This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Daily popups/popunders! Please help

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been fighting this malware for a couple of weeks now! I have MS AntiSpyware, SpyBot S&D, AdShiels, AdAware, Ewido, Spyware Blaster, HJT, CWShredder, Symantec AV and they have all found infected items from time to time and I have quarantined or deleted the infections as instructed by the scanners, but I still have troubles. I get uninvited blank IE windows as well as Red Nova, Tizzle Talk, something that wants to translate German to English for me and a bunch of others throughout the day. I hope that you can help me! Thanks very much in advance. If this doesn't get me fixed up I eventually will have to restore the system and I would absolutely hate to give in to that.

Best regards,
Rick

Logfile of HijackThis v1.99.1
Scan saved at 9:07:28 AM, on 9/14/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\vyxbyv\bsrxwxc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\PROGRA~1\CYBERG~1\cgasvc.exe
C:\PROGRA~1\CYBERG~1\cgagent.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\hidserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\smsnm.exs
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\MS\SMS\CLICOMP\RemCtrl\Wuser32.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\CyberArmor\casvc.exe
C:\PROGRA~1\CYBERA~1\pcs.exe
C:\PROGRA~1\CYBERA~1\pcshelp.exe
C:\WINNT\MS\SMS\clicomp\apa\Bin\smsapm32.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\CyberArmor\pcshelp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINNT\MS\SMS\CORE\BIN\LAUNCH32.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\MS\SMS\CLICOMP\SWDist32\bin\smsmon32.exe
C:\WINNT\system32\ezSP_Px.exe
C:\PROGRA~1\CYBERG~1\cgav.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\CYBERG~1\cgahelp.exe
C:\WINNT\system32\jffsyoou\aaxfrk.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\AccessManager\Client\AccessMgr.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\WINNT\system32\DllHost.exe
C:\Documents and Settings\rdavis\Desktop\spystoppers\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ilsnet.sharpssg.com/
O1 - Hosts: 216.39.69.102 view.atdmt.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AdShield.AdShield - {7559B76E-0222-4d77-9499-CCE9EB4EDC2F} - C:\PROGRA~1\AdShield\AdShield\AdShield.dll
O4 - HKLM\..\Run: [CyberArmorHelper] C:\PROGRA~1\CyberArmor\pcshelp.exe -check
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SMS Application Launcher] C:\WINNT\MS\SMS\CORE\BIN\LAUNCH32.EXE
O4 - HKLM\..\Run: [cepdpn] C:\WINNT\system32\ukgho\cepdpn.exe
O4 - HKLM\..\Run: [cbfpjuma] C:\WINNT\system32\nmekd\cbfpjuma.exe
O4 - HKLM\..\Run: [qnvr] C:\WINNT\system32\kbvffdhs\qnvr.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINNT\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [CgaViewer] C:\PROGRA~1\CYBERG~1\cgav.exe -check
O4 - HKLM\..\Run: [CgaHelper] C:\PROGRA~1\CYBERG~1\cgahelp.exe -check
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [iqxgwkd] C:\WINNT\system32\luvfvg\iqxgwkd.exe
O4 - HKLM\..\Run: [fvdh] C:\WINNT\system32\nsvnn\fvdh.exe
O4 - HKLM\..\Run: [vomkt] C:\WINNT\system32\gxyg\vomkt.exe
O4 - HKLM\..\Run: [wofxxgak] C:\WINNT\system32\fsutfbu\wofxxgak.exe
O4 - HKLM\..\Run: [mqtlsy] C:\WINNT\system32\uhfxveuj\mqtlsy.exe
O4 - HKLM\..\Run: [ohwtrua] C:\WINNT\system32\keft\ohwtrua.exe
O4 - HKLM\..\Run: [lbpdksqo] C:\WINNT\system32\ctey\lbpdksqo.exe
O4 - HKLM\..\Run: [wrissjrj] C:\WINNT\system32\iailjc\wrissjrj.exe
O4 - HKLM\..\Run: [aaxfrk] C:\WINNT\system32\jffsyoou\aaxfrk.exe
O4 - HKLM\..\Run: [bsrxwxc] C:\WINNT\system32\vyxbyv\bsrxwxc.exe
O4 - HKLM\..\Run: [xlyi] C:\WINNT\system32\ajvvx\xlyi.exe
O4 - HKLM\..\Run: [rirmuwk] C:\WINNT\system32\urgsih\rirmuwk.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Access Manager Client.lnk = C:\Program Files\AccessManager\Client\AccessMgr.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://ilsnet.sharpssg.com
O15 - Trusted Zone: http://*.ilsnet (HKLM)
O15 - Trusted Zone: http://www.mindbuilder.com (HKLM)
O15 - Trusted Zone: http://www.sharp-service.com (HKLM)
O15 - Trusted Zone: http://*.sharpnet98 (HKLM)
O16 - DPF: Expense Report Solutions - http://tesprod/Exc.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1122045930264
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1122045911157
O16 - DPF: {A00D615E-B878-4DCF-8B9A-C1AD302D4C4D} (AssetAgent Class) - http://www.assetmetrix.com/epulse/assetMetrix.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://demos.webex.com/client/v_mywebex-t2…bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sharpssg.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sharpssg.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = sharpssg.com
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: bsrxwxcvyxbyv - Unknown owner - C:\WINNT\system32\vyxbyv\bsrxwxc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CyberGatekeeper Agent (CGAgent) - InfoExpress - C:\PROGRA~1\CYBERG~1\cgasvc.exe
O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\davis\Desktop\CWShredder.exe (file missing)
O23 - Service: CyberArmor Run Service (CyberArmorRunService) - InfoExpress - C:\Program Files\CyberArmor\casvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: qnvrkbvffdhs - Unknown owner - C:\WINNT\system32\kbvffdhs\qnvr.exe
O23 - Service: SMS Net Monitor - Sharp Electronics Corp. - C:\WINNT\System32\smsnm.exs
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
We are sorry for the delay in replying to you. If you still require help, please Post a fresh Hijackthis log as a reply to this thread. I'll receive an e-mail notification of your reply and will respond as soon as possible. Thank you for your patience.
Alan,

Thanks for your assistance here. I won't be mad about any delays if this system can be saved from the REIMAGER in the end. :)

Here is the new log. I have to admit that I went in and deleted a bunch of entries trying to fight this off myself.

Thanks again,
Rick

Logfile of HijackThis v1.99.1
Scan saved at 8:56:06 AM, on 10/7/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\PROGRA~1\CYBERG~1\cgasvc.exe
C:\PROGRA~1\CYBERG~1\cgagent.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\hidserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\kbvffdhs\qnvr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\smsnm.exs
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\CyberArmor\casvc.exe
C:\PROGRA~1\CYBERA~1\pcs.exe
C:\PROGRA~1\CYBERA~1\pcshelp.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\CyberArmor\pcshelp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\system32\nmekd\cbfpjuma.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\ezSP_Px.exe
C:\PROGRA~1\CYBERG~1\cgav.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\CYBERG~1\cgahelp.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINNT\system32\DllHost.exe
C:\WINNT\MS\SMS\CORE\BIN\LAUNCH32.EXE
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\AccessManager\Client\AccessMgr.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Documents and Settings\rdavis\Desktop\spystoppers\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ilsnet.sharpssg.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ilsnet.sharpssg.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AdShield.AdShield - {7559B76E-0222-4d77-9499-CCE9EB4EDC2F} - C:\PROGRA~1\AdShield\AdShield\AdShield.dll
O4 - HKLM\..\Run: [CyberArmorHelper] C:\PROGRA~1\CyberArmor\pcshelp.exe -check
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [cepdpn] C:\WINNT\system32\ukgho\cepdpn.exe
O4 - HKLM\..\Run: [cbfpjuma] C:\WINNT\system32\nmekd\cbfpjuma.exe
O4 - HKLM\..\Run: [qnvr] C:\WINNT\system32\kbvffdhs\qnvr.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINNT\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [CgaViewer] C:\PROGRA~1\CYBERG~1\cgav.exe -check
O4 - HKLM\..\Run: [CgaHelper] C:\PROGRA~1\CYBERG~1\cgahelp.exe -check
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [iqxgwkd] C:\WINNT\system32\luvfvg\iqxgwkd.exe
O4 - HKLM\..\Run: [fvdh] C:\WINNT\system32\nsvnn\fvdh.exe
O4 - HKLM\..\Run: [vomkt] C:\WINNT\system32\gxyg\vomkt.exe
O4 - HKLM\..\Run: [wofxxgak] C:\WINNT\system32\fsutfbu\wofxxgak.exe
O4 - HKLM\..\Run: [mqtlsy] C:\WINNT\system32\uhfxveuj\mqtlsy.exe
O4 - HKLM\..\Run: [ohwtrua] C:\WINNT\system32\keft\ohwtrua.exe
O4 - HKLM\..\Run: [lbpdksqo] C:\WINNT\system32\ctey\lbpdksqo.exe
O4 - HKLM\..\Run: [wrissjrj] C:\WINNT\system32\iailjc\wrissjrj.exe
O4 - HKLM\..\Run: [aaxfrk] C:\WINNT\system32\jffsyoou\aaxfrk.exe
O4 - HKLM\..\Run: [bsrxwxc] C:\WINNT\system32\vyxbyv\bsrxwxc.exe
O4 - HKLM\..\Run: [xlyi] C:\WINNT\system32\ajvvx\xlyi.exe
O4 - HKLM\..\Run: [rirmuwk] C:\WINNT\system32\urgsih\rirmuwk.exe
O4 - HKLM\..\Run: [ajegcej] C:\WINNT\system32\jchgq\ajegcej.exe
O4 - HKLM\..\Run: [sxfdfk] C:\WINNT\system32\lodekxwh\sxfdfk.exe
O4 - HKLM\..\Run: [sjmgmkqv] C:\WINNT\system32\taneaw\sjmgmkqv.exe
O4 - HKLM\..\Run: [cmfy] C:\WINNT\system32\vgolxvlv\cmfy.exe
O4 - HKLM\..\Run: [aymekdt] C:\WINNT\system32\iqkutl\aymekdt.exe
O4 - HKLM\..\Run: [drhd] C:\WINNT\system32\akdexbdj\drhd.exe
O4 - HKLM\..\Run: [ldcg] C:\WINNT\system32\iqsaatsk\ldcg.exe
O4 - HKLM\..\Run: [mxjud] C:\WINNT\system32\guvaene\mxjud.exe
O4 - HKLM\..\Run: [SMS Application Launcher] C:\WINNT\MS\SMS\CORE\BIN\LAUNCH32.EXE
O4 - HKLM\..\Run: [oqfqej] C:\WINNT\system32\fivgtl\oqfqej.exe
O4 - HKLM\..\Run: [rrmqaxvt] C:\WINNT\system32\wgdbfsa\rrmqaxvt.exe
O4 - HKLM\..\Run: [bucgl] C:\WINNT\system32\fcir\bucgl.exe
O4 - HKLM\..\Run: [tqcpgov] C:\WINNT\system32\qoxt\tqcpgov.exe
O4 - HKLM\..\Run: [tcorcvh] C:\WINNT\system32\favyn\tcorcvh.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Access Manager Client.lnk = C:\Program Files\AccessManager\Client\AccessMgr.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O14 - IERESET.INF: START_PAGE_URL=http://ilsnet.sharpssg.com
O15 - Trusted Zone: http://*.ilsnet (HKLM)
O15 - Trusted Zone: http://www.mindbuilder.com (HKLM)
O15 - Trusted Zone: http://www.sharp-service.com (HKLM)
O15 - Trusted Zone: http://*.sharpnet98 (HKLM)
O16 - DPF: Expense Report Solutions - http://tesprod/Exc.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1122045930264
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1122045911157
O16 - DPF: {A00D615E-B878-4DCF-8B9A-C1AD302D4C4D} (AssetAgent Class) - http://www.assetmetrix.com/epulse/assetMetrix.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://demos.webex.com/client/v_mywebex-t2…bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sharpssg.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sharpssg.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = sharpssg.com
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: aymekdtiqkutl - Unknown owner - C:\WINNT\system32\iqkutl\aymekdt.exe
O23 - Service: bsrxwxcvyxbyv - Unknown owner - C:\WINNT\system32\vyxbyv\bsrxwxc.exe
O23 - Service: bucglfcir - Unknown owner - C:\WINNT\system32\fcir\bucgl.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CyberGatekeeper Agent (CGAgent) - InfoExpress - C:\PROGRA~1\CYBERG~1\cgasvc.exe
O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\davis\Desktop\CWShredder.exe (file missing)
O23 - Service: CyberArmor Run Service (CyberArmorRunService) - InfoExpress - C:\Program Files\CyberArmor\casvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: drhdakdexbdj - Unknown owner - C:\WINNT\system32\akdexbdj\drhd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: qnvrkbvffdhs - Unknown owner - C:\WINNT\system32\kbvffdhs\qnvr.exe
O23 - Service: SMS Net Monitor - Sharp Electronics Corp. - C:\WINNT\System32\smsnm.exs
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Hello rickstar and welcome to TomCoyote. :wavey:

Step 1
You have Spybot S&D's Teatimer running which is good, but we need you to disable it for the remainder of the fix as it will interfere with the registry changes being made.
  • Open Spybot S&D in advanced mode, click Tools > Resident, and remove the check from "Resident Tea-Timer".
Be sure to re-enable this option again once the computer is clean.


Step 2
Open HijackThis, run a scan, then check the following:

O4 - HKLM\..\Run: [cepdpn] C:\WINNT\system32\ukgho\cepdpn.exe
O4 - HKLM\..\Run: [cbfpjuma] C:\WINNT\system32\nmekd\cbfpjuma.exe
O4 - HKLM\..\Run: [qnvr] C:\WINNT\system32\kbvffdhs\qnvr.exe
O4 - HKLM\..\Run: [iqxgwkd] C:\WINNT\system32\luvfvg\iqxgwkd.exe
O4 - HKLM\..\Run: [fvdh] C:\WINNT\system32\nsvnn\fvdh.exe
O4 - HKLM\..\Run: [vomkt] C:\WINNT\system32\gxyg\vomkt.exe
O4 - HKLM\..\Run: [wofxxgak] C:\WINNT\system32\fsutfbu\wofxxgak.exe
O4 - HKLM\..\Run: [mqtlsy] C:\WINNT\system32\uhfxveuj\mqtlsy.exe
O4 - HKLM\..\Run: [ohwtrua] C:\WINNT\system32\keft\ohwtrua.exe
O4 - HKLM\..\Run: [lbpdksqo] C:\WINNT\system32\ctey\lbpdksqo.exe
O4 - HKLM\..\Run: [wrissjrj] C:\WINNT\system32\iailjc\wrissjrj.exe
O4 - HKLM\..\Run: [aaxfrk] C:\WINNT\system32\jffsyoou\aaxfrk.exe
O4 - HKLM\..\Run: [bsrxwxc] C:\WINNT\system32\vyxbyv\bsrxwxc.exe
O4 - HKLM\..\Run: [xlyi] C:\WINNT\system32\ajvvx\xlyi.exe
O4 - HKLM\..\Run: [rirmuwk] C:\WINNT\system32\urgsih\rirmuwk.exe
O4 - HKLM\..\Run: [ajegcej] C:\WINNT\system32\jchgq\ajegcej.exe
O4 - HKLM\..\Run: [sxfdfk] C:\WINNT\system32\lodekxwh\sxfdfk.exe
O4 - HKLM\..\Run: [sjmgmkqv] C:\WINNT\system32\taneaw\sjmgmkqv.exe
O4 - HKLM\..\Run: [cmfy] C:\WINNT\system32\vgolxvlv\cmfy.exe
O4 - HKLM\..\Run: [aymekdt] C:\WINNT\system32\iqkutl\aymekdt.exe
O4 - HKLM\..\Run: [drhd] C:\WINNT\system32\akdexbdj\drhd.exe
O4 - HKLM\..\Run: [ldcg] C:\WINNT\system32\iqsaatsk\ldcg.exe
O4 - HKLM\..\Run: [mxjud] C:\WINNT\system32\guvaene\mxjud.exe
O4 - HKLM\..\Run: [oqfqej] C:\WINNT\system32\fivgtl\oqfqej.exe
O4 - HKLM\..\Run: [rrmqaxvt] C:\WINNT\system32\wgdbfsa\rrmqaxvt.exe
O4 - HKLM\..\Run: [bucgl] C:\WINNT\system32\fcir\bucgl.exe
O4 - HKLM\..\Run: [tqcpgov] C:\WINNT\system32\qoxt\tqcpgov.exe
O4 - HKLM\..\Run: [tcorcvh] C:\WINNT\system32\favyn\tcorcvh.exe

O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -

O23 - Service: aymekdtiqkutl - Unknown owner - C:\WINNT\system32\iqkutl\aymekdt.exe
O23 - Service: bsrxwxcvyxbyv - Unknown owner - C:\WINNT\system32\vyxbyv\bsrxwxc.exe
O23 - Service: bucglfcir - Unknown owner - C:\WINNT\system32\fcir\bucgl.exe
O23 - Service: drhdakdexbdj - Unknown owner - C:\WINNT\system32\akdexbdj\drhd.exe
O23 - Service: qnvrkbvffdhs - Unknown owner - C:\WINNT\system32\kbvffdhs\qnvr.exe


Optional items to check with HijackThis.
Fix if you or an administrator didn't set this Control Panel restriction in Internet Explorer or a program such as Spybot S&D wasn't used to set it.
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

With all other programs and browsers closed, click fix checked.


Step 3
Please set your computer to show all files.
  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.
You will need to reverse this process when all steps are done.


Step 4
Please delete the following folders:

C:\WINNT\system32\ukgho
C:\WINNT\system32\nmekd
C:\WINNT\system32\kbvffdhs
C:\WINNT\system32\luvfvg
C:\WINNT\system32\nsvnn
C:\WINNT\system32\gxyg
C:\WINNT\system32\fsutfbu
C:\WINNT\system32\uhfxveuj
C:\WINNT\system32\keft
C:\WINNT\system32\ctey
C:\WINNT\system32\iailjc
C:\WINNT\system32\jffsyoou
C:\WINNT\system32\vyxbyv
C:\WINNT\system32\ajvvx
C:\WINNT\system32\urgsih
C:\WINNT\system32\jchgq
C:\WINNT\system32\lodekxwh
C:\WINNT\system32\taneaw
C:\WINNT\system32\vgolxvlv
C:\WINNT\system32\iqkutl
C:\WINNT\system32\akdexbdj
C:\WINNT\system32\iqsaatsk
C:\WINNT\system32\guvaene
C:\WINNT\system32\fivgtl
C:\WINNT\system32\wgdbfsa
C:\WINNT\system32\fcir
C:\WINNT\system32\qoxt
C:\WINNT\system32\favyn
C:\WINNT\system32\iqkutl
C:\WINNT\system32\vyxbyv
C:\WINNT\system32\fcir
C:\WINNT\system32\akdexbdj
C:\WINNT\system32\kbvffdhs

If you have any problem deleting these items, reboot into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter') and try again.


Step 5
Go to start > run, then copy and paste the next commands in the field:

sc delete "aymekdtiqkutl"

Click OK

sc delete "bsrxwxcvyxbyv"

Click OK

sc delete "bucglfcir "

Click Ok

sc delete "drhdakdexbdj"

Click OK

sc delete "qnvrkbvffdhs"

Click OK


Step 6
Reboot normally and scan with HijackThis. Post the new log as a reply to this thread.
Please let us know of any complications you had and how the computer is behaving.
Alan,

Thanks for the help! That was interesting stuff! sc delete was not on my PC so I had to search to get the Win2K resource kit out to get the sc delete command to work, but I was able to find it! I kept getting the message that 'sc' or one of its components could not be found. I fixed that though!

I have finished all of the steps. I had some trouble with the folder kbvffdhs because qnvr.exe was 'in use' it said - probably creating new folders and copying itself several more times. So I did have to go into safe mode and kill it from there.

I have just finished and the PC seems stable and is behaving - No popups yet! I was told that it really looks like I am working hard too!

So here is the new HJT log after all is done. Please let me know if I need to do more.

Thanks much!
Rick

Logfile of HijackThis v1.99.1
Scan saved at 2:58:28 PM, on 10/7/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\PROGRA~1\CYBERG~1\cgasvc.exe
C:\PROGRA~1\CYBERG~1\cgagent.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\hidserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\smsnm.exs
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\CyberArmor\casvc.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\CYBERA~1\pcs.exe
C:\PROGRA~1\CYBERA~1\pcshelp.exe
C:\PROGRA~1\CyberArmor\pcshelp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\system32\ezSP_Px.exe
C:\PROGRA~1\CYBERG~1\cgav.exe
C:\PROGRA~1\CYBERG~1\cgahelp.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINNT\MS\SMS\CORE\BIN\LAUNCH32.EXE
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\AccessManager\Client\AccessMgr.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\DllHost.exe
C:\Documents and Settings\rdavis\Desktop\spystoppers\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ilsnet.sharpssg.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ilsnet.sharpssg.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AdShield.AdShield - {7559B76E-0222-4d77-9499-CCE9EB4EDC2F} - C:\PROGRA~1\AdShield\AdShield\AdShield.dll
O4 - HKLM\..\Run: [CyberArmorHelper] C:\PROGRA~1\CyberArmor\pcshelp.exe -check
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINNT\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [CgaViewer] C:\PROGRA~1\CYBERG~1\cgav.exe -check
O4 - HKLM\..\Run: [CgaHelper] C:\PROGRA~1\CYBERG~1\cgahelp.exe -check
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [SMS Application Launcher] C:\WINNT\MS\SMS\CORE\BIN\LAUNCH32.EXE
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Global Startup: Access Manager Client.lnk = C:\Program Files\AccessManager\Client\AccessMgr.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O14 - IERESET.INF: START_PAGE_URL=http://ilsnet.sharpssg.com
O15 - Trusted Zone: http://*.ilsnet (HKLM)
O15 - Trusted Zone: http://www.mindbuilder.com (HKLM)
O15 - Trusted Zone: http://www.sharp-service.com (HKLM)
O15 - Trusted Zone: http://*.sharpnet98 (HKLM)
O16 - DPF: Expense Report Solutions - http://tesprod/Exc.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {52A2AAAE-085D-4187-97EA-8C30DB990436} (HHCtrl Object) - http://studio1555.net/e3/hhctrl.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1122045930264
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1122045911157
O16 - DPF: {A00D615E-B878-4DCF-8B9A-C1AD302D4C4D} (AssetAgent Class) - http://www.assetmetrix.com/epulse/assetMetrix.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://demos.webex.com/client/v_mywebex-t2…bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sharpssg.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sharpssg.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = sharpssg.com
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CyberGatekeeper Agent (CGAgent) - InfoExpress - C:\PROGRA~1\CYBERG~1\cgasvc.exe
O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\davis\Desktop\CWShredder.exe (file missing)
O23 - Service: CyberArmor Run Service (CyberArmorRunService) - InfoExpress - C:\Program Files\CyberArmor\casvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SMS Net Monitor - Sharp Electronics Corp. - C:\WINNT\System32\smsnm.exs
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
One new item showing the latest HijackThis log. Everything else appears clean. :thumbup:

Step 1
Open HijackThis, run a scan, then check the following:

O16 - DPF: {52A2AAAE-085D-4187-97EA-8C30DB990436} (HHCtrl Object) - http://studio1555.net/e3/hhctrl.ocx

With all other programs and browsers closed, click fix checked.


Step 2
Reboot normally and scan with HijackThis. Post the new log as a reply to this thread.
Please let us know of any complications you had and how the computer is behaving. If everything is still working well, I'll give you some recommendations to better secure the computer.
Alan,

This is cool!! It seems like the computer is behaving now. Thanks a bunch! It may actually be starting up a bit faster as well!

I have fixed the item in the last entry as you pointed out. Here is the latest HJT log.

Thanks again,
Rick

Logfile of HijackThis v1.99.1
Scan saved at 9:10:27 AM, on 10/8/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\PROGRA~1\CYBERG~1\cgasvc.exe
C:\PROGRA~1\CYBERG~1\cgagent.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\hidserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\smsnm.exs
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\CyberArmor\casvc.exe
C:\PROGRA~1\CYBERA~1\pcs.exe
C:\PROGRA~1\CYBERA~1\pcshelp.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\CyberArmor\pcshelp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\system32\ezSP_Px.exe
C:\PROGRA~1\CYBERG~1\cgav.exe
C:\PROGRA~1\CYBERG~1\cgahelp.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINNT\MS\SMS\CORE\BIN\LAUNCH32.EXE
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AccessManager\Client\AccessMgr.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\DllHost.exe
C:\Documents and Settings\rdavis\Desktop\spystoppers\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ilsnet.sharpssg.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ilsnet.sharpssg.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AdShield.AdShield - {7559B76E-0222-4d77-9499-CCE9EB4EDC2F} - C:\PROGRA~1\AdShield\AdShield\AdShield.dll
O4 - HKLM\..\Run: [CyberArmorHelper] C:\PROGRA~1\CyberArmor\pcshelp.exe -check
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINNT\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [CgaViewer] C:\PROGRA~1\CYBERG~1\cgav.exe -check
O4 - HKLM\..\Run: [CgaHelper] C:\PROGRA~1\CYBERG~1\cgahelp.exe -check
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [SMS Application Launcher] C:\WINNT\MS\SMS\CORE\BIN\LAUNCH32.EXE
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Global Startup: Access Manager Client.lnk = C:\Program Files\AccessManager\Client\AccessMgr.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O14 - IERESET.INF: START_PAGE_URL=http://ilsnet.sharpssg.com
O15 - Trusted Zone: http://*.ilsnet (HKLM)
O15 - Trusted Zone: http://www.mindbuilder.com (HKLM)
O15 - Trusted Zone: http://www.sharp-service.com (HKLM)
O15 - Trusted Zone: http://*.sharpnet98 (HKLM)
O16 - DPF: Expense Report Solutions - http://tesprod/Exc.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1122045930264
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1122045911157
O16 - DPF: {A00D615E-B878-4DCF-8B9A-C1AD302D4C4D} (AssetAgent Class) - http://www.assetmetrix.com/epulse/assetMetrix.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://demos.webex.com/client/v_mywebex-t2…bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sharpssg.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sharpssg.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = sharpssg.com
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CyberGatekeeper Agent (CGAgent) - InfoExpress - C:\PROGRA~1\CYBERG~1\cgasvc.exe
O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\davis\Desktop\CWShredder.exe (file missing)
O23 - Service: CyberArmor Run Service (CyberArmorRunService) - InfoExpress - C:\Program Files\CyberArmor\casvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SMS Net Monitor - Sharp Electronics Corp. - C:\WINNT\System32\smsnm.exs
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Your new log appears clean. :)

Not much I can give you for programs to help protect the computer as you have most of the was I would normally recommend. I suggest that you download these programs to help keep the computer clean:

ie-spyad - Puts over 12,000 bad URLs into your restricted sites for Internet Explorer.
Google Toolbar - Blocks many unwanted pop-ups in Internet Explorer.
Firefox - 'Safer' alternative to the Internet Explorer web browser.

Update these regularly along with all of the malware scanners.

You may also want to read "So how did I get infected in the first place" or "Securing Your PC After An Attack" to learn how to better secure your computer.

Be sure to keep Windows and your Anti-virus updated.
Thanks for your help! I am so glad that I didn't have to go through reimaging my computer! I will follow your suggestions and if I can squeeze out the time, I'll also check out some of the training offered here. Perhaps I can help out some other poor soul in trouble. It is very, very nice to be able to use my PC without closing 4 or 5 IE windows first, each time! Thank you, thank you, thank you! Best always, Rick
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI