Author Topic: Worms, Trojans (A crapload of Spyware, Adds ETC!)  (Read 2111 times)

Offline kold_flame

  • Newbie
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
Worms, Trojans (A crapload of Spyware, Adds ETC!)
« on: January 08, 2006, 10:09:28 PM »
Ok, well I have been VERY careful when surfing on the net, but recently my sis downloaded Morpheus and...well she is just retarded when it comes to computers. So whatever she clicked...I have been getting plumeted with adds and that WinFix 2006 Crap...oh boy.

Well the first thing I did was scan my Spybot S&D then Ad-Aware SE...they found alot of junk, but they STILL have been popping out!

WinFix and Zeno & elitemedia have been tag teaming all day, it HAS been very low, but I never get adds...even at my homepage!

I looked here on the Forum and used some of your tips to use in SafeMode with CLEAN UP! and Ewido, it searched very well, with the majority of infected files being from:

[color=\"#FF0000\"]C://Documents & Settings/welcome/Complete [/color](and I cant find that folder!)

But after Ewido ends its scan, it then says that the files infected cannot be removed...and must be remove the ENTIRE Archive...so that means I HAVE to click 6500 (a rough estimate on my infections) times!

So can anyone please help me make a fresh start and get rid of these buggers? Its like they never cease to end, they practically regenerate! Ewido found them all but then GAVE me that problem!



I dont have HiJack This - so that might be a problem too. [color=\"#33CC00\"]I will give you my Ad-Aware SE scan.[/color]

Ad-Aware SE Build 1.06r1
Logfile Created on:Sunday, January 08, 2006 3:30:11 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R85 04.01.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Adware.ZenoSearch(TAC index:4):1 total references
MRU List(TAC index:0):9 total references
Tracking Cookie(TAC index:3):6 total references
Win32.P2P-Worm.Alcan.a(TAC index:8):9 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects


1-8-2006 3:30:11 PM - Scan started. (Full System Scan)

 MRU List Object Recognized!
    Location:          : S-1-5-21-1512123046-3571661679-3809596110-1005\software\microsoft\direct3d\mostrecentapplication
    Description        : most recent application to use microsoft direct3d


 MRU List Object Recognized!
    Location:          : software\microsoft\direct3d\mostrecentapplication
    Description        : most recent application to use microsoft direct3d


 MRU List Object Recognized!
    Location:          : S-1-5-21-1512123046-3571661679-3809596110-1005\software\microsoft\direct3d\mostrecentapplication
    Description        : most recent application to use microsoft direct X


 MRU List Object Recognized!
    Location:          : software\microsoft\direct3d\mostrecentapplication
    Description        : most recent application to use microsoft direct X


 MRU List Object Recognized!
    Location:          : software\microsoft\directdraw\mostrecentapplication
    Description        : most recent application to use microsoft directdraw


 MRU List Object Recognized!
    Location:          : S-1-5-21-1512123046-3571661679-3809596110-1005\software\microsoft\directinput\mostrecentapplication
    Description        : most recent application to use microsoft directinput


 MRU List Object Recognized!
    Location:          : S-1-5-21-1512123046-3571661679-3809596110-1005\software\microsoft\directinput\mostrecentapplication
    Description        : most recent application to use microsoft directinput


 MRU List Object Recognized!
    Location:          : S-1-5-21-1512123046-3571661679-3809596110-1005\software\microsoft\internet explorer\typedurls
    Description        : list of recently entered addresses in microsoft internet explorer


 MRU List Object Recognized!
    Location:          : S-1-5-21-1512123046-3571661679-3809596110-1005\software\microsoft\windows media\wmsdk\general
    Description        : windows media sdk


Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [smss.exe]
    FilePath           : \SystemRoot\System32\
    ProcessID          : 348
    ThreadCreationTime : 1-8-2006 6:45:46 PM
    BasePriority       : Normal


#:2 [csrss.exe]
    FilePath           : \??\C:\WINDOWS\system32\
    ProcessID          : 572
    ThreadCreationTime : 1-8-2006 6:45:48 PM
    BasePriority       : Normal


#:3 [winlogon.exe]
    FilePath           : \??\C:\WINDOWS\system32\
    ProcessID          : 596
    ThreadCreationTime : 1-8-2006 6:45:49 PM
    BasePriority       : High


#:4 [services.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 640
    ThreadCreationTime : 1-8-2006 6:45:51 PM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Services and Controller app
    InternalName       : services.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : services.exe

#:5 [lsass.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 652
    ThreadCreationTime : 1-8-2006 6:45:51 PM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : LSA Shell (Export Version)
    InternalName       : lsass.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : lsass.exe

#:6 [svchost.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 820
    ThreadCreationTime : 1-8-2006 6:45:53 PM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:7 [svchost.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 868
    ThreadCreationTime : 1-8-2006 6:45:54 PM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:8 [svchost.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 964
    ThreadCreationTime : 1-8-2006 6:45:54 PM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:9 [svchost.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 1028
    ThreadCreationTime : 1-8-2006 6:45:54 PM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:10 [svchost.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 1108
    ThreadCreationTime : 1-8-2006 6:45:55 PM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:11 [lexbces.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 1812
    ThreadCreationTime : 1-8-2006 6:46:00 PM
    BasePriority       : Normal
    FileVersion        : 8.18
    ProductVersion     : 8.18
    ProductName        : MarkVision for Windows (32 bit)
    CompanyName        : Lexmark International, Inc.
    FileDescription    : LexBce Service
    InternalName       : LexBce Service
    LegalCopyright     : © 1993 - 2003 Lexmark International, Inc.
    OriginalFilename   : LexBceS.exe

#:12 [spoolsv.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 1920
    ThreadCreationTime : 1-8-2006 6:46:03 PM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
    ProductVersion     : 5.1.2600.2696
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Spooler SubSystem App
    InternalName       : spoolsv.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : spoolsv.exe

#:13 [lexpps.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 1928
    ThreadCreationTime : 1-8-2006 6:46:03 PM
    BasePriority       : Normal
    FileVersion        : 8.18
    ProductVersion     : 8.18
    ProductName        : MarkVision for Windows (32 bit)
    CompanyName        : Lexmark International, Inc.
    FileDescription    : LEXPPS.EXE
    InternalName       : LEXPPS
    LegalCopyright     : © 1993 - 2003 Lexmark International, Inc.
    OriginalFilename   : LEXPPS.EXE
    Comments           : MarkVision for Windows '95 New P2P Server  (32-bit)

#:14 [explorer.exe]
    FilePath           : C:\WINDOWS\
    ProcessID          : 1956
    ThreadCreationTime : 1-8-2006 6:46:03 PM
    BasePriority       : Normal
    FileVersion        : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 6.00.2900.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Windows Explorer
    InternalName       : explorer
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : EXPLORER.EXE

#:15 [ccsetmgr.exe]
    FilePath           : C:\Program Files\Common Files\Symantec Shared\
    ProcessID          : 304
    ThreadCreationTime : 1-8-2006 6:46:15 PM
    BasePriority       : Normal
    FileVersion        : 2.1.5.1
    ProductVersion     : 2.1.5.1
    ProductName        : Common Client
    CompanyName        : Symantec Corporation
    FileDescription    : Common Client Settings Manager Service
    InternalName       : ccSetMgr
    LegalCopyright     : Copyright © 2000-2003 Symantec Corporation. All rights reserved.
    OriginalFilename   : ccSetMgr.exe

#:16 [navapsvc.exe]
    FilePath           : C:\Program Files\Norton AntiVirus\
    ProcessID          : 440
    ThreadCreationTime : 1-8-2006 6:46:20 PM
    BasePriority       : Normal
    FileVersion        : 10.00.2
    ProductVersion     : 10.00.2
    ProductName        : Norton AntiVirus
    CompanyName        : Symantec Corporation
    FileDescription    : Norton AntiVirus Auto-Protect Service
    InternalName       : NAVAPSVC
    LegalCopyright     : Norton AntiVirus 2004 for Windows 98/ME/2000/XP Copyright © 2003 Symantec Corporation. All rights reserved.
    OriginalFilename   : NAVAPSVC.EXE

#:17 [savscan.exe]
    FilePath           : C:\Program Files\Norton AntiVirus\
    ProcessID          : 1180
    ThreadCreationTime : 1-8-2006 6:46:26 PM
    BasePriority       : Normal

    ProductVersion     : 9.2
    ProductName        : Symantec AntiVirus AutoProtect
    CompanyName        : Symantec Corporation
    FileDescription    : Symantec AntiVirus Scanner
    InternalName       : SAVSCAN
    LegalCopyright     : Copyright © 2004 Symantec Corporation
    OriginalFilename   : SAVSCAN.EXE

#:18 [svchost.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 1284
    ThreadCreationTime : 1-8-2006 6:46:29 PM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:19 [symlcsvc.exe]
    FilePath           : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\
    ProcessID          : 1348
    ThreadCreationTime : 1-8-2006 6:46:30 PM
    BasePriority       : Normal
    FileVersion        : 1, 8, 48, 77
    ProductVersion     : 1, 8, 48, 77
    ProductName        : Symantec Core Component
    CompanyName        : Symantec Corporation
    FileDescription    : Symantec Core Component
    InternalName       : symlcsvc
    LegalCopyright     : Copyright © 2003
    OriginalFilename   : symlcsvc.exe

#:20 [wdfmgr.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 1428
    ThreadCreationTime : 1-8-2006 6:46:35 PM
    BasePriority       : Normal
    FileVersion        : 5.2.3790.1230 built by: DNSRV(bld4act)
    ProductVersion     : 5.2.3790.1230
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Windows User Mode Driver Manager
    InternalName       : WdfMgr
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : WdfMgr.exe

#:21 [ccevtmgr.exe]
    FilePath           : C:\Program Files\Common Files\Symantec Shared\
    ProcessID          : 1508
    ThreadCreationTime : 1-8-2006 6:46:36 PM
    BasePriority       : Normal
    FileVersion        : 2.1.5.1
    ProductVersion     : 2.1.5.1
    ProductName        : Common Client
    CompanyName        : Symantec Corporation
    FileDescription    : Common Client Event Manager Service
    InternalName       : ccEvtMgr
    LegalCopyright     : Copyright © 2000-2003 Symantec Corporation. All rights reserved.
    OriginalFilename   : ccEvtMgr.exe

#:22 [symwsc.exe]
    FilePath           : C:\Program Files\Common Files\Symantec Shared\Security Center\
    ProcessID          : 1616
    ThreadCreationTime : 1-8-2006 6:46:40 PM
    BasePriority       : Normal
    FileVersion        : 2005.1.2.20
    ProductVersion     : 2005.1
    ProductName        : Norton Security Center
    CompanyName        : Symantec Corporation
    FileDescription    : Norton Security Center Service
    InternalName       : SymWSC.exe
    LegalCopyright     : Copyright © 1997-2004 Symantec Corporation
    OriginalFilename   : SymWSC.exe

#:23 [wscntfy.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 544
    ThreadCreationTime : 1-8-2006 6:46:53 PM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Windows Security Center Notification App
    InternalName       : wscntfy.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : wscntfy.exe

#:24 [alg.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 864
    ThreadCreationTime : 1-8-2006 6:46:56 PM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Application Layer Gateway Service
    InternalName       : ALG.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : ALG.exe

#:25 [ccapp.exe]
    FilePath           : C:\Program Files\Common Files\Symantec Shared\
    ProcessID          : 1468
    ThreadCreationTime : 1-8-2006 6:47:02 PM
    BasePriority       : Normal
    FileVersion        : 2.1.5.1
    ProductVersion     : 2.1.5.1
    ProductName        : Common Client
    CompanyName        : Symantec Corporation
    FileDescription    : Common Client User Session
    InternalName       : ccApp
    LegalCopyright     : Copyright © 2000-2003 Symantec Corporation. All rights reserved.
    OriginalFilename   : ccApp.exe

#:26 [jusched.exe]
    FilePath           : C:\Program Files\Java\j2re1.4.2_03\bin\
    ProcessID          : 1104
    ThreadCreationTime : 1-8-2006 6:47:02 PM
    BasePriority       : Normal


#:27 [winupdates.exe]
    FilePath           : C:\Program Files\winupdates\
    ProcessID          : 1392
    ThreadCreationTime : 1-8-2006 6:47:05 PM
    BasePriority       : Normal
    FileVersion        : 3.06
    ProductVersion     : 3.06
    ProductName        : inno setup
    CompanyName        : inno setup
    FileDescription    : inno setup
    InternalName       : Setup
    LegalCopyright     : inno setup
    LegalTrademarks    : inno setup
    OriginalFilename   : Setup.exe
    Comments           : inno setup

#:28 [viewmgr.exe]
    FilePath           : C:\Program Files\Viewpoint\Viewpoint Manager\
    ProcessID          : 2124
    ThreadCreationTime : 1-8-2006 6:47:06 PM
    BasePriority       : Normal
    FileVersion        : 2, 0, 0, 42
    ProductVersion     : 2, 0, 0, 42
    ProductName        : Viewpoint Manager
    CompanyName        : Viewpoint Corporation
    FileDescription    : ViewMgr
    InternalName       : Viewpoint Manager
    LegalCopyright     : Copyright © 2004
    OriginalFilename   : ViewMgr.exe
    Comments           : Viewpoint Manager

#:29 [realsched.exe]
    FilePath           : C:\Program Files\Common Files\Real\Update_OB\
    ProcessID          : 2188
    ThreadCreationTime : 1-8-2006 6:47:08 PM
    BasePriority       : Normal
    FileVersion        : 0.1.0.3208
    ProductVersion     : 0.1.0.3208
    ProductName        : RealPlayer (32-bit)
    CompanyName        : RealNetworks, Inc.
    FileDescription    : RealNetworks Scheduler
    InternalName       : schedapp
    LegalCopyright     : Copyright © RealNetworks, Inc. 1995-2004
    LegalTrademarks    : RealAudio(tm) is a trademark of RealNetworks, Inc.
    OriginalFilename   : realsched.exe

#:30 [ituneshelper.exe]
    FilePath           : C:\Program Files\iTunes\
    ProcessID          : 2244
    ThreadCreationTime : 1-8-2006 6:47:09 PM
    BasePriority       : Normal
    FileVersion        : 6.0.1.3
    ProductVersion     : 6.0.1.3
    ProductName        : iTunes
    CompanyName        : Apple Computer, Inc.
    FileDescription    : iTunesHelper Module
    InternalName       : iTunesHelper
    LegalCopyright     : © 2003-2005 Apple Computer, Inc. All Rights Reserved.
    OriginalFilename   : iTunesHelper.exe

#:31 [elitemediapop.exe]
    FilePath           : C:\WINDOWS\
    ProcessID          : 2372
    ThreadCreationTime : 1-8-2006 6:47:12 PM
    BasePriority       : Normal
    FileVersion        : 6.04
    ProductVersion     : 6.04
    ProductName        : pop64
    CompanyName        : Network1
    InternalName       : elitemediapop
    OriginalFilename   : elitemediapop.exe

#:32 [lwintsap.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 2432
    ThreadCreationTime : 1-8-2006 6:47:14 PM
    BasePriority       : Normal
    FileVersion        : 0.42
    ProductVersion     : 1.0b
    LegalCopyright     : Copyright © 2004

#:33 [ipodservice.exe]
    FilePath           : C:\Program Files\iPod\bin\
    ProcessID          : 2456
    ThreadCreationTime : 1-8-2006 6:47:14 PM
    BasePriority       : Normal
    FileVersion        : 6.0.1.3
    ProductVersion     : 6.0.1.3
    ProductName        : iTunes
    CompanyName        : Apple Computer, Inc.
    FileDescription    : iPodService Module
    InternalName       : iPodService
    LegalCopyright     : © 2003-2005 Apple Computer, Inc. All Rights Reserved.
    OriginalFilename   : iPodService.exe

#:34 [kodak software updater.exe]
    FilePath           : C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\
    ProcessID          : 2760
    ThreadCreationTime : 1-8-2006 6:47:20 PM
    BasePriority       : Normal


#:35 [iexplore.exe]
    FilePath           : C:\Program Files\Internet Explorer\
    ProcessID          : 3664
    ThreadCreationTime : 1-8-2006 6:48:16 PM
    BasePriority       : Normal
    FileVersion        : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 6.00.2900.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Internet Explorer
    InternalName       : iexplore
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : IEXPLORE.EXE

#:36 [realplay.exe]
    FilePath           : C:\Program Files\Real\RealPlayer\
    ProcessID          : 2440
    ThreadCreationTime : 1-8-2006 7:48:42 PM
    BasePriority       : Idle
    FileVersion        : 6.0.12.1056
    ProductVersion     : 6.0.12.1056
    ProductName        : RealPlayer (32-bit)
    CompanyName        : RealNetworks, Inc.
    FileDescription    : RealPlayer
    InternalName       : REALPLAY
    LegalCopyright     : Copyright © RealNetworks, Inc. 1995-2004
    LegalTrademarks    : RealAudio(tm) is a trademark of RealNetworks, Inc.
    OriginalFilename   : REALPLAY.EXE

#:37 [ad-aware.exe]
    FilePath           : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
    ProcessID          : 4032
    ThreadCreationTime : 1-8-2006 10:29:58 PM
    BasePriority       : Normal
    FileVersion        : 6.2.0.236
    ProductVersion     : SE 106
    ProductName        : Lavasoft Ad-Aware SE
    CompanyName        : Lavasoft Sweden
    FileDescription    : Ad-Aware SE Core application
    InternalName       : Ad-Aware.exe
    LegalCopyright     : Copyright © Lavasoft AB Sweden
    OriginalFilename   : Ad-Aware.exe
    Comments           : All Rights Reserved

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 9


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

 Adware.ZenoSearch Object Recognized!
    Type               : RegValue
    Data               :
    TAC Rating         : 4
    Category           : Adware
    Comment            : "BrowserUpdateSched"
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : software\microsoft\windows\currentversion\run
    Value              : BrowserUpdateSched

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 10


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 10


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : [email protected][1].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : Hits:1
    Value              : Cookie:[email protected]/
    Expires            : 1-8-2007 11:59:10 AM
    LastSync           : Hits:1
    UseCount           : 0
    Hits               : 1

 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : [email protected][1].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : Hits:6
    Value              : Cookie:[email protected]/
    Expires            : 1-8-2007 12:32:50 PM
    LastSync           : Hits:6
    UseCount           : 0
    Hits               : 6

 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : welcome@zedo[2].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : Hits:9
    Value              : Cookie:[email protected]/
    Expires            : 1-6-2016 12:57:58 AM
    LastSync           : Hits:9
    UseCount           : 0
    Hits               : 9

 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : welcome@realmedia[1].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : Hits:11
    Value              : Cookie:[email protected]/
    Expires            : 12-31-2020 5:00:00 PM
    LastSync           : Hits:11
    UseCount           : 0
    Hits               : 11

 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : welcome@trafficmp[2].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : Hits:9
    Value              : Cookie:[email protected]/
    Expires            : 1-8-2007 3:37:56 PM
    LastSync           : Hits:9
    UseCount           : 0
    Hits               : 9

 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : welcome@pro-market[1].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : Hits:4
    Value              : Cookie:[email protected]/
    Expires            : 5-31-2030 5:00:00 PM
    LastSync           : Hits:4
    UseCount           : 0
    Hits               : 4

Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 6
Objects found so far: 16



Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

 Win32.P2P-Worm.Alcan.a Object Recognized!
    Type               : File
    Data               : bszip.dll
    TAC Rating         : 8
    Category           : Worm
    Comment            :
    Object             : C:\WINDOWS\system32\
    FileVersion        : 3.0.2.0
    ProductVersion     : 3.02
    ProductName        : BigSpeed Zip DLL
    CompanyName        : BigSpeedSoft
    InternalName       : bszip.dll
    LegalCopyright     : © BigSpeedSoft
    LegalTrademarks    : BigSpeed is a trademark of BigSpeedSoft
    OriginalFilename   : bszip.dll


Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 17


Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
11 entries scanned.
New critical objects:0
Objects found so far: 17




Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

 Win32.P2P-Worm.Alcan.a Object Recognized!
    Type               : Regkey
    Data               :
    TAC Rating         : 8
    Category           : Worm
    Comment            :
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : software\microsoft\downloadmanager

 Win32.P2P-Worm.Alcan.a Object Recognized!
    Type               : File
    Data               : cmd.com
    TAC Rating         : 8
    Category           : Worm
    Comment            :
    Object             : C:\WINDOWS\system32\



 Win32.P2P-Worm.Alcan.a Object Recognized!
    Type               : File
    Data               : netstat.com
    TAC Rating         : 8
    Category           : Worm
    Comment            :
    Object             : C:\WINDOWS\system32\



 Win32.P2P-Worm.Alcan.a Object Recognized!
    Type               : File
    Data               : ping.com
    TAC Rating         : 8
    Category           : Worm
    Comment            :
    Object             : C:\WINDOWS\system32\



 Win32.P2P-Worm.Alcan.a Object Recognized!
    Type               : File
    Data               : regedit.com
    TAC Rating         : 8
    Category           : Worm
    Comment            :
    Object             : C:\WINDOWS\system32\



 Win32.P2P-Worm.Alcan.a Object Recognized!
    Type               : File
    Data               : taskkill.com
    TAC Rating         : 8
    Category           : Worm
    Comment            :
    Object             : C:\WINDOWS\system32\



 Win32.P2P-Worm.Alcan.a Object Recognized!
    Type               : File
    Data               : tasklist.com
    TAC Rating         : 8
    Category           : Worm
    Comment            :
    Object             : C:\WINDOWS\system32\



 Win32.P2P-Worm.Alcan.a Object Recognized!
    Type               : File
    Data               : tracert.com
    TAC Rating         : 8
    Category           : Worm
    Comment            :
    Object             : C:\WINDOWS\system32\



Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 8
Objects found so far: 25

4:10:19 PM Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:40:07.610
Objects scanned:183828
Objects identified:16
Objects ignored:0
New critical objects:16

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Worms, Trojans (A crapload of Spyware, Adds ETC!)
« Reply #1 on: January 08, 2006, 10:12:20 PM »
Can you do the following please

Post a Hijackthis log back to this thread

Here's the Instructions

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline kold_flame

  • Newbie
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
Worms, Trojans (A crapload of Spyware, Adds ETC!)
« Reply #2 on: January 08, 2006, 10:24:13 PM »
Logfile of HijackThis v1.99.1
Scan saved at 8:21:33 PM, on 1/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\lwintsap.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.elp.rr.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ATLDistrib Object - {2353FCBC-012D-487B-8BF3-865C0929FBEB} - C:\WINDOWS\system32\geedb.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\lwintsap.exe FI002
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\lwintsap.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} - http://www.miniclip.com/bestfriends/retro64_loader.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/2438d7c7946c22...ip/RdxIE601.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppD...sharingctrl.cab
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} (Mirar_Dummy_ATS1 Class) - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...StatsClient.cab
O20 - Winlogon Notify: geedb - C:\WINDOWS\system32\geedb.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Worms, Trojans (A crapload of Spyware, Adds ETC!)
« Reply #3 on: January 08, 2006, 11:15:58 PM »
Good job kold_flame
Can I have you first disable Norton's ScriptBlocking please
It may, and probably will interfere with any of the fixes we are about to try
You can reenable this after we have you clean
Code: [Select]
To disable Norton AntiVirus Script Blocking

   1. Start Norton AntiVirus.
 If Norton AntiVirus is installed as part of Norton SystemWorks or Norton Internet Security, then start that program.
   2. Click Options.
 If you see a menu, click Norton AntiVirus.
   3. In the left pane, click Script Blocking.
   4. In the right pane, uncheck Enable Script Blocking (recommended).
   5. Click OK.

I need you too download a couple small tools please

Please download VundoFix.exe to your desktop.
*Double-click VundoFix.exe to extract the files
*This will create a VundoFix folder on your desktop.
We'll need this later

When I ask you too download a zip file, make sure you choose SAVE TO DISK rather than Open
Please download miekiemoes' LQfix batch here:
http://users.telenet.be/bluepatchy/miekiem...tools/LQfix.zip
Unzip it to the desktop but do NOT run it yet.

Can you open "MyComputer"
Double click to open Local Disk C: drive
Right click an empty spot  and left click NEW>>Folder
A new folder will be placed in the C: folder , name it BFU
So you now have C:\BFU

Download and save p2pnetwork.zip
Then UNZIP it to the BFU Folder
So you now have p2pnetwork.bfu extracted to the BFU folder

Download and save and then UNZIP to the BFU folder
BFU.zip
So you now have BFU.exe extracted

Now that you have the extra tools we need
Can you make sure that you check for updates with Ewido before we begin
Close out Ewido once it is updated

Please  save these instructions to a Notepad file and save it to your Desktop for reference
or Print them out!

This is important as we must do this all in safe mode if possible, without networking
And you must follow all instructions properly

RESTART your Computer into SAFE MODE
You can do this by tapping the F8 key as the system is restarting, just before Windows loads
Choose Safe mode from the startup menu and hit Enter

Access your Add/Remove via Control Panel and remove if found
Enhanced Ads by Zeno removal
Zeno Search Assistant removal

Additionally, I would remove if found
Viewpoint
Viewpoint Manager
Viewpoint Media Player
<-Viewpoint isn't  necessarily bad, but are installed normally without users consent, I would opt to remove them

Stay in safe mode
==Open the BFU folder
Double click to run BFU.exe
Use the "Open Script file" button (the folder icon next to Scriptfile to execute)
Navigate to p2pnetwork.bfu in the BFU folder
Right click p2pnetwork.bfu and choose Select
In Brute Force Uninstaller select Execute
Let it finish then Exit

==Double click on LQFix.bat you unzipped earlier to your desktop
Let it finish, A window will open and close

Set Windows To Show Hidden Files and Folders
    * Click Start.
    * Open My Computer.
    * Select the Tools menu and click Folder Options.
    * Select the View Tab.
    * Under the Hidden files and folders heading select Show hidden files and folders.
    * Uncheck the Hide protected operating system files (recommended) option.
    * Uncheck the Hide Extensions for known file types
    * Click Yes to confirm.
    * Click OK.
Navigate to the
C://Documents & Settings/welcome/Complete <-this folder
You may see it now with Windows set to show hidden files and folders
Open  the "complete" folder and delete any ZIP files you didn't manually download yourself to this folder

Also find this file and delete it if found
C:\WINDOWS\system32\lwintsap.exe <-this file

==Open the VundoFix folder and doubleclick on KillVundo.bat
*You will first be presented with a warning.
It should look like this
Quote
[color=\"blue\"]VundoFix by Atri
By using VundoFix you agree that you are doing so at your own risk
Press enter to continue....
[/color]

* At this point press enter one time.

* Next you will see:
Quote
[color=\"blue\"]Please Type in the filepath as instructed by the forum staff
and then press enter:[/color]

*At this point please type the following file path (make sure to enter it exactly as below!):
    C:\WINDOWS\system32\geedb.dll

    *Press [color=\"red\"]Enter[/color] to continue with the fix.

    *Next you will see:
    Quote
    [color=\"blue\"]Please type in the second filepath as instructed by the forum
    staff then press enter: [/color]
    *At this point please type the following file path (make sure to enter it exactly as below!):
    C:\WINDOWS\system32\bdeeg.*
    [/list]*Press [color=\"red\"]Enter[/color] to continue with the fix.
    [/list]*The fix will run then HijackThis will open, if it does not open automatically please open it manually.
    *In HiJackThis, please place a check next to the following items and click FIX CHECKED:
      R3 - Default URLSearchHook is missing

      O2 - BHO: ATLDistrib Object - {2353FCBC-012D-487B-8BF3-865C0929FBEB} - C:\WINDOWS\system32\geedb.dll
      O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
      O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

      O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\lwintsap.exe FI002
      O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe
      O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\lwintsap.exe
      O15 - Trusted Zone: *.elitemediagroup.net
      O15 - Trusted Zone: http://click.getmirar.com (HKLM)
      O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
      O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
      O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/2438d7c7946c22...ip/RdxIE601.cab
      O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} (Mirar_Dummy_ATS1 Class) - http://awbeta.net-nucleus.com/FIX/WinATS.cab

      O20 - Winlogon Notify: geedb - C:\WINDOWS\system32\geedb.dll

      [/list]*After you have fixed these items, close Hijackthis.
      *Press enter to exit the program

      Remain in safe mode
      ==Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
      Set the program up as follows:
      Click "Options..."
      Move the arrow down to "Custom CleanUp!"
      Put a check next to the following (Make sure nothing else is checked!):

          * Empty Recycle Bins
          * Delete Cookies
          * Delete Prefetch files
          * Cleanup! All Users

      Click OK
      Press the CleanUp! button to start the program.
      When it's done, decline to log off or restart the computer

      ==Open Ewido Security Suite
      Click on the Scanner button on the left menu
      Select Complete System Scan
      *If Ewido finds something it will prompt you with "Infected Object found"
      Ensure the following are Selected
        *1. Perform Action = Remove
        *2. Create Encrypted Backup in Quarantine (Recommended)
        *3. Perform action with all infections
       
        Then click OK
      When Ewido has finished it's scan click the "Save Report" button
      Save the report to desktop
      Exit Ewido
      NOTE: When Ewido is running, don't open any other Windows

      Open Ad-aware and run a scan, let it fix all Critical objects

      Reboot back to Normal mode

      Back in windows
      I need to see the following logs please

      1. Post a fresh hijackthis log
      2. Post vundofix.txt file from the vundofix folder into this topic
      3. Post the report from Ewido's
      « Last Edit: January 08, 2006, 11:21:11 PM by guestolo »

      Do you want to post your own logs from FRST?

      Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


      Offline kold_flame

      • Newbie
      • *
      • Posts: 5
      • Karma: +0/-0
        • View Profile
      Worms, Trojans (A crapload of Spyware, Adds ETC!)
      « Reply #4 on: January 11, 2006, 05:20:45 PM »
      [color=\"#009900\"]Ok, I did everything that you said, except for the p2p BFU thing, cuz I extract it but it doesnt open up...I dont know how to open it as a .exe ...so lol. And as for Ewido, I told you about the problem in the "Complete" Folder, are you serious!? Everything, every stream or d/l is saved in there!? I have like all this movie trailers n crap like that, isnt it slowing my comp down? As for Ewido, when it finalizes the search, I get the Pop up if I want to delete it (ARCHIVE)...and I HAVE to click on YES OR NO...there isnt "Yes to All"...so its gonna b a prob.

      Well this is my recent HJT
      [/color]

      Logfile of HijackThis v1.99.1
      Scan saved at 3:15:56 PM, on 1/11/2006
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\LEXBCES.EXE
      C:\WINDOWS\system32\LEXPPS.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      C:\Program Files\ewido anti-malware\ewidoctrl.exe
      C:\Program Files\Norton AntiVirus\navapsvc.exe
      C:\Program Files\Norton AntiVirus\SAVScan.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Messenger\msmsgs.exe
      C:\HJT\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.elp.rr.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
      R3 - Default URLSearchHook is missing
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
      O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
      O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
      O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
      O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
      O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\pkpyry.exe reg_run
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
      O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab
      O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} - http://www.miniclip.com/bestfriends/retro64_loader.dll
      O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
      O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
      O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppD...sharingctrl.cab
      O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...StatsClient.cab
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
      O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
      O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
      O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

      Offline guestolo

      • Site Donator
      • Administrator
      • Hero Member
      • *****
      • Posts: 16034
      • Karma: +1/-0
        • View Profile
        • http://
      Worms, Trojans (A crapload of Spyware, Adds ETC!)
      « Reply #5 on: January 11, 2006, 08:35:33 PM »
      Quote
      Ok, I did everything that you said, except for the p2p BFU thing, cuz I extract it but it doesnt open up

      I have no idea what your talking about, did you print my instructions or save them too a Notepad file for reference?
      If not, you should have, because you surely didn't do everything I said

      Here's what I said
      Quote
      Download and save p2pnetwork.zip
      Then UNZIP it to the BFU Folder
      So you now have p2pnetwork.bfu extracted to the BFU folder

      As you can see, no mention of running p2pnetwork.bfu

      Then I said
      Quote
      Download and save and then UNZIP to the BFU folder
      BFU.zip
      So you now have BFU.exe extracted

      Ok, now you have BFU.exe and p2pnetwork.bfu extracted to the C:\BFU folder
      If not, you did it wrong

      To run it I said this
      Quote
      Open the BFU folder
      Double click to run BFU.exe
      Use the "Open Script file" button (the folder icon next to Scriptfile to execute)
      Navigate to p2pnetwork.bfu in the BFU folder
      Right click p2pnetwork.bfu and choose Select
      In Brute Force Uninstaller select Execute
      Let it finish then Exit

      I think you better go back up to my instructions I posted earlier
      Whatever you missed doing properly, redo  the steps

      NOTE: Allow Ewido to remove the Archives

      You said this
      Quote
      I told you about the problem in the "Complete" Folder, are you serious!? Everything, every stream or d/l is saved in there!? I have like all this movie trailers n crap like that, isnt it slowing my comp down? As for Ewido

      I told you to do this
      Quote
      Navigate to the
      C://Documents & Settings/welcome/Complete <-this folder
      You may see it now with Windows set to show hidden files and folders
      Open the "complete" folder and delete any ZIP files you didn't manually download yourself to this folder

      What don't you understand about this???

      Your log is still not clean, PRINT the above instructions so you can better understand them in my other reply to you

      I asked for this
      Quote
      Open Ewido Security Suite
      Click on the Scanner button on the left menu
      Select Complete System Scan
      *If Ewido finds something it will prompt you with "Infected Object found"
      Ensure the following are Selected
      *1. Perform Action = Remove
      *2. Create Encrypted Backup in Quarantine (Recommended)
      *3. Perform action with all infections

      Then click OK
      When Ewido has finished it's scan click the "Save Report" button
      Save the report to desktop
      Exit Ewido
      NOTE: When Ewido is running, don't open any other Windows

      And then this
      Quote
      1. Post a fresh hijackthis log
      2. Post vundofix.txt file from the vundofix folder into this topic
      3. Post the report from Ewido's

      Thanks for the new Hijackthis log, didn't you forget something
      Where is the Ewido report I asked you too save in safe mode to desktop????
      Where is the vundofix.txt file from the vundofix folder???

      I would have to say that instructions weren't followed properly

      Please post the logs I asked for

      I still need to see a couple more logs, but I won't ask for them right now until you can post the above
      I don't need it too confuse you
      « Last Edit: January 11, 2006, 08:36:44 PM by guestolo »

      Do you want to post your own logs from FRST?

      Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


      Offline kold_flame

      • Newbie
      • *
      • Posts: 5
      • Karma: +0/-0
        • View Profile
      Worms, Trojans (A crapload of Spyware, Adds ETC!)
      « Reply #6 on: January 11, 2006, 10:17:36 PM »
      Sorry about that guestolo, I just read to fast and didn't pay close attention.

      This is the [color=\"#FF0000\"]Vundofix.txt [/color]file you asked for:

      VundoFix V2.15 by Atri
      --------------------------------------------------------------------------------------
       
      Listing files contained in the vundofix folder.
      --------------------------------------------------------------------------------------
       
      killvundo.bat
      process.exe
      ReadMe.txt
      vundo.reg
      vundofix.txt
       
      --------------------------------------------------------------------------------------
       
      Filepaths entered
      --------------------------------------------------------------------------------------
       
      The filepath entered was C:\WINDOWS\system32\geedb.dll
       
      The second filepath entered was C:\WINDOWS\system32\bdeeg.*
       
      --------------------------------------------------------------------------------------
       
      Log from Process
      --------------------------------------------------------------------------------------
       

      Killing PID 128 'smss.exe'

      Killing PID 1296 'explorer.exe'


      Killing PID 204 'winlogon.exe'
      --------------------------------------------------------------------------------------
       
      C:\WINDOWS\system32\geedb.dll Deleted sucessfully.
      C:\WINDOWS\system32\bdeeg.* Deleted sucessfully.
       
      Fixing Registry
      --------------------------------------------------------------------------------------
       



      And as for the Ewido, the thing is, when the SCAN is finalizing it asks me, "Dou you want to delete the Archive completely?" YES / NO (Yes, it does mispell 'Do')

      and it asks me literally 6000 times, due to it being my Complete Folder, so I can never get a Log for it.


      But I DID download and Run - Spy Sweeper. It killed a bunch of things, and so far no pop ups from Web Nexus. Everything else has stopped, so thanks. If I do get another pop up from those guys, I'll try Ewido again.

      This is the LATEST [color=\"#FF0000\"]High Jack This [/color]
      Log for you, just for good measure.[/b]

      Logfile of HijackThis v1.99.1
      Scan saved at 8:14:17 PM, on 1/11/2006
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\LEXBCES.EXE
      C:\WINDOWS\system32\LEXPPS.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
      C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      C:\Program Files\ewido anti-malware\ewidoctrl.exe
      C:\Program Files\Norton AntiVirus\navapsvc.exe
      C:\Program Files\Norton AntiVirus\SAVScan.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
      C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Messenger\msmsgs.exe
      C:\HJT\HijackThis.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
      R3 - Default URLSearchHook is missing
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
      O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
      O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
      O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
      O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab
      O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} - http://www.miniclip.com/bestfriends/retro64_loader.dll
      O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
      O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
      O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppD...sharingctrl.cab
      O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...StatsClient.cab
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
      O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
      O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
      O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
      O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

      Offline guestolo

      • Site Donator
      • Administrator
      • Hero Member
      • *****
      • Posts: 16034
      • Karma: +1/-0
        • View Profile
        • http://
      Worms, Trojans (A crapload of Spyware, Adds ETC!)
      « Reply #7 on: January 11, 2006, 11:12:29 PM »
      We're still not there

      Did you do this and do it properly

      Quote
      Open the BFU folder
      Double click to run BFU.exe
      Use the "Open Script file" button (the folder icon next to Scriptfile to execute)
      Navigate to p2pnetwork.bfu in the BFU folder
      Right click p2pnetwork.bfu and choose Select
      In Brute Force Uninstaller select Execute
      Let it finish then Exit
      Go back up and read carefully how I  wanted you too create the BFU folder
      Then download and UNZIP 2 files to that folder

      Did you do this before you ran the scan from Ewido's
      The archive files are the zip files I wanted you to remove!!!
      If you didn't manually download them, remove them
      ONLY in the complete folder
      Quote
      Navigate to the
      C://Documents & Settings/welcome/Complete <-this folder
      You may see it now with Windows set to show hidden files and folders
      Open the "complete" folder and delete any ZIP files you didn't manually download yourself to this folder

      We still have a bit more cleaning, but please try and do what I ask
      Are you sure you went back and ran BFU.exe properly
      The way I posted???
      « Last Edit: January 11, 2006, 11:13:24 PM by guestolo »

      Do you want to post your own logs from FRST?

      Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


      Offline kold_flame

      • Newbie
      • *
      • Posts: 5
      • Karma: +0/-0
        • View Profile
      Worms, Trojans (A crapload of Spyware, Adds ETC!)
      « Reply #8 on: January 12, 2006, 05:19:39 PM »
      Can I just delete the Complete Folder? There is like a crap load of stuff (Batman Begins.zip etc) and the scroll pad is like really small. lol. Nothing is in there that i need huh? Theyre all zips.

      Offline guestolo

      • Site Donator
      • Administrator
      • Hero Member
      • *****
      • Posts: 16034
      • Karma: +1/-0
        • View Profile
        • http://
      Worms, Trojans (A crapload of Spyware, Adds ETC!)
      « Reply #9 on: January 12, 2006, 07:00:29 PM »
      Yes, you shouldn't need the "Complete" folder

      Carry on and post all logs back please

      Do you want to post your own logs from FRST?

      Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


      Offline guestolo

      • Site Donator
      • Administrator
      • Hero Member
      • *****
      • Posts: 16034
      • Karma: +1/-0
        • View Profile
        • http://
      Worms, Trojans (A crapload of Spyware, Adds ETC!)
      « Reply #10 on: January 30, 2006, 12:04:45 AM »
      Since the original poster has not returned
      I'll lock this topic

      Do you want to post your own logs from FRST?

      Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here