I was at a client today two machines on their network really spywared to bits (main PC Norton's was 4 months out of date!) Got rid of lots, but still loads remaining, so would like you to assess the hijackthis for me.
Machine is slow, I think IE is now affected after having removed some of the spyware. Once I have identified stuff from hijackthis, I can run new scans of ad-aware and spybot and also a Norton AV
Thanks, hijackthis log below:
Logfile of HijackThis v1.97.7
Scan saved at 22:51:23, on 07/07/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.
exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\
Binn\sqlse
rvr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\hkcmd.
exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Real\RealPlayer\Real
Play.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\COMETS~1\DM\bi
n\dmserver
.exe
C:\PROGRA~1\MYWEBS~1\bar\2
.bin\mwsoe
mon.exe
C:\documents and settings\steve\local settings\temp\yN2.exe
C:\WINDOWS\System32\ycllau
k.exe
C:\WINDOWS\system32\pcs\pc
svc.exe
C:\Program Files\Common Files\Dpi\dpi.exe
C:\Program Files\Common files\updmgr\updmgr.exe
C:\WINDOWS\System32\automo
ve.exe
C:\WINDOWS\System32\fasrov
.exe
C:\Program Files\WindowsSA\omniscient
.exe
C:\WINDOWS\System32\ctfmon
.exe
C:\WINDOWS\System32\fdemlr
.exe
C:\Program Files\FinePixViewer\QuickD
CF.exe
C:\WINDOWS\System32\DCT.ex
e
C:\WINDOWS\System32\OhjOUe
Cw.exe
C:\WINDOWS\System32\Fnjt.e
xe
C:\WINDOWS\System32\wuaucl
t.exe
C:\test\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar = file://C:\WINDOWS\System32
\SearchBar
.htm
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.euro.dell.com/countries/uk/enu/gen/default.htmR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.euro.dell.com/countries/uk/enu/gen/default.htmR3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-
00C04FD644
97} - (no file)
R3 - URLSearchHook: (no name) - _{4FC95EDD-4796-4966-9049-
29649C8011
1D} - (no file)
F2 - REG:system.ini: UserInit=C:\Windows\System
32\wsaupda
ter.exe,
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {00000000-0000-0000-0000-0
0000000022
1} - C:\Program Files\ClearSearch\CSIE.DLL
(file missing)
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4
A4827C2E4C
8} - C:\WINDOWS\nem219.dll (file missing)
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-D
D56626C6C4
2} - C:\WINDOWS\twaintec.dll
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5
838F569A31
D} - C:\Program Files\MyWebSearch\SrchAstt
\2.bin\MWS
SRCAS.DLL
O2 - BHO: (no name) - {01C5BF6C-E699-4CD7-BEA1-7
86FA05C83A
B} - C:\Program Files\SysAI\plg0\AproposPl
ugin.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEH
elper.ocx
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-1
70DE4475CC
A} - C:\Program Files\MyWebSearch\bar\2.bi
n\MWSBAR.D
LL
O2 - BHO: NavErrRedir Class - {4FC95EDD-4796-4966-9049-2
9649C80111
D} - C:\PROGRA~1\INCRED~1\BHO\I
NCFIN~2.DL
L
O2 - BHO: (no name) - {5FA6752A-C4A0-4222-88C2-9
28AE5AB496
6} - C:\WINDOWS\System32\SWin32
.dll
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-0
0E04C60FAF
2} - C:\WINDOWS\2_0_1browserhel
per2.dll
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C
176083F35C
F} - C:\WINDOWS\System32\bridge
.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-5
00A16B6CF9
4} - C:\Program Files\SEP\sep.dll
O2 - BHO: WinPage Affiliate - {E8EAEB34-F7B5-4C55-87FF-7
20FAF53D84
1} - C:\Program Files\Common Files\midaddle\midaddle.dl
l
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-1
70DE4475CC
A} - C:\Program Files\MyWebSearch\bar\2.bi
n\MWSBAR.D
LL
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-5
00A16B6CF9
4} - C:\Program Files\SEP\sep.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtr
ay.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.
exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\Real
Play.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EX
E /AUTORUN
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [DM_Server] C:\PROGRA~1\COMETS~1\DM\bi
n\dmserver
.exe /onreboot
O4 - HKLM\..\Run: [SSWPlauncher] C:\PROGRA~1\COMETS~1\Platf
orm\Bin\co
met.exe /app:SSWPlauncher
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2
.bin\mwsoe
mon.exe
O4 - HKLM\..\Run: [yN2] C:\documents and settings\steve\local settings\temp\yN2.exe
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\System32\Jhng4O
.exe
O4 - HKLM\..\Run: [qrqwfx] C:\WINDOWS\System32\ycllau
k.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdat
e.exe"
O4 - HKLM\..\Run: [Pcsv] C:\WINDOWS\system32\pcs\pc
svc.exe
O4 - HKLM\..\Run: [Dpi] C:\Program Files\Common Files\Dpi\dpi.exe
O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\automo
ve.exe
O4 - HKLM\..\Run: [rFni3qW] fasrov.exe
O4 - HKLM\..\Run: [wmplayer] C:\Program Files\Windows Media Player\wmplayer.exe -invisible
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridg
e.dll",Loa
d
O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient
.exe
O4 - HKLM\..\Run: [DCT] C:\WINDOWS\System32\DCT.ex
e
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon
.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2
.bin\mwsoe
mon.exe
O4 - HKCU\..\Run: [ao4sRka6S] fdemlr.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bi
n\MWSOEMON
.EXE
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickD
CF.exe
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bi
n\MWSOEMON
.EXE
O4 - Global Startup: updater.lnk = ?
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZSzeb029O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\OFFICE11\
EXCEL.EXE/
3000
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .au: C:\Program Files\Internet Explorer\PLUGINS\npqtplugi
n2.dll
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugi
n2.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: {00B71CFB-6864-4346-A978-C
0A14556272
C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cabO16 - DPF: {166B1BCA-3F9C-11CF-8075-4
4455354000
0} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cabO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1
E41684E07B
B} -
http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cabO16 - DPF: {2917297F-F02B-4B9D-81DF-4
94B6333150
B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cabO16 - DPF: {33564D57-0000-0010-8000-0
0AA00389B7
1} -
http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CABO16 - DPF: {8E0D4DE5-3180-4024-A327-4
DFAD1796A8
D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-4
7A8489BB47
F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38047.5511342593O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D
3E34FC7B00
A} -
http://install.wildtangent.com/bgn/partners/shockwave/polarbowler/install.cabO16 - DPF: {AD7FAFB0-16D6-40C3-AF27-5
85D6E6453F
D} -
http://dload.ipbill.com/del/loader.cabO16 - DPF: {AE1C01E3-0283-11D3-9B3F-0
0C04F8EF46
6} (HeartbeatCtl Class) -
http://fdl.msn.com/zone/datafiles/heartbeat.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {EC5A4E7B-02EB-451D-B310-D
5F2E0A4D8C
3} (webhelper Class) -
http://register.btinternet.com/templates/btwebcontrol023.cabO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F
385591623A
F} (Solitaire Showdown Class) -
http://messenger.zone.msn.com/binary/SolitaireShowdown.cab27571.cabO16 - DPF: {FA13A9FA-CA9B-11D2-9780-0
0104B242EA
3} -
http://install.wildtangent.com/bgn/partners/shockwave/polarbowler/install.cab