe

Then reboot and post a fresh hijack log.
Hi, Nellie2, I'm afraid the 018-Protocol Start file is the one that keeps coming back after I fix/delete it in HJT. Any other thoughts on getting rid of it? I just want to verify that you want me to save the quotebox contents to my desktop (not the C: drive, which is where notebpad wants default-save things). Once again, I can't find the msxword.dll file (also note that I'm on Windows XP, not NT; was that a typo or should I be looking for something I didn't think I have; can't search right know as I'm at work and the problem is on the home unit.) Thanks, S.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI