Ebates Money Maker [CLOSED], AdAware SE seemingly impotent on removal |
![]() ![]() |
Ebates Money Maker [CLOSED], AdAware SE seemingly impotent on removal |
Jul 12 2005, 07:24 AM
Post
#1
|
|
|
New Member ![]() Posts: 2 OS: W2K |
Posting in the appropriate forum this time, long day yesterday...
I run ZoneAlarm and Ad-Aware SE on a regular basis, have never had an issue like this before, it only happened after I plugged into the WAN (test) side of the corporate firewall, oops. EbatesMoneyMaker shows up whenever I do an AdAware scan, AdAware acts like it's removing it, but it's always there next time. Causes "Crystal Palace" online poker ads to popup. I can block the services request with za but that causes Windows to not resolve DNS, popup still shows up with Cannot Find Page. The log is below, the packet capture stuff is legit, it's Ethereal The only thing I see as suspect is: O4 - HKLM\..\Run: [checkrun] C:\winnt\system32\elitelvt32.exe What do you think? Logfile of HijackThis v1.99.1 Scan saved at 7:52:18 PM, on 7/7/2005 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\Program Files\NavNT\defwatch.exe C:\WINNT\system32\drivers\KodakCCS.exe C:\Program Files\NavNT\rtvscan.exe C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\system32\ScsiAccess.EXE C:\WINNT\system32\stisvc.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\Program Files\RealVNC\VNC4\WinVNC4.exe C:\WINNT\system32\mspmspsv.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\MsgSys.EXE C:\WINNT\Explorer.EXE C:\Program Files\NavNT\vptray.exe C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\WINNT\system32\WLANSTA.EXE C:\WINNT\system32\ctfmon.exe C:\Program Files\AirDash WRCB-1011r Config Utility\AirDash WRCB-1011r Config Utility\RtlWake.exe C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\WINZIP\winzip32.exe C:\Documents and Settings\Administrator\Local Settings\Temp\HijackThis.exe R3 - Default URLSearchHook is missing O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [WLANSTA.EXE] WLANSTA.EXE START O4 - HKLM\..\Run: [checkrun] C:\winnt\system32\elitelvt32.exe O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe O4 - Global Startup: AirDash WRCB-1011r Config Utility.lnk = C:\Program Files\AirDash WRCB-1011r Config Utility\AirDash WRCB-1011r Config Utility\RtlWake.exe O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing) O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact... - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing) O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion...ctor/WebAAS.cab O16 - DPF: {CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.2) - https://cpsosasos.asi.sbc.com/cpsosasos/DSL...re-1_4_2_01.exe O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe O23 - Service: ptssvc - KODAK - C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing) O23 - Service: ScsiAccess - Unknown owner - C:\WINNT\system32\ScsiAccess.EXE O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing) Thanks, RWS |
|
|
| Guest_usetobe_* |
Jul 13 2005, 09:28 AM
Post
#2
|
|
|
Please read these instructions carefully and print them out! Be sure to follow ALL instructions!
Download, install, and update Ewido Security Suite
After the updates are installed, exit Ewido Please download Cleanup from here: Cleanup. Do not run it yet. Set up PC to show hidden files.(Click link if you do not know how) Show hidden files Next, please reboot your computer in Safe Mode by doing the following: 1) Restart your computer 2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8. 3) Instead of Windows loading as normal, a menu should appear 4) Select the first option, to run Windows in Safe Mode. Once in Safe Mode, Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows: *Click "Options..." *Move the arrow down to "Custom CleanUp!" *Put a check next to the following:
Press the CleanUp! button to start the program. After Cleanup! is finished:
Once the scan has completed, there will be a button located on the bottom of the screen named Save report[list] [*]Click Save report [*]Save the report to your desktop [*]Exit Ewido Now scan with HJT and check the following entries if they still exist: R3 - Default URLSearchHook is missing O4 - HKLM\..\Run: [checkrun] C:\winnt\system32\elitelvt32.exe Ensure no windows open except HJT and click fix checked Using windows explorer locate and delete the following file if found C:\winnt\system32\elitelvt32.exe Now reboot pc normally. Run this online virus scan: ActiveScan - Save the results from the scan! Rescan with HJT and post the log back, with the ewido and panda logs. |
|
|
| Guest_usetobe_* |
Jul 31 2005, 10:29 AM
Post
#3
|
|
|
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
6 / 1,508 | 25th July 2005 - 12:10 PM wchoghm started - last by Excal |
|||||
![]() |
1 / 239 | 12th July 2005 - 04:50 AM reallywildstuff started - last by Metallica |
|||||
![]() |
5 / 915 | 7th August 2005 - 01:51 AM GreeNirZeppelin started - last by Excal |
|||||
![]() |
17 / 2,760 | 13th August 2005 - 05:32 AM mosd3f started - last by Metallica |
|||||
|
Time is now: 21st November 2009 - 01:48 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising