Anti-Virus Apps
--
Questions
--
Followers
Top Experts
I believe I have a virus that causes my computer to increase network traffic. When I look at the PPPoE connection status, I can see that even when I'm not surfing the internet or using the email (basically all applications are closed), the computer is still sending like 10,000 bytes/second and receiving 200 bytes/second. And it keeps doing that as long as I'm connected.
At first, I thought it was the W32.Welchia.Worm virus, so I ensured I updated to any critical update of Windows XP, updated my anti-virus definition of Norton Anti-Virus, go to Safe Mode, and ran my Norton Anti-Virus. At the same time, I ran the FixWelch.exe program from Symantec. Both the Norton Anti-Virus and Symantec did not detect anything.
Please help,
Andrew
Zero AI Policy
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
It does sound like a trojan.
Just to eliminate the possibility that NAV has been compromised, I'd try doing some online scanning. Below are links to the most popular online scanners:
Symantec:
http://security.symantec.com/sscv6/default.asp?productid=symhome&langid=ie&venid=sym
Trend Micro:
http://housecall.antivirus.com/housecall/start_corp.asp
Panda ActiveScan:
http://www.pandasoftware.com/activescan/
PC PitStop:
http://www.pcpitstop.com/antivirus/default.asp
Good Vibes!
Lobo






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
I just finished an online scan with Symantec and there's no virus or trojan detected.
Maybe it's spyware, will try that.
Any other possibilities?
Logfile of HijackThis v1.98.0
Scan saved at 11:32:30 PM, on 30/7/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools
C:\WINDOWS\System32\atipta
C:\Program Files\Synaptics\SynTP\SynT
C:\Program Files\Synaptics\SynTP\SynT
C:\Program Files\Compaq\EAB\EabServr.
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\sbnet\ShowBehin
C:\Program Files\Samsung\SmarThru\POR
C:\WINDOWS\System32\rundll
C:\WINDOWS\System32\SSCFBT
C:\WINDOWS\System32\Notify
C:\PROGRA~1\WIRELE~1\Keybo
C:\PROGRA~1\WIRELE~1\Mouse
C:\Program Files\Common Files\Real\Update_OB\reals
C:\Program Files\iHateSpam4.0\siServi
C:\Program Files\SealedMedia\sealmon.
C:\Program Files\iHateSpam4.0\siSpamF
C:\WINDOWS\System32\RUNDLL
C:\WINDOWS\System32\winini
C:\Program Files\CashBack\bin\cashbac
C:\Program Files\NaviSearch\bin\nls.e
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEED
C:\WINDOWS\System32\svchos
C:\MS Office 2000\Office10\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iHateSpam4.0\siMain.
C:\WINDOWS\System32\MSCSta
C:\PROGRA~1\POPUPB~1\Popup
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijack This\HijackThis.exe
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
O2 - BHO: IPInsigtObj Class - {000004CC-E4FF-4F2C-BC30-D
O2 - BHO: TwaintecObj Class - {000020DD-C72E-4113-AF77-D
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7
O2 - BHO: ZIBho Class - {029CA12C-89C1-46a7-A3C7-8
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: Lexico Toolbar - {11359F4A-B191-42d7-905A-5
O2 - BHO: IEHlprObj Class - {19075736-64F1-4BD4-95B0-E
O2 - BHO: IE 4.x-6.x BHO - {49E0E0F0-5C30-11D4-945D-0
O2 - BHO: Xbrowse Class - {AC109D01-32D6-4EB5-8300-D
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
O2 - BHO: Url Catcher - {CE31A1F7-3D90-4874-8FBE-A
O2 - BHO: Xbrowse Class - {D319662B-D5BF-4538-ADF3-8
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
O3 - Toolbar: (no name) - {856D6A8E-A24C-498A-A55A-2
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
O3 - Toolbar: Dictionary.com - {11359F4A-B191-42D7-905A-5
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-B
O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-1
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynT
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynT
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.
O4 - HKLM\..\Run: [Sentry] C:\WINDOWS\Sentry.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\system32\spool\
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ShowBehind] C:\WINDOWS\sbnet\ShowBehin
O4 - HKLM\..\Run: [GW Port Controller] C:\Program Files\Samsung\SmarThru\POR
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [RAS2000] C:\WINDOWS\System32\Ras200
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCh
O4 - HKLM\..\Run: [SSCFBTN.EXE] SSCFBTN.EXE
O4 - HKLM\..\Run: [Power Scan] C:\Documents and Settings\Andrew\Local Settings\Temp\powerscan.ex
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\WIRELE~1\Keybo
O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\WIRELE~1\Mouse
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
O4 - HKLM\..\Run: [siService.exe] "C:\Program Files\iHateSpam4.0\siServi
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [sealmon] C:\Program Files\SealedMedia\sealmon.
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA
O4 - HKLM\..\Run: [Microsoft Update Machine] winini.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IM
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IME
O4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashbac
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.e
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\RunServices: [Microsoft Update Machine] winini.exe
O4 - HKLM\..\RunOnce: [Compaq_RBA] C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe
O4 - HKLM\..\RunOnce: [mscrp] C:\WINDOWS\System32\\winbp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
O4 - HKCU\..\Run: [System Soap Pro] C:\PROGRA~1\SYSTEM~1\soap.
O4 - HKCU\..\Run: [Microsoft Update Machine] winini.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Ad
O4 - Global Startup: Microsoft Office.lnk = C:\MS Office 2000\Office10\OSA.EXE
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dl
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\MSOFFI~1\Office10
O8 - Extra context menu item: Get It With Kontiki - res://C:\Program Files\Kontiki\bin\bh304181
O8 - Extra context menu item: Search &Dictionary - C:\Program files\Lexico\Toolbar\dicti
O8 - Extra context menu item: Search &Thesaurus - C:\Program files\Lexico\Toolbar\thesa
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-0
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-0
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-0
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-0
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-0
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-0
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-0
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A
O9 - Extra button: Advisor - {9EBC1900-098C-40D1-9AA0-6
O16 - DPF: {018B7EC3-EECA-11D3-8E71-0
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
O16 - DPF: {359F7E49-1EA0-4671-92E9-6
O16 - DPF: {41F17733-B041-4099-A042-B
O16 - DPF: {421A63BA-4632-43E0-A942-3
O16 - DPF: {644E432F-49D3-41A1-8DD5-E
O16 - DPF: {90C9629E-CD32-11D3-BBFB-0
O16 - DPF: {91BE8DAC-957E-416C-B735-E
O16 - DPF: {9600F64D-755F-11D4-A47F-0
O16 - DPF: {E2F2B9D0-96B9-4B25-B90C-6
O16 - DPF: {EE2589EB-7FC8-44DB-A892-5
O16 - DPF: {F0E2D69A-DC2F-4E9B-A993-6
O16 - DPF: {F5192746-22D6-41BD-9D2D-1
O16 - DPF: {F5820AD3-9B20-423E-B2AA-7
O16 - DPF: {FC327B3F-377B-4CB7-8B61-2
O17 - HKLM\System\CCS\Services\T

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
You have a number of things on your computer - among them are:
Gator/Gain
Istbar
WildTangent
Kontiki
just to mention a few.
Going through your log right now.
Regards...
RF
Bullet proof spyware is my alltime favorite tho. (trial only unless you purchase) Â comes with pop up blocker, spyware remover, spyware watcher, and a form of hijackthis (which actually catches some things hijackthis wont. But most people use hijackthis, and is easy to use. Â
Anyway let us know how it goes.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Do not have HijackThis "fix" Twain-tec:
O2 - BHO: TwaintecObj Class - {000020DD-C72E-4113-AF77-D
Twaintec.dll is a transponder. HijackThis will detect it as a BHO but it must not be removed using HijackThis.
This is because of the remaining registry entries and files which can be dangerous.
RF
more info on twain tech

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Logfile of HijackThis v1.98.0
Scan saved at 10:39:32 AM, on 31/7/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools
C:\WINDOWS\System32\atipta
C:\Program Files\Synaptics\SynTP\SynT
C:\Program Files\Synaptics\SynTP\SynT
C:\Program Files\Compaq\EAB\EabServr.
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Samsung\SmarThru\POR
C:\WINDOWS\System32\rundll
C:\WINDOWS\System32\SSCFBT
C:\PROGRA~1\WIRELE~1\Keybo
C:\WINDOWS\System32\Notify
C:\PROGRA~1\WIRELE~1\Mouse
C:\Program Files\iHateSpam4.0\siServi
C:\Program Files\SealedMedia\sealmon.
C:\WINDOWS\System32\winini
C:\Program Files\CashBack\bin\cashbac
C:\Program Files\NaviSearch\bin\nls.e
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iHateSpam4.0\siSpamF
C:\WINDOWS\System32\ctfmon
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEED
C:\WINDOWS\System32\svchos
C:\WINDOWS\System32\MSCSta
C:\PROGRA~1\POPUPB~1\Popup
C:\PROGRA~1\POPUPB~1\Popup
C:\Program Files\Hijack This\HijackThis.exe
R0 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: Lexico Toolbar - {11359F4A-B191-42d7-905A-5
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
O3 - Toolbar: Dictionary.com - {11359F4A-B191-42D7-905A-5
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynT
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynT
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.
O4 - HKLM\..\Run: [Sentry] C:\WINDOWS\Sentry.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\system32\spool\
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [GW Port Controller] C:\Program Files\Samsung\SmarThru\POR
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCh
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\WIRELE~1\Keybo
O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\WIRELE~1\Mouse
O4 - HKLM\..\Run: [siService.exe] "C:\Program Files\iHateSpam4.0\siServi
O4 - HKLM\..\Run: [Microsoft Update Machine] winini.exe
O4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashbac
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.e
O4 - HKLM\..\RunServices: [Microsoft Update Machine] winini.exe
O4 - HKLM\..\RunOnce: [Compaq_RBA] C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
O4 - HKCU\..\Run: [Microsoft Update Machine] winini.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Ad
O4 - Global Startup: Microsoft Office.lnk = C:\MS Office 2000\Office10\OSA.EXE
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dl
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\MSOFFI~1\Office10
O8 - Extra context menu item: Search &Dictionary - C:\Program files\Lexico\Toolbar\dicti
O8 - Extra context menu item: Search &Thesaurus - C:\Program files\Lexico\Toolbar\thesa
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A
O9 - Extra button: Advisor - {9EBC1900-098C-40D1-9AA0-6
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
O16 - DPF: {41F17733-B041-4099-A042-B
O16 - DPF: {644E432F-49D3-41A1-8DD5-E
O16 - DPF: {F0E2D69A-DC2F-4E9B-A993-6






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
C:\WINDOWS\System32\Notify
C:\Program Files\iHateSpam4.0\siServi
C:\Program Files\SealedMedia\sealmon.
C:\WINDOWS\System32\winini
C:\Program Files\CashBack\bin\cashbac
C:\Program Files\NaviSearch\bin\nls.e
C:\Program Files\iHateSpam4.0\siSpamF
C:\WINDOWS\System32\MSCSta
C:\PROGRA~1\POPUPB~1\Popup
C:\PROGRA~1\POPUPB~1\Popup
Your running processes here look like some might be spam. Â IE: cashback.exe, nls.exe, popupbegone.exe (run twice), SSCFBTN.EXE
O2 - BHO: Lexico Toolbar - {11359F4A-B191-42d7-905A-5
O3 - Toolbar: Dictionary.com - {11359F4A-B191-42D7-905A-5
O4 - HKLM\..\Run: [Sentry] C:\WINDOWS\Sentry.exe
O4 - HKLM\..\Run: [siService.exe] "C:\Program Files\iHateSpam4.0\siServi
O4 - HKLM\..\Run: [Microsoft Update Machine] winini.exe
O4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashbac
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.e
O4 - HKLM\..\RunServices: [Microsoft Update Machine] winini.exe
O4 - HKCU\..\Run: [Microsoft Update Machine] winini.exe
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dl
O8 - Extra context menu item: Search &Dictionary - C:\Program files\Lexico\Toolbar\dicti
O8 - Extra context menu item: Search &Thesaurus - C:\Program files\Lexico\Toolbar\thesa
O16 - DPF: {F0E2D69A-DC2F-4E9B-A993-6
All the rest of these things too some are the same as whats in your process so removing them or using hijack to remove these from startup will help.. (if hijackthis can do that) Â some spyware will just reinstall or put it back in right after you stop them.
I would suggest using Bullet Proof Spyware(BPS) remover. Â Again that is my all time favorite. Â IE: Adaware and spybot search and destroy and X-clearner may catch (for example) 400 or 500 instances of spyware, whereas end result with BPS, it may detect several thousand after you've used all the other ones. Â However as I stated earlier, I use MULTIPLE tools, not just one. Â Try CWShredder as well, and get spybot search and destroy, it's free. Â Suggest picking up X-cleaner free version as well. Â These will all pick up different ones that one or the other may not be able to find or remove. Â Also try running these programs in safe mode. Â That may be part of the problem is that some of these may be running in memory and the removal programs may not be able to touch them.
also if you get BPS, try using their hijack scanner and post it's log here as well...it may pick up stuff that hijackthis may not.

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Thanks again.
Process      PID      CPU      Description      Company Name
System Idle Process      0      77           Â
 DPCs      n/a      1      Hardware Interrupts     Â
 DPCs      n/a      3      Deferred Procedure Calls     Â
 System      4                Â
 smss.exe      608            Windows NT Session Manager      Microsoft Corporation
  csrss.exe      664            Client Server Runtime Process      Microsoft Corporation
  winlogon.exe      688            Windows NT Logon Application      Microsoft Corporation
  services.exe      732      3      Services and Controller app      Microsoft Corporation
   svchost.exe      1016            Generic Host Process for Win32 Services      Microsoft Corporation
   siSpamFilterEngine.exe      528                 GIANT Company Software
   svchost.exe      1116            Generic Host Process for Win32 Services      Microsoft Corporation
   svchost.exe      1388            Generic Host Process for Win32 Services      Microsoft Corporation
   svchost.exe      1432            Generic Host Process for Win32 Services      Microsoft Corporation
   spoolsv.exe      1728            Spooler SubSystem App      Microsoft Corporation
   alg.exe      1856            Application Layer Gateway Service      Microsoft Corporation
   CCEVTMGR.EXE      1888            Event Manager Service      Symantec Corporation
   compaq-rba.exe      1900            RBA      NeoPlanet
   NAVAPSVC.EXE      1596            Norton AntiVirus Auto-Protect Service      Symantec Corporation
   NPROTECT.EXE      180            Norton Protection Status      Symantec Corporation
   NOPDB.EXE      784            NOPDB      Symantec Corporation
   svchost.exe      1396            Generic Host Process for Win32 Services      Microsoft Corporation
  lsass.exe      744            LSA Shell (Export Version)      Microsoft Corporation
explorer.exe      1664            Windows Explorer      Microsoft Corporation
 atiptaxx.exe      2016            ATI Desktop Control Panel      ATI Technologies, Inc.
 SynTPLpr.exe      2024            TouchPad Driver Helper Application      Synaptics, Inc.
 SynTPEnh.exe      2032            Synaptics TouchPad Enhancements      Synaptics, Inc.
 eabservr.exe      2040            eabsrvr      Compaq
 ccApp.exe      168            Common Client CC App      Symantec Corporation
 Portctrl.exe      216            Fax printer driver control program for SmarThru      Samsung Electronics Co., Ltd., Samsung Software Center.
 Ikeymain.exe      232                Â
 Amoumain.exe      220                Â
 siService.exe      264      1            GIANT Company Software, inc.
 winini.exe      328      3           Â
 cashback.exe      336            CashBack Module      eXact Advertising
 nls.exe      348            NLS Module      eXact Advertising
 msmsgs.exe      388            Messenger      Microsoft Corporation
 ctfmon.exe      416            CTF Loader      Microsoft Corporation
 iexplore.exe      2788      1      Internet Explorer      Microsoft Corporation
 procexp.exe      3136      11      Sysinternals Process Explorer      Sysinternals
Process: System Idle Process Pid: 0
Type      Name






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Just by going to Task Manager, and ending the process winini.exe, it seems to stop the internet traffic!!!
But isn't that for automatic Windows update?
You mentioned to run services.msc, but I can't find winini.exe, where can I find it in services.msc?
Thanks,
Andrew
Winini.exe may not show up in services.msc
A good clue concerning this comes from your Process Explorer log -
you'll notice that there is no description or company name for winini.exe - that's a "Red Flag"!
Look at C:\WINDOWS\System32\winini
what does it show - manufacturer - version?
Also, just because you see a "supposedly" valid name listed in your HijackThis log -
"O4 - HKCU\..\Run: [Microsoft Update Machine] winini.exe" -
does not necessarily, mean that it's a valid file - we see this quite often in HJT logs.
It's one of the ways that these "malware" writers have of trying to hide these things.
Make sure "System Restore" is disabled.
Turn on "Show all Files and Folders", including hidden and system.
Use Task Manager and Kill winini.exe.
Search your ENTIRE computer for any instances of winini.exe - particularly,
the "Prefetch", "dllcache", "System32", folders and all temp folders.
delete any that you find.
Clean out all your temp files:
# C:\Windows\Temp - delete ALL of the CONTENTS of the folder - Not the "temp" folder itself!
# C:\Documents and Settings\<Your Profile>\Local Settings\Temporary Internet Files (all contents)
 <=This will delete all your cached internet content including cookies.
 This is recommended and strongly suggested!
# C:\Documents and Settings\<Your Profile>\Local Settings\Temp (all contents)
# C:\Documents and Settings\<Any other users Profile>\Local Settings\Temporary Internet Files (all contents)
# C:\Documents and Settings\<Any other users Profile>\Local Settings\Temp (all contents)
# Empty your "Recycle Bin".
Reboot your computer and post a new HijackThis log here.
Good luck!
RF
Ross is right. However, there's something else you can do with Process Explorer. When you run it, you can double-click on the entry for winini.exe. It'll give you more information on what is running and where, and even an IP address of where it's connecting to if available. You can post that info here.
Good Vibes!
Lobo

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
RF
Good Vibes!
Lobo






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
By the way, Ikeymain.exe is an Internet Keyboard driver; and Amoumain.exe is a driver for a A4 mouse. Both are safe.
Good Vibes!
Lobo
I think we're very close to identifying the problem!!! Thanks guys.
Regarding the winini.exe in C:\windows\system32, it doesn't have any info on manufacturer or version, but it was created on July 23, 2004, which I believe is exactly the date I start to face this problem! So this is likely the file that causes the internet traffic. By the way, this winini.exe is a hidden, system file.
When searching my harddisk for winini.exe, I found two instances as follows:
c:\windows\prefetch\WININI
c:\windows\system32\winini
I've deleted the c:\windows\system32\winini
Before I delete the winini.exe, I ran Process Explorer and double-click it, and there seems to be a lot of activity going on with green and red highlights turning on and off,and many IP addresses, etc, it's so much that I don't think I can post it here. But winini.exe seems like the culprit, you agree?
After deleting my temp files, emptying recycle bin, reboot, I ran the Hijack This again, and the log info is as below:
Logfile of HijackThis v1.98.0
Scan saved at 12:02:55 PM, on 2/8/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools
C:\WINDOWS\System32\atipta
C:\Program Files\Synaptics\SynTP\SynT
C:\Program Files\Synaptics\SynTP\SynT
C:\Program Files\Compaq\EAB\EabServr.
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Samsung\SmarThru\POR
C:\PROGRA~1\WIRELE~1\Keybo
C:\PROGRA~1\WIRELE~1\Mouse
C:\Program Files\iHateSpam4.0\siServi
C:\Program Files\CashBack\bin\cashbac
C:\Program Files\NaviSearch\bin\nls.e
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon
C:\Program Files\iHateSpam4.0\siSpamF
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEED
C:\WINDOWS\System32\svchos
C:\Program Files\Hijack This\HijackThis.exe
R0 - HKCU\Software\Microsoft\In
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: Lexico Toolbar - {11359F4A-B191-42d7-905A-5
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
O3 - Toolbar: Dictionary.com - {11359F4A-B191-42D7-905A-5
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynT
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynT
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\system32\spool\
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [GW Port Controller] C:\Program Files\Samsung\SmarThru\POR
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCh
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\WIRELE~1\Keybo
O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\WIRELE~1\Mouse
O4 - HKLM\..\Run: [siService.exe] "C:\Program Files\iHateSpam4.0\siServi
O4 - HKLM\..\Run: [Microsoft Update Machine] winini.exe
O4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashbac
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.e
O4 - HKLM\..\RunServices: [Microsoft Update Machine] winini.exe
O4 - HKLM\..\RunOnce: [Compaq_RBA] C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
O4 - HKCU\..\Run: [Microsoft Update Machine] winini.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Ad
O4 - Global Startup: Microsoft Office.lnk = C:\MS Office 2000\Office10\OSA.EXE
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dl
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\MSOFFI~1\Office10
O8 - Extra context menu item: Search &Dictionary - C:\Program files\Lexico\Toolbar\dicti
O8 - Extra context menu item: Search &Thesaurus - C:\Program files\Lexico\Toolbar\thesa
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A
O9 - Extra button: Advisor - {9EBC1900-098C-40D1-9AA0-6
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
O16 - DPF: {41F17733-B041-4099-A042-B
O16 - DPF: {644E432F-49D3-41A1-8DD5-E
O16 - DPF: {F0E2D69A-DC2F-4E9B-A993-6
O17 - HKLM\System\CCS\Services\T
Thanks,
Andrew
but some bad things still exist:
O4 - HKLM\..\Run: [Microsoft Update Machine] winini.exe
O4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashbac
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dl
O17 - HKLM\System\CCS\Services\T
Try removing those. Â
I also see in your running process STILL:
C:\Program Files\CashBack\bin\cashbac
C:\Program Files\NaviSearch\bin\nls.e
What other programs have you used to remove or scan or check for viruses and spyware?
Again, the one's I listed earlier you should continue to use or try.

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Using HiJack This, after checking that item, and fixing it, the winini.exe still appears after rescanning. No matter how many times I do, it still reappears. Why? What should I do?
I leave the cashback.exe because I know what it is. I've deleted the O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dl
I've used Norton Anti-virus, Ad-aware 6.0, Hijack This, Spyware Remover, Process Explorer so far.
However, my network traffic has stopped since I deleted the winini.exe file.
O4 - HKLM\..\Run: [Microsoft Update Machine] winini.exe
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dl
O17 - HKLM\System\CCS\Services\T
Try CWShredder, and Spybot Search and Destroy.
I would also suggest using a different Anti virus software just to see. Â
Get Trendmicro's Syscleaner. Â It too will also scan for both viruses and some spyware.
Most likely your traffic has stopped due to removal of the winini.exe file, and you may not have any probs anymore with it. Â You can....if you feel like you know how is to go into the registry (regedit) and remove winini.exe from any run commands in the registry...but only do it if you feel comfortable. Â You can always make a backup and then go from there.
Run Process Explorer again and see if winini.exe is still reported. If so, double click on it to get a detailed report on its activity; it may be working in association with a DLL that, if that's the case, will have to be removed as well.
Good Vibes!
Lobo






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Thank you very much for solving my problem. While it seems I still have a few spyware lying around, the main problem of high network traffic is solved and I do not want to bother you again. I will try other spyware remover applications when I have the time and settle on my own.
I've also run the Process Explorer and don't see winini.exe.
Thank you once again, and you guys are just amazing!
Andrew
Good Vibes!
Lobo
You're not bothering us - as Lobo said above:
"we're here to help"
Thanks - best regards - let us know if you have further problems.
Cheers and good luck!
RF
P.S. - also good to see that you spread the points around - acknowledge the efforts! :)

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
I have this problem too, and now I know what to do, thanks very much.
I have a "msjarun.exe" that is like winini.exe, have you some infos on this program?
We may, but you'll need to start a new Question in order to get the full advantages of Experts Exchange's system.
Good Vibes!
Lobo
Anti-Virus Apps
--
Questions
--
Followers
Top Experts
Anti-virus software was originally developed to detect and remove computer viruses. However, with the proliferation of other kinds of malware, antivirus software started to provide protection from other computer threats. In particular, modern antivirus software can protect from malicious browser helper objects (BHOs), browser hijackers, ransomware, keyloggers, backdoors, rootkits, trojan horses, worms, malicious layered service providers (LSPs), dialers, fraud tools, adware and spyware. Some products also include protection from other computer threats, such as infected and malicious URLs, spam, scam and phishing attacks, online identity theft (privacy), online banking attacks, social engineering techniques, Advanced Persistent Threat (APT), botnets and DDoS attacks.