This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trying To Help A Friend W/ Severely Infected Pc

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:unsure: I'm a newbie on forums, so if I screw-up, please understand and forgive. Thanks.

Ran Norton Systemworks/AntiVirus/Internet Security
Ran AdAware SE
Ran SpyBot S & D
Ran MS [beta] AntiSpyware
Ran Spyware Doctor
Updated all, including MS-Windows updates and re-ran everything, again.

older, HP Pavillian 8756C [PIII/850MHz]
MS-XP Pro SP2

Belongs to an employee of mine with teenage sons. I suspect KazaA is source of their problems. PC was really in a mess when she brought it to me. Could not access internet at all because of multiple hijackings / viruses competeing with each other for clock-time.

And I still have a few issues after clearing what I could.
1.] There is a dialup network connection named HAPPY - which continuously re-installs itself faster than I can delete it. SYSTEM - SVCHOST.EXE pegs CPU resources to 100% every 30 seconds or so as HAPPY briefly disappears and re-appears in Network Connection view
2.] The BroadBand connection will not stay connected for more than a few seconds. Using same modem with my PC creates no such behavior. Disabling Internet Security did not alter behavior.
3.] Network Adapter will not stay connected - keep getting limited functionality warning]. I removed driver twice for XP to re-install - no change.
4.] There are a few entries in the NHJT log which I am not sure whether to delete, or not - But probability for deletion seems good:
omnczb - I did rename two files in Sys32 folder - then moved them to desktop in effort to deactivate them.
LTMSG.exe 7 [Although this may be Agere modem file.]
the two "016 - DPF" entries.
No Name, No File entry
Pynix.dll ?????


Log created from Safe Mode with System Restore turned-off.

Your assistance would be appreciated. Thanks
=====================================================

Logfile of HijackThis v1.98.2
Scan saved at 1:02:00 PM, on 3/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Donna K\Desktop\Spyware search and destroy programs\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: PynixObj Class - {00000000-DD60-0064-6EC2-6E0100000000} - C:\WINDOWS\Pynix.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: X1IEHook Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O2 - BHO: (no name) - {C7469AD8-4E29-42C7-B671-F3938B0E68DF} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [omnczb] C:\WINDOWS\System32\omnczb.exe
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: WinUpdate.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\explorer.cab
O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} - http://download.redswoosh.net/Installer/113/rsinstaller.cab
Hi Ken , Welcome to TomCoyote forum. I must be candid, I am not sure if I can help you but I am willing to give it a try. You have a nasty issue.
Read this so you will know what we are after: O4 - Global Startup: WinUpdate.exe
http://www.liutilities.com/products/wintas…rary/winupdate/
http://castlecops.com/startuplist-4494.html

Since you have Symantec, I will let you try to kill it with their instruction. Make sure to read the information carefully:
Please note the Technical details, especially 6 and 7. You will probably have to reinstall your av software and firewall once this item is gone. I would cut off communication to the trojan by staying offline as much as possible until it is gone. http://securityresponse.symantec.com/avcen…kdoor.rado.html

Your HijackThis.exe is very outdated, the new version is 1.99.1. Update to the new version for the removal with HJT. I will include the trojan in the instructions also, but it should be gone when you get to that part. Taking no chances.

You have TeaTimer running and a good program it is. It will stop the fix with HJT so you must turn it off. You may be able to exit near the clock if not instructions are here: http://russelltexas.com/malware/teatimer.htm

Download and save this program until I tell you to run it: http://www.ccleaner.com/

Scan with HJT v1.99.1 and check the box in front of these items:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: PynixObj Class - {00000000-DD60-0064-6EC2-6E0100000000} - C:\WINDOWS\Pynix.dll
O2 - BHO: (no name) - {C7469AD8-4E29-42C7-B671-F3938B0E68DF} - (no file)
O4 - HKLM\..\Run: [omnczb] C:\WINDOWS\System32\omnczb.exe
O4 - Global Startup: WinUpdate.exe
O16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\explorer.cab
-Adult Content Dialer
O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} - http://download.redswoosh.net/Installer/113/rsinstaller.cab
adware

Close all programs but HJT and all browser windows then click on "Fix Checked"

SHOW HIDDEN FILES: Follow the instructions in the follow link to enable hidden files for your operating system.
You may wish to reverse this process if you have any concern about anyone getting into these hidden system files.
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Search to make sure this item is gone: WinUpdate.exe If located, write down the location.

RIGHT click on Start then click on Explore. Locate and delete these items:

WinUpdate.exe >>> file (if there)

C:\WINDOWS\System32\omnczb.exe >>> file

Now run CCleaner

I am not sure CCleaner cleans the Prefetch Folder, use the instructions in this link to make sure the Prefetch files were deleted: http://www.safecomputing.umn.edu/guides/tempdirectories.html
DO NOT delete the FOLDER, just the files.

Empty the recycle bin and restart the computer. Stay in this same thread and post a new log along with any feedback you think I should have. Good Luck.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
:( I was not able to run several programs: Norton A/V, SEARCH, or Explorer. When I opened Task Manager, several Norton processes are chewing clock cycles, but there is no screen display. Guess I will have to uninstall and reinstall. I will let KAV run overnight to see if anything else will be found. SEARCH would not acknowledge a click on FILES … and, a second click would close the search window. So I ran SpyBot S & D, AdAware SE and Spy Hunter which found several more items to delete. I did not find the Registry values where you indicated, but did find both omnczb.exe and winupdate.exe files in different keys. I was able to use the SEARCH function within the registry file to find and then delete these items and Pynix. Here is the most recent HJT log. I see at least one more (file missing) item which may need to be deleted. Thank you for your assistance to this point. Logfile of HijackThis v1.99.1 Scan saved at 1:04:15 AM, on 3/24/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Norton Internet Security\NISUM.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Norton Internet Security\ccPxySvc.exe C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe C:\WINDOWS\LTMSG.exe C:\windows\system32\wdfmgr.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\NetZero\exec.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\System32\wbem\wmiprvse.exe C:\Documents and Settings\Donna K\Desktop\Spyware search and destroy programs\HijackThis.exe C:\WINDOWS\system32\taskmgr.exe R3 - Default URLSearchHook is missing O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: X1IEHook Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7 O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [uoltray] C:\Program Files\NetZero\exec.exe regrun O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ? O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPxySvc.exe O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing) O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hi Ken, You did good, just a couple of things:

1) I could not see this, I guess it was the old version: R3 - Default URLSearchHook is missing, a left over from an infection. Probably the BHO we removed. When you use HJT next, check and fix that one. Make sure TT is off.

2) I see your ran this log with Selective Startup in MSCONFIG. I would really like to know if there is anything unchecked I should have seen that could be bad. You can enable all, then scan with HJT, then return to Selective and post that log without restarting, or you can give me a list of the unchecked items, or you can assure me as well as yourself that the unchecked items pose no threat.

3) You should know this log fairly well by now, if your friend wants anything else removed that is not malware that they no longer need, let me know. I should also say at this point that HJT sometimes reports missing files in some of the new scan areas. This is not always the case, it is usually a glitch that gets repaired in the next version. We are kept informed of this so we do not remove something in error. If you have questions about specific items, send them along.

4) Since the leftover item: R3 - Default URLSearchHook is missing is all I see and you are going to remove that, and we are going to resolve the Selective Startup issue I see no reason not to give you the "All Clean" information so you can see what some of the experts advise to keep the computer clean and safe online: Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Thanks…pskelley
TomCoyote forum
Slyware Warrior
:P We might be good to go, now, thanks to your kind assistance. There was one more NONAME [NO FILE] BHO entry that occured, but I zapped that. I ran all the spyware detection/removal programs one more time and then uninstalled them. Norton A/V still will not run, so I uninstalled SYSTEMWORKS and INTERNET SECURITY. Funny thing is, SYSTEMWORKS with the A/V only still shows in Program List and there are still multiple Norton entries in this latest log, but there are no more UNINSTALL options anywhere for me to select. SpyBot [TeaTimer disabled] and AdAware are the only functional spyware detection programs I have loaded at time of this scan. Thanks again for your assistance. I'll check back tonight for any further updates. I'll reinstall Norton and then attempt to connect to internet and keep my fingers crossed. I'll update Norton, SpyBot S & D as well as AdAware and run all three. I'll let you know the results. Thanks. Logfile of HijackThis v1.99.1 Scan saved at 8:48:29 AM, on 3/24/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\LTMSG.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\NetZero\exec.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe C:\Documents and Settings\Donna K\Desktop\Spyware search and destroy programs\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: X1IEHook Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7 O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [uoltray] C:\Program Files\NetZero\exec.exe regrun O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ? O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing) O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
OK Ken, remember this from the Symantec instructions:

May kill processes that are associated with antivirus and firewall software.

There is a very good chance it has been compromised, I suggest you re-read those Symantec instructions and proceed assuming this to be so. You may have to contact Symantec for instructions?

I see no malware in the current log. I do see running programs that I have to
believe are not used enough to warrant booting them at every startup and MSCONFIG or in the case of these you may be able to stop them from running at every start up from within the program, here are just a couple of examples:

C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray

Here are the links I use when I am researching items I want to know about. Be careful not to turn off anything Windows needs to run. If you are not 100% sure, leave it alone:
http://www.answersthatwork.com/Tasklist_pages/tasklist.htm
http://www.pacs-portal.co.uk/startup_index.htm
http://computercops.biz/StartupList.html
http://www.sysinfo.org/startuplist.php
http://www.bleepingcomputer.com/startups/

Once you know you are clean, I would enable TT again, It is a good program. Since you are running those two, here are the others I suggest which are proactive for your consideration. I will toss in the tutorials for Spybot and Adaware in case the information helps:

Spybot
http://www.bleepingcomputer.com/forums/tutorial43.html
Ad-aware
http://www.bleepingcomputer.com/forums/tutorial48.html
SpywareBlaster
http://www.bleepingcomputer.com/forums/tutorial49.html
SpywareGuard:
http://www.bleepingcomputer.com/forums/tutorial50.html
IE-Spyad
http://www.bleepingcomputer.com/forums/tutorial53.html

Last but not least since your log is showing clean, here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Thanks…pskelley
TomCoyote forum
Slyware Warrior
If you get help here consider a donation:
http://tomcoyote.com/donate.php
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI