This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help Me Please...

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.97.7
Scan saved at 5:38:27 PM, on 1/28/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\EPOAgent\naimas32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\EPOAgent\naimag32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Documents and Settings\Jeff Curvin\Start Menu\Programs\Startup\winupdate28871048[1].exe
C:\Documents and Settings\Jeff Curvin\Start Menu\Programs\Startup\winupdate30944442[1].exe
C:\Documents and Settings\Jeff Curvin\Start Menu\Programs\Startup\winupdate41618125[1].exe
C:\Documents and Settings\Jeff Curvin\Start Menu\Programs\Startup\winupdate87874329[1].exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\Program Files\Internet Optimizer\actalert.exe
C:\WINDOWS\System32\SahAgent.exe
c:\temp\salm.exe
C:\WINDOWS\System32\urldata.exe
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\Program Files\Windows AdStatus\WinStat.exe
C:\Program Files\Windows AdStatus\WinStatKeep.exe
C:\WINDOWS\System32\wmpclr40.exe
C:\Program Files\CxtPls\CxtPls.exe
C:\Program Files\WebSiteViewer\10362560temp.exe
C:\Program Files\WebSiteViewer\126099.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.auburn.edu/main/currentstudents.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
O2 - BHO: (no name) - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL
O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} - C:\WINDOWS\questmod.dll
O2 - BHO: (no name) - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem303.dll
O2 - BHO: (no name) - {962F12AE-2773-4BEB-99EA-B5C3AB9A6606} - C:\WINDOWS\System32\DSMANA~1.DLL
O2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NaimAgent_UI] C:\EPOAgent\naimag32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
O4 - HKLM\..\Run: [onyrmb] C:\WINNT\onyrmb.exe
O4 - HKLM\..\Run: [SAHAgent] C:\WINDOWS\System32\SahAgent.exe
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\Run: [Windows AdStatus] C:\Program Files\Windows AdStatus\WinStat.exe
O4 - HKLM\..\Run: [47Ek36W] wmpclr40.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [LwxqRWath] urldata.exe
O4 - Startup: winupdate28871048[1].exe
O4 - Startup: winupdate30944442[1].exe
O4 - Startup: winupdate38981076[1].exe
O4 - Startup: winupdate41618125[1].exe
O4 - Startup: winupdate87874329[1].exe
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/get/shock…director/sw.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://cam5.brett-robinson.com/activex/AxisCamControl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab
hello swirvin5, you have quite a collection. ok we will uninstall some files, use hjt, boot to safe mode, delete files. ok i would print this out or copy it to a text file somwhere so you can get to it. also before starting pull plug on modem until done. first; make sure files are set to show: FOr XP: on the desktop double click my computer,go to tools>folder options>view> then select "show hidden files and folders", then UNcheck "hide protected operating system files " also UNcheck "hide extensions for known file types" click apply to all folders, apply then ok ———————————- look in add/remove programs panel and uninstall these if present: Internet Optimizer BullsEye Network WebSiteViewer also uninstall any web helpers or toolbars or anything you dont recognize or know how it got there, after uninstalling all–reboot computer. ———————————- Run HJT and check the following items: Close all open windows except HiJackThis and press 'Fix Checked' log may be alittle different after uninstalling stuff, if you dont see something dont worry about it. R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll O2 - BHO: (no name) - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} - C:\WINDOWS\questmod.dll O2 - BHO: (no name) - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem303.dll O2 - BHO: (no name) - {962F12AE-2773-4BEB-99EA-B5C3AB9A6606} - C:\WINDOWS\System32\DSMANA~1.DLL O2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe" O4 - HKLM\..\Run: [salm] c:\temp\salm.exe O4 - HKLM\..\Run: [onyrmb] C:\WINNT\onyrmb.exe O4 - HKLM\..\Run: [SAHAgent] C:\WINDOWS\System32\SahAgent.exe O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe O4 - HKLM\..\Run: [Windows AdStatus] C:\Program Files\Windows AdStatus\WinStat.exe O4 - HKLM\..\Run: [47Ek36W] wmpclr40.exe O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe" O4 - HKCU\..\Run: [LwxqRWath] urldata.exe O4 - Startup: winupdate28871048[1].exe O4 - Startup: winupdate30944442[1].exe O4 - Startup: winupdate38981076[1].exe O4 - Startup: winupdate41618125[1].exe O4 - Startup: winupdate87874329[1].exe —————————————— ok now boot into safe mode by tapping the f8 key at restart, chose safe mode, once in safe mode you see all the above 04 items? find and delete them, for example. those in C:\Program Files>>delete entire folder, example:Internet Optimizer there are acouple of these in c:\program files also delete these folders: C:\Program Files\WebSiteViewer\10362560temp.exe C:\Program Files\WebSiteViewer\126099.exe for the rest delete just the .exe file in the directory, example: salm.exe>>delete just that located here>>c:\temp onyrmb.exe>>delete only that located here>>C:\WINNT wmpclr40.exe >>here>>C:\WINDOWS\System32 urldata.exe>> here>> C:\WINDOWS\System32 dont worry about those in the Startup: (for now) ok still in safe mode do this: Click Start>Run then type %temp% Hit OK. Delete all the files you can. Empty your Temp folders. Go to Start > Run and type:cleanmgr. Windows will scan. When done check these 3 and press *ok* to remove: Temporary Files Temporary Internet Files Recycle Bin also delete these numbered .exe all located>>C:\Documents and Settings\Jeff Curvin\Start Menu\Programs\Startup C:\Documents and Settings\Jeff Curvin\Start Menu\Programs\Startup\winupdate28871048[1].exe C:\Documents and Settings\Jeff Curvin\Start Menu\Programs\Startup\winupdate30944442[1].exe C:\Documents and Settings\Jeff Curvin\Start Menu\Programs\Startup\winupdate41618125[1].exe C:\Documents and Settings\Jeff Curvin\Start Menu\Programs\Startup\winupdate87874329[1].exe —————————————— reboot normally rescan with hjt and post new log……………….shelf life
Did i miss anything


Logfile of HijackThis v1.99.0
Scan saved at 6:36:00 PM, on 1/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\EPOAgent\naimas32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.auburn.edu/main/currentstudents.html
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {7F241C00-DAB6-11d5-AAA8-0001028DF1BC} - file://C:\Program Files\EbatesMoeMoneyMaker\System\Temp\ebates_script0.htm (file missing) (HKCU)
O21 - SSODL: AdobeESD - {6A3AB885-B377-4EA4-6290-CD40F09D9021} - C:\Program Files\Common Files\Adobe\Color.dll
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: McAfee Framework Service - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NAI ePolicy Orchestrator Agent - Network Associates, Inc. - C:\EPOAgent\naimas32.exe
O23 - Service: WLTRYSVC - Unknown - C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe (file missing)
O23 - Service: ZESOFT - Unknown - C:\WINDOWS\zeta.exe
hello swirvin5, good work. log looks much better. look in add/remove panel and uninstall these if present; BullsEye Network EbatesMoeMoneyMaker ———————– run hjt and have it fix these: O9 - Extra button: (no name) - {7F241C00-DAB6-11d5-AAA8-0001028DF1BC} - file://C:\Program Files\EbatesMoeMoneyMaker\System\Temp\ebates_script0.htm (file missing) (HKCU) O23 - Service: WLTRYSVC - Unknown - C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe (file missing) O23 - Service: ZESOFT - Unknown - C:\WINDOWS\zeta.exe ——————————————————– next: boot into safe mode by tapping the f8 key at startup, chose safe mode from the options. once in safe mode: BullsEye Network>>delete entire folder located here>>C:\Program Files\ zeta.exe>> delete the .exe located here>>C:\WINDOWS ok still in safe mode do this: Click Start>Run then type %temp% Hit OK. Delete all the files you can. Empty your Temp folders. Go to Start > Run and type:cleanmgr. Windows will scan. When done check these 3 and press *ok* to remove: Temporary Files Temporary Internet Files Recycle Bin ———————————————————- reboot normally rescan with hjt and post new log…………….shelf life
ok i think i got it all this time.. thanks for all the help

Logfile of HijackThis v1.99.0
Scan saved at 6:20:40 PM, on 1/30/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\DOCUME~1\JEFFCU~1\LOCALS~1\Temp\tmpD.tmp
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Java\j2re1.4.2_06\bin\javaw.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.auburn.edu/main/currentstudents.html
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe
hello swirvin5

the log looks much better, good job.
you can delete this one also, if still present:
tmpD.tmp located here>>>C:\DOCUME~1\JEFFCU~1\LOCALS~1

other than that looks good,

for reference:

Please follow a few tips to remain malware free:

1) Make sure you keep your Windows OS current by visiting Windows update occasionaly to download and install any critical updates and service packs. With out these you are leaving the backdoor open.
http://v4.windowsupdate.microsoft.com/en/default.asp

Also download, install and keep updated- Antivirus Software (and use only one):
Free for home users:
http://www.avast.com/eng/free_virus_protectio.html
http://free.grisoft.com/freeweb.php/doc/2/ AVG free version v6.0 updates end 12/31/04>>>get new (still free) version 7.0
http://www.free-av.com/

2) Watch what you download, and where you download it from. Alot of software comes bundled with "extra" crapware you may not want. Make sure you know what it is you will be downloading and installing. Visit the makers website, learn more about the program, Does the program you want come bundled with other "3rd party" programs? What do the 3rd party programs do? Will they deliver ads? Track your surfing habits?.You may be installing more than you think, Read the EULA agreement, you know that paragraph of stuff you "agree to" before the software installs? Stay away from warez and crack sites. Becarful what you download from file sharing networks.If you are not sure, scan it with your Antivirus app. A small file (in KB) is probably not what you think it is. Some p2p clients may also install 3rd party stuff you probably dont want.

3)Adjust your browser settings: Change your(active x) settings in IE. With IE open go to tools, internet options, security tab. Click on the internet globe, then custom level. Set the first option "download signed active x controls" to prompt, the next two to disable. Read more: https://netfiles.uiuc.edu/ehowes/www/btw/ie/ie-opts.htm
http://www.microsoft.com/windows/ie/using/…y/settings.mspx
Many exploits are directed at Internet Explorer, you dont have to use it. Try a different browser: http://www.mozilla.org/products/firefox/

4)Install a firewall. A firewall will control what comes in from the internet and what leaves your computer to the internet. A firewall will also alert you when a application trys to connect to the internet from your computer, this is a good way to catch crapware or trojans, trying to connect out bound from your computer- whats that and why does it need a internet connection? You can deny it access it until more investigation is done. Zone Alarm is a free and easy to use firewall, that will provide in and outbound protection. Microsoft XP firewall only provides inbound protection. SP2 adds in and out bound protection which is better than nothing, but is not as robust as third party firewalls, Be sure to run only >one< firewall.If you use another, be sure to disable XP's built in firewall.A inexpensive NAT hardware router with SPI (firewall)would be even better,along with a software firewall.
Zone Alarm: http://www.zonelabs.com/store/content/home.jsp
Kerio Personal Firewall: http://www.kerio.com/us/kpf_home.html
Outpost Firewall: http://www.agnitum.com/products/outpost/

5)Download, install and update before using:(if these are constantly finding malware, then you need to make some changes)
Ad-Aware SE Personal edition: http://www.lavasoft.de/
Spybot Search and destroy: http://www.safer-networking.org/en/index.html
Becarful with spyware "removers and scanners"– there are many "rogue/suspect" programs that "claim to remove" spyware.


6)Other programs to consider:
SpywareBlaster: http://www.bleepingcomputer.com/forums/ind…showtutorial=49
IE-SPYAD: https://netfiles.uiuc.edu/ehowes/www/resource.htm#IESPYAD
AntiTrojan software to fill in the gap:
a2 free: http://www.emsisoft.com/en/software/free/
Ewido Security Suite: http://www.ewido.net/en/
Trojan Hunter (30 day trial version) http://www.misec.net/

7) Learn More:
http://www.dslreports.com/faq/8463#Tighten%20IE
http://www.cert.org/homeusers/HomeComputerSecurity/
http://www.wilders.org/index.htm

. . .
,-. |-. ,-. | ," | . ," ,-.
`-. | | |-' | |- | | |- |-'
`-' ' ' `-' `' | `' ' | `-'
' '
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.


To help keep you clean follow the recommendations in Tony's article here:
So how did I get infected in the first place?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI