dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
Hi Bob, first of all, there is an anouncement at the top of this forum requesting that all hijackthis logs be posted in the security forum. Someone will probably be moving it there shortly.
Yes. Moving now...
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
Also, Download CWShredder from here & run it. Select the fix button & it will fix everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including Internet Explorer, before running CWShredder. Reboot.
To help prevent this from happening again, install the patches for the vulnerabilities that this hijacker exploits by going here for your critical updates.
Reboot after doing this & post another log please.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
You're still heavily infested. Can you give us the locations (folders) of the infected files that Norton could not fix? That info would help.
Also- most of your problems are coming from the dreaded "about:blank" infection, which can be a nasty beast to remove; search this forum and Google for the keyphrase "about:blank" and you'll find many possible solutions. Try them and tell us the results.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
Just to get your log cleaned up a bit so it's easier to read, close all windows and scan with hjt.
Have it fix all items ending with (file missing)
And these:
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) - http://www.xxxtoolbar.com/ist/softw...006_regular.cab
Scan again and post a new log. I believe you will need to run aboutbuster to finish cleaning this up, but someone else will have to guide you through it.
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
Log's getting better, but there are still some nasties.
Have HJT fix:
- All entries which indicate "(file missing)"
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
O2 - BHO: Band Class - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - C:\WINDOWS\DEALHLPR.DLL
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\BXXS5.DLL
O3 - Toolbar: Begin2Search.com Bar - {52FE5233-367C-4EFB-BDD7-0BE4D212C107} - C:\WINDOWS\SYSTEM\WINB2S32.DLL
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\BXXS5.DLL,DllRun
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\PROGRAM FILES\SIDEFIND\SIDEFIND.DLL
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/05419fb...ip/RdxIE601.cab
O16 - DPF: ConferenceRoom Java Client - http://mail.igl.net:8000/java/cr.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://mirror.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {E62A47D8-74B1-4A93-963A-E5E43B7CC5C2} (UCSearch.ucUCSearch) - http://www.zuvio.com/opnste/UCSearch.CAB
O16 - DPF: v2cab - http://searchmiracle.com/cab/v2cab.cab
- Restart
- Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files".
- Find and delete all of the .dll files mentioned in the HJT entries above.
- Delete the entire C:\Program Files\ISTsvc folder.
- Delete the entire C:\PROGRAM FILES\SIDEFIND folder.
- Empty your Recycle Bin.
- Post'um heap new HJT log.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370