This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Could use some help

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I prefer DIY, but in this case I'm completely stumped. Barely a week ago I was infected with some type of adware (adssite I believe, if not more). Ive been endlessly searching through forums for methods of cleaning the computer but all my efforts have failed. I have scanned with NOD32 ESET Smart Security, and AVG Anti-Spyware 7.5 and a few others. Symptoms include a flash ad popping up on my desktop accompanied by a very irritating clicking sound. I have also tried uninstalling firefox as well. Here is my hijack log. Thank you!

logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:39:14 PM, on 1/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MICROS~2\rapimgr.exe
C:\Program Files\NETGEAR\WG511v2\wlancfg5.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\CPSHelpRunner.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Master\Desktop\HiJackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [AT&T Communication Manager] "C:\Program Files\AT&T\Communication Manager\ATTCM.exe" -a
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [postSetupCheck] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\gzmrt.dll" DllStart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - Global Startup: NETGEAR WG511v2 Wireless Assistant.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1191390160760
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1191390151567
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe


Also, during one of my AVG scans NOD32 blocked several trojans, atleast 10-12; here they are:

1/29/2008 10:45:01 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP81\A0020520.exe Win32/TrojanDownloader.Zlob.BMC trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:45:01 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP81\A0020519.exe Win32/TrojanDownloader.Zlob.BMC trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:45:01 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP81\A0020518.exe Win32/TrojanDownloader.Zlob.BMC trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:45:01 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP81\A0020511.exe Win32/Adware.VirusProtectPro application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:45:01 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP81\A0020511.exe Win32/Adware.VirusProtectPro application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:45:00 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP81\A0020513.dll Win32/Agent.NNO trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:45:00 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP81\A0020514.dll Win32/TrojanDownloader.FakeAlert.L trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:44:59 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP81\A0020517.exe Win32/TrojanDownloader.Zlob.BMC trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:44:55 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP81\A0020492.exe Win32/TrojanDownloader.Zlob.BMC trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

in32/TrojanDownloader.Zlob.BMC trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:44:52 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP81\A0020493.exe Win32/TrojanDownloader.Zlob.BMC trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:44:52 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP81\A0020494.dll Win32/TrojanDownloader.Zlob.BMC trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:44:50 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP80\A0020486.exe Win32/TrojanDownloader.Zlob.BMC trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:44:46 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP80\A0020470.exe Win32/TrojanDownloader.Zlob.BMC trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:44:46 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP80\A0020485.dll Win32/TrojanDownloader.Zlob.BMC trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:44:45 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP80\A0020468.exe Win32/TrojanDownloader.Zlob.BMC trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:44:43 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP80\A0020466.dll Win32/TrojanDownloader.Zlob.BMC trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:44:42 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP80\A0020465.exe Win32/TrojanDownloader.Zlob.BMC trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:43:24 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP115\A0032449.dll probably a variant of Win32/Adware.Agent application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.

1/29/2008 10:42:13 AM Real-time file system protection file C:\System Volume Information\_restore{79F400A4-FB41-4D4E-83CA-0350FAF4EED9}\RP103\A0027905.dll probably a variant of Win32/Adware.Agent application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe.
Hello and welcome to the forum. Sorry about the delay in responding :( If you still need help, Scan again with HijackThis, and copy/paste" a new log file into this thread. Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI