Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Desktophijack trojan infection [resolved]


  • This topic is locked This topic is locked

#1
bgeddings

bgeddings

    New Member

  • Member
  • Pip
  • 9 posts
I have two desktophijack trojans that I can not remove off of my friends computer. I have followed the instructions on your website and have run everything on there and still could not get rid of them. Please help!!!

Hijack this results:

Logfile of HijackThis v1.99.1
Scan saved at 2:16:48 AM, on 7/10/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\HPONE-~1\OneTouch.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\HP Display Settings\hpdisply.exe
C:\WINDOWS\essspk.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\HPConfig.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\RadioSvr.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\update\update.exe
C:\Program Files\hjt\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.updatesea...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.updatesea...earch.php?qq=%1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.updatesea...earch.php?qq=%1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.qfind.net/search.php?qq=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.updatesea...earch.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.updatesearches.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.qfind.net/
R3 - Default URLSearchHook is missing
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O4 - HKLM\..\Run: [CP4HPOT] C:\PROGRA~1\HPONE-~1\OneTouch.EXE
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [WorksFUD] c:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [MoneyStartUp10.0] "c:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] c:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HP Presentation Ready] C:\Program Files\Hewlett-Packard\HP Presentation Ready\PresRdy.exe -r
O4 - HKLM\..\Run: [HP Display Settings] C:\Program Files\Hewlett-Packard\HP Display Settings\hpdisply.exe /s
O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\System32\winnook.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Microsoft AntiSpyware helper - {6EA2FCE2-68F6-472B-B2BA-BC7113A2AC50} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {6EA2FCE2-68F6-472B-B2BA-BC7113A2AC50} - (no file) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com/notebooks/pavilion/e-center
O16 - DPF: Yahoo! MahJong Solitaire - http://download.game...s/y/mjst4_x.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {7CF052DE-C74F-421B-B04A-3B3037EF5887} (CCMPGui Class) - http://64.124.45.181.../proxy/CCMP.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v6.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.c...ebio5_1_2_0.cab
O16 - DPF: {F57D27AE-CE57-4BC8-B232-EA57747BE5B7} -
O20 - AppInit_DLLs: c:\windows\system32\hk.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: HP Configuration Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\System32\HPConfig.exe
O23 - Service: HP RF Device Service (HpRfDev) - Hewlett-Packard - C:\WINDOWS\system32\HpRfDev.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: RadioSvr - Hewlett-Packard - C:\WINDOWS\system32\RadioSvr.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

EWIDO scan results:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 8:50:28 PM, 7/9/2005
+ Report-Checksum: CECD416D

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{6257B617-2809-056A-FCEC-83AB849FBF72} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9C07AC43-1C2D-BD1B-FEDF-58BEDA6A49E1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{DE064CF5-809E-A243-CC14-F5427E5967A1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objecta\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF} -> Spyware.EasySearch : Cleaned with backup
C:\WINDOWS\CHGPATH.REG:lzkdto -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\CHGPATH.REG:urdcna -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\control.ini:rdxhtb -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\CTRYLOC.REG:wbnnqj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\desktop.ini:qbizca -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.PornWare.PopCap.b : Cleaned with backup
C:\WINDOWS\htefj.txt:cqrsnp -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\htefj.txt:gsutpe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\loewy.txt:xkjmje -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msdfmap.ini:bzmvzo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msdfmap.ini:wmmvqf -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\MSDraw.ini:fgezoc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\MSDraw.ini:ojrbwo -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\MSDraw.ini:titirg -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\MSDraw.ini:uftncj -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\MSDraw.ini:xdvzpk -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msoffice.ini:acarqo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msoffice.ini:eepqfy -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msoffice.ini:pnfblp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mwlru.txt:tdlxsy -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mwlru.txt:wehvzj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ODBCINST.INI:ntheaf -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\ODBCINST.INI:wphpnj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ODBCINST.INI:ygdnf -> TrojanDownloader.Agent.lz : Cleaned with backup
C:\WINDOWS\OEWABLog.txt:lbyzbv -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\orun32.ini:fwvjct -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\orun32.ini:rtunau -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\PerWin.ini:adsbna -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\SchedLgU.Txt:asmotw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\SchedLgU.Txt:zxzyuu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\setuplog.txt:gsbtir -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\setuplog.txt:gzuvap -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\msole32.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\system32\ntax32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\ole32vbs.exe -> Trojan.Favadd.aa : Cleaned with backup
C:\WINDOWS\system32\oleadm.dll -> TrojanDownloader.Agent.ns : Cleaned with backup
C:\WINDOWS\vb.ini:ferrul -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\vb.ini:rzamlj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:amtlca -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:antfdg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:aswalj -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:bgmsxj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:brgaby -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:btnpnf -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:bzrwsb -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:cfdync -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:cfsjna -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:cowtyk -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:cvizyp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:czuapk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:dpjiph -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:dplzmt -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:dryoju -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:dvpfhc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:efphrc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:efxitc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:eizswh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:eluwvl -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:emvquj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:erkxsn -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:esbuao -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:esmicc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:euecxa -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:evhauz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:ewfghf -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:faqtcr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:fatehc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:fowuaq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:gquirv -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:gzorut -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:hgfkqd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:hrswla -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:hwjbdo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:iaermd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:icdomd -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:ikmsqt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:ikxhkb -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:imayap -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:imjaae -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:intpdz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:ixnltu -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:iyyjyy -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:iyzygb -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:izhhtz -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:jmclyv -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:juqtef -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:jwhjsq -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:kcnhtd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:kcxzfs -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:kpzduw -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:kqfzcl -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:kvbydx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:kxdkks -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:loprzq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:majzfs -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:mgjbej -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:mhxluv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:mlvdss -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:mqrrxc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:msjlxk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:msudas -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:mtmovx -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:mxwlpn -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:mzyozh -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:nndogg -> Trojan.Agent.bi : Cleaned with backup


::Report End

Thanks in advance!!!
  • 0

Advertisements


#2
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
Welcome bgeddings to Geeks to Go!

Please read these instructions carefully. You may want to print them. Copy the text to a Notepad file and save it to your desktop! We will need the file later.
Be sure to follow ALL instructions!


***

Go to Start - run.
copy and paste the next line:
regsvr32 /u hk.dll
press OK.

***
Download SmitRem
your desktop.
Right click on the file and extract it to it's own folder on the desktop.

***

Place a shortcut to Panda ActiveScan on your desktop.

***

Please download the trial version of ewido security suite.Install ewido security suite
When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".

Launch ewido, there should be an icon on your desktop double-click it.
The program will prompt you to update click the OK button

The program will now go to the main screen
You will need to update ewido to the latest definition files.On the left hand side of the main screen click update
Click on Start
The update will start and a progress bar will show the updates being installed.
Once the updates are installed, close Ewido for now.

***

If you have not already installed Ad-Aware SE 1.06, please download and install AdAware SE 1.06.
Check Here on how setup and use it - please make sure you update it first.

***

Please download the Killbox.
Unzip it to the desktop. Run Killbox.

Select "Delete on Reboot".

Open the text file with these instructions in it, and copy the file names below to the clipboard by highlighting them and pressing Control-C:

c:\windows\system32\hk.dll

Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

***

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.co.../safemode.shtml

***

Open HijackThis
Place a check against each of the following, making sure you get them all and not any others by mistake:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.updatesea...earch.php?qq=%1

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.updatesea...earch.php?qq=%1

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.updatesea...earch.php?qq=%1

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.qfind.net/search.php?qq=%s

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.updatesea...earch.php?qq=%1

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.updatesearches.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.qfind.net/

R3 - Default URLSearchHook is missing

O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)

O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\System32\winnook.exe

O9 - Extra button: Microsoft AntiSpyware helper - {6EA2FCE2-68F6-472B-B2BA-BC7113A2AC50} - (no file) (HKCU)

O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {6EA2FCE2-68F6-472B-B2BA-BC7113A2AC50} - (no file) (HKCU)

O16 - DPF: {F57D27AE-CE57-4BC8-B232-EA57747BE5B7} -

O20 - AppInit_DLLs: c:\windows\system32\hk.dll

Close all programs leaving only HijackThis running.
Click on Fix Checked when finished and exit HijackThis.

***

Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.
The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed.
Post me the contents of the smitfiles.txt log as you post back.

***

Open Ad-aware and do a full scan. Remove all it finds.

***

Now open Ewido Security Suite:* Click on scanner
* Click Complete System Scan and the scan will begin.
* During the scan it will prompt you to clean files, click OK
* When the scan is finished, look at the bottom of the screen and click the Save report button.
* Save the report to your desktop
Reboot your machine and post back a new HJT log and the ewido.txt log file you saved by using Add Reply

***

Next go to Control Panel click Display > Desktop > Customize Desktop > Website > Uncheck "Security Info" if present.

***

Reboot back into Windows and click the Panda ActiveScan shortcut, then do a full system scan. Make sure the autoclean box is checked!
Save the scan log and post it along with a new HijackThis Log, the contents of the smitfiles.txt log and the Ewido Log by using Add Reply.
  • 0

#3
bgeddings

bgeddings

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Thanks so much for you assistance, things are looking better. I did recieve and error message when I was running, I think, SmitRem. However here are my results from your instructions:

Hijack This:


Logfile of HijackThis v1.99.1
Scan saved at 5:09:43 PM, on 7/10/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\HPONE-~1\OneTouch.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\HP Display Settings\hpdisply.exe
C:\WINDOWS\essspk.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\System32\HPConfig.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\RadioSvr.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\hjt\HijackThis.exe

O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -

C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [CP4HPOT] C:\PROGRA~1\HPONE-~1\OneTouch.EXE
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch

Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec

Shared\ccApp.exe"
O4 - HKLM\..\Run: [WorksFUD] c:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor]

C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec

Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe

SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [MoneyStartUp10.0] "c:\Program Files\Microsoft

Money\System\Activation.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] c:\Program

Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] c:\Program Files\Microsoft

Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HP Presentation Ready] C:\Program Files\Hewlett-Packard\HP

Presentation Ready\PresRdy.exe -r
O4 - HKLM\..\Run: [HP Display Settings] C:\Program Files\Hewlett-Packard\HP

Display Settings\hpdisply.exe /s
O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"

/background
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton

SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE

CfgWiz
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\Money

Express.exe"
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} -

C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program

Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -

C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} -

c:\Program Files\Microsoft Money\System\mnyviewer.dll
O12 - Plugin for .spop: C:\Program Files\Internet

Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF:

START_PAGE_URL=http://www.hp.com/notebooks/pavilion/e-center
O16 - DPF: Yahoo! MahJong Solitaire -

http://download.game...s/y/mjst4_x.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus

scanner) -

http://security.syma...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility

Class) -

http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -

http://a840.g.akamai...icro.com/housec

all/xscan53.cab
O16 - DPF: {7CF052DE-C74F-421B-B04A-3B3037EF5887} (CCMPGui Class) -

http://64.124.45.181.../proxy/CCMP.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -

http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -

http://download.game...ed2/popcaploade

r_v6.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} -

http://us.dl1.yimg.c...ebio5_1_2_0.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation

- C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program

Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program

Files\ewido\security suite\ewidoguard.exe
O23 - Service: HP Configuration Service (HPConfig) - Hewlett-Packard -

C:\WINDOWS\System32\HPConfig.exe
O23 - Service: HP RF Device Service (HpRfDev) - Hewlett-Packard -

C:\WINDOWS\system32\HpRfDev.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec

Corporation - C:\Program Files\Norton SystemWorks\Norton

AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) -

Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton

AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec

Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: RadioSvr - Hewlett-Packard - C:\WINDOWS\system32\RadioSvr.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton

SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -

C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec

Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation -

C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


EWIDO:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 5:01:34 PM, 7/10/2005
+ Report-Checksum: 1A540201

+ Scan result:

C:\WINDOWS\_default.pif:oghone -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:ohgvuv -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:oiaupk -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:oozxfh -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:ovfhmz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:owlflr -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:pghkrj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:pnmwwt -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:psmahy -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:ptlfme -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:pyptmr -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:pyyqbd -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:qjcewj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:qpwrbz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:qxndeo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:qztmss -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:rbdcqb -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:rbjynq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:rhbvma -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:rwqahj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:sgbfqd -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:sonfzw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:sputab -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:tkjjbj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:tksutz -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:tnemwg -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:tsyfda -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:ubuhhu -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:ufqocg -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:uheyrl -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:vcxnrv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:vgkoqk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:vpozav -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:vumcko -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:wfclaa -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:wghulm -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:wnnvpu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:wsbuno -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:wxqlbq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:xbmrcn -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:xfoeoz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:xnrfwc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:xoeehp -> Trojan.Agent.bi : Cleaned with backup


::Report End



Thanks again, I look forward to your response.

Edited by bgeddings, 10 July 2005 - 03:30 PM.

  • 0

#4
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
Can you post me the smitfiles.txt log and the Panda log?

Edited by g2i2r4, 10 July 2005 - 03:33 PM.

  • 0

#5
bgeddings

bgeddings

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Sorry, did not finish reading instructions. Running Panda now. Will post them both as soon as they are finished. Sorry for the confusion.
  • 0

#6
bgeddings

bgeddings

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Here are the other two scan reports:

SmitRem:


Pre-run Files Present


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ system32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~



Post-run Files Present


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ system32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~



~~~ Wininet.dll ~~~

Not Infected!


Panda:


Incident Status Location

Adware:Adware/DownloadWare No disinfected C:\Program Files\MediaLoads*
Adware:Adware/PortalScan No disinfected C:\Program Files\Common Files\slmss
Spyware:Spyware/TVMedia No disinfected C:\WINDOWS\addyc.dll
Adware:Adware/DelFinMedia No disinfected C:\Program Files\DelFin
Adware:Adware/ExactSearch No disinfected Windows Registry
Adware:Adware/Popuper No disinfected C:\Online Pharmacy.url
Adware:Adware/Novo No disinfected Windows Registry
Adware:Adware/Popuper No disinfected C:\Documents and Settings\All Users\Desktop\Online Dating.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\All Users\Desktop\Remove Spyware.url
Adware:Adware/Popuper No disinfected C:\Online Pharmacy.url
Adware:Adware/Medload No disinfected C:\Program Files\MediaLoads\v1\ML.exe
Spyware:Spyware/TVMedia No disinfected C:\WINDOWS\addyc.dll
Adware:Adware/PopCapLoader No disinfected C:\WINDOWS\Downloaded Program Files\popcaploader.inf

I look forward to your response.
  • 0

#7
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
Use Windows Explorer to remove these folders:

C:\Program Files\MediaLoads
C:\Program Files\Common Files\slmss
C:\Program Files\DelFin

Close Windows Explorer.

***

Double-click on Killbox.exe to run it. Place the following lines (complete paths) in bold in the "Full Path of File to Delete" box in Killbox, and click the red button with the white X on it after each

C:\WINDOWS\addyc.dll
C:\Online Pharmacy.url
C:\Documents and Settings\All Users\Desktop\Online Dating.url
C:\Documents and Settings\All Users\Desktop\Remove Spyware.url
C:\Online Pharmacy.url
C:\Program Files\MediaLoads\v1\ML.exe
C:\WINDOWS\Downloaded Program Files\popcaploader.inf

For these file, put a mark next to "Delete on Reboot". Copy and paste each file into the file name box, then click the red button with the X after each. It will ask you if you want to reboot each time you click it, answer NO until after you've pasted the last file name, at which time you should answer Yes.

If your computer does not restart automatically, please restart it manually.

***

Please download and unzip
About:Buster to a folder. Inside the folder is a readme file that has instructions on the use of the program.
AboutBuster MUST be updated before you use it.
Start AboutBuster, click the update button, check for update, drag the box to the side and hit download updates, close the box. Don't run it yet.

***

Reboot to safe mode.
Run AboutBuster . This will scan your computer for the bad files and delete them.
Please run About:Buster:
  • Click Start and then OK to allow AboutBuster to scan for Alternate Data Streams.
  • Click Yes to allow it to shutdown explorer.exe.
  • It will begin to check your computer for malicious files. If it asks if you would like to do a second pass, allow it to do so.
  • When it has finished, click Save Log. Make sure you save it as I may need a copy of it later.
  • Reboot your computer into safe mode again
Run about:buster again following the same instructions as above, this time without the restart at the end.

If it keeps finding files or ADS; rerun it a couple of time. I would like a clean result.

Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.
  • 0

#8
bgeddings

bgeddings

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Okay ran about:buster: and this is the results:

AboutBuster 5.0 reference file 30
Scan started on [7/11/2005] at [11:50:38 AM]
------------------------------------------------
Removed Stream! C:\WINDOWS\Blue Lace 16.bmp:lgsepb
Removed Stream! C:\WINDOWS\bshmd.log:rgvxxg
Removed Stream! C:\WINDOWS\CHGPATH.REG:zefibe
Removed Stream! C:\WINDOWS\clock.avi:huroft
Removed Stream! C:\WINDOWS\clock.avi:zdfcrr
Removed Stream! C:\WINDOWS\Coffee Bean.bmp:cdvqyd
Removed Stream! C:\WINDOWS\comsetup.log:eacinz
Removed Stream! C:\WINDOWS\CP4HPOT.UNI:kgiaxz
Removed Stream! C:\WINDOWS\CP4HPOT.UNI:ueovsf
Removed Stream! C:\WINDOWS\CP4HPOT.UNI:xapuiq
Removed Stream! C:\WINDOWS\dasetup.log:hljwom
Removed Stream! C:\WINDOWS\desktop.ini:nfgauq
Removed Stream! C:\WINDOWS\DtcInstall.log:pcmtmb
Removed Stream! C:\WINDOWS\FaxSetup.log:golpvq
Removed Stream! C:\WINDOWS\FaxSetup.log:zfdavb
Removed Stream! C:\WINDOWS\fcdyj.dat:pkfybt
Removed Stream! C:\WINDOWS\Greenstone.bmp:cggsro
Removed Stream! C:\WINDOWS\Greenstone.bmp:jqhntn
Removed Stream! C:\WINDOWS\ikmsq.dat:nsxdkw
Removed Stream! C:\WINDOWS\jjmvl.log:damvbi
Removed Stream! C:\WINDOWS\jjmvl.log:tdeina
Removed Stream! C:\WINDOWS\lwdkm.txt:hemxni
Removed Stream! C:\WINDOWS\ModemLog_ESS SuperLink-M Data Fax Voice Modem.txt:tizwrv
Removed Stream! C:\WINDOWS\msgsocm.log:mjrblg
Removed Stream! C:\WINDOWS\msoffice.ini:buzldw
Removed Stream! C:\WINDOWS\msoffice.ini:srmgjh
Removed Stream! C:\WINDOWS\mwlru.txt:krells
Removed Stream! C:\WINDOWS\ntdtcsetup.log:qsnpjt
Removed Stream! C:\WINDOWS\ocmsn.log:jsfvdd
Removed Stream! C:\WINDOWS\ODBCINST.INI:bhoilp
Removed Stream! C:\WINDOWS\ODBCINST.INI:mvkeai
Removed Stream! C:\WINDOWS\OEWABLog.txt:xxpjbj
Removed Stream! C:\WINDOWS\oobeact.log:forpfx
Removed Stream! C:\WINDOWS\oobeact.log:qkzvlp
Removed Stream! C:\WINDOWS\ovpst.dat:bbzuvn
Removed Stream! C:\WINDOWS\Prairie Wind.bmp:edsjza
Removed Stream! C:\WINDOWS\Prairie Wind.bmp:obxayo
Removed Stream! C:\WINDOWS\Q308387.log:axpunn
Removed Stream! C:\WINDOWS\Q308387.log:dasahb
Removed Stream! C:\WINDOWS\Q308387.log:dnykjy
Removed Stream! C:\WINDOWS\Q308387.log:lagmut
Removed Stream! C:\WINDOWS\Q308387.log:mklhim
Removed Stream! C:\WINDOWS\Q308402.log:jhuusf
Removed Stream! C:\WINDOWS\Q308677.log:iinnwv
Removed Stream! C:\WINDOWS\Q308677.log:iztuqw
Removed Stream! C:\WINDOWS\Q308677.log:qkjimk
Removed Stream! C:\WINDOWS\Q308677Uninst.log:fldwhs
Removed Stream! C:\WINDOWS\Q311889.log:rbbldk
Removed Stream! C:\WINDOWS\Q315000.log:aalzsg
Removed Stream! C:\WINDOWS\qcexe.dat:uzgqgb
Removed Stream! C:\WINDOWS\qlqug.txt:marvie
Removed Stream! C:\WINDOWS\Readme.txt:cceezf
Removed Stream! C:\WINDOWS\Readme.txt:eakbco
Removed Stream! C:\WINDOWS\Readme.txt:tkqxsh
Removed Stream! C:\WINDOWS\REGLOCS.OLD:uixnpz
Removed Stream! C:\WINDOWS\regopt.log:vnlwtp
Removed Stream! C:\WINDOWS\regopt.log:wbkluf
Removed Stream! C:\WINDOWS\regopt.log:zfnhqx
Removed Stream! C:\WINDOWS\REGULOCS.OLD:cahiti
Removed Stream! C:\WINDOWS\REGULOCS.OLD:hyqikh
Removed Stream! C:\WINDOWS\REGULOCS.OLD:lkjlus
Removed Stream! C:\WINDOWS\REGULOCS.OLD:mdwjuh
Removed Stream! C:\WINDOWS\REGULOCS.OLD:qnohdn
Removed Stream! C:\WINDOWS\REGULOCS.OLD:xbcgey
Removed Stream! C:\WINDOWS\reinstall.ico:xjdbuu
Removed Stream! C:\WINDOWS\Rhododendron.bmp:hxpsss
Removed Stream! C:\WINDOWS\Rhododendron.bmp:isbbzu
Removed Stream! C:\WINDOWS\Rhododendron.bmp:kjoqnp
Removed Stream! C:\WINDOWS\Rhododendron.bmp:obvqpi
Removed Stream! C:\WINDOWS\River Sumida.bmp:inzmxp
Removed Stream! C:\WINDOWS\rysdo.log:dkgvqr
Removed Stream! C:\WINDOWS\rysdo.log:dtzdce
Removed Stream! C:\WINDOWS\rysdo.log:gcndrs
Removed Stream! C:\WINDOWS\rysdo.log:ipmwqg
Removed Stream! C:\WINDOWS\sessmgr.setup.log:qmzehu
Removed Stream! C:\WINDOWS\setupact.log:oycpge
Removed Stream! C:\WINDOWS\setupact.log:xpbdbf
Removed Stream! C:\WINDOWS\setuperr.log:jmrjcf
Removed Stream! C:\WINDOWS\Sti_Trace.log:tkfnsj
Removed Stream! C:\WINDOWS\tsoc.log:cjckij
Removed Stream! C:\WINDOWS\wiadebug.log:emjxhw
Removed Stream! C:\WINDOWS\wiadebug.log:ltuhlz
Removed Stream! C:\WINDOWS\wiadebug.log:pdfooj
Removed Stream! C:\WINDOWS\Windows Update.log:cnpxbr
Removed Stream! C:\WINDOWS\Windows Update.log:eufnfk
Removed Stream! C:\WINDOWS\Windows Update.log:kilxjb
Removed Stream! C:\WINDOWS\Windows Update.log:qwujxj
Removed Stream! C:\WINDOWS\winnt.bmp:lvqfuo
Removed Stream! C:\WINDOWS\winnt256.bmp:jxmwzl
Removed Stream! C:\WINDOWS\wkina.log:afysnn
Removed Stream! C:\WINDOWS\WMSysPrx.prx:wlsegm
Removed Stream! C:\WINDOWS\wrhoc.txt:tfqxpy
Removed Stream! C:\WINDOWS\xxzfs.dat:sfncej
Removed Stream! C:\WINDOWS\yjtmw.txt:cyvybr
Removed Stream! C:\WINDOWS\yyswj.log:fdzvyt
Removed Stream! C:\WINDOWS\Zapotec.bmp:oocxqb
Removed Stream! C:\WINDOWS\Zapotec.bmp:uyfddt
Removed Stream! C:\WINDOWS\zhppk.log:dbehxk
Removed Stream! C:\WINDOWS\zhppk.log:rvitbm
Removed Stream! C:\WINDOWS\_default.pif:agizot
Removed Stream! C:\WINDOWS\_default.pif:ajagrp
Removed Stream! C:\WINDOWS\_default.pif:awasox
Removed Stream! C:\WINDOWS\_default.pif:cajcms
Removed Stream! C:\WINDOWS\_default.pif:csfapr
Removed Stream! C:\WINDOWS\_default.pif:cxttew
Removed Stream! C:\WINDOWS\_default.pif:dkehmd
Removed Stream! C:\WINDOWS\_default.pif:dovdxa
Removed Stream! C:\WINDOWS\_default.pif:dprxvj
Removed Stream! C:\WINDOWS\_default.pif:dwasrg
Removed Stream! C:\WINDOWS\_default.pif:eibjte
Removed Stream! C:\WINDOWS\_default.pif:evkocx
Removed Stream! C:\WINDOWS\_default.pif:exfdht
Removed Stream! C:\WINDOWS\_default.pif:glqxmx
Removed Stream! C:\WINDOWS\_default.pif:hfqmuj
Removed Stream! C:\WINDOWS\_default.pif:hrdury
Removed Stream! C:\WINDOWS\_default.pif:iewgze
Removed Stream! C:\WINDOWS\_default.pif:iipbwf
Removed Stream! C:\WINDOWS\_default.pif:jrafcu
Removed Stream! C:\WINDOWS\_default.pif:kjlust
Removed Stream! C:\WINDOWS\_default.pif:koysby
Removed Stream! C:\WINDOWS\_default.pif:kxayxz
------------------------------------------------
Removed File! : C:\Windows\jfvyj.dat
Removed File! : C:\Windows\kmnok.dat
Removed File! : C:\Windows\kwivn.dat
Removed File! : C:\Windows\ovpst.dat
Removed File! : C:\Windows\qcexe.dat
Removed File! : C:\Windows\qenel.dat
Removed File! : C:\Windows\xtxnw.dat
Removed File! : C:\Windows\yopzc.dat
Removed File! : C:\Windows\System32\bfcoe.dat
Removed File! : C:\Windows\System32\czuap.dat
Removed File! : C:\Windows\System32\efphr.dat
Removed File! : C:\Windows\System32\krdpv.dat
Removed File! : C:\Windows\System32\kvofc.dat
Removed File! : C:\Windows\System32\kysnk.dat
Removed File! : C:\Windows\System32\mlemc.dat
Removed File! : C:\Windows\System32\mnplf.dat
Removed File! : C:\Windows\System32\msjlx.dat
Removed File! : C:\Windows\System32\pimmb.dat
Removed File! : C:\Windows\System32\qztms.dat
Removed File! : C:\Windows\System32\varxy.dat
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 11:51:32 AM


AboutBuster 5.0 reference file 30
Scan started on [7/11/2005] at [11:55:44 AM]
------------------------------------------------
Removed Stream! C:\WINDOWS\_default.pif:lmezok
Removed Stream! C:\WINDOWS\_default.pif:lnkxdp
Removed Stream! C:\WINDOWS\_default.pif:lvimpw
Removed Stream! C:\WINDOWS\_default.pif:nmisme
Removed Stream! C:\WINDOWS\_default.pif:nzweaq
Removed Stream! C:\WINDOWS\_default.pif:oclltt
Removed Stream! C:\WINDOWS\_default.pif:ookkss
Removed Stream! C:\WINDOWS\_default.pif:pefhsg
Removed Stream! C:\WINDOWS\_default.pif:phwwuc
Removed Stream! C:\WINDOWS\_default.pif:pjmcqr
Removed Stream! C:\WINDOWS\_default.pif:pqlppo
Removed Stream! C:\WINDOWS\_default.pif:pvhmuu
Removed Stream! C:\WINDOWS\_default.pif:pxvyyk
Removed Stream! C:\WINDOWS\_default.pif:qdpdpg
Removed Stream! C:\WINDOWS\_default.pif:rzyjqx
Removed Stream! C:\WINDOWS\_default.pif:suphvu
Removed Stream! C:\WINDOWS\_default.pif:sxsfqh
Removed Stream! C:\WINDOWS\_default.pif:tvcslg
Removed Stream! C:\WINDOWS\_default.pif:ukdyyh
Removed Stream! C:\WINDOWS\_default.pif:vjneqk
Removed Stream! C:\WINDOWS\_default.pif:vlwmog
Removed Stream! C:\WINDOWS\_default.pif:vnhsdf
Removed Stream! C:\WINDOWS\_default.pif:vqjdpt
Removed Stream! C:\WINDOWS\_default.pif:vylyyg
Removed Stream! C:\WINDOWS\_default.pif:whoiak
Removed Stream! C:\WINDOWS\_default.pif:wqakvl
Removed Stream! C:\WINDOWS\_default.pif:xitoog
Removed Stream! C:\WINDOWS\_default.pif:xwctwz
Removed Stream! C:\WINDOWS\_default.pif:yjmvlg
Removed Stream! C:\WINDOWS\_default.pif:ymjcoh
Removed Stream! C:\WINDOWS\_default.pif:zbqttg
Removed Stream! C:\WINDOWS\_default.pif:znvael
Removed Stream! C:\WINDOWS\_default.pif:zqfimw
Removed Stream! C:\WINDOWS\_default.pif:zqnvof
Removed Stream! C:\WINDOWS\_default.pif:zvxvny
------------------------------------------------
No Files Found!
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 11:56:26 AM


AboutBuster 5.0 reference file 30
Scan started on [7/11/2005] at [11:56:46 AM]
------------------------------------------------
No Ads Found!
------------------------------------------------
No Files Found!
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 11:57:12 AM


AboutBuster 5.0 reference file 30
Scan started on [7/11/2005] at [11:57:26 AM]
------------------------------------------------
No Ads Found!
------------------------------------------------
No Files Found!
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 11:57:49 AM


I look forward to your reply!
  • 0

#9
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
Looks good, you did great :tazz:

Let's look at another HijackThis log again.
  • 0

#10
bgeddings

bgeddings

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Here is my current HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 4:24:07 PM, on 7/11/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\HPONE-~1\OneTouch.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\HP Display Settings\hpdisply.exe
C:\WINDOWS\essspk.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\HPConfig.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\RadioSvr.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\hjt\HijackThis.exe

O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [CP4HPOT] C:\PROGRA~1\HPONE-~1\OneTouch.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [WorksFUD] c:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [MoneyStartUp10.0] "c:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] c:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HP Presentation Ready] C:\Program Files\Hewlett-Packard\HP Presentation Ready\PresRdy.exe -r
O4 - HKLM\..\Run: [HP Display Settings] C:\Program Files\Hewlett-Packard\HP Display Settings\hpdisply.exe /s
O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com/notebooks/pavilion/e-center
O16 - DPF: Yahoo! MahJong Solitaire - http://download.game...s/y/mjst4_x.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {7CF052DE-C74F-421B-B04A-3B3037EF5887} (CCMPGui Class) - http://64.124.45.181.../proxy/CCMP.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v6.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.c...ebio5_1_2_0.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: HP Configuration Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\System32\HPConfig.exe
O23 - Service: HP RF Device Service (HpRfDev) - Hewlett-Packard - C:\WINDOWS\system32\HpRfDev.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: RadioSvr - Hewlett-Packard - C:\WINDOWS\system32\RadioSvr.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

I look forward to your response, thanks so much for your help!

Also, when we get done let me know if it is okay to go ahead and install MS XP SP2 on this machine.

Edited by bgeddings, 11 July 2005 - 02:27 PM.

  • 0

#11
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
The log looks good to me.

I'll give you some advise for the future and close this topic as the problem looks resolved.

Is that OK by you?
  • 0

#12
bgeddings

bgeddings

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Sounds like a plan to me. Thanks for all your help. What do I need to do about MS XP SP2?
  • 0

#13
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
Step 6 describes how to get the updates for Microsoft. Do follow all steps!!

----------

Please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and reenable system restore to make sure there are no infected files found in a restore point.

    You can find instructions on how to enable and reenable system restore here:

    Managing Windows Millenium System Restore

    or

    Windows XP System Restore Guide

    Renable system restore with instructions from tutorial above

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP