This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Flashing cursor and no control alt delete

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My cursor has started flashing from the standard white arrow to the busy (hour glass) arrow every second. Also when i press control, alt and delete i dont get a window showing me what programs are running, and i can press control, alt and delete numerous times and it does nothing.

I'd really appreciate some help with it as its bugging me big time (pardon the pun). Think i will have to go for a reformat if i cant get help here and i dont fancy that…..i'm not very hot with computers!

Anyway heres my hijackthis log file:

Logfile of HijackThis v1.99.1
Scan saved at 01:40:56, on 30/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\Program Files\ZyXEL\ADSL USB Modem\CnxDslTb.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\ONSPEED\onspeedcore.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE
C:\WINDOWS\ddgefl.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\ONSPEED\onspeedgui.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\FRU\Remind32.exe
C:\Program Files\blcorp\WinCleaner AntiSpyware\WCAntiSpy.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Bob\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5400
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\Program Files\ONSPEED\PBHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ONSPEED - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - C:\Program Files\ONSPEED\Toolband.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [pdfFactory Dispatcher v2] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZyXEL\ADSL USB Modem\CnxDslTb.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [SlipStream] "C:\Program Files\ONSPEED\onspeedcore.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R1800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE /P24 "EPSON Stylus Photo R1800" /O6 "USB001" /M "Stylus Photo R1800"
O4 - HKLM\..\Run: [yAGsH] C:\WINDOWS\ddgefl.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: Hewlett-Packard Recorder.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\FRU\Remind32.exe
O4 - Startup: WCAntiSpy.lnk = C:\Program Files\blcorp\WinCleaner AntiSpyware\WCAntiSpy.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: ONSPEED.lnk = C:\Program Files\ONSPEED\onspeedgui.exe
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/…tail/DASAct.cab
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://D:\SuperCD\IntraLaunch.CAB
O16 - DPF: {C1BAC744-8F0B-11D0-89E7-00C0A8295197} (Cameractl Class) - http://www.nwales-traffic.co.uk/files/activex/camera.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?321
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE05D28B-3E6B-4585-9B8A-D67B0557F12B}: NameServer = 195.184.228.6 195.184.228.7
O23 - Service: BackupClientSvc - Unknown owner - C:\PROGRA~1\MYDATA~1\BackupClientSvc.Exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hi Bob, I am not sure what is causing the cursor to act up but you do have some junk that needs to go. You have a New.Net hijacker. I have yet to find anyone who downloaded this junk on purpose, if you are the first, stop and make me aware of that fact. If not, use these instructions to remove this hijacker: http://www.newdotnet.com/removal.html
Here is what New.Net looks like in the log so you will know when it is gone: O10 - Hijacked Internet access by New.Net

Now read these instructions: http://securityresponse.symantec.com/avcen…are.istbar.html then download and run the removal tool.

Please move HJT from the Desktop, I prefer here: C:\HJT\HijackThis.exe. If you must run from the Desktop, we need a folder where I have indicated the need in red to protect logs and backups for safety.
C:\Documents and Settings\Bob\Desktop\HJT\HijackThis.exe

Post a new HJT log in this same tread, there will be more to do.

Thanks…pskelley
TomCoyote forum
Expert Member
Hi PK, I have done as you asked regarding C:\HJT\HijackThis.exe —- I have also managed to uninstall NewDotNet. I was prompted to do a reboot and did so, then ran HJT again and it has been removed. Also downloaded the symantec removal tool and successfully removed the istbar problem. It reported 2 files deleted, 1 directory deleted and 20 registry entries fixed. Anyway, I have managed to fix the cursor problem and have checked for and removed spywear a number of times since posting the above log. I hope this doesn’t cause a problem for you! I also have a real problem now with IE, as it keeps locking up/crashing on me and I can’t access the internet very easily. It’s become a real issue. (this was the case before i carried out the steps above….so no worries about me blaming you….not that i would anyway!). When you say post a new log in the same thread, do you mean here: TomCoyote Forums > Computer Help > HijackThis Logs and Spyware/Malware Removal I'll await your reply to confirm this (or not) before i carry on and post my new HJT log Sorry this post turned out so large …..and for being thick! Your help is greatly appreciated ….. Thank you very much! :thumbup:
Post the new HJT log the same way you posted the first one. I will not know what has occured or if you completed the instructions I gave you until I see the new log. Thanks…Phil Simply click on Add Reply at the bottom and copy/paste the new log.
Sorry about the missunderstanding, i was sure i read somewhere that you had to post a new topic everytime you posted a log….maybe i missinterpreted.

I didnt do anything with the lines you underlined in my HJT log. The reasons being -

1) i have tried to fix things since posting the log above and therefore wasnt sure if it was ok to make changes.

2) I am not sure whether i should delete the entire line or just the section that has been underlined.

I have tried to find the intructions again but just cannot seem to locate them. But i assume from what i did manage to find was that i just check the box in HJT at the appropriate line and clear it (which would address my problem number 2 above)….would this be correct?

Ok Phil, sorry if i'm a pain, but i'm trying my best believe it or not. :huh: Is it ok to delete the previouse log from my computer now?? I will be sure and wait for your reply this time —Anyway heres my new HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 11:02:00, on 04/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\Program Files\ZyXEL\ADSL USB Modem\CnxDslTb.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\ONSPEED\onspeedcore.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\ONSPEED\onspeedgui.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\FRU\Remind32.exe
C:\Program Files\blcorp\WinCleaner AntiSpyware\WCAntiSpy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5400
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\Program Files\ONSPEED\PBHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: LinkTracker Class - {85A77577-A8CA-41b7-AA1E-DDAD4C0B12B1} - C:\WINDOWS\system32\hlwin.dll
O2 - BHO: Accoona Search Assistant - {944864A5-3916-46E2-96A9-A2E84F3F1208} - C:\Documents and Settings\Bob\Local Settings\Temp\ASearchAssist.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ONSPEED - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - C:\Program Files\ONSPEED\Toolband.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [pdfFactory Dispatcher v2] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZyXEL\ADSL USB Modem\CnxDslTb.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [SlipStream] "C:\Program Files\ONSPEED\onspeedcore.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R1800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE /P24 "EPSON Stylus Photo R1800" /O6 "USB001" /M "Stylus Photo R1800"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: Hewlett-Packard Recorder.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\FRU\Remind32.exe
O4 - Startup: WCAntiSpy.lnk = C:\Program Files\blcorp\WinCleaner AntiSpyware\WCAntiSpy.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: ONSPEED.lnk = C:\Program Files\ONSPEED\onspeedgui.exe
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Show All Original Images - res://C:\Program Files\ONSPEED\gui_resource.dll/327
O8 - Extra context menu item: Show Original Image - res://C:\Program Files\ONSPEED\gui_resource.dll/328
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1131071378661
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/…tail/DASAct.cab
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://D:\SuperCD\IntraLaunch.CAB
O16 - DPF: {C1BAC744-8F0B-11D0-89E7-00C0A8295197} (Cameractl Class) - http://www.nwales-traffic.co.uk/files/activex/camera.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?321
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by103fd.bay103.hotmail.msn.com/activex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE05D28B-3E6B-4585-9B8A-D67B0557F12B}: NameServer = 195.184.228.6 195.184.228.7
O18 - Filter: text/html - {03974811-C15F-462c-B6B0-2D2336AA57D0} - C:\WINDOWS\system32\hlwin.dll
O23 - Service: BackupClientSvc - Unknown owner - C:\PROGRA~1\MYDATA~1\BackupClientSvc.Exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hi, and I do understand this can be a little confusing the first time. All you need to do is focus on me and what I tell you to do and all will go well. I am going to answer your questions and send this information. Right after that I will post again with instruction AFTER I review the log you just sent me. Don't be afraid to ask questions, that's how we all started.

Sorry about the missunderstanding, i was sure i read somewhere that you had to post a new topic everytime you posted a log….maybe i missinterpreted

This is a NO, stay in this thread where we are working, if you start new topics it adds to the confusion and I am not notified when you post the new ones. Anytime you post in this topic I am notified so I can respond.
The balance of the information I am not going to read so I don't get confused also…lol.
Everything from the beginning is in this same thread, just scroll up and down to see past instructions. Once I review the new HJT log, I will post instructions and it may appear I am getting very detailed, but I want to make sure you understand. If you do not understand something, post a question in the same thread. I want you to look at the new instructions and follow them carefully.

Thanks…Phil
Here is what I want you to do, read the instructions carefully, you may want to print them. Unless you know something is not bad allow ewido to delete the items it finds. Make sure you save the report, I must see it.

Please download Ewido Security Suite it is a trial version of the program.
  • Install ewido security suite
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update Ewido.
Ewido manual updates

Once the updates are installed do the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • NOTE: During some scans with ewido it is finding cases of false positives.**
    • You will need to step through the process of cleaning files one-by-one.
    • If ewido detects a file you KNOW to be legitimate, select none as the action.
    • DO NOT select "Perform action on all infections"
    • If you are unsure of any entry found select none for now.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.
**(Ewido for example has been flagging parts of AVG Anti-Virus, pcAnywhere and the game "Risk")

Once the above is completed, then do this:

Open HJT and click on "Do a system scan only" In the small boxes in front of the lines, I want you to put a check in these boxes, some may not be there if ewido removed them, just do not miss any.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: LinkTracker Class - {85A77577-A8CA-41b7-AA1E-DDAD4C0B12B1} - C:\WINDOWS\system32\hlwin.dll
O2 - BHO: Accoona Search Assistant - {944864A5-3916-46E2-96A9-A2E84F3F1208} - C:\Documents and Settings\Bob\Local Settings\Temp\ASearchAssist.dll
O18 - Filter: text/html - {03974811-C15F-462c-B6B0-2D2336AA57D0} - C:\WINDOWS\system32\hlwin.dll

Make sure all programs and all browser windows are closed, then click on "Fix Checked".

Use the instructions in the link to enable hidden files and folders:
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

RIGHT click on START. then click on Explore. I want you to locate this:

C:\Documents and Settings\Bob\Local Settings\Temp\ <<< delete everything in that TEMP folder (NOT THE FOLDER)

Open this folder: C:\WINDOWS\system32\hlwin.dll >>> file
If the file in red is there delete it and move on to the next instruction

Empty your Recycle Bin and restart your computer. Open HJT and choose "Do a system scan and save a logfile", wait until the notepad opens with the logfile in it. Now click on Edit at the top then Select all. The contents of the notepad will be highlited. Copy and Paste that log and the ewido scan results to THIS SAME TOPIC then wait for my next instructions.

Thanks…Phil
Ok Phil, I have done all but the very last of the instructions from your last reply. I just need to know if it is ok for me to delete my previous HJT log files????? Thanks again …….Stewart (Bobs my dad :weee: )
Hi Stewart, are you talking about HJT logs that are in the folder here: C:\HJT\HijackThis.exe? Do not concern yourself with those logs at this point. You will also have a folder for backups once you remove items with HJT. Once we are all finished, you can remove all but the most recent log, but for now, just leave them alone. A mouse over will tell you when the log was created. I do suggest you print the log that we are using at the time I tell you that you are clean. You can compare that log against future logs to spot new stuff that might note belong there.

Thanks…Phil
:wavey:
Hi again,

Yeah i was refering to the previous HJT logs, i have made a seperate folder for the older ones just to keep them all seperste from the current one.

OK, as soon as the EWIDO scan was complete i was presented with a pop up box with the folowing in it:

The file "C:\Documents and Settings\Bob\Local Settings\Temp\wh.exe/whAgent.exe" cannot be removed as it is embedded in the archive "C:\Documents and Settings\Bob\Local Settings\Temp\wh.exe". Do you want to remove the whole archive? YES or NO?

Had no idea what this meant so just chose NO!

Anyway, is the latest HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 19:58:47, on 04/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\Program Files\ZyXEL\ADSL USB Modem\CnxDslTb.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\ONSPEED\onspeedcore.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\ONSPEED\onspeedgui.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\FRU\Remind32.exe
C:\Program Files\blcorp\WinCleaner AntiSpyware\WCAntiSpy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5400
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\Program Files\ONSPEED\PBHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ONSPEED - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - C:\Program Files\ONSPEED\Toolband.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [pdfFactory Dispatcher v2] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZyXEL\ADSL USB Modem\CnxDslTb.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [SlipStream] "C:\Program Files\ONSPEED\onspeedcore.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R1800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE /P24 "EPSON Stylus Photo R1800" /O6 "USB001" /M "Stylus Photo R1800"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: Hewlett-Packard Recorder.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\FRU\Remind32.exe
O4 - Startup: WCAntiSpy.lnk = C:\Program Files\blcorp\WinCleaner AntiSpyware\WCAntiSpy.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: ONSPEED.lnk = C:\Program Files\ONSPEED\onspeedgui.exe
O8 - Extra context menu item: Send To &Bluetooth; - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Show All Original Images - res://C:\Program Files\ONSPEED\gui_resource.dll/327
O8 - Extra context menu item: Show Original Image - res://C:\Program Files\ONSPEED\gui_resource.dll/328
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1131071378661
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/…tail/DASAct.cab
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://D:\SuperCD\IntraLaunch.CAB
O16 - DPF: {C1BAC744-8F0B-11D0-89E7-00C0A8295197} (Cameractl Class) - http://www.nwales-traffic.co.uk/files/activex/camera.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?321
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by103fd.bay103.hotmail.msn.com/activex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE05D28B-3E6B-4585-9B8A-D67B0557F12B}: NameServer = 195.184.228.6 195.184.228.7
O23 - Service: BackupClientSvc - Unknown owner - C:\PROGRA~1\MYDATA~1\BackupClientSvc.Exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


And Here is the EWIDO log:

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 17:05:14, 04/11/2005
+ Report-Checksum: AC8130C3

+ Scan result:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Spyware.InternetOptimizer : Ignored
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Spyware.InternetOptimizer : Ignored
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webHancer Agent -> Spyware.WebHancer : Ignored
HKLM\SOFTWARE\webHancer -> Spyware.Webhancer : Ignored
HKLM\SOFTWARE\webHancer\CC -> Spyware.Webhancer : Ignored
HKLM\SOFTWARE\webHancer\ESO -> Spyware.Webhancer : Ignored
HKU\S-1-5-21-790525478-920026266-1343024091-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8} -> Spyware.InternetOptimizer : Ignored
HKU\S-1-5-21-790525478-920026266-1343024091-1004\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Spyware.InternetOptimizer : Ignored
:mozilla.31:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Fastclick : Ignored
:mozilla.53:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Mediaplex : Ignored
:mozilla.61:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Overture : Ignored
:mozilla.62:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Overture : Ignored
:mozilla.75:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Doubleclick : Ignored
C:\Documents and Settings\Bob\Cookies\bob@2o7[2].txt -> Spyware.Cookie.2o7 : Ignored
C:\Documents and Settings\Bob\Cookies\[removed][1].txt -> Spyware.Cookie.Pointroll : Ignored
C:\Documents and Settings\Bob\Cookies\bob@atdmt[2].txt -> Spyware.Cookie.Atdmt : Ignored
C:\Documents and Settings\Bob\Cookies\bob@com[2].txt -> Spyware.Cookie.Com : Ignored
C:\Documents and Settings\Bob\Cookies\bob@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Ignored
C:\Documents and Settings\Bob\Local Settings\Temp\Del295.tmp -> Spyware.180Solutions : Ignored
C:\Program Files\Internet Optimizer -> Spyware.InternetOptimizer : Ignored
C:\Program Files\Power Scan -> Spyware.PowerScan : Ignored
C:\Program Files\Power Scan\powerscan.exe -> Spyware.PowerScan : Ignored
C:\Program Files\Power Scan\uninstall.exe -> Spyware.PowerScan : Ignored
C:\Program Files\SurfAccuracy -> Adware.SurfAccuracy : Ignored
C:\Program Files\SurfAccuracy\License.lnk -> Adware.SurfAccuracy : Ignored
C:\Program Files\SurfAccuracy\SAcc.cfg -> Adware.SurfAccuracy : Ignored
C:\Program Files\SurfAccuracy\SAcc.exe -> Adware.SurfAccuracy : Ignored
C:\Program Files\SurfAccuracy\SAccU.exe -> Adware.SurfAccuracy : Ignored
C:\Program Files\whInstall\webhdll.dll -> Spyware.WebHancer : Ignored
C:\Program Files\whInstall\whInstaller.exe -> Spyware.WebHancer : Ignored
C:\WINDOWS\system32\hlwin.dll -> Spyware.Suggestor : Ignored
HKLM\SOFTWARE\Classes\Interface\{03B800F9-2536-4441-8CDA-2A3E6D15B4F8} -> Spyware.YourSiteBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{03B800F9-2536-4441-8CDA-2A3E6D15B4F8}\TypeLib\\ -> Spyware.YourSiteBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{DFBCC1EB-B149-487E-80C1-CC1562021542} -> Spyware.YourSiteBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{DFBCC1EB-B149-487E-80C1-CC1562021542}\TypeLib\\ -> Spyware.YourSiteBar : Cleaned with backup
HKLM\SOFTWARE\Classes\LinkMaker.LinkMakerFilter -> Spyware.LinkMaker : Cleaned with backup
HKLM\SOFTWARE\Classes\LinkMaker.LinkMakerFilter\CLSID -> Spyware.LinkMaker : Cleaned with backup
HKLM\SOFTWARE\Classes\LinkMaker.LinkMakerFilter.1 -> Spyware.LinkMaker : Cleaned with backup
HKLM\SOFTWARE\Classes\LinkMaker.LinkTracker -> Spyware.LinkMaker : Cleaned with backup
HKLM\SOFTWARE\Classes\LinkMaker.LinkTracker\CLSID -> Spyware.LinkMaker : Cleaned with backup
HKLM\SOFTWARE\Classes\LinkMaker.LinkTracker.1 -> Spyware.LinkMaker : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{4EE12B71-AA5E-45EC-8666-2DB3AD3FDF44} -> Spyware.YourSiteBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YourSiteBar -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\YourSiteBar -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\YourSiteBar\Historyfiles -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-790525478-920026266-1343024091-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10E42047-DEB9-4535-A118-B3F6EC39B807} -> Spyware.SideFind : Cleaned with backup
HKU\S-1-5-21-790525478-920026266-1343024091-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -> Spyware.PopularScreensavers : Cleaned with backup
HKU\S-1-5-21-790525478-920026266-1343024091-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Spyware.NewDotNet : Cleaned with backup
HKU\S-1-5-21-790525478-920026266-1343024091-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227D9C-0EFE-4F8A-AA55-30386A3F5686} -> Spyware.YourSiteBar : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\dgrkl3np.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Bob\Cookies\bob@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Bob\Cookies\[removed][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Bob\Cookies\bob@hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Bob\Cookies\bob@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Bob\Cookies\bob@microsofteup.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Bob\Cookies\bob@paycounter[1].txt -> Spyware.Cookie.Paycounter : Cleaned with backup
C:\Documents and Settings\Bob\Cookies\bob@statcounter[1].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Bob\Cookies\[removed][2].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\Bob\Cookies\bob@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Bob\Local Settings\Temp\Cookies\bob@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Bob\Local Settings\Temp\fLkynvo.exe -> TrojanDownloader.IstBar.lw : Cleaned with backup
C:\Documents and Settings\Bob\Local Settings\Temp\optimize.exe -> TrojanDownloader.Dyfuca.ei : Cleaned with backup
C:\Documents and Settings\Bob\Local Settings\Temp\SHNT288.exe -> Spyware.NewDotNet : Cleaned with backup
C:\Documents and Settings\Bob\Local Settings\Temp\sidefind.exe -> TrojanDownloader.IstBar.jm : Cleaned with backup
C:\Documents and Settings\Bob\Local Settings\Temp\wh.exe/whAgent.exe -> Spyware.WebHancer : Error during cleaning
C:\Program Files\SideFind\update\sidefind.exe -> TrojanDownloader.IstBar.jm : Cleaned with backup
C:\WINDOWS\NDNuninstall6_98.exe -> Adware.NewDotNet : Cleaned with backup


::Report End



Hope i have done everything correctly…….thanks again phil. :thumbup:
Stewart, here is what I am finding out about this item:

The file "C:\Documents and Settings\Bob\Local Settings\Temp\wh.exe/whAgent.exe" cannot be removed as it is embedded in the archive "C:\Documents and Settings\Bob\Local Settings\Temp\wh.exe". Do you want to remove the whole archive? YES or NO?

http://www.liutilities.com/products/wintas…ibrary/whagent/ <<< bad!!

You have also ignored items in the ewido scan. Those items are all bad. Here is what I want you to do. First, open ewido and then choose UPDATE. After the program is updated, close the program and follow these instructions to start you computer in safe mode:
http://www.bleepingcomputer.com/forums/tutorial61.html
Once in safe mode, open ewido and run a scan. I looked at the log and everything you ignored is bad stuff. As ewido scans, choose to delete everything it locates. Once the scan is complete, don't forget to save the log. Post that log for me to view.

Thanks…Phil
Hi Stewart, I have a few questions about the HJT log.
Logfile of HijackThis v1.99.1 Scan saved at 19:58:47, on 04/11/2005 This item: WinCleaner AntiSpyware, did you purchase it? It is considered rouge spyware by my authority on spyware products and I suggest you remove it from your computer. I will suggest freeware products to replace it. http://www.spywarewarrior.com/rogue_anti-spyware.htm

This program: C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe is out of date, and a security issue. Open your Control Panel and locate the coffee cup. Open the Java console and update to the newest version. If no one is updating manually, I suggest you set updates to automatic.

Since I see no "malware" in the log, here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://boards.cexx.org/viewtopic.php?t=957
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

You will find suggestions for good, freeware products within those links to replace the rouge products and enhance your security. You also have programs running at startup that you can turn off in MSConfig and save resources and help you to run a little faster. If you wish this information, let me know. If you have plenty of resources and speed is not an issue, you may wish to leave them alone??

Post the ewido log run in safe mode and you may be finished. If you have any questions about the above information, let me know.

Thanks…Phil
Hi Phil,

Tried to get updates for Java but was greated with this message:

This installation package could not be opened. Verify that the package exists and that you can access it, or contact the application vendor to verify that this is a valid Windows Installer Pack.

Regarding WinCleaner AntiSpyware, this was installed as a free download on the machine by my father before he gave it to me. I have uninstalled WinCleaner AntiSpyware and have gone for Spybot Search and Destroy, and Ad Aware (which i had on another machine), which have now both been installed and updated but no system scan has been done yet. Also went for SpywareBlaster, which I have not installed yet as I am unsure what it is, how it functions and (everything really….lol) how to use it and want to get things moving with the rest of the issues first.

Quote from your previous reply “You also have programs running at startup that you can turn off in MSConfig and save resources and help you to run a little faster”—– I would be interested to hear more about this…..thanks.

I was wandering if you don need to see another HJT log?

Heres hoping this time then eh…… :)

Heres the latest Ewido log then:

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 23:23:08, 04/11/2005
+ Report-Checksum: CD6A0A07

+ Scan result:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Spyware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Spyware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webHancer Agent -> Spyware.WebHancer : Cleaned with backup
HKLM\SOFTWARE\webHancer -> Spyware.Webhancer : Cleaned with backup
HKLM\SOFTWARE\webHancer\CC -> Spyware.Webhancer : Cleaned with backup
HKLM\SOFTWARE\webHancer\ESO -> Spyware.Webhancer : Cleaned with backup
HKU\S-1-5-21-790525478-920026266-1343024091-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8} -> Spyware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-790525478-920026266-1343024091-1004\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Spyware.InternetOptimizer : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\q32m68oy.me\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Bob\Cookies\bob@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Bob\Cookies\[removed][1].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Bob\Cookies\bob@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Bob\Cookies\bob@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Bob\Cookies\bob@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Bob\Cookies\bob@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
C:\Documents and Settings\Bob\Cookies\bob@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\HJT\backups\backup-20051104-172009-833.dll -> Spyware.Suggestor : Cleaned with backup
C:\Program Files\Internet Optimizer -> Spyware.InternetOptimizer : Cleaned with backup
C:\Program Files\Power Scan -> Spyware.PowerScan : Cleaned with backup
C:\Program Files\Power Scan\powerscan.exe -> Spyware.PowerScan : Cleaned with backup
C:\Program Files\Power Scan\uninstall.exe -> Spyware.PowerScan : Cleaned with backup
C:\Program Files\SurfAccuracy -> Adware.SurfAccuracy : Cleaned with backup
C:\Program Files\SurfAccuracy\License.lnk -> Adware.SurfAccuracy : Cleaned with backup
C:\Program Files\SurfAccuracy\SAcc.cfg -> Adware.SurfAccuracy : Cleaned with backup
C:\Program Files\SurfAccuracy\SAcc.exe -> Adware.SurfAccuracy : Cleaned with backup
C:\Program Files\SurfAccuracy\SAccU.exe -> Adware.SurfAccuracy : Cleaned with backup
C:\Program Files\whInstall\webhdll.dll -> Spyware.WebHancer : Cleaned with backup
C:\Program Files\whInstall\whInstaller.exe -> Spyware.WebHancer : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00086052.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00086371.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00086373.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00086376.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\RECYCLER\NPROTECT\00087024.exe -> TrojanDownloader.IstBar.jm : Cleaned with backup
C:\RECYCLER\NPROTECT\00087025.EXE -> Adware.NewDotNet : Cleaned with backup
C:\RECYCLER\NPROTECT\00087042.dll -> Spyware.Suggestor : Cleaned with backup


::Report End


Thanks Phil. :thumbup:
Sorry for the delay, site was down for a while.

Hi Stewart, let me look things over and see where we are.

Tried to get updates for Java but was greated with this message:

This is a problem we must fix, what you might try is uninstalling the program and downloading it again from here: http://www.java.com/en/download/manual.jsp
Why don't we hold off on that until we are sure everything else is working properly.

Regarding WinCleaner AntiSpyware, this was installed as a free download on the machine by my father before he gave it to me. I have uninstalled WinCleaner AntiSpyware

That was a good move, Ad-aware and Spybot are usually two programs I start with, but you had other issues, so I hit the stuff with ewido. I want you to have this link: http://tomcoyote.org/aawsb.php so you can check those programs to make sure you have them configured properly.
SpywareBlaster is a great freeware program, I run it on all three of my computers. There are a couple of other freeware programs I believe you should run, and you will see then mentioned in those links I provided. They are SpywareGuard and IE-Spyad. Let's get everything clean and then you can try those.
Since you are unsure about SpywareBlaster. I am going to place tutorials for those I believe would be best for you here:
Spybot
http://www.bleepingcomputer.com/forums/tutorial43.html
Ad-aware
http://www.bleepingcomputer.com/forums/tutorial48.html
SpywareBlaster
http://www.bleepingcomputer.com/forums/tutorial49.html
SpywareGuard:
http://www.bleepingcomputer.com/forums/tutorial50.html
IE-Spyad
http://www.bleepingcomputer.com/forums/tutorial53.html
Don't try to do them all at once. One at a time, learn about it, read the tutorials for the next one so you will know what it will do when you install it.

Good job with ewido that time. I know it is tricky to see the stuff and wonder if it bad or good. Believe me, all of that junk was bad. ewido should scan clean now. You will pick up some bad cookies, when time permits, use this information to control them also.
http://www.microsoft.com/windows/ie/using/…acy/config.mspx

Here is information about using MSConfig if you need it: http://netsquirrel.com/msconfig/ and the programs you can start manually with information about them.

O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
http://castlecops.com/startuplist-3315.html

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
http://castlecops.com/startuplist-3552.html <<< only if you are going to update it manually once you get it working.

O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
http://castlecops.com/startuplist-3365.html <<< not 100% sure, check to see if it can be started manually. I guess it depends on how often you use it?

O4 - HKLM\..\Run: [EPSON Stylus Photo R1800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE /P24 "EPSON Stylus Photo R1800" /O6 "USB001" /M "Stylus Photo R1800"
This should be your printer, you should be able to start this manually in All Programs. I start my HP that way the rare times I have to print.

Here is some Java information: http://www.java.com/en/download/help/ Since it is not malware, I rarely do more that have it updated. You will have to work with it, you may have to uninstall the program and download it fresh from the Java link.

Yes, I would like to see one last HJT log, let me know how things are going now.

Thanks…Phil
Hi Phil,

Had some bother getting in here today, all other sites seemed to work though so i assume it was just this site that was having trouble.

Did what you said above (apart from the java thingy, which i'll do when i get the go-ahead from you). The only Java i can see on my machine is this: Java 2 Runtime Environment, SE v1.4.2_06…..Which i located using add/remove programs. Is this what i am looking to re-install?….quite a large download if it is…108MB or there-abouts.

I got hit with this: wuwmsg.exe is trying to access the internet …..this was after rebooting, after the scan with EWIDO. I have however not seen it since and have rebooted a few times now.

Also, after configuring and scanning both Spybot and Ad-Aware, once i rebooted i was met with a security shield in my task bar telling me norton firewall and antivirus, at first it didnt go away and i couldnt get rid of it, but for now it seems to be behaving. It told me that norton wasnt on but it was when i checked, i am thinking it is because it has priority in start up and this means it effectlively isnt giving norton a chance….i you get me!? ;)

Ok, if i remember from your post you asked me for a log from Ad-Aware, and from HJT.

So, first Ad-Aware, followed by HJT:

ArchiveData(auto-quarantine- 2005-11-05 14-01-52.bckp)
Referencefile : SE1R73 03.11.2005
======================================================

TRACKING COOKIE
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=IECache Entry : Cookie:[removed]/
obj[1]=IECache Entry : Cookie:[removed]/
obj[2]=IECache Entry : Cookie:[removed]/
obj[3]=IECache Entry : Cookie:[removed]/
obj[4]=IECache Entry : Cookie:[removed]/
obj[5]=IECache Entry : Cookie:[removed]/
obj[6]=IECache Entry : Cookie:[removed]/
obj[7]=IECache Entry : Cookie:[removed]/
obj[8]=IECache Entry : Cookie:[removed]/
obj[9]=IECache Entry : Cookie:[removed]/
obj[10]=IECache Entry : Cookie:[removed]/
obj[11]=IECache Entry : Cookie:[removed]/
obj[12]=IECache Entry : Cookie:[removed]/

ISTBAR
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[13]=Regkey : aspfile\persistenthandler
obj[14]=Regkey : software\microsoft\downloadmanager
obj[16]=File : C:\System Volume Information\_restore{880D9CCF-2AA4-4ED9-8DE7-39B873FAB1B7}\RP444\A0065511.exe
obj[17]=File : C:\System Volume Information\_restore{880D9CCF-2AA4-4ED9-8DE7-39B873FAB1B7}\RP444\A0065531.exe

180SOLUTIONS
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[15]=Regkey : software\microsoft\internet explorer\explorer bars\{30d02401-6a81-11d0-8274-00c04fd5ae38}
obj[18]=File : C:\System Volume Information\_restore{880D9CCF-2AA4-4ED9-8DE7-39B873FAB1B7}\RP447\A0065612.exe

DYFUCA
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[19]=File : C:\System Volume Information\_restore{880D9CCF-2AA4-4ED9-8DE7-39B873FAB1B7}\RP447\A0065762.dll
obj[23]=File : C:\System Volume Information\_restore{880D9CCF-2AA4-4ED9-8DE7-39B873FAB1B7}\RP449\A0067392.exe

YOURSITEBAR
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[20]=File : C:\System Volume Information\_restore{880D9CCF-2AA4-4ED9-8DE7-39B873FAB1B7}\RP447\A0065765.dll

SIDEFIND
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[21]=File : C:\System Volume Information\_restore{880D9CCF-2AA4-4ED9-8DE7-39B873FAB1B7}\RP447\A0065766.dll
obj[22]=File : C:\System Volume Information\_restore{880D9CCF-2AA4-4ED9-8DE7-39B873FAB1B7}\RP447\A0065767.dll
obj[25]=File : C:\System Volume Information\_restore{880D9CCF-2AA4-4ED9-8DE7-39B873FAB1B7}\RP450\A0069107.exe

POWERSCAN
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[24]=File : C:\System Volume Information\_restore{880D9CCF-2AA4-4ED9-8DE7-39B873FAB1B7}\RP450\A0069099.exe

NOW HJT LOG

Logfile of HijackThis v1.99.1
Scan saved at 20:52:51, on 05/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\Program Files\ZyXEL\ADSL USB Modem\CnxDslTb.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\ONSPEED\onspeedcore.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\ONSPEED\onspeedgui.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\FRU\Remind32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\Program Files\ONSPEED\PBHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ONSPEED - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - C:\Program Files\ONSPEED\Toolband.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [pdfFactory Dispatcher v2] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZyXEL\ADSL USB Modem\CnxDslTb.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [SlipStream] "C:\Program Files\ONSPEED\onspeedcore.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R1800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE /P24 "EPSON Stylus Photo R1800" /O6 "USB001" /M "Stylus Photo R1800"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: Hewlett-Packard Recorder.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\FRU\Remind32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: ONSPEED.lnk = C:\Program Files\ONSPEED\onspeedgui.exe
O8 - Extra context menu item: Send To &Bluetooth; - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1131071378661
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/…tail/DASAct.cab
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://D:\SuperCD\IntraLaunch.CAB
O16 - DPF: {C1BAC744-8F0B-11D0-89E7-00C0A8295197} (Cameractl Class) - http://www.nwales-traffic.co.uk/files/activex/camera.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?321
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by103fd.bay103.hotmail.msn.com/activex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE05D28B-3E6B-4585-9B8A-D67B0557F12B}: NameServer = 195.184.228.6 195.184.228.7
O23 - Service: BackupClientSvc - Unknown owner - C:\PROGRA~1\MYDATA~1\BackupClientSvc.Exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

END HJT LOG

If you let me know if i have my claws on the correct java program, i'll get on with uninstalling and re-installing it, (whats it for anyway?).

Thanks for all your help so far Phil, just makes me realise how little i know. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI