This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Uh oh.... losing battle.. need help!

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello! I'm a new member here and I've been reading a lot of the old threads regarding spyware/malware removal since I accidentally clicked open an e-mail. Now, I'm getting random popups every 5-10 minutes. :(

I have tried the latest AdAware SE , Spybot S&D, and just scanned with the latest trial version of Norton. Unfortunately, I'm still getting the pop ups. I would really appreciate it if someone can help me! Just want to say thanks in advance, I think you guys are great! :thumbup:

Here is my HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 12:42:10 AM, on 10/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\toshiba\ivp\swupdate\swupdtmr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Norton AntiVirus\OPScan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Sam Ho\My Documents\HiJackThis\HijackThis.exe

N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Documents and Settings\Sam Ho\Application Data\Mozilla\Profiles\default\ber9z2e6.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\Sam Ho\Application Data\Mozilla\Profiles\default\ber9z2e6.slt\prefs.js)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAcc…e/bridge-c7.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1115169301921
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O20 - Winlogon Notify: MediaContentIndex - C:\WINDOWS\system32\ennsl1571.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\U2FtIEhv\command.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\toshiba\ivp\swupdate\swupdtmr.exe
Hi Sam, welcome to TomCoyote forum. You do have some nasty stuff onboard, if you still need help and are not receiving it elsewhere, please start like this:

Please download the trial version of Spy Sweeper from here:
http://www.webroot.com/consumer/products/spysweeper

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it) If you receive alerts from your firewall, allow all activities for Spy Sweeper)

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.

When the sweep has finished, click Remove to remove any items found.

SpySweeper produces a log that I would like to see along with your new HJT log

Click on "Results" on the left, then "Session Log" at the top. Save the log, then copy and paste that in your next reply.

Reboot/restart your computer and post those two logs. We will have more to do.

Thanks…pskelley
TomCoyote forum
Expert Member
Hi! thanks for getting back to me…. since my first post, I have done a bit of manual cleaning myself (just because I really need the internet for work). I am not getting any more popups so far, but I believe the adware/virus is still hanging around somewhere. This is what I did: I found a post regarding having the file "guard.tmp" consistently showing up in windows/system32 along w/ 2 random .dll files, which all are unable to remove due to association w/ winlogon.exe and rundll32.exe. I followed their solution, which is to open guard.tmp w/ notepad and delete everything, then add the text "dummy". So far so good.. but I think this is only a temporary solution.

The following at the logs from Spy Sweeper and HJT, thank you for your help, please let me know what's the next step:

********
1:47 PM: | Start of Session, Saturday, October 29, 2005 |
1:47 PM: Spy Sweeper started
1:47 PM: Sweep initiated using definitions version 564
1:47 PM: Starting Memory Sweep
1:48 PM: Memory Sweep Complete, Elapsed Time: 00:01:06
1:48 PM: Starting Registry Sweep
1:48 PM: Registry Sweep Complete, Elapsed Time:00:00:08
1:48 PM: Starting Cookie Sweep
1:48 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
1:48 PM: Starting File Sweep
1:58 PM: File Sweep Complete, Elapsed Time: 00:10:23
1:58 PM: Full Sweep has completed. Elapsed time 00:11:42
1:58 PM: Traces Found: 0
********
1:28 PM: | Start of Session, Saturday, October 29, 2005 |
1:28 PM: Spy Sweeper started
1:28 PM: Sweep initiated using definitions version 564
1:28 PM: Starting Memory Sweep
1:30 PM: Memory Sweep Complete, Elapsed Time: 00:01:13
1:30 PM: Starting Registry Sweep
1:30 PM: Found Adware: cws_analyzeie
1:30 PM: HKCR\clsid\{60d75c7f-d119-4a89-b3b3-d8aa07ef3300}\ (ID = 116873)
1:30 PM: HKLM\software\classes\clsid\{60d75c7f-d119-4a89-b3b3-d8aa07ef3300}\ (ID = 116895)
1:30 PM: Found Adware: dialerplatform
1:30 PM: HKLM\software\ptssa\ (2 subtraces) (ID = 125166)
1:30 PM: Found Adware: subsearch
1:30 PM: HKCR\interface\{5a4e1627-8677-41f7-b78c-4cacdf5b12ff}\ (8 subtraces) (ID = 143047)
1:30 PM: HKCR\interface\{47d8f3a0-c511-4d91-a963-f00dddee4e49}\ (8 subtraces) (ID = 143049)
1:30 PM: HKLM\software\classes\interface\{5a4e1627-8677-41f7-b78c-4cacdf5b12ff}\ (8 subtraces) (ID = 143075)
1:30 PM: HKLM\software\classes\interface\{47d8f3a0-c511-4d91-a963-f00dddee4e49}\ (8 subtraces) (ID = 143077)
1:30 PM: Found Adware: targetsoft
1:30 PM: HKLM\software\microsoft\windows\currentversion\uninstall\tsl installer\ (1 subtraces) (ID = 143608)
1:30 PM: Found Adware: targetsaver
1:30 PM: HKLM\software\microsoft\windows\currentversion\uninstall\tsl installer\ (1 subtraces) (ID = 143608)
1:30 PM: Found Adware: winad
1:30 PM: HKLM\software\microsoft\code store database\distribution units\{15ad6789-cdb4-47e1-a9da-992ee8e6bad6}\ (10 subtraces) (ID = 147185)
1:30 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediaaccx.dll\ (2 subtraces) (ID = 147191)
1:30 PM: Found Adware: quicklink search toolbar
1:30 PM: HKCR\qlink.qlfilter\ (3 subtraces) (ID = 890588)
1:30 PM: HKCR\qlink.qlfilter.1\ (3 subtraces) (ID = 890592)
1:30 PM: HKCR\qlink.qlhelper\ (3 subtraces) (ID = 890596)
1:30 PM: HKCR\qlink.qlhelper.1\ (3 subtraces) (ID = 890600)
1:30 PM: HKCR\clsid\{aa3c0ffe-758e-4c41-b1b9-2d711915a938}\ (8 subtraces) (ID = 890604)
1:30 PM: HKCR\clsid\{e225ab73-4d7e-45f7-9425-47d2f7c7a8ab}\ (10 subtraces) (ID = 890613)
1:30 PM: HKCR\typelib\{090712ed-1622-4227-94d3-f573a9c2577f}\ (9 subtraces) (ID = 890624)
1:30 PM: HKLM\software\classes\qlink.qlfilter\ (3 subtraces) (ID = 890661)
1:30 PM: HKLM\software\classes\qlink.qlfilter.1\ (3 subtraces) (ID = 890665)
1:30 PM: HKLM\software\classes\qlink.qlhelper\ (3 subtraces) (ID = 890669)
1:30 PM: HKLM\software\classes\qlink.qlhelper.1\ (3 subtraces) (ID = 890673)
1:30 PM: HKLM\software\classes\clsid\{aa3c0ffe-758e-4c41-b1b9-2d711915a938}\ (8 subtraces) (ID = 890677)
1:30 PM: HKLM\software\classes\clsid\{e225ab73-4d7e-45f7-9425-47d2f7c7a8ab}\ (10 subtraces) (ID = 890686)
1:30 PM: Found Adware: instant access
1:30 PM: HKLM\software\classes\clsid\{e225ab73-4d7e-45f7-9425-47d2f7c7a8ab}\progid\ (1 subtraces) (ID = 890691)
1:30 PM: HKLM\software\classes\typelib\{090712ed-1622-4227-94d3-f573a9c2577f}\ (9 subtraces) (ID = 890697)
1:30 PM: HKLM\software\microsoft\windows\currentversion\explorer\browser qlhelper objects\{aa3c0ffe-758e-4c41-b1b9-2d711915a938}\ (ID = 909564)
1:30 PM: Found Adware: ist sidefind
1:30 PM: HKU\S-1-5-21-3126384089-3149985835-1891350246-1006\software\microsoft\internet explorer\extensions\cmdmapping\ || {10e42047-deb9-4535-a118-b3f6ec39b807} (ID = 141778)
1:30 PM: HKU\S-1-5-21-3126384089-3149985835-1891350246-1006\software\tsl2\ (1 subtraces) (ID = 143616)
1:30 PM: HKU\S-1-5-18\software\microsoft\internet explorer\extensions\cmdmapping\ || {10e42047-deb9-4535-a118-b3f6ec39b807} (ID = 141778)
1:30 PM: Registry Sweep Complete, Elapsed Time:00:00:09
1:30 PM: Starting Cookie Sweep
1:30 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
1:30 PM: Starting File Sweep
1:30 PM: Found Adware: advis
1:30 PM: c:\windows\configsys (2 subtraces) (ID = -2147481454)
1:30 PM: c:\documents and settings\all users\application data\ieservice (3 subtraces) (ID = -2147480200)
1:30 PM: v28.exe (ID = 77441)
1:34 PM: tsuninst.exe (ID = 78276)
1:35 PM: qlutility.exe (ID = 168232)
1:36 PM: preuninstallql.exe (ID = 131326)
1:37 PM: Found Adware: abetterinternet
1:37 PM: alchem.inf (ID = 83109)
1:37 PM: Found Adware: twain-tech
1:37 PM: polmx.inf (ID = 81856)
1:37 PM: File Sweep Complete, Elapsed Time: 00:07:19
1:37 PM: Full Sweep has completed. Elapsed time 00:08:46
1:37 PM: Traces Found: 171
1:43 PM: Removal process initiated
1:43 PM: Quarantining All Traces: abetterinternet
1:43 PM: Quarantining All Traces: cws_analyzeie
1:43 PM: Quarantining All Traces: advis
1:43 PM: Quarantining All Traces: dialerplatform
1:43 PM: Quarantining All Traces: instant access
1:43 PM: Quarantining All Traces: ist sidefind
1:43 PM: Quarantining All Traces: quicklink search toolbar
1:44 PM: Quarantining All Traces: subsearch
1:44 PM: Quarantining All Traces: targetsaver
1:44 PM: Quarantining All Traces: targetsoft
1:44 PM: Quarantining All Traces: twain-tech
1:44 PM: Quarantining All Traces: winad
1:44 PM: Removal process completed. Elapsed time 00:00:11
********
1:27 PM: | Start of Session, Saturday, October 29, 2005 |
1:27 PM: Spy Sweeper started
1:28 PM: Your spyware definitions have been updated.
1:28 PM: | End of Session, Saturday, October 29, 2005 |







Logfile of HijackThis v1.99.1
Scan saved at 2:11:08 PM, on 10/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Sam Ho\My Documents\HiJackThis\HijackThis.exe

N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Documents and Settings\Sam Ho\Application Data\Mozilla\Profiles\default\ber9z2e6.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\Sam Ho\Application Data\Mozilla\Profiles\default\ber9z2e6.slt\prefs.js)
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Copy Location - C:\WINDOWS\WEB\graburl.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra 'Tools' menuitem: Add to R&estricted Zone - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra button: (no name) - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra 'Tools' menuitem: Add to Tr&usted Zone - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra button: Offline - {FC09D8A3-C85A-11d2-92D0-0000F87A4A55} - C:\WINDOWS\system32\oline.dll
O15 - Trusted Zone: http://www.ncbi.nlm.nih.gov
O15 - Trusted Zone: http://mds.bussvc.wisc.edu
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1115169301921
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\U2FtIEhv\command.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
OK, thanks for the new logs, looks like Spysweeper killed what it was supposed to, let's see what is left.

Looks like you may have removed some programs also, you don't appear to be running in safe mode. It creates a bit of a problem when you post for help, then troubleshoot yourself. I can't judge exactly how my tools worked when this happens. Spysweeper has recently been updated to handle some of the nasties like the Look2me infection you had. There is no way to judge it not knowing exactly what you removed.

You have one nasty left that I can see: Command Service (cmdService) X command.exe Adware This one will also supply you with popups, please do this:
You can look at it here: http://www.spywareaid.com/023l.php?action=…e%20(cmdService

Disable the offending Service
Click Start < Run and type services.msc.
Scroll down to Command Service and right click on it.
Click Properties and under Service Status click Stop, then under Startup Type change it to Disabled.

Delete the offending Service
Open HijackThis and click Config -> Misc Tools -> Delete an NT service.
In the Delete window, type cmdService and press OK.
OK any prompts, close HijackThis, and restart your computer.

The line should be gone, but check it:

Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\U2FtIEhv\command.exe (file missing)

Close all programs but HJT and all browser windows, then click on "Fix Checked"

Post one more log along with your comments.
Thanks…Phil
Hi Phil. Thanks for your help. I was a bit desperate (deadlines at work) that's why I decided to go ahead w/ the temporary solution, sorry. I followed your instructions, here is the lastest HJT log after cleaing out the Command service:

(one side note: I didn't find O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll in this scan, is it something I should be worried about if it comes back?)

Logfile of HijackThis v1.99.1
Scan saved at 4:33:54 PM, on 10/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Documents and Settings\Sam Ho\My Documents\HiJackThis\HijackThis.exe
C:\Documents and Settings\Sam Ho\My Documents\HiJackThis\HijackThis.exe

N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Documents and Settings\Sam Ho\Application Data\Mozilla\Profiles\default\ber9z2e6.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\Sam Ho\Application Data\Mozilla\Profiles\default\ber9z2e6.slt\prefs.js)
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Copy Location - C:\WINDOWS\WEB\graburl.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra 'Tools' menuitem: Add to R&estricted Zone - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra button: (no name) - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra 'Tools' menuitem: Add to Tr&usted Zone - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra button: Offline - {FC09D8A3-C85A-11d2-92D0-0000F87A4A55} - C:\WINDOWS\system32\oline.dll
O15 - Trusted Zone: http://www.ncbi.nlm.nih.gov
O15 - Trusted Zone: http://mds.bussvc.wisc.edu
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1115169301921
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Thanks for that information, it is just a little rough doing a fix without complete control, This item: O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll is the marker for Spysweeper. Let's look at the log and see how you did.
HJT is running twice in this log, did you open it twice. Check to make sure you only have one instance of it onboard, if there are two, delete one.

I passed over these assuming there are valid:
O15 - Trusted Zone: http://www.ncbi.nlm.nih.gov
O15 - Trusted Zone: http://mds.bussvc.wisc.edu
If you do not want these in the trusted zone, use HJT to remove them.

You HJT log is clean so here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://boards.cexx.org/viewtopic.php?t=957
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Safe surfing…Phil

Thanks…pskelley
TomCoyote forum
Expert Member
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
Hi Phil, Great! glad to hear that I'm clean. Yea, I accidentally opened HJT twice so it got listed twice… thanks again for all your help, I really appreciate it. Hope you had a great weekend, take care! Sam
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI