I have been struggling with the malware a few days and found som different families (coolwebsearch, V2X etc).

Kim Logfile of HijackThis v1.99.1 Scan saved at 5:31:19 PM, on 9/6/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\System32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program

You may need to restore .exe file by following the below steps. MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://support.gateway.com/support/profiler/PCPitStop.CAB O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab

  Norton antivirus returns a high risk alert - NAV has detected a virus, hclean32.exe - "unable to repair file".
  The log file is below, along with a current hijack this log.   Everything loaded normally, did not get any norton AV message like i did before.
  The program will prompt you to update click the OK button The program will now go to the main screen You will need to update ewido to the latest definition files.
If you encounter this problem, using a different browser like Firefox or Chrome seems to get around the problem. Be sure you don't miss any. Share this post Link to post Share on other sites LonnyRJones Forum Deity Developer 958 posts Posted September 3, 2005 · Report post Hi   yes delete both cabs and This is how the regfix must look afterwards: Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.

O17 - HKLM\System\CCS\Services\Tcpip\..\{10EE1BB2-79D7-4090-BF70-E7E4163BE22B}: NameServer =, O17 - HKLM\System\CCS\Services\Tcpip\..\{42572EA3-0AA3-4016-93F2-A5E959F369A0}: NameServer =, O17 - HKLM\System\CS1\Services\Tcpip\..\{10EE1BB2-79D7-4090-BF70-E7E4163BE22B}: NameServer =, * Go to Control Panel.

Get a Free tool Fix hclean32.exe Problem! reboot to normal mode Run ActiveScan online virus scan here http://www.pandasoftware.com/activescan/ When the scan is finished, anything that it cannot clean have it delete it.

Go to Tools > Folder Options. When I try to open IE, I get an error message that says the file IEXPLORE.exe cannot be found, but when I search for it, it is there. Later I removed it using HijackThis (hopefully I did not brake something by doing so...)   I also installed Netcraft MSIE toolbar yesterday, but removed it this morning using Add/Remove Programs

Please re-enable javascript to access full functionality. Now put a tick by Standard File Kill. Double click on cmd.com file and a little black window will popup. this time be offline and disable norton first norton might have already deleted it, if so never mind.

I am going to continue on to the next step in your instructions, to right click on the silentrunners link. I'm attaching FindT as a zip file.

But don't randomly remove any files manually from your registry database attempting to fix this error as it is a very risky operation. Select next items in blacklite and choose rename:   C:\WINDOWS\system32\csrix.exe C:\WINDOWS\system32\dmqye.exe C:\WINDOWS\system32\ntfsnlpa.exe C:\WINDOWS\system32\hclean32.exe C:\WINDOWS\system32\loadctr32.exe C:\WINDOWS\system32\rdsndin.exe   DON'T let it rename C:\WINDOWS\system32\wbem\wbemtest.exe, because that's a legit windows-file!   The tool will ask

My computer is slow---My Blog---Follow me on Twitter.My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!Asking for help

I want to see the log first, because legit items can also be present there... If not, read on and you will find simple ways to solve the problem. Perform the following steps in safe mode: have hijack this fix these entries.

But maybe there's time for a fresh Windows installation.And the other concern is: When monitoring my network ports I see connections to deploy.akamaitechnologies.com. Well, as you say yourself, you installed all the windows updates from those packages: http://www.betatesteur.com/download.php?action=go&file_id=33   May I ask you why?

close all browsers and programmes before clicking FIX. button to start the program. Tools->Open process manager.

Rightclick on it and choose 'install'.     Download Find T.zip to root (C:\ ) http://forums.net-integration.net/index.ph...=post&id=156424 Extract the files inside also to root (C:\). The most that can be done with an unpatched system is put a temporary bandage on it. Examples > http://forums.net-integration.net/index.ph...=post&id=154446 http://forums.net-integration.net/index.ph...=post&id=154447 Note: csyew.exe and dmwlr.exe are randomly named files yours will be differant.   After you have rebooted post back with backlites log, it will be next to My Norton is now coming up.

Get a Free tool Fix hclean32.exe Problems now! We know that any spyware is able to rename the programs on your computer. Excal 0 #3 markw1 Posted 25 September 2005 - 02:44 AM markw1 New Member Topic Starter Member 2 posts Hi ExcalMany thanks for coming back and no problem at all re

To solve it, you should uninstall all the recently installed programs to see whether the problem was caused by this issue. Once the spyware disguises as a normal hclean32.exe and run on the computer, it will seriously destroy system core files and steal your personal information, leaving your computer/ your files unprotected. Thanks! Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically   Press OK twice to get out of the properties screen and reboot

If you have resolved this issue please let us know. 0 #3 Rotor Posted 11 September 2005 - 09:29 AM Rotor New Member Topic Starter Member 7 posts Hi Sam! Is this also caused by the trojan?

