This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Need Help

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have run Ad-Aware, Spybot, and CWSShreader several times and can't solve my problem. I did read some of the other posts and apparently cured the about:blank problem by checking everything that ended with about:blank on Hijackthis.

Any help you can give me is greatly appreciated.

This is my current hijackthis log.

Logfile of HijackThis v1.98.2
Scan saved at 11:39:33 PM, on 12/9/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\System32\CTsvcCDA.exe
C:\WINNT\SYSTEM32\DNTUS26.EXE
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
c:\winnt\system32\drivers\etc\svchost.exe
c:\winnt\system32\drivers\etc\rcmdsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\Proxy.exe
c:\winnt\system32\drivers\etc\winxz\f\FireDaemon.exe
C:\WINNT\system32\MSTask.exe
C:\winnt\system32\drivers\etc\winxz\scannerap.exe
c:\winnt\system32\drivers\etc\svchost.exe
c:\winnt\system32\drivers\etc\svchost.exe
c:\winnt\system32\drivers\etc\spoolsv.exe
c:\winnt\system32\drivers\etc\SysMgmt.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\Common Files\WinTools\WToolsS.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\devldr32.exe
C:\WINNT\system32\tibs3.exe
C:\WINNT\system32\ntpel.exe
C:\Program Files\SED\SED.exe
C:\WINNT\system32\ntbavi32.exe
C:\Program Files\Navnt\navapw32.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Navnt\alertsvc.exe
C:\PROGRA~1\NTS\ENTERN~1\app\EnterNet.exe
C:\PROGRA~1\WINZIP\wzqkpick.exe
C:\WINNT\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\unzipped\hijackthis[1]\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = ,
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\dqzid.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\dqzid.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\dqzid.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\dqzid.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: earch
O1 - Hosts: earch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\Navnt\defalert.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [tibs3] C:\WINNT\system32\tibs3.exe
O4 - HKLM\..\Run: [0Z.exe] C:\documents and settings\brad hickman\local settings\temp\0Z.exe
O4 - HKLM\..\Run: [Windows ControlAd] C:\Program Files\Windows ControlAd\WinCtlAd.exe
O4 - HKLM\..\Run: [apiwl.exe] C:\WINNT\system32\apiwl.exe
O4 - HKLM\..\Run: [ipoz32.exe] C:\WINNT\system32\ipoz32.exe
O4 - HKLM\..\Run: [nttz.exe] C:\WINNT\system32\nttz.exe
O4 - HKLM\..\Run: [p3tV34R] ntpel.exe
O4 - HKLM\..\Run: [winji32.exe] C:\WINNT\system32\winji32.exe
O4 - HKLM\..\Run: [ienu.exe] C:\WINNT\system32\ienu.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [Uninstall_TBPS] C:\WINNT\Temp\TBuninst.exe /remove
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Y029RQd2e] ntbavi32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O10 - Unknown file in Winsock LSP: c:\winnt\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\aklsp.dll
O13 - WWW. Prefix: http://
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsupp/ac…supportutil.CAB
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://64.124.45.181/downloads/ccpm_0237.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
Tried a few more things and my log has changed some. This is the latest.

Logfile of HijackThis v1.98.2
Scan saved at 1:51:49 AM, on 12/10/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\System32\CTsvcCDA.exe
C:\WINNT\SYSTEM32\DNTUS26.EXE
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
c:\winnt\system32\drivers\etc\svchost.exe
c:\winnt\system32\drivers\etc\rcmdsvc.exe
C:\WINNT\system32\Proxy.exe
c:\winnt\system32\drivers\etc\winxz\f\FireDaemon.exe
C:\WINNT\system32\MSTask.exe
C:\winnt\system32\drivers\etc\winxz\scannerap.exe
c:\winnt\system32\drivers\etc\svchost.exe
c:\winnt\system32\drivers\etc\svchost.exe
c:\winnt\system32\drivers\etc\spoolsv.exe
c:\winnt\system32\drivers\etc\SysMgmt.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\devldr32.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\tibs3.exe
C:\WINNT\system32\nttz.exe
C:\WINNT\system32\ntpel.exe
C:\Program Files\SED\SED.exe
C:\WINNT\system32\ntbavi32.exe
C:\Program Files\Navnt\navapw32.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\ntgm32.exe
C:\PROGRA~1\Navnt\alertsvc.exe
C:\PROGRA~1\NTS\ENTERN~1\app\EnterNet.exe
C:\WINNT\system32\cmd.exe
c:\Program Files\interMute\SpySubtract\SpySub.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\HPZSTC04.EXE
C:\WINNT\system32\spool\DRIVERS\W32X86\3\HPZENG04.EXE
C:\unzipped\hijackthis[1]\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = ,
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\ngzrk.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\ngzrk.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\system32\ngzrk.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\ngzrk.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\ngzrk.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\ngzrk.dll/sp.html#12345
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\ngzrk.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: (no name) - {27622543-E879-3A47-D05A-97903406A96F} - C:\WINNT\addbm.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\Navnt\defalert.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [tibs3] C:\WINNT\system32\tibs3.exe
O4 - HKLM\..\Run: [0Z.exe] C:\documents and settings\brad hickman\local settings\temp\0Z.exe
O4 - HKLM\..\Run: [Windows ControlAd] C:\Program Files\Windows ControlAd\WinCtlAd.exe
O4 - HKLM\..\Run: [apiwl.exe] C:\WINNT\system32\apiwl.exe
O4 - HKLM\..\Run: [ipoz32.exe] C:\WINNT\system32\ipoz32.exe
O4 - HKLM\..\Run: [nttz.exe] C:\WINNT\system32\nttz.exe
O4 - HKLM\..\Run: [p3tV34R] ntpel.exe
O4 - HKLM\..\Run: [winji32.exe] C:\WINNT\system32\winji32.exe
O4 - HKLM\..\Run: [ienu.exe] C:\WINNT\system32\ienu.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Y029RQd2e] ntbavi32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O13 - WWW. Prefix: http://
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsupp/ac…supportutil.CAB
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://64.124.45.181/downloads/ccpm_0237.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
Hello Brad,

This one is a difficult hijack to remove. Experts will be here to help you soon. Meanwhile, you can do the following which help you to stay safe


SpywareBlaster doesn't scan and clean for spyware - it prevents it from ever being installed.
http://www.wilderssecurity.com/spywareblaster.html

IE-SPYAD puts over 4000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
http://www.staff.uiuc.edu/~ehowes/resource.htm#IESPYAD

Both are very small free programs that you run once, and then just occasionally to check for updates.

And also see TonyKlein's good advice
So how did I get infected in the first place?


Regards,
Baskar
Update: While I've been waiting I removed Spyware Blaster and IE-SPYAD when I installed Norton Internet Security 2005 Upgrade. When I scan with Norton I get around 17 files that it can't seem to remove. I'm still getting a dozen or so critical errors with with Ad-Aware SE and five or so hits with Spybot. I'd be glad to post fresh logs for everything when my number comes up. Thanks, Brad
Update:

These are scans run after running Spybot, Ad-Aware, and Norton Antivirus then rebooting.

Logfile of HijackThis v1.98.2
Scan saved at 4:35:55 PM, on 12/16/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\System32\CTsvcCDA.exe
C:\WINNT\SYSTEM32\DNTUS26.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
c:\winnt\system32\drivers\etc\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\Proxy.exe
c:\winnt\system32\drivers\etc\winxz\f\FireDaemon.exe
C:\WINNT\system32\MSTask.exe
C:\winnt\system32\drivers\etc\winxz\scannerap.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\winnt\system32\drivers\etc\svchost.exe
c:\winnt\system32\drivers\etc\svchost.exe
c:\winnt\system32\drivers\etc\spoolsv.exe
c:\winnt\system32\drivers\etc\SysMgmt.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\devldr32.exe
C:\Program Files\SED\SED.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\WINNT\system32\netmz.exe
C:\WINNT\system32\emdcmn.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\ntgm32.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\HJT\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\jtwml.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\jtwml.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\jtwml.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\jtwml.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\jtwml.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\jtwml.dll/sp.html#12345
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\jtwml.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {0B28B10C-0852-4322-CD8D-98680E44C015} - C:\WINNT\atlnf32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [0Z.exe] C:\documents and settings\brad hickman\local settings\temp\0Z.exe
O4 - HKLM\..\Run: [Windows ControlAd] C:\Program Files\Windows ControlAd\WinCtlAd.exe
O4 - HKLM\..\Run: [apiwl.exe] C:\WINNT\system32\apiwl.exe
O4 - HKLM\..\Run: [ipoz32.exe] C:\WINNT\system32\ipoz32.exe
O4 - HKLM\..\Run: [nttz.exe] C:\WINNT\system32\nttz.exe
O4 - HKLM\..\Run: [winji32.exe] C:\WINNT\system32\winji32.exe
O4 - HKLM\..\Run: [ienu.exe] C:\WINNT\system32\ienu.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [AutoLoaderpw2f1OMWZJLc] "C:\WINNT\system32\escon32.exe"
O4 - HKLM\..\Run: [p3tV34R] escon32.exe
O4 - HKLM\..\Run: [apijw.exe] C:\WINNT\system32\apijw.exe
O4 - HKLM\..\Run: [javadj.exe] C:\WINNT\system32\javadj.exe
O4 - HKLM\..\Run: [netmz.exe] C:\WINNT\system32\netmz.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Y029RQd2e] emdcmn.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O10 - Unknown file in Winsock LSP: c:\winnt\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\aklsp.dll
O13 - WWW. Prefix: http://
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsupp/ac…supportutil.CAB
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://64.124.45.181/downloads/ccpm_0237.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab


Ad-Aware SE Build 1.05
Logfile Created on:Thursday, December 16, 2004 4:37:53 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R21 03.12.2004
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
CoolWebSearch(TAC index:10):13 total references
MRU List(TAC index:0):5 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects


12-16-2004 4:37:53 PM - Scan started. (Full System Scan)

MRU List Object Recognized!
Location: : S-1-5-21-839522115-1202660629-1343024091-1000\software\microsoft\windows\currentversion\explorer\runmru
Description : mru list for items opened in start | run


MRU List Object Recognized!
Location: : S-1-5-21-839522115-1202660629-1343024091-1000\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension


MRU List Object Recognized!
Location: : S-1-5-21-839522115-1202660629-1343024091-1000\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened


MRU List Object Recognized!
Location: : S-1-5-21-839522115-1202660629-1343024091-1000\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened


MRU List Object Recognized!
Location: : C:\Documents and Settings\Brad Hickman\recent
Description : list of recently opened documents


Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 156
ThreadCreationTime : 12-16-2004 10:33:24 PM
BasePriority : Normal


#:2 [winlogon.exe]
FilePath : \??\C:\WINNT\system32\
ProcessID : 200
ThreadCreationTime : 12-16-2004 10:33:42 PM
BasePriority : High


#:3 [services.exe]
FilePath : C:\WINNT\system32\
ProcessID : 228
ThreadCreationTime : 12-16-2004 10:33:44 PM
BasePriority : Normal
FileVersion : 5.00.2195.6700
ProductVersion : 5.00.2195.6700
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : services.exe

#:4 [lsass.exe]
FilePath : C:\WINNT\system32\
ProcessID : 240
ThreadCreationTime : 12-16-2004 10:33:44 PM
BasePriority : Normal
FileVersion : 5.00.2195.6902
ProductVersion : 5.00.2195.6902
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Executable and Server DLL (Export Version)
InternalName : lsasrv.dll and lsass.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : lsasrv.dll and lsass.exe

#:5 [ccproxy.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 408
ThreadCreationTime : 12-16-2004 10:33:47 PM
BasePriority : Normal
FileVersion : 103.0.2.10
ProductVersion : 103.0.2.10
ProductName : Client and Host Security Platform
CompanyName : Symantec Corporation
FileDescription : Symantec Network Proxy Service
InternalName : ccProxy
LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved.
OriginalFilename : ccProxy.exe

#:6 [issvc.exe]
FilePath : C:\Program Files\Norton Internet Security\
ProcessID : 432
ThreadCreationTime : 12-16-2004 10:33:49 PM
BasePriority : Normal
FileVersion : 8.0.2.5
ProductVersion : 8.0
ProductName : Norton Internet Security
CompanyName : Symantec Corporation
FileDescription : IS Service
InternalName : ISSVC.exe
LegalCopyright : Copyright © 2004 Symantec Corporation
OriginalFilename : ISSVC.exe

#:7 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 444
ThreadCreationTime : 12-16-2004 10:33:49 PM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe

#:8 [sndsrvc.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 456
ThreadCreationTime : 12-16-2004 10:33:49 PM
BasePriority : Normal
FileVersion : 5.4.3.11
ProductVersion : 5.4
ProductName : Symantec Security Drivers
CompanyName : Symantec Corporation
FileDescription : Network Driver Service
InternalName : SndSrvc
LegalCopyright : Copyright 2002, 2003, 2004 Symantec Corporation
OriginalFilename : SndSrvc.exe

#:9 [ccsetmgr.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 504
ThreadCreationTime : 12-16-2004 10:33:50 PM
BasePriority : Normal
FileVersion : 103.0.2.10
ProductVersion : 103.0.2.10
ProductName : Client and Host Security Platform
CompanyName : Symantec Corporation
FileDescription : Symantec Settings Manager Service
InternalName : ccSetMgr
LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved.
OriginalFilename : ccSetMgr.exe

#:10 [spbbcsvc.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\SPBBC\
ProcessID : 524
ThreadCreationTime : 12-16-2004 10:33:50 PM
BasePriority : Normal
FileVersion : 1,0,1,47
ProductVersion : 1,0,1,47
ProductName : SPBBC
CompanyName : Symantec Corporation
FileDescription : SPBBC Service
InternalName : SPBBCSvc
LegalCopyright : Copyright © 2004 Symantec Corporation. All rights reserved.
OriginalFilename : SPBBCSvc.exe

#:11 [ccevtmgr.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 588
ThreadCreationTime : 12-16-2004 10:33:54 PM
BasePriority : Normal
FileVersion : 103.0.2.10
ProductVersion : 103.0.2.10
ProductName : Client and Host Security Platform
CompanyName : Symantec Corporation
FileDescription : Symantec Event Manager Service
InternalName : ccEvtMgr
LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved.
OriginalFilename : ccEvtMgr.exe

#:12 [spoolsv.exe]
FilePath : C:\WINNT\system32\
ProcessID : 816
ThreadCreationTime : 12-16-2004 10:33:58 PM
BasePriority : Normal
FileVersion : 5.00.2195.6659
ProductVersion : 5.00.2195.6659
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolss.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : spoolss.exe

#:13 [ati2evxx.exe]
FilePath : C:\WINNT\System32\
ProcessID : 852
ThreadCreationTime : 12-16-2004 10:34:04 PM
BasePriority : Normal


#:14 [ctsvccda.exe]
FilePath : C:\WINNT\System32\
ProcessID : 868
ThreadCreationTime : 12-16-2004 10:34:04 PM
BasePriority : Normal
FileVersion : 1.0.1.0
ProductVersion : 1.0.0.0
ProductName : Creative Service for CDROM Access
CompanyName : Creative Technology Ltd
FileDescription : Creative Service for CDROM Access
InternalName : CTsvcCDAEXE
LegalCopyright : Copyright © Creative Technology Ltd., 1999. All rights reserved.
OriginalFilename : CTsvcCDA.EXE

#:15 [dntus26.exe]
FilePath : C:\WINNT\SYSTEM32\
ProcessID : 884
ThreadCreationTime : 12-16-2004 10:34:04 PM
BasePriority : Normal
FileVersion : 3, 69, 2, 2
ProductVersion : 3, 69, 2, 2
ProductName : DameWare Development Remote Command Server
CompanyName : DameWare Development
FileDescription : DameWare Development Remote Command Server
InternalName : DNTUSrv
LegalCopyright : Copyright © 1991-2002 DameWare Development
LegalTrademarks : DameWare NT Utilities
OriginalFilename : DNTUSrv.exe
Comments : http://www.dameware.com

#:16 [svchost.exe]
FilePath : C:\WINNT\System32\
ProcessID : 896
ThreadCreationTime : 12-16-2004 10:34:04 PM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe

#:17 [navapsvc.exe]
FilePath : C:\Program Files\Norton Internet Security\Norton AntiVirus\
ProcessID : 924
ThreadCreationTime : 12-16-2004 10:34:04 PM
BasePriority : Normal
FileVersion : 11.0.2.4
ProductVersion : 11.0.2
ProductName : Norton AntiVirus
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Auto-Protect Service
InternalName : NAVAPSVC
LegalCopyright : Norton AntiVirus 2005 for Windows 98/ME/2000/XP Copyright © 2004 Symantec Corporation. All rights reserved.
OriginalFilename : NAVAPSVC.EXE

#:18 [pppoeservice.exe]
FilePath : C:\PROGRA~1\NTS\ENTERN~1\app\
ProcessID : 964
ThreadCreationTime : 12-16-2004 10:34:05 PM
BasePriority : Normal


#:19 [svchost.exe]
FilePath : c:\winnt\system32\drivers\etc\
ProcessID : 1008
ThreadCreationTime : 12-16-2004 10:34:05 PM
BasePriority : Normal


#:20 [regsvc.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1028
ThreadCreationTime : 12-16-2004 10:34:06 PM
BasePriority : Normal
FileVersion : 5.00.2195.6701
ProductVersion : 5.00.2195.6701
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Remote Registry Service
InternalName : regsvc
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : REGSVC.EXE

#:21 [proxy.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1040
ThreadCreationTime : 12-16-2004 10:34:06 PM
BasePriority : Normal


#:22 [firedaemon.exe]
FilePath : c:\winnt\system32\drivers\etc\winxz\f\
ProcessID : 1092
ThreadCreationTime : 12-16-2004 10:34:07 PM
BasePriority : Normal
FileVersion : v1.6
ProductVersion : v1.6
ProductName : FireDaemon
CompanyName : Sublime Solutions Pty Ltd
FileDescription : FireDaemon
InternalName : FireDaemon
LegalCopyright : Copyright © 2003 Sublime Solutions Pty Ltd
OriginalFilename : FireDaemon.exe

#:23 [mstask.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1124
ThreadCreationTime : 12-16-2004 10:34:08 PM
BasePriority : Normal
FileVersion : 4.71.2195.6920
ProductVersion : 4.71.2195.6920
ProductName : Microsoft® Windows® Task Scheduler
CompanyName : Microsoft Corporation
FileDescription : Task Scheduler Engine
InternalName : TaskScheduler
LegalCopyright : Copyright © Microsoft Corp. 1997
OriginalFilename : mstask.exe

#:24 [scannerap.exe]
FilePath : C:\winnt\system32\drivers\etc\winxz\
ProcessID : 1132
ThreadCreationTime : 12-16-2004 10:34:08 PM
BasePriority : Normal
FileVersion : 6.03
ProductVersion : 6.03
ProductName : mIRC
CompanyName : mIRC Co. Ltd.
FileDescription : mIRC
InternalName : mIRC
LegalCopyright : Copyright © 1995-2002 mIRC Co. Ltd.
LegalTrademarks : mIRC® is a Registered Trademark of mIRC Co. Ltd.
OriginalFilename : mirc.exe

#:25 [symlcsvc.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\
ProcessID : 1172
ThreadCreationTime : 12-16-2004 10:34:08 PM
BasePriority : Normal
FileVersion : 1, 8, 54, 478
ProductVersion : 1, 8, 54, 478
ProductName : Symantec Core Component
CompanyName : Symantec Corporation
FileDescription : Symantec Core Component
InternalName : symlcsvc
LegalCopyright : Copyright © 2003
OriginalFilename : symlcsvc.exe

#:26 [svchost.exe]
FilePath : c:\winnt\system32\drivers\etc\
ProcessID : 1228
ThreadCreationTime : 12-16-2004 10:34:10 PM
BasePriority : Normal


#:27 [svchost.exe]
FilePath : c:\winnt\system32\drivers\etc\
ProcessID : 1240
ThreadCreationTime : 12-16-2004 10:34:10 PM
BasePriority : Normal


#:28 [spoolsv.exe]
FilePath : c:\winnt\system32\drivers\etc\
ProcessID : 1256
ThreadCreationTime : 12-16-2004 10:34:11 PM
BasePriority : Normal


#:29 [sysmgmt.exe]
FilePath : c:\winnt\system32\drivers\etc\
ProcessID : 1264
ThreadCreationTime : 12-16-2004 10:34:11 PM
BasePriority : Normal


#:30 [winmgmt.exe]
FilePath : C:\WINNT\System32\WBEM\
ProcessID : 1268
ThreadCreationTime : 12-16-2004 10:34:11 PM
BasePriority : Normal
FileVersion : 1.50.1085.0100
ProductVersion : 1.50.1085.0100
ProductName : Windows Management Instrumentation
CompanyName : Microsoft Corporation
FileDescription : Windows Management Instrumentation
InternalName : WINMGMT
LegalCopyright : Copyright © Microsoft Corp. 1995-1999

#:31 [rundll32.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1504
ThreadCreationTime : 12-16-2004 10:34:23 PM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Run a DLL as an App
InternalName : rundll
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : RUNDLL.EXE

#:32 [devldr32.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1680
ThreadCreationTime : 12-16-2004 10:34:39 PM
BasePriority : Normal
FileVersion : 1, 0, 0, 17
ProductVersion : 1, 0, 0, 17
ProductName : Creative Ring3 NT Inteface
CompanyName : Creative Technology Ltd.
FileDescription : DevLdr32
InternalName : DevLdr
LegalCopyright : Copyright © 1998 - 2000 Creative Technology Ltd.
OriginalFilename : DevLdr32.exe

#:33 [sed.exe]
FilePath : C:\Program Files\SED\
ProcessID : 1704
ThreadCreationTime : 12-16-2004 10:34:41 PM
BasePriority : Normal


#:34 [usrprmpt.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\Security Center\
ProcessID : 1752
ThreadCreationTime : 12-16-2004 10:34:41 PM
BasePriority : Normal
FileVersion : 2005.1.2.20
ProductVersion : 2005.1
ProductName : Norton Security Center
CompanyName : Symantec Corporation
FileDescription : Norton Security Center Helper
InternalName : UsrPrmpt.dll
LegalCopyright : Copyright © 1997-2004 Symantec Corporation
OriginalFilename : UsrPrmpt.dll

#:35 [emdcmn.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1776
ThreadCreationTime : 12-16-2004 10:34:42 PM
BasePriority : Normal


#:36 [wzqkpick.exe]
FilePath : C:\Program Files\WinZip\
ProcessID : 1852
ThreadCreationTime : 12-16-2004 10:34:43 PM
BasePriority : Normal
FileVersion : 1.0 (32-bit)
ProductVersion : 9.0 (6224)
ProductName : WinZip
CompanyName : WinZip Computing, Inc.
FileDescription : WinZip Executable
InternalName : WZQKPICK.EXE
LegalCopyright : Copyright © WinZip Computing, Inc. 1991-2004 - All Rights Reserved
LegalTrademarks : WinZip is a registered trademark of WinZip Computing, Inc
OriginalFilename : WZQKPICK.EXE
Comments : StringFileInfo: U.S. English

#:37 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1324
ThreadCreationTime : 12-16-2004 10:34:44 PM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe

#:38 [ntgm32.exe]
FilePath : C:\WINNT\
ProcessID : 1388
ThreadCreationTime : 12-16-2004 10:34:44 PM
BasePriority : Normal


#:39 [mpbtn.exe]
FilePath : C:\Program Files\SBC Self Support Tool\bin\
ProcessID : 1340
ThreadCreationTime : 12-16-2004 10:34:49 PM
BasePriority : Normal


#:40 [notepad.exe]
FilePath : C:\WINNT\system32\
ProcessID : 2228
ThreadCreationTime : 12-16-2004 10:35:55 PM
BasePriority : Normal
FileVersion : 5.00.2140.1
ProductVersion : 5.00.2140.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Notepad
InternalName : Notepad
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : NOTEPAD.EXE

#:41 [wuauclt.exe]
FilePath : C:\WINNT\system32\
ProcessID : 348
ThreadCreationTime : 12-16-2004 10:36:06 PM
BasePriority : Normal
FileVersion : 5.4.3790.20 built by: lab04_n
ProductVersion : 5.4.3790.20
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Update AutoUpdate Client
InternalName : wuauclt.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : wuauclt.exe

#:42 [explorer.exe]
FilePath : C:\WINNT\
ProcessID : 1648
ThreadCreationTime : 12-16-2004 10:37:41 PM
BasePriority : Normal
FileVersion : 5.00.3700.6690
ProductVersion : 5.00.3700.6690
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : EXPLORER.EXE

#:43 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 1876
ThreadCreationTime : 12-16-2004 10:37:44 PM
BasePriority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 5


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{676575dd-4d46-911d-8037-9b10d6ee8bb5}

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 6


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 6


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 6



Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

CoolWebSearch Object Recognized!
Type : File
Data : mqjjk.dat
Category : Malware
Comment :
Object : C:\WINNT\system32\



Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 7

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
0 entries scanned.
New critical objects:0
Objects found so far: 7




Performing conditional scans…
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\sw

CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\sw
Value : DisplayName

CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\sw
Value : UninstallString

CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\se

CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\se
Value : DisplayName

CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\se
Value : UninstallString

CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\hsa

CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\hsa
Value : DisplayName

CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\hsa
Value : UninstallString

CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\search
Value : SearchAssistant

CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main
Value : Search Bar

Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 11
Objects found so far: 18

4:40:39 PM Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:02:45.868
Objects scanned:55623
Objects identified:14
Objects ignored:1
New critical objects:13
Hi Brad - I'll work with you from now on to get rid of this.

First let's make sure everything is up to date. Open CWShredder and check for updates then hit Fix. Open AAW and check for updates and run a full scan. Finally open HJT>Config>Misc Tools and update to version 1.99.

Also, click here to download ServiceFilter, a little script by rand1038 that reveals potential unauthorised running services in your system. Download, unzip and double-click ServiceFilter.vbs (you may need to enable your antivirus program to run the file). This script will create a text file named Post_This.txt in the same folder as the script itself has been saved - copy and paste the contents of Post_This.txt in your next reply here.

Post a new HJT log when done and we'll move to the next step.
Thanks Daemon, these are the new logs after running Spybot, Ad-Aware, and Norton antivirus.

Logfile of HijackThis v1.99.0
Scan saved at 5:37:52 PM, on 12/19/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\System32\CTsvcCDA.exe
C:\WINNT\SYSTEM32\DNTUS26.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
c:\winnt\system32\drivers\etc\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\Proxy.exe
c:\winnt\system32\drivers\etc\winxz\f\FireDaemon.exe
C:\WINNT\system32\MSTask.exe
C:\winnt\system32\drivers\etc\winxz\scannerap.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\winnt\system32\drivers\etc\svchost.exe
c:\winnt\system32\drivers\etc\svchost.exe
c:\winnt\system32\drivers\etc\SysMgmt.exe
c:\winnt\system32\drivers\etc\spoolsv.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\devldr32.exe
C:\Program Files\SED\SED.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINNT\system32\emdcmn.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\explorer.exe
C:\PROGRA~1\NTS\ENTERN~1\app\EnterNet.exe
C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\oyyor.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\system32\oyyor.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\oyyor.dll/sp.html#12345
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\oyyor.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [0Z.exe] C:\documents and settings\brad hickman\local settings\temp\0Z.exe
O4 - HKLM\..\Run: [Windows ControlAd] C:\Program Files\Windows ControlAd\WinCtlAd.exe
O4 - HKLM\..\Run: [apiwl.exe] C:\WINNT\system32\apiwl.exe
O4 - HKLM\..\Run: [ipoz32.exe] C:\WINNT\system32\ipoz32.exe
O4 - HKLM\..\Run: [nttz.exe] C:\WINNT\system32\nttz.exe
O4 - HKLM\..\Run: [winji32.exe] C:\WINNT\system32\winji32.exe
O4 - HKLM\..\Run: [ienu.exe] C:\WINNT\system32\ienu.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [AutoLoaderpw2f1OMWZJLc] "C:\WINNT\system32\escon32.exe"
O4 - HKLM\..\Run: [p3tV34R] escon32.exe
O4 - HKLM\..\Run: [apijw.exe] C:\WINNT\system32\apijw.exe
O4 - HKLM\..\Run: [javadj.exe] C:\WINNT\system32\javadj.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Y029RQd2e] emdcmn.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O10 - Unknown file in Winsock LSP: c:\winnt\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\aklsp.dll
O13 - WWW. Prefix: http://
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsupp/ac…supportutil.CAB
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://64.124.45.181/downloads/ccpm_0237.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O23 - Service: Ati HotKey Poller - Unknown - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare NT Utilities 2.6 - DameWare Development - C:\WINNT\SYSTEM32\DNTUS26.EXE
O23 - Service: ISEXEng - Unknown - C:\WINNT\system32\angelex.exe (file missing)
O23 - Service: ISSvc - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PPPoE Service - Unknown - C:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
O23 - Service: Remote Command Terminal - Unknown - c:\winnt\system32\drivers\etc\svchost.exe
O23 - Service: Remote Procedure Call (RPC) Manager - Unknown - C:\WINNT\system32\Proxy.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: FireDaemon Service: scannerap - Sublime Solutions Pty Ltd - c:\winnt\system32\drivers\etc\winxz\f\FireDaemon.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: System Management - Unknown - c:\winnt\system32\drivers\etc\svchost.exe
O23 - Service: System Tracker - Unknown - c:\winnt\system32\drivers\etc\svchost.exe
O23 - Service: winx - mIRC Co. Ltd. - c:\winnt\system32\drivers\etc\winxz\scannerap.exe
O23 - Service: Remote Procedure Call (RPC) Helper - Unknown - C:\WINNT\ntgm32.exe (file missing)

The script did not recognize the services listed below.
This does not mean that they are a problem.

To copy the entire contents of this document for posting:
At the top of this window click "Edit" then "Select All"
Next click "Edit" again then "Copy"
Now right click in the forum post box then click "Paste"

########################################

ServiceFilter 1.1
by rand1038

Microsoft Windows 2000 Professional
Version: 5.0.2195 Service Pack 4
Dec 19, 2004 5:40:31 PM


—> Begin Service Listing <—

Unknown Service # 1
Service Name: Ati HotKey Poller
Display Name: Ati HotKey Poller
Start Mode: Auto
Start Name: LocalSystem
Description: Ati HotKey …
Service Type: Own Process
Path: c:\winnt\system32\ati2evxx.exe
State: Running
Process ID: 864
Started: True
Exit Code: 0
Accept Pause: False
Accept Stop: False

Unknown Service # 2
Service Name: ccProxy
Display Name: Symantec Network Proxy
Start Mode: Auto
Start Name: LocalSystem
Description: Symantec Network …
Service Type: Own Process
Path: "c:\program files\common files\symantec shared\ccproxy.exe"
State: Running
Process ID: 420
Started: True
Exit Code: 0
Accept Pause: False
Accept Stop: True

Unknown Service # 3
Service Name: DNTUS26
Display Name: DameWare NT Utilities 2.6
Start Mode: Auto
Start Name: LocalSystem
Description: DameWare NT Utilities …
Service Type: Own Process
Path: c:\winnt\system32\dntus26.exe
State: Running
Process ID: 896
Started: True
Exit Code: 0
Accept Pause: False
Accept Stop: True

Unknown Service # 4
Service Name: ISEXEng
Display Name: ISEXEng
Start Mode: Auto
Start Name: LocalSystem
Description: ISEXEng…
Service Type: Own Process
Path: c:\winnt\system32\angelex.exe
State: Stopped
Process ID: 0
Started: False
Exit Code: 0
Accept Pause: False
Accept Stop: False

Unknown Service # 5
Service Name: ISSVC
Display Name: ISSvc
Start Mode: Auto
Start Name: LocalSystem
Description: ISSvc…
Service Type: Own Process
Path: c:\program files\norton internet security\issvc.exe
State: Running
Process ID: 444
Started: True
Exit Code: 0
Accept Pause: False
Accept Stop: True

Unknown Service #6
Service Name: navapsvc
Display Name: Norton AntiVirus Auto-Protect Service
Start Mode: Auto
Start Name: LocalSystem
Description: Norton AntiVirus Auto-Protect …
Service Type: Own Process
Path: "c:\program files\norton internet security\norton antivirus\navapsvc.exe"
State: Running
Process ID: 936
Started: True
Exit Code: 0
Accept Pause: False
Accept Stop: True

Unknown Service # 7
Service Name: PPPoEService
Display Name: PPPoE Service
Start Mode: Auto
Start Name: LocalSystem
Description: PPPoE …
Service Type: Own Process
Path: c:\progra~1\nts\entern~1\app\pppoeservice.exe
State: Running
Process ID: 996
Started: True
Exit Code: 0
Accept Pause: False
Accept Stop: True

Unknown Service # 8
Service Name: RCmd
Display Name: Remote Command Terminal
Start Mode: Auto
Start Name: LocalSystem
Description: Remote Command …
Service Type: Own Process
Path: c:\winnt\system32\drivers\etc\svchost.exe
State: Running
Process ID: 1020
Started: True
Exit Code: 0
Accept Pause: True
Accept Stop: True

Unknown Service # 9
Service Name: RpcMgr
Display Name: Remote Procedure Call (RPC) Manager
Start Mode: Auto
Start Name: LocalSystem
Description: Remote Procedure Call (RPC) …
Service Type: Own Process
Path: c:\winnt\system32\proxy.exe -p 5490
State: Running
Process ID: 1052
Started: True
Exit Code: 0
Accept Pause: False
Accept Stop: True

Unknown Service #10
Service Name: SAVScan
Display Name: SAVScan
Start Mode: Manual
Start Name: LocalSystem
Description: SAVScan…
Service Type: Own Process
Path: c:\program files\norton internet security\norton antivirus\savscan.exe
State: Stopped
Process ID: 0
Started: False
Exit Code: 1077
Accept Pause: False
Accept Stop: False

Unknown Service # 11
Service Name: scannerap
Display Name: FireDaemon Service: scannerap
Start Mode: Auto
Start Name: LocalSystem
Description: FireDaemon Service: …
Service Type: Own Process
Path: c:\winnt\system32\drivers\etc\winxz\f\firedaemon.exe -s
State: Running
Process ID: 1104
Started: True
Exit Code: 0
Accept Pause: False
Accept Stop: True

Unknown Service # 12
Service Name: SNDSrvc
Display Name: Symantec Network Drivers Service
Start Mode: Auto
Start Name: LocalSystem
Description: Symantec Network Drivers …
Service Type: Own Process
Path: c:\program files\common files\symantec shared\sndsrvc.exe
State: Running
Process ID: 468
Started: True
Exit Code: 0
Accept Pause: False
Accept Stop: True

Unknown Service # 13
Service Name: SPBBCSvc
Display Name: Symantec SPBBCSvc
Start Mode: Auto
Start Name: LocalSystem
Description: Symantec …
Service Type: Own Process
Path: c:\program files\common files\symantec shared\spbbc\spbbcsvc.exe
State: Running
Process ID: 548
Started: True
Exit Code: 0
Accept Pause: False
Accept Stop: True

Unknown Service # 14
Service Name: SysMgmt
Display Name: System Management
Start Mode: Auto
Start Name: LocalSystem
Description: System …
Service Type: Own Process
Path: c:\winnt\system32\drivers\etc\svchost.exe
State: Running
Process ID: 1240
Started: True
Exit Code: 0
Accept Pause: True
Accept Stop: True

Unknown Service # 15
Service Name: System
Display Name: System Tracker
Start Mode: Auto
Start Name: LocalSystem
Description: System …
Service Type: Own Process
Path: c:\winnt\system32\drivers\etc\svchost.exe
State: Running
Process ID: 1252
Started: True
Exit Code: 0
Accept Pause: True
Accept Stop: True

Unknown Service # 16
Service Name: winx
Display Name: winx
Start Mode: Auto
Start Name: LocalSystem
Description: winx…
Service Type: Own Process
Path: c:\winnt\system32\drivers\etc\winxz\scannerap.exe
State: Stopped
Process ID: 0
Started: False
Exit Code: 0
Accept Pause: False
Accept Stop: False

Unknown Service # 17
Service Name: %AF夶À¨
Display Name: Remote Procedure Call (RPC) Helper
Start Mode: Auto
Start Name: LocalSystem
Description: Remote Procedure Call (RPC) …
Service Type: Share Process
Path: c:\winnt\ntgm32.exe /s
State: Stopped
Process ID: 0
Started: False
Exit Code: 0
Accept Pause: False
Accept Stop: False

—> End Service Listing <—

There are 79 Win32 services on this machine.
17 were unrecognized.

Script Execution Time: 18.51563 seconds.
OK, you have a few nasties in there, CWS, eXact, VX2 amongst others. We'll park the VX2 pop-up generator for now and deal with it at the end. Print out these instructions as most of the steps need to be done in Safe Mode and you won't be able to go online.

First click here to download LSPFix. Extract the program from the zip file and run it, make sure you click the "I know what I'm doing" button. Select calsp.dll and using the right-pointing 'arrows' and move all instances of calsp.dll it mentions to the Remove (RHS) side but leave everything else (it might already be over there when you open LSPFix). Repeat for aklsp.dll. Click the 'Finished' button (if you exit with the X at top right nothing happens).

Do this so you can see hidden files and folders - click here to download xphidden.zip. Extract xphidden.reg from the zip file and save it to the desktop. When done, double-click the xphidden.reg and when asked to merge say yes. Click here to download About:Buster and unzip it to your desktop. Don´t run it yet. Also, click here to download System Security Suite. Extract it from the zip file into a folder.

Next, go to Start->Run and type Services.msc then hit Ok. Scroll down and find the service called "Remote Procedure Call (RPC) Helper". When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Repeat for "ISEXEng". Now hit Apply and then Ok and close any open windows.

Reboot into Safe Mode by tapping F8 after the BIOS has loaded.

Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\oyyor.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\system32\oyyor.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\oyyor.dll/sp.html#12345
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\oyyor.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [0Z.exe] C:\documents and settings\brad hickman\local settings\temp\0Z.exe
O4 - HKLM\..\Run: [Windows ControlAd] C:\Program Files\Windows ControlAd\WinCtlAd.exe
O4 - HKLM\..\Run: [apiwl.exe] C:\WINNT\system32\apiwl.exe
O4 - HKLM\..\Run: [ipoz32.exe] C:\WINNT\system32\ipoz32.exe
O4 - HKLM\..\Run: [nttz.exe] C:\WINNT\system32\nttz.exe
O4 - HKLM\..\Run: [winji32.exe] C:\WINNT\system32\winji32.exe
O4 - HKLM\..\Run: [ienu.exe] C:\WINNT\system32\ienu.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [AutoLoaderpw2f1OMWZJLc] "C:\WINNT\system32\escon32.exe"
O4 - HKLM\..\Run: [p3tV34R] escon32.exe
O4 - HKLM\..\Run: [apijw.exe] C:\WINNT\system32\apijw.exe
O4 - HKLM\..\Run: [javadj.exe] C:\WINNT\system32\javadj.exe
O4 - HKCU\..\Run: [Y029RQd2e] emdcmn.exe
O13 - WWW. Prefix: http://
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)

Find and delete the following (if there):

c:\winnt\ntgm32.exe
c:\winnt\system32\angelex.exe
C:\documents and settings\brad hickman\local settings\temp\0Z.exe
C:\Program Files\Windows ControlAd\ <– folder
C:\WINNT\system32\apiwl.exe
C:\WINNT\system32\ipoz32.exe
C:\WINNT\system32\nttz.exe
C:\WINNT\system32\winji32.exe
C:\WINNT\system32\ienu.exe
C:\Program Files\SED\ <– folder
C:\WINNT\system32\escon32.exe
C:\WINNT\system32\apijw.exe
C:\WINNT\system32\javadj.exe

Now double click AboutBuster.exe that you downloaded earlier. Click Start then click OK. This will scan your computer for the bad files and delete them. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

Rescan with Adaware and let it remove any bad files found.

Reboot back into Normal Mode. Click here to download cwsuninst.zip. Extract cwsuninst.reg from the zip file and save it to the desktop. When done, double-click the cwsuninst.reg and when asked to merge say yes. Open System Security Suite and doubleclick on sss.exe. Check the boxes under the 'Items to Clear' tab and click 'Clear Selected Items'. You will be prompted to reboot, do so. Repeat for all log-in accounts on your computer.

Rescan with HijackThis and post a new log here.
I didn't find the following files to delete.

c:\winnt\ntgm32.exe
c:\winnt\system32\angelex.exe
C:\documents and settings\brad hickman\local settings\temp\0Z.exe
C:\WINNT\system32\apiwl.exe
C:\WINNT\system32\ipoz32.exe
C:\WINNT\system32\nttz.exe
C:\WINNT\system32\winji32.exe
C:\WINNT\system32\ienu.exe
C:\WINNT\system32\escon32.exe
C:\WINNT\system32\apijw.exe
C:\WINNT\system32\javadj.exe

I couldn't run AboutBuster in safe mode so I rebooted and ran it.

Scanned at: 10:59:50 AM on: 12/20/2004


– Scan 1 —————————
About:Buster Version 4.0
Reference List : 19


Removed Data Streams:
C:\WINNT\clock.avi:bndhl
C:\WINNT\CTDiskID.INI:tclxf
C:\WINNT\EventSystem.log:ckpry
C:\WINNT\iconu.exe:lvcuk
C:\WINNT\KB823182.log:erzrw
C:\WINNT\KB824141.log:ettmv
C:\WINNT\KB828035.log:cuben
C:\WINNT\mmdet.log:dedav
C:\WINNT\ockodak.log:hrofl
C:\WINNT\POCE98.DLL:vjzxu
C:\WINNT\Q330994.exe:hfrog
C:\WINNT\qeyfacuylu.exe:vsvsd
C:\WINNT\Santa Fe Stucco.bmp:syuhd
C:\WINNT\SchedLgU.Txt:rmrib
C:\WINNT\SYMEVENT.LOG:dsvkp
C:\WINNT\_detmp.3:vsqes


Attempted Clean Of Temp folder.
Pages Reset… Done!

– Scan 2 —————————
About:Buster Version 4.0
Reference List : 19


Removed Data Streams:
C:\WINNT\clock.avi:bndhl
C:\WINNT\CTDiskID.INI:tclxf
C:\WINNT\EventSystem.log:ckpry
C:\WINNT\iconu.exe:lvcuk
C:\WINNT\KB823182.log:erzrw
C:\WINNT\KB824141.log:ettmv
C:\WINNT\KB828035.log:cuben
C:\WINNT\mmdet.log:dedav
C:\WINNT\ockodak.log:hrofl
C:\WINNT\POCE98.DLL:vjzxu
C:\WINNT\Q330994.exe:hfrog
C:\WINNT\qeyfacuylu.exe:vsvsd
C:\WINNT\Santa Fe Stucco.bmp:syuhd
C:\WINNT\SchedLgU.Txt:rmrib
C:\WINNT\SYMEVENT.LOG:dsvkp
C:\WINNT\_detmp.3:vsqes


Attempted Clean Of Temp folder.
Pages Reset… Done!


I did everything else as instructed. This is the latest HJT log.

Logfile of HijackThis v1.99.0
Scan saved at 11:46:30 AM, on 12/20/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\System32\CTsvcCDA.exe
C:\WINNT\SYSTEM32\DNTUS26.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
c:\winnt\system32\drivers\etc\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\Proxy.exe
c:\winnt\system32\drivers\etc\winxz\f\FireDaemon.exe
C:\winnt\system32\drivers\etc\winxz\scannerap.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\winnt\system32\drivers\etc\svchost.exe
c:\winnt\system32\drivers\etc\svchost.exe
c:\winnt\system32\drivers\etc\SysMgmt.exe
c:\winnt\system32\drivers\etc\spoolsv.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\devldr32.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINNT\system32\wuauclt.exe
C:\PROGRA~1\NTS\ENTERN~1\app\EnterNet.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\unzipped\hijackthis\hijackthis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsupp/ac…supportutil.CAB
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://64.124.45.181/downloads/ccpm_0237.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O23 - Service: Ati HotKey Poller - Unknown - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare NT Utilities 2.6 - DameWare Development - C:\WINNT\SYSTEM32\DNTUS26.EXE
O23 - Service: ISSvc - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PPPoE Service - Unknown - C:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
O23 - Service: Remote Command Terminal - Unknown - c:\winnt\system32\drivers\etc\svchost.exe
O23 - Service: Remote Procedure Call (RPC) Manager - Unknown - C:\WINNT\system32\Proxy.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: FireDaemon Service: scannerap - Sublime Solutions Pty Ltd - c:\winnt\system32\drivers\etc\winxz\f\FireDaemon.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: System Management - Unknown - c:\winnt\system32\drivers\etc\svchost.exe
O23 - Service: System Tracker - Unknown - c:\winnt\system32\drivers\etc\svchost.exe
O23 - Service: winx - mIRC Co. Ltd. - c:\winnt\system32\drivers\etc\winxz\scannerap.exe
OK, it's looking a lot better - let's see how we get on with the next bit.

Go here, download the FindItNT-2K-XP.zip and extract the files from the zip. Navigate to the Find It NT-2K-XP folder and double-click on find.bat. A command prompt will open and it will search your computer for malicious files. Once it has finished a Notepad window will pop up with output.txt. Copy the entire contents of output.txt into your next post.

Don't reboot from now on unless I instruct it otherwise this pest will morph.
How long should find.bat take to run? I ran it more than 20 min. the first time and more than 15 min. this time and it seems to be hanging up. It does write ten text files to a folder called Find-It.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI