This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help with Trojans

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello there clever people!

I was wondering if someone could help me to get rid of some trojans that I think I may have.

My e-trust EZ anti virus programme flashed up a message saying I had 28 infections and strongly recommended that I did a full scan.

I duly did the scan and it was unable to clean/delete 4 files.

Here is my current HJT log


Logfile of HijackThis v1.99.0
Scan saved at 20:09:06, on 16/06/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
C:\Program Files\NuCam\CamCheck\CamCheck.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\LVComS.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\WINDOWS\twain_32\SiPix\SCBlink2\Srvany.exe
C:\WINDOWS\twain_32\SiPix\SCBlink2\USBPNP.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\isafe.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://www-cache.freeserve.com:8080;ftp=http://www-cache.freeserve.com:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;;localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VetTray] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
O4 - HKLM\..\Run: [CamCheck] C:\Program Files\NuCam\CamCheck\CamCheck.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-18.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O23 - Service: Blink2PnP - Unknown - C:\WINDOWS\twain_32\SiPix\SCBlink2\Srvany.exe
O23 - Service: CA ISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\isafe.exe
O23 - Service: Virtual NIC Service - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: Sygate Personal Firewall - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: VET Message Service - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe


Many thanks in advance for your time.

Cheers

Vicky x
Hi Vicky, Welcome to TomCoyote forum, if you are not receiving help elsewhere, please follow these directions in the posted order.

I duly did the scan and it was unable to clean/delete 4 files.

Anytime a scan gives you information like this you always want to write down the exact name and locate of items that can't be cleaned.
I don't see a lot going on in this log, but even the miracle it is HJT can't see everything. I will use some scans to see what we can find out.

1) Your version of HJT is outdated, you can update from within the program like this: Open HJT > Open the Misc Tools section > Scroll to Check for update online > Follow instructions. Here are download links if you need them: http://www.malwareremoval.com/downloads.html

2) Download CCleaner from this link: http://www.ccleaner.com/ Take the time to review the instructions on the download page so that when I ask you to run it you will know what you are doing.

3) I see Spybot in your log, but do you have Ad-aware? and are you aware both programs very recently upgraded to new versions? Use the most recent versions of Ad-aware and Spybot as they can get to places HJT cannot. Please use this link: http://tomcoyote.org/aawsb.php to download, update, configure and run these two "big guns" and allow them to remove anything bad they locate. Both programs provide backups for your safety. ***note: please do not activate Spybot TeaTimer until your computer is clean. Run Spybot first and reboot between the scans. It is good to run both programs at least twice, and run the "Full System Scan".

3) Ewido trojan scanner: http://www.ewido.net/en/download/
Please download, install, update and scan your system with the free version of Ewido trojan scanner:
  1. When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  2. When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  3. From the main ewido screen, click on update in the left menu, then click the Start update button.
  4. After the update finishes (the status bar at the bottom will display "Update successful"), click on the Scanner button in the left menu, then click on the Start button. This scan can take quite a while to run, so time to go get a drink and a snack….
  5. If ewido finds anything, it will pop up a notification. You can select "clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
  6. When the scan finishes, click on "Save Report". This will create a text file. Please then paste the contents of the text file to this thread.

  7. 4) Run CCleaner then post a new HJT log using version 1.99.1 along with the results of the Ewido scan. Also include any feedback you have for me.

    Thanks…pskelley
    TomCoyote forum
    Slyware Warrior
Hi pskelley,

I believe you helped me earlier this year to clen up my PC - nice to see a 'familiar' face!

From your advice, at that time I installed Spybot, Adaware and spyware blaster. I have tried to run these just about weekly (checking for updates each time).

I currenty have Adaware version 1.06 which I believe to be the latest. I did, however, only have version 1.3 Spybot - this has now been changed for the 1.4 version.

You pointed out that I should have made a note of what e-trust could not clean. Good Advice! I realised my error whilst awaiting a reply from the forum. I ran the scan again and pasted the info in to a word document. Here is the said information;

Finished scanning: 19:48:23, 21/06/2005
Number of files scanned: 139650.
Number of files that could not be scanned: 75
Number of archives containing infected files: 1
Number of infections: 4
Number of infected files not cleaned/deleted/renamed: 4
C:\Documents and Settings\Vicky\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv699.jar-6fa002f0-676c2f0d.zip>Matrix.class (Java.Shinwow.W trojan)
C:\Documents and Settings\Vicky\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv699.jar-6fa002f0-676c2f0d.zip>Counter.class (Java.ByteVerify!exploit trojan)
C:\Documents and Settings\Vicky\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv699.jar-6fa002f0-676c2f0d.zip>Dummy.class (Java.ByteVerify!exploit trojan)
C:\Documents and Settings\Vicky\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv699.jar-6fa002f0-676c2f0d.zip>Parser.class (Java.ByteVerify!exploit trojan)


Additionaly, whilst awaiting a reply from yourselves, I remember you had recommended running the Panda activescan to clear out bad stuff. So I ran the on line scan which seemed to disenfect the trojan files, but could not clean some other files. Thinking you may ask for this information, I again saved it and here it is;

Incident Status Location

Adware:Adware/SaveNow No disinfected Windows Registry
Adware:Adware/ExactSearch No disinfected C:\WINDOWS\system32\exul?.exe
Adware:Adware/Beginto No disinfected Windows Registry
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Vicky\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv699.jar-6fa002f0-676c2f0d.zip[Matrix.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Vicky\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv699.jar-6fa002f0-676c2f0d.zip[Counter.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Vicky\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv699.jar-6fa002f0-676c2f0d.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Vicky\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv699.jar-6fa002f0-676c2f0d.zip[Parser.class]
Adware:Adware/ExactSearch No disinfected C:\WINDOWS\system32\exul1.exe
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\msbe.dll_tobedeleted
I remember you telling me not to do anything I had not been instructed to do if I was receiving help from the forum. As I had not had a response at this time, I hope this is ok that I had a go at some stuff myself. (Only what I had learnt from your good self may I add!)

So, on to your instructions to me. I followed your list, however, got so wrapped up in updating stuff that I forgot to install CCleaner until the end (after I had updated and ran Spybot, adaware and ewido) Hope this does not cause a problem.

I ran CCleaner at the end as instructed. I left all the boxes on the main page (windows and applications) ticked as they seemed to default to. Is this right? Also, the download page said it would take seconds to run. It seemed to continuously. I stopped it after about 10 minutes, whereby it said it was complete - no files deleted.

Finally I am posting the latest HJT log (updated version of course!)

Logfile of HijackThis v1.99.1
Scan saved at 22:03:31, on 26/06/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
C:\Program Files\NuCam\CamCheck\CamCheck.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\LVComS.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\WINDOWS\twain_32\SiPix\SCBlink2\Srvany.exe
C:\WINDOWS\twain_32\SiPix\SCBlink2\USBPNP.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\isafe.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://www-cache.freeserve.com:8080;ftp=http://www-cache.freeserve.com:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;;localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VetTray] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
O4 - HKLM\..\Run: [CamCheck] C:\Program Files\NuCam\CamCheck\CamCheck.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-18.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Blink2PnP - Unknown owner - C:\WINDOWS\twain_32\SiPix\SCBlink2\Srvany.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\isafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe

So there we are. Hope I have done everything right. Apologies for the length of this post. I always prefer to give the full story when I'm not confident enough in what I am doing. That way the experts (that's you by the way!) can filter out the important stuff and ignore the rubbish.

Many thanks as always for your time and help.

Vicky x
Hi again So much to remember! Forgot to tell you that I downloaded and ran ewido with no problems. Here are the results; ——————————————————— ewido security suite - Scan report ——————————————————— + Created on: 21:49:22, 26/06/2005 + Report-Checksum: AEC1CBB8 + Date of database: 26/06/2005 + Version of scan engine: v3.0 + Duration: 51 min + Scanned Files: 112890 + Speed: 36.57 Files/Second + Infected files: 8 + Removed files: 8 + Files put in quarantine: 8 + Files that could not be opened: 0 + Files that could not be cleaned: 0 + Binder: Yes + Crypter: Yes + Archives: Yes + Scanned items: C:\ + Scan result: C:\Documents and Settings\Vicky\Cookies\[removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup C:\Documents and Settings\Vicky\Cookies\vicky@geocities[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup C:\Documents and Settings\Vicky\Cookies\[removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup C:\Documents and Settings\Vicky\Cookies\[removed]-cash[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup C:\Program Files\HJT\backups\backup-20050110-143417-905.dll -> Spyware.HotSearchBar.b -> Cleaned with backup C:\WINDOWS\system32\exul1.exe -> Spyware.Bargainbuddy -> Cleaned with backup C:\WINDOWS\system32\msbe.dll_tobedeleted -> Spyware.BargainBuddy.i -> Cleaned with backup C:\WINDOWS\system32\Sexy Girls-uninstall.exe -> Dialer.Generic -> Cleaned with backup ::Report End Sorry to add to an already excessively long reply. Thanks again, Vicky x
Hi Vicky, Nice to see you again. I could not see anything in the first HJT log, but your AV scan seemed to indicate something was present. That was the reason for making sure Ad-aware and Spybot were updated and run, and the Ewido scan. It is good that we have the other scans to look at also. The most recent HJT log is clean and the Ewido scan is also.

My e-trust EZ anti virus programme flashed up a message saying I had 28 infections and strongly recommended that I did a full scan.

I am interested in how the computer is running now? Let me ask a few questions.

1) You are running Avast, are you using the SP2 firewall and do you have your Windows Updates set to automatic? You can get this information from Start > Control Panel > Security Center. All three items should be on OK. You are also running if I am correct:
Spybot S&D V1.4
Ad-aware SE Personal V1.6
SpywareBlaster should be version 3.4
SpywareGuard
Have you considered IE-Spyad? Here is information, a tutorial with the download site. You do not see this program run, it knows the bad sites and blocks them in the registry.
IE-Spyad
http://www.bleepingcomputer.com/forums/tutorial53.html

2) Each of your programs like Ad-aware, etc. backup what they remove. Ad-aware quarantines files, Spybot has a feature called Recovery. You will want to empty those areas on a fairly regular basis as scans and perhaps Avast will see this junk as still being on the computer. Avast will also have a quarantine area somewhere that should be cleaned out. If you can locate it let me know and I will ask around.
We are doing our best, yet some malware is finding it's way into the computer. Let me give you a few links that might shine light on how this can happen, some of this information might be a repeat of what I gave you before. Better to view it twice than not at all:

http://whatis.techtarget.com/definition/0,…i887624,00.html
http://home.planet.nl/~kleyn080/Spywareinfoen.html
http://www.safecomputing.umn.edu/studentchecklist.html
http://windowssecrets.com/comp/050127/

3) CCleaner…they just released a new version. Did you make sure you updated. If you ran it correctly it will remove a lot of junk. I have a tutorial:

CCleaner is a small freeware program that cleans out temp folders, cookies, index.dat files, autocomplete, histories, MRU's(Most Recently Used lists), and a bunch of windows and program log files.

To use it:
Download CCleaner from http://www.ccleaner.com/ and install.
Open CCleaner.
Place a check by everything in the Applications tab.
Place a check by Internet Explorer, Windows explorer, and System in the Windows tab.
Hit the button that says Run CCleaner
Reboot to remove index.dat files.

CCleaner also has some other useful features:

Cookies: In CCleaner, you can customize which cookies to delete and which to keep, so you won't lose valuble logon information. To do so, open CCleaner, then go to Options>Cookies. Select the name of a website you logon to often (For example, forums.tomcoyote.org). Then, click the '–>' button so it's in the 'Cookies to keep' list. Repeat this for any other cookie you wish to keep. To place a cookie back on the 'Cookies to Remove' list, simply select the cookie and hit the '<–' button.

Uninstall manager: It's a tool to let you uninstall programs, and rename and delete uninstall entries.

It also has a forum here: http://forum.ccleaner.com/

Check for updates weekly, as new versions are released periodically

VIP: if you use the registry cleaner, you will get a prompt to back up the registry. I have had no issues with the software, but do follow those directions. I have been using it for around six months in almost every post and most folks sing it's praises.

4) Let's clean out all of those quarantine/recovery areas. I would normally even purge System Restore but none of the scans is showing anything there. Ewido always shows it if it is there. Run each of your adware scans and and clean with CCleaner. The run the computer a bit to see how it is running. Now update your AV and run a complete system scan, posting the results along with a new HJT log. I will keep this thread open until you have been able to accomplish this. Last thing to mention is that you should look at the items located by all three scans. Avast, Panda and Ewido. This will give you an idea of where the stuff may be coming from and it will also show you where cookies are hiding so you can clean them out. If you have any questions, post away. Thanks…Phil
Hi Phil Latest update; 1 - You mention in your last post about Avast. My anti virus is actually e-trust EZ anti-virus. I am awaiting the lastest update disc as I actually use the same one that my Husbands work use for their system. I will run a new scan when I have updated and post any results - this shoudl be within the next week. 2 - I did have IE spyad downloaded. However, it was just sat there and I hadn't actually merged the info!. I uninstalled it and loaded the latest version. It now seems to be holding a massive list in my restricted sites list. 3 - Had a good look through those links you gave me and googled a bit myself for info too. I read somewhere that under recent tests, that Webrooter and Giant are the best to have although even together they will catch only about half of the rubbish on your system. What's your opinion? Should I stick with what I've got and remain as vigilant as I can, or is it worth investing in this extra software? 4 - Read through all the CCleaner stuff and ran it. Worked perfectly! It seemed to clear out all the backup stuff from Spybot, ad-aware, e-trust etc. I have saved a text file but it's far to long to post here. 5 - PC is running well, although to be honest I didn't notice any huge fall in speed or performance before. 6 - Will post a HJT log once e-trust has been updated. Will also make sure spybot and ad-aware have done a recent scan before I run HJT. Thanks as always for your support. Vicky x
Hi Vicky, See you are in the UK, my friend Chris, who teaches here and helps too has started his own great forum on your side of the pond. You might want to pop in and take a look, great site: http://malwareremoval.com/ If you get a chance to say hi to Chris, tell him I sent you.

Covering your feedback in your same format:

1) My bad, I must have been seeing things :( or maybe too busy??

2) You will not see IE-Spyad working, uses no resources and does not run, but all of those items on that massive list can not access your registry. Update once in a while.

3) http://windowssecrets.com/comp/050127/
http://spywarewarrior.com/asw-test-guide.htm http://ralphcaddell.com/pchelp/spyware.htm There's lots more information if you need it. I like the free ones, the only paid security product I use is McAfee VSO. They let me run three computer and only charge me $20 a year (been with them a long time), otherwise I would use AVG by Grisoft which is freeware.
The links you reviewed will have covered the other freeware products.

4) CCleaner…be sure to backup like promoted if you use the registry cleaner.

5) :thumbup:

6) I will keep the post open for the last look at your HJT log. TC likes the posts closed when done for organizational reasons, so don't keep me waiting too long.

Safe surfing…Phil :wavey:
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI