
I need help ridding my system of several spyware/adware and virus programs. The problem seems to be growing with each step I take to rid these problems from my system.
I have run Ad-Aware, Spybot, VCom's version of PC-Cillian and use Zone Alarm. My system is Windows 2000 Pro with Update 4 installed.
I have supposedly removed the following problems with Ad-Aware, Spybot & VCom:
worm_bagle.z
worm_mydoom.m
worm_sober.I
adware.elitebar
troj_small.aa
worm_netsky.p
dploader.exe
twink64.exe
wuclient.exe
xpsp2fw.exe
However, I'm still being bombarded with hijacked IE (v6) windows, EliteBar contnues to hijack any attempt to browse with IE and programs are loading very slowly (particularly IE).
My latest scan with Ad-Aware and VCOM show no files with problems yet they obviously still exist. It seems that once something is deleted it is being re-installed from somewhere (I have discontected from the internet and this still happens).
Here is a current Hijack This log:
Logfile of HijackThis v1.98.2
Scan saved at 12:49:34, on 12/15/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
E:\PROGRA~1\VCOM\SYSTEM~1\MXTask.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
E:\Program Files\scanner\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04. exe
E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
E:\Program Files\Iomega HotBurn Pro\Autolaunch.exe
C:\WINNT\system32\aaarsehl.exe
C:\WINNT\system32\internat.exe
E:\Program Files\scanner\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\Hijack This\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://aflashcounter.com/?a=2
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL =
http://aflashcounter.com/?a=2
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.themoscowtimes.ru/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://aflashcounter.com/?a=2
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://aflashcounter.com/?a=2
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL =
http://aflashcounter.com/?a=2
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL =
http://aflashcounter.com/?a=2
F3 - REG:win.ini: load=
F3 - REG:win.ini: run=C:\WINNT\system32\services\msxmidi.exe
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINNT\EliteToolBar\EliteToolBar version 58.dll
O2 - BHO: (no name) - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] E:\Program Files\scanner\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RCScheduleCheck] E:\Program Files\VCOM\Recovery Commander\RCSCHED.EXE -CHECK
O4 - HKLM\..\Run: [Fix-It AV] E:\PROGRA~1\VCOM\SYSTEM~1\MemCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04. exe
O4 - HKLM\..\Run: [Zone Labs Client] "e:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Drag'n'Drop_Autolaunch] "E:\Program Files\Iomega HotBurn Pro\Autolaunch.exe"
O4 - HKLM\..\Run: [F379588B] C:\WINNT\system32\aaarsehl.exe
O4 - HKLM\..\Run: [kalvsys] C:\winnt\system32\kalvxib32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [F379588B] C:\WINNT\system32\aaarsehl.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {578FC4E3-151E-456c-AF8E-B63061EFE228}} - (no file)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{58E12C35-F85B-4C65-BFA7-9ADA0E6AA406}: NameServer = 192.168.1.1
I would appreciate all the help you can offer!
Thanks!!