I've tried scanning with Adaware, spybot, spy doctor, spy sweeper, cwsshredder, about buster and hijack this. All in safemode and to top it off i did a full system scan with my norton after each scan AND proceeded to delete various executables and dll's manually. Deleted everything in my temp folder, temp internet folder, prefech folder. It keeps coming back nomatter what i do or try. I've been at it for 3 days and i'm completely stumped and out of ideas, hopefully someone here isn't :s
Some details about the things i'm experiencing:
Everytime i open an IE or explorer window an executable is run on my system that consumes 99% of my cpu recourses. I'm getting frequent pop-up and my home page has been changed to 'about:blanc' and won't change back. I noticed some softawre in my software list called 'home search assistant, shopping wizzard (x2), search extender and offer optimizer'. Attemps to uninstall these send me to a website where i can download a tool that doesn't seem to work (it doesn't remove the progs).
Here is a norton log listing the trojans norton found. These are the files that run with each new explorer or IE window:
16/06/2005 23:03:34,Auto-Protect,Trojan Horse,Access denied,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\winlf.exe
16/06/2005 23:03:34,Auto-Protect,Trojan Horse,Repair failed,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\winlf.exe
16/06/2005 22:51:09,Auto-Protect,Trojan Horse,Access denied,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\javaqh32.exe
16/06/2005 22:51:09,Auto-Protect,Trojan Horse,Repair failed,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\javaqh32.exe
16/06/2005 22:50:53,Auto-Protect,Trojan Horse,Access denied,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\d3im.exe
16/06/2005 22:50:53,Auto-Protect,Trojan Horse,Repair failed,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\d3im.exe
16/06/2005 22:49:47,Auto-Protect,Trojan Horse,Access denied,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\d3nd.exe
16/06/2005 22:49:47,Auto-Protect,Trojan Horse,Repair failed,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\d3nd.exe
16/06/2005 22:47:10,Auto-Protect,Trojan Horse,Access denied,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\system32\addxo32.exe
16/06/2005 22:47:10,Auto-Protect,Trojan Horse,Repair failed,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\system32\addxo32.exe
16/06/2005 17:41:47,Auto-Protect,Trojan Horse,Access denied,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\addsl.exe
16/06/2005 17:41:47,Auto-Protect,Trojan Horse,Repair failed,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\addsl.exe
16/06/2005 17:40:27,Auto-Protect,Trojan Horse,Access denied,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\addsl.exe
16/06/2005 17:40:27,Auto-Protect,Trojan Horse,Repair failed,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\addsl.exe
16/06/2005 17:40:07,Auto-Protect,Trojan Horse,Access denied,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\addsl.exe
16/06/2005 17:40:07,Auto-Protect,Trojan Horse,Repair failed,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\addsl.exe
16/06/2005 17:37:17,Auto-Protect,Trojan Horse,Access denied,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\addsl.exe
16/06/2005 17:37:17,Auto-Protect,Trojan Horse,Repair failed,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\addsl.exe
16/06/2005 17:33:47,Auto-Protect,Trojan Horse,Access denied,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\addsl.exe
16/06/2005 17:33:47,Auto-Protect,Trojan Horse,Repair failed,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\addsl.exe
16/06/2005 17:31:27,Auto-Protect,Trojan Horse,Access denied,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\addsl.exe
16/06/2005 17:31:27,Auto-Protect,Trojan Horse,Repair failed,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\addsl.exe
16/06/2005 17:29:27,Auto-Protect,Trojan Horse,Access denied,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\addsl.exe
16/06/2005 17:29:27,Auto-Protect,Trojan Horse,Repair failed,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\addsl.exe
16/06/2005 17:28:18,Auto-Protect,Trojan Horse,Access denied,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\addsl.exe
16/06/2005 17:28:18,Auto-Protect,Trojan Horse,Repair failed,File,N/A,N/A,Dr N0,ATHLONDELUXE,Source: E:\WINDOWS\addsl.exe
And here is a hijack this log:
Logfile of HijackThis v1.99.1
Scan saved at 23:29:11, on 16/06/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\csrss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
E:\WINDOWS\SOUNDMAN.EXE
E:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
E:\Program Files\Common Files\Symantec Shared\ccApp.exe
E:\Program Files\D-Tools\daemon.exe
E:\WINDOWS\System32\rundll32.exe
E:\Program Files\iTunes\iTunesHelper.exe
E:\Program Files\QuickTime\qttask.exe
E:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\Program Files\Creative\PC-CAM Center\CAMTRAY.EXE
E:\WINDOWS\System32\ctfmon.exe
E:\WINDOWS\System32\NotifyPhoneBook.exe
E:\program files\valve\steam\steam.exe
E:\Program Files\MSGTAG\MSGTAG.exe
E:\Program Files\MSN Messenger\msnmsgr.exe
E:\Program Files\MSI\Core Center\CoreCenter.exe
E:\Program Files\Proxomitron Naoko-4\Proxomitron.exe
E:\WINDOWS\System32\alg.exe
E:\Program Files\Norton AntiVirus\navapsvc.exe
E:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
E:\WINDOWS\System32\nvsvc32.exe
E:\Program Files\iPod\bin\iPodService.exe
E:\PROGRA~1\SPYWAR~1\swdoctor.exe
E:\WINDOWS\System32\taskmgr.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\ewido\security suite\ewidoctrl.exe
E:\Program Files\ewido\security suite\ewidoguard.exe
C:\appz\DEATHTOSPYWARE!!!\hijackthis\HijackThis.exe
E:\WINDOWS\system32\applj32.exe
E:\WINDOWS\system32\crnu32.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://E:\WINDOWS\tpbsf.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://E:\WINDOWS\tpbsf.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://E:\WINDOWS\tpbsf.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://E:\WINDOWS\tpbsf.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://E:\WINDOWS\tpbsf.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://E:\WINDOWS\tpbsf.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://E:\WINDOWS\tpbsf.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080;https=localhost:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {AFE9366B-5984-4CD9-5214-CD1D2AC39783} - E:\WINDOWS\system32\ieyd32.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [USRpdA] E:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
O4 - HKLM\..\Run: [ccApp] "E:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "E:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] E:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "E:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [iTunesHelper] E:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "E:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Creative WebCam Tray] E:\Program Files\Creative\PC-CAM Center\CAMTRAY.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [d3fu32.exe] E:\WINDOWS\d3fu32.exe
O4 - HKLM\..\RunServices: [strmsnmgrs] msnxmsgrsc.exe
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "e:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MSGTAG] "E:\Program Files\MSGTAG\MSGTAG.exe" /startup
O4 - HKCU\..\Run: [strmsnmgrs] msnxmsgrsc.exe
O4 - HKCU\..\Run: [msnmsgr] "E:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: The Proxomitron.lnk = E:\Program Files\Proxomitron Naoko-4\Proxomitron.exe
O4 - Global Startup: Adobe Reader Snelle start.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: CoreCenter.lnk = E:\Program Files\MSI\Core Center\CoreCenter.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.co...UC/MsnPUpld.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ED7C7C88-11C3-4897-82ED-9532D527FDBF}: NameServer = 212.71.8.11,212.71.0.2
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - E:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - E:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod-service (iPodService) - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - E:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - E:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - E:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - E:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcSandraSrv.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - E:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartFinder Uninstall (SmartFinder_Uninstall) - Unknown owner - E:\Documents and Settings\Dr N0\Local Settings\Temporary Internet Files\Content.IE5\US8FQ523\sfuninstall[1].exe" service (file missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hopefully someone can help me. I'm getting fed up with running at the speed of a p2 and having my taskmanager open all the time ready to kill trojans trying to run on my computer :s