Unsolved

This post is more than 5 years old

1222

July 26th, 2005 21:00

My HijackThis Log for Adware.iefeats

Logfile of HijackThis v1.99.1
Scan saved at 11:21:00 PM, on 7/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\STOPzilla!\SZServer.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\atlzw.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\combo.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\explorer.exe
C:\Program Files\hijackthis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.cnn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {009057E0-E644-7B31-F576-A66A75B760A4} - C:\WINDOWS\system32\addgf32.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O2 - BHO: Class - {EADA4515-E8ED-E2B5-DA95-FF9E2AA68F8F} - C:\WINDOWS\addfn.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [atlzw.exe] C:\WINDOWS\system32\atlzw.exe
O4 - HKLM\..\Run: [combo.exe] combo.exe
O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\system32\intell32.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [STOPzilla] C:\Program Files\STOPzilla!\STOPzilla.exe /autostart
O4 - HKLM\..\RunOnce: [ntol32.exe] C:\WINDOWS\system32\ntol32.exe
O4 - HKLM\..\RunOnce: [croj32.exe] C:\WINDOWS\croj32.exe
O4 - HKLM\..\RunOnce: [d3os32.exe] C:\WINDOWS\d3os32.exe
O4 - HKLM\..\RunOnce: [sysub.exe] C:\WINDOWS\sysub.exe
O4 - HKLM\..\RunOnce: [iejv.exe] C:\WINDOWS\system32\iejv.exe
O4 - HKLM\..\RunOnce: [addmw32.exe] C:\WINDOWS\addmw32.exe
O4 - HKLM\..\RunOnce: [apioh.exe] C:\WINDOWS\apioh.exe
O4 - HKLM\..\RunOnce: [msxf.exe] C:\WINDOWS\system32\msxf.exe
O4 - HKLM\..\RunOnce: [addhf32.exe] C:\WINDOWS\addhf32.exe
O4 - HKLM\..\RunOnce: [syslp32.exe] C:\WINDOWS\system32\syslp32.exe
O4 - HKLM\..\RunOnce: [d3vo.exe] C:\WINDOWS\system32\d3vo.exe
O4 - HKLM\..\RunOnce: [sdkiv.exe] C:\WINDOWS\sdkiv.exe
O4 - HKLM\..\RunOnce: [iess32.exe] C:\WINDOWS\system32\iess32.exe
O4 - HKLM\..\RunOnce: [msco.exe] C:\WINDOWS\msco.exe
O4 - HKLM\..\RunOnce: [d3yf.exe] C:\WINDOWS\d3yf.exe
O4 - HKLM\..\RunOnce: [ipdz.exe] C:\WINDOWS\ipdz.exe
O4 - HKLM\..\RunOnce: [apiwb32.exe] C:\WINDOWS\apiwb32.exe
O4 - HKLM\..\RunOnce: [sdkuz.exe] C:\WINDOWS\sdkuz.exe
O4 - HKLM\..\RunOnce: [ntfg.exe] C:\WINDOWS\ntfg.exe
O4 - HKLM\..\RunOnce: [appav32.exe] C:\WINDOWS\system32\appav32.exe
O4 - HKLM\..\RunOnce: [mfcto32.exe] C:\WINDOWS\mfcto32.exe
O4 - HKLM\..\RunOnce: [winsu32.exe] C:\WINDOWS\system32\winsu32.exe
O4 - HKLM\..\RunOnce: [javaxy32.exe] C:\WINDOWS\system32\javaxy32.exe
O4 - HKLM\..\RunOnce: [javapg32.exe] C:\WINDOWS\javapg32.exe
O4 - HKLM\..\RunOnce: [crxe32.exe] C:\WINDOWS\system32\crxe32.exe
O4 - HKLM\..\RunOnce: [netwu.exe] C:\WINDOWS\system32\netwu.exe
O4 - HKLM\..\RunOnce: [appyw32.exe] C:\WINDOWS\appyw32.exe
O4 - HKLM\..\RunOnce: [addkc32.exe] C:\WINDOWS\system32\addkc32.exe
O4 - HKLM\..\RunOnce: [javasi32.exe] C:\WINDOWS\javasi32.exe
O4 - HKLM\..\RunOnce: [ieom.exe] C:\WINDOWS\system32\ieom.exe
O4 - HKLM\..\RunOnce: [netnq.exe] C:\WINDOWS\system32\netnq.exe
O4 - HKLM\..\RunOnce: [addss.exe] C:\WINDOWS\addss.exe
O4 - HKLM\..\RunOnce: [ntnb32.exe] C:\WINDOWS\ntnb32.exe
O4 - HKLM\..\RunOnce: [javael32.exe] C:\WINDOWS\javael32.exe
O4 - HKLM\..\RunOnce: [mfckf.exe] C:\WINDOWS\system32\mfckf.exe
O4 - HKLM\..\RunOnce: [d3ga32.exe] C:\WINDOWS\d3ga32.exe
O4 - HKLM\..\RunOnce: [iezl32.exe] C:\WINDOWS\system32\iezl32.exe
O4 - HKLM\..\RunOnce: [ntei32.exe] C:\WINDOWS\system32\ntei32.exe
O4 - HKLM\..\RunOnce: [netul32.exe] C:\WINDOWS\netul32.exe
O4 - HKLM\..\RunOnce: [d3sv.exe] C:\WINDOWS\d3sv.exe
O4 - HKLM\..\RunOnce: [sdkwh.exe] C:\WINDOWS\sdkwh.exe
O4 - HKLM\..\RunOnce: [winfo32.exe] C:\WINDOWS\system32\winfo32.exe
O4 - HKLM\..\RunOnce: [d3vv.exe] C:\WINDOWS\d3vv.exe
O4 - HKLM\..\RunOnce: [javank32.exe] C:\WINDOWS\javank32.exe
O4 - HKLM\..\RunOnce: [d3hd32.exe] C:\WINDOWS\d3hd32.exe
O4 - HKLM\..\RunOnce: [atlns.exe] C:\WINDOWS\system32\atlns.exe
O4 - HKLM\..\RunOnce: [msbm32.exe] C:\WINDOWS\system32\msbm32.exe
O4 - HKLM\..\RunOnce: [netmz32.exe] C:\WINDOWS\system32\netmz32.exe
O4 - HKLM\..\RunOnce: [crrv.exe] C:\WINDOWS\crrv.exe
O4 - HKLM\..\RunOnce: [mfcng32.exe] C:\WINDOWS\system32\mfcng32.exe
O4 - HKLM\..\RunOnce: [ntrk.exe] C:\WINDOWS\ntrk.exe
O4 - HKLM\..\RunOnce: [addgk32.exe] C:\WINDOWS\system32\addgk32.exe
O4 - HKLM\..\RunOnce: [addwa32.exe] C:\WINDOWS\addwa32.exe
O4 - HKLM\..\RunOnce: [winev.exe] C:\WINDOWS\winev.exe
O4 - HKLM\..\RunOnce: [ipjo.exe] C:\WINDOWS\system32\ipjo.exe
O4 - HKLM\..\RunOnce: [netfd32.exe] C:\WINDOWS\system32\netfd32.exe
O4 - HKLM\..\RunOnce: [javadl32.exe] C:\WINDOWS\javadl32.exe
O4 - HKLM\..\RunOnce: [addgu32.exe] C:\WINDOWS\addgu32.exe
O4 - HKLM\..\RunOnce: [mfcec.exe] C:\WINDOWS\mfcec.exe
O4 - HKLM\..\RunOnce: [atlga.exe] C:\WINDOWS\system32\atlga.exe
O4 - HKLM\..\RunOnce: [sysnt32.exe] C:\WINDOWS\sysnt32.exe
O4 - HKLM\..\RunOnce: [iefq32.exe] C:\WINDOWS\system32\iefq32.exe
O4 - HKLM\..\RunOnce: [javadf32.exe] C:\WINDOWS\javadf32.exe
O4 - HKLM\..\RunOnce: [apiqp32.exe] C:\WINDOWS\apiqp32.exe
O4 - HKLM\..\RunOnce: [addgf32.exe] C:\WINDOWS\system32\addgf32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: STOPzilla - C:\WINDOWS\SYSTEM32\IS3WLHandler.dll
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\ntol32.exe
br>23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
br>23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
br>23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
br>23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
br>23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
br>23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
br>23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
br>23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
br>23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
br>23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
br>23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
br>23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
br>23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
br>23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
br>23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
br>23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
br>23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
br>23 - Service: STOPzilla Service (szserver) - Unknown owner - C:\Program Files\Common Files\STOPzilla!\SZServer.exe
br>23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

2 Intern

 • 

5.9K Posts

July 27th, 2005 14:00

I think you set the record for number of malware processes running on one computer!  I'll get back to you in a few minutes.

Ron

2 Intern

 • 

5.9K Posts

July 27th, 2005 15:00

You should probably print out these instructions or copy them to a text file.
DO NOT INSTALL ANY SOFTWARE UNLESS I TELL YOU TO UNTIL WE ARE FINISHED!
Download the Hoster from:
Unpack to your desktop and run it.  If you have green print at the top then just press Restore Original Hosts then OK. 
IF you have red print then press make Hosts Writeable first.
(This resets your hosts file which is a list of site names and IP addresses.  This is often corrupted by spyware leaving you unable to get to antivirus or search sites.)
 

Get DelDomain.inf from:
 
http://www.mvps.org/winhelp2002/restricted.htm  and then right click on it and Install. 
(This cleans up all entries in IE's REstricted and Trusted Zones.  Spyware likes to put itself in the Trusted Zone and antivirus companies in the restricted zone.)
Download a new wininet.dll file from:
http://www.dll-files.com/dllindex/dll-files.shtml?wininet
and save it to C:\.
(This is a safety feature.  You have intell32.dll on your PC and this often infects wininet.dll.  See the PS on how and when to use.)

Also download and install ccleaner.exe from http://www.ccleaner.com. Don't let
it clean anything yet. 
Run HijackThis and check the box in front of each and then ADD TO IGNORE LIST.  THese are the good guys!
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.cnn.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [STOPzilla] C:\Program Files\STOPzilla!\STOPzilla.exe /autostart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: STOPzilla - C:\WINDOWS\SYSTEM32\IS3WLHandler.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: STOPzilla Service (szserver) - Unknown owner - C:\Program Files\Common Files\STOPzilla!\SZServer.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
(We have told HijackThis to Ignore the good guys.  So anything that shows up is a bad guy.)
Now press Config.
CHECK the box in front of:  Mark everything found for fixing after a scan.
Press Back.
(We just told HijackThis to check everything it finds.  This makes it quicker to delete stuff adn we don't have to worry about malware that changes its name.  If it shows up we kill it.)
Exit HijackTHis for now.
Get Pocket Killbox
 
http://www.bleepingcomputer.com/files/killbox.php
 
and unpack it to your desktop.  Run it and select Delete on Reboot then where it says Full Path of File to Delete type in:
C:\WINDOWS\system32\ntol32.exe
 then press the Red button. Agree that you want to delete the file but do not let it reboot yet.  Repeat for:
C:\WINDOWS\system32\intell32.dll
C:\WINDOWS\system32\oleext.dll
C:\WINDOWS\system32\oleext32.dll
C:\WINDOWS\system32\wppp.html 
C:\WINDOWS\system32\uninstIU.exe
Let it reboot after the last one.
(This program gets rid of one of the infections that runs as a service.  Plus several files that often come with intell32.dll)
Shutdown again and restart then boot into Safe Mode by tapping the F8 key when you see the PC maker's logo.
Keep tapping until it tells you it is going to Safe Mode or you see the Safe
Mode menu. Select the top option.
Run HijackThis and SCAN and Fix Checked.
(This removes the registry entries that tell the system to run the malware and sometimes the files that are referenced.  All entries are backed up in the same folder where hiajckThis.exe lives.  You can restore anything that you accidentally remove by View the List of Backup then highlighting the entry you want to restore then Restore.)

Wait 60 seconds and repeat the scan. Did anything come back? IF so
leave HijackThis up and right click on the clock and select Task Manager. Then
Processes. Find Explorer.exe, right click on it and select End Process. The
desktop will disappear but HijackThis should still be there. IF you don't see
it switch to Applications in Task Manager and highlight it there then press
Switch To or just double click on it. Check and Fix Checked the above again.
Restart Explorer by Task Manager, File, New Task(Run), explorer.exe, OK.
Run ccleaner.exe, UNCHECK everything on the first page EXCEPT the two entries
with Temporary and then Run Cleaner.
(This just cleans out your temp files where malware often hides.)

Reboot into regular mode and again install deldomain.inf and run hoster
just to make sure. 
Run another HijackThis log and post it as a reply. Let's
see how we did.
Ron
PS.  If you lose control of your desktop then you will need to download and run smitfraud.reg.
 
If you lose your desktop altogether:
Boot into Safe Mode and select the Command Prompt option.
 
Type:
 
 
cd \
 
(Moves you to the root ( \ ) folder.)
 
del /f \windows\system32\dllcache\wininet.dll
(Deletes the backup copy from dllcache.  We have to do that or it will replace it the minute we change it.)
ren \windows\system32\wininet.bad
(Renames the bad file.  This is easier for some reason that deleting it.  If a rename fails you can try del /f instead of ren)
copy c:\wininet.dll c:\windows\system32\
(this replaces the bad file with the good one that we downloaded earlier.)

2 Intern

 • 

5.9K Posts

July 27th, 2005 16:00

Correction:

Down in the PS it should read:

 

ren \windows\system\wininet.dll \windows\system\wininet.bad

 

instead of

 

ren \windows\system\wininet.bad

 

Sorry about that.

 

Ron

July 27th, 2005 18:00

Okay, Im really sorry about this but I have installed Ad-aware and Stinger software since then as was reccomended to me by my father.  Should I send you a new log to see if I should do anything different than what you've already told me?

2 Intern

 • 

5.9K Posts

July 27th, 2005 19:00

Just go ahead and follow the original instructions.  You can always reinstall them later.
 
Ron

July 28th, 2005 03:00

Okay, so I got stuck on the very first step. I downloaded Hoster and ran it. It said my files were writeable but when I tried to restore the original hosts it said "Hoster can not write to your hosts file, Please check file permissions". What do I do?

2 Intern

 • 

5.9K Posts

July 28th, 2005 13:00

Are you running from a login that has admin rights?  (On Xp Home the first login is given admin rights by default.  Subsequent logins are just regular users.  If you boot into Safe Mode you should have a choice of logging in as administrator (usually without a password).)
 
You can also try changing permissions:
 
Start, Run, cmd, OK
 
then type:
 
attrib -r -h -s c:\windows\system32\drivers\etc\hosts
 
notepad c:\windows\system32\drivers\etc\hosts
 
Then delete anything except lines that start with # and the one line:
 
127.0.0.1 localhost
 
Then close and save the file.  Return to the black cmd screen and change it to read only.
 
attrib +r c:\windows\system32\drivers\etc\hosts
 
It may be that whatever bug you have doesn't want you to play with the hosts file.  Perhaps you can run hoster in Safe Mode.  Or maybe you just have to wait until later in the process when the bugs have been killed off.
 
Ron

July 29th, 2005 04:00

When I ran the HijackThis program again after doing everything you said, there was still one program that returned (I think it contains the ntol32.exe. Actually when I ran the Killbox and restarted the computer, a message came up saying that windows could not find this file when it was trying to delete it.) Here is the log.

Logfile of HijackThis v1.99.1
Scan saved at 1:33:42 AM, on 7/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\STOPzilla!\SZServer.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\hijackthis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\ntol32.exe (file missing)

2 Intern

 • 

5.9K Posts

July 29th, 2005 14:00

Looks like we got it.  The last remaining thing is nothing but a remnant left in the registry.  The file it calls is gone so it can't hurt you any more.  If HijackThis can't get rid of it then you would have to use regedit to get rid of it for good.  Unless you are comfortable with regedit it would be best to just ignore it.  If you insist I think it hides out under:
 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
and/or
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services
 
Search for:
Network Security Service
or
 11Fßä#·ºÄÖ`I
 
It's also possible that an online scan from trend or panda would remove it.  You should run one anyway just to be sure there is nothing else hiding.
 
 
 
Also recommend procedures on these pages:
 
 
 
And MicrosoftAntiSpyware
 
 
It says it is a beta but Microsoft bought it from Giant so it's pretty mature.  It currently expires in December but Gates has said he will make it available free to every licensed Windows XP user.  Has lots of nice protection features on it.
 
Ron

July 29th, 2005 16:00

Wow, thanks a lot. Everything seems to have worked. My CPU is no longer buzzing at 100% all the time now, and HijackThis confirms that everything has been removed.

Originally I was unable to access the internet unless I turned off Norton internet security for some reason, I figure because some weird setting that it was on. This is probably how this stuff got on my computer in the first place, so now I just have to figure out how to fix this. Do you know who I should talk to?

2 Intern

 • 

5.9K Posts

July 29th, 2005 16:00

I'd uninstall and reinstall the Symantec software.  If you need help they have a website at:
 
 
Ron
 
 
No Events found!

Top