This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow start-up

47 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Phil, Thanks for your prompt reaction. Is it possible that you referred to the wrong tutorial i.r.o. Ewido safe mode? The tutorial you mentioned in your reply seems to deal with how to post a HJT log? As to your 4th point: I think the problems started after the installation of Norton Internet Security. I am sure they aggravated substantially after that installation. I think that prior to that installation I was experiencing some slow-down already (that was when I had my previous topic discussion with your colleague Ken. I am fairly sure that was before the Norton Internet Security Installation). As I wrote before, I never get any error messages, so I cannot report of any of those. I will not be able to react for a number of days due to personal reasons. I will follow up a.s.a.p. Kind regards, JvdV
Sorry…I guess I am trying to do to much…starving and I need a break.

Try this one: http://www.bleepingcomputer.com/forums/tutorial61.html

You keep mentioning NAV, have you thought to discuss it with Symantec? I will say I have never had any experience with NAV but I am told it is a huge resource user. I wish I could report that folks with NAV never get infected, but I can not. If we can't locate another software reason for the issue, before you start looking at a possible hardware failure, you may want to uninstall the product and try something like this free product which is not resource heavy:
http://free.grisoft.com/freeweb.php

In case I have not asked (I am working around 50 or so logs at any one time) I would like to make sure you do not have the SP2 firewall activated if you are running one in NAV, I am not sure that could cause your issues but it not a suggested proceedure.

If I remember correctly, Ken was also not able to locate a malware reason for your issues. Ken is a friend and I will discuss this with him if he ever stops watching the NY Yankee's play baseball.

Thanks…Phil
Hello Again JvdV, I'm sorry your still having problems, both PSKELLEY and myself have looked over your log with a fine tooth comb and don't see any evidence of any malware or a virus. I wonder if you could give us some stats on your system. * Make and Model * Age of system * Processor type and speed * Motherboard maker * Amount of memory * Hard drive make ans size (How old is the drive and how full is it, do you have plenty of free space. This is also very important to consider, think back, prior to this problem, did you install or uninstall and software programs or changed any hardware like printers, scanners, added memory, a new CD-Rom or anything that would have changed your system. Please let is know,we sure would like to pin point this problem. Ken :D
To: Pskelly and Ken545

Hi Phil and Ken,

Thanks to both of you for your feedback and for your perseverance.
Apologies for not responding dunring 1½ week, but, as I indicated in my last reply, I was out of the country for over a week, so could not react.

I did everything Phil suggested and the results are as follows:

1. I ran Ewido in Safe Mode and the results are as follows:


———————————————————
ewido security suite - Scan rapport
———————————————————

+ Gemaakt op: 23:44:46, 22-10-2005
+ Rapport samenvatting: 90D96588

+ Scan resultaten:

C:\Documents and Settings\Joost\Cookies\[removed][1].txt -> Spyware.Cookie.Euroclick : Schoongemaakt met een backup
C:\Documents and Settings\Joost\Cookies\joost@burstnet[2].txt -> Spyware.Cookie.Burstnet : Schoongemaakt met een backup
C:\Documents and Settings\Joost\Cookies\[removed][2].txt -> Spyware.Cookie.Onestat : Schoongemaakt met een backup


::Einde rapport


2. I ran the Housecall scan and the results were was an infection with BKDR_NETPALS.A in C:\windows\system32\netpole.dll. What should I do about this?


3. I tried to run the Panda Software scan a couple of times, but it failed each time at the same spot, i.e. after some 250 files whilst processing the file C:\windows\explorer.exe. Does this point in any direction?

4. I ran the Kaspersky scan and it gave the following results:

——————————————————————————-
KASPERSKY ON-LINE SCANNER REPORT
Sunday, October 23, 2005 12:21:27
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 23/10/2005
Kaspersky Anti-Virus database records: 146347
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 79651
Number of viruses found: 3
Number of infected objects: 4
Number of suspicious objects: 0
Duration of the scan process: 3832 sec

Infected Object Name - Virus Name
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E4637A0.dll Infected: Trojan-Dropper.Win32.Mudrop.w
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E49619D.dll Infected: Trojan-Dropper.Win32.Mudrop.w
C:\WINDOWS\system32\netpal2.dll Infected: Backdoor.Win32.Adbreak.e
C:\WINDOWS\system32\sstep.dll Infected: Trojan-Dropper.Win32.Small.so

Scan process completed.


5. Next, I ran Silentrunners and the results of that process were as follows:

"Silent Runners.vbs", revision 41, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
———————————

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
"PowerBar" = (empty string)

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"EM_EXEC" = "C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE" ["Logitech Inc."]
"ACTIVBOARD" = "C:\Apps\ActivBoard\MMKeybd.exe" ["Netropa Corp."]
"Logitech Utility" = "Logi_MwX.Exe" ["Logitech Inc."]
"ccApp" = ""C:\Program Files\Common Files\Symantec Shared\ccApp.exe"" ["Symantec Corporation"]
"Symantec NetDriver Monitor" = "C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer" ["Symantec Corporation"]
"NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
{9ECB9560-04F9-4bbc-943D-298DDF1699E1}\(Default) = "Norton Internet Security"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"]
{BDF3E430-B101-42AD-A544-FADC6B084872}\(Default) = "NAV Helper"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]
"{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"]
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"]
"{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{950FF917-7A57-46BC-8017-59D9BF474000}" = "Shell Extension for CDRW"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Ahead\InCD\incdshx.dll" ["Ahead Software AG"]
"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
"{8BE13461-936F-11D1-A87D-444553540000}" = "Eraser Shell Extension"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Eraser\erasext.dll" ["-"]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
INFECTION WARNING! "{54D9498B-CF93-414F-8984-8CE7FDE0D391}" = "ewido shell guard"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\shellhook.dll" ["TODO: "]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
EasyCryptoMenu\(Default) = "{A0752120-6D75-D111-B5B1-0800095A2318}"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\tsseCryp.dll" [null data]
Erasext\(Default) = "{8BE13461-936F-11D1-A87D-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Eraser\erasext.dll" ["-"]
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\context.dll" ["ewido networks"]
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
EasyCryptoMenu\(Default) = "{A0752120-6D75-D111-B5B1-0800095A2318}"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\tsseCryp.dll" [null data]
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\context.dll" ["ewido networks"]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
Erasext\(Default) = "{8BE13461-936F-11D1-A87D-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Eraser\erasext.dll" ["-"]
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]


Active Desktop and Wallpaper:
—————————–

Active Desktop is disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\Joost\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"


Startup items in "Joost" & "All Users" startup folders:
——————————————————-

C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten
"Adobe Gamma Loader" -> shortcut to: "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]
"Adobe Reader Snelle start" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]
"Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office10\OSA.EXE -b -l" [MS]


Enabled Scheduled Tasks:
————————

"Herinnering voor registratie 1" -> launches: "C:\WINDOWS\System32\OOBE\oobebaln.exe /sys /r /n:1" [MS]
"Herinnering voor registratie 2" -> launches: "C:\WINDOWS\System32\OOBE\oobebaln.exe /sys /r /n:2" [MS]
"Herinnering voor registratie 3" -> launches: "C:\WINDOWS\System32\OOBE\oobebaln.exe /sys /r /n:3" [MS]
"Norton AntiVirus - Mijn computer scannen - Joost" -> launches: "C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe /task:"C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\mycomp.sca"" ["Symantec Corporation"]
"Symantec NetDetect" -> launches: "C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE" ["Symantec Corporation"]
"SyncBack Back-up Excel" -> launches: "C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe -m "Back-up Excel"" ["2BrightSparks"]
"SyncBack Back-up Word" -> launches: "C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe -m "Back-up Word"" ["2BrightSparks"]


Winsock2 Service Provider DLLs:
——————————-

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 19
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
————————————

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" = "Norton AntiVirus" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{327C2873-E90D-4C37-AA9D-10AC9BABA46C}" = "Easy-WebPrint"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]

"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" = "Norton Internet Security"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"]

"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" = "Norton AntiVirus"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

Explorer Bars

HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
{FE54FA40-D68C-11D2-98FA-00C0F0318AFE}\ = "Real.com" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Shdocvw.dll" [MS]

Dormant Explorer Bars in "View, Explorer Bar" menu

HKLM\Software\Classes\CLSID\{03C1C47F-0538-4645-8372-D3109B9FC636}\ = "Easy-WebPrint"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll" ["Sun Microsystems, Inc."]

{CD67F990-D8E9-11D2-98FE-00C0F0318AFE}\
"ButtonText" = "Real.com"


Running Services (Display Name, Service Name, Path {Service DLL}):
——————————————————————

C-DillaCdaC11BA, C-DillaCdaC11BA, "C:\WINDOWS\system32\drivers\CDAC11BA.EXE" ["C-Dilla Ltd"]
ewido security suite control, ewido security suite control, "C:\Program Files\ewido\security suite\ewidoctrl.exe" ["ewido networks"]
InCD Helper, InCDsrv, "C:\Program Files\Ahead\InCD\InCDsrv.exe" ["Ahead Software AG"]
ISSvc, ISSVC, ""C:\Program Files\Norton Internet Security\ISSVC.exe"" ["Symantec Corporation"]
Netropa NHK Server, nhksrv, "C:\Apps\ActivBoard\nhksrv.exe" [null data]
Norton AntiVirus Auto-Protect-service, navapsvc, ""C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe"" ["Symantec Corporation"]
NVIDIA Display Driver Service, NVSvc, "C:\WINDOWS\System32\nvsvc32.exe" ["NVIDIA Corporation"]
Symantec Core LC, Symantec Core LC, "C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe" ["Symantec Corporation"]
Symantec Event Manager, ccEvtMgr, ""C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"" ["Symantec Corporation"]
Symantec Network Drivers Service, SNDSrvc, ""C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"" ["Symantec Corporation"]
Symantec Network Proxy, ccProxy, ""C:\Program Files\Common Files\Symantec Shared\ccProxy.exe"" ["Symantec Corporation"]
Symantec Settings Manager, ccSetMgr, ""C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"" ["Symantec Corporation"]
Symantec SPBBCSvc, SPBBCSvc, ""C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"" ["Symantec Corporation"]
Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]


Keyboard Driver Filters:
————————

HKLM\System\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\
"UpperFilters" = INFECTION WARNING! "msikbd2k" ["Netropa Corporation"]


Print Monitors:
—————

HKLM\System\CurrentControlSet\Control\Print\Monitors\
Canon BJ Language Monitor PIXMA iP3000\Driver = "CNMLM61.DLL" ["CANON INC."]
Canon BJ Language Monitor S100\Driver = "CNMLM3A.DLL" ["CANON INC."]


———-
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 113 seconds.
+ The search for all Registry CLSIDs containing dormant Explorer Bars
took 29 seconds.
———- (total run time: 203 seconds)


6. As to your other questions, Phil:
If I try to remember when the speed slowed down, I can think of the following:
- SP2
- various Windows Updates (they are installed automaticaly)
- Azureus (i.e. a torrent program to download music and movies using torrents)
- Pinnacle Studio 9
- Office XP Suite (Word, Excel, Power Point, erc.)
- Google Earth
- Music Stream (a service provided by my Internet Service Provider to legally download music)
- Ewido Security Suite.

On each of these installations I had the impression my PC got slower. I tried if deinstalling e.g. Google Earth would make a difference, but it did not.
But despite the gradual increase in slowness, for a long time I got a desktop with all the icons appearing in one single moment upon start-up (i.e. after the Windows XP welcome screen), whereas since a month (or is it two months?) I first get the desktop background, then all the icons in white and after that, at a very slow pace, the icons fill up to their normal appearance one by one. This is an extremely slow process. At this moment one gets the impression that some (hidden?) process is using up all the memory of the PC.


7. Now as to Ken's questions:

Make and model of my PC: Packard bell, iMedia 3700
Bought in November 2001
Processor tpye and speed: AMD Athlon XP 1700+; cloclspeed 1,47 Ghz
Motherboard maker: Explorer
Amount of memory: 512 MB
Hard drive make and size: Make unknown (does ST340810A mean something to you?), size 40 GB (actually 37,2 GB available) of which 6,06 GB free.
I defragmented recently, but this did not yield any noticeable results.

A year ago, I added a Maxtor 160 GB hard disk, of which 109 GB is still free. At the same time I added 256 MB memory (i.e. I ugraded from 256 to 512) and I installed a DVD rewriter. But it all has worked fine and smooth (and fast!) for quite a while, so I don't think the source of the problem is there. Otherwise no new hardware installed other than a Canon Pixma inkjet printer a couple of months ago.

I look forward to your views with much interest.

Kind regards,
JvdV
Hi Phil, I realised I did not answer all of your question in my previous post. So I'll continue with the rest right here: 1. Windows Firewall is switched off as I use Norton Internet Security's firewall. 2. No, I never discussed my problem with Symantec. I wasn't aware of that possibility. If I would deinstall NAV and install the alternative antivirus programme, would I then have to activate the Windows Firewall? Kind regards, JvdV
Hi JvdV, First let me once again assure you I have no idea why your are having these spped issues. I have made many suggestions and at this point I really can't say if you tried what I suggested or not. I will carry this forward for a bit more, then I will have to admit is is beyond my expertise to help you. In the meantime, let's see if any information you presented me with gives us any clues.

1)These items:
C:\windows\system32\netpole.dll
C:\WINDOWS\system32\netpal2.dll
C:\WINDOWS\system32\sstep.dll
I would like to know more about these. Use the following free online scans, post the results.
http://virusscan.jotti.org/
http://www.kaspersky.com/scanforvirus
http://www.virustotal.com/flash/index_en.html
Once you have established they are bad, then use this tool to remove them:
http://forum.malwareremoval.com/viewtopic.php?t=320
You may not find them unless you enable hidden files:
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

2)

I tried to run the Panda Software scan a couple of times, but it failed each time at the same spot, i.e. after some 250 files whilst processing the file C:\windows\explorer.exe. Does this point in any direction?

Not sure yet, considering and researching.

3)

I ran the Kaspersky scan and it gave the following results:

Open NAV quarantine area and delete anything in there.

4) SilentRunners, nothing jumps out at me…This one is unusual, but there is no file to delete so I am not sure what it means. I am asking a Finish friend to take a look and will let you know when I hear from him if it means anything:
HKLM\System\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\
"UpperFilters" = INFECTION WARNING! "msikbd2k" ["Netropa Corporation"]

5) Since I asked these questions and you were nice enough to answer them, I will try to respond.
SP2: There is no doubt you will experience a slowdown with the installation of SP2. Microsoft knew this would happen and tried to warn folks to make sure their computer was prepared for the installation:
http://www.microsoft.com/windowsxp/sp2/sp2_whattoknow.mspx

various Windows Updates (they are installed automaticaly) it happens here also, some folks have to remove some of these because they effect their computer so dramatically. I don't know how to advise you here. It would require something like removing them all and installing them one at a time to see if you can spot one update that slows you dramatically. You can also go into your update history and read about each of the downloads looking for a clue.

- Azureus (i.e. a torrent program to download music and movies using torrents)
- Pinnacle Studio 9
- Office XP Suite (Word, Excel, Power Point, erc.)
- Google Earth
- Music Stream (a service provided by my Internet Service Provider to legally download music)
We are getting way away from my area now, but a few thoughts off the record: First, and you probably did not, you should never install more than one program at a time, then allow time to see if the installation is going to have any negative impact on your configuration. At this point troubleshooting would require removing the programs one at a time looking for any significant change in overall performation. It is a tough way to troubleshoot.

Ewido Security Suite. Now there is no doubt during the trial period ewido uses a lot of resources. Once the trial period is over, if the program is not running it will do nothing to slow you down until you activate it to run a scan. If you do not use ewido, at this point you may want to uninstall it completely? Your call.

I may be wrong, and I have been wrong before, but you keep mentioning a "Hidden" process. I am beginning to believe it is the visable processes slowing you down and not something hidden.

Here is another program you can run that has just updated and now locates some new stuff. Be aware you will be adding a porgram and that is certainly not going to make your computer run faster.
You may give it a try if you wish:
Download SpySweeper Trial (on right side of page):
http://www.webroot.com/consumer/products/spysweeper

Install SpySweeper v4.5 (Double click: ssfsetup1_….)
Follow the prompts and do a Typical installation
Click: Install, make sure Run SpySweeper Now is checked, and click Finish.

Update the program definitions
Select: Sweep
It will take a while to scan the computer.

When the scan is done, remove whatever it finds.

Then, press the Results button
Select the Session Log tab
Select: Save to File
Save wherever is convenient
Copy/Paste the results in your response.

Post the SpySweeper Session log, and I would also like to see a new HijackThis log.

PCPitStop is offering a free scan that may give you some ideas, if you would like it try that here is the link:
http://www.pcpitstop.com/store/optimizescan.asp
I have lost track of what we have tried, if you have not run a diagnostic at PCPitStop, I suggest you do. They also have a forum there were they will help you understand the results of your tests.
http://www.pcpitstop.com/

Thanks…Phil


Adding this because of the additional post you made.

1) That is the way it should be set, one firewall at a time.

2) Humm, that is what you pay their technical support for and they just raised their rates. As we discussed before, NAV is very resource heavy. It may be that this security suite will slow down an older system like your and there may be nothing you can do about it. I would be interested in hearing what they say myself and it is not even my computer.

3) Yes…AVG by Grisoft does not contain a firewall, and the SP2 firewall would have to be activated.
JVDV, Sorry to hear that you are still having problems, just wanted to throw in my 2 cents if I may. Besides fighting malware, I am also a system builder, built about a dozen or so new systems and have redone so many that I lost track. The Packard Bell system that you have would not be my first choice if I had to buy a computer. There popularity and quality got so bad that they finnaly pulled out of the USA and continued to produce them in Europe. All there internal parts are made by manufacturers that I really never heard of. All my systems are built around the Intel motherboard and Processor and I have not ever experienced any major problems. Even on Intel based systems, technology has changed so fast that programs that are written today require a lot more firing power than the systems 4 or 5 years old can provide. You mentioned that you upgraded the hard drive and memory, your money would be better spent on a new system than pouring money into an older system, but only you can make that decision. Like PSKELLEY mentioned, the programs written today as far as anti virues and the security suites are resource hogs and could possibly be what it slowing your system down. We did find some files using Ewido and Kapasky on line, they could just be reminants of componants that were already removed, just follow his fine instructions and after the removal of those files, if your system does not perk up, then it is a hardware problems that needs to be dealt with by calling Packard Bell. Ken
Hi Phil,

1. I misread my own handwriting. The file netpole.dll that was found by the Housecall scan should have read netpal2.dll, i.e. the same file as appeared in the results of the Kaspersky scan.

I performed the further analysis of netpal2.dll and sstep.dll and the results are as follows:

File: netpal2.dll
Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 4b1f35cd594a1229c58788b2e311d2a1
Packers detected: -
Scanner results
AntiVir Found nothing
ArcaVir Found Trojan.Adbreak.E
Avast Found nothing
AVG Antivirus Found BackDoor.Adbreak.F
BitDefender Found nothing
ClamAV Found Trojan.BHO-1
Dr.Web Found STPAGE.Trojan (probable variant)
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found Backdoor.Win32.Adbreak.e
NOD32 Found a variant of Win32/Adware.NetPal application
Norman Virus Control Found nothing
UNA Found nothing
VBA32 Found nothing

—————————————————————————————————————————

File: sstep.dll
Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 494777b05f15b579984e02e38d594d84
Packers detected: UPX
Scanner results
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found Trojan-Dropper.Win32.Small.so
NOD32 Found nothing
Norman Virus Control Found nothing
UNA Found nothing
VBA32 Found Adware.ShopAtHome.6 (probable variant)

—————————————————————————————————————————

This is a report processed by VirusTotal on 10/23/2005 at 23:31:01 (CET) after scanning the file "netpal2.dll" file.
Antivirus Version Update Result
AntiVir 6.32.0.6 10.22.2005 no virus found
Avast 4.6.695.0 10.21.2005 no virus found
AVG 718 10.21.2005 BackDoor.Adbreak.F
Avira 6.32.0.6 10.22.2005 no virus found
BitDefender 7.2 10.22.2005 no virus found
CAT-QuickHeal 8.00 10.22.2005 no virus found
ClamAV devel-20050917 10.21.2005 no virus found
DrWeb 4.32b 10.23.2005 no virus found
eTrust-Iris 7.1.194.0 10.23.2005 no virus found
eTrust-Vet 11.9.1.0 10.21.2005 no virus found
Fortinet 2.48.0.0 10.22.2005 no virus found
F-Prot 3.16c 10.20.2005 no virus found
Ikarus 0.2.59.0 10.21.2005 no virus found
Kaspersky 4.0.2.24 10.23.2005 Backdoor.Win32.Adbreak.e
McAfee 4610 10.21.2005 potentially unwanted program Adware-NetPals
NOD32v2 1.1263 10.21.2005 a variant of Win32/Adware.NetPal
Norman 5.70.10 10.21.2005 no virus found
Panda 8.02.00 10.23.2005 Adware/NetPals
Sophos 3.98.0 10.23.2005 no virus found
Symantec 8.0 10.23.2005 no virus found
TheHacker 5.8.4.127 10.21.2005 Adware/NetPals
VBA32 3.10.4 10.23.2005 no virus found

————————————————————————————————————————–

This is a report processed by VirusTotal on 10/23/2005 at 23:34:37 (CET) after scanning the file "sstep.dll" file.
Antivirus Version Update Result
AntiVir 6.32.0.6 10.22.2005 no virus found
Avast 4.6.695.0 10.21.2005 no virus found
AVG 718 10.21.2005 no virus found
Avira 6.32.0.6 10.22.2005 no virus found
BitDefender 7.2 10.22.2005 no virus found
CAT-QuickHeal 8.00 10.22.2005 no virus found
ClamAV devel-20050917 10.21.2005 no virus found
DrWeb 4.32b 10.23.2005 no virus found
eTrust-Iris 7.1.194.0 10.23.2005 no virus found
eTrust-Vet 11.9.1.0 10.21.2005 no virus found
Fortinet 2.48.0.0 10.22.2005 no virus found
F-Prot 3.16c 10.20.2005 no virus found
Ikarus 0.2.59.0 10.21.2005 no virus found
Kaspersky 4.0.2.24 10.23.2005 Trojan-Dropper.Win32.Small.so
McAfee 4610 10.21.2005 Generic MultiDropper.f
NOD32v2 1.1263 10.21.2005 no virus found
Norman 5.70.10 10.21.2005 no virus found
Panda 8.02.00 10.23.2005 Adware/SideStep
Sophos 3.98.0 10.23.2005 no virus found
Symantec 8.0 10.23.2005 no virus found
TheHacker 5.8.4.127 10.21.2005 Adware/180Solutions
VBA32 3.10.4 10.23.2005 suspected of Adware.ShopAtHome.6

————————————————————————————————————————

Do these results confirm that both files are infected and should be deleted (or cleaned)? Please confirm. I am not sure how exactly the malware removal tool you mentioned works.


2. I cleaned the items in the NAV quarantaine section.


3. I did a run with Spy Sweeper and the log of that is as follows:

********
23:55: | Start of Session, zondag 23 oktober 2005 |
23:55: Spy Sweeper started
23:55: Sweep initiated using definitions version 560
23:55: Starting Memory Sweep
23:57: Memory Sweep Complete, Elapsed Time: 00:01:51
23:57: Starting Registry Sweep
23:57: Registry Sweep Complete, Elapsed Time:00:00:17
23:57: Starting Cookie Sweep
23:57: Cookie Sweep Complete, Elapsed Time: 00:00:00
23:57: Starting File Sweep
0:06: Found System Monitor: ufp 007 spy
0:06: unins000.exe (ID = 48061)
0:06: Found Adware: ignkeys
0:06: nlnupgradev4_5p13.exe (ID = 63471)
0:11: uninstall unidream photoplayer.lnk (ID = 48061)
0:11: File Sweep Complete, Elapsed Time: 00:13:34
0:11: Full Sweep has completed. Elapsed time 00:15:47
0:11: Traces Found: 3
0:12: Removal process initiated
0:12: Quarantining All Traces: ufp 007 spy
0:12: Quarantining All Traces: ignkeys
0:12: Removal process completed. Elapsed time 00:00:01
********
23:47: | Start of Session, zondag 23 oktober 2005 |
23:47: Spy Sweeper started
23:48: Your spyware definitions have been updated.
23:55: | End of Session, zondag 23 oktober 2005 |


How bad are the traces that have been found?

4. We already ran Pitstop before. I ran it again at it gave no special results other than some obsolete registry entries.

5. My HJT log currently looks like this:

Logfile of HijackThis v1.99.1
Scan saved at 0:32:33, on 24-10-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Apps\ActivBoard\MMKeybd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Apps\ActivBoard\TrayMon.exe
C:\Apps\ActivBoard\nhksrv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Apps\ActivBoard\OSD.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijack This\hijackthis versie 1.99.0.1\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.planet.nl/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.planet.nl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer geleverd door CompuServe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Program Files\Netscape\Users\personal_investor_informer\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [PCPitstop Optimize Registration Reminder] C:\Program Files\PCPitstop\Optimize\Reminder.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Snelle start.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav…can_unicode.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - http://sib1.od2.com/common/Member/ClientIn…6/OCI/setup.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) - http://webdisk.planet.nl/webdisk/objects/u…geUploader3.cab
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprintit.de/ips-opdata/74914…IPSUploader.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect-service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

6. Any further feedback you received on the items in my previous post?

7. What should I do with illukka's remark? Should I install a kystroke logger????

Kind regards,
JvdV
OK, I am sure you are satisfied those files are bad, so remove them. I doubt they will make your computer run faster but they should don't need to be on it. Is NAV finding any of this stuff?

Killbox is a tool that will remove those files for you. This link includes a tutorial for it's use. This is a public link at a forum I know well, follow the instructions and you will have no problems:
http://forum.malwareremoval.com/viewtopic.php?t=320

How bad are the traces that have been found?

Hard to tell, but we have them quarantined. after a week or so, empty the quarantine area. I can't think of a valid program that does not quarantine, except Spybot S&D and it calls it something else, Recovery. All quarantine areas should be cleaned out on a regular basis.

We already ran Pitstop before. I ran it again at it gave no special results other than some obsolete registry entries.

We may have run the diagnostic at PCPitStop but this link is to a tool which is a free trial version that just came to me today in my most recent copy of Langalist: http://www.pcpitstop.com/store/optimizescan.asp It is worth a try.

Any further feedback you received on the items in my previous post?

Nope, any relevant information will be posted to you as I receive it.

What should I do with illukka's remark? Should I install a kystroke logger????

illukka is a good friend and a expert who I trust. He has only asked you a question here. He will give you only good advice and I suggest you supply any information he asks for if you can.

The question he asked again: To your knowledge

have you ever installed actmon keystroke logger ? or is it currently installed
http://www.actmon.com/

Logfile of HijackThis v1.99.1 Scan saved at 0:32:33, on 24-10-2005

Did you install this service? Do you know why it is there? I would like to remove it if you know of no reason for it being there.
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
http://www.liutilities.com/products/wintas…brary/cdac11ba/
Do you know what product on your computer it may be associated with?
You can see more here: http://www.google.com/search?sourceid=navc…=CDAC11BA%2EEXE

Thanks
hi this line: HKLM\System\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\ "UpperFilters" = INFECTION WARNING! "msikbd2k" ["Netropa Corporation"] was in your silent runners log it is evidence that this keylogger either is currently installed on your system, or it is a remnant of a removed installation we can dig this even further if you wish..
To Pskelly and Illukka:

Hi Phil and Illukka,

1. I deleted the two fies with Killbox. No, NAV did not find these files.

2. I think I ran that same Pitstop programme before. In order to execute the suggested actions I apparently have to register and to buy the software. I did not do that.

3. To my knowledge I have never installed a keystroke logger. It sounds bad. Can we investigate this further and have it removed?

4. I have no clue what the file CDAC11BA.EXE might be associated with. I have fixed the entry in HJT. My log now looks like this:

Logfile of HijackThis v1.99.1
Scan saved at 17:13:48, on 24-10-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Apps\ActivBoard\nhksrv.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Apps\ActivBoard\MMKeybd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Apps\ActivBoard\TrayMon.exe
C:\Apps\ActivBoard\OSD.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Hijack This\hijackthis versie 1.99.0.1\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.planet.nl/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.planet.nl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer geleverd door CompuServe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Program Files\Netscape\Users\personal_investor_informer\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [PCPitstop Optimize Registration Reminder] C:\Program Files\PCPitstop\Optimize\Reminder.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Snelle start.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav…can_unicode.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - http://sib1.od2.com/common/Member/ClientIn…6/OCI/setup.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) - http://webdisk.planet.nl/webdisk/objects/u…geUploader3.cab
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprintit.de/ips-opdata/74914…IPSUploader.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect-service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe



Regards,
JvdV
hi first, what version of norton antivirus you have, is it enabled to scan for security risks if that option is available if its not available we will have to search the files/reg entries manually. if that option is ther, enable it. then reboot to safe mode and do a scan with NAV save the report and post here
Hi Illukka, I have Norton Internet Security 2005. It comprises Norton Internet Security, Norton Anti Virus and Norton Anti Spam. I cannot find anything about scanning for security risks. Where should I look to find it? Or is it not there on this version of the Norton Software. Please advise. Kind regards, JvdV
please print this to see it in safe mode too
download registry search tools from here:
http://www.billsway.com/vbspage/
unzip the file to a folder on your desktop

Next, please reboot your computer in SafeMode by doing the following:

1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the first option, to run Windows in Safe Mode.


then
double click on regrch.vbs, into the field "enter string to search" type or copy paste 4D36E96B-E325-11CE-BFC1-08002BE10318
and hit ok
save the result and after rebooting back to normal mode post it here

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI