I deleted the stuff, but they keep coming back.
Im running a virus scanning program called AVG free edition
It has found sp.dll wich I delete and comes back.
There is a virus called kbd.dll somewhere that I cant find myself and the program wont delete. [external image: Posted Image]
Its still scanning so Ill let you know how it goes.
Click here to download CWShredder and run it, hit 'fix' as opposed to 'scan only'. Reboot when done.
Click here to download ServiceFilter, a little script by rand1038 that reveals potential unauthorised running services in your system. Download, unzip and double-click ServiceFilter.vbs (you may need to enable your antivirus program to run the file). This script will create a text file named Post_This.txt in the same folder as the script itself has been saved - copy and paste the contents of Post_This.txt in your next reply here.
The script did not recognize the services listed below.
This does not mean that they are a problem.
To copy the entire contents of this document for posting:
At the top of this window click "Edit" then "Select All"
Next click "Edit" again then "Copy"
Now right click in the forum post box then click "Paste"
########################################
ServiceFilter 1.1
by rand1038
Microsoft Windows XP Professional
Version: 5.1.2600 Service Pack 1
Jan 20, 2005 11:03:34 PM
===> Begin Service Listing <===
Unknown Service #1
Service Name: NProtectService
Display Name: Norton Unerase Protection
Start Mode: Auto
Start Name: LocalSystem
Description: …
Service Type: Own Process
Path: "c:\program files\norton antivirus\advtools\nprotect.exe"
State: Running
Process ID: 188
Started: True
Exit Code: 0
Accept Pause: False
Accept Stop: True
Unknown Service #2
Service Name: SwPrv
Display Name: MS Software Shadow Copy Provider
Start Mode: Manual
Start Name: LocalSystem
Description: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this …
Service Type: Own Process
Path: c:\windows\system32\dllhost.exe /processid:{e29f4360-b212-4e6b-978f-eba30af84016}
State: Stopped
Process ID: 0
Started: False
Exit Code: 1077
Accept Pause: False
Accept Stop: False
—> End Service Listing <—
There are 85 Win32 services on this machine.
2 were unrecognized.
Script Execution Time: 0.9375 seconds.
* DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________
O^E says: "There were no files found :)"
________________________________________________
1,405 items found: 1,405 files, 0 directories.
Total of file sizes: 278,935,377 bytes 266.01 M
Administrator Account = True
AppInit_DLLs value = c:\windows\system32\kbd.dll (not hidden)
——————–End log———————
Unzip it to the desktop and run it. First press *Find Updates* and let it download them (I think we are on Ref. file #21 on that one). Then follow the instruction to scan and fix.
Post a fresh HijackThis log and the AboutBuster report back here please.
Logfile of HijackThis v1.99.0
Scan saved at 9:34:41 AM, on 1/21/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avginet.exe
C:\Documents and Settings\betty\My Documents\programs\spyware\HijackThis.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Scanned at: 12:00:03 AM on: 1/21/2005
– Scan 1 —————————
About:Buster Version 4.0
Reference List : 23
No ADS found on system
Removed! : C:\WINDOWS\System32\kbd.dll
Attempted Clean Of Temp folder.
Pages Reset… Done!
– Scan 2 —————————
About:Buster Version 4.0
Reference List : 23
No ADS found on system
Attempted Clean Of Temp folder.
Pages Reset… Done!
– Scan 3 —————————
About:Buster Version 4.0
Reference List : 23
No ADS found on system
Attempted Clean Of Temp folder.
Pages Reset… Done!
It was normal mode.
I think I may be clean. So far so good.
Do I need to remove virtual machine?
I use addaware
Spybot & hijackthis to keep a check.
I really appreciate all your help.
That thing has plagued me for about a year.
So far so good.
I think its really nice of you to take your time walking people through all these steps to help them out. Im gonna hold on to these programs and hopefully be able to fix it if it ever happens again.
Again Thank You Very Much!
If you dont have these three programs I would recommend that you get them. Spywareblaster,Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.
It is critical to have both a firewall and anti virus to protect your system.
Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.
If you need this topic reopened, please request this by sending an email to us at the following link (Click for address) Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.
If this is not your thread please start a New Topic.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI