Unsolved

This post is more than 5 years old

6 Posts

4335

June 23rd, 2004 00:00

Adware.iefeats

Norton detected Adware.iefeats in file sdkpn32.exe in directory Windows/System32. Norton attempts to delete but fails. Norton recommends a manual deletion. I attempted this through Windows Explorer and get the message  "access denied". They say this is a low threat but it has changed the registry so that everytime I open Internet Explorer, it goes to a set "home page". How can I eliminate this sdkpn32.exe file? After this is eliminated, Norton provides instruction to correct the registry. 

66 Posts

June 23rd, 2004 07:00

It's easy to get rid of. Here's how I did it. I've posted this a bunch of times already, but since I'm nice I'll post it again for you:

I now have 4, count em, 4 spyware removal and spyware protection programs on my computer. They have cleaned up my system very well. AND ALL OF THEM ARE FREE. First thing you have to do is go on download.com and download these removal tools and protection tools. The first one is X-Cleaner. It's awesome, it has like 1500 different types of spyware that it can find. It can clean your Internet cache, history, EVERYTHING. Anyway, the program is really small. The download itself IS the program, so you don't have to install anything. It runs the first time you click the icon so make sure when you download it that you save it to your Desktop. Here's the link to it on download.com: http://www.download.com/X-Cleaner-Freeware-Version/3000-2092-10254992.html?tag=lst-0-1

The next program I recommend is Bazooka. It only finds stuff but it is very fast at searching and it found a lot of stuff on my computer. It doesn't remove stuff, but it's still good to have it for finding things. Here's the link for it: http://www.download.com/Bazooka-Adware-and-Spyware-Scanner/3000-8022-10247783.html?tag=lst-0-1

The next two programs are for protection mainly. First, download Spyware Blaster. It protects against everything and you should click "Enable All Protection" for the options that they give you. Just explore the options because there are a lot, including disabling Flash which has become a way for websites to put pop ups on you that you don't want. Here's Spyware Blaster: http://www.javacoolsoftware.com/sbdownload.html   Just choose a site you wanna download it from. If it's slow, cancel it and choose another site on the list.

The final program is Spybot Search and Destroy. Now, one thing I HIGHLY recommend is that you turn on the Advanced mode...Click Mode, and change from Default to Advanced. On both Spybot and Spyware Blaster there is protection on your internet HOME PAGE. It can block the home page from being tampered with. This includes from you tampering with it unless you turn the protection off. However, this is GREAT for even if you do get spyware (which you won't with two programs like this running) because the spyware won't be able to change your home page like many of them try to do. One thing I'd like to note about Spyware Blaster is that it doesn't need to stay running. You just hit close and it runs in the background, but no icon by the clock on your computer. Spybot Search and Destroy, however, has an option where you can run it by the clock. You right click on it's icon and it gives you the option of running Spybot or exiting the icon. It also has an option for Internet Explorer "page blocking" where it has different levels of protection against certain KNOWN bad web pages. Anyway, the best thing to do is update these programs as often as you can, because different types of spyware/adware are ALWAYS coming out. Here's the link to Spybot Search and Destroy: http://www.download.com/Spybot-Search-Destroy/3000-8022-10289035.html?tag=lst-0-3

The thing I suggest HIGHLY is running the X-Cleaner first. It found a bunch of spyware on my PC and removed all of it. Then after cleaning it will ask you to restart. DO IT. You must restart or the spyware will stay on your machine. I restarted, and it got rid of CoolWebSearch and the other 15 spyware/adware I had on my computer. Good luck, and remember to tinker around with all the options, because these programs are GREAT for protection and prevention. Have fun killing all that spyware!!!!

Good luck killing that spyware. I guarantee this will work and if you don't believe me, check the user ratings on download.com for those programs. Almost all of them have a 90% or better POSITIVE rating. Again, have fun killing the spyware!

2 Intern

 • 

3.9K Posts

June 23rd, 2004 20:00

And if that does not work - and it probably will not - follow the rest of this post to give us a hijackthis log to check.
=========================
Use these to remove Malware (Virus, Spyware and Adware).

First :-
Spybot S&D and Ad-aware using the settings and links provided
Here

Failing those solving your problems a post of a hijackthis log for the experts to advise.
HijackThis From Here
or one of these other links:-
http://www.merijn.org/files/hijackthis.zip
http://www.aluriasoftware.com/tools/hijackthis.zip
http://mjc1.com/mirror/hjt/

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT. Unzip HijackThis into this folder. (See this link for graphical instructions)
Then run, scan, save log, then in notepad copy the FULL log by copy and paste as a reply to this post and an expert with HijackThis Knowldge, will have a go at giving advice. A lot of posters make mistakes here in copying and pasting so reread the left info sidebar called Copy and Paste
Please note the list of experts names below, very few forum regulars here have had this training.

DO NOT FIX ANYTHING WITH HIJACKTHIS WITHOUT EXPERT ADVICE
, most of what it finds you need for normal MS Windows tasks.

Known Spyware HijackThis fighters in DellTalk - If you are, and are not on the list please PM Me.

TomCoyote (of http://tomcoyote.com/forums/index.php fame)
YoKenny (Expert at TomCoyotes, Trusted Advisor Spywareinfo)
baskar1234 (Slyware Warrior at TomCoyotes, Trusted Advisor Spywareinfo)
ChrisRLG (Classroom Teacher at TomCoyotes, Trusted Advisor Net-Intergration and Spywareinfo, Spyware Fighter at Wilders)
Tuxedo Jack (Slyware Warrior at TomCoyotes, Trusted Advisor Spywareinfo)
Yellowhammer (Slyware Warrior at Tomcoyotes, Trusted Advisor at Net-Integration, First Responder at Computer Cops)
tashi (Slyware Warrior at TomCoyotes, Trusted Advisor Spywareinfo)
therock247uk (In Training at TomCoyotes and Spywareinfo)
irelynmisses (In Training at TomCoyotes and Spywareinfo)
Texruss (Spyware Fighter at Wildersecurity, Slyware Warrior at TomCoyotes)
PGPhantom (Trusted Advisor at Spywareinfo)

6 Posts

June 28th, 2004 22:00

Logfile of HijackThis v1.97.7
Scan saved at 7:25:36 PM, on 6/28/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\WINDOWS\appac32.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Sunbelt Software\iHateSpam\siService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe
C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Sunbelt Software\iHateSpam\siMailProxyServer.exe
C:\Program Files\Sunbelt Software\iHateSpam\siSpamFilterEngine.exe
C:\WINDOWS\ipre.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\cxzcm.dll/sp.html#26980
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://cxzcm.dll/index.html#26980
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://cxzcm.dll/index.html#26980
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\cxzcm.dll/sp.html#26980
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://cxzcm.dll/index.html#26980
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\cxzcm.dll/sp.html#26980
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {6C66CA22-7393-6B62-A8F4-419874BE0C08} - C:\WINDOWS\addop.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [siService.exe] "C:\Program Files\Sunbelt Software\iHateSpam\siService.exe"
O4 - HKLM\..\Run: [iHatePopups.exe] "C:\Program Files\Sunbelt Software\iHatePopups\iHatePopups.exe"
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\ppe.exe
O4 - HKLM\..\Run: [ipre.exe] C:\WINDOWS\ipre.exe
O4 - HKLM\..\Run: [PestPatrolCL] C:\PROGRA~1\PESTPA~1\PestPatrolCL.exe c:\
O4 - HKLM\..\Run: [Ad-aware] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-aware.exe" +c
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKLM\..\RunOnce: [appac32.exe] C:\WINDOWS\appac32.exe
O4 - HKLM\..\RunOnce: [sysjd.exe] C:\WINDOWS\sysjd.exe
O4 - HKLM\..\RunOnce: [appay32.exe] C:\WINDOWS\system32\appay32.exe
O4 - HKLM\..\RunOnce: [addzr.exe] C:\WINDOWS\system32\addzr.exe
O4 - HKLM\..\RunOnce: [appid32.exe] C:\WINDOWS\system32\appid32.exe
O4 - HKLM\..\RunOnce: [addfv.exe] C:\WINDOWS\addfv.exe
O4 - HKLM\..\RunOnce: [ipxa32.exe] C:\WINDOWS\ipxa32.exe
O4 - HKLM\..\RunOnce: [javakc.exe] C:\WINDOWS\javakc.exe
O4 - HKLM\..\RunOnce: [netwb.exe] C:\WINDOWS\netwb.exe
O4 - Startup: Microsoft Office Outlook 2003.lnk = ?
O8 - Extra context menu item: Allow popups from this web page - C:\Program Files\Sunbelt Software\iHatePopups\allowsite.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Stop popups from this web page - C:\Program Files\Sunbelt Software\iHatePopups\denysite.htm
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: iHatePopups (HKCU)
O9 - Extra 'Tools' menuitem: iHatePopups (HKCU)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://131.204.99.250/activex/AxisCamControl.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37999.1428935185
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup144.cab

 

6 Posts

July 1st, 2004 10:00

I might note that after original post, I opened Windows in Safe Mode and deleted the file in question. This did not do away with the problem. Evidentally there is spyware/adware on my computer that keeps producing *.exe files that continue causing these annoying problems.
No Events found!

Top