
Attachment uploads are currently disabled. This is a temporary situation and will resume as normal in the coming days.
UNSOLVED
Spyware? - Again
Hi,
Sorry to post yet another Spyware/Adware problem but it seems to be a common theme.
Last week I encountered a problem which consisted of my IE homepage being hijacked AND an advertisment replacing my desktop image - 'WARNING! YOU'RE IN DANGER! .........' (for software to delete data from your PC).
I have run Ad-Aware SE Personal, Spybot and SpySubtract software and deleted/fixed everything indicated by these.
I also ran CWShredder but this did not identify anything.
I have deleted the image C:\WINDOWS\desktop.html and now have a blank grey screen as a background to my usual icons.
My Homepage is OK now but there is something present that still attempts to load the desktop image.
Way out of my depth with this.
HijackThis file is shown below.
Any help appreciated.
Fraser
Logfile of HijackThis v1.99.0
Scan saved at 21:42:49, on 01/02/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Scan saved at 21:42:49, on 01/02/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\mshelp32.exe
C:\WINDOWS\System32\cmd32.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\SED\SED.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Fraser\Application Data\eetu.exe
C:\WINDOWS\System32\r?gsvr32.exe
C:\Program Files\interMute\SpySubtract\SpySub.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Fraser\Desktop\HijackThis.exe
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\mshelp32.exe
C:\WINDOWS\System32\cmd32.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\SED\SED.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Fraser\Application Data\eetu.exe
C:\WINDOWS\System32\r?gsvr32.exe
C:\Program Files\interMute\SpySubtract\SpySub.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Fraser\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: (no name) - {4523B332-0625-4D1D-AA0C-D6A30BC60466} - C:\WINDOWS\System32\poahji.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {A708A39C-8DA7-4e36-B3B0-0A1FFAFD4B6D} - C:\WINDOWS\system32\javafix3.dll
O2 - BHO: (no name) - {AC746932-A083-8F09-8013-8B1D813010E7} - C:\WINDOWS\System32\nzjzcpiq.dll
O2 - BHO: AntiSpyware Class - {C6176B04-8896-4446-9939-E00EE94C420F} - C:\WINDOWS\System32\ash.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_5_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mshelp32] C:\WINDOWS\System32\mshelp32.exe
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\cmd32.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [db5uL8dH] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [AdStatus Service] C:\Program Files\AdStatus Service\AdStatServ.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [W2Ex] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [db5uL8ÏÔ@ÔÁß]ú"ü‰üC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [bsbav] C:\WINDOWS\bsbav.exe
O4 - HKLM\..\Run: [¢‰¸u0–4C
}ïÁzî[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [¢‰¸K0¨4W
}ïÁzî[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msjava critical update] c:\windows\jjfixer.exe
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Fraser\Application Data\eetu.exe
O4 - HKCU\..\Run: [Smm] C:\WINDOWS\System32\r?gsvr32.exe
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner\RegClean.exe"
O4 - Startup: WindowsUpdate82427[1].exe
O4 - Global Startup: AOL 8.0 Tray Icon.lnk = C:\Program Files\AOL 8.0\aoltray.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab30149.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab30149.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v6.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: (no name) - {4523B332-0625-4D1D-AA0C-D6A30BC60466} - C:\WINDOWS\System32\poahji.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {A708A39C-8DA7-4e36-B3B0-0A1FFAFD4B6D} - C:\WINDOWS\system32\javafix3.dll
O2 - BHO: (no name) - {AC746932-A083-8F09-8013-8B1D813010E7} - C:\WINDOWS\System32\nzjzcpiq.dll
O2 - BHO: AntiSpyware Class - {C6176B04-8896-4446-9939-E00EE94C420F} - C:\WINDOWS\System32\ash.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_5_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mshelp32] C:\WINDOWS\System32\mshelp32.exe
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\cmd32.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [db5uL8dH] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [AdStatus Service] C:\Program Files\AdStatus Service\AdStatServ.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [W2Ex] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [db5uL8ÏÔ@ÔÁß]ú"ü‰üC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [bsbav] C:\WINDOWS\bsbav.exe
O4 - HKLM\..\Run: [¢‰¸u0–4C
}ïÁzî[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [¢‰¸K0¨4W
}ïÁzî[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msjava critical update] c:\windows\jjfixer.exe
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Fraser\Application Data\eetu.exe
O4 - HKCU\..\Run: [Smm] C:\WINDOWS\System32\r?gsvr32.exe
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner\RegClean.exe"
O4 - Startup: WindowsUpdate82427[1].exe
O4 - Global Startup: AOL 8.0 Tray Icon.lnk = C:\Program Files\AOL 8.0\aoltray.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab30149.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab30149.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v6.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Responses (7)
Solutions (0)
Mike,
Thanks for the advice, it’s taken 4 hours to scan, carefully follow your instructions and report back so here goes with the results:
Results of Trend Micro Housecall scan:Initial message reads ‘Clean unsuccessful’ TROJ_ISTBAR.GM.
Scan lists 74 files ‘non cleanable or cannot access’!
C:\Documents and Settings\Arran\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-41742b8a-307032df.zip*Gummy.class*
C:\Documents and Settings\Arran\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arch22776.jar-68c62f3c-167f3abb.zip*RunString.class*
C:\Documents and Settings\Arran\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arch22776.jar-68c62f3c-167f3abb.zip*Colors.class*
C:\Documents and Settings\Arran\Local settings\Temp\Patch221.exe
C:\Documents and Settings\Arran\Local settings\Temp\Rem54.exe
C:\Documents and Settings\Arran\Local settings\Temp\_update.dat
C:\Documents and Settings\Arran\3.dat
C:\Documents and Settings\Arran\4.dat
C:\Documents and Settings\Arran\6.dat
C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-1466ed40-713f166b.class
C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-56bf106c-605a363a.class
C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3jar-5ef20017-2a5a5ce9.zip*Gummy.class*
C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3jar-f30ee60-21874800.zip*Gummy.class*
C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arc.jar-31224e69-20a79f5e.zip*Dummy.class*
C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arc.jar-36dfcd99-2104661d.zip*Dummy.class*
C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-79c87584-713d8a4e.zip*BlackBox.class*
C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-79c87584-713d8a4e.zip*VB.class*
C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-79c87584-713d8a4e.zip*Dummy.class*
C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-79c87584-713d8a4e.zip*Beyond.class*
C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv283.jar-35dl530c-3551aecb.zip*Dummy.class*
C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv453.lfl6a0fa-55152ddf.zip*Dummy.class*
C:\Documents and Settings\Fraser\LocalSettings\Temp\itlWe.exe
C:\Documents and Settings\Fraser\LocalSettings\Temp\SEGCRL.exe
C:\Documents and Settings\Fraser\LocalSettings\Temp\_update.dat
C:\Documents and Settings\Jane\3.dat
C:\Documents and Settings\Jane\4.dat
C:\Documents and Settings\Jane\6.dat
C:\Documents and Settings\Jordan\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\SecurityClassLoader.class-lac02c55-210de88b.class
C:\Documents and Settings\Jordan\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\SecurityClassLoader.class-305f4c99-32d096.class
C:\Documents and Settings\Jordan\Local Settings\Temp\1RWcme.exe
C:\Documents and Settings\Jordan\Local Settings\Temp\2atnoG.exe
C:\Documents and Settings\Jordan\Local Settings\Temp\aqhEq3.exe
C:\Documents and Settings\Jordan\Local Settings\Temp\cNsYub.exe
C:\Documents and Settings\Jordan\Local Settings\Temp\liCroN.exe
C:\Documents and Settings\Jordan\Local Settings\Temp\RwBwSN.exe
C:\Documents and Settings\Jordan\Local Settings\Temp\TLw3Be.exe
C:\Documents and Settings\Jordan\Local Settings\Temp\uEBOvb.exe
C:\Documents and Settings\Jordan\Local Settings\Temp\vHshhK.exe
C:\Documents and Settings\Jordan\Local Settings\Temp\xbyb7c.exe
C:\Documents and Settings\Jordan\3.dat
C:\Documents and Settings\Jordan\4.dat
C:\Documents and Settings\Jordan\6.dat
C:\Documents and Settings\Taylor\3.dat
C:\Documents and Settings\Taylor\4.dat
C:\Documents and Settings\Taylor\6.dat
C:\ProgramFiles\WindowsMediaPlayer\wmplayer.exe.tmp
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP228\A0056063.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP229\A0056111.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP293\A0075874.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP293\A0075875.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP293\A0075886.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP293\A0075887.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP293\A0075907.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP293\A0075910.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP295\A0076902.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP295\A0076904.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP302\A0079038.dll
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP302\A0081135.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP303\A0081198.dll
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP304\A0081218.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP304\A0081225.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP304\A0081227.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP322\A0081643.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP322\A0081644.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP322\A0081675.dll
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP322\A0081934.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP325\A0083115.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP334\A0083960.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP344\A0083962.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP344\A0084065.exe
C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP344\A0084067.exe
C:\WINDOWS\DownloadedProgramFiles\VM.exe
C:\WINDOWS\SYSTEM32\akrules.dll
C:\WINDOWS\Temp\akrules.dll
Downloaded and ran the Adware.Istbar removal tool FxIstbar.exeScanned OK then appeared to reach a loop where it scanned the same files over and over again C:\SystemVolumeInformation\_restore{B37680B2-B……….. so stopped scan
Ran HiJackThis and ‘Killed’ the following:C:\WINDOWS\System32\mshelp32.exe
C:\Program Files\SED\SED.exe
C:\Documents and Settings\Fraser\Application Data\eetu.exe
C:\WINDOWS\System32\r?gsvr32.exe
Opened command prompt and unregistered the following:
regsvr32 /u javafix3.dll
regsvr32 /u nzjzcpiq.dll
regsvr32 /u ash.dll
Ran HiJackThis and found and fixed the following:
O2 - BHO: (no name) - {A708A39C-8DA7-4e36-B3B0-0A1FFAFD4B6D} - C:\WINDOWS\system32\javafix3.dll
O4 - HKLM\..\Run: [mshelp32] C:\WINDOWS\System32\mshelp32.exe
O4 - HKLM\..\Run: [AdStatus Service] C:\Program Files\AdStatus Service\AdStatServ.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [bsbav] C:\WINDOWS\bsbav.exe
O4 - HKCU\..\Run: [msjava critical update] c:\windows\jjfixer.exe
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Fraser\Application Data\eetu.exe
O4 - HKCU\..\Run: [Smm] C:\WINDOWS\System32\r?gsvr32.exe
O4 - Startup: WindowsUpdate82427[1].exe
Deleted - C:\Program Files\SED and C:\Program Files\AdStatus Service
However C:\Program Files\ISTsvc was in use and could not delete. Not present in ‘Safe Mode’!
Deleted - C:\WINDOWS\System32\mshelp32.exe and C:\WINDOWS\System32\nzjzcpiq.dll
Access denied to C:\WINDOWS\System32\ash.dll but deleted in ‘Safe mode’
Others not found:
C:\Documents and Settings\Fraser\Application Data\eetu.exe
C:\WINDOWS\system32\javafix3.dll
C:\WINDOWS\bsbav.exe
C:\windows\jjfixer.exe
C:\WINDOWS\qpexcccd.exe
WindowsUpdate82427[1].exe
Ran HiJackThis log to follow as exceeded 2000 characters!
Thanks again for the help.
Fraser
Reply Midnight Star
4791 Posts
316
0
Posted February 2nd, 2005 23:00
Fraser N,Ok, let's start out by clearing the temporary files and system restore area; that should remove most of the bad files that HouseCall couldn't clean,and hopefully keep the Symantec tool from looping.
To clear the cached java files, which are also called ' jar' files:1. Click " Start"
2. Click " Control Panel"
3. Click " Other Control Panel Options".
4. Cick " Java Plug-in".( when the Java plug-in starts up)5. Click the " Cache" tab.
6. Click " Clear"
7. Click " Yes".
8. Exit the " Java(TM) Plug-in Control Panel".
1. Run " Disk Cleanup" and allow it to remove everything it finds.2. Disable, then re-enable system restore; with a reboot in-between. Then immediately create a new system point manually.
Go to Add/Remove programs and remove(uninstall) the following, if present:Windows AdStatusThe above could appear anywhere within the entry. Be careful not to remove any personal or system software.
Download the Adware.Istbar removal utility from Symantec and following the instructions on the same page.
Run HiJackThis then:1. Click " Config..."
2. Click " Misc Tools"
3. Click " Open Process manager"-Next, while holding down the CTRL key, locate ( if present) and click on ( highlight) each of the following:C:\WINDOWS\cngwqfu.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\WINDOWS\qpexcccd.exeNow double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.
Run HiJackThis and click " Scan", then check(tick) the following, if present:
R3 - Default URLSearchHook is missingO2 - BHO: (no name) - {28EA8754-0D69-47BC-AE0A-AE2D6B9B9292} - C:\WINDOWS\System32\nhkpaaa.dll (file missing)O4 - HKLM\..\Run: [db5uL8dH] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [W2Ex] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [db5uL8ÏÔ@ÔÁß]ú"ü‰üC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [Windows AdStatus] C:\Program Files\Windows AdStatus\WinStat.exe
O4 - HKLM\..\Run: [fmsVpUMU] C:\WINDOWS\cngwqfu.exe
O4 - HKLM\..\Run: [tol] C:\WINDOWS\tol.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - Startup: WindowsUpdate82427[1].exe
Now, with all windows closed except HiJackThis, click " Fix checked".
Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:folders...C:\Program Files\ISTsvc
ü‰üC:\Program Files\ISTsvc
C:\Program Files\Windows AdStatusfiles...C:\WINDOWS\cngwqfu.exe
C:\WINDOWS\qpexcccd.exe
C:\WINDOWS\tol.exeSearch for...WindowsUpdate82427[1].exe...using " Start | Search...".-Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".
Post back a new log.-Mike.Reply Ran HiJackThis log:
Logfile of HijackThis v1.99.0
Scan saved at 01:26:43, on 03/02/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\WINDOWS\System32\cmd32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\cngwqfu.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\interMute\SpySubtract\SpySub.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\Fraser\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: (no name) - {28EA8754-0D69-47BC-AE0A-AE2D6B9B9292} - C:\WINDOWS\System32\nhkpaaa.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_5_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\cmd32.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [db5uL8dH] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [W2Ex] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [db5uL8ÏÔ@ÔÁß]ú"ü‰üC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [¢‰¸u0–4C
}ïÁzî[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\qpexcccd.exeO4 - HKLM\..\Run: [¢‰¸K0¨4W
}ïÁzî[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\cngwqfu.exeO4 - HKLM\..\Run: [Windows AdStatus] C:\Program Files\Windows AdStatus\WinStat.exe
O4 - HKLM\..\Run: [fmsVpUMU] C:\WINDOWS\cngwqfu.exe
O4 - HKLM\..\Run: [tol] C:\WINDOWS\tol.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner\RegClean.exe"
O4 - Startup: WindowsUpdate82427[1].exe
O4 - Global Startup: AOL 8.0 Tray Icon.lnk = C:\Program Files\AOL 8.0\aoltray.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab30149.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab30149.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v6.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
I’m beginning to lose the will to live so I am going to call it a day for today, I hope this all makes sense.
Regards
Fraser
Message Edited by FraserN on 02-02-2005 07:47 PM
Reply Midnight Star
4791 Posts
316
0
Posted February 4th, 2005 01:00
Fraser N,
Let's start with these. When your done, post back the results of each, and let me know if they we're able to locate and remove anything.
Download the Backdoor Agent cleanup utility from Symantec and follow the instructions on their page.
Download, unzip to your desktop CWShredder and run it, then:
1. Click " Check For Update"
( If an update isn't available, skip to step #4.)
2. Click " Click here to Download the upate".
3. When the new version has been downloaded, click " Save".
4. Click " Fix ->"
Download, unzip to your desktop About:Buster and run it, then:
1. Click " Update".
2. Click " Check For Update"
( If no new version is available, skip to step #4.)
3. Click " Download Update", and wait for it to be installed.
4. Click " Start".
( Wait for the initial ADS scan to complete.)
5. Click "Yes", to shutdown any IE session currently open.
( Wait for the about:blank scan to complete.)
6. Click " Ok", to scan once more.
7. Click " Yes", to shutdown any IE sessions currently open.
8. Click " Yes", to begin the second pass.
9. Click " Save log", and post this log back along with your new log.
10. Click " Exit".
11. Click " Exit".
When your done, post back a new log.
-
Mike.Reply Hi
Many thanks for your time trying to sort out my adware/spyware problem.
Things got a bit out of control - my HijackThis logs were too big to post and I was getting more propbems each time I attempted to read your messages. I cut my losses and have paid for someone to rebuild my PC from scratch, he cloned the hard drive and then moved all my data over to the newly installed 'clean' PC. I feel rather frustrated at not being able to sort out the problems but I guess I had spent about 25hrs and the situation didn't seem to be getting any better!
Thanks again for your time.
Keep up the good work!
Fraser
fraser
Reply Midnight Star
4791 Posts
316
0
Posted February 22nd, 2005 19:00
Fraser,Anytime! Glad to hear you we're able to finally get everything sorted out.Mike.Reply

Midnight Star
4791 Posts
316
0
Posted February 2nd, 2005 00:00
Let's see what we can do...
Go to www.trendmicro.com, and then:
1. Click " Free Online Scan".
2. Click " Scan now, it's free".
It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down:
1. Select all available drives.
2. Check(tick) " Auto Clean".
3. Click " Scan".
When it completes, post back the full filename of any files that cannot be cleaned or deleted.
Download the Adware.Istbar removal utility from Symantec and following the instructions on the same page.
Run HiJackThis then:
1. Click " Config..."
2. Click " Misc Tools"
3. Click " Open Process manager"
-
Next, while holding down the CTRL key, locate ( if present) and click on ( highlight) each of the following:
C:\WINDOWS\System32\mshelp32.exe
C:\Program Files\SED\SED.exe
C:\Documents and Settings\Fraser\Application Data\eetu.exe
C:\WINDOWS\System32\r?gsvr32.exe
Now double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.
Now, let's open a command prompt and unregister the dll(s) we're going to remove, by entering the following:
regsvr32 /u javafix3.dll
regsvr32 /u nzjzcpiq.dll
regsvr32 /u ash.dll
It's ok, if these aren't found or 'error' out. If you want, just copy and paste the individual lines to the command prompt to save on the typing.
Run HiJackThis and click " Scan", then check(tick) the following, if present:
O2 - BHO: (no name) - {4523B332-0625-4D1D-AA0C-D6A30BC60466} - C:\WINDOWS\System32\poahji.dll (file missing)
O2 - BHO: (no name) - {A708A39C-8DA7-4e36-B3B0-0A1FFAFD4B6D} - C:\WINDOWS\system32\javafix3.dll
O2 - BHO: (no name) - {AC746932-A083-8F09-8013-8B1D813010E7} - C:\WINDOWS\System32\nzjzcpiq.dll
O2 - BHO: AntiSpyware Class - {C6176B04-8896-4446-9939-E00EE94C420F} - C:\WINDOWS\System32\ash.dll
O4 - HKLM\..\Run: [mshelp32] C:\WINDOWS\System32\mshelp32.exe
O4 - HKLM\..\Run: [AdStatus Service] C:\Program Files\AdStatus Service\AdStatServ.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [bsbav] C:\WINDOWS\bsbav.exe
O4 - HKCU\..\Run: [msjava critical update] c:\windows\jjfixer.exe
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Fraser\Application Data\eetu.exe
O4 - HKCU\..\Run: [Smm] C:\WINDOWS\System32\r?gsvr32.exe
O4 - Startup: WindowsUpdate82427[1].exe
Now, with all windows closed except HiJackThis, click " Fix checked".
Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
folders...
C:\Program Files\SED
C:\Program Files\AdStatus Service
C:\Program Files\ISTsvc
files...
C:\WINDOWS\System32\mshelp32.exe
C:\Documents and Settings\Fraser\Application Data\eetu.exe
C:\WINDOWS\system32\javafix3.dll
C:\WINDOWS\System32\nzjzcpiq.dll
C:\WINDOWS\System32\ash.dll
C:\WINDOWS\bsbav.exe
c:\windows\jjfixer.exe
C:\WINDOWS\qpexcccd.exe
Search for...
WindowsUpdate82427[1].exe
...using " Start | Search...".
-
Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".
Post back a new log.
-
Mike.
Edits: Fixed a broken, indirect link. Thanks 100mph ... :)
Message Edited by Midnight Star on 02-01-2005 10:49 PM