Hello... I've come here in search for some people who know about these things. I seem to have caught a trojan, and also have a few hijackers running around on my system. So far, my system resources are starting to decline and windows are taking exceedingly long to close. My system startup is also slowing down. Beyond that, every 10 min or so I get a popup window saying "No modem found!", if left alone it will keep trying to open whatever program and will send more msgs saying "already running!". Also, there are Internet Explorer popup windows that just open when I browse my files or close my browser saying I have spyware installed on my computer. Though I use Opera as my primary browser, I caught this by using Flashpeak slimbrowser, Norton caught a virus and deleted it, but it's still infected my computer. There used to be no homepage on Flashpeak, but now there is some page that has no address but shows as "Search for" with links in it. I can't seem to get rid of this, as it keeps coming back. My Incredimail has also recieved emails from myself with the homepage for a "search for" and Norton crashed saying it had corrupted files, then came back up again, a scan with Norton revealed nothing. I've used Spybot to delete everything possible, HiJack this, and Adware Gold.
Adware gave me 16 spywares it found including a "Hijacker.CoolWebSearch" 4 seperate times. This just keeps coming back.
Trojan Hunter gave me 2 seperate Trojans, both of which I have tried renaming. The g1d.exe file keeps renaming itself to something else if I use Trojan Hunter to rename the file.
Found trojan file: C:\WINDOWS\system32\oimg.dll (Hijacker.Plc.100)
Found trojan file: C:\WINDOWS\windial32.exe/g1d.exe (Dialer.Sks.100)
2 trojan files found
Here's a copy of my hijackthis log:
I have deleted the searchmeup files, as well as the iexplorer.exe and they keep coming back.
Logfile of HijackThis v1.97.7
Scan saved at 2:02:30 PM, on 5/11/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Executive Software\Diskeeper Home Edition\DKService.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
D:\retrorun.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Creative\ShareDLL\MediaDet.exe
C:\Program Files\Registry Firewall\RegFirewall.exe
C:\WINDOWS\runwin32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Sony Handheld\HOTSYNC.EXE
C:\Program Files\Windows Media Player\wmplayer.exe
D:\downloads\HijackThis.exe
C:\Program Files\Opera721\opera.exe
C:\Program Files\IncrediMail\bin\IncMail.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.searchmeup.com/search.php?aid=1057R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.searchmeup.com/search.php?aid=1057R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.searchmeup.com/search.php?aid=1057R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\oimg.dll/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.searchmeup.com/search.php?aid=1057R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.searchmeup.com/search.php?aid=1057R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.searchmeup.com/search.php?aid=1057R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.searchmeup.com/search.php?aid=1057R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.searchmeup.com/search.php?aid=1057R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.searchmeup.com/search.php?aid=1057R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {C12F1F25-2A4A-43D5-B8E4-F85AE5C5BC15} - C:\WINDOWS\System32\oimg.dll
O2 - BHO: (no name) - {F2D58883-C656-4BCA-9361-CD9BC102F291} - C:\WINDOWS\System32\mli.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: i&Won Co-Pilot - {CA0B9B71-C2AF-11D3-B376-0800460222F0} - C:\Program Files\iWon\iWonBar\1.bin\IWONBAR.DLL
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [RegFirewall] C:\Program Files\Registry Firewall\RegFirewall.exe -A
O4 - HKCU\..\Run: [runwin32] C:\WINDOWS\runwin32.exe
O4 - HKCU\..\Run: [iexplore] C:\WINDOWS\System32\iexplore.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: Send Image to Photo Library - file://C:\Documents and Settings\seth\Application Data\MGI\PhotoSuite4\Temp\MGI00000.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52/200207...meInstaller.exeO16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) -
http://216.249.24.141/code/PWActiveXImgCtl.CABO16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} (iWon Progressive Counter) -
http://download.iwon.com/ct/pm3/iwonpm_3_1,0,2,5.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/...7520.9263078704O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwa...ash/swflash.cab