UNSOLVED

JamesConnell

updated

22 years ago

0

9124

July 7th, 2004 05:00

advanced INF installer

hey guys.  whenever i sign on to windows (XP) i get two duplicate warnings..  with the header, "Advanced INF Installer"  it reads, "Error unregistering the OCX  C:\Windows\iesearch.dll"    

also, i don't know if it has anything to do with it, but a few icons have appeared on my desktop, (don't know how)  the one of primary concern being something called "Second Thought"..    the others are myPCsearch, and "Free Travel Voucher" all of which seemed to appear at the same time.  i've tried getting rid of them, but to no avail-- they just keep coming back.   thanks for your time.. you guys are a godsend..         --jim--

  • pskelley

    933 Posts

    1625

    0

    Posted July 7th, 2004 13:00

    Hi Jim,  Give us a log and be patient, we will take a look, since a new version of HJT was released recently, if you have any problems with any of the links, let me know.  Thanks...pskelley

    We need to make you aware that many, many logs are being posted.  Because we are few, all volunteers with families and real jobs, we will have to ask you to be patient.  We work the logs in the order they come in, if you would like us to look at your computer, please follow the instructions below. One of the experts (trained at SpywareInfo & Tom Coyote) will assist with your log as soon as possible. They may ask for a fresh log as rebooting can mutate the newest infections.

     

    We need you to download and install an analysis and repair tool called Hijackthis.
     
    Download the zipped file from here: http://www.majorgeeks.com/download3155.html.  Please see the following link for information about downloading and other FAQ's.  There is also a link there to an .exe version of HijackThis if there is anyone who absolutely can not open a .zip file.  Please use this for that purpose only due to limited bandwidth, thank you.  

    http://russelltexas.com/malware/faqhijackthis.htm

     

    Please unzip Hijackthis.zip or move the hijackthis.exe file into a new folder you create in the root (first) level of the C: drive. Name this folder HJT for best and safest results. Don't place it on the Wallpaper, in a temp folder, or the My Documents folder. It will create many backup files and they need to be stored in a unique Hijackthis folder. If it is properly placed it will look like this:   C:\HJT\HijackThis.exe.

    Hijackthis FAQ (Frequently Asked Questions) at:  http://russelltexas.com/malware/faqhijackthis.htm
     
    After downloading, and unzipping the hijackthis file into a safe folder you create (preferably a folder named HJT in the first level of the C: drive)...run Hijackthis, click on the 'scan' button and then 'save log' button.
     
    Copy and paste the contents of the text file you save into a reply to this message. A lot of posters make mistakes here in copying and pasting so reread the left info sidebar called Copy and Paste at http://www.tomcoyote.com/hjt
     
    Special Notice! Hijackthis is a powerful tool that edits the brains of Windows (the Registry). DO NOT FIX anything in the Hijackthis log screen without assistance from the experts! Most of the line items in the scanned log are normal for Windows operation. Hijackthis should identify the vast majority of your problems and enable us to help you clean them off your system.
     

    Stay in this thread for continuity. Reply to this message.
     
    Thanks,
     
    pskelley
    In Training at TomCoyote.com and Spywareinfo.com

    Please be aware only the following DellForum members were trained at TomCoyote.com and SpywareInfo.com to help with malware like viruses, worms, adware, scumware, foistware and crudware in general. They are also the only experts specifically trained to analyze and advise on Hijackthis logs: Texruss, Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley. (If you are one of our classmates and not on this list email me for an addition to this list...we need all the help we can get *;-) 

     

  • 1627

    0

    Posted July 8th, 2004 01:00

    Logfile of HijackThis v1.97.7

    Scan saved at 3:00:57 AM, on 7/7/2004

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe

    C:\WINDOWS\system32\drivers\KodakCCS.exe

    C:\WINDOWS\System32\ScsiAccess.EXE

    C:\WINDOWS\wanmpsvc.exe

    C:\Program Files\Common Files\Dell\EUSW\Support.exe

    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe

    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe

    C:\PROGRA~1\mcafee.com\agent\McAgent.exe

    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

    C:\Program Files\QuickTime\qttask.exe

    C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe

    C:\WINDOWS\bokja.exe

    C:\Program Files\America Online 9.0c\aoltray.exe

    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe

    C:\Program Files\AOL COMPANION\COMPANION.EXE

    C:\Program Files\STC\CSV5P070.exe

    C:\Program Files\Common Files\Slmss\slmss.exe

    C:\WINDOWS\System32\RUNDLL32.exe

    C:\WINDOWS\mwsvm.exe

    C:\Program Files\Lycos\IEagent\csAOLldr.exe

    C:\WINDOWS\System32\bhuxllp.exe

    C:\WINDOWS\System32\wuauclt.exe

    C:\Documents and Settings\Jim\My Documents\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.dell4me.com/myway

    R3 - URLSearchHook: (no name) - _{965A592F-8EFA-4250-8630-7960230792F1} - (no file)

    R3 - URLSearchHook: URLSearch Class - {965A592F-8EFA-4250-8630-7960230792F1} - C:\WINDOWS\System32\cdsm32.dll

    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497 - (no file)

    R3 - URLSearchHook: (no name) - _{965A592F-8EFA-4250-8630-7960230792F1 - (no file)

    O2 - BHO: (no name) - SOFTWARE - (no file)

    O2 - BHO: (no name) - {00000250-0320-4DD4-BE4F-7566D2314352} - C:\WINDOWS\VoiceIP.dll

    O2 - BHO: (no name) - {00000762-3965-4A1A-98CE-3D4BF457D4C8} - C:\Program Files\Lycos\Sidesearch\sidesearch1400.dll

    O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll

    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O2 - BHO: (no name) - {57CD6D2E-0291-488F-B846-AF101B367DD5} - C:\WINDOWS\SYSTEM32\41q5hx.dll

    O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

    O2 - BHO: (no name) - {5FA6752A-C4A0-4222-88C2-928AE5AB4966} - C:\WINDOWS\System32\SWin32.dll

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll

    O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll

    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe

    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe

    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe

    O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe

    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe

    O4 - HKLM\..\Run: [aqadcup] C:\WINDOWS\aqadcup.exe

    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"

    O4 - HKLM\..\Run: [dbfehmcwgtfn] C:\WINDOWS\System32\bhuxllp.exe

    O4 - HKLM\..\Run: [bokja] C:\WINDOWS\bokja.exe

    O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\automove.exe

    O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe

    O4 - HKLM\..\RunOnce: [7hl90o.exe] C:\WINDOWS\System32\7hl90o.exe

    O4 - HKCU\..\RunOnce: [7hl90o.exe] C:\WINDOWS\System32\7hl90o.exe

    O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0c\aoltray.exe

    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

    O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe

    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML

    O9 - Extra button: Sidesearch (HKLM)

    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)

    O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)

    O9 - Extra button: AOL Toolbar (HKLM)

    O9 - Extra 'Tools' menuitem: AOL Toolbar (HKLM)

    O9 - Extra button: AIM (HKLM)

    O9 - Extra button: Real.com (HKLM)

    O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://www.classlink2000.com/sites/FILES/wfica.cab

    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB

  • Texruss

    2 Intern

    3447 Posts

    1627

    0

    Posted July 8th, 2004 02:00

    Download and run these two programs (Spybot S&D and Adaware) at the link below. Use Spybot first.

    Most of the Internet baddies can be killed by a one-two punch with Spybot and Adaware assuming these three factors are achieved:

    1. Latest version
    2. Configured correctly for running options
    3. New definitions from update feature

    Chris has posted an excellent tutorial by dgosling on how to run Spybot S&D and also how to enable customized deep scanning functions for Adaware. Once you set these options they will be retained for future scans by Adaware.

    Follow the directions in this detailed guide for Spybot and Adaware...print out the directions in the custom scan tutorial as a reference while you set these options for the custom setup of Adaware. These custom settings will be retained for future custom scans so don't go nuts thinking you have to do this every time you run it! It may take you five minutes to set them up, but it's worth it.

    http://www.cjwd.demon.co.uk/spybot-adaware.html

    Please note the free Spybot 1.3 does have a slight bug...it detects some DSO exploits falsely. Hopefully an upgrade will fix this.The problem is not serious and should not deter people from using Spybot.

    I also like to run Windows Disk Cleanup after cleaning with those two tools. Make sure you reboot if any reboot cleanup functions of Spybot and Adaware are advised by these tools (this may happen at the end of their cleanup).

    Run Disk Cleanup: type cleanmgr at Start/Run. Scan all hard drives and check all categories at the end and click OK.

    If you have any problems with Disk Cleanup completing...XP users can fix it here:

    http://support.microsoft.com/default.aspx?scid=kb;en-us;812248

    Or try this fix: http://www2.whidbey.net/djdenham/DeleteOldFiles.htm

    Reboot and browse a bit, exit IE 6 and post a new Hijackthis log. This will clean up some of the stuff to enable final manual cleanup to be quicker.

    All the best,

    Texruss
    www.russelltexas.com
    Spyware Fighter Wilders Forum
    Slyware Warrior Tom Coyote Forum
    Expert Malware Responder Dell Forum

    Please be aware only the following DellForum members were trained at TomCoyote.com and SpywareInfo.com to help with malware like viruses, worms, adware, scumware, foistware and crudware in general. They are also the only experts specifically trained to analyze and advise on Hijackthis logs: Texruss, Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley. (If you are one of our classmates and not on this list email me for an addition to this list...we need all the help we can get *;-)  BTW...clicking on people's usernames at the left will reveal information about them if they chose to have an open profile. My credentials are available for your perusal.

  • 1627

    0

    Posted July 10th, 2004 18:00

    Logfile of HijackThis v1.97.7
    Scan saved at 3:11:19 PM, on 7/10/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Dell\EUSW\Support.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\PROGRA~1\mcafee.com\agent\McAgent.exe
    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
    C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    C:\Program Files\Common Files\WinTools\WToolsA.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\Program Files\America Online 9.0c\aoltray.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
    C:\WINDOWS\system32\drivers\KodakCCS.exe
    C:\WINDOWS\System32\ScsiAccess.EXE
    C:\WINDOWS\wanmpsvc.exe
    C:\Program Files\Common Files\WinTools\WToolsS.exe
    C:\Program Files\AOL COMPANION\COMPANION.EXE
    C:\Program Files\Common Files\WinTools\WSup.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Documents and Settings\Jim\My Documents\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50167
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50167
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50167
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - SOFTWARE - (no file)
    O2 - BHO: (no name) - {00000250-0320-4DD4-BE4F-7566D2314352} - C:\WINDOWS\VoiceIP.dll
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {57CD6D2E-0291-488F-B846-AF101B367DD5} - C:\WINDOWS\SYSTEM32\41q5hx.dll
    O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: (no name) - {5FA6752A-C4A0-4222-88C2-928AE5AB4966} - (no file)
    O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
    O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
    O2 - BHO: (no name) - {9E992732-295F-4987-8BE3-16FAC1639198} - C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    O4 - HKLM\..\Run: [dbfehmcwgtfn] C:\WINDOWS\System32\bhuxllp.exe
    O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common Files\WinTools\WToolsA.exe
    O4 - HKLM\..\RunOnce: [7hl90o.exe] C:\WINDOWS\System32\7hl90o.exe
    O4 - HKCU\..\RunOnce: [7hl90o.exe] C:\WINDOWS\System32\7hl90o.exe
    O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0c\aoltray.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
    O9 - Extra button: AOL Toolbar (HKLM)
    O9 - Extra 'Tools' menuitem: AOL Toolbar (HKLM)
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: Real.com (HKLM)
    O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://www.classlink2000.com/sites/FILES/wfica.cab
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB

    thank you for your help!

  • Texruss

    2 Intern

    3447 Posts

    1627

    0

    Posted July 10th, 2004 19:00

    Ah...Huntbar!  Also known vernacularly as Wintools. The Traffic Syndicate people have earned my undying enmity against their exploit. I guess I won't get a Christmas card from them.

    Run Hijackthis, scan and check the box left of these numbered line items:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50167

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50167
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50167
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - SOFTWARE - (no file)
    O2 - BHO: (no name) - {00000250-0320-4DD4-BE4F-7566D2314352} - C:\WINDOWS\VoiceIP.dll
    Comments: http://webhelper4u.com/transponders/freephone.html
    O2 - BHO: (no name) - {57CD6D2E-0291-488F-B846-AF101B367DD5} - C:\WINDOWS\SYSTEM32\41q5hx.dll

    O2 - BHO: (no name) - {5FA6752A-C4A0-4222-88C2-928AE5AB4966} - (no file)
    O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
    O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
    O2 - BHO: (no name) - {9E992732-295F-4987-8BE3-16FAC1639198} - C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.dll
    O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
    O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe
    O4 - HKLM\..\Run: [dbfehmcwgtfn] C:\WINDOWS\System32\bhuxllp.exe
    O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common Files\WinTools\WToolsA.exe
    O4 - HKLM\..\RunOnce: [7hl90o.exe] C:\WINDOWS\System32\7hl90o.exe
    O4 - HKCU\..\RunOnce: [7hl90o.exe] C:\WINDOWS\System32\7hl90o.exe


    With no other windows open click on fix checked button in Hijackthis.

    Exit Hijackthis.

    Reboot to SAFE MODE

    Show HIDDEN FILES and folders

    FAQ 8 and 9 on this page:

    http://www.russelltexas.com/malware/faqhijackthis.htm

    Hit Control-Shift-Escape keys at same time. Click on Applications tab and end Task for the Wintools entry. Click on Processes tab and end any Huntbar apps:

    WToolsA.exe    WToolsS.exe   WSup.exe

    Open Windows Explorer: type the word explorer at Start/Run box and click OK:

    Drill on down and delete the following files and/or folders:

    folders:
    C:\Program Files\Toolbar
    C:\Program Files\Common Files\WinTools
    C:\Documents and Settings\All Users\Applications\IESERVices
    C:\installer


    files:


    C:\WINDOWS\ VoiceIP.dll
    C:\WINDOWS\SYSTEM32\
    41q5hx.dll
    C:\WINDOWS\System32\bhuxllp.exe
    C:\WINDOWS\System32\7hl90o.exe

    Special Deletion Comments: If Wintools
    resists: Navigate to C:\Program Files\Common Files\Wintools

    Right button click on Wintools folder icon and uncheck Read-only box. Click on Advanced tab and see if there is a security tab. Go in it and check all boxes to give you permissions over that folder.

    Do the same if there is a Temp subfolder under WinTools.

    Now right button click on Wintools folder and delete. If it doesn't go away then try some more investigation in those Properties. Report back on how you do for this and if these directions worked. If it deletes, exit Explorer and empty Recycle Bin.

    Reboot in normal mode Windows and run Disk Cleanup: type cleanmgr at Start/Run. Scan all hard drives and check all categories at the end and click OK.

    If you have any problems with Disk Cleanup completing...XP users can fix it here:

     http://www2.whidbey.net/djdenham/DeleteOldFiles.htm

    Download and run these two programs (Spybot S&D and Adaware) at the link below. Use Spybot first.

    Most of the Internet baddies can be killed by a one-two punch with Spybot and Adaware assuming these three factors are achieved:

    1. Latest version
    2. Configured correctly for running options
    3. New definitions from update feature

    Chris has posted an excellent tutorial by dgosling on how to run Spybot S&D and also how to enable customized deep scanning functions for Adaware. Once you set these options they will be retained for future scans by Adaware.

    Follow the directions in this detailed guide for Spybot and Adaware...print out the directions in the custom scan tutorial as a reference while you set these options for the custom setup of Adaware. These custom settings will be retained for future custom scans so don't go nuts thinking you have to do this every time you run it! It may take you five minutes to set them up, but it's worth it.

    http://www.cjwd.demon.co.uk/spybot-adaware.html

    Please note the free Spybot 1.3 does have a slight bug...it detects some DSO exploits falsely. Hopefully an upgrade will fix this.The problem is not serious and should not deter people from using Spybot.

    Reboot and browse a bit, exit IE 6 and post a new Hijackthis log.

    Special Comments: After the final all clear is given by us you should flush your Restore Points for XP. That means disabling the Restore Point, rebooting to flush it, then re-enabling a new Restore Point. The reason why we need to do this is to purge the bad files hidden in System Restore which can't be cleaned by your antivirus programs.

    I also highly recommend uninstalling Kodak's Easy Share (AKA Backweb) in Add/Remove Programs. It is my brother's most hated foistware program and pretty high on my list also).

    http://www.cexx.org/dlgli.htm

    http://www.backweb.com/services/html/kodak.html

    See FAQ 12 here: http://www.russelltexas.com/malware/faqhijackthis.htm

    Texruss
    www.russelltexas.com
    Spyware Fighter Wilders Forum
    Slyware Warrior Tom Coyote Forum
    Expert Malware Responder Dell Forum

    Please be aware only the following DellForum members were trained at TomCoyote.com and SpywareInfo.com to help with malware like viruses, worms, adware, scumware, foistware and crudware in general. They are also the only experts specifically trained to analyze and advise on Hijackthis logs: Texruss, Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley.

    Also...these longtime DellForum regulars have proven to me time and again their advice is excellent for malware questions in general and many specific items in Hijackthis logs:  jimw, ddeerrff, and msgale.

    BTW...clicking on people's usernames at the left will reveal information about them if they chose to have an open profile. My credentials are available for your perusal.

  • 1627

    0

    Posted July 10th, 2004 21:00

    Logfile of HijackThis v1.97.7
    Scan saved at 6:26:29 PM, on 7/10/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\Program Files\Common Files\Dell\EUSW\Support.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\PROGRA~1\mcafee.com\agent\McAgent.exe
    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    C:\Program Files\America Online 9.0c\aoltray.exe
    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\Program Files\AOL COMPANION\COMPANION.EXE
    C:\Documents and Settings\Jim\My Documents\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll (file missing)
    O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\Program Files\Toolbar\toolbar.dll (file missing)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common Files\WinTools\WToolsA.exe
    O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0c\aoltray.exe
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
    O9 - Extra button: AOL Toolbar (HKLM)
    O9 - Extra 'Tools' menuitem: AOL Toolbar (HKLM)
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: Real.com (HKLM)
    O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://www.classlink2000.com/sites/FILES/wfica.cab
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38178.5163541667

    thanks!  i just have a few questions--   in trying to delete 41q5hx.dll i was told that i could not, and that access was denied.(?)  also, after doing everything else, i went to uninstall the Kodak Easy Share, (which i did successfully, but for some reason, i can't get Search to run. i click on it, and nothing happens, and i can't do anything for a few seconds.  any ideas??        thx again...   -jim-

  • Texruss

    2 Intern

    3447 Posts

    1627

    0

    Posted July 10th, 2004 23:00

    Search won't run...

    Try Method 3:

    http://support.microsoft.com/default.aspx?scid=kb;en-us;Q319949

    Do you still have a WinTools folder in C:\Program Files\Common Files\WinTools?

     >in trying to delete 41q5hx.dll i was told that i could not, and that access was denied

    Right button click on file and remove Read Only checkbox.

    HTH,

    Texruss

     

  • 1627

    0

    Posted July 12th, 2004 17:00

    i followed method 3 up to inserting my XP CD-ROM.  i went to browse for the file needed, but i couldn't figure out how to (or why i couldn't?) access my CD-ROM drive at the Open dialog box.

    the funny thing is, though, is under the administrator Windows user name, search opened fine. then, when i rebooted out of safe mode, and back to my personal user name, i had the same problem opening it! (sufferin' succotash..) 

    as for the WinTools folder, i couldn't find a trace of it.

    finally, as for 41q5hx.dll, the check box for 'read only' was already cleared, and i still couldn't delete the file. the actual notice i get is (under "error deleting file or folder"), "cannot delete 41q5hx : access is denied.  make sure the disk is not full or write-protected and that the file is not currently in use."

    again, thanks for your time, TexRuss

  • Texruss

    2 Intern

    3447 Posts

    1627

    0

    Posted July 12th, 2004 23:00

    >the funny thing is, though, is under the administrator Windows user name, search opened fine. then, when i rebooted out of safe mode, and back to my personal user name, i had the same problem opening it! (sufferin' succotash..) 

    Give your profile admin rights in the Admin logon...in Control Panel/User Accounts .

    >cannot delete 41q5hx : access is denied.  make sure the disk is not full or write-protected and that the file is not currently in use

    Hit Control-Shift-Escape keys at same time and in Processes end that task for the file. Then delete.

    HTH,

    Texruss

     

  • Texruss

    2 Intern

    3447 Posts

    122

    0

    Posted July 13th, 2004 00:00

    Did you try deleting the file in Safe Mode?

    The Search feature may only be solved by a refresher Windows reinstall.

    Texruss