Need help with Trojan Zblog

Status
Not open for further replies.

Designer A

Solid State Member
Messages
13
I disabled system restore, scanned with Norton and checked the registry per their instructions for values added by Zblog. After that Winpatrol keeps finding a file "hpFCDD.tmp" that keeps trying to execute. I posted this in the wrong forum before..sorry.
Here's my log:
Logfile of HijackThis v1.99.1
Scan saved at 1:04:43 PM, on 1/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\Tablet.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvctrl.exe
C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\WINDOWS\System32\EZSP_PX.EXE
C:\toshiba\ivp\ism\pinger.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\WINDOWS\system32\00THotkey.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\NETGEAR\MA101 USB\WlanMonitor.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\user\My Documents\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
O1 - Hosts: 127.0.0.0 localhost
O1 - Hosts: 127.0.0.2 auditmypc.com
O1 - Hosts: 127.0.0.4 bulletproofsoft.net
O1 - Hosts: 127.0.0.5 camtech2000.net
O1 - Hosts: 127.0.0.6 cexx.org
O1 - Hosts: 127.0.0.7 computercops.us
O1 - Hosts: 127.0.0.8 ct7support.com
O1 - Hosts: 127.0.0.9 doxdesk.com
O1 - Hosts: 127.0.0.20 kellys-korner-xp.com
O1 - Hosts: 127.0.0.21 kephyr.com
O1 - Hosts: 127.0.0.24 lurkhere.com
O1 - Hosts: 127.0.0.25 majorgeeks.com
O1 - Hosts: 127.0.0.26 merijn.org
O1 - Hosts: 127.0.0.27 mjc1.com
O1 - Hosts: 127.0.0.28 moosoft.com
O1 - Hosts: 127.0.0.29 mvps.org
O1 - Hosts: 127.0.0.30 net-integration.net
O1 - Hosts: 127.0.0.31 noadware.net
O1 - Hosts: 127.0.0.32 no-spybot.com
O1 - Hosts: 127.0.0.33 onlinepcfix.com
O1 - Hosts: 127.0.0.34 pchell.com
O1 - Hosts: 127.0.0.35 pestpatrol.com
O1 - Hosts: 127.0.0.36 safer-networking.org
O1 - Hosts: 127.0.0.37 secure.spykiller.com
O1 - Hosts: 127.0.0.38 secureie.com
O1 - Hosts: 127.0.0.39 security.kolla.de
O1 - Hosts: 127.0.0.40 spybot.info
O1 - Hosts: 127.0.0.41 spychecker.com
O1 - Hosts: 127.0.0.42 spychecker.com
O1 - Hosts: 127.0.0.43 spycop.com
O1 - Hosts: 127.0.0.44 spyguard.com
O1 - Hosts: 127.0.0.45 spykiller.com
O1 - Hosts: 127.0.0.46 spyware.co.uk
O1 - Hosts: 127.0.0.47 spyware-cop.com
O1 - Hosts: 127.0.0.48 spywareinfo.com
O1 - Hosts: 127.0.0.49 spywarenuker.com
O1 - Hosts: 127.0.0.50 spywareremove.com
O1 - Hosts: 127.0.0.51 spywareremove.com
O1 - Hosts: 127.0.0.52 stopzillapro.com
O1 - Hosts: 127.0.0.53 sunbelt-software.com
O1 - Hosts: 127.0.0.54 thiefware.com
O1 - Hosts: 127.0.0.55 tomcoyote.org
O1 - Hosts: 127.0.0.56 unwantedlinks.com
O1 - Hosts: 127.0.0.57 webattack.com
O1 - Hosts: 127.0.0.58 wilders.org
O1 - Hosts: 127.0.0.59 www.auditmypc.com
O1 - Hosts: 127.0.0.60 www.bulletproofsoft.net
O1 - Hosts: 127.0.0.61 www.cexx.org
O1 - Hosts: 127.0.0.62 www.computercops.us
O1 - Hosts: 127.0.0.63 www.ct7support.com
O1 - Hosts: 127.0.0.64 www.doxdesk.com
O1 - Hosts: 127.0.0.65 www.eblocs.com
O1 - Hosts: 127.0.0.66 www.enigmasoftwaregroup.com
O1 - Hosts: 127.0.0.67 www.free-spyware-scan.com
O1 - Hosts: 127.0.0.68 www.free-web-browsers.com
O1 - Hosts: 127.0.0.69 www.grc.com
O1 - Hosts: 127.0.0.70 www.grisoft.com
O1 - Hosts: 127.0.0.71 www.hackfaq.org
O1 - Hosts: 127.0.0.72 www.hazeleger.net
O1 - Hosts: 127.0.0.73 www.javacoolsoftware.com
O1 - Hosts: 127.0.0.74 www.kellys-korner-xp.com
O1 - Hosts: 127.0.0.75 www.kephyr.com
O1 - Hosts: 127.0.0.78 www.lurkhere.com
O1 - Hosts: 127.0.0.79 www.majorgeeks.com
O1 - Hosts: 127.0.0.80 www.merijn.org
O1 - Hosts: 127.0.0.81 www.mjc1.com
O1 - Hosts: 127.0.0.82 www.moosoft.com
O1 - Hosts: 127.0.0.83 www.mvps.org
O1 - Hosts: 127.0.0.84 www.net-integration.net
O1 - Hosts: 127.0.0.85 www.noadware.net
O1 - Hosts: 127.0.0.86 www.no-spybot.com
O1 - Hosts: 127.0.0.87 www.onlinepcfix.com
O1 - Hosts: 127.0.0.88 www.pchell.com
O1 - Hosts: 127.0.0.89 www.pestpatrol.com
O1 - Hosts: 127.0.0.90 www.safer-networking.org
O1 - Hosts: 127.0.0.91 www.secureie.com
O1 - Hosts: 127.0.0.92 www.security.kolla.de
O1 - Hosts: 127.0.0.93 www.spybot.info
O1 - Hosts: 127.0.0.94 www.spychecker.com
O1 - Hosts: 127.0.0.95 www.spychecker.com
O1 - Hosts: 127.0.0.96 www.spycop.com
O1 - Hosts: 127.0.0.97 www.spyguard.com
O1 - Hosts: 127.0.0.98 www.spykiller.com
O1 - Hosts: 127.0.0.99 www.spyware.co.uk
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpFCDD.tmp (file missing)
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 28
O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files\Toshiba\ConfigFree\NDSTray.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\EZSP_PX.EXE
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Configuration & Monitor Utility.lnk = C:\Program Files\NETGEAR\MA101 USB\WlanMonitor.exe
O4 - Global Startup: MA101 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA101 USB\WlanMonitor.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Download all by Net Transport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: Download by Net Transport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\System32\Tablet.exe
 
Hi and Welcome to TF

Please DISABLE spybot's teatimer and LEAVE IT OFF until the fix is complete! I need you to also shut down WinPatrol as both with block fixes we are going to make.

Before attacking an adware/spyware problem with hijackthis make sure you have already run the following tools. Download and update the databases on each program before running.

Also make sure you are using the the latest version (1.99.1) of HijackThis and it's installed in it's own folder on the root drive. (C:\HJT)

Please go to at least two of these sites and run an online Virus Scan.
Be sure to have the AutoFix box(s) checked if the site has that option.

http://housecall.trendmicro.com/
http://www3.ca.com/virusinfo/virusscan.aspx
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
http://www.bitdefender.com/scan/license.php
http://us.mcafee.com/root/mfs/default.asp
http://security.symantec.com/sscv6/default.asp?productid=symhome&langid=ie&venid=sym
http://www3.ca.com/virusinfo/virusscan.aspx

Download Hoster http://www.greyknight17.com/spy/Hoster.exe

Download smitRem.exe and save the file to your desktop.
Double click on the file to extract it to it's own folder on the desktop.

Place a shortcut to Panda ActiveScan on your desktop.

Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/

Please read Ewido Setup Instructions
Install it, and update the definitions to the newest files. Do NOT run a scan yet.

If you have not already installed Ad-Aware SE 1.06, follow these download and setup instructions, otherwise, check for updates:
Ad-Aware SE Setup
Don't run it yet!

Next, please reboot your computer in SafeMode by doing the following:
  1. Restart your computer
  2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  3. Instead of Windows loading as normal, a menu should appear
  4. Select the first option, to run Windows in Safe Mode.
Now scan with HJT and place a checkmark next to each of the following items and click FIX CHECKED:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
O1 - Hosts: 127.0.0.0 localhost
O1 - Hosts: 127.0.0.2 auditmypc.com
O1 - Hosts: 127.0.0.4 bulletproofsoft.net
O1 - Hosts: 127.0.0.5 camtech2000.net
O1 - Hosts: 127.0.0.6 cexx.org
O1 - Hosts: 127.0.0.7 computercops.us
O1 - Hosts: 127.0.0.8 ct7support.com
O1 - Hosts: 127.0.0.9 doxdesk.com
O1 - Hosts: 127.0.0.20 kellys-korner-xp.com
O1 - Hosts: 127.0.0.21 kephyr.com
O1 - Hosts: 127.0.0.24 lurkhere.com
O1 - Hosts: 127.0.0.25 majorgeeks.com
O1 - Hosts: 127.0.0.26 merijn.org
O1 - Hosts: 127.0.0.27 mjc1.com
O1 - Hosts: 127.0.0.28 moosoft.com
O1 - Hosts: 127.0.0.29 mvps.org
O1 - Hosts: 127.0.0.30 net-integration.net
O1 - Hosts: 127.0.0.31 noadware.net
O1 - Hosts: 127.0.0.32 no-spybot.com
O1 - Hosts: 127.0.0.33 onlinepcfix.com
O1 - Hosts: 127.0.0.34 pchell.com
O1 - Hosts: 127.0.0.35 pestpatrol.com
O1 - Hosts: 127.0.0.36 safer-networking.org
O1 - Hosts: 127.0.0.37 secure.spykiller.com
O1 - Hosts: 127.0.0.38 secureie.com
O1 - Hosts: 127.0.0.39 security.kolla.de
O1 - Hosts: 127.0.0.40 spybot.info
O1 - Hosts: 127.0.0.41 spychecker.com
O1 - Hosts: 127.0.0.42 spychecker.com
O1 - Hosts: 127.0.0.43 spycop.com
O1 - Hosts: 127.0.0.44 spyguard.com
O1 - Hosts: 127.0.0.45 spykiller.com
O1 - Hosts: 127.0.0.46 spyware.co.uk
O1 - Hosts: 127.0.0.47 spyware-cop.com
O1 - Hosts: 127.0.0.48 spywareinfo.com
O1 - Hosts: 127.0.0.49 spywarenuker.com
O1 - Hosts: 127.0.0.50 spywareremove.com
O1 - Hosts: 127.0.0.51 spywareremove.com
O1 - Hosts: 127.0.0.52 stopzillapro.com
O1 - Hosts: 127.0.0.53 sunbelt-software.com
O1 - Hosts: 127.0.0.54 thiefware.com
O1 - Hosts: 127.0.0.55 tomcoyote.org
O1 - Hosts: 127.0.0.56 unwantedlinks.com
O1 - Hosts: 127.0.0.57 webattack.com
O1 - Hosts: 127.0.0.58 wilders.org
O1 - Hosts: 127.0.0.59 www.auditmypc.com
O1 - Hosts: 127.0.0.60 www.bulletproofsoft.net
O1 - Hosts: 127.0.0.61 www.cexx.org
O1 - Hosts: 127.0.0.62 www.computercops.us
O1 - Hosts: 127.0.0.63 www.ct7support.com
O1 - Hosts: 127.0.0.64 www.doxdesk.com
O1 - Hosts: 127.0.0.65 www.eblocs.com
O1 - Hosts: 127.0.0.66 www.enigmasoftwaregroup.com
O1 - Hosts: 127.0.0.67 www.free-spyware-scan.com
O1 - Hosts: 127.0.0.68 www.free-web-browsers.com
O1 - Hosts: 127.0.0.69 www.grc.com
O1 - Hosts: 127.0.0.70 www.grisoft.com
O1 - Hosts: 127.0.0.71 www.hackfaq.org
O1 - Hosts: 127.0.0.72 www.hazeleger.net
O1 - Hosts: 127.0.0.73 www.javacoolsoftware.com
O1 - Hosts: 127.0.0.74 www.kellys-korner-xp.com
O1 - Hosts: 127.0.0.75 www.kephyr.com
O1 - Hosts: 127.0.0.78 www.lurkhere.com
O1 - Hosts: 127.0.0.79 www.majorgeeks.com
O1 - Hosts: 127.0.0.80 www.merijn.org
O1 - Hosts: 127.0.0.81 www.mjc1.com
O1 - Hosts: 127.0.0.82 www.moosoft.com
O1 - Hosts: 127.0.0.83 www.mvps.org
O1 - Hosts: 127.0.0.84 www.net-integration.net
O1 - Hosts: 127.0.0.85 www.noadware.net
O1 - Hosts: 127.0.0.86 www.no-spybot.com
O1 - Hosts: 127.0.0.87 www.onlinepcfix.com
O1 - Hosts: 127.0.0.88 www.pchell.com
O1 - Hosts: 127.0.0.89 www.pestpatrol.com
O1 - Hosts: 127.0.0.90 www.safer-networking.org
O1 - Hosts: 127.0.0.91 www.secureie.com
O1 - Hosts: 127.0.0.92 www.security.kolla.de
O1 - Hosts: 127.0.0.93 www.spybot.info
O1 - Hosts: 127.0.0.94 www.spychecker.com
O1 - Hosts: 127.0.0.95 www.spychecker.com
O1 - Hosts: 127.0.0.96 www.spycop.com
O1 - Hosts: 127.0.0.97 www.spyguard.com
O1 - Hosts: 127.0.0.98 www.spykiller.com
O1 - Hosts: 127.0.0.99 www.spyware.co.uk
O2 - BHO: (no name) - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpFCDD.tmp (file missing)


Close HiJackThis.

Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.


Open Ad-aware and do a full scan. Remove all it finds.


Run Ewido:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • NOTE: During some scans with ewido it is finding cases of false positives.
  • You will need to step through the process of cleaning files one-by-one.
  • If ewido detects a file you KNOW to be legitimate, select none as the action.
  • DO NOT select "Perform action on all infections"
  • If you are unsure of any entry found select none for now.
  • When the scan is finished, click the Save report button at the bottom of the screen.
  • Save the report to your desktop
Close Ewido

Next go to Control Panel click Display > Desktop > Customize Desktop > Web > Uncheck "Security Info" or somthing simular in name if present.

Run the Hoster program and select "Restore Orginal Hosts File"

Reboot back into Windows and click the Panda ActiveScan shortcut.
** click on "Free use ActiveScan" located on the top right hand corner
  1. Click Check Now & a 'pop up' window shall appear. *ensure that your pop up blocker doesn't block it
  2. Enter your e-mail address, country, and state & click Scan Now ...begins downloading 8 MB Panda's ActiveX controls
Begin the scan by selecting My Computer
  • If it finds any malware, it will offer you a report.
    [*] Please ignore any entry it finds and wants you to buy the program for removal as we will address this later.
    [*] Click on see report. Then click Save report

Post the contents of the Panda scan report, along with a new HijackThis Log, the contents of smitfiles.txt and the Ewido Log by using Add Reply.
 
Run the fix as is...skipping the HJT entrys. Then run the fix again in normal mode. Post the requested logs.
 
I ran all as you suggested. I think Zblog continues to generate new random "hp****.tmp" files in system32 folder.
Here are reports and HJ log---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 8:22:28 AM, 1/4/2006
+ Report-Checksum: 29661120

+ Scan result:

:mozilla.25:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Specificclick : Ignored
:mozilla.26:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Specificclick : Ignored
:mozilla.27:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.28:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.29:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.38:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.39:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.60:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.67:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.68:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.69:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.70:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.71:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
:mozilla.72:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
:mozilla.73:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
:mozilla.116:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.124:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.128:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.129:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.130:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.131:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.132:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.133:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.192:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.199:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.200:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.205:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.208:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.234:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.279:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Porngraph : Cleaned with backup
:mozilla.280:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.281:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.283:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.284:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.308:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.312:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.313:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.314:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.315:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.323:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.324:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.382:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.383:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.384:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.385:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.405:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.406:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.407:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.408:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.431:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Estat : Cleaned with backup
:mozilla.458:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.459:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.463:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.464:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.471:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.475:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.480:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.481:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.482:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.541:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.542:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.543:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.580:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.593:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.609:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.610:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.618:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
:mozilla.679:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.680:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup


::Report End
Smit files:

smitRem © log file
version 2.8

by noahdfear


Microsoft Windows XP [Version 5.1.2600]
The current date is: Tue 01/03/2006
The current time is: 22:03:05.95

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key


WinHound.com key not present!

spyaxe uninstaller NOT present
Winhound uninstaller NOT present
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~

Online Security Guide.url
Security Troubleshooting.url


~~~ Favorites ~~~

Antivirus Test Online.url


~~~ system32 folder ~~~

1024 dir
msvol.tlb
ld****.tmp
mssearchnet.exe
ncompat.tlb
nvctrl.exe
mscornet.exe
hp***.tmp


~~~ Icons in System32 ~~~

ts.ico
ot.ico


~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1512 'explorer.exe'
Killing PID 1512 'explorer.exe'

Starting registry repairs

Deleting files


Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~

Online Security Guide.url


~~~ Favorites ~~~



~~~ system32 folder ~~~

ld****.tmp
mssearchnet.exe
ncompat.tlb
nvctrl.exe
mscornet.exe
hp***.tmp


~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~



~~~ Miscellaneous Files/folders ~~~




~~~ Wininet.dll ~~~

CLEAN! :)
Panda Log:

Incident Status Location

Adware:adware/securityerror Not disinfected C:\WINDOWS\system32\nvctrl.exe
Adware:adware/securityerror Not disinfected C:\WINDOWS\SYSTEM32\mscornet.exe
Adware:adware/isearch Not disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\initial.inf
Adware:adware/gator Not disinfected C:\WINDOWS\GatorPatch.log
Adware:adware/powerstrip Not disinfected Windows Registry
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\user\Cookies\user@zedo[1].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\47be2fru.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\47be2fru.default\cookies.txt[.kinghost.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.com.com/]
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.target.com/]
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.winfixer.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.kinghost.com/]
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.ccbill.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Hypercount Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.hypercount.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[sel.as-eu.falkag.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[server.iad.liveperson.net/hc/13611470]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/C.porngraph Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[c.porngraph.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.belnk.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[landing.domainsponsor.com/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/web-stat Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[www.web-stat.com/]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[stat.onestat.com/]
Spyware:Cookie/go Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.go.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[server.iad.liveperson.net/hc/5073161]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.tickle.com/]
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[www.burstbeacon.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.ath.belnk.com/]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[c3.gostats.com/]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.gostats.com/]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.c3.gostats.com/]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.gostats.com/]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.c3.gostats.com/]
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.ask.com/]
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[c.enhance.com/]
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[fe.lea.lycos.de/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\47be2fru.default\cookies.txt[]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\47be2fru.default\cookiesnew.txt[]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\Cache\3EFBEAA3d01[Process.exe]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[13611470]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[5073161]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\user\Cookies\user@zedo[1].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\user\Desktop\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\user\Desktop\smitRem.exe[Process.exe]
Adware:Adware/ISearch Not disinfected C:\WINDOWS\Downloaded Program Files\initial.inf

HJLOG:
Logfile of HijackThis v1.99.1
Scan saved at 10:08:52 AM, on 1/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\Tablet.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvctrl.exe
C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\WINDOWS\System32\EZSP_PX.EXE
C:\toshiba\ivp\ism\pinger.exe
C:\WINDOWS\system32\00THotkey.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\NETGEAR\MA101 USB\WlanMonitor.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpBA6E.tmp (file missing)
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 28
O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files\Toshiba\ConfigFree\NDSTray.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\EZSP_PX.EXE
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Configuration & Monitor Utility.lnk = C:\Program Files\NETGEAR\MA101 USB\WlanMonitor.exe
O4 - Global Startup: MA101 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA101 USB\WlanMonitor.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Download all by Net Transport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: Download by Net Transport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\System32\Tablet.exe

See that bho hp***.tmp ?
 
Negative. That hp****.tmp file is generated by the Spysheriff/Smitfraud infection.

Please DISABLE Spybots Teatimer and WinPatrol again!!!!!

Download KillBox http://www.bleepingcomputer.com/files/spyware/KillBox.zip

Please download AproposFix from here:
http://swandog46.geekstogo.com/aproposfix.exe

Save it to your desktop but do NOT run it yet.


Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
*Click "Options..."
*Move the arrow down to "Custom CleanUp!"
*Put a check next to the following:
  • Empty Recycle Bins
  • Delete Cookies
  • Delete Prefetch files
    [X]Scan local drives for temporary files (Please uncheck this option)
  • Cleanup! All Users
Click OK
Press the CleanUp! button to start the program. DO NOT reboot/logoff when asked.

Run hijackthis and fix this entry:

O2 - BHO: (no name) - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpBA6E.tmp (file missing)

Run KILL box. Paste the following locations into KILL BOX one at a time. Checkmark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletionÂ…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot.

C:\WINDOWS\system32\nvctrl.exe
C:\WINDOWS\SYSTEM32\mscornet.exe
C:\WINDOWS\DOWNLOADED PROGRAM FILES\initial.inf
C:\WINDOWS\GatorPatch.log


Once you reboot.....boot back to "Safe Mode"

Run Ewdio again and let it clean the PC.

Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish.

Make sure your still in SAFE MODE and please double-click aproposfix.exe and unzip it to the desktop. Open the aproposfix folder on your desktop and run RunThis.bat. Follow the prompts.

When the tool is finished, please reboot back into normal mode, and post a new HijackThis log, along with the entire contents of the log.txt file in the aproposfix folder and a new Panda log.
 
OOPS! Sorry, I booted in safe mode in wrong profile...no wonder I couldn't find that stuff...will post all later. Thanks
 
Designer A said:
What is "Cleanup" ? I don't have it on desktop or programs...

Sorry..thought I included the link in the last fix....

Download and install Cleanup but DO NOT run it yet!

*WARNING* Cleanup deletes EVERYTHING out of temp/temporary folders and does not make backups.

Set it up and run it as stated.
 
Microbell: Here are the logs. After I ran everything and rebooted in normal mode, Norton popped up with zblog again, but deleted it. I checked the directories they recommended for any remaining trojan files and found nothing. HJ log attached was after this incident. I have had no further problems...maybe you got me fixed!

Logfile of HijackThis v1.99.1
Scan saved at 2:31:42 PM, on 1/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\Tablet.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\WINDOWS\System32\EZSP_PX.EXE
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\WINDOWS\system32\00THotkey.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\NETGEAR\MA101 USB\WlanMonitor.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Norton AntiVirus\NAVW32.EXE
C:\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 28
O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files\Toshiba\ConfigFree\NDSTray.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\EZSP_PX.EXE
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Configuration & Monitor Utility.lnk = C:\Program Files\NETGEAR\MA101 USB\WlanMonitor.exe
O4 - Global Startup: MA101 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA101 USB\WlanMonitor.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Download all by Net Transport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: Download by Net Transport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\System32\Tablet.exe

Log of AproposFix v1

************

Running from directory:
C:\Documents and Settings\user\Desktop\aproposfix

************

Registry entries found:


************

No service found!

Removing hidden folder:
No folder found!

Deleting files:


Backing up files:
Done!

Removing registry entries:

REGEDIT4


Done!

Finished!
Panda Report:

Incident Status Location

Adware:adware/isearch Not disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\initial.inf
Adware:adware/powerstrip Not disinfected Windows Registry
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\47be2fru.default\cookies.txt[.kinghost.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\r1u2wkqn.default\cookies.txt[]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\user\Desktop\smitRem\Process.exe
Adware:Adware/ISearch Not disinfected C:\WINDOWS\Downloaded Program Files\initial.inf

thanks again.
 
Status
Not open for further replies.
Back
Top Bottom