This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please Help

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Greetings! I clearly have some very nasty spyware that's come in recently, as my computer is getting slower and slower, not just when online, but every command in Windows. My NAV (2003, updated, scanned daily) shows no virus. Spybot (latest downloads) was not detecting anything until this evening - when it started to abort in mid-scan. I tried it just now, and it won't even open from the desktop. It gives an error message:EreadError in Modul SPYBOTSD.EXE bei 00021E87. I can only give you 22nd Feb 05 as the most recent AdAware scan, as AdAware now cannot complete the Custom Scan you recommend, or even the shorter Smart Scan - it keeps on sticking at C:\WUTemp or the AAWTMP folder and will not move any further. (I had that problem before, and the AdAware team suggested unchecking the AAWTMP file from NAV manually to avoid a conflict - it worked at the time, but now it's sticking again.) What's puzzling is that by the time the scan has stuck at WUTemp, it's already checked 65000 folders, but it shows no red 'adware found' warnings during the scan. So I wonder if it's working properly. (No logs of the incomplete scans are possible, as you know.) As I expect the 02/22 log will tell you, I have SE Plus 1.05, and the latest downloads. I also have ZoneAlarm. In case it's useful: an hour or two ago I downloaded a 'free scan' from your website from NoAdware, which showed that I have 2 critical objects: VBS Buttershot, in C:\WINDOWS\Winstart.bat and Gator-EWallet in C:\WINDOWS\Downloaded Program Folder. When I tried several times to register at the NoAdware site in order to start the malware removal, the site promised to go to 'Step 2' but then disappeared after I'd typed in my name, country and postcode in Step 1. Sorry for the long message: Here's my most recent (complete and logged) AdAware scan - which may not show the most rceent problems, naturally. I'd be grateful for your speedy advice, as I fear my system will get so slow it'll crash soon. Many thanks and best wishes JayTee Ad-Aware SE Build 1.05 Logfile Created on:22 February 2005 11:51:54 Using definitions file:SE1R28 16.02.2005 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking Cookie(TAC index:3):1 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Ad-Aware SE Settings =========================== Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Ignore spanned files when scanning cab archives Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Block pop-ups aggressively Set : Automatically select problematic objects in results lists Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Show splash screen Set : Backup current definitions file before updating Set : Play sound at scan completion if scan locates critical objects 22-02-2005 11:51:54 - Scan started. (Custom mode) Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [KERNEL32.DLL] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4279235065 Threads : 5 Priority : High FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : Win32 Kernel core component InternalName : KERNEL32 LegalCopyright : Copyright © Microsoft Corp. 1991-2000 OriginalFilename : KERNEL32.DLL #:2 [MSGSRV32.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294915985 Threads : 1 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : Windows 32-bit VxD Message Server InternalName : MSGSRV32 LegalCopyright : Copyright © Microsoft Corp. 1992-1998 OriginalFilename : MSGSRV32.EXE #:3 [mmtask.tsk] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294875021 Threads : 1 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft Windows CompanyName : Microsoft Corporation FileDescription : Multimedia background task support module InternalName : mmtask.tsk LegalCopyright : Copyright © Microsoft Corp. 1991-2000 OriginalFilename : mmtask.tsk #:4 [MPREXE.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294876481 Threads : 2 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : WIN32 Network Interface Service Process InternalName : MPREXE LegalCopyright : Copyright © Microsoft Corp. 1993-2000 OriginalFilename : MPREXE.EXE #:5 [VSMON.EXE] FilePath : C:\WINDOWS\SYSTEM\ZONELABS\ ProcessID : 4294887725 Threads : 17 Priority : Normal FileVersion : 5.5.062.011 ProductVersion : 5.5.062.011 ProductName : TrueVector Service CompanyName : Zone Labs LLC FileDescription : TrueVector Service InternalName : vsmon LegalCopyright : Copyright © 1998-2005, Zone Labs LLC OriginalFilename : vsmon.exe #:6 [EXPLORER.EXE] FilePath : C:\WINDOWS\ ProcessID : 4294889221 Threads : 8 Priority : Normal FileVersion : 5.50.4134.100 ProductVersion : 5.50.4134.100 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : Copyright © Microsoft Corp. 1981-2000 OriginalFilename : EXPLORER.EXE #:7 [CCEVTMGR.EXE] FilePath : C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\ ProcessID : 4294844717 Threads : 18 Priority : Normal FileVersion : 1.03.4 ProductVersion : 1.03.4 ProductName : Event Manager CompanyName : Symantec Corporation FileDescription : Event Manager Service InternalName : ccEvtMgr LegalCopyright : Copyright © 2000-2002 Symantec Corporation. All rights reserved. OriginalFilename : ccEvtMgr.exe #:8 [MSTASK.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294919909 Threads : 2 Priority : Normal FileVersion : 4.71.2721.1 ProductVersion : 4.71.2721.1 ProductName : Microsoft® Windows® Task Scheduler CompanyName : Microsoft Corporation FileDescription : Task Scheduler Engine InternalName : TaskScheduler LegalCopyright : Copyright © Microsoft Corp. 2000 OriginalFilename : mstask.exe #:9 [STMGR.EXE] FilePath : C:\WINDOWS\SYSTEM\RESTORE\ ProcessID : 4294749013 Threads : 4 Priority : Normal FileVersion : 4.90.0.2533 ProductVersion : 4.90.0.2533 ProductName : Microsoft ® PCHealth CompanyName : Microsoft Corporation FileDescription : Microsoft ® PC State Manager InternalName : StateMgr.exe LegalCopyright : Copyright © Microsoft Corp. 1981-2000 OriginalFilename : StateMgr.exe #:10 [SYSTRAY.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294767553 Threads : 2 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : System Tray Applet InternalName : SYSTRAY LegalCopyright : Copyright © Microsoft Corp. 1993-2000 OriginalFilename : SYSTRAY.EXE #:11 [TASKMON.EXE] FilePath : C:\WINDOWS\ ProcessID : 4294641037 Threads : 1 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : Task Monitor InternalName : TaskMon LegalCopyright : Copyright © Microsoft Corp. 1998 OriginalFilename : TASKMON.EXE #:12 [IMGICON.EXE] FilePath : C:\PROGRAM FILES\IOMEGA\DRIVEICONS\ ProcessID : 4294642757 Threads : 1 Priority : Normal #:13 [WMIEXE.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294651397 Threads : 3 Priority : Normal FileVersion : 4.90.2452.1 ProductVersion : 4.90.2452.1 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : WMI service exe housing InternalName : wmiexe LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : wmiexe.exe #:14 [CCAPP.EXE] FilePath : C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\ ProcessID : 4294661977 Threads : 17 Priority : Normal FileVersion : 1.0.10.006 ProductVersion : 1.0.10.006 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client CC App InternalName : ccApp LegalCopyright : Copyright © 2000-2002 Symantec Corporation. All rights reserved. OriginalFilename : ccApp.exe #:15 [ZLCLIENT.EXE] FilePath : C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ ProcessID : 4294621045 Threads : 7 Priority : Normal FileVersion : 5.5.062.011 ProductVersion : 5.5.062.011 ProductName : Zone Labs Client CompanyName : Zone Labs LLC FileDescription : Zone Labs Client InternalName : zlclient LegalCopyright : Copyright © 1998-2005, Zone Labs LLC OriginalFilename : zlclient.exe #:16 [AD-AWARE.EXE] FilePath : C:\PROGRAM FILES\LAVASOFT\AD-AWARE SE PLUS\ ProcessID : 4294534833 Threads : 3 Priority : Normal FileVersion : 6.2.0.207 ProductVersion : VI.Second Edition ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt Category : Data Miner Comment : Hits:3 Value : Cookie:[removed]/ Expires : 30-12-2037 16:00:00 LastSync : Hits:3 UseCount : 0 Hits : 3 Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 1 Objects found so far: 1 Deep scanning and examining files (C:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 1 Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 0 entries scanned. New critical objects:0 Objects found so far: 1 Performing conditional scans… »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 1 11:57:44 Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:05:50.200 Objects scanned:65779 Objects identified:1 Objects ignored:0 New critical objects:1
Download hijackthis from here >>>> http://www.majorgeeks.com/download3155.html
Save it to its own floder.
Close all browser windows
Open hijackthis click on scan
Save the log it produces and post it here by clicking on "add reply" at the bottom right please.
Hi Syggix
Many thanks for your quick reply - here's my hijackthis log file of today. Computer is getting slower and slower, and strange things happening e.g. I couldn't connect to your website for several hours, or even to my (Virgin) homepage. Kept getting diverted to 'Connecting to site [removed]'.
AdAware is now completing checks but not finding anything wrong, which suggests something is concealing itself from AdAware. I've now downloaded the 3 IE 6 critical updates (dated 14 Jan) from the MS Windows Updates site, but I can not as yet see a tangible improvement in performance. Still, I managed to crawl here to your website, so here's the logfile: hope you can see what's wrong! It feels as if it's going to go critical any moment.
Best wishes
JayTee

Logfile of HijackThis v1.99.1
Scan saved at 19:38:30, on 25/02/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\IOMEGA\DRIVEICONS\IMGICON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\LAVASOFT\AD-AWARE SE PLUS\AD-WATCH.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\TEMP\TD_0001.DIR\HIJACKTHIS.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\WINWORD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virgin.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} (RdxIE Class) - http://207.188.7.105/199749ebf0f015b41800/netzip/RdxIE.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200110…meInstaller.exe
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/region/reg_…/ActiveData.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…dc/SymAData.dll
Hmmmm not a heck of a lot in that log. OK let's try this.

Please download and run CWShredder.
http://www.softpedia.com/get/Internet/Popu…WShredder.shtml

REBOOT to safe Mode (tap f8 while bios loads)

Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX.

Scan with both AdAware SE and Spybot in safe mode also.

Reboot.

Please do an online scan,

Trend Micro http://housecall.trendmicro.com/housecall/start_corp.asp

Make sure that you choose "fix" or "clean".

Reboot and post a new HiJackThis log.
Dear Siggyx,

Reporting back after following your instructions.


I ran CWShredder - according to the results I do NOT have any of the Cool Search virus variants.

Scanned with AdAware and Spybot in safe mode - both completed 100% without finding any malware. Puzzling.


Yet surfing the internet is still very slow, and opening Word while on the internet now takes a very long time - a minute or two, with a long 'virus scan ' check on Word. Switching between 2 or 3 different internet pages and open programs is also very slow, 30 secs - 1 minute. (Connectivity and bps dial-up speed is apparently normal, so it's not that.) I can hear the drive working away in the way it does when Norton Anti Virus is doing updates - but when I check, there aren't any NAV updates, so it's not apparently that - NAV and ZoneAlarm are both up to date.

Went to the Housecall Trend Micro address you gave. It would not do the free spyware scan from the main page; a Microsoft message box came up: something like 'English language or Traditional Chinese language only' - and then no further action. Went to my local (UK) address page, and it offered a 'virus scan'. But I could not complete the scan as the program gives an 'incompatibility' reading against the Java Vendor (Microsoft) and the Java Version (1.1). Should I 'automatically install a proper JavaVM' as the prompt asks? Might this be the reason for the problems? (Is Microsoft v1.1. not a 'proper' java version, then?)

Or is there some spyware still concealed somewhere? Not CoolSearch, apparently.


Sorry this one is proving so elusive. I'm happy to do any other tests you suggest.
And here's my HJT log file.

Best wishes
JayTee

Logfile of HijackThis v1.99.1
Scan saved at 15:35:32, on 02/03/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\IOMEGA\DRIVEICONS\IMGICON.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\TEMP\TD_0004.DIR\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virgin.net/
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE"
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} (RdxIE Class) - http://207.188.7.105/199749ebf0f015b41800/netzip/RdxIE.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200110…meInstaller.exe
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/region/reg_…/ActiveData.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…dc/SymAData.dll
Please download and run the MicroWorld scanner from the link below. Make sure that you choose all files and directories. I warn you it will take a long time to run and will not fix anything only identify files. When it is f9inished hilight all the files in the lower box ctrl + c then copy and paste them here.

MicroWorld >>> http://www.soft32.com/download_5985.html
Dear Siggyx, Just a quick PS to my last post, as I would not want you to waste your timeand expertise in case my HFT file shows no evidence of spyware. A couple of days ago, going down as many paths of enquiry as I could for this 'slow activity' problem I've been having, I came across and downloaded three critical updates to IE 6 from Microsoft Windows (for my Windows ME). Today suddenly my Internet Explorer icon stopped connecting me to the internet ("This program is incompatible with this version of Windows" - "You are attempting to install an earlier version of Internet Explorer than was installed with Windows. Installing an earlier version of Internet Explorer replaces the up-to-date files with obsolete files and causes the operating system to malfunction.") Well, I knew I'd had that IE icon on my desktop for ages, clicking on it daily to connect or open a new homepage, so I wondered if my IE6 had fouled up, perhaps, I thought, due to malware. I was thinking that a malfunction of IE6 might explain the slowness in opening and closing windows, difficulty in switching from one page to another, or to Word while on the internet, taskbar keys jamming, etc etc. So I decided I'd re-install IE6. I checked for an update to IE 6 - there wasn't one for Windows ME on the MSN updates page, critical or other. But I found my way to an IE 6 page, and lo and behold, there IS a new 'Service pack 1' for most versions of Windows (including Windows ME) dated 9th February 2005, in the wake of MSN's much-trumpeted 'Service Pack 2' updates to XP. So I installed it. That may well be it. Even without re-booting, the internet is faster, and I'm not getting all the weird 'drive hyperactivity and nothing happening' problems. I'm still a bit apprehensive about the spyware that NoAdware claimed it had found on my system. But I realise some anti-spyware 'free scan' programs actually put spyware on your system (v.naughty!) and of course you can't possibly avoid or control the sponsoring ads and download hyperlinks that appear on your site. But do you think I might have these invisible bugs, "VBS Buttershot, in C:\WINDOWS\Winstart.bat" and "Gator-EWallet in C:\WINDOWS\Downloaded Program Folder" as NoAdware claimed? (see my initial post) And if you have time, I'd be interested to know if you recommend I download a new ('proper') java program from Sun, or if the existing Microsoft v1.1 is OK. I tried to make a subscription, but we don't seem to have this Paypal thingy in the UK, and a money order to the US - I've done it in the past - would cost more than the subscription. But I'd be happy to do something for you in return, or send or research something from here, if there is anything you need from the UK. If you can think of something, I'll be happy to oblige. Best wishes JayTee
Yes get the sun Java update as the older one has a security hole it it. If you want you can run that scanner I sent you and I will take a look for you. Some spyware programs are prone to false/positives.
Hi Siggyx, 1) I downloaded the updated Sun java version (1.4.2) from the trendmicro hyperlink 2) I then did the trendmicro Housescan - it completed, finding no viruses. (I think the UK trendmicro site just allows a virus scan, not a spyware scan.) 3) HOWEVER - I then did the MicroWorld scan as you told me to: what an impressive scanning tool that is. It showed up with stuff that all the other anti-virus progs couldn't find. Here's the virus log, that displays quite a few viruses on my system, including I note a couple on NAV itself (I typed out the scan checklist at the start) Just a couple of 'can't scan this' folders I noticed as I went through - among them C:\_RESTORE\TEMP\A0312808.CPY and C:\_RESTORE\TEMP\A0354975.CPY and a 'Pest Patrol set up' - a program I thought I'd uninstalled ages ago. Your recommendations for zapping the following bugs are eagerly awaited! Many thanks for your patient help Best wishes JayTee Total files scanned: 37319 Total viruses found: 15 Disinfected: 0 Activate 0 Renamed 0 Total Errors: 58 Time elapsed: 1h 55’ 18” File C:\WINDOWS\mruninst.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\WINDOWS\installer[vnn-10018,de].exe infected by "not-a-virus:PornWare.Dialer.Intexdial" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\nrqccdq.dll infected by "Email-Worm.Win32.Tanatos.b.dam2" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\cpqiix.dll infected by "Email-Worm.Win32.Tanatos.b.dam2" Virus. Action Taken: No Action Taken. File C:\WINDOWS\OPTIONS\CABS\OLS\AOL\AOL40HK.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\WINDOWS\OPTIONS\CABS\OLS\AT&T\ATTKIT.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\WINDOWS\SYSTEM\nrqccdq.dll infected by "Email-Worm.Win32.Tanatos.b.dam2" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\cpqiix.dll infected by "Email-Worm.Win32.Tanatos.b.dam2" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Desktop\ioware-w32-x86-306.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\WINDOWS\Downloaded Program Files\ParisVoyeur.exe tagged as not-a-virus:RiskWare.Dialer.gen. No Action Taken. File C:\WINDOWS\mruninst.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\WINDOWS\installer[vnn-10018,de].exe infected by "not-a-virus:PornWare.Dialer.Intexdial" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\41BC2455.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\58E67AD7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: No Action Taken. File C:\FinWinNotePad.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
…just to add that I had notification today that I'd sent a virus via e-mail to an (unknown) recipient in Italy. Name of virus: Worm.SomeFool.P virus but I can't find this virus on the NAV or trendmicro site registers. Best wishes JayTee
Boot to safe mode (tap f8 while bios loads) then look for and delete these files C:\WINDOWS\mruninst.exe C:\WINDOWS\installer[vnn-10018,de].exe C:\WINDOWS\SYSTEM\nrqccdq.dll C:\WINDOWS\SYSTEM\cpqiix.dll C:\WINDOWS\Desktop\ioware-w32-x86-306.exe C:\WINDOWS\Downloaded Program Files\ParisVoyeur.exe Then rescan with the Microworld scanner please and post its log. The dll files above are the email worms.
Hi there Siggyx, I did as you recommended and deleted all the files you named via My Computer, except for one (C:\WINDOWS\Downloaded Program Files\ParisVoyeur.exe) which I couldn't find even with 'show hidden files and folders'. (The Downloaded Program Files show as completely empty. The good news is that the new MicroWorld scan shows as follows, with no viruses or other info in the virus scan log:- Fri Mar 04 16:48:55 2005 => ***** Scanning complete. ***** Fri Mar 04 16:48:55 2005 => Total Files Scanned: 2639 Fri Mar 04 16:48:55 2005 => Total Virus(es) Found: 0 Fri Mar 04 16:48:55 2005 => Total Disinfected Files: 0 Fri Mar 04 16:48:55 2005 => Total Files Renamed: 0 Fri Mar 04 16:48:55 2005 => Total Deleted Files: 0 Fri Mar 04 16:48:55 2005 => Total Errors: 0 Fri Mar 04 16:48:55 2005 => Time Elapsed: 00:04:10 Fri Mar 04 16:48:55 2005 => Virus Database Date: 2005/03/04 Fri Mar 04 16:48:55 2005 => Virus Database Count: 120198 Fri Mar 04 16:48:55 2005 => Scan Completed. ——————– Does that mean everything's OK? Or should I search further (but how) for the infected file I couldn't find? That MicroWorld scanner tool is really impressive. I may well buy it. Do you have any other recommendations for avoiding future viruses? (I have ZoneAlarm as well as NAV.) Many thanks again for all your help so far. JayTee
Here you are!


Logfile of HijackThis v1.99.1
Scan saved at 10:50:19, on 05/03/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\IOMEGA\DRIVEICONS\IMGICON.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\TEMP\TD_0008.DIR\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virgin.net/
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE"
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} (RdxIE Class) - http://207.188.7.105/199749ebf0f015b41800/netzip/RdxIE.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200110…meInstaller.exe
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/region/reg_…/ActiveData.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…dc/SymAData.dll

Best wishes

JayTee

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI