This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Homepage Hijacked - Help!

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been running Netscape in order to avoid this constant annoyance with IE but its time to address it. It always resets my homepage to "about:blank" which becomes some sort of search engine. I also get pop-ups with IE too every time I start up. Here's my log file - beware the abundance of crap on my computer, sorry:


Logfile of HijackThis v1.98.2
Scan saved at 1:07:51 AM, on 8/24/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Winamp3\winampa.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = http://www.search-1.net/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = http://www.search-1.net/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://solongas.com/sp.htm?id=9
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\LILBUD~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\LILBUD~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\LILBUD~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\LILBUD~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchdot.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\LILBUD~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.searchv.com/1/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/w/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\LILBUD~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.searchv.com/1/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&ssPageName=h%3Ah%3Amyebay%3AUS"); (C:\Documents and Settings\Lil Buddy\Application Data\Mozilla\Profiles\default\vsl9036o.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Lil Buddy\Application Data\Mozilla\Profiles\default\vsl9036o.slt\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {E05306B8-CC65-435C-BC9C-0FA89DA3DFEF} - C:\WINDOWS\System32\jgaf.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [Msoffice] C:\WINDOWS\Fonts\msoffice.hta
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [jopa] C:\WINDOWS\System32\sysstartup.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [RealUpdater] C:\WINDOWS\System32\realupd.exe
O4 - HKCU\..\Run: [uninstal] regsvr32 /u /s image.dll
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: winlogin.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (HKCU)
O15 - Trusted Zone: *.greg-search.com
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\update.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebpr…etup1.0.0.5.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {69432678-2906-2705-1128-068943397621} -
O16 - DPF: {7CA3D0A3-7E2E-4AAB-A75E-FAB8ECA8BD95} (Skilljam Game Player Object) - http://ign.skilljam.com/ssp/SSP.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://128.164.199.30/activex/AxisCamControl.ocx
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v5.cab
O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Installer/104/rsinstaller.cab
O18 - Filter: text/html - {9934060D-27C2-4E80-A340-330D76464C09} - C:\WINDOWS\System32\jgaf.dll
O18 - Filter: text/plain - {9934060D-27C2-4E80-A340-330D76464C09} - C:\WINDOWS\System32\jgaf.dll


Please help - I'm fully willing to donate to the site!
I am not surprised that you are having trouble with your start page as you have one of the more severe spyware infections that we are dealing with these days. It will take several steps to remove so please do the following in order:


Step#1

First of all you have a file on your system that was dropped by the hijacker that our developers have been looking for. They need a copy of the file to identify it so that we can help you clear up your infection and also for others who have been attacked by the same hijacker, more effectively. (This is the way all spyware is identified and then placed into the current definitions for the appropriate application: anti-virus, anti-trojan, anti-spyware, so that they can be removed easily in the future)

Please Search for and Find
O2 - BHO: (no name) - {E05306B8-CC65-435C-BC9C-0FA89DA3DFEF} C:\WINDOWS\System32\jgaf.dll

Then make a Zip file with it and send it by email as an attachment to :
"submit_stuff AT xs4 all.nl" (replace AT with @ and remove all of the spaces in the email address please.) Please also include a link to this post in your email.


Step#2

Please download and open the following zip file. Double-click on the file inside the zip and when it asks you if you would like to merge the file into your registry, please answer yes. This will make sure all files are visible on your computer.

http://www.davehigham.zen.co.uk/downloads/xphidden.zip



Step#3

Now to find the hidden file so that we can prevent it from reinstalling every time you restart your computer please:

1. Please download DllCompare
( The Screenshot will show you how the program will look when it starts.)

2. Start the Program with its default settings and put a check mark in the include subdirectories. Click the Run Locate.com and wait until the scan says complete.

3. Click the Compare button to start the next process.

4. Files in the upper portion have been verified to "exist", Files in the bottom section were not able to be accessed. Very few files should be listed in the bottom section when the Compare scan is complete.

5. Click on each of the listed entries in the lower section to select them. Right-click on the file and use the Option Rescan screenshot.

6. This will cause Windows Find to see if the file does exist, and then it will be removed from the list (to reduce the number of identified files) screenshot

7. Click the Make a Log of what was found button, and post the log here in this thread using Add Reply to receive further instructions.


Good Luck!
I followed your instructions exactly. I sent you the zip file with jgaf.dll and then ran the File Sort utility program. At first 6 files were listed in the bottom but after rescanning them, only one was left: kbdm.dll in my WINDOWS–>SYSTEM32 folder. Here's the log: * DLLCompare Log version(1.0.0.125) Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ C:\WINDOWS\SYSTEM32\kbdm.dll Thu Jun 24 2004 2:29:38a A…R 57,344 56.00 K ________________________________________________ 1,527 items found: 1,527 files (5 H/S), 0 directories. Total of file sizes: 327,975,964 bytes 312.78 M Administrator Account = True ——————–End log——————— Where to from here? Thanks for all the help - can't tell you how much I appreciate it!
Hi jspiler

Step #1

1. Click here to download and install Registrar Lite.

2. Install, run, copy and paste this line to reglite's address bar:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

3. click the "go" tab. Find: "Appinit_Dlls" and look for the value on the right side panel.

4. DoubleClick on AppInit_DLLs to open the data editor window. Then confirm that the filename listed in the Value box is C:\WINDOWS\SYSTEM32\kbdm.dll

5. If it is C:\WINDOWS\SYSTEM32\kbdm.dll then using Windows Explorer, go to your root drive: C:\ and create a new folder called 'Hijack' and within that folder , create two new folders, one called 'Backups' and one called 'Junk'.

6. Using the Registrar Lite program. Copy and paste the key below into reglite's address bar and hit 'Go':

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\

7. To backup the registry key for later use please click on the Windows key folder in the left hand pane (will be blue/purple) to highlight it, and use the top menu File>Export and save (in the C:\Hijack\Backups folder) as :

1.) Winkey.reg (Save as type: regedit4 .reg type)
2.) Winkey.hiv (Save as type: Scroll to select-regetd32/WinAPI *hiv *dat files)

Navigate to C:\Hijack\Backups and confirm both files have been successfully saved.

8. Using Registrar Lite again. Copy and paste the key below into reglite's address bar and hit 'Go':

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

9. Right-click on the Windows key folder in the left pane and rename it to 'NotWindows':

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NotWindows

10. DoubleClick "Appinit_Dlls" on right pane and in the data editor go to "value" box and erase the data The data to remove will be:

"C:\WINDOWS\System32\kbdm.dll", click 'Apply' and 'Ok' to finish.

11. Rename 'NotWindows' back to 'Windows' in the left pane, close Registrar Lite and reboot the computer.

If all goes well the hidden process will not run at startup and you should now be able to find and *see* the kbdm.dll in C:\WINDOWS\System32\kbdm.dll.

12. Unzip and run Winfile from here. Open it up, click File>Move…

13. Copy and paste this into the 'From' box: C:\WINDOWS\System32\kbdm.dll
Copy and paste this into the 'To' box: C:\Hijack\Junk\kbdm.dll

14. Click OK. Now Close Winfile and check in C:\Hijack\Junk for that file - please post back what is in this folder.

Good Luck!
I did everything you said up downloading Winfile - the file wasn't working. I tried to open it in Power Archiver and Winzip and it was saying it wasn't a valid zip file. Is there a mirror I can download it at?
It must be the infection that is preventing you from downloading winfile as I was able to download and use it on my PC from this link. DId you try just double clicking on the file? There is a manual way of completing the task:

1. Go to My Computer and open your root directory C:\

2. Right click in the window and choose New > Folder and name it Hijack

3. now open the new folder and right-click in the window and again choose New > Folder and name it Junk.

4. You now should have a new directory: C:\ Hijack\Junk\.

5. Go to C:\Windows\System32\ and find the file called kbdm.dll.

6. Right-click on the file and choose cut, then close the window

7. Navigate to C:\Hijack\Junk\ and right-click and choose paste. Close the window

8. Go back to C:\WINDOWS\System32\ and check for kbdm.dll, you should not find it there

9. Navigate to C:\Hijack\Junk\ and look to make sure that kbdm.dll is now there in this folder.

10. Post the contents of the C:\Hijack\Junk\ here.


hope this helps
9.
Ok, so now the "kbdm.dll" file is in the C:\Hijack\Junk folder. I'm not sure if this was all you needed to know……Where to from here? By the way, and I'm going to assume this is for the same reason, but I saw another person in the forum post a problem where an icon on the bottom right of the toolbar says the PC is low on virtual memory every once in a while - it happens to me too. Just thought I'd mention it in case it might change anything. Thanks for the continuing help!!
We don't have too much left to do. I am about to give instructions for something you may find confusing so please bear with me.

When we renamed the Windows key in the registry we reduced the security permissions to access it. Therefore we have to repeat some of the steps we did before to return the previous security level to protect windows.

Step#1

Navigate to C:\Hijack\Backups and double-click on the "Winkey.reg" file. Answer yes to the prompt asking to merge the information into the registry.


Step#2

Run Registrar Lite again, copy and paste the key below into reglite's address bar and hit 'Go':

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\


Step #3

Click on the Windows key to highlight it, and use the top menu File>Import browse to and select the "Winkey.hiv" you saved earlier in C:\Hijack\Backups. Click 'open', 'merge' and 'ok' to finish. This will return the registry permissions to normal.

Step#4

Click here to download CWShredder by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'. Reboot when done.

Step#5

Scan again with HJT and Post a new log file
Logfile of HijackThis v1.98.2
Scan saved at 2:09:48 PM, on 8/30/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\knlwrap.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\iKernel.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\explorer.exe
C:\CWShredder.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.searchv.com/1/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.searchv.com/1/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&ssPageName=h%3Ah%3Amyebay%3AUS"); (C:\Documents and Settings\Lil Buddy\Application Data\Mozilla\Profiles\default\vsl9036o.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Lil Buddy\Application Data\Mozilla\Profiles\default\vsl9036o.slt\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [RealUpdater] C:\WINDOWS\System32\realupd.exe
O4 - HKCU\..\Run: [uninstal] regsvr32 /u /s image.dll
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (HKCU)
O15 - Trusted Zone: *.greg-search.com
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebpr…etup1.0.0.5.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {69432678-2906-2705-1128-068943397621} -
O16 - DPF: {7CA3D0A3-7E2E-4AAB-A75E-FAB8ECA8BD95} (Skilljam Game Player Object) - http://ign.skilljam.com/ssp/SSP.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://128.164.199.30/activex/AxisCamControl.ocx
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v5.cab
O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Installer/104/rsinstaller.cab
Ok! I'm using IE now and everything seems to be running ok…..no more hijacked homepage or popups. I'm not sure if there's anything else I should do but I can't tell you how much I appreciate the help!! Please let me know where to send donations to via paypal. THANKS!!!!!!!!!!!!!!
A couple more things to do:

Step #1

First of all you have a trojan on your PC. Please go to both of the Online AV scanners linked at the bottom of this post and allow them to scan and fix everything they find. Then report back what they found.
Panda Antivirus
Housecall Trend Micro Online AV


Step#2

You have a program which is not recommended because it is associated with adware. I recommend that you go to Start > Control Panel > Add Remove Programs and uninstall Weatherbug. A replacement can be found in this list of Safe Programs.


Step#3

I would like you to delete the file :C:\Hijack\Junk\kbdm.dll. You may have to *take ownership* of the file.

1. Boot into Safe Mode by tapping F8 after the BIOS has loaded.

2. Right-click on the C:\Hijack\Junk\kbdm.dll go to the Security tab>advanced and take ownership giving yourself 'Full control' (preferably to Administrators 'group').

3.Check the box that says reset permissions on all child objects. Click apply.

4. You should now be able to delete the file and folder.


Step#4

For the cleanup please:

1. Scan with HijackThis (ALL WINDOWS CLOSED EXCEPT HJT)

2. Put a check mark beside each of the following entries in HJT:

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.searchv.com/1/

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.searchv.com/1/

O4 - HKCU\..\Run: [RealUpdater] C:\WINDOWS\System32\realupd.exe

O4 - HKCU\..\Run: [uninstal] regsvr32 /u /s image.dll

O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (HKCU)

O15 - Trusted Zone: *.greg-search.com
Any site in the trusted zone has complete access to your computer and all of it's files. To double check the removal of this one please go to Start > Control Panel > Internet Options and click on the the security tab. Then choose Trusted Zone, then sites. Remove all sites that are entered here except your bank, or other place you would want to have complete access to your computer.

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebpr…etup1.0.0.5.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {69432678-2906-2705-1128-068943397621} -
O16 - DPF: {7CA3D0A3-7E2E-4AAB-A75E-FAB8ECA8BD95} (Skilljam Game Player Object) - http://ign.skilljam.com/ssp/SSP.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://128.164.199.30/activex/AxisCamControl.ocx
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v5.cab
O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Installer/104/rsinstaller.cab
<— all of these can be removed as they will be reinstalled the next time you visit the website IF they are LEGITIMATE.

3. Click 'fix checked'

4. REBOOT into Safe Mode by tapping F8 while booting up


5. In Safe Mode please DELETE the following file:

C:\WINDOWS\System32\realupd.exe <–this is the trojan


6. REBOOT into normal mode

7. please SCAN again with HJT and

8. POST a new log file here in this thread using 'Add Reply' to see what
is left to clean.

Good Luck!
The Panda and Housecall sites were both not working when I tried them, although I see they are working now, so I skipped that step and went on to deleting weatherbug. I did went through the process with the kbdm.dll file, scanned with HJT and fixed those problems, and then booted in safe mood and deleted the realupd.exe file. However, when I booted back up again NONE OF MY EXECUTABLE PROGRAMS ARE ABLE TO RUN!! This includes IE, HJT, everything. I'm in a computer lab right now because I cant use the internet from that computer. What went wrong and what should I do??
Hi jSpiler

Unfortunately it is the infection kicking and screaming as we try to get rid of it. Do you know exactly what the error message was? IF so could you post it with the log file please.

1. Please download the following file:
XP exe Fix

2. Extract it to a folder of its own

3. Double Click on the exe file that is in the folder and let it run

4. It should fix the file associations that the infection has destroyed.

5. Scan again with HJT and POST a log file to see what is left of the infection.

Good Luck!
Ok, downloaded the file, and it worked…that was a relief. Here's the new HJT log:

Logfile of HijackThis v1.98.2
Scan saved at 9:54:33 PM, on 9/6/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&ssPageName=h%3Ah%3Amyebay%3AUS"); (C:\Documents and Settings\Lil Buddy\Application Data\Mozilla\Profiles\default\vsl9036o.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Lil Buddy\Application Data\Mozilla\Profiles\default\vsl9036o.slt\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI