This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ISTbar, YourSiteBar, KnownBadSites, PurityScan

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First I would like to know if Spyware Doctor is a credible program or if they would tell me they found stuff on my computer that isn't really there just so I would buy the full version? I downloaded the trial and it has found 4 high risk. ISTbar, KnownBadSites, YourSiteBar, PurityScan, and a bunch of low risk stuff connected with BEARSHARE LITE.
I have run Spybot and ad-aware with updated definitions but Spybot didn't find anything. Ad-Aware was able to find some of the same cookies that Spyware doctor found when I ran it, such as (Username)@oinadserve[1].txt I have deleted that numerous times only to find it again, almost instantly.
MediaAccess (Registry key) also appeared on the Spyware Doctor scan, I deleted the keys and they have not appeared on any current scans so far. The ones I'm really worried about are the high risk infections I cannot seem to remove, the following is the full paths of the infections:
ISTbar - C:\Windows\Downloaded Program Files\CONFLICT.1\ysbactivex.dll

YourSiteBar - C:\Windows\Downloaded Program Files\CONFLICT.1\ysbactivex.dll

KnownBadSites- C:\Documents and Settings\Username\Local Settings\Temp internet\Content.IES\1G83X1WD\!Update - 2495[1].0000

KnownBadSites - C:\Documents and Settings\Username\Cookies\Username@oinadserve[1].txt

PurityScan - C:\Windows\system32\wintit.exe

I have searched for the CONFLICT.1 and the Content.IES\1G83X1WD folders but cannot find them anywhere, leading me to believe that Spyware Doctor is giving false information. I have searched with all hidden files, folders, and subfolders unhiddend, also all protected windows operating prgrams unhidden as well, but still to no prevail. While doing these searches I have come across some other unusal content such as !Update.exe and ersr.exe I have deleted both or tried but they come back.(Of course) I went to MSCONFIG - Startup- and turned off ersr.exe but it still starts up upon turning on my computer. The full path to ersr is:
C:\ProgramFiles\rttt\iiro\ersr.exe

Before I downloaded the trial version of Spyware Doctor I deleted my old HijackThis and downloaded the latest version from a differnt form. It was some time after that, when my pc became incredibly slow! I'm not sure if that could have any effect but I just thought I'd throw it in there.
My DSL connection used to test at 2.3Mbps, after I noticed it was running slow I ran the test again, it tested at 117kbps.

http://www.bandwidthplace.com/speedtest/

That's when I got Spyware Doctor I was able to delete some other junk that if found and scince then my last test ran at 717kbps which is still slow I think, especially scince my dsl is fairly new and I installed all new catagory 5 phonelines and even had a new underground cable installed by the phone company. Should I wait until after the phone company contacts me before trying to remove anything??? Anyways, sorry about any unimportant information, here is my Hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 6:54:42 PM, on 9/9/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\r?gsvr32.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\rttt\ersr.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Wfxif] C:\WINDOWS\System32\r?gsvr32.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [Clau] C:\Program Files\rttt\ersr.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/29b37e43cab282…ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1111273098488
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v6.cab
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
Hello and welcome to TomCoyote. I can't comment about Spyware Doctor having never used it but I will say I have been hearing a lot of comments of the type you are making lately. Here is the list I work by: http://www.spywarewarrior.com/rogue_anti-spyware.htm and I'll throw this one in also: http://www.spywareinfo.com/articles/p2p/ I see PurityScan adware and other garbage I have not identified, what I would like to do is run the uninstaller Symantec suggests for PurityScan, run some great scans, clean a little with HJT and see how you are running. If that works for you, proceed like this and in the order.

1) Review this information: http://sarc.com/avcenter/venc/data/adware.purityscan.html and when you find the PurityScan uninstaller, download an run it.

2) Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions http://www.ccleaner.com/help/tour1.asp and please do not run it until I ask you to.

3) Download, update, configure and run these two programs: http://tomcoyote.org/aawsb.php
The newest version of Ad-aware is 1.06 and Spybot 1.04. Even if you have these programs, use the link to get the newest version, update and configure them as in the link. Run Spybot first, reboot then run Ad-aware. Both programs back up what they remove so delete anything the programs say should be removed.

4) Ewido scan:
Please download Ewido Security Suite it is a trial version of the program.
  • Install ewido security suite
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update Ewido.
Ewido manual updates

Once the updates are installed do the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • NOTE: During some scans with ewido it is finding cases of false positives.**
    • You will need to step through the process of cleaning files one-by-one.
    • If ewido detects a file you KNOW to be legitimate, select none as the action.
    • DO NOT select "Perform action on all infections"
    • If you are unsure of any entry found select none for now.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.
**(Ewido for example has been flagging parts of AVG Anti-Virus, pcAnywhere and the game "Risk")

TeaTimer: http://russelltexas.com/malware/teatimer.htm ,Spyware Doctor, and any other spyware program that might block the HJT fix needs to be off when you run HJT.

5) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
see this: http://castlecops.com/startuplist-6959.html
O4 - HKCU\..\Run: [Wfxif] C:\WINDOWS\System32\r?gsvr32.exe
PurityScan/Clickspring adware
O4 - HKCU\..\Run: [Clau] C:\Program Files\rttt\ersr.exe
random trojan
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/29b37e43cab282…ip/RdxIE601.cab
NetsterAdware
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v6.cab
Grayware

Close all programs but HJT and all browser windows, then click on "Fix Checked"

6) SHOW HIDDEN FILES: Follow the instructions in the link to enable hidden files for your operating system.
You may wish to reverse this process if you have any concern about anyone getting into these hidden system files.
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

RIGHT Click on Start then click on Explore. Locate and delete these items:

C:\WINDOWS\System32\r?gsvr32.exe >>> file (may be gone, if it is there a letter will be where the wildcard ? is indicated. Just be careful all of the rest of the spelling is the same)

C:\Program Files\rttt\ >>> folder

C:\Windows\Prefetch: Locate this folder and delete all of the contents (NOT THE FOLDER) This information will tell you more about Prefetch:
http://www.windowsnetworking.com/articles_…refetch-XP.html

7) Run CCleaner, when you run the registry cleaner (Issues) you will be prompted to backup before you can remove stuff, make sure you do. Then restart the computer and post a new HJT log and the Ewido scan results in this same thread along with any feedback you have. Let me know how you are running now.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Logfile of HijackThis v1.99.1
Scan saved at 1:43:00 AM, on 9/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~2\swdoctor.exe /Q
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1111273098488
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe




———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 10:47:57 PM, 9/14/2005
+ Report-Checksum: BB2F322D

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{9F95F736-0F62-4214-A4B4-CAA6738D4C07} -> Spyware.SaveNow : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C285D18D-43A2-4AEF-83FB-BF280E660A97} -> Spyware.SaveNow : Cleaned with backup
C:\Documents and Settings\Steven\Cookies\[removed][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Steven\Cookies\[removed][1].txt -> Spyware.Cookie.Addcontrol : Cleaned with backup
C:\Documents and Settings\Steven\Cookies\steven@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Steven\Cookies\steven@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Steven\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Steven\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Steven\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Steven\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Steven\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Steven\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Steven\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Steven\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Steven\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Steven\Cookies\[removed][2].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\Steven\Cookies\[removed][1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Steven\Cookies\steven@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Steven\Local Settings\Temp\!update.exe -> TrojanDownloader.PurityScan.af : Cleaned with backup
C:\Program Files\rttt\ersr.exe -> TrojanDownloader.PurityScan.af : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\ysbactivex.dll -> TrojanDownloader.IstBar : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.PornWare.PopCap.b : Cleaned with backup


::Report End

I deleted regsvr32.exe in the System32 folder but it keeps coming back a few seconds after I delete it.

I have ran the new version of Spybot with no results and the new version of Ad-Aware which came back with 6 objects (they were cookies) which appear to be deleted. I ran SpywareDoctor while posting this reply, the only objects I see are the WhenU Save! Registry keys and a few other files accociated with Bear share, I'm not sure but I would think that getting rid of those may cause bear share to stop working.

So far the only pop up I've had was winfixer, which still shows up on SpywareDoctor as :
C:\WINDOWS\Downloaded Program Files\UWFX5LP_0001_0614NetInstaller.exe Which needless to say doesn't show up in the folder.

When I tried to delete all the files in the Prefetch folder I could not delete BFVIETNAM.EXE-28DDEEB9.pf The message was: The file is corrupt and unreadable. I retstarted and I did not see the file. I have been having problems with BFV crashing or displaying a message that data differs from server so maybe that was the problem.

Thank you very much for your help so far.
OK, for starters your HJT log is clean :thumbup: You keep mentioning BearShare, I do not see it, if you have it installed, beaware that unless it is a paid version you should remove it from your computer.

Look in Add Remove programs for Winfixer…if there uninstall it. In fact, please let me look at what is installed there. You can do that like this:
Open Hijackthis.
Click the "Open the Misc Tools" section Button.
Click the "Open Uninstall Manager" Button.
Click the "Save list…" Button.
Save it to your desktop. Copy and paste the contents into your reply.

This Winfixer is a real piece of junk that has been causing a lot of folks problems.

So far the only pop up I've had was winfixer, which still shows up on SpywareDoctor as :
C:WINDOWSDownloaded Program FilesUWFX5LP_0001_0614NetInstaller.exe  Which needless to say doesn't show up in the folder.

They are probably hiding the item, so enable hidden files and see if it is there and delete it: http://www.bleepingcomputer.com/forums/tutorial62.html if it resists, try to remove it in safe mode: http://www.bleepingcomputer.com/forums/tutorial61.html
You can empty that Prefetch folder in safe mode also.
One more place you can look is here: Internet Explorer > Tools > Internet Options > Settings > View Objects. If it is there, highlite and delete it. Let me know if this works, post the list of programs and any information you think will help.

Thanks…Phil
Ad-Aware SE Personal Adobe Acrobat 7.0.1 and Reader 7.0.1 Update Adobe Acrobat 7.0.2 and Reader 7.0.2 Update Adobe Acrobat 7.0.3 and Reader 7.0.3 Update Adobe Download Manager 2.0 (Remove Only) Adobe Photoshop Album 2.0 Starter Edition Adobe Reader 7.0 AOL Instant Messenger BearShare CCleaner (remove only) DivX ewido security suite Google Toolbar for Internet Explorer HijackThis 1.99.1 Intel A/V Codecs V2.0 iTunes J2SE Runtime Environment 5.0 Update 2 J2SE Runtime Environment 5.0 Update 4 Macromedia Shockwave Player NVIDIA Drivers QuickTime RealPlayer SBC Yahoo! Applications Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB903235) Spybot - Search & Destroy 1.4 Spyware Doctor 3.2 SpywareBlaster v3.4 Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Windows Genuine Advantage v1.3.0254.0 Windows Installer 3.1 (KB893803) Windows Media Format Runtime Windows Media Player 10 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888162 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 XoftSpy Awww, I need to remove BearshareLite? :( What will that do? I did a search in both normal and safe mode with all files and folders and subfolders unhidden and all protected operating systems unhidden as well and was still unable to locate C:\WINDOWS\Downloaded Program Files\UWFX5LP_0001_0614NetInstaller.exe However it has been awhile and I have not had a single pop-up, even though the file still shows up on the SpywareDoctor scan. The following is what I found in C:\WINDOWS\Dowloaded Program Files: HouseCall Control 432KB HouseCall Control 624KB Java Runtime Environment 1.5.0 none Java Runtime Environment 1.5.0 none Java Runtime Environment 1.5.0 none Shockwave Activex Control 4KB Shockwave Flash Object 4KB Symantec AntiVirus Scanner 652KB Symantec RUFSI Utility Class 164KB WScanCtl Class 392KB WUWeb Control Class 176KB YInstStarter Class 176KB I was able to delete regsvr32.exe in safe mode and it has yet to appear again, which is good news.
Well EboyIsNumeroUno, I see nothing in your programs that jumps out to me as malware, unless Bearshare is not a paid version. You read what they had to say about Bearshare lite under the UNKNOWN heading. It is your computer and you can run what you wish.
I'm not a fan of AOL Instant Messenger but hey, I don't like aol. If you use the IM to share files it can be more dangerous that any instance of BearShare. I always like to mention while looking at the list of programs, if you see third party software that you did not install or no longer use, now would be a good time to uninstall it. I see nothing to be concerned about in your DPF's either. Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Let's keep an eye on things for a few days. We may have stopped Winfixer and the item you are seeing may be a false positive or a remnant leftover somewhere. You may try running CCleaners again making sure to use and backup the "Issues" regcleaner. See how it goes.

Thanks…Phil
Thank you very very much for your help! What an outstanding job you did. I do have a few questions though, I now have 10 or 11 different anti-virus and anti-spyware programs: (Spybot, Spywareblaster, HiJackThis, CCleaner, IE-Spyad, Ad-Aware, SpywareGuard, SpywareDoctor, XoftSpy-free scanner, and Ewido-free trial, I'm sure I left out something.) including I believe, two real time protectors, or whatever they're called, the kind that block you from going to bad sites and from downloading bad files or bad Activex content. (SpywareDoctor and SpywareGuard) I am going to hang on to all of them, or in the case of Ewido, until the trial is up. :P cause I'm cheap like that. lol My question is, is it safe to run both programs together at the same time? I heard it's not, and when I'm running one program I should make sure that I am exited out of all the other anti-virus\spyware programs right? I always do, I just want to know if it is necessary. If it's not safe to let them run together which do you suggest? SpywareDoctor has been the most effective of the two that I have seen so far. I also downloaded the Host file from that link you posted. Although I'll have to go back over those pages because I'm not sure I absorbed all the information correctly about the update or how to update the file….something like that. Anyways, thank you for all your time and effort you put into this. Let me know if you put all those links down to let me pick and choose as I wish or if I should download all that applies. I'm trying to get all this stuff up to date before I ship out. After I'm gone my mom will be the only one on here. ;) Anyways, thanks again!
I have given some thought to your questions and complexities make it a little hard to answer. We do know that running more than one antivirus program can cause problems, but as far as I know the jury is still out on multiple spyware programs. I personally would be suspect of two many programs doing the same thing. For instance, Spybot TeaTimer and SpywareGuard perform the same function so we suggest not running them both. I have no experience with Spyware Doctor and can't speak to the program. I will give you this link where you can learn about rouge spyware software, and questionable products: http://www.spywarewarrior.com/rogue_anti-spyware.htm
Before I give you my thoughts on some of the programs, let me show you what I run, and I take my computer to places while checking logs that most folks would never go. Here is what I run and keep in mind all but McAfee are freeware:

1) McAfee VSO
2) Zone Alarm free
(I do use a Linksys router)
3) Spybot
http://www.bleepingcomputer.com/forums/tutorial43.html
4) Ad-aware
http://www.bleepingcomputer.com/forums/tutorial48.html
5) SpywareBlaster
http://www.bleepingcomputer.com/forums/tutorial49.html
6) SpywareGuard:
http://www.bleepingcomputer.com/forums/tutorial50.html
7) IE-Spyad
http://www.bleepingcomputer.com/forums/tutorial53.html

Now to mention the products you have onboard and my suggestions:
Spybot and Ad-aware: Unless you are running TeaTimer, you can run the programs after an update on a regular basis, and I have rarely heard of any conflicts with other software.

Spywareblaster, SpywareGuard: Realtime protection, work well with each other, do not require running as they do their job in the backgound, your tutorial will explain this better. Do need updates, SB more ofthen the SG. Bad stuff can slip by if the data bases are not kept current.

IE-Spyad: Registry merge, has a list of bad sites that it just plain blocks from your registry. Does not "Run", but it does need an rare update.

CCleaner: Run it when you need it, keep it off when you don't.

Ewido: Once the trial is over, you loose the realtime protection but can update and use the scanner for as long as you wish. Only run it when you want a good spyware scan.

HiJackThis: Only runs when you start it.

SpywareDoctor, XoftSpy-free scanner: Can't help with these, a little Google searching may?

Use: http://netsquirrel.com/msconfig/ to turn off programs you use once in a while and can start in All Programs.

Let me know if you put all those links down to let me pick and choose as I wish or if I should download all that applies.

Indeed this is the case, while this is just some of the malware experts who's advice I follow and there are certainly others, the final decision comes down to the computer owner who must choose what works best for him/her and the configuration of hardware and software on their computer. I hope this helps, and I will leave your post open for a couple of days in the event you have aditional questions…Phil :wavey:

Thanks…pskelley
TomCoyote forum
Slyware Warrior
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
Wow, Once again my deepest thank you. A lot of people don't understand just how big of an impact something small they say can have. And, if any free person in this world (including Marines) can get on their computer and not be engulfed in a world of carp**……thank Phil and people like him. :P So we're even. lol Oorah!! to you sir Forgive my failure to clarify, I know all of those programs don't run at start up. and I know it's recommended that all other programs be closed when running a scan. Currently the only programs running at startup are: ewido, SpywareDoctor, Yahoo Online Protection(I knew I left out one! I'm not sure how much good it actually does at protecting, but whatever.), and SpywareGuard. So here's the plan……I'll turn off all the programs to run at start up except, SpywareBlaster,Ewindo, since that's what the professial(you) uses. :P Until the trial is over, then I will reconfigure Spywareblaster and SpyBot to run at start up, scince spybot alerts me to changes in the registry. Does that sound good?????(Granted I will do all this only if I'm stil here.lol :oops: ) I'll do it before I leave, because my mom can berly turn on the computer by herself. :rofl: I have a question about ewindo. When I click on "Quarantine", it shows that big list of bad files and cookies, I am supposed to click the "Remove Finally" Button at the bottom and delete them all right? I'll have to see how it works out, because I think Yahoo Online Protection tries to start up everytime I sign on to Yahoo messanger. Oh and for the record I don't like AOL either, I just have it because that's all that a few of my friend have. I think there is something that I have to get in order to have Google talk.
Wow, Once again my deepest thank you. A lot of people don't understand just how big of an impact something small they say can have. And, if any free person in this world (including Marines) can get on their computer and not be engulfed in a world of carp**……thank Phil and people like him. :P So we're even. lol Oorah!! to you sir Forgive my failure to clarify, I know all of those programs don't run at start up. and I know it's recommended that all other programs be closed when running a scan. Currently the only programs running at startup are: ewido, SpywareDoctor, Yahoo Online Protection(I knew I left out one! I'm not sure how much good it actually does at protecting, but whatever.), and SpywareGuard. So here's the plan……I'll turn off all the programs to run at start up except, SpywareBlaster,Ewindo, since that's what the professial(you) uses. :P Until the trial is over, then I will reconfigure Spywareblaster and SpyBot to run at start up, scince spybot alerts me to changes in the registry. Does that sound good?????(Granted I will do all this only if I'm stil here.lol :oops: ) I'll do it before I leave, because my mom can berly turn on the computer by herself. :rofl: I have a question about ewindo. When I click on "Quarantine", it shows that big list of bad files and cookies, I am supposed to click the "Remove Finally" Button at the bottom and delete them all right? I'll have to see how it works out, because I think Yahoo Online Protection tries to start up everytime I sign on to Yahoo messanger. Oh and for the record I don't like AOL either, I just have it because that's all that a few of my friend have. I think there is something that I have to get in order to have Google talk.
Wow, Once again my deepest thank you. A lot of people don't understand just how big of an impact something small they say can have. And, if any free person in this world (including Marines) can get on their computer and not be engulfed in a world of carp**……thank Phil and people like him. :P So we're even. lol Oorah!! to you sir Forgive my failure to clarify, I know all of those programs don't run at start up. and I know it's recommended that all other programs be closed when running a scan. Currently the only programs running at startup are: ewido, SpywareDoctor, Yahoo Online Protection(I knew I left out one! I'm not sure how much good it actually does at protecting, but whatever.), and SpywareGuard. So here's the plan……I'll turn off all the programs to run at start up except, SpywareBlaster,Ewindo, since that's what the professial(you) uses. :P Until the trial is over, then I will reconfigure Spywareblaster and SpyBot to run at start up, scince spybot alerts me to changes in the registry. Does that sound good?????(Granted I will do all this only if I'm stil here.lol :oops: ) I'll do it before I leave, because my mom can berly turn on the computer by herself. :rofl: I have a question about ewindo. When I click on "Quarantine", it shows that big list of bad files and cookies, I am supposed to click the "Remove Finally" Button at the bottom and delete them all right? I'll have to see how it works out, because I think Yahoo Online Protection tries to start up everytime I sign on to Yahoo messanger. Oh and for the record I don't like AOL either, I just have it because that's all that a few of my friend have. I think there is something that I have to get in order to have Google talk.
I also know little about Yahoo (seems they have been caught in bed with the enemy or so I hear) so I use a free email account for storage and have nothing else Yahoo on my computers (3) Your plan sounds good so see how it works for you. I personally prefer SpywareGuard to Spybot TeaTimer but they are both good programs. SpywareGuard will also alert you to registry change attempts. Here are a few links for your Mom so she can lean how to avoid problems:
http://www.resnet.umn.edu/html/rn_security.html
http://www.safecomputing.umn.edu/studentchecklist.html
http://whatis.techtarget.com/definition/0,…i887624,00.html
http://www.staysafeonline.info/home-tips.html

You may delete anything in the Ewido quarantine folder. They do cover the few problem areas in the instructions. You should also clean out Ad-aware quarantine, Spybot Recovery and any other area in any security program that stores bad stuff rather than delete it right away. Allow a few days to make sure you are functioning properly then dump the junk. Easier to wait a few then to locate and download a file removed in error. HJT also makes backups in the HJT folder. Those backups can also be removed after a brief safe period. I hope this helps…Phil :)
Hmmm I apologize for that last post, as I'm sure you noticed, the same reply was posted three times. It was one of those days when my DSL was going unbelievably slow. I thought I was disconnected so I tried it again and still nothing, I guess that just shows that it was working, just super slow for some reason. I'll have to call the phone company I guess. It took an hour just for the progress bar in the window to get to the middle. Anyways another thing I was wondering about was the advice of Jason's Browser Security Test. I've had my settings set to it's recommendations for a few days now and it's starting to get really old. lol Right now I have it set to where everytime I open up my browser it ask me if I would like to allow scripts to run. In the security settings at the moment I have everything under Scripting set to prompt. I'm not sure how useful scripting is but I think I need it to play games on Yahoo messanger with friends so I'd like to keep that. The problem is, is that it ask me if I want to run script for everything connected to the internet. I'd like to be able to tell it to run script for Yahoo Messanger, but not for anything else. I find myself clicking yes all the way so I'm not sure that if I always say yes, how much good I'm doing in keeping it from running something bad lol. Maybe I should disable. What do you think? Another thing I was wondering about is cookies. Should I just set it to disable instead of prompt? That is getting old too. Anyways, I was just wondering if that stuff was necessary of just Overkill. I do know that even with cookies set to prompt I did a scan and found 4 bad cookies. :oops: oops My fault. lol
Grinler has good suggestions: http://www.bleepingcomputer.com/forums/topict2520.html I found Jason's Browser Security Test a little hard to maintain when I first tried it also. Setting those ActiveX controls will do a lot to stop bad stuff.
Here's some good information: http://www.networkworld.com/reviews/2005/0…op-spyware.html
http://www.microsoft.com/windowsxp/evaluat…cookiemgmt.mspx
http://www.microsoft.com/windowsxp/using/s…december22.mspx

Make sure Windows Updates are set to Auto. I have found that here is only one sure tool for 100% computer safety and that is a pair of wire cutters, and you know what wire you have to cut.

Hope that helps…Phil :rofl:
Thanks again for all you've done. I just turned cookies and Active scripting off because I got tired of it asking me. lol I'm pretty sure I won't miss too much.
I had already read and done everything that this link: http://www.bleepingcomputer.com/forums/topict2520.html said to do. I did it the first time you sent it, the same goes for this one: http://www.microsoft.com/windowsxp/using/s…december22.mspx except with the exception that I built this computer so I guess I can't be 100% sure on how fast it's supposed to run and junk. But now scince I turned cookies off completely, does that mean I wont be able to add stuff to my shopping cart when I'm shopping online? I know Jason's Browser Security Test mentioned something about that. I guess I should read it again before I ask. Oops Anyways, I'll stop bugging you after this, lol I know there are a lot more people on here that need your expertise. I also left (Scripting of Java applets) on "Prompt"
So hopefully I won't have to go to Internet Options everytime I try to play pool with a friend. Do let me know if turning off "Cookies" and "Active Scripting" is advisable. Also, how much am I supposed to donate?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI