This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can't remove xkeyshll

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been trying to find someone who can help me remove this junk off my PC. There are at least two issues I know of, one is the xkeyshll that shows up in HJT but not anywhere else. The second is these three executable files that show in C:/, lableled: 23100247.exe, 17212037107.exe, and 36110103225.exe.

I scanned them with NAV and Ewido but neither said they were infected. In C:/ they show as being 25KB, 11KB and 3KB respectively in size.

I also tried to use the "Fix Checked" key in HJT to remove the xkeyshll.dll but to no avail.

I need help figuring out what else needs to go in order to get rid of xkeyshll, (and how to remove them) and any advice on the best way to get rid of the three mystery files in C:/

Below is a copy of the last HJT logfile for consideration. Thank you in advance for any help.

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\wwSecure.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/Administrator/Desktop/somepage
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [\\MYPC\EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P33 "\\MYPC\EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesuite…vex-2.0.5.0.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1139736399187
O16 - DPF: {BA5E57BB-88D5-422A-AC9E-C01A6EEE2537} (WebDvr3 Class) - http://192.168.2.3/WebDvr3.cab
O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) - http://apps.corel.com/nos_dl_manager/plugi…NetOpPlugin.ocx
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: xkeyshll - C:\WINDOWS\SYSTEM32\xkeyshll.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\System32\wwSecure.exe
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download the trial version of Ewido anti-spyware from here and save it to your Desktop.
If you already have this program installed, skip to Updating Ewido: below.

* Please note that these instructions are for the new version - Ewido anti-spyware. If you have the old version - Ewido anti-malware and it is the:
  • paid-for version - you will need to go here and obtain an updated license code before you upgrade.
  • free version - you will need to uninstall it and reboot before installing the new version.
Double click the ewido-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, Ewido anti-spyware will open.
  • Updating Ewido:

    By default Ewido is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
  • Click the Update icon at the top and under "Manual Update" - click the Start update button.
  • Either Ewido will update or inform you that no update was available.
  • If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
    Once you have installed Ewido, double click ewido-signatures-full-current.exe to update it.

    Disabling the Resident Shield:
  • By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
    (When the PC has been cleaned you can activate the shield again, if you wish.)
  • Click the Shield icon at the top and under "Resident shield is…" - click active.
  • This should now change to inactive.

    Changing Recommended Actions
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
You can now close Ewido anti-spyware.

Ewido anti-spyware is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that Ewido will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.


2) You will need to know how to boot into Safe Mode.
Instructions can be found here.

3) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

4) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Run HJT and click on Open the Misc Tools section.
Click on delete a file on reboot…
Copy and paste the following into the "File name:" text box and then click Open:

C:\WINDOWS\SYSTEM32\xkeyshll.dll

When you are asked "Do you want to restart your computer now?", click OK.

Your PC MUST reboot fully to delete the file!

2) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

O20 - Winlogon Notify: xkeyshll - C:\WINDOWS\SYSTEM32\xkeyshll.dll

CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

3) Boot into Safe Mode.

4) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.
Do this for all Usernames.

5) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

6) Go to Start > Control Panel > Internet Options and under Temporary Internet files, click on Delete Files…
Check the box to the left of 'Delete all offline content' and then click on OK.

7) Ensure that ALL open Windows / Programs / Folders are closed and then run Ewido anti-spyware.
  • If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
  • Click "Complete System Scan"
  • While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
  • When the scan has completed, any threats that Ewido has detected will be displayed.
  • Click the Apply all actions button at the bottom.
  • When Ewido has finished, it will display the message "All actions have been applied".

    Saving a report:
  • Click the Save Report button at the bottom left and the "Reports" window will open.
  • The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\ewido anti-spyware 4.0\Reports folder.
  • You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
    Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close Ewido Anti-Spyware.

8) Boot into Normal Mode.

Post a new HJT log, the Ewido log AND a description of how your PC is running.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

If the three executable files did not get deleted by Ewido, then I want you to do the following:

Go to Jotti's and click on the Browse… button at the top and navigate to the following files in turn, and then click on Submit:

23100247.exe
17212037107.exe
36110103225.exe


When all the scans have been completed, please copy and paste the results into your next reply.

If this site is busy, try VirusTotal: Click the Browse … button at the top, navigate to the file and double click it and then click the Send button.

You may need to split the information into a couple of replies to ensure that it all gets posted.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I will also need to know if these files are in folders or the root of your C: drive - the filepath will be important in deleting them.
Noviciate:

Did all the steps you indicated…wow!

Ewido did not get the three mystery files so I did scan with BOTH Jotti and VirusTotal and did comparison of each for your review.

Ran Ewido in Safemode and perhaps misinterpreted one of the popups. I'll point that out when I post the report from Ewido scan.

Here is the HJT updated:

Logfile of HijackThis v1.99.1
Scan saved at 5:39:24 PM, on 9/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\wwSecure.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

file:///C:/Documents%20and%20Settings/Administrator/Desktop/somepage
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [\\MYPC\EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P33 "\\MYPC\EPSON

Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) -

http://dlmanager.akamaitools.com.edgesuite…vex-2.0.5.0.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://update.microsoft.com/windowsupdate/…b?1139736399187
O16 - DPF: {BA5E57BB-88D5-422A-AC9E-C01A6EEE2537} (WebDvr3 Class) - http://192.168.2.3/WebDvr3.cab
O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) - http://apps.corel.com/nos_dl_manager/plugi…NetOpPlugin.ocx
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton

AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton

AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\System32\wwSecure.exe

I will add another reply behind this one due to the volume of reports.
———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 4:59:08 PM 9/19/2006

+ Scan result:
C:\Documents and Settings\Administrator\Desktop\internet\folder1\optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder2\old\optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder3\old\optin_pop.zip/optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Error during cleaning.
This is the one I mentioned on the first page. It popped up saying because this file was archived should I quarantine the whole folder. It is an old version
of one of my websites and can be deleted but I'm not exactly sure what "Not-A-Virus.Exploit.IframeJS" is. I'm wondering if its a javascript I use for an
email opt-in popup box? Should I go back and delete this?

C:\Documents and Settings\Administrator\Desktop\internet\folder4\old\rxdrug-md\optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder5\old\www.zip/www/optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Error during cleaning.
C:\Documents and Settings\Administrator\Desktop\internet\folder6\old\www.zip/www/optin_pop.zip/optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Error during cleaning.
C:\Documents and Settings\Administrator\Desktop\internet\folder7\optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder8\www\emailpop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder9\www\popupJS.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder10\www\optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder11\www\optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder12/www/java/emailpop.js -> Not-A-Virus.Exploit.IframeJS : Error during cleaning.
C:\Documents and Settings\Administrator\Desktop\internet\folder13/www/java/optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Error during cleaning.
C:\Documents and Settings\Administrator\Desktop\internet\folder14\www\java\emailpop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder15\www\java\optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder16\www\backup\java\emailpop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder17\www\backup\java\optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder18\www\java\emailpop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder19\www\java\optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder20\www\optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder21\www\common\optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder22\travelb_JS.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folde23\1src_JS.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder24\findonclose1.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder25\temp\optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\ofolder26\1src_JS.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder27\optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder28\optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder29\www\java\emailpop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\internet\folder30\www\java\optin_pop.js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00053844.dll -> Proxy.Xorpix.am : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).


::Report end



http://virusscan.jotti.org/
File: 23100247.exe
Status: INFECTED/MALWARE
MD5 9ba9058052483650498a7408fc566adb
Packers detected: FSG

Scanner results

AntiVir Found Heuristic/Crypted (probable variant)
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found Dropped:Generic.Malware.SFYVdlwdld.97593776
ClamAV Found nothing
Dr.Web Found Trojan.PWS.GoldSpy
F-Prot Antivirus Found W32/Dropper.gen2
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found probably a variant of Win32/Spy.Goldun.HP (probable variant)
Norman Virus Control Found Suspicious_F.gen
UNA Found nothing
VirusBuster Found nothing
VBA32 Found Malware.Agent.41 (probable variant)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

http://www.virustotal.com/vt/en/resultadof…c800e66cdd575c7
File: 23100247.exe

Antivirus Version Update Result
AntiVir 7.2.0.16 09.19.2006 HEUR/Crypted
Authentium 4.93.8 09.19.2006 W32/Dropper.gen2
Avast 4.7.844.0 09.19.2006 no virus found
AVG 386 09.19.2006 no virus found
BitDefender 7.2 09.20.2006 Dropped:Generic.Malware.SFYVdlwdld.97593776
CAT-QuickHeal 8.00 09.18.2006 (Suspicious) - DNAScan
ClamAV devel-20060426 09.20.2006 no virus found
DrWeb 4.33 09.20.2006 Trojan.PWS.GoldSpy
eTrust-InoculateIT 23.72.128 09.19.2006 no virus found
eTrust-Vet 30.3.3086 09.19.2006 Win32/Haxdoor!generic
Ewido 4.0 09.19.2006 no virus found
Fortinet 2.82.0.0 09.20.2006 suspicious
F-Prot 3.16f 09.19.2006 W32/Dropper.gen2
F-Prot4 4.2.1.29 09.19.2006 W32/Dropper.gen2
Ikarus 0.2.65.0 09.19.2006 no virus found
Kaspersky 4.0.2.24 09.20.2006 no virus found
McAfee 4855 09.19.2006 no virus found
Microsoft 1.1560 09.19.2006 no virus found
NOD32v2 1.1763 09.19.2006 probably a variant of Win32/Spy.Goldun.HP
Norman 5.90.23 09.19.2006 Suspicious_F.gen
Panda 9.0.0.4 09.19.2006 Suspicious file
Sophos 4.09.0 09.20.2006 no virus found
Symantec 8.0 09.20.2006 no virus found
TheHacker 6.0.1.073 09.19.2006 no virus found
UNA 1.83 09.19.2006 no virus found
VBA32 3.11.1 09.19.2006 suspected of Malware.Agent.41
VirusBuster 4.3.7:9 09.19.2006 no virus found

Aditional Information
File size: 25340 bytes
MD5: 9ba9058052483650498a7408fc566adb
SHA1: 25200561b37c39bc9dcab7da3845636cad6ab0ba
packers: FSG
packers: FSG
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
http://virusscan.jotti.org/
File: 17212037107.exe
Status: INFECTED/MALWARE
MD5 1e6065b2095b69cbecb875e059bb3a58
Packers detected: UPX


Scanner results
AntiVir Found Trojan/Hijack.Explor.363
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found BehavesLike:Win32.ExplorerHijack (probable variant)
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found Possibly a new variant of W32/Threat-HLLSI-based!Maximus
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found probably unknown NewHeur_PE (probable variant)
Norman Virus Control Found nothing
UNA Found nothing
VirusBuster Found nothing
VBA32 Found nothing


++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
http://www.virustotal.com/vt/en/resultadof…7b9ed9ef96bc6f1
File: 17212037107.exe
Antivirus Version Update Result
AntiVir 7.2.0.16 09.19.2006 TR/Hijack.Explor.363
Authentium 4.93.8 09.19.2006 Possibly a new variant of W32/Threat-HLLSI-based!Maximus
Avast 4.7.844.0 09.19.2006 no virus found
AVG 386 09.19.2006 no virus found
BitDefender 7.2 09.20.2006 BehavesLike:Win32.ExplorerHijack
CAT-QuickHeal 8.00 09.18.2006 no virus found
ClamAV devel-20060426 09.20.2006 no virus found
DrWeb 4.33 09.20.2006 no virus found
eTrust-InoculateIT 23.72.128 09.19.2006 no virus found
eTrust-Vet 30.3.3086 09.19.2006 no virus found
Ewido 4.0 09.19.2006 no virus found
Fortinet 2.82.0.0 09.20.2006 suspicious
F-Prot 3.16f 09.19.2006 Possibly a new variant of W32/Threat-HLLSI-based!Maximus
F-Prot4 4.2.1.29 09.19.2006 W32/Threat-HLLSI-based!Maximus
Ikarus 0.2.65.0 09.19.2006 no virus found
Kaspersky 4.0.2.24 09.20.2006 no virus found
McAfee 4855 09.19.2006 no virus found
Microsoft 1.1560 09.19.2006 no virus found
NOD32v2 1.1763 09.19.2006 probably unknown NewHeur_PE virus
Norman 5.90.23 09.19.2006 no virus found
Panda 9.0.0.4 09.19.2006 Trj/Count.A
Sophos 4.09.0 09.20.2006 no virus found
Symantec 8.0 09.20.2006 no virus found
TheHacker 6.0.1.073 09.19.2006 no virus found
UNA 1.83 09.19.2006 no virus found
VBA32 3.11.1 09.19.2006 no virus found
VirusBuster 4.3.7:9 09.19.2006 no virus found

Aditional Information
File size: 12994 bytes
MD5: 1e6065b2095b69cbecb875e059bb3a58
SHA1: 5f5fc949fc56361cb476f42a724808999573d6f7
packers: UPX
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
http://virusscan.jotti.org/
File: 36110103225.exe

Status: INFECTED/MALWARE
MD5 29307f9030cafaf0f2a8a5868073297b
Packers detected: FSG

Scanner results
AntiVir Found Heuristic/Crypted (probable variant)
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found GenPack:Generic.Malware.dld!!.89A9781D
ClamAV Found nothing
Dr.Web Found Trojan.DownLoader.12800
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found Suspicious_F.gen
UNA Found nothing
VirusBuster Found nothing
VBA32 Found nothing
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
http://www.virustotal.com/vt/en/resultadof…803e3a771580c01
File: 36110103225.exe

Antivirus Version Update Result
AntiVir 7.2.0.16 09.19.2006 HEUR/Crypted
Authentium 4.93.8 09.19.2006 no virus found
Avast 4.7.844.0 09.19.2006 no virus found
AVG 386 09.19.2006 no virus found
BitDefender 7.2 09.20.2006 GenPack:Generic.Malware.dld!!.89A9781D
CAT-QuickHeal 8.00 09.18.2006 (Suspicious) - DNAScan
ClamAV devel-20060426 09.20.2006 no virus found
DrWeb 4.33 09.20.2006 Trojan.DownLoader.12800
eTrust-InoculateIT 23.72.128 09.19.2006 no virus found
eTrust-Vet 30.3.3086 09.19.2006 no virus found
Ewido 4.0 09.19.2006 no virus found
Fortinet 2.82.0.0 09.20.2006 suspicious
F-Prot 3.16f 09.19.2006 no virus found
F-Prot4 4.2.1.29 09.19.2006 no virus found
Ikarus 0.2.65.0 09.19.2006 no virus found
Kaspersky 4.0.2.24 09.20.2006 no virus found
McAfee 4855 09.19.2006 no virus found
Microsoft 1.1560 09.19.2006 no virus found
NOD32v2 1.1763 09.19.2006 no virus found
Norman 5.90.23 09.19.2006 Suspicious_F.gen
Panda 9.0.0.4 09.19.2006 Suspicious file
Sophos 4.09.0 09.20.2006 no virus found
Symantec 8.0 09.20.2006 no virus found
TheHacker 6.0.1.073 09.19.2006 no virus found
UNA 1.83 09.19.2006 no virus found
VBA32 3.11.1 09.19.2006 no virus found
VirusBuster 4.3.7:9 09.19.2006 no virus found

Aditional Information
File size: 2601 bytes
MD5: 29307f9030cafaf0f2a8a5868073297b
SHA1: 23a0fb4a049d51175d7758063c77c032668f30c7
packers: FSG

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

That's everything except about how the computer is running. I can say that there were a few websites that I log into the backend for stats and traffic info that I could not pull up the last few days, but I can now. I don't really want to do a lot yet until you instruct me how to get rid of the three executable files which the paths are: c:\23100247.exe, c:\17212037107.exe and c:\36110103225.exe.

Also, if there is anything I need to do with the Not-A-Virus issue above.

One last, you said to go into C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that I find there for all usernames. I don't want to sound rhetorical but just like to make sure, you wanted me to delete the Files and not Folders, correct?

Thanks so much for the fast, expert help with this.
1) Ewido can give false-positive reports so if you know any file to be legit, just tell Ewido to ignore it. FPs don't happen very often but they do happen.

2) Delete the temp. files NOT the folders.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

For the files, try the following which may or may not work. If it doesn't, I have Plans B and C so don't worry.
  • Create a new folder in the root of your C: drive and call it deletions.
  • Drag and drop the three files into it.
  • Go to Start > Run, enter, or copy and paste, the following in blue into the textbox and click OK: cmd
  • In the command window that should open, copy and paste the following and then hit :

    rd /s /q c:\deletions
That should hopefully remove the folder and the files contained within. If the folder doesn't delete, or if the files can't be dragged into the folder, we'll go with Plan B next.
Let me know how you get on.
Noviciate: I was able to drag and drop files into deletions and that command did remove the folder. Should I run any other application or do anything further? It looks as if there are no more ware's on the computer. I have not cleared out the Norton recycle bin yet from when I deleted the files in the temp folder, should I just empty or shred the contents? Other than that it appears all is well and as it should be. Thank you very much for taking your time to walk thru these steps and respond so quickly. Truly, thank you isn't thanks enough. All the best, Greg
I don't have any experience of the Norton Recycle Bin but I presume that just dumping the contents is sufficient. You can shred the files if you feel that you may be overcome with an overwhelming desire to recover and run them but otherwise it's unnecessary.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I would say that you're done malware-wise. I want you to run your PC as normal for a few days. When you are happy that everything is fine, do the following:

Update your anti-virus program,
Disable System Restore,
Boot into Safe Mode,
Scan your computer for viruses.
When you get the all clear, reboot into Normal Mode.
Re-enable System Restore,
Create a Restore Point.
This will give a clean Restore Point should you need it in the future.
A tutorial for System Restore is available here.

The reason for waiting is that if removing the malware has caused a problem, which it occasionally does, you can put your PC back to how it was before the fix. This will re-install the malware, but an infected PC is better than an expensive paperweight!

Some bedtime reading: This is a very good tutorial about keeping your computer safe and secure on the internet.
I was looking at some of the folders after my last post and came across something that I did not recognize called ~tmp0374.exe. It was in C:\Documents and Settings\Administrator\~tmp0374.exe. I used VirusTotal to scan it and 3 of the tools listed called it either suspicious or Malware. I would like to delete it so I'm going to create a new folder called deletions in the same folder and slide ~tmp into it. I'll then go to Start > Run > CMD and enter in rd /s /q c:\Documents and Settings\Administrator\deletions and press . Is that correct? (As I was writing this I saw you post your note.) Thanks Greg
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI