This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Several viruses, hj and ewido log here

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, this is my friends comp and he gave me it to try to get rid of viruses. I have tried with adaware, s&d, troyanhunter, and now ewido just founded 7 more viruses. please help me to clean his comp. i have my own hj log somewhere on this forum that noone answered for more than 5 days, but that's ok, i think my comp is fine.

ewido anti-spyware - Scan Report
———————————————————

+ Created at: 1:29:00 AM 9/22/2006

+ Scan result:



C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP91\A0028028.dll -> Backdoor.Padodor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP90\A0027434.exe -> Backdoor.Padodor.ax : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP90\A0027460.exe -> Backdoor.Padodor.ax : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP91\A0027572.exe -> Backdoor.Padodor.ax : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\on.exe -> Downloader.Femad : Cleaned with backup (quarantined).
C:\Documents and Settings\Dell.DBCH2P0J\Local Settings\Temp\ccee.exe -> Downloader.Small.crc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP90\A0027442.exe -> Downloader.Small.crc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP91\A0027768.exe -> Downloader.Small.crc : Cleaned with backup (quarantined).
C:\Documents and Settings\Dell.DBCH2P0J\Local Settings\Temp\docg.exe -> Downloader.Small.dkt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP91\A0028265.exe -> Downloader.Tibs.ic : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP91\A0028029.dll -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP91\A0028696.dll -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP91\A0031067.dll -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP91\A0028033.dll -> Proxy.Xmiler.a : Cleaned with backup (quarantined).
:mozilla.72:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.73:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.74:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Documents and Settings\Dell.DBCH2P0J\Cookies\dell@com[1].txt -> TrackingCookie.Com : Cleaned.
:mozilla.82:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.49:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned.
:mozilla.12:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.13:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.14:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.15:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.16:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.17:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.18:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.19:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.20:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.21:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.22:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.23:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.24:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.25:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.26:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.27:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.28:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.29:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.30:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.31:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.32:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.33:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.34:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.35:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.36:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.37:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.38:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.39:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.40:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.41:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.42:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.43:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.44:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.45:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.46:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.47:C:\Documents and Settings\Dell.DBCH2P0J\Application Data\Mozilla\Firefox\Profiles\tkv1iffb.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
C:\Documents and Settings\Dell.DBCH2P0J\Local Settings\Temp\apihelp.chm -> Trojan.Dialer.lm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP91\A0028264.exe -> Trojan.Dialer.lm : Cleaned with backup (quarantined).


::Report end

Logfile of HijackThis v1.99.1
Scan saved at 1:34:48 AM, on 9/22/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Dell\AccessDirect\DadTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\WINDOWS\Downloaded Program Files\ycomp5_3_12_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\WINDOWS\Downloaded Program Files\ycomp5_3_12_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ww\msntabres.dll.mui/229?5e7dc9261b914a1283ae7d9878d246f5
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ww\msntabres.dll.mui/230?5e7dc9261b914a1283ae7d9878d246f5
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {33331111-1111-1111-1111-611111193423} -
O16 - DPF: {33331111-1111-1111-1111-611111193429} -
O16 - DPF: {33331111-1111-1111-1111-615111193427} -
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Companion) - http://us.dl1.yimg.com/download.companion….bio5_3_12_0.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\System32\vbsys2.dll (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

tnx in advance
Welcome to the forum, those "Viruses" ewido found are in System Restore and can not get on the computer unless you do a Restore (do not) We will clean that area before we finish.

1) First I see this: Kaspersky Anti-Virus Personal and this: Norton AntiVirus, see this information
http://service1.symantec.com/SUPPORT/nav.n…000031316555206
"Microsoft recommends that you have only one anti-virus program installed on your computer."
http://www.washingtonpost.com/wp-dyn/conte…5120300087.html
You are running two antivirus programs at the same time and this is not a good thing. They conflict with each other and you will be less safe than if you ran one good program and maintained it properly. Uninstall one, update the one you keep and run a complete system scan, post for me any item that can't be removed, the complete name and pathway.

2) How to make files and folders visible:
Click Start > Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Click OK.

3) Please download ATF Cleaner by Atribune
http://www.atribune.org/content/view/25/2/
Save it to your Desktop. We will use this later.

4) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

O16 - DPF: {33331111-1111-1111-1111-611111193423} -
-LipGame.a Trojan
O16 - DPF: {33331111-1111-1111-1111-611111193429} -
-LipGame.a Trojan
O16 - DPF: {33331111-1111-1111-1111-615111193427} -
-LipGame.a Trojan
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\System32\vbsys2.dll (file missing)
Troj/AdClick-AC

Close all programs but HJT and all browser windows, then click on "Fix Checked"

5) RIGHT Click on Start then click on Explore. Locate and delete these items:

C:\WINDOWS\System32\vbsys2.dll <<< delete that file if there

6) Run ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Click Select All found at the bottom of the list.
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

7) MANUAL INSTRUCTIONS FOR SYSTEM RESTORE
Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Reboot.

Turn ON System Restore,
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

8) Update the ewido program, then run a complete system scan in Safe Mode using these instructions, delete everything it lkocats unless you know it is not bad.
http://www.bleepingcomputer.com/tutorials/tutorial61.html

[*]Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.

[*]Once in the Settings screen click on "Recommended actions" and then select "Quarantine".

[*]Under "Reports"
  • Select "Automatically generate report after every scan"
  • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode and post the results of the ewido report scan.
Make sure you have done a restart, then post the ewido scan results, a new HJT log and any comments you think will help. How is the computer running now?

Thanks

If your topic has been five (5) days without an answer, you should post a link here:
http://forums.tomcoyote.org/index.php?showtopic=65180
Thank You vey much for responding.
I've uninstalled now both kaspersky and norton since they had no valid licence for updating anyway. I've installed Avast now and scanned with it, no problems found. There is still symantec live update running, becouse when i tried to remove it, it said that there is something else from symantec on comp installed and i shouldn't remove live update before removing that first ( in symantec folder in program files is only live update folder though )

My new logs after i did everything else you told me to do:


———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 1:27:32 AM 9/25/2006

+ Scan result:



C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP89\A0027280.exe -> Downloader.Small.ddx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP91\A0028169.dll -> Downloader.Small.ddx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP91\A0027803.exe -> Proxy.Lager.di : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP91\A0028266.exe -> Proxy.Lager.di : Cleaned with backup (quarantined).


::Report end


Scan saved at 2:56:53 AM, on 9/25/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Dell\AccessDirect\DadTray.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.teamnet.ws:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = www.teamnet.ws
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\WINDOWS\Downloaded Program Files\ycomp5_3_12_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\WINDOWS\Downloaded Program Files\ycomp5_3_12_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ww\msntabres.dll.mui/229?5e7dc9261b914a1283ae7d9878d246f5
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ww\msntabres.dll.mui/230?5e7dc9261b914a1283ae7d9878d246f5
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Companion) - http://us.dl1.yimg.com/download.companion….bio5_3_12_0.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe



I forgot to mention that i get popup messages through messenger like:

"message from system to alert

stop! WINDOWS REQUIRES IMMEDIATE ATTENTION.
windows has found CRITYCAL SYSTEM ERRORS.

run registry repair from: http://fixwin32.com"

Or similar ones with address reguprade.com

I tried to stop messenger in administrative tools, but when i reboot it become active again




tnx again
Thanks for returning your information, careful to post complete logs by click Edit > Select all. The first line of the header is missing.

ewido looks good, we will clean System Restore (C:\System Volume Information\_restore) before we finish.

Messenger Service popups, reand and follow these directions:
http://www.microsoft.com/windowsxp/using/s…e/stopspam.mspx

C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

To get the Symantec stuff off the computer, do this:

Disable the Service
Click Start > Run and type services.msc
Scroll down to SymWMI Service and right click on it.
Click Properties and under Service Status click Stop, then under Startup Type change it to Disabled.

You may need hidden files and folders visable as in #2 above, navigate to:
C:\Program Files\Common Files\Symantec Shared\ <<< delete the folder in red. If Windows gives message about it being runinng, then boot to safe mode and delete it there:
http://www.bleepingcomputer.com/tutorials/tutorial61.html

I see no malware, I will post the closing instructions. Just let me know that everything went ok with that Symantec removal and the Messenger Service junk.

Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.spybot.info/showthread.php?t=279
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml

ewido is a great program but it does use some resources. Once the trial is over you can update and use the scanner for as long as you wish, but unless you purchase it you should turn it off completely so it does not run unless you start it manually.

System Restore does not know the good files from the bad. In case bad stuff has gotten into your System Restore files, follow the instructions in this link to get clean System Restore files. Turn it off, reboot then turn it back on:
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

Thanks
I'm sorry for that missing line. I did evrything you said, cleaned restore, disabled messenger and deleted symantec folder. It still warning me when i try to uninstall symantec live update in add/remove programs, that there something running and depending on it. I know that's probably nothing and that i should unistall it anyway, but this is not my comp and i dont want to mess up something. There's only one line in hj this new log related to symantec : O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe tnx again for all your help
Nope, just have the owner review the information I posted from the experts for their benefit. If they do not own ewido, turn it off so it is not running. It is a good scanner and they lose only the realtime protection that they would have to pay for. Follow the instructions to get clean Sytem Restore files and you should be good. :wavey: Thanks
Ok, tyvm for your time. I have installed him firefox, and all those protections you guys recomended (ewido, s&d, spywareblaster, adaware, troyan hunter,avast) so i hope he won't get in trouble again ;) . I'll tell him to install zone alarm too tnx again :wavey:
Trojan hunter I am sure you pay for. I would use the free online version if it is needed. Make sure you run ONE antivirus program and ONE firewall (if you install a third party firewall like free Zone Alarm, the Windows XP firewall in the Security Center needs to be disabled). My advice is to set Windows updates to automatic also.

Thanks
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI