This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help - No Luck With Adaware/spybot/norton/xoftspy

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Following in my HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 4:42:53 PM, on 3/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
F:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
F:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
F:\WINDOWS\system32\brsvc01a.exe
F:\WINDOWS\system32\LEXBCES.EXE
F:\WINDOWS\system32\brss01a.exe
F:\WINDOWS\system32\LEXPPS.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
F:\Program Files\Norton AntiVirus\navapsvc.exe
F:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
F:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
F:\WINDOWS\system32\dla\tfswctrl.exe
F:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\WINDOWS\system32\Atiptaxx.exe
C:\Program Files\Yxkma\Knkyq.exe
F:\WINDOWS\system32\ayjnkwmn\oxbapo.exe
F:\WINDOWS\system32\pmdgus\aahkw.exe
F:\WINDOWS\system32\otrdcqw\pbwmwjs.exe
F:\WINDOWS\system32\blpbbp\evwy.exe
F:\WINDOWS\system32\rrhdxekq\hfspdp.exe
F:\WINDOWS\system32\gvbhxyrg\ovbcv.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\WINDOWS\system32\RUNDLL32.exe
F:\windows\system32\sdxregvv.exe
F:\WINDOWS\system32\wintask.exe
F:\WINDOWS\system32\iffsysi6.exe
F:\Program Files\Messenger\msmsgs.exe
F:\WINDOWS\system32\??oolsv.exe
F:\Documents and Settings\Heather\Application Data\reem.exe
F:\WINDOWS\system32\ctfmon.exe
F:\WINDOWS\system32\wscript.exe
F:\Documents and Settings\Heather\Desktop\hijackthis-1\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.altavista.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.altavista.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {F40CEC47-20FB-5C2B-DC98-72A2DDD168E3} - F:\WINDOWS\system32\tmh.dll
O3 - Toolbar: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] F:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [PRONoMgrWired] F:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NeroFilterCheck] F:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [dla] F:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [Ahrodfyi] C:\Program Files\Yxkma\Knkyq.exe
O4 - HKLM\..\Run: [2L@T#ZQ57G3CCM] F:\WINDOWS\system32\Kvbi1.exe
O4 - HKLM\..\Run: [sixtysix] F:\WINDOWS\sixtypopsix.exe
O4 - HKLM\..\Run: [yrdo9lua] F:\Program Files\yrdo9lua\yrdo9lua.exe
O4 - HKLM\..\Run: [oxbapo] F:\WINDOWS\system32\ayjnkwmn\oxbapo.exe
O4 - HKLM\..\Run: [aahkw] F:\WINDOWS\system32\pmdgus\aahkw.exe
O4 - HKLM\..\Run: [pbwmwjs] F:\WINDOWS\system32\otrdcqw\pbwmwjs.exe
O4 - HKLM\..\Run: [evwy] F:\WINDOWS\system32\blpbbp\evwy.exe
O4 - HKLM\..\Run: [ddxifc] F:\WINDOWS\system32\ddxifc.exe
O4 - HKLM\..\Run: [BPT] "c:\Program Files\Bpt\bpt.exe"
O4 - HKLM\..\Run: [DI2] "F:\DOCUME~1\Kelly\LOCALS~1\Temp\27.exe\27.exe"
O4 - HKLM\..\Run: [Makarzy] F:\WINDOWS\nyei.exe
O4 - HKLM\..\Run: [fecbyfdj] F:\WINDOWS\system32\rsoqop\fecbyfdj.exe
O4 - HKLM\..\Run: [slhm] F:\WINDOWS\system32\tsaym\slhm.exe
O4 - HKLM\..\Run: [xjby] F:\WINDOWS\system32\ogyyerx\xjby.exe
O4 - HKLM\..\Run: [nwuynwic] F:\WINDOWS\system32\wbsbq\nwuynwic.exe
O4 - HKLM\..\Run: [ypawxn] F:\WINDOWS\system32\ljnu\ypawxn.exe
O4 - HKLM\..\Run: [vdubiq] F:\WINDOWS\system32\groxbser\vdubiq.exe
O4 - HKLM\..\Run: [ovbcv] F:\WINDOWS\system32\gvbhxyrg\ovbcv.exe
O4 - HKLM\..\Run: [hfspdp] F:\WINDOWS\system32\rrhdxekq\hfspdp.exe
O4 - HKLM\..\Run: [SystemCheck] F:\WINDOWS\SysCheckBop32
O4 - HKLM\..\Run: [gwhrqyhi] F:\WINDOWS\system32\ofoif\gwhrqyhi.exe
O4 - HKLM\..\Run: [rvcbjxy] F:\WINDOWS\system32\ngvous\rvcbjxy.exe
O4 - HKLM\..\Run: [Camp Bait Site Two] F:\Documents and Settings\All Users\Application Data\WarnStopCampBait\Hold hope.exe
O4 - HKLM\..\Run: [cpuvo] F:\WINDOWS\system32\dpnj\cpuvo.exe
O4 - HKLM\..\Run: [garltpep] F:\WINDOWS\system32\uhddpe\garltpep.exe
O4 - HKLM\..\Run: [jrsabx] F:\WINDOWS\system32\oecq\jrsabx.exe
O4 - HKLM\..\Run: [wdfrygv] F:\WINDOWS\system32\fruaca\wdfrygv.exe
O4 - HKLM\..\Run: [qqmvttj] F:\WINDOWS\system32\muxx\qqmvttj.exe
O4 - HKLM\..\Run: [tskrtvqp] F:\WINDOWS\system32\diwwj\tskrtvqp.exe
O4 - HKLM\..\Run: [ggxb] F:\WINDOWS\system32\evnjxy\ggxb.exe
O4 - HKLM\..\Run: [xtuwx] F:\WINDOWS\system32\owkfiyn\xtuwx.exe
O4 - HKLM\..\Run: [cvilwu] f:\windows\system32\cvilwu.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [etbrun] F:\windows\system32\eliteeng32.exe
O4 - HKLM\..\Run: [ZStart] F:\windows\system32\sdxregvv.exe lee0105
O4 - HKLM\..\Run: [WinTask driver] F:\WINDOWS\system32\wintask.exe
O4 - HKLM\..\Run: [SysStart] F:\WINDOWS\system32\iffsysi6.exe lee0105
O4 - HKLM\..\Run: [razin] F:\DOCUME~1\Heather\LOCALS~1\Temp\rm05040901.Stub.exe
O4 - HKLM\..\Run: [5F8f32V] tasecsvc.exe
O4 - HKLM\..\Run: [zstghqd] F:\WINDOWS\zstghqd.exe
O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] "F:\Program Files\AIM+\AIM+.exe" -cnetwait.odl
O4 - HKCU\..\Run: [Yahoo! Pager] F:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Zknypmhz] F:\WINDOWS\system32\??oolsv.exe
O4 - HKCU\..\Run: [KorpRSZ5l] subpsp.exe
O4 - HKCU\..\Run: [ptbch] F:\WINDOWS\system32\ptbch.exe
O4 - HKCU\..\Run: [Odua] F:\Documents and Settings\Heather\Application Data\reem.exe
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [Web Offer] Command /c del F:\WINDOWS\system32\EZPOPS~1.EXE
O8 - Extra context menu item: &AIM Search - res://F:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Yahoo! Search - file:///F:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///F:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///F:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {539DA0E0-74A7-11D9-9669-0800200C9A66} - http://www.ouchvideo.com/mmviewer_ic13.cab
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - F:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - F:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - F:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - IntelĀ® Corporation - F:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - F:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - F:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - F:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Thanks
Locate these files.
F:\WINDOWS\system32\otrdcqw\pbwmwjs.exe
F:\WINDOWS\system32\blpbbp\evwy.exe
F:\WINDOWS\system32\rrhdxekq\hfspdp.exe
F:\WINDOWS\system32\gvbhxyrg\ovbcv.exe

Copy them all to one folder then zip the entire folder and email them to me at
racktrackerATnet-integration.net

Note you will have to change the AT to @ for the address to work

You are infected with the peper trojan. Run this uninstaller, reboot when finished.

http://downloads.subratam.org/PeperFix.exe

Run another hijackthis scan. Place a check next to the following entries, then close all other windows and click the fix button.

R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {F40CEC47-20FB-5C2B-DC98-72A2DDD168E3} - F:\WINDOWS\system32\tmh.dll
O3 - Toolbar: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O4 - HKLM\..\Run: [Ahrodfyi] C:\Program Files\Yxkma\Knkyq.exe
O4 - HKLM\..\Run: [2L@T#ZQ57G3CCM] F:\WINDOWS\system32\Kvbi1.exe
O4 - HKLM\..\Run: [sixtysix] F:\WINDOWS\sixtypopsix.exe
O4 - HKLM\..\Run: [yrdo9lua] F:\Program Files\yrdo9lua\yrdo9lua.exe
O4 - HKLM\..\Run: [oxbapo] F:\WINDOWS\system32\ayjnkwmn\oxbapo.exe
O4 - HKLM\..\Run: [aahkw] F:\WINDOWS\system32\pmdgus\aahkw.exe
O4 - HKLM\..\Run: [pbwmwjs] F:\WINDOWS\system32\otrdcqw\pbwmwjs.exe
O4 - HKLM\..\Run: [evwy] F:\WINDOWS\system32\blpbbp\evwy.exe
O4 - HKLM\..\Run: [ddxifc] F:\WINDOWS\system32\ddxifc.exe
O4 - HKLM\..\Run: [BPT] "c:\Program Files\Bpt\bpt.exe"
O4 - HKLM\..\Run: [DI2] "F:\DOCUME~1\Kelly\LOCALS~1\Temp\27.exe\27.exe"
O4 - HKLM\..\Run: [Makarzy] F:\WINDOWS\nyei.exe
O4 - HKLM\..\Run: [fecbyfdj] F:\WINDOWS\system32\rsoqop\fecbyfdj.exe
O4 - HKLM\..\Run: [slhm] F:\WINDOWS\system32\tsaym\slhm.exe
O4 - HKLM\..\Run: [xjby] F:\WINDOWS\system32\ogyyerx\xjby.exe
O4 - HKLM\..\Run: [nwuynwic] F:\WINDOWS\system32\wbsbq\nwuynwic.exe
O4 - HKLM\..\Run: [ypawxn] F:\WINDOWS\system32\ljnu\ypawxn.exe
O4 - HKLM\..\Run: [vdubiq] F:\WINDOWS\system32\groxbser\vdubiq.exe
O4 - HKLM\..\Run: [ovbcv] F:\WINDOWS\system32\gvbhxyrg\ovbcv.exe
O4 - HKLM\..\Run: [hfspdp] F:\WINDOWS\system32\rrhdxekq\hfspdp.exe
O4 - HKLM\..\Run: [SystemCheck] F:\WINDOWS\SysCheckBop32
O4 - HKLM\..\Run: [gwhrqyhi] F:\WINDOWS\system32\ofoif\gwhrqyhi.exe
O4 - HKLM\..\Run: [rvcbjxy] F:\WINDOWS\system32\ngvous\rvcbjxy.exe
O4 - HKLM\..\Run: [Camp Bait Site Two] F:\Documents and Settings\All Users\Application Data\WarnStopCampBait\Hold hope.exe
O4 - HKLM\..\Run: [cpuvo] F:\WINDOWS\system32\dpnj\cpuvo.exe
O4 - HKLM\..\Run: [garltpep] F:\WINDOWS\system32\uhddpe\garltpep.exe
O4 - HKLM\..\Run: [jrsabx] F:\WINDOWS\system32\oecq\jrsabx.exe
O4 - HKLM\..\Run: [wdfrygv] F:\WINDOWS\system32\fruaca\wdfrygv.exe
O4 - HKLM\..\Run: [qqmvttj] F:\WINDOWS\system32\muxx\qqmvttj.exe
O4 - HKLM\..\Run: [tskrtvqp] F:\WINDOWS\system32\diwwj\tskrtvqp.exe
O4 - HKLM\..\Run: [ggxb] F:\WINDOWS\system32\evnjxy\ggxb.exe
O4 - HKLM\..\Run: [xtuwx] F:\WINDOWS\system32\owkfiyn\xtuwx.exe
O4 - HKLM\..\Run: [cvilwu] f:\windows\system32\cvilwu.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [etbrun] F:\windows\system32\eliteeng32.exe
O4 - HKLM\..\Run: [ZStart] F:\windows\system32\sdxregvv.exe lee0105
O4 - HKLM\..\Run: [WinTask driver] F:\WINDOWS\system32\wintask.exe
O4 - HKLM\..\Run: [SysStart] F:\WINDOWS\system32\iffsysi6.exe lee0105
O4 - HKLM\..\Run: [razin] F:\DOCUME~1\Heather\LOCALS~1\Temp\rm05040901.Stub.exe
O4 - HKLM\..\Run: [5F8f32V] tasecsvc.exe
O4 - HKLM\..\Run: [zstghqd] F:\WINDOWS\zstghqd.exe
O4 - HKCU\..\Run: [Zknypmhz] F:\WINDOWS\system32\??oolsv.exe
O4 - HKCU\..\Run: [KorpRSZ5l] subpsp.exe
O4 - HKCU\..\Run: [ptbch] F:\WINDOWS\system32\ptbch.exe
O4 - HKCU\..\Run: [Odua] F:\Documents and Settings\Heather\Application Data\reem.exe
O4 - HKCU\..\RunOnce: [Web Offer] Command /c del F:\WINDOWS\system32\EZPOPS~1.EXE

Then reboot into safe mode and delete these files.
F:\WINDOWS\sixtypopsix.exe
F:\WINDOWS\system32\ddxifc.exe
F:\WINDOWS\nyei.exe
F:\WINDOWS\SysCheckBop32
f:\windows\system32\cvilwu.exe
AUNPS2.DLL,
F:\windows\system32\eliteeng32.exe
F:\windows\system32\sdxregvv.exe
F:\WINDOWS\system32\wintask.exe
F:\WINDOWS\system32\iffsysi6.exe
tasecsvc.exe
F:\WINDOWS\zstghqd.exe
F:\WINDOWS\system32\??oolsv.exe
subpsp.exe
F:\WINDOWS\system32\ptbch.exe
F:\Documents and Settings\Heather\Application Data\reem.exe

And these folders.
C:\Program Files\Yxkma
F:\Program Files\yrdo9lua
F:\WINDOWS\system32\ayjnkwmn
F:\WINDOWS\system32\pmdgus
F:\WINDOWS\system32\otrdcqw
F:\WINDOWS\system32\blpbbp
c:\Program Files\Bpt
F:\WINDOWS\system32\rsoqop
F:\WINDOWS\system32\tsaym
F:\WINDOWS\system32\ogyyerx
F:\WINDOWS\system32\wbsbq
F:\WINDOWS\system32\ljnu
F:\WINDOWS\system32\groxbser
F:\WINDOWS\system32\gvbhxyrg
F:\WINDOWS\system32\rrhdxekq
F:\WINDOWS\system32\ofoif
F:\WINDOWS\system32\ngvous
F:\Documents and Settings\All Users\Application Data\WarnStopCampBait
F:\WINDOWS\system32\dpnj
F:\WINDOWS\system32\uhddpe
F:\WINDOWS\system32\oecq
F:\WINDOWS\system32\fruaca
F:\WINDOWS\system32\muxx
F:\WINDOWS\system32\diwwj
F:\WINDOWS\system32\evnjxy
F:\WINDOWS\system32\owkfiyn

Empty the contents of thes folders.
F:\DOCUME~1\Kelly\LOCALS~1\Temp
F:\DOCUME~1\Heather\LOCALS~1\Temp

You may have to enable hidden files to find all the files.

Then reboot and run another hijackthis scan and post your new log here.
I have completed all that you ask for. The peperfix program reported that it could find no files that were infected. Following is the nes HJT log. - Thanks for your help

Logfile of HijackThis v1.99.1
Scan saved at 12:54:42 PM, on 3/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
F:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
F:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
F:\WINDOWS\system32\brsvc01a.exe
F:\WINDOWS\system32\brss01a.exe
F:\WINDOWS\system32\LEXBCES.EXE
F:\WINDOWS\system32\LEXPPS.EXE
F:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
F:\Program Files\Norton AntiVirus\navapsvc.exe
F:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
F:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
F:\WINDOWS\system32\dla\tfswctrl.exe
F:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\WINDOWS\system32\Atiptaxx.exe
F:\Program Files\Messenger\msmsgs.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Documents and Settings\Heather\Desktop\hijackthis-1\HijackThis.exe
F:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.altavista.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.altavista.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] F:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [PRONoMgrWired] F:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NeroFilterCheck] F:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [dla] F:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] "F:\Program Files\AIM+\AIM+.exe" -cnetwait.odl
O4 - HKCU\..\Run: [Yahoo! Pager] F:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AIM Search - res://F:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Yahoo! Search - file:///F:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///F:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///F:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {539DA0E0-74A7-11D9-9669-0800200C9A66} - http://www.ouchvideo.com/mmviewer_ic13.cab
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - F:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - F:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - F:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - IntelĀ® Corporation - F:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - F:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - F:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - F:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Print Spooler (Spooler) - Unknown owner - F:\WINDOWS\system32\spoolsv.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Your log looks good.

How are things on your end?

You should read this to help prevent future problems.

So how did I get infected
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI