After already sugesting CWS shredder I now urge you to use HijackThis and
either post the scan-log here or in the HJT forum.
http://mjc1.com/mirror/hjt/
Thanks SFB,
I ran Hijackthis and got the below log. Then I ran CWSShredder and it
came up clean except for one "CWS variant" which it needed me to
reboot to clean. Ran again after reboot and CWSShredder claimed clean.
Do you see anything in the HijackThis log?
Thanks again!
Jaz
==============================
Logfile of HijackThis v1.97.7
Scan saved at 1:44:55 PM, on 2/26/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Programs\Norton AntiVirus\navapsvc.exe
C:\Programs\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\CTHELPER.EXE
C:\WINNT\system32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Programs\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Documents and Settings\jaz\Application Data\saer.exe
C:\WINNT\system32\wnsintit.exe
C:\Programs\SpywareGuard\sgmain.exe
C:\Programs\SpywareGuard\sgbhp.exe
C:\Programs\MozillaFirebird\MozillaFirebird.exe
C:\Programs\Utils\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.searchant.com/sp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.searchant.com/sp
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant
=
http://www.searchant.com/sp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.searchant.com/sp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.searchant.com/sp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant
=
http://www.searchant.com/sp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.searchant.com/r=6&s=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName
=
R3 - URLSearchHook: IncrediFindBHO Class -
{5D60FF48-95BE-4956-B4C6-6BB168A70310} -
C:\Programs\INCRED~1\BHO\INCFIN~1.DLL
O1 - Hosts: 172.16.30.16 ganymede harbell.<snip>.net
O2 - BHO: SpywareGuard Download Protection -
{4A368E80-174F-4872-96B5-0B27DDD11DB2} -
C:\Programs\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\Programs\Spybot\SDHelper.dll
O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} -
C:\Programs\INCRED~1\BHO\INCFIN~1.DLL
O2 - BHO: (no name) - {BB9361E5-52F8-E083-E7AB-4576D31A9DC0} - (no
file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} -
C:\Programs\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus -
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programs\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: 2020SEARCH2 - {4E7BD74F-2B8D-469E-92C6-CE7EB590A94D} -
C:\WINNT\2020Search2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon
initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [FinePrint Dispatcher v5]
C:\WINNT\system32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec
Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [version] C:\WINNT\system32\version.exe
O4 - HKLM\..\Run: [WinEssential] C:\WINNT\system32\Keyhost.exe
O4 - HKLM\..\Run: [updater] C:\Programs\Common
files\updater\wupdater.exe
O4 - HKLM\..\Run: [Zone Labs Client]
C:\Programs\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKCU\..\Run: [ntbalckup.exe] C:\WINNT\system32\ntbalckup.exe
O4 - HKCU\..\Run: [Atro] C:\Documents and Settings\jaz\Application
Data\saer.exe
O4 - HKCU\..\Run: [WNSC] C:\WINNT\system32\wnsintit.exe
O4 - Startup: SpywareGuard.lnk = C:\Programs\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel
present
O10 - Unknown file in Winsock LSP: c:\winnt\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\inetadpt.dll
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37997.7060763889
O17 -
HKLM\System\CCS\Services\Tcpip\..\{5A4B41E3-8E4B-4A6B-8C3C-6CF2FFC6C813}:
NameServer = 4.2.2.1,4.2.2.2
O17 -
HKLM\System\CS1\Services\Tcpip\..\{5A4B41E3-8E4B-4A6B-8C3C-6CF2FFC6C813}:
NameServer = 4.2.2.1,4.2.2.2
O17 -
HKLM\System\CS2\Services\Tcpip\..\{5A4B41E3-8E4B-4A6B-8C3C-6CF2FFC6C813}:
NameServer = 4.2.2.1,4.2.2.2
=====================================
(Please excuse the 'burp' when replying)