This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Stubborn Trojan Or Virus Hides Well

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Have run AdAware & Spybot S&D, removing/cleaning all found excit MRUs. Installed Norton Antivirus which won't run after install. Preinstall scan found msjarun.exe but could not repair or delete it, and I can't find it in the location NAV reported. Have been rebooting between runs - original scans cleaned hundreds of files/components, but there is clearly something that will not allow itself to be found. Tried to run HiJackThis but it would not start. Neither will regedit or Task Manager. Regedit and Taskmanager will run in safe mode. Did not try HJT this way - will it return any useful information from safe mode if malicious process is not running? It is possible IE search is hijacked, as occasionally get message that search page cannot be found. Something appears to be tampering with hosts file as well - some web sites are blocked, hosts file has 28 entries mainly antivirus sites like Symantec and McAfee. I #'d out several of interest to me, no overall improvement. The file has no localhost entry. Symantec support was alarmed that there was also no copyright information or anything else, and didn't want me to save changes. Thanks in advance for everyone's help - I will try to follow whatever instructions you have, am not a PC novice but also not overly technical, I am just out of places to look and tools to try.
Greetings and welcome to TomCoyote.org!

Some types of viral infections stop Hijack This! from running. I have had succeses if your rename "hijackthis.exe" to something else like "monday.exe".

Or, you could try to run Hijack This! while in "safe" mode.

I did find one link that suggested that "msjarun.exe" was related to the "W32/Gaobot.worm" family of infections.

If you succeed in getting a log, please post it in this thread.

If you can get to these sites, a good thing to try would be some online virus scans:

Trend-Micro:
http://housecall.trendmicro.com/housecall/start_corp.asp

Panda:
http://www.pandasoftware.com/activescan/

Etrust:
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

Choose fix or clean.

Let them remove any infections found. Reboot inbetween each scan.

Let me know how things go.
:)
Thank you, it's a relief to have some guidance before facing fdisk. I'm running FxGaobot, tool from Symantec. Pretty much can't get to anything online - can connect but can't get to sites (intermittently). When Panda was attempted, there was an error during trying to install its ActiveX controls. I was able to run HJT this morning (in regular mode, not safe mode) and the logfile is attached to this message. Thanks again!
FxGaobot finished. Its logfile is below. At completion, Symantec recommended:

The following two patched be installed:
The DCOMRPC vulnerability
http://www.microsoft.com/technet/security/…in/MSO3-026.asp
The WebDay vulnerability
http://www.microsoft.com/technet/security/…in/MSO3-007.asp

Seems like a good idea so the effort to apply these patches in progress. Comparing the FxGaobot log to the HJT log, I'm not sure if I should think I've found and removed everything. Is there a way to tell, beyond just seeing if all the symptoms are gone after rebooting? Thanks again!

Symantec Gaobot FixTool 1.0.17.0

Deleted the value "Configuration Loader" from the registry key
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run".
Deleted the value "System Startup" from the registry key
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run".
Deleted the value "System Startup" from the registry key
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices".
Deleted the value "Video Process" from the registry key
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run".
Deleted the value "Video Process" from the registry key
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices".
Deleted the value "Win32 USB2 Driver" from the registry key
"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run".
Deleted the value "Win32 USB2 Driver" from the registry key
"HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run".
Deleted the value "Win32 USB2 Driver" from the registry key
"HKEY_USERS\S-1-5-21-1220945662-790525478-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run".
Deleted the value "Win32 USB2 Driver" from the registry key
"HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce".
Deleted the value "Win32 USB2 Driver" from the registry key
"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices".

W32.Gaobot has not been found on your computer.
Please do not "attach" log files. They should be "copied/pasted" into this post. :)

I will examine it closer, and post later this evening.

One thing you can do before then is to make a "permanant folder" for Hijack This!, and move it off your desktop.

I'm assuming that this entry in the log:

C:\Documents and Settings\joyce\Desktop\heidi.exe

Is the renamed Hijack This! exe file.

It needs to be in a folder of it's own because it makes "backups" when you fix things with it. These backups are important. If you accidentally fix the wrong thing, it is possible to restore them, provided the backup file is still around. If all the files related to Hijack This! are in a folder of it's own, there is less chance the backup is accidentally destroyed.

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT.
MOVE HijackThis into this folder.

If required a tutorial is here = Hijackthis Folder Tutorial

Will post later….

M68 :)

Here is your log for all to see:

Logfile of HijackThis v1.98.2
Scan saved at 1:06:37 PM, on 9/8/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\SYSCFG16.EXE
C:\WINDOWS\System32\scdewp.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\System32\bippgq.exe
C:\WINDOWS\System32\wmplayer.exe
C:\WINDOWS\System32\reqxdwe.exe
C:\WINDOWS\System32\voltio.exe
C:\WINDOWS\System32\mobsynca.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Symantec\ACT\ACTLDR.EXE
C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\System32\hpoipm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ftp.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\MDM.EXE
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\System32\cidaemon.exe
C:\Documents and Settings\joyce\Desktop\heidi.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://msn.com/
O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\localNRD.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [wpds.exe] C:\WINDOWS\System32\doriot.exe
O4 - HKLM\..\Run: [Windows System Configuration] C:\WINDOWS\SYSCFG16.EXE
O4 - HKLM\..\Run: [Windows DLL Loader] C:\WINDOWS\SYSCFG16.EXE
O4 - HKLM\..\Run: [Windows Registry Scan] regscan32.exe
O4 - HKLM\..\Run: [nqectk] C:\WINDOWS\System32\scdewp.exe
O4 - HKLM\..\Run: [System Security Updates] bippgq.exe
O4 - HKLM\..\Run: [Media Player] wmplayer.exe
O4 - HKLM\..\Run: [Configuration Loader] syscfg32.exe
O4 - HKLM\..\Run: [Win32 USB2 Driver] svchosting.exe
O4 - HKLM\..\Run: [SpyBlocs] C:\Program Files\SpyBlocs\SpyBlocs.exe
O4 - HKLM\..\Run: [Microsoft Search Companion] pgexzrirk.exe
O4 - HKLM\..\Run: [Video Process] reqxdwe.exe
O4 - HKLM\..\Run: [Win32 USB2.0 Driver] w32usb2.exe
O4 - HKLM\..\Run: [Microsoft Update Machine] wuamgrd.exe
O4 - HKLM\..\Run: [Microsoft JavaVM] msjarun.exe
O4 - HKLM\..\Run: [System Startup] voltio.exe
O4 - HKLM\..\Run: [Mobile Synchronization Service] mobsynca.exe
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\cxargbt.exe
O4 - HKLM\..\RunServices: [Windows Registry Scan] regscan32.exe
O4 - HKLM\..\RunServices: [System Security Updates] bippgq.exe
O4 - HKLM\..\RunServices: [Media Player] wmplayer.exe
O4 - HKLM\..\RunServices: [Win32 USB2 Driver] svchosting.exe
O4 - HKLM\..\RunServices: [Microsoft Search Companion] pgexzrirk.exe
O4 - HKLM\..\RunServices: [Video Process] reqxdwe.exe
O4 - HKLM\..\RunServices: [Win32 USB2.0 Driver] w32usb2.exe
O4 - HKLM\..\RunServices: [Microsoft Update Machine] wuamgrd.exe
O4 - HKLM\..\RunServices: [Microsoft JavaVM] msjarun.exe
O4 - HKLM\..\RunServices: [System Startup] voltio.exe
O4 - HKLM\..\RunServices: [Mobile Synchronization Service] mobsynca.exe
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [wpds.exe] C:\WINDOWS\System32\doriot.exe
O4 - HKCU\..\Run: [Microsoft JavaVM] msjarun.exe
O4 - HKCU\..\Run: [System Security Updates] bippgq.exe
O4 - HKCU\..\Run: [Win32 USB2 Driver] svchosting.exe
O4 - HKCU\..\Run: [Microsoft Search Companion] pgexzrirk.exe
O4 - HKCU\..\Run: [Video Process] reqxdwe.exe
O4 - HKCU\..\Run: [Win32 USB2.0 Driver] w32usb2.exe
O4 - HKCU\..\Run: [Microsoft Update Machine] wuamgrd.exe
O4 - HKCU\..\Run: [System Startup] voltio.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunServices: [Microsoft Search Companion] pgexzrirk.exe
O4 - HKCU\..\RunServices: [Video Process] reqxdwe.exe
O4 - Global Startup: ACT! Speed Loader.lnk = C:\Program Files\Symantec\ACT\ACTLDR.EXE
O4 - Global Startup: HPAiODevice(hp officejet 7100 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0B70F0A-B4CE-4B0E-B116-84B1EF2EB8A0}: NameServer = 207.69.188.187 207.69.188.186

Thank you, I'm sorry I didn't realize I shouldn't attach it and I appreciate your patience. I'll do as you instruct regarding the HJT folder. Yes, heidi.exe is the renamed hijack.exe. Thanks again for your help.
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This! and fix these items:

O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\localNRD.dll

O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll

O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll

O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll

O4 - HKLM\..\Run: [wpds.exe] C:\WINDOWS\System32\doriot.exe

O4 - HKLM\..\Run: [Windows System Configuration] C:\WINDOWS\SYSCFG16.EXE

O4 - HKLM\..\Run: [Windows DLL Loader] C:\WINDOWS\SYSCFG16.EXE

O4 - HKLM\..\Run: [Windows Registry Scan] regscan32.exe

O4 - HKLM\..\Run: [nqectk] C:\WINDOWS\System32\scdewp.exe

O4 - HKLM\..\Run: [System Security Updates] bippgq.exe

O4 - HKLM\..\Run: [Configuration Loader] syscfg32.exe

O4 - HKLM\..\Run: [Win32 USB2 Driver] svchosting.exe

O4 - HKLM\..\Run: [Microsoft Search Companion] pgexzrirk.exe

O4 - HKLM\..\Run: [Video Process] reqxdwe.exe

O4 - HKLM\..\Run: [Win32 USB2.0 Driver] w32usb2.exe

O4 - HKLM\..\Run: [Microsoft Update Machine] wuamgrd.exe

O4 - HKLM\..\Run: [Microsoft JavaVM] msjarun.exe

O4 - HKLM\..\Run: [System Startup] voltio.exe

O4 - HKLM\..\Run: [Mobile Synchronization Service] mobsynca.exe

O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\cxargbt.exe

O4 - HKLM\..\RunServices: [Windows Registry Scan] regscan32.exe

O4 - HKLM\..\RunServices: [System Security Updates] bippgq.exe

O4 - HKLM\..\RunServices: [Win32 USB2 Driver] svchosting.exe

O4 - HKLM\..\RunServices: [Microsoft Search Companion] pgexzrirk.exe

O4 - HKLM\..\RunServices: [Video Process] reqxdwe.exe

O4 - HKLM\..\RunServices: [Win32 USB2.0 Driver] w32usb2.exe

O4 - HKLM\..\RunServices: [Microsoft Update Machine] wuamgrd.exe

O4 - HKLM\..\RunServices: [Microsoft JavaVM] msjarun.exe

O4 - HKLM\..\RunServices: [System Startup] voltio.exe

O4 - HKLM\..\RunServices: [Mobile Synchronization Service] mobsynca.exe

O4 - HKCU\..\Run: [wpds.exe] C:\WINDOWS\System32\doriot.exe

O4 - HKCU\..\Run: [Microsoft JavaVM] msjarun.exe

O4 - HKCU\..\Run: [System Security Updates] bippgq.exe

O4 - HKCU\..\Run: [Win32 USB2 Driver] svchosting.exe

O4 - HKCU\..\Run: [Microsoft Search Companion] pgexzrirk.exe

O4 - HKCU\..\Run: [Video Process] reqxdwe.exe

O4 - HKCU\..\Run: [Win32 USB2.0 Driver] w32usb2.exe

O4 - HKCU\..\Run: [Microsoft Update Machine] wuamgrd.exe

O4 - HKCU\..\Run: [System Startup] voltio.exe

O4 - HKCU\..\RunServices: [Microsoft Search Companion] pgexzrirk.exe

O4 - HKCU\..\RunServices: [Video Process] reqxdwe.exe


Reboot in "safe" mode. Use the link in my signature to tell you how if necessary.

Find and delete:

c:\windows\localnrd.dll <β€” file

c:\windows\syscfg16.exe <β€” file

c:\windows\system32\bippgq.exe <β€” file

c:\windows\system32\cxargbt.exe <β€” file

c:\windows\system32\doriot.exe <β€” file

c:\windows\system32\mobsynca.exe <β€” file

c:\windows\system32\msbe.dll <β€” file

c:\windows\system32\mscb.dll <β€” file

c:\windows\system32\nvms.dll <β€” file

c:\windows\system32\reqxdwe.exe <β€” file

c:\windows\system32\scdewp.exe <β€” file

c:\windows\system32\voltio.exe <β€” file

msjarun.exe <β€” file
(use windows explorer to find)

pgexzrirk.exe <β€” file
(use windows explorer to find)

regscan32.exe <β€” file
(use windows explorer to find)

svchosting.exe <β€” file
(use windows explorer to find)

syscfg32.exe <β€” file
(use windows explorer to find)

w32usb2.exe <β€” file
(use windows explorer to find)

wuamgrd.exe <β€” file
(use windows explorer to find)

Some malware files may be "hidden". Use the link in my signature to explain how to show "hidden" files if necessary.

Reboot in normal mode and post a new log file. :)

Here is a list of known infections on your machine:

O4 - HKLM\..\Run: [wpds.exe] C:\WINDOWS\System32\doriot.exe

Read about it here

O4 - HKLM\..\Run: [Windows System Configuration] C:\WINDOWS\SYSCFG16.EXE

Read about it here

O4 - HKLM\..\Run: [Windows Registry Scan] regscan32.exe

Read about it here

O4 - HKLM\..\Run: [Configuration Loader] syscfg32.exe

Read about it here

O4 - HKLM\..\Run: [Win32 USB2 Driver] svchosting.exe

Read about it here

O4 - HKLM\..\Run: [Win32 USB2.0 Driver] w32usb2.exe

Read about it here

O4 - HKLM\..\Run: [Microsoft Update Machine] wuamgrd.exe

Read about it here

O4 - HKLM\..\Run: [Microsoft JavaVM] msjarun.exe

Read about it here

O4 - HKLM\..\Run: [System Startup] voltio.exe

Read about it here

O4 - HKLM\..\Run: [Mobile Synchronization Service] mobsynca.exe

Read about it here

I would bet a pickled buffalo tongue that your wmplayer.exe is also infected, but that can't be proven until you are able to run the online virus scans suggested earlier(which you should try to do ASAP).

:)
I followed your instructions. I also am starting a Trend Micro scan.

Here is the latest and greatest HJT log.

Logfile of HijackThis v1.98.2
Scan saved at 8:33:58 PM, on 9/8/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\wmplayer.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\uzpdate2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Symantec\ACT\ACTLDR.EXE
C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\System32\hpoipm07.exe
c:\hjt\heidi.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://msn.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Media Player] wmplayer.exe
O4 - HKLM\..\Run: [SpyBlocs] C:\Program Files\SpyBlocs\SpyBlocs.exe
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\yaqkwn.exe
O4 - HKLM\..\Run: [zerzvpack2] uzpdate2.exe
O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\quqarcm.exe
O4 - HKLM\..\RunServices: [Media Player] wmplayer.exe
O4 - HKLM\..\RunServices: [zerzvpack2] uzpdate2.exe
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: ACT! Speed Loader.lnk = C:\Program Files\Symantec\ACT\ACTLDR.EXE
O4 - Global Startup: HPAiODevice(hp officejet 7100 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
Excellent work!!!! :thumbup:

The malware is way down to a managable size!

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This! and fix these items:

O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\yaqkwn.exe

O4 - HKLM\..\Run: [zerzvpack2] uzpdate2.exe

O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\quqarcm.exe

O4 - HKLM\..\RunServices: [zerzvpack2] uzpdate2.exe


Reboot in "safe" mode. Use the link in my signature to tell you how if necessary.

Find and delete:

c:\windows\system32\quqarcm.exe <β€” file

c:\windows\system32\uzpdate2.exe <β€” file

c:\windows\system32\yaqkwn.exe <β€” file

Some malware files may be "hidden". Use the link in my signature to explain how to show "hidden" files if necessary.

Reboot in normal mode and post a new log file. :)

OPTIONAL FIX

Remove "Incredimail" via Start > Control Panel > Add/Remove Programs.

A link about Incredimail:

http://www.langa.com/newsletters/2002/2002-10-10.htm#6

My own personal "Incredimail" Story:

A week ago my Mom was having problems with her PC being really slow. I went over and did some investigating. I disabled a few non-essential programs with the task manager, but her CPU was still running at 100%!!!!

Then I noticed the Incredimail icon in the system tray doing weird things. So I it, then exited Incredimail.

Immeadiately her CPU usage went down to 2 or 3 %.

I uninstalled Incredimail, and her machine is back to normal.
Here is the most recent HJT log. I notice that not all the keys and files HJT reported were found when I returned to do these steps. I suppose that must be a good thing. Norton is running now, and sometimes reports msjarun.exe but I cannot find the file. Also there is now a new file, C:\WINDOWS\System32\xwinrpc32.exe, and two associated registry keys, and I don't know if I should be concerned about that one. As I'm writing this, Spybot reported an attempt to add a registry key (something about Microsoft upnp Update) which I denied, but I'm concerned there might still be something lurking in here. I certainly appreciate all your help and it's a relief to be able to feel that the system might be clean, or nearly so, and I won't have to deal with reformatting the drive!

Logfile of HijackThis v1.98.2
Scan saved at 10:49:44 AM, on 9/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\wmplayer.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\xwinrpc32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Symantec\ACT\ACTLDR.EXE
C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\System32\hpoipm07.exe
c:\hjt\heidi.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://msn.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Media Player] wmplayer.exe
O4 - HKLM\..\Run: [SpyBlocs] C:\Program Files\SpyBlocs\SpyBlocs.exe
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [asdx] xwinrpc32.exe
O4 - HKLM\..\RunServices: [Media Player] wmplayer.exe
O4 - HKLM\..\RunServices: [asdx] xwinrpc32.exe
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: ACT! Speed Loader.lnk = C:\Program Files\Symantec\ACT\ACTLDR.EXE
O4 - Global Startup: HPAiODevice(hp officejet 7100 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
I was pretty suspicious of xwinrpc32.exe, so I googled it and the top result was a Trend Micro report of I think W.AGOBOT.OV. So, I removed the registry keys using HJT, rebooted in safe mode, deleted the file, rebooted, and re-ran HJT. Here is the HJT log taken afterwards (so this is the latest log).

Logfile of HijackThis v1.98.2
Scan saved at 11:06:11 AM, on 9/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\wmplayer.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Symantec\ACT\ACTLDR.EXE
C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\System32\hpoipm07.exe
c:\hjt\heidi.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://msn.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Media Player] wmplayer.exe
O4 - HKLM\..\Run: [SpyBlocs] C:\Program Files\SpyBlocs\SpyBlocs.exe
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\RunServices: [Media Player] wmplayer.exe
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: ACT! Speed Loader.lnk = C:\Program Files\Symantec\ACT\ACTLDR.EXE
O4 - Global Startup: HPAiODevice(hp officejet 7100 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
Great work!!! :thumbup:

We're almost there…

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This! and fix these items:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =


Reboot.

I'd like you to go here, and submit this file:

C:\WINDOWS\System32\wmplayer.exe

For an online virus check. Let me know what it says.

Post a new log file. :)
The two R0 search-related keys keep returning after reboot, and they don't appear in regedit either.

I went out on a limb a little bit this time around. I took three applications out of the Startup folder. I also removed the two wmplayer registry keys. I did go to kaspersy.com (found my hosts file had been corrupted yet again so removed all the blocked sites from it) but could not find wmplayer.exe in the location reported by HJT. I did scan the wmplayer.exe file that is in the Program Files/Windows Media Player folder. Kaspersky reported it clean, but I thought the scan acted funny, so I did not delete the file but did remove the two registry keys. In HJT I also removed the registry keys that started QuickTime and Incredimail. I believe them to be harmless, but I thought if fewer things start when Windows starts it might be easier to isolate the last issues.

There was a new registry key that had to do with TCP/IP, it set name servers to 207.69.188.187 & 186. I noticed that when starting IE in the status bar there appeared to be a number of redirects happening and I saw one of these IP addresses flash through the displayed status messages, so I made a note of the addresses and removed the registry key.

I hope I haven't been too bold in making those changes. The system seems fine right now although there are some things I haven't tested - and just now again I have a Spybot message System Startup global entry, value added, Microsoft upnp Update, msie.exe - I am denying the change.

Here is the logfile taken after the last reboot:


Logfile of HijackThis v1.98.2
Scan saved at 1:06:12 PM, on 9/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
c:\hjt\heidi.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://msn.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SpyBlocs] C:\Program Files\SpyBlocs\SpyBlocs.exe
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
Sounds like you're way ahead of the game to me. :thumbup: Two things to try with the "R0" entries that return. First, boot in "safe" mode and fix them. If that doesn't work, I have heard that "TeaTimer.exe" will sometimes prohibit registry changes. You could temporarily stop or disable that program and fix them. Good work!!! :)
Will do, as the two search and the one name server entries keep coming back.

I was finally able to get TrendMicro's online virus scan to run all the way through. It found several pests - worm.rbot.* (multiple variants), worm.bobax.c, worm.bagle.al, worm.sasser.b, troj.bagle.dam, troj.delf.ar, and bat.zapchast.c. It couldn't clean or delete reporting all the files in use. The files are reported to be in c:\Documents & Settings\localservice.NT AUTHORITY\Application Data\Share-To-Web Upload Folder\*, a folder I cannot locate.

I rebooted and re-ran TrendMicro, which reported that it removed worm.sasser-1, worm.rbot.hb. It still found 7 files infected with worm.bagle.al. I downloaded a removal tool for this from Panda, but it did not find any virus. Nevertheless, Norton AV still is being killed so something is still not right.

Latest HJT log is below. I'll try the safe mode thing to see if that works on those three entries.

Logfile of HijackThis v1.98.2
Scan saved at 3:17:25 PM, on 9/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
c:\hjt\heidi.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SpyBlocs] C:\Program Files\SpyBlocs\SpyBlocs.exe
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0B70F0A-B4CE-4B0E-B116-84B1EF2EB8A0}: NameServer = 207.69.188.187 207.69.188.186

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI