This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack log for you :-?

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I seem have gotten myself into, what seems to be common for your eyes, a little problem.

About two weeks ago (12NOV05) started getting popup windows and various virus alerts, so with a freind I dabled a little on my own to solve the problem and have now come to realize that I am in over my head. I need some help. I think that I might have gotten rid of a couple of things but the war was not won.

Pasted below is a copy of the hijack log as per Hijackthis instruciton..

If you could help me, please…

Cookie

Logfile of HijackThis v1.99.1
Scan saved at 3:32:57 PM, on 23-Nov-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\PopUpWasher\PopUpWasher.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
O1 - Hosts: 72.9.232.244 www.bankone.com
O1 - Hosts: 72.9.232.244 bankone.com
O1 - Hosts: 72.9.232.244 halifax.com
O1 - Hosts: 72.9.232.244 www.halifax.com
O1 - Hosts: 72.9.232.244 halifax.co.uk
O1 - Hosts: 72.9.232.244 www.halifax.co.uk
O1 - Hosts: 72.9.232.244 www.bankofamerika.com
O1 - Hosts: 72.9.232.244 bankofamerika.com
O1 - Hosts: 72.9.232.244 www.paypal.com
O1 - Hosts: 72.9.232.244 paypal.com
O1 - Hosts: 72.9.232.244 www.lloydstsb.com
O1 - Hosts: 72.9.232.244 lloydstsb.com
O1 - Hosts: 72.9.232.244 www.lloydstsb.co.uk
O1 - Hosts: 72.9.232.244 lloydstsb.co.uk
O1 - Hosts: 72.9.232.244 www.bbvanet.com
O1 - Hosts: 72.9.232.244 bbvanet.com
O1 - Hosts: 72.9.232.244 www.bancopostaonline.poste.it
O1 - Hosts: 72.9.232.244 bancopostaonline.poste.it
O1 - Hosts: 72.9.232.244 www.poste.it
O1 - Hosts: 72.9.232.244 poste.it
O1 - Hosts: 72.9.232.244 www.credem.it
O1 - Hosts: 72.9.232.244 credem.it
O1 - Hosts: 72.9.232.244 www.creval.it
O1 - Hosts: 72.9.232.244 creval.it
O1 - Hosts: 72.9.232.244 www.gruppocarige.it
O1 - Hosts: 72.9.232.244 gruppocarige.it
O1 - Hosts: 72.9.232.244 www.rasbank.it
O1 - Hosts: 72.9.232.244 rasbank.it
O1 - Hosts: 72.9.232.244 www.bancagenerali.it
O1 - Hosts: 72.9.232.244 bancagenerali.it
O1 - Hosts: 72.9.232.244 www.garanti.com.tr
O1 - Hosts: 72.9.232.244 garanti.com.tr
O1 - Hosts: 72.9.232.244 www.kocbank.com.tr
O1 - Hosts: 72.9.232.244 kocbank.com.tr
O1 - Hosts: 72.9.232.244 www.finansbank.com.tr
O1 - Hosts: 72.9.232.244 finansbank.com.tr
O1 - Hosts: 72.9.232.244 www.disbank.com.tr
O1 - Hosts: 72.9.232.244 disbank.com.tr
O1 - Hosts: 72.9.232.244 www.cassarimini.it
O1 - Hosts: 72.9.232.244 cassarimini.it
O1 - Hosts: 72.9.232.244 www.unicredit.it
O1 - Hosts: 72.9.232.244 unicredit.it
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [timessquare] C:\windows\timessquare.exe
O4 - HKLM\..\Run: [adtech2005] C:\windows\adtech2005.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O4 - HKCU\..\Run: [wokr] C:\PROGRA~1\COMMON~1\wokr\wokrm.exe
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [PopUpWasher] C:\Program Files\Webroot\PopUpWasher\PopUpWasher.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O8 - Extra context menu item: &Dictionary - http://www.ezreference.com/_/ie-com-sp.htm
O8 - Extra context menu item: &Encyclopedia - http://www.ezreference.com/_/ie-com-e-sp.htm
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://66.242.36.116/view22/View22RTE.cab
O20 - Winlogon Notify: SideBySide - C:\WINDOWS\system32\i4nm0e51eh.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWFydGluIE1hcmtpZGVz\command.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
Hello Cookies, welcome to the TC.

I don't know if your a victim of ID THEF or not.

I suggest you do this:


Please download hoster from the link below.

http://www.funkytoad.com/download/hoster.zip

Unzip Hoster.zip
Open Hoster.exe.

Then click on "Restore Original Hosts"

Close program when complete.



Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html

O1 - Hosts: 72.9.232.244 www.bankone.com
O1 - Hosts: 72.9.232.244 bankone.com
O1 - Hosts: 72.9.232.244 halifax.com
O1 - Hosts: 72.9.232.244 www.halifax.com
O1 - Hosts: 72.9.232.244 halifax.co.uk
O1 - Hosts: 72.9.232.244 www.halifax.co.uk
O1 - Hosts: 72.9.232.244 www.bankofamerika.com
O1 - Hosts: 72.9.232.244 bankofamerika.com
O1 - Hosts: 72.9.232.244 www.paypal.com
O1 - Hosts: 72.9.232.244 paypal.com
O1 - Hosts: 72.9.232.244 www.lloydstsb.com
O1 - Hosts: 72.9.232.244 lloydstsb.com
O1 - Hosts: 72.9.232.244 www.lloydstsb.co.uk
O1 - Hosts: 72.9.232.244 lloydstsb.co.uk
O1 - Hosts: 72.9.232.244 www.bbvanet.com
O1 - Hosts: 72.9.232.244 bbvanet.com
O1 - Hosts: 72.9.232.244 www.bancopostaonline.poste.it
O1 - Hosts: 72.9.232.244 bancopostaonline.poste.it
O1 - Hosts: 72.9.232.244 www.poste.it
O1 - Hosts: 72.9.232.244 poste.it
O1 - Hosts: 72.9.232.244 www.credem.it
O1 - Hosts: 72.9.232.244 credem.it
O1 - Hosts: 72.9.232.244 www.creval.it
O1 - Hosts: 72.9.232.244 creval.it
O1 - Hosts: 72.9.232.244 www.gruppocarige.it
O1 - Hosts: 72.9.232.244 gruppocarige.it
O1 - Hosts: 72.9.232.244 www.rasbank.it
O1 - Hosts: 72.9.232.244 rasbank.it
O1 - Hosts: 72.9.232.244 www.bancagenerali.it
O1 - Hosts: 72.9.232.244 bancagenerali.it
O1 - Hosts: 72.9.232.244 www.garanti.com.tr
O1 - Hosts: 72.9.232.244 garanti.com.tr
O1 - Hosts: 72.9.232.244 www.kocbank.com.tr
O1 - Hosts: 72.9.232.244 kocbank.com.tr
O1 - Hosts: 72.9.232.244 www.finansbank.com.tr
O1 - Hosts: 72.9.232.244 finansbank.com.tr
O1 - Hosts: 72.9.232.244 www.disbank.com.tr
O1 - Hosts: 72.9.232.244 disbank.com.tr
O1 - Hosts: 72.9.232.244 www.cassarimini.it
O1 - Hosts: 72.9.232.244 cassarimini.it
O1 - Hosts: 72.9.232.244 www.unicredit.it
O1 - Hosts: 72.9.232.244 unicredit.it

O4 - HKLM\..\Run: [timessquare] C:\windows\timessquare.exe

O4 - HKLM\..\Run: [adtech2005] C:\windows\adtech2005.exe

O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"

O4 - HKCU\..\Run: [wokr] C:\PROGRA~1\COMMON~1\wokr\wokrm.exe

O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://66.242.36.116/view22/View22RTE.cab

O20 - Winlogon Notify: SideBySide - C:\WINDOWS\system32\i4nm0e51eh.dll

O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWFydGluIE1hcmtpZGVz\command.exe (file missing)


Close ALL windows and browsers except HijackThis and click "Fix checked"



Restart in Safe Mode:
Restart your computer.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.



delete these folders if listed:
C:\Program Files\Common Files\wokr
C:\WINDOWS\TWFydGluIE1hcmtpZGVz



delete these files if listed:
C:\windows\timessquare.exe
C:\windows\adtech2005.exe
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
C:\WINDOWS\system32\i4nm0e51eh.dll
C:\WINDOWS\TWFydGluIE1hcmtpZGVz\command.exe


Open C:\Windows\Prefetch\ Delete ALL files in this folder.


Do this also if these Temp Folders are part of your OS.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


Next navigate to the C:\Documents and Settings\(EVERY LISTED PROFILE USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty the Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Good afternoon LDTate,

Thanks for you reply and your help, what I have done since the file log that you saw was to also install webroots spysweeper and ewido which each came up with their share of problems and fixes..

I alowed each of the programs to do what they suggested without pushing them to resolve anything else.

I origonaly have Norton,which funny enough didnt react at all throughout the ordeal… at first anyway..

I have now completed the items as described in you post (to the extent that they still applied) and will post the new hijack below.

In regards to how the comuter runs I would comment on three things;

1. I have noticed that Autocad and Photoshop CS seem to be a little slower over the last week but could be my idea, they are heavy programs after all.

2.I have notice as a problem though is that as I start up the computer i get a program installation notice bar and after a fail message that norton dose not support repair and needs to be unistalled and reinstalled. I'm not really sure what to do about that but imagine that it could be a smaller bad in the world of good being done.

3. When on line through a ADSL Lan network, many times when I try to reload a screen or access a download section of a site, I get prompted with my PST dialup commenction. For some reason the page that I am in gets bumped off line and reconnecting prompts the dial-up intreface. Just now I found this page working off line and have to go to the File menue bar and remove the tick work offline. I have found this to block on some site completly. Round and round, uncheck work offline and get the dial-up connection, cancel connection and page goes back to work offline…and so on…..

Well here is my log and if you need the logs of spysweeper or ewido i have them as well.

Looking forword to hearing from you soon.

COOKIE


Logfile of HijackThis v1.99.1
Scan saved at 1:46:52 PM, on 30-Nov-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Webroot\PopUpWasher\PopUpWasher.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PopUpWasher] C:\Program Files\Webroot\PopUpWasher\PopUpWasher.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O8 - Extra context menu item: &Dictionary - http://www.ezreference.com/_/ie-com-sp.htm
O8 - Extra context menu item: &Encyclopedia - http://www.ezreference.com/_/ie-com-e-sp.htm
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe


PS.
I dont know if it is relevant but my mail server has been bombared with virus mail shortly after my situation with this hijack… could this be relevant or related?? I have attached the text of the mail from the GREEK mail server from which one of my accounts run.

< OTEnet's E-mail Antivirus Service has deleted a message sent to you, because it contained dangerous code (virus).
Further details about the deleted message can be found at the end of the current warning message.

E-mail Antivirus Protection by OTEnet!
For more information please visit http://www.cool4u.gr/antivirus.asp
The message sent from <[removed]> to <[removed]>
<[removed]>
<[removed]>
<[removed]>
<[removed]>
….. continues list of aprox. 80 client of the service (non known to me or any of their addressess on my computer)

DS.
Hey you… yea. I was on a job and didnt get to my computer for a couple of days.. but low and behold everything seems to be okay with my tin can… As requested; in the order that i ran them; 1) First run at spy sweeper found a bunch of trouble and fixed what it could. 2) Cleanup run after reboot found some things again 3) As I thought that Sweeping was not getting it I ran ewido last… so, three logs as follows; ——————- 1 ——————– ******** 10:03 AM: | Start of Session, Thursday, November 24, 2005 | 10:03 AM: Spy Sweeper started 10:03 AM: Sweep initiated using definitions version 574 10:03 AM: Starting Memory Sweep 10:04 AM: Found Adware: look2me 10:04 AM: Detected running threat: C:\WINDOWS\system32\h4j40e1qeh.dll (ID = 163672) 10:04 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:04 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:04 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:04 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:05 AM: Detected running threat: C:\WINDOWS\system32\sworprop.dll (ID = 163672) 10:05 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:05 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:05 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:05 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:06 AM: Memory Sweep Complete, Elapsed Time: 00:02:32 10:06 AM: Starting Registry Sweep 10:06 AM: Found Adware: command 10:06 AM: HKLM\software\microsoft\windows\currentversion\uninstall\{3877c2cd-f137-4144-bdb2-0a811492f920}\ (7 subtraces) (ID = 892523) 10:06 AM: Found Adware: dollarrevenue 10:06 AM: HKLM\software\microsoft\drsmartload\ (1 subtraces) (ID = 916795) 10:06 AM: Found Adware: cws_secure32.html hijack 10:06 AM: HKLM\software\microsoft\internet explorer\main\ || local page (ID = 946024) 10:06 AM: HKLM\software\microsoft\internet explorer\main\ || default_page_url (ID = 946027) 10:06 AM: HKLM\system\currentcontrolset\services\cmdservice\ (12 subtraces) (ID = 958670) 10:06 AM: HKLM\software\microsoft\windows\currentversion\run\ || timessquare (ID = 1004206) 10:06 AM: Found Adware: adtech2005 10:06 AM: HKLM\software\microsoft\windows\currentversion\run\ || adtech2005 (ID = 1005415) 10:06 AM: Found Trojan Horse: trojan-backdoor-us15info 10:06 AM: HKU\S-1-5-21-2068918388-2360199117-439726964-1006\software\microsoft\windows\currentversion\run\ || shell (ID = 650813) 10:06 AM: HKU\S-1-5-21-2068918388-2360199117-439726964-1006\software\microsoft\internet explorer\main\ || local page (ID = 946022) 10:06 AM: HKU\S-1-5-21-2068918388-2360199117-439726964-1006\software\microsoft\internet explorer\main\ || default_page_url (ID = 946026) 10:06 AM: Registry Sweep Complete, Elapsed Time:00:00:10 10:06 AM: Starting Cookie Sweep 10:06 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00 10:06 AM: Starting File Sweep 10:07 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:07 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:07 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:07 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:07 AM: installer[1].exe (ID = 185986) 10:07 AM: a0019395.dll (ID = 163672) 10:08 AM: dc505.exe (ID = 194580) 10:08 AM: Found Adware: targetsaver 10:08 AM: a0019414.exe (ID = 195128) 10:08 AM: a0020458.dll (ID = 163672) 10:08 AM: a0019367.exe (ID = 193995) 10:08 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:08 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:08 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:08 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:08 AM: a0021861.dll (ID = 163672) 10:08 AM: a0019370.exe (ID = 195130) 10:08 AM: a0019412.exe (ID = 193995) 10:08 AM: a0019413.exe (ID = 193259) 10:08 AM: Found Adware: effective-i toolbar 10:08 AM: a0019347.dll (ID = 59843) 10:09 AM: hr8605lse.dll (ID = 163672) 10:09 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:09 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:09 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:09 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:10 AM: dc328.exe (ID = 185986) 10:10 AM: a0019415.exe (ID = 195131) 10:10 AM: a0021550.dll (ID = 163672) 10:10 AM: timessquare[1].exe (ID = 194150) 10:10 AM: dc500.exe (ID = 194150) 10:10 AM: tsupdate2[1].ini (ID = 193498) 10:10 AM: a0021873.dll (ID = 163672) 10:10 AM: a0019371.exe (ID = 195132) 10:10 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:10 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:10 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:10 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:11 AM: Found Adware: spysheriff 10:11 AM: dc501.html (ID = 178574) 10:11 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:11 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:11 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:11 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:12 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:12 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:12 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:12 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:12 AM: adtech2005[1].exe (ID = 194580) 10:12 AM: mte3ndi6odoxng[1].exe (ID = 185985) 10:12 AM: dc507.exe (ID = 185985) 10:12 AM: dc493.exe (ID = 183857) 10:12 AM: dc492.exe (ID = 183857) 10:13 AM: sworprop.dll (ID = 163672) 10:13 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:13 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:13 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:13 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:13 AM: g604lgdq160e.dll (ID = 159) 10:14 AM: Found Adware: apropos 10:14 AM: dc676._ (ID = 166754) 10:14 AM: a0021549.dll (ID = 163672) 10:14 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:14 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:14 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:14 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:15 AM: dc491.exe (ID = 192928) 10:16 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:16 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:16 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:16 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:16 AM: a0021514.dll (ID = 163672) 10:16 AM: a0020486.dll (ID = 163672) 10:17 AM: a0019417.dll (ID = 163672) 10:17 AM: a0021555.dll (ID = 163672) 10:17 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:17 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:17 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:17 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:17 AM: a0019382.dll (ID = 163672) 10:17 AM: a0020424.dll (ID = 163672) 10:17 AM: a0019369.exe (ID = 168558) 10:17 AM: dc675.dll (ID = 166754) 10:17 AM: wokrc.dll (ID = 195129) 10:17 AM: a0021587.dll (ID = 163672) 10:17 AM: a0021486.dll (ID = 163672) 10:17 AM: a0021533.exe (ID = 59853) 10:17 AM: a0019416.dll (ID = 163672) 10:18 AM: a0021804.dll (ID = 163672) 10:18 AM: a0020555.dll (ID = 163672) 10:18 AM: irl0l53m1.dll (ID = 163672) 10:18 AM: a0019418.dll (ID = 163672) 10:18 AM: a0020459.dll (ID = 163672) 10:18 AM: a0021588.dll (ID = 163672) 10:18 AM: a0019409.exe (ID = 193496) 10:18 AM: a0019424.dll (ID = 163672) 10:18 AM: a0021805.dll (ID = 163672) 10:18 AM: a0019353.dll (ID = 163672) 10:18 AM: a0021567.dll (ID = 163672) 10:18 AM: a0021535.dll (ID = 163672) 10:18 AM: a0021574.dll (ID = 163672) 10:18 AM: a0021842.dll (ID = 163672) 10:18 AM: a0019346.dll (ID = 106574) 10:18 AM: a0019411.exe (ID = 168558) 10:18 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:18 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:18 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:18 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:18 AM: a0021515.dll (ID = 163672) 10:18 AM: a0021553.exe (ID = 144946) 10:18 AM: dc665.dll (ID = 144945) 10:18 AM: a0021536.dll (ID = 163672) 10:18 AM: dc678.dll (ID = 163672) 10:19 AM: dc677.exe (ID = 193501) 10:19 AM: a0021843.dll (ID = 163672) 10:19 AM: h4j40e1qeh.dll (ID = 163672) 10:20 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:20 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:20 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:20 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:20 AM: a0019349.lnk (ID = 59855) 10:20 AM: a0019350.lnk (ID = 59838) 10:20 AM: dc666.vbs (ID = 185675) 10:21 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:21 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:21 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:21 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:22 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:22 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:22 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:22 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:23 AM: Warning: Invalid Stream 10:23 AM: Warning: Invalid file - not a PKZip file 10:24 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:24 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:24 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:24 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:24 AM: File Sweep Complete, Elapsed Time: 00:17:37 10:24 AM: Full Sweep has completed. Elapsed time 00:20:29 10:24 AM: Traces Found: 103 10:25 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:25 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:25 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:25 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:25 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:25 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:25 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:25 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:25 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:25 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:25 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:25 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:26 AM: Removal process initiated 10:26 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:26 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:26 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:26 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:26 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:26 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:26 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:26 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:26 AM: Quarantining All Traces: look2me 10:26 AM: look2me is in use. It will be removed on reboot. 10:26 AM: sworprop.dll is in use. It will be removed on reboot. 10:26 AM: g604lgdq160e.dll is in use. It will be removed on reboot. 10:26 AM: h4j40e1qeh.dll is in use. It will be removed on reboot. 10:26 AM: C:\WINDOWS\system32\h4j40e1qeh.dll is in use. It will be removed on reboot. 10:26 AM: C:\WINDOWS\system32\sworprop.dll is in use. It will be removed on reboot. 10:26 AM: Quarantining All Traces: spysheriff 10:26 AM: Quarantining All Traces: trojan-backdoor-us15info 10:26 AM: Quarantining All Traces: apropos 10:26 AM: Quarantining All Traces: adtech2005 10:26 AM: Quarantining All Traces: command 10:26 AM: Quarantining All Traces: cws_secure32.html hijack 10:26 AM: Quarantining All Traces: dollarrevenue 10:26 AM: Quarantining All Traces: effective-i toolbar 10:26 AM: Quarantining All Traces: targetsaver 10:27 AM: Warning: Launched explorer.exe 10:27 AM: Warning: Quarantine process could not restart Explorer. 10:28 AM: Preparing to restart your computer. Please wait… 10:28 AM: Removal process completed. Elapsed time 00:02:10 10:37 AM: Processing Hosts File Alerts 10:37 AM: Fixed Hosts File entry: www.bankone.com 10:37 AM: Fixed Hosts File entry: bankone.com 10:37 AM: Fixed Hosts File entry: halifax.com 10:37 AM: Fixed Hosts File entry: www.halifax.com 10:37 AM: Fixed Hosts File entry: halifax.co.uk 10:37 AM: Fixed Hosts File entry: www.halifax.co.uk 10:37 AM: Fixed Hosts File entry: www.bankofamerika.com 10:37 AM: Fixed Hosts File entry: bankofamerika.com 10:37 AM: Fixed Hosts File entry: www.paypal.com 10:37 AM: Fixed Hosts File entry: paypal.com 10:37 AM: Fixed Hosts File entry: www.lloydstsb.com 10:37 AM: Fixed Hosts File entry: lloydstsb.com 10:37 AM: Fixed Hosts File entry: www.lloydstsb.co.uk 10:37 AM: Fixed Hosts File entry: lloydstsb.co.uk 10:37 AM: Fixed Hosts File entry: www.bbvanet.com 10:37 AM: Fixed Hosts File entry: bbvanet.com 10:37 AM: Fixed Hosts File entry: www.bancopostaonline.poste.it 10:37 AM: Fixed Hosts File entry: bancopostaonline.poste.it 10:37 AM: Fixed Hosts File entry: www.poste.it 10:37 AM: Fixed Hosts File entry: poste.it 10:37 AM: Fixed Hosts File entry: www.credem.it 10:37 AM: Fixed Hosts File entry: credem.it 10:37 AM: Fixed Hosts File entry: www.creval.it 10:37 AM: Fixed Hosts File entry: creval.it 10:37 AM: Fixed Hosts File entry: www.gruppocarige.it 10:37 AM: Fixed Hosts File entry: gruppocarige.it 10:37 AM: Fixed Hosts File entry: www.rasbank.it 10:37 AM: Fixed Hosts File entry: rasbank.it 10:37 AM: Fixed Hosts File entry: www.bancagenerali.it 10:37 AM: Fixed Hosts File entry: bancagenerali.it 10:37 AM: Fixed Hosts File entry: www.garanti.com.tr 10:37 AM: Fixed Hosts File entry: garanti.com.tr 10:37 AM: Fixed Hosts File entry: www.kocbank.com.tr 10:37 AM: Fixed Hosts File entry: kocbank.com.tr 10:37 AM: Fixed Hosts File entry: www.finansbank.com.tr 10:37 AM: Fixed Hosts File entry: finansbank.com.tr 10:37 AM: Fixed Hosts File entry: www.disbank.com.tr 10:37 AM: Fixed Hosts File entry: disbank.com.tr 10:37 AM: Fixed Hosts File entry: www.cassarimini.it 10:37 AM: Fixed Hosts File entry: cassarimini.it 10:37 AM: Fixed Hosts File entry: www.unicredit.it 10:37 AM: Fixed Hosts File entry: unicredit.it ******** 9:59 AM: | Start of Session, Thursday, November 24, 2005 | 9:59 AM: Spy Sweeper started 10:00 AM: Your spyware definitions have been updated. 10:00 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:00 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:00 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:00 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:01 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:01 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:01 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:01 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:03 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:03 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com 10:03 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:03 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com 10:03 AM: | End of Session, Thursday, November 24, 2005 | ——————- 2 ——————– ******** 10:51 AM: | Start of Session, Thursday, November 24, 2005 | 10:51 AM: Spy Sweeper started 10:51 AM: Sweep initiated using definitions version 574 10:51 AM: Starting Memory Sweep 10:53 AM: Memory Sweep Complete, Elapsed Time: 00:02:07 10:53 AM: Starting Registry Sweep 10:54 AM: Registry Sweep Complete, Elapsed Time:00:00:07 10:54 AM: Starting Cookie Sweep 10:54 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00 10:54 AM: Starting File Sweep 10:55 AM: Found Adware: adtech2005 10:55 AM: a0021892.exe (ID = 194580) 10:56 AM: Found Adware: look2me 10:56 AM: a0021887.dll (ID = 163672) 10:57 AM: Found Adware: command 10:57 AM: a0021896.exe (ID = 185986) 10:57 AM: Found Adware: dollarrevenue 10:57 AM: a0021897.exe (ID = 194150) 10:59 AM: a0021895.exe (ID = 185985) 11:00 AM: Found Trojan Horse: trojan-backdoor-us15info 11:00 AM: a0021890.exe (ID = 183857) 11:00 AM: a0021889.exe (ID = 183857) 11:02 AM: Found Adware: spysheriff 11:02 AM: a0021888.exe (ID = 192928) 11:03 AM: Found Adware: apropos 11:03 AM: a0021891.dll (ID = 166754) 11:03 AM: Found Adware: targetsaver 11:03 AM: a0021899.dll (ID = 195129) 11:04 AM: a0021886.dll (ID = 163672) 11:04 AM: a0021894.dll (ID = 144945) 11:04 AM: a0021885.dll (ID = 163672) 11:04 AM: a0021898.exe (ID = 193501) 11:06 AM: a0021893.vbs (ID = 185675) 11:06 AM: File Sweep Complete, Elapsed Time: 00:12:55 11:07 AM: Full Sweep has completed. Elapsed time 00:15:20 11:07 AM: Traces Found: 15 11:07 AM: Removal process initiated 11:07 AM: Quarantining All Traces: look2me 11:07 AM: Quarantining All Traces: spysheriff 11:07 AM: Quarantining All Traces: trojan-backdoor-us15info 11:07 AM: Quarantining All Traces: apropos 11:07 AM: Quarantining All Traces: adtech2005 11:07 AM: Quarantining All Traces: command 11:07 AM: Quarantining All Traces: dollarrevenue 11:07 AM: Quarantining All Traces: targetsaver 11:07 AM: Removal process completed. Elapsed time 00:00:26 ******** 10:45 AM: | Start of Session, Thursday, November 24, 2005 | 10:45 AM: Spy Sweeper started 10:47 AM: IE Tracking Cookies Shield: Removed 2o7.net cookie 10:51 AM: | End of Session, Thursday, November 24, 2005 | ——————- 3 ——————– ——————————————————— ewido security suite - Scan report ——————————————————— + Created on: 11:43:55 AM, 24-Nov-05 + Report-Checksum: 4AF1B459 + Scan result: HKU\S-1-5-21-2068918388-2360199117-439726964-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{44BE0690-5429-47F0-85BB-3FFD8020233E} -> Spyware.UCmore : Cleaned with backup C:\Documents and Settings\mma\Local Settings\Temp\Cookies\[removed][1].txt -> Spyware.Cookie.Falkag : Cleaned with backup C:\Documents and Settings\mma\Local Settings\Temp\Cookies\mma@bluestreak[2].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup C:\Documents and Settings\mma\Local Settings\Temp\Cookies\mma@msnportal.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Documents and Settings\mma\Local Settings\Temp\Cookies\mma@statcounter[1].txt -> Spyware.Cookie.Statcounter : Cleaned with backup C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe -> TrojanSpy.Small.dg : Cleaned with backup C:\RECYCLER\S-1-5-21-2068918388-2360199117-439726964-1006\Dc497.exe -> TrojanSpy.Small.dg : Cleaned with backup C:\RECYCLER\S-1-5-21-2068918388-2360199117-439726964-1006\Dc517.1_crack\P3_3.1_crack.exe/run.exe -> TrojanDownloader.Small.bfy : Cleaned with backup C:\RECYCLER\S-1-5-21-2068918388-2360199117-439726964-1006\Dc519.zip/Matrix.class -> TrojanDownloader.Java.OpenStream.c : Cleaned with backup C:\RECYCLER\S-1-5-21-2068918388-2360199117-439726964-1006\Dc550.exe -> Dialer.Generic : Cleaned with backup C:\RECYCLER\S-1-5-21-2068918388-2360199117-439726964-1006\Dc575.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup C:\RECYCLER\S-1-5-21-2068918388-2360199117-439726964-1006\Dc587.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup C:\RECYCLER\S-1-5-21-2068918388-2360199117-439726964-1006\Dc590.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup C:\WINDOWS\Temp\Cookies\[removed][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup C:\WINDOWS\Temp\Cookies\mma@tradedoubler[2].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup C:\WINDOWS\Temp\Cookies\mma@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\CDUJKH2B\game[1].exe -> Heuristic.Win32.Dialer : Cleaned with backup ::Report End Okay, thats it… Please tell me that I am clean.. Regards, Cookie
Well hello again.. Just thought I would let you know that I figured out why Notron was giveing repair problems and installation screens upon startup of windows, like you already know I am sure, Norton dose not ''enjoy'' being moved around in the start menu.. Seemingly, I created a new section in my start menu for security items and move norton there as well.. it was then sadly missed by various plug-ins… hence the configuration and repair splash screens… so, I guess you dont move stuff around the start menu so freely… I did not know that…. But I guess you did… any way.. on with the rest of the problems, I just ran another sweep to see what I would find and came up with the following log… It seems that my problems have not been solved.. ******** 12:06 PM: | Start of Session, Monday, December 05, 2005 | 12:06 PM: Spy Sweeper started 12:06 PM: Sweep initiated using definitions version 577 12:07 PM: Starting Memory Sweep 12:09 PM: Memory Sweep Complete, Elapsed Time: 00:02:25 12:09 PM: Starting Registry Sweep 12:09 PM: Found Adware: command 12:09 PM: HKLM\system\currentcontrolset\enum\root\legacy_cmdservice\0000\ (6 subtraces) (ID = 1016064) 12:09 PM: HKLM\system\currentcontrolset\enum\root\legacy_cmdservice\ (8 subtraces) (ID = 1016072) 12:09 PM: Registry Sweep Complete, Elapsed Time:00:00:11 12:09 PM: Starting Cookie Sweep 12:09 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00 12:09 PM: Starting File Sweep 12:12 PM: Found Adware: dollarrevenue 12:12 PM: a0019410.exe (ID = 194384) 12:23 PM: Found Adware: coolwebsearch (cws) 12:23 PM: a0021874.exe (ID = 198543) 12:26 PM: donotdelete[1].htm (ID = 198788) 12:26 PM: dc502.dat (ID = 198788) 12:26 PM: Warning: Invalid Stream 12:26 PM: Warning: Invalid file - not a PKZip file 12:26 PM: Warning: Unhandled Archive Type 12:27 PM: File Sweep Complete, Elapsed Time: 00:18:04 12:27 PM: Full Sweep has completed. Elapsed time 00:20:53 12:27 PM: Traces Found: 20 12:32 PM: Removal process initiated 12:32 PM: Quarantining All Traces: coolwebsearch (cws) 12:32 PM: Quarantining All Traces: command 12:32 PM: Quarantining All Traces: dollarrevenue 12:32 PM: Removal process completed. Elapsed time 00:00:17 ******** 9:00 AM: | Start of Session, Monday, December 05, 2005 | 9:00 AM: Spy Sweeper started 12:00 PM: IE Tracking Cookies Shield: Removed 2o7.net cookie 12:06 PM: | End of Session, Monday, December 05, 2005 |
Good morning…. Have done two sweeps of spyboot and one ewido. Both came up clean this time.. I will run another this afternoon after a bit of work on the net and see what they report… anything else?
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI