This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with vcodec

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is nasty stuff. Spybot can see it, but can't remove it. I'm being redirected to http://uptodatesecurity.com Here's my HiJackThis logfile. Please help! I've tried Spybot, Ad-Aware, Macafee, House call ( won't let me run it), Panda (won't let me install it - reboots computer when tried).

It's now attempting to block me from this forum!!

Thanks,
jwh

Logfile of HijackThis v1.99.1
Scan saved at 5:39:02 PM, on 1/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\Symantec\WinFax\WFXMOD32.EXE
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\KMaestro\KMaestro.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\PGP\PGP602i\PGPtray.exe
C:\Palm\HOTSYNC.EXE
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\Symantec\WinFax\WFXCTL32.EXE
C:\PROGRA~1\Webshots\webshots.scr
C:\WINDOWS\system32\nvctrl.exe
C:\WINDOWS\system32\mssearchnet.exe
C:\DOCUME~1\JAMESH~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://msnmember.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: RandomName - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpC36A.tmp
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_16_0.DLL (file missing)
O3 - Toolbar: CM Band - {159C2E51-9823-11D2-8DDC-D84A1B4ACD4D} - (no file)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [BtcMaestro] C:\Program Files\KMaestro\KMaestro.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: PGPtray.lnk = C:\Program Files\PGP\PGP602i\PGPtray.exe
O4 - Global Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Controller.LNK = C:\Program Files\Symantec\WinFax\WFXCTL32.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Search - http://speedbar.myway.com/menusearch.html?p=MG1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1125321530830
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {FA9740A2-5802-42E2-B509-81186EEB3C42} (WABControl Class) - https://www.linkedin.com/cab/wabctrl.cab
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE
Please help! I don't know what to do with this. Here's the latest HijackThis logfile.

Logfile of HijackThis v1.99.1
Scan saved at 7:57:35 AM, on 1/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\mssearchnet.exe
C:\Program Files\KMaestro\KMaestro.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\PGP\PGP602i\PGPtray.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\Palm\HOTSYNC.EXE
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\Symantec\WinFax\WFXCTL32.EXE
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\Symantec\WinFax\WFXMOD32.EXE
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\Lotus\Notes\NLNOTES.EXE
C:\Lotus\Notes\ntaskldr.EXE
C:\WINDOWS\system32\nvctrl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\JAMESH~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://msnmember.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: International - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hp3C09.tmp
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_16_0.DLL (file missing)
O3 - Toolbar: CM Band - {159C2E51-9823-11D2-8DDC-D84A1B4ACD4D} - C:\Program Files\Crystalys media\cm.dll (file missing)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [BtcMaestro] C:\Program Files\KMaestro\KMaestro.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: PGPtray.lnk = C:\Program Files\PGP\PGP602i\PGPtray.exe
O4 - Global Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Controller.LNK = C:\Program Files\Symantec\WinFax\WFXCTL32.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Search - http://speedbar.myway.com/menusearch.html?p=MG1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1125321530830
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {FA9740A2-5802-42E2-B509-81186EEB3C42} (WABControl Class) - https://www.linkedin.com/cab/wabctrl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{997E5266-AFD2-432E-9554-00127524B51B}: NameServer = 209.244.0.3 209.244.0.4
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE

Thanks,
jwh
Downloaded and ran ewido. Here is the ewido scanlog and the latest HJT scanlog. Am I now clean? System seems a little slow. Please help.

Thank you,

jwh

———————————————————
ewido anti-malware - Scan report
———————————————————

+ Created on: 12:04:33 AM, 1/13/2006
+ Report-Checksum: DF30A0B

+ Scan result:

[384] C:\WINDOWS\system32\ldD546.tmp -> Downloader.Zlob.dy : Error during cleaning
C:\WINDOWS\SYSTEM\SBUtils\SBWebCtl.dll -> Adware.WindowEnhancer : Cleaned with backup
C:\WINDOWS\SYSTEM32\1024\ldDFEB.tmp -> Not-A-Virus.Hoax.Win32.Renos.am : Cleaned with backup
C:\WINDOWS\SYSTEM32\1024\ld5711.tmp -> Not-A-Virus.Hoax.Win32.Renos.am : Cleaned with backup
C:\WINDOWS\SYSTEM32\1024\ld8D2B.tmp -> Not-A-Virus.Hoax.Win32.Renos.am : Cleaned with backup
C:\WINDOWS\SYSTEM32\1024\ld9707.tmp -> Not-A-Virus.Hoax.Win32.Renos.am : Cleaned with backup
C:\WINDOWS\SYSTEM32\msvol.tlb -> Downloader.Zlob.dz : Cleaned with backup
C:\WINDOWS\SYSTEM32\hpDBE.tmp -> Downloader.Zlob.eo : Cleaned with backup
C:\WINDOWS\SYSTEM32\hpD4F6.tmp -> Downloader.Zlob.eo : Cleaned with backup
C:\WINDOWS\SYSTEM32\hp985C.tmp -> Downloader.Zlob.dr : Cleaned with backup
C:\WINDOWS\SYSTEM32\__delete_on_reboot__ldD546.tmp -> Downloader.Zlob.dy : Cleaned with backup
C:\SMSLOGON\pskill.exe -> Not-A-Virus.NetTool.Win32.PsKill : Cleaned with backup
C:\Documents and Settings\James Havidic\Local Settings\Temp\llkiglmd.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\Documents and Settings\James Havidic\Local Settings\Temp\nobbcpmd.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\Documents and Settings\James Havidic\Local Settings\Temp\mnoecpmd.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\Documents and Settings\James Havidic\Local Settings\Temp\abaldpmd.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\Documents and Settings\James Havidic\Local Settings\Temp\jhahcpmd.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\Documents and Settings\James Havidic\Local Settings\Temp\mnhkdpmd.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\Documents and Settings\James Havidic\Local Settings\Temporary Internet Files\Content.IE5\XWON5DSH\gdnUS2218[1].exe -> Downloader.Small.ayl : Cleaned with backup
C:\Documents and Settings\James Havidic\Local Settings\Temporary Internet Files\Content.IE5\KVZ328T5\gdnUS2218[1].exe -> Downloader.Small.ayl : Cleaned with backup
C:\Documents and Settings\James Havidic\Cookies\james [removed][2].txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
C:\Documents and Settings\James Havidic\Cookies\james havidic@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.14:C:\Documents and Settings\James Havidic\Application Data\Mozilla\Profiles\default\mo9sal4l.slt\cookies.txt -> Spyware.Cookie.Paycounter : Cleaned with backup
:mozilla.20:C:\Documents and Settings\James Havidic\Application Data\Mozilla\Profiles\default\mo9sal4l.slt\cookies.txt -> Spyware.Cookie.Counted : Cleaned with backup
:mozilla.21:C:\Documents and Settings\James Havidic\Application Data\Mozilla\Profiles\default\mo9sal4l.slt\cookies.txt -> Spyware.Cookie.Counted : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP129\A0009931.exe -> Downloader.Zlob.dz : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP129\A0009932.exe -> Downloader.Zlob : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP131\A0009951.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0014993.exe -> Downloader.Zlob.ef : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0014994.tlb -> Downloader.Zlob.dz : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0014995.exe -> Downloader.Zlob.ee : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0015002.tlb -> Downloader.Zlob.dr : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0015006.exe -> Downloader.Zlob.dr : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0016002.tlb -> Downloader.Zlob.dr : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0017002.tlb -> Downloader.Zlob.dr : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0017011.tlb -> Downloader.Zlob.dr : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0017020.tlb -> Downloader.Zlob.dr : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0017030.tlb -> Downloader.Zlob.dr : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0018031.tlb -> Downloader.Zlob.dr : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0019031.tlb -> Downloader.Zlob.dr : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0020030.tlb -> Downloader.Zlob.dr : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0021031.tlb -> Downloader.Zlob.dr : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0022030.tlb -> Downloader.Zlob.dr : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0022039.tlb -> Downloader.Zlob.dr : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0022047.tlb -> Downloader.Zlob.dr : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP134\A0022064.tlb -> Downloader.Zlob.dr : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP134\A0022067.exe -> Downloader.Zlob.dr : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP134\A0022068.exe -> Downloader.Zlob.ej : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP135\A0022130.exe -> Downloader.Zlob.dy : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP135\A0022142.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP135\A0022145.exe -> Downloader.Zlob.dy : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP135\A0022150.tlb -> Downloader.Zlob.dz : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP135\A0022161.tlb -> Downloader.Zlob.dz : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP135\A0022167.dll -> Not-A-Virus.Hoax.Win32.Renos.am : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP135\A0022175.dll -> Not-A-Virus.Hoax.Win32.Renos.ap : Cleaned with backup


::Report End

Logfile of HijackThis v1.99.1
Scan saved at 5:53:33 PM, on 1/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\KMaestro\KMaestro.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\PGP\PGP602i\PGPtray.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Palm\HOTSYNC.EXE
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\Symantec\WinFax\WFXCTL32.EXE
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\Symantec\WinFax\WFXMOD32.EXE
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\JAMESH~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://msnmember.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: International - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpDBE.tmp (file missing)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_16_0.DLL (file missing)
O3 - Toolbar: CM Band - {159C2E51-9823-11D2-8DDC-D84A1B4ACD4D} - C:\Program Files\Crystalys media\cm.dll (file missing)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [BtcMaestro] C:\Program Files\KMaestro\KMaestro.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: PGPtray.lnk = C:\Program Files\PGP\PGP602i\PGPtray.exe
O4 - Global Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Controller.LNK = C:\Program Files\Symantec\WinFax\WFXCTL32.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Search - http://speedbar.myway.com/menusearch.html?p=MG1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1125321530830
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {FA9740A2-5802-42E2-B509-81186EEB3C42} (WABControl Class) - https://www.linkedin.com/cab/wabctrl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{997E5266-AFD2-432E-9554-00127524B51B}: NameServer = 209.244.0.3 209.244.0.4
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE
Hello James, welcome to TomCoyote forum and sorry for the wait. The volunteers are swamped with requests. You are still displaying signs of the Smitfraud trojan and I will send you to instuctions for it first.

Before we start, You are running HJT.exe from a .zip file in a Temporary Directory. This is unsafe as we will have no backups. That is why you received this message when you used HJT: http://russelltexas.com/malware/images/unsafefolder.gif
Please use the information in the following link to place HJT in a permanent, safe folder, I prefer C:\HJT\HijackThis.exe. If you need additional instructions use these: http://russelltexas.com/malware/createhjtfolder.htm

Please follow the instructions here: http://forums.tomcoyote.org/index.php?showtopic=54307 then return to this topic and post the logs requested. Since ewido may have new updates, make sure you do before you run it. I will be notified and repond as soon as possible. We will clean up anything left at that point.

Thanks…pskelley
TomCoyote forum
Expert Member
pskelley:
Thanks so very much for helping me out! Here are the latest scans.

Logfile of HijackThis v1.99.1
Scan saved at 3:41:49 PM, on 1/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\Program Files\KMaestro\KMaestro.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\PGP\PGP602i\PGPtray.exe
C:\Palm\HOTSYNC.EXE
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\Symantec\WinFax\WFXCTL32.EXE
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\Symantec\WinFax\WFXMOD32.EXE
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\Lotus\Notes\NLNOTES.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Lotus\Notes\ntaskldr.EXE
C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://msnmember.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: International - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpDBE.tmp (file missing)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_16_0.DLL (file missing)
O3 - Toolbar: CM Band - {159C2E51-9823-11D2-8DDC-D84A1B4ACD4D} - C:\Program Files\Crystalys media\cm.dll (file missing)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [BtcMaestro] C:\Program Files\KMaestro\KMaestro.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: PGPtray.lnk = C:\Program Files\PGP\PGP602i\PGPtray.exe
O4 - Global Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Controller.LNK = C:\Program Files\Symantec\WinFax\WFXCTL32.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Search - http://speedbar.myway.com/menusearch.html?p=MG1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1125321530830
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/gs/instal…edsolutions.cab
O16 - DPF: {FA9740A2-5802-42E2-B509-81186EEB3C42} (WABControl Class) - https://www.linkedin.com/cab/wabctrl.cab
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE


———————————————————
ewido anti-malware - Scan report
———————————————————

+ Created on: 12:00:45 AM, 1/27/2006
+ Report-Checksum: 176A86C0

+ Scan result:

[388] C:\WINDOWS\system32\ldDDD7.tmp -> Downloader.Zlob.fa : Cleaned with backup
C:\WINDOWS\SYSTEM32\mscornet.exe -> Downloader.Zlob.fa : Cleaned with backup
C:\WINDOWS\SYSTEM32\ldDDD7.tmp -> Downloader.Zlob.fa : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP127\A0008843.exe -> Adware.SpywareStrike : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP128\A0008900.exe -> Adware.SpywareStrike : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0018033.exe -> Adware.SpywareStrike : Cleaned with backup


::Report End

Best regards,
jwh
Hello and patience, that was the first step to remove the Smitfraud junk. We have more work to do and I must say I am concerned with the malware on the computer. Speed may or may not improve, though I do have suggestions I will provide once you are clean.

This item: O4 - HKLM\..\Run: [SystemTray] SysTray.Exe is probably safe, but I wish to be sure. Would you search for the file in red to get the pathway, then use these tools to validate it is not a problem, and post the results for me to view.
http://virusscan.jotti.org/
http://www.kaspersky.com/scanforvirus
http://www.virustotal.com/flash/index_en.html

It appears from looking at the first and second ewido logs that ewido has removed everything it located. You should take a good look at where this junk is hiding and where it is coming from. These: C:\System Volume Information\_restore are of course your System Restore files and we will be purging them to get out anything bad before we are finished.

To make sure you have a clean computer, please follow these instructions.

1) Download, update, configure and run these two programs: http://tomcoyote.org/aawsb.php
The newest version of Ad-aware is 1.06 and Spybot 1.04. Even if you have these programs, use the link to get the newest version, update and configure them as in the link. Run Spybot first, reboot then run Ad-aware. Both programs back up what they remove so delete anything the programs say should be removed.

2) Look in Start > Control Panel > Add Remove programs for: C:\Program Files\Crystalys media\ and uninstall it if it is there.

3) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: International - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpDBE.tmp (file missing)
(next item is not malware, but with the missing file, can not be working right. If you use this, download it again once you are clean)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_16_0.DLL (file missing)
O3 - Toolbar: CM Band - {159C2E51-9823-11D2-8DDC-D84A1B4ACD4D} - C:\Program Files\Crystalys media\cm.dll (file missing)
O8 - Extra context menu item: &Search - http://speedbar.myway.com/menusearch.html?p=MG1

Close all programs but HJT and all browser windows, then click on "Fix Checked"

4) Enable hidden files&folders..reverse the process when finished.
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

RIGHT Click on Start then click on Explore. Locate and delete these items:

C:\Program Files\Crystalys media\ >>> folder (if there)

C:\Windows\Prefetch\ >>> delete everything in this folder (NOT THE FOLDER)
Prefetch info: http://www.windowsnetworking.com/articles_…refetch-XP.html

Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions http://www.ccleaner.com/help/tour1.asp
Run CCleaner, Windows & Applications when you run the registry cleaner (Issues) you will be prompted to backup before you can remove stuff, make sure you do. Post a new HJT log and your comments, and the results from the trojan scans. How are you running now?

Thanks…Phil
Phil: As you suspected, it looks like SysTray.Exe is OK. Here are the scans you requested: Jotti's malware scan 2.99-TRANSITION_TO_3.00 File to upload & scan: Service Service load: 0% 100% File: SysTray.exe Status: OK MD5 46e07fd3a40760fda18cf6b4fc691742 Packers detected: - Scanner results AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing Fortinet Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing UNA Found nothing VBA32 Found nothing Scanned file: SysTray.exe SysTray.exe - OKStatistics:Known viruses: 173915 Updated: 30-01-2006 File size (Kb): 3 Virus bodies: 0 Files: 1 Warnings: 0 Archives: 0 Suspicious: 0 This is a report processed by VirusTotal on 01/30/2006 at 16:45:47 (CET) after scanning the file "SysTray.exe" file. Antivirus Version Update Result AntiVir 6.33.0.81 01.30.2006 no virus found Avast 4.6.695.0 01.29.2006 no virus found AVG 718 01.27.2006 no virus found Avira 6.33.0.81 01.30.2006 no virus found BitDefender 7.2 01.30.2006 no virus found CAT-QuickHeal 8.00 01.27.2006 no virus found ClamAV devel-20051123 01.30.2006 no virus found DrWeb 4.33 01.30.2006 no virus found eTrust-InoculateIT 23.71.63 01.29.2006 no virus found eTrust-Vet 12.4.2060 01.30.2006 no virus found Ewido 3.5 01.30.2006 no virus found Fortinet 2.54.0.0 01.30.2006 no virus found F-Prot 3.16c 01.28.2006 no virus found Ikarus 0.2.59.0 01.30.2006 no virus found Kaspersky 4.0.2.24 01.30.2006 no virus found McAfee 4684 01.27.2006 no virus found NOD32v2 1.1388 01.30.2006 no virus found Norman 5.70.10 01.30.2006 no virus found Panda 9.0.0.4 01.30.2006 no virus found Sophos 4.02.0 01.30.2006 no virus found Symantec 8.0 01.30.2006 no virus found TheHacker 5.9.3.084 01.29.2006 no virus found UNA 1.83 01.27.2006 no virus found VBA32 3.10.5 01.30.2006 no virus found VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware. I'm now going to move on to your next suggestions and let you know how it works out. Thanks again! Jim
Phil:
Everything seems to be running properly now. Ad Aware and Spybot removed a lot of junk it they didn't see before. Sorry, but I forgot to save those logs. Here are the HJT and Ewido logs:

Logfile of HijackThis v1.99.1
Scan saved at 6:22:47 PM, on 1/30/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\KMaestro\KMaestro.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\PGP\PGP602i\PGPtray.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\Palm\HOTSYNC.EXE
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\Symantec\WinFax\WFXCTL32.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\Symantec\WinFax\WFXMOD32.EXE
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://msnmember.msn.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [BtcMaestro] C:\Program Files\KMaestro\KMaestro.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: PGPtray.lnk = C:\Program Files\PGP\PGP602i\PGPtray.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Controller.LNK = C:\Program Files\Symantec\WinFax\WFXCTL32.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1125321530830
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/gs/instal…edsolutions.cab
O16 - DPF: {FA9740A2-5802-42E2-B509-81186EEB3C42} (WABControl Class) - https://www.linkedin.com/cab/wabctrl.cab
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE

———————————————————
ewido anti-malware - Scan report
———————————————————

+ Created on: 12:00:45 AM, 1/27/2006
+ Report-Checksum: 176A86C0

+ Scan result:

[388] C:\WINDOWS\system32\ldDDD7.tmp -> Downloader.Zlob.fa : Cleaned with backup
C:\WINDOWS\SYSTEM32\mscornet.exe -> Downloader.Zlob.fa : Cleaned with backup
C:\WINDOWS\SYSTEM32\ldDDD7.tmp -> Downloader.Zlob.fa : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP127\A0008843.exe -> Adware.SpywareStrike : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP128\A0008900.exe -> Adware.SpywareStrike : Cleaned with backup
C:\System Volume Information\_restore{9770CE2D-8480-46EE-94B4-9EDE8789596B}\RP133\A0018033.exe -> Adware.SpywareStrike : Cleaned with backup


::Report End

Thank you very much once again!! I couldn't have done this without your help.

Best regards,
Jim
Hi Jim, I would say it was a team effort, could you see it happening without both members of the team :rofl:

Logfile of HijackThis v1.99.1 Scan saved at 6:22:47 PM, on 1/30/2006

Looking over the HJT log first and I will have a few comments

C:\Program Files\ewido anti-malware\ewidoctrl.exe
ewido is a great program but it does use some resources.
Once the trial is over you can update and use the scanner
for as long as you wish, but unless you purchase it you should turn it off
completely so it does not run unless you start it manually.

Look at the 016 DPF ActiveX plugins. They will be put back if you visit the site again so use HJT to remove any you are done with or don't know what are.

Jim, it appears you want your Antivirus program to be Network Associates. You are running some items in your Services (023) that I believe should be at least turned off. I will show you how to disable them, if you want them removed from your computer let me know and I will show you how to remove them with HJT. Here they are, and you will know I am sure if they are doing something other than virus protection. Multiple virus programs is not a good thing.

O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
disable this one so ewido will not run after the trial is over

O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE

These are the others and if they should not be running, use these instructions to disable them:
as I said if they have another function that I am not aware of, leave them run.

Disable the offending Service
Click Start < Run and type services.msc.
Scroll down to (xxxxxxxxxxx ) and right click on it.
Click Properties and under Service Status click Stop, then under Startup Type change it to Disabled.

Where the x's is the name of the item you wish to disable.

Since we got the malware out of the computer, here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://boards.cexx.org/viewtopic.php?t=957
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

You saw all of that junk in the System Restore files, follow these directions to take care of that.
System Restore does not know good from bad, it backs up everything. In case some of the infection got into your System Restore files, follow the instructions in this link to get clean System Restore files. Turn it off, restart your computer and turn it back on.
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

That should do it, pleasure working with you and safe surfing…Phil :wavey:

Thanks…pskelley
TomCoyote forum
Expert Member
If you are reading this information…thank a teacher,
If you are reading it in English…thank a soldier.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI