This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Home Search Assistant.

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.98.2
Scan saved at 12:41:19, on 03/10/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\CTSvcCDA.exe
C:\WINNT\System32\GEARSec.exe
C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
C:\WINNT\system32\hidserv.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINNT\system32\regsvc.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINNT\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SymTray.exe
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\WINNT\SYSTEM32\starter.exe
C:\WINNT\system32\wfxsnt40.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\WINNT\System32\USBMonit.exe
C:\Program Files\Creative\ShareDLL\MediaDet.Exe
C:\WINNT\twain_32\SiPix\SCBLINK2\BLINK2CC.exe
C:\WINNT\twain_32\SiPix\SCBLINK2\USBPNP.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINNT\UsbPad.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINNT\Greenstone.bmp:pcsbq
C:\WINNT\system32\appkz32.exe
C:\Program Files\Opera75\opera.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\gdhge.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\gdhge.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\gdhge.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\gdhge.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\gdhge.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\gdhge.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\gdhge.dll/sp.html#28129
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.bbc.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.bbc.co.uk
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 62.254.32.6:8080
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2F44B042-675A-B758-1A82-FF8492CBA9DD} - C:\WINNT\d3el.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [EnsoniqMixer] C:\WINNT\SYSTEM32\starter.exe
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINNT\System32\USBMonit.exe
O4 - HKLM\..\Run: [BLINK2CC] C:\WINNT\twain_32\SiPix\SCBLINK2\BLINK2CC.exe
O4 - HKLM\..\Run: [USBPNP] C:\WINNT\twain_32\SiPix\SCBLINK2\USBPNP.exe
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [PSDrvCheck] C:\WINNT\system32\PSDrvCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [USBPAD] UsbPad.exe Install
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Bouncer RunStartup] C:\Program Files\Bouncer\LiveUpdate.exe 000
O4 - HKLM\..\Run: [msuw.exe] C:\WINNT\system32\msuw.exe
O4 - HKLM\..\Run: [appkz32.exe] C:\WINNT\system32\appkz32.exe
O4 - HKLM\..\RunOnce: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtrdr.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download all by Net Transport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: Download by Net Transport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: SYSTRAN: &Clear Translation Cache - C:\Program Files\Systran\Standard\menuClearCache.html
O8 - Extra context menu item: SYSTRAN: &Options - C:\Program Files\Systran\Standard\menuConfigure.html
O8 - Extra context menu item: SYSTRAN: &Register - C:\Program Files\Systran\Standard\menuRegister.html
O8 - Extra context menu item: SYSTRAN: &Translate - C:\Program Files\Systran\Standard\menuTranslate.html
O8 - Extra context menu item: SYSTRAN: Check for &Updates - C:\Program Files\Systran\Standard\menuUpdate.html
O8 - Extra context menu item: SYSTRAN: Translate All &Frames - C:\Program Files\Systran\Standard\menuTranslateAll.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: @sysiecom.dll,-2100 - {703436F1-3E1F-11d3-8F6B-00105A2A1D59} - C:\Program Files\Systran\Standard\MenuTranslate.html
O9 - Extra 'Tools' menuitem: @sysiecom.dll,-2102 - {703436F1-3E1F-11d3-8F6B-00105A2A1D59} - C:\Program Files\Systran\Standard\MenuTranslate.html
O9 - Extra button: @sysiecom.dll,-2103 - {703436F2-3E1F-11d3-8F6B-00105A2A1D59} - C:\Program Files\Systran\Standard\MenuTranslateAll.html
O9 - Extra 'Tools' menuitem: @sysiecom.dll,-2105 - {703436F2-3E1F-11d3-8F6B-00105A2A1D59} - C:\Program Files\Systran\Standard\MenuTranslateAll.html
O9 - Extra button: @sysiecom.dll,-2115 - {703436F3-3E1F-11d3-8F6B-00105A2A1D59} - C:\Program Files\Systran\Standard\MenuConfigure.html
O9 - Extra 'Tools' menuitem: @sysiecom.dll,-2117 - {703436F3-3E1F-11d3-8F6B-00105A2A1D59} - C:\Program Files\Systran\Standard\MenuConfigure.html
O9 - Extra button: (no name) - {703436F4-3E1F-11d3-8F6B-00105A2A1D59} - C:\Program Files\Systran\Standard\MenuClearCache.html
O9 - Extra 'Tools' menuitem: @sysiecom.dll,-2108 - {703436F4-3E1F-11d3-8F6B-00105A2A1D59} - C:\Program Files\Systran\Standard\MenuClearCache.html
O9 - Extra button: (no name) - {703436F5-3E1F-11d3-8F6B-00105A2A1D59} - C:\Program Files\Systran\Standard\MenuRegister.html
O9 - Extra 'Tools' menuitem: @sysiecom.dll,-2111 - {703436F5-3E1F-11d3-8F6B-00105A2A1D59} - C:\Program Files\Systran\Standard\MenuRegister.html
O9 - Extra button: (no name) - {703436F6-3E1F-11d3-8F6B-00105A2A1D59} - C:\Program Files\Systran\Standard\MenuUpdates.html (file missing)
O9 - Extra 'Tools' menuitem: @sysiecom.dll,-2114 - {703436F6-3E1F-11d3-8F6B-00105A2A1D59} - C:\Program Files\Systran\Standard\MenuUpdates.html (file missing)
O9 - Extra button: Magic Nettrace - {92848C13-5482-49CB-B31C-CA8D74EFF508} - C:\Program Files\Magic NetTrace\MTIE.exe
O9 - Extra 'Tools' menuitem: &Magic Nettrace - {92848C13-5482-49CB-B31C-CA8D74EFF508} - C:\Program Files\Magic NetTrace\MTIE.exe
O16 - DPF: {15AF6247-8420-4A42-B78E-6BACB05985B0} (Msoftdld Control) - http://www.moneysoft.co.uk/download/msoftdld.ocx
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) -
O16 - DPF: {858B4F85-E945-4F0C-AF65-059E0AD9EEC0} (IntraLaunch.MainControl) - file://F:\Interface\IntraLaunch.CAB
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O18 - Protocol: stibo - {FFAD3420-6D61-44F6-BA25-293F17152D79} - C:\Program Files\RS Electronic Catalogue\ProtocolHandler.dll
12:46 03/10/2004 PsService v1.1 - local and remote services viewer/controller Copyright © 2001-2003 Mark Russinovich Sysinternals - www.sysinternals.com SERVICE_NAME: Alerter Notifies selected users and computers of administrative alerts. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\services.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Alerter DEPENDENCIES : LanmanWorkstation SERVICE_START_NAME: LocalSystem SERVICE_NAME: AppMgmt Provides software installation services such as Assign, Publish, and Remove. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\services.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Application Management DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: aspnet_state Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start. TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : ASP.NET State Service DEPENDENCIES : SERVICE_START_NAME: .\ASPNET SERVICE_NAME: BITS Transfers files in the background using idle network bandwidth. If the service is stopped, features such as Windows Update, and MSN Explorer will be unable to automatically download programs and other information. If this service is disabled, any services that explicitly depend on it may fail to transfer files if they do not have a fail safe mechanism to transfer files directly through IE in case BITS has been disabled. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k BITSgroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Background Intelligent Transfer Service DEPENDENCIES : LanmanWorkstation : Rpcss : SENS : Wmi SERVICE_START_NAME: LocalSystem SERVICE_NAME: Browser Maintains an up-to-date list of computers on your network and supplies the list to programs that request it. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\services.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Computer Browser DEPENDENCIES : LanmanWorkstation : LanmanServer SERVICE_START_NAME: LocalSystem SERVICE_NAME: ccEvtMgr Symantec Event Manager TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" LOAD_ORDER_GROUP : Symantec Services TAG : 0 DISPLAY_NAME : Symantec Event Manager DEPENDENCIES : RPCSS : ccSetMgr SERVICE_START_NAME: LocalSystem SERVICE_NAME: ccPwdSvc Symantec Password Validation Service TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Symantec Password Validation DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: ccSetMgr Symantec Settings Manager TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" LOAD_ORDER_GROUP : Symantec Services TAG : 0 DISPLAY_NAME : Symantec Settings Manager DEPENDENCIES : RPCSS SERVICE_START_NAME: LocalSystem SERVICE_NAME: cisvc (null) TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\cisvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Indexing Service DEPENDENCIES : RPCSS SERVICE_START_NAME: LocalSystem SERVICE_NAME: ClipSrv Supports ClipBook Viewer, which allows pages to be seen by remote ClipBooks. TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\clipsrv.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : ClipBook DEPENDENCIES : NetDDE SERVICE_START_NAME: LocalSystem SERVICE_NAME: Creative Service for CDROM Access (null) TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\CTSvcCDA.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Creative Service for CDROM Access DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: Dhcp Manages network configuration by registering and updating IP addresses and DNS names. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\services.exe LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : DHCP Client DEPENDENCIES : Tcpip : Afd : NetBT : SYMTDI SERVICE_START_NAME: LocalSystem SERVICE_NAME: dmadmin Administrative service for disk management requests TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\dmadmin.exe /com LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Logical Disk Manager Administrative Service DEPENDENCIES : RpcSs : PlugPlay : DmServer SERVICE_START_NAME: LocalSystem SERVICE_NAME: dmserver Logical Disk Manager Watchdog Service TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\services.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Logical Disk Manager DEPENDENCIES : RpcSs : PlugPlay SERVICE_START_NAME: LocalSystem SERVICE_NAME: Dnscache Resolves and caches Domain Name System (DNS) names. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\services.exe LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : DNS Client DEPENDENCIES : Tcpip SERVICE_START_NAME: LocalSystem SERVICE_NAME: Eventlog Logs event messages issued by programs and Windows. Event Log reports contain information that can be useful in diagnosing problems. Reports are viewed in Event Viewer. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\services.exe LOAD_ORDER_GROUP : Event log TAG : 0 DISPLAY_NAME : Event Log DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: EventSystem Provides automatic distribution of events to subscribing COM components. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : Network TAG : 0 DISPLAY_NAME : COM+ Event System DEPENDENCIES : RPCSS SERVICE_START_NAME: LocalSystem SERVICE_NAME: Fax Helps you send and receive faxes TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\faxsvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Fax Service DEPENDENCIES : TapiSrv : RpcSs : PlugPlay : Spooler SERVICE_START_NAME: LocalSystem SERVICE_NAME: GEARSecurity (null) TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINNT\System32\GEARSec.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : GEARSecurity DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: GhostStartService Background service to allow Norton Ghost to perform priviledged operations TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : GhostStartService DEPENDENCIES : RPCSS SERVICE_START_NAME: LocalSystem SERVICE_NAME: HidServ (null) TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\hidserv.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : HID Input Service DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: Iprip Listens for route updates sent by routers that use the Routing Information Protocol version 1 (RIPv1). TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : RIP Listener DEPENDENCIES : RpcSS SERVICE_START_NAME: LocalSystem SERVICE_NAME: Irmon Supports infrared devices installed on the computer and detects other devices that are in range. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Infrared Monitor DEPENDENCIES : irda : RpcSs SERVICE_START_NAME: LocalSystem SERVICE_NAME: lanmanworkstation Provides network connections and communications. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\services.exe LOAD_ORDER_GROUP : NetworkProvider TAG : 0 DISPLAY_NAME : Workstation DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: LmHosts Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\services.exe LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : TCP/IP NetBIOS Helper Service DEPENDENCIES : NetBT : Afd SERVICE_START_NAME: LocalSystem SERVICE_NAME: LPDSVC Provides a TCP/IP-based printing service that uses the Line Printer protocol. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\tcpsvcs.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : TCP/IP Print Server DEPENDENCIES : Tcpip : Spooler SERVICE_START_NAME: LocalSystem SERVICE_NAME: Messenger Sends and receives messages transmitted by administrators or by the Alerter service. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\services.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Messenger DEPENDENCIES : LanmanWorkstation : NetBIOS : RpcSS SERVICE_START_NAME: LocalSystem SERVICE_NAME: mnmsrvc Allows authorized people to remotely access your Windows desktop using NetMeeting. TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\mnmsrvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : NetMeeting Remote Desktop Sharing DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: MSDTC Coordinates transactions that are distributed across two or more databases, message queues, file systems, or other transaction protected resource managers. TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\msdtc.exe LOAD_ORDER_GROUP : MS Transactions TAG : 0 DISPLAY_NAME : Distributed Transaction Coordinator DEPENDENCIES : RPCSS : SamSS SERVICE_START_NAME: LocalSystem SERVICE_NAME: MSIServer Installs, repairs and removes software according to instructions contained in .MSI files. TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\MsiExec.exe /V LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Installer DEPENDENCIES : RpcSs SERVICE_START_NAME: LocalSystem SERVICE_NAME: navapsvc Handles Norton AntiVirus Auto-Protect events. TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Norton AntiVirus Auto Protect Service DEPENDENCIES : RPCSS SERVICE_START_NAME: LocalSystem SERVICE_NAME: NetDDE Provides network transport and security for dynamic data exchange (DDE). TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\netdde.exe LOAD_ORDER_GROUP : NetDDEGroup TAG : 0 DISPLAY_NAME : Network DDE DEPENDENCIES : NetDDEDSDM SERVICE_START_NAME: LocalSystem SERVICE_NAME: NetDDEdsdm Manages shared dynamic data exchange and is used by Network DDE TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\netdde.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network DDE DSDM DEPENDENCIES : : EGrLocalSystem : Network DDE DSDM : etwork DDE : LocalSystem : Norton AntiVirus Auto Protect Service : ager SERVICE_START_NAME: LocalSystem SERVICE_NAME: netlogon Supports pass-through authentication of account logon events for computers in a domain. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\lsass.exe LOAD_ORDER_GROUP : RemoteValidation TAG : 0 DISPLAY_NAME : Net Logon DEPENDENCIES : LanmanWorkstation SERVICE_START_NAME: LocalSystem SERVICE_NAME: Netman Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections. TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Network Connections DEPENDENCIES : RpcSs SERVICE_START_NAME: LocalSystem SERVICE_NAME: NProtectService (null) TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Norton Unerase Protection DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: NtLmSsp Provides security to remote procedure call (RPC) programs that use transports other than named pipes. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\lsass.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : NT LM Security Support Provider DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: NtmsSvc Manages removable media, drives, and libraries. TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Removable Storage DEPENDENCIES : RpcSs SERVICE_START_NAME: LocalSystem SERVICE_NAME: NWCWorkstation Provides access to file and print resources on NetWare networks. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\services.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Client Service for NetWare DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: PlugPlay Manages device installation and configuration and notifies programs of device changes. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\services.exe LOAD_ORDER_GROUP : PlugPlay TAG : 0 DISPLAY_NAME : Plug and Play DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: PolicyAgent Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\lsass.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : IPSEC Policy Agent DEPENDENCIES : RPCSS SERVICE_START_NAME: LocalSystem SERVICE_NAME: ProtectedStorage Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users. TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\services.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Protected Storage DEPENDENCIES : RpcSs SERVICE_START_NAME: LocalSystem SERVICE_NAME: RasAuto Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address. TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Access Auto Connection Manager DEPENDENCIES : RasMan : Tapisrv SERVICE_START_NAME: LocalSystem SERVICE_NAME: RasMan Creates a network connection. TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Access Connection Manager DEPENDENCIES : Tapisrv SERVICE_START_NAME: LocalSystem SERVICE_NAME: RemoteAccess Offers routing services to businesses in local area and wide area network environments. TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Routing and Remote Access DEPENDENCIES : RpcSS : +NetBIOSGroup SERVICE_START_NAME: LocalSystem SERVICE_NAME: RemoteRegistry Allows remote registry manipulation. TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\regsvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Registry Service DEPENDENCIES : SERVICE_START_NAME: LocalSystem FAIL_RESET_PERIOD : 0 seconds FAILURE_ACTIONS : Restart DELAY: 1000 seconds SERVICE_NAME: RpcLocator Manages the RPC name service database. TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\locator.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Procedure Call (RPC) Locator DEPENDENCIES : LanmanWorkstation SERVICE_START_NAME: LocalSystem SERVICE_NAME: RpcSs Provides the endpoint mapper and other miscellaneous RPC services. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\svchost -k rpcss LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Procedure Call (RPC) DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: RSVP Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets. TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\rsvp.exe -s LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : QoS RSVP DEPENDENCIES : TcpIp : Afd SERVICE_START_NAME: LocalSystem SERVICE_NAME: SamSs Stores security information for local user accounts. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\lsass.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Security Accounts Manager DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: SAVScan Handles Norton AntiVirus Auto-Protect Archive Scanning TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : SAVScan DEPENDENCIES : SAVRT SERVICE_START_NAME: LocalSystem SERVICE_NAME: SBService (null) TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : ScriptBlocking Service DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: SCardDrv Provides support for legacy smart card readers attached to the computer. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINNT\System32\SCardSvr.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Smart Card Helper DEPENDENCIES : +Smart Card Reader SERVICE_START_NAME: LocalSystem SERVICE_NAME: SCardSvr Manages and controls access to a smart card inserted into a smart card reader attached to the computer. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINNT\System32\SCardSvr.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Smart Card DEPENDENCIES : PlugPlay SERVICE_START_NAME: LocalSystem SERVICE_NAME: Schedule Enables a program to run at a designated time. TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\MSTask.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Task Scheduler DEPENDENCIES : RpcSs SERVICE_START_NAME: LocalSystem SERVICE_NAME: seclogon Enables starting processes under alternate credentials TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINNT\system32\services.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : RunAs Service DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: SENS Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : Network TAG : 0 DISPLAY_NAME : System Event Notification DEPENDENCIES : EventSystem SERVICE_START_NAME: LocalSystem SERVICE_NAME: SharedAccess Provides network address translation, addressing, and name resolution services for all computers on your home network through a dial-up connection. TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Internet Connection Sharing DEPENDENCIES : RasMan SERVICE_START_NAME: LocalSystem SERVICE_NAME: SimpTcp Supports the following TCP/IP services: Character Generator, Daytime, Discard, Echo, and Quote of the Day. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\tcpsvcs.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Simple TCP/IP Services DEPENDENCIES : AFD SERVICE_START_NAME: LocalSystem SERVICE_NAME: SNMP Includes agents that monitor the activity in network devices and report to the network console workstation. TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\snmp.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : SNMP Service DEPENDENCIES : EventLog SERVICE_START_NAME: LocalSystem SERVICE_NAME: SNMPTRAP Receives trap messages generated by local or remote SNMP agents and forwards the messages to SNMP management programs running on this computer. TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\snmptrap.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : SNMP Trap Service DEPENDENCIES : EventLog SERVICE_START_NAME: LocalSystem SERVICE_NAME: Speed Disk service (null) TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Speed Disk service DEPENDENCIES : RPCSS SERVICE_START_NAME: LocalSystem SERVICE_NAME: Spooler Loads files to memory for later printing. TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\spoolsv.exe LOAD_ORDER_GROUP : SpoolerGroup TAG : 0 DISPLAY_NAME : Print Spooler DEPENDENCIES : RPCSS SERVICE_START_NAME: LocalSystem SERVICE_NAME: StiSvc (null) TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\stisvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Still Image Service DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: Symantec Core LC Symantec Core LC TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Symantec Core LC DEPENDENCIES : RPCSS SERVICE_START_NAME: LocalSystem SERVICE_NAME: SymWSC Symantec WMI Service TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : SymWMI Service DEPENDENCIES : winmgmt SERVICE_START_NAME: LocalSystem SERVICE_NAME: SysmonLog Configures performance logs and alerts. TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\smlogsvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Performance Logs and Alerts DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: TapiSrv Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service. TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Telephony DEPENDENCIES : PlugPlay : RpcSs SERVICE_START_NAME: LocalSystem SERVICE_NAME: TlntSvr Allows a remote user to log on to the system and run console programs using the command line. TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\tlntsvr.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Telnet DEPENDENCIES : RpcSs : TcpIp SERVICE_START_NAME: LocalSystem SERVICE_NAME: TrkWks Sends notifications of files moving between NTFS volumes in a network domain. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\services.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Distributed Link Tracking Client DEPENDENCIES : RpcSs SERVICE_START_NAME: LocalSystem SERVICE_NAME: UPS Manages an uninterruptible power supply (UPS) connected to the computer. TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\ups.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Uninterruptible Power Supply DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: UtilMan Starts and configures accessibility tools from one window TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\UtilMan.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Utility Manager DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: V2i Protector Administrative service for scheduling and disk imaging. TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : V2i Protector DEPENDENCIES : RPCSS : EventLog : PlugPlay SERVICE_START_NAME: LocalSystem SERVICE_NAME: Visual Studio Analyzer RPC bridge (null) TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Program Files\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\varpc.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Visual Studio Analyzer RPC bridge DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: W32Time Sets the computer clock. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\services.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Time DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: wfxsvc (null) TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS START_TYPE : 4 DISABLED ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\WFXSVC.EXE LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : WinFax PRO DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: WinMgmt Provides system management information. TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINNT\System32\WBEM\WinMgmt.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Management Instrumentation DEPENDENCIES : RPCSS SERVICE_START_NAME: LocalSystem FAIL_RESET_PERIOD : 86400 seconds FAILURE_ACTIONS : Restart DELAY: 60000 seconds : Restart DELAY: 60000 seconds SERVICE_NAME: WmdmPmSN Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Portable Media Serial Number Service DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: Wmi Provides systems management information to and from drivers. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\Services.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Windows Management Instrumentation Driver Extensions DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: wuauserv Enables the download and installation of critical Windows updates. If the service is disabled, the operating system can be manually updated at the Windows Update Web site. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k wugroup LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Automatic Updates DEPENDENCIES : SERVICE_START_NAME: LocalSystem SERVICE_NAME: WZCSVC Provides authenticated network access control using IEEE 802.1x for wired and wireless Ethernet networks. TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs LOAD_ORDER_GROUP : TDI TAG : 0 DISPLAY_NAME : Wireless Configuration DEPENDENCIES : RpcSs : Ndisuio : ProtectedStorage : WMI SERVICE_START_NAME: LocalSystem SERVICE_NAME: O?’ŽrtñåȲ$Ó (null) TYPE : 20 WIN32_SHARE_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 0 IGNORE BINARY_PATH_NAME : C:\WINNT\Greenstone.bmp:pcsbq /s LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : Remote Procedure Call (RPC) Helper DEPENDENCIES : SERVICE_START_NAME: LocalSystem
Welcome to the forum.

Please don't start multiple post, stay in one - THIS ONE

This is the bad service:
SERVICE_NAME: O?-’ŽrtñåȲ$Ó
(null)
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 0 IGNORE
BINARY_PATH_NAME : C:\WINNT\Greenstone.bmp:pcsbq /s
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Remote Procedure Call (RPC) Helper
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

Please read through the instructions before you start (you may want to print this out).

Please note that everytime you reboot your computer there's a good chance that the files names may have changed.
The link below will help ID them:
http://www.pchell.com/support/onlythebest.shtml

Please download and unzip
AboutBuster to a folder. Inside the folder is a readme file that has instructions on the use of the program.
AboutBuster MUST be updated before you use it.
Start AboutBuster, click the update button, check for update, drag the box to the side and hit download updates, close the box . Don't run it yet.
Current reference list # is 15


You may also find the TheKillBox helpful for deleting and ending task on files to be deleted.
To end task on a file that's running use the drop down arrow in the right lower corner of the program and the button to the left of it.


1. Please download and install AD-Aware.
Check Here on how setup and use it - please make sure you update it first.

Important Step
2. Go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called: (you may find one or more)
Network Security Service <—this is exactly what they look like
Remote Procedure Call (RPC) Helper <—
or
Workstation NetLogon Service
<—

There are two other RPC services that should be left alone.

When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.

3. Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked.
Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

For anyone using Windows XP, 'Search' will not automatically show hidden files even if your folder options settings are set to do that. Do this so you can see hidden files and folders - click here http://www.davehigham.zen.co.uk/downloads/xphidden.zip to download xphidden.zip. Extract xphidden.reg from the zip file and save it to the desktop. When done, double-click the xphidden.reg and when asked to merge say yes.

4. Press Ctrl+Alt+Delete once => Click Task Manager => Click the Processes tab => Double-click the Image Name column header to alphabetically sort the processes => Scroll through the list and look for:

msuw.exe
appkz32.exe


If you find the files, click on them, and then click End Process => Exit the Task Manager.


5. CLOSE ALL WINDOWS AND BROWSERS Scan with Hijack This and put checks next to all the following, then click "Fix Checked"

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\gdhge.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\gdhge.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\gdhge.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\gdhge.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\gdhge.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\gdhge.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\gdhge.dll/sp.html#28129

O2 - BHO: (no name) - {2F44B042-675A-B758-1A82-FF8492CBA9DD} - C:\WINNT\d3el.dll

O4 - HKLM\..\Run: [msuw.exe] C:\WINNT\system32\msuw.exe
O4 - HKLM\..\Run: [appkz32.exe] C:\WINNT\system32\appkz32.exe

6. Delete the following files if present:
If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.

C:\WINNT\gdhge.dll
C:\WINNT\d3el.dll
C:\WINNT\system32\msuw.exe
C:\WINNT\system32\appkz32.exe

(and any other files with the same name that end in .dll, .exe or .dat, you may find them right next to each other, example - appsw.exe, appsw.dll, appsw.dat)

7. Run AboutBuster . This will scan your computer for the bad files and delete them. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

8. Scan with AdAware and let it remove any bad files found.

9. Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin

10. Click here http://www.davehigham.zen.co.uk/downloads/cwsuninst.zip to download cwsuninst.zip.
Extract cwsuninst.reg from the zip file and save it to the desktop.
When done, double-click the cwsuninst.reg and when asked to merge say yes.

11. Download the Hoster from here http://members.aol.com/toadbee/hoster.zip. Press "Restore Original Hosts" and press "OK". Exit Program.

12. Download and run this online virus scan:
http://housecall.trendmicro.com/housecall/start_corp.asp
Make sure you check "AutoClean"

12a. Download to and run from your desktop CW-Shredder
Hit the fix button and let it run and fix what it finds, make sure you have all browser windows closed.


13. Reboot to normal mode and post a fresh HJT log back here by using the add reply button below, MrC
Hi Mr Charlie….. you are quick off the block! :D Thanks very much for stepping in… I asked 99ab to post here because his getservices log didn't look quite right… I will merge his posts into this one. 99ab….. before we go any further could you test something that is being developed, it is similar to the getservices.zip but gives a shorter list. I will upload the file to this post for you to download. It is important that you extract it out of the zip file before you run it, once you have double click on the vbs application and post the resulting log here. There are instructions included. You may find that Norton warns you about running unknown scripts… allow this one. You may also get an error.. if you do don't worry it won't do any harm to your pc… but could you let us know what it says if you do.
99ab,

I wasn't yelling at you, :rant:

I just didn't know what was going on. :scratch:

I just wanted to know If I was going to help with the problem you or not.

Good Luck, MrC
B)
Hi, Nellie2, Here is the script from the program you just sent me: ********** The script did not recognize the services listed below. This does not mean they are a problem. Please post everything below the row of # signs and nothing from above it. Thank You ################################################################################ ServiceFilter by rand1038 Oct 3, 2004 20:35:08 Service Name: aspnet_state Display Name: ASP.NET State Service Start Mode: Manual Start Name: .\ASPNET Description: ASP.NET State … Service Type: Own Process Path: c:\winnt\microsoft.net\framework\v1.1.4322\aspnet_state.exe State: Stopped Process ID: 0 Started: False Exit Code: 1077 Accept Pause: False Accept Stop: False Service Name: BITS Display Name: Background Intelligent Transfer Service Start Mode: Disabled Start Name: LocalSystem Description: Background Intelligent Transfer … Service Type: Share Process Path: c:\winnt\system32\svchost.exe -k bitsgroup State: Stopped Process ID: 0 Started: False Exit Code: 1077 Accept Pause: False Accept Stop: False Service Name: ccEvtMgr Display Name: Symantec Event Manager Start Mode: Auto Start Name: LocalSystem Description: Symantec Event … Service Type: Own Process Path: "c:\program files\common files\symantec shared\ccevtmgr.exe" State: Running Process ID: 584 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Service Name: ccPwdSvc Display Name: Symantec Password Validation Start Mode: Manual Start Name: LocalSystem Description: Symantec Password … Service Type: Own Process Path: "c:\program files\common files\symantec shared\ccpwdsvc.exe" State: Stopped Process ID: 0 Started: False Exit Code: 1077 Accept Pause: False Accept Stop: False Service Name: ccSetMgr Display Name: Symantec Settings Manager Start Mode: Auto Start Name: LocalSystem Description: Symantec Settings … Service Type: Own Process Path: "c:\program files\common files\symantec shared\ccsetmgr.exe" State: Running Process ID: 552 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Service Name: Creative Service for CDROM Access Display Name: Creative Service for CDROM Access Start Mode: Auto Start Name: LocalSystem Description: Creative Service for CDROM … Service Type: Own Process Path: c:\winnt\system32\ctsvccda.exe State: Running Process ID: 740 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Service Name: GEARSecurity Display Name: GEARSecurity Start Mode: Auto Start Name: LocalSystem Description: GEARSecurity… Service Type: Own Process Path: c:\winnt\system32\gearsec.exe State: Running Process ID: 760 Started: True Exit Code: 0 Accept Pause: True Accept Stop: True Service Name: GhostStartService Display Name: GhostStartService Start Mode: Auto Start Name: LocalSystem Description: GhostStartService… Service Type: Own Process Path: c:\progra~1\norton~1\norton~4\ghosts~2.exe State: Running Process ID: 780 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Service Name: HidServ Display Name: HID Input Service Start Mode: Auto Start Name: LocalSystem Description: HID Input … Service Type: Own Process Path: c:\winnt\system32\hidserv.exe State: Running Process ID: 800 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Service Name: Iprip Display Name: RIP Listener Start Mode: Auto Start Name: LocalSystem Description: RIP … Service Type: Share Process Path: c:\winnt\system32\svchost.exe -k netsvcs State: Running Process ID: 512 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Service Name: Irmon Display Name: Infrared Monitor Start Mode: Auto Start Name: LocalSystem Description: Infrared … Service Type: Share Process Path: c:\winnt\system32\svchost.exe -k netsvcs State: Running Process ID: 512 Started: True Exit Code: 0 Accept Pause: True Accept Stop: True Service Name: LPDSVC Display Name: TCP/IP Print Server Start Mode: Manual Start Name: LocalSystem Description: TCP/IP Print … Service Type: Share Process Path: c:\winnt\system32\tcpsvcs.exe State: Stopped Process ID: 0 Started: False Exit Code: 1077 Accept Pause: False Accept Stop: False Service Name: navapsvc Display Name: Norton AntiVirus Auto Protect Service Start Mode: Auto Start Name: LocalSystem Description: Norton AntiVirus Auto Protect … Service Type: Own Process Path: "c:\program files\norton systemworks\norton antivirus\navapsvc.exe" State: Running Process ID: 836 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Service Name: NProtectService Display Name: Norton Unerase Protection Start Mode: Auto Start Name: LocalSystem Description: Norton Unerase … Service Type: Own Process Path: c:\progra~1\norton~1\norton~2\nprotect.exe State: Running Process ID: 856 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Service Name: NWCWorkstation Display Name: Client Service for NetWare Start Mode: Auto Start Name: LocalSystem Description: Client Service for … Service Type: Share Process Path: c:\winnt\system32\services.exe State: Stopped Process ID: 0 Started: False Exit Code: 87 Accept Pause: False Accept Stop: False Service Name: O?’ŽrtñåȲ$Ó Display Name: Remote Procedure Call (RPC) Helper Start Mode: Auto Start Name: LocalSystem Description: Remote Procedure Call (RPC) … Service Type: Share Process Path: c:\winnt\greenstone.bmp:pcsbq /s State: Running Process ID: 804 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Service Name: SAVScan Display Name: SAVScan Start Mode: Auto Start Name: LocalSystem Description: SAVScan… Service Type: Own Process Path: c:\program files\norton systemworks\norton antivirus\savscan.exe State: Running Process ID: 952 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Service Name: SBService Display Name: ScriptBlocking Service Start Mode: Auto Start Name: LocalSystem Description: ScriptBlocking … Service Type: Own Process Path: c:\progra~1\common~1\symant~1\script~1\sbserv.exe State: Stopped Process ID: 0 Started: False Exit Code: 0 Accept Pause: False Accept Stop: False Service Name: Speed Disk service Display Name: Speed Disk service Start Mode: Auto Start Name: LocalSystem Description: Speed Disk … Service Type: Own Process Path: c:\progra~1\norton~1\norton~2\speedd~1\nopdb.exe State: Running Process ID: 1188 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Service Name: StiSvc Display Name: Still Image Service Start Mode: Auto Start Name: LocalSystem Description: Still Image … Service Type: Own Process Path: c:\winnt\system32\stisvc.exe State: Running Process ID: 1208 Started: True Exit Code: 0 Accept Pause: True Accept Stop: True Service Name: Symantec Core LC Display Name: Symantec Core LC Start Mode: Auto Start Name: LocalSystem Description: Symantec Core … Service Type: Own Process Path: c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe State: Running Process ID: 1236 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Service Name: SymWSC Display Name: SymWMI Service Start Mode: Auto Start Name: LocalSystem Description: SymWMI … Service Type: Own Process Path: c:\program files\common files\symantec shared\security center\symwsc.exe State: Stopped Process ID: 0 Started: False Exit Code: 0 Accept Pause: False Accept Stop: False Service Name: TapiSrv Display Name: Telephony Start Mode: Manual Start Name: LocalSystem Description: Telephony… Service Type: Share Process Path: c:\winnt\system32\svchost.exe -k netsvcs State: Running Process ID: 512 Started: True Exit Code: 0 Accept Pause: True Accept Stop: True Service Name: V2i Protector Display Name: V2i Protector Start Mode: Auto Start Name: LocalSystem Description: V2i … Service Type: Own Process Path: c:\program files\powerquest\drive image 7.0\agent\pqv2isvc.exe State: Running Process ID: 1264 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Service Name: Visual Studio Analyzer RPC bridge Display Name: Visual Studio Analyzer RPC bridge Start Mode: Manual Start Name: LocalSystem Description: Visual Studio Analyzer RPC … Service Type: Own Process Path: c:\program files\microsoft visual studio\common\tools\vs-ent98\vanalyzr\varpc.exe State: Stopped Process ID: 0 Started: False Exit Code: 1077 Accept Pause: False Accept Stop: False Service Name: wfxsvc Display Name: WinFax PRO Start Mode: Disabled Start Name: LocalSystem Description: WinFax … Service Type: Own Process Path: c:\winnt\system32\wfxsvc.exe State: Stopped Process ID: 0 Started: False Exit Code: 1077 Accept Pause: False Accept Stop: False Service Name: WmdmPmSN Display Name: Portable Media Serial Number Service Start Mode: Manual Start Name: LocalSystem Description: Portable Media Serial Number … Service Type: Share Process Path: c:\winnt\system32\svchost.exe -k netsvcs State: Stopped Process ID: 0 Started: False Exit Code: 1077 Accept Pause: False Accept Stop: False Service Name: wuauserv Display Name: Automatic Updates Start Mode: Auto Start Name: LocalSystem Description: Automatic … Service Type: Share Process Path: c:\winnt\system32\svchost.exe -k wugroup State: Running Process ID: 1368 Started: True Exit Code: 0 Accept Pause: False Accept Stop: True Service Name: WZCSVC Display Name: Wireless Configuration Start Mode: Manual Start Name: LocalSystem Description: Wireless … Service Type: Share Process Path: c:\winnt\system32\svchost.exe -k netsvcs State: Stopped Process ID: 0 Started: False Exit Code: 1077 Accept Pause: False Accept Stop: False Script Execution Time: 15.72656 seconds.
Hi, MrCharlie, I am sorry if I sounded ungrateful for your offer of help but being lazy and not very computer savvy, I didn't want to have to repeat everything yet again when I had set out the whole story to Nellie2. I do hope I had not caused you any upset. – Ali
Hello again… there is a bit of discussion going on at the minute about your problem… stick with us and don't reboot! Someone will be along shortly to help ;)
Hi, Nellie2, It's now 0:47 on Monday and I need to go to bed. Do you want me to leave the computer running all night or can I switch it off and resume later this morning? – Ali
You may want to print out these directions as the Internet will not be available. You must totally disconnect from the internet as staying connect will prevent the fix from working. Also please keep Internet Explorer closed throughout as opening it will reinstall the infection. Read through all the instructions so that you can ask any questions now, before you disconnect from the Internet.

Please continue with the next step and if you run into any problems with the current one, just keep going through the list step by step. Just be sure to let us know what the problem was when you finally reply.

Do you recognize this as being legitimate: C:\Program Files\RS Electronic Catalogue\ProtocolHandler.dll
I do not think it should be where it is but cannot find information about it. It is redirecting your browser at the moment and I will ask you to remove it further in the fix. However if you recognize it as being legitimate do NOT fix it.

Step#1:

Please download and open the following zip file. Double-click on the file inside the zip and when it asks you if you would like to merge the file into your registry, please answer yes. This will make sure all files are visible on your computer.
http://www.davehigham.zen.co.uk/downloads/xphidden.zip


Step#2:

The following programs are not recommended because of the junk that comes with them. Find replacements for them and read about the Safe Programs
Please go to Start > Control Panel > Add Remove Programs and uninstall each of the following:



Step#3:

1. Please download About:Buster from here: http://tools.zerosrealm.com/AboutBuster.zip.

2. Once it is downloaded extract it to c:\aboutbuster. Do NOT use it yet

3. Reboot your computer into Safe Mode by tapping F8 while booting up and continue for the rest of the fix in SAFE MODE



Step#4:

Another program to download is Registrar Lite for use later: Please download Registrar Lite and install it to C:\Program Files\RegLite\ . This is a registry editor that is very easy to use.


Step#5:

Please disconnect from the Internet and unplug your modem for the duration of this fix

1. Click on start > control panel > administrative programs > services. Look for a service called . Double click on that service and click stop and then set the startup to disabled. Also write down the name and path of the file listed in the Path to executable field. This filename must be deleted below. It is likely to be c:\winnt\greenstone.bmp:pcsbq but may have changed since you posted the log.


Step#6:

Press control-alt-delete to get into the task manager and end the follow processes if they exist:

appkz32.exe>
Greenstone.bmp:pcsbq>


Step#7:

I now need you to delete the following files:

C:\WINNT\Greenstone.bmp:pcsbq
C:\WINNT\system32\appkz32.exe
C:\WINNT\gdhge.dll
C:\WINNT\d3el.dll
C:\Program Files\Bouncer\LiveUpdate.exe 000
C:\WINNT\system32\msuw.exe
C:\WINNT\system32\appkz32.exe



If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.



Step#8:

Then close all programs and windows and run hijackthis. Put a checkmark next to each of these entries and click 'fix checked' button when ready (some may be gone after uninstalling some programs):


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\gdhge.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\gdhge.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\gdhge.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\gdhge.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\gdhge.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\gdhge.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\gdhge.dll/sp.html#28129
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.bbc.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.bbc.co.uk
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 62.254.32.6:8080
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {2F44B042-675A-B758-1A82-FF8492CBA9DD} - C:\WINNT\d3el.dll
O4 - HKLM\..\Run: [Bouncer RunStartup] C:\Program Files\Bouncer\LiveUpdate.exe 000
O4 - HKLM\..\Run: [msuw.exe] C:\WINNT\system32\msuw.exe
O4 - HKLM\..\Run: [appkz32.exe] C:\WINNT\system32\appkz32.exe
O16 - DPF: {15AF6247-8420-4A42-B78E-6BACB05985B0} (Msoftdld Control) - http://www.moneysoft.co.uk/download/msoftdld.ocx
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) -
O16 - DPF: {858B4F85-E945-4F0C-AF65-059E0AD9EEC0} (IntraLaunch.MainControl) - file://F:\Interface\IntraLaunch.CAB
O18 - Protocol: stibo - {FFAD3420-6D61-44F6-BA25-293F17152D79} - C:\Program Files\RS Electronic Catalogue\ProtocolHandler.dl




Step#9:

In the next step we are going to remove a service that gets installed by this malware.

1. Open Registrar Lite and run it.

2. Copy and paste the bold text below into the address bar of Registrar Lite:(this is making a Registry backup for safety in case of error)

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\

Go to File> Export and and save as (in the C:\Program Files\Registrar Lite (Reglite) folder):

1.) Winkey.reg (Save as type: regedit4 .reg type)
2.) Winkey.hiv (Save as type: Scroll to select-regetd32/WinAPI *hiv *dat files)


3. Copy and paste the bold text below into the address bar of Reglite:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\O?’ŽrtñåȲ$Ó

3. Click Go

4. If O?’ŽrtñåȲ$Ó exists it will be highlighted in the left pane , right click on it and choose delete from the menu.


5. Copy and Paste the bold text below into the address bar of Registrar Lite:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_O?’ŽrtñåȲ$Ó

6. Click Go

7. If LEGACY_O?’ŽrtñåȲ$Ó exists then right click on it and choose delete from the menu.

8. If you have trouble deleting a key. Then click once on the key name to highlight it and on the top menu choose Security, then Edit Permissions. Then make sure you are an Administrator and give yourself Full Control of that key. Then click on everyone and put a checkmark in "full control". Then press apply and ok and attempt to delete the key again.

9. If you have had to change the permissions on the keys in Registrar Lite then they will have to be returned to the way they were . To do this please navigate to C:\ProgramFiles\Registrar Lite (Reglite) and double-click on Winkey.reg. It will ask if you want to merge this file with the registry, say Yes. Then double-click on Winkey.hiv and merge this file with the Registry. You have now returned the permissions to the way they were.




Step#10:

This is the step where we will use About:Buster that you had downloaded previously.

Navigate to the c:\aboutbuster directory and double-click on aboutbuster.exe When the tool is open press the OK button, then the Start button, then the OK button, and then finally the Yes button. It will start scanning your computer for files. If it asks if you would like to do a second pass, allow it to do so. Post the log file in your next reply



When it has completed move on to step 11.

Step#11:

Copy the contents of the Quote Box below to Notepad.
Name the file as fix.reg
Change the Save as Type to All Files
and Save it on the desktop

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW]


Then double-click on the fix.reg file, and when it prompts to merge say yes, and this will clear some registry entries left behind by the process.

Step#12:

1.Reboot your computer back to normal mode and Scan again with HijackThis. We still have a few steps to complete but a log file at this time would be helpful.

2. Post both your log from About Buster and your HijackThis log here in this thread with any questions or problems that you have run into. There are still some steps that are necessary to clear out all of the malware. There will be necessary files that it has deleted that will need to be replaced.

Good Luck!
Hi, DGosling, I'm a bit confused. Under Step#2 you say "Please go to Start > Control Panel > Add Remove Programs and uninstall each of the following:" but you don't say which programs to uninstall.
oops I posted that late last night - it is not applicable to you - sorry for the confusion. Just go ahead and complete the other steps

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI