Spyware - the little critter keeps re-spawning
Discussion
Folks, I am having a 'mare with what I think is some spyware that is totally driving me mad. I've posted on this before and tried various suggestions, but nothing has worked.
The problem is that I have some sort of spyware / virus whereby a programme loads a .dll application extension to my c:windowssystem32 directory which causes a hijack to Internet Explorer whereby my homepage is redirected to "about:blank" and an add for spyware removal software pops up. No big deal you may say, but when this happens I cannot get to many sites (e.g. Hotmail and eBay) and the browser starts to load them but then switches back to "about:blank", so I cannot access these sites.
If I shut down IE and disconnect from my service provider I can then delete the .dll manually, but it comes back sometime later (sometimes after a few minutes and others after a few hours) with a different filename. That said, it seems this has taken a new twist as I now cannot delete the .dll manually as per the above process - so I'm even more stuck.
I run Norton Anti-Virus as my main protection, and have Zone Alarm and Spybot working as well. All 3 are useless at detecting or deleting this spyware / virus.
I have also tried:
* Ad-Aware
* Spy Subtract
* CWShredder
* Hijack This
* Startpage Guard
which don't work either (Hijack this might, but I don't have a clue how to read the output of it's scans).
With my extremely limited computing knowledge, I am guessing that there is some sort of programme constantly running that causes the .dll to re-spawn after I delete it manually - buy how to find and remove this programme?
Once I get this cleaned I have vowed to stop using IE as much as possible.
Can anyone help.
Many thanks,
gixxer
The problem is that I have some sort of spyware / virus whereby a programme loads a .dll application extension to my c:windowssystem32 directory which causes a hijack to Internet Explorer whereby my homepage is redirected to "about:blank" and an add for spyware removal software pops up. No big deal you may say, but when this happens I cannot get to many sites (e.g. Hotmail and eBay) and the browser starts to load them but then switches back to "about:blank", so I cannot access these sites.
If I shut down IE and disconnect from my service provider I can then delete the .dll manually, but it comes back sometime later (sometimes after a few minutes and others after a few hours) with a different filename. That said, it seems this has taken a new twist as I now cannot delete the .dll manually as per the above process - so I'm even more stuck.
I run Norton Anti-Virus as my main protection, and have Zone Alarm and Spybot working as well. All 3 are useless at detecting or deleting this spyware / virus.
I have also tried:
* Ad-Aware
* Spy Subtract
* CWShredder
* Hijack This
* Startpage Guard
which don't work either (Hijack this might, but I don't have a clue how to read the output of it's scans).
With my extremely limited computing knowledge, I am guessing that there is some sort of programme constantly running that causes the .dll to re-spawn after I delete it manually - buy how to find and remove this programme?
Once I get this cleaned I have vowed to stop using IE as much as possible.
Can anyone help.
Many thanks,
gixxer
This is all from my somewhat hazy memory but there is a hijack around which uses a file called HOSTS somewhere in your system32 folder. In this it has a list of domains (if you open it in notepad), when these domains are requested this HOSTS file makes your browser go to 127.0.0.1 (i.e. Your computer). You can delete the contents of this file safely. That may or may not solve the hijack problem but probably wont stop it happening again.
I see you have tried the usual suspects in the anti spyware field and I have no more to add really!
Ben
I see you have tried the usual suspects in the anti spyware field and I have no more to add really!
Ben
BliarOut said:
Post the output of hijack this.
Here it is. Mostly double-dutch to me.
Logfile of HijackThis v1.97.7
Scan saved at 13:44:21, on 05/01/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedccProxy.exe
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
C:Program FilesNorton Internet SecurityISSVC.exe
C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:Program FilesAlcatelSpeedTouch USBDragdiag.exe
C:Program FilesIomegaAutoDiskADUserMon.exe
C:Program FilesRoxioEasy CD Creator 6AudioCentralRxMon.exe
C:Program FilesQuickTimeqttask.exe
C:Program FilesiTunesiTunesHelper.exe
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Documents and SettingsGeoffGeoff's DataApps one Alarm_free firewall oneAlarmzlclient.exe
C:Program FilesWasherwasher.exe
C:Program FilesMicrosoft ActiveSyncWCESCOMM.EXE
C:Program FilesRoxioEasy CD Creator 6AudioCentralPlaylist.exe
C:Documents and SettingsGeoffGeoff's DataAppsSpybot - Search and Destroyversion 1.3Spybot - Search & DestroyTeaTimer.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesFinePixViewerQuickDCF.exe
C:Program FilesHewlett-PackardAiOhp officejet g seriesBinhpoavn07.exe
C:Program FilesInterVideoCommonBinWinCinemaMgr.exe
C:Program FilesCommon FilesMicrosoft SharedWorks Sharedwkcalrem.exe
C:Program FilesNikonPictureProjectNkbMonitor.exe
C:Program FilesSony EricssonMobileaudevicemgr.exe
C:Program FilesPsionPsiWinPsconsv.exe
C:Program FilesinterMuteSpySubtractSpySub.exe
C:Program FilesSonyVAIO Action SetupVAServ.exe
C:PROGRA~1SONYER~1MobileCONNEC~1CONNMN~1.EXE
C:PROGRA~1PsionPsiWinElogerr.exe
C:Program FilesRoadAngelRoadAngel.exe
c:Program FilesIntuwave LtdSharedmRouterRunTimemRouterRuntime.exe
C:PROGRA~1IomegaSystem32AppServices.exe
C:Program FilesNorton Internet SecurityNorton AntiVirus avapsvc.exe
C:PROGRA~1SONYER~1MobileMOBILE~1EPMWOR~1.EXE
C:WINDOWSSystem32 vsvc32.exe
C:PROGRA~1HEWLET~1AiOSharedBinhpoevm07.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
C:WINDOWSsystem32 oneLabsvsmon.exe
C:Program FilesIomegaAutoDiskADService.exe
C:WINDOWSsystem32hpoipm07.exe
C:Program FilesCommon FilesSymantec SharedSecurity CenterSymWSC.exe
C:Program FilesiPod iniPodService.exe
C:Program FilesHewlett-PackardAiOShared inhpOSTS07.exe
C:Program FilesHewlett-PackardAiOShared inhpOFXM07.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesCommon FilesSymantec SharedAdBlockingNSMdtr.exe
C:Documents and SettingsGeoffGeoff's DataAppsAutorunsautoruns.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesMicrosoft OfficeOfficeWINWORD.EXE
C:Documents and SettingsGeoffGeoff's DataAppsSpybot - Search and Destroyversion 1.3Spybot - Search & DestroySpybotSD.exe
C:Program FilesMicrosoft OfficeOfficeEXCEL.EXE
C:Documents and SettingsGeoffGeoff's DataAppsHijack thisHijackThis.exe
C:WINDOWSsystem32wuauclt.exe
C:Program FilesMessengermsmsgs.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:Program FilesCommon FilesSymantec SharedAdBlockingNISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:Program FilesNorton Internet SecurityNorton AntiVirusNavShExt.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:Program FilesMSN Toolbar 1.01.1629.0en-usmsntb.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:Program FilesCommon FilesSymantec SharedAdBlockingNISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:Program FilesNorton Internet SecurityNorton AntiVirusNavShExt.dll
O4 - HKLM..Run: [SpeedTouch USB Diagnostics] "C:Program FilesAlcatelSpeedTouch USBDragdiag.exe" /icon
O4 - HKLM..Run: [Microsoft Works Portfolio] C:Program FilesMicrosoft WorksWksSb.exe /AllUsers
O4 - HKLM..Run: [ADUserMon] C:Program FilesIomegaAutoDiskADUserMon.exe
O4 - HKLM..Run: [RoxioEngineUtility] "C:Program FilesCommon FilesRoxio SharedSystemEngUtil.exe"
O4 - HKLM..Run: [RoxioAudioCentral] "C:Program FilesRoxioEasy CD Creator 6AudioCentralRxMon.exe"
O4 - HKLM..Run: [zSPGuard] c:program filespjwspguardspguard.exe /s /r
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [iTunesHelper] C:Program FilesiTunesiTunesHelper.exe
O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 - HKLM..Run: [IS CfgWiz] C:Program FilesNorton Internet Securitycfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM..Run: [Zone Labs Client] "C:Documents and SettingsGeoffGeoff's DataApps one Alarm_free firewall oneAlarmzlclient.exe"
O4 - HKLM..Run: [MSConfig] C:WINDOWSPCHealthHelpCtrBinariesMSConfig.exe /auto
O4 - HKCU..Run: [Washer] C:Program FilesWasherwasher.exe /0
O4 - HKCU..Run: [H/PC Connection Agent] "C:Program FilesMicrosoft ActiveSyncWCESCOMM.EXE"
O4 - HKCU..Run: [SpybotSD TeaTimer] C:Documents and SettingsGeoffGeoff's DataAppsSpybot - Search and Destroyversion 1.3Spybot - Search & DestroyTeaTimer.exe
O4 - Startup: Road Angel.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: Exif Launcher.lnk = C:Program FilesFinePixViewerQuickDCF.exe
O4 - Global Startup: HPAiODevice(hp officejet g series) - 2.lnk = C:Program FilesHewlett-PackardAiOhp officejet g seriesBinhpoavn07.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:Program FilesInterVideoCommonBinWinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:Program FilesNikonPictureProjectNkbMonitor.exe
O4 - Global Startup: Phone Connection Monitor.lnk = ?
O4 - Global Startup: PsiWin 2.3 Connection Server.lnk = C:Program FilesPsionPsiWinPsconsv.exe
O4 - Global Startup: SpySubtract.lnk = C:Program FilesinterMuteSpySubtractSpySub.exe
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerRestrictions present
O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O15 - Trusted Zone: *.Sony-europe.com
O15 - Trusted Zone: *.Sonystyle-europe.com
O16 - DPF: ppctlcab - http://69.44.122.156/scanner/ppctlcab.cab
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v43/yacscom.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://69.44.122.156/scanner/axscanner.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-17.cab
O16 - DPF: {71057C18-0507-4747-86BC-E11CE7512C5F} (mailhelper Class) - http://register.btinternet.com/templates/btmailcontrol013.cab
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - www.microsoft.com/security/controls/SassCln.CAB
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/region/reg_eu/techsupp/activedata/ActiveData.cab
O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) - http://register.btinternet.com/templates/btwebcontrol023.cab
O17 - HKLMSystemCCSServicesTcpip..{33C739C7-920F-4A14-81E0-5F6F1183F329}: NameServer = 194.74.65.86 194.72.9.44
O17 - HKLMSystemCS1ServicesTcpip..{33C739C7-920F-4A14-81E0-5F6F1183F329}: NameServer = 194.74.65.86 194.72.9.44
2nd part of file (would not take it all in one post)
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:Program FilesCommon FilesSymantec SharedAdBlockingNISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:Program FilesNorton Internet SecurityNorton AntiVirusNavShExt.dll
O4 - HKLM..Run: [SpeedTouch USB Diagnostics] "C:Program FilesAlcatelSpeedTouch USBDragdiag.exe" /icon
O4 - HKLM..Run: [Microsoft Works Portfolio] C:Program FilesMicrosoft WorksWksSb.exe /AllUsers
O4 - HKLM..Run: [ADUserMon] C:Program FilesIomegaAutoDiskADUserMon.exe
O4 - HKLM..Run: [RoxioEngineUtility] "C:Program FilesCommon FilesRoxio SharedSystemEngUtil.exe"
O4 - HKLM..Run: [RoxioAudioCentral] "C:Program FilesRoxioEasy CD Creator 6AudioCentralRxMon.exe"
O4 - HKLM..Run: [zSPGuard] c:program filespjwspguardspguard.exe /s /r
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [iTunesHelper] C:Program FilesiTunesiTunesHelper.exe
O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 - HKLM..Run: [IS CfgWiz] C:Program FilesNorton Internet Securitycfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM..Run: [Zone Labs Client] "C:Documents and SettingsGeoffGeoff's DataApps one Alarm_free firewall oneAlarmzlclient.exe"
O4 - HKLM..Run: [MSConfig] C:WINDOWSPCHealthHelpCtrBinariesMSConfig.exe /auto
O4 - HKCU..Run: [Washer] C:Program FilesWasherwasher.exe /0
O4 - HKCU..Run: [H/PC Connection Agent] "C:Program FilesMicrosoft ActiveSyncWCESCOMM.EXE"
O4 - HKCU..Run: [SpybotSD TeaTimer] C:Documents and SettingsGeoffGeoff's DataAppsSpybot - Search and Destroyversion 1.3Spybot - Search & DestroyTeaTimer.exe
O4 - Startup: Road Angel.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: Exif Launcher.lnk = C:Program FilesFinePixViewerQuickDCF.exe
O4 - Global Startup: HPAiODevice(hp officejet g series) - 2.lnk = C:Program FilesHewlett-PackardAiOhp officejet g seriesBinhpoavn07.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:Program FilesInterVideoCommonBinWinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:Program FilesNikonPictureProjectNkbMonitor.exe
O4 - Global Startup: Phone Connection Monitor.lnk = ?
O4 - Global Startup: PsiWin 2.3 Connection Server.lnk = C:Program FilesPsionPsiWinPsconsv.exe
O4 - Global Startup: SpySubtract.lnk = C:Program FilesinterMuteSpySubtractSpySub.exe
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerRestrictions present
O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O15 - Trusted Zone: *.Sony-europe.com
O15 - Trusted Zone: *.Sonystyle-europe.com
O16 - DPF: ppctlcab - http://69.44.122.156/scanner/ppctlcab.cab
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v43/yacscom.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://69.44.122.156/scanner/axscanner.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-17.cab
O16 - DPF: {71057C18-0507-4747-86BC-E11CE7512C5F} (mailhelper Class) - http://register.btinternet.com/templates/btmailcontrol013.cab
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - www.microsoft.com/security/controls/SassCln.CAB
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/region/reg_eu/techsupp/activedata/ActiveData.cab
O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) - http://register.btinternet.com/templates/btwebcontrol023.cab
O17 - HKLMSystemCCSServicesTcpip..{33C739C7-920F-4A14-81E0-5F6F1183F329}: NameServer = 194.74.65.86 194.72.9.44
O17 - HKLMSystemCS1ServicesTcpip..{33C739C7-920F-4A14-81E0-5F6F1183F329}: NameServer = 194.74.65.86 194.72.9.44
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:Program FilesCommon FilesSymantec SharedAdBlockingNISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:Program FilesNorton Internet SecurityNorton AntiVirusNavShExt.dll
O4 - HKLM..Run: [SpeedTouch USB Diagnostics] "C:Program FilesAlcatelSpeedTouch USBDragdiag.exe" /icon
O4 - HKLM..Run: [Microsoft Works Portfolio] C:Program FilesMicrosoft WorksWksSb.exe /AllUsers
O4 - HKLM..Run: [ADUserMon] C:Program FilesIomegaAutoDiskADUserMon.exe
O4 - HKLM..Run: [RoxioEngineUtility] "C:Program FilesCommon FilesRoxio SharedSystemEngUtil.exe"
O4 - HKLM..Run: [RoxioAudioCentral] "C:Program FilesRoxioEasy CD Creator 6AudioCentralRxMon.exe"
O4 - HKLM..Run: [zSPGuard] c:program filespjwspguardspguard.exe /s /r
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [iTunesHelper] C:Program FilesiTunesiTunesHelper.exe
O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 - HKLM..Run: [IS CfgWiz] C:Program FilesNorton Internet Securitycfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM..Run: [Zone Labs Client] "C:Documents and SettingsGeoffGeoff's DataApps one Alarm_free firewall oneAlarmzlclient.exe"
O4 - HKLM..Run: [MSConfig] C:WINDOWSPCHealthHelpCtrBinariesMSConfig.exe /auto
O4 - HKCU..Run: [Washer] C:Program FilesWasherwasher.exe /0
O4 - HKCU..Run: [H/PC Connection Agent] "C:Program FilesMicrosoft ActiveSyncWCESCOMM.EXE"
O4 - HKCU..Run: [SpybotSD TeaTimer] C:Documents and SettingsGeoffGeoff's DataAppsSpybot - Search and Destroyversion 1.3Spybot - Search & DestroyTeaTimer.exe
O4 - Startup: Road Angel.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: Exif Launcher.lnk = C:Program FilesFinePixViewerQuickDCF.exe
O4 - Global Startup: HPAiODevice(hp officejet g series) - 2.lnk = C:Program FilesHewlett-PackardAiOhp officejet g seriesBinhpoavn07.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:Program FilesInterVideoCommonBinWinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:Program FilesNikonPictureProjectNkbMonitor.exe
O4 - Global Startup: Phone Connection Monitor.lnk = ?
O4 - Global Startup: PsiWin 2.3 Connection Server.lnk = C:Program FilesPsionPsiWinPsconsv.exe
O4 - Global Startup: SpySubtract.lnk = C:Program FilesinterMuteSpySubtractSpySub.exe
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerRestrictions present
O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O15 - Trusted Zone: *.Sony-europe.com
O15 - Trusted Zone: *.Sonystyle-europe.com
O16 - DPF: ppctlcab - http://69.44.122.156/scanner/ppctlcab.cab
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v43/yacscom.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://69.44.122.156/scanner/axscanner.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-17.cab
O16 - DPF: {71057C18-0507-4747-86BC-E11CE7512C5F} (mailhelper Class) - http://register.btinternet.com/templates/btmailcontrol013.cab
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - www.microsoft.com/security/controls/SassCln.CAB
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/region/reg_eu/techsupp/activedata/ActiveData.cab
O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) - http://register.btinternet.com/templates/btwebcontrol023.cab
O17 - HKLMSystemCCSServicesTcpip..{33C739C7-920F-4A14-81E0-5F6F1183F329}: NameServer = 194.74.65.86 194.72.9.44
O17 - HKLMSystemCS1ServicesTcpip..{33C739C7-920F-4A14-81E0-5F6F1183F329}: NameServer = 194.74.65.86 194.72.9.44
Fix the two R1's below.
R1 - HKCUSoftwareMicrosoftInternet explorerSearch,SearchAssistant = about:blank
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
These shortcuts with the question marks look broken..... If the apps are gone, fix these too.
O4 - Startup: Road Angel.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Phone Connection Monitor.lnk = ?
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
Do you know what this is?
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-17.cab
Couldn't see anything else in there. See how it goes afterwards.
Before you run higjack this to fix, close down all apps/messenger etc.
R1 - HKCUSoftwareMicrosoftInternet explorerSearch,SearchAssistant = about:blank
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
These shortcuts with the question marks look broken..... If the apps are gone, fix these too.
O4 - Startup: Road Angel.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Phone Connection Monitor.lnk = ?
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
Do you know what this is?
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-17.cab
Couldn't see anything else in there. See how it goes afterwards.
Before you run higjack this to fix, close down all apps/messenger etc.
BliarOut said:
Fix the two R1's below.
R1 - HKCUSoftwareMicrosoftInternet explorerSearch,SearchAssistant = about:blank
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
These shortcuts with the question marks look broken..... If the apps are gone, fix these too.
O4 - Startup: Road Angel.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Phone Connection Monitor.lnk = ?
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
Do you know what this is?
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-17.cab
Couldn't see anything else in there. See how it goes afterwards.
Before you run higjack this to fix, close down all apps/messenger etc.
Fixed the lot (except the Road Angel thing) and nothing has changed. .dll is still there and cannot be deleted. Browser still diverting and unable to access hotmail, ebay etc.
Rats.
gixxer.
ywouldi said:
This is all from my somewhat hazy memory but there is a hijack around which uses a file called HOSTS somewhere in your system32 folder. In this it has a list of domains (if you open it in notepad), when these domains are requested this HOSTS file makes your browser go to 127.0.0.1 (i.e. Your computer). You can delete the contents of this file safely. That may or may not solve the hijack problem but probably wont stop it happening again.
I see you have tried the usual suspects in the anti spyware field and I have no more to add really!
Ben
Ben, thanks for this. I have removed the sites that were listed in this hosts file so let's see if that stops it happening again. Now if only I could delete that pesky .dll
gixxer.
malman said:
hijack this doesn't remove the dll it just removes references to it but it didn't look like it showed it anyway.
what was the name and path to the .dll
You might need to to a registry search to remove all references to it
Standard registry editor disclaimer applies here
Hi malman. My first run of Hijack did have a reference to the dll so I asked it to fix it, which didn't seem to help.
The dll is at c:windowssystem32molc.dll (note: every time it re-spawns the dll has a different name). When I search the registry for "molc.dll" I get 2 returns:
1)
Name: ab(Default)
Type: REG_SZ
Data: c:windowssystem32molc.dll
2)
Name: ab ThreadingModel
Type: REG_SZ
Data: Apartment
when I delete them both and do another registry search they reappear!
Help.
Open Task Manager (right-click taskbar) and click on Processes. Look for anything in there that you don't recognise, and search for it in Google. That will typically take you to WinTasks process library which will tell you what it is. Do this until you find dodgy ones. You can then search for them using Windows Explorer and delete them. Often you won't be able to delete them because they are in use. If you stop the process in Task Manager then delete the file quickly, it will often get rid before it gets a chance to start back up again.
I had a similar thing where one process was running and recreating the spyware every time I deleted it. The above procedure sorted it.
HTH
I had a similar thing where one process was running and recreating the spyware every time I deleted it. The above procedure sorted it.
HTH
BliarOut said:
Hosts SHOULD contain a localhost entry 127.0.0.1
If you've ballsed it up, there should be a hosts.sam just put the contents of hosts.sam inside hosts
(Dumbed down answer)
Andwhat's the dll
I left the localhost 127.0.0.1 entry and deleted the other site references, so the hosts file now only contains "127.0.0.1 localhost". Is that ok?
dll name is molc.dll, but everytime it re-spawns it comes back with a new name.
miniman said:
Open Task Manager (right-click taskbar) and click on Processes. Look for anything in there that you don't recognise, and search for it in Google. That will typically take you to WinTasks process library which will tell you what it is. Do this until you find dodgy ones. You can then search for them using Windows Explorer and delete them. Often you won't be able to delete them because they are in use. If you stop the process in Task Manager then delete the file quickly, it will often get rid before it gets a chance to start back up again.
I had a similar thing where one process was running and recreating the spyware every time I deleted it. The above procedure sorted it.
HTH
I did think of that, but there are a ridiculous number of processes I don't recognise - this could take quite some time.
Still, I've got to be patient

I've seen this on a customer machine. It means there is a process running that checks the registry then puts the entries back in if they are deleted. If you are lucky then this process is in the process list that hijack this showed. If not then its one of the spyware progs that hides itself from the process list. You need to use a process viewer util to uncover it.
I'm halfway out the door here and can't find my link to it at the moment but I will look for it later and post details if I can find it
I'm halfway out the door here and can't find my link to it at the moment but I will look for it later and post details if I can find it
Having now painstakingly analysed all 57 process running when I have nothing other than IE, Excel, and Task Manager open (IE to search the web to see if the process is dodgy, Excel to document findings, Task Manager to see the processes in the first place), I came up with the following potentially suspicious list:
* svchost.exe (various of these running - SYSTEM, LOCAL SERVICE and NETWORK SERVICE) - this is part of Windows but is also registered as W32.Welchia.worm. If it's not in c:windowssystem32 then be suspicious
* spoolsv.exe - Microsoft printer spooler process but also registered as Backdoor.Ciadoor.B Trojan. If not in c:windowssystem32 be suspicious.
* iexplorer.exe - main exe for internet explorer. Also registered as the Trojan.KillAV.B virus. Normal location of this file is C:program filesinternet exploreriexplorer.exe. If not it's a virus.
* Isass.exe - a systems process of Windows security mechanism, but also relates to Windang.worm, irc.ratsou.b, Webus.B, Mydoom.L, Randex.AR, Nimos.worm, which spread via floppy-disk, mass mailing or peer-to-peer sharing. Ok if located in c:windowssystem32. It's a virus otherwise.
* services.exe - vital part of Windows that manages the operation of starting and stopping services. Also deals with the automatic starting of services during boot-up. It's also a process registered as the W32.Randex.R Trojan. Ok if located in c:windowssystem32. It's a virus otherwise.
* winlogon.exe - Windows NT logon manager. It's also registered as the W32.Netsky.D@mm worm. Ok if located in c:windowssystem32. It's a virus otherwise.
* csrss.exe - main exe for Microsoft client/server Runtime server subsystem. Ok if located in c:windowssystem32. It's a virus otherwise.
* smss.exe - part of windows Session Manager subsystem. Also registered as the Win32.Ladex.a Trojan. Ok if located in c:windowssystem32. It's a virus otherwise.
* explorer.exe - windows programe manager or windows explorer. Also registered as w32.Codered and w32.mydoom.b@mm viruses. If in c:windowssystem 32 (or c:windows) then ok, otherwise it's a virus.
Having then downloaded Security Task Manager v1.6 I checked the locations of the above and they are all where they are supposed to be so seem not to be suspicious.
That said, I am somewhat suspicious of Isass.exe as I am sure my problems started once I started using peer-to-peer.
I presume Task Manager only displays visible processes, and my little critter is most likely hidden. Security Task Manager 1.6 also shows hidden processes but it didn't flag anything as suspicious either.
I am tying myself in knots here and can't seem to find a solution. Any ideas folks.
Thanks,
gixxer

* svchost.exe (various of these running - SYSTEM, LOCAL SERVICE and NETWORK SERVICE) - this is part of Windows but is also registered as W32.Welchia.worm. If it's not in c:windowssystem32 then be suspicious
* spoolsv.exe - Microsoft printer spooler process but also registered as Backdoor.Ciadoor.B Trojan. If not in c:windowssystem32 be suspicious.
* iexplorer.exe - main exe for internet explorer. Also registered as the Trojan.KillAV.B virus. Normal location of this file is C:program filesinternet exploreriexplorer.exe. If not it's a virus.
* Isass.exe - a systems process of Windows security mechanism, but also relates to Windang.worm, irc.ratsou.b, Webus.B, Mydoom.L, Randex.AR, Nimos.worm, which spread via floppy-disk, mass mailing or peer-to-peer sharing. Ok if located in c:windowssystem32. It's a virus otherwise.
* services.exe - vital part of Windows that manages the operation of starting and stopping services. Also deals with the automatic starting of services during boot-up. It's also a process registered as the W32.Randex.R Trojan. Ok if located in c:windowssystem32. It's a virus otherwise.
* winlogon.exe - Windows NT logon manager. It's also registered as the W32.Netsky.D@mm worm. Ok if located in c:windowssystem32. It's a virus otherwise.
* csrss.exe - main exe for Microsoft client/server Runtime server subsystem. Ok if located in c:windowssystem32. It's a virus otherwise.
* smss.exe - part of windows Session Manager subsystem. Also registered as the Win32.Ladex.a Trojan. Ok if located in c:windowssystem32. It's a virus otherwise.
* explorer.exe - windows programe manager or windows explorer. Also registered as w32.Codered and w32.mydoom.b@mm viruses. If in c:windowssystem 32 (or c:windows) then ok, otherwise it's a virus.
Having then downloaded Security Task Manager v1.6 I checked the locations of the above and they are all where they are supposed to be so seem not to be suspicious.
That said, I am somewhat suspicious of Isass.exe as I am sure my problems started once I started using peer-to-peer.
I presume Task Manager only displays visible processes, and my little critter is most likely hidden. Security Task Manager 1.6 also shows hidden processes but it didn't flag anything as suspicious either.
I am tying myself in knots here and can't seem to find a solution. Any ideas folks.
Thanks,
gixxer

Gassing Station | Computers, Gadgets & Stuff | Top of Page | What's New | My Stuff





what's the dll 