This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE Defender Pop-up & Bargain Buddy Bundle

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I was led into downloading a Video Codec from a video streaming website. Thinking that it was legitimate, i saved the file into my computer.
Since then my IE search function has had porn related links in the results displayed. There is also a pop-up offering to install IE-Defender every now and then.

I tried running several free software which offers to clean up spyware, (ie Ad-Aware, Spybot, XoftSpySE) but they were unable to detect anything with regards to this issue

After running XoftSpySE, it showed there there is this spyware called "Bargain Buddy Bundle". However there was no option for me to remove it as I needed to purchase the software before it would be able to remove that particular spyware.

It seems that I have two issues at hand. I hope you would be able to help me out as this is my 1st time trying to clean spyware through posting on forums. Please guide me along smoothly as I might not be sure about the various steps that are required to carry out to post the various logs here. Thanks.

Logfile of HijackThis v1.99.1
Scan saved at 3:57:21 PM, on 10/28/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\GSICON.EXE
C:\WINNT\system32\dslagent.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: IntelVideoCodec - {33A12BEB-3219-4CA8-99B4-733192704C62} - C:\WINNT\system32\IntelVideoDivX.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1187496373703
O17 - HKLM\System\CCS\Services\Tcpip\..\{54B1B358-61D6-4C05-98D3-8DCAD4089F9C}: NameServer = 202.136.162.11 202.136.163.11
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
Welcome to the forum.
1. Please download the OTMoveIt by OldTimer to your desktop.
2. Please double-click OTMoveIt.exe to run it.
Where it says: "Paste List of Files/Folders to be Moved", copy and paste next blue part into that Window:

C:\WINNT\system32\IntelVideoDivX.dll

3. Then click the red Moveit! button below.
This will display the results in the right windows where it says Results on top
4. Copy and paste everything present in the Results window (right window) and save these results in notepad and save it on your desktop, because I need to see those results afterwards.
5. Close OTMoveIt
Note:
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

——————

Close ALL programs down, leaving ONLY HijackThis running - Click Scan and…..
Place a check against the following items if found:

O2 - BHO: IntelVideoCodec - {33A12BEB-3219-4CA8-99B4-733192704C62} - C:\WINNT\system32\IntelVideoDivX.dll

Click on Fix Checked and exit HijackThis.

—————–


1. Download RVAXO.exe into a folder.

2. Double click on RVAXO.exe, then click "Installeren" to install the program.
("Bladeren" = Browse for Folder and "Annuleren" = Cancel)
It will install to a folder called Rvaxo

3. Now open up the Rvaxo folder and double click on RVAXO.cmd

You will see a small window pop up, and quickly some lines will run , then the window will close by itself, this is normal behavior.
Then it is possible for an uninstaller of some roque scanner to start up, do not close this but follow all prompts there, and let it run its course.

4. When it's done….reboot the computer.
Now double click on RVAXO.cmd again to run the program……..Let it finish.

5. After it's done it will create a file called RVAXO-results.log in C:\
(C:\RVAXO-results.log)

Copy and paste it back here.

—————–

Next…….

Please download SUPERAntiSpyware Home Edition (free)

Install it and double-click the icon on your desktop to run it.
It will ask if you want to update the program definitions, click Yes, Let it through your firewall!
Under Configuration and Preferences, click the Preferences button.
Click the Scanning Control tab.
Under Scanner Options make sure the following are checked:
  • Close browsers before scanning
  • Scan for tracking cookies
  • Terminate memory threats before quarantining.
  • Ignore System Restore/Volume Information on ME and XP
  • Please leave the others unchecked.
  • Click the Close button to leave the control center screen.
On the main screen, under Scan for Harmful Software click Scan your computer.
On the left check C:\Fixed Drive.
On the right, under Complete Scan, choose Perform Complete Scan.
Click Next to start the scan. Please be patient while it scans your computer.
After the scan is complete a summary box will appear. Click OK.
Make sure everything in the white box has a check next to it, then click Next.
It will quarantine what it found and if it asks if you want to reboot, click
Yes.

To retrieve the removal information - please do the following:
  • After reboot, double-click the SUPERAntispyware icon on your desktop.
  • Click Preferences . Click the Statistics/Logs tab .
  • Under Scanner Logs , double-click SUPERAntiSpyware Scan Log .
  • It will open in your default text editor (such as Notepad/Wordpad).
  • Please highlight everything , then right-click and choose copy.
  • Click close and close again to exit the program.
Now please paste the removal information along with a fresh HijackThis log in your reply. If it's a large log, you may need several replies to post it.
Please don't forget the log from RVAXO.

Good Luck, MrC
Hi MrC,

Thanks for replying to my post.

During the process of carrying out your instructions, there were some discrepancy as to what appeared on my screen. (i.e when trying to install RVAXO.exe, upon double clicking, it prompted me to unzip the files inside)
While trying to run SUPERAntiSpyware, i faced a certain problem. Upon double-clicking the icon "perform complete scan" the software came up with a message "initializing scan". After leaving it overnight the message "initialiazing scan" remains there. I close the software and restarted it again but the problem still persists. Is there any other link/software for me to try to scan my computer again?

Thank you for your patience.

This is the displayed information of the "Results Windows" from OTMoveIt.

C:\WINNT\system32\IntelVideoDivX.dll unregistered successfully.
C:\WINNT\system32\IntelVideoDivX.dll moved successfully.

Created on 10/30/2007 19:51:39

This is the log file of RVAXO,

—————-RVAXO.exe first run————-

Files found:

C:\WINNT\system32\sysinit32.exe

Uninstallers Rogue scanners:


Folders Found:


Hosts-file was reset, If you use a custom hosts file please replace it…

————–RVAXO.exe last run—————

Files found:

Folders Found:

————–RVAXO.exe finished—————-


The removal information from SUPERAntispyware,

Unable to initialize scan.

And lastly, a fresh HijackThis log upon completion of the above steps.

Logfile of HijackThis v1.99.1
Scan saved at 11:13:06 AM, on 10/31/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\GSICON.EXE
C:\WINNT\system32\dslagent.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1187496373703
O17 - HKLM\System\CCS\Services\Tcpip\..\{54B1B358-61D6-4C05-98D3-8DCAD4089F9C}: NameServer = 202.136.162.11 202.136.163.11
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
The log looks Good!

During the process of carrying out your instructions, there were some discrepancy as to what appeared on my screen. (i.e when trying to install RVAXO.exe, upon double clicking, it prompted me to unzip the files inside)


That's OK…it usually unzips itself.

————————

Uninstall SAS and run AVG AntiSpyware to clean up any leftovers.

You can find the link and info at the link below:

http://forums.maddoktor2.com/index.php?showtopic=9590

MrC
Hey,

I think there's something very wrong with my computer now.
Upon startup, there will be pop-up "iexplorer.exe unable to initialise" - refer to Screenshot1
The Time and Date will also be reset every time the computer is being started. Time will be changed to 1/1/2000 12:00AM. - refer to Screenshot1

After which pop-ups will appear from Spybot. - refer to Screenshot2
and these pop-ups appear a few times per minute, for every single minute. (in the screenshot case, 30mins before i restarted the computer) - refer to Screenshot3

Once during starting up, mIRC was running at the back by itself, after which a black window (something similar to the black DOS box to type commands with appeared) popped up, with extension C:\WINNT\system32\Killme.. or something similar at the top of the window. I restarted the com to try and get the screenshot, but it failed to materialize.

The loading time for starting the computer has also increased, and I uninstalled some spyware cleaners (which could only scan and not remove the treat, as it is not freeware) to try and remove the lag.


Is there anyway for me to upload the screenshots? I pressed print screen and paste it to paint. However the file size is 2.25MB each and the attachment sizes for this reply is restricted to 250k..

———————————————————————————————————————————————————————————–

Log from AVG Anti-Spyware Scan

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 12:26:35 AM 1/1/2000

+ Scan result:



C:\WINNT\system32\scansql.exe -> Not-A-Virus.NetTool.Win32.SQLAccount.180 : Cleaned.
:mozilla.38:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.39:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Ak1\Cookies\ak1@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.18:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.19:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.20:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.22:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.46:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.47:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.


::Report end

———————————————————————————————————————————————————————————–

And a new HijackThis log

Logfile of HijackThis v1.99.1
Scan saved at 12:27:53 AM, on 1/1/2000
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\MSupdate.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\GSICON.EXE
C:\WINNT\system32\dslagent.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINNT\system32\nero.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\program files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1187496373703
O17 - HKLM\System\CCS\Services\Tcpip\..\{54B1B358-61D6-4C05-98D3-8DCAD4089F9C}: NameServer = 202.136.162.11 202.136.163.11
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlackHole Remote Control Services (BRC_Services) - Unknown owner - C:\WINNT\system32\brc_Server.exe" /service (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: net1.3322.org - Unknown owner - C:\WINNT\system32\FireFoxUpdater.exe
O23 - Service: Serv-U FTP Server (Serv-U) - Unknown owner - C:\WINNT\system32\MSupdate.exe
O23 - Service: system - Unknown owner - C:\WINNT\system\G_Server123
O23 - Service: Windows (Windows ) - Unknown owner - C:\WINNT\doc
O23 - Service: Windows System Hardware BackUp (WindowsSystemHDBackUp) - Unknown owner - C:\WINNT\system32\¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡
Another thing to add, when surfing the net, AVG will display this pop-up every now and then, This is what that is displayed, ! Malware found Name: Backdoor.GreyBird.nc Location: C:\WINNT\TEMP\IXP000.TMP\12.exe Risk: High Description: This malicious software bypasses normal authentication or provides remote access to a computer, while attempting to remain hidden from casual inspection. Is it due to infected temporary internet files, and I just have to clear the cache to remove it?
You're all infected with new malware.

Do you have a good system retore point…if so please use it.

EDIT: I forgot you have 2K not XP..no system restore

If not………

Please disable TeaTimer and SDHelper by opening Spybot SD, click Mode>Advanced>and on the left menu choose Tools and then Resident. In the right hand pane you will see a check box for TeaTimer and for SDHelper . Please uncheck both boxes and then close Spybot. You can reinstate it later but we don't want it interfering with what we need to do. Reboot when done

—————-

1. Clean out temp files: ATF Cleaner
Download ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All (cookies optional)
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All (cookies optional)
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All (cookies optional)
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

—————

So far as I can see all these services are malware…if you think differently…please let me know.

Go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called:
net1.3322.org

When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.

Do the same for these:
Serv-U FTP Server
system
Windows
Windows System Hardware BackUp


Close ALL programs down, leaving ONLY HijackThis running - Click Scan and…..
Place a check against the following items if found:

O23 - Service: net1.3322.org - Unknown owner - C:\WINNT\system32\FireFoxUpdater.exe
O23 - Service: Serv-U FTP Server (Serv-U) - Unknown owner - C:\WINNT\system32\MSupdate.exe
O23 - Service: system - Unknown owner - C:\WINNT\system\G_Server123
O23 - Service: Windows (Windows ) - Unknown owner - C:\WINNT\doc
O23 - Service: Windows System Hardware BackUp (WindowsSystemHDBackUp) - Unknown owner - C:\WINNT\system32\¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡

Click on Fix Checked and exit HijackThis.

Delete these files if found:

C:\WINNT\system32\FireFoxUpdater.exe
C:\WINNT\system32\MSupdate.exe

Reboot and post a fresh HijackThis log and we'll take another look. MrC
Hey,

Cleaned up the temp files and was able to disable the various services as listed. However upon scanning with Hijackthis this, none of the services or files were found.

Things seem to be better, the clock's working now. However, the layout of this forum has changed. I do not see any lines or formats. Everything is just in text. Was it due to the cleaning up of firefox?

————————————————————

Fresh Hijackthis log upon restart

Logfile of HijackThis v1.99.1
Scan saved at 12:18:03 AM, on 1/1/2000
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\GSICON.EXE
C:\WINNT\system32\dslagent.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\program files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nb4f.com.cn
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nb4f.com.cn
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1187496373703
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlackHole Remote Control Services (BRC_Services) - Unknown owner - C:\WINNT\system32\brc_Server.exe" /service (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
That's Good News!

The log looks OK

Cleaned up the temp files and was able to disable the various services as listed. However upon scanning with Hijackthis this, none of the services or files were found.


That's OK

——————

Things seem to be better, the clock's working now. However, the layout of this forum has changed. I do not see any lines or formats. Everything is just in text. Was it due to the cleaning up of firefox?


I don't think so….look at the bottom left of this page…there's a skin selector…play with that….see if it makes a difference.

You may have deleted the cookies this forum sets when you log in also.

Let me know, MrC
Nope, toggling with the skin selector has not resulted in any changes at all. Its ok I guess, been surfing about and other sites does not seem to have this problem. Guess i'll figure out a way sooner or later. However, when choosing to run a program, there will be this pop-up. 'The instruction at "0x010af1af" referenced memory at "0x10012658". The memory could not be "read". Click on OK to terminate the program. This pop-up appears whenever I choose to run a program, even for Task Manager. However upon clicking on "OK", the application is still able to run. Any idea what is the problem? Thanks!
Hey,

There havent been much problems, until a few days back when i ran a check on AVG Anti-Spyware just to be sure. Turned out that there were Trojons and backdoors, and I cleaned all these infected files based on the recommended actions.

================================================================================

Upon startup,

A black window ""C:\WINNT\system32\cmd.exe" will run, with some texts in it. After a while, it will close by itself.
After which there will be 2 black windows with title "C:\WINNT\system32\svchost.exe". There are no texts in the box. Just a black background. Nothing happens when I close the pop-up.

EDIT:
I realised that everytime that i run a new program on my computer, the black box "C:\WINNT\system32\svchost.exe" will pop-up.


After a while of using, there will also be this pop-up with title "Dialuppass.exe - Unable to Locate DLL"

The content written inside is,
"The dyanamic link library SOFT2CN(some weird symbols) could not be found in the specified path
C:\WINNT;,;C:\WINNT\system32;C:\WINNT\system;C:\WINNT;C:\WINNT\system32;C:\WINNT;C:\WINNT\System32\Wbem

================================================================================

In AVG Anti-Spyware, there's a tab "Analysis", "Autostart". In which, there is 3 applications "ctfmen" with an icon of a penguin. I have listed them below.

Application: ctfmen
Location: Registry\HKLM\Run
Path: C:\WINNT\ctfmen.exe

Application: C:\WINNT\ctfmen.exe
Location: WIN.INI\WINDOWS\LOAD
Path: C:\WINNT\ctfmen.exe

Applicatoin: C:\WINNT\ctfmen.exe
Location :WIN.INI\WINDOWS\RUN
Path: C:\WINNT\ctfmen.exe


I googled the term "ctfmen", and it is being labelled as a trojan_backdoor on this website,
"http://www.processlib.net/files/ctfmen.exe.html"

"http://www.liutilities.com/products/campai…hatsrunning/rb/" offers to run scans to clear any such exe problem.

Is there anyway to differentiate genuine sites which offer real help and malicious sites which trick you to download even more trojans?

================================================================================

In my external Hard Disc, E Drive, there is a hidden icon, with the same picture of the penguin.

I right-clicked to check the properties and it is an application. After which I scanned it with AVG Anti-Spyware and nothing turned up. However when I double-clicked on the icon, my whole screen turns blue. After which it will auto-restart.

I do not remember downloading or installing any files with ctfmen, or with the penguin icon.

I hope you can help me out with regards to this.

================================================================================

I ran AVG Anti-Spyware. This is the log.

AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 8:11:05 AM 11/9/2007

+ Scan result:



[576] C:\WINNT\system32\FireFoxUpdater.exe -> Downloader.Small.dwp : Cleaned with backup (quarantined).
:mozilla.14:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.15:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.16:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.33:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.34:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.35:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.36:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.37:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.40:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.


::Report end

================================================================================

Log of HijaskThis

Logfile of HijackThis v1.99.1
Scan saved at 8:12:22 AM, on 11/9/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\GSICON.EXE
C:\WINNT\system32\dslagent.exe
C:\PROGRA~1\Java\JRE16~1.0_0\bin\jusched.exe
C:\program files\internet explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nb4f.com.cn
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nb4f.com.cn
F3 - REG:win.ini: load=C:\WINNT\ctfmen.exe
F3 - REG:win.ini: run=C:\WINNT\ctfmen.exe
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Win2KService] C:\WINNT\system32\os\system32.exe
O4 - HKLM\..\Run: [ctfmen] C:\WINNT\ctfmen.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{54B1B358-61D6-4C05-98D3-8DCAD4089F9C}: NameServer = 202.136.162.11 202.136.163.11
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlackHole Remote Control Services (BRC_Services) - Unknown owner - C:\WINNT\system32\brc_Server.exe" /service (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: GrayPigeon_Hacker.com.cn - Unknown owner - C:\WINNT\Hacker.com.cn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: llahl - Unknown owner - C:\Program Files\llah\llah.exe
O23 - Service: Å̹Å2007×îа汾·þÎñ¶Ë (pangu_service_name) - Unknown owner - C:\WINNT\system32\FireFoxUpdater.exe (file missing)
O23 - Service: PSEXESVC - Sysinternals - C:\WINNT\System32\PSEXESVC.EXE
O23 - Service: Remote Procedure Call System(RPCScc) (RpcScc) - Unknown owner - C:\WINNT\system32\Rpcscc.exe (file missing)
O23 - Service: svchost.exe (svcname) - Unknown owner - C:\WINNT\system32svchs0t.exe (file missing)
O23 - Service: system - Unknown owner - C:\WINNT\system\G_Server123
O23 - Service: Windows (Windows ) - Unknown owner - C:\WINNT\doc
O23 - Service: Windows Accounts Driver (windows_0) - Unknown owner - C:\WINNT\system32\Down(0).exe (file missing)
O23 - Service: winlogon - Unknown owner - C:\Program Files\winlogon.exe
O23 - Service: zhwe - Unknown owner - C:\WINNT\sx1101.exe
O23 - Service: Liang_liang_Server2.03 (¡¼ÁÁÁÁ¡½×¨ÒµÍêÃÀÆÆ½â) - Unknown owner - C:\WINNT\wappdx

================================================================================

Of the mentioned above, R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nb4f===.com.cn, seems to be a pop-up which I am trying to clear.
Furthermore, I have only been visiting trustworthy websites and not downloaded anything onto my computer. Why is it that the trojans always seems present?

I hope to hear from you. Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI