This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

about:blank removal

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 7:05:22 PM, on 7/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
E:\APC\mainserv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
E:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
E:\Program Files\Norton System Works\Norton Antivirus\navapsvc.exe
E:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
E:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
E:\Program Files\Norton System Works\Norton Antivirus\SAVScan.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\qttask.exe
G:\Logitech\Mouse\MouseWare\system\em_exec.exe
C:\Program Files\Intel\Intel® Active Monitor\imontray.exe
E:\clone cd\CloneCDTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
E:\Program Files\Norton System Works\Password Manager\AcctMgr.exe
G:\Any DVD\AnyDVD\AnyDVD.exe
C:\WINDOWS\netev.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\WINDOWS\System32\svchost.exe
E:\Adobe Full\Distillr\acrotray.exe
E:\APC\apcsystray.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
I:\Remove About Blank Buddy\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\uwvad.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\uwvad.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\uwvad.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\uwvad.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\uwvad.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\uwvad.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\uwvad.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Adobe Full\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Adobe Full\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Program Files\Norton System Works\Norton Antivirus\NavShExt.dll
O2 - BHO: Class - {BEE4D4B4-B9F5-A799-6F43-FECDC7D512FE} - C:\WINDOWS\winur32.dll
O2 - BHO: Class - {D262910D-9F97-CA3A-15AA-9A5DEF559433} - C:\WINDOWS\d3sm32.dll
O2 - BHO: Class - {F52CB52B-6628-EA91-1D05-EFF204064C92} - C:\WINDOWS\system32\crvb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Program Files\Norton System Works\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Adobe Full\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SonicFocus] "C:\Program Files\Sonic Focus\SFIGUI\SFIGUI.EXE" BOOT
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QD FastAndSafe] E:\Program Files\Norton System Works\Norton CleanSweep\QDCSFS.exe /startup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IMONTRAY] C:\Program Files\Intel\Intel® Active Monitor\imontray.exe
O4 - HKLM\..\Run: [CloneCDTray] e:\clone cd\CloneCDTray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AcctMgr] E:\Program Files\Norton System Works\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [AnyDVD] G:\Any DVD\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [netev.exe] C:\WINDOWS\netev.exe
O4 - HKLM\..\RunOnce: [apiiv32.exe] C:\WINDOWS\system32\apiiv32.exe
O4 - HKLM\..\RunOnce: [syszx.exe] C:\WINDOWS\system32\syszx.exe
O4 - HKLM\..\RunOnce: [sdkez32.exe] C:\WINDOWS\sdkez32.exe
O4 - HKLM\..\RunOnce: [adduq.exe] C:\WINDOWS\adduq.exe
O4 - HKLM\..\RunOnce: [apirj32.exe] C:\WINDOWS\apirj32.exe
O4 - HKLM\..\RunOnce: [netcx.exe] C:\WINDOWS\netcx.exe
O4 - HKLM\..\RunOnce: [addir.exe] C:\WINDOWS\system32\addir.exe
O4 - HKLM\..\RunOnce: [netuj.exe] C:\WINDOWS\system32\netuj.exe
O4 - HKLM\..\RunOnce: [ipfw32.exe] C:\WINDOWS\ipfw32.exe
O4 - HKLM\..\RunOnce: [appky.exe] C:\WINDOWS\appky.exe
O4 - HKLM\..\RunOnce: [d3jy32.exe] C:\WINDOWS\d3jy32.exe
O4 - HKLM\..\RunOnce: [netpa.exe] C:\WINDOWS\netpa.exe
O4 - HKLM\..\RunOnce: [d3sm32.exe] C:\WINDOWS\d3sm32.exe
O4 - HKLM\..\RunOnce: [atlys32.exe] C:\WINDOWS\system32\atlys32.exe
O4 - HKLM\..\RunOnce: [ipoi32.exe] C:\WINDOWS\ipoi32.exe
O4 - HKLM\..\RunOnce: [appcc.exe] C:\WINDOWS\system32\appcc.exe
O4 - HKLM\..\RunOnce: [apimd.exe] C:\WINDOWS\apimd.exe
O4 - HKLM\..\RunOnce: [netsa.exe] C:\WINDOWS\system32\netsa.exe
O4 - HKLM\..\RunOnce: [winfu32.exe] C:\WINDOWS\system32\winfu32.exe
O4 - HKLM\..\RunOnce: [winur32.exe] C:\WINDOWS\winur32.exe
O4 - HKLM\..\RunOnce: [javazt.exe] C:\WINDOWS\system32\javazt.exe
O4 - HKLM\..\RunOnce: [javaqn32.exe] C:\WINDOWS\system32\javaqn32.exe
O4 - HKLM\..\RunOnce: [ntoq.exe] C:\WINDOWS\system32\ntoq.exe
O4 - HKLM\..\RunOnce: [atluk32.exe] C:\WINDOWS\system32\atluk32.exe
O4 - HKLM\..\RunOnce: [appnq32.exe] C:\WINDOWS\system32\appnq32.exe
O4 - HKLM\..\RunOnce: [msts.exe] C:\WINDOWS\system32\msts.exe
O4 - HKLM\..\RunOnce: [addxo32.exe] C:\WINDOWS\system32\addxo32.exe
O4 - HKLM\..\RunOnce: [d3cq.exe] C:\WINDOWS\d3cq.exe
O4 - HKLM\..\RunOnce: [iegx.exe] C:\WINDOWS\system32\iegx.exe
O4 - HKLM\..\RunOnce: [sdkmr32.exe] C:\WINDOWS\sdkmr32.exe
O4 - HKLM\..\RunOnce: [iphc.exe] C:\WINDOWS\iphc.exe
O4 - HKLM\..\RunOnce: [addux.exe] C:\WINDOWS\addux.exe
O4 - HKLM\..\RunOnce: [addgk32.exe] C:\WINDOWS\system32\addgk32.exe
O4 - HKLM\..\RunOnce: [d3tm32.exe] C:\WINDOWS\d3tm32.exe
O4 - HKLM\..\RunOnce: [sysyr.exe] C:\WINDOWS\sysyr.exe
O4 - HKLM\..\RunOnce: [crog.exe] C:\WINDOWS\system32\crog.exe
O4 - HKLM\..\RunOnce: [apita32.exe] C:\WINDOWS\system32\apita32.exe
O4 - HKLM\..\RunOnce: [netbi.exe] C:\WINDOWS\system32\netbi.exe
O4 - HKLM\..\RunOnce: [apicq.exe] C:\WINDOWS\apicq.exe
O4 - HKLM\..\RunOnce: [crzg32.exe] C:\WINDOWS\system32\crzg32.exe
O4 - HKLM\..\RunOnce: [iepn32.exe] C:\WINDOWS\system32\iepn32.exe
O4 - HKLM\..\RunOnce: [d3lr.exe] C:\WINDOWS\system32\d3lr.exe
O4 - HKLM\..\RunOnce: [ipkh32.exe] C:\WINDOWS\system32\ipkh32.exe
O4 - HKLM\..\RunOnce: [appiw.exe] C:\WINDOWS\appiw.exe
O4 - HKLM\..\RunOnce: [mshm32.exe] C:\WINDOWS\mshm32.exe
O4 - HKLM\..\RunOnce: [sdkxb32.exe] C:\WINDOWS\system32\sdkxb32.exe
O4 - HKLM\..\RunOnce: [msbd32.exe] C:\WINDOWS\msbd32.exe
O4 - HKLM\..\RunOnce: [mfcqs.exe] C:\WINDOWS\mfcqs.exe
O4 - HKLM\..\RunOnce: [netpa32.exe] C:\WINDOWS\system32\netpa32.exe
O4 - HKCU\..\Run: [Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID {DA9935BA-22F7-44ee-BD12-BD8B87700BEA}
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = E:\Adobe Full\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: APC UPS Status.lnk = E:\APC\Display.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MSOFFI~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4F5E4276-C120-11D6-A1FD-00508B9D48EA} (dldisplay Class) - http://www.gamehouse.com/ghdlctl.cab
O16 - DPF: {5DDF3BA5-7DCD-45A9-B4A1-601E67700271} (DDv4_Member.DDv4) - http://www.drivershq.com/cab/prod/DDv4_Member.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} (Personal System Administrator Control) - http://206.65.172.231/check/netset//install/gtdowngc.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O16 - DPF: {ED6D016A-12F8-4871-BEDC-CE13AAAB4F0B} (DD_v4_Member.DDv4) - http://www.drivershq.com/members/DD_v4_Member.CAB
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\adduq.exe" /s (file missing)
O23 - Service: APC UPS Service - American Power Conversion Corporation - E:\APC\mainserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: GhostStartService - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
O23 - Service: Intel® Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - E:\Program Files\Norton System Works\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - E:\Program Files\Norton System Works\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Speed Disk service - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Welcome to the forum.

Please read through the instructions before you start (you may want to print this out).

Please download and install these programs - don't run them yet!!

Please download and unzip
AboutBuster to a folder.
AboutBuster MUST be updated before you use it.
Check the AboutBuster Tutorial for instructions.
Don't run it yet.

Download and unzip cwsserviceremove to your desktop. use link below:
DownloadItHere

The above Registry file was written specifically for this infection and is not to be used on any other infection as it could damage a person's PC



Download CW-Shredder at the link below:
http://cwshredder.net/bin/CWShredder.exe

Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked.
Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

Reboot into SafeMode. <—MAKE SURE YOU KNOW HOW TO DO THIS!!

+++++++++++++++++++++++++++++++++++++++++++++++++

Here's the fix:

Important Step
1. Go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called:
Network Security Service

When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.

2. Reboot into Safe Mode

3. Press Ctrl+Alt+Delete once => Click Task Manager => Click the Processes tab => Double-click the Image Name column header to alphabetically sort the processes => Scroll through the list and look for:

netev.exe

If you find the files, click on them, and then click End Process => Exit the Task Manager.

4. CLOSE ALL WINDOWS AND BROWSERS Scan with Hijack This and put checks next to all the following, then click "Fix Checked"

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\uwvad.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\uwvad.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\uwvad.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\uwvad.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\uwvad.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\uwvad.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\uwvad.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {BEE4D4B4-B9F5-A799-6F43-FECDC7D512FE} - C:\WINDOWS\winur32.dll
O2 - BHO: Class - {D262910D-9F97-CA3A-15AA-9A5DEF559433} - C:\WINDOWS\d3sm32.dll
O2 - BHO: Class - {F52CB52B-6628-EA91-1D05-EFF204064C92} - C:\WINDOWS\system32\crvb.dll
O4 - HKLM\..\Run: [netev.exe] C:\WINDOWS\netev.exe
O4 - HKLM\..\RunOnce: [apiiv32.exe] C:\WINDOWS\system32\apiiv32.exe
O4 - HKLM\..\RunOnce: [syszx.exe] C:\WINDOWS\system32\syszx.exe
O4 - HKLM\..\RunOnce: [sdkez32.exe] C:\WINDOWS\sdkez32.exe
O4 - HKLM\..\RunOnce: [adduq.exe] C:\WINDOWS\adduq.exe
O4 - HKLM\..\RunOnce: [apirj32.exe] C:\WINDOWS\apirj32.exe
O4 - HKLM\..\RunOnce: [netcx.exe] C:\WINDOWS\netcx.exe
O4 - HKLM\..\RunOnce: [addir.exe] C:\WINDOWS\system32\addir.exe
O4 - HKLM\..\RunOnce: [netuj.exe] C:\WINDOWS\system32\netuj.exe
O4 - HKLM\..\RunOnce: [ipfw32.exe] C:\WINDOWS\ipfw32.exe
O4 - HKLM\..\RunOnce: [appky.exe] C:\WINDOWS\appky.exe
O4 - HKLM\..\RunOnce: [d3jy32.exe] C:\WINDOWS\d3jy32.exe
O4 - HKLM\..\RunOnce: [netpa.exe] C:\WINDOWS\netpa.exe
O4 - HKLM\..\RunOnce: [d3sm32.exe] C:\WINDOWS\d3sm32.exe
O4 - HKLM\..\RunOnce: [atlys32.exe] C:\WINDOWS\system32\atlys32.exe
O4 - HKLM\..\RunOnce: [ipoi32.exe] C:\WINDOWS\ipoi32.exe
O4 - HKLM\..\RunOnce: [appcc.exe] C:\WINDOWS\system32\appcc.exe
O4 - HKLM\..\RunOnce: [apimd.exe] C:\WINDOWS\apimd.exe
O4 - HKLM\..\RunOnce: [netsa.exe] C:\WINDOWS\system32\netsa.exe
O4 - HKLM\..\RunOnce: [winfu32.exe] C:\WINDOWS\system32\winfu32.exe
O4 - HKLM\..\RunOnce: [winur32.exe] C:\WINDOWS\winur32.exe
O4 - HKLM\..\RunOnce: [javazt.exe] C:\WINDOWS\system32\javazt.exe
O4 - HKLM\..\RunOnce: [javaqn32.exe] C:\WINDOWS\system32\javaqn32.exe
O4 - HKLM\..\RunOnce: [ntoq.exe] C:\WINDOWS\system32\ntoq.exe
O4 - HKLM\..\RunOnce: [atluk32.exe] C:\WINDOWS\system32\atluk32.exe
O4 - HKLM\..\RunOnce: [appnq32.exe] C:\WINDOWS\system32\appnq32.exe
O4 - HKLM\..\RunOnce: [msts.exe] C:\WINDOWS\system32\msts.exe
O4 - HKLM\..\RunOnce: [addxo32.exe] C:\WINDOWS\system32\addxo32.exe
O4 - HKLM\..\RunOnce: [d3cq.exe] C:\WINDOWS\d3cq.exe
O4 - HKLM\..\RunOnce: [iegx.exe] C:\WINDOWS\system32\iegx.exe
O4 - HKLM\..\RunOnce: [sdkmr32.exe] C:\WINDOWS\sdkmr32.exe
O4 - HKLM\..\RunOnce: [iphc.exe] C:\WINDOWS\iphc.exe
O4 - HKLM\..\RunOnce: [addux.exe] C:\WINDOWS\addux.exe
O4 - HKLM\..\RunOnce: [addgk32.exe] C:\WINDOWS\system32\addgk32.exe
O4 - HKLM\..\RunOnce: [d3tm32.exe] C:\WINDOWS\d3tm32.exe
O4 - HKLM\..\RunOnce: [sysyr.exe] C:\WINDOWS\sysyr.exe
O4 - HKLM\..\RunOnce: [crog.exe] C:\WINDOWS\system32\crog.exe
O4 - HKLM\..\RunOnce: [apita32.exe] C:\WINDOWS\system32\apita32.exe
O4 - HKLM\..\RunOnce: [netbi.exe] C:\WINDOWS\system32\netbi.exe
O4 - HKLM\..\RunOnce: [apicq.exe] C:\WINDOWS\apicq.exe
O4 - HKLM\..\RunOnce: [crzg32.exe] C:\WINDOWS\system32\crzg32.exe
O4 - HKLM\..\RunOnce: [iepn32.exe] C:\WINDOWS\system32\iepn32.exe
O4 - HKLM\..\RunOnce: [d3lr.exe] C:\WINDOWS\system32\d3lr.exe
O4 - HKLM\..\RunOnce: [ipkh32.exe] C:\WINDOWS\system32\ipkh32.exe
O4 - HKLM\..\RunOnce: [appiw.exe] C:\WINDOWS\appiw.exe
O4 - HKLM\..\RunOnce: [mshm32.exe] C:\WINDOWS\mshm32.exe
O4 - HKLM\..\RunOnce: [sdkxb32.exe] C:\WINDOWS\system32\sdkxb32.exe
O4 - HKLM\..\RunOnce: [msbd32.exe] C:\WINDOWS\msbd32.exe
O4 - HKLM\..\RunOnce: [mfcqs.exe] C:\WINDOWS\mfcqs.exe
O4 - HKLM\..\RunOnce: [netpa32.exe] C:\WINDOWS\system32\netpa32.exe
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\adduq.exe" /s (file missing)

Click on Fix Checked and exit HijackThis.


5. SKIP THIS STEP


6. Run AboutBuster . This will scan your computer for the bad files and delete them. It will ask to scan the system again, let it. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

7. Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin

8. Double click on the cwsserviceremove and when asked to merge say yes.

9. Run CW-Shredder - Hit the FIX button - let it run and fix what it finds.

10. Reboot into normal mode.

11. Download and run this online virus scan:<—Important
http://housecall.trendmicro.com/housecall/start_corp.asp
Make sure you check "AutoClean"

12. Reboot and post a fresh HJT log back here by using the add reply button below, and lets see how we did, MrC
Thank you for the directions, they were very good. I completed them with only a few problems. This is the latest Hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 8:14:12 PM, on 7/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
E:\APC\mainserv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
E:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
E:\Program Files\Norton System Works\Norton Antivirus\navapsvc.exe
E:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
E:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\mqtgsvc.exe
E:\Program Files\Norton System Works\Norton Antivirus\SAVScan.exe
C:\WINDOWS\ntpr.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\qttask.exe
G:\Logitech\Mouse\MouseWare\system\em_exec.exe
C:\Program Files\Intel\Intel® Active Monitor\imontray.exe
E:\clone cd\CloneCDTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
G:\Any DVD\AnyDVD\AnyDVD.exe
C:\WINDOWS\netev.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
E:\Adobe Full\Distillr\acrotray.exe
C:\WINDOWS\System32\svchost.exe
E:\APC\apcsystray.exe
C:\WINDOWS\system32\wuauclt.exe
I:\Spyware Removers\HijackThis.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\fswvn.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.news-journalonline.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\fswvn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\fswvn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\fswvn.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\fswvn.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Adobe Full\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {13BDAC8B-1A3C-6F50-5113-67600907C445} - C:\WINDOWS\system32\ipvo32.dll
O2 - BHO: Class - {A4571542-A194-3710-8763-F3C447885424} - C:\WINDOWS\netxz.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Adobe Full\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Program Files\Norton System Works\Norton Antivirus\NavShExt.dll
O2 - BHO: Class - {C74EE4E0-7821-6A4A-65E2-38C5FEA0CDEB} - C:\WINDOWS\system32\javaru.dll
O2 - BHO: Class - {FEF27C0E-F323-983C-7373-F21C8EF035DF} - C:\WINDOWS\system32\javagj.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Program Files\Norton System Works\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Adobe Full\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SonicFocus] "C:\Program Files\Sonic Focus\SFIGUI\SFIGUI.EXE" BOOT
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QD FastAndSafe] E:\Program Files\Norton System Works\Norton CleanSweep\QDCSFS.exe /startup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IMONTRAY] C:\Program Files\Intel\Intel® Active Monitor\imontray.exe
O4 - HKLM\..\Run: [CloneCDTray] e:\clone cd\CloneCDTray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AcctMgr] E:\Program Files\Norton System Works\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [AnyDVD] "G:\Any DVD\AnyDVD\AnyDVD.exe"
O4 - HKLM\..\Run: [netev.exe] C:\WINDOWS\netev.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\RunOnce: [apiiv32.exe] C:\WINDOWS\system32\apiiv32.exe
O4 - HKLM\..\RunOnce: [ntpr.exe] C:\WINDOWS\ntpr.exe
O4 - HKCU\..\Run: [Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID {DA9935BA-22F7-44ee-BD12-BD8B87700BEA}
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Global Startup: Acrobat Assistant.lnk = E:\Adobe Full\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: APC UPS Status.lnk = E:\APC\Display.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MSOFFI~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4F5E4276-C120-11D6-A1FD-00508B9D48EA} (dldisplay Class) - http://www.gamehouse.com/ghdlctl.cab
O16 - DPF: {5DDF3BA5-7DCD-45A9-B4A1-601E67700271} (DDv4_Member.DDv4) - http://www.drivershq.com/cab/prod/DDv4_Member.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} (Personal System Administrator Control) - http://206.65.172.231/check/netset//install/gtdowngc.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O16 - DPF: {ED6D016A-12F8-4871-BEDC-CE13AAAB4F0B} (DD_v4_Member.DDv4) - http://www.drivershq.com/members/DD_v4_Member.CAB
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\apiiv32.exe" /s (file missing)
O23 - Service: APC UPS Service - American Power Conversion Corporation - E:\APC\mainserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: GhostStartService - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
O23 - Service: Intel® Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - E:\Program Files\Norton System Works\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - E:\Program Files\Norton System Works\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Speed Disk service - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
It's still there but we'll get it.

Do this in regular mode this time.
Also download a fresh copy of cwsserviceremove (delete the old one):

Download and unzip cwsserviceremove to your desktop. use link below:
DownloadItHere


Press Control-Alt-Del to enter the Task Manager.
Click on the Processes tab and end the following processes if listed:

ntpr.exe
netev.exe

Exit the Task Manager when finished

Close ALL programs down, leaving ONLY HijackThis running.
Place a check against the following items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\fswvn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\fswvn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\fswvn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\fswvn.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\fswvn.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {13BDAC8B-1A3C-6F50-5113-67600907C445} - C:\WINDOWS\system32\ipvo32.dll
O2 - BHO: Class - {A4571542-A194-3710-8763-F3C447885424} - C:\WINDOWS\netxz.dll
O2 - BHO: Class - {C74EE4E0-7821-6A4A-65E2-38C5FEA0CDEB} - C:\WINDOWS\system32\javaru.dll
O2 - BHO: Class - {FEF27C0E-F323-983C-7373-F21C8EF035DF} - C:\WINDOWS\system32\javagj.dll
O4 - HKLM\..\Run: [netev.exe] C:\WINDOWS\netev.exe
O4 - HKLM\..\RunOnce: [apiiv32.exe] C:\WINDOWS\system32\apiiv32.exe
O4 - HKLM\..\RunOnce: [ntpr.exe] C:\WINDOWS\ntpr.exe
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\apiiv32.exe" /s (file missing)

Click on Fix Checked and exit HijackThis.

Delete these files if found:


C:\WINDOWS\netxz.dll <—typical
C:\WINDOWS\ntpr.exe
C:\WINDOWS\netev.exe
C:\WINDOWS\fswvn.dll
C:\WINDOWS\system32\apiiv32.exe
C:\WINDOWS\system32\javagj.dll
C:\WINDOWS\system32\javaru.dll
C:\WINDOWS\system32\ipvo32.dll

(and any other files with the same name that end in .dll, .exe or .dat, you may find them right next to each other, example - appsw.exe, appsw.dll, appsw.dat)
If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.

Run AboutBuster

Double click on the cwsserviceremove and when asked to merge say yes.

Run CW-Shredder - Hit the FIX button - let it run and fix what it finds.


Reboot and post a fresh HijackThis log and we'll take another look. MrC
Ran it a couple times to make sure I got it all. Noticed that "Network Security Service" came up, went back to the first instructions and did it again. Here is the latest. Regards Al
Logfile of HijackThis v1.99.1
Scan saved at 9:52:14 AM, on 7/17/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
E:\APC\mainserv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
E:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
E:\Program Files\Norton System Works\Norton Antivirus\navapsvc.exe
E:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
E:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
E:\Program Files\Norton System Works\Norton Antivirus\SAVScan.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Intel\Intel® Active Monitor\imontray.exe
E:\clone cd\CloneCDTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
G:\Any DVD\AnyDVD\AnyDVD.exe
C:\WINDOWS\ipsl.exe
C:\WINDOWS\system32\ctfmon.exe
E:\Adobe Full\Distillr\acrotray.exe
G:\Logitech\Mouse\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\wuauclt.exe
E:\APC\apcsystray.exe
I:\Spyware Removers\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.news-journalonline.com/
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Adobe Full\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {072E058D-3046-1956-68F1-D9BA95C696E9} - C:\WINDOWS\system32\sdkiy.dll
O2 - BHO: Class - {34AA49E4-4ACB-EE28-1C88-D1ECE6822FF6} - C:\WINDOWS\system32\ntgx.dll
O2 - BHO: Class - {84726F98-05BE-A8F9-2D6E-FA2D7F559343} - C:\WINDOWS\ipsl.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Adobe Full\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Program Files\Norton System Works\Norton Antivirus\NavShExt.dll
O2 - BHO: Class - {DF77D786-7899-DE17-AC07-FBA8FA5E3372} - C:\WINDOWS\netab.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Program Files\Norton System Works\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Adobe Full\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SonicFocus] "C:\Program Files\Sonic Focus\SFIGUI\SFIGUI.EXE" BOOT
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QD FastAndSafe] E:\Program Files\Norton System Works\Norton CleanSweep\QDCSFS.exe /startup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IMONTRAY] C:\Program Files\Intel\Intel® Active Monitor\imontray.exe
O4 - HKLM\..\Run: [CloneCDTray] e:\clone cd\CloneCDTray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AcctMgr] E:\Program Files\Norton System Works\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [AnyDVD] G:\Any DVD\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [ipsl.exe] C:\WINDOWS\ipsl.exe
O4 - HKLM\..\Run: [sdkiy.exe] C:\WINDOWS\system32\sdkiy.exe
O4 - HKLM\..\RunOnce: [sysoa.exe] C:\WINDOWS\sysoa.exe
O4 - HKLM\..\RunOnce: [sysew.exe] C:\WINDOWS\sysew.exe
O4 - HKLM\..\RunOnce: [crrs32.exe] C:\WINDOWS\system32\crrs32.exe
O4 - HKLM\..\RunOnce: [ipkr32.exe] C:\WINDOWS\system32\ipkr32.exe
O4 - HKCU\..\Run: [Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID {DA9935BA-22F7-44ee-BD12-BD8B87700BEA}
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = E:\Adobe Full\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: APC UPS Status.lnk = E:\APC\Display.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MSOFFI~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4F5E4276-C120-11D6-A1FD-00508B9D48EA} (dldisplay Class) - http://www.gamehouse.com/ghdlctl.cab
O16 - DPF: {5DDF3BA5-7DCD-45A9-B4A1-601E67700271} (DDv4_Member.DDv4) - http://www.drivershq.com/cab/prod/DDv4_Member.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} (Personal System Administrator Control) - http://206.65.172.231/check/netset//install/gtdowngc.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O16 - DPF: {ED6D016A-12F8-4871-BEDC-CE13AAAB4F0B} (DD_v4_Member.DDv4) - http://www.drivershq.com/members/DD_v4_Member.CAB
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\sysoa.exe" /s (file missing)
O23 - Service: APC UPS Service - American Power Conversion Corporation - E:\APC\mainserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GhostStartService - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
O23 - Service: Intel® Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - E:\Program Files\Norton System Works\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - E:\Program Files\Norton System Works\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Speed Disk service - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Lets try it again.

Reboot into safemode.

1. Go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called:
Remote Procedure Call (RPC) Helper

When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.


Press Control-Alt-Del to enter the Task Manager.
Click on the Processes tab and end the following processes if listed:

ipsl.exe

Exit the Task Manager when finished

Close ALL programs down, leaving ONLY HijackThis running.
Place a check against the following items:

R3 - Default URLSearchHook is missing
O2 - BHO: Class - {072E058D-3046-1956-68F1-D9BA95C696E9} - C:\WINDOWS\system32\sdkiy.dll
O2 - BHO: Class - {34AA49E4-4ACB-EE28-1C88-D1ECE6822FF6} - C:\WINDOWS\system32\ntgx.dll
O2 - BHO: Class - {84726F98-05BE-A8F9-2D6E-FA2D7F559343} - C:\WINDOWS\ipsl.dll
O2 - BHO: Class - {DF77D786-7899-DE17-AC07-FBA8FA5E3372} - C:\WINDOWS\netab.dll
O4 - HKLM\..\Run: [ipsl.exe] C:\WINDOWS\ipsl.exe
O4 - HKLM\..\Run: [sdkiy.exe] C:\WINDOWS\system32\sdkiy.exe
O4 - HKLM\..\RunOnce: [sysoa.exe] C:\WINDOWS\sysoa.exe
O4 - HKLM\..\RunOnce: [sysew.exe] C:\WINDOWS\sysew.exe
O4 - HKLM\..\RunOnce: [crrs32.exe] C:\WINDOWS\system32\crrs32.exe
O4 - HKLM\..\RunOnce: [ipkr32.exe] C:\WINDOWS\system32\ipkr32.exe
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\sysoa.exe" /s (file missing)

Click on Fix Checked and exit HijackThis.

Delete these files:

C:\WINDOWS\sysoa.exe <—typical
C:\WINDOWS\system32\sdkiy.dll
C:\WINDOWS\system32\ntgx.dll
C:\WINDOWS\ipsl.dll
C:\WINDOWS\netab.dll
C:\WINDOWS\ipsl.exe
C:\WINDOWS\system32\sdkiy.exe
C:\WINDOWS\sysoa.exe
C:\WINDOWS\sysew.exe
C:\WINDOWS\system32\crrs32.exe
C:\WINDOWS\system32\ipkr32.exe

Make sure you get the next step right

Double click on the cwsserviceremove and when asked to merge say yes.

Run AboutBuster

Run the Shredder

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin

Reboot into normal mode.

Download and run this online virus scan:<—Important
http://housecall.trendmicro.com/housecall/start_corp.asp
Make sure you check "AutoClean"

Reboot and post a fresh HJT log back here by using the add reply button below, and lets see how we did, MrC
Maybe? Finally got into Housecall (IE problems). Spent most of the day deleting files. Tks AL

Logfile of HijackThis v1.99.1
Scan saved at 9:45:14 PM, on 7/17/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
E:\APC\mainserv.exe
G:\Logitech\Mouse\MouseWare\system\em_exec.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Intel\Intel® Active Monitor\imontray.exe
E:\clone cd\CloneCDTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
G:\Any DVD\AnyDVD\AnyDVD.exe
C:\WINDOWS\system32\ctfmon.exe
E:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
E:\Program Files\Norton System Works\Norton Antivirus\navapsvc.exe
E:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
E:\Adobe Full\Distillr\acrotray.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
E:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
E:\APC\apcsystray.exe
E:\Program Files\Norton System Works\Norton Antivirus\SAVScan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\WINDOWS\system32\wuauclt.exe
I:\Spyware Removers\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.news-journalonline.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Adobe Full\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Adobe Full\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Program Files\Norton System Works\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Program Files\Norton System Works\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Adobe Full\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SonicFocus] "C:\Program Files\Sonic Focus\SFIGUI\SFIGUI.EXE" BOOT
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QD FastAndSafe] E:\Program Files\Norton System Works\Norton CleanSweep\QDCSFS.exe /startup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IMONTRAY] C:\Program Files\Intel\Intel® Active Monitor\imontray.exe
O4 - HKLM\..\Run: [CloneCDTray] e:\clone cd\CloneCDTray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AcctMgr] E:\Program Files\Norton System Works\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [AnyDVD] G:\Any DVD\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID {DA9935BA-22F7-44ee-BD12-BD8B87700BEA}
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = E:\Adobe Full\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: APC UPS Status.lnk = E:\APC\Display.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MSOFFI~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {5DDF3BA5-7DCD-45A9-B4A1-601E67700271} (DDv4_Member.DDv4) - http://www.drivershq.com/cab/prod/DDv4_Member.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} (Personal System Administrator Control) - http://206.65.172.231/check/netset//install/gtdowngc.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O16 - DPF: {ED6D016A-12F8-4871-BEDC-CE13AAAB4F0B} (DD_v4_Member.DDv4) - http://www.drivershq.com/members/DD_v4_Member.CAB
O23 - Service: APC UPS Service - American Power Conversion Corporation - E:\APC\mainserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GhostStartService - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
O23 - Service: Intel® Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - E:\Program Files\Norton System Works\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - E:\Program Files\Norton System Works\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Speed Disk service - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
YES! Well Done :thumbup: It's Gone :)

Just clean this one up:

Close ALL programs down, leaving ONLY HijackThis running.
Place a check against the following items:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

Click on Fix Checked and exit HijackThis.

Open up Internet Explorer , Tools, General Tab, reset your home page to what you want, now the Programs Tab, click Reset Web Settings
That will change everything back to the default settings.

If you have any questions please post back.



I'll leave you with……..

Some preventive maintenance:

——————Must have or do:—————–

Now that you're clean: <—-Important Step!!!!
Delete your system restore files and create a new restore point:
(ME and XP users only)

XP system restore

ME system restore


Visit Windows Update and install all the lastest critical updates.

Install these two free programs, they sit in the backround and protect your system from spy and adware being installed on your system, also from your browser being hijacked. Check for updates weekly.

SpywareBlaster

SpywareGuard


IE-SPYAD
Puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
IE-SPYAD

SpyBot has some protection benefits - use them.

Need a free anti virus?
AVG*free
(check for updates - daily)

How about a firewall? The front door to your computer.
ZoneAlarm*free



———-Free malware removal programs:———-

SpyBot
AD-Aware
CW-Shredder

Free Online Trojan Scan

A SQUARED FREE TROJAN SCANNER

Trojan Hunter
TrojanHunter - free trial

Please consider using FireFox instead of Internet Explorer

Replace Java with SunJava

Pop-up stoppers:
GoogleToolBar
Pop-upStopperFree

Disable Windows MessengerXP - 2K (stops pop-up ads -etc):
Disabling Messenger Service in Windows XP
How to Remove Windows Messenger on Windows XP
How to Remove Windows Messenger on Windows XP
Shoot The Messenger


Don't open e-mail attachments without first scanning them with an up-to-date
anti virus program, even after doing that I would be very careful. Don't click on any executables in e-mails or any other links that you're not sure of.
Watch your surfing habits, don't click on or download anything you're not sure of. Don't install a program that hasn't been recommended by a reputable organization.

Good luck and thanks for using the forum - MrC
:wavey:
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI