Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.
Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.
Note : process.exeis detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. http://www.beyondlogic.org/consulting/proc…processutil.htm
Then, run Hijack This. Scan and copy the log, then post it into this topic, along with the text file from SmitfraudFix.
Please use the [external image: Posted Image] button to reply.
When I try to access VundoFix.txt I'm presented with a dialog box informing me that Access is denied. I tried everything I could think of to access the file such as, changing it's name(access denied), copying the file and pasting elsewhere(access denied), opening it with wordpad instead of notepad(access denied), and I also tryed opening it with MSWord but still access denied. Oops. Just before I posted this I tried one more thing. I changed the permissions on the file to full control -> everyone and it worked. Hehe.
Here's the log for VundoFix.txt:
VundoFix V4.2.84
Running as SYSTEM
from c:\windows\system32\VundoFix.exe
Checking Java version…
Scan started at 5:12:03 PM 7/5/2006
Listing files found while scanning….
There were about four files that vundo found while scanning. They were listed in the box while the program ran, but I see nothing listed here. If that's normal then I guess I'm okay. But it seems that there should have been a list after "Listing files found while scanning…." Anyways…… I have no idea what I'm talking about and your an expert so I'll just keep quiet.
Here's the HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 5:17:45 PM, on 7/5/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Your input is very valuable and greatly appreciated.
I don't know why there were the problems you had with VundoFix. That isn't at all normal.
There does seem to be something wrong with how the VundoFix worked. It didn't. Not only is the VundoFix report not there, the Trojan is still showing in your Hijack This logfile. We will give it another shot, using another program.
Please print, or copy and paste this text into a Notepad file and place it on your desktop, to review as you work. Please proceed with this fix in the order provided below. Please read this text fully, or there may be an unplesant surprise in store for you. A BSOD
I thought this first part could wait until some other things were resolved, but it looks like that may not have been best after all.
Sorry, this is going to be a bit long, so take your time and double check everything.
Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.
Next, please reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.
Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.
The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".
The tool may need to restart your computer to finish the cleaning process. A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
Then please restart it into Normal Windows.
Next:
Please delete the copy of VundoFix that you have and download this one. We will see if it works any better.
Please download VirtumundoBeGone: http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
* Save it to the Desktop
* Close all running programs (including your Internet Browser)
* Double-click VirtumundoBeGone.exe on the Desktop
* Follow the directions as indicated
This program may generate a "BLUE SCREEN OF DEATH" which is an expected/necessary part of the process.
Do not be concerned.
Just reboot if your system "jams".
Next:
Please go to Control Panel>Add/Remove Programs and Uninstall/Remove... winupdates
Next:
Please set your system to show all files; please see here if you're unsure how to do this.
Disable Ewido:
Please disable Ewido, as it may interfere with the fix.[br]To disable Ewido:
From the system tray:
Right-click the system tray icon and uncheck real time protection.
or From within Ewido -
Under 'Your security status', if the real time protection is active, deactivate it by clicking 'real time protection' until the status says 'inactive'.
Once your log is clean you can re-enable Ewido.
Close all Windows and browsers, leaving only HijackThis running.
Place a check against each of the following, if present.
Exit Explorer, enable hidden files and reboot as normal.
If you were unable to delete any of the files then please follow these additional instructions:
Download Pocket Killbox and unzip it; save it to your Desktop.
Run it, and click the radio button that says Delete a file on reboot. For each of the files you could not delete, paste them one at a time into the full path of file to delete box and click the red circle with a white cross in it.
The program will ask you if you want to reboot; say No each time until the last one has been pasted in whereupon you should answer Yes.
Let the system reboot.
Please post the contents of the SmitfraudFix log located at C:\rapport.txt, the contents of VirtumundoBeGone log (VBG.txt on your desktop)and a fresh HijackThis log, into this topic.
Please advise if any problems remain.
Please use the [external image: Posted Image] button to reply.
Wowzers!!!!!! That took me a while. Believe it or not I'd gone through the self-help section before I posted and used the Smitfraudfix program with no results. Going through the program this time, I see why. For one reason or another, even though I'm the administrator on this system, I didn't have all the proper permissions set. So when I ran Smitfraudfix the first time, and the second time, I was presented with line upon line of "Access denied" banter. So, I reset my permissions and went through your instructions and did not encounter "Acess denied" anywhere.
Winupdates was not in Control Panel/Add remove, but it was is Program Files. Keyword: was. Also, Smitfraudfix was attempting to delete Temp files from the "C:\" drive. Unfortunately the Temp files weren't there. Fortunately, however; I figured out what the program wanted to do and hunted down the Temp files and subsequently removed them from the same path save the drive letter. Long story short - the temp folder was on the "H:\" drive. I'm long winded at times.
When I ran HJT there were a few, but not all, items from your list above:(to save some keystrokes I paraphrased the items)
O2 BHO:(lots of stuff here I'm paraphrasing) hp100.tmp
O4 HKLM winupdates
O20 winlogon notify winmoy32
The files were deleted from "C:\Windows\System32\" with some variation. "hp100.tmp" wasn't there. And "ddaba.dll" was, in my case, "ddaba.dll.vir" I don't know if that is of significance but I thought you might want to know.
Thanks again for your help, and if there are any questions you have for me I'll answer to the best of my knowledge.
Here are the logs you requested:
Hijack This:
Logfile of HijackThis v1.99.1
Scan saved at 11:59:00 PM, on 7/5/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
H:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
C:\WINDOWS\System32\atiptaxx.exe
H:\Program Files\iTunes\iTunesHelper.exe
H:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
H:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Common Files\TiVo Shared\Transfer\TivoTransfer.exe
H:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
H:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
h:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
H:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\iPod\bin\iPodService.exe
H:\Hijack\HJT.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [MimBoot] h:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [DAEMON Tools] "H:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [iTunesHelper] "H:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "H:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "H:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [TivoTransfer] "C:\Program Files\Common Files\TiVo Shared\Transfer\TivoTransfer.exe" /auto:TivoTransfer /registry /service
O4 - HKCU\..\Run: [TivoServer] "H:\Program Files\TiVo\Desktop\TiVoServer.exe" /registry /service
O4 - HKCU\..\Run: [Creative Detector] "H:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - h:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - h:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - h:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O20 - Winlogon Notify: winmoy32 - winmoy32.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - H:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Smitfraudfix's "rapport.txt:"
SmitFraudFix v2.65
Scan done at 23:04:54.53, Wed 07/05/2006
Run from H:\Firefox DL\My Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{7916f057-223f-4612-ac84-e882cbe043d4}"="bals"
[HKEY_CLASSES_ROOT\CLSID\{7916f057-223f-4612-ac84-e882cbe043d4}\InProcServer32]
@="C:\WINDOWS\System32\hvcycg.dll"
[HKEY_CURRENT_USER\Software\Classes\CLSID\{7916f057-223f-4612-ac84-e882cbe043d4}\InProcServer32]
@="C:\WINDOWS\System32\hvcycg.dll"
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
C:\WINDOWS\System32\hvcycg.dll -> Missing File
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{7916f057-223f-4612-ac84-e882cbe043d4}"="bals"
[HKEY_CLASSES_ROOT\CLSID\{7916f057-223f-4612-ac84-e882cbe043d4}\InProcServer32]
@="C:\WINDOWS\System32\hvcycg.dll"
[HKEY_CURRENT_USER\Software\Classes\CLSID\{7916f057-223f-4612-ac84-e882cbe043d4}\InProcServer32]
@="C:\WINDOWS\System32\hvcycg.dll"
»»»»»»»»»»»»»»»»»»»»»»»» End
And, finally, Virtumudobegone log VBG.txt:
[07/05/2006, 23:10:25] - VirtumundoBeGone v1.5 ( "H:\Firefox DL\My Desktop\VirtumundoBeGone.exe" )
[07/05/2006, 23:10:33] - Detected System Information:
[07/05/2006, 23:10:33] - Windows Version: 5.1.2600,
[07/05/2006, 23:10:33] - Current Username: James Terry Jr (Admin)
[07/05/2006, 23:10:33] - Windows is in NORMAL mode.
[07/05/2006, 23:10:33] - Searching for Browser Helper Objects:
[07/05/2006, 23:10:33] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[07/05/2006, 23:10:33] - BHO 2: {5f4c3d09-b3b9-4f88-aa82-31332fee1c08} (Nothing)
[07/05/2006, 23:10:33] - BHO 3: {804E0644-3B61-4D04-83A7-27D4C47E3137} ()
[07/05/2006, 23:10:33] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/05/2006, 23:10:33] - Checking for HKLM\…\Winlogon\Notify\ddaba
[07/05/2006, 23:10:33] - Found: HKLM\…\Winlogon\Notify\ddaba - This is probably Virtumundo.
[07/05/2006, 23:10:33] - Assigning {804E0644-3B61-4D04-83A7-27D4C47E3137} MSEvents Object
[07/05/2006, 23:10:33] - BHO list has been changed! Starting over…
[07/05/2006, 23:10:33] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[07/05/2006, 23:10:33] - BHO 2: {5f4c3d09-b3b9-4f88-aa82-31332fee1c08} (Nothing)
[07/05/2006, 23:10:33] - BHO 3: {804E0644-3B61-4D04-83A7-27D4C47E3137} (MSEvents Object)
[07/05/2006, 23:10:33] - ALERT: Found MSEvents Object!
[07/05/2006, 23:10:33] - Finished Searching Browser Helper Objects
[07/05/2006, 23:10:33] - *** Detected MSEvents Object
[07/05/2006, 23:10:33] - Trying to remove MSEvents Object…
[07/05/2006, 23:10:34] - Terminating Process: IEXPLORE.EXE
[07/05/2006, 23:10:34] - Terminating Process: RUNDLL32.EXE
[07/05/2006, 23:10:35] - Disabling Automatic Shell Restart
[07/05/2006, 23:10:35] - Terminating Process: EXPLORER.EXE
[07/05/2006, 23:10:35] - Suspending the NT Session Manager System Service
[07/05/2006, 23:10:35] - Terminating Windows NT Logon/Logoff Manager
[07/05/2006, 23:15:36] - Re-enabling Automatic Shell Restart
[07/05/2006, 23:15:36] - File to disable: C:\WINDOWS\System32\ddaba.dll
[07/05/2006, 23:15:36] - Renaming C:\WINDOWS\System32\ddaba.dll -> C:\WINDOWS\System32\ddaba.dll.vir
[07/05/2006, 23:15:36] - File successfully renamed!
[07/05/2006, 23:15:36] - Removing HKLM\…\Browser Helper Objects\{804E0644-3B61-4D04-83A7-27D4C47E3137}
[07/05/2006, 23:15:36] - Removing HKCR\CLSID\{804E0644-3B61-4D04-83A7-27D4C47E3137}
[07/05/2006, 23:15:36] - Adding Kill Bit for ActiveX for GUID: {804E0644-3B61-4D04-83A7-27D4C47E3137}
[07/05/2006, 23:15:36] - Deleting ATLEvents/MSEvents Registry entries
[07/05/2006, 23:15:36] - Removing HKLM\…\Winlogon\Notify\ddaba
[07/05/2006, 23:15:36] - Searching for Browser Helper Objects:
[07/05/2006, 23:15:36] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[07/05/2006, 23:15:36] - BHO 2: {5f4c3d09-b3b9-4f88-aa82-31332fee1c08} (Nothing)
[07/05/2006, 23:15:36] - Finished Searching Browser Helper Objects
[07/05/2006, 23:15:36] - Finishing up…
[07/05/2006, 23:15:36] - A restart is needed.
[07/05/2006, 23:18:47] - Attempting to Restart via STOP error (Blue Screen!)
I have a feeling it'll take you as long to read all this as it took me to follow your instructions. Sorry for the eye strain. Thanks again for you diligence.
You're right, those are some long reports, but not the longest I've seen, by a long shot. I knew it would take a while to get it done, but you did very well and much better than most would have.
About you being long winded. Not at all !!!!! Your input is greatly appreciated and will definately help in figuring this out.
The good news is, that "hopefully" we can now remove some of those that have been so troublesome.
If any of those files give you problems deleting them, try using Killbox. Directions will be below, with the RED header.
Be sure to enter the entire file paths, beginning with the drive letter.
Please do delete C:\Windows\System32\ddaba.dll.vir, if you haven't already. That is a bad file, which has been renamed, with vir tacked on the end. It shouldn't give you any trouble with its deletion. (see below)
This one should also be deleted. Use Killbox if it gives any trouble. C:\WINDOWS\System32\hvcycg.dll (see below)
That's a good one, about having your temp files in your "H:\" drive, hiding from SmitfraudFix. Good work, figuring out what the program couldn't.
Please set your system to show all files; please see here if you're unsure how to do this.
Disable Ewido:
Please disable Ewido, as it may interfere with the fix.[br]To disable Ewido:
From the system tray:
Right-click the system tray icon and uncheck real time protection.
or From within Ewido -
Under 'Your security status', if the real time protection is active, deactivate it by clicking 'real time protection' until the status says 'inactive'.
Once your log is clean you can re-enable Ewido.
Next: Close all Windows and browsers, leaving only HijackThis running.
And this one. It may also be in the System32 folder, but if not found, do an ALL FILES SEARCH and delete it. winmoy32 - winmoy32.dll
Exit Explorer, enable hidden files and reboot as normal.
If you were unable to find, or delete any of the files then please follow these additional instructions:
Download Pocket Killbox and unzip it; save it to your Desktop.
Run it, and click the radio button that says Delete a file on reboot. For each of the files you could not delete, paste them one at a time into the full path of file to delete box and click the red circle with a white cross in it.
The program will ask you if you want to reboot; say No each time until the last one has been pasted in whereupon you should answer Yes.
Let the system reboot.
Then, please run Hijack This again. Scan and copy the log and post it into this topic.
Please advise if any problems remain.
Please use the [external image: Posted Image] button to reply.
I think that must have it. Computer is running great with no sillyness. I didn't find hvcycg.dll and I had already deleted ddaba.dll.vir. After reading the logs that I posted I saw where one of the programs had renamed it. If only I was more of a "read everything before you do anything" type, I would have seen that.
The only winmoy32 I found was in "C:\!Killbox\" and I removed that folder since you didn't need the log. So with all that here is what, I hope anyway, the last HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 12:05:15 AM, on 7/7/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
H:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
C:\WINDOWS\System32\atiptaxx.exe
H:\Program Files\iTunes\iTunesHelper.exe
H:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
H:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Common Files\TiVo Shared\Transfer\TivoTransfer.exe
H:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
H:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
h:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
H:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\wuauclt.exe
H:\Hijack\HJT.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [MimBoot] h:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [DAEMON Tools] "H:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [iTunesHelper] "H:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "H:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "H:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [TivoTransfer] "C:\Program Files\Common Files\TiVo Shared\Transfer\TivoTransfer.exe" /auto:TivoTransfer /registry /service
O4 - HKCU\..\Run: [TivoServer] "H:\Program Files\TiVo\Desktop\TiVoServer.exe" /registry /service
O4 - HKCU\..\Run: [Creative Detector] "H:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - h:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - h:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - h:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - H:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Thanks once again for all your help. You are trully a gentleman and a scholar. Thanks again.
Those things are too easy to miss. I wouldn't read everything either, if I didn't have to. They are usually much too long and booooorinnnnnggggg. But, the devil is in the details.
By the way, watch those updates from Zone Alarm. There is a glitch in the latest updates/downloads that prevents changing your Home Page and is causing lots of problems. Hopefully, it will be fixed soon.
Your Hijack This log looks to be clean and since there are no problems, I suggest the following.
One of the best features of Windows XP is the System Restore option, however if Malware infects a computer with this operating system the Malware can be backed up in the System Restore folder. Therefore, clearing the restore points is necessary after a virus removal.
To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.
(winXP)
1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
2. Reboot.
3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.
Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications:
Spywareblaster <=SpywareBlaster will prevent spyware from being installed.
Spywareguard<=SpywareGuard offers realtime protection from spyware installation attempts.
Download the new Ad-Aware SE version, and follow the instructions on how to do a full scan: http://forums.spywareinfo.com/index.php?showtopic=11150
-reboot after using Ad-Aware SE. Also while there get the VX2 plugin and follow the instructions to run it also.
How to use Spybot to remove Spyware<=If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
To protect yourself further:
MVPS Hosts file<=The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
Google Toolbar<=Get the free google toolbar to help stop pop up windows.
I also suggest that you delete any files from "temp", "tmp" folders. In Internet Explorer, click on "Tools" => "Internet Options" => "Delete Files" and select the box that says "Delete All Offline Content" and click on "OK" twice. Also, empty the recycle bin by right clicking on it and selecting "Empty Recycle Bin". These steps should be done on a regular basis.
And also see TonyKlein's good advice
http://castlecops.com/postlite7736-.html So how did I get infected in the first place?
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.
Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.