This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Zlob.downloader and others.

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

In brief:

Assorted weirdness going on. IE Browser hijacked to "sysprotect.com", software installing itself (Cowbanga by oin), shortcuts appearing on desktop (green and yellow shields resemblinging Windows Update, but advising that computer is infected, lots of popups trying to have me by anti-spyware software…etc.)

Have done the following:

1. Updated and ran NAV: Detected two viruses "Trojan.Zlob" and "Trojan.Nebuler". Could not repair, access to file denied. File was: C:\Windows\system32\winrvc32.dll
2. Updated and Ran SpyBot. Detected "Zlob.downloader". Attempted repair. Could not repair two files beloning to Zlob: C:\Windows\system32\stdole3.tlb and C:\Windows\system32\\afmclk.exe
3. Updated and Ran Adaware SE. Detected "Trojan.small". Attempted repair. Again could not repair two files named: C:\Windows\system32\dcomcfg.exe and C:\Windows\system32\stdole3.tbl (again).
4. Downloaded, updated and ran EWIDO in safe mode. Detected 28 things. Repaired them all. Saved log (below)
5. Reboot
6. Was able to reset homepage on IE.
7. Re-Ran Spybot and Adaware…still detecting "Zlob" and not able to repair +C:\Windows\system32\stdole3.tbl
8. Ran HJT (Renamed to AnalyzeMe as advised on this forum). Log attached below.

Any help greatly appreciated.

Mr. B.

HJT Log
———-
Logfile of HijackThis v1.99.1
Scan saved at 3:51:58 PM, on 7/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
D:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Common Files\{E8A7665F-0963-1033-0209-040311190001}\Update.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\Navnt\navapw32.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\PROGRA~1\Navnt\alertsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\John\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://antwrp.gsfc.nasa.gov/apod/astropix.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…B_PVER}&ar;=home
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\Navnt\defalert.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [Omnipage] D:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NAV Alert - Symantec Corporation - C:\PROGRA~1\Navnt\alertsvc.exe
O23 - Service: NAV Auto-Protect - Symantec Corporation - C:\PROGRA~1\Navnt\navapsvc.exe
O23 - Service: Norton Program Scheduler - Symantec Corporation - C:\PROGRA~1\Navnt\npssvc.exe



Ewido Log
———–
———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 3:44:36 PM 7/8/2006

+ Scan result:



C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\UYX8ZF9W\YazzleActiveX[1].cab/YazzleActiveX.ocx -> Adware.MediaTickets : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\YazzleActiveX.ocx -> Adware.MediaTickets : Cleaned with backup (quarantined).
C:\WINDOWS\system32\taskmgr.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\UYX8ZF9W\anti4[1].exe -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\cbxyxvt.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
D:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-18038922-6af18ed8.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : Ignored.
C:\WINDOWS\system32\zlara.dll -> Not-A-Virus.Hoax.Win32.Renos.dw : Ignored.
:mozilla.54:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.123:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.125:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.29:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.31:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.19:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.49:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.50:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.51:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.52:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.20:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.16:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.17:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.10:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\f07ajj8p.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.81:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
C:\WINDOWS\system32\winrvc32.dll -> Trojan.Agent.vg : Cleaned with backup (quarantined).
C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\R25A5NYS\!update-4020[1].0000 -> Trojan.PurityAd : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\!update.exe -> Trojan.PurityAd : Cleaned with backup (quarantined).
C:\WINDOWS\system32\1024 -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\1024\ldE030.tmp -> Trojan.Small : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\\kernel32.dll -> Trojan.Small : Cleaned with backup (quarantined).


::Report end
Hello and welcome to the TC Forum.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time..


Download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES.
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on. Please reboot your computer.
  • Please post a new HijackThis logusing the Add Reply Button below.
Please post the contents of C:\vundofix.txt and a new HijackThis log.
Thanks for the lightning fast response! I was expecting to wait at least a couple days! The prompt service is certainly appreciated.

Ran ATF Cleaner

Ran VundoFix.exe…."no infected files found".

VundoFix Log:
—————–
VundoFix V4.2.84

Checking Java version…

Sun Java not detected
Scan started at 9:02:50 PM 7/8/2006

Listing files found while scanning….


No infected files were found.


HJT log
——–
Logfile of HijackThis v1.99.1
Scan saved at 9:00:15 PM, on 7/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\PROGRA~1\Navnt\alertsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
D:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\{E8A7665F-0963-1033-0209-040311190001}\Update.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\Navnt\navapw32.exe
C:\Documents and Settings\John\Desktop\VundoFix.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AnalyzeMe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://antwrp.gsfc.nasa.gov/apod/astropix.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…B_PVER}&ar=home
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\Navnt\defalert.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [Omnipage] D:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NAV Alert - Symantec Corporation - C:\PROGRA~1\Navnt\alertsvc.exe
O23 - Service: NAV Auto-Protect - Symantec Corporation - C:\PROGRA~1\Navnt\navapsvc.exe
O23 - Service: Norton Program Scheduler - Symantec Corporation - C:\PROGRA~1\Navnt\npssvc.exe

The red line above seems to be new. Is this part of the problem?

Assorted weirdness going on. IE Browser hijacked to "sysprotect.com", software installing itself (Cowbanga by oin), shortcuts appearing on desktop (green and yellow shields resemblinging Windows Update, but advising that computer is infected, lots of popups trying to have me by anti-spyware software…etc.)

Are you still getting this?

Assorted weirdness going on. IE Browser hijacked to "sysprotect.com", software installing itself (Cowbanga by oin), shortcuts appearing on desktop (green and yellow shields resemblinging Windows Update, but advising that computer is infected, lots of popups trying to have me by anti-spyware software…etc.)

Are you still getting this?



No. Just the two files that spybot and adaware can't fix, the red item in HJT above, and this service that is "new". Anything I need to worry about?

C:\Program Files\Common Files\{E8A7665F-0963-1033-0209-040311190001}\Update.exe

Not sure about this one. After reboot see if it's still there.

It's OK.
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

File Description
Winlogon Notify WgaLogon WgaLogon.dll Windows Genuine Advantage



Close all windows and browsers.
Open HijackThis

Click on Open Misc Tools
Click on Delete a File On Reboot
Click once on the file below to select it:
C:\Windows\system32\dcomcfg.exe

Do the same for this one C:\Windows\system32\stdole3.tbl



Click on the Back button to exit Process Manager



Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

C:\Program Files\Common Files\{E8A7665F-0963-1033-0209-040311190001}\Update.exe

Not sure about this one. After reboot see if it's still there.

It is…see below.

Close all windows and browsers.
Open HijackThis

Click on Open Misc Tools
Click on Delete a File On Reboot
Click once on the file below to select it:
C:\Windows\system32\dcomcfg.exe

Do the same for this one C:\Windows\system32\stdole3.tbl

Click on the Back button to exit Process Manager

Reboot and "copy/paste" a new HijackThis log file into this thread.

See below.

Also please describe how your computer behaves at the moment.


Computer is working perfectly…except for those two files….and the service entry above. Just don't wan't to have to go through this all again if I missed anything.

Updated HJT log
——————-

Logfile of HijackThis v1.99.1
Scan saved at 9:00:15 PM, on 7/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\PROGRA~1\Navnt\alertsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
D:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\{E8A7665F-0963-1033-0209-040311190001}\Update.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\Navnt\navapw32.exe
C:\Documents and Settings\John\Desktop\VundoFix.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AnalyzeMe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://antwrp.gsfc.nasa.gov/apod/astropix.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…B_PVER}&ar=home
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\Navnt\defalert.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [Omnipage] D:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NAV Alert - Symantec Corporation - C:\PROGRA~1\Navnt\alertsvc.exe
O23 - Service: NAV Auto-Protect - Symantec Corporation - C:\PROGRA~1\Navnt\navapsvc.exe
O23 - Service: Norton Program Scheduler - Symantec Corporation - C:\PROGRA~1\Navnt\npssvc.exe

Computer is working perfectly…except for those two files

Are they still there?

C:\Program Files\Common Files\{E8A7665F-0963-1033-0209-040311190001} <–Delete

Computer is working perfectly…except for those two files

Are they still there?

Yes they are…cannot delete.

C:\Program Files\Common Files\{E8A7665F-0963-1033-0209-040311190001} <–Delete


Likewise…cannot delete…access is denied. (folder contains two items…update.exe and services.dll)
Restart your computer in Safe Mode.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.
This can take several miniutes to load.

Now see if you can delete them.

Restart your computer in Safe Mode.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.
This can take several miniutes to load.

Now see if you can delete them.


YES! Thanks. Everything seems 100%….I'll wait a few days and see if anything strange "pops up"…otherwise I think we're done here.

You guys ROCK!

Mr. B
Good Job :thumbup:

Log looks good :D


You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.





If you dont have these programs I would recommend that you get them. Spywareblaster, Spywareguard. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI