Parasite help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by LauraJ, Apr 17, 2004.

  1. LauraJ

    LauraJ Private E-2

    I am having problems with my pc - internet programs that keep coming back no matter what I do. I have run AdAware, Spy Killer, and HiJack This. Can someone please look at my log file and tell me if there is anything here that may be causing this? Thank you very much.
    Logfile of HijackThis v1.97.7
    Scan saved at 8:48:16 PM, on 04/17/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\hkcmd.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Common Files\Dell\EUSW\Support.exe
    C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe
    C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\WINDOWS\bgbfzc.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\SpyKiller\spykiller.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\Program Files\Trend Micro\PC-cillin 2000\PNTIOMON.exe
    C:\Program Files\RingCentral\RingCentral\RCUI.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Trend Micro\PC-cillin 2000\pccntupd.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\System32\msiexec.exe
    C:\Program Files\550AccessToolbar\550AccessToolbar.exe
    C:\Documents and Settings\Laura\Desktop\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://smbusiness.dellnet.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/keyword/%s
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://c:\program files\550accesstoolbar\proxy.pac
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {16CC93F1-3CF3-4AF3-B124-BB231B9A809B} - C:\WINDOWS\bspfvd.dll
    O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: 550Access Toolbar - {26CB33C5-1F3C-4C52-8B26-29D6E0635770} - C:\Program Files\550AccessToolbar\550AccessToolbar.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
    O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
    O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
    O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    O4 - HKLM\..\Run: [xzizng] C:\WINDOWS\bgbfzc.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O4 - Global Startup: Real-time Monitor.lnk = ?
    O4 - Global Startup: RingCentral.lnk = C:\Program Files\RingCentral\RingCentral\RCUI.exe
    O8 - Extra context menu item: 550Access Toolbar Search - C:\Program Files\550AccessToolbar\550accessmenusearch.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: 550Access Toolbar (HKLM)
    O9 - Extra 'Tools' menuitem: 550Access Toolbar (HKLM)
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: ICQ Lite (HKLM)
    O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
    O9 - Extra button: Real.com (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://download.yahoo.com/dl/mail/ymmapi.cab
     
  2. LauraJ

    LauraJ Private E-2

    Thanks.....

    Thanks for your help. The system seems to be running better, but I'm still getting the internet things in the background. I did install 550 Access, but have just uninstalled it. It's a site that comes up as "advnt". Sometimes 01, sometimes 05. It runs on start-up, but flashes by very quickly. I've searched all files and folders, but can only find the cookies it leaves behind, and even after clearing my internet files, it comes back on the next startup. Also, when I first open IE, the page comes up blank, even though the address bar says the page is open. I click refresh, and it fills in, then works fine after that. I'm not sure if the 2 are related. Thanks again for your help. LauraJ
     
  3. jujet84

    jujet84 Master Sergeant

  4. LauraJ

    LauraJ Private E-2

    Ran CWShredder

    Thanks so much - I did download Shredder and ran it - it said everything was clean except this: windows/sys_ai_client_loader.exe. It said it couldn't identify the file for sure, but it may be part of CWS.Contro.4. Do you know? Thanks again.
     
  5. LauraJ

    LauraJ Private E-2

    You were right!

    I renamed the file and deleted it, and it doesn't appear to be anything I need, and for the first time, didn't see it loading in the background when the system re-booted. I searched the registry, and did find the "advnt" and the "sfondi" which I knew was part of it, as well as the
    windows/sys_ai_client_loader.exe file - all in the same folder. Can I just delete this folder from the registry?
     
  6. jujet84

    jujet84 Master Sergeant

    Good advice from Robo------- Laura why don't you leave as is for a week.It's not doing any harm. If no problems delete si ation. Better to be safe than sorry. :) :cool:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds