This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.Win32.Agent.em

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi.
I have f-secure installed on my computer and I get the message that I am infected with a trojan. It is not possible to desinfect with f-secure but it is possible to delete it. The problem is that it is coming back all the time.
I have runned spybot and Adaware many times, each session ended with a reboot.
I am sending my hijack this log and I hope someone can help

Dont really know if this can be fixed with Hijack this, or how or where to post this guestion but hope you can help

Logfile of HijackThis v1.99.1
Scan saved at 18:07:29, on 17.06.05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAMFILER\F-SECURE\COMMON\FSMA32.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSMB32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FCH32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FNRB32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FAMEH32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSGK32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FIH32.EXE
C:\PROGRAMFILER\F-SECURE\ANTI-VIRUS\FSAV32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\PROGRAMFILER\HP\SMART\SMARTALERTS.EXE
C:\PROGRAMFILER\HEWLETT-PACKARD\UTVIDET TASTATUR\HPMMKBD.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSM32.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\PROGRAMFILER\LOGITECH\IMAGESTUDIO\LOGITRAY.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAMFILER\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAMFILER\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAMFILER\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAMFILER\WINZIP\WZQKPICK.EXE
C:\PROGRAMFILER\WINDOWS MEDIA COMPONENTS\ENCODER\WMENCAGT.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
D:\MINE DOKUMENTER\ULRIK\PROG\SPYSUB.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://209.25.177.187/top/out.cgi?search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\awelo.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\awelo.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\awelo.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\awelo.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\awelo.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\awelo.dll/sp.html#93256
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\awelo.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - Tele2.Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - Default URLSearchHook is missing
F1 - win.ini: run=hpfsched
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMFILER\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Class - {E5BCD11D-CF53-13E8-21A0-55210FBE13D2} - C:\WINDOWS\CRVI.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SoundFusion] RunDll32 cwcprops.cpl,CrystalControlWnd
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [SMARTAlerts] C:\Programfiler\HP\SMART\SMARTAlerts.exe
O4 - HKLM\..\Run: [HpMmKbd] "C:\Programfiler\Hewlett-Packard\Utvidet tastatur\HpMmKbd.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programfiler\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [LVComs] c:\windows\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Programfiler\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Programfiler\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [xopub] C:\WINDOWS\xopub.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAMFILER\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [fsaa] C:\Programfiler\F-Secure\Common\fsaa.exe
O4 - HKLM\..\RunServices: [F-Secure Management Agent] C:\Programfiler\F-Secure\Common\FSMA32.EXE
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [APIOL.EXE] C:\WINDOWS\APIOL.EXE /s
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Mirabilis ICQ] C:\Programfiler\ICQ\NDetect.exe
O4 - Startup: Office Oppstart.lnk = C:\Programfiler\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Hurtigsøk.lnk = C:\Programfiler\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Microsoft Office.lnk = C:\Programfiler\Microsoft Office\Office\OSA9.EXE
O4 - Startup: WinZip Quick Pick.lnk = C:\Programfiler\WinZip\WZQKPICK.EXE
O4 - Startup: Encoder Agent.lnk = C:\Programfiler\Windows Media Components\Encoder\WMENCAGT.EXE
O4 - Startup: SpySubtract.lnk = D:\Mine dokumenter\Ulrik\Prog\SpySub.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O16 - DPF: {D9CA5D65-52BE-4790-BEA3-F3E2F5A76B02} (WebRecomendada Class) - http://62.97.81.200/dll/clickweb.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
Please save these instructions to a text file in Wordpad or print them out because we will be restarting in Safe Mode and you will have no Internet Connection
  • Download CWShredder.
  • Save CWShredder.exe to a convenient location.
  • Please Do Not Use It Yet.
  • Download AboutBuster.
  • Unzip AboutBuster.zip and it will install in it's own folder.
  • Double-click on AboutBuster.exe and then click 'OK' then 'Update'
  • Click "Check For Update" and then "Download Update".
  • Click "Exit"
  • Please Do Not Use It Yet.
Disconnect From The Internet

Boot into Safe Mode:
Restart your computer and tap F8 repeatedly while booting up and choose Safe Mode at the menu.

In Safe Mode Please Clean with CWShredder
  • Please Double-click on CWShredder.exe.
  • Click "Fix ->" and click "OK" at the prompt.
  • CWShredder will scan and clean your system of CWS files.
  • Click "Next->" and then "Exit".
In Safe Mode Please Use AboutBuster
  • Please Double-click on AboutBuster.exe.
  • Click "OK" then "Start" and then "OK" to allow AboutBuster to scan for all bad files.
  • Click "Yes" when About Buster asks if you will allow it to shutdown explorer.exe.
  • Allow AboutBuster to scan for all malicious files.
  • Repeat the scan if it asks to do another.
  • After the scan, click "Save Log". Post the log in your next post as it is necessary to make sure all has been cleaned
  • Then Click "Exit"
This infection often deletes necessary system files.
Reboot your computer back into normal mode so that we can see if any files need to be restored.
  • This infection deletes the windows file, shell.dll.

    If you are using XP,2000, or NT please download shell.dll from here: shell-dll.zip. Once the file is downloaded uncompress the zip file and copy shell.dll to the following locations:
    C:\Windows\system32
    C:\Windows\system


    If you are using Windows 98/ME please download shell.dll from here: shell98-dll.zip. Once the file is downloaded uncompress the zip file and copy shell.dll to the following locations
    C:\Windows\system
  • Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original deleted Hosts file.
  • If you have Spybot S&D installed you will also need to replace one file. Go here: Merijn's Files (sdhelper) and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy). Then click Start > Run > regsvr32 "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" and press the OK button
  • If you are using Windows 95, 98, or ME it is possible that the malware deleted your control.exe. Please check for the existence of this file by going to to Merijn Files control.exe and examine where the file should be for your operating system. If the file is missing then download the appropriate file and place it in the proper place according to this information.
  • There are several other files that are not targeted as often as the above, but new copies of them can be downloaded from
    Merijn Files
Online Antivirus Scan
  • Please go to The TrendMicro Housecall website.
  • Allow it to scan and fix anything that it finds.
  • Please Clean out temporary files:
  • Start> Run> then type cleanmgr and click enter
  • Please put a check mark beside Temporary Files, Temporary Internet Files, and Recycle Bin
  • Let cleanmgr scan your system and remove the files indicated
Reboot and Post a New HijackThis Log and your About Buster Log in this thread, using Add Reply to see what is left to clean.
Ok…this was not easy! I downloaded CWShredder and AboutBuster. I did not manage to update AboutBuster because the process failed. I disconnected from the internet and restarted in safemode. Ran CWShredder but didnt find anything. Ran AboutBuster but dont know if I did it right because the only options when running the program is to ether update or to begin removal. The log can be seen below

AboutBuster 5.0 reference file 28
Scan started on [26.06.05] at [22:40:51]
————————————————
Streams(ADS) not scanned: System not NTFS
————————————————
No Files Found!
————————————————
Scan was ABORTED at 22:40:55


AboutBuster 5.0 reference file 28
Scan started on [26.06.05] at [22:41:46]
————————————————
Streams(ADS) not scanned: System not NTFS
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 22:41:48


AboutBuster 5.0 reference file 28
Scan started on [26.06.05] at [22:43:27]
————————————————
Streams(ADS) not scanned: System not NTFS
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 22:43:30


AboutBuster 5.0 reference file 28
Scan started on [26.06.05] at [22:44:56]
————————————————
Streams(ADS) not scanned: System not NTFS
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 22:44:59


as you can see I tried a couple of times ;)

I also tried to restore the shell.dll but when extracting to C:\Windows\system it failed because the file was in use in another process…so guess its still there then?!

I downloaded the Hoster and restored the original hosts

when I in the end wanted to run the online antivirus scan there was a problem with internet explorer so I was not able to run the scan :(

here is my new HJT log
Logfile of HijackThis v1.99.1
Scan saved at 23:40:18, on 26.06.05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAMFILER\F-SECURE\COMMON\FSMA32.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSMB32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FCH32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FNRB32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FAMEH32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSGK32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FIH32.EXE
C:\PROGRAMFILER\F-SECURE\ANTI-VIRUS\FSAV32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\PROGRAMFILER\HP\SMART\SMARTALERTS.EXE
C:\PROGRAMFILER\HEWLETT-PACKARD\UTVIDET TASTATUR\HPMMKBD.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSM32.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\PROGRAMFILER\LOGITECH\IMAGESTUDIO\LOGITRAY.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAMFILER\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAMFILER\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAMFILER\WINZIP\WZQKPICK.EXE
C:\PROGRAMFILER\WINDOWS MEDIA COMPONENTS\ENCODER\WMENCAGT.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
D:\MINE DOKUMENTER\ULRIK\PROG\SPYSUB.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\APIAO32.EXE
C:\WINDOWS\SYSTEM\APIAO32.EXE
C:\WINDOWS\SYSTEM\APIAO32.EXE
C:\WINDOWS\SYSTEM\APIAO32.EXE
C:\WINDOWS\SYSTEM\APIAO32.EXE
C:\WINDOWS\SYSTEM\APIAO32.EXE
C:\HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://209.25.177.187/top/out.cgi?search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\fydrm.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\fydrm.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\fydrm.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\fydrm.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\fydrm.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\fydrm.dll/sp.html#93256
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\fydrm.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - Tele2.Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - Default URLSearchHook is missing
F1 - win.ini: run=hpfsched
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMFILER\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Class - {E5BCD11D-CF53-13E8-21A0-55210FBE13D2} - C:\WINDOWS\CRVI.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SoundFusion] RunDll32 cwcprops.cpl,CrystalControlWnd
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [SMARTAlerts] C:\Programfiler\HP\SMART\SMARTAlerts.exe
O4 - HKLM\..\Run: [HpMmKbd] "C:\Programfiler\Hewlett-Packard\Utvidet tastatur\HpMmKbd.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programfiler\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [LVComs] c:\windows\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Programfiler\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Programfiler\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [xopub] C:\WINDOWS\xopub.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAMFILER\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\Run: [MSQW.EXE] C:\WINDOWS\MSQW.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [fsaa] C:\Programfiler\F-Secure\Common\fsaa.exe
O4 - HKLM\..\RunServices: [F-Secure Management Agent] C:\Programfiler\F-Secure\Common\FSMA32.EXE
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [APIOL.EXE] C:\WINDOWS\APIOL.EXE /s
O4 - HKLM\..\RunServices: [SDKIH32.EXE] C:\WINDOWS\SYSTEM\SDKIH32.EXE /s
O4 - HKLM\..\RunServices: [D3LM.EXE] C:\WINDOWS\D3LM.EXE /s
O4 - HKLM\..\RunServices: [IPBN.EXE] C:\WINDOWS\IPBN.EXE /s
O4 - HKLM\..\RunServices: [APIAO32.EXE] C:\WINDOWS\SYSTEM\APIAO32.EXE /s
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Mirabilis ICQ] C:\Programfiler\ICQ\NDetect.exe
O4 - Startup: Office Oppstart.lnk = C:\Programfiler\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Hurtigsøk.lnk = C:\Programfiler\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Microsoft Office.lnk = C:\Programfiler\Microsoft Office\Office\OSA9.EXE
O4 - Startup: WinZip Quick Pick.lnk = C:\Programfiler\WinZip\WZQKPICK.EXE
O4 - Startup: Encoder Agent.lnk = C:\Programfiler\Windows Media Components\Encoder\WMENCAGT.EXE
O4 - Startup: SpySubtract.lnk = D:\Mine dokumenter\Ulrik\Prog\SpySub.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O16 - DPF: {D9CA5D65-52BE-4790-BEA3-F3E2F5A76B02} (WebRecomendada Class) - http://62.97.81.200/dll/clickweb.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab

Thank you so much for helping me. As you can se I really need the help :D
b]Download CW-Shredder at the link below: (don't run it yet)
http://cwshredder.net/bin/CWShredder.exe

Download 'SpSeHjfix'. >>> http://www.derbilk.de/SpSeHjfix109.zip

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin


Make sure you know how to boot into - SafeMode

Reboot into safe mode.

Disconnect from the net and Close ALL OPEN PROGRAMS.
Run 'SpSeHjfix'. and click on "Start Disinfection".
When it's finished it will reboot your machine to finish the cleaning process.
The tool creates a log of the fix which will appear in the folder.

Now run the Shredder - Hit The FIX button!

Reboot and repeat the process above.

Reboot and post a fresh HJT log and the log that was created by 'SpSeHjfix'.
I cleaned out the temporary and TIF files. Rebooted into safe mode and ran SpSeHjfix and pressed start. It did not reboot my machine. I ran the Shredder.

here is the log from SpSeHjfix:

(6.27.05 21:18:56) SPSeHjFix started v1.09
(6.27.05 21:18:56) OS: Win98 (4.10.67766222)
(6.27.05 21:18:56) Language: norsk (bokmål)
(6.27.05 21:19:02) Disinfect started
(6.27.05 21:19:02) Bad-Dll(IEP): fydrm.dll
(6.27.05 21:19:02) UBF: 4
(6.27.05 21:19:02) UBB: 1
(6.27.05 21:19:02) UBR: 30
(6.27.05 21:19:02) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://C:\WINDOWS\fydrm.dll/sp.html#93256
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: res://C:\WINDOWS\fydrm.dll/sp.html#93256
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: res://C:\WINDOWS\fydrm.dll/sp.html#93256
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://C:\WINDOWS\fydrm.dll/sp.html#93256
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: res://C:\WINDOWS\fydrm.dll/sp.html#93256
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Page_URL: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Search_URL: res://C:\WINDOWS\fydrm.dll/sp.html#93256
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: res://C:\WINDOWS\fydrm.dll/sp.html#93256
(6.27.05 21:19:02) Stealth-String not found:
(6.27.05 21:19:02) No Files to delete. End without Reboot
(6.27.05 21:19:41) Disinfect started
(6.27.05 21:19:41) Bad-Dll(IEP): fydrm.dll
(6.27.05 21:19:41) UBF: 4
(6.27.05 21:19:41) UBB: 1
(6.27.05 21:19:41) UBR: 30
(6.27.05 21:19:41) Bad IE-pages:
(6.27.05 21:19:41) Stealth-String not found:
(6.27.05 21:19:41) No Files to delete. End without Reboot
(6.27.05 21:19:52) Disinfect started
(6.27.05 21:19:52) Bad-Dll(IEP): fydrm.dll
(6.27.05 21:19:52) UBF: 4
(6.27.05 21:19:52) UBB: 1
(6.27.05 21:19:52) UBR: 30
(6.27.05 21:19:52) Bad IE-pages:
(6.27.05 21:19:52) Stealth-String not found:
(6.27.05 21:19:52) No Files to delete. End without Reboot
(6.27.05 21:19:53) Disinfect started
(6.27.05 21:19:53) Bad-Dll(IEP): fydrm.dll
(6.27.05 21:19:53) UBF: 4
(6.27.05 21:19:53) UBB: 1
(6.27.05 21:19:53) UBR: 30
(6.27.05 21:19:53) Bad IE-pages:
(6.27.05 21:19:53) Stealth-String not found:
(6.27.05 21:19:53) No Files to delete. End without Reboot
(6.27.05 21:19:53) Disinfect started
(6.27.05 21:19:53) Bad-Dll(IEP): fydrm.dll
(6.27.05 21:19:53) UBF: 4
(6.27.05 21:19:53) UBB: 1
(6.27.05 21:19:53) UBR: 30
(6.27.05 21:19:53) Bad IE-pages:
(6.27.05 21:19:53) Stealth-String not found:
(6.27.05 21:19:53) No Files to delete. End without Reboot
(6.27.05 21:19:53) Disinfect started
(6.27.05 21:19:53) Bad-Dll(IEP): fydrm.dll
(6.27.05 21:19:53) UBF: 4
(6.27.05 21:19:53) UBB: 1
(6.27.05 21:19:53) UBR: 30
(6.27.05 21:19:53) Bad IE-pages:
(6.27.05 21:19:53) Stealth-String not found:
(6.27.05 21:19:53) No Files to delete. End without Reboot
(6.27.05 21:19:54) Disinfect started
(6.27.05 21:19:54) Bad-Dll(IEP): fydrm.dll
(6.27.05 21:19:54) UBF: 4
(6.27.05 21:19:54) UBB: 1
(6.27.05 21:19:54) UBR: 30
(6.27.05 21:19:54) Bad IE-pages:
(6.27.05 21:19:54) Stealth-String not found:
(6.27.05 21:19:54) No Files to delete. End without Reboot
(6.27.05 21:20:08) Disinfect started
(6.27.05 21:20:08) Bad-Dll(IEP): fydrm.dll
(6.27.05 21:20:08) UBF: 4
(6.27.05 21:20:08) UBB: 1
(6.27.05 21:20:08) UBR: 30
(6.27.05 21:20:08) Bad IE-pages:
(6.27.05 21:20:08) Stealth-String not found:
(6.27.05 21:20:08) No Files to delete. End without Reboot
(6.27.05 21:21:18) SPSeHjFix 2nd Step
(6.27.05 21:21:18) RunServicesOnce-Key: (edited)
(6.27.05 21:21:23) Cleaned


(6.27.05 21:21:49) SPSeHjFix started v1.09
(6.27.05 21:21:49) OS: Win98 (4.10.67766222)
(6.27.05 21:21:49) Language: norsk (bokmål)
(6.27.05 21:21:50) Disinfect started
(6.27.05 21:21:50) Bad-Dll(IEP): (not found)
(6.27.05 21:21:50) Bad-Dll(IEP) in BHO: (not found)
(6.27.05 21:21:50) UBF: 4
(6.27.05 21:21:50) UBB: 1
(6.27.05 21:21:50) UBR: 30
(6.27.05 21:21:50) Bad IE-pages:
(6.27.05 21:21:50) Stealth-String not found:
(6.27.05 21:21:50) Not infected->END


(6.27.05 21:50:25) SPSeHjFix started v1.09
(6.27.05 21:50:25) OS: Win98 (4.10.67766222)
(6.27.05 21:50:25) Language: norsk (bokmål)
(6.27.05 21:50:27) Disinfect started
(6.27.05 21:50:27) Bad-Dll(IEP): irgpw.dll
(6.27.05 21:50:27) UBF: 4
(6.27.05 21:50:27) UBB: 1
(6.27.05 21:50:27) UBR: 30
(6.27.05 21:50:27) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://C:\WINDOWS\system\irgpw.dll/sp.html#93256
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: res://C:\WINDOWS\system\irgpw.dll/sp.html#93256
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: res://C:\WINDOWS\system\irgpw.dll/sp.html#93256
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://C:\WINDOWS\system\irgpw.dll/sp.html#93256
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: res://C:\WINDOWS\system\irgpw.dll/sp.html#93256
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Page_URL: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Search_URL: res://C:\WINDOWS\system\irgpw.dll/sp.html#93256
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: res://C:\WINDOWS\system\irgpw.dll/sp.html#93256
(6.27.05 21:50:27) Stealth-String not found:
(6.27.05 21:50:27) No Files to delete. End without Reboot
(6.27.05 21:50:59) Disinfect started
(6.27.05 21:50:59) Bad-Dll(IEP): irgpw.dll
(6.27.05 21:50:59) UBF: 4
(6.27.05 21:50:59) UBB: 1
(6.27.05 21:50:59) UBR: 30
(6.27.05 21:50:59) Bad IE-pages:
(6.27.05 21:50:59) Stealth-String not found:
(6.27.05 21:50:59) No Files to delete. End without Reboot
(6.27.05 21:51:24) Disinfect started
(6.27.05 21:51:24) Bad-Dll(IEP): irgpw.dll
(6.27.05 21:51:24) UBF: 4
(6.27.05 21:51:24) UBB: 1
(6.27.05 21:51:24) UBR: 30
(6.27.05 21:51:24) Bad IE-pages:
(6.27.05 21:51:24) Stealth-String not found:
(6.27.05 21:51:24) No Files to delete. End without Reboot
(6.27.05 21:51:25) Disinfect started
(6.27.05 21:51:25) Bad-Dll(IEP): irgpw.dll
(6.27.05 21:51:25) UBF: 4
(6.27.05 21:51:25) UBB: 1
(6.27.05 21:51:25) UBR: 30
(6.27.05 21:51:25) Bad IE-pages:
(6.27.05 21:51:25) Stealth-String not found:
(6.27.05 21:51:25) No Files to delete. End without Reboot
(6.27.05 21:51:26) Disinfect started
(6.27.05 21:51:26) Bad-Dll(IEP): irgpw.dll
(6.27.05 21:51:26) UBF: 4
(6.27.05 21:51:26) UBB: 1
(6.27.05 21:51:26) UBR: 30
(6.27.05 21:51:26) Bad IE-pages:
(6.27.05 21:51:26) Stealth-String not found:
(6.27.05 21:51:26) No Files to delete. End without Reboot
(6.27.05 21:51:26) Disinfect started
(6.27.05 21:51:26) Bad-Dll(IEP): irgpw.dll
(6.27.05 21:51:26) UBF: 4
(6.27.05 21:51:26) UBB: 1
(6.27.05 21:51:26) UBR: 30
(6.27.05 21:51:26) Bad IE-pages:
(6.27.05 21:51:26) Stealth-String not found:
(6.27.05 21:51:26) No Files to delete. End without Reboot
(6.27.05 21:51:26) Disinfect started
(6.27.05 21:51:26) Bad-Dll(IEP): irgpw.dll
(6.27.05 21:51:26) UBF: 4
(6.27.05 21:51:26) UBB: 1
(6.27.05 21:51:26) UBR: 30
(6.27.05 21:51:26) Bad IE-pages:
(6.27.05 21:51:26) Stealth-String not found:
(6.27.05 21:51:26) No Files to delete. End without Reboot

ran it a couple of times because nothing seemed to happen.

here is my new HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 22:06:25, on 27.06.05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAMFILER\F-SECURE\COMMON\FSMA32.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSMB32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FCH32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FNRB32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FAMEH32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSGK32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FIH32.EXE
C:\PROGRAMFILER\F-SECURE\ANTI-VIRUS\FSAV32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\PROGRAMFILER\HP\SMART\SMARTALERTS.EXE
C:\PROGRAMFILER\HEWLETT-PACKARD\UTVIDET TASTATUR\HPMMKBD.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSM32.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\PROGRAMFILER\LOGITECH\IMAGESTUDIO\LOGITRAY.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAMFILER\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAMFILER\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAMFILER\WINZIP\WZQKPICK.EXE
C:\PROGRAMFILER\WINDOWS MEDIA COMPONENTS\ENCODER\WMENCAGT.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
D:\MINE DOKUMENTER\ULRIK\PROG\SPYSUB.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://209.25.177.187/top/out.cgi?search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wisjj.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wisjj.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\wisjj.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wisjj.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wisjj.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\wisjj.dll/sp.html#93256
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\wisjj.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - Tele2.Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - Default URLSearchHook is missing
F1 - win.ini: run=hpfsched
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMFILER\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Class - {E5BCD11D-CF53-13E8-21A0-55210FBE13D2} - C:\WINDOWS\CRVI.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SoundFusion] RunDll32 cwcprops.cpl,CrystalControlWnd
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [SMARTAlerts] C:\Programfiler\HP\SMART\SMARTAlerts.exe
O4 - HKLM\..\Run: [HpMmKbd] "C:\Programfiler\Hewlett-Packard\Utvidet tastatur\HpMmKbd.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programfiler\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [LVComs] c:\windows\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Programfiler\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Programfiler\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [xopub] C:\WINDOWS\xopub.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAMFILER\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\Run: [MSQW.EXE] C:\WINDOWS\MSQW.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [fsaa] C:\Programfiler\F-Secure\Common\fsaa.exe
O4 - HKLM\..\RunServices: [F-Secure Management Agent] C:\Programfiler\F-Secure\Common\FSMA32.EXE
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [APIOL.EXE] C:\WINDOWS\APIOL.EXE /s
O4 - HKLM\..\RunServices: [SDKIH32.EXE] C:\WINDOWS\SYSTEM\SDKIH32.EXE /s
O4 - HKLM\..\RunServices: [D3LM.EXE] C:\WINDOWS\D3LM.EXE /s
O4 - HKLM\..\RunServices: [IPBN.EXE] C:\WINDOWS\IPBN.EXE /s
O4 - HKLM\..\RunServices: [APIAO32.EXE] C:\WINDOWS\SYSTEM\APIAO32.EXE /s
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Mirabilis ICQ] C:\Programfiler\ICQ\NDetect.exe
O4 - HKCU\..\RunServices: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\RunServices: [Mirabilis ICQ] C:\Programfiler\ICQ\NDetect.exe
O4 - Startup: Office Oppstart.lnk = C:\Programfiler\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Hurtigsøk.lnk = C:\Programfiler\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Microsoft Office.lnk = C:\Programfiler\Microsoft Office\Office\OSA9.EXE
O4 - Startup: WinZip Quick Pick.lnk = C:\Programfiler\WinZip\WZQKPICK.EXE
O4 - Startup: Encoder Agent.lnk = C:\Programfiler\Windows Media Components\Encoder\WMENCAGT.EXE
O4 - Startup: SpySubtract.lnk = D:\Mine dokumenter\Ulrik\Prog\SpySub.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O16 - DPF: {D9CA5D65-52BE-4790-BEA3-F3E2F5A76B02} (WebRecomendada Class) - http://62.97.81.200/dll/clickweb.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab

Thanks for all help so far!
my new hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 10:10:43, on 21.07.05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAMFILER\F-SECURE\COMMON\FSMA32.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSMB32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FCH32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FNRB32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FAMEH32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSGK32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FIH32.EXE
C:\PROGRAMFILER\F-SECURE\ANTI-VIRUS\FSAV32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\PROGRAMFILER\HP\SMART\SMARTALERTS.EXE
C:\PROGRAMFILER\HEWLETT-PACKARD\UTVIDET TASTATUR\HPMMKBD.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSM32.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\PROGRAMFILER\LOGITECH\IMAGESTUDIO\LOGITRAY.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAMFILER\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAMFILER\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAMFILER\WINZIP\WZQKPICK.EXE
C:\PROGRAMFILER\WINDOWS MEDIA COMPONENTS\ENCODER\WMENCAGT.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
D:\MINE DOKUMENTER\ULRIK\PROG\SPYSUB.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://209.25.177.187/top/out.cgi?search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wisjj.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wisjj.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\wisjj.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wisjj.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wisjj.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\wisjj.dll/sp.html#93256
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\wisjj.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - Tele2.Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - Default URLSearchHook is missing
F1 - win.ini: run=hpfsched
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMFILER\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Class - {E5BCD11D-CF53-13E8-21A0-55210FBE13D2} - C:\WINDOWS\CRVI.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SoundFusion] RunDll32 cwcprops.cpl,CrystalControlWnd
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [SMARTAlerts] C:\Programfiler\HP\SMART\SMARTAlerts.exe
O4 - HKLM\..\Run: [HpMmKbd] "C:\Programfiler\Hewlett-Packard\Utvidet tastatur\HpMmKbd.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programfiler\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [LVComs] c:\windows\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Programfiler\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Programfiler\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [xopub] C:\WINDOWS\xopub.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAMFILER\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\Run: [MSQW.EXE] C:\WINDOWS\MSQW.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [fsaa] C:\Programfiler\F-Secure\Common\fsaa.exe
O4 - HKLM\..\RunServices: [F-Secure Management Agent] C:\Programfiler\F-Secure\Common\FSMA32.EXE
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [APIOL.EXE] C:\WINDOWS\APIOL.EXE /s
O4 - HKLM\..\RunServices: [SDKIH32.EXE] C:\WINDOWS\SYSTEM\SDKIH32.EXE /s
O4 - HKLM\..\RunServices: [D3LM.EXE] C:\WINDOWS\D3LM.EXE /s
O4 - HKLM\..\RunServices: [IPBN.EXE] C:\WINDOWS\IPBN.EXE /s
O4 - HKLM\..\RunServices: [APIAO32.EXE] C:\WINDOWS\SYSTEM\APIAO32.EXE /s
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Mirabilis ICQ] C:\Programfiler\ICQ\NDetect.exe
O4 - Startup: Office Oppstart.lnk = C:\Programfiler\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Hurtigsøk.lnk = C:\Programfiler\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Microsoft Office.lnk = C:\Programfiler\Microsoft Office\Office\OSA9.EXE
O4 - Startup: WinZip Quick Pick.lnk = C:\Programfiler\WinZip\WZQKPICK.EXE
O4 - Startup: Encoder Agent.lnk = C:\Programfiler\Windows Media Components\Encoder\WMENCAGT.EXE
O4 - Startup: SpySubtract.lnk = D:\Mine dokumenter\Ulrik\Prog\SpySub.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O16 - DPF: {D9CA5D65-52BE-4790-BEA3-F3E2F5A76B02} (WebRecomendada Class) - http://62.97.81.200/dll/clickweb.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
I ran CWShredder in safe mode.

I successfully updated AboutBuster and here is the log from the scan:

AboutBuster 5.0 reference file 31
Scan started on [25.07.05] at [13:44:14]
————————————————
Streams(ADS) not scanned: System not NTFS
————————————————
Removed File! : C:\Windows\jqebbf.dat
Error Removing ! : C:\Windows\crvi.dll
Removed File! : C:\Windows\oepor.dat
Removed File! : C:\Windows\qwtptb.dat
Error Removing ! : C:\Windows\msqw.exe
Removed File! : C:\Windows\jgtfwo.dat
Removed File! : C:\Windows\xgvhx.dll
————————————————
Scan was COMPLETED SUCCESSFULLY at 13:55:06


I rebooted and ran HijackThis

Logfile of HijackThis v1.99.1
Scan saved at 14:08:07, on 25.07.05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAMFILER\F-SECURE\COMMON\FSMA32.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSMB32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FCH32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FNRB32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FAMEH32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSGK32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FIH32.EXE
C:\PROGRAMFILER\F-SECURE\ANTI-VIRUS\FSAV32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\PROGRAMFILER\HP\SMART\SMARTALERTS.EXE
C:\PROGRAMFILER\HEWLETT-PACKARD\UTVIDET TASTATUR\HPMMKBD.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSM32.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\PROGRAMFILER\LOGITECH\IMAGESTUDIO\LOGITRAY.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAMFILER\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAMFILER\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAMFILER\WINZIP\WZQKPICK.EXE
C:\PROGRAMFILER\WINDOWS MEDIA COMPONENTS\ENCODER\WMENCAGT.EXE
D:\MINE DOKUMENTER\ULRIK\PROG\SPYSUB.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://209.25.177.187/top/out.cgi?search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\rzjrr.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\rzjrr.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\rzjrr.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\rzjrr.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\rzjrr.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\rzjrr.dll/sp.html#93256
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\rzjrr.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - Tele2.Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - Default URLSearchHook is missing
F1 - win.ini: run=hpfsched
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMFILER\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Class - {E5BCD11D-CF53-13E8-21A0-55210FBE13D2} - C:\WINDOWS\CRVI.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SoundFusion] RunDll32 cwcprops.cpl,CrystalControlWnd
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [SMARTAlerts] C:\Programfiler\HP\SMART\SMARTAlerts.exe
O4 - HKLM\..\Run: [HpMmKbd] "C:\Programfiler\Hewlett-Packard\Utvidet tastatur\HpMmKbd.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programfiler\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [LVComs] c:\windows\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Programfiler\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Programfiler\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [xopub] C:\WINDOWS\xopub.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAMFILER\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [fsaa] C:\Programfiler\F-Secure\Common\fsaa.exe
O4 - HKLM\..\RunServices: [F-Secure Management Agent] C:\Programfiler\F-Secure\Common\FSMA32.EXE
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [APIOL.EXE] C:\WINDOWS\APIOL.EXE /s
O4 - HKLM\..\RunServices: [SDKIH32.EXE] C:\WINDOWS\SYSTEM\SDKIH32.EXE /s
O4 - HKLM\..\RunServices: [D3LM.EXE] C:\WINDOWS\D3LM.EXE /s
O4 - HKLM\..\RunServices: [IPBN.EXE] C:\WINDOWS\IPBN.EXE /s
O4 - HKLM\..\RunServices: [APIAO32.EXE] C:\WINDOWS\SYSTEM\APIAO32.EXE /s
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Mirabilis ICQ] C:\Programfiler\ICQ\NDetect.exe
O4 - Startup: Office Oppstart.lnk = C:\Programfiler\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Hurtigsøk.lnk = C:\Programfiler\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Microsoft Office.lnk = C:\Programfiler\Microsoft Office\Office\OSA9.EXE
O4 - Startup: WinZip Quick Pick.lnk = C:\Programfiler\WinZip\WZQKPICK.EXE
O4 - Startup: Encoder Agent.lnk = C:\Programfiler\Windows Media Components\Encoder\WMENCAGT.EXE
O4 - Startup: SpySubtract.lnk = D:\Mine dokumenter\Ulrik\Prog\SpySub.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O16 - DPF: {D9CA5D65-52BE-4790-BEA3-F3E2F5A76B02} (WebRecomendada Class) - http://62.97.81.200/dll/clickweb.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab

Thank you for all help so far!
runned dll compare and here is the log * DLLCompare Log version(1.0.0.127) Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ O^E says: "There were no files found :)" ________________________________________________ 857 items found: 857 files, 0 directories. Total of file sizes: 149 721 064 bytes 142,78 M ——————–End log——————— do we have any progress at all? :huh:
Please diable SpySubtract.


(the reason Wordpad was chosen is that Notepad is often deleted by this variant)

Please save these instructions to WordPad so that you have them accessible while following the steps. You also may want to print out these directions as the Internet will not be available. You must disconnect from the internet totally, as staying connected while fixing will prevent the fix from working. Also please keep Internet Explorer and Outlook Express closed throughout as opening them will reinstall the infection. Read through all the instructions so that you can ask any questions now, before you disconnect from the Internet.

Close Outlook Express and Internet Explorer for the duration of this fix

Please continue with the next steps and if you run into any problems with the current one, just keep going through the list step by step. Just be sure to let us know what the problem was when you finally reply.



Step#1:Make Sure Hidden Files Are Visible
  • Please make sure you can view all Hidden Files by choosing the instructions for your Windows OS.

Step#2:Download and Update CWShredder
  • Download CWShredder.Do Not Use It Yet
  • Save CWShredder.exe to a convenient location.
  • make sure it is up to date.

Step#3:Download DllCompare
Step#4:Download Killbox
  • Download the Killbox.Do Not Use It Yet
  • Unzip the contents of KillBox.zip to a convenient location.
Step#5:Download About Buster
  • Please download About:Buster from here: Do Not Use It Yet
  • About Buster.
  • extract it to c:\aboutbuster.
  • update. to latest definitions


Please disconnect from the Internet and unplug your modem for the duration of this fix



Step#6:Reboot To Safe Mode

Reboot your computer into Safe Mode by tapping F8 while booting up and continue for the rest of the fix in SAFE MODE



Step#7: Use CWShredder
  • Open CWShredder.exe.
  • Click "Fix ->" and click "OK" at the prompt.
  • CWShredder will scan and clean your system of CWS files.
  • Click "Next->" and then "Exit".
  • REBOOT back into Safe Mode by tapping F8 while booting up.l


Step#8:Use DllCompare
  • Open DllCompare.exe to run the program.
  • Click "Run Locate.com" and it will scan your system for files.
  • Once the scan has finished click "Compare" to compare your files to valid Windows files.
    Files in the upper window have now been verified to "exist", Files in the lower window were not able to be accessed. Very few files should be listed in the lower window when the Compare scan is complete.
  • Once it has finished comparing click " Make a Log of what was found".
  • Click on each of the listed entries in the lower section to select them. Right-click on the file and use the Option Rescan This will cause Windows Find to see if the file does exist, and then it will be removed from the list (to reduce the number of identified files)
  • Click "Yes" at the ‘View Log file’ prompt to view the log.
  • Copy and paste the entire log into your next reply after completing all steps.(saved as log.txt in the DllCompare folder)
  • Click "Exit".

Step#9:Delete Running Processes
  • In Safe Mode delete the Running Processes that have been Identified as being part of the infection. If unable to delete them, see below to use Killbox.
C:\WINDOWS\xopub.exe
C:\WINDOWS\APIOL.EXE
C:\WINDOWS\SYSTEM\SDKIH32.EXE
C:\WINDOWS\D3LM.EXE
C:\WINDOWS\IPBN.EXE
C:\WINDOWS\SYSTEM\APIAO32.EXE



Step#10:Delete Infected Files

Please boot into Safe Mode and delete the following files:C:\WINDOWS\xopub.exe
C:\WINDOWS\APIOL.EXE
C:\WINDOWS\SYSTEM\SDKIH32.EXE
C:\WINDOWS\D3LM.EXE
C:\WINDOWS\IPBN.EXE
C:\WINDOWS\SYSTEM\APIAO32.EXE
C:\WINDOWS\rzjrr.dll
C:\WINDOWS\CRVI.DLL




Step#11:Use Killbox(may not be necessary)
  • If unable to delete files above in safe mode please use KillBox that you downloaded earlier:
  • Open KillBox
  • Highlight the list of names to delete then CTRL-C to copy and then Paste all files into the box "Full Path of File to Delete" .

    C:\WINDOWS\xopub.exe
    C:\WINDOWS\APIOL.EXE
    C:\WINDOWS\SYSTEM\SDKIH32.EXE
    C:\WINDOWS\D3LM.EXE
    C:\WINDOWS\IPBN.EXE
    C:\WINDOWS\SYSTEM\APIAO32.EXE
    C:\WINDOWS\rzjrr.dll
    C:\WINDOWS\CRVI.DLL

  • Choose Delete on Reboot.
  • Click the "Delete File" button which looks like a stop sign.
  • Click "Yes" at the Delete on Reboot prompt.
  • If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.


Step#12:Use HijackThis

Then close all programs and windows and run hijackthis. Put a checkmark next to each of these entries and click 'fix checked' button when ready (some may be gone after uninstalling some programs):



R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://209.25.177.187/top/out.cgi?search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\rzjrr.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\rzjrr.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\rzjrr.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\rzjrr.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\rzjrr.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\rzjrr.dll/sp.html#93256
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\rzjrr.dll/sp.html#93256
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

R3 - Default URLSearchHook is missing

O2 - BHO: Class - {E5BCD11D-CF53-13E8-21A0-55210FBE13D2} - C:\WINDOWS\CRVI.DLL

O4 - HKLM\..\Run: [xopub] C:\WINDOWS\xopub.exe
O4 - HKLM\..\RunServices: [APIOL.EXE] C:\WINDOWS\APIOL.EXE /s
O4 - HKLM\..\RunServices: [SDKIH32.EXE] C:\WINDOWS\SYSTEM\SDKIH32.EXE /s
O4 - HKLM\..\RunServices: [D3LM.EXE] C:\WINDOWS\D3LM.EXE /s
O4 - HKLM\..\RunServices: [IPBN.EXE] C:\WINDOWS\IPBN.EXE /s
O4 - HKLM\..\RunServices: [APIAO32.EXE] C:\WINDOWS\SYSTEM\APIAO32.EXE /s

O16 - DPF: {D9CA5D65-52BE-4790-BEA3-F3E2F5A76B02} (WebRecomendada Class) - http://62.97.81.200/dll/clickweb.cab






Step#13:Use About Buster


This is the step where we will use About:Buster that you had downloaded previously.
  • Navigate to the c:\aboutbuster directory and double-click on aboutbuster.exe
  • When the tool is open press the OK button,
  • then the Start button, then the OK button, and then finally the Yes button.
  • It will start scanning your computer for files. If it asks if you would like to do a second pass, allow it to do so.
  • Post the log file in your next reply


Step#14:Use Registry File
  • Copy the contents of the Quote Box below to Notepad.
  • Name the file as fix.reg
  • Change the Save as Type to All Files
  • and Save it on the desktop

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW]

  • Then double-click on the fix.reg file, and when it prompts to merge say yes, and this will clear some registry entries left behind by the process.

Reboot your computer back to normal mode



Reconnect To The Internet




Step#15:Use HijackThis and Post To Thread In Forum

1. Scan again with HijackThis. We still have a few steps to complete but a log file at this time would be helpful.

2. Post your logs from About Buster, DllCompare and your HijackThis log here in this thread with any questions or problems that you have run into. There are still some steps that are necessary to clear out all of the malware. There will be necessary files that it has deleted that will need to be replaced.

Good Luck!
AboutBuster 5.0 reference file 31
Scan started on [27.07.05] at [13:31:57]
————————————————
Streams(ADS) not scanned: System not NTFS
————————————————
Removed File! : C:\Windows\addan32.exe
Removed File! : C:\Windows\mfcfz32.exe
Removed File! : C:\Windows\iexh32.exe
Removed File! : C:\Windows\javaxy.exe
Removed File! : C:\Windows\sysoy.exe
Removed File! : C:\Windows\sdkgl.exe
Removed File! : C:\Windows\ntar.exe
Removed File! : C:\Windows\addik32.exe
Removed File! : C:\Windows\addjq32.exe
Removed File! : C:\Windows\netvd.exe
Removed File! : C:\Windows\sdkhc32.exe
Removed File! : C:\Windows\atlzv32.exe
Removed File! : C:\Windows\d3mj32.exe
Removed File! : C:\Windows\sdkne.exe
Removed File! : C:\Windows\msqw.exe
Removed File! : C:\Windows\syspz.exe
Removed File! : C:\Windows\sysdq.exe
Removed File! : C:\Windows\winix.exe
Removed File! : C:\Windows\sdkuv32.exe
Removed File! : C:\Windows\d3zx.exe
Removed File! : C:\Windows\apiyf.exe
Removed File! : C:\Windows\d3dh32.exe
Removed File! : C:\Windows\atlzz32.exe
Removed File! : C:\Windows\winni32.exe
Removed File! : C:\Windows\javanq.exe
————————————————
Scan was COMPLETED SUCCESSFULLY at 13:32:15



* DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________

O^E says: "There were no files found :)"
________________________________________________

857 items found: 857 files, 0 directories.
Total of file sizes: 149,721,064 bytes 142.78 M

——————–End log———————


Logfile of HijackThis v1.99.1
Scan saved at 13:46:11, on 27.07.05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAMFILER\F-SECURE\COMMON\FSMA32.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSMB32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FCH32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FNRB32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FAMEH32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSGK32.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FIH32.EXE
C:\PROGRAMFILER\F-SECURE\ANTI-VIRUS\FSAV32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\PROGRAMFILER\HP\SMART\SMARTALERTS.EXE
C:\PROGRAMFILER\HEWLETT-PACKARD\UTVIDET TASTATUR\HPMMKBD.EXE
C:\PROGRAMFILER\F-SECURE\COMMON\FSM32.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\PROGRAMFILER\LOGITECH\IMAGESTUDIO\LOGITRAY.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAMFILER\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAMFILER\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAMFILER\WINZIP\WZQKPICK.EXE
C:\PROGRAMFILER\WINDOWS MEDIA COMPONENTS\ENCODER\WMENCAGT.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - Tele2.Internet
F1 - win.ini: run=hpfsched
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMFILER\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SoundFusion] RunDll32 cwcprops.cpl,CrystalControlWnd
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [SMARTAlerts] C:\Programfiler\HP\SMART\SMARTAlerts.exe
O4 - HKLM\..\Run: [HpMmKbd] "C:\Programfiler\Hewlett-Packard\Utvidet tastatur\HpMmKbd.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programfiler\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [LVComs] c:\windows\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Programfiler\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Programfiler\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAMFILER\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [fsaa] C:\Programfiler\F-Secure\Common\fsaa.exe
O4 - HKLM\..\RunServices: [F-Secure Management Agent] C:\Programfiler\F-Secure\Common\FSMA32.EXE
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Mirabilis ICQ] C:\Programfiler\ICQ\NDetect.exe
O4 - Startup: Office Oppstart.lnk = C:\Programfiler\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Hurtigsøk.lnk = C:\Programfiler\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Microsoft Office.lnk = C:\Programfiler\Microsoft Office\Office\OSA9.EXE
O4 - Startup: WinZip Quick Pick.lnk = C:\Programfiler\WinZip\WZQKPICK.EXE
O4 - Startup: Encoder Agent.lnk = C:\Programfiler\Windows Media Components\Encoder\WMENCAGT.EXE
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab


Questions/problems

- I did not have any entires in the lower window on DllCompare
- I am not sure how to delete running processes. so I handled step #9 and #10 the same way, I tried to find the files and deleted them.
- I did NOT find c:\windows\xopub.exe
- I did NOT find c:\windows\apiol.exe
- I did NOT find c:\windows\rzjrr.dll
- when I tried to start aboutbuster.exe from c:\aboutbuster I got the message: Run time errer '52' Bad file name or number. I went to another directory where I have aboutbuster.exe and runned it from there. I do not recognise the steps for use of aboutbuster but hope the logfile is useable.


Thanks so far!
If you are having any difficulty with Notepad, please go to Merijn's Files and choose 'Windows Files' from the menu on the left hand side of the page. Then choose 'Notepad' from the list and download it to C:\Windows and C:\Windows\System32

Step#1:Check For Deleted Files

Now we need to see if we need to restore some deleted files:
  • Please check for the following files using the Windows Search Engine:
    • control.exe
    • rundll32.exe
    • wmplayer.exe
    • msconfig.exe
    • notepad.exe
    • shell.dll
    • SDHelper.dll
    If any are missing or not working properly then you can download new copies from
    Merijn's Files and following the instructions at that site to have them where they belong for your OS.

  • Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original deleted Hosts file.
  • This infection often deletes some system files that need to be replaced. The most frequent one it deletes is shell.dll in Win2K or XP. In XP there are two copies of this file, one in Windows (WINNT) and one in Windows\System32. It does not delete the one in Windows\System so it does not affect Win9x/ME. If you find it missing, please copy the shell.dll from c:\windows\system32\dllcache into both \Windows (WINNT) and Windows\System32 .
  • The other system file which is most frequently deleted is control.exe. Please check to make sure that you have this file and it is the correct size. If not Please check for the existence of this file by going to to Merijn's Files (sdhelper) and examine where the file should be for your operating system. If the file is missing then download the appropriate file and place it in the proper place according to the information at this website. The control.exe is more often deleted in Win9x/ME.
  • If you have Spybot S&D installed you will also need to replace one file. Go here: Merijn's Files (sdhelper) and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy). Then click Start > Run > regsvr32 "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" and press the OK button

Step#2:Scan With Online AV Scanner

Run an online antivirus scan at:

Trend Micro Online AV

Reboot


Step#3:Scan With HijackThis and Post In Forum

1. Scan again with HijackThis

2. POST your log file to see if there is anything left to fix

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI