This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Another infected PC, please help end my headaches...

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been trying to fix a PC for a friend and am having problems removing all of the trojans and spyware from it. I am using Antivir along with Microsoft Antispyware, Spybot S&D and Ad-aware SE. No matter how many times I scan some of the infected files come back, and Spybot cannot ever remove all of the CollWWW stuff that it finds, even though it says it can after a restart. I have tried everything and cannot get this computer cleaned. Besides all of this I am getting alot of popups even though I am using IE's built in blocker set to high. Please review my Hijackthis log and advise.
Also there are some apps I cannot uninstall from the CP. They are: Home Search Assistant, Search Assistant and Shopping Wizard.

Log:
Logfile of HijackThis v1.99.1
Scan saved at 9:43:54 PM, on 10/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ww3.weatherbug.com/survey/uninstall…D=1800&Version=
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {19925772-DE39-9691-D57F-EDB5A0FE9C94} - C:\WINDOWS\syszu32.dll (file missing)
O2 - BHO: Class - {369847CF-6C33-1F19-CDB0-702AB6C96489} - C:\WINDOWS\system32\mseg32.dll
O2 - BHO: Class - {3B81C91B-4D4F-FD3F-FEDF-7A66D0FF7970} - C:\WINDOWS\system32\mseg32.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: wb - {55BE9F0D-6CAF-4c3e-B125-5A13A8C9D0EC} - C:\WINDOWS\system32\nsmD.dll
O2 - BHO: Class - {7AE7CAC6-2EE1-E959-4E3A-02B4D1889480} - C:\WINDOWS\iexu.dll (file missing)
O2 - BHO: IRiras Class - {95C60327-8E17-44D6-98EB-7EB70CC606DD} - C:\WINDOWS\system32\irastybo.dll
O2 - BHO: Class - {B2499FC4-394E-BB59-F460-5927910CA03B} - C:\WINDOWS\ipwr.dll (file missing)
O2 - BHO: Class - {D843F6EE-4E69-643C-4943-BEFB0BC15E7E} - C:\WINDOWS\msdw.dll (file missing)
O2 - BHO: Class - {E147AAF3-2C0B-3A3F-4FC5-5E61B062F9D9} - C:\WINDOWS\ipby32.dll (file missing)
O2 - BHO: Class - {EF0124CB-C96F-7679-6100-05A3C16A52D7} - C:\WINDOWS\sdkox.dll (file missing)
O4 - HKLM\..\Run: [dzyuuey] C:\WINDOWS\dzyuuey.exe
O4 - HKLM\..\Run: [appit32.exe] C:\WINDOWS\system32\appit32.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [apipg32.exe] C:\WINDOWS\apipg32.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\RunOnce: [crlr32.exe] C:\WINDOWS\system32\crlr32.exe
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\apepbdf.exe
Was able to get rid of a few things. Here is a new log. Thanks in advance.

Logfile of HijackThis v1.99.1
Scan saved at 8:46:25 PM, on 10/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVPersonal\AVGNT.EXE
C:\WINDOWS\dzyuuey.exe
C:\WINDOWS\system32\appve.exe
C:\WINDOWS\system32\addrl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\cnocg.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\cnocg.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\cnocg.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\cnocg.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\cnocg.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\cnocg.dll/sp.html#28129
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {19925772-DE39-9691-D57F-EDB5A0FE9C94} - C:\WINDOWS\syszu32.dll (file missing)
O2 - BHO: Class - {369847CF-6C33-1F19-CDB0-702AB6C96489} - C:\WINDOWS\system32\mseg32.dll
O2 - BHO: Class - {3B81C91B-4D4F-FD3F-FEDF-7A66D0FF7970} - C:\WINDOWS\system32\mseg32.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: wb - {55BE9F0D-6CAF-4c3e-B125-5A13A8C9D0EC} - C:\WINDOWS\system32\nsmD.dll
O2 - BHO: Class - {6B9C3DD2-4CF0-1EBB-83DC-6E15C177098B} - C:\WINDOWS\netbh.dll
O2 - BHO: Class - {7AE7CAC6-2EE1-E959-4E3A-02B4D1889480} - C:\WINDOWS\iexu.dll (file missing)
O2 - BHO: IRiras Class - {95C60327-8E17-44D6-98EB-7EB70CC606DD} - C:\WINDOWS\system32\irastybo.dll
O2 - BHO: Class - {B2499FC4-394E-BB59-F460-5927910CA03B} - C:\WINDOWS\ipwr.dll (file missing)
O2 - BHO: Class - {D843F6EE-4E69-643C-4943-BEFB0BC15E7E} - C:\WINDOWS\msdw.dll (file missing)
O2 - BHO: Class - {E147AAF3-2C0B-3A3F-4FC5-5E61B062F9D9} - C:\WINDOWS\ipby32.dll (file missing)
O2 - BHO: Class - {EF0124CB-C96F-7679-6100-05A3C16A52D7} - C:\WINDOWS\sdkox.dll (file missing)
O2 - BHO: Class - {FA55FE92-9317-0E72-9BED-1211735C089D} - C:\WINDOWS\system32\appbh32.dll
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [dzyuuey] C:\WINDOWS\dzyuuey.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [addrl.exe] C:\WINDOWS\system32\addrl.exe
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted IP range: 206.161.125.149
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\appve.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Hello tmazzullo, welcome to the forum

Download CW-Shredder at the link below: (don't run it yet)
http://www.trendmicro.com/ftp/products/onl…/cwshredder.exe

Download 'SpSeHjfix'. into a folder. (don't run it yet)

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin


Make sure you know how to boot into - SafeMode

Reboot into safe mode.

Disconnect from the net and Close ALL OPEN PROGRAMS.
Run 'SpSeHjfix'. and click on "Start Disinfection".
When it's finished it will reboot your machine to finish the cleaning process.
The tool creates a log of the fix which will appear in the folder.

Now run the Shredder - Hit The FIX button!

Reboot and repeat the process above starting with Reboot in Safe Mode.

Reboot and post a fresh HJT log and the log that was created by 'SpSeHjfix'.




run it in safe mode and run it twice
New logs after instruction above:

HJT Log
Logfile of HijackThis v1.99.1
Scan saved at 9:24:19 PM, on 10/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVPersonal\AVGNT.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\cnocg.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\cnocg.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {3B81C91B-4D4F-FD3F-FEDF-7A66D0FF7970} - C:\WINDOWS\system32\mseg32.dll (file missing)
O2 - BHO: wb - {55BE9F0D-6CAF-4c3e-B125-5A13A8C9D0EC} - C:\WINDOWS\system32\nsmD.dll
O2 - BHO: IRiras Class - {95C60327-8E17-44D6-98EB-7EB70CC606DD} - C:\WINDOWS\system32\irastybo.dll
O2 - BHO: Class - {EF0124CB-C96F-7679-6100-05A3C16A52D7} - C:\WINDOWS\sdkox.dll (file missing)
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted IP range: 206.161.125.149
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


SpSeHj Log:
(10/26/05 9:15:51 PM) SPSeHjFix started v1.1.2
(10/26/05 9:15:51 PM) OS: WinXP Service Pack 2 (5.1.2600)
(10/26/05 9:15:51 PM) Language: english
(10/26/05 9:15:51 PM) Win-Path: C:\WINDOWS
(10/26/05 9:15:51 PM) System-Path: C:\WINDOWS\system32
(10/26/05 9:15:51 PM) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(10/26/05 9:15:57 PM) Disinfection started
(10/26/05 9:15:57 PM) Bad-Dll(IEP): c:\windows\cnocg.dll
(10/26/05 9:15:57 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:15:57 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:15:57 PM) Bad IE-pages:
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\cnocg.dll/sp.html#28129
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: res://c:\windows\cnocg.dll/sp.html#28129
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Page_URL: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Search_URL: res://c:\windows\cnocg.dll/sp.html#28129
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: res://c:\windows\cnocg.dll/sp.html#28129
(10/26/05 9:15:57 PM) Stealth-String not found
(10/26/05 9:15:57 PM) No locked Files to delete. End without Reboot
(10/26/05 9:16:03 PM) Disinfection started
(10/26/05 9:16:03 PM) Bad-Dll(IEP): c:\windows\cnocg.dll
(10/26/05 9:16:03 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:03 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:03 PM) Bad IE-pages: (none)
(10/26/05 9:16:03 PM) Stealth-String not found
(10/26/05 9:16:03 PM) No locked Files to delete. End without Reboot
(10/26/05 9:16:08 PM) Disinfection started
(10/26/05 9:16:08 PM) Bad-Dll(IEP): c:\windows\cnocg.dll
(10/26/05 9:16:08 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:08 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:08 PM) Bad IE-pages: (none)
(10/26/05 9:16:08 PM) Stealth-String not found
(10/26/05 9:16:08 PM) No locked Files to delete. End without Reboot
(10/26/05 9:16:09 PM) Disinfection started
(10/26/05 9:16:09 PM) Bad-Dll(IEP): c:\windows\cnocg.dll
(10/26/05 9:16:09 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:09 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:09 PM) Bad IE-pages: (none)
(10/26/05 9:16:09 PM) Stealth-String not found
(10/26/05 9:16:09 PM) No locked Files to delete. End without Reboot
(10/26/05 9:16:09 PM) Disinfection started
(10/26/05 9:16:09 PM) Bad-Dll(IEP): c:\windows\cnocg.dll
(10/26/05 9:16:09 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:09 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:09 PM) Bad IE-pages: (none)
(10/26/05 9:16:09 PM) Stealth-String not found
(10/26/05 9:16:09 PM) No locked Files to delete. End without Reboot
(10/26/05 9:16:09 PM) Disinfection started
(10/26/05 9:16:09 PM) Bad-Dll(IEP): c:\windows\cnocg.dll
(10/26/05 9:16:09 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:09 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:09 PM) Bad IE-pages: (none)
(10/26/05 9:16:09 PM) Stealth-String not found
(10/26/05 9:16:09 PM) No locked Files to delete. End without Reboot
(10/26/05 9:16:10 PM) Disinfection started
(10/26/05 9:16:10 PM) Bad-Dll(IEP): c:\windows\cnocg.dll
(10/26/05 9:16:10 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:10 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:10 PM) Bad IE-pages: (none)
(10/26/05 9:16:10 PM) Stealth-String not found
(10/26/05 9:16:10 PM) No locked Files to delete. End without Reboot
(10/26/05 9:16:10 PM) Disinfection started
(10/26/05 9:16:10 PM) Bad-Dll(IEP): c:\windows\cnocg.dll
(10/26/05 9:16:10 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:10 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:10 PM) Bad IE-pages: (none)
(10/26/05 9:16:10 PM) Stealth-String not found
(10/26/05 9:16:10 PM) No locked Files to delete. End without Reboot
(10/26/05 9:16:10 PM) Disinfection started
(10/26/05 9:16:10 PM) Bad-Dll(IEP): c:\windows\cnocg.dll
(10/26/05 9:16:10 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:10 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:10 PM) Bad IE-pages: (none)
(10/26/05 9:16:10 PM) Stealth-String not found
(10/26/05 9:16:10 PM) No locked Files to delete. End without Reboot
(10/26/05 9:16:10 PM) Disinfection started
(10/26/05 9:16:10 PM) Bad-Dll(IEP): c:\windows\cnocg.dll
(10/26/05 9:16:10 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:10 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:10 PM) Bad IE-pages: (none)
(10/26/05 9:16:10 PM) Stealth-String not found
(10/26/05 9:16:10 PM) No locked Files to delete. End without Reboot
(10/26/05 9:16:13 PM) Disinfection started
(10/26/05 9:16:13 PM) Bad-Dll(IEP): c:\windows\cnocg.dll
(10/26/05 9:16:13 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:13 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:13 PM) Bad IE-pages: (none)
(10/26/05 9:16:13 PM) Stealth-String not found
(10/26/05 9:16:13 PM) No locked Files to delete. End without Reboot
(10/26/05 9:16:14 PM) Disinfection started
(10/26/05 9:16:14 PM) Bad-Dll(IEP): c:\windows\cnocg.dll
(10/26/05 9:16:14 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:14 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:14 PM) Bad IE-pages: (none)
(10/26/05 9:16:14 PM) Stealth-String not found
(10/26/05 9:16:14 PM) No locked Files to delete. End without Reboot
(10/26/05 9:16:14 PM) Disinfection started
(10/26/05 9:16:14 PM) Bad-Dll(IEP): c:\windows\cnocg.dll
(10/26/05 9:16:14 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:14 PM) UBF: 7 - UBB: 12 - UBR: 5
(10/26/05 9:16:14 PM) Bad IE-pages: (none)
(10/26/05 9:16:14 PM) Stealth-String not found
(10/26/05 9:16:14 PM) No locked Files to delete. End without Reboot

More to do I am sure, thanks again. Please instruct on next step.
I suggest you do this:

Download this file from the link to your desktop.
http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click on the deldomains.inf file and select 'Install'

Once it is finished your Zones should be reset.

Note, if you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection



Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.





Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\cnocg.dll/sp.html#28129

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\cnocg.dll/sp.html#28129

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R3 - Default URLSearchHook is missing

O2 - BHO: Class - {3B81C91B-4D4F-FD3F-FEDF-7A66D0FF7970} - C:\WINDOWS\system32\mseg32.dll (file missing)

O2 - BHO: wb - {55BE9F0D-6CAF-4c3e-B125-5A13A8C9D0EC} - C:\WINDOWS\system32\nsmD.dll

O2 - BHO: IRiras Class - {95C60327-8E17-44D6-98EB-7EB70CC606DD} - C:\WINDOWS\system32\irastybo.dll

O2 - BHO: Class - {EF0124CB-C96F-7679-6100-05A3C16A52D7} - C:\WINDOWS\sdkox.dll (file missing)

O15 - Trusted Zone: *.frame.crazywinnings.com

O15 - Trusted IP range: 206.161.125.149


Close ALL windows and browsers except HijackThis and click "Fix checked"





Restart in Safe Mode:
Restart your computer.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.



Open C:\Windows\Prefetch\ Delete ALL files in this folder.



Do this also if these Temp Folders are part of your OS.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


Next navigate to the C:\Documents and Settings\(EVERY LISTED PROFILE USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty the Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Here is my new HJT log. Computer is running alot better now. The only problem that I can see is that Spybot S&D cannot remove some items still. They are CoolWWWSearch.Feat2DLL, CoolWWWSearch.HomeSearch, CoolWWWSearch.SearchKlick. Is it OK to leave these alone or do I need to remove them. It says it can remove them after a restart but fails.

Logfile of HijackThis v1.99.1
Scan saved at 6:17:39 PM, on 10/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVPersonal\AVGNT.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
CoolWWWSearch.Feat2DLL, CoolWWWSearch.HomeSearch, CoolWWWSearch.SearchKlick

Do a file search for these and delete if found.
Feat2DLL
HomeSearch
SearchKlick
Good Job :thumbup:

Open SpyBot and Select Recovery> Select all backups and then select Purge Selected Items.


Log looks good :D :thumbup: How is it running any issues?

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Click Start> My Computer, select the Tools menu and then Folder Options, after the new window appears select the View tab…]
This time select the: Restore Defaults
Select: Apply, and click OK




If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI