Hi. First of all you need to update hijackthis to version 1.98. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. Remove 1.97 from the folder it is in & replace it with 1.98.
Then, open Task Manager & end process on the following;
Loader.exe
Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. (Not a temporary folder or directly on the desktop (in a folder on the desktop is fine) & not directly on your hard drive). Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {00000000-0000-0000-0000-000000000221} - C:\PROGRA~1\Lycos\IEagent\CSIE.DLL
O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - (no file)
O2 - BHO: (no name) - {00000EF1-0786-4633-87C6-1AA7A44296DA} - (no file)
O4 - HKLM\..\Run: [ClrSchLoader] C:\PROGRA~1\Lycos\IEagent\Loader.exe
O4 - HKLM\..\Run: [Belt] C:\WINNT\Belt.exe
O4 - HKCU\..\Run: [nm2360cp] C:\WINNT\system32\nm2360cp.exe
Reboot into safe mode following the instructions here & navigate to & delete the following if found:
C:\PROGRA~1\Lycos-folder
C:\WINNT\Belt.exe-file
C:\WINNT\system32\nm2360cp.exe
Reboot normally after doing the above then post a fresh log please.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
I have deleted your other thread. Please stay with this one until your problem is resolved.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
First one looks ok. Do this for the other then post another log.
Download CWShredder from here & run it. Select the fix button & it will fix everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including Iinternet Explorer, before running CWShredder. Reboot.
To help prevent this from happening again, install the patches for the vulnerabilities that this hijacker exploits by going here for your critical updates.
Download & instal Adaware from here
& update it before scanning.
In settings under 'scanning,' have it set to
'scan within archives,'
'scan active processes,'
'scan registry,'
'deepscan registry'
'scan my IE Favourites for banned URL's,'
'scan my host's file.'
In 'tweaks' under 'scanning engine' set it to 'unload recognised processes during scanning.'
Also in 'tweaks' under 'cleaning engine' set it to 'Automatically try to unregister objects prior to deletion' & 'let Windows remove files in use at next reboot.'
Select 'activate in-depth scan' before starting scan.
When the scan is finished select 'next.'
Remove what it finds by placing a check in the box to the left of the object. Reboot
Download & instal Spybot S&D from here. Update it before scanning.
After the scan is complete, have spybot fix everything marked RED.
On the page that first opens when you start Spybot there is an option to immunise, you should do this. In the immunise section there is also a link to download Spywareblaster. This program will prevent the install of bad activex controls that it has knowledge of. Download that & you can keep it updated by selecting the same link that you use to download it.
Reboot after doing this & post another log please.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Run Kazaabegone from here. to clear out Kazaa.
Open Task Manager & end process on the following;
[b]oksuninst.exe
Delete this file;
C:\WINDOWS\System32\oksuninst.exe
Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked':
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32/left.html
R3 - URLSearchHook: (no name) - - (no file)
O3 - Toolbar: (no name) - {8FB0F3E2-5193-11d7-9F88-0050FC5441CB} - C:\WINDOWS\SYSTEM32\shdocvw.dll
O3 - Toolbar: (no name) - {8A794988-E7F7-4C8C-97F2-D1D14512F9B4} - (no file)
O4 - HKLM\..\Run: [oksuninst.exe] C:\WINDOWS\System32\oksuninst.exe
O4 - HKCU\..\Run: [oksuninst.exe] C:\WINDOWS\System32\oksuninst.exe
O15 - Trusted Zone: *.teen-me.com
O16 - DPF: {f760cb9e-c60f-4a89-890e-fae8b849493e} -
Reboot & post another log.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Try system restore to take you back before this occurred.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Hit the Windows button on your keyboard & then navigate to [All Programs] [Accessories] [System Tools] [System Restore]. Select Restore my computer to an earlier time. Choose a date that you wish to go back to & click next.
Confirm your selection.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
I am not sure, as I do not have XP. Will endeavour to find out for you. If someone else has the answer, please post :).
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Try clicking on *My Computer* & from there navigate to c:\windows\System32\restore\rstrui.exe & click (or double click) on the rstrui.exe file. Hopefully that will open up system restore for you.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985