Announcement Banner
UNSOLVED

FraserN

updated

22 years ago

F

FraserN

4 Posts

0

8897

February 1st, 2005 19:00

Spyware? - Again

Hi,
Sorry to post yet another Spyware/Adware problem but it seems to be a common theme.
Last week I encountered a problem which consisted of my IE homepage being hijacked AND an advertisment replacing my desktop image - 'WARNING! YOU'RE IN DANGER! .........' (for software to delete data from your PC). 
I have run Ad-Aware SE Personal, Spybot and SpySubtract software and deleted/fixed everything indicated by these. 
I also ran CWShredder but this did not identify anything.
I have deleted the image C:\WINDOWS\desktop.html and now have a blank grey screen as a background to my usual icons.
My Homepage is OK now but there is something present that still attempts to load the desktop image.
Way out of my depth with this.
HijackThis file is shown below.
Any help appreciated.
Fraser
 
 
Logfile of HijackThis v1.99.0
Scan saved at 21:42:49, on 01/02/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\mshelp32.exe
C:\WINDOWS\System32\cmd32.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\SED\SED.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Fraser\Application Data\eetu.exe
C:\WINDOWS\System32\r?gsvr32.exe
C:\Program Files\interMute\SpySubtract\SpySub.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Fraser\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: (no name) - {4523B332-0625-4D1D-AA0C-D6A30BC60466} - C:\WINDOWS\System32\poahji.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {A708A39C-8DA7-4e36-B3B0-0A1FFAFD4B6D} - C:\WINDOWS\system32\javafix3.dll
O2 - BHO: (no name) - {AC746932-A083-8F09-8013-8B1D813010E7} - C:\WINDOWS\System32\nzjzcpiq.dll
O2 - BHO: AntiSpyware Class - {C6176B04-8896-4446-9939-E00EE94C420F} - C:\WINDOWS\System32\ash.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_5_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mshelp32] C:\WINDOWS\System32\mshelp32.exe
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\cmd32.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [db5uL8dH] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [AdStatus Service] C:\Program Files\AdStatus Service\AdStatServ.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [W2Ex] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [db5uL8ÏÔ@ÔÁß]­ú"ü‰üC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [bsbav] C:\WINDOWS\bsbav.exe
O4 - HKLM\..\Run: [¢‰¸u0–4C
}ïÁzî[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\Run: [¢‰¸K0¨4W
}ïÁzî[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\qpexcccd.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msjava critical update] c:\windows\jjfixer.exe
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Fraser\Application Data\eetu.exe
O4 - HKCU\..\Run: [Smm] C:\WINDOWS\System32\r?gsvr32.exe
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner\RegClean.exe"
O4 - Startup: WindowsUpdate82427[1].exe
O4 - Global Startup: AOL 8.0 Tray Icon.lnk = C:\Program Files\AOL 8.0\aoltray.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab30149.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab30149.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v6.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
 
  • Midnight Star

    4791 Posts

    316

    0

    Posted February 2nd, 2005 00:00

    Fraser N,

    Let's see what we can do...



    Go to www.trendmicro.com, and then:

    1. Click " Free Online Scan".
    2. Click " Scan now, it's free".

    It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down:

    1. Select all available drives.
    2. Check(tick) " Auto Clean".
    3. Click " Scan".

    When it completes, post back the full filename of any files that cannot be cleaned or deleted.



    Download the Adware.Istbar removal utility from Symantec and following the instructions on the same page.



    Run HiJackThis then:

    1. Click " Config..."
    2. Click " Misc Tools"
    3. Click " Open Process manager"

    -

    Next, while holding down the CTRL key, locate ( if present) and click on ( highlight) each of the following:

    C:\WINDOWS\System32\mshelp32.exe
    C:\Program Files\SED\SED.exe
    C:\Documents and Settings\Fraser\Application Data\eetu.exe
    C:\WINDOWS\System32\r?gsvr32.exe

    Now double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.



    Now, let's open a command prompt and unregister the dll(s) we're going to remove, by entering the following:

    regsvr32 /u javafix3.dll
    regsvr32 /u nzjzcpiq.dll
    regsvr32 /u ash.dll

    It's ok, if these aren't found or 'error' out. If you want, just copy and paste the individual lines to the command prompt to save on the typing.




    Run HiJackThis and click " Scan", then check(tick) the following, if present:


    O2 - BHO: (no name) - {4523B332-0625-4D1D-AA0C-D6A30BC60466} - C:\WINDOWS\System32\poahji.dll (file missing)
    O2 - BHO: (no name) - {A708A39C-8DA7-4e36-B3B0-0A1FFAFD4B6D} - C:\WINDOWS\system32\javafix3.dll
    O2 - BHO: (no name) - {AC746932-A083-8F09-8013-8B1D813010E7} - C:\WINDOWS\System32\nzjzcpiq.dll
    O2 - BHO: AntiSpyware Class - {C6176B04-8896-4446-9939-E00EE94C420F} - C:\WINDOWS\System32\ash.dll

    O4 - HKLM\..\Run: [mshelp32] C:\WINDOWS\System32\mshelp32.exe
    O4 - HKLM\..\Run: [AdStatus Service] C:\Program Files\AdStatus Service\AdStatServ.exe
    O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
    O4 - HKLM\..\Run: [bsbav] C:\WINDOWS\bsbav.exe
    O4 - HKCU\..\Run: [msjava critical update] c:\windows\jjfixer.exe
    O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Fraser\Application Data\eetu.exe
    O4 - HKCU\..\Run: [Smm] C:\WINDOWS\System32\r?gsvr32.exe
    O4 - Startup: WindowsUpdate82427[1].exe


    Now, with all windows closed except HiJackThis, click " Fix checked".



    Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:

    folders...

    C:\Program Files\SED
    C:\Program Files\AdStatus Service
    C:\Program Files\ISTsvc

    files...

    C:\WINDOWS\System32\mshelp32.exe
    C:\Documents and Settings\Fraser\Application Data\eetu.exe
    C:\WINDOWS\system32\javafix3.dll
    C:\WINDOWS\System32\nzjzcpiq.dll
    C:\WINDOWS\System32\ash.dll
    C:\WINDOWS\bsbav.exe
    c:\windows\jjfixer.exe
    C:\WINDOWS\qpexcccd.exe

    Search for...

    WindowsUpdate82427[1].exe

    ...using " Start | Search...".

    -

    Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".



    Post back a new log.

    -

    Mike.

    Edits: Fixed a broken, indirect link. Thanks 100mph ... :)

    Message Edited by Midnight Star on 02-01-2005 10:49 PM

  • FraserN

    4 Posts

    316

    0

    Posted February 2nd, 2005 23:00

    Mike,

    Thanks for the advice, it’s taken 4 hours to scan, carefully follow your instructions and report back so here goes with the results:



    Results of Trend Micro Housecall scan:

    Initial message reads ‘Clean unsuccessful’ TROJ_ISTBAR.GM.

    Scan lists 74 files ‘non cleanable or cannot access’!

    C:\Documents and Settings\Arran\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-41742b8a-307032df.zip*Gummy.class*

    C:\Documents and Settings\Arran\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arch22776.jar-68c62f3c-167f3abb.zip*RunString.class*

    C:\Documents and Settings\Arran\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arch22776.jar-68c62f3c-167f3abb.zip*Colors.class*

    C:\Documents and Settings\Arran\Local settings\Temp\Patch221.exe

    C:\Documents and Settings\Arran\Local settings\Temp\Rem54.exe

    C:\Documents and Settings\Arran\Local settings\Temp\_update.dat

    C:\Documents and Settings\Arran\3.dat

    C:\Documents and Settings\Arran\4.dat

    C:\Documents and Settings\Arran\6.dat

    C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-1466ed40-713f166b.class

    C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-56bf106c-605a363a.class

    C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3jar-5ef20017-2a5a5ce9.zip*Gummy.class*

    C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3jar-f30ee60-21874800.zip*Gummy.class*

    C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arc.jar-31224e69-20a79f5e.zip*Dummy.class*

    C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arc.jar-36dfcd99-2104661d.zip*Dummy.class*

    C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-79c87584-713d8a4e.zip*BlackBox.class*

    C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-79c87584-713d8a4e.zip*VB.class*

    C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-79c87584-713d8a4e.zip*Dummy.class*

    C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-79c87584-713d8a4e.zip*Beyond.class*

    C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv283.jar-35dl530c-3551aecb.zip*Dummy.class*

    C:\Documents and Settings\Fraser\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv453.lfl6a0fa-55152ddf.zip*Dummy.class*

    C:\Documents and Settings\Fraser\LocalSettings\Temp\itlWe.exe

    C:\Documents and Settings\Fraser\LocalSettings\Temp\SEGCRL.exe

    C:\Documents and Settings\Fraser\LocalSettings\Temp\_update.dat

    C:\Documents and Settings\Jane\3.dat

    C:\Documents and Settings\Jane\4.dat

    C:\Documents and Settings\Jane\6.dat

    C:\Documents and Settings\Jordan\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\SecurityClassLoader.class-lac02c55-210de88b.class

    C:\Documents and Settings\Jordan\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\SecurityClassLoader.class-305f4c99-32d096.class

    C:\Documents and Settings\Jordan\Local Settings\Temp\1RWcme.exe

    C:\Documents and Settings\Jordan\Local Settings\Temp\2atnoG.exe

    C:\Documents and Settings\Jordan\Local Settings\Temp\aqhEq3.exe

    C:\Documents and Settings\Jordan\Local Settings\Temp\cNsYub.exe

    C:\Documents and Settings\Jordan\Local Settings\Temp\liCroN.exe

    C:\Documents and Settings\Jordan\Local Settings\Temp\RwBwSN.exe

    C:\Documents and Settings\Jordan\Local Settings\Temp\TLw3Be.exe

    C:\Documents and Settings\Jordan\Local Settings\Temp\uEBOvb.exe

    C:\Documents and Settings\Jordan\Local Settings\Temp\vHshhK.exe

    C:\Documents and Settings\Jordan\Local Settings\Temp\xbyb7c.exe

    C:\Documents and Settings\Jordan\3.dat

    C:\Documents and Settings\Jordan\4.dat

    C:\Documents and Settings\Jordan\6.dat

    C:\Documents and Settings\Taylor\3.dat

    C:\Documents and Settings\Taylor\4.dat

    C:\Documents and Settings\Taylor\6.dat

    C:\ProgramFiles\WindowsMediaPlayer\wmplayer.exe.tmp

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP228\A0056063.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP229\A0056111.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP293\A0075874.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP293\A0075875.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP293\A0075886.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP293\A0075887.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP293\A0075907.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP293\A0075910.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP295\A0076902.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP295\A0076904.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP302\A0079038.dll

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP302\A0081135.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP303\A0081198.dll

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP304\A0081218.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP304\A0081225.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP304\A0081227.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP322\A0081643.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP322\A0081644.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP322\A0081675.dll

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP322\A0081934.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP325\A0083115.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP334\A0083960.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP344\A0083962.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP344\A0084065.exe

    C:\SystemVolumeInformation\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}\RP344\A0084067.exe

    C:\WINDOWS\DownloadedProgramFiles\VM.exe

    C:\WINDOWS\SYSTEM32\akrules.dll

    C:\WINDOWS\Temp\akrules.dll



    Downloaded and ran the Adware.Istbar removal tool FxIstbar.exe

    Scanned OK then appeared to reach a loop where it scanned the same files over and over again C:\SystemVolumeInformation\_restore{B37680B2-B……….. so stopped scan



    Ran HiJackThis and ‘Killed’ the following:

    C:\WINDOWS\System32\mshelp32.exe
    C:\Program Files\SED\SED.exe
    C:\Documents and Settings\Fraser\Application Data\eetu.exe
    C:\WINDOWS\System32\r?gsvr32.exe


    Opened command prompt and unregistered the following:

    regsvr32 /u javafix3.dll
    regsvr32 /u nzjzcpiq.dll
    regsvr32 /u ash.dll


    Ran HiJackThis and found and fixed the following:

    O2 - BHO: (no name) - {A708A39C-8DA7-4e36-B3B0-0A1FFAFD4B6D} - C:\WINDOWS\system32\javafix3.dll

    O4 - HKLM\..\Run: [mshelp32] C:\WINDOWS\System32\mshelp32.exe
    O4 - HKLM\..\Run: [AdStatus Service] C:\Program Files\AdStatus Service\AdStatServ.exe
    O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
    O4 - HKLM\..\Run: [bsbav] C:\WINDOWS\bsbav.exe
    O4 - HKCU\..\Run: [msjava critical update] c:\windows\jjfixer.exe
    O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Fraser\Application Data\eetu.exe
    O4 - HKCU\..\Run: [Smm] C:\WINDOWS\System32\r?gsvr32.exe
    O4 - Startup: WindowsUpdate82427[1].exe


    Deleted - C:\Program Files\SED and C:\Program Files\AdStatus Service

    However C:\Program Files\ISTsvc was in use and could not delete. Not present in ‘Safe Mode’!

    Deleted - C:\WINDOWS\System32\mshelp32.exe and C:\WINDOWS\System32\nzjzcpiq.dll

    Access denied to C:\WINDOWS\System32\ash.dll  but deleted in ‘Safe mode’

    Others not found:
    C:\Documents and Settings\Fraser\Application Data\eetu.exe
    C:\WINDOWS\system32\javafix3.dll
    C:\WINDOWS\bsbav.exe
    C:\windows\jjfixer.exe
    C:\WINDOWS\qpexcccd.exe
    WindowsUpdate82427[1].exe


    Ran HiJackThis log to follow as exceeded 2000 characters!

    Thanks again for the help.

    Fraser

  • Midnight Star

    4791 Posts

    316

    0

    Posted February 2nd, 2005 23:00

    Fraser N,
     
    Ok, let's start out by clearing the temporary files and system restore area; that should remove most of the bad files that HouseCall couldn't clean,and hopefully keep the Symantec tool from looping.
     


    To clear the cached java files, which are also called ' jar' files:
     
    1.  Click " Start"
    2.  Click " Control Panel"
    3.  Click " Other Control Panel Options".
    4.  Cick " Java Plug-in".
     
        ( when the Java plug-in starts up)
     
    5.  Click the " Cache" tab.
    6.  Click " Clear"
    7.  Click " Yes".
    8.  Exit the " Java(TM) Plug-in Control Panel".
     


    1.  Run " Disk Cleanup" and allow it to remove everything it finds.
     
    2.  Disable, then re-enable system restore; with a reboot in-between. Then immediately create a new system point manually.
     


    Go to Add/Remove programs and remove(uninstall) the following, if present:
     
        Windows AdStatus
     
    The above could appear anywhere within the entry. Be careful not to remove any personal or system software.
     


    Download the Adware.Istbar removal utility from Symantec and following the instructions on the same page.
     


    Run HiJackThis then:
    1.  Click " Config..."
    2.  Click " Misc Tools"
    3.  Click " Open Process manager"
     
    -
     
    Next, while holding down the CTRL key, locate ( if present) and click on ( highlight) each of the following:
     
        C:\WINDOWS\cngwqfu.exe
        C:\Program Files\ISTsvc\istsvc.exe
        C:\WINDOWS\qpexcccd.exe
     
    Now double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.
     


    Run HiJackThis and click " Scan", then check(tick) the following, if present:
     

    R3 - Default URLSearchHook is missing
     
    O2 - BHO: (no name) - {28EA8754-0D69-47BC-AE0A-AE2D6B9B9292} - C:\WINDOWS\System32\nhkpaaa.dll (file missing)
     
    O4 - HKLM\..\Run: [db5uL8dH] C:\WINDOWS\qpexcccd.exe
    O4 - HKLM\..\Run: [W2Ex] C:\WINDOWS\qpexcccd.exe
    O4 - HKLM\..\Run: [db5uL8ÏÔ@ÔÁß]­ú"ü‰üC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\qpexcccd.exe
    O4 - HKLM\..\Run: [Windows AdStatus] C:\Program Files\Windows AdStatus\WinStat.exe
    O4 - HKLM\..\Run: [fmsVpUMU] C:\WINDOWS\cngwqfu.exe
    O4 - HKLM\..\Run: [tol] C:\WINDOWS\tol.exe
    O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
    O4 - Startup: WindowsUpdate82427[1].exe
     

    Now, with all windows closed except HiJackThis, click " Fix checked".
     


    Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
     
    folders...
     
        C:\Program Files\ISTsvc
        ü‰üC:\Program Files\ISTsvc
        C:\Program Files\Windows AdStatus
     
    files...
     
        C:\WINDOWS\cngwqfu.exe
        C:\WINDOWS\qpexcccd.exe
        C:\WINDOWS\tol.exe
     
    Search for...
     
        WindowsUpdate82427[1].exe
     
    ...using " Start | Search...".
     
    -
    Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".
     


    Post back a new log.
     
    -
     
    Mike.
     
  • FraserN

    4 Posts

    316

    0

    Posted February 2nd, 2005 23:00

    Ran HiJackThis log:

     

    Logfile of HijackThis v1.99.0

    Scan saved at 01:26:43, on 03/02/2005

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

     

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\LEXBCES.EXE

    C:\WINDOWS\system32\LEXPPS.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\System32\CTsvcCDA.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe

    C:\Program Files\Norton AntiVirus\navapsvc.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\wanmpsvc.exe

    C:\WINDOWS\System32\MsPMSPSv.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\BCMSMMSG.exe

    C:\WINDOWS\system32\dla\tfswctrl.exe

    C:\Program Files\Dell\Media Experience\PCMService.exe

    C:\WINDOWS\System32\DSentry.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\Program Files\Real\RealPlayer\RealPlay.exe

    C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\QuickTime\qttask.exe

    C:\Program Files\Dell AIO Printer A940\dlbabmon.exe

    C:\WINDOWS\System32\cmd32.exe

    C:\WINDOWS\System32\ctfmon.exe

    C:\WINDOWS\cngwqfu.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe

    C:\WINDOWS\System32\wuauclt.exe

    C:\Program Files\interMute\SpySubtract\SpySub.exe

    C:\Program Files\ISTsvc\istsvc.exe

    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE

    C:\Documents and Settings\Fraser\Desktop\HijackThis.exe

     

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    R3 - Default URLSearchHook is missing

    F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe

    O2 - BHO: (no name) - {28EA8754-0D69-47BC-AE0A-AE2D6B9B9292} - C:\WINDOWS\System32\nhkpaaa.dll (file missing)

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll

    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_5_0.dll

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe

    O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup

    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE

    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"

    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe

    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"

    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

    O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"

    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\cmd32.exe internat.dll,LoadKeyboardProfile

    O4 - HKLM\..\Run: [db5uL8dH] C:\WINDOWS\qpexcccd.exe

    O4 - HKLM\..\Run: [W2Ex] C:\WINDOWS\qpexcccd.exe

    O4 - HKLM\..\Run: [db5uL8ÏÔ@ÔÁß]­ú"ü‰üC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\qpexcccd.exe

    O4 - HKLM\..\Run: [¢‰¸u0–4C


    }ïÁzî­[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\qpexcccd.exe

    O4 - HKLM\..\Run: [¢‰¸K0¨4W


    }ïÁzî­[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\cngwqfu.exe

    O4 - HKLM\..\Run: [Windows AdStatus] C:\Program Files\Windows AdStatus\WinStat.exe

    O4 - HKLM\..\Run: [fmsVpUMU] C:\WINDOWS\cngwqfu.exe

    O4 - HKLM\..\Run: [tol] C:\WINDOWS\tol.exe

    O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

    O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner\RegClean.exe"

    O4 - Startup: WindowsUpdate82427[1].exe

    O4 - Global Startup: AOL 8.0 Tray Icon.lnk = C:\Program Files\AOL 8.0\aoltray.exe

    O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab30149.cab

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab

    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab30149.cab

    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab

    O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab

    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v6.cab

    O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe

    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

    O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe

    O23 - Service: Intel NCS NetService - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe

    O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

    O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

     

    I’m beginning to lose the will to live so I am going to call it a day for today, I hope this all makes sense.

    Regards

    Fraser

    Message Edited by FraserN on 02-02-2005 07:47 PM

  • Midnight Star

    4791 Posts

    316

    0

    Posted February 4th, 2005 01:00

    Fraser N,

    Let's start with these. When your done, post back the results of each, and let me know if they we're able to locate and remove anything.



    Download the Backdoor Agent cleanup utility from Symantec and follow the instructions on their page.



    Download, unzip to your desktop CWShredder and run it, then:

    1. Click " Check For Update"

    ( If an update isn't available, skip to step #4.)

    2. Click " Click here to Download the upate".
    3. When the new version has been downloaded, click " Save".

    4. Click " Fix ->"



    Download, unzip to your desktop About:Buster and run it, then:

    1. Click " Update".
    2. Click " Check For Update"

    ( If no new version is available, skip to step #4.)

    3. Click " Download Update", and wait for it to be installed.
    4. Click " Start".

    ( Wait for the initial ADS scan to complete.)

    5. Click "Yes", to shutdown any IE session currently open.

    ( Wait for the about:blank scan to complete.)

    6. Click " Ok", to scan once more.
    7. Click " Yes", to shutdown any IE sessions currently open.
    8. Click " Yes", to begin the second pass.

    9. Click " Save log", and post this log back along with your new log.
    10. Click " Exit".
    11. Click " Exit".



    When your done, post back a new log.

    -

    Mike.
  • FraserN

    4 Posts

    316

    0

    Posted February 16th, 2005 20:00

    Hi

    Many thanks for your time trying to sort out my adware/spyware problem. 

     

    Things got a bit out of control - my HijackThis logs were too big to post and I was getting more propbems each time I attempted to read your messages.  I cut my losses and have paid for someone to rebuild my PC from scratch, he cloned the hard drive and then moved all my data over to the newly installed 'clean' PC.  I feel rather frustrated at not being able to sort out the problems but I guess I had spent about 25hrs and the situation didn't seem to be getting any better! 

    Thanks again for your time.

    Keep up the good work!

    Fraser

    fraser 

  • Midnight Star

    4791 Posts

    316

    0

    Posted February 22nd, 2005 19:00

    Fraser,
     
    Anytime! Glad to hear you we're able to finally get everything sorted out.
     
    Mike.