This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I think this is malware - Do I delete?

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Recently I have been having a few niggling problems with my Toshiba Notebook, running XP Home SP1 with regular updates. Thinking of updating to SP2 but for the loaded HDD and the niggling problems which I'd put down to program conflicts and incomplete uninstalls clogging the registry.

Mostly just unexpected program crashes or non-starts. Worst issue is the Taskmanager not coming up in full configuration - only the running processes tab showing. Restricts a number of admin tasks.

A few days ago when I ran a full scan on NAV (current version fully updated) it found 2 viruses on 3 files. Unusual but not an issue. Most commonly, even with connection to an ASDL LAN, viruses and malware seem to be found by NAV, MS AntiSpyware and Spybot as it arrives or on already deleted Spam emails or regularly deleted Temp Ineternet files.

Anyway ran NAV under safe mode and showed it clean. Both Spybot and MS AntiSpyware showed as clean. Then ran Hijack This which found a few dubious entries. A net search suggested I still definitely have a malware problem.

Did a Trend Micro online scan to find 3 virus and 3 spyware infections. Trend Micro service indicated they deleted all except a cookie which I have since blocked. (Computer set to no cookies with only designated exceptions)

After that I did a Hijack This log in safe mode to get the file copied below.

Some of my concerns have gone but 2 registry entries I had deleted have returned.

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
is Webshots which I do not want running

O2 - BHO: (no name) - {4401FDC3-7996-4774-8D2B-C1AE9CD6CC25} - (no file)
DEFINITELY appears to be malware

I deleted both these files previously (not in safe mode)

Can I just delete these in Safe Mode or do I need to do something more significant?

The last entry
Files\TOSHIBA\TME3\Tmesbs32.exe" /Service (file missing)

shows a file missing and yet the folder appears to be OK, is this likely to be a problem?

BTW TaskManager still is not operating correctly…

Thanks for any advice and help you can give

YvonneG.








Logfile of HijackThis v1.99.1
Scan saved at 1:59:25 PM, on 01/08/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\ACD Systems\IDBSvr.exe
C:\Program Files\Adware -BHO removers\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://hotmail.com
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com");

(C:\Documents and Settings\Admin\Application

Data\Mozilla\Profiles\default\ypdjx1of.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine",

"engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSB

Web_01.src"); (C:\Documents and Settings\Admin\Application

Data\Mozilla\Profiles\default\ypdjx1of.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4401FDC3-7996-4774-8D2B-C1AE9CD6CC25} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -

C:\PROGRA~1\ADWARE~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} -

C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -

C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TFncKy] C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe

/Type 28
O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless

Hotkey\TosHKCW.exe"
O4 - HKLM\..\Run: [TMESBS.EXE] C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE

/Client
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Adware -BHO removers\Microsoft

Antispyware\gcasServ.exe"
O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec

Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Adware -BHO

removers\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco

Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft

Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download using Download &Express -

file://C:\Program Files\Download Express\Add_Url.htm
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -

C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links -

{c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\MSMSGS.EXE
O16 - DPF: webiress - http://web.iress.com.au/webiress-0_8_3_4.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -

http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {11B2C0D3-DFFB-11D3-9253-00500498D7E3} (ShowSetupObj3 Class) -

http://invite.mshow.com/ShowSetup.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine

Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=36467&clcid;=0x409
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} -
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} -
O16 - DPF: {FD18DD5E-B398-452A-B22A-B54636BA9F0D} (Aurigma Image Uploader

2.5) - http://www.getjealous.com/ImageUploader2.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. -

C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec

Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. -

C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: GhostStartService - Symantec Corporation -

C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
O23 - Service: InterBase Guardian (InterBaseGuardian) - Inprise Corporation -

c:\program files\Interbase\bin\ibguard.exe
O23 - Service: InterBase Server (InterBaseServer) - Inprise Corporation - c:\program

files\Interbase\bin\ibserver.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program

Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation -

C:\Program Files\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec

AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog

Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program Files\Speed

Disk\nopdb.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program

Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Tmesbs32 (Tmesbs) - Unknown owner - C:\Program

Files\TOSHIBA\TME3\Tmesbs32.exe" /Service (file missing)
I went back to Trend Micro and did a SpyWare Check only. It found some additional spyware which I have deleted, then did another Hijack This log, this time without restarting and not in safe mode. The log was no change. One of the main issues I am concerned about is the file (folders?) in the Downloaded Program Files named: {556DDE35-E955-11D0-A707-000000521957} This appears to be related to the SmithFraud which affects admin capabilities. But nothing is picking this up anywhere else. I am thinking of installing a second antivirus/ antispyware program. Choosing between PC-Cillin, Panda and Kaspersky. Trend Micro would make the most sense, but they haven't detected this one if that is the problem. I think most of the others are leftovers - like Webshots which I don't want and a PDF Flipalbum capability where the relevant file has been deleted already. Thanks for any advice as to whether this is a SmithFraud attack YvonneG.
:rofl: I will post to the "Over 5 days without a reply forum!" to indicate I have added the following details. I still have no MAJOR probems with my computer. Just a little slow in starting programs, only partial use of the TaskManager, and occassional inexplicable hangs in some programs - particularly notebook. However some entries on my log definitely appear to be related to spyware etc. I have updated my version of SpyBot to 1.4 and rerun. It still indicates a "Clean" computer. My version of MS AntiSpyware has just expired, although I can rund by changing the date. It shows nothing. I ran the "Spyware/Adware only" online scan on Trend Micro. It found numerous problems which it indicated it had removed. (Arrived since previous scan?). Running HiJack This again showed an unaltered log. I I reinstalled AdAware 6, but it may be an old version as it does not appear to be updating correctly. THE RESULTS WERE: Started registry scan ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ Alexa Object recognized! Type : RegKey Data : Rootkey : HKEY_LOCAL_MACHINE Object : SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} It since showed no infections. I downloaded ewido as recommended on other posts. I ran it under normal operating system and it identified the following: (Log posted) ——————————————————— ewido security suite - Scan report ——————————————————— + Created on: 2:42:19 PM, 06/08/2005 + Report-Checksum: D648A7AA + Scan result: HKLM\SOFTWARE\Classes\Interface\{8C505A6B-124B-4768-8FD3-1A066C839848} -> Spyware.BlazeFind : Cleaned with backup HKLM\SOFTWARE\Classes\TypeLib\{0B3569D7-1EA4-4CBA-AC13-225902619789} -> Spyware.BlazeFind : Cleaned with backup HKLM\SOFTWARE\Classes\TypeLib\{B000D07B-6877-4D37-B6B2-BB800504ADE1} -> Dialer.Generic : Cleaned with backup HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\nCASE -> Spyware.180Solutions : Cleaned with backup HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4401FDC3-7996-4774-8D2B-C1AE9CD6CC25} -> Spyware.E-booksystems : Cleaned with backup C:\Documents and Settings\Admin\Local Settings\Application Data\Wildtangent\Cdacache\00\00\0F.dat/files\wtvh.dll -> Spyware.WildTangent : Cleaned with backup C:\Program Files\Netscape\Netscape\Plugins\npwthost.dll -> Spyware.WildTangent : Cleaned with backup C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1015.dll -> Spyware.Browsertoolbar : Cleaned with backup C:\WINDOWS\Downloaded Program Files\HDPlugin1015.dll -> Spyware.Browsertoolbar : Cleaned with backup C:\WINDOWS\system32\axuninstall.exe -> Spyware.BlazeFind : Cleaned with backup ::Report End I then ran ewido again in safe mode (with all hidden files shown). The same files showed in the Norton's Recycle bin I think!!!!!! (Ewido log posted) ——————————————————— ewido security suite - Scan report ——————————————————— + Created on: 3:54:17 PM, 06/08/2005 + Report-Checksum: EE23893F + Scan result: C:\RECYCLER\NPROTECT\00016366.dat/files\wtvh.dll -> Spyware.WildTangent : Cleaned with backup C:\RECYCLER\NPROTECT\00016367.dll -> Spyware.WildTangent : Cleaned with backup C:\RECYCLER\NPROTECT\00016368.DLL -> Spyware.Browsertoolbar : Cleaned with backup C:\RECYCLER\NPROTECT\00016369.DLL -> Spyware.Browsertoolbar : Cleaned with backup C:\RECYCLER\NPROTECT\00016370.EXE -> Spyware.BlazeFind : Cleaned with backup ::Report End I then ran Hijack This in safe mode: Though there are different registry entries, there still appear to be the same worrisome registry entries relating to webshots which I have asked repeated to be deleted and x-boot? i.e. NOTE: O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} - AND O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - These appear to recur in various guises even after I delete them. Is there something more I need to do other than just delete them? BTW notepad is still constantly closing unexpectedly and the Taskmanager is still not operating fully. E.g. First time in safe mode it didn't appear to boot fully and Windows Explorere went into a hang when I went to Start/Programs. I could not restart from TaskManager. I had to use the Power key to reboot. WinDoctor found one ActiveX registry problem which has been fixed prior to starting in safe mode. But the operation of the laptop has not changed. Thankyou very much for any advice you can give me. Yvonne
Sorry, I forgot to add the HJT log. It follows. From safe mode:


Logfile of HijackThis v1.99.1
Scan saved at 4:02:05 PM, on 06/08/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adware -BHO removers\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://hotmail.com
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com");

(C:\Documents and Settings\Admin\Application

Data\Mozilla\Profiles\default\ypdjx1of.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine",

"engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSB

Web_01.src"); (C:\Documents and Settings\Admin\Application

Data\Mozilla\Profiles\default\ypdjx1of.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -

C:\PROGRA~1\ADWARE~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} -

C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -

C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TFncKy] C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe

/Type 28
O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless

Hotkey\TosHKCW.exe"
O4 - HKLM\..\Run: [TMESBS.EXE] C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE

/Client
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Adware -BHO removers\Microsoft

Antispyware\gcasServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec

Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco

Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft

Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download using Download &Express -

file://C:\Program Files\Download Express\Add_Url.htm
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\MSMSGS.EXE
O16 - DPF: webiress - http://web.iress.com.au/webiress-0_8_3_4.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -

http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {11B2C0D3-DFFB-11D3-9253-00500498D7E3} (ShowSetupObj3 Class) -

http://invite.mshow.com/ShowSetup.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine

Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=36467&clcid;=0x409
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} -
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} -
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.5.0_02) -
O16 - DPF: {FD18DD5E-B398-452A-B22A-B54636BA9F0D} (Aurigma Image Uploader

2.5) - http://www.getjealous.com/ImageUploader2.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. -

C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec

Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. -

C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program

Files\Adware -BHO removers\ewido security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program

Files\Adware -BHO removers\ewido security suite\ewidoguard.exe
O23 - Service: GhostStartService - Symantec Corporation -

C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
O23 - Service: InterBase Guardian (InterBaseGuardian) - Inprise Corporation -

c:\program files\Interbase\bin\ibguard.exe
O23 - Service: InterBase Server (InterBaseServer) - Inprise Corporation - c:\program

files\Interbase\bin\ibserver.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program

Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation -

C:\Program Files\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec

AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog

Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program Files\Speed

Disk\nopdb.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program

Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Tmesbs32 (Tmesbs) - Unknown owner - C:\Program

Files\TOSHIBA\TME3\Tmesbs32.exe" /Service (file missing)
UPDATE:

I ran an online Panda Scan while in SAFE mode.
Here is the result:

Incident Status Location

Adware:Adware/BlazeFind No disinfected
C:\Documents and Settings\Admin\Local Settings\Temp\bar.exe
Spyware:Spyware/BetterInet No disinfected
C:\Documents and Settings\Admin\Local Settings\Temp\bi.exe
Dialer:dialer.asl No disinfected
C:\WINDOWS\Downloaded Program Files\internazionale_ver10.INF
Adware:adware/gator No disinfected
C:\WINDOWS\GatorHDPlugin.log-old.log

While still in safe mode I deleted bar.exe, bi.exe and GatorHDPlugin.log-old.log
But the file internzionale_ver10.INF did not exist in the Windows DPF file.
However there was a suspicious file labeled: {9F1C11AA-197B-4942-BA54-47A8489BB47F} status: unknown
I checked its properties which were as follows:
File Name:

{9F1C11AA-197B-4942-BA54-47A8489BB47F}
Status: Unknown
PROPERTIES:
ActiveX Control Created 1/6/03 Accessed 8/6/05
ID: {9F1C11AA-197B-4942-BA54-47A8489BB47F}
Version 5,4,3790,14

Dependency

C:\WINDOWS\DOWNLOAD…\IUCTL.INF 4096b
C:\WINDOWS\SYSTE…\IUENGINE.DLL 200704b
C:WINDOWS\SYSTEM32\IUCTL.DLL 118784b

CodeBase:

http://v4.windowsupdate.microsoft.com/CAB/x86/

unicode/iuctl.CAB?38399.6847453704


I looked for these files.
IUCTL.DLL and IUENGINE.DLL in Windows\System32\ appear to be part of the Windows Updated control engine by Microsoft. There is no IUCTL.INF in WINDOWS\DPF or any additional suspicious looking files. There is no other file labelled IUENGINE.DLL in windows\System\ or any other folder commencing Windows\Syste….

So Where is internazionale_ver10.INF?

What do I do next?

Any help appreciated.

Thanks
UPDATE 7-8-05 I was able to use the CMD prompt last night to delete the internazionale+ver10.INF program from Windows DPF.

The completed another Panda on-line scan which showed no infections.
I have added SpywareBlaster and SpywareGuard. I was considering installing Panda 7 AntiVirus Platinum, seeing as they do such a good job at locating problems, but then the reviews suggest it is unstable on many machines, uses excessive resources, slow the system down and can cause crashes. The last thing I need! Not worth that risk.

I can get Norton's Internet Security 2005. OR is Trend Micro PC-Cillin or Zonelabs ZoneAlarm better? My NAV seems to detect the viruses quite satisfactorily. I will run a couple more scans today. But system seems clean. Other problems probably remain so my earlier thoughts are more probably correct.

What about O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - and
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} -


My searches have determined that these things are not a problem, but I do not really need or want them. Can I delete them using HJT?

My latest HJT log after rebootingetc.

Logfile of HijackThis v1.99.1
Scan saved at 6:59:17 AM, on 07/08/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\TPWRTRAY.EXE
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Adware -BHO removers\ewido security suite\ewidoctrl.exe
C:\Program Files\Adware -BHO removers\ewido security suite\ewidoguard.exe
C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
c:\program files\Interbase\bin\ibguard.exe
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\TFNF5.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Speed Disk\nopdb.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
c:\program files\Interbase\bin\ibserver.exe
C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE
C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\System32\00THotkey.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Common Files\ACD Systems\IDBSvr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Adware -BHO removers\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://hotmail.com
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com");

(C:\Documents and Settings\Admin\Application

Data\Mozilla\Profiles\default\ypdjx1of.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine",

"engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBW

eb_01.src"); (C:\Documents and Settings\Admin\Application

Data\Mozilla\Profiles\default\ypdjx1of.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection -

{4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program

Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -

C:\PROGRA~1\ADWARE~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} -

C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program

Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [StartupDelayer] "C:\Program Files\Startup Delayer\Startup Launcher

GUI.exe"
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download using Download &Express - file://C:\Program

Files\Download Express\Add_Url.htm
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}

- C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: webiress - http://web.iress.com.au/webiress-0_8_3_4.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -

http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {11B2C0D3-DFFB-11D3-9253-00500498D7E3} (ShowSetupObj3 Class) -

http://invite.mshow.com/ShowSetup.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage

Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid;=0x409
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} -
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -

http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.5.0_02) -
O16 - DPF: {FD18DD5E-B398-452A-B22A-B54636BA9F0D} (Aurigma Image Uploader 2.5)

- http://www.getjealous.com/ImageUploader2.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. -

C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec

Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. -

C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\Adware

-BHO removers\ewido security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\Adware

-BHO removers\ewido security suite\ewidoguard.exe
O23 - Service: GhostStartService - Symantec Corporation -

C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
O23 - Service: InterBase Guardian (InterBaseGuardian) - Inprise Corporation -

c:\program files\Interbase\bin\ibguard.exe
O23 - Service: InterBase Server (InterBaseServer) - Inprise Corporation - c:\program

files\Interbase\bin\ibserver.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program

Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation -

C:\Program Files\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec

AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog

Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program Files\Speed

Disk\nopdb.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec

AntiVirus\Rtvscan.exe
O23 - Service: Tmesbs32 (Tmesbs) - Unknown owner - C:\Program

Files\TOSHIBA\TME3\Tmesbs32.exe" /Service (file missing)
Hello yvonnegee, welcome to the TC.

It looks like you've had quite a time with this :rant2:

You can remove all the 016's if you like. They will come back if needed the next time you visit the site.

I would leave this one.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid;=0x409
Thanks, I will delete the rest of the 016s. I think I shall try to clear some more memory and upgrade to XP SP2. I can add either of 3 firewalls with SP2 (assuming I have no problem with nstallation!). Symantec Interent Security 2005, Zonelabs Zonealarm 5.5, or PC Cillin Internet Security v12. (I am currently working behind a hardware firewall incorporated in the router). I have been satisfied with NAV and my son found Norton's Firewall works well for him, but I am concerned about resource use, and many expert forums recommend one of the other 2. Which woud you prefer?

Thanks, I will delete the rest of the 016s.
I think I shall try to clear some more memory and upgrade to XP SP2. I can add either of 3 firewalls with SP2 (assuming I have no problem with nstallation!).  Symantec Interent Security 2005, Zonelabs Zonealarm 5.5, or PC Cillin Internet Security v12. (I am currently working behind a hardware firewall incorporated in the router).

I have been satisfied with NAV and my son found Norton's Firewall works well for him, but I am concerned about resource use, and many expert forums recommend one of the other 2.  Which woud you prefer?

195788

First off, if your concerned about resources, SP2 will take alot more resources to run. Be sure to read the information about SP2 before upgrading.
I don't see anything wrong with using your Hardware Firewall.

This is the firewall I use.
Go here and download SyGate Personal Firewall 5.X Basic Firewall
http://www.sygate.ca/free/downloads.htm

just fill out the information.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI