This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Need help, somethings wrong

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I have some strange things starting when windows, starts, pls help me, here's a hijackthis log:


Logfile of HijackThis v1.99.1
Scan saved at 19:56:19, on 2006-08-11
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Wintab32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program\Delade filer\Symantec Shared\ccProxy.exe
C:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
C:\Program\Norton Internet Security\ISSVC.exe
c:\windows\system32\drivers\etc\rmtx\SVCHOST.EXE
C:\Program\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\java\classes\driver\install\services.exe
C:\Program\NORTON~2\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program\Delade filer\Symantec Shared\SNDSrvc.exe
C:\Program\Delade filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Logi_MwX.Exe
C:\Program\Delade filer\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\qttask.exe
C:\WINDOWS\Acecad\Wtxpload.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\Acecad\xpoint32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program\MSI\Live Update 3\LMonitor.exe
C:\Program\VIA\RAID\raid_tool.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program\Xfire\Xfire.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\CCP\EVE\bin\ExeFile.exe
C:\Documents and Settings\Patte\Skrivbord\HijackThis.exe
C:\Program\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
R3 - URLSearchHook: (no name) - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: (no name) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program\Delade filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\Program\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [anvshell] anvshell.exe
O4 - HKLM\..\Run: [Acecad.Wtxpload] C:\WINDOWS\Acecad\Wtxpload.exe Acecad
O4 - HKLM\..\Run: [PtiuPbmd] Rundll32.exe ptipbm.dll,SetWriteBack
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [LiveMonitor] C:\Program\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [RaidTool] C:\Program\VIA\RAID\raid_tool.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Xfire.lnk = C:\Program\Xfire\Xfire.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1121269293734
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1123436890906
O18 - Protocol: Festoon - (no CLSID) - (no file)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\Program\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: vskype - (no CLSID) - (no file)
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Adobe LM Service - Unknown owner - C:\Program\Delade filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
O23 - Service: GEMSJAF - Unknown owner - C:\DOCUME~1\Patte\LOKALA~1\Temp\GEMSJAF.exe (file missing)
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program\Norton Internet Security\ISSVC.exe
O23 - Service: FireDaemon Service: leeche (leeche) - Unknown owner - c:\windows\system32\drivers\etc\rmtx\FireDaemon.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Ms-java - Unknown owner - C:\WINDOWS\java\classes\driver\install\ms-java.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program\NORTON~2\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\Program\DELADE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Wintab32 - Unknown owner - C:\WINDOWS\system32\Wintab32.exe


Tell me what to do, what to keep and so on….

Regards
Patte
hi patteSatan,

dont see much in the log.
i would do this:


* Install Ewido Anti-Malware, 30 day trial version.

http://download.ewido.net/ewido-setup.exe

* Double-click the icon on Desktop to launch Ewido

You will need to update Ewido to the latest definition files.

* On the top of the main screen click Shield
* Click the word active to change it to inactive
* On the top of the main screen click Update.
* Then click on Start Update. The update will start and a progress bar will show the updates being installed.

If you are having problems with the updater, you can use this link to manually update Ewido. When you have finished updating, EXIT Ewido.


* run Ewido.
* Click Scanner
* Click on the Scan tab
* Click Complete System Scan to begin scanning.
* When the scan is complete click Recommended Action and change it to Quarantine
* Then click Apply all actions

Once finished, click the Save report button, then click Save Report As. This will create a text file.

Make sure you know where to find this file again (like on the Desktop).
post the saved ewido log in your reply.

shelf life
Logfile of HijackThis v1.99.1
Scan saved at 06:07:22, on 2006-08-12
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Wintab32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program\Delade filer\Symantec Shared\ccProxy.exe
C:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
C:\Program\Norton Internet Security\ISSVC.exe
C:\WINDOWS\java\classes\driver\install\ms-java.exe
c:\windows\system32\drivers\etc\rmtx\SVCHOST.EXE
C:\Program\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\java\classes\driver\install\services.exe
C:\WINDOWS\system32\cmd.exe
C:\Program\NORTON~2\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program\Delade filer\Symantec Shared\SNDSrvc.exe
C:\Program\Delade filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Logi_MwX.Exe
C:\Program\Delade filer\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\qttask.exe
C:\WINDOWS\Acecad\Wtxpload.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\Acecad\xpoint32.exe
C:\Program\MSI\Live Update 3\LMonitor.exe
C:\Program\VIA\RAID\raid_tool.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Xfire\Xfire.exe
C:\Program\Messenger\msmsgs.exe
C:\Documents and Settings\Patte\Skrivbord\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
R3 - URLSearchHook: (no name) - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: (no name) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program\Delade filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\Program\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [anvshell] anvshell.exe
O4 - HKLM\..\Run: [Acecad.Wtxpload] C:\WINDOWS\Acecad\Wtxpload.exe Acecad
O4 - HKLM\..\Run: [PtiuPbmd] Rundll32.exe ptipbm.dll,SetWriteBack
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [LiveMonitor] C:\Program\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [RaidTool] C:\Program\VIA\RAID\raid_tool.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Xfire.lnk = C:\Program\Xfire\Xfire.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1121269293734
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1123436890906
O18 - Protocol: Festoon - (no CLSID) - (no file)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\Program\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: vskype - (no CLSID) - (no file)
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Adobe LM Service - Unknown owner - C:\Program\Delade filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
O23 - Service: GEMSJAF - Unknown owner - C:\DOCUME~1\Patte\LOKALA~1\Temp\GEMSJAF.exe (file missing)
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program\Norton Internet Security\ISSVC.exe
O23 - Service: FireDaemon Service: leeche (leeche) - Unknown owner - c:\windows\system32\drivers\etc\rmtx\FireDaemon.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Ms-java - Unknown owner - C:\WINDOWS\java\classes\driver\install\ms-java.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program\NORTON~2\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\Program\DELADE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Wintab32 - Unknown owner - C:\WINDOWS\system32\Wintab32.exe




The log directly after starting, I forgot I had turned off 2 things with taskmanager in the last, sorry.

hi patteSatan,

dont see much in the log.
i would do this:


* Install Ewido Anti-Malware, 30 day trial version.

http://download.ewido.net/ewido-setup.exe

* Double-click the icon on Desktop to launch Ewido

You will need to update Ewido to the latest definition files.

* On the top of the main screen click Shield
* Click the word active to change it to inactive
* On the top of the main screen click Update.
* Then click on Start Update. The update will start and a progress bar will show the updates being installed.

If you are having problems with the updater, you can use this link to manually update Ewido. When you have finished updating, EXIT Ewido.


* run Ewido.
* Click Scanner
* Click on the Scan tab
* Click Complete System Scan to begin scanning.
* When the scan is complete click Recommended Action and change it to Quarantine
* Then click Apply all actions

Once finished, click the Save report button, then click Save Report As. This will create a text file.

Make sure you know where to find this file again (like on the Desktop).
post the saved ewido log in your reply.

shelf life



I forgot to save the log, but the things ewido quarantined was:
Trojan.KillAV.av (windows.bat)
Backdoor.Hupigon.hk (sp33d.exe)
Backdoor.Iroffer.1221 (iroffer.exe)
Backsdoor.Iroffer.1221 (WINDOWS.RAR)
Backdoor.Iroffer.13b11 (C:\WINDOWS\java\classes\driver\install\services.exe)

And a regkey wich I cant copy now that its quarantined…..
hi patteSatan, thanks for the info: hjt log looks ok. ewido got some nasty stuff.. hows it on that end? scan with HJT, put a checkmark beside the items below, close all windows and click fix checked. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - URLSearchHook: (no name) - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file) O3 - Toolbar: (no name) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - (no file) O18 - Protocol: Festoon - (no CLSID) - (no file) O18 - Protocol: vskype - (no CLSID) - (no file). do this also: check for updates to ewido then close it. we will use it in SAFE MODE. to reach safe mode tap the f8 key during a computer restart. chso the first option from the list safe mode. run ewido in safe mode. then reboot normally. shelf life
This is the log from ewido in safe mode:
———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 01:57:16 2006-08-14

+ Scan result:



C:\WINDOWS\system32\drivers\etc\rmtx\firedaemon.exe -> Not-A-Virus.RemoteAdmin.Win32.RA.3826 : No action taken.
:mozilla.158:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.124:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.125:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.118:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.119:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.121:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.122:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.123:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.100:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Clickbank : No action taken.
:mozilla.126:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.59:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.60:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.101:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.140:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.25:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.26:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.28:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.29:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.150:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.I12 : No action taken.
:mozilla.44:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Masterstats : No action taken.
:mozilla.151:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.145:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.146:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.147:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.148:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.169:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Sexlist : No action taken.
:mozilla.49:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Sextracker : No action taken.
:mozilla.50:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Sextracker : No action taken.
:mozilla.42:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.43:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.132:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Tracking101 : No action taken.
:mozilla.133:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Tracking101 : No action taken.
:mozilla.111:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.112:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.113:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.87:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Trafic : No action taken.
:mozilla.71:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.72:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.21:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Yadro : No action taken.
:mozilla.22:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Yadro : No action taken.
:mozilla.86:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.88:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.90:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.91:C:\Documents and Settings\Patte\Application Data\Mozilla\Firefox\Profiles\cpnz50jt.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.


::Report end



Only cookies

This is a new Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 02:04:35, on 2006-08-14
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Wintab32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Logi_MwX.Exe
C:\Program\Delade filer\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\qttask.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program\MSI\Live Update 3\LMonitor.exe
C:\Program\VIA\RAID\raid_tool.exe
C:\Program\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program\Xfire\Xfire.exe
C:\Program\Delade filer\Symantec Shared\ccProxy.exe
C:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
C:\Program\ewido anti-spyware 4.0\guard.exe
C:\Program\Norton Internet Security\ISSVC.exe
c:\windows\system32\drivers\etc\rmtx\SVCHOST.EXE
C:\WINDOWS\java\classes\driver\install\ms-java.exe
C:\Program\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program\NORTON~2\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program\Delade filer\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\cmd.exe
C:\Program\Delade filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRAM\MOZILL~1\FIREFOX.EXE
C:\Program\Messenger\msmsgs.exe
C:\Documents and Settings\Patte\Skrivbord\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program\Delade filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\Program\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [anvshell] anvshell.exe
O4 - HKLM\..\Run: [Acecad.Wtxpload] C:\WINDOWS\Acecad\Wtxpload.exe Acecad
O4 - HKLM\..\Run: [PtiuPbmd] Rundll32.exe ptipbm.dll,SetWriteBack
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [LiveMonitor] C:\Program\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [RaidTool] C:\Program\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Xfire.lnk = C:\Program\Xfire\Xfire.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1121269293734
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1123436890906
O18 - Protocol: Festoon - (no CLSID) - (no file)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\Program\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: vskype - (no CLSID) - (no file)
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Adobe LM Service - Unknown owner - C:\Program\Delade filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program\ewido anti-spyware 4.0\guard.exe
O23 - Service: GEMSJAF - Unknown owner - C:\DOCUME~1\Patte\LOKALA~1\Temp\GEMSJAF.exe (file missing)
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program\Norton Internet Security\ISSVC.exe
O23 - Service: FireDaemon Service: leeche (leeche) - Unknown owner - c:\windows\system32\drivers\etc\rmtx\FireDaemon.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Ms-java - Unknown owner - C:\WINDOWS\java\classes\driver\install\ms-java.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program\NORTON~2\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\Program\DELADE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Wintab32 - Unknown owner - C:\WINDOWS\system32\Wintab32.exe



And, I took away those entries you told me to, but they are back……

And I STILL have a service named "ms-java" that I must shut down to shut down the dayam irritating "diskinfo"-thing
hi patteSatan, lets take care of these first: go to start>run and type in–> services.msc,<–in the list of services that comes up look for>>FireDaemon Service: leeche right click on it and select properties. under the general tab: make sure that the service status is: Stopped and the Startup type is: disabled look for and do the same with>>Ms-java and this one also>>GEMSJAF ———————————————————– see if you can manually find and delete those files after stopping them delete only the FireDaemon.EXE located >>>c:\windows\system32\drivers\etc\rmtx\FireDaemon.EXE delete only the ms-java.exe> located here>>C:\WINDOWS\java\classes\driver\install\ms-java.exe see if you can find this one also: GEMSJAF.exe located C:\DOCUME~1\Patte\LOKALA~1\Temp\GEMSJAF.exe shelf life
hi patteSatan,

good.

How to uninstall the "rouge" services?


as long as they are not running they are harmless, did you manually look for and delete them. these i mean:

delete only the FireDaemon.EXE located >>>c:\windows\system32\drivers\etc\rmtx\FireDaemon.EXE

delete only the ms-java.exe> located here>>C:\WINDOWS\java\classes\driver\install\ms-java.exe

see if you can find this one also:
GEMSJAF.exe located C:\DOCUME~1\Patte\LOKALA~1\Temp\GEMSJAF.exe

shelf life
hi patteSatan,

good, glad to help. happy safe surfing. for your reference:

Be careful of what you download, and where you download it from. Many programs come bundled with extra software.You may be installing more than you think. Learn more about the program, Does it come bundled with other "3rd party" programs? If you search hard enough you can always find a "clean" alternative to any software. Stay away from warez and crack sites. Becarful what you download from file sharing networks. If you are not sure, scan it with your Antivirus app. A small file (in KB) is probably not what you think it is. DO YOU TRUST THE SOURCE? Check this database:Spyware Guide or this: Library before installing free/shareware.

Make sure you keep your Windows OS current by visiting Windows update
occasionaly to download and install any critical updates and service packs. These patch flaws/bugs that can be exploited.

Adjust your browser settings: Change your(active x) settings in IE. With IE open go to tools, internet options, security tab. Click on the internet globe, then custom level. Set the first option "download signed active x controls" to prompt, the next two to disable. Read more:
Working with Internet Explorer 6 Security
Many exploits are directed at Internet Explorer, you dont have to use it. Try a different browser. You can have and use more than one browser on your computer.
Like Firefox,


Install a Firewall:A firewall will help to control what comes in from the internet and what leaves your computer to the internet. Zone Alarm is a free and easy to use firewall, that will provide in and outbound protection. XP firewall dosnt block outbound traffic. Its important to know/learn what routinely needs a internet connection.
Zone Alarm
OutPost Lite
Jetico Personal Firewall
Look n Stop

Outlook Express with the default settings is not secure. It will run scripts, download images etc, just like a browser, but this was the old Outlook Express. Service Pack 2 has made huge improvements to Outlook, but just like with Internet Explorer, you dont have to use it.
try Pegasus E-Mail.

Make sure you have and keep updated Antivirus software
Free for home users:
avast! 4 Home Edition Download
AVG free version 7.0
AntiVir Personal Edition
Clam Win

Download one or two of these, install and update before using:(if these are constantly finding malware, then you need to make changes to your browser and or your habits)
CounterSpy Free trial version
Spybot Search and destroy
Ad-Aware SE Personal edition
Microsoft Windows Defender
Becarful with spyware "removers and scanners"– there are many "rogue/suspect" programs that "claim to remove" spyware.Check here first.


AntiTrojan software to fill in the gap:
a2 free
Ewido Anti-Spyware
Trojan Hunter
Tauscan trial version

Other programs to consider:
Process Guard stop events/processes with user intervention
SpywareBlaster add security to IE
IE-SPYAD adds adware peddlers sites/domains to IE restricted zone
ATF cleaner (W2K,XP only) cleans out temp files,history, cookies etc.

Learn More:
Test Your Browser
Parasite Free
Safe Hex
Shelf Lifes page
Browser Security Checkup
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI