This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Veryeasysearch Hijack

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have run adaware and sbot s&d. I have run HJT and this is the log.

Please help!

Logfile of HijackThis v1.99.0
Scan saved at 3:48:26 PM, on 4/12/2005
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\ibmpmsvc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\drivers\trcboot.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
c:\sdwork\issimsvc.exe
C:\WINNT\System32\drivers\ldlcserv.exe
C:\PROGRA~1\AT&TNE~1\NetCfgSv.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\TIVOLI\TRIP\trip.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\WRTService.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINNT\system32\tp4serv.exe
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINNT\system32\winbh32.exe
C:\Program Files\Zone Labs\Integrity Client\iclient.exe
C:\tass\printnow\printnow.exe
C:\WINNT\system32\mobsync.exe
C:\Interwise\Student\pull.exe
C:\Program Files\AT&T Net Client\NetClient.exe
C:\Program Files\C4EBReg\isamsmt.exe
C:\Program Files\C4ebreg\c4ebreg.exe
C:\Program Files\IBM\NotesBuddy\NotesBuddy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\pejkk.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\pejkk.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\pejkk.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\pejkk.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\pejkk.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\pejkk.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\pejkk.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
R3 - Default URLSearchHook is missing
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://w3.ibm.com"); (C:\Program Files\Netscape\Users\default\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0DA39540-9898-A0A6-B6D4-21AE7E36D909} - C:\WINNT\system32\d3ve32.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [TpHotkey] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [ISAM SMT Service] "C:\Program Files\C4EBReg\isamsmt.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AS00_Gear511] C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe -hide
O4 - HKLM\..\Run: [Tray] C:\DOCUME~1\dstillwl\LOCALS~1\Temp\c4c59e4c.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [winbh32.exe] C:\WINNT\system32\winbh32.exe
O4 - HKLM\..\Run: [ISSI EZUpdate Service] "c:\sdwork\issimsvc.exe"
O4 - HKLM\..\Run: [C4EBReg] "C:\Program Files\C4ebreg\c4ebreg.exe" /q
O4 - Global Startup: Integrity Client.lnk = C:\Program Files\Zone Labs\Integrity Client\iclient.exe
O4 - Global Startup: PrintNow.lnk = C:\tass\printnow\printnow.exe
O4 - Global Startup: Push Client.LNK = C:\Interwise\Student\pull.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.com/
O16 - DPF: IBM EA2000 - https://w3-1.ibm.com/tools/us/expenses/EA2000.cab
O16 - DPF: {9519B2A2-6592-4E41-8290-D0298459270C} (LNWebAssist Class) - http://w3.ibm.com/bluepages/scripts/lnwebassist.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://cisco.webex.com/client/latest/training/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = naasc.ibm.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{0AA56F83-57E3-4626-BCCD-9E0FD14F0D23}: Domain = ibm.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{0AA56F83-57E3-4626-BCCD-9E0FD14F0D23}: NameServer = 9.0.4.1,9.0.5.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = naasc.ibm.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = nadsc.ibm.com,ibm.com,naasc.ibm.com,dalcmc.ibm.com,atlnasc.ibm.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{0AA56F83-57E3-4626-BCCD-9E0FD14F0D23}: Domain = ibm.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{0AA56F83-57E3-4626-BCCD-9E0FD14F0D23}: NameServer = 9.0.4.1,9.0.5.1
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = naasc.ibm.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = ibm.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{0AA56F83-57E3-4626-BCCD-9E0FD14F0D23}: Domain = ibm.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{0AA56F83-57E3-4626-BCCD-9E0FD14F0D23}: NameServer = 9.0.4.1,9.0.5.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = nadsc.ibm.com,ibm.com,naasc.ibm.com,dalcmc.ibm.com,atlnasc.ibm.com
O23 - Service: Remote Procedure Call (RPC) Helper - Unknown - C:\WINNT\system32\addlq32.exe (file missing)
O23 - Service: ADSM Client Acceptor - Unknown - C:\Progra~1\IBM\ADSM\baclient\dsmcad.exe
O23 - Service: ADSM Remote Client Agent - Unknown - C:\Progra~1\IBM\ADSM\baclient\dsmagent.exe
O23 - Service: Ati HotKey Poller - Unknown - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DB2 JDBC Applet Server - Unknown - C:\SQLLIB\bin\db2jds.exe
O23 - Service: DB2 Security Server - Unknown - C:\SQLLIB\bin\db2sec.exe
O23 - Service: Symantec AntiVirus Definition Watcher - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: IBM PM Service - IBM Corp. - C:\WINNT\System32\ibmpmsvc.exe
O23 - Service: ISAM SMT Service - IBM Global Services - C:\Program Files\C4EBReg\isamsmt.exe
O23 - Service: ISSI EZUpdate - IBM Global Services - c:\sdwork\issimsvc.exe
O23 - Service: LocalSystem - Unknown - C:\WINNT\System32\drivers\ldlcserv.exe
O23 - Service: Network Configuration Service - AT&T - C:\PROGRA~1\AT&TNE~1\NetCfgSv.EXE
O23 - Service: SAVRoam - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrcBoot - Unknown - C:\WINNT\System32\drivers\trcboot.exe
O23 - Service: Tivoli Remote Execution Service - Unknown - C:\TIVOLI\TRIP\trip.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINNT\system32\ZoneLabs\vsmon.exe
O23 - Service: WRT Service - Unknown - C:\WINNT\WRTService.exe
Hello dstillwl and welcome to TomCoyote. :wavey:

You may want to print out these instructions or save them to your desktop as a text file with Notepad because we will be restarting into Safe Mode later on in the fix and you might not be able to access the Internet.
  • Prepare CWShredder for use:
    • Download CWShredder.
    • Save CWShredder.exe to a convenient location.
    • Please do not do anything with it yet.
  • Prepare AboutBuster for use:
    • Download AboutBuster.
    • Unzip the contents of AboutBuster.zip and an AboutBuster directory will be created.
    • Navigate to the AboutBuster directory and double-click on AboutBuster.exe.
    • Click "OK" at the prompt with instructions.
    • Click "Update" and then "Check For Update" to begin the update process.
    • If any updates exist please download them by clicking "Download Update".
    • You should not run the program yet so click "Exit".
  • Prepare cwsserviceremove.reg for use:
    • Download cwsserviceremove.zip.
    • Unzip the contents of cwsserviceremove.zip (cwsserviceremove.reg) to your desktop.
    • Please do not do anything with it yet.
  • Reconfigure Windows XP to show hidden files:
    • Click Start. Open My Computer.
    • Select the Tools menu and click Folder Options. Select the View Tab.
    • Under the Hidden files and folders heading select "Show hidden files and folders".
    • Uncheck the "Hide protected operating system files (recommended)" option.
    • Uncheck the "Hide file extensions for known file types" option.
    • Click Yes to confirm. Click OK.
  • Disable the offending service.
    • Go to Start->Run and type Services.msc then hit Ok
    • Scroll down and find the service called:Remote Procedure Call (RPC) Helper << There are two similar named services. Make sure to fix the correct one.
    • When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.
Boot into Safe Mode:
Restart your computer and immediately begin tapping the F8 key on your keyboard.
If done right a Windows Advanced Options menu will appear. Select the Safe Mode option and press Enter.
To return to normal mode just restart your computer as you normally would.
  • Run CWShredder:
    • Double-click on CWShredder.exe.
    • Click "Fix ->" and click "OK" at the prompt.
    • CWShredder will scan and clean your system of CWS files.
    • Click "Next->" and then "Exit".
  • Remove the offending service:
    • Double-click on cwsserviceremove.reg you downloaded earlier.
    • When it asks you to merge the information to the registry click "Yes".
  • Run AboutBuster and save the logs:
    • Browse to where you saved AboutBuster and run AboutBuster.exe.
    • Click OK at the directions prompt.
    • Click Start and then OK to allow AboutBuster to scan for Alternate Data Streams.
    • Click Yes to allow it to shutdown explorer.exe.
    • It will begin to your computer for malicious files. If it asks if you would like to do a second pass, allow it to do so.
    • When it has finished, click Save Log. Make sure you save it as I need a copy of it.
  • Fix with Hijackthis:
    • Open Hijackthis, Run a scan and check the following:

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\pejkk.dll/sp.html#28129
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\pejkk.dll/sp.html#28129
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\pejkk.dll/sp.html#28129
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\pejkk.dll/sp.html#28129
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\pejkk.dll/sp.html#28129
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\pejkk.dll/sp.html#28129
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\pejkk.dll/sp.html#28129
      R3 - Default URLSearchHook is missing

      O2 - BHO: (no name) - {0DA39540-9898-A0A6-B6D4-21AE7E36D909} - C:\WINNT\system32\d3ve32.dll

      O4 - HKLM\..\Run: [Tray] C:\DOCUME~1\dstillwl\LOCALS~1\Temp\c4c59e4c.exe
      O4 - HKLM\..\Run: [winbh32.exe] C:\WINNT\system32\winbh32.exe

      O23 - Service: Remote Procedure Call (RPC) Helper - Unknown - C:\WINNT\system32\addlq32.exe (file missing)
    • With all other programs and browsers closed, click fix checked.
  • Delete the following files:
    • C:\WINNT\pejkk.dll
    • C:\WINNT\system32\d3ve32.dll
    • C:\WINNT\system32\winbh32.exe
    • C:\WINNT\system32\addlq32.exe
  • Clean out temporary files:
    • Start | Run | type cleanmgr | OK
    • Let it scan your system for files to remove.
    • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
    • Click "OK" to remove them.
    • Click "Yes" to confirm the deletion.
  • Restart your computer normally to return to normal mode.
  • Free TrendMicro Housecall scan:
    • Vist the TrendMicro Housecall website.
    • Select your country from the drop-down list and click "Go".
    • Choose "Yes" at the ActiveX Security Warning prompt.
    • Please wait while the Housecall engine is updated.
    • Select the drives to be scanned by placing a check in their respective boxes.
    • Check the "Auto Clean" box.
    • Click "SCAN" in order to begin scanning your system.
    • Please be patient while Housecall scans your system for malicious files.
    • If not auto-cleaned, remove anything it finds.
    • Click "Close" to exit the Housecall scanner.
    • Choose "Yes" at the HouseCall message prompt.
  • Prepare your reply:
    • Please post a fresh HijackThis log
    • Please post the AboutBuster log.
    • Please note any complications you had.
Thanks Again for you help Alan. Everything seemed to go pretty well. When I went to Clean out my temporary files the Clean disk would not run, so I manually cleaned out everything that was in my Temporary Internet and Temp files as well as what was in my Recycle Bin. Following are my fresh HJT log and Aboutbuster Log.

Logfile of HijackThis v1.99.0
Scan saved at 3:24:21 PM, on 4/13/2005
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\ibmpmsvc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\drivers\trcboot.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\C4EBReg\isamsmt.exe
C:\WINNT\System32\drivers\ldlcserv.exe
C:\PROGRA~1\AT&TNE~1\NetCfgSv.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\TIVOLI\TRIP\trip.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\WRTService.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINNT\system32\tp4serv.exe
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINNT\AGRSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
c:\program files\c4ebreg\c4ebreg.exe
C:\Program Files\Zone Labs\Integrity Client\iclient.exe
C:\tass\printnow\printnow.exe
C:\Interwise\Student\pull.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\hostw\cmm\RXAPI.EXE
C:\hijackthis\hijackthis_sfx.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://w3.ibm.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://w3.ibm.com"); (C:\Program Files\Netscape\Users\default\prefs.js)
O1 - Hosts: 9.9.162.19 callpath.atlnasc.ibm.com callpath
O1 - Hosts: 9.19.81.30 cpath1.dalcmc.ibm.com cpath1
O1 - Hosts: 9.9.125.13 ibmds1
O1 - Hosts: 9.9.74.162 ibmds2
O1 - Hosts: 9.45.101.37 SBGENCFGS
O1 - Hosts: 9.45.101.36 SBGENSTAT
O1 - Hosts: 9.45.101.35 SBGENICS
O1 - Hosts: 9.45.101.39 SBGENDB
O1 - Hosts: 9.45.101.38 SBGENRPT
O1 - Hosts: 9.45.101.42 sbgenweb
O1 - Hosts: 9.45.101.43 sbgenproxy
O1 - Hosts: 9.10.33.246 rscvoice2.rchland.ibm.com
O1 - Hosts: 9.9.202.24 smytsrv01.naasc.ibm.com smytsrv01
O1 - Hosts: 9.134.138.25 ukgnkgtatsp1.greenock.uk.ibm.com
O1 - Hosts: 9.134.138.26 ukgnkgtatsp2.greenock.uk.ibm.com
O1 - Hosts: 9.134.138.27 ukgnkgtatsp3.greenock.uk.ibm.com
O1 - Hosts: 9.134.138.28 ukgnkgtatsp4.greenock.uk.ibm.com
O1 - Hosts: 9.134.138.29 ukgnkgtatsb1.greenock.uk.ibm.com
O1 - Hosts: 9.134.138.30 ukgnkgtatsb2.greenock.uk.ibm.com
O1 - Hosts: 9.134.138.31 ukgnkgtatsb3.greenock.uk.ibm.com
O1 - Hosts: 9.134.138.32 ukgnkgtatsb4.greenock.uk.ibm.com
O1 - Hosts: 9.9.126.5 atl8500a
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [TpHotkey] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [ISAM SMT Service] "C:\Program Files\C4EBReg\isamsmt.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AS00_Gear511] C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe -hide
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [wamregfix] C:\program files\c4ebreg\wamreg.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Integrity Client.lnk = C:\Program Files\Zone Labs\Integrity Client\iclient.exe
O4 - Global Startup: PrintNow.lnk = C:\tass\printnow\printnow.exe
O4 - Global Startup: Push Client.LNK = C:\Interwise\Student\pull.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.com/
O16 - DPF: IBM EA2000 - https://w3-1.ibm.com/tools/us/expenses/EA2000.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9519B2A2-6592-4E41-8290-D0298459270C} (LNWebAssist Class) - http://w3.ibm.com/bluepages/scripts/lnwebassist.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://cisco.webex.com/client/latest/training/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = naasc.ibm.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{0AA56F83-57E3-4626-BCCD-9E0FD14F0D23}: Domain = ibm.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{0AA56F83-57E3-4626-BCCD-9E0FD14F0D23}: NameServer = 9.0.4.1,9.0.5.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = naasc.ibm.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = nadsc.ibm.com,ibm.com,naasc.ibm.com,dalcmc.ibm.com,atlnasc.ibm.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{0AA56F83-57E3-4626-BCCD-9E0FD14F0D23}: Domain = ibm.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{0AA56F83-57E3-4626-BCCD-9E0FD14F0D23}: NameServer = 9.0.4.1,9.0.5.1
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = naasc.ibm.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = nadsc.ibm.com,ibm.com,naasc.ibm.com,dalcmc.ibm.com,atlnasc.ibm.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{0AA56F83-57E3-4626-BCCD-9E0FD14F0D23}: Domain = ibm.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{0AA56F83-57E3-4626-BCCD-9E0FD14F0D23}: NameServer = 9.0.4.1,9.0.5.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = nadsc.ibm.com,ibm.com,naasc.ibm.com,dalcmc.ibm.com,atlnasc.ibm.com
O23 - Service: ADSM Client Acceptor - Unknown - C:\Progra~1\IBM\ADSM\baclient\dsmcad.exe
O23 - Service: ADSM Remote Client Agent - Unknown - C:\Progra~1\IBM\ADSM\baclient\dsmagent.exe
O23 - Service: Ati HotKey Poller - Unknown - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DB2 JDBC Applet Server - Unknown - C:\SQLLIB\bin\db2jds.exe
O23 - Service: DB2 Security Server - Unknown - C:\SQLLIB\bin\db2sec.exe
O23 - Service: Symantec AntiVirus Definition Watcher - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: IBM PM Service - IBM Corp. - C:\WINNT\System32\ibmpmsvc.exe
O23 - Service: ISAM SMT Service - IBM Global Services - C:\Program Files\C4EBReg\isamsmt.exe
O23 - Service: LocalSystem - Unknown - C:\WINNT\System32\drivers\ldlcserv.exe
O23 - Service: Network Configuration Service - AT&T - C:\PROGRA~1\AT&TNE~1\NetCfgSv.EXE
O23 - Service: SAVRoam - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrcBoot - Unknown - C:\WINNT\System32\drivers\trcboot.exe
O23 - Service: Tivoli Remote Execution Service - Unknown - C:\TIVOLI\TRIP\trip.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINNT\system32\ZoneLabs\vsmon.exe
O23 - Service: WRT Service - Unknown - C:\WINNT\WRTService.exe



Scanned at: 10:52:12 AM on: 4/13/2005


– Scan 1 —————————
About:Buster Version 4.0
Reference List : 26

No ADS found on system
Attempted Clean Of Temp folder.
Pages Reset… Done!

– Scan 2 —————————
About:Buster Version 4.0
Reference List : 26

No ADS found on system
Attempted Clean Of Temp folder.
Pages Reset… Done!


Everything seems to be working as normal now…You guys are the best. I truly appreciate what you are doing.
Log looks good. :thumbup:


MOST IMPORTANT: You Need to Update Windows and IE to get all the Latest Security Patches to protect your computer from the malware that is on the internet. Please go to Microsoft Windows and Internet Explorer Updates to get the critical updates. Windows 2000 should be at SP4.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the cirtical updates installed (Free) Microsoft Office Update


Reset and Re-enable your System Restore to remove bad files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected.)

In Windows ME, you can go to do this as follows:

1. Open System properties in Control Panel.
2. Click the Performance tab, and then click File System.
3. Click the Troubleshooting tab, and then make sure the
4. Disable System Restore check box is checked. When you choose to disable system restore
5. You will get a message that it will erase all your previous restore points, and that is ok.


Now that everything is fixed, I suggest that you get these programs to help keep the computer clean:

Spyware Blaster - Blocks bad ActiveX items from installing on your computer. Spyware Blaster runs silently in the background.
SpywareGuard - Real-time protection from spyware installation attempts
ie-spyad - Puts over 8,000 bad URLs into your restricted sites for Internet Explorer.
Google Toolbar - Blocks many unwanted pop-ups in Internet Explorer.
Firefox - Safer alternative to the Internet Explorer web browser.

AVG AntiVirus - Free antivirus program if you currently are not using one.
ZoneAlarm - Free firewall program if you currently are not using one.

Update these regularly.

You may also want to read "How did I get infected in the first place" to learn how to better secure your computer.

Be sure to keep Windows and your Anti-virus updated.
As this topic has been resolved, the thread will be closed.

If you need this topic reopened, please request this by sending an email to us at the following link:
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI