Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


log file Goya

  • This topic is locked This topic is locked
1 reply to this topic

#1 Goya


  • Members
  • 3 posts
  • Local time:05:41 AM

Posted 21 October 2004 - 03:34 AM

Thanks grinler !!

Attached Files

BC AdBot (Login to Remove)


#2 CalamityKen


  • Members
  • 128 posts
  • Location:Whitby. Ont.
  • Local time:05:41 AM

Posted 21 October 2004 - 08:02 AM

Goya, welcome.

Please print this out and follow ALL these directions carefully.

This is a new CoolWebSearch (CWS) hijack infection and is hard to remove.

Note: Every time you reboot the files multiply and change names. This process is like exterminating cockroaches.

If you insist on running file (music) sharing applications like KaZaa then you will continually be infected by all kinds of nasties in the downloaded files.
This is the new prefered method of virus/worm/trojan spreaders to get into your system and there will be no detection nor removal capability for days/weeks.
The spreaders count on this time to do their nastieness and create new nasties that are not detected.

Go to Add/Remove Programs and uninstall it.

Please download the tool called about:buster from

Unzip it to your desktop.

In WinME/XP turn off System Restore.

Then reboot into Safe Mode by tapping F8 key repeatedly during bootup.

Enable System Restore after the infection is removed.

Double click aboutbuster.exe, click OK, click Start, then click OK.
This will scan your computer for the bad files and delete them.

Now start Hijack this and tick the boxes next to these items.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\nqwlb.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\nqwlb.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINDOWS\system32\nqwlb.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://C:\WINDOWS\system32\nqwlb.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\nqwlb.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\nqwlb.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\nqwlb.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINDOWS\system32\nqwlb.dll/index.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\nqwlb.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\nqwlb.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {489CB8A5-F200-EAC7-EB4D-CADBFD62480E} - C:\WINDOWS\mfcak32.dll
O4 - HKLM\..\Run: [iegx32.exe] C:\WINDOWS\system32\iegx32.exe
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\kazaa\kazaa.exe /SYSTRAY
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

Now close ALL windows and hit fix checked.
Do not open internet explorer to come back here until after running the tool.

Install the prevention protection below and help your friends from being infected on the Internet.

Empty the Recycle Bin.

The Temp folders should be cleaned out periodically as installation programs and hijack programs leave a lot of junk there.
Index.dat Suite helps with this.

Insure that Index.dat Suite is Setup to empty the Temp folders especially
C:\Documents and Settings\{user}\Local Settings\Temp
then run the Find and create the run.bat and reboot to have it remove what it finds.

{user} is the User Account ID.
Removal of infections and prevention protection should be installed on ALL User Account IDS.

Download and install WinPatrol.

Browser settings for increased security:

Install IE-SPYAD then run the install.bat in the ie-spyad folder and SpywareBlaster then keep them up to date as today's Internet is full of nasty infections.

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users