After renewing my subscription to PestPatrol on 16 November 2005, I installed the new version of the application as required and updated the definitions. A comprehensive scan immediately identified two pests: CWS.LoadAdv.400 and MidAddle. I quarantined all items shown followed by a restart and delete of quarantined items.
Subsequent PestPatrol scans show remnants from both CWS.LoadAdv.400 and MidAddle. I have not noticed obvious behavior such as re-directed webpages, changes to my selected home pages, slow downs, etc, but I cannot swear they have never occurred. The pests do not always show up in a PestPatrol scan, and have never shown up with subsequent scans using other anti-spyware aplications (see below).
PestPatrol customer service merely told me that they only support Internet Explorer. Any assistance ridding myself of these pests would be most welcome!
Summary of information posted below:
PestPatrol logs before and after quarantine and deletion.
Additional general information and summary of actions taken.
HJT log.
Thanks very much.
The following PestPatrol log outputs compare the data when the infections were first encountered, and a typical one after initial quarantine and reoccurrence of the pests:
First Detection:
CWS.LoadAdv.400:
File "C:\Documents and Settings\rjm\Application Data\Mozilla\Firefox\Profiles\rnuhywid.default\Cache\_CACHE_001_"
File "C:\Documents and Settings\rjm\Application Data\Mozilla\Firefox\Profiles\rnuhywid.default\Cache\_CACHE_002_"
File "C:\Documents and Settings\rjm\Application Data\Mozilla\Firefox\Profiles\rnuhywid.default\Cache\_CACHE_003_"
File "C:\Documents and Settings\rjm\Local Settings\History\History.IE5\MSHist012004110320041104\index.dat"
File "C:\Documents and Settings\rjm\Local Settings\History\History.IE5\MSHist012004120720041208\index.dat"
File "C:\Documents and Settings\rjm\Local Settings\History\History.IE5\MSHist012004121020041211\index.dat"
File "C:\Documents and Settings\rjm\Local Settings\History\History.IE5\MSHist012005030120050302\index.dat"
File "C:\Documents and Settings\rjm\Local Settings\History\History.IE5\MSHist012005080120050802\index.dat"
File "C:\Documents and Settings\rjm\Local Settings\History\History.IE5\MSHist012005091320050914\index.dat"
File "C:\Documents and Settings\rjm\Local Settings\History\History.IE5\MSHist012005091620050917\index.dat"
File "C:\Documents and Settings\rjm\Local Settings\History\History.IE5\MSHist012005100220051003\index.dat"
File "C:\Documents and Settings\rjm\Local Settings\History\History.IE5\MSHist012005100320051004\index.dat"
File "C:\Documents and Settings\rjm\Local Settings\History\History.IE5\MSHist012005101120051012\index.dat"
File "C:\i386\bios1.rom"
File "C:\WINDOWS\system32\bios1.rom"
MidAddle:
File "C:\Documents and Settings\rjm\Local Settings\Temp\~DF5A76.tmp"
File "C:\Documents and Settings\rjm\Local Settings\Temp\~DF80D3.tmp"
File "C:\Documents and Settings\rjm\Local Settings\Temp\~DF87CC.tmp"
File "C:\Documents and Settings\rjm\Local Settings\Temp\~DF8FAC.tmp"
File "C:\Documents and Settings\rjm\Local Settings\Temp\~DFB5CF.tmp"
File "C:\Documents and Settings\rjm\Local Settings\Temp\~DFB8B4.tmp"
After Quarantine and Deletion:
CWS.LoadAdv.400:
File "C:\Documents and Settings\...\Application Data\Mozilla\Firefox\Profiles\rnuhywid.default\Cache\_CACHE_001_"
File "C:\Documents and Settings\...\Application Data\Mozilla\Firefox\Profiles\rnuhywid.default\Cache\_CACHE_002_"
File "C:\Documents and Settings\...\Application Data\Mozilla\Firefox\Profiles\rnuhywid.default\Cache\_CACHE_003_"
MidAddle:
File "C:\Documents and Settings\...\Local Settings\Temp\~DF4495.tmp"
File "C:\Documents and Settings\...\Local Settings\Temp\~DF69CA.tmp"
File "C:\Documents and Settings\...\Local Settings\Temp\~DF7E4B.tmp"
CleanUp! successfully removes the cache files associated with CWS.LoadAdv.400 only to have them reappear the next time I run the Firefox browser.
CleanUp! fails to remove the Temp files associated with MidAddle although they can be removed by a manual wipe using Norton System Works. They also seem to reappear the next time I run Internet Explorer. Typically I do not run the IE browser.
If the Cache and Temp files have been removed as discussed above, a PestPatrol scan indicates no infections to be present.
Additional general information and summary of actions taken:
Operating System: Windows XP Pro SP2.
Firewall: ZoneAlarm Security Suite with both Anti-virus and Anti-spyware enabled. ZoneAlarm has never indicated an infection of any kind.
Spyware Guard: active prior to infection being found.
Spyware Blaster: active prior to infection being found.
Anti-Spyware scanners that did not pickup the infections after they were initially found by PestPatrol, quarantined and deleted (none of these scanners were on the computer prior to the infections being found):
Trend Micro Anti-Spyware
Trend Micro HouseCall online scan.
CWShredder
Spybot Search&Destroy
Trojan Hunter
Ad-Aware SE Personal
XoftSpy
TrustSoft Anti-Spyware.
The following Hijack This log was obtained under NORMAL conditions while CWS.LoadAdv.400 showed up in a PestPatrol scan, but not MidAddle.
Logfile of HijackThis v1.99.1
Scan saved at 13:32:46, on 2005.11.27
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\basfipm.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe
C:\WINDOWS\system32\kmw_run.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\rjm\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\system32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe"
O4 - HKLM\..\Run: [kmw_run.exe] kmw_run.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKCU\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKCU\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKCU\..\Run: [Norton SystemWorks] C:\Program Files\Norton SystemWorks\CfgWiz.exe /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (HKCU)
O23 - Service: Broadcom ASF IP monitoring service v6.0.3 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE