This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Wwwcoolwebsearch And Www.ad-w-a-r-e

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi B) I am having problems with spyware "wwwcoolwebsearch" and It keeps locking me off of the internet. If I run spybot it finds several wwwcoolwebsearch entries and will fix them for awhile but they just come back the next day or so :( :scratch: 2nd problem or maybe the same ?? I keep getting pop ups or search redirects to "http://www.ad-w-a-r-e.com/cgi-bin/KeywordV2?query=wwwcoolwebsearch" I have Trend Micro Internet Security 11 set to block it and it blocks it but will not get rid of it. I have scanned with spybot, cwshredder and spyware doctor but can't get rid of them completle they all seem to detect them but will not fix it …? I have hijackthis and will post log with your permission. Thanks ……….Trake52 :wavey:

I have hijackthis and will post log with your permission.


Hello Trake52 , welcome to the TC.

"copy/paste" a new log file into this thread.
Here is my log

Logfile of HijackThis v1.98.2
Scan saved at 10:25:59 PM, on 12/16/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\C\WINXP\System32\smss.exe
C:\C\WINXP\system32\winlogon.exe
C:\C\WINXP\system32\services.exe
C:\C\WINXP\system32\lsass.exe
C:\C\WINXP\system32\svchost.exe
C:\C\WINXP\System32\svchost.exe
C:\C\WINXP\system32\spoolsv.exe
C:\C\WINXP\system32\rundll32.exe
C:\C\WINXP\System32\svchost.exe
C:\Program Files\Trend Micro2004\Tmntsrv.exe
C:\Program Files\Trend Micro2004\tmproxy.exe
C:\C\WINXP\Explorer.EXE
C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE
C:\Program Files\Trend Micro2004\pccguide.exe
C:\Program Files\Trend Micro2004\PCClient.exe
C:\Program Files\Trend Micro2004\TMOAgent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Trend Micro2004\PccPfw.exe
C:\C\WINXP\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.theglobeandmail.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = ———>Weatherbee**
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: Shell=
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE /P23 "EPSON Stylus C64 Series" /O6 "USB003" /M "Stylus C64"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro2004\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro2004\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro2004\TMOAgent.exe" /run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [EPSON Stylus C64 Series] C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE /P23 EPSON Stylus C64 Series /M Stylus C64 /EF HKCU
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Downloads - {AF0828BC-CB46-4C8D-95B6-8A7C4988F9FF} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\c\winxp\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\c\winxp\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\c\winxp\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\c\winxp\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\c\winxp\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\c\winxp\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\c\winxp\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\c\winxp\system32\aklsp.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {1C955F3B-5B32-4393-A05D-24B4970CD2A1} - http://streamp.babenet.com/cabs/videox.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…74/mcinsctl.cab
O16 - DPF: {5DF6FB84-749D-4AAE-AE37-708DE09B0588} - http://213.229.160.219/dialers/dialnew.cab
O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} - http://212.145.159.194/251065/dialercab/WebRecomendada.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://142.176.20.26/islandcam/AxisCamControl.ocx
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {CA797B15-445F-4AA9-9828-8A88502F560F} (Uninstall Control) - http://www.worldwinner.com/games/shared/uninstall.cab
O16 - DPF: {DF6504AC-3EFE-4287-B259-FB299B069C95} (WEBDE Fotoalbum Upload Control) - https://img.web.de/v/fotoalbum/activex/upload_1119.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup141.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion….ebio5_1_6_0.cab
O16 - DPF: {F5131C24-E56D-11CF-B78A-444553540000} (Ikonic Menu Control) - http://activex.microsoft.com/controls/iptdweb/ikcntrls.cab
O16 - DPF: {F5820AD3-9B20-423E-B2AA-7AF2B4055746} (CRegistryDownload Class) - http://download.paltalk.com/webregtest/RegDload.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{7456B80B-5571-4D10-B49F-353894925AEB}: NameServer = 24.222.0.91,24.222.0.75
O17 - HKLM\System\CS1\Services\Tcpip\..\{7456B80B-5571-4D10-B49F-353894925AEB}: NameServer = 24.222.0.91,24.222.0.75
O17 - HKLM\System\CS2\Services\Tcpip\..\{7456B80B-5571-4D10-B49F-353894925AEB}: NameServer = 24.222.0.91,24.222.0.75
Open Spybot S&D, click Mode>Advanced>Tools>Resident and remove the check from the Tea Timer box. You can reinstate it later but we don't want it interfering with what we need to do. Reboot when done.


Please do all the steps in the order they are listed

Uninstall Virtumundo from control panel >> add remove program if listed there. If not listed then skip the reboot.

Reboot

Download LSPfix here: http://www.cexx.org/lspfix.htm

Start the program and then check the I know what I'm doing box.

Move all instances of aklsp.dll and calsp.dll
(and nothing else), to the Remove pane.
Click the Finish Button and reboot.

Find and delete the file c:\windows\system\aklsp.dll
Find and delete the file c:\windows\system\calsp.dll


1. Open My Computer
2. Right click on your hard drive that you wish to clean (C drive, for example)
3. In the context menu that opens, select properties
4. Under the general tab you should select Disk Cleanup
5. Windows will scan your drive which will take a few seconds/minutes
6. A box will display the various files you can remove.
Check all boxes except compress old files
7. Click OK and windows will comply.

Restart your computer.

Reboot and "copy/paste" a new log file into this thread.
here is another log file B)

I could not find Virtumundo install on my computer..

Still got a redirect to " http://www.ad-w-a-r-e.com/cgi-bin/KeywordV…0ba9acf6514a03e " that Trend Micro Internet Security blocked when I restarted internet explorer ..



Logfile of HijackThis v1.98.2
Scan saved at 11:24:39 PM, on 12/16/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\C\WINXP\System32\smss.exe
C:\C\WINXP\system32\winlogon.exe
C:\C\WINXP\system32\services.exe
C:\C\WINXP\system32\lsass.exe
C:\C\WINXP\system32\svchost.exe
C:\C\WINXP\System32\svchost.exe
C:\C\WINXP\system32\spoolsv.exe
C:\C\WINXP\system32\rundll32.exe
C:\C\WINXP\Explorer.EXE
C:\C\WINXP\System32\svchost.exe
C:\Program Files\Trend Micro2004\Tmntsrv.exe
C:\Program Files\Trend Micro2004\tmproxy.exe
C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE
C:\Program Files\Trend Micro2004\pccguide.exe
C:\Program Files\Trend Micro2004\PCClient.exe
C:\Program Files\Trend Micro2004\TMOAgent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Trend Micro2004\PccPfw.exe
C:\Program Files\Trend Micro2004\TSC.EXE
C:\C\WINXP\system32\wuauclt.exe
C:\Program Files\Hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.theglobeandmail.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = ———>Weatherbee**
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: Shell=
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE /P23 "EPSON Stylus C64 Series" /O6 "USB003" /M "Stylus C64"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro2004\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro2004\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro2004\TMOAgent.exe" /run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [EPSON Stylus C64 Series] C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE /P23 EPSON Stylus C64 Series /M Stylus C64 /EF HKCU
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Downloads - {AF0828BC-CB46-4C8D-95B6-8A7C4988F9FF} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {1C955F3B-5B32-4393-A05D-24B4970CD2A1} - http://streamp.babenet.com/cabs/videox.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…74/mcinsctl.cab
O16 - DPF: {5DF6FB84-749D-4AAE-AE37-708DE09B0588} - http://213.229.160.219/dialers/dialnew.cab
O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} - http://212.145.159.194/251065/dialercab/WebRecomendada.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://142.176.20.26/islandcam/AxisCamControl.ocx
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {CA797B15-445F-4AA9-9828-8A88502F560F} (Uninstall Control) - http://www.worldwinner.com/games/shared/uninstall.cab
O16 - DPF: {DF6504AC-3EFE-4287-B259-FB299B069C95} (WEBDE Fotoalbum Upload Control) - https://img.web.de/v/fotoalbum/activex/upload_1119.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup141.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion….ebio5_1_6_0.cab
O16 - DPF: {F5131C24-E56D-11CF-B78A-444553540000} (Ikonic Menu Control) - http://activex.microsoft.com/controls/iptdweb/ikcntrls.cab
O16 - DPF: {F5820AD3-9B20-423E-B2AA-7AF2B4055746} (CRegistryDownload Class) - http://download.paltalk.com/webregtest/RegDload.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{7456B80B-5571-4D10-B49F-353894925AEB}: NameServer = 24.222.0.91,24.222.0.75
O17 - HKLM\System\CS1\Services\Tcpip\..\{7456B80B-5571-4D10-B49F-353894925AEB}: NameServer = 24.222.0.91,24.222.0.75
O17 - HKLM\System\CS2\Services\Tcpip\..\{7456B80B-5571-4D10-B49F-353894925AEB}: NameServer = 24.222.0.91,24.222.0.75
Good Morning :D

Here is a new log file.

Still getting redirect when starting internet explorer.

Logfile of HijackThis v1.98.2
Scan saved at 9:54:35 AM, on 12/17/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\C\WINXP\System32\smss.exe
C:\C\WINXP\system32\winlogon.exe
C:\C\WINXP\system32\services.exe
C:\C\WINXP\system32\lsass.exe
C:\C\WINXP\system32\svchost.exe
C:\C\WINXP\System32\svchost.exe
C:\C\WINXP\system32\spoolsv.exe
C:\C\WINXP\system32\rundll32.exe
C:\C\WINXP\System32\svchost.exe
C:\Program Files\Trend Micro2004\Tmntsrv.exe
C:\Program Files\Trend Micro2004\tmproxy.exe
C:\C\WINXP\Explorer.EXE
C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE
C:\Program Files\Trend Micro2004\pccguide.exe
C:\Program Files\Trend Micro2004\PCClient.exe
C:\Program Files\Trend Micro2004\TMOAgent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Trend Micro2004\PccPfw.exe
C:\C\WINXP\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.theglobeandmail.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = ———>Weatherbee**
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: Shell=
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE /P23 "EPSON Stylus C64 Series" /O6 "USB003" /M "Stylus C64"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro2004\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro2004\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro2004\TMOAgent.exe" /run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [EPSON Stylus C64 Series] C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE /P23 EPSON Stylus C64 Series /M Stylus C64 /EF HKCU
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Downloads - {AF0828BC-CB46-4C8D-95B6-8A7C4988F9FF} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…74/mcinsctl.cab
O16 - DPF: {5DF6FB84-749D-4AAE-AE37-708DE09B0588} - http://213.229.160.219/dialers/dialnew.cab
O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} - http://212.145.159.194/251065/dialercab/WebRecomendada.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://142.176.20.26/islandcam/AxisCamControl.ocx
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {CA797B15-445F-4AA9-9828-8A88502F560F} (Uninstall Control) - http://www.worldwinner.com/games/shared/uninstall.cab
O16 - DPF: {DF6504AC-3EFE-4287-B259-FB299B069C95} (WEBDE Fotoalbum Upload Control) - https://img.web.de/v/fotoalbum/activex/upload_1119.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup141.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion….ebio5_1_6_0.cab
O16 - DPF: {F5131C24-E56D-11CF-B78A-444553540000} (Ikonic Menu Control) - http://activex.microsoft.com/controls/iptdweb/ikcntrls.cab
O16 - DPF: {F5820AD3-9B20-423E-B2AA-7AF2B4055746} (CRegistryDownload Class) - http://download.paltalk.com/webregtest/RegDload.CAB
First, enable the viewing of Hidden Files and Folders as follows:
-At your Desktop, go to Start>My Computer
-Select the Tools menu and then Folder Options
-After the new window appears select the View tab
-Select: Display the contents of system folders
-Under the Hidden files and folders section select: Show hidden files and folders
-Remove the checkmark from Hide file extensions for known file types
-Remove the checkmark from Hide protected operating system files (Recommended)
-Press the Apply button
Click OK



NEXT

Please download Vx2 Finder and safe it to its own folder. http://downloads.subratam.org/VX2Finder(126).exe
Run VX2Finder(126).exe
Select: Click to Find VX2.Betterinternet
When the scan is done, select the Make Log
Copy the log and post it.

NEXT

Download Find_It.zip:
http://computercops.biz/zx/Zupe/Find%20It%20NT-2K-XP.zip
Unzip its contents to its own folder
Open the folder and double click on Find.bat (File with a gear symbol)
Ignore any File not found messages
It runs for a minute, and produces a log
Please copy and paste the log on your next response.

NEXT

Also, download KillBox.zip from the link below.
http://www.subratam.org/?page=removal
Place it in a folder on your Desktop.
Do not run it yet.

NEXT

Please look in your sytem32 folder and let me know if the below file is preset.

C:/Windoews/system32/guard.tmp

NEXT

Post all the logs and DO NOT REBOOT please.
Here is another Hijack log.
Please check it again because there may be some changes from previous log…

Thanks


Logfile of HijackThis v1.98.2
Scan saved at 8:43:12 PM, on 12/17/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\C\WINXP\System32\smss.exe
C:\C\WINXP\system32\winlogon.exe
C:\C\WINXP\system32\services.exe
C:\C\WINXP\system32\lsass.exe
C:\C\WINXP\system32\svchost.exe
C:\C\WINXP\System32\svchost.exe
C:\C\WINXP\system32\spoolsv.exe
C:\C\WINXP\System32\svchost.exe
C:\Program Files\Trend Micro2004\Tmntsrv.exe
C:\Program Files\Trend Micro2004\tmproxy.exe
C:\C\WINXP\Explorer.EXE
C:\Program Files\Trend Micro2004\PccPfw.exe
C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE
C:\Program Files\Trend Micro2004\pccguide.exe
C:\Program Files\Trend Micro2004\PCClient.exe
C:\Program Files\Trend Micro2004\TMOAgent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\C\WINXP\Explorer.EXE
C:\Program Files\Hijack this\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.theglobeandmail.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = ———>Weatherbee**
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: Shell=
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE /P23 "EPSON Stylus C64 Series" /O6 "USB003" /M "Stylus C64"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro2004\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro2004\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro2004\TMOAgent.exe" /run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKCU\..\Run: [EPSON Stylus C64 Series] C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE /P23 EPSON Stylus C64 Series /M Stylus C64 /EF HKCU
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Downloads - {AF0828BC-CB46-4C8D-95B6-8A7C4988F9FF} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…74/mcinsctl.cab
O16 - DPF: {5DF6FB84-749D-4AAE-AE37-708DE09B0588} - http://213.229.160.219/dialers/dialnew.cab
O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} - http://212.145.159.194/251065/dialercab/WebRecomendada.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://142.176.20.26/islandcam/AxisCamControl.ocx
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {CA797B15-445F-4AA9-9828-8A88502F560F} (Uninstall Control) - http://www.worldwinner.com/games/shared/uninstall.cab
O16 - DPF: {DF6504AC-3EFE-4287-B259-FB299B069C95} (WEBDE Fotoalbum Upload Control) - https://img.web.de/v/fotoalbum/activex/upload_1119.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup141.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion….ebio5_1_6_0.cab
O16 - DPF: {F5131C24-E56D-11CF-B78A-444553540000} (Ikonic Menu Control) - http://activex.microsoft.com/controls/iptdweb/ikcntrls.cab
O16 - DPF: {F5820AD3-9B20-423E-B2AA-7AF2B4055746} (CRegistryDownload Class) - http://download.paltalk.com/webregtest/RegDloa





Log for VX2.BetterInternet File Finder (msg126)

Files Found—

Additional Files—

Keys Under Notify—
CSCSettings


Guardian Key— is called:
Asynchronous 000
DllName
Impersonate 000
Logon WinLogon
Logoff WinLogoff
Shutdown WinShutdown

User Agent String—
{79566745-D0FB-48AE-AF41-6713B6D718E8}




Warning! This utility will find legitimate files in addition

to malware.
Do not remove anything unless you are sure you know

what you're doing.

——- System Files in System32 Directory ——-

Warning! This utility will find legitimate files in addition

to malware.
Do not remove anything unless you are sure you know

what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C is WEATHERBEE
Volume Serial Number is 0C8A-9D36

Directory of C:\C\WINXP\System32

12/17/2004 08:27 PM 225,642 maxml3a.dll
12/17/2004 08:25 PM 224,777 n44s0eh7eh4.dll
12/17/2004 08:23 PM 225,642 hr6805jue.dll
12/15/2004 05:41 AM 223,522 lv8s09l7e.dll
12/14/2004 05:50 AM 223,993 k062lajo1doc.dll
12/13/2004 05:51 AM 223,913 l08mlal11dq.dll
12/11/2004 08:29 AM 222,572 lv2s09f7e.dll
12/10/2004 05:05 PM 225,702 da16gt.dLL
12/10/2004 05:48 AM 222,605 s4rs0e97eh.dll
12/09/2004 07:37 AM 222,467 absnt.dll
12/09/2004 05:49 AM 222,467 kurnel32.dll
12/09/2004 05:49 AM 223,707 azau0ef9eh2.dll
12/08/2004 01:07 PM 224,371 az1olaf31d2.dll
12/07/2004 11:39 PM 225,849 d0j00a1med.dll
12/07/2004 01:38 PM 224,737 enrql1951.dll
12/07/2004 01:14 PM 223,762 h0l2la3o1d.dll
12/07/2004 11:11 AM 224,037 ir0ql5d51.dll
12/07/2004 07:03 AM 223,502 s0pu0a79ed.dll
12/07/2004 06:56 AM 224,168 azaolaf31d2.dll
12/07/2004 05:49 AM 223,026 p4r40e9qeh.dll
12/06/2004 12:11 PM 223,447 hrju0519e.dll
12/05/2004 08:54 AM 223,186 q6nulg5916.dll
12/05/2004 08:46 AM 225,638 s4880eluehq80.dll
12/04/2004 07:15 PM 225,763 mv00l9dm1.dll
12/04/2004 10:32 AM 223,429 dpmsvinn.dll
12/04/2004 10:32 AM 223,627 m8rm0i91e8.dll
12/02/2004 09:15 PM 222,901 m4640ejqehoe0.dll
12/01/2004 07:42 PM 225,525 l42s0ef7eh2.dll
12/01/2004 07:50 AM 225,550 lv4s09h7e.dll
11/30/2004 05:56 AM 225,944 gp4ml3h11.dll
11/29/2004 09:59 PM 225,435 l4l60e3seh.dll
11/29/2004 08:52 PM 225,985 l48mlel11hq.dll
11/29/2004 07:44 PM 225,720 lvju0919e.dll
11/27/2004 07:23 PM 223,115 l4j8le1u1h.dll
11/27/2004 06:03 AM 225,277 h02olaf31d2.dll
11/26/2004 07:25 PM 225,164 p64ulgh9164.dll
11/26/2004 05:34 PM 225,159 en4ul1h91.dll
11/25/2004 06:43 PM 223,944 n42u0ef9eh2.dll
11/24/2004 06:24 PM 223,033 enn6l15s1.dll
09/08/2004 12:56 PM dllcache
08/13/2003 01:52 PM 32

{EFE48D05-B5B5-4E0B-9380-50521AC3710B}.dat
08/02/2003 11:12 PM Microsoft
09/30/1999 06:21 PM 166,672 mstext35.dll
09/28/1999 08:42 PM 1,050,896 msjet35.dll
09/09/1999 09:06 PM 168,720 msltus35.dll
09/09/1999 09:06 PM 252,688 msexcl35.dll
08/25/1999 01:57 PM 415,504 msrepl35.dll
06/07/1999 05:59 PM 250,128 mspdox35.dll
04/25/1999 04:00 PM 287,504 Msxbse35.dll
47 File(s) 11,340,447 bytes
2 Dir(s) 12,732,157,440 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C is WEATHERBEE
Volume Serial Number is 0C8A-9D36

Directory of C:\C\WINXP\System32

11/16/2004 12:50 PM 19 winrscpxd.ini
09/08/2004 12:56 PM dllcache
08/19/2003 11:12 PM GroupPolicy
08/13/2003 01:52 PM 32

{EFE48D05-B5B5-4E0B-9380-50521AC3710B}.dat
08/02/2003 06:05 PM 488 logonui.exe.manifest
08/02/2003 06:05 PM 488

WindowsLogon.manifest
08/02/2003 06:05 PM 749 sapi.cpl.manifest
08/02/2003 06:05 PM 749 cdplayer.exe.manifest
08/02/2003 06:05 PM 749 nwc.cpl.manifest
08/02/2003 06:05 PM 749 ncpa.cpl.manifest
08/02/2003 06:05 PM 749 wuaucpl.cpl.manifest
09/04/1992 02:26 PM 44,669 Pleap.wav
10 File(s) 49,441 bytes
2 Dir(s) 12,732,157,440 bytes free

———- Files Named "Guard" ————-

Volume in drive C is WEATHERBEE
Volume Serial Number is 0C8A-9D36

Directory of C:\C\WINXP\System32


——— Temp Files in System32 Directory ——–

Volume in drive C is WEATHERBEE
Volume Serial Number is 0C8A-9D36

Directory of C:\C\WINXP\System32


—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\C

urrentVersion\Internet Settings\User Agent\Post

Platform]
"{79566745-D0FB-48AE-AF41-6713B6D718E8}"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify\CSCSettings]
"Asynchronous"=dword:00000000
"DllName"="C:\\C\\WINXP\\system32\\hr6805jue.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"


—————- Xfind Locked Files —————–

C:\C\WINXP\System32\HR6805~1.DLL +++ File read error

————– XFind Qoologic Results ————–

C:\C\WINXP\System32\HR6805~1.DLL +++ File read error

————– XFind Aspack Results —————

C:\C\WINXP\System32\HR6805~1.DLL +++ File read error

————– Locate.com Results —————

C:\C\WINXP\SYSTEM32\
absnt.dll Thu Dec 9 2004 7:37:08a ..S.R

222,467 217.25 K
az1ola~1.dll Wed Dec 8 2004 1:07:04p ..S.R

224,371 219.11 K
azaola~1.dll Tue Dec 7 2004 6:56:52a ..S.R

224,168 218.91 K
azau0e~1.dll Thu Dec 9 2004 5:49:10a ..S.R

223,707 218.46 K
d0j00a~1.dll Tue Dec 7 2004 11:39:52p ..S.R

225,849 220.55 K
da16gt.dll Fri Dec 10 2004 5:05:22p ..S.R

225,702 220.41 K
dpmsvinn.dll Sat Dec 4 2004 10:32:14a ..S.R

223,429 218.19 K
en4ul1~1.dll Fri Nov 26 2004 5:34:06p ..S.R

225,159 219.88 K
enn6l1~1.dll Wed Nov 24 2004 6:24:36p ..S.R

223,033 217.80 K
enrql1~1.dll Tue Dec 7 2004 1:38:50p ..S.R

224,737 219.47 K
gp4ml3~1.dll Tue Nov 30 2004 5:56:26a ..S.R

225,944 220.65 K
h02ola~1.dll Sat Nov 27 2004 6:03:08a ..S.R

225,277 219.99 K
h0l2la~1.dll Tue Dec 7 2004 1:14:16p ..S.R

223,762 218.52 K
hr6805~1.dll Fri Dec 17 2004 8:23:32p ..S.R

225,642 220.35 K
hrju05~1.dll Mon Dec 6 2004 12:11:52p ..S.R

223,447 218.21 K
ir0ql5~1.dll Tue Dec 7 2004 11:11:34a ..S.R

224,037 218.79 K
k062la~1.dll Tue Dec 14 2004 5:50:12a ..S.R

223,993 218.74 K
kurnel32.dll Thu Dec 9 2004 5:49:10a ..S.R

222,467 217.25 K
l08mla~1.dll Mon Dec 13 2004 5:51:12a ..S.R

223,913 218.66 K
l42s0e~1.dll Wed Dec 1 2004 7:42:32p ..S.R

225,525 220.24 K
l48mle~1.dll Mon Nov 29 2004 8:52:56p ..S.R

225,985 220.69 K
l4j8le~1.dll Sat Nov 27 2004 7:23:28p ..S.R

223,115 217.88 K
l4l60e~1.dll Mon Nov 29 2004 9:59:58p ..S.R

225,435 220.15 K
lv2s09~1.dll Sat Dec 11 2004 8:29:50a ..S.R

222,572 217.36 K
lv4s09~1.dll Wed Dec 1 2004 7:50:12a ..S.R

225,550 220.26 K
lv8s09~1.dll Wed Dec 15 2004 5:41:28a ..S.R

223,522 218.28 K
lvju09~1.dll Mon Nov 29 2004 7:44:12p ..S.R

225,720 220.43 K
m4640e~1.dll Thu Dec 2 2004 9:15:54p ..S.R

222,901 217.68 K
m8rm0i~1.dll Sat Dec 4 2004 10:32:14a ..S.R

223,627 218.38 K
maxml3a.dll Fri Dec 17 2004 8:27:06p ..S.R

225,642 220.35 K
mv00l9~1.dll Sat Dec 4 2004 7:15:26p ..S.R

225,763 220.47 K
n42u0e~1.dll Thu Nov 25 2004 6:43:36p ..S.R

223,944 218.70 K
n44s0e~1.dll Fri Dec 17 2004 8:25:34p ..S.R

224,777 219.51 K
p4r40e~1.dll Tue Dec 7 2004 5:49:28a ..S.R

223,026 217.80 K
p64ulg~1.dll Fri Nov 26 2004 7:25:48p ..S.R

225,164 219.89 K
q6nulg~1.dll Sun Dec 5 2004 8:54:06a ..S.R

223,186 217.95 K
s0pu0a~1.dll Tue Dec 7 2004 7:03:58a ..S.R

223,502 218.26 K
s4880e~1.dll Sun Dec 5 2004 8:46:16a ..S.R

225,638 220.35 K
s4rs0e~1.dll Fri Dec 10 2004 5:48:02a ..S.R

222,605 217.39 K
winrsc~1.ini Tue Nov 16 2004 12:50:04p …H.

19 0.02 K

40 items found: 40 files, 0 directories.
Total of file sizes: 8,748,322 bytes 8.34 M

IMPORTANT:
Open Spybot S&D, click Mode>Advanced>Tools>Resident and remove the check from the Tea Timer box. You can reinstate it later but we don't want it interfering with what we need to do. Reboot when done.

Please take your time and follow the instructions.

If you have not rebooted or shutdown/restarted, proceed as follows:

First, Disconnect from the Internet!!

(Please copy these instructions to NotePad for copy/paste use, since you will be off the Internet.)
____
Next, launch Notepad, and copy/paste all the blue REGEDIT below to it
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{79566745-D0FB-48AE-AF41-6713B6D718E8}"=-

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\CSCSettings]



Back on the Desktop, double-click on the fixme.reg file you just saved and click on Yes when asked to merge the information.
____
Now, extract KillBox (downloaded earlier) from the zip file and double-click on KillBox.exe to run it.

In the main screen of Pocket KillBox, go to Tools in the top menu bar, and select: Delete Temp Files.

Back at the main screen of KillBox, select the option: Delete on Reboot

In the Full Path of File to Delete box, copy and paste this entry:
C:\\C\\WINXP\\system32\\hr6805jue.dll
Press the button with a red circle and a white X.
When asked if you would like to Reboot, select No.

Do the same as above for each of the files that follow, and select No when asked to reboot!

C:\C\WINXP\System32\HR6805~1.DLL
C:\WINDOWS\System32\enn6l15s1.dll
C:\WINDOWS\System32\maxml3a.dll
C:\WINDOWS\System32\n44s0eh7eh4.dll
C:\WINDOWS\System32\hr6805jue.dll
C:\WINDOWS\System32\lv8s09l7e.dll
C:\WINDOWS\System32\k062lajo1doc.dll
C:\WINDOWS\System32\l08mlal11dq.dll
C:\WINDOWS\System32\lv2s09f7e.dll
C:\WINDOWS\System32\da16gt.dLL
C:\WINDOWS\System32\s4rs0e97eh.dll
C:\WINDOWS\System32\absnt.dll
C:\WINDOWS\System32\kurnel32.dll
C:\WINDOWS\System32\azau0ef9eh2.dll
C:\WINDOWS\System32\az1olaf31d2.dll
C:\WINDOWS\System32\d0j00a1med.dll
C:\WINDOWS\System32\enrql1951.dll
C:\WINDOWS\System32\h0l2la3o1d.dll
C:\WINDOWS\System32\ir0ql5d51.dll
C:\WINDOWS\System32\s0pu0a79ed.dll
C:\WINDOWS\System32\azaolaf31d2.dll
C:\WINDOWS\System32\p4r40e9qeh.dll
C:\WINDOWS\System32\hrju0519e.dll
C:\WINDOWS\System32\q6nulg5916.dll
C:\WINDOWS\System32\s4880eluehq80.dll
C:\WINDOWS\System32\mv00l9dm1.dll
C:\WINDOWS\System32\dpmsvinn.dll
C:\WINDOWS\System32\m8rm0i91e8.dll
C:\WINDOWS\System32\m4640ejqehoe0.dll
C:\WINDOWS\System32\l42s0ef7eh2.dll
C:\WINDOWS\System32\lv4s09h7e.dll
C:\WINDOWS\System32\gp4ml3h11.dll
C:\WINDOWS\System32\l4l60e3seh.dll
C:\WINDOWS\System32\l48mlel11hq.dll
C:\WINDOWS\System32\lvju0919e.dll
C:\WINDOWS\System32\l4j8le1u1h.dll
C:\WINDOWS\System32\h02olaf31d2.dll
C:\WINDOWS\System32\p64ulgh9164.dll
C:\WINDOWS\System32\en4ul1h91.dll
C:\WINDOWS\System32\n42u0ef9eh2.dll
C:\C\WINXP\SYSTEM32\absnt.dll
C:\C\WINXP\SYSTEM32\az1ola~1.dll
C:\C\WINXP\SYSTEM32\azau0e~1.dll
C:\C\WINXP\SYSTEM32\d0j00a~1.dll
C:\C\WINXP\SYSTEM32\da16gt.dll
C:\C\WINXP\SYSTEM32\dpmsvinn.dll
C:\C\WINXP\SYSTEM32\en4ul1~1.dll
C:\C\WINXP\SYSTEM32\enn6l1~1.dll
C:\C\WINXP\SYSTEM32\enrql1~1.dll
C:\C\WINXP\SYSTEM32\gp4ml3~1.dll
C:\C\WINXP\SYSTEM32\h02ola~1.dll
C:\C\WINXP\SYSTEM32\h0l2la~1.dll
C:\C\WINXP\SYSTEM32\hr6805~1.dll
C:\C\WINXP\SYSTEM32\hrju05~1.dll
C:\C\WINXP\SYSTEM32\ir0ql5~1.dll
C:\C\WINXP\SYSTEM32\k062la~1.dll
C:\C\WINXP\SYSTEM32\kurnel32.dll
C:\C\WINXP\SYSTEM32\l08mla~1.dll
C:\C\WINXP\SYSTEM32\l42s0e~1.dll
C:\C\WINXP\SYSTEM32\l48mle~1.dll
C:\C\WINXP\SYSTEM32\l4j8le~1.dll
C:\C\WINXP\SYSTEM32\l4l60e~1.dll
C:\C\WINXP\SYSTEM32\lv2s09~1.dll
C:\C\WINXP\SYSTEM32\lv4s09~1.dll
C:\C\WINXP\SYSTEM32\lv8s09~1.dll
C:\C\WINXP\SYSTEM32\lvju09~1.dll
C:\C\WINXP\SYSTEM32\m4640e~1.dll
C:\C\WINXP\SYSTEM32\m8rm0i~1.dll
C:\C\WINXP\SYSTEM32\maxml3a.dll
C:\C\WINXP\SYSTEM32\mv00l9~1.dll
C:\C\WINXP\SYSTEM32\n42u0e~1.dll
C:\C\WINXP\SYSTEM32\n44s0e~1.dll
C:\C\WINXP\SYSTEM32\p4r40e~1.dll
C:\C\WINXP\SYSTEM32\p64ulg~1.dll
C:\C\WINXP\SYSTEM32\q6nulg~1.dll
C:\C\WINXP\SYSTEM32\s0pu0a~1.dll
C:\C\WINXP\SYSTEM32\s4880e~1.dll
C:\C\WINXP\SYSTEM32\s4rs0e~1.dll


Finally, in the Full Path of File to Delete, copy and paste the following:
C:\WINDOWS\System32\guard.tmp
Press the button with a red circle and a white X.
When asked to Reboot, select Yes!!
____
Make sure all windows are closed before proceeding to run HijackThis and Scan. Fix the following by placing a check in the appropriate box and selecting Fix Checked:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

F2 - REG:system.ini: Shell=

ALL O1 - Hosts:

ALL O16 - DPF:



Reboot the computer.
____
Since this intruder may alter the Hosts file, download the Hoster to restore the file:
http://members.aol.com/toadbee/hoster.zip
Select: Restore Original Hosts
Click OK and exit Hoster.
____
Next, download AdAware SE from the following link:
http://www.majorgeeks.com/download506.html
Install the program and launch it.

First in the main window look in the bottom right corner and click on Check for updates now then click Connect and download the latest reference files.

From main window :Click Start then under Select a scan Mode tick Perform full system scan.

Next deselect Search for negligible risk entries.

Now to scan just click the Next button.

When the scan is finished mark everything for removal and get rid of it.(Right-click the window and choose select all from the drop down menu and click Next)


Also, check the Recycle Bin to see if it works properly. A side effect of VX2 is to sometimes damage the Recycle Bin operation.
Create an blank Notepad file on the Desktop: right click the Desktop, select New>Text Document
Right click the text document and delete it.
When a file is deleted, it should ask if you want to send it to Recycle Bin.
Does it ask if you want to send the file to the Recycle Bin, or, does the file just get deleted?
Post back what it does.

When done with all of the above, close all windows and browsers, run HijackThis, Scan, post a new HijackThis log, and a new Find_It log.

If you encounter any problems with the steps above, please describe them.
I think I got a lot of things fixed.. :thumbup:

Recycle bin in not working properly..Does not ask if I want to send the file to the Recycle Bin, the file just get deleted?

Do you see anything else I should do to improve my system. Just let me know what you think and I will give it a try.
:thumbup:

Thanks. :P


My new HijackThis log, and a new Find_It log.


Logfile of HijackThis v1.98.2
Scan saved at 1:19:21 AM, on 12/18/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\C\WINXP\System32\smss.exe
C:\C\WINXP\system32\winlogon.exe
C:\C\WINXP\system32\services.exe
C:\C\WINXP\system32\lsass.exe
C:\C\WINXP\system32\svchost.exe
C:\C\WINXP\System32\svchost.exe
C:\C\WINXP\system32\spoolsv.exe
C:\C\WINXP\System32\svchost.exe
C:\Program Files\Trend Micro2004\Tmntsrv.exe
C:\Program Files\Trend Micro2004\tmproxy.exe
C:\C\WINXP\Explorer.EXE
C:\Program Files\Trend Micro2004\PccPfw.exe
C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE
C:\Program Files\Trend Micro2004\pccguide.exe
C:\Program Files\Trend Micro2004\PCClient.exe
C:\Program Files\Trend Micro2004\TMOAgent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.theglobeandmail.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = ———>Weatherbee**
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE /P23 "EPSON Stylus C64 Series" /O6 "USB003" /M "Stylus C64"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro2004\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro2004\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro2004\TMOAgent.exe" /run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKCU\..\Run: [EPSON Stylus C64 Series] C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE /P23 EPSON Stylus C64 Series /M Stylus C64 /EF HKCU
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Downloads - {AF0828BC-CB46-4C8D-95B6-8A7C4988F9FF} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll





Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C is WEATHERBEE
Volume Serial Number is 0C8A-9D36

Directory of C:\C\WINXP\System32

12/07/2004 06:56 AM 224,168 azaolaf31d2.dll
09/08/2004 12:56 PM dllcache
08/13/2003 01:52 PM 32

{EFE48D05-B5B5-4E0B-9380-50521AC3710B}.dat
08/02/2003 11:12 PM Microsoft
09/30/1999 06:21 PM 166,672 mstext35.dll
09/28/1999 08:42 PM 1,050,896 msjet35.dll
09/09/1999 09:06 PM 168,720 msltus35.dll
09/09/1999 09:06 PM 252,688 msexcl35.dll
08/25/1999 01:57 PM 415,504 msrepl35.dll
06/07/1999 05:59 PM 250,128 mspdox35.dll
04/25/1999 04:00 PM 287,504 Msxbse35.dll
9 File(s) 2,816,312 bytes
2 Dir(s) 12,732,052,480 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C is WEATHERBEE
Volume Serial Number is 0C8A-9D36

Directory of C:\C\WINXP\System32

11/16/2004 12:50 PM 19 winrscpxd.ini
09/08/2004 12:56 PM dllcache
08/19/2003 11:12 PM GroupPolicy
08/13/2003 01:52 PM 32

{EFE48D05-B5B5-4E0B-9380-50521AC3710B}.dat
08/02/2003 06:05 PM 488 logonui.exe.manifest
08/02/2003 06:05 PM 488 WindowsLogon.manifest
08/02/2003 06:05 PM 749 sapi.cpl.manifest
08/02/2003 06:05 PM 749 cdplayer.exe.manifest
08/02/2003 06:05 PM 749 nwc.cpl.manifest
08/02/2003 06:05 PM 749 ncpa.cpl.manifest
08/02/2003 06:05 PM 749 wuaucpl.cpl.manifest
09/04/1992 02:26 PM 44,669 Pleap.wav
10 File(s) 49,441 bytes
2 Dir(s) 12,732,047,360 bytes free

———- Files Named "Guard" ————-

Volume in drive C is WEATHERBEE
Volume Serial Number is 0C8A-9D36

Directory of C:\C\WINXP\System32


——— Temp Files in System32 Directory ——–

Volume in drive C is WEATHERBEE
Volume Serial Number is 0C8A-9D36

Directory of C:\C\WINXP\System32


—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Interne

t Settings\User Agent\Post Platform]
"{79566745-D0FB-48AE-AF41-6713B6D718E8}"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify\Explorer]
"Asynchronous"=dword:00000000
"DllName"="C:\\C\\WINXP\\system32\\n44s0eh7eh4.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"


—————- Xfind Locked Files —————–


————– XFind Qoologic Results ————–


————– XFind Aspack Results —————

* resultC:\C\WINXP\System32\INCINE~1.DLL
* resultC:\C\WINXP\System32\NTDLL.DLL

————– Locate.com Results —————

C:\C\WINXP\SYSTEM32\
azaola~1.dll Tue Dec 7 2004 6:56:52a ..S.R 224,168 218.91 K
winrsc~1.ini Tue Nov 16 2004 12:50:04p …H. 19 0.02 K

2 items found: 2 files, 0 directories.
Total of file sizes: 224,187 bytes 218.93 K

If you have not rebooted or shutdown/restarted, proceed as follows:

First, Disconnect from the Internet!!

(Please copy these instructions to NotePad for copy/paste use, since you will be off the Internet.)
____
Next, launch Notepad, and copy/paste all the blue REGEDIT below to it
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{7573AB4A-C0D1-4BE2-9BE0-54451F6BC572}"=-

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Explorer]



Back on the Desktop, double-click on the fixme.reg file you just saved and click on Yes when asked to merge the information.
____
Now, extract KillBox (downloaded earlier) from the zip file and double-click on KillBox.exe to run it.

In the main screen of Pocket KillBox, go to Tools in the top menu bar, and select: Delete Temp Files.

Back at the main screen of KillBox, select the option: Delete on Reboot

In the Full Path of File to Delete box, copy and paste this entry:
C:\\C\\WINXP\\system32\\n44s0eh7eh4.dll
Press the button with a red circle and a white X.
When asked if you would like to Reboot, select No.

Do the same as above for each of the files that follow, and select No when asked to reboot!

C:\C\WINXP\System32\azaolaf31d2.dll

Finally, in the Full Path of File to Delete, copy and paste the following:
C:\WINDOWS\System32\guard.tmp
Press the button with a red circle and a white X.
When asked to Reboot, select Yes!!
____
Make sure all windows are closed before proceeding to run HijackThis and Scan. Fix the following by placing a check in the appropriate box and selecting Fix Checked:

O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause

O9 - Extra button: Downloads - {AF0828BC-CB46-4C8D-95B6-8A7C4988F9FF} - (no file)


Go to Start>Run, and type in: cmd
Select: OK
At the cmd prompt, type the following commands and press Enter after each:

cd\
attrib -h -s c:\recycler
del c:\recycler

Create a blank NotePad file again, and delete it. Do you now get asked if you want to send the file to the Recycle Bin, and then the file shows up in the RB? If that is the case, you‘re good!

Reboot the computer.
____
Since this intruder may alter the Hosts file, download the Hoster to restore the file:
http://members.aol.com/toadbee/hoster.zip
Select: Restore Original Hosts
Click OK and exit Hoster.
____


When done with all of the above, close all windows and browsers, run HijackThis, Scan, post a new HijackThis log, and a new Find_It log.
Hey i'm back

:thumbup: :thumbup:

Here is my latest log files

Recycle bin is back and no more pop ups on redirects …thanks :D

My Quick Launch tool bar goes away everytime I reboot, any ideas how to keep it.
I have it set to "show quick launch " in toolbars and start menu properties.

Willing to try anything you suggest…

Do these need to be loaded at start up ?
I seldom use real player or OmniPageSE…

C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe



Logfile of HijackThis v1.98.2
Scan saved at 8:01:30 AM, on 12/19/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\C\WINXP\System32\smss.exe
C:\C\WINXP\system32\winlogon.exe
C:\C\WINXP\system32\services.exe
C:\C\WINXP\system32\lsass.exe
C:\C\WINXP\system32\svchost.exe
C:\C\WINXP\System32\svchost.exe
C:\C\WINXP\system32\spoolsv.exe
C:\C\WINXP\System32\svchost.exe
C:\Program Files\Trend Micro2004\Tmntsrv.exe
C:\Program Files\Trend Micro2004\tmproxy.exe
C:\Program Files\Trend Micro2004\PccPfw.exe
C:\C\WINXP\Explorer.EXE
C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE
C:\Program Files\Trend Micro2004\pccguide.exe
C:\Program Files\Trend Micro2004\PCClient.exe
C:\Program Files\Trend Micro2004\TMOAgent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\C\WINXP\system32\taskmgr.exe
C:\Program Files\Hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.theglobeandmail.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = ———>Weatherbee**
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE /P23 "EPSON Stylus C64 Series" /O6 "USB003" /M "Stylus C64"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro2004\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro2004\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro2004\TMOAgent.exe" /run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKCU\..\Run: [EPSON Stylus C64 Series] C:\C\WINXP\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE /P23 EPSON Stylus C64 Series /M Stylus C64 /EF HKCU
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll





Warning! This utility will find legitimate files in addition

to malware.
Do not remove anything unless you are sure you know

what you're doing.

——- System Files in System32 Directory ——-

Volume in drive C is WEATHERBEE
Volume Serial Number is 0C8A-9D36

Directory of C:\C\WINXP\System32

09/08/2004 12:56 PM dllcache
08/13/2003 01:52 PM 32

{EFE48D05-B5B5-4E0B-9380-50521AC3710B}.dat
08/02/2003 11:12 PM Microsoft
09/30/1999 06:21 PM 166,672 mstext35.dll
09/28/1999 08:42 PM 1,050,896 msjet35.dll
09/09/1999 09:06 PM 168,720 msltus35.dll
09/09/1999 09:06 PM 252,688 msexcl35.dll
08/25/1999 01:57 PM 415,504 msrepl35.dll
06/07/1999 05:59 PM 250,128 mspdox35.dll
04/25/1999 04:00 PM 287,504 Msxbse35.dll
8 File(s) 2,592,144 bytes
2 Dir(s) 12,825,315,840 bytes free

——- Hidden Files in System32 Directory ——-

Volume in drive C is WEATHERBEE
Volume Serial Number is 0C8A-9D36

Directory of C:\C\WINXP\System32

11/16/2004 12:50 PM 19 winrscpxd.ini
09/08/2004 12:56 PM dllcache
08/19/2003 11:12 PM GroupPolicy
08/13/2003 01:52 PM 32

{EFE48D05-B5B5-4E0B-9380-50521AC3710B}.dat
08/02/2003 06:05 PM 488 logonui.exe.manifest
08/02/2003 06:05 PM 488

WindowsLogon.manifest
08/02/2003 06:05 PM 749 sapi.cpl.manifest
08/02/2003 06:05 PM 749 cdplayer.exe.manifest
08/02/2003 06:05 PM 749 nwc.cpl.manifest
08/02/2003 06:05 PM 749 ncpa.cpl.manifest
08/02/2003 06:05 PM 749 wuaucpl.cpl.manifest
09/04/1992 02:26 PM 44,669 Pleap.wav
10 File(s) 49,441 bytes
2 Dir(s) 12,825,313,792 bytes free

———- Files Named "Guard" ————-

Volume in drive C is WEATHERBEE
Volume Serial Number is 0C8A-9D36

Directory of C:\C\WINXP\System32


——— Temp Files in System32 Directory ——–

Volume in drive C is WEATHERBEE
Volume Serial Number is 0C8A-9D36

Directory of C:\C\WINXP\System32


—————- User Agent ————

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\C

urrentVersion\Internet Settings\User Agent\Post

Platform]
"{79566745-D0FB-48AE-AF41-6713B6D718E8}"=""


———— Keys Under Notify ————

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"


—————- Xfind Locked Files —————–


————– XFind Qoologic Results ————–


————– XFind Aspack Results —————

* resultC:\C\WINXP\System32\INCINE~1.DLL
* resultC:\C\WINXP\System32\NTDLL.DLL

————– Locate.com Results —————

C:\C\WINXP\SYSTEM32\
winrsc~1.ini Tue Nov 16 2004 12:50:04p …H.

19 0.02 K

1 item found: 1 file, 0 directories.
Total of file sizes: 19 bytes 0.02 K

Double-click on KillBox.exe to run it.

In the main screen of Pocket KillBox, go to Tools in the top menu bar, and select: Delete Temp Files.

Back at the main screen of KillBox, select the option: Delete on Reboot

In the Full Path of File to Delete box, copy and paste this entry:
C:\C\WINXP\System32\INCINE~1.DLL
Press the button with a red circle and a white X.
When asked if you would like to Reboot, select No.

Do the same as above for each of the files that follow, and select No when asked to reboot!

C:\C\WINXP\System32\NTDLL.DLL
C:\C\WINXP\SYSTEM32\winrsc~1.ini


Finally, in the Full Path of File to Delete, copy and paste the following:
C:\WINDOWS\System32\guard.tmp
Press the button with a red circle and a white X.
When asked to Reboot, select Yes!!



Make sure all windows are closed before proceeding to run HijackThis and Scan. Fix the following by placing a check in the appropriate box and selecting Fix Checked:

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe


Open C:\Program Files\Common Files\Real\Update_OB\realsched.exe <–Delete File


When done with all of the above, close all windows and browsers, run HijackThis, Scan, post a new HijackThis log, and a new Find_It log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI