Kazaa.Irc.Spybot13.World

Please Help

Sbybot picks up the above at every start.. But I have been unable to install HJT or even get to any AV sites since, I suspect this thing has managed to impregnate my system..

I have had to get out the Company laptop to get to this site let alone any other security sites. The browser (Firefox and IE) closes as soon as any form of security or AV seems to be detectd.

I have been unable to start Regedit and cannot see any running processes in task manager (Blank screen)

I have been unable to get to Services.mmc either.. All of this in "safe" mode.

Does anybody know of any way to kill this one.

Comments

  • shwaipshwaip bluffin' with my muffin Icrontian
    edited December 2004
    Are you unable to download hijackthis, or unable to run it?

    if the former, try downloading it from here:

    http://209.133.47.12/~merijn/files/HijackThis.exe

    i've also attached cwshredder. try putting it on a floppy or cdrom, and running it on the other pc.
  • edited December 2004
    I am unable to run HJT, Regedit, Services.mmc, Adaware, or any Anti virus software..

    I have managed to get Spybot to run but probably because it was already loaded onto my machine and did not require an installation routine.

    I also seem to be excluded from getting to any websites that contain AV software or updates.. Or any websites that seem to have any form of security related SW or forums. Even this one.

    CW shredder did manage to install and run it removed two files and I managed to get it to run it's report

    *** Run Keys ****

    RUN: [Synchronization Manager] mobsync.exe /logon
    RUN: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
    RUN: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
    RUN: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
    RUN: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe
    RUN: [POINTER] point32.exe
    RUN: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
    RUN: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
    RUN: [DllCacherv2] C:\WINNT\system32\dllcachev2.exe
    RUN: [IPConfig] svcxnw32.exe
    RUN: [mswnvmx32] winclk4.exe init
    RUN: [DriveStat] vxdscan16.exe -services
    RUN: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    RUN: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
    RUN: [ctfmon.exe] ctfmon.exe
    RUN: [seticlient] C:\Program Files\SETI@home\SETI@home.exe -min
    RUN: [IPConfig] svcxnw32.exe
    RUN: [DriveStat] vxdscan16.exe -drivers


    **** Browser Helper Objects ****

    BHO: [HelperObject Class] C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
    BHO: [AcroIEHlprObj Class] C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    BHO: [Google Toolbar Helper] c:\winnt\googletoolbar2.dll
    BHO: [AcroIEToolbarHelper Class] C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll


    **** IE Toolbars ****

    TOOLBAR: [&Radio] C:\WINNT\System32\msdxm.ocx
    TOOLBAR: [SnagIt] C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
    TOOLBAR: [Adobe PDF] C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    TOOLBAR: [&Google] c:\winnt\googletoolbar2.dll


    **** IE Extensions ****

    IEExt: [Web Browser Applet Control] C:\WINNT\System32\msjava.dll
    IEExt: [Create Mobile Favorite] C:\WINNT\System32\msjava.dll
    IEExt: [Create Mobile Favorite] C:\WINNT\System32\msjava.dll
    IEExt: [@shdoclc.dll,-866] C:\WINNT\System32\msjava.dll


    **** Hosts File Entries ****

    HOSTS: 127.0.0.1 localhost
    HOSTS: 127.200.67.252 www.symantec.com
    HOSTS: 127.181.175.155 securityresponse.symantec.com
    HOSTS: 127.92.225.242 www.mcafee.com
    HOSTS: 127.111.240.197 mcafee.com
    HOSTS: 127.230.248.95 us.mcafee.com
    HOSTS: 127.87.207.33 www.sophos.com
    HOSTS: 127.124.161.246 sophos.com
    HOSTS: 127.51.15.5 www.viruslist.com
    HOSTS: 127.18.122.110 viruslist.com
    HOSTS: 127.191.38.70 f-secure.com
    HOSTS: 127.39.72.51 www.f-secure.com
    HOSTS: 127.191.163.225 kaspersky.com
    HOSTS: 127.108.160.181 www.avp.com
    HOSTS: 127.103.221.150 www.kaspersky.com
    HOSTS: 127.181.180.156 avp.com
    HOSTS: 127.212.165.129 www.networkassociates.com
    HOSTS: 127.4.137.229 networkassociates.com
    HOSTS: 127.34.102.144 www.ca.com
    HOSTS: 127.138.190.33 ca.com
    HOSTS: 127.0.118.233 my-etrust.com
    HOSTS: 127.244.168.61 www.my-etrust.com
    HOSTS: 127.205.138.151 secure.nai.com
    HOSTS: 127.97.120.162 nai.com
    HOSTS: 127.162.136.26 www.nai.com
    HOSTS: 127.203.157.151 trendmicro.com
    HOSTS: 127.227.46.174 www.trendmicro.com
    HOSTS: 127.215.168.25 housecall.trendmicro.com
    HOSTS: 127.29.71.105 www.pandasoftware.com
    HOSTS: 127.57.83.181 www.bitdefender.com
    HOSTS: 127.96.100.117 www.ravantivirus.com
    HOSTS: 127.58.131.3 www3.ca.com
    HOSTS: 127.91.77.30 v4.windowsupdate.microsoft.com
    HOSTS: 127.252.90.204 v5.windowsupdate.microsoft.com
    HOSTS: 127.219.180.100 v5windowsupdate.microsoft.nsatc.net
    HOSTS: 127.146.174.15 windowsupdate.microsoft.com
    HOSTS: 127.133.198.80 www.windowsupdate.com
    HOSTS: 127.10.134.81 windowsupdate.com


    **** IE Settings ****

    Default Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    Default Search: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Local Page: C:\WINNT\System32\blank.htm
    Search Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch


    **** IE Context Menu (Right click) ****

    IEContext: [&Google Search] res://c:\winnt\GoogleToolbar2.dll/cmsearch.html
    IEContext: [Backward Links] res://c:\winnt\GoogleToolbar2.dll/cmbacklinks.html
    IEContext: [Cached Snapshot of Page] res://c:\winnt\GoogleToolbar2.dll/cmcache.html
    IEContext: [Open Link Target in Firefox] file://C:\Documents and Settings\Derek Bradshaw\Application Data\Mozilla\Firefox\Profiles\98reh5xn.default\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
    IEContext: [Similar Pages] res://c:\winnt\GoogleToolbar2.dll/cmsimilar.html
    IEContext: [Translate into English] res://c:\winnt\GoogleToolbar2.dll/cmtrans.html
    IEContext: [View This Page in Firefox] file://C:\Documents and Settings\Derek Bradshaw\Application Data\Mozilla\Firefox\Profiles\98reh5xn.default\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html


    **** Layered Service Providers ****

    LSP: MSAFD Tcpip [TCP/IP]
    LSP: MSAFD Tcpip [UDP/IP]
    LSP: RSVP UDP Service Provider
    LSP: RSVP TCP Service Provider
    LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C11BFF5E-7A16-4043-B23D-14D4A5C97AB8}] SEQPACKET 1
    LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C11BFF5E-7A16-4043-B23D-14D4A5C97AB8}] DATAGRAM 1
    LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{B3906B32-3E78-4081-B18E-3C30FCCDB218}] SEQPACKET 2
    LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{B3906B32-3E78-4081-B18E-3C30FCCDB218}] DATAGRAM 2
    LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{8FAB8D91-55F4-4837-B2CB-7A777C004F10}] SEQPACKET 0
    LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{8FAB8D91-55F4-4837-B2CB-7A777C004F10}] DATAGRAM 0
    LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{D73602BB-68D2-4471-8C29-6A31FB3CBCAD}] SEQPACKET 3
    LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{D73602BB-68D2-4471-8C29-6A31FB3CBCAD}] DATAGRAM 3


    **** Blocked Control Panel Items ****

    BLOCKED: [ncpa.cpl] No
    BLOCKED: [odbccp32.cpl] No


    **** Downloaded Program Files ****

    DirectAnimation Java Classes [file://C:\WINNT\Java\classes\dajava.cab]
    Microsoft XML Parser for Java [file://C:\WINNT\Java\classes\xmldso.cab]
    {00000075-9980-0010-8000-00AA00389B71} [http://codecs.microsoft.com/codecs/i386/voxacm.CAB]
    {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} [http://www.apple.com/qtactivex/qtplugin.cab]
    {166B1BCA-3F9C-11CF-8075-444553540000} [http://active.macromedia.com/pub/shockwave/cabs/director/sw.cab]
    {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} [http://office.microsoft.com/officeupdate/content/opuc.cab] C:\WINNT\opuc.dll
    {41F17733-B041-4099-A042-B518BB6A408C} [http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe]
    {597C45C2-2D39-11D5-8D53-0050048383FE} [http://office.microsoft.com/productupdates/content/opuc.cab]
    {77460D96-3DB1-11D6-B121-004005E35DF1} [http://software.ibi-tec.net/ibi-xs.ocx] C:\WINNT\Downloaded Program Files\CONFLICT.1\ibi-xs.ocx
    {7A32634B-029C-4836-A023-528983982A49} [http://fdl.msn.com/public/chat/msnchat42.cab]
    {8699D723-6DC6-47D3-B55C-489BA006B917} [http://membersites.namezero.com/guiseppe.mail.com/england/webinstall.cab]
    {86A88967-7A20-11D2-8EDA-00600818EDB1} [http://www.parallelgraphics.com/bin/cortvrml.cab] C:\WINNT\Downloaded Program Files\RevancheOGL.dll C:\WINNT\Downloaded Program Files\DXSelector.dll C:\WINNT\Downloaded Program Files\RevancheDX7.dll C:\WINNT\Downloaded Program Files\RevancheDX5.dll C:\WINNT\Downloaded Program Files\movieimager.dll C:\WINNT\Downloaded Program Files\movietexturerenderer.dll C:\WINNT\Downloaded Program Files\cortona_js2.dll C:\WINNT\Downloaded Program Files\classes.zip C:\WINNT\Downloaded Program Files\cortjava.dll C:\WINNT\Downloaded Program Files\shelley3.dll C:\WINNT\Downloaded Program Files\corteai.zip C:\WINNT\Downloaded Program Files\corteai.dll C:\WINNT\Downloaded Program Files\cortona_support.dll C:\WINNT\Downloaded Program Files\cortmime.dll C:\WINNT\Downloaded Program Files\engine.dll C:\WINNT\Downloaded Program Files\cortona_res.dll C:\WINNT\Downloaded Program Files\chameleon.dll C:\WINNT\Downloaded Program Files\rob.dll C:\WINNT\Downloaded Program Files\rsoft32.dll C:\WINNT\Downloaded Program Files\cortona_imagers.dll C:\WINNT\Downloaded Program Files\cortona_transport.dll C:\WINNT\Downloaded Program Files\cortona_control.dll C:\WINNT\Downloaded Program Files\cortona_native.dll
    {8AD9C840-044E-11D1-B3E9-00805F499D93} [http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab]
    {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} [http://toolbar.google.com/data/GoogleActivate.cab]
    {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} [http://www.pandasoftware.com/activescan/as5/asinst.cab]
    {9F1C11AA-197B-4942-BA54-47A8489BB47F} [http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37606.4618171296]
    {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} [http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab]
    {D27CDB6E-AE6D-11CF-96B8-444553540000} [http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab]
    {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} [http://chat.msn.com/bin/msnchat45.cab]


    **** Windows Services ****

    [AppMgmt] %SystemRoot%\system32\services.exe
    [aspnet_state] %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
    [BITS] %SystemRoot%\System32\svchost.exe -k BITSgroup
    [Browser] %SystemRoot%\System32\services.exe
    [cisvc] C:\WINNT\System32\cisvc.exe
    [ClipSrv] %SystemRoot%\system32\clipsrv.exe
    [Dhcp] %SystemRoot%\System32\services.exe
    [dmadmin] %SystemRoot%\System32\dmadmin.exe /com
    [dmserver] %SystemRoot%\System32\services.exe
    [Dnscache] %SystemRoot%\System32\services.exe
    [Eventlog] %SystemRoot%\system32\services.exe
    [EventSystem] C:\WINNT\System32\svchost.exe -k netsvcs
    [Fax] %systemroot%\system32\faxsvc.exe
    [Iomega Activity Disk2] ""
    [Iomega App Services] "C:\PROGRA~1\Iomega\System32\AppServices.exe"
    [IomegaAccess] C:\WINNT\System32\IomegaAccess.exe /S
    [lanmanserver] %SystemRoot%\System32\services.exe
    [lanmanworkstation] %SystemRoot%\System32\services.exe
    [LmHosts] %SystemRoot%\System32\services.exe
    [MDM] "C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"
    [mnmsrvc] C:\WINNT\System32\mnmsrvc.exe
    [MSDTC] C:\WINNT\System32\msdtc.exe
    [MSIServer] C:\WINNT\System32\MsiExec.exe /V
    [NetDDE] %SystemRoot%\system32\netdde.exe
    [NetDDEdsdm] %SystemRoot%\system32\netdde.exe
    [Netlogon] %SystemRoot%\System32\lsass.exe
    [Netman] %SystemRoot%\System32\svchost.exe -k netsvcs
    [NtLmSsp] %SystemRoot%\System32\lsass.exe
    [NtmsSvc] %SystemRoot%\System32\svchost.exe -k netsvcs
    [PlugPlay] %SystemRoot%\system32\services.exe
    [PolicyAgent] %SystemRoot%\System32\lsass.exe
    [ProtectedStorage] %SystemRoot%\system32\services.exe
    [RasAuto] %SystemRoot%\System32\svchost.exe -k netsvcs
    [RasMan] %SystemRoot%\System32\svchost.exe -k netsvcs
    [RemoteAccess] %SystemRoot%\System32\svchost.exe -k netsvcs
    [RemoteRegistry] %SystemRoot%\system32\regsvc.exe
    [RpcLocator] %SystemRoot%\System32\locator.exe
    [RpcSs] %SystemRoot%\system32\svchost -k rpcss
    [RSVP] %SystemRoot%\System32\rsvp.exe -s
    [SamSs] %SystemRoot%\system32\lsass.exe
    [SCardDrv] %SystemRoot%\System32\SCardSvr.exe
    [SCardSvr] %SystemRoot%\System32\SCardSvr.exe
    [Schedule] %SystemRoot%\system32\MSTask.exe
    [seclogon] %SystemRoot%\system32\services.exe
    [SENS] %SystemRoot%\system32\svchost.exe -k netsvcs
    [SharedAccess] %SystemRoot%\System32\svchost.exe -k netsvcs
    [Spooler] %SystemRoot%\system32\spoolsv.exe
    [StiSvc] %systemroot%\system32\stisvc.exe
    [SysmonLog] %SystemRoot%\system32\smlogsvc.exe
    [TapiSrv] %SystemRoot%\System32\svchost.exe -k netsvcs
    [TlntSvr] %SystemRoot%\system32\tlntsvr.exe
    [TrkWks] %SystemRoot%\system32\services.exe
    [UPS] %SystemRoot%\System32\ups.exe
    [UtilMan] %SystemRoot%\System32\UtilMan.exe
    [W32Time] %SystemRoot%\System32\services.exe
    [WinMgmt] %SystemRoot%\System32\WBEM\WinMgmt.exe
    [WMDM PMSP Service] C:\WINNT\System32\mspmspsv.exe
    [WmdmPmSN] %SystemRoot%\System32\svchost.exe -k netsvcs
    [Wmi] %SystemRoot%\system32\Services.exe
    [WZCSVC] %SystemRoot%\System32\svchost.exe -k netsvcs
    [ZipToA] C:\WINNT\System32\ZipToA.exe /S
    [_IOMEGA_ACTIVE_DISK_SERVICE_] "C:\Program Files\Iomega\AutoDisk\ADService.exe"


    **** Custom IE Search Items ****

    SEARCH: [SearchAssistant] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
    SEARCH: [CustomizeSearch] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm


    **** Complete IE Options ****

    IEOPT: [NoUpdateCheck]
    IEOPT: [NoJITSetup]
    IEOPT: [Show_ChannelBand] No
    IEOPT: [Anchor Underline] yes
    IEOPT: [Cache_Update_Frequency] Once_Per_Session
    IEOPT: [Display Inline Images] yes
    IEOPT: [Do404Search]
    IEOPT: [Local Page] C:\WINNT\System32\blank.htm
    IEOPT: [Save_Session_History_On_Exit] no
    IEOPT: [Show_FullURL] no
    IEOPT: [Show_StatusBar] yes
    IEOPT: [Show_ToolBar] yes
    IEOPT: [Show_URLinStatusBar] yes
    IEOPT: [Show_URLToolBar] yes
    IEOPT: [Start Page] http://www.google.co.uk/
    IEOPT: [Use_DlgBox_Colors] yes
    IEOPT: [Search Page] http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    IEOPT: [FullScreen] no
    IEOPT: [Window_Placement] ,
    IEOPT: [Q261272] yes
    IEOPT: [Disable Script Debugger] no
    IEOPT: [AddToFavoritesExpanded]
    IEOPT: [NotifyDownloadComplete] yes
    IEOPT: [Use FormSuggest] no
    IEOPT: [Error Dlg Displayed On Every Error] no
    IEOPT: [Error Dlg Details Pane Open] yes
    IEOPT: [Expand Alt Text] no
    IEOPT: [Move System Caret] no
    IEOPT: [NscSingleExpand]
    IEOPT: [NoWebJITSetup]
    IEOPT: [Page_Transitions]
    IEOPT: [FavIntelliMenus] no
    IEOPT: [Enable Browser Extensions] yes
    IEOPT: [Force Offscreen Composition]
    IEOPT: [AllowWindowReuse]
    IEOPT: [Friendly http errors] yes
    IEOPT: [ShowGoButton] yes
    IEOPT: [SmoothScroll]
    IEOPT: [Enable AutoImageResize] yes
    IEOPT: [Enable_MyPics_Hoverbar] yes
    IEOPT: [Play_Animations] yes
    IEOPT: [Play_Background_Sounds] yes
    IEOPT: [Display Inline Videos] yes
    IEOPT: [Show image placeholders]
    IEOPT: [Print_Background] no
    IEOPT: [AutoSearch]
    IEOPT: [LastCheckedHi]
    IEOPT: [Save Directory] A:\
    IEOPT: [ShowedCheckBrowser] Yes
    IEOPT: [Check_Associations] No
    IEOPT: [Default_Page_URL] http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    IEOPT: [Default_Search_URL] http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    IEOPT: [Search Page] http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    IEOPT: [Enable_Disk_Cache] yes
    IEOPT: [Cache_Percent_of_Disk]
    IEOPT: [Delete_Temp_Files_On_Exit] yes
    IEOPT: [Local Page] %SystemRoot%\system32\blank.htm
    IEOPT: [Anchor_Visitation_Horizon]
    IEOPT: [Use_Async_DNS] yes
    IEOPT: [Placeholder_Width]
    IEOPT: [Placeholder_Height]
    IEOPT: [Start Page] http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
    IEOPT: [CompanyName] Microsoft Corporation
    IEOPT: [Custom_Key] MICROSO
    IEOPT: [Wizard_Version] 6.00.2800.1106
    IEOPT: [FullScreen] no


    I hope you can make sense of this.


    I have also managed to run Spybot again and this is the printed report I am geting

    Kazaa.Irc.Spybot13.World: Settings (Registry value, nothing done)
    HKEY_USERS\S-1-5-21-789336058-1383384898-1202660629-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun
    DSO Exploit: Data source object exploit (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-789336058-1383384898-1202660629-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3
    DSO Exploit: Data source object exploit (Registry change, nothing done)
    HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3


    --- Spybot - Search && Destroy version: 1.3 ---
    2004-11-29 Includes\Cookies.sbi
    2004-12-15 Includes\Dialer.sbi
    2004-12-16 Includes\Hijackers.sbi
    2004-12-15 Includes\Keyloggers.sbi
    2004-05-12 Includes\LSP.sbi
    2004-12-15 Includes\Malware.sbi
    2004-08-11 Includes\plugin-ignore.ini
    2004-11-29 Includes\Revision.sbi
    2004-11-29 Includes\Security.sbi
    2004-12-16 Includes\Spybots.sbi
    2004-11-29 Includes\Tracks.uti
    2004-12-15 Includes\Trojans.sbi
  • edited December 2004
    After reading the log I have restored a backup of my Hosts file and made it read only.

    At last I can at least attempt to get to the internet although my browser keeps shutting down whenever I try to get to any decent sites that may be able to help with this, thus leaving me somewhat in the lurch and stuck with using the company laptop to get to here.
  • shwaipshwaip bluffin' with my muffin Icrontian
    edited December 2004
    here is a program that removes one of the variants of CoolWebSearch, which is what may be causing your inability to run hijackthis or other anti-spyware programs.

    http://www.safer-networking.org/files/delcwssk.zip


    I see that you have firefox installed on the other computer. Do you have the same problems accessing the security/spyware/etc related sites in firefox and IE?
  • edited December 2004
    shwaip wrote:
    here is a program that removes one of the variants of CoolWebSearch, which is what may be causing your inability to run hijackthis or other anti-spyware programs.

    http://www.safer-networking.org/files/delcwssk.zip


    I see that you have firefox installed on the other computer. Do you have the same problems accessing the security/spyware/etc related sites in firefox and IE?
    I have exactly the same issues when accessing the same websites using FF as I do using IE.. (That was my first thought as well.)

    The Mini removal tol did not find CWS on my system..

    I do seem to have lost all admin rights to my PC and am unable to run any Admin tools at all...

    I still have not been able to install HJT so that I can get a log out.
  • TroganTrogan London, UK
    edited December 2004
    Hi!

    Can you access your email account on the infected computer? If you can then download HijackThis onto the company's computer and email it to yourself and then try downloading on the infected computer.
  • edited December 2004
    Downloads is not the issue..
    Installing is.

    Three registry keys keep getting remade each restart.

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
    "DisallowRun"=dword:00000001

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun]
    "0"="blackd.exe"
    "1"="blackice.exe"
    "2"="lockdown.exe"
    "3"="lockdown2000.exe"
    "4"="netmon.exe"
    "5"="processmonitor.exe"
    "6"="taskkill.exe"
    "7"="tskill.exe"
    "8"="smc.exe"
    "9"="sniffem.exe"
    "10"="zapro.exe"
    "11"="zlclient.exe"
    "12"="zonealarm.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "DisableRegistryTools"=dword:00000001

    Thus making it very difficult to actually do any diagnosis.

    **************************************************************

    At Last -- A HJT LOG..

    Logfile of HijackThis v1.99.0
    Scan saved at 21:01:55, on 27/12/2004
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\svchost.exe
    C:\PROGRA~1\Iomega\System32\AppServices.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\System32\mspmspsv.exe
    C:\WINNT\System32\ZipToA.exe
    C:\Program Files\Iomega\AutoDisk\ADService.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
    C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
    C:\Program Files\Microsoft Hardware\Mouse\point32.exe
    C:\Program Files\Java\jre1.5.0\bin\jusched.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
    C:\WINNT\system32\ctfmon.exe
    C:\Program Files\SETI@home\SETI@home.exe
    C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    D:\Program Files\Microsoft Office\Office\1033\msoffice.exe
    C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe
    C:\Documents and Settings\Derek Bradshaw\Desktop\Time service\nistime-32bit.exe
    C:\Program Files\TechSmith\SnagIt 7\TSCHelp.exe
    C:\WINNT\System32\MsiExec.exe
    C:\WINNT\system32\taskmgr.exe
    C:\Program Files\Common Files\Network Associates\On Demand Scanner\Scan32\scan32.exe
    C:\WINNT\system32\NOTEPAD.EXE
    C:\WINNT\system32\mmc.exe
    C:\Documents and Settings\Derek Bradshaw\Desktop\Security bits\HJT\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    F2 - REG:system.ini: Shell=Explorer.exe,vxdscan16.exe -shell
    O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\winnt\googletoolbar2.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\winnt\googletoolbar2.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
    O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
    O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
    O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe
    O4 - HKLM\..\Run: [POINTER] point32.exe
    O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
    O4 - HKLM\..\Run: [IPConfig] svcxnw32.exe
    O4 - HKLM\..\Run: [DriveStat] vxdscan16.exe -services
    O4 - HKLM\..\RunServices: [DriveStat] vxdscan16.exe -services
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
    O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
    O4 - HKCU\..\Run: [seticlient] C:\Program Files\SETI@home\SETI@home.exe -min
    O4 - HKCU\..\Run: [IPConfig] svcxnw32.exe
    O4 - HKCU\..\Run: [DriveStat] vxdscan16.exe -drivers
    O4 - Startup: Shortcut to nistime-32bit.exe.lnk = C:\Documents and Settings\Derek Bradshaw\Desktop\Time service\nistime-32bit.exe
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
    O4 - Global Startup: Microsoft Office Shortcut Bar.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: SnagIt 7.lnk = C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe
    O8 - Extra context menu item: &Google Search - res://c:\winnt\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://c:\winnt\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\winnt\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: Open Link Target in Firefox - file://C:\Documents and Settings\Derek Bradshaw\Application Data\Mozilla\Firefox\Profiles\98reh5xn.default\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
    O8 - Extra context menu item: Similar Pages - res://c:\winnt\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://c:\winnt\GoogleToolbar2.dll/cmtrans.html
    O8 - Extra context menu item: View This Page in Firefox - file://C:\Documents and Settings\Derek Bradshaw\Application Data\Mozilla\Firefox\Profiles\98reh5xn.default\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
    O16 - DPF: {77460D96-3DB1-11D6-B121-004005E35DF1} (Ctrl_ibi Control 1.3) - http://software.ibi-tec.net/ibi-xs.ocx
    O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} - http://fdl.msn.com/public/chat/msnchat42.cab
    O16 - DPF: {8699D723-6DC6-47D3-B55C-489BA006B917} - http://membersites.namezero.com/guiseppe.mail.com/england/webinstall.cab
    O16 - DPF: {86A88967-7A20-11D2-8EDA-00600818EDB1} (ParallelGraphics Cortona Control) - http://www.parallelgraphics.com/bin/cortvrml.cab
    O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
    O23 - Service: IomegaAccess - Iomega Corporation - C:\WINNT\System32\IomegaAccess.exe
    O23 - Service: ZipToA - Iomega Corporation - C:\WINNT\System32\ZipToA.exe
    O23 - Service: Iomega Active Disk - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

    Any help would be appreciated..... Many thanks
  • edited January 2005
    seems that i have the same problem, but if i reboot in safe mode, i kill one service and can run hjthis.

    Any one got an idea?
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited January 2005
    CyberMulot wrote:
    seems that i have the same problem, but if i reboot in safe mode, i kill one service and can run hjthis...
    Which service?

    Post your log! :wave:

    BTW: I'm tied up at the moment, but I'll take a look at your log and bradshawd's as soon as I can, assuming no one else takes care of it beforehand. :)
  • edited January 2005
    the service i'm killing is sysstat.exe
    I deleted all the O1 which blocked the access to online scans.
    I also have in My Documents folder a folder called backups that is recreated each time i reboot the PC. It contains files of different sizes called backups with numbers....



    Logfile of HijackThis v1.99.0
    Scan saved at 22:15:09, on 7/01/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\cisvc.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\nvsvc32.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Fichiers communs\Adaptec Shared\CreateCD\CreateCD50.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\WINNT\system32\svcxnw32.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    C:\Documents and Settings\Administrateur\Local Settings\Temp\DynDNS.exe
    C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
    C:\Program Files\Plaxo\2.1.0.80\InstallStub.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Valve\Steam\Steam.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    C:\Program Files\Nikon\NkView6\NkvMon.exe
    C:\WINNT\System32\cidaemon.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\PROGRA~1\WINZIP\winzip32.exe
    C:\Documents and Settings\Administrateur\Mes documents\Mes fichiers reçus\ferooz.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.skynet.be/search
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.skynet.be/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.skynet.be/search
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.skynet.be/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    F2 - REG:system.ini: Shell=Explorer.exe,sysstat.exe -shell
    O1 - Hosts: 127.120.35.227 www.symantec.com
    O1 - Hosts: 127.221.39.109 securityresponse.symantec.com
    O1 - Hosts: 127.2.206.146 www.mcafee.com
    O1 - Hosts: 127.26.79.31 mcafee.com
    O1 - Hosts: 127.99.191.213 us.mcafee.com
    O1 - Hosts: 127.236.113.66 www.sophos.com
    O1 - Hosts: 127.102.198.19 sophos.com
    O1 - Hosts: 127.104.143.200 www.viruslist.com
    O1 - Hosts: 127.37.188.129 viruslist.com
    O1 - Hosts: 127.4.158.141 f-secure.com
    O1 - Hosts: 127.188.229.181 www.f-secure.com
    O1 - Hosts: 127.78.101.110 kaspersky.com
    O1 - Hosts: 127.149.94.87 www.avp.com
    O1 - Hosts: 127.22.242.246 www.kaspersky.com
    O1 - Hosts: 127.243.192.22 avp.com
    O1 - Hosts: 127.234.150.52 www.networkassociates.com
    O1 - Hosts: 127.95.124.179 networkassociates.com
    O1 - Hosts: 127.216.214.236 www.ca.com
    O1 - Hosts: 127.216.163.66 ca.com
    O1 - Hosts: 127.174.205.157 my-etrust.com
    O1 - Hosts: 127.197.16.233 www.my-etrust.com
    O1 - Hosts: 127.41.251.25 secure.nai.com
    O1 - Hosts: 127.25.56.208 nai.com
    O1 - Hosts: 127.214.113.151 www.nai.com
    O1 - Hosts: 127.57.3.250 trendmicro.com
    O1 - Hosts: 127.153.214.144 www.trendmicro.com
    O1 - Hosts: 127.120.123.60 housecall.trendmicro.com
    O1 - Hosts: 127.13.195.197 www.pandasoftware.com
    O1 - Hosts: 127.64.58.149 www.bitdefender.com
    O1 - Hosts: 127.57.92.58 www.ravantivirus.com
    O1 - Hosts: 127.78.221.135 www3.ca.com
    O1 - Hosts: 127.90.58.16 v4.windowsupdate.microsoft.com
    O1 - Hosts: 127.133.225.80 v5.windowsupdate.microsoft.com
    O1 - Hosts: 127.164.254.129 v5windowsupdate.microsoft.nsatc.net
    O1 - Hosts: 127.67.182.12 windowsupdate.microsoft.com
    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_18_0.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_18_0.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Fichiers communs\Adaptec Shared\CreateCD\CreateCD50.exe" -r
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [RoxAssistant] C:\Program Files\Common Files\Roxio Shared\Upgrade\RoxAssist.exe /s
    O4 - HKLM\..\Run: [I/O Controllers] svcnet.exe
    O4 - HKLM\..\Run: [RegLoad16] sysstat.exe -services
    O4 - HKLM\..\Run: [mswnvmx32] explorer
    O4 - HKLM\..\Run: [KAZAA] "C:\Program Files\Kazaa Lite K++\kpp.exe" "C:\Program Files\Kazaa Lite K++\KazaaLite.kpp" /SYSTRAY
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [IPConfig] svcxnw32.exe
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    O4 - HKLM\..\RunServices: [RegLoad16] sysstat.exe -services
    O4 - HKCU\..\Run: [DynDNS Updater] "C:\Documents and Settings\Administrateur\Local Settings\Temp\DynDNS.exe"
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.1.0.80\InstallStub.exe -a
    O4 - HKCU\..\Run: [I/O Controllers] svcnet.exe
    O4 - HKCU\..\Run: [Steam] C:\Valve\Steam\Steam.exe -silent
    O4 - HKCU\..\Run: [RegLoad16] sysstat.exe -drivers
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [IPConfig] svcxnw32.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Startup: AxelTime.lnk = C:\Documents and Settings\Administrateur\Mes documents\Axel Time\AxelTime.exe
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: Dexia netbanking - http://netbanking.dexia.be/PC//Dynamic/Shared/Applet//DexiaIIA.cab
    O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.com/down/release/PlaxoInstall.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O23 - Service: Gestion d'applications - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Explorateur d'ordinateur - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Client DHCP - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Service d'administration du Gestionnaire de disque logique - Unknown - C:\WINNT\System32\dmadmin.exe
    O23 - Service: Gestionnaire de disque logique - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Client DNS - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Journal des événements - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Service de télécopie - Unknown - C:\WINNT\system32\faxsvc.exe
    O23 - Service: Serveur - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Station de travail - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Service d'application d'assistance TCP/IP NetBIOS - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Partage de Bureau à distance NetMeeting - Unknown - C:\WINNT\System32\mnmsrvc.exe
    O23 - Service: DDE réseau - Unknown - C:\WINNT\system32\netdde.exe
    O23 - Service: DSDM DDE réseau - Unknown - C:\WINNT\system32\netdde.exe
    O23 - Service: Ouverture de session réseau - Unknown - C:\WINNT\System32\lsass.exe
    O23 - Service: Fournisseur de la prise en charge de sécurité LM NT - Unknown - C:\WINNT\System32\lsass.exe
    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
    O23 - Service: Plug-and-Play - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Agent de stratégie IPSEC - Unknown - C:\WINNT\System32\lsass.exe
    O23 - Service: Emplacement protégé - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Gestionnaire de comptes de sécurité - Unknown - C:\WINNT\system32\lsass.exe
    O23 - Service: Prise en charge des cartes à puces - Unknown - C:\WINNT\System32\SCardSvr.exe
    O23 - Service: Carte à puce - Unknown - C:\WINNT\System32\SCardSvr.exe
    O23 - Service: Planificateur de tâches - Unknown - C:\WINNT\system32\MSTask.exe
    O23 - Service: Service d'exécution par délégation - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Still Image Service - Unknown - C:\WINNT\system32\stisvc.exe
    O23 - Service: Journaux et alertes de performance - Unknown - C:\WINNT\system32\smlogsvc.exe
    O23 - Service: Telnet - Unknown - C:\WINNT\system32\tlntsvr.exe
    O23 - Service: Client de suivi de lien distribué - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Gestionnaire d'utilitaires - Unknown - C:\WINNT\System32\UtilMan.exe
    O23 - Service: Horloge Windows - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Infrastructure de gestion Windows - Unknown - C:\WINNT\System32\WBEM\WinMgmt.exe
    O23 - Service: Extensions du pilote WMI - Unknown - C:\WINNT\system32\Services.exe
  • SpywareShooterSpywareShooter 127.0.0.1
    edited January 2005
    O1 - Hosts: 127.120.35.227 www.symantec.com
    O1 - Hosts: 127.221.39.109 securityresponse.symantec.com
    O1 - Hosts: 127.2.206.146 www.mcafee.com
    O1 - Hosts: 127.26.79.31 mcafee.com
    O1 - Hosts: 127.99.191.213 us.mcafee.com
    O1 - Hosts: 127.236.113.66 www.sophos.com
    O1 - Hosts: 127.102.198.19 sophos.com
    O1 - Hosts: 127.104.143.200 www.viruslist.com
    O1 - Hosts: 127.37.188.129 viruslist.com
    O1 - Hosts: 127.4.158.141 f-secure.com
    O1 - Hosts: 127.188.229.181 www.f-secure.com
    O1 - Hosts: 127.78.101.110 kaspersky.com
    O1 - Hosts: 127.149.94.87 www.avp.com
    O1 - Hosts: 127.22.242.246 www.kaspersky.com
    O1 - Hosts: 127.243.192.22 avp.com
    O1 - Hosts: 127.234.150.52 www.networkassociates.com
    O1 - Hosts: 127.95.124.179 networkassociates.com
    O1 - Hosts: 127.216.214.236 www.ca.com
    O1 - Hosts: 127.216.163.66 ca.com
    O1 - Hosts: 127.174.205.157 my-etrust.com
    O1 - Hosts: 127.197.16.233 www.my-etrust.com
    O1 - Hosts: 127.41.251.25 secure.nai.com
    O1 - Hosts: 127.25.56.208 nai.com
    O1 - Hosts: 127.214.113.151 www.nai.com
    O1 - Hosts: 127.57.3.250 trendmicro.com
    O1 - Hosts: 127.153.214.144 www.trendmicro.com
    O1 - Hosts: 127.120.123.60 housecall.trendmicro.com
    O1 - Hosts: 127.13.195.197 www.pandasoftware.com
    O1 - Hosts: 127.64.58.149 www.bitdefender.com
    O1 - Hosts: 127.57.92.58 www.ravantivirus.com
    O1 - Hosts: 127.78.221.135 www3.ca.com
    O1 - Hosts: 127.90.58.16 v4.windowsupdate.microsoft.com
    O1 - Hosts: 127.133.225.80 v5.windowsupdate.microsoft.com
    O1 - Hosts: 127.164.254.129 v5windowsupdate.microsoft.nsatc.net
    O1 - Hosts: 127.67.182.12 windowsupdate.microsoft.com
    O4 - HKLM\..\Run: [I/O Controllers] svcnet.exe
    O4 - HKLM\..\Run: [RegLoad16] sysstat.exe -services
    O4 - HKLM\..\Run: [KAZAA] "C:\Program Files\Kazaa Lite K++\kpp.exe" "C:\Program Files\Kazaa Lite K++\KazaaLite.kpp" /SYSTRAY
    O4 - HKLM\..\Run: [IPConfig] svcxnw32.exe
    O4 - HKLM\..\RunServices: [RegLoad16] sysstat.exe -services
    O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.1.0.80\InstallStub.exe -a
    O4 - HKCU\..\Run: [I/O Controllers] svcnet.exe
    O4 - HKCU\..\Run: [IPConfig] svcxnw32.exe
    O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.com/down/release/PlaxoInstall.cab

    Fix those entries then find and delete the files listed above, reboot and post a new log.
  • edited January 2005
    O1 - Hosts: 127.120.35.227 www.symantec.com
    O1 - Hosts: 127.221.39.109 securityresponse.symantec.com
    O1 - Hosts: 127.2.206.146 www.mcafee.com
    O1 - Hosts: 127.26.79.31 mcafee.com
    O1 - Hosts: 127.99.191.213 us.mcafee.com
    O1 - Hosts: 127.236.113.66 www.sophos.com
    O1 - Hosts: 127.102.198.19 sophos.com
    O1 - Hosts: 127.104.143.200 www.viruslist.com
    O1 - Hosts: 127.37.188.129 viruslist.com
    O1 - Hosts: 127.4.158.141 f-secure.com
    O1 - Hosts: 127.188.229.181 www.f-secure.com
    O1 - Hosts: 127.78.101.110 kaspersky.com
    O1 - Hosts: 127.149.94.87 www.avp.com
    O1 - Hosts: 127.22.242.246 www.kaspersky.com
    O1 - Hosts: 127.243.192.22 avp.com
    O1 - Hosts: 127.234.150.52 www.networkassociates.com
    O1 - Hosts: 127.95.124.179 networkassociates.com
    O1 - Hosts: 127.216.214.236 www.ca.com
    O1 - Hosts: 127.216.163.66 ca.com
    O1 - Hosts: 127.174.205.157 my-etrust.com
    O1 - Hosts: 127.197.16.233 www.my-etrust.com
    O1 - Hosts: 127.41.251.25 secure.nai.com
    O1 - Hosts: 127.25.56.208 nai.com
    O1 - Hosts: 127.214.113.151 www.nai.com
    O1 - Hosts: 127.57.3.250 trendmicro.com
    O1 - Hosts: 127.153.214.144 www.trendmicro.com
    O1 - Hosts: 127.120.123.60 housecall.trendmicro.com
    O1 - Hosts: 127.13.195.197 www.pandasoftware.com
    O1 - Hosts: 127.64.58.149 www.bitdefender.com
    O1 - Hosts: 127.57.92.58 www.ravantivirus.com
    O1 - Hosts: 127.78.221.135 www3.ca.com
    O1 - Hosts: 127.90.58.16 v4.windowsupdate.microsoft.com
    O1 - Hosts: 127.133.225.80 v5.windowsupdate.microsoft.com
    O1 - Hosts: 127.164.254.129 v5windowsupdate.microsoft.nsatc.net
    O1 - Hosts: 127.67.182.12 windowsupdate.microsoft.com
    O4 - HKLM\..\Run: [I/O Controllers] svcnet.exe
    O4 - HKLM\..\Run: [RegLoad16] sysstat.exe -services
    O4 - HKLM\..\Run: [KAZAA] "C:\Program Files\Kazaa Lite K++\kpp.exe" "C:\Program Files\Kazaa Lite K++\KazaaLite.kpp" /SYSTRAY
    O4 - HKLM\..\Run: [IPConfig] svcxnw32.exe
    O4 - HKLM\..\RunServices: [RegLoad16] sysstat.exe -services
    O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.1.0.80\InstallStub.exe -a
    O4 - HKCU\..\Run: [I/O Controllers] svcnet.exe
    O4 - HKCU\..\Run: [IPConfig] svcxnw32.exe
    O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.com/down/release/PlaxoInstall.cab

    Fix those entries then find and delete the files listed above, reboot and post a new log.

    only fixing them or block them also. I double checked also for Plaxo, and this is not a problem, but i will uninstall it just to make sure. Never had problems with it.
  • edited January 2005
    Logfile of HijackThis v1.99.0
    Scan saved at 9:15:12, on 8/01/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\Explorer.EXE
    C:\Documents and Settings\Administrateur\Mes documents\Mes fichiers reçus\ferooz.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.skynet.be/search
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.skynet.be/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.skynet.be/search
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.skynet.be/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O1 - Hosts: 127.153.192.25 symantec.com
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Fichiers communs\Adaptec Shared\CreateCD\CreateCD50.exe" -r
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [RoxAssistant] C:\Program Files\Common Files\Roxio Shared\Upgrade\RoxAssist.exe /s
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
    O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
    O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [IPConfig] svcxnw32.exe
    O4 - HKLM\..\RunServices: [DJSNetCN] C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
    O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
    O4 - HKCU\..\Run: [DynDNS Updater] "C:\Documents and Settings\Administrateur\Local Settings\Temp\DynDNS.exe"
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [Steam] C:\Valve\Steam\Steam.exe -silent
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE
    O4 - HKCU\..\Run: [IPConfig] svcxnw32.exe
    O4 - Startup: AxelTime.lnk = C:\Documents and Settings\Administrateur\Mes documents\Axel Time\AxelTime.exe
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: Dexia netbanking - http://netbanking.dexia.be/PC//Dynamic/Shared/Applet//DexiaIIA.cab
    O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.com/down/release/PlaxoInstall.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O23 - Service: Gestion d'applications - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Explorateur d'ordinateur - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    O23 - Service: Client DHCP - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Symantec Licensing Detect Internet Connection - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
    O23 - Service: Service d'administration du Gestionnaire de disque logique - Unknown - C:\WINNT\System32\dmadmin.exe
    O23 - Service: Gestionnaire de disque logique - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Client DNS - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Journal des événements - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Service de télécopie - Unknown - C:\WINNT\system32\faxsvc.exe
    O23 - Service: IS Service - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: Serveur - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Station de travail - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Service d'application d'assistance TCP/IP NetBIOS - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Partage de Bureau à distance NetMeeting - Unknown - C:\WINNT\System32\mnmsrvc.exe
    O23 - Service: DDE réseau - Unknown - C:\WINNT\system32\netdde.exe
    O23 - Service: DSDM DDE réseau - Unknown - C:\WINNT\system32\netdde.exe
    O23 - Service: Ouverture de session réseau - Unknown - C:\WINNT\System32\lsass.exe
    O23 - Service: Fournisseur de la prise en charge de sécurité LM NT - Unknown - C:\WINNT\System32\lsass.exe
    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
    O23 - Service: Plug-and-Play - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Agent de stratégie IPSEC - Unknown - C:\WINNT\System32\lsass.exe
    O23 - Service: Emplacement protégé - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Gestionnaire de comptes de sécurité - Unknown - C:\WINNT\system32\lsass.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: Prise en charge des cartes à puces - Unknown - C:\WINNT\System32\SCardSvr.exe
    O23 - Service: Carte à puce - Unknown - C:\WINNT\System32\SCardSvr.exe
    O23 - Service: Planificateur de tâches - Unknown - C:\WINNT\system32\MSTask.exe
    O23 - Service: Service d'exécution par délégation - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Still Image Service - Unknown - C:\WINNT\system32\stisvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Journaux et alertes de performance - Unknown - C:\WINNT\system32\smlogsvc.exe
    O23 - Service: Telnet - Unknown - C:\WINNT\system32\tlntsvr.exe
    O23 - Service: Client de suivi de lien distribué - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Gestionnaire d'utilitaires - Unknown - C:\WINNT\System32\UtilMan.exe
    O23 - Service: Horloge Windows - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Infrastructure de gestion Windows - Unknown - C:\WINNT\System32\WBEM\WinMgmt.exe
    O23 - Service: Extensions du pilote WMI - Unknown - C:\WINNT\system32\Services.exe
  • edited January 2005
    CyberMulot wrote:
    Logfile of HijackThis v1.99.0
    Scan saved at 9:15:12, on 8/01/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    ...
    C:\Documents and Settings\Administrateur\Mes documents\Mes fichiers reçus\ferooz.exe
    ...
    I renamed hijack in ferooz.exe as at the beginning didn't want to run it

    the log posted is in safe mode
  • SpywareShooterSpywareShooter 127.0.0.1
    edited January 2005
    Please post a normal mode hijackthis log
  • edited January 2005
    Logfile of HijackThis v1.99.0
    Scan saved at 3:06:24, on 9/01/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
    C:\WINNT\system32\svchost.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    C:\WINNT\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINNT\System32\cisvc.exe
    C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\nvsvc32.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\System32\cidaemon.exe
    C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Fichiers communs\Adaptec Shared\CreateCD\CreateCD50.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Program Files\Norton Internet Security\cfgwiz.exe
    C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Documents and Settings\Administrateur\Local Settings\Temp\DynDNS.exe
    C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
    C:\Valve\Steam\Steam.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINNT\system32\svcxnw32.exe
    C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    C:\Program Files\Nikon\NkView6\NkvMon.exe
    C:\Documents and Settings\Administrateur\Mes documents\Mes fichiers reçus\ferooz.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.skynet.be/search
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.skynet.be/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.skynet.be/search
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.skynet.be/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O1 - Hosts: 127.153.192.25 symantec.com
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Fichiers communs\Adaptec Shared\CreateCD\CreateCD50.exe" -r
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [RoxAssistant] C:\Program Files\Common Files\Roxio Shared\Upgrade\RoxAssist.exe /s
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
    O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
    O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [IPConfig] svcxnw32.exe
    O4 - HKLM\..\RunServices: [DJSNetCN] C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
    O4 - HKCU\..\Run: [DynDNS Updater] "C:\Documents and Settings\Administrateur\Local Settings\Temp\DynDNS.exe"
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [Steam] C:\Valve\Steam\Steam.exe -silent
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [IPConfig] svcxnw32.exe
    O4 - Startup: AxelTime.lnk = C:\Documents and Settings\Administrateur\Mes documents\Axel Time\AxelTime.exe
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: Dexia netbanking - http://netbanking.dexia.be/PC//Dynamic/Shared/Applet//DexiaIIA.cab
    O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.com/down/release/PlaxoInstall.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O23 - Service: Gestion d'applications - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Explorateur d'ordinateur - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    O23 - Service: Client DHCP - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Symantec Licensing Detect Internet Connection - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
    O23 - Service: Service d'administration du Gestionnaire de disque logique - Unknown - C:\WINNT\System32\dmadmin.exe
    O23 - Service: Gestionnaire de disque logique - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Client DNS - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Journal des événements - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Service de télécopie - Unknown - C:\WINNT\system32\faxsvc.exe
    O23 - Service: IS Service - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: Serveur - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Station de travail - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Service d'application d'assistance TCP/IP NetBIOS - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Partage de Bureau à distance NetMeeting - Unknown - C:\WINNT\System32\mnmsrvc.exe
    O23 - Service: DDE réseau - Unknown - C:\WINNT\system32\netdde.exe
    O23 - Service: DSDM DDE réseau - Unknown - C:\WINNT\system32\netdde.exe
    O23 - Service: Ouverture de session réseau - Unknown - C:\WINNT\System32\lsass.exe
    O23 - Service: Fournisseur de la prise en charge de sécurité LM NT - Unknown - C:\WINNT\System32\lsass.exe
    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
    O23 - Service: Plug-and-Play - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Agent de stratégie IPSEC - Unknown - C:\WINNT\System32\lsass.exe
    O23 - Service: Emplacement protégé - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Gestionnaire de comptes de sécurité - Unknown - C:\WINNT\system32\lsass.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: Prise en charge des cartes à puces - Unknown - C:\WINNT\System32\SCardSvr.exe
    O23 - Service: Carte à puce - Unknown - C:\WINNT\System32\SCardSvr.exe
    O23 - Service: Planificateur de tâches - Unknown - C:\WINNT\system32\MSTask.exe
    O23 - Service: Service d'exécution par délégation - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Still Image Service - Unknown - C:\WINNT\system32\stisvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Journaux et alertes de performance - Unknown - C:\WINNT\system32\smlogsvc.exe
    O23 - Service: Telnet - Unknown - C:\WINNT\system32\tlntsvr.exe
    O23 - Service: Client de suivi de lien distribué - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Gestionnaire d'utilitaires - Unknown - C:\WINNT\System32\UtilMan.exe
    O23 - Service: Horloge Windows - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Infrastructure de gestion Windows - Unknown - C:\WINNT\System32\WBEM\WinMgmt.exe
    O23 - Service: Extensions du pilote WMI - Unknown - C:\WINNT\system32\Services.exe
  • SpywareShooterSpywareShooter 127.0.0.1
    edited January 2005
    O1 - Hosts: 127.153.192.25 symantec.com
    O4 - HKCU\..\Run: [IPConfig] svcxnw32.exe
    O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.com/down/release/PlaxoInstall.cab

    Fix those entries then find and delete svcxnw32.exe, reboot and post a new log.
  • edited January 2005
    Logfile of HijackThis v1.99.0
    Scan saved at 3:28:58, on 9/01/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
    C:\WINNT\system32\svchost.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    C:\WINNT\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINNT\System32\cisvc.exe
    C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\nvsvc32.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Fichiers communs\Adaptec Shared\CreateCD\CreateCD50.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    C:\Program Files\Nikon\NkView6\NkvMon.exe
    C:\Documents and Settings\Administrateur\Mes documents\Mes fichiers reçus\ferooz.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.skynet.be/search
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.skynet.be/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.skynet.be/search
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.skynet.be/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Fichiers communs\Adaptec Shared\CreateCD\CreateCD50.exe" -r
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [RoxAssistant] C:\Program Files\Common Files\Roxio Shared\Upgrade\RoxAssist.exe /s
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
    O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
    O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [IPConfig] svcxnw32.exe
    O4 - HKLM\..\RunServices: [DJSNetCN] C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
    O4 - HKCU\..\Run: [DynDNS Updater] "C:\Documents and Settings\Administrateur\Local Settings\Temp\DynDNS.exe"
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [Steam] C:\Valve\Steam\Steam.exe -silent
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [IPConfig] svcxnw32.exe
    O4 - Startup: AxelTime.lnk = C:\Documents and Settings\Administrateur\Mes documents\Axel Time\AxelTime.exe
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: Dexia netbanking - http://netbanking.dexia.be/PC//Dynamic/Shared/Applet//DexiaIIA.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O23 - Service: Gestion d'applications - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Explorateur d'ordinateur - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    O23 - Service: Client DHCP - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Symantec Licensing Detect Internet Connection - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
    O23 - Service: Service d'administration du Gestionnaire de disque logique - Unknown - C:\WINNT\System32\dmadmin.exe
    O23 - Service: Gestionnaire de disque logique - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Client DNS - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Journal des événements - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Service de télécopie - Unknown - C:\WINNT\system32\faxsvc.exe
    O23 - Service: IS Service - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: Serveur - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Station de travail - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Service d'application d'assistance TCP/IP NetBIOS - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Partage de Bureau à distance NetMeeting - Unknown - C:\WINNT\System32\mnmsrvc.exe
    O23 - Service: DDE réseau - Unknown - C:\WINNT\system32\netdde.exe
    O23 - Service: DSDM DDE réseau - Unknown - C:\WINNT\system32\netdde.exe
    O23 - Service: Ouverture de session réseau - Unknown - C:\WINNT\System32\lsass.exe
    O23 - Service: Fournisseur de la prise en charge de sécurité LM NT - Unknown - C:\WINNT\System32\lsass.exe
    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
    O23 - Service: Plug-and-Play - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Agent de stratégie IPSEC - Unknown - C:\WINNT\System32\lsass.exe
    O23 - Service: Emplacement protégé - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Gestionnaire de comptes de sécurité - Unknown - C:\WINNT\system32\lsass.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: Prise en charge des cartes à puces - Unknown - C:\WINNT\System32\SCardSvr.exe
    O23 - Service: Carte à puce - Unknown - C:\WINNT\System32\SCardSvr.exe
    O23 - Service: Planificateur de tâches - Unknown - C:\WINNT\system32\MSTask.exe
    O23 - Service: Service d'exécution par délégation - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Still Image Service - Unknown - C:\WINNT\system32\stisvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Journaux et alertes de performance - Unknown - C:\WINNT\system32\smlogsvc.exe
    O23 - Service: Telnet - Unknown - C:\WINNT\system32\tlntsvr.exe
    O23 - Service: Client de suivi de lien distribué - Unknown - C:\WINNT\system32\services.exe
    O23 - Service: Gestionnaire d'utilitaires - Unknown - C:\WINNT\System32\UtilMan.exe
    O23 - Service: Horloge Windows - Unknown - C:\WINNT\System32\services.exe
    O23 - Service: Infrastructure de gestion Windows - Unknown - C:\WINNT\System32\WBEM\WinMgmt.exe
    O23 - Service: Extensions du pilote WMI - Unknown - C:\WINNT\system32\Services.exe
Sign In or Register to comment.