This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

CoolWebSearch-HomeSearch

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I believe i'm having a problem with a variant of CWS called HomeSearch, but i am not sure. My homepage has been hijacked and i am getting popups among other problems. I first ran both Ad-Aware and spybot and eliminated a number of things. I then used the CWSshredder. Initially during a scan only this listed the HomeSearch variant as being present, after trying to fix it a couple of times, it finally went away supposedly, but the same problems are still present and the CWSshredder claims there are no problems, although repeated runs of ad-aware show that CWS is still on the computer. After this i followed a number of protocols i found on the web to no avail (all of my temp, internet temp files, cookies etc. have been completely deleted). I also tried using aboutbuster and eliminating a number of things via Hijackthis, but i am apparently missing something. I am not comfortable going in manually with regedit. I was hoping someone could read my HijackThis log and advise me on any possible solutions and/or point out whatever it is that i am missing (note i have repeatedly deleted the R0 and R1 instances, along with the Default URL SearchHook is missing line, i tried searching through the others using some online guides but didn't find the things they listed. Thanks for the help.


Logfile of HijackThis v1.99.1
Scan saved at 10:18:22 PM, on 5/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ntda.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\system32\carpserv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\CMMON32.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\jiqtt.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jiqtt.dll/sp.html#93256
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\jiqtt.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\jiqtt.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jiqtt.dll/sp.html#93256
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\jiqtt.dll/sp.html#93256
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.iub.edu"); (C:\Documents and Settings\Casey\Application Data\Mozilla\Profiles\default\0nrbdnyx.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Casey\Application Data\Mozilla\Profiles\default\0nrbdnyx.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {2366F987-C10B-122D-8480-E366C679402B} - C:\WINDOWS\system32\d3hc.dll
O2 - BHO: Class - {A989B009-49B7-5A55-1A34-1D32EE1EA30B} - C:\WINDOWS\ntda.dll
O2 - BHO: Class - {DDF69936-9289-A3BA-6911-C5BB49DC85D8} - C:\WINDOWS\system32\appui32.dll
O2 - BHO: Class - {F452FA15-98C9-BD51-AC62-418E0C391EC0} - C:\WINDOWS\ipog.dll
O2 - BHO: Class - {FA6A4655-C13C-BF9A-C97E-513B7A9A010A} - C:\WINDOWS\system32\apijv32.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [sdkcs.exe] C:\WINDOWS\system32\sdkcs.exe
O4 - HKLM\..\Run: [nettn.exe] C:\WINDOWS\nettn.exe
O4 - HKLM\..\Run: [atlbb32.exe] C:\WINDOWS\atlbb32.exe
O4 - HKLM\..\Run: [ntgz.exe] C:\WINDOWS\ntgz.exe
O4 - HKLM\..\Run: [crel.exe] C:\WINDOWS\crel.exe
O4 - HKLM\..\Run: [javajr.exe] C:\WINDOWS\system32\javajr.exe
O4 - HKLM\..\Run: [ntda.exe] C:\WINDOWS\ntda.exe
O4 - HKLM\..\RunOnce: [nthh.exe] C:\WINDOWS\system32\nthh.exe
O4 - HKLM\..\RunOnce: [d3ra.exe] C:\WINDOWS\d3ra.exe
O4 - HKLM\..\RunOnce: [netbl32.exe] C:\WINDOWS\netbl32.exe
O4 - HKLM\..\RunOnce: [syskp32.exe] C:\WINDOWS\system32\syskp32.exe
O4 - HKLM\..\RunOnce: [javasa.exe] C:\WINDOWS\system32\javasa.exe
O4 - HKLM\..\RunOnce: [iekt32.exe] C:\WINDOWS\iekt32.exe
O4 - HKLM\..\RunOnce: [crbk32.exe] C:\WINDOWS\system32\crbk32.exe
O4 - HKLM\..\RunOnce: [msbx.exe] C:\WINDOWS\msbx.exe
O4 - HKLM\..\RunOnce: [msrw.exe] C:\WINDOWS\msrw.exe
O4 - HKLM\..\RunOnce: [apipw.exe] C:\WINDOWS\apipw.exe
O4 - HKLM\..\RunOnce: [ntzj.exe] C:\WINDOWS\ntzj.exe
O4 - HKLM\..\RunOnce: [atlka32.exe] C:\WINDOWS\atlka32.exe
O4 - HKLM\..\RunOnce: [javayx32.exe] C:\WINDOWS\system32\javayx32.exe
O4 - HKLM\..\RunOnce: [msak.exe] C:\WINDOWS\msak.exe
O4 - HKLM\..\RunOnce: [sdkkx32.exe] C:\WINDOWS\sdkkx32.exe
O4 - HKLM\..\RunOnce: [appwv.exe] C:\WINDOWS\system32\appwv.exe
O4 - HKLM\..\RunOnce: [msff32.exe] C:\WINDOWS\system32\msff32.exe
O4 - HKLM\..\RunOnce: [winge.exe] C:\WINDOWS\winge.exe
O4 - HKLM\..\RunOnce: [d3do32.exe] C:\WINDOWS\d3do32.exe
O4 - HKLM\..\RunOnce: [sdkma.exe] C:\WINDOWS\sdkma.exe
O4 - HKLM\..\RunOnce: [ipff32.exe] C:\WINDOWS\system32\ipff32.exe
O4 - HKLM\..\RunOnce: [crzf32.exe] C:\WINDOWS\crzf32.exe
O4 - HKLM\..\RunOnce: [d3hn32.exe] C:\WINDOWS\d3hn32.exe
O4 - HKLM\..\RunOnce: [iefp32.exe] C:\WINDOWS\iefp32.exe
O4 - HKLM\..\RunOnce: [d3eo.exe] C:\WINDOWS\system32\d3eo.exe
O4 - HKLM\..\RunOnce: [nethi32.exe] C:\WINDOWS\nethi32.exe
O4 - HKLM\..\RunOnce: [d3ks32.exe] C:\WINDOWS\system32\d3ks32.exe
O4 - HKLM\..\RunOnce: [addoy.exe] C:\WINDOWS\addoy.exe
O4 - HKLM\..\RunOnce: [ntjq.exe] C:\WINDOWS\system32\ntjq.exe
O4 - HKLM\..\RunOnce: [iptm32.exe] C:\WINDOWS\iptm32.exe
O4 - HKLM\..\RunOnce: [appxs.exe] C:\WINDOWS\system32\appxs.exe
O4 - HKLM\..\RunOnce: [d3dm32.exe] C:\WINDOWS\system32\d3dm32.exe
O4 - HKLM\..\RunOnce: [appun32.exe] C:\WINDOWS\system32\appun32.exe
O4 - HKLM\..\RunOnce: [creu.exe] C:\WINDOWS\system32\creu.exe
O4 - HKLM\..\RunOnce: [atloo.exe] C:\WINDOWS\atloo.exe
O4 - HKLM\..\RunOnce: [iebj32.exe] C:\WINDOWS\system32\iebj32.exe
O4 - HKLM\..\RunOnce: [crii.exe] C:\WINDOWS\system32\crii.exe
O4 - HKLM\..\RunOnce: [apioc.exe] C:\WINDOWS\apioc.exe
O4 - HKLM\..\RunOnce: [d3vh.exe] C:\WINDOWS\system32\d3vh.exe
O4 - HKLM\..\RunOnce: [ipab.exe] C:\WINDOWS\system32\ipab.exe
O4 - HKLM\..\RunOnce: [crkm32.exe] C:\WINDOWS\system32\crkm32.exe
O4 - HKLM\..\RunOnce: [atldb.exe] C:\WINDOWS\system32\atldb.exe
O4 - HKLM\..\RunOnce: [nettl.exe] C:\WINDOWS\system32\nettl.exe
O4 - HKLM\..\RunOnce: [netmr.exe] C:\WINDOWS\netmr.exe
O4 - HKLM\..\RunOnce: [iezk.exe] C:\WINDOWS\system32\iezk.exe
O4 - HKLM\..\RunOnce: [sdkwo.exe] C:\WINDOWS\system32\sdkwo.exe
O4 - HKLM\..\RunOnce: [apivz32.exe] C:\WINDOWS\system32\apivz32.exe
O4 - HKLM\..\RunOnce: [sdkki32.exe] C:\WINDOWS\system32\sdkki32.exe
O4 - HKLM\..\RunOnce: [ipfo32.exe] C:\WINDOWS\system32\ipfo32.exe
O4 - HKLM\..\RunOnce: [sdkrx.exe] C:\WINDOWS\sdkrx.exe
O4 - HKLM\..\RunOnce: [sysnv32.exe] C:\WINDOWS\sysnv32.exe
O4 - HKLM\..\RunOnce: [netpb.exe] C:\WINDOWS\system32\netpb.exe
O4 - HKLM\..\RunOnce: [sdkdb.exe] C:\WINDOWS\sdkdb.exe
O4 - HKLM\..\RunOnce: [mfcyd32.exe] C:\WINDOWS\mfcyd32.exe
O4 - HKLM\..\RunOnce: [appfk.exe] C:\WINDOWS\system32\appfk.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PowerReg Scheduler.exe
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1100384263687
O17 - HKLM\System\CCS\Services\Tcpip\..\{82885F72-3646-4E49-B714-35D795F0F5F2}: NameServer = 129.79.1.1 129.79.5.100
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\nthh.exe" /s (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Okay, I tried a few different trojan horse tools, and it seemed to help -Ewigo and Trojan hunter. However, they passed over a few. It seems that there are programs listed in the O4 line that are trojans but get passed over, at least that's what the online HijackThis analyzers suggest, and upon further inspection on my own they seem to be correct. After deleting one of them that was actively running i was able to keep my browser homepage the same and had no new R0,R1,R3, or O4 lines appear in safe mode at least, even between reboots. However, when i loaded back into normal mode, sure enough i had a couple of new 04's and all the old R0's, R1's, and R3's were back again (. It seems to me that i should be able to just delete the 04 lines with ntur.exe, nthh.exe, and appxs.exe which are supposedly trojans, but i'm not sure, furthermore, every time i reboot i'm getting more of these little .exe files that the analyzer is labeling trojans, even without connecting to the internet. Are they spawning? If i delete them all will they finally go away (or are there some i should keep)? Please advise.

My Latest log without anything removed::

Logfile of HijackThis v1.99.1
Scan saved at 4:11:06 AM, on 5/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\system32\carpserv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\ntur.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\CMMON32.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\gvjwu.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\gvjwu.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\gvjwu.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\gvjwu.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\gvjwu.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\gvjwu.dll/sp.html#37049
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.iub.edu"); (C:\Documents and Settings\Casey\Application Data\Mozilla\Profiles\default\0nrbdnyx.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Casey\Application Data\Mozilla\Profiles\default\0nrbdnyx.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {BD9F01E8-BBEC-4791-99A6-0B3141961A1C} - C:\WINDOWS\system32\mfcde32.dll
O2 - BHO: Class - {FA6A4655-C13C-BF9A-C97E-513B7A9A010A} - C:\WINDOWS\system32\apijv32.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ntur.exe] C:\WINDOWS\ntur.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\RunOnce: [nthh.exe] C:\WINDOWS\system32\nthh.exe
O4 - HKLM\..\RunOnce: [appxs.exe] C:\WINDOWS\system32\appxs.exe
O4 - HKLM\..\RunOnce: [adduu32.exe] C:\WINDOWS\adduu32.exe
O4 - HKLM\..\RunOnce: [appxj32.exe] C:\WINDOWS\system32\appxj32.exe
O4 - HKLM\..\RunOnce: [ntou32.exe] C:\WINDOWS\ntou32.exe
O4 - HKLM\..\RunOnce: [javaxr.exe] C:\WINDOWS\javaxr.exe
O4 - HKLM\..\RunOnce: [apigb32.exe] C:\WINDOWS\apigb32.exe
O4 - HKLM\..\RunOnce: [appoy32.exe] C:\WINDOWS\system32\appoy32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PowerReg Scheduler.exe
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1100384263687
O17 - HKLM\System\CCS\Services\Tcpip\..\{82885F72-3646-4E49-B714-35D795F0F5F2}: NameServer = 129.79.1.1 129.79.5.100
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\nthh.exe" /s (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Hello copperfox3c, welcome to the TC.

Please save these instructions to a text file in Wordpad or print them out because we will be restarting in Safe Mode and you will have no Internet Connection
  • Download CWShredder.
  • Save CWShredder.exe to a convenient location.
  • Please Do Not Use It Yet.
  • Download AboutBuster.
  • Unzip AboutBuster.zip and it will install in it's own folder.
  • Double-click on AboutBuster.exe and then click 'OK' then 'Update'
  • Click "Check For Update" and then "Download Update".
  • Click "Exit"
  • Please Do Not Use It Yet.
Disconnect From The Internet

Boot into Safe Mode:
Restart your computer and tap F8 repeatedly while booting up and choose Safe Mode at the menu.

In Safe Mode Please Clean with CWShredder
  • Please Double-click on CWShredder.exe.
  • Click "Fix ->" and click "OK" at the prompt.
  • CWShredder will scan and clean your system of CWS files.
  • Click "Next->" and then "Exit".
In Safe Mode Please Use AboutBuster
  • Please Double-click on AboutBuster.exe.
  • Click "OK" then "Start" and then "OK" to allow AboutBuster to scan for all bad files.
  • Click "Yes" when About Buster asks if you will allow it to shutdown explorer.exe.
  • Allow AboutBuster to scan for all malicious files.
  • Repeat the scan if it asks to do another.
  • After the scan, click "Save Log". Post the log in your next post as it is necessary to make sure all has been cleaned
  • Then Click "Exit"
This infection often deletes necessary system files.
Reboot your computer back into normal mode so that we can see if any files need to be restored.
  • This infection deletes the windows file, shell.dll.

    If you are using XP,2000, or NT please download shell.dll from here: shell-dll.zip. Once the file is downloaded uncompress the zip file and copy shell.dll to the following locations:
    C:\Windows\system32
    C:\Windows\system


    If you are using Windows 98/ME please download shell.dll from here: shell98-dll.zip. Once the file is downloaded uncompress the zip file and copy shell.dll to the following locations
    C:\Windows\system
  • Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original deleted Hosts file.
  • If you have Spybot S&D installed you will also need to replace one file. Go here: Merijn's Files (sdhelper) and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy). Then click Start > Run > regsvr32 "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" and press the OK button
  • If you are using Windows 95, 98, or ME it is possible that the malware deleted your control.exe. Please check for the existence of this file by going to to Merijn Files control.exe and examine where the file should be for your operating system. If the file is missing then download the appropriate file and place it in the proper place according to this information.
  • There are several other files that are not targeted as often as the above, but new copies of them can be downloaded from
    Merijn Files
Online Antivirus Scan
  • Please go to The TrendMicro Housecall website.
  • Allow it to scan and fix anything that it finds.
  • Please Clean out temporary files:
  • Start> Run> then type cleanmgr and click enter
  • Please put a check mark beside Temporary Files, Temporary Internet Files, and Recycle Bin
  • Let cleanmgr scan your system and remove the files indicated
Reboot and Post a New HijackThis Log and your About Buster Log in this thread, using Add Reply to see what is left to clean.
Logfile of HijackThis v1.99.1
Scan saved at 2:26:31 PM, on 5/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\system32\carpserv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\CMMON32.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iub.edu/
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.iub.edu"); (C:\Documents and Settings\Casey\Application Data\Mozilla\Profiles\default\0nrbdnyx.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Casey\Application Data\Mozilla\Profiles\default\0nrbdnyx.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1100384263687
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{82885F72-3646-4E49-B714-35D795F0F5F2}: NameServer = 129.79.1.1 129.79.5.100
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe






Scanned at: 6:11:53 PM on: 5/28/2005


– Scan 1 —————————
About:Buster Version 4.0
Reference List : 25


Removed Data Streams:
C:\WINDOWS\KB810243.log:bvenv
C:\WINDOWS\KB839643-DirectX9.log:twzzb
C:\WINDOWS\KB839645.log:idtug
C:\WINDOWS\Sti_Trace.log:hzotc


Removed 2 Random Key Entries
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset… Done!

– Scan 2 —————————
About:Buster Version 4.0
Reference List : 25


Removed Data Streams:
C:\WINDOWS\KB810243.log:bvenv
C:\WINDOWS\KB839643-DirectX9.log:twzzb
C:\WINDOWS\KB839645.log:idtug
C:\WINDOWS\Sti_Trace.log:hzotc


Attempted Clean Of Temp folder.
Pages Reset… Done!
Good Job :thumbup:


Log looks good :D :thumbup: How is it running any issues?

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Click Start> My Computer, select the Tools menu and then Folder Options, after the new window appears select the View tab…]
This time select the: Restore Defaults
Select: Apply, and click OK




If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D
Thanks for the help. The computer is running fine. I can't see any issues at the moment. I have a couple of anti-virus programs and use both ad-aware and spybot regularly, as well as have all the windows security updates. Most things don't get through, and i've never before had a problem like this. The little bugger got through anyway, and before i could react had downloaded about 200 trojan horses onto my computer and a whole slew of things had been altered. Furthermore it evaded detection by all my AV and anti-spyware and even was impervious to the CWS shredder program (after initially showing up there it simply disappeared, the Shredder claiming it was fixed but really it just couldn't detect it anymore), among other programs i downloaded. In the end it wasted a whole bunch of my time and required hours of work to fix manually, not very cool if you ask me. On the other hand, i traced back the ip of the link associated with the hijacked page to Go Daddy Software Inc. of 14455 N Hayden Rd suite 226 in Scottsdale, AZ. Oddly enough they peddle and promote anti-spyware programs and services.

Go Daddy Software Inc. of 14455 N Hayden Rd suite 226 in Scottsdale, AZ. Oddly enough they peddle and promote anti-spyware programs and services

. Sounds about right.

Great job :thumbup:

You're more then welcome.
Glad we were able to help :wavey:





If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI