trig
Topic Starter
Somehow this (Adware.Agent.BN) has slipped through the net on my work laptop (Sophos protection)
I have installed and run:
AdwareAlert
Spyware Doctor
Zone Alarm
They keep removing bugs but everytime I reboot it is still there!
It has installed 3 icons on the desktop:
"Error Cleaner"
"Privacy Protector"
"Spyware & Protection"
These are shortcuts to websites
http://virusprotectionproonline.com/shandler.php?s...
http://virusprotectionproonline.com/shandler.php?s...
http://virusprotectionproonline.com/shandler.php?s...
Anyway I keep getting a pop up saying Windows has detected a virus and then it opens IE and trys to goto various sites (Url is referencing something to do with a virus - "safewebnavigate"
I am also getting a red circle with a white cross on the toolbar which flashes and "virus warnings pop up from it also"
Does anyone know the best way to remove this, it doesnt seem to be doing anything else.
It is really starting to get annoying now especially as these spyware remover programmes are still not getting rid completely of it.
I have attached the log from HijackThis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:04:21, on 13/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Novadigm\AXF\Bin\XFSrvcNT.Exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ipUnplugged\Roaming Client\w2kMCService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Novadigm\AXF\Bin\XFStatus.Exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ipUnplugged\Roaming Client\w2kConfig.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\TalkTalk\bin\sprtcmd.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\ISS\issSensors\DesktopProtection\blackice.exe
C:\Program Files\Altiris\AClient\AClient.exe
C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Equant\Dialer\EACSvrMngr.exe
C:\Program Files\Novadigm\radexecd.exe
C:\Program Files\Novadigm\radsched.exe
C:\Program Files\Novadigm\Radstgms.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Free Download Manager\fdm.exe
C:\Downloads\HiJackThis.exe
C:\Program Files\Equant\Dialer\dialer.exe
C:\Program Files\Equant\Dialer\EACSys.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavMain.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\WINDOWS\System32\uWDF.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavProgress.exe
C:\Program Files\Internet Explorer\iexplore.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://intranet/newintranet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://intranet/newintranet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Capgemini UK plc
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = websense:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = intranet;intratest;dtxwebserver;tolorl;cbtweb;tbu;deliver.iweb.ey.com;sharepoint
cgey.com;peoplecube.capgemini.co.uk;https://www.topaz.genieinternet.com;192.168.26.248;knew.capgemini.com;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: MSVPS System - {47C54F02-1B28-45F1-AE46-B5CDFB6E7926} - C:\WINDOWS\duocore.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - C:\Program Files\ONSPEED\components\NOWImaging.dll (file missing)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: ONSPEED - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - C:\Program Files\ONSPEED\TOOLBAND.DLL (file missing)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [!AXF XFRunOne.Exe] "C:\Program Files\Novadigm\AXF\Bin\XFRunOne.Exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [RoamingClient] "C:\Program Files\ipUnplugged\Roaming Client\w2kConfig.exe"
O4 - HKLM\..\Run: [SP2DelFiles] c:\progra~1\novadigm\radntfyc localhost radrexxw SP2del.rex
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TalkTalk] "C:\Program Files\TalkTalk\bin\sprtcmd.exe" /P TalkTalk
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [!AXF XFRunOne.Exe] "C:\Program Files\Novadigm\AXF\Bin\XFRunOne.Exe" /1
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Shortcut to 1stlog0n.lnk = C:\WINDOWS\1stlog0n.bat (User 'SYSTEM')
O4 - .DEFAULT Startup: Shortcut to 1stlog0n.lnk = C:\WINDOWS\1stlog0n.bat (User 'Default user')
O4 - .DEFAULT User Startup: Shortcut to 1stlog0n.lnk = C:\WINDOWS\1stlog0n.bat (User 'Default user')
O4 - Startup: VPN Dialer (OnStartup).lnk = ?
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: InterCheck Monitor.LNK = ?
O4 - Global Startup: RealSecure® Desktop Protector.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://intranet/newintranet
O15 - Trusted Zone: http://cgfind.capgemini.co.uk
O15 - Trusted Zone: http://cgmisprodas1.capgemini.co.uk
O15 - Trusted Zone: http://cgmisprodas2.capgemini.co.uk
O15 - Trusted Zone: http://cgmisprodas3.capgemini.co.uk
O15 - Trusted Zone: http://cgmissuppas1.capgemini.co.uk
O15 - Trusted Zone: http://cgmissuppas2.capgemini.co.uk
O15 - Trusted Zone: http://cgmissuppas3.capgemini.co.uk
O15 - Trusted Zone: http://spade.capgemini.com
O15 - Trusted Zone: http://spadecrm.capgemini.com
O15 - Trusted Zone: http://spadereporting.capgemini.com
O15 - Trusted Zone: http://mygalaxyclassic.capgemini.fr
O15 - Trusted Zone: http://www.conecx-test.co.uk
O15 - Trusted Zone: http://chs.web.ey.com
O15 - Trusted Zone: http://deliver.iweb.ey.com
O15 - Trusted Zone: http://home.iweb.ey.com
O15 - Trusted Zone: http://my.infotriever.com
O15 - Trusted Zone: http://*.intranet
O15 - Trusted Zone: http://www.metalink.oracle.com
O15 - Trusted Zone: http://chat.scholars.com
O15 - Trusted Zone: http://capgemini.skillport.com
O15 - Trusted Zone: http://www.skillsoft.com
O15 - Trusted Zone: http://ccp.smartforce.com
O15 - Trusted Zone: http://content.smartforce.com
O15 - Trusted Zone: http://courseware.smartforce.com
O15 - Trusted Zone: http://dhtml.smartforce.com
O15 - Trusted Zone: http://discussions.smartforce.com
O15 - Trusted Zone: http://ghost.smartforce.com
O15 - Trusted Zone: http://jwolf.smartforce.com
O15 - Trusted Zone: http://my.smartforce.com
O15 - Trusted Zone: http://pet.smartforce.com
O15 - Trusted Zone: http://real01.smartforce.com
O15 - Trusted Zone: http://reports.smartforce.com
O15 - Trusted Zone: http://seminar01.smartforce.com
O15 - Trusted Zone: http://skl.smartforce.com
O15 - Trusted Zone: http://wms01.smartforce.com
O15 - Trusted Zone: http://www.smartforce.com
O15 - Trusted Zone: http://www.virtuallythere.com
O15 - Trusted Zone: http://cgfind.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmisprodas1.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmisprodas2.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmisprodas3.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmissuppas1.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmissuppas2.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmissuppas3.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://spade.capgemini.com (HKLM)
O15 - Trusted Zone: http://spadecrm.capgemini.com (HKLM)
O15 - Trusted Zone: http://spadereporting.capgemini.com (HKLM)
O15 - Trusted Zone: http://mygalaxyclassic.capgemini.fr (HKLM)
O15 - Trusted Zone: http://www.conecx-test.co.uk (HKLM)
O15 - Trusted Zone: http://chs.web.ey.com (HKLM)
O15 - Trusted Zone: http://deliver.iweb.ey.com (HKLM)
O15 - Trusted Zone: http://home.iweb.ey.com (HKLM)
O15 - Trusted Zone: http://my.infotriever.com (HKLM)
O15 - Trusted Zone: http://*.intranet (HKLM)
O15 - Trusted Zone: http://www.metalink.oracle.com (HKLM)
O15 - Trusted Zone: http://chat.scholars.com (HKLM)
O15 - Trusted Zone: http://capgemini.skillport.com (HKLM)
O15 - Trusted Zone: http://www.skillsoft.com (HKLM)
O15 - Trusted Zone: http://ccp.smartforce.com (HKLM)
O15 - Trusted Zone: http://content.smartforce.com (HKLM)
O15 - Trusted Zone: http://courseware.smartforce.com (HKLM)
O15 - Trusted Zone: http://dhtml.smartforce.com (HKLM)
O15 - Trusted Zone: http://discussions.smartforce.com (HKLM)
O15 - Trusted Zone: http://ghost.smartforce.com (HKLM)
O15 - Trusted Zone: http://jwolf.smartforce.com (HKLM)
O15 - Trusted Zone: http://my.smartforce.com (HKLM)
O15 - Trusted Zone: http://pet.smartforce.com (HKLM)
O15 - Trusted Zone: http://real01.smartforce.com (HKLM)
O15 - Trusted Zone: http://reports.smartforce.com (HKLM)
O15 - Trusted Zone: http://seminar01.smartforce.com (HKLM)
O15 - Trusted Zone: http://skl.smartforce.com (HKLM)
O15 - Trusted Zone: http://wms01.smartforce.com (HKLM)
O15 - Trusted Zone: http://www.smartforce.com (HKLM)
O15 - Trusted Zone: http://www.virtuallythere.com (HKLM)
O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - https://www.wanadoo.co.uk/time/anytimereg_d…rs/sd0101_5.exe
O16 - DPF: {205E7068-6D03-4566-AD06-A146B592FBA5} (Loader Class v2) - http://ws000202:18001/qcbin/Spider80.ocx
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {761CFA89-FE48-42E7-B4E4-638ED17E72A2} (dtxProject.dtx) - file://C:\5.11\dtx.CAB
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://ve.ukie.capgemini.com/dana-cached/s…perSetupSP1.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = uki.capgemini.com
O17 - HKLM\Software\..\Telephony: DomainName = uki.capgemini.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{32F98DFB-90FB-4A97-A730-76ED4787BE32}: NameServer = 10.16.16.28 10.16.112.38
O17 - HKLM\System\CCS\Services\Tcpip\..\{56BA3966-3EB7-4004-B60A-5EF5FBD92C6F}: Domain = uki.capgemini.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{56BA3966-3EB7-4004-B60A-5EF5FBD92C6F}: NameServer = 10.16.31.17,10.16.23.138
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = uki.capgemini.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = uki.capgemini.com,capgemini.co.uk,capgemini.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = uki.capgemini.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = uki.capgemini.com,capgemini.co.uk,capgemini.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = uki.capgemini.com,capgemini.co.uk,capgemini.com
O21 - SSODL: wmpenv - {DB7B6586-84D5-4539-A02E-001F7490F8A3} - C:\WINDOWS\wmpenv.dll
O21 - SSODL: wmpconf - {91943DCA-B71B-4E7D-AFF5-798F3A0F9D12} - C:\WINDOWS\wmpconf.dll
O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - C:\Program Files\Altiris\AClient\AClient.exe
O23 - Service: AdwareAlert Scanning Engine (AdwareAlertSrv) - Unknown owner - C:\Program Files\AdwareAlert\AdwareAlertSrv.srv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: (Equant Access Companion) Services Manager (EACSvrMngr) - Unknown owner - C:\Program Files\Equant\Dialer\EACSvrMngr.exe
O23 - Service: (Equant Access Companion) Devices and Services Monitoring (EACSys) - Unknown owner - C:\Program Files\Equant\Dialer\EACSys.exe
O23 - Service: Radia Notify Daemon (radexecd) - Hewlett-Packard - C:\Program Files\Novadigm\radexecd.exe
O23 - Service: Radia Scheduler Daemon (radsched) - Hewlett-Packard - C:\Program Files\Novadigm\radsched.exe
O23 - Service: Radia MSI Redirector (Radstgms) - Hewlett-Packard - C:\Program Files\Novadigm\Radstgms.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\issSensors\DesktopProtection\RapApp.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: ipUnplugged Roaming Client Service (w2kMCService) - ipUnplugged - C:\Program Files\ipUnplugged\Roaming Client\w2kMCService.exe
O23 - Service: XFSrvcNT - Hewlett-Packard - C:\Program Files\Novadigm\AXF\Bin\XFSrvcNT.Exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
–
End of file - 17004 bytes
I have installed and run:
AdwareAlert
Spyware Doctor
Zone Alarm
They keep removing bugs but everytime I reboot it is still there!
It has installed 3 icons on the desktop:
"Error Cleaner"
"Privacy Protector"
"Spyware & Protection"
These are shortcuts to websites
http://virusprotectionproonline.com/shandler.php?s...
http://virusprotectionproonline.com/shandler.php?s...
http://virusprotectionproonline.com/shandler.php?s...
Anyway I keep getting a pop up saying Windows has detected a virus and then it opens IE and trys to goto various sites (Url is referencing something to do with a virus - "safewebnavigate"
I am also getting a red circle with a white cross on the toolbar which flashes and "virus warnings pop up from it also"
Does anyone know the best way to remove this, it doesnt seem to be doing anything else.
It is really starting to get annoying now especially as these spyware remover programmes are still not getting rid completely of it.
I have attached the log from HijackThis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:04:21, on 13/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Novadigm\AXF\Bin\XFSrvcNT.Exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ipUnplugged\Roaming Client\w2kMCService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Novadigm\AXF\Bin\XFStatus.Exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ipUnplugged\Roaming Client\w2kConfig.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\TalkTalk\bin\sprtcmd.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\ISS\issSensors\DesktopProtection\blackice.exe
C:\Program Files\Altiris\AClient\AClient.exe
C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Equant\Dialer\EACSvrMngr.exe
C:\Program Files\Novadigm\radexecd.exe
C:\Program Files\Novadigm\radsched.exe
C:\Program Files\Novadigm\Radstgms.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Free Download Manager\fdm.exe
C:\Downloads\HiJackThis.exe
C:\Program Files\Equant\Dialer\dialer.exe
C:\Program Files\Equant\Dialer\EACSys.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavMain.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\WINDOWS\System32\uWDF.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavProgress.exe
C:\Program Files\Internet Explorer\iexplore.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://intranet/newintranet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://intranet/newintranet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Capgemini UK plc
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = websense:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = intranet;intratest;dtxwebserver;tolorl;cbtweb;tbu;deliver.iweb.ey.com;sharepoint
cgey.com;peoplecube.capgemini.co.uk;https://www.topaz.genieinternet.com;192.168.26.248;knew.capgemini.com;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: MSVPS System - {47C54F02-1B28-45F1-AE46-B5CDFB6E7926} - C:\WINDOWS\duocore.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - C:\Program Files\ONSPEED\components\NOWImaging.dll (file missing)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: ONSPEED - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - C:\Program Files\ONSPEED\TOOLBAND.DLL (file missing)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [!AXF XFRunOne.Exe] "C:\Program Files\Novadigm\AXF\Bin\XFRunOne.Exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [RoamingClient] "C:\Program Files\ipUnplugged\Roaming Client\w2kConfig.exe"
O4 - HKLM\..\Run: [SP2DelFiles] c:\progra~1\novadigm\radntfyc localhost radrexxw SP2del.rex
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TalkTalk] "C:\Program Files\TalkTalk\bin\sprtcmd.exe" /P TalkTalk
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [!AXF XFRunOne.Exe] "C:\Program Files\Novadigm\AXF\Bin\XFRunOne.Exe" /1
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Shortcut to 1stlog0n.lnk = C:\WINDOWS\1stlog0n.bat (User 'SYSTEM')
O4 - .DEFAULT Startup: Shortcut to 1stlog0n.lnk = C:\WINDOWS\1stlog0n.bat (User 'Default user')
O4 - .DEFAULT User Startup: Shortcut to 1stlog0n.lnk = C:\WINDOWS\1stlog0n.bat (User 'Default user')
O4 - Startup: VPN Dialer (OnStartup).lnk = ?
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: InterCheck Monitor.LNK = ?
O4 - Global Startup: RealSecure® Desktop Protector.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://intranet/newintranet
O15 - Trusted Zone: http://cgfind.capgemini.co.uk
O15 - Trusted Zone: http://cgmisprodas1.capgemini.co.uk
O15 - Trusted Zone: http://cgmisprodas2.capgemini.co.uk
O15 - Trusted Zone: http://cgmisprodas3.capgemini.co.uk
O15 - Trusted Zone: http://cgmissuppas1.capgemini.co.uk
O15 - Trusted Zone: http://cgmissuppas2.capgemini.co.uk
O15 - Trusted Zone: http://cgmissuppas3.capgemini.co.uk
O15 - Trusted Zone: http://spade.capgemini.com
O15 - Trusted Zone: http://spadecrm.capgemini.com
O15 - Trusted Zone: http://spadereporting.capgemini.com
O15 - Trusted Zone: http://mygalaxyclassic.capgemini.fr
O15 - Trusted Zone: http://www.conecx-test.co.uk
O15 - Trusted Zone: http://chs.web.ey.com
O15 - Trusted Zone: http://deliver.iweb.ey.com
O15 - Trusted Zone: http://home.iweb.ey.com
O15 - Trusted Zone: http://my.infotriever.com
O15 - Trusted Zone: http://*.intranet
O15 - Trusted Zone: http://www.metalink.oracle.com
O15 - Trusted Zone: http://chat.scholars.com
O15 - Trusted Zone: http://capgemini.skillport.com
O15 - Trusted Zone: http://www.skillsoft.com
O15 - Trusted Zone: http://ccp.smartforce.com
O15 - Trusted Zone: http://content.smartforce.com
O15 - Trusted Zone: http://courseware.smartforce.com
O15 - Trusted Zone: http://dhtml.smartforce.com
O15 - Trusted Zone: http://discussions.smartforce.com
O15 - Trusted Zone: http://ghost.smartforce.com
O15 - Trusted Zone: http://jwolf.smartforce.com
O15 - Trusted Zone: http://my.smartforce.com
O15 - Trusted Zone: http://pet.smartforce.com
O15 - Trusted Zone: http://real01.smartforce.com
O15 - Trusted Zone: http://reports.smartforce.com
O15 - Trusted Zone: http://seminar01.smartforce.com
O15 - Trusted Zone: http://skl.smartforce.com
O15 - Trusted Zone: http://wms01.smartforce.com
O15 - Trusted Zone: http://www.smartforce.com
O15 - Trusted Zone: http://www.virtuallythere.com
O15 - Trusted Zone: http://cgfind.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmisprodas1.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmisprodas2.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmisprodas3.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmissuppas1.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmissuppas2.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmissuppas3.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://spade.capgemini.com (HKLM)
O15 - Trusted Zone: http://spadecrm.capgemini.com (HKLM)
O15 - Trusted Zone: http://spadereporting.capgemini.com (HKLM)
O15 - Trusted Zone: http://mygalaxyclassic.capgemini.fr (HKLM)
O15 - Trusted Zone: http://www.conecx-test.co.uk (HKLM)
O15 - Trusted Zone: http://chs.web.ey.com (HKLM)
O15 - Trusted Zone: http://deliver.iweb.ey.com (HKLM)
O15 - Trusted Zone: http://home.iweb.ey.com (HKLM)
O15 - Trusted Zone: http://my.infotriever.com (HKLM)
O15 - Trusted Zone: http://*.intranet (HKLM)
O15 - Trusted Zone: http://www.metalink.oracle.com (HKLM)
O15 - Trusted Zone: http://chat.scholars.com (HKLM)
O15 - Trusted Zone: http://capgemini.skillport.com (HKLM)
O15 - Trusted Zone: http://www.skillsoft.com (HKLM)
O15 - Trusted Zone: http://ccp.smartforce.com (HKLM)
O15 - Trusted Zone: http://content.smartforce.com (HKLM)
O15 - Trusted Zone: http://courseware.smartforce.com (HKLM)
O15 - Trusted Zone: http://dhtml.smartforce.com (HKLM)
O15 - Trusted Zone: http://discussions.smartforce.com (HKLM)
O15 - Trusted Zone: http://ghost.smartforce.com (HKLM)
O15 - Trusted Zone: http://jwolf.smartforce.com (HKLM)
O15 - Trusted Zone: http://my.smartforce.com (HKLM)
O15 - Trusted Zone: http://pet.smartforce.com (HKLM)
O15 - Trusted Zone: http://real01.smartforce.com (HKLM)
O15 - Trusted Zone: http://reports.smartforce.com (HKLM)
O15 - Trusted Zone: http://seminar01.smartforce.com (HKLM)
O15 - Trusted Zone: http://skl.smartforce.com (HKLM)
O15 - Trusted Zone: http://wms01.smartforce.com (HKLM)
O15 - Trusted Zone: http://www.smartforce.com (HKLM)
O15 - Trusted Zone: http://www.virtuallythere.com (HKLM)
O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - https://www.wanadoo.co.uk/time/anytimereg_d…rs/sd0101_5.exe
O16 - DPF: {205E7068-6D03-4566-AD06-A146B592FBA5} (Loader Class v2) - http://ws000202:18001/qcbin/Spider80.ocx
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {761CFA89-FE48-42E7-B4E4-638ED17E72A2} (dtxProject.dtx) - file://C:\5.11\dtx.CAB
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://ve.ukie.capgemini.com/dana-cached/s…perSetupSP1.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = uki.capgemini.com
O17 - HKLM\Software\..\Telephony: DomainName = uki.capgemini.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{32F98DFB-90FB-4A97-A730-76ED4787BE32}: NameServer = 10.16.16.28 10.16.112.38
O17 - HKLM\System\CCS\Services\Tcpip\..\{56BA3966-3EB7-4004-B60A-5EF5FBD92C6F}: Domain = uki.capgemini.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{56BA3966-3EB7-4004-B60A-5EF5FBD92C6F}: NameServer = 10.16.31.17,10.16.23.138
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = uki.capgemini.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = uki.capgemini.com,capgemini.co.uk,capgemini.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = uki.capgemini.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = uki.capgemini.com,capgemini.co.uk,capgemini.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = uki.capgemini.com,capgemini.co.uk,capgemini.com
O21 - SSODL: wmpenv - {DB7B6586-84D5-4539-A02E-001F7490F8A3} - C:\WINDOWS\wmpenv.dll
O21 - SSODL: wmpconf - {91943DCA-B71B-4E7D-AFF5-798F3A0F9D12} - C:\WINDOWS\wmpconf.dll
O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - C:\Program Files\Altiris\AClient\AClient.exe
O23 - Service: AdwareAlert Scanning Engine (AdwareAlertSrv) - Unknown owner - C:\Program Files\AdwareAlert\AdwareAlertSrv.srv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: (Equant Access Companion) Services Manager (EACSvrMngr) - Unknown owner - C:\Program Files\Equant\Dialer\EACSvrMngr.exe
O23 - Service: (Equant Access Companion) Devices and Services Monitoring (EACSys) - Unknown owner - C:\Program Files\Equant\Dialer\EACSys.exe
O23 - Service: Radia Notify Daemon (radexecd) - Hewlett-Packard - C:\Program Files\Novadigm\radexecd.exe
O23 - Service: Radia Scheduler Daemon (radsched) - Hewlett-Packard - C:\Program Files\Novadigm\radsched.exe
O23 - Service: Radia MSI Redirector (Radstgms) - Hewlett-Packard - C:\Program Files\Novadigm\Radstgms.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\issSensors\DesktopProtection\RapApp.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: ipUnplugged Roaming Client Service (w2kMCService) - ipUnplugged - C:\Program Files\ipUnplugged\Roaming Client\w2kMCService.exe
O23 - Service: XFSrvcNT - Hewlett-Packard - C:\Program Files\Novadigm\AXF\Bin\XFSrvcNT.Exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
–
End of file - 17004 bytes