First off, I'd like to mention that I'm new to this so I'm not sure if I'm posting correctly. Please advise me if not.

The OS is WinXP Home, SP1
The make and model is Dell, Dimension 4400, P4-1.6G, 384mb RAM

Started having problems after installing Incredimail, may or may not be related.

Had (have?) CWS and Trojan.bookmarker.gen infections, used CWshredder and Norton instructions to get rid of most problems.

I'd like to post my first hijackthis log as well as the current one to make sure I didn't delete something I shouldn't have and to find out what else I need to fix.

Current problem is the .gen keeps coming back. Norton finds it but can't fix it. I go to the temp folder where it says the files are and delete them, but it also says there's a .dll in the System 32 folder but I can't find it; I've even tried the PV runme.bat.

Thanks for any assistance you can offer!

Dani AI

Generated

A short, practical plan to get a useful HijackThis log posted and to track the persistent .gen/.dll that Norton reports.

For : run HijackThis from Safe Mode (press F8 at boot), click "Do a system scan and save a logfile", and paste the entire log as plain text here. Also post the exact filenames and full paths Norton quarantined or reported, and say whether you still see copies in Temp. If you have an earlier HijackThis log, include that too so helpers can compare changes. As noted, also check the forum's "Helping yourself" sticky for posting rules.

Basic troubleshooting workflow (do these before removing entries):

  • Boot to Safe Mode, save and post the full HijackThis log. Do not use the "Fix" buttons until a helper confirms which lines to remove.
  • Use Sysinternals Process Explorer to find which process has the DLL loaded: run Process Explorer as admin, use Find -> Find Handle or DLL and search the DLL name; note the owning process, right-click to close/kill it, then delete or rename the DLL from Safe Mode.
  • Use Sysinternals Autoruns to identify and disable suspicious startup entries that recreate the file.
  • After changes, reboot and run a full scan with an updated antimalware tool (secondary scanners often find what one misses). If the file is recreated, a scheduled task, service, or hidden autorun is likely responsible.

Cautions: do not delete unknown System32 DLLs without a backup or restore point; removing the wrong file can make Windows unbootable. If the infection persists or the DLL is locked, consider an offline rescue CD or expert removal. and other helpers will want the full HijackThis log plus the Norton filenames to give precise removal steps.

Recommended Answers

All 3 Replies

Check out our Security forum section, please. You should start with the "Helping yourself" topic which is 'Stickied' near the top of page. I'll move this topic to that section for you, to save you the trouble of posting it again.

I'll move this topic to that section for you, to save you the trouble of posting it again.

And you would be moving this when, Terry? :mrgreen:


- Thread moving now...

Oh! :o

heh heh.........

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.