cromwell_4 Posted July 27, 2005 Report Share Posted July 27, 2005 Hi,I have completed the steps you posted on a 2nd laptop that was affected by coolwebsearch. Everything looks ok now. Can you please have a look att he log to confirm if I have been successful in removing it?Logfile of HijackThis v1.99.1Scan saved at 16:01:16, on 27/07/05Platform: Windows 2000 SP4 (WinNT 5.00.2195)MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\System32\ibmpmsvc.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\svchost.exeC:\WINNT\system32\spoolsv.exeC:\PROGRA~1\PEREGR~1\DESKTO~1\bin\iftlsnr.exeC:\WINNT\floplock.exeC:\Program Files\BT Digital Access USB\vstartx.exeC:\Program Files\BT Digital Access USB\gisdnlog.exeC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\Program Files\Network Associates\VirusScan\mcshield.exeC:\Program Files\Network Associates\VirusScan\vstskmgr.exeC:\program files\notes\ntmulti.exeC:\WINNT\system32\NALNTSRV.EXEC:\PROGRA~1\AT&TGL~1\NetCfgSv.EXEC:\WINNT\system32\regsvc.exeC:\WINNT\system32\MSTask.exeC:\WINNT\System32\WBEM\WinMgmt.exeC:\WINNT\System32\mspmspsv.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\wm.exeC:\NOVELL\ZENRC\wuser32.exeC:\NOVELL\ZENRC\WUOLService.exeC:\WINNT\Explorer.EXEC:\WINNT\system32\tp4serv.exeC:\WINNT\system32\ltmsg.exeC:\WINNT\system32\PRPCUI.exeC:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXEC:\WINNT\system32\RunDll32.exeC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exeC:\WINNT\System32\dpmw32.exeC:\WINNT\system32\NWTRAY.EXEC:\Program Files\Network Associates\Common Framework\UpdaterUI.exeC:\Program Files\Network Associates\VirusScan\SHSTAT.EXEC:\Program Files\Common Files\XCPCSync\Translators\LtNts4\NtsAgent.exeC:\Program Files\BT Digital Access USB\gsyno.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\QuickTime\qttask.exeC:\WINNT\system32\internat.exeC:\Program Files\WinZip\WZQKPICK.EXEC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Documents and Settings\admcouplac\Desktop\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://campbellcorner.soups.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 195.51.87.140:8080R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 213.*;170.*;*.soups.com;194.253.155.19;62.185.95.179;62.185.95.184;<local>O1 - Hosts: 170.230.110.20 ocieO1 - Hosts: 170.230.107.200 ftp.campbellplace.com www.campbellplace.comO1 - Hosts: 194.118.99.14 GBBSERVER1 KGLHUB01O1 - Hosts: 213.62.238.230 GBBIPMSO1 - Hosts: 195.118.243.105 GBCAMP01 GBCAMP01-IPO1 - Hosts: 195.51.85.1 PUURSO1 - Hosts: 195.118.243.101 GBBDGM1O1 - Hosts: 32.77.1.31 DMCAMUS02O1 - Hosts: 32.77.1.28 DMCAMUS06O1 - Hosts: 170.230.46.6 DACAMUS04 DACAMUS04.SOUPS.COMO1 - Hosts: 170.230.115.80 campbellcornerO1 - Hosts: 213.62.238.15 DMKGLUK01O1 - Hosts: 195.118.243.108 DHDIEBE01O1 - Hosts: 195.118.243.100 Y2CAMD00 Y2CAMD00-IPO1 - Hosts: 194.253.61.57 COMFIERYO1 - Hosts: 194.253.61.73 GENFIERYO1 - Hosts: 213.62.238.49 GBBTOWERO1 - Hosts: 203.8.80.233 DMSYDAU01O1 - Hosts: 203.8.80.234 DMSYDAU02O1 - Hosts: 141.94.135.6 FIREWALL1O1 - Hosts: 141.94.135.4 FIREWALL2O1 - Hosts: 213.62.238.12 EKGLAPP02O1 - Hosts: 213.62.238.20 EKGLCMB01O1 - Hosts: 170.230.105.27 DACAMUS02O1 - Hosts: 128.1.0.9 S4441272O1 - Hosts: 128.1.0.10 CBS270O1 - Hosts: 195.118.243.109 EURAPP01O1 - Hosts: 213.62.238.11 GBBSERVER2O1 - Hosts: 213.62.238.23 GBBSQLO1 - Hosts: 170.230.236.44 GBBCOGNOSO1 - Hosts: 170.230.113.75 CAMPBELLDW01O1 - Hosts: 213.62.238.17 DAKGLUK01O1 - Hosts: 170.230.185.20 DMASHUK10O1 - Hosts: 170.230.240.20 DMWORUK10O1 - Hosts: 170.230.197.20 DMCRAUK10O1 - Hosts: 213.62.238.30 GBBPSOFTO1 - Hosts: 213.62.238.40 GBBIPMS2O1 - Hosts: 213.62.238.5 FIREWALLO1 - Hosts: 195.118.243.110 EUCAMD00O1 - Hosts: 170.230.113.75 WHQDWH41O1 - Hosts: 170.230.104.217 DDACAMUS01O1 - Hosts: 170.230.240.15 EWORCMB01O1 - Hosts: 170.230.185.15 EASHCMB01O1 - Hosts: 170.230.197.50 ECRACMB01O1 - Hosts: 170.230.191.3 DMDUNFR10O1 - Hosts: 213.62.238.34 GBBCITRIXO1 - Hosts: 213.62.238.18 EKGLAPP04O1 - Hosts: 170.230.185.20 DMASHUK10O1 - Hosts: 170.230.189.178 DAKARSE01O1 - Hosts: 170.230.113.149 psacpt PSACPTO1 - Hosts: 170.230.128.36 DMTORCA01O1 - Hosts: 170.230.243.9 CAMBOURNE-UNITYO1 - Hosts: 170.230.243.7 CAMBOURNE-PUBO1 - Hosts: 170.230.215.123 DMHBUAU10O1 - Hosts: 170.230.115.101 DMCAMUS12O1 - Hosts: 170.230.46.11 DMCAMUS10O1 - Hosts: 213.62.238.25 DGKGLUK01O1 - Hosts: 170.230.236.42 DMCAMUK10O1 - Hosts: 170.230.115.80 CAMPBELLCORNERO1 - Hosts: 195.51.83.8 DMBOUFR10O1 - Hosts: 170.230.113.198 DCCAMUS01O1 - Hosts: 213.62.238.33 EKGLAPP07O1 - Hosts: 170.230.236.40 ECAMCMB01O1 - Hosts: 213.62.238.28 DANOSBE01O1 - Hosts: 213.62.238.26 DSDIEBE01O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocxO4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exeO4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9O4 - HKLM\..\Run: [tourpath] regedit /s c:\winnt\tour.regO4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logonO4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exeO4 - HKLM\..\Run: [TP4EX] tp4ex.exeO4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXEO4 - HKLM\..\Run: [bMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitorO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exeO4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.EXEO4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.EXE -CHECKO4 - HKLM\..\Run: [Client Access Service] "C:\Program Files\IBM\Client Access\cwbsvstr.exe"O4 - HKLM\..\Run: [Client Access Help Update] "C:\Program Files\IBM\Client Access\cwbinhlp.exe"O4 - HKLM\..\Run: [Client Access Check Version] "C:\Program Files\IBM\Client Access\cwbckver.exe" LOGINO4 - HKLM\..\Run: [Client Access Express Welcome] "C:\Program Files\IBM\Client Access\cwbwlwiz.exe"O4 - HKLM\..\Run: [NDPS] C:\WINNT\System32\dpmw32.exeO4 - HKLM\..\Run: [ZENRC Tray Icon] zentray.exeO4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXEO4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exeO4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKeyO4 - HKLM\..\Run: [shStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONEO4 - HKLM\..\Run: [EasySync Pro - LtNts4] C:\Program Files\Common Files\XCPCSync\Translators\LtNts4\NtsAgent.exeO4 - HKLM\..\Run: [EasySync Pro] C:\Program Files\Common Files\XCPCMenu.exeO4 - HKLM\..\Run: [GazelDisplay] "C:\Program Files\BT Digital Access USB\gsyno.exe" -hO4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKCU\..\Run: [internat.exe] internat.exeO4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXEO12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO14 - IERESET.INF: START_PAGE_URL=about:blankO16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} (Support.com ActionRunner Class) - https://www-3.ibm.com/pc/support/access/sdc...oad/tgctlar.cabO16 - DPF: {01111E00-3E00-11D2-8470-0060089874ED} (Support.com SmartIssue) - https://www-3.ibm.com/pc/support/access/sdc...oad/tgctlsi.cabO16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://dccamus01.soups.com/qp2.cabO16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - https://www-3.ibm.com/pc/support/access/sdc...ad/IbmEgath.cabO16 - DPF: {95E52A86-61B2-11D6-976A-00B0D09A3628} (ProjectBPSInterface3.BPSInterface3) - http://worldpanel.tns-global.com/Worldpane...SInterface3.CABO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eu.cpb.comO17 - HKLM\System\CCS\Services\Tcpip\..\{3A22ECFD-1D48-4F30-A047-F4AB3D5657DC}: Domain = europe.soups.comO17 - HKLM\System\CCS\Services\Tcpip\..\{B8FFE0DF-1558-4B64-A3B7-2285A3E7CFE7}: NameServer = 170.230.236.46,170.230.236.36O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eu.cpb.comO17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = eu.cpb.com,cpb.com,europe.soups.com,soups.comO17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eu.cpb.comO17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = eu.cpb.com,cpb.com,europe.soups.com,soups.comO17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = eu.cpb.com,cpb.com,europe.soups.com,soups.comO23 - Service: Peregrine Listener 6.0.1 (agtlsnr601) - Peregrine Systems, Inc. - C:\PROGRA~1\PEREGR~1\DESKTO~1\bin\iftlsnr.exeO23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exeO23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINNT\system32\cusrvc.exeO23 - Service: Client Access Express Remote Command (Cwbrxd) - IBM Corporation - C:\WINNT\CWBRXD.EXEO23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exeO23 - Service: floppylock - Unknown owner - C:\WINNT\floplock.exeO23 - Service: BT Digital Access USB start up (Gazel Startup) - Unknown owner - C:\Program Files\BT Digital Access USB\vstartx.exe" /s (file missing)O23 - Service: ISDN connection log (GisdnLog) - Unknown owner - C:\Program Files\BT Digital Access USB\gisdnlog.exe" -s (file missing)O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINNT\System32\ibmpmsvc.exeO23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exeO23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exeO23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exeO23 - Service: Multi-user Cleanup Service - Unknown owner - C:\program files\notes\ntmulti.exeO23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\WINNT\system32\NALNTSRV.EXEO23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXEO23 - Service: Remote management (Novell WUser Agent) - Novell, Inc. - C:\NOVELL\ZENRC\wuser32.exeO23 - Service: PictureTaker - LANovation - C:\WINNT\System32\PCTKRNT.SYSO23 - Service: Novell Workstation Manager (WM) - Novell, Inc. - C:\WINNT\System32\wm.exeO23 - Service: WUOLservice (WUOLService) - Novell, Inc. - C:\NOVELL\ZENRC\WUOLService.exeThanks,Claire Link to post Share on other sites
Excal Posted July 31, 2005 Report Share Posted July 31, 2005 Hi cromwell_4 and welcome to Best Techie!Have you altered your Host file at all? It has a lot of interesting entries.I need to see a Copy of you Hosts File and a HijackThis log from Normal Mode please!Open HijackThis-> Click Config-> Click Misc Tools-> Click Open Hosts File Manager-> Click Open in Notepad->Copy&Paste the entire Contents of that Notepad Page to your Next Post!Thanks, Excal Link to post Share on other sites
Recommended Posts