This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijackthis Log - Please Help

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Today I ran SpyBot and AVG.

The following was extracted from the AVG log. The execom stuff is part of one of my programs and is not a virus.

"C:\MyDisk\JIGSAW\JIGSAW\WWW\STATE\JULY5\TEMPLA~1.DAT","Could be infected W97M/Ethan","Infected"
"C:\MyDisk\OPEN\EXECOM.EXE","Suspicion: unknown virus .TSR","Infected"
"C:\MyDisk\OpenV\EXECOM.BAK","Suspicion: unknown virus .TSR","Infected"
"C:\MyDisk\OpenV\Execom.exe","Suspicion: unknown virus .TSR","Infected"
"C:\MyDisk\OpenV\Back\Execom.exe","Suspicion: unknown virus .TSR","Infected"
"C:\MyDisk\OpenV\OpenDev\Execom\Execom2\EXECOM.EXE","Suspicion: unknown virus .TSR","Infected"
"C:\MyDisk\OpenV\OpenDev\Execom\Execom2\_XECOM.$$$","Suspicion: unknown virus .TSR","Infected"
"C:\OPEN\EXECOM.EXE","Suspicion: unknown virus .TSR","Infected"
"C:\OpenV\EXECOM.BAK","Suspicion: unknown virus .TSR","Infected"
"C:\OpenV\EXECOM.EXE","Suspicion: unknown virus .TSR","Infected"
"C:\OpenV\Back\Execom.BAK","Suspicion: unknown virus .TSR","Infected"
"C:\OpenV\Back\Execom.exe","Suspicion: unknown virus .TSR","Infected"
"C:\OpenV\Old\EXECOM.EXE","Suspicion: unknown virus .TSR","Infected"
"C:\OpenV\OpenDev\Execom\Execom2\EXECOM.EXE","Suspicion: unknown virus .TSR","Infected"
"C:\OpenV\OpenDev\Execom\Execom2\_XECOM.$$$","Suspicion: unknown virus .TSR","Infected"

"C:\Downloads\Anti-Parasite\KillBox\crsss.exe","","Deleted"
"C:\Downloads\Anti-Parasite\KillBox\syshost.exe","","Deleted"
"C:\WINDOWS\MatAdown.dll","","Deleted"
"C:\WINDOWS\system32\MatAdown.dll","","Deleted"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\DF7ZLTIR\istsvc[1].exe","","Deleted"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet
Files\Content.IE5\J20ZYTGA\bobby[1].exe","","Deleted"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet
Files\Content.IE5\P8UJHVWL\istrecover[1].exe","","Deleted"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\P8UJHVWL\x[1].exe","","Deleted"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\P8UJHVWL\x[2].exe","","Deleted"


Then I decided to “go round again”, rebooting the machine after using each utility.

First I ran RegCleaner – Tools > RegCleanup > Do them all > select all > delete.

Then I did Start > Run > %temp% and tried to delete the contents of the directory. It said “Cannot delete Perflib_Perfdata_1d4.dat. It is being used by another person or program.” Also, KillBox could not delete it.

Then I did Control Panel > Internet Options > General > Delete Files > Offline content > ok.

Then I did Start > Run > cleanMgr on Temporary Files, Temporary Internet Files and Recycle Bin. While in cleanMgr, I looked at its list of installed programs. I don’t know what DeskAd Services and Windows ServeAd are.

Then I ran Stinger and this is the log.

McAfee AVERT Stinger Version 2.4.7 built on Jan 3 2005
Copyright © 2004 Networks Associates Technology, Inc. All Rights Reserved.
Virus data file v1000 created on Dec 14 2004.
Ready to scan for 47 viruses, trojans and variants.
Scan initiated on Thu Jan 13 14:22:30 2005

C:\!Submit\o
Found the W32/Sdbot.worm!ftp virus !!!
C:\!Submit\o has been deleted.

C:\WINDOWS\system32\o
Found the W32/Sdbot.worm!ftp virus !!!
C:\WINDOWS\system32\o has been deleted.

Number of clean files: 500972
Number of infected files: 2
Number of files deleted: 2
——————————————————————————————————-

Then I ran AdAware, SpyBot and AVG and cleaned/deleted as much as I could.

Then I ran the eSpan (mWav.exe) utility and it found the following (just seen your last post and I see I should ignore the !Submit items - I’ve just deleted the folder).

File C:\WINDOWS\System32\navprotect.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\winxpdriver.exe infected by "Backdoor.Win32.Wootbot.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\winxpdriver.exe infected by "Backdoor.Win32.Wootbot.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\zzz.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\ESOWF.dll infected by "Backdoor.Win32.Haxdoor.ay" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\mswe1.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\navprotect.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\!Submit\aRMlpbBvH.exe infected by "not-a-virus:AdWare.WinFetcher.c" Virus. Action Taken: No Action Taken.
File C:\!Submit\askjhfs3.exe infected by "TrojanDownloader.Win32.Small.qd" Virus. Action Taken: No Action Taken.
File C:\!Submit\Config.sys tagged as not-a-virus:Porn-Dialer.Win32.Generic. No Action Taken.
File C:\!Submit\DeskAdKeep.exe infected by "not-a-virus:AdWare.WinAD.k" Virus. Action Taken: No Action Taken.
File C:\!Submit\DLC[1].exe infected by "TrojanDownloader.Win32.Small.qd" Virus. Action Taken: No Action Taken.
File C:\!Submit\ESOWF.dll infected by "Backdoor.Win32.Haxdoor.ay" Virus. Action Taken: No Action Taken.
File C:\!Submit\freedownload.exe tagged as not-a-virus:Porn-Dialer.Win32.Generic. No Action Taken.
File C:\!Submit\Inbox infected by "Macro.Word97.Marker.q" Virus. Action Taken: No Action Taken.
File C:\!Submit\instsrv.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken.
File C:\!Submit\jhfhjj.exe infected by "TrojanDownloader.Win32.Small.qd" Virus. Action Taken: No Action Taken.
File C:\!Submit\KILLAPPS.EXE tagged as not-a-virus:RiskWare.Tool.KillApp.b. No Action Taken.
File C:\!Submit\mac80ex.idf infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken.
File C:\!Submit\mediaplayer.exe infected by "TrojanDropper.Win32.Juntador.c" Virus. Action Taken: No Action Taken.
File C:\!Submit\navprotect.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\!Submit\netut80ex.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken.
File C:\!Submit\ov.exe infected by "not-a-virus:AdWare.WinFetcher.b" Virus. Action Taken: No Action Taken.
File C:\!Submit\ringtone.exe tagged as not-a-virus:RiskWare.Dialer.PlayGames. No Action Taken.
File C:\!Submit\Sent infected by "Macro.Word97.Marker.q" Virus. Action Taken: No Action Taken.
File C:\!Submit\SexPress - UK.EXE tagged as not-a-virus:Porn-Dialer.Win32.Frelex. No Action Taken.
File C:\!Submit\systemupdate.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\!Submit\targetsaver[1].exe infected by "TrojanDownloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken.
File C:\!Submit\tmpf04.exe infected by "Backdoor.Win32.Haxdoor.az" Virus. Action Taken: No Action Taken.
File C:\!Submit\tmpf06.exe infected by "Backdoor.Win32.Haxdoor.az" Virus. Action Taken: No Action Taken.
File C:\!Submit\WebRebates0.exe infected by "not-a-virus:AdWare.WebRebates.d" Virus. Action Taken: No Action Taken.
File C:\!Submit\WebRebates1.exe infected by "not-a-virus:AdWare.WebRebates.d" Virus. Action Taken: No Action Taken.
File C:\!Submit\WinServAd.exe infected by "not-a-virus:AdWare.WinAD.f" Virus. Action Taken: No Action Taken.
File C:\!Submit\WinServSuit.exe infected by "not-a-virus:AdWare.WinAD.h" Virus. Action Taken: No Action Taken.
File C:\Downloads\Anti-Parasite\HighjackThis\backups\backup-20050108-121417-120.dll infected by "not-a-virus:AdWare.Relevance.b" Virus. Action Taken: No Action Taken.
File C:\Downloads\IomegaWin98\ioware-w32-x86-402.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\My Downloads\Iomega\ioware-w32-x86-402.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\Downloads\Copy (2) of PBCC2\setupcc.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\Downloads\Copy (2) of PBDLL6\setupdll.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\Downloads\Copy of PBCC2\setupcc.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\Downloads\Copy of PBDLL6\setupdll.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\Downloads\PBCC2\setupcc.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\Downloads\PBDLL6\setupdll.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\Downloads\PBUPGR~1\setupcc.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\Downloads\PBUPGR~1\setupdll.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\JDK12~1.2\DEMO\APPLETS\BARCHART\Chart.class tagged as not-a-virus:JavaClass.Chart. No Action Taken.
File C:\MyDisk\LOSTFILE\DIR171\AOL\AOL40US.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\PROGRA~1\ONLINE~1\AT&T\ATTSETUP.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\WIN32API\WIN32API.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\program files\Iomega\AutoDisk\Setup_enu.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\program files\Iomega\DriveIcons\imghr.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\program files\Iomega\System32\Win2kDrivers.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\RECYCLER\undo.exe infected by "Trojan.WinREG.LowZones.a" Virus. Action Taken: No Action Taken.
File C:\trots.exe infected by "TrojanDropper.Win32.PurityScan.h" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\J20ZYTGA\data[1].exe infected by "TrojanDropper.Win32.Juntador.c" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\J20ZYTGA\DTBC[1].exe infected by "TrojanDownloader.Win32.Small.qd" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\J20ZYTGA\webrebates_europe[1].exe infected by "not-a-virus:AdWare.WebRebates.d" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\P8UJHVWL\data[1].exe infected by "TrojanDropper.Win32.Juntador.c" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\ESOWF.dll infected by "Backdoor.Win32.Haxdoor.ay" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\mswe1.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\navprotect.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\zzz.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\Zips\Backup Disk #2\Downloads1.zip tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Zips\Backup Disk #3\My Downloads.zip tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Zips\MyDisk1.zip tagged as not-a-virus:Porn-Dialer.Win32.Frelex. No Action Taken.
File C:\Zips\MyDisk2.zip tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Zips\Program files.zip tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.


Finally I ran HJT and here is the log.

Logfile of HijackThis v1.99.0
Scan saved at 20:04:47, on 13/01/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\navprotect.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\System32\winxpdriver.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\ahead\InCD\InCD.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\navprotect.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\navprotect.exe
C:\program files\Microsoft Office\Office\OSA.EXE
C:\program files\WinZip\WZQKPICK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Downloads\Anti-Parasite\HighjackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.evesham.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://signup.e2binternet.com/cdsignup/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
O2 - BHO: ZIBho Class - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh304181.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NAV Auto Protect] navprotect.exe
O4 - HKLM\..\Run: [Windows Driver] winxpdriver.exe
O4 - HKLM\..\RunServices: [NAV Auto Protect] navprotect.exe
O4 - HKLM\..\RunServices: [Windows Driver] winxpdriver.exe
O4 - HKLM\..\RunOnce: [Windows Driver] winxpdriver.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NAV Auto Protect] navprotect.exe
O4 - HKCU\..\Run: [Windows Driver] winxpdriver.exe
O4 - HKCU\..\RunOnce: [Windows Driver] winxpdriver.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\program files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\program files\Microsoft Office 2000\Office\OSA9.EXE
O4 - Global Startup: Office Startup.lnk = C:\program files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\program files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Get It With Kontiki - res://C:\Program Files\Kontiki\bin\bh304181.dll/201
O14 - IERESET.INF: START_PAGE_URL=http://www.evesham.com/
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/16ecf39562da2cd08715/netzip/RdxIE6.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: CTI Central Management - Unknown - C:\WINDOWS\cti.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Iomega Active Disk - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe
Question for you:

Do you recognize this service: CTI Central Management

Service: CTI Central Management - Unknown - C:\WINDOWS\cti.exe


If not have HJT fix it and delete the file: C:\WINDOWS\cti.exe


I don’t know what DeskAd Services and Windows ServeAd are.


They're malware - uninstall them - delete the folders - etc.

Press Control-Alt-Del to enter the Task Manager.
Click on the Processes tab and end the following processes if listed:

C:\WINDOWS\System32\navprotect.exe
C:\WINDOWS\System32\winxpdriver.exe

Exit the Task Manager when finished

Close all programs down, leaving only HijackThis running.
Place a check against the following items:

O4 - HKLM\..\Run: [NAV Auto Protect] navprotect.exe
O4 - HKLM\..\RunServices: [NAV Auto Protect] navprotect.exe
O4 - HKLM\..\RunServices: [Windows Driver] winxpdriver.exe
O4 - HKLM\..\RunOnce: [Windows Driver] winxpdriver.exe
O4 - HKCU\..\Run: [NAV Auto Protect] navprotect.exe
O4 - HKCU\..\Run: [Windows Driver] winxpdriver.exe
O4 - HKCU\..\RunOnce: [Windows Driver] winxpdriver.exe

O23 - Service: CTI Central Management - Unknown - C:\WINDOWS\cti.exe
Only if you don't recognize it

Click on Fix Checked and exit HijackThis.

Then I did Start > Run > %temp% and tried to delete the contents of the directory. It said “Cannot delete Perflib_Perfdata_1d4.dat. It is being used by another person or program.” Also, KillBox could not delete it.


Try the KillBox again, this time use "Replace On Reboot" and "Use Dummy"

Get the KillBox out and delete these:

C:\WINDOWS\System32\navprotect.exe
C:\WINDOWS\System32\winxpdriver.exe
C:\WINDOWS\zzz.exe
C:\WINDOWS\System32\ESOWF.dll
C:\WINDOWS\system32\mswe1.exe
C:\RECYCLER\undo.exe
C:\trots.exe


C:\WINDOWS\cti.exe <—only if you don't recognize it!!!



See if you can delete these - they all seem to be temp internet files

C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\J20ZYTGA\data[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\J20ZYTGA\DTBC[1].exe
: C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\J20ZYTGA\webrebates_europe[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\P8UJHVWL\data[1].exe

Reboot and delete that "Submit" folder again - empty recycle bin.
Let me know , MrC
I deleted C:\Windows\cti.exe. I tried to get CleanMgr to remove the DeskAd and ServeAd but it said it couldn’t. I did a search for source files/folder but found nothing.

I did all the other things you said except KillBox couldn’t delete ESOWF.dll. I used HJT’s process manager to see if I could find any process that was using the dll but found nothing.

After rebooting I see that Perflib_Perfdata_1d4.dat is still in the temp folder and cannot be deleted. The latest HJT log is below. I suppose I should now “go round again” with mWav, AdAware etc.

Just as I was about to post this message I noticed I’m still getting those wretched “Messenger Service” popups. Also, I tried running the BitDefender online scan but the computer crashed/rebooted part way through.


Logfile of HijackThis v1.99.0
Scan saved at 21:34:45, on 14/01/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\ahead\InCD\InCD.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\program files\Microsoft Office\Office\OSA.EXE
C:\program files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\Downloads\Anti-Parasite\HighjackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.evesham.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://signup.e2binternet.com/cdsignup/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
O2 - BHO: ZIBho Class - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh304181.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Find Fast.lnk = C:\program files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\program files\Microsoft Office 2000\Office\OSA9.EXE
O4 - Global Startup: Office Startup.lnk = C:\program files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\program files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Get It With Kontiki - res://C:\Program Files\Kontiki\bin\bh304181.dll/201
O14 - IERESET.INF: START_PAGE_URL=http://www.evesham.com/
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/16ecf39562da2cd08715/netzip/RdxIE6.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Iomega Active Disk - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

Just as I was about to post this message I noticed I’m still getting those wretched “Messenger Service” popups. Also, I tried running the BitDefender online scan but the computer crashed/rebooted part way through.



Check the link below to disable it:

http://www.microsoft.com/windowsxp/using/s…e/stopspam.mspx

Do you have DSL or on a cable modem?
I have a program to run that will scan and DELETE the bad files, but it's a large download.

Let me know - MrC
Ok – I’ve just been using IE for a while (that’s all I was doing) and suddenly the computer crashed/rebooted. I tried using IE again but its now back in “snail-pace” mode. In fact, it’s so slow I’m having trouble getting to the point where I can post this message. I keep noticing that the little ISP icon on the task bar indicates that megabytes of data are being sent but only a few kilobytes are being received.

Before posting, I checked for running processes and navprotect.exe is back. Then I ran HJT and the [NAV Auto Protect] entries are back. We keep going round in circles and there’s no way out.

Thanks for the link, which I will study now. But disabling Messenger Service is treating the symptoms and not the disease, isn’t it. Unfortunately I only have a straight phone link. I have successfully downloaded 10 Mbyte but that was before the system was infected.


Logfile of HijackThis v1.99.0
Scan saved at 22:41:15, on 14/01/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\Program Files\ahead\InCD\InCD.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\navprotect.exe
C:\Program Files\Messenger\msmsgs.exe
C:\program files\Microsoft Office\Office\OSA.EXE
C:\program files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Downloads\Anti-Parasite\HighjackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.evesham.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://signup.e2binternet.com/cdsignup/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
O2 - BHO: ZIBho Class - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh304181.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NAV Auto Protect] navprotect.exe
O4 - HKLM\..\RunServices: [NAV Auto Protect] navprotect.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NAV Auto Protect] navprotect.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\program files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\program files\Microsoft Office 2000\Office\OSA9.EXE
O4 - Global Startup: Office Startup.lnk = C:\program files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\program files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Get It With Kontiki - res://C:\Program Files\Kontiki\bin\bh304181.dll/201
O14 - IERESET.INF: START_PAGE_URL=http://www.evesham.com/
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/16ecf39562da2cd08715/netzip/RdxIE6.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Iomega Active Disk - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe
See if you can find that file:
C:\WINDOWS\System32\navprotect.exe

Right click on it and choose properties, see what info you can find out about it.
Did you ever have any Norton products on the system??

But disabling Messenger Service is treating the symptoms and not the disease, isn’t it. Unfortunately I only have a straight


The Messenger Service was originally designed for use by system administrators to notify Windows users about their networks. However, some advertisers have started using this service to send information via the Internet, and these messages could be used maliciously to distribute a virus.

Let me know, MrC
Messenger service is disabled. Also, I’ve never had any Norton products installed. I can’t get into the C:\Windows\System32 folder – same old problem – computer crashes/reboots when I access it from Explorer or KillBox. The navprotect.exe process was back and running – I ended it. The [NAV Auto Protect] items were back – I fixed them in HJT. Cti.exe was back – I killed it. C:\Windows\Sytem32\navprotect.exe – I assume its back but I can’t get near it without the computer crashing. Also, IE now crashes/reboots at random moments. Are we ever going to get out of this hell?
If you feel like doing it, you can try the program I talked about.
I know it's a big download - it's up to you.

Other then that - I say back-up, format and reinstall.
The system is so badly infected and corrupt.

Here's how the program goes:


Download Sysclean Package (2.4mb) :
http://www.trendmicro.com/ftp/products/tsc/sysclean.com <–direct download
http://www.trendmicro.com/download/dcs.asp <—it's on this page

Download the latest pattern file ltp349.zip (5.6mb)
http://www.trendmicro.com/ftp/products/pattern/lpt349.zip <–direct download
http://www.trendmicro.com/download/pattern.asp <—on this page

Unzip it to a folder.
Now move the sysclean.com (that you downloaded before) into the folder with the
lpt$vpn.349 in it.
Now you should end up with one folder with sysclean.com and lpt$vpn.349 in it.
To start the scan, just click the sysclean.com.
Make sure the box in the lower left of the program is checked:!!!!!!
Automatically clean or delete detected files

Sit back - it takes a while to complete and does create a log of what was fixed. MrC
Thanks MrCharlie. I'll see how I feel in the morning. I don't fancy a format/reinstall but that might be the only way. Whatever the outcome, I want you to know that I really appreciate the time and effort you have given to helping me.
Hello Keith,

Nick from PB forum again. Hope you get cleaned up. Would like to suggest you visit

http://www.diamondcs.com.au/portexplorer/

and download the 30 day trial. From your log I see no firewall, and you need to monitor at times port activity. I finally bought it ! Works great ?

Also they have one of what I consider the best software program for XP against malware (Process Guard). At least read reviews !

I followed your progress. Mine would not run HiJackThis, and took 6 weeks to clean up, and another 4 weeks to almost trust it again.

Its hard to clean an infected computer, without a 2nd one to access the internet.
MrCharlie – I tried the Sysclean package. It found a couple or three things but it didn’t clear the problem. Everytime I run IE I find that the navprotect process and exe is back – goodness knows where it’s coming from. I’ve more or less committed myself to a format/reinstall and have pressed an old computer into temporary service while I make sure backups are up to date. Nick – as you see all attempts at cleaning my computer seem to have failed. Thanks for the link, which I will study. I can see I have to gen up on the subject a bit. For instance, I thought XP came with its own firewall. Also, I am seriously considering going broadband so presumable a firewall is even more important. Mr Charlie said he would point me to some programs to protect the system and it will be interesting to see what he recommends.
I think that's the best thing to do now, start with a clean system and install all these programs so your protected.

Everything in red you must install - the rest is optional.


++++++++++++++++++++++++++++++++++++++++++++++++++


Some preventive maintenance:

Now that you're clean: <—-Important Step!!!!
Delete your system restore files and create a new restore point:

XP system restore

ME system restore


Visit Windows Update and install all the lastest critical updates.

Install these two free programs, they sit in the backround and protect your system from spy and adware being installed on your system, also from your browser being hijacked. Check for updates weekly.

SpywareBlaster

SpywareGuard


IE-SPYAD
Puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
IE-SPYAD



Need a free anti virus?
AVG*free
(check for updates - daily)

How about a firewall? The front door to your computer.
ZoneAlarm*free

Free spyware removal programs:
SpyBot
AD-Aware
CW-Shredder


Free Online Trojan Scan

TrojanHunter - free trial

Please consider using FireFox instead of Internet Explorer

Replace Java with SunJava

Pop-up stoppers:
GoogleToolBar
Pop-upStopperFree

Don't open e-mail attachments without first scanning them with an up-to-date
anti virus program, even after doing that I would be very careful. Don't click on any executables in e-mails or any other links that you're not sure of.
Watch your surfing habits, don't click on or download anything you're not sure of. Don't install a program that hasn't been recommended by a reputable organization.


Good luck and thanks for using the forum - MrC
As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be
"Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Thanks, MrC

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI