Unsolved

This post is more than 5 years old

1 Rookie

 • 

66 Posts

520

December 3rd, 2005 04:00

Has Winfixer been removed from my computer?

I ran all the programs. Here are my log files. Let me know if I am clean.

VBG.TXT

[12/02/2005, 23:22:39] - Starting Process...
[12/02/2005, 23:22:39] - Looking for Browser Helper Object [MSEvents Object]
[12/02/2005, 23:22:39] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[12/02/2005, 23:22:39] - 2: {549B5CA7-4A86-11D7-A4DF-000874180BB3} -
[12/02/2005, 23:22:39] - WARNING: 2: {549B5CA7-4A86-11D7-A4DF-000874180BB3} - BHO Name is blank.
[12/02/2005, 23:22:39] - Checking for WinLogon Notify reference. (File: )
[12/02/2005, 23:22:39] - Couldn't find in Winlogon Notify. Ignoring {549B5CA7-4A86-11D7-A4DF-000874180BB3}.
[12/02/2005, 23:22:39] - 3: {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} - MSEvents Object
[12/02/2005, 23:22:39] - Found MSEvents Object!
[12/02/2005, 23:22:39] - File location: C:\WINDOWS\system32\mljji.dll
[12/02/2005, 23:22:39] - Attempting to kill C:\WINDOWS\system32\mljji.dll
[12/02/2005, 23:22:39] - Terminating Process: RUNDLL32.EXE
[12/02/2005, 23:22:40] - Terminating Process: IEXPLORE.EXE
[12/02/2005, 23:22:41] - Disabling Automatic Shell Restart
[12/02/2005, 23:22:41] - Terminating Process: EXPLORER.EXE
[12/02/2005, 23:22:42] - Suspending the NT Session Manager System Service
[12/02/2005, 23:22:42] - Terminating Windows NT Logon/Logoff Manager
[12/02/2005, 23:22:43] - Re-enabling Automatic Shell Restart
[12/02/2005, 23:22:43] - Renaming C:\WINDOWS\system32\mljji.dll -> C:\WINDOWS\system32\mljji.dll.vir
[12/02/2005, 23:22:44] - File successfully renamed!
[12/02/2005, 23:22:44] - Removing Registry references to {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152}
[12/02/2005, 23:22:45] - Adding Internet Explorer Protection (Kill ActiveX) for {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152}
[12/02/2005, 23:22:45] - Removing Winlogon Notify Entry: mljji
[12/02/2005, 23:22:45] - BHO list has been changed! Starting over...
[12/02/2005, 23:22:45] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[12/02/2005, 23:22:45] - 2: {549B5CA7-4A86-11D7-A4DF-000874180BB3} -
[12/02/2005, 23:22:45] - WARNING: 2: {549B5CA7-4A86-11D7-A4DF-000874180BB3} - BHO Name is blank.
[12/02/2005, 23:22:45] - Checking for WinLogon Notify reference. (File: )
[12/02/2005, 23:22:45] - Couldn't find in Winlogon Notify. Ignoring {549B5CA7-4A86-11D7-A4DF-000874180BB3}.
[12/02/2005, 23:22:45] - 3: {A7327C09-B521-4EDB-8509-7D2660C9EC98} - Viewpoint Toolbar BHO
[12/02/2005, 23:22:45] - 4: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} -
[12/02/2005, 23:22:45] - WARNING: 4: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - BHO Name is blank.
[12/02/2005, 23:22:45] - Checking for WinLogon Notify reference. (File: )
[12/02/2005, 23:22:45] - Couldn't find in Winlogon Notify. Ignoring {FDD3B846-8D59-4ffb-8758-209B6AD74ACC}.
[12/02/2005, 23:22:45] - Finished searching for [MSEvents Object]
[12/02/2005, 23:22:45] - Finishing up...
[12/02/2005, 23:22:45] - Enabling Automatic Reboot on STOP Error.
[12/02/2005, 23:22:45] - Attempting to Restart via STOP error (Blue Screen!)

FixVundo.log

(note: the first time I ran this the log had found the file C:\WINDOWS\system32\mljji.dll.vir as noted above, and removed it)

Symantec Trojan.Vundo Removal Tool 1.5.0

C:\System Volume Information: (not scanned)
Trojan.Vundo has not been found on your computer.

HiJack This Log

Logfile of HijackThis v1.99.1
Scan saved at 12:50:32 AM, on 12/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\WINDOWS\system32\cidaemon.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=6.1&bm=ho_search
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=33568
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.com"); (C:\Documents and Settings\Bud\Application Data\Mozilla\Profiles\default\3rbo36gr.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1119673224273
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe



Thanks!


Gary

Message Edited by ravens515 on 12-03-2005 12:07 AM

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

December 3rd, 2005 17:00

Looks like VirtumunodBeGone successfully deactivated the bad WinFixer/Vundo file... have you noticed any difference, in terms of WinFixer popups, and overall system speed/performance?

 

Next, i'm gonna help you with some minor "touch-ups":

Run HiJackThis. Place a check-mark in the box in front of each of the lines:

 

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)


O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

Click on FIX CHECKED. Close HiJackThis.

*******************************

it appears you're running Sun Java j2re1.4.2_03 .   there is much speculation that a "hole" in this particular version is being exploited by WinFixer.   so we should upgrade to the latest version, 1.5.0_06 from http://www.java.com/en/download/manual.jsp
my personal preference is to download the MANUAL (OFFline) installation version (16 MB).  but if you prefer the online installation, that choice is yours.
 
AFTER you successfully install the new java, go to your control panel, ADD/REMOVE programs, and UNinstalll all older versions of Java (if any) that still show up there.... especially the 1.4.2_03.
 
when you're done, REPLY here, and post an updated/revised HJT log.

 

At that point, I'm gonna try to ask someone else to step-in, to determine additional problems (if any) that you might have. Please be advised that we're very "understaffed" at the moment, so I can't make any guarantee as to when (or even if) the next helper will arrive.

 

Good luck.

4 Apprentice

 • 

8.8K Posts

December 3rd, 2005 19:00

Hi

Thanks ky331, excellent work

This is just minor cleanup for you here, no infections


Run HiJackThis and click " Scan", then check(tick) the following, if present:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=6.1&bm=ho_search
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=33568

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u

Now, with all windows closed except HiJackThis, click " Fix checked".


Reboot and post a new log, and let me know how everything goes.

Steve

-

4 Apprentice

 • 

8.8K Posts

December 3rd, 2005 20:00

I only removed some junk settings and cleaned up the registry a bit

Your computer is clean of malware. I am not sure if your other problems are malware related.

That Winfixer program in this computer sounds like a scanner of some sort that the owner put in.

This is my normal post for when you are clean - which you now are - or seem to be. Please advise of any problems you still have :-

Here are some last minute instructions.

  • Download and run CleanUp and clean up all the junk we have left.

  • Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.
  • You can find instructions on how to enable and re enable system restore here:
    Managing Windows Millennium System Restore
    or
    Windows XP System Restore Guide
    re-enable system restore with instructions from tutorial above

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    1. From within Internet Explorer click on the Tools menu and then click on Options.
    2. Click once on the Security tab
    3. Click once on the Internet icon so it becomes highlighted.
    4. Click once on the Custom Level button.

      1. This is my normal post for when you are clear - which you now are - or seem to be. Please advise of any problems you still have :-

        Here are some last minute instructions.

      2. Download and run CleanUp and clean up all the junk we have left.

      3. Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.
      4. You can find instructions on how to enable and re enable system restore here:
        Managing Windows Millennium System Restore
        or
        Windows XP System Restore Guide
        re-enable system restore with instructions from tutorial above

      5. Make your Internet Explorer more secure - This can be done by following these simple instructions:
        1. From within Internet Explorer click on the Tools menu and then click on Options.
        2. Click once on the Security tab
        3. Click once on the Internet icon so it becomes highlighted.
        4. Click once on the Custom Level button.

          1. Change the Download signed ActiveX controls to Prompt
          2. Change the Download unsigned ActiveX controls to Disable
          3. Change the Initialise and script ActiveX controls not marked as safe to Disable
          4. Change the Installation of desktop items to Prompt
          5. Change the Launching programs and files in an IFRAME to Prompt
          6. Change the Navigate sub-frames across different domains to Prompt
          7. When all these settings have been made, click on the OK button.
          8. If it prompts you as to whether or not you want to save the settings, press the Yes button.
      6. Next press the Apply button and then the OK to exit the Internet Properties page.

      7. Use an Anti Virus Software
        - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
      8. Computer Safety On line - Anti-Virus

      9. Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.

      10. Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For an article on Firewalls and a listing of some available ones see the link below:
      11. Computer Safety On line - Software Firewalls

      12. Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

      13. Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
      14. This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:
        Instructions for - Spybot S & D and Ad-aware

      15. Install Ad-Aware - Install and download Ad-Aware. You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot. A tutorial on installing & using this product can be found here:
      16. Instructions for - Spybot S & D and Ad-aware

      17. Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. A article on anti-malware products with links for this program and others can be found here:
      18. Computer Safety on line - Anti-Malware

      19. Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
      20. Follow this list and your potential for being infected again will reduce dramatically.

        Steve

      1 Rookie

       • 

      66 Posts

      December 3rd, 2005 20:00

      OK, first a few things.
       
      1) Even after running the winfixer remove programs, the computer was dog slow. After removing those 4 things above, it seems to have sped up a bit. What exactly was it that I removed?
       
      2) There is a program in My Documents called winfixer2005ScannerInstall.exe This is not my computer, so I do not know how it got there. It has a date of 10/1/2005. What is this file and where did it come from?
       
      3) Here is the latest HiJack Log. I still see a JRE 1.4.1_02 entry. I removed all old Java programs and installed the new one. I guess this is something still hanging around in the registry?
       
      4) As you can see I have since uninstalled AVG and installed Norton Anti Virus, not that either one of them seems to do much good.
       
      Thank you very much.
       
      Logfile of HijackThis v1.99.1
      Scan saved at 5:27:42 PM, on 12/3/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\cisvc.exe
      C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
      C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
      C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\Program Files\Dell\Media Experience\PCMService.exe
      C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
      C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\Program Files\AIM\aim.exe
      C:\Program Files\Dell Support\DSAgnt.exe
      C:\Program Files\Verizon Online\bin\mpbtn.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\WINDOWS\system32\cidaemon.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\HJT\HijackThis.exe
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
      N3 - Netscape 7: user_pref("browser.startup.homepage", " http://www.google.com"); (C:\Documents and Settings\Bud\Application Data\Mozilla\Profiles\default\3rbo36gr.slt\prefs.js)
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
      O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
      O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
      O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
      O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
      O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
      O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
      O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1119673224273
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) -
      O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
      O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
       
       
       

      4 Apprentice

       • 

      8.8K Posts

      December 4th, 2005 00:00

      Sorry, it has been brought to my attention that the installer scanner might not be what I thought, I am sorry for the misdiagnosis.

      Go into that folder and delete that .exe file.


      Run HiJackThis and click " Scan", then check(tick) the following, if present:

      O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
      Now, with all windows closed except HiJackThis, click " Fix checked".


      Reboot and post a fresh log, and go into the Documents folder and make sure that .exe file we deleted is gone. If not we will get rid of it another way.
      Steve

      -

      1 Rookie

       • 

      66 Posts

      December 4th, 2005 02:00

      Before you responded, I ran ewido and it found and removed that winfixer exe file. Here is my latest HJT file:

      Logfile of HijackThis v1.99.1
      Scan saved at 11:47:10 PM, on 12/3/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\Program Files\Dell\Media Experience\PCMService.exe
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
      C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\WINDOWS\system32\cisvc.exe
      C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
      C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
      C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
      C:\WINDOWS\system32\cidaemon.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\ewido\security suite\ewidoguard.exe
      C:\Program Files\ewido\security suite\ewidoctrl.exe
      C:\HJT\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
      N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.com"); (C:\Documents and Settings\Bud\Application Data\Mozilla\Profiles\default\3rbo36gr.slt\prefs.js)
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
      O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
      O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
      O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
      O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
      O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
      O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
      O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1119673224273
      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) -
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
      O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
      O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
      O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

       

      5 Journeyman

       • 

      15.6K Posts

       • 

      45K Points

      December 4th, 2005 13:00

      ravens,
       
      something weird just happened here.... after you successfully upgraded java, your post-upgrade log properly indicated:
       
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
       
      but now, in your most recent log (after ewido, and removing WinFixer.exe), it shows:
       
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)

      did you do something to remove ssv.dll ???  


      1 Rookie

       • 

      66 Posts

      December 4th, 2005 20:00

      I did a web search for ssv.dll and found this: http://www.dslreports.com/forum/remark,14929585

      I could not find anything specific to ewido and if it was removing it, but I uninstalled/reinstalled java on the computer and re-ran ewido, and it was not removed.

      I checked the original log file from ewido and the file was NOT listed.

      So, I wonder how the file was originally removed?

      5 Journeyman

       • 

      15.6K Posts

       • 

      45K Points

      December 5th, 2005 09:00

      I can't explain how the file was removed. This file (and BHO) is a new item, introduced in  Update 6 of Java 1.5.0.   Since the product comes directly from SUN Microsystems, there's every reason to trust it as legitimate.

      In fact, according to one of the people in the thread you cited (which I have not tried to verify):

      "I attempted to remove it, but it kept Java from working in IE".

      As long as Java is now working for you, with the latest version, that's all that matters. 

      by the way, if you ever want to test your Java version, you can go here:

      http://java.com/en/download/help/testvm.xml

      (from my own experiences there, you can trust the version number listed... but even if it tells you that it's "the latest", it may not be)

      Message Edited by ky331 on 12-05-2005 06:52 AM

      1 Rookie

       • 

      66 Posts

      December 5th, 2005 22:00

      I don't know who you guys are or who you work for but your dedication to helping me with this problem is much appreciated. I don't recall ever getting such prompt support for anything anywhere. Thank you very much.

      -- Gary

      5 Journeyman

       • 

      15.6K Posts

       • 

      45K Points

      December 6th, 2005 01:00

      we're all a bunch of volunteers.   we do NOT work for DELL.  we just get tremendous satisfaction out of combating spyware.
      No Events found!

      Top