This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Best Web Search

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer seems to be hijacked with something called "best-web-search". I have tried to search the forums for clues, but nothing that I have found helped me. I used Spybot, Adaware and CWShredder without result. Can anyone help me please. My HiJack log is as follows.

Logfile of HijackThis v1.99.1
Scan saved at 22:30:43, on 2005-03-16
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\System32\sndsys.exe
C:\Program\Logitech\iTouch\iTouch.exe
C:\Program\PHILIP~1\VProperty.exe
C:\Program\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\yonqdx.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program\MSN Messenger\MsnMsgr.Exe
C:\Program\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\j?vaw.exe
C:\Antispyware\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5F128734-4FD0-1A7D-81DD-1234E353B7E2} - C:\WINDOWS\System32\frdzt.dll
O2 - BHO: (no name) - {A708A39C-8DA7-4e36-B3B0-0A1FFAFD4B6D} - C:\WINDOWS\system32\javafix3.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [Netunit32] wunit32.exe
O4 - HKLM\..\Run: [Windows Sound System] sndsys.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ToUcamVProperty] C:\Program\PHILIP~1\VProperty.exe
O4 - HKLM\..\Run: [mshelp32] C:\WINDOWS\System32\mshelp32.exe
O4 - HKLM\..\Run: [UGASpK] C:\WINDOWS\yonqdx.exe
O4 - HKLM\..\Run: [Oztxuaot] c:\Program Files\Mrii\Ggtbex.exe
O4 - HKLM\..\Run: [avast!] C:\Program\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [¢‰¸u0–4C
}ïÁzî[8C:\Program\ISTsvc\istsvc.exe] C:\WINDOWS\yonqdx.exe
O4 - HKLM\..\RunServices: [Netunit32] wunit32.exe
O4 - HKLM\..\RunServices: [Windows Sound System] sndsys.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [msjava critical update] c:\windows\jjfixer.exe
O4 - HKCU\..\Run: [Woto] C:\Documents and Settings\olle\Application Data\ersa.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\aklsp.dll' missing
O12 - Plugin for .mov: C:\Program\Internet Explorer\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://GLOBAL.ACER.COM/
O15 - Trusted IP range: 67.19.185.246
O16 - DPF: {10000000-1000-0000-1000-000000000000} - mhtml:file://C:\ARCHIVE.MHT!http://67.15.120.3/server.exe
O16 - DPF: {5345455D-45D0-540A-7343-88754562B4D2} (CCAxDialerDlg Class) - http://www.advnt01.com/dialer/98_compr/win98_P.cab
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} - http://67.19.185.246/i/8/loader2.ocx
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program\Delade filer\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program\Delade filer\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe
Hej igen Rekord

Your computer has some nasty stuff on it.

RED or UNDERLINED words are links that can be clicked.

HOW TO Instructions: This is where you find instructions or references for a number of common tasks. If you do not know how to do something then try to find it in this part.

Should you need instructions for:
Showing hidden files and folders in Windows.
Reboot in safe mode. If you have a keyboard with a "F Lock" key click it so that the "F" light above it is on when you start tapping the "F8" key.
How to print the fix instructions
Click the red links above.

How to unzip a downloaded zip file.
Place the zip file in the folder where you want the unzipped program to be.
If you are running Windows XP you simply right click the zip file and select "Extract Files".
For the other versions of Windows you will need a program like 7-Zip . If you decide to use 7-Zip down load the newest version that is not a beta version.
Open 7-Zip. Navigate to to the downloaded zipfile and highlight it. Right click and select "Extract Here"

When asked to post a new HijackThis log please
Close all windows and browsers.
Find the HijackThis folder. Open it and double click "HijackThis.exe". Click "Do a system scan" and save a "logfile". (If Hijack this shows you a "Scan" button instead of "Do a system scan" that is OK. Just click it.)
When the scan is finished, the "Scan" button will change into a "Save Log" button. Click it. Click "Ctrl-A" (the "Ctrl" key and the "A" key at the same time) to highlight the whole log. Now click "Ctrl-C" to copy the text. Open this topic and click the "Add Reply" button at the bottom of the page. Paste the log into the window that opens up by clicking "Ctrl-V". Click "Add Reply" to post.

DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL INSTRUCTED TO DO SO. SOME OF THE FILES ARE LEGIT AND VITAL TO YOUR COMPUTER'S HEALTH


Preliminaries:

1. Please copy the instructions to a notepad or preferably print them.

2. Make sure to work through the fixes exactly as given and in the exact order they are mentioned below.

3. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

4. Configure Windows to show all files.

Start the cleanup:

5. Download FixISTbar from http://securityresponse.symantec.com/avcenter/FxIstbar.exe .
Run it.

6. Download the latest version of Ad-Aware SE (Ad-Aware SE Build 1.05).
If you have a previous version of Ad-Aware installed, during the installation of the new version you will be prompted to uninstall or keep the older version - be sure to uninstall the previous version.
After installing Ad-aware, you will be prompted to update the program and run a full scan. De-select all boxes so that it does not run.
Manually run "Ad-Aware SE Personal" and from the main screen Click on "Check for Updates Now".
Once the definitions have been updated:

Reconfigure Ad-Aware for Full Scan as per the following instructions:
-Launch the program, and click on the Gear at the top of the start screen.

-Under General Settings the following boxes should all be checked off: (Checked will be indicated by a green circle with a check mark in it, Un-Checked is a red circle with an X in it. If it is greyed out, those features are only available in the retail version.)
- Automatically save logfile"
- Automatically quarantine objects prior to removal"
- Safe Mode (always request confirmation)
- Prompt to update outdated confirmation) - Change to 7 days.
- Click the "Scanning" button (On the left side).

- Under Drives & Folders, select "Scan within Archives"
- Click "Click here to select Drives + folders" and select your installed hard drives.

- Under Memory & Registry, select all options.
- Click the "Advanced" button (On the left hand side).

- Under "Shell Integration", select "Move deleted files to Recycle Bin".

- Under "Log-file detail", select all options.
- Click on the "Defaults" button on the left.
- Type in the full url of what you want as your default homepage and searchpage e.g. http://www.google.com.
- Click the "Tweak" button (Again, on the left hand side).
- Expand "Scanning Engine" by clicking on the "+" (Plus) symbol) and select the following:
- "Unload recognized processes during scanning."
- "Obtain command line of scanned processes"
- "Scan registry for all users instead of current user only"

- Under "Cleaning Engine", select the following:
-"Automatically try to unregister objects prior to deletion."
-"During removal, unload explorer and IE if necessary"
-"Let Windows remove files in use at next reboot."
- "Delete quarrantined objects after restoring"
- Click on "Safety Settings" and select "Write-protect system files after repair (Hosts file, etc)"
- Click on "Proceed" to save these Preferences.
- Click on the "Scan Now" button on the left.
- Under "Select Scan Mode, be sure to select "Use Custom Scanning Options".

- Close all programs except ad-aware.
- Click on "Next" in the bottom right corner to start the scan.
- Run the Ad-Aware scan and allow it to remove everything it finds and then REBOOT - Even if not prompted to.
- After you log back in, Ad-Aware may run to finalize the scan and remove any locked files that it may of found. Allow it to finish.

Plug-Ins for Ad-Aware (VX2 Cleaner)
Download the free VX2 Cleaner here

Close Ad-Aware SE build 1.05 and Ad-Watch (if running)
Install the VX2 Cleaner
Start Ad-Aware SE build 1.05
Go to “Plug-ins”
Select the VX2 Cleaner plug-in and click “Run Plugin”
If your computer isn’t infected, click “Close”.

If your computer is infected:

Select “Clean System”
Reboot your computer
Scan your computer with Ad-Aware
Remove any VX2 objects detected
Reboot your computer again
Run a second scan to make sure the files have been removed from your computer

Virus warnings while performing a scan with Ad-Aware

While performing a scan with Ad-Aware, a background antivirus monitor may issue an alert, stating that a virus has been found in the temporary directory (%temp%) for the current user. This does not necessarily mean your computer has been infected with an active virus. Most antivirus resident scanners will not scan compressed files and only monitor your memory for the sign of an active viral process.
During a scan, Ad-Aware will temporarily decompress files to scan their contents without activating the content, but in doing so, the file is noticed by the antivirus' resident scanner.

Also, some antivirus applications include an option to quarantine infected files, and when Ad-Aware decompresses these quarantined files, the antivirus background scanner detects the virus moving outside the quarantine area. To avoid this you can either remove the quarantined files via your antivirus application, or have Ad-Aware ignore the antivirus program's quarantine folders/files during a scan.
Then,

7. Download SPYBOT Search and Destroy here if it is not already installed on your computer.

Install the program and then start it. Once the program has started make sure you are in the Spybot-S&D section. Click on the "Search for Updates" button. Download all updates. In some cases the program will restart after an update. When updated, click on the "Check for Problems" button. When the Check is over All problems displayed in red are regarded as real threats and should be dealt with. Make sure they are all selected and click the "Fix selected problems" button.

8. Please use the following links to run the two online Virus Scanners and let them fix whatever they find.

Panda
http://www.pandasoftware.com/activescan/co…n_principal.htm

Trend Micro
http://housecall.trendmicro.com/housecall/start_corp.asp

And here are links to two online Trojan Scanners. Run one and let it fix what it finds.

http://scan.sygatetech.com/pretrojanscan.html

Or here:
http://www.windowsecurity.com/trojanscan/

9.Post a new HJT log and let's see what we have.

Lycka till. Som du ser kan jag svenska.

Per
Thank you for helping me, here is the mew log, it seems that the computer works fine now, and many bad things are removed.

Logfile of HijackThis v1.99.1
Scan saved at 08:59:10, on 2005-03-24
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\System32\sndsys.exe
C:\Program\Logitech\iTouch\iTouch.exe
C:\Program\PHILIP~1\VProperty.exe
C:\Program\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program\MSN Messenger\MsnMsgr.Exe
C:\Program\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\cmd.exe
C:\Antispyware\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {A708A39C-8DA7-4e36-B3B0-0A1FFAFD4B6D} - C:\WINDOWS\system32\javafix3.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [Netunit32] wunit32.exe
O4 - HKLM\..\Run: [Windows Sound System] sndsys.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ToUcamVProperty] C:\Program\PHILIP~1\VProperty.exe
O4 - HKLM\..\Run: [Oztxuaot] c:\Program Files\Mrii\Ggtbex.exe
O4 - HKLM\..\Run: [avast!] C:\Program\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunServices: [Netunit32] wunit32.exe
O4 - HKLM\..\RunServices: [Windows Sound System] sndsys.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [msjava critical update] c:\windows\jjfixer.exe
O4 - HKCU\..\Run: [Woto] C:\Documents and Settings\olle\Application Data\ersa.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE
O12 - Plugin for .mov: C:\Program\Internet Explorer\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://GLOBAL.ACER.COM/
O15 - Trusted IP range: 67.19.185.246
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program\Delade filer\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program\Delade filer\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe

Sitter du också i Sverige?
Hej Rekord

Nej, jag är en utlandssvensk. Bor i New York men är upvuxen på Östermalm i Stockholm. :wavey:

Du har fortfarande en massa skräp i din dator. :( Låt oss ta itu med smörjan.

The following items are malware and must be fixed

1. Please set your system to show all files; See here if you're unsure how to do this. http://www.xtra.co.nz/help/0,,4155-1916458,00.html#5

2. Press Control-Alt-Del to enter the Task Manager.
Click on the Processes tab and end the following processes:
C:\WINDOWS\System32\sndsys.exe
C:\Program\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

Exit the Task Manager when finished.

3. Close all programs leaving only HijackThis running. Place a check against each of the following, making sure you get them all and not any others by mistake:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {A708A39C-8DA7-4e36-B3B0-0A1FFAFD4B6D} - C:\WINDOWS\system32\javafix3.dll
O4 - HKLM\..\Run: [Netunit32] wunit32.exe
O4 - HKLM\..\Run: [Windows Sound System] sndsys.exe
O4 - HKLM\..\RunServices: [Netunit32] wunit32.exe
O4 - HKCU\..\Run: [msjava critical update] c:\windows\jjfixer.exe
O15 - Trusted IP range: 67.19.185.246


Do you know what these items are? If not please check mark it.
O4 - HKCU\..\Run: [Woto] C:\Documents and Settings\olle\Application Data\ersa.exe
O4 - HKLM\..\Run: [Oztxuaot] c:\Program Files\Mrii\Ggtbex.exe


Optional but recomended fixes:
This program comes with Logitech software. It is known to being able to collect and send data about your computer. It also permits Outsiders to change settings on your machine. To stop it from running please check mark the following:
O4 - HKCU\..\Run: [LDM] C:\Program\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe


Click on Fix Checked when finished and exit HijackThis.

4. Reboot into Safe Mode: please see here if you are not sure how to do this.

5. Using Windows Explorer, locate the following files, and delete them:


C:\WINDOWS\system32\javafix3.dll
C:\WINDOWS\system32\sndsys.exe
c:\windows\jjfixer.exe
C:\Documents and Settings\olle\Application Data\ersa.exe <—Only if you check marked the O4 line that I questioned above.

Also delete the following folders:
c:\Program Files\Mrii <—–Only if you check marked the O4 line that I questioned above.

6. Exit Explorer.

7. "Run "Start">"Search">"All Files and Folders"> enter wunit32.exe in "All or part of file name". Select "More advanced options". Check-mark "Search System Folders", "Search hidden files and folders", and "Search subfolders". Click "Search". Write down the location of the file.
Highlight the file. Right click it. Select "Delete".

8. Reboot in normal mode.

9. Post back a fresh HijackThis log and we will take another look. :)
Thank you for helping me, I´m learning quite a lot myself by doing this :)

I´ve done what you told me, but I didn´t fint two of the listed files, but I found somthing else in the folder C:\WINDOWS\Prefetch;
JJFIXER.EXE-3495E218.pf and
WUNIT32.EXE-0FFAF489.pf

There was more of the "deleted files" there with "same" additions, some text and ending with .pf
Is this a place where malware hides?

Everything else worked fine and here is the new HiJack log

Logfile of HijackThis v1.99.1
Scan saved at 12:21:49, on 2005-03-25
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program\Logitech\iTouch\iTouch.exe
C:\Program\PHILIP~1\VProperty.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program\MSN Messenger\MsnMsgr.Exe
C:\Program\Logitech\MouseWare\system\em_exec.exe
C:\Antispyware\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ToUcamVProperty] C:\Program\PHILIP~1\VProperty.exe
O4 - HKLM\..\Run: [avast!] C:\Program\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunServices: [Windows Sound System] sndsys.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE
O12 - Plugin for .mov: C:\Program\Internet Explorer\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://GLOBAL.ACER.COM/
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program\Delade filer\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program\Delade filer\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe

Thanks again!!
Hej igen Rekord

Det går framåt. :) Det mesta av skräpet är borta. Har du några spesiella problem med din dator nu?


Please do a search:
"Run "Start">"Search">"All Files and Folders"> enter sndsys.exe in "All or part of file name". Select "More advanced options". Check-mark "Search System Folders", "Search hidden files and folders", and "Search subfolders". Click "Search". Write down the complete path to the location of the file. Please also add it to your next post.

You have one or more files that I need to know more about. Please go to
http://virusscan.jotti.org/. Once it is open please click browse and find sndsys.exe. This is the file you just found the path for. Highlight it and click submit. You should get a log with answers. Copy it and include it in your next post.

I will not be avaiable from now until late Saturday night but will answer you as soon as possible thereafter.

Glad påsk :wavey:

Per
The only file i found was a file in C:\WINDOWS\Prefetch folder, and it had some strange aditions in the fi´lename. Can you tell me what that folder "Prrefetch" contains, it seems to be a lot of files there. The log is for the file that I found there. Service load: 0% 100% File: SNDSYS.EXE-034D01A9.pf Status: MIGHT BE INFECTED/MALWARE (Sandbox emulation took a long time and/or runtime packers were found, this is suspicious. Normally programs aren't packed and don't force the sandbox into lengthy emulation. Do realize no scanner issued any warning, the file can very well be harmless. Caution is advised, however.) Packers detected: - AntiVir No viruses found Avast No viruses found AVG Antivirus No viruses found BitDefender No viruses found ClamAV No viruses found Dr.Web No viruses found F-Prot Antivirus No viruses found Fortinet No viruses found Kaspersky Anti-Virus No viruses found mks_vir No viruses found NOD32 No viruses found Norman Virus Control No viruses found My computer seems to be working just fine, no problems at all. Glad påsk, den firar ni väl ungefär som här hemma :wavey: Conny
Hej Conny

Vi är inne på sista varvet. Vi ska bara rensa upp lite skräp.

Do the following:

Open HijackThis and click "Do a System Scan Only" or "Scan". Put a check mark by the items that are listed below.
O4 - HKLM\..\RunServices: [Windows Sound System] sndsys.exe
Close all open windows except HijackThis and then click the "Fix checked" button.

Reboot

This is IMPORTANT: You need to update your Windows. It is out of date. The version you should have at this time is Windows XP with SP2.

If you have a high-speed internet connection, you can download SP2 from http://support.microsoft.com/kb/322389 .

However if you have a dialup connection I would advise you to order the CD as the download is huge and will take a VERY long time to download.
You can get the CD here .
Please inform me if you had any problems with the upgrade.

Run another HijackThis log and post it.

If nothing else comes up you should have a clean computer now but I want to make sure. :)
My computer seems to be working very good. Yes, I know that it shold have been updated, but the problem you helped me with is one resaon why it is not done. Now that it works I´ll update ASAP.

Here is the log

Logfile of HijackThis v1.99.1
Scan saved at 20:04:24, on 2005-03-27
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program\Logitech\iTouch\iTouch.exe
C:\Program\PHILIP~1\VProperty.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program\MSN Messenger\MsnMsgr.Exe
C:\Program\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program\Logitech\MouseWare\system\em_exec.exe
C:\Antispyware\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ToUcamVProperty] C:\Program\PHILIP~1\VProperty.exe
O4 - HKLM\..\Run: [avast!] C:\Program\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE
O12 - Plugin for .mov: C:\Program\Internet Explorer\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://GLOBAL.ACER.COM/
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program\Delade filer\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program\Delade filer\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe

Tack så mycket för hjälpen, hoppas att jag klarar mig ett tag nu :-)
Hej Rekord

Here is my recomendations to you to keep your computer clean.


Congratulations and well done , your log looks clean.

Now that your computer is free of malware, I want you to take some precautions to avoid being re-infected.
If something does not pertain to your version of Windows please just skip that instruction.

Settings and maintenance

1. Clean out temporary files etc.
Download and install CCleaner
Under windows tab check the boxes next to the blue "internet explorer", "windows explorer", and "system".There will be other check marked boxes under them. That is OK
Click Run Cleaner.
You should do this every few weeks to avoid buildup of unnecessary junk. Run it for each user account on the computer.

2. Clean Out System Restore.
Malware could get backed up in System Restore.
a. Go to "Start" > "Control Panel".
b. Make sure the Control Panel is in "Classic View". If it is not, click "Switch to Classic View" towards the top-left of the screen.
c. Double-click "System" and go to the "System Restore" tab.
d. Check "Turn off System Restore" and click "OK" and then "Yes".

After restarting your computer you should turn it back on by following the above procedure and uncheck "Turn off System Restore".

You can find out more about this subject at
How to turn off or turn on Windows XP System Restore

3. You reconfigured Windows to show hidden files and you should reset this to its original state using the instructions from here except that
1. Under the "Hidden files and folders" heading put a mark for "Do not show hidden files and folders".
2. Uncheck "Display content of system folders"
3. Check the "Hide protected operating system files (recommended)" option.

4. Make your Internet Explorer more secure

a. Less restrictive but less secure:
Adjust your browser settings: Change your(active x) settings in IE. With IE open go to tools, internet options, security tab. Click on the internet globe, then custom level. Set the first option "download signed active x controls" to prompt, the next two to disable. Read more in
Internet Explorer Privacy & Security Settings
Working with Internet Explorer 6 Security
Many exploits are directed at Internet Explorer, you don't have to use it. Try a different browser like
Firefox . It is also worth trying
Thunderbird for controlling spam in your e-mail.

b. More secure but very restrictive.
This can be done by following these simple instructions that apply to all "Windows" except "Windows XP with SP2". In SP2 many of those setting are the default settings but check your settings anyhow. The settings can become restrictive but you should use them anyhow. If there are sites that will not show up right with those settings and that you rely on to be free of malware place them in the trusted zone.

1. Click "Start". Open "Control Panel".
2. Select the "Internet Options"
3. Select "Security" Tab and select the following settings.

* ActiveX controls and plug-ins
• Download signed ActiveX controls: Disable
• Download unsigned ActiveX controls: Disable
• Initialize and script ActiveX controls not marked as safe: Disable
• Run ActiveX controls and plug-ins: Disable
• Script ActiveX controls marked safe for scripting: Disable

* Downloads
• Font Download: Disable

* Microsoft VM
• Java permissions: Disable Java

* Miscellaneous
• Allow META REFRESH: Disable
• Display mixed content: Disable
• Drag and drop or copy and paste files: Disable
• Installation of desktop items: Disable
• Launching programs and files in an IFRAME: Disable
• Navigate sub-frames across different domains: Disable
• Software channel permissions: High Safety
• Userdata persistence: Disable

* Scripting
• Active scripting: Disable
• Allow paste operations via script: Disable
• Scripting of Java applets: Disable

* User Authentication
• Logon: Prompt for username and password
4. When all these settings have been made, click on the OK button.
5. If it prompts you as to whether or not you want to save the settings, press the Yes button.
6. Next press the Apply button and then the OK to exit the Internet Properties page.


These are a MUST to protect yourself from malware.

5. Always use a good anti-virus..
KEEP IT UPDATED

6. Always use a good firewall.
Be restrictive with access to the internet. If you are unsure if the program really needs the access, test it by denying the access and see if this has any negative effects. If not make the block permanent.

Never run two Antivirus programs or two Firewalls at the same time. The can interfere with each other and cause problems.

Download and install “SpywareBlaster” and "SpywareGuard".

You will find the addresses for the programs that I recommend at this website . It is important that you go to there. It is good source of information about computer security. It will give you recommendations for more security tools as well as tips about how to stay clean on the internet. PLEASE FOLLOW THE RECOMENDATIONS TO PROTECT YOURSELF.

7. MOST IMPORTANT for all versions: You Need to keep “Windows” and "Internet Explorer” updated. Open ‘Internet Explorer” and go to”Start”> "Tools" > "Windows Update" or go to Microsoft Windows and Internet Explorer Updates to get the critical updates.

8.If you are running Microsoft Office, or any portion thereof you must keep it updated as well. Go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed. Update MS Office here.

9. Keep your programs updated.

10. I highly recommend downloading and installing the newest versions of “AdAware SE Personal” and “Spybot Search and Destroy”
After installing remember to update the definition files for each program.
I also suggest that you visit this website and follow the instructions on how to configure both programs for best detection. These instructions are the best even though they refer to a cleanup of an infected computer.

11. It is worth while to take a look at "So how did I get infected in the first place? for some good advice.


VERY IMPORTANT. Update all protective programs regularly - Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow these recommendations and your potential for being infected again will be dramatically reduced.

Do you have any problems with your computer? If so please post the details.

It has been a pleasure helping you.

Best of luck and clean computing

Elrond
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI