This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Something evil and intelligent.....

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

For the last week my computer seems to be infected with something weird. Probably a malware rather than virus.

What happens is this:
I start up the machine, log onto the net - everything is fine…
After a while suddenly Zone-alarm pops up to ask if a program is allowed to access the net. The prog varies but its always a prog that is in use, such as notepad, hidefolders, zonealarm, and so on. If I say no it usually asks if "i0sndwvJ.exe" is allowed to access the net.
If I say no "firefox" uses a lot of memory. If I say yes, a pop-up of some sort suddenly arrives at my screen often with content suited my country.

Tried to delete the "i0sndwvJ.exe" file. No use. Tried to scan the computer from safe-mode and startup and shutting down system restore. No help - (Avast). Tried spybot - no help. Tried Malwarebyte - no help. Atf-cleaner is also used.

Task-manager says the "i0sndwvJ.exe" file is a running process. I can shut it down but it reappeares after a while.
I'm lost….

Using Firefox and Iexplorer. Avast, spybot and zone-alarm. Cant have anything running besides avast and zone-alarm since this is an old PC. XP-pro. Lexmark printer. hidefolders, downloadexpress.

Logfile of HijackThis v1.99.1
Scan saved at 19:08:29, on 22.06.2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\driven\Hide Folders XP 2\hfxp.exe
C:\WINDOWS\System32\taskmgr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\System32\i0sndwvJ.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.no/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: Download using Download &Express - C:\Program Files\Download Express\Add_Url.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\System32\tmp_8j0.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Every other virus and malware I have managed to get rid off - but here I need help….
Run HJT and click on Open the Misc Tools section.
Click on delete a file on reboot…
Copy and paste the following into the "File name:" text box and then click Open:

C:\WINDOWS\System32\i0sndwvJ.exe

When you are asked "Do you want to restart your computer now?", click NO.
Repeat these steps for the following file(s) and this time, when you reach the end, click OK:

C:\WINDOWS\System32\tmp_8j0.dll

Your PC MUST reboot to delete the files!

Post a fresh HJT log once your PC has rebooted.
Hi, thanks for fast reply :)

Done what you requested. Always terrified of deleting things from the system32 folder so its assuring to have somone to tell me what to do.

The new log

Logfile of HijackThis v1.99.1
Scan saved at 00:19:04, on 23.06.2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.no/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: Download using Download &Express - C:\Program Files\Download Express\Add_Url.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\System32\tmp_8j0.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

I see the tmp-8j0.dll is still there. Should I be worried?
Dont really know if things are ok yet as it takes a while before this thing pops up…

I see the tmp-8j0.dll is still there. Should I be worried?

What you see in the HJT log is a registry entry that instructs your PC to start the naughty file on boot-up. As long as the file was successfully deleted, this instruction won't achieve anything as a missing file can't be started.
As I don't see C:\WINDOWS\System32\i0sndwvJ.exe in your list of Running Processes, i'd say that at least something good had been done.

1) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

O20 - AppInit_DLLs: C:\WINDOWS\System32\tmp_8j0.dll

CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

2) Go here and click the Kaspersky Online Scanner button - I.E. is required for this scan.
  • Read the Requirements and limitations before you click Accept.
  • Allow the ActiveX download if necessary.
  • Once the database has downloaded click Next.
  • Click Scan Settings and check the "Scan using the following antivirus database" is set to extended, not standard, and then click OK.
  • Click on "My Computer" and then put the kettle on!
  • When the scan has completed, click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
Copy and paste the report into your next reply along with a fresh HJT log, run in Normal Mode, and a description of how your PC is behaving.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

Also, run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
Thanks again. My PC still behaved a little suspicious. Taskmanager, zapro and some other legit progs asked for permission to connect to the net. when I refused, nothing more happened. No i0sndwvJ.exe and no eating of resources. Tried to fix the tmp_8j0.dll with Hijackthis but it said it couldnt be done. So, I tried to set it on delete on next startup again (even if I couldnt find the file in system32) - and now its gone from the hijackthis-scan. OHHH happy day, ohhh happy day :) Will still use the kapersky scan and do the uninstall list. My imidiate problem however seems to be solved. Thanks again from the bottom of my heart :)
Hi again. Well the i0sndwvJ.exe has returned, so i wasnt rid of it after all. Behaves much in the same way as before. Some suspicious questions from zonealarm about letting taskmanager and notepad access the net. Dont allow that. After a while, suddenly a qompletely unknown .exe file asks for permission. Its located in the tmp folder and has a name consisting of random letters and numbers. This file changes for each time. When denied access, it dies and i0sndwvJ.exe pops up in taskmanager and starts stealing resources. I cant kill the process and delete the file. The tmp_80.dll file has not reappeared. the Kapersky scan showed this: ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Thursday, June 26, 2008 Operating System: Microsoft Windows XP Professional Service Pack 1 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Wednesday, June 25, 2008 20:44:07 Records in database: 884401 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ Scan statistics: Files scanned: 116845 Threat name: 6 Infected objects: 8 Suspicious objects: 0 Duration of the scan: 01:45:43 File name / Threat name / Threats count C:\WINDOWS\Driver Cache\i386\driver.cab Infected: not-a-virus:Monitor.Win32.UberKeylogger.b 1 C:\WINDOWS\system32\JExOl7MA.exe Infected: Trojan-Downloader.Win32.Firu.eh 1 C:\WINDOWS\system32\omniband.dll Infected: not-a-virus:AdWare.Win32.BlazeFind.e 1 G:\dirkfolder\cracks\Goldeneye\goldeneye\GoldenEye.exe Infected: HackTool.Win32.GoldenEye.a 1 G:\dirkfolder\cracks\Goldeneye\goldeneye.zip Infected: HackTool.Win32.GoldenEye.a 1 G:\dirkfolder\crackz\exploiter\wsexpl\WSF.exe Infected: HackTool.Win32.Delf.cx 1 G:\dirkfolder\oldcomp\download\try\wsf12.zip Infected: HackTool.Win32.Delf.cx 1 G:\fromtheold\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.603 1 The selected area was scanned. Goldeneye, mirc and wsf are tools I used in the old days. Not in use anymore and hasnt been accessed for a couple of years. The 3 first ones however might be the bad guy. I seem to remember removing blazefind for some time ago. The install/uninstall list from Hijackthis: µTorrent 7-Zip 4.42 ACDSee 6.0 PowerPack Ad-aware 6 Professional Adobe Acrobat 4.0 Adobe Flash Player 9 ActiveX Adobe Flash Player Plugin Adobe Photoshop CS Adobe Reader 8.1.0 Adobe Shockwave Player Advanced Networking Pack for Windows XP AnalogX Vocal Remover AnalogX Vocal Remover (WinAmp) ArcSoft PhotoImpression 5 Asono BeatsoundsConfig AudibleManager avast! Antivirus Bit Che CDisplay 1.8 Creative WebCam Center Creative WebCam Live! Driver (1.01.01.0730) Creative WebCam Live! User's Guide (English) Data Lifeguard Tools DiscAPI DivX Codec DivX Converter DivX Player DivX Web Player DreamStation DXi DVD Shrink 3.2 DVD to VCD SVCD AVI Converter 2.05 Easy Video Joiner 5.01 Easy Video Splitter 1.26 Empire Earth II Hide Folders XP 2.9.2 for Windows XP/Vista HighMAT Extension to Microsoft Windows XP CD Writing Wizard HijackThis 1.99.1 Intel A/V Codecs V2.0 Intel® Extreme Graphics Driver Internet Explorer Q831167 InterVideo WinDVD 4 InterVideo WinProducer3 InterVideo WinRip IZArc [removed] J2SE Runtime Environment 5.0 Update 2 Jasc Paint Shop Pro 8 Java 2 Runtime Environment, SE v1.4.2_08 Java™ 6 Update 5 K-Lite Codec Pack 2.85 Full Lexmark Z600 Series MainConcept MPEG Encoder Malwarebytes' Anti-Malware MetaProducts Download Express Microsoft .NET Framework 1.1 Microsoft Office 2000 Professional mIRC Mozilla Firefox (2.0.0.5) MSXML4 Parser Nero 7 Premium Paint Shop Pro 7 Evaluation PDFtoJPG PeerGuardian 2.0 Pinnacle Hollywood FX for Studio Pinnacle Instant DVD Recorder proDAD Heroglyph 2.0 QuickTime RAPID RAR Password Cracker 4.12 RealPlayer Realtek AC'97 Audio Security Update for Windows Media Player 10 (KB917734) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB921883) SmartSound Quicktracks Plugin Spybot - Search & Destroy Spybot - Search & Destroy 1.5.2.20 Studio 10 Studio 10 Bonus DVD SUPER © Version 2007.bld.23 (July 4, 2007) Twins Video Player Ultimate ZIP Cracker Update for Windows XP (KB898461) VeloMaster Lite CW VideoLAN VLC media player 0.8.6c Virtual Sound Canvas DXi WA Update v3.50 beta2 WebRipper 1.1 Winamp (remove only) Winamp3 (remove only) Windows Installer 3.1 (KB893803) Windows Live Messenger Windows Media Encoder 9 Series Windows Media Encoder 9 Series Windows Media Format Runtime Windows Media Player 10 Windows SA Windows SR 2.0 Windows XP Hotfix - KB820291 Windows XP Hotfix - KB821253 Windows XP Hotfix - KB822603 Windows XP Hotfix - KB823182 Windows XP Hotfix - KB824105 Windows XP Hotfix - KB824141 Windows XP Hotfix - KB825119 Windows XP Hotfix - KB826939 Windows XP Hotfix - KB826942 Windows XP Hotfix - KB828035 Windows XP Hotfix - KB828741 Windows XP Hotfix - KB835732 Windows XP Hotfix - KB837001 Windows XP Hotfix - KB840374 Windows XP Hotfix - KB842773 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB911567 Windows XP Hotfix (SP2) Q322011 Windows XP Hotfix (SP2) Q327979 Windows XP Hotfix (SP2) q329623 Windows XP Hotfix (SP2) Q814995 Windows XP Hotfix (SP2) Q819696 WinMX WinZip WM Recorder 11.0 Xilisoft DVD Ripper Platinum 5 ZoneAlarm Pro I will await your answer before trying to remove the 3 suspects myself :) Oh and the reason for servicepack 1 is that when I tried to update to nr 2 the last time - the computer crashed.

Copy and paste the report into your next reply along with a fresh HJT log, run in Normal Mode

I'll need to see this.

Well the i0sndwvJ.exe has returned, so i wasnt rid of it after all.

I suspect that you have been reinfected rather than the file having been lurking on your system.

Go to Start > Control Panel > Add/Remove Programs and remove the following, and then reboot your PC:

J2SE Runtime Environment 5.0 Update 2
Java 2 Runtime Environment, SE v1.4.2_08


Both contain security flaws that could be responsible for the current problem, or not.
Hi again :) the hijacklog after removing the two javas: Logfile of HijackThis v1.99.1 Scan saved at 00:39:15, on 27.06.2008 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\System32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\HijackThis\HijackThis.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe O8 - Extra context menu item: Download using Download &Express - C:\Program Files\Download Express\Add_Url.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe Since the last post Avast suddenly (after an automatic update) suddenly detected and removed the C:\WINDOWS\system32\JExOl7MA.exe Infected: Trojan-Downloader.Win32.Firu.eh 1 There hasnt been any problems since then. Is it safe for me to remove the two other files detected by Kapersky C:\WINDOWS\Driver Cache\i386\driver.cab Infected: not-a-virus:Monitor.Win32.UberKeylogger.b 1 C:\WINDOWS\system32\omniband.dll Infected: not-a-virus:AdWare.Win32.BlazeFind.e 1 or should I leave them alone? And a type error in the last post: " I cant kill the process and delete the file." - should be: "I can kill the process and delete the file"

Since the last post Avast suddenly (after an automatic update) suddenly detected and removed the
C:\WINDOWS\system32\JExOl7MA.exe Infected: Trojan-Downloader.Win32.Firu.eh 1
There hasnt been any problems since then.

Always nice to see something offering a helping hand.

Is it safe for me to remove the two other files detected by Kapersky
C:\WINDOWS\Driver Cache\i386\driver.cab Infected: not-a-virus:Monitor.Win32.UberKeylogger.b 1

This one is a false positive that needs to be ignored as the file is a legitimate Microsoft creation - OOOPS!

C:\WINDOWS\system32\omniband.dll Infected: not-a-virus:AdWare.Win32.BlazeFind.e 1

This one can go.

I see from your uninstall list that you have a copy of Ad-aware 6 Professional. As far as i'm aware it doesn't update any more so it's useless and will need to be removed. There is a newer version that is free, but i'd stick with MBAM as it does a better job, in my opinion. If you prefer Ad-Aware, then feel free - you can have both if you wish.

I think that you are about done as I can't see anything else in your log. As long as the PC is behaving itself, I want you to run your PC as normal for a few days and when you are happy that everything is fine, do the following:

Disable System Restore,
Reboot your PC,
Re-enable System Restore,
Create a Restore Point - this will give a clean one should you need it in the future.
A tutorial for System Restore is available here.

The reason for waiting is that if removing the malware has caused a problem, which it occasionally does, you can put your PC back to how it was before the fix. This will re-install the malware, but an infected PC is better than an expensive paperweight!

Some bedtime reading: This is a very good tutorial about keeping your computer safe and secure on the internet.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI