This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Test After A Troublesome Adaware And Zonealarm Install

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Just finished (I hope) installing AdAware 2007 Pro and ZoneAlarm Pro. Had many problems with the AdAware install and a few with ZoneAlarm, so I want to see if I picked up any problems during the installs before I install the AVG AntiMalware.

Here's the HJT Stuff:
——————————————————————
Logfile of HijackThis v1.99.1
Scan saved at 5:25:40 PM, on 7/4/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZONELABS\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINNT\system32\RunDll32.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINNT\StartupMonitor.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Eraser\eraser.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.arkansas.net/webmail/src/login.php
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) - http://tw.msi.com.tw/autobios/client/iftwclix.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1170259838203
O16 - DPF: {E735FF6D-53C6-4C4D-BDC0-26CB90EE6C88} (setup_assistant.SetupAssistant) - https://oracle.anc.net/gck/setup_assistant.CAB
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZONELABS\vsmon.exe
——————————————————————
Thanks, Bob

hi bobberles,

your hjt log looks ok. now that you have ad aware, avg and a firewall learn how to prevent malware in the first place. more security apps dosnt equal more protection.

http://security-central.us/SafeHex/prevention.htm

shelf life


I agree wholeheartedly, shelf life. The trouble is, wherever I go, online or off, there are dozens of "experts", each with a different outlook on which is the best Antiwhatever, and how many different ones should be installed. Then there's the group that says, "NO Antiwhatever can catch them all," so you need a this and a that and a something else, ad infinitum. It would be real nice if y'all could get together and publish a list of "The Invincibles" and THEN … teach us how to set them up!

I've been an EE for many years (long retired now), did some Fortran, some Assembly Language, some hardware design, construction, repair… loved every minute of it. But retired before I got into PC's. And when I DID get into them it was a different world from what I once knew, a world that I didn't really want to get into because now I wanted to spend my time fishing, and working in my woodshop, etc. But my wife wanted it for bookkeeping and I wanted it for CAD and we both wanted it for Genealogy, and that was IT! Now I've been in it for 12 years and am beginning to hate every bit of it. I don't want to spend half of my daily life downloading (ESPECIALLY at 26.4 kbps!) and upgrading and scanning and trying to install poorly written programs that don't want to be installed, and when you ask "Support" for help, and some robot answers four days later with the same boilerplate carp** that you got from the last robot, carp** that wasn't even written for this particular version, it makes me wonder why I still do this. And if and when it IS installed, there's the VERY poorly written and horribly organized "Help" manuals that are more confusing than helpful.

Why don't you write a book that teaches us '… how to prevent malware in the first place.' The 12 year-old kids who write most of that malware will make it obselete before you can get it published.
hi bobberles, i agree. i suppose there is two schools of thought to most things. my reasoning is that software cannot save you from yourself. the proof is right here. pick some random posts, see what and how many security apps people have in there log and the malware they still get. they dont get it. you see post topics like "under attack", "they got me" etc. no, its your own doing, nobody attacked you. there are certain basic things you can do, which i try to show on my prevention page, the simple act of downloading and installing software can get you malware because you didnt read the EULA. Keep your AV updated, use a malware scanner occasionally. these should both be "monitors" to how you are doing also, is my AV flagging stuff all the time? does my occassional malware scan find loads of malware? not counting cookies, if so then you are not doing something right. if not, then you are doing ok. its very possible to not have AV/malware scanners if you avoid certain things and practice safe hex. I wouldnt recommend it for most people. I also think a firewall would be a good idea, not that it would prevent a malware install, but it should alert you to malware trying to connect out from your computer, in which case the malware is already on your computer, sort of like a last wake up call to the user: "ok, whats that? "ive never seen that process before" "maybe i should think about this" Even malware scanners have changed. At one time you actually had to run one to remove malware, now alot of them have "real time protection" that runs in the background, but not even this will save you because the prompts etc require a decision on the users part. The malware scanners are very good, many are free and they are updated alot, i suppose some might just not care how they got it, they just run the scanner to remove it and move on to make more poor decisions and continue getting malware. I dont think most people care to learn anything about how, why or prevention. So some might suggest a "army' of software or they swear by this or that software, you see lists people post in different forums. i think if you do afew things and know what to avoid you will be ok. shelf life
Hello again shelf_life,

I thought we were finished, but Doug and I had another discussion in 'Other Computer Problems' and he suggested that I send you a new HJT. So here it is:

——————–
Logfile of HijackThis v1.99.1
Scan saved at 5:03:06 PM, on 7/12/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\RunDll32.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINNT\StartupMonitor.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\system32\taskmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.arkansas.net/webmail/src/login.php
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) - http://tw.msi.com.tw/autobios/client/iftwclix.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1170259838203
O16 - DPF: {E735FF6D-53C6-4C4D-BDC0-26CB90EE6C88} (setup_assistant.SetupAssistant) - https://oracle.anc.net/gck/setup_assistant.CAB
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{84CD0A23-BEC1-48DE-8976-26C6102AB5C9}: NameServer = 209.244.0.3 209.244.0.4
O20 - Winlogon Notify: avgwlntf - C:\WINNT\SYSTEM32\avgwlntf.dll
O23 - Service: 6F0D0C5E - Unknown owner - C:\WINNT\system32\1639E8CD.EXE (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

——————–
Bob
Hello again Bobberles, lets make sure that service is really gone: go to start>run and type in–> services.msc,<–in the list of services that comes up look for>>6F0D0C5E right click on it and select properties. under the general tab: the path to the .exe should be:C:\WINNT\system32\1639E8CD.EXE make sure that the service status is: Stopped, if not click the Stop button and the Startup type is: disabled, if not change it to disable click apply, then ok ———————– open hjt, click on –open misc tools section click on– delete a file on reboot in the –file name window: copy/paste: C:\WINNT\system32\1639E8CD.EXE click–open button. at the prompt to reboot select yes. ———————— rescan and post new hjt log please. shelf life
Here's the new HJT log:
————————–
Logfile of HijackThis v1.99.1
Scan saved at 8:20:30 PM, on 7/12/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\UPHClean\uphclean.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\RunDll32.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINNT\StartupMonitor.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.arkansas.net/webmail/src/login.php
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) - http://tw.msi.com.tw/autobios/client/iftwclix.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1170259838203
O16 - DPF: {E735FF6D-53C6-4C4D-BDC0-26CB90EE6C88} (setup_assistant.SetupAssistant) - https://oracle.anc.net/gck/setup_assistant.CAB
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{84CD0A23-BEC1-48DE-8976-26C6102AB5C9}: NameServer = 209.244.0.3 209.244.0.4
O20 - Winlogon Notify: avgwlntf - C:\WINNT\SYSTEM32\avgwlntf.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
————————–
Bob
Hello, shelf_life! That last HJT really worked! The Recycle Bin is now empty and working as it should, and two or three Event Viewer problems have disappeared. I spent a lot of time in the past trying to decode those EV problems, never thinking they were malware related. Live and learn! Thank you for helping me and for teaching me to open my mind. Best regards, Bob
Well, shelf life, I guess I was too soon saying goodbye. The Trojan keeps coming back. I keep getting, day after day, the same: Trojan Horse Generic5.JZM at C:\WINNT\System32\FC4ABA24.DLL My AVG Anti-Malware always finds it (often when I tell it to scan, see below), and deletes it, but it keeps coming back! Most of my surfing each day is Intellicast and/or NWS for the weather and, for the past few weeks, places like Coyote, MS, trend-Micro and others connected with cleaning up my computer. I DO NOT go to sicko websites! Last time it messed up the Recycle Bin; today I couldn't get into Add/Remove Programs until I scanned AVG and they deleted it. This pattern started on or before 17 May when my tray clock showed year 2005 instead of 2007 and AVG (Free) was going bananas about terrible things happening if I don't download some updates. I fixed this (or thought I did) by deleting 3 files whose names I have forgotten. On 9 Jun, the same thing happened with 3 different names: 8ABE4C4.exe, 1639E8CD.exe, and FC4ABA24.dll; and again on 11 Jun with the same files. Trend Micro cleared the first one but I got sick of staying up all night for that again so I took the box to a local shop. On 16 Jun, the same files came back and I deleted them all again. And again on 25 Jun, with a small message in the LR corner: New Message £° §Á You receive a new message Convert Your Traffic Into Cash but always with the same three files. On 26 Jun, that same message and three files returned and were erased with Gutmann; but I had to do that again later in the day! I finally sent a post to Tom Coyote. The next day I Started downloading ZA Firewall on recommendation of Trevuren; found FC4ABA24, 1639E8CD.EXE and 8ABE4C4.EXE sitting there in System32. Rebooted to Safe Mode; deleted all three; rebooted. Thanks to Don Coyote Forum and Trevuren, the Trojan is gone on 29 Jun. While all this was going on I was trying to install Ad-Aware 2007 and having no luck in registering that software so I demanded my money back and got it! But I got nothing for my frustration. I was able to update AVG Free to AVG AntiMalware Pro, but that is obviously not stopping malware from getting on the computer, only detecting it when it scans, then deleting it. And so I get a crippled computer in between scans, and I have to start another scan to get rid of the new trojan and this is getting to be a real PITA! Today, after thanking shelf_life and Doug for all their help, thinking I was finally in the clear, I can't get into the Add/Remove Programs, so I initiate another scan and AVG detects yet another FC4ABA24.dll. They delete that one but don't delete 1639E8CD.EXE, still in System32. I believe that both need to be deleted. But all three were deleted a number of times already! What else can I do? This is driving me crazy! Bob
hi bobberles,

lets try doing a online scan to see what it can dig up:

F-secure scan:
http://support.f-secure.com/enu/home/ols.shtml

click on the "start scanning button"at bottom of page
click to accept/install the ActiveX applet,Click Full System Scan
Once the download completes (may take awhile),the scan will begin automatically.
The scan will take some time to finish.
When the scan completes, click the Automatic cleaning (recommended) button.

Click the Show Report button and Copy&Paste the entire report in your next reply along with a current HijackThis log.

shelf life
Hi, shelf life,
Well, that was certainly an experience. I got your reply around 2100 last night; immediately went to work on it. You weren't kidding when you said …(may take awhile)…; it took 17 hours!

I thought it didn't look right when the small F-secure window didn't show any response after I clicked on Full System Scan. I looked at my dialup Status box and it showed the fastest download rate I've ever had since Ma Bell cut me down to 26.4 - more than double that! So I didn't complain. But when the downcount passed 26MB (F-secure said it would be about 24) I got a bit nervous. At 30MB I went to bed.

I got up three times during the night and it was still chugging along, so I figured it must be scanning and I opened Task Manager to monitor (sure wish there was a better one). Finally got up, got breakfast, read the paper, worked in the shop and finally saw other signs of life. The screen showed a list of things yet to be done, along with the EULA license acceptance! And after the EULA was: DOWNLOAD THE PROGRAM!

What the hell was going on while I slept?

Long story short - I downloaded the program (27MB - 2 hours) and let it scan and got the data that you want. Total Bytes delivered - 311,304,714. Never thought I'd ever see that in one day of struggling. Do you have ANY idea what was going on? That was 17 hours that should have been 4; 284MB that are…WHAT!

Anyway, here's the F-secure report and the HJT log; hope you haven't given up on me!

—————————————
Scanning Report
Monday, July 16, 2007 12:50:42 - 13:52:35
Computer name: PITA
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ K:\ L:\

Result: 6 malware found
Backdoor.Win32.Agent.ahj <http://cgi.f-secure.com/cgi-bin/websearch/vsearch.cgi?q=Backdoor.Win32.Agent.ahj&orig='disk'> (virus)
C:\WINNT\SYSTEM32\1639E8CD.EXE (Renamed & Submitted)
Hupigon.gen66 <http://cgi.f-secure.com/cgi-bin/websearch/vsearch.cgi?q=Hupigon.gen66&orig='disk'> (virus)
C:\WINNT\SYSTEM32\FC4ABA24.DLL (Submitted)
Tracking Cookie <http://cgi.f-secure.com/cgi-bin/websearch/vsearch.cgi?q=Tracking Cookie&orig='disk'> (spyware)
System (Disinfected)
System
System
W32/SDBot.ACBD <http://cgi.f-secure.com/cgi-bin/websearch/vsearch.cgi?q=W32/SDBot.ACBD&orig='disk'> (virus)
C:\WINNT\SYSTEM32\TFTP684 (Submitted)

Statistics
Scanned:
Files: 23496
System: 3777
Not scanned: 3
Actions:
Disinfected: 1
Renamed: 1
Deleted: 0
None: 4
Submitted: 3
Files not scanned:
C:\PAGEFILE.SYS
C:\WINNT\SOFTWAREDISTRIBUTION\EVENTCACHE\{5CAE9857-32D6-46B5-82A3-AE828EB70BD4}.BIN
C:\WINNT\SYSTEM32\CONFIG\SECURITY

Options
Scanning engines:
F-Secure Libra: 2.4.2, 2007-07-16
F-Secure AVP: 7.0.171, 2007-07-16
F-Secure Orion: 1.2.37, 2007-07-16
F-Secure Blacklight: 1.0.64
F-Secure Draco: 1.0.35, 0260-23-12
F-Secure Pegasus: 1.19.0, 2007-06-12
Scanning options:
Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB BAT LNK ANI AVB CEO CMD LSP MAP MHT MIF PDF PHP POT WMF NWS TAR TGZ WSF ZL? {* ZIP JAR ARJ LZH TAR TGZ GZ CAB RAR BZ2 HQX
Use Advanced heuristics
—————————————
Logfile of HijackThis v1.99.1
Scan saved at 2:50:46 PM, on 7/16/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINNT\system32\regsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\RunDll32.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINNT\StartupMonitor.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

http://www.arkansas.net/webmail/src/login.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program

Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -

C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio -

{8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [RemoteControl] "C:\Program

Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common

Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]

"C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_01\bin\ssv.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner

3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -

http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX

Control) - http://tw.msi.com.tw/autobios/client/iftwclix.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://update.microsoft.com/windowsupdate/…/client/wuweb_s

ite.cab?1170259838203
O16 - DPF: {E735FF6D-53C6-4C4D-BDC0-26CB90EE6C88}

(setup_assistant.SetupAssistant) -

https://oracle.anc.net/gck/setup_assistant.CAB
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX

Control) - http://driveragent.com/files/driveragent.cab
O17 -

HKLM\System\CCS\Services\Tcpip\..\{84CD0A23-BEC1-48DE-8976-26C6102AB5C9}:

NameServer = 209.244.0.3 209.244.0.4
O20 - Winlogon Notify: avgwlntf - C:\WINNT\SYSTEM32\avgwlntf.dll
O23 - Service: 6F0D0C5E - Unknown owner - C:\WINNT\system32\1639E8CD.EXE

(file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -

C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -

C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. -

C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. -

C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) -

VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak

Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: LightScribeService Direct Disc Labeling Service

(LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common

Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common

Files\Ahead\Lib\NMIndexingService.exe

—————————————
Bob
hi bobberles, i should have remembered you had a dial up connection. i wouldnt have suggested such a massive download. my experience with dialup is that the window showing the "flying" folder (transfer) can remain showing even though nothing is happeneing? looks like f-secure removed some goodies. i think that took care of it, (i think that .dll was the hold up) but we can go thru this to hopefully be sure: —————————————————– lets do all this in safe mode, so i would copy/paste what follows into notepad, call it something and save it to your desktop so you can read it in safe mode. to reach safe mode you would tap the f8 key during a computer reboot. chose the first option form the list: safe mode. ok once at the safe mode desktop: go to start>run and type in–> services.msc <–in the list of services that comes up look for>>1639E8CD.EXE right click on it and select properties. under the general tab: the path to the .exe should be:C:\WINNT\system32\1639E8CD.EXE make sure that the service status is: Stopped, if not click the Stop button and the Startup type is: disabled, if not change it to disable click apply, then ok ———————————- next: to show all files do this: * Open My Computer. * Select the Tools menu and click Folder Options. * Select the View Tab. * Under the Hidden files and folders heading select Show hidden files and folders. * Uncheck the Hide protected operating system files (recommended) option. * Click Yes to confirm. * Click OK. —————————————– next: using explorer(right click on start>explore) drill down to these you want to delete whats >inside< the folder, not the folder itself. might be slightly different in windows 2000. just delete what you can. C:\Windows\Temp\ C:\Documents and Settings\-Your Profile-\Local Settings\Temporary Internet Files\ (will dump all your cached internet content including cookies) C:\Documents and Settings\-Your Profile-\Local Settings\Temp\ C:\Documents and Settings\-Any other users Profile-\Local Settings\Temporary Internet Files\ C:\Documents and Settings\-Any other users Profile-\Local Settings\Temp\ ————————————— next: Go to Start > Run and type:cleanmgr. Windows will scan. When done check these 3 and press *ok* to remove: Temporary Files Temporary Internet Files Recycle Bin ————————————– run your AVG antivirus then spybot in safe mode. ————————————– last: open hjt, click on –open misc tools section click on– delete a file on reboot in the –file name window: copy/paste: C:\WINNT\System32\FC4ABA24.DLL click–open button. at the prompt to reboot select yes. reboot computer normally, see how it goes now. shelf life
Hi shelf life, Well, I may have aged a lot on the download, but the rest went OK. But first, what was that 'massive' download that was neither announced nor explained to me? Thirteen hours is a hell of a long time when one is expecting two or three. I think even a broadbander would wonder what's going on; "What's this seven minutes instead of two?" Some other questions: 1. Why did AVG 7.5 not find this malware when they had plenty of opportunities? Did I waste my money with Grisoft? Isn't their Resident Shield supposed to intercept malware and block it? Or did I do something wrong in the install? According to their blurbs everything is set on install, which tells me that they should have found the malware even if it was already in my system. 2. Why did I have to delete the bad stuff when F-secure already had done that? (At least, I thought they did!) I couldn't find 1639E8CD.EXE in the Services.msc list, but when I saw Name: 6F0D0C5E and Description: FC4ABA24 I thought it must be hiding there, and it was. (FC4ABA24 is almost an old friend!) And I couldn't delete FC4ABA24 using HJT because F-secure had already deleted it. I AM NOT trying to nitpick, I just want to be sure that I'm doing the right thing. I've got a lot of learning to do. Do you think I can safely make a Drive Image now? Bob
hi bobberles, i will try to answer your questions: iam not sure what the total MB download was, but on dialup i can imagine it would take some time to download. a scan of your computer could also take awhile mainly if you have a older cpu and maybe 256MB memory or less. Nothing wrong with AVG, i believe thats AVG antivirus you have. Antivirus is getting better and better at finding malware (non virus)but its not as good as a antimlaware app like spybot or ad aware for finding malware like trojans. (non virus) if problems arent cleared up with one app, then i always suggest a online scan or a second malware scanner. having one antivirus and two antimalware apps is plenty. Last: we could have skipped that last part in safe mode and kept are fingers crossed. just being more aggressive i guess by going into safe mode and repeating whats been done. deleting all those temp files also being more aggressive, those are places malware can lurk. the idea behind safe mode is that it just "loads" the bare minimum so most processes arent active and may be easier to get rid of by deleting or using your scanners. shelf life

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI