Thanks for agreeing to look at this. I have been getting messages that look like microsoft messages in box saying that my system can be intruded and I need to download drivecleaner. In running etrust antivirus wLogfile of HijackThis v1.99.1
Scan saved at 3:58:32 PM, on 7/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Your Java application is out of date.
Click start-->control panel-->add/remove programs
Scroll down the list and locate each instance of Java. Click
Remove. When the uninstallation completes, reboot the computer.
Disable your
Symantec Script Blocking from within your Norton so it does not interfere with anything during our fixes now or later. You can enable this whenever we have verified that your system is clean.
To disable Norton AntiVirus Script Blocking:
1. Start Norton AntiVirus.
If Norton AntiVirus is installed as part of Norton SystemWorks or Norton Internet Security, then start that program.
2. Click Options.
If you see a menu, click Norton AntiVirus.
3. In the left pane, click Script Blocking.
4. In the right pane, uncheck Enable Script Blocking (recommended).
5. Click OK.
Please disable
SpySweeper, as it may hinder the removal of some entries. You can re-enable it after you're clean.
To disable SpySweeper:
Open it click >Options over to the left then >program options >Uncheck "load at windows startup".
Over to the left click "shields" and uncheck all there.
Uncheck "home page shield".
Uncheck 'automatically restore default without notification".
* Double-click VundoFix.exe to run it. * Put a check next to Run VundoFix as a task. * You will receive a message saying vundofix will close and re-open in a minute or less. Click OK * When VundoFix re-opens,Click Scan for Vundo button. * Once the scan is complete, Right Click inside the listbox (white box) and click add more files * Copy&Paste the entry below into the top box
C:\WINDOWS\SYSTEM32\clicdpo.dll
* Click Add Files and Click Close Window * Click the Remove Vundo button. * You will receive a prompt asking if you want to remove the files, click YES * Once you click yes, your desktop will go blank as it starts removing Vundo. * When completed, it will prompt that it will shutdown your computer, click OK. * Turn your computer back on. * Please post the contents of C:\vundofix.txt when you reply next.
Please run HijackThis again and check the following that may still exist:
Close all windows except for HijackThis then click
Fix Checked.
Reboot the computer.
Download
Ewido anti-spyware to your desktop.
This is a 30 day free trial. At the end of the 30-day trial period the full version features (active guard, automatic updates...) will be deactivated and the program will become a feature-limited freeware version...You can still keep it and use it for "On Demand" scanning.
Double click the icon on the desktop to launch the set up program.
Select Change state to inactivate "Resident Shield" and "Automatic Updates". Right click on ewido in the system tray and uncheck "Start with Windows".
Once the setup is complete you will need to update the definition files.
On the main screen select the icon Update then select the Update now link.
Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
Once in the Settings screen click on Recommended actions and then select Quarantine.
Under Reports
Select Automatically generate report after every scan
Un-Select Only if threats were found
Close ewido anti-spyware.
Please boot into Safe mode:
Restart the computer and immediately begin tapping the F8 key (or F5 on some Dell machines). Use the arrow keys to highlight Safe Mode and press the Enter key. Once in safe mode, continue with the instructions below:
Launch ewido anti-spyware by double-clicking the icon on your desktop.
Select the Scanner icon at the top, then the Scan tab then click on Complete System Scan.
ewido will now begin the scanning process, be patient this may take some time.
When prompted of an infection, please select Apply all actions
Once the scan is complete do the following:
Next select the Reports icon at the top.
Select the Save report as button in the lower left hand of the screen and save it to your Desktop.
Now close ewido anti-spyware.
Reboot back into your normal user mode and post back a new HijackThis log along with the log from your Ewido scan and the VundoFix.txt log. Thanks!
I have followed the directions you have given me up through running the VundoFix software. When it was done running, it already had the C:\windows\system32\clicdpo.dll file name in the box. I also added the filename (this same one to the box) and continued to have it removed. Before it shut down the system I got the message: C:\windows\system32\clicdpo.dll could not be deleted twice (once for each file name in the box) and it said that it would attempt to delete it on the reboot. The computer then restarted. I did NOT get a C:\vundofix.txt file though. I ran a find on the entire hard drive and this file was not on it anywhere. I have not gone any further in the steps that you have recommended. Should I continue on with the rest of the steps or wait for further instructions? Thanks for your help!!
Yes. The only thing different is that I did not have a shield to uncheck that said about automatically restoring the default (the last one on your list of shields to uncheck). Is it someplace else other than in the shields? If this is a problem, can I just remove the spybot software from the system altoghether?
Was it Spybot you were looking at or WebRoot's SpySweeper? The only thing Spybot has that would need to be disabled is the Tea Timer, and I did not see that running in your log.
You do however have SpySweeper running, and the instructions to disable it were, I thought, up to date.
So long as you have unchecked the
Load at Windows Startup and have unchecked all of the options under "shields", you should be ok.
Let's try the VundoFix.exe again a little differently. The application has been updated.
Double-click
VundoFix.exe to run it.
Put a check next to "
Run VundoFix as a task."
You will receive a message saying
vundofix will close and re-open in a minute or less. Click "
OK".
When VundoFix re-opens, click the "
Scan for Vundo" button.
Once it's done scanning, click the "
Remove Vundo" button.
If it says "
No infected files were found",
right-click the blank listbox (white box) in the main VundoFix window.
Select "
Add More Files?" from the menu that comes up. This will open a new VundoFix window that says "
Paste files into the boxes below:"
In the top/first field, copy and paste
the path to the dll:
C:\WINDOWS\SYSTEM32\clicdpo.dll In the next/second field, copy and paste
the path to the reversed file:
C:\WINDOWS\system32\opdcilc.dll Click the "
Add Files" button.
Click the "
Close Window" button.
Click the
Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click "
YES".
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will shutdown your computer, click "
OK".
Turn your computer back on.
Please post the contents of C:\
vundofix.txt and a new HiJackThis log.
C:\Documents and Settings\ashley erhart\My Documents\HJT\backups\backup-20060713-094353-764.dll -> Downloader.ConHook.aa : Cleaned with backup (quarantined). C:\VundoFix Backups\clicdpo.dll -> Downloader.ConHook.aa : Cleaned with backup (quarantined). C:\WINDOWS\system32\clicdpo.dll -> Downloader.ConHook.aa : Cleaned with backup (quarantined). C:\WINDOWS\system32\efcbawx.dll -> Downloader.ConHook.ab : Cleaned with backup (quarantined). C:\WINDOWS\system32\urssq.exe -> Dropper.Agent.arj : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Local Settings\Temp\Cookies\ashley erhart@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Cookies\ashley erhart@stats.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Cookies\ashley erhart@www.adtrak[2].txt -> TrackingCookie.Adtrak : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Local Settings\Temp\Cookies\ashley erhart@advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Local Settings\Temp\Cookies\ashley erhart@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Local Settings\Temp\Cookies\ashley erhart@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Cookies\ashley erhart@com[2].txt -> TrackingCookie.Com : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Cookies\ashley erhart@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Local Settings\Temp\Cookies\ashley erhart@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Cookies\ashley erhart@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Local Settings\Temp\Cookies\ashley erhart@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Cookies\ashley erhart@sales.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Cookies\ashley erhart@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Local Settings\Temp\Cookies\ashley erhart@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Cookies\ashley erhart@ads.realcastmedia[2].txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Cookies\ashley erhart@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Local Settings\Temp\Cookies\ashley erhart@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined). C:\Documents and Settings\ashley erhart\Local Settings\Temp\Cookies\ashley erhart@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
::Report end
Thank you for your help and please let me know what else I need to do. If that is the end, could you please let me know how to keep this problem from happening again...or at least lessen the chances of it happening again!
I have gone through the entire instructions that you have given. Sorry about the first vundo. I think that was an operator error on my part! Here is the vundofix.txt report
VundoFix V5.1.1
Running as SYSTEM from c:\windows\system32\VundoFix.exe
Checking Java version...
Java version is 1.4.2.3
Java version is 1.5.0.7
Scan started at 8:37:10 PM 7/11/2006
Listing files found while scanning....
C:\windows\system32\clicdpo.dll
Beginning removal...
The process smss.exe was successfully stopped
The process winlogon.exe was successfully stopped
The process explorer.exe was successfully stopped
The process iexplore.exe was successfully stopped
The process rundll32.exe was successfully stopped
Attempting to delete C:\windows\system32\clicdpo.dll C:\windows\system32\clicdpo.dll Could not be deleted.
Attempting to delete C:\WINDOWS\SYSTEM32\clicdpo.dll C:\WINDOWS\SYSTEM32\clicdpo.dll Could not be deleted.
Performing Repairs to the registry. Done!
VundoFix V5.1.2
Running as SYSTEM from c:\windows\system32\VundoFix.exe
Checking Java version...
Java version is 1.4.2.3
Java version is 1.5.0.7
Scan started at 9:08:09 AM 7/13/2006
Listing files found while scanning....
C:\windows\system32\clicdpo.dll
Beginning removal...
VundoFix V5.1.2
Running as SYSTEM from c:\windows\system32\VundoFix.exe
Checking Java version...
Java version is 1.4.2.3
Java version is 1.5.0.7
Scan started at 9:12:05 AM 7/13/2006
Listing files found while scanning....
C:\windows\system32\clicdpo.dll
Beginning removal...
The process smss.exe was successfully stopped
The process winlogon.exe was successfully stopped
The process explorer.exe was successfully stopped
The process iexplore.exe was successfully stopped
The process rundll32.exe was successfully stopped
Attempting to delete C:\windows\system32\clicdpo.dll C:\windows\system32\clicdpo.dll Could not be deleted.
Performing Repairs to the registry. Done!
VundoFix V5.1.2
Running as SYSTEM from c:\windows\system32\VundoFix.exe
Checking Java version...
Java version is 1.4.2.3
Java version is 1.5.0.7
Scan started at 9:21:26 AM 7/13/2006
Listing files found while scanning....
C:\windows\system32\clicdpo.dll
Beginning removal...
The process smss.exe was successfully stopped
The process winlogon.exe was successfully stopped
The process explorer.exe was successfully stopped
The process iexplore.exe was successfully stopped
The process rundll32.exe was successfully stopped
Attempting to delete C:\windows\system32\clicdpo.dll C:\windows\system32\clicdpo.dll Could not be deleted.
Performing Repairs to the registry. Done!
It still didn't seem able to delete that file. I kept going and did the hijackthis and it found the first 2 things you mentioned but not the third. So I checked those 2 and selected fix checked. Here is the log from that...
Logfile of HijackThis v1.99.1 Scan saved at 9:31:59 AM, on 7/13/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
You got rid of that Vundo Trojan, good job!
Now, we're almost home. I need you to look for a program to uninstall. Click start-->control panel-->add/remove programs.
Scroll down the list and locate a program named
MyWaySearch Assistant.
Also look for "MyWebSearch", "MyWay Speedbar" or anything that might have the name "FunWebProducts" associated with it. If you locate any of them, click
Remove.
Reboot when finished uninstalling.
Next, please run HijackThis again and check the following:
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll O2 - BHO: (no name) - {19efbb4f-0c80-4cc7-ae5a-8ce031c2d61c} - C:\WINDOWS\system32\clicdpo.dll O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
Close all windows except for HijackThis, then click
Fix Checked.
Reboot and post a new HijackThis log. Please advise how the system is running and if you are having any other issues. Thanks!
I have completed the last procedures you requested I removed the MyWaySearch Assistant program and did not find any others. Then I restarted the system. I ran Hijack this again. I did not have any R3s and only one O2 that looked like it had something to do with Spybot. So I did not do a fixcheck. Here is the log file from Hijack this...
Logfile of HijackThis v1.99.1 Scan saved at 8:41:27 PM, on 7/13/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Let me know if you think this is the end of the fixes. Do I then need to go back and change settings back on Norton Internet Security and any of the antispyware programs that I have running? If so, can you please advise? Thanks!!
Don't forget to re-enable your protective software that we disabled for the fix:
1. Start Norton AntiVirus.
If Norton AntiVirus is installed as part of Norton SystemWorks or Norton Internet Security, then start that program.
2. Click Options.
If you see a menu, click Norton AntiVirus.
3. In the left pane, click Script Blocking.
4. In the right pane,
check the "Enable Script Blocking (recommended)."
5. Click OK. Close the application.
Next, open WebRoot's SpySweeper:
click-->Options over to the left then-->program options-->check the "load at windows startup" option.
Over to the left click "shields" and
check all there.
Check "home page shield".
check "automatically restore default without notification".
Close the application and reboot. Upon reboot, check to make sure your Norton script blocking and WebRoot SpySweeper start up when windows starts. Look for the icons in the system tray and right click each of them. Make sure your real time protection options are all enabled.
If something doesn't look right, stop here and post back with any questions you may have about your real time protection.
Otherwise, please continue with these instructions below for your system restore point and future recommendations:
Now that your system is clean, let's create a new restore point. Please click "Start > Programs > Accessories > System Tools > System Restore"
In the new window, check the 'Create a restore point' in the right pane and click "Next".
In the "Restore point description" textbox, name your restore point to something you will easily recognize. I recommend something like yyyymmdd_Clean (ex. 20060101_Clean)
Click "Create" and reboot your computer.
In the future, there are some things you can do to prevent spyware infections:
Keep your anti-virus and spyware definitions up to date. Be sure to scan often.
If you should choose later on when your subscription expires not to renew with Symantec, please consider using one of these free firewall applications:
Kerio Personal Firewall Zone Alarm
...and for antivirus protection, in the event you decide not to renew your subscription with Symantec, there are these free applications available on the public domain:
Please select and install One of these free antivirus applications:
AVG Free for Windows AntiVir Personal Edition Classic Avast! 4 Home Edition
Using an alternate browser can reduce your chance of certain infections installing themselves. We recommend installing Mozilla Firefox from
http://www.mozilla.org
If you still wish to use Internet Explorer, please make sure you install SpywareBlaster (from above) to protect you from most ActiveX infections.
Run
CCleaner often
or Disk Cleanup ("Start > Programs > Accessories > System Tools > Disk Cleanup" ) and check off the following:
Downloaded Program Files, Temporary Internet Files, Recycle Bin, and Temporary Files
1972vet
3305 Posts
340
0
Posted July 9th, 2006 03:00
Click start-->control panel-->add/remove programs
Scroll down the list and locate each instance of Java. Click Remove. When the uninstallation completes, reboot the computer.
You can download the latest version of Java here.
Disable your Symantec Script Blocking from within your Norton so it does not interfere with anything during our fixes now or later. You can enable this whenever we have verified that your system is clean.
To disable Norton AntiVirus Script Blocking:
1. Start Norton AntiVirus.
If Norton AntiVirus is installed as part of Norton SystemWorks or Norton Internet Security, then start that program.
2. Click Options.
If you see a menu, click Norton AntiVirus.
3. In the left pane, click Script Blocking.
4. In the right pane, uncheck Enable Script Blocking (recommended).
5. Click OK.
Please disable SpySweeper, as it may hinder the removal of some entries. You can re-enable it after you're clean.
To disable SpySweeper:
Open it click >Options over to the left then >program options >Uncheck "load at windows startup".
Over to the left click "shields" and uncheck all there.
Uncheck "home page shield".
Uncheck 'automatically restore default without notification".
Please download VundoFix.exe to your desktop.
* Put a check next to Run VundoFix as a task.
* You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
* When VundoFix re-opens,Click Scan for Vundo button.
* Once the scan is complete, Right Click inside the listbox (white box) and click add more files
* Copy&Paste the entry below into the top box
C:\WINDOWS\SYSTEM32\clicdpo.dll
* Click Add Files and Click Close Window
* Click the Remove Vundo button.
* You will receive a prompt asking if you want to remove the files, click YES
* Once you click yes, your desktop will go blank as it starts removing Vundo.
* When completed, it will prompt that it will shutdown your computer, click OK.
* Turn your computer back on.
* Please post the contents of C:\vundofix.txt when you reply next.
Please run HijackThis again and check the following that may still exist:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
O2 - BHO: (no name) - {19efbb4f-0c80-4cc7-ae5a-8ce031c2d61c} - C:\WINDOWS\system32\clicdpo.dll
O20 - Winlogon Notify: clicdpo - C:\WINDOWS\SYSTEM32\clicdpo.dll
Close all windows except for HijackThis then click Fix Checked.
Reboot the computer.
Download Ewido anti-spyware to your desktop.
This is a 30 day free trial. At the end of the 30-day trial period the full version features (active guard, automatic updates...) will be deactivated and the program will become a feature-limited freeware version...You can still keep it and use it for "On Demand" scanning.
Close ewido anti-spyware.
Please boot into Safe mode:
Restart the computer and immediately begin tapping the F8 key (or F5 on some Dell machines).
Use the arrow keys to highlight Safe Mode and press the Enter key. Once in safe mode, continue with the instructions below:
Once the scan is complete do the following:
- Next select the Reports icon at the top.
- Select the Save report as button in the lower left hand of the screen and save it to your Desktop.
Now close ewido anti-spyware.Reboot back into your normal user mode and post back a new HijackThis log along with the log from your Ewido scan and the VundoFix.txt log. Thanks!