Xadso - Please help. - Frustrated Newbie

If anyone would provide a way out of this, I'd appreciate it.
My wife acquired a lot of viruses the other day, and I've cleaned them all up (panda scan, command anti virus,cwshredder, ad-aware, and spybot) except for on persistant one "Xadso", which seems to be a common topic here.
I know it is Xadso as when a new IE window opens, I can see "Xadso" for a 1/2 second on the tool bar (nice of them to at least give us that clue!).
I've done some reading in this forum on what tools to run, and it's helped a lot so far, but this one seems persistant. I did not run the utilities in safe mode, should I have?


Here is my hijackthis log (first time I've used the program).

I'm affraid to touch this stuff, not understanding all of it, but I would guess that "Web Offer\wo.exe" is not good.
again, any help would be appreciated.

Logfile of HijackThis v1.98.2
Scan saved at 12:19:05 PM, on 9/5/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Command Software\Command AntiVirus\schscnt.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\COMMAN~1\COMMAN~1\untray.exe
C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe
C:\PROGRA~1\COMMAN~1\COMMAN~1\avtray.exe
C:\WINNT\System32\qqhchr.exe
C:\Program Files\Microsoft Office97\Office\MSOFFICE.EXE
C:\download\HijackThis.exe
C:\WINNT\System32\shell32.exe

O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINNT\localNRD.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll (file missing)
O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SAClient] "C:\Program Files\Insight\BBClient\Programs\RegCon.exe" /admincheck
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [untray] C:\PROGRA~1\COMMAN~1\COMMAN~1\untray.exe
O4 - HKLM\..\Run: [dvprpt] C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe
O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe
O4 - HKLM\..\Run: [avtray] C:\PROGRA~1\COMMAN~1\COMMAN~1\avtray.exe
O4 - HKLM\..\Run: [vnfqadvdwsa] C:\WINNT\System32\qqhchr.exe
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - HKCU\..\Run: [shell32] C:\WINNT\System32\shell32.exe
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
O4 - Startup: Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft Office97\Office\MSOFFICE.EXE
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

Comments

  • shwaipshwaip bluffin' with my muffin Icrontian
    edited September 2004
    hiyo!

    boot into safe mode and remove the following entries with hijackthis:
    O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINNT\localNRD.dll
    O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll (file missing)
    O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (resource hog, optional removal)
    O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
    O4 - HKLM\..\Run: [vnfqadvdwsa] C:\WINNT\System32\qqhchr.exe
    O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
    O4 - HKCU\..\Run: [shell32] C:\WINNT\System32\shell32.exe (appears to be a trojan/backdoor)

    now, delete the following files:
    C:\WINNT\localNRD.dll
    C:\Program Files\TV Media (delete this folder)
    C:\WINNT\System32\qqhchr.exe
    C:\PROGRAM FILES\Web Offer\ (delete this folder)

    move this file:
    C:\WINNT\System32\shell32.exe
    to a folder on your hard drive called c:\quarantine, and rename it to:
    shell32.xxx

    reboot and be sure to tell us if it worked or not.
  • edited September 2004
    Thanks, Shwaip, I did as you said, but ran into a couple problems, and I still have the problem.
    1)localNRD.dll was not in c:\winnt\. I did find it in c:\documents and settings\steve\local settings\temp\thi2d4.tmp so I moved it from there to a floppy in case I needed it later.
    2) c:\program files\tv media does not exist. the folder tv media is not on the computer if I search for tv. I have the view set to show hidden folders and files.
    3) the folder web offer also does not exist.

    Everything else you mentioned went pretty smooth.

    Here is a re-run of my HJT log, run from normal mode. Anything else I should delete?
    I don't need the pandascan or the trend micro active scan, should I get rid of them?

    Logfile of HijackThis v1.98.2
    Scan saved at 10:55:30 PM, on 9/5/2004
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
    C:\Program Files\Common Files\Command Software\dvpapi.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\Program Files\Command Software\Command AntiVirus\schscnt.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\PROGRA~1\COMMAN~1\COMMAN~1\untray.exe
    C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe
    C:\PROGRA~1\COMMAN~1\COMMAN~1\avtray.exe
    C:\Program Files\Microsoft Office97\Office\MSOFFICE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\download\HijackThis.exe

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [SAClient] "C:\Program Files\Insight\BBClient\Programs\RegCon.exe" /admincheck
    O4 - HKLM\..\Run: [untray] C:\PROGRA~1\COMMAN~1\COMMAN~1\untray.exe
    O4 - HKLM\..\Run: [dvprpt] C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe
    O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe
    O4 - HKLM\..\Run: [avtray] C:\PROGRA~1\COMMAN~1\COMMAN~1\avtray.exe
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
    O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
    O4 - Startup: Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft Office97\Office\MSOFFICE.EXE
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
  • edited September 2004
    One other interesting tidbit... every time I run spybot S&D, it tells me I have DSO something or another. I clean it up, but it keeps coming back.
  • DexterDexter Vancouver, BC Canada
    edited September 2004
    That log looks clean.

    Do not worry about the DSO warnings in Spybot. That is a bug. Make sure your Windows updates are up to date, and they are not a problem.


    Please read our article on Defeating Spyware for tips on how to improve your Internet Explorer security, or to learn how to switch to a different browser. For more general information about spyware read this page.

    Finally, if you have not already done so, please take the time to find out more about Folding For a Cure, a good cause by which your computer uses it's spare power to help search for cures to diseases. We would love to have you on our Team.

    Dexter...
This discussion has been closed.