Hey People, I'm working on a customers computer that's been hijacked by Cool Web Search. I've tried everything...spybot, CWShredder, Norton, Panda etc. Trendmicro won't run..I get an internet explorer error. Here's my Hijack this log...I'll be checking back in a couple of hours...gotta get away from this comp before I kill it. Thanks guys.
Logfile of HijackThis v1.97.7
Scan saved at 4:01:25 PM, on 30/05/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc3
2.exe
C:\windows\system\hpsysdrv
.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.
exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://cashsearch.biz/redir1.phpR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://cashsearch.biz/redir1.phpR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://cashsearch.biz/redir1.phpR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://cashsearch.biz/redir1.phpR1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Local Page =
http://cashsearch.biz/redir1.phpR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Local Page =
http://cashsearch.biz/redir1.phpR3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-
00C04FD644
97} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEH
elper.ocx
O2 - BHO: (no name) - {4BCF322B-9621-4e90-9678-F
1424EB7584
E} - C:\WINDOWS\udpmod.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-0
0E04C60FAF
2} - C:\WINDOWS\2_0_1browserhel
per2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: &Zero-Knowledge Freedom - {FA91B828-F937-4568-82C1-8
43627E63ED
7} - C:\Program Files\Zero Knowledge\Freedom\BandObjs
.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv
.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD
.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtr
ay.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.
exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.ex
e
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O9 - Extra button: TREND MICRO HouseCall (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-0
0104BD12D9
4} (PCPitstop Utility) -
http://www.pcpitstop.com/pcpitstop/PCPitStop.CABO16 - DPF: {74D05D43-3236-11D4-BDCD-0
0C04F9A3B6
1} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2e529727a6ef04/housecall.antivirus.com/housecall/xscan53.cabO16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F
243C4B8260
F} (HouseCallButton.setup) -
http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CABO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5
009F29E09E
1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-4
7A8489BB47
F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38136.3633796296O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-F
B9E207A39E
6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4363/mcfscan.cabHope for a quick response
P.S. spybot and cwshredder were both updated versions.
<--CREE-->