Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93099 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

New Microsoft Windows Malicious Software Removal Tool & Spybot SD


  • This topic is locked This topic is locked
7 replies to this topic

#1 NewXPdown

NewXPdown

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 15 March 2006 - 05:03 PM

I just updated my Windows XP at www.microsoft.com which included the installation of the new Microsoft Windows Malicious Software Removal Tool (more info can be found here: http://support.micro...om/?kbid=890830)

Immediately during/after it's installation it appeared to be deleting what it determined to be "Malicious Software" from the registry which the Spybot SD thus asked to allow, which I said yes to all. Upon reboot, I was surprised that Spybot SD asked again, since I thought they were all permanently deleted from the system now. I allowed all of them again, but noticed that my McAfee Personal Firewall and McAfee Privacy Center were also shut off in the process (indicating what appeared to be a misidentification of those two start up files as "Malicious"). I was able to re-enable both McAfee settings from the McAfee Security Center.

I then rebooted again, hoping that this time the change would be permanent, but it wasn't. Once again, Spybot SD asked to approve every single deletion. So this time I checked the "Remember this decision" box for each.

Of course, now, I get a flood of little yellow boxes reminding me of these allowed deletions every time I reboot.

Isn't there a way to remove these files permanently? Are they all really bad? How do I identify which are good McAfee files and keep those settings?

Here is my recent Spybot SD Log (followed by my HijackThis Log):
3/14/2006 12:47:40 PM Allowed value "MCUpdateExe" (new data: "C:\PROGRA~1\mcafee.com\agent\mcupdate.exe") changed in System Startup global entry!
3/14/2006 12:47:46 PM Allowed value "MCUpdateExe" (new data: "c:\PROGRA~1\mcafee.com\agent\mcupdate.exe") changed in System Startup global entry!
3/14/2006 4:02:59 PM Allowed value "SunKistEM" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:00 PM Allowed value "" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:01 PM Allowed value "MCAgentExe" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:01 PM Allowed value "MCUpdateExe" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:02 PM Allowed value "Gateway Extended Warranty" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:03 PM Allowed value "IgfxTray" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:04 PM Allowed value "HotKeysCmds" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:04 PM Allowed value "CHotkey" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:05 PM Allowed value "Reminder" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:06 PM Allowed value "Recguard" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:06 PM Allowed value "RemoteControl" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:07 PM Allowed value "High Definition Audio Property Page Shortcut" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:07 PM Allowed value "Mixersel" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:08 PM Allowed value "SoundMan" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:08 PM Allowed value "AlcWzrd" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:08 PM Allowed value "InstantAccess" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:09 PM Allowed value "RegisterDropHandler" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:11 PM Allowed value "VSOCheckTask" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:12 PM Allowed value "VirusScan Online" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:13 PM Allowed value "OASClnt" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:13 PM Allowed value "MPFExe" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:14 PM Allowed value "MPSExe" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:14 PM Allowed value "NeroFilterCheck" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:15 PM Allowed value "_AntiSpyware" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:15 PM Allowed value "iTunesHelper" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:16 PM Allowed value "QuickTime Task" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:16 PM Allowed value "Adobe Photo Downloader" (new data: "") deleted in System Startup global entry!
3/14/2006 4:03:18 PM Allowed value "InvisibleBrowsing" (new data: "") deleted in System Startup global entry!
3/14/2006 4:04:49 PM Allowed value "{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}" (new data: "") added in ActiveX Distribution Unit!
3/14/2006 4:06:24 PM Allowed value "MCUpdateExe" (new data: "C:\PROGRA~1\mcafee.com\agent\McUpdate.exe") added in System Startup global entry!
3/14/2006 8:08:06 PM Allowed value "MCUpdateExe" (new data: "c:\PROGRA~1\mcafee.com\agent\mcupdate.exe") changed in System Startup global entry!
3/15/2006 1:45:36 PM Allowed value "MCUpdateExe" (new data: "C:\PROGRA~1\mcafee.com\agent\mcupdate.exe") changed in System Startup global entry!
3/15/2006 2:12:05 PM Allowed value "SunKistEM" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:13 PM Allowed value "" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:19 PM Allowed value "MCAgentExe" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:29 PM Allowed value "Gateway Extended Warranty" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:31 PM Allowed value "IgfxTray" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:32 PM Allowed value "HotKeysCmds" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:33 PM Allowed value "CHotkey" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:34 PM Allowed value "Reminder" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:35 PM Allowed value "Recguard" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:37 PM Allowed value "RemoteControl" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:48 PM Allowed value "High Definition Audio Property Page Shortcut" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:50 PM Allowed value "Mixersel" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:51 PM Allowed value "SoundMan" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:52 PM Allowed value "AlcWzrd" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:55 PM Allowed value "InstantAccess" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:55 PM Allowed value "RegisterDropHandler" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:56 PM Allowed value "VSOCheckTask" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:57 PM Allowed value "VirusScan Online" (new data: "") deleted in System Startup global entry!
3/15/2006 2:12:59 PM Allowed value "OASClnt" (new data: "") deleted in System Startup global entry!
3/15/2006 2:13:01 PM Allowed value "MPFExe" (new data: "") deleted in System Startup global entry!
3/15/2006 2:13:02 PM Allowed value "MPSExe" (new data: "") deleted in System Startup global entry!
3/15/2006 2:13:03 PM Allowed value "NeroFilterCheck" (new data: "") deleted in System Startup global entry!
3/15/2006 2:13:03 PM Allowed value "_AntiSpyware" (new data: "") deleted in System Startup global entry!
3/15/2006 2:13:04 PM Allowed value "iTunesHelper" (new data: "") deleted in System Startup global entry!
3/15/2006 2:13:04 PM Allowed value "QuickTime Task" (new data: "") deleted in System Startup global entry!
3/15/2006 2:13:05 PM Allowed value "Adobe Photo Downloader" (new data: "") deleted in System Startup global entry!
3/15/2006 2:13:06 PM Allowed value "MCUpdateExe" (new data: "c:\PROGRA~1\mcafee.com\agent\McUpdate.exe") changed in System Startup global entry!
3/15/2006 2:13:07 PM Allowed value "MCAgentExe" (new data: "c:\PROGRA~1\mcafee.com\agent\McAgent.exe") added in System Startup global entry!
3/15/2006 2:14:02 PM Allowed value "MCUpdateExe" (new data: "C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe") changed in System Startup global entry!
3/15/2006 2:16:25 PM Allowed value "MPFEXE" (new data: ""C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe"") added in System Startup global entry!
3/15/2006 2:23:17 PM Allowed value "MCUpdateExe" (new data: "C:\PROGRA~1\mcafee.com\agent\McUpdate.exe") changed in System Startup global entry!
3/15/2006 2:23:21 PM Allowed value "MCAgentExe" (new data: "c:\PROGRA~1\mcafee.com\agent\McAgent.exe") changed in System Startup global entry!
3/15/2006 2:23:24 PM Allowed value "SunKistEM" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:28 PM Allowed value "" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:38 PM Allowed value "Gateway Extended Warranty" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:39 PM Allowed value "IgfxTray" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:41 PM Allowed value "HotKeysCmds" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:42 PM Allowed value "CHotkey" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:44 PM Allowed value "Reminder" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:46 PM Allowed value "Recguard" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:47 PM Allowed value "RemoteControl" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:49 PM Allowed value "High Definition Audio Property Page Shortcut" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:50 PM Allowed value "Mixersel" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:52 PM Allowed value "SoundMan" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:53 PM Allowed value "AlcWzrd" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:54 PM Allowed value "InstantAccess" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:55 PM Allowed value "RegisterDropHandler" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:56 PM Allowed value "VSOCheckTask" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:57 PM Allowed value "VirusScan Online" (new data: "") deleted in System Startup global entry!
3/15/2006 2:23:58 PM Allowed value "OASClnt" (new data: "") deleted in System Startup global entry!
3/15/2006 2:24:01 PM Allowed value "MPSExe" (new data: "") deleted in System Startup global entry!
3/15/2006 2:24:02 PM Allowed value "NeroFilterCheck" (new data: "") deleted in System Startup global entry!
3/15/2006 2:24:03 PM Allowed value "_AntiSpyware" (new data: "") deleted in System Startup global entry!
3/15/2006 2:24:04 PM Allowed value "iTunesHelper" (new data: "") deleted in System Startup global entry!
3/15/2006 2:24:05 PM Allowed value "QuickTime Task" (new data: "") deleted in System Startup global entry!
3/15/2006 2:24:06 PM Allowed value "Adobe Photo Downloader" (new data: "") deleted in System Startup global entry!
3/15/2006 2:24:06 PM Allowed value "MPFEXE" (new data: "") deleted in System Startup global entry!
3/15/2006 2:24:07 PM Allowed value "MPFEXE" (new data: ""C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe"") added in System Startup global entry!
3/15/2006 2:24:36 PM Allowed value "MPFExe" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "MCUpdateExe" (new data: "C:\PROGRA~1\mcafee.com\agent\McUpdate.exe") changed in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "MCAgentExe" (new data: "c:\PROGRA~1\mcafee.com\agent\McAgent.exe") changed in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "SunKistEM" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "Gateway Extended Warranty" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "IgfxTray" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "HotKeysCmds" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "CHotkey" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "Reminder" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "Recguard" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "RemoteControl" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "High Definition Audio Property Page Shortcut" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "Mixersel" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "SoundMan" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "AlcWzrd" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "InstantAccess" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "RegisterDropHandler" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "VSOCheckTask" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "VirusScan Online" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "OASClnt" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "MPSExe" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "NeroFilterCheck" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "_AntiSpyware" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "iTunesHelper" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "QuickTime Task" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "Adobe Photo Downloader" (new data: "") deleted in System Startup global entry!
3/15/2006 2:29:58 PM Allowed value "MPFEXE" (new data: "") deleted in System Startup global entry!
3/15/2006 2:30:00 PM Allowed value "MPFEXE" (new data: ""C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe"") added in System Startup global entry!
3/15/2006 2:30:00 PM Allowed value "MPFExe" (new data: "") deleted in System Startup global entry!

---------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 2:30:45 PM, on 3/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.my.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\PROGRA~1\NETSCA~1\NETSCA~1\pbhelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [MPFEXE] "C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe"
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...99/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1126471301164
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,26/mcgdmgr.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: Netscape Update Service (NCUpdateSvc) - Netscape Communications Corporation - C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

Thank you for your help. :wavey:

    Advertisements

Register to Remove


#2 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 27 March 2006 - 11:06 AM

Open Spybot Mode | Advanced Tools | Resident and untick the box for TeaTimer to disable it. Exit Spybot. In the Windows system tray, if the TeaTimer icon is still present, right click it and exit the TeaTimer. Then remove and reinstall spybot and make sure it is version 1.4

#3 NewXPdown

NewXPdown

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 27 March 2006 - 05:03 PM

:scratch: Mkay... so you appear to be saying that I do NOT need to worry about any of those files, and it is OK to have them all permanently deleted? So apparently now it is just a matter of resetting SpyBotS&D to remove the annoying repeated alerts? Sorry if I seem skeptical, but I am surprised that it took so long to get an answer to my concern if it was as simple as that. But, as suggested, I went ahead and removed and reinstalled SpyBotS&D (it was already updated, but did so again from scratch anyway to reset everything), and as expected the alerts have discontinued. Here's hoping nothing important got lost in the shuffle. Thank you for your help. :wavey:

Edited by NewXPdown, 27 March 2006 - 05:03 PM.


#4 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 28 March 2006 - 01:03 AM

Can you now post another log from hijackthis.

So we may see if anything is installed that you may not want.

Sorry if I seem skeptical, but I am surprised that it took so long to get an answer to my concern if it was as simple as that.

Sorry we are swamped here and some logs go unanswered because of lack of time.

#5 NewXPdown

NewXPdown

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 29 March 2006 - 10:29 AM

I understand. I myself was offline yesterday. Please do not mistake my concerns for being ungrateful.

Here is my new HJT Log:
Logfile of HijackThis v1.99.1
Scan saved at 8:22:58 AM, on 3/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Yahoo!\Messenger\YPager.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.my.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\PROGRA~1\NETSCA~1\NETSCA~1\pbhelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [MPFEXE] "C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe"
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...99/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1126471301164
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,26/mcgdmgr.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: Netscape Update Service (NCUpdateSvc) - Netscape Communications Corporation - C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

#6 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 29 March 2006 - 11:26 PM

Log looks clean :thumbup:

To help keep your PC clean follow the recommendations in Tony Klein's article
So how did I get infected in the first place?

#7 NewXPdown

NewXPdown

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 31 March 2006 - 02:22 AM

:thumbup: Thank you kindly! :wavey:



#8 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 31 March 2006 - 09:15 AM

Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoy...showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users