Hello Eli, and welcome to the TomCoyote Forums. I will be helping you get
your system cleaned up and protected.
I am currently reviewing your HiJackThis log and will post a suggested fix shortly.
While you're waiting, your copy of HijackThis should be moved into a permanent folder,
and not on the desktop. HJT creates backups in case anything goes wrong and it is easier
to retrieve them from a permanent folder if needed.
Please go to your 'My Documents' folder, right-click and select 'New > Folder'
then name the folder 'HJT'.
NOTE: You can place HJT in a directory of your choice. As long as it has it's own
folder and is NOT on the desktop or in a temp directory.
Copy and paste HijackThis.exe to the new folder.
Regards,
Dave
Please follow these instructions exactly as described and I recommend that
you print them out to use as a reference during the fix. I find it easy to keep
track of what you're doing by crossing out each item as you go.
Just a reminder also about making sure that HJT is in it's own folder before making any changes with it.
You need to prevent Ad-Watch from loading at Windows startup, because Ad-Watch will block any changes made by HijackThis. To do this:
Open Ad-Aware.
Click the Ad-Watch icon on the top of the screen.
Go to "Tools" and "Preferences".
At the bottom of the program window there are two items, "Active" and "Automatic".
Uncheck both items.
Make sure when we are done with the fix to re-enable Ad-Watch by checking these two items.
We need to stop some processes from running so HJT can fix them.
Please open Task Manager with Ctrl-Alt-Del and END TASK on the following files:
C:\Program Files\AdTools Service\AdTools.exe
C:\WINDOWS\System32\navwindows.exe
C:\WINDOWS\a64sddd.exe
C:\WINDOWS\System32\scvhost.exe
Now you can run HiJackThis. Check the boxes next to these items:
O4 - HKLM\..\Run: [Admanager Controller] C:\Program Files\Admanager Controller\AdManCtl.exe
O4 - HKLM\..\Run: [AdTools Service] C:\Program Files\AdTools Service\AdTools.exe
O4 - HKLM\..\Run: [NAV Auto Updates] navwindows.exe
O4 - HKLM\..\Run: [popuppers64] C:\WINDOWS\a64sddd.exe
O4 - HKLM\..\Run: [Regmgr] scvhost.exe
O4 - HKLM\..\Run: [Cr9W] C:\WINDOWS\icscuptq.exe
O4 - HKLM\..\RunServices: [Regmgr] scvhost.exe
O4 - HKLM\..\RunServices: [NAV Auto Updates] navwindows.exe
O4 - HKLM\..\RunServices: [Microsofts MediaScope] winmep.exe
O4 - HKCU\..\Run: [Regmgr] scvhost.exe
O4 - HKCU\..\Run: [NAV Auto Updates] navwindows.exe
O4 - HKCU\..\RunServices: [Regmgr] scvhost.exe
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
Now close all browser and explorer windows, and tell HijackThis to "Fix checked".
We need to make sure all hidden files are showing so please:
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.
Now boot the computer into safe mode:
*Restart the computer.
*As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
*Use the arrow keys to select the Safe mode menu item
*Press Enter.
Using Windows Explorer delete the following files if present:
C:\Program Files\Admanager Controller > folder
C:\Program Files\AdTools Service > folder
You will need to do a search for the next file and delete if found. To do this:
Search for winmep.exe
Click "Start > Search".
Click "All files and folders link on left".
Enter or cut and paste the file name into the "All or part of the file name:" box.
Click "Search" button.
If found please delete all instances of it.
We're almost done. We just have one more stubborn item to try and remove.
Please open Task Manager with Ctrl-Alt-Del and END TASK on the following file if it is running (it may not be and that's OK):
winmep.exe
Now you can run HiJackThis. Check the box next to this item:
O4 - HKLM\..\RunServices: [Microsofts MediaScope] winmep.exe
Now close all browser and explorer windows, and tell HijackThis to "Fix checked".
We need to make sure all hidden files are showing so please:
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.
Now boot the computer into safe mode:
*Restart the computer.
*As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
*Use the arrow keys to select the Safe mode menu item
*Press Enter.
You will need to do a search for the next file and delete if found. To do this:
Search for winmep.exe
Click "Start > Search".
Click "All files and folders link on left".
Enter or cut and paste the file name into the "All or part of the file name:" box.
Click "Search" button.
If found please delete all instances of it.
Hello Dave,
Here is the HJT log. The only problem we still have is a message "Generic Host Process for Win32 Services has encountered a problem and needs to close" that pops up occasionally, but it might be completely unrelated.
Also, if everything is fixed, could you tell me where I can look to find out how to avoid this in the future?
Thank you again so much.
Best,
Eli
Logfile of HijackThis v1.99.0
Scan saved at 9:54:47 PM, on 12/02/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Documents and Settings\Eli and Kieva\My Documents\HJT\HijackThis.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SCA - Unknown - C:\WINDOWS\System32\SYSTEM.EXE
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Those 4 items you listed that Spybot found are obviously Adware/Spyware. Did Spybot successfully fix them? It looks like from your log it did.
We do have one more item to fix in your HJT log though.
Run HJT and put a check next to this item:
O23 - Service: SCA - Unknown - C:\WINDOWS\System32\SYSTEM.EXE (file missing)
Now close all browser and explorer windows, and tell HijackThis to "Fix checked".
Make sure you can still see hidden files as I described in an earlier post.
Now boot the computer into safe mode:
*Restart the computer.
*As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
*Use the arrow keys to select the Safe mode menu item
*Press Enter.
The following item in your HJT log may have been set by you or your system administrator using a tool such as Spybot S&D or SpywareBlaster. You can have HijackThis fix this if you did not set it. Leave it if you did.
06 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
Now for the 3 items that Spybot is finding:
Symantec has a removal tool for n-Case: there will be another link for the tool on this page – follow all the instructions:
For the other 2 items I would like you to run Ad-Aware and Spybot again. Make sure that you update both of them before running and reboot after each one. Here is a link to a tutorial on setting up, updating, and running Ad-Aware and Spybot. Please read through before running them. If Spybot is not able to fix them please check the Spybot log to find where they are located and post back with that.
Let's try this. Please download and run CWShredder. Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX. Then REBOOT.
Then run Spybot again, once again making sure it has all the current updates installed.
Hi Eli,
Just a follow up. If Spybot still finds those 2 objects please check the Spybot log for the exact path and location of the files and post that back here.
Thanks,
Dave