This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please Help With Coolwebsearch

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please help me to get rid of the CoolWebSearch.
It changes my startup page and search page and drives me cracy.
I really would apresiate your help.
This is my log file
Logfile of HijackThis v1.98.2
Scan saved at 15:32:34, on 2004-09-19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program\AMD\PowerNow!\GemServ.exe
C:\Program\Ahead\InCD\InCDsrv.exe
C:\Program\AMD\PowerNow!\gemback.exe
C:\Norman\NVC\BIN\Zanda.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\Smartscaps.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\WZCBDL Service\WZCBDLS.exe
C:\NORMAN\Nvc\BIN\nvcoas.exe
C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
C:\NORMAN\Nvc\BIN\NJEEVES.EXE
C:\NORMAN\Nvc\BIN\nipsvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\NORMAN\Nvc\BIN\ZLH.EXE
C:\Program\iTunes\iTunesHelper.exe
C:\Program\Ahead\InCD\InCD.exe
C:\Program\D-Link\Air USB Utility\AirCFG.exe
C:\Program\Java\j2re1.4.2_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Webroot\Spy Sweeper\SpySweeper.exe
C:\NORMAN\Nvc\BIN\NYMSE.EXE
C:\NORMAN\Nvc\BIN\NIP.EXE
C:\Program\iPod\bin\iPodService.exe
C:\NORMAN\Nvc\BIN\cclaw.exe
C:\Program\Labtec\Wireless Mouse\MulMouse.exe
C:\Program\SmartTrust\SmartTrust Personal\Csp\SmartCertmover.exe
C:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\Program\FlashGet\jccatch.dll
O2 - BHO: (no name) - {ACE58BB6-6D10-4214-812E-CC59ECA92434} - C:\WINDOWS\system32\hog.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [iTunesHelper] C:\Program\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [InCD] C:\Program\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [D-Link Air USB Utility] C:\Program\D-Link\Air USB Utility\AirCFG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: Labtec Mouse Software 2.0.lnk = C:\Program\Labtec\Wireless Mouse\MulMouse.exe
O4 - Global Startup: Certificate Mover.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1094663432628
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} (WebCam Control) - http://webcamnow.com/broadcast/ActiveXWebCam.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O18 - Filter: text/html - {9F4C29E0-641A-484B-96D2-431E38C6019A} - C:\WINDOWS\system32\hog.dll
O18 - Filter: text/plain - {9F4C29E0-641A-484B-96D2-431E38C6019A} - C:\WINDOWS\system32\hog.dll

RGDS Trenter
Let's see if you have a hidden hijacker. Do this for me.

Click here to download DllCompare. Start the Program with and click the Run Locate.com - be sure the \Windows\System32 directory is in the box and wait until the the blue text says it has 'completed the scan'.

Click the Compare button to start the next process. The results appear in two panes - files in the upper pane have been verified to 'exist', files in the lower pane were 'not able to be accessed'. Very few files should be listed in the lower pane when the Compare scan is complete. Click on each of the listed entries in the lower pane to select them. Right-click on the file and use the option Rescan. This will cause Windows Find to see if the file does exist, and then if so it will be removed from the list to reduce the number of identified files.

Click the Make a Log of what was found button and post the log here in this thread and wait for further instructions.
Hi There and thanks for helping me out. I really aprisiate it. This is what the log file showed. * DLLCompare Log version(1.0.0.125) Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ C:\WINDOWS\SYSTEM32\resgc.dll Sat 2004-05-01 23.47.26 A…R 57 344 56,00 K ________________________________________________ 1 268 items found: 1 268 files, 0 directories. Total of file sizes: 251 722 748 bytes 240,06 M Administrator Account = True ——————–End log——————— RGDS Trenter
OK looks like it's there.

Click here to download FindnFix.exe (2K/XP only!) by freeatlast. Double-click on the FINDnFIX.exe and it will install a folder called FINDnFIX on your system. Go to that folder and double-click on !LOG!.bat. The program takes a few minutes to collect the necessary information. When done post the contents of Log.txt in this thread.
OK here comes the log file. Sun 19 Sep 04 23:28:13 »»»»»»»»»»»»»»»»»»***LOG!***(*updated *9/1*)»»»»»»»»»»»»»»»» *System: Microsoft Windows XP Home Edition 5.1 Service Pack 2 (Build 2600) *IE version: 6.0.2900.2180 SP2 MS-DOS version 5.00.500 *command.com test passed! __________________________________ !!*Creating backups…!! The operation completed successfully 23:28:11,91 2004-09-19 __________________________________ *Local time: den 19 september 2004 (2004-09-19) 23:28, Västeuropa, normaltid *Uptime: 23:28:15 up 0 days, 0:47:22 *Path: C:\FINDnFIX —————————————————- »»Member of…: ("ADMIN" logon + group match required!) User is a member of group LENNART\Ingen. User is a member of group \Alla. User is a member of group BUILTIN\Administratörer. User is a member of group BUILTIN\Användare. User is a member of group NT INSTANS\INTERAKTIV. User is a member of group NT INSTANS\Autentiserade användare. User is a member of group \LOKAL. !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! User: [LENNART\Lennarts_Bärbara], is a member of: BUILTIN\Administratörer \Everyone Running in WORKSTATION MODE. SystemDrive is C: SystemRoot is C:\WINDOWS Logon Domain is LENNART Administrator's Name is Lennarts_B„rbara Computer Name is LENNART LOGON SERVER is \\LENNART »»»»»»»»»»»»»»»»»»*** Note! ***»»»»»»»»»»»»»»»» The list will produce a small database of files that will match certain criteria. Ex: read only files, s/h files, last modified date. size, etc. The filters provided and registry scan should match the corresponding file(s) listed. »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Unless the file match the entire criteria, it should not be pointed to remove without attempting to confirm it's nature! »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» At times there could be several (legit) files flagged, and/or duplicate culprit file(s)! If in doubt, always search the file(s) and properties according to criteria! The file(s) found should be moved to \FINDnFIX\"junkxxx" Subfolder ______________________________________________________________________________ ***YOU NEED TO DISABLE YOUR ACTIVE ANTI VIRUS PROTECTION TO AVOID CONFLICTS!*** ______________________________________________________________________________ ……Scanning for file(s)… *Note! The list(s) may include legitimate files! »»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»» »»»»» (*1*) »»»»» ……… »»Read access error(s)… C:\WINDOWS\SYSTEM32\RESGC.DLL +++ File read error \\?\C:\WINDOWS\System32\RESGC.DLL +++ File read error »»»»» (*2*) »»»»»…….. RESGC.DLL Can't Open! »»»»» (*3*) »»»»»…….. C:\WINDOWS\SYSTEM32\ resgc.dll Sat 2004-05-01 23.47.26 A…R 57 344 56,00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57 344 bytes 56,00 K unknown/hidden files… No matches found. »»»»» (*4*) »»»»»……… Sniffing………. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\RESGC.DLL SNiF 1.34 statistics Matching files : 1 Amount in bytes : 57344 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL »»»»»(*5*)»»»»» ¯ Access denied ® ………………… RESGC.DLL …..57344 01.05.2004 »»»»»(*6*)»»»»» fgrep: can't open input C:\WINDOWS\SYSTEM32\RESGC.DLL »»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»» »»»»»Search by size… *List of files and specs according to 'size' : *Note: Not all files listed here are infected, but *may include* the name and spces of the offending file… ___________________________________________________________________________ Path: C:\WINDOWS\SYSTEM32 Including: *.DLL 220. Dpwsockx Dll 57,344 . . . . A 8-04-04 10:33 am 634. Msasn1 Dll 57,344 . . . . A 8-04-04 10:33 am 941. Resgc Dll 57,344 . . R . A 5-01-04 11:47 pm 192. Dmloader Dll 35,840 . . . . A 8-04-04 10:33 am 358. Imgutil Dll 35,840 . . . . A 8-04-04 10:33 am 216. Dpvacm Dll 21,504 . . . . A 8-04-04 10:33 am 266. Feclient Dll 21,504 . . . . A 8-04-04 10:33 am ____________________________________________________________________________ *By size and date… C:\WINDOWS\SYSTEM32\ dpwsockx.dll Wed 2004-08-04 10.33.34 A…. 57 344 56,00 K msasn1.dll Wed 2004-08-04 10.33.44 A…. 57 344 56,00 K resgc.dll Sat 2004-05-01 23.47.26 A…R 57 344 56,00 K 3 items found: 3 files, 0 directories. Total of file sizes: 172 032 bytes 168,00 K C:\WINDOWS\SYSTEM32\ dmloader.dll Wed 2004-08-04 10.33.34 A…. 35 840 35,00 K imgutil.dll Wed 2004-08-04 10.33.38 A…. 35 840 35,00 K 2 items found: 2 files, 0 directories. Total of file sizes: 71 680 bytes 70,00 K C:\WINDOWS\SYSTEM32\ dpvacm.dll Wed 2004-08-04 10.33.34 A…. 21 504 21,00 K feclient.dll Wed 2004-08-04 10.33.36 A…. 21 504 21,00 K 2 items found: 2 files, 0 directories. Total of file sizes: 43 008 bytes 42,00 K Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\DPWSOCKX.DLL Sniffed -> C:\WINDOWS\SYSTEM32\MSASN1.DLL Sniffed -> C:\WINDOWS\SYSTEM32\RESGC.DLL SNiF 1.34 statistics Matching files : 3 Amount in bytes : 172032 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\DMLOADER.DLL Sniffed -> C:\WINDOWS\SYSTEM32\IMGUTIL.DLL SNiF 1.34 statistics Matching files : 2 Amount in bytes : 71680 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\DPVACM.DLL Sniffed -> C:\WINDOWS\SYSTEM32\FECLIENT.DLL SNiF 1.34 statistics Matching files : 2 Amount in bytes : 43008 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL »»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»» BHO search and other files… **File C:\WINDOWS\SYSTEM32\AMBHD.DLL 000020E4: 25 25 25 30 32 78 00 00 . 00 00 00 00 C0 82 05 B3 %%%02x.. ….À‚.³ fgrep: can't open input C:\WINDOWS\SYSTEM32\RESGC.DLL No matches found. "C:\WINDOWS\system32\" ambhd.dll 2004-09-19 31744 "ambhd.dll" rtipxmib.dll 2004-08-04 31744 "rtipxmib.dll" 2 items found: 2 files, 0 directories. Total of file sizes: 63 488 bytes 62,00 K *sp.html found in temp folder: –a– - - - - - 7,976 09-19-2004 sp.html File: CRC-32 : 93866C48 MD5 : CE5B5B5B DFD4A959 9F4A95C7 6FA46BD2 *Filter keys search… HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html CLSID = {3B25C72C-BEFE-4272-984C-9FFB2B6005A5} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/plain CLSID = {3B25C72C-BEFE-4272-984C-9FFB2B6005A5} »»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»» »»Size of Windows key: (*Default-450 *No AppInit-398 *fake(infected)-448,504,512…) Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 448 »»Checking for AppInit_DLLs (empty) value… ________________________________ !"AppInit_DLLs"=""! Value does not match ________________________________ »»Comparing *saved* key with *original*… REGDIFF 2.1 - Freeware written by Gerson Kurz (http://www.p-nand-q.com) Comparing File #1 (Keys1\winkey.reg) with File #2 (HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows). Value "AppInit_DLLs" in key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" has different lengths (1 vs 30) »»Dumping Values…….. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows AppInit_DLLs = (*** MISSING TRAILING NULL CHARACTER ***) DeviceNotSelectedTimeout = 15 GDIProcessHandleQuota = REG_DWORD 0x00002710 Spooler = yes swapdisk = TransmissionRetryTimeout = 90 USERProcessHandleQuota = REG_DWORD 0x00002710 »»Security settings for 'Windows' key: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: (ID-NI) ALLOW Read BUILTIN\Anv„ndare (ID-IO) ALLOW Read BUILTIN\Anv„ndare (ID-NI) ALLOW Full access BUILTIN\Administrat”rer (ID-IO) ALLOW Full access BUILTIN\Administrat”rer (ID-NI) ALLOW Full access NT INSTANS\SYSTEM (ID-IO) ALLOW Full access NT INSTANS\SYSTEM (ID-IO) ALLOW Full access SKAPARE ŽGARE Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: Read BUILTIN\Anv„ndare Full access BUILTIN\Administrat”rer Full access NT INSTANS\SYSTEM »»Performing string scan…. 00001150: vk < f AppInit_DLLs G 00001190: C : \ W I N D O W S \ S y s t e m 3 2 \ r e s g c . d l l 000011D0: h vk UDeviceNotSelectedTimeout 1 5 00001210: I 6* 9 0 | . vk ' zGDIProcessHandle 00001250:Quota" vk x Spooler2 y e s h h 00001290: ( X vk swapdisk vk 000012D0: TransmissionRetryTimeout h ( X 00001310: vk ' E USERProcessHandleQuota H 00001350: 00001390: 000013D0: 00001410: 00001450: 00001490: 000014D0: 00001510: 00001550: 00001590: 000015D0: ———- WIN.TXT fùAppInit_DLLs֍æGÀÿÿÿC ————– ————– $01180: AppInit_DLLs $011EF: UDeviceNotSelectedTimeout $0123F: zGDIProcessHandleQuota $012D8: TransmissionRetryTimeout $01328: USERProcessHandleQuota ————– ————– C:\WINDOWS\System32\resgc.dll ————– ————– REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" "DeviceNotSelectedTimeout"="15" "GDIProcessHandleQuota"=dword:00002710 "Spooler"="yes" "swapdisk"="" "TransmissionRetryTimeout"="90" "USERProcessHandleQuota"=dword:00002710 …………. A handle was successfully obtained for the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows key. This key has 0 subkeys. The AppInitDLLs value exists and reports as 60 bytes, including the 2 for string termination. [AppInitDLLs] Ansi string : "C:\WINDOWS\System32\resgc.dll" 0000 43 00 3a 00 5c 00 57 00 49 00 4e 00 44 00 4f 00 | C.:.\.W.I.N.D.O. 0010 57 00 53 00 5c 00 53 00 79 00 73 00 74 00 65 00 | W.S.\.S.y.s.t.e. 0020 6d 00 33 00 32 00 5c 00 72 00 65 00 73 00 67 00 | m.3.2.\.r.e.s.g. 0030 63 00 2e 00 64 00 6c 00 6c 00 00 00 | c…d.l.l… ———————– »»»»»»Backups list…»»»»»» 23:32:31 up 0 days, 0:51:39 ———————– Sun 19 Sep 04 23:32:31 C:\FINDNFIX\ keyback.hiv Sun 2004-09-19 23.28.12 A…. 8 192 8,00 K 1 item found: 1 file, 0 directories. Total of file sizes: 8 192 bytes 8,00 K C:\FINDNFIX\KEYS1\ winkey.reg Sun 2004-09-19 23.28.14 A…. 287 0,28 K 1 item found: 1 file, 0 directories. Total of file sizes: 287 bytes 0,28 K *Temp backups… "C:\Documents and Settings\Lennarts_B„rbara\Lokala inst„llningar\Temp\Backs2\" keyback2.hi_ 2004-09-19 8192 "keyback2.hi_" winkey2.re_ 2004-09-19 287 "winkey2.re_" 2 items found: 2 files, 0 directories. Total of file sizes: 8 479 bytes 8,28 K -D—- JUNKXXX 00000000 23:28.12 19/09/2004 A—– STARTIT .BAT 00000060 23:28.14 19/09/2004 ________________________________________________________________________________ ***THE FIX IS NOT COMPATIBLE WITH EARLIER;UNPATCHED VERSIONS OF WIN2K'(SP3 and BELLOW)' AND/OR LAX OF SECURITY UPDATES AND SERVICE PACKS FOR ALL PLATFORMS! MINIMAL REQUIREMENTS INCLUDE: _________XP HOME/PRO; SP1; IE6/SP1 _________2K/SP4; IE6/SP1 ________________________________________________________________________________ »»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»» —–END—— Sun 19 Sep 04 23:32:33  RGDS Trenter
Completely disable any antivirus software you have running from this point on until we have finished.

In the keys1 folder, double click on FIX.bat. You will get an alert of about 15 seconds before reboot - allow it to reboot. On restart, open Explorer and navigate to C:\Windows\System32 folder, find the RESGC.DLL file (it should be visible now). Highlight the file and using top menu, click Edit>Move to folder…

Select C:\Findnfix\junkxxx as destination. Move the file.

Open the FINDnFIX folder again and double-click on RESTORE.bat. When it is finished, in FINDnFIX folder, there will be a file called Log2.txt - post it's contents in your next reply.
Hi , sorry about the virus program.
Hera are the log2.txt file.

Mon 20 Sep 04 22:32:29

»»»»»»»»»»»»»»»»»»***LOG2!(*updated *9/1*)***»»»»»»»»»»»»»»»»

*System:
Microsoft Windows XP Home Edition 5.1 Service Pack 2 (Build 2600)
*IE version:
6.0.2900.2180 SP2


___________________________________________
!!Restoring backups!!

The operation completed successfully

The operation completed successfully
22:32:27,66 2004-09-20
___________________________________________

*Local time:
den 20 september 2004 (2004-09-20)
22:32, Västeuropa, normaltid
*Uptime:
22:32:31 up 0 days, 0:04:13

*path:
C:\FINDnFIX
Running in WORKSTATION MODE.

SystemDrive is C:
SystemRoot is C:\WINDOWS
Logon Domain is LENNART
Administrator's Name is Lennarts_B„rbara
Computer Name is LENNART
LOGON SERVER is \\LENNART
——————————————


This log will confirm if the file was successfully moved, and/or
the right file was selected…

Scanning for file(s) in System32…

»»»»»»» (1) »»»»»»»

»»»»»»» (2) »»»»»»»

»»»»»»» (3) »»»»»»»

No matches found.
Unknown/hidden files…

No matches found.

»»»»»»» (4) »»»»»»»
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

SNiF 1.34 statistics

Matching files : 0 Amount in bytes : 0
Directories searched : 1 Commands executed : 0

Masks sniffed for: *.DLL

»»»»»(5)»»»»»

»»»»»(6)»»»»»

»»»»»»» Search by size And Date…

*List of files specs according to size:
*Note: Not all files listed here are infected!
____________________________________________________________________________
Path: C:\WINDOWS\SYSTEM32 Including: *.DLL

219. Dpwsockx Dll 57,344 . . . . A 8-04-04 10:33 am
633. Msasn1 Dll 57,344 . . . . A 8-04-04 10:33 am
191. Dmloader Dll 35,840 . . . . A 8-04-04 10:33 am
357. Imgutil Dll 35,840 . . . . A 8-04-04 10:33 am
215. Dpvacm Dll 21,504 . . . . A 8-04-04 10:33 am
265. Feclient Dll 21,504 . . . . A 8-04-04 10:33 am

____________________________________________________________________________

C:\WINDOWS\SYSTEM32\
dpwsockx.dll Wed 2004-08-04 10.33.34 A…. 57 344 56,00 K
msasn1.dll Wed 2004-08-04 10.33.44 A…. 57 344 56,00 K

2 items found: 2 files, 0 directories.
Total of file sizes: 114 688 bytes 112,00 K

C:\WINDOWS\SYSTEM32\
dmloader.dll Wed 2004-08-04 10.33.34 A…. 35 840 35,00 K
imgutil.dll Wed 2004-08-04 10.33.38 A…. 35 840 35,00 K

2 items found: 2 files, 0 directories.
Total of file sizes: 71 680 bytes 70,00 K

C:\WINDOWS\SYSTEM32\
dpvacm.dll Wed 2004-08-04 10.33.34 A…. 21 504 21,00 K
feclient.dll Wed 2004-08-04 10.33.36 A…. 21 504 21,00 K

2 items found: 2 files, 0 directories.
Total of file sizes: 43 008 bytes 42,00 K

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Sniffed -> C:\WINDOWS\SYSTEM32\DPWSOCKX.DLL
Sniffed -> C:\WINDOWS\SYSTEM32\MSASN1.DLL
SNiF 1.34 statistics

Matching files : 2 Amount in bytes : 114688
Directories searched : 1 Commands executed : 0

Masks sniffed for: *.DLL
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Sniffed -> C:\WINDOWS\SYSTEM32\DMLOADER.DLL
Sniffed -> C:\WINDOWS\SYSTEM32\IMGUTIL.DLL
SNiF 1.34 statistics

Matching files : 2 Amount in bytes : 71680
Directories searched : 1 Commands executed : 0

Masks sniffed for: *.DLL
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Sniffed -> C:\WINDOWS\SYSTEM32\DPVACM.DLL
Sniffed -> C:\WINDOWS\SYSTEM32\FECLIENT.DLL
SNiF 1.34 statistics

Matching files : 2 Amount in bytes : 43008
Directories searched : 1 Commands executed : 0

Masks sniffed for: *.DLL

»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»

BHO search and other files…



No matches found.

"C:\WINDOWS\system32\"
rtipxmib.dll 2004-08-04 31744 "rtipxmib.dll"

1 item found: 1 file, 0 directories.
Total of file sizes: 31 744 bytes 31,00 K


No matches found.

–*sp.html in temp folder was NOT FOUND!–

*Filter keys search…
REGDMP: Unable to open key 'HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html' (2)

–(*text/html Subkey was NOT FOUND!)–

REGDMP: Unable to open key 'HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/plain' (2)

–(*text/plain Subkey was NOT FOUND!)–

»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»

»»»*»»» Scanning for moved file… »»»*»»»

* result\\?\C:\FINDnFIX\junkxxx\RESGC.333


C:\FINDNFIX\JUNKXXX\
resgc.333 Sat 2004-05-01 23.47.26 A…. 57 344 56,00 K

1 item found: 1 file, 0 directories.
Total of file sizes: 57 344 bytes 56,00 K

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Sniffed -> C:\FINDNFIX\JUNKXXX\RESGC.333
SNiF 1.34 statistics

Matching files : 1 Amount in bytes : 57344
Directories searched : 1 Commands executed : 0

Masks sniffed for: *.*

**File C:\FINDNFIX\JUNKXXX\RESGC.333
0000DEBE: 67 44 65 76 69 63 65 00 . 00 53 74 72 65 61 6D 69 gDevice. .Streami
0000DED3: 63 65 53 65 74 75 70 00 . 32 00 00 00 00 00 E0 01 ceSetup. 2…..à.

A—– RESGC .333 0000E000 23:47.26 01/05/2004

Analyzer v1.36 by Boogie Copyright © 1997 ESP Team
Files: C:\FINDNFIX\JUNKXXX\*.*
Ä
RESGC.333 MS Windows 95 / Windows NT Exe
Ä


Volume: LENNART * DDIR * 10:35 pm | Mon, 9-20-04
Ser #: 0832-9C16 DOS Ver. 5.00 0% Used space
Path: C:\FINDNFIX\JUNKXXX All files selected

1. Resgc 333 57,344 . . . . A 5-01-04 11:47 pm

No. of files: 1 | List size: 57,344
Disk size: 976.5 M | Actual spc: 65,024
Bytes free: 976.5 M | Wasted space: 7,680

–a– W32i - - - - 57,344 05-01-2004 resgc.333
A C:\FINDnFIX\junkxxx\resgc.333

CHK-SAFE.EXE Ver 2.51 by Bill Lambdin Don Peters and Robert Bullock.
MD5 Message Digest Algorithm by RSA Data Security, Inc.

File name Size Date Time MD5 Hash
________________________________________________________________________
RESGC.333 57344 05-01-104 23:47 c185b36f9969d3a6d2122ba7cbc02249

CRC-Cyclic Redundancy Checker, Version 1.20, 08-Feb-92, rtk

C:\FINDNFIX\JUNKXXX
RESGC.333 : crc16=3138 crc32=D5C9FB2E

File:

CRC-32 : D5C9FB2E

MD5 : C185B36F 9969D3A6 D2122BA7 CBC02249




#######################################################
*Known files are…
——————–
File: ((56k; (57,344 bytes)
CRC-32 : D5C9FB2E
MD5 : C185B36F 9969D3A6 D2122BA7 CBC02249
——————–
File: ((35k; (35,840 bytes)
CRC-32 : 33081C8B
MD5 : 1DE9A8E2 4C826006 7A479B09 577D9CAE
——————–
File: ((21k; (21,504 bytes)
CRC-32 : 2258F59E
MD5 : EFEE2CB3 B342A351 51802356 9637F8E6
#######################################################
»»Permissions:
C:\FINDnFIX\junkxxx\resgc.333 NT INSTANS\SYSTEM:F
LENNART\Lennarts_Bärbara:F
BUILTIN\Administratörer:F
BUILTIN\Användare:R

Directory "C:\FINDnFIX\junkxxx\."
Permissions:
Type Flags Inh. Mask Gen. Std. File Group or User
======= ======== ==== ======== ==== ==== ==== ================
Allow 00000003 tco- 001F01FF —- DSPO rw+x NT INSTANS\SYSTEM
Allow 0000000B -co- 10000000 —A —- —- \SKAPARE ÄGARE
Allow 00000003 tco- 001F01FF —- DSPO rw+x BUILTIN\Administratörer
Allow 00000002 tc– 00000004 —- —- –+- BUILTIN\Användare
Allow 00000002 tc– 00000002 —- —- -w– BUILTIN\Användare
Allow 00000003 tco- 001200A9 —- -S– r–x BUILTIN\Användare
Allow 00000000 t— 001F01FF —- DSPO rw+x LENNART\Lennarts_Bärbara
Allow 00000013 tco- 001F01FF —- DSPO rw+x BUILTIN\Administratörer
Allow 00000013 tco- 001F01FF —- DSPO rw+x NT INSTANS\SYSTEM
Allow 00000010 t— 001F01FF —- DSPO rw+x LENNART\Lennarts_Bärbara
Allow 0000001B -co- 10000000 —A —- —- \SKAPARE ÄGARE
Allow 00000013 tco- 001200A9 —- -S– r–x BUILTIN\Användare
Allow 00000012 tc– 00000004 —- —- –+- BUILTIN\Användare
Allow 00000012 tc– 00000002 —- —- -w– BUILTIN\Användare

Owner: LENNART\Lennarts_Bärbara

Primary Group: LENNART\Ingen

Directory "C:\FINDnFIX\junkxxx\.."
Permissions:
Type Flags Inh. Mask Gen. Std. File Group or User
======= ======== ==== ======== ==== ==== ==== ================
Allow 00000003 tco- 001F01FF —- DSPO rw+x BUILTIN\Administratörer
Allow 00000003 tco- 001F01FF —- DSPO rw+x NT INSTANS\SYSTEM
Allow 00000000 t— 001F01FF —- DSPO rw+x LENNART\Lennarts_Bärbara
Allow 0000000B -co- 10000000 —A —- —- \SKAPARE ÄGARE
Allow 00000003 tco- 001200A9 —- -S– r–x BUILTIN\Användare
Allow 00000002 tc– 00000004 —- —- –+- BUILTIN\Användare
Allow 00000002 tc– 00000002 —- —- -w– BUILTIN\Användare

Owner: LENNART\Lennarts_Bärbara

Primary Group: LENNART\Ingen

File "C:\FINDnFIX\junkxxx\resgc.333"
Permissions:
Type Flags Inh. Mask Gen. Std. File Group or User
======= ======== ==== ======== ==== ==== ==== ================
Allow 00000010 t— 001F01FF —- DSPO rw+x NT INSTANS\SYSTEM
Allow 00000010 t— 001F01FF —- DSPO rw+x LENNART\Lennarts_Bärbara
Allow 00000010 t— 001F01FF —- DSPO rw+x BUILTIN\Administratörer
Allow 00000010 t— 001200A9 —- -S– r–x BUILTIN\Användare

Owner: LENNART\Lennarts_Bärbara

Primary Group: LENNART\Ingen

C:\FINDnFIX\junkxxx\resgc.333;NT INSTANS\SYSTEM:F
C:\FINDnFIX\junkxxx\resgc.333;LENNART\Lennarts_B„rbara:F
C:\FINDnFIX\junkxxx\resgc.333;BUILTIN\Administrat”rer:F
C:\FINDnFIX\junkxxx\resgc.333;BUILTIN\Anv„ndare:RX



»»Size of Windows key:
(*Default-450 *No AppInit-398 *fake(infected)-448,504,512…)

Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 450

»»Checking for AppInit_DLLs (empty) value…
________________________________
!"AppInit_DLLs"=""!

Value Matches
________________________________

»»Comparing *saved* key with *original*…

REGDIFF 2.1 - Freeware written by Gerson Kurz (http://www.p-nand-q.com)

Comparing File #1 (Keys1\winkey.reg) with File #2 (HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows).

No differences found.

»»Dumping Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
DeviceNotSelectedTimeout = 15
GDIProcessHandleQuota = REG_DWORD 0x00002710
Spooler = yes
swapdisk =
TransmissionRetryTimeout = 90
USERProcessHandleQuota = REG_DWORD 0x00002710
AppInit_DLLs =

»»Security settings for 'Windows' key:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
(ID-NI) ALLOW Read BUILTIN\Anv„ndare
(ID-IO) ALLOW Read BUILTIN\Anv„ndare
(ID-NI) ALLOW Full access BUILTIN\Administrat”rer
(ID-IO) ALLOW Full access BUILTIN\Administrat”rer
(ID-NI) ALLOW Full access NT INSTANS\SYSTEM
(ID-IO) ALLOW Full access NT INSTANS\SYSTEM
(ID-IO) ALLOW Full access SKAPARE ŽGARE

Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
Read BUILTIN\Anv„ndare
Full access BUILTIN\Administrat”rer
Full access NT INSTANS\SYSTEM



00001150: vk UDeviceNotSelecte
00001190:dTimeout 1 5 I 6* h vk ' zGDIProce
000011D0:ssHandleQuota" 9 0 | . vk Spooler2
00001210: y e s h vk swapdisk h
00001250: X vk TransmissionRetryTimeout vk
00001290: ' E USERProcessHandleQuota H h X
000012D0: vk f AppInit_DLLs G
00001310:
00001350:
00001390:
000013D0:
00001410:
00001450:
00001490:
000014D0:
00001510:
00001550:

———- NEWWIN.TXT
fùAppInit_DLLs֍æG
————–
————–
$0117F: UDeviceNotSelectedTimeout
$011C7: zGDIProcessHandleQuota
$01270: TransmissionRetryTimeout
$012A0: USERProcessHandleQuota
$012F0: AppInit_DLLs
————–
————–
No strings found.

————–
————–
d…. 0 Sep 19 23:28 .
d…. 0 Sep 19 23:28 ..
….a 57344 May 1 23:47 resgc.333

3 files found occupying 55296 bytes

——– C:\FINDNFIX\JUNKXXX\RESGC.333
InstallStreamingDeviceStreamingDeviceSetupStreamingDeviceSetup2
===============================================================================
57,344 bytes 5,734,400 cps
Files: 1 Records: 13,139 Matches: 3 Elapsed Time: 00:00:00.01

VDIR v1.00
Path: C:\FINDNFIX\JUNKXXX\*.*
—————————————+—————————————
. <dir> 09-19-:4 23:28|RESGC 333 57344 A 05-01-:4 23:47
.. <dir> 09-19-:4 23:28|
—————————————+—————————————
3 files totaling 57344 bytes consuming 65024 bytes of disk space.
17299968 bytes available on Drive C: Volume label: LENNART

…File dump…

junkxxx\resgc.333
1 fil(er) kopierad(e).
56880 00000000 4b45524e 454c3332 2e444c4c |….KERNEL32.DLL| 0de30
56896 00004c6f 61644c69 62726172 79410000 |..LoadLibraryA..| 0de40
56912 47657450 726f6341 64647265 73730000 |GetProcAddress..| 0de50
56928 00000000 00000000 00000000 a6f00100 |…………….| 0de60
56944 01000000 03000000 03000000 88f00100 |…………….| 0de70
56960 94f00100 a0f00100 05270000 9a230000 |………'…#..| 0de80
56976 242a0000 a7f00100 bef00100 d3f00100 |$*…………..| 0de90
56992 00000100 02000049 6e737461 6c6c5374 |…….InstallSt| 0dea0
57008 7265616d 696e6744 65766963 65005374 |reamingDevice.St| 0deb0
57024 7265616d 696e6744 65766963 65536574 |reamingDeviceSet| 0dec0
57040 75700053 74726561 6d696e67 44657669 |up.StreamingDevi| 0ded0
57056 63655365 74757032 |ceSetup2 | 0dee0

Detecting…

C:\FINDnFIX\junkxxx
resgc.333 ACL has 4 ACE(s)
SID = NT INSTANS/SYSTEM S-1-5-18
ACE 0 is an ACCESS_ALLOWED_ACE_TYPE
ACE 0 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN
SID = LENNART/Lennarts_Bärbara S-1-5-21–1441484089-612769468-1211791559-1005
ACE 1 is an ACCESS_ALLOWED_ACE_TYPE
ACE 1 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN
SID = BUILTIN/Administratörer S-1-5-32-544
ACE 2 is an ACCESS_ALLOWED_ACE_TYPE
ACE 2 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN
SID = BUILTIN/Användare S-1-5-32-545
ACE 3 is an ACCESS_ALLOWED_ACE_TYPE
ACE 3 mask = 0x001200a9 -R -X
ACL done…


Finished Detecting…
=========================================
57344 C:\FINDnFIX\junkxxx\resgc.333 Lennarts_Bärbara
57344 C:\FINDnFIX\junkxxx (DIR Total)

Owner No. Files Total Size
=========================================
Lennarts_Bärbara 1 57344
________________________________________________________________________________
***THE FIX IS NOT COMPATIBLE WITH EARLIER;UNPATCHED VERSIONS OF WIN2K'(SP3 and BELLOW)'
AND/OR LAX OF SECURITY UPDATES AND SERVICE PACKS FOR ALL PLATFORMS!
MINIMAL REQUIREMENTS INCLUDE:
_________XP HOME/PRO; SP1; IE6/SP1
_________2K/SP4; IE6/SP1
________________________________________________________________________________
»»»»»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»»»»
Mon 20 Sep 04 22:35:17
—–END—–

Nearly there, open the FINDnFIX folder again and open the Files2 folder. Double-click on the ZIPZAP.bat. It will quickly clean the rest and will make a copy of the bad file(s) in the same folder (junkxxx.zip) and open your email client with instructions. Simply drag and drop the junkxxx.zip file from the folder into the mail message and submit to the specified addresses.

Please be sure to include a link to this thread in the body of your email. Reboot when done, then delete the entire FINDnFIX folder. Could you click here to download CWShredder by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'. If you already have CWShredder, click 'Check for update' and make sure you are running version 1.59.1 Reboot when done. Rescan with HJT and post a new log in your next reply.
OK everything seems OK so far.
Here are my new log file.

Logfile of HijackThis v1.98.2
Scan saved at 23:22:47, on 2004-09-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program\AMD\PowerNow!\GemServ.exe
C:\Program\Ahead\InCD\InCDsrv.exe
C:\Program\AMD\PowerNow!\gemback.exe
C:\Norman\NVC\BIN\Zanda.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\Smartscaps.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\WZCBDL Service\WZCBDLS.exe
C:\WINDOWS\System32\alg.exe
C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
C:\NORMAN\Nvc\BIN\NJEEVES.EXE
C:\NORMAN\Nvc\BIN\nipsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\NORMAN\Nvc\BIN\ZLH.EXE
C:\Program\iTunes\iTunesHelper.exe
C:\Program\Ahead\InCD\InCD.exe
C:\Program\D-Link\Air USB Utility\AirCFG.exe
C:\Program\Java\j2re1.4.2_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program\Labtec\Wireless Mouse\MulMouse.exe
C:\Program\SmartTrust\SmartTrust Personal\Csp\SmartCertmover.exe
C:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\NORMAN\Nvc\BIN\NYMSE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\NORMAN\Nvc\BIN\NIP.EXE
C:\Program\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://login1.telia.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://login1.telia.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\Program\FlashGet\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [iTunesHelper] C:\Program\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [InCD] C:\Program\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [D-Link Air USB Utility] C:\Program\D-Link\Air USB Utility\AirCFG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: Labtec Mouse Software 2.0.lnk = C:\Program\Labtec\Wireless Mouse\MulMouse.exe
O4 - Global Startup: Certificate Mover.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1094663432628
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} (WebCam Control) - http://webcamnow.com/broadcast/ActiveXWebCam.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
Well I am not sure. After last bootup I run Adaware SE and then my virusprogram Norman find a Trojan Java/Byte verify. Adaware did not find any thing. I run SpySweeper and it found one adware CWS About blank. But my start page have not been hijacket so far. I will restart the PC and start ie a few times, it is then it happend and I will see. Any way a very big thank you for your support. It is very nice to know some one out there cares. BRGDS Trenter
Hi Daemon Yes it is still running OK now. You can close it. What a relive it is to get rid of this. I take my hat off for you and if you are a girl I would kiss you. Thanks allot. Have a nice day BRGDS Trenter
You're welcome - glad to help :D

To help keep you clean follow the recommendations in Tony's article here:

So how did I get infected in the first place?



As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI