This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

After removal, spyware keeps coming back

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Believe it or not, I have four (4) anti-spyware programs plus Trojan Hunter, and NOD32, and use all religiously on my PC which OS is Windows XP Home SP2. I have a Linksys WRT54GL router (with SPI protection) and use Zone Alarm (free version) configured for maximum protection.

Two weeks ago, Spysweeper 4.5.9 found "IEHELPER" after a scam; there were five (5) instances under that name, all for the same entry in the registry, which is:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A2B7A0F0-B697-4A71-8D91-43443F57D7BB}

Approximately 4-5 times I used Spysweeper to quarantine this item, and each time it did, and I rebooted and then conducted a scan, Spysweeper found it again. After 4 or 5 scans, and quarantine actions, Spysweeper no longer found IEHELPER.

FWIW, during this time frame, the latest versions of Spyware Doctor, NOD32, TrojanHunter and AdAware SE Professional found nothing when I conducted scans with them, lulling me into complacency.

After Spysweeper stopped finding IEHELPER during its scans, just to be 100% sure, I updated my CounterSpy (Version 1.5.82) definitions (hadn't done a CounterSpy scan for a long time), and ran a scan and lo and behold it found:

adware.iehlpr

and identified it as a BHO.

The results screen shows two slightly different registry entries (Spysweeper showed five identical entries, all for the same registry address) as follows:

Adware.IEhlpr Browser Plug-in
Status: Quarantined

Infected registry entries detected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A2B7A0F0-B697-4A71-8D91-43443F57D7BB}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A2B7A0F0-B697-4A71-8D91-43443F57D7BB} Compatibility Flags 102


When CounterSpy first ID'd adware.iehlpr, and before I elected to quarantine it, I verified it existed, by running regedit. I then rebooted and ran CounterSpy again.

To my dismay, several times, on successive CounterSpy scans, I have encountered and have had to quarantine adware.iehlpr after verifying that it exists in the registry (deja vu all over again, so to speak, i.e., similar to my Spysweeper experience). After each CounterSpy scan, after CounterSpy has quarantined adware.iehlpr, I have verified the aforementioned registry entry is removed, but then when I reboot, the registry entry returns and indeed on the next CounterSpy scan, CounterSpy finds this item again. I have removed adware.iehlpr several times using CounterSpy, but Counterspy cannot permanently remove it. I've even gone so far as to conduct a CounterSpy scan in Safe Mode, hoping the quarantining process in Safe Mode will prevent the item from returning on rebooting; unfortunately that didn't work; it always comes back. Counterspy hasn't ceased alerting on adware.iehlpr, despite numerous attempts to remove it, unlike Spysweeper which no longer finds IEHELPR, after the fifth SpySweeper scan, although it is there when I run the scan (i.e., I see it when I run regedit, just before the Spysweeper scan).

Although Spysweeper alerted on IEHELPR and CounterSpy alerts on adware.iehlpr, I believe they are the same bad actor, becuase the registry entry shown in the results of each program's scan is the same, only the number of instances of the same registry line that each program (Spysweeper and CounterySpy) found during their respective scans, were different.

Throughout the time frame involved, and through the present time, Spyware Doctor and Adaware SE Pro and Trojan Hunter and NOD32, have never alerted on anything whatsoever; go figure.

I was thinking of deleting the apparently guilty registry entry, manually, from the registry (after backuping my registry of course) but then decided seeking the advice of experts on this forum was the way to go.

Any ideas? Should I run HijackThis and reply to this post, attaching the Hijackthis.log? Nella

Edited a few minutes after posting the above, to add:

I forgot to say that I have contacted CounterSpy seeking their advice and help and they promptly replied as follows:

Thank you for contacting Sunbelt Software Technical Support.

I apologize for the inconvenience; unfortunately there is not a 100% solution against spyware/adware. Due to the nature of the spyware/adware that is out there, it is always being update/modified, and there are new variants of it released everyday. At one point an anti-spyware program might be able to completely detect and remove a threat, but in a week that could change. The anti-spyware companies always have to research these new versions and variants, and then update the definitions.

If you have any information about a new threat/variant that CounterSpy is not detecting you can submit it at the following link.

http://research.sunbelt-software.com/software_submission.cfm

Until we get this in our definitions, the best thing that you can do is go to http://tomcoyote.com/hjt/ and run the HijackThis program. This will create logs for you. You can then go to their forum: http://forums.tomcoyote.org/index.php?showforum=27 and post your logs. They can give you step by step removal.

Regards,

Consumer Support
Hello and Welcome to the forum.

"copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
LDTate,

Below please find my HijackThis log.

At this point the registry entry which many internet websites identify as related to malware, i.e.:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A2B7A0F0-B697-4A71-8D91-43443F57D7BB}

still exists in my registry, although CounterSpy and SpySweeper, when I scan with them, respectively, no longer alert on it indicating I have IEHELPER (SpySweeper) or adware.iehlpr (CounterSpy). TIA. Nella

————————–
Logfile of HijackThis v1.99.1
Scan saved at 11:14:06 AM, on 9/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
E:\Norton SystemWorks\Norton GoBack\GBPoll.exe
E:\NOD32 Program\nod32krn.exe
E:\Norton Ghost\Agent\PQV2iSvc.exe
e:\Spyware Doctor 9-11\sdhelp.exe
C:\WINDOWS\System32\slpservice.exe
C:\WINDOWS\system32\slpmonx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\dllhost.exe
E:\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
E:\Scansoft\PaperPort\pptd40nt.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\WINDOWS\System32\msdtc.exe
E:\Norton Ghost\Agent\GhostTray.exe
E:\NOD32 Program\nod32kui.exe
E:\winpatrol\WinPatrol.exe
E:\Acronis\TrueImage 8.0\TrueImageMonitor.exe
E:\Java\jre1.5.0_06\bin\jusched.exe
E:\Zone Labs2\ZoneAlarm\zlclient.exe
E:\Spy Sweeper 4-11-06\SpySweeper.exe
E:\Logitech\MouseWare\system\em_exec.exe
E:\HostsMan\hostssrv.exe
C:\WINDOWS\system32\devldr32.exe
E:\PC Magazine Utilities\WinPointer\WinPointer.exe
E:\Actual Window Manager\ActualWindowManagerCenter.exe
E:\ClipMate7\clipmate.exe
E:\Directory Opus\dopus.exe
E:\Pure Text utility\puretext20_x86\PureText.exe
E:\Strokeit\strokeit.exe
e:\Spy Sweeper 4-11-06\WRSSSDK.exe
E:\DriveSitter\DriveSitter.exe
E:\Backup copies of programs and patches\Knockout\KnockOut-1.3\KnockOut.exe
E:\Macro Express3\MacExp.exe
E:\Norton SystemWorks\Norton GoBack\GBTray.exe
E:\Smart Label\slpwin.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Clipboard.exe
E:\Backup copies of programs and patches\sysinternals\DiskMon\diskmon\Diskmon.exe
E:\File-Ex 3\FileEx.exe
E:\CE Software\QuicKeys\QkEngine.exe
E:\ScreenHunter 4-3\ScreenHunter.exe
E:\Toggle\ToggleMOUSE\ToggleMouse.exe
E:\MailWasher Pro\MailWasher.exe
E:\WebSite-Watcher\wswatch.exe
E:\hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://127.0.0.1:8100
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - E:\Spyware Doctor 9-11\tools\iesdsg.dll
O2 - BHO: Powermarks - {6172E460-FAE3-11D2-B494-004005A47AAA} - E:\POWERM~1.5\iec.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - E:\Spyware Doctor 9-11\tools\iesdpb.dll
O2 - BHO: SpoofStick BHO - {CBA74CDA-DF78-4AD9-954E-3B15D0A993DE} - e:\CoreStreet\SpoofStick for IE\SpoofStickBHO.dll
O2 - BHO: CookieCop3 - {D7EEF1C5-B053-4a70-B378-3462074D3226} - E:\PC Magazine Utilities\CookieCop\CookieHlpr.dll
O2 - BHO: PassCrypt - {EC732582-7C24-4301-87F4-724E0DB3FDD4} - E:\Permutations Software\PassCrypt\PassHlprNT.dll
O3 - Toolbar: SpoofStick - {4D46ED77-1429-4CF6-8F63-C84B5D710BAF} - e:\CoreStreet\SpoofStick for IE\SpoofStick.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: FraudEliminator - {A5181F8A-0B9D-43AC-8BE5-EB61651DB685} - C:\Program Files\FraudEliminator\2.3.1\FETB.dll
O3 - Toolbar: Powermarks - {E166B4A2-83E7-11D3-B4FD-004005A47AAA} - E:\POWERM~1.5\iec.dll
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "E:\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Enterra Icon Keeper] "e:\Icon Keeper\IcnKeepr.exe" ssp /s
O4 - HKLM\..\Run: [PaperPort PTD] E:\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v2] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /source=HKLM
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Norton Ghost 9.0] E:\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [nod32kui] "E:\NOD32 Program\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [WinPatrol] "e:\winpatrol\WinPatrol.exe"
O4 - HKLM\..\Run: [Acronis True Image Monitor] "e:\Acronis\TrueImage 8.0\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] "e:\Zone Labs2\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SpySweeper] "E:\Spy Sweeper 4-11-06\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [THGuard] "E:\TrojanHunter 4.6\THGuard.exe"
O4 - HKLM\..\Run: [HostsServer] E:\HostsMan\hostssrv.exe –start
O4 - HKCU\..\Run: [WinPointer3] "E:\PC Magazine Utilities\WinPointer\WinPointer.exe"
O4 - HKCU\..\Run: [Actual Window Manager] E:\Actual Window Manager\ActualWindowManagerCenter.exe
O4 - HKCU\..\Run: [ClipMate7] E:\ClipMate7\clipmate.exe
O4 - HKCU\..\Run: [DOpus] E:\Directory Opus\dopus.exe
O4 - HKCU\..\Run: [PureText] "E:\Pure Text utility\puretext20_x86\PureText.exe"
O4 - HKCU\..\Run: [StrokeIt] E:\Strokeit\strokeit.exe
O4 - HKCU\..\Run: [updateMgr] "E:\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcStd7_0_8 -reboot 1
O4 - Startup: Clipboard (MS).lnk = C:\Documents and Settings\All Users\Start Menu\Programs\Clipboard.exe
O4 - Startup: Diskmon.lnk = E:\Backup copies of programs and patches\sysinternals\DiskMon\diskmon\Diskmon.exe
O4 - Startup: File-Ex.lnk = E:\File-Ex 3\FileEx.exe
O4 - Startup: Notepad.lnk = C:\WINDOWS\system32\notepad.exe
O4 - Startup: QkEngine.lnk = E:\CE Software\QuicKeys\QkEngine.exe
O4 - Startup: ScreenHunter 4.3 Pro.lnk = E:\ScreenHunter 4-3\ScreenHunter.exe
O4 - Startup: ToggleMOUSE.lnk = E:\Toggle\ToggleMOUSE\ToggleMouse.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: DriveSitter.lnk = E:\DriveSitter\DriveSitter.exe
O4 - Global Startup: KnockOut.lnk = E:\Backup copies of programs and patches\Knockout\KnockOut-1.3\KnockOut.exe
O4 - Global Startup: Macro Express 3.lnk = E:\Macro Express3\MacExp.exe
O4 - Global Startup: Norton GoBack.lnk = E:\Norton SystemWorks\Norton GoBack\GBTray.exe
O4 - Global Startup: Smart Label.lnk = E:\Smart Label\slpwin.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Copy Location - C:\WINDOWS\WEB\graburl.htm
O8 - Extra context menu item: Add to Local Website Archive - e:\Local Website Archive\iearc.htm
O8 - Extra context menu item: Add to WebSite-Watcher - C:\Documents and Settings\Jay\Application Data\aignes\WebSite-Watcher\config\settings\wswie.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Open Link Target in Firefox - file://C:\Documents and Settings\Jay\Application Data\Mozilla\Firefox\Profiles\default.n32\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
O8 - Extra context menu item: View This Page in Firefox - file://C:\Documents and Settings\Jay\Application Data\Mozilla\Firefox\Profiles\default.n32\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html
O9 - Extra button: LWA - Load - {2070D42E-0F9D-473C-9780-0971F611B907} - e:\Local Website Archive\wsarc.exe
O9 - Extra button: LWA - Add - {85956C87-B0CA-418D-BBDC-1046F60AC0E3} - e:\Local Website Archive\wsarc_add.exe
O9 - Extra button: (no name) - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra 'Tools' menuitem: Add to R&estricted Zone - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra button: (no name) - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra 'Tools' menuitem: Add to Tr&usted Zone - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Offline - {FC09D8A3-C85A-11d2-92D0-0000F87A4A55} - C:\WINDOWS\system32\oline.dll
O9 - Extra button: (no name) - {25D5DB7E-D410-4EE1-9CF9-4DE1E19A0775} - e:\Local Website Archive\wsarc_add.exe (HKCU)
O9 - Extra 'Tools' menuitem: Add to Local Website Archive - {25D5DB7E-D410-4EE1-9CF9-4DE1E19A0775} - e:\Local Website Archive\wsarc_add.exe (HKCU)
O9 - Extra button: (no name) - {4FCCA77A-FABF-44aa-9B3A-AF5D075144A7} - (no file) (HKCU)
O15 - Trusted Zone: http://www.acronis.com
O15 - Trusted Zone: http://*.adobe.com
O15 - Trusted Zone: http://www.bandwidthplace.com
O15 - Trusted Zone: http://webmail.bellsouth.net
O15 - Trusted Zone: http://*.brownstone.com
O15 - Trusted Zone: http://*.citynational.com
O15 - Trusted Zone: http://www.clifford.com
O15 - Trusted Zone: *.cliffordgps.com
O15 - Trusted Zone: http://*.clmtoolkit.com
O15 - Trusted Zone: http://mailcenter.comcast.net
O15 - Trusted Zone: http://www.comcast.net
O15 - Trusted Zone: http://*.www.computercops.biz
O15 - Trusted Zone: http://www.consumerreports.org
O15 - Trusted Zone: http://www.dasautoshippers.com
O15 - Trusted Zone: http://www.dynomax.com
O15 - Trusted Zone: http://apps.etrac.net
O15 - Trusted Zone: http://www.extremetech.com
O15 - Trusted Zone: www.fedex.com
O15 - Trusted Zone: http://*.fedex.com
O15 - Trusted Zone: http://*.flabar.org
O15 - Trusted Zone: http://*.IRMI-Online.com
O15 - Trusted Zone: http://www.kirbanperformance.com
O15 - Trusted Zone: http://www.loislaw.com
O15 - Trusted Zone: http://www.macromedia.com
O15 - Trusted Zone: http://www.medpagetoday.com
O15 - Trusted Zone: http://gisims2.co.miami-dade.fl.us
O15 - Trusted Zone: http://www.miami-dadeclerk.com
O15 - Trusted Zone: http://baron.law.miami.edu
O15 - Trusted Zone: http://*.discuss.pcmag.com
O15 - Trusted Zone: http://www.pcmag.com
O15 - Trusted Zone: http://*.pcmag.com
O15 - Trusted Zone: http://*.pinecrest-fl.gov
O15 - Trusted Zone: http://www.safcoproducts.com
O15 - Trusted Zone: www.sitehound.com
O15 - Trusted Zone: http://www.sunbelt-software.com
O15 - Trusted Zone: http://www.sunbiz.org
O15 - Trusted Zone: http://*.service1.symantec.com
O15 - Trusted Zone: http://*.symantec.com
O15 - Trusted Zone: http://www.therealyellowpageslive.net
O15 - Trusted Zone: http://www.uscourts.gov
O15 - Trusted Zone: http://*.usps.com
O15 - Trusted Zone: http://realestate.vendomegrp.com
O15 - Trusted Zone: http://www.vendomegrp.com
O15 - Trusted Zone: http://support.webroot.com
O15 - Trusted Zone: http://www.webroot.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
O16 - DPF: {A1337CC4-FF8E-11D1-9C48-00A0CC20E0D2} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} (CTAdjust Class) -
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AutoWhat Registry Service (AutoWhatService) - Ziff Davis Media, Inc. - e:\PC Magazine Utilities\AutoWhat\Autoserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - E:\Executive Software3\Diskeeper\DkService.exe
O23 - Service: Fix-It Task Manager - V Communications, Inc. - E:\VCOM\Fix-It\mxtask.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - E:\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - E:\INCD\InCD\InCDsrv.exe
O23 - Service: Iomega Activity Disk2 - Iomega Corporation - C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - E:\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - E:\NOD32 Program\nod32krn.exe
O23 - Service: Norton Ghost - Symantec Corporation - E:\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - E:\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Retrospect Helper - EMC Dantz - E:\Retrospect 7.0\rthlpsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - e:\Spyware Doctor 9-11\sdhelp.exe
O23 - Service: SLPMONX - ProdEx Technologies - C:\WINDOWS\System32\slpservice.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - E:\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - e:\Spy Sweeper 4-11-06\WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: SystemSuite Task Manager - Ontrack Data International - E:\Ontrack\SYSTEM~1\MXTask.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


————————–
Not seeing anything bad in your log.


Next, launch Notepad (Start>All Programs>Accessories), and copy/paste all the BOLD REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A2B7A0F0-B697-4A71-8D91-43443F57D7BB}]


On the desktop, doubleclick fix.reg and allow it to run. Let it merge.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
LDTate,

I followed your concise directions to the letter. Now, the subject registry entry no longer appears even after rebooting. Something good happenend. If you could share with me what you think I had, I'd appreciate it.

Below please find a new HijackThis log I just ran, after rebooting and determining the suspect entry no longer is present.

Actually, I have another PC (PC#2) right next to this main one you've been working with me on (PC#1), with the same situation; they are not connected to each other although each obtains its intenet connection from the same router. PC#2's only difference is that its OS is XP Pro SP2, rathern than XP Home SP2. Otherwise, same exact suspect registry entry problem; same exact "alerts" given off by SpywareSweeper and Spyware Doctor, respecitvely (including each program's stopping alerting on this registry entry, after awhile, why each stopped I don't know). Do you think it would be safe to follow the directions in your most recent post, to fix PC#2 just as you've repaired PC#, without my submitting a HijackThis log for PC#2 for review, first?

In any event, thanks LDTate for fixing my problem; I'm keenly interested to know if you think I had a malware or if my two (2) anti-spyware programs described above were giving me false positives.

I made a donation to the forum last night via PayPal and urge everybody to. Nella

Logfile of HijackThis v1.99.1
Scan saved at 7:34:41 AM, on 9/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
E:\Norton SystemWorks\Norton GoBack\GBPoll.exe
E:\NOD32 Program\nod32krn.exe
E:\Norton Ghost\Agent\PQV2iSvc.exe
e:\Spyware Doctor 9-11\sdhelp.exe
C:\WINDOWS\System32\slpservice.exe
C:\WINDOWS\system32\slpmonx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\msdtc.exe
E:\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
E:\Scansoft\PaperPort\pptd40nt.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
E:\Norton Ghost\Agent\GhostTray.exe
E:\NOD32 Program\nod32kui.exe
E:\winpatrol\WinPatrol.exe
E:\Logitech\MouseWare\system\em_exec.exe
E:\Acronis\TrueImage 8.0\TrueImageMonitor.exe
E:\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\devldr32.exe
E:\Zone Labs2\ZoneAlarm\zlclient.exe
E:\Spy Sweeper 4-11-06\SpySweeper.exe
E:\HostsMan\hostssrv.exe
E:\PC Magazine Utilities\WinPointer\WinPointer.exe
E:\Actual Window Manager\ActualWindowManagerCenter.exe
E:\ClipMate7\ClipMate.exe
E:\Directory Opus\dopus.exe
E:\Pure Text utility\puretext20_x86\PureText.exe
E:\Strokeit\strokeit.exe
E:\DriveSitter\DriveSitter.exe
E:\Backup copies of programs and patches\Knockout\KnockOut-1.3\KnockOut.exe
E:\Macro Express3\MacExp.exe
e:\Spy Sweeper 4-11-06\WRSSSDK.exe
E:\Norton SystemWorks\Norton GoBack\GBTray.exe
E:\Smart Label\slpwin.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Clipboard.exe
E:\Backup copies of programs and patches\sysinternals\DiskMon\diskmon\Diskmon.exe
E:\File-Ex 3\FileEx.exe
C:\WINDOWS\system32\notepad.exe
E:\CE Software\QuicKeys\QkEngine.exe
E:\ScreenHunter 4-3\ScreenHunter.exe
E:\Toggle\ToggleMOUSE\ToggleMouse.exe
E:\Executive Software3\Diskeeper\DkService.exe
E:\FIREFOX\FIREFOX.EXE
E:\hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://127.0.0.1:8100
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - E:\Spyware Doctor 9-11\tools\iesdsg.dll
O2 - BHO: Powermarks - {6172E460-FAE3-11D2-B494-004005A47AAA} - E:\POWERM~1.5\iec.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - E:\Spyware Doctor 9-11\tools\iesdpb.dll
O2 - BHO: SpoofStick BHO - {CBA74CDA-DF78-4AD9-954E-3B15D0A993DE} - e:\CoreStreet\SpoofStick for IE\SpoofStickBHO.dll
O2 - BHO: CookieCop3 - {D7EEF1C5-B053-4a70-B378-3462074D3226} - E:\PC Magazine Utilities\CookieCop\CookieHlpr.dll
O2 - BHO: PassCrypt - {EC732582-7C24-4301-87F4-724E0DB3FDD4} - E:\Permutations Software\PassCrypt\PassHlprNT.dll
O3 - Toolbar: SpoofStick - {4D46ED77-1429-4CF6-8F63-C84B5D710BAF} - e:\CoreStreet\SpoofStick for IE\SpoofStick.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: FraudEliminator - {A5181F8A-0B9D-43AC-8BE5-EB61651DB685} - C:\Program Files\FraudEliminator\2.3.1\FETB.dll
O3 - Toolbar: Powermarks - {E166B4A2-83E7-11D3-B4FD-004005A47AAA} - E:\POWERM~1.5\iec.dll
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "E:\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Enterra Icon Keeper] "e:\Icon Keeper\IcnKeepr.exe" ssp /s
O4 - HKLM\..\Run: [PaperPort PTD] E:\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v2] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /source=HKLM
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Norton Ghost 9.0] E:\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [nod32kui] "E:\NOD32 Program\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [WinPatrol] "e:\winpatrol\WinPatrol.exe"
O4 - HKLM\..\Run: [Acronis True Image Monitor] "e:\Acronis\TrueImage 8.0\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] "e:\Zone Labs2\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SpySweeper] "E:\Spy Sweeper 4-11-06\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [THGuard] "E:\TrojanHunter 4.6\THGuard.exe"
O4 - HKLM\..\Run: [HostsServer] E:\HostsMan\hostssrv.exe –start
O4 - HKCU\..\Run: [WinPointer3] "E:\PC Magazine Utilities\WinPointer\WinPointer.exe"
O4 - HKCU\..\Run: [Actual Window Manager] E:\Actual Window Manager\ActualWindowManagerCenter.exe
O4 - HKCU\..\Run: [ClipMate7] E:\ClipMate7\ClipMate.exe
O4 - HKCU\..\Run: [DOpus] E:\Directory Opus\dopus.exe
O4 - HKCU\..\Run: [PureText] "E:\Pure Text utility\puretext20_x86\PureText.exe"
O4 - HKCU\..\Run: [StrokeIt] E:\Strokeit\strokeit.exe
O4 - HKCU\..\Run: [updateMgr] "E:\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcStd7_0_8 -reboot 1
O4 - Startup: Clipboard (MS).lnk = C:\Documents and Settings\All Users\Start Menu\Programs\Clipboard.exe
O4 - Startup: Diskmon.lnk = E:\Backup copies of programs and patches\sysinternals\DiskMon\diskmon\Diskmon.exe
O4 - Startup: File-Ex.lnk = E:\File-Ex 3\FileEx.exe
O4 - Startup: Notepad.lnk = C:\WINDOWS\system32\notepad.exe
O4 - Startup: QkEngine.lnk = E:\CE Software\QuicKeys\QkEngine.exe
O4 - Startup: ScreenHunter 4.3 Pro.lnk = E:\ScreenHunter 4-3\ScreenHunter.exe
O4 - Startup: ToggleMOUSE.lnk = E:\Toggle\ToggleMOUSE\ToggleMouse.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: DriveSitter.lnk = E:\DriveSitter\DriveSitter.exe
O4 - Global Startup: KnockOut.lnk = E:\Backup copies of programs and patches\Knockout\KnockOut-1.3\KnockOut.exe
O4 - Global Startup: Macro Express 3.lnk = E:\Macro Express3\MacExp.exe
O4 - Global Startup: Norton GoBack.lnk = E:\Norton SystemWorks\Norton GoBack\GBTray.exe
O4 - Global Startup: Smart Label.lnk = E:\Smart Label\slpwin.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Copy Location - C:\WINDOWS\WEB\graburl.htm
O8 - Extra context menu item: Add to Local Website Archive - e:\Local Website Archive\iearc.htm
O8 - Extra context menu item: Add to WebSite-Watcher - C:\Documents and Settings\Jay\Application Data\aignes\WebSite-Watcher\config\settings\wswie.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://E:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Open Link Target in Firefox - file://C:\Documents and Settings\Jay\Application Data\Mozilla\Firefox\Profiles\default.n32\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
O8 - Extra context menu item: View This Page in Firefox - file://C:\Documents and Settings\Jay\Application Data\Mozilla\Firefox\Profiles\default.n32\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html
O9 - Extra button: LWA - Load - {2070D42E-0F9D-473C-9780-0971F611B907} - e:\Local Website Archive\wsarc.exe
O9 - Extra button: LWA - Add - {85956C87-B0CA-418D-BBDC-1046F60AC0E3} - e:\Local Website Archive\wsarc_add.exe
O9 - Extra button: (no name) - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra 'Tools' menuitem: Add to R&estricted Zone - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra button: (no name) - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra 'Tools' menuitem: Add to Tr&usted Zone - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Offline - {FC09D8A3-C85A-11d2-92D0-0000F87A4A55} - C:\WINDOWS\system32\oline.dll
O9 - Extra button: (no name) - {25D5DB7E-D410-4EE1-9CF9-4DE1E19A0775} - e:\Local Website Archive\wsarc_add.exe (HKCU)
O9 - Extra 'Tools' menuitem: Add to Local Website Archive - {25D5DB7E-D410-4EE1-9CF9-4DE1E19A0775} - e:\Local Website Archive\wsarc_add.exe (HKCU)
O9 - Extra button: (no name) - {4FCCA77A-FABF-44aa-9B3A-AF5D075144A7} - (no file) (HKCU)
O15 - Trusted Zone: http://www.acronis.com
O15 - Trusted Zone: http://*.adobe.com
O15 - Trusted Zone: http://www.bandwidthplace.com
O15 - Trusted Zone: http://webmail.bellsouth.net
O15 - Trusted Zone: http://*.brownstone.com
O15 - Trusted Zone: http://*.citynational.com
O15 - Trusted Zone: http://www.clifford.com
O15 - Trusted Zone: *.cliffordgps.com
O15 - Trusted Zone: http://*.clmtoolkit.com
O15 - Trusted Zone: http://mailcenter.comcast.net
O15 - Trusted Zone: http://www.comcast.net
O15 - Trusted Zone: http://*.www.computercops.biz
O15 - Trusted Zone: http://www.consumerreports.org
O15 - Trusted Zone: http://www.dasautoshippers.com
O15 - Trusted Zone: http://www.dynomax.com
O15 - Trusted Zone: http://apps.etrac.net
O15 - Trusted Zone: http://www.extremetech.com
O15 - Trusted Zone: www.fedex.com
O15 - Trusted Zone: http://*.fedex.com
O15 - Trusted Zone: http://*.flabar.org
O15 - Trusted Zone: http://*.IRMI-Online.com
O15 - Trusted Zone: http://www.kirbanperformance.com
O15 - Trusted Zone: http://www.loislaw.com
O15 - Trusted Zone: http://www.macromedia.com
O15 - Trusted Zone: http://www.medpagetoday.com
O15 - Trusted Zone: http://gisims2.co.miami-dade.fl.us
O15 - Trusted Zone: http://www.miami-dadeclerk.com
O15 - Trusted Zone: http://baron.law.miami.edu
O15 - Trusted Zone: http://*.discuss.pcmag.com
O15 - Trusted Zone: http://www.pcmag.com
O15 - Trusted Zone: http://*.pcmag.com
O15 - Trusted Zone: http://*.pinecrest-fl.gov
O15 - Trusted Zone: http://www.safcoproducts.com
O15 - Trusted Zone: www.sitehound.com
O15 - Trusted Zone: http://www.sunbelt-software.com
O15 - Trusted Zone: http://www.sunbiz.org
O15 - Trusted Zone: http://*.service1.symantec.com
O15 - Trusted Zone: http://*.symantec.com
O15 - Trusted Zone: http://www.therealyellowpageslive.net
O15 - Trusted Zone: http://www.uscourts.gov
O15 - Trusted Zone: http://*.usps.com
O15 - Trusted Zone: http://realestate.vendomegrp.com
O15 - Trusted Zone: http://www.vendomegrp.com
O15 - Trusted Zone: http://support.webroot.com
O15 - Trusted Zone: http://www.webroot.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
O16 - DPF: {A1337CC4-FF8E-11D1-9C48-00A0CC20E0D2} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} (CTAdjust Class) -
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AutoWhat Registry Service (AutoWhatService) - Ziff Davis Media, Inc. - e:\PC Magazine Utilities\AutoWhat\Autoserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - E:\Executive Software3\Diskeeper\DkService.exe
O23 - Service: Fix-It Task Manager - V Communications, Inc. - E:\VCOM\Fix-It\mxtask.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - E:\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - E:\INCD\InCD\InCDsrv.exe
O23 - Service: Iomega Activity Disk2 - Iomega Corporation - C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - E:\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - E:\NOD32 Program\nod32krn.exe
O23 - Service: Norton Ghost - Symantec Corporation - E:\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - E:\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Retrospect Helper - EMC Dantz - E:\Retrospect 7.0\rthlpsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - e:\Spyware Doctor 9-11\sdhelp.exe
O23 - Service: SLPMONX - ProdEx Technologies - C:\WINDOWS\System32\slpservice.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - E:\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - e:\Spy Sweeper 4-11-06\WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: SystemSuite Task Manager - Ontrack Data International - E:\Ontrack\SYSTEM~1\MXTask.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Field Value
GUID {A2B7A0F0-B697-4A71-8D91-43443F57D7BB}
Filename estAlive.dll
Object Name estAliveObj Class
Status X BHO
Description AskYaya aka Estalive adware


Yes you can use that fix on the other pc if it's the same.
LDTate, Thanks. you got rid of this pest for me when neither anti-spyware program, which for a time detected it, could not. I have to wonder about Spyware Doctor and Ad-Aware SE Pro which NEVER alerted on this item, unlike the other two programs (SpySweeper and CounterSpy, though for some reason they stopped alerting though the malware remained). A follow up question: I had many IE cookies which ATF-cleaner erased. I could manually recreate them, over time. On the other hand, I have backups of all those cookies and could easily copy them back into the respective folders they resided in before the cleaning exercise you outlined for me. I realize it's possible that the malware in question resided in either the Temporary Internet Files folder which contained my IE cookie pointer files, or the Cookies folder which contains the cookies themselves. Do you think it is safe to copy the cookies from my backup, into the existing folders, or is that likely to re-introduce the malware? I realize your thoughs are just a SWAG but would appreciate your best guess. In any event, I could "image" my hard drive and then, if after copying the old cookies back, signs of this malware re-occur, I'll know it resided in either the cookie files (for example, nellaATwilderssecurity{2].txt or index.dat) or in the folder containing the pointers to the cookies file (such as a file named cookie:nellaATwilderssecurity.com), and in that event I could restore the image to my hard drive. Nella
I see no problem putting the cookies back. I don't think they had anything to do with the infection.

As for the programs you're running, none will find everything. That's why we recommend:
Spywareblaster, Spywareguard. They will add 1000's of sites to your resticted zone and block some hijacks from happening. Also a FREE FIREWALL

Along with Ad-Aware and SpyBot.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI