<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Another Virus/Hijack Removal Problem in Security</title>
<link>http://www.dslreports.com/forum/r12423314</link>
<description></description>
<language>en</language>
<pubDate>Thu, 26 Nov 2009 18:42:31 EDT</pubDate>
<lastBuildDate>Thu, 26 Nov 2009 18:42:31 EDT</lastBuildDate>

<item>
<title>Re: Another Virus/Hijack Removal Problem</title>
<link>http://www.dslreports.com/forum/remark,12568470</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : That uninstaller is best avoided according to several experts the antispyware community:<br><br>&raquo;<A HREF="http://forum.iamnotageek.com/t-805880.html" >forum.iamnotageek.com/t-805880.html</A><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Though MyPCTuneUp does attempt to remove many of the parasites<br>connected to the Transponder gang, it runs using their 'Thinstaller'<br>program also used by Transponder and FavoriteMan, which connects to<br>their servers and spews out information about your machine, such as<br>computer and account names, and what software is installed.<br><br>Advice: avoid.<br>--<br>Andrew Clover<br>mailto:and@doxdesk.com<br>&raquo;<A HREF="http://www.doxdesk.com/" >www.doxdesk.com/</A><HR></BLOCKQUOTE><br><br>Is This Software On Your Hard Drive?<br>How one of the Internet&#146;s largest and most secretive adware companies really operates. With new regulations coming, will it really reform?<br>&raquo;<A HREF="http://www.msnbc.msn.com/id/6689667/site/newsweek/" >www.msnbc.msn.com/id/6689667/site/newsweek/</A><br><br>Giving your email to MyPCtuneup.com in order to obtain a user ID starts SPM from Traffix!<br>&raquo;<A HREF="http://netrn.net/spywareblog/archives/2004/05/13/giving-your-email-to-mypctuneupcom-in-order-to-obtain-a-user-id-starts-spm-from-traffix/" >netrn.net/spywareblog/archives/2&middot;&middot;&middot;traffix/</A><br><br>Ceres.dll:<br>Attacking a firewall near you.<br>&raquo;<A HREF="http://www.vitalsecurity.org/ceres.htm" >www.vitalsecurity.org/ceres.htm</A><br><br>webhelper Alert - Transponder Gangs On the Move Ipinsight.net now MyPctuneup.com<br>&raquo;<A HREF="http://www.webhelper4u.com/tnewswritigs/mypctuneup.html" >www.webhelper4u.com/tnewswritigs&middot;&middot;&middot;eup.html</A><br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR><br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</A><BR><br><br>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12568470</guid>
<pubDate>Thu, 03 Feb 2005 08:50:04 EDT</pubDate>
</item>

<item>
<title>Re: Another Virus/Hijack Removal Problem</title>
<link>http://www.dslreports.com/forum/remark,12568273</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Ceres PopUps was on my computer at work. The company that I traced the ceres.dll to is MyPCTUNEup.com. Their removal tool seemed to work and they claim to not install any spyware on your box. I checked to see if the Ceres.dll was still in my Windows directory, and it was not after I ran the removal software. I will keep my fingers crossed!!!<br>Good Luck]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12568273</guid>
<pubDate>Thu, 03 Feb 2005 08:16:00 EDT</pubDate>
</item>

<item>
<title>Re: Another Virus/Hijack Removal Problem</title>
<link>http://www.dslreports.com/forum/remark,12568233</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : To remove our advertising software from your computer, please visit HTTP://www.MyPCTuneUp.com/unistaller_exe.php, where you will be guided through an easy uninstall process. <br>It will remove the following Advertising Software programs from your computer: BestOffers, BetterInternet, Ceres, LocalNRD, MSView, MultiMPP, MXTarget, OfferOptimizer, Twaintec, and some others.<br>Good Luck!!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12568233</guid>
<pubDate>Thu, 03 Feb 2005 08:01:52 EDT</pubDate>
</item>

<item>
<title>Re: Another Virus/Hijack Removal Problem</title>
<link>http://www.dslreports.com/forum/remark,12446234</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Oh, no...doesn't work for Mozilla just IE, but also no - it doesn't interfere with SpywareBlaster or Spybot or any other security programs for those using IE.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12446234</guid>
<pubDate>Fri, 21 Jan 2005 13:09:30 EDT</pubDate>
</item>

<item>
<title>Re: Another Virus/Hijack Removal Problem</title>
<link>http://www.dslreports.com/forum/remark,12446219</link>
<description><![CDATA[<A HREF="/useremail/u/911232"><b>hgratt</b></A> : Does IESPYAD do anything for Mozilla? Also, will it conflict with SpywareBlaster and/or SpyBot's immunization procedures?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12446219</guid>
<pubDate>Fri, 21 Jan 2005 13:07:43 EDT</pubDate>
</item>

<item>
<title>Re: Another Virus/Hijack Removal Problem</title>
<link>http://www.dslreports.com/forum/remark,12445720</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Great!  I figured you would fix him up :)<br><br>Another really *must get* free tool is Eric Howe's IESPYAD.  That will put over 5,000 known malicious and/or dangerous sites into his restricted zone.  It needs to be updated periodically (see our Updates list at the top of this forum each day for the latest) but installing that tool will help stop reinfections and increase his protection without using any memory resources :)<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR><br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</A><BR><br><br>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12445720</guid>
<pubDate>Fri, 21 Jan 2005 12:07:37 EDT</pubDate>
</item>

<item>
<title>Re: Another Virus/Hijack Removal Problem</title>
<link>http://www.dslreports.com/forum/remark,12445653</link>
<description><![CDATA[<A HREF="/useremail/u/911232"><b>hgratt</b></A> : You bet! I've loaded Ad-Aware, Spybot, CWShredder and SpywareBlaster onto his system. Also installed AVAST anti-virus and a2 anti-trojan on his system.<br><br>Hopefully, this will give him adequate automatic protection and manual scanning/checking capabilities. <br><br>Thanks again for your help.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12445653</guid>
<pubDate>Fri, 21 Jan 2005 12:00:24 EDT</pubDate>
</item>

<item>
<title>Re: Another Virus/Hijack Removal Problem</title>
<link>http://www.dslreports.com/forum/remark,12439648</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Ok, good job.<br><br>The log looks clean :)<br><br>I assume you are getting some prevention programs and extra security in place for them]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12439648</guid>
<pubDate>Thu, 20 Jan 2005 18:52:06 EDT</pubDate>
</item>

<item>
<title>Re: Another Virus/Hijack Removal Problem</title>
<link>http://www.dslreports.com/forum/remark,12439157</link>
<description><![CDATA[<A HREF="/useremail/u/911232"><b>hgratt</b></A> : All right! The de-registration seems to have done it and allowed me to proceed successfully with your instructions.<br><br>Here is the latest HJT log:<br>Thanks for all the help. Hopefully this will last.<br><br>Logfile of HijackThis v1.99.0<br>Scan saved at 5:04:28 PM, on 1/20/05<br>Platform: Windows 98 SE (Win9x 4.10.2222A)<br>MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)<br><br>Running processes:<br>C:\WINDOWS\SYSTEM\KERNEL32.DLL<br>C:\WINDOWS\SYSTEM\MSGSRV32.EXE<br>C:\WINDOWS\SYSTEM\MPREXE.EXE<br>C:\WINDOWS\SYSTEM\mmtask.tsk<br>C:\WINDOWS\SYSTEM\ATI2PLXX.EXE<br>C:\PROGRAM FILES\EASY INTERNET\ENCMONTR.EXE<br>C:\WINDOWS\SYSTEM\MSTASK.EXE<br>C:\WINDOWS\EXPLORER.EXE<br>C:\WINDOWS\TASKMON.EXE<br>C:\WINDOWS\SYSTEM\SYSTRAY.EXE<br>C:\WINDOWS\SYSTEM\ATIPTAXX.EXE<br>C:\WINDOWS\SYSTEM\ATI2CWXX.EXE<br>C:\PROGRAM FILES\TIOGA\CLIENT\BIN\TGCMD.EXE<br>C:\TOSHIBA\IVP\ISM\PINGER.EXE<br>C:\WINDOWS\LOADQM.EXE<br>C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKUFIND.EXE<br>C:\PROGRAM FILES\TECH\WHEEL MOUSE\5.0\MOUSE32A.EXE<br>C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE<br>C:\PROGRAM FILES\A2\A2GUARD.EXE<br>C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE<br>C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE<br>C:\PROGRAM FILES\INTERSIL\PRISM 802.11 WIRELESS LAN\CONFIG.EXE<br>C:\PROGRAM FILES\LINKSYS\WIRELESS-B NOTEBOOK ADAPTER\WPC11CFG.EXE<br>C:\WINDOWS\SYSTEM\WMIEXE.EXE<br>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE<br>C:\WINDOWS\SYSTEM\DDHELP.EXE<br>C:\WINDOWS\SYSTEM\PSTORES.EXE<br>C:\HJT\HIJACKTHIS.EXE<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://my.iwon.com/" >my.iwon.com/</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost<br>F1 - win.ini: run=hpfsched<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br>O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun<br>O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe<br>O4 - HKLM\..\Run: [SystemTray] SysTray.Exe<br>O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe<br>O4 - HKLM\..\Run: [Ati2cwxx] Ati2cwxx.exe<br>O4 - HKLM\..\Run: [TgAddServer] "C:\Program Files\tioga\Client\bin\tgfix.exe" /fds "http://vtsupport.answerteam.com/global"<br>O4 - HKLM\..\Run: [Tgcmd] "C:\Program Files\tioga\Client\bin\tgcmd.exe" /nosystray<br>O4 - HKLM\..\Run: [tgsetsite] "C:\Program Files\tioga\Client\bin\tgfix.exe" /i /f "C:\Program Files\tioga\client\bin\toshibasup.dna"<br>O4 - HKLM\..\Run: [Pinger] C:\TOSHIBA\IVP\ISM\pinger.exe<br>O4 - HKLM\..\Run: [mgavrtclexe] c:\windows\MCBin\AV\Rt\mgavrtcl.exe<br>O4 - HKLM\..\Run: [LoadQM] loadqm.exe<br>O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe<br>O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup<br>O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme<br>O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Tech\Wheel Mouse\5.0\MOUSE32A.EXE<br>O4 - HKLM\..\Run: [Logitech Utility] LOGI_MWX.EXE<br>O4 - HKLM\..\RunServices: [ATIPOLAB] ati2plxx.exe<br>O4 - HKLM\..\RunServices: [Encompass_ENCMONTR] C:\Program Files\Easy Internet\ENCMONTR.EXE<br>O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme<br>O4 - HKLM\..\RunServices: [SchedulingAgent] c:\windows\SYSTEM\mstask.exe<br>O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\mnyexpr.exe"<br>O4 - HKCU\..\Run: [MsnMsgr] "c:\Program Files\MSN Messenger\MsnMsgr.Exe" /background<br>O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a2\a2guard.exe"<br>O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br>O4 - Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Desktop Messenger\8876480\Program\LDMConf.exe<br>O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE<br>O4 - Startup: Configuration Utility.lnk = C:\Program Files\Intersil\PRISM 802.11 Wireless LAN\Config.exe<br>O4 - Startup: Wireless-B Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-B Notebook Adapter\WPC11Cfg.exe<br>O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html<br>O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html<br>O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html<br>O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html<br>O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html<br>O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm<br>O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm<br>O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - &raquo;<A HREF="http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab" >messenger.msn.com/download/MsnMe&middot;&middot;&middot;ader.cab</A><br>O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - &raquo;<A HREF="http://www2.incredimail.com/contents/setup/downloader_sp1/imloader.cab" >www2.incredimail.com/contents/se&middot;&middot;&middot;ader.cab</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12439157</guid>
<pubDate>Thu, 20 Jan 2005 17:58:09 EDT</pubDate>
</item>

<item>
<title>Re: Another Virus/Hijack Removal Problem</title>
<link>http://www.dslreports.com/forum/remark,12426491</link>
<description><![CDATA[<A HREF="/useremail/u/911232"><b>hgratt</b></A> : Thanks. I will provide them with this information.<br><br>Harvey]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12426491</guid>
<pubDate>Wed, 19 Jan 2005 11:38:07 EDT</pubDate>
</item>

<item>
<title>Re: Another Virus/Hijack Removal Problem</title>
<link>http://www.dslreports.com/forum/remark,12426425</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> :  <div class="bquote"><SMALL>said by  hgratt <A HREF="/useremail/u/911232"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>BTW, these people use the www.iwon.com page as their home page  In fact, everytime we update SpywareBlaster , I have to remove the entry in the IE Restricted Zone. To me, the page just looks like a general information page where they sign up for news , weather updates, etc. What are the nasties associated with this page?<br><br>Thanks again,<br>Harvey<br> </DIV>From Symantec<br><br>Behavior<br>Adware.IWon is a Browser Helper Object that sends data to and receives data from a remote Web site.<br><br>Symptoms<br>You notice outgoing connections to www.iwon.com.<br><br>Transmission<br>This adware is installed when you download and install software from www.iwon.com.<br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12426425</guid>
<pubDate>Wed, 19 Jan 2005 11:31:07 EDT</pubDate>
</item>

<item>
<title>Re: Another Virus/Hijack Removal Problem</title>
<link>http://www.dslreports.com/forum/remark,12426384</link>
<description><![CDATA[<A HREF="/useremail/u/911232"><b>hgratt</b></A> : Thanks. I plan on getting over there again Thursday and will try the removal procedures. I will post back as soon as I can.<br><br>BTW, these people use the www.iwon.com page as their home page  In fact, everytime we update SpywareBlaster , I have to remove the entry in the IE Restricted Zone. To me, the page just looks like a general information page where they sign up for news , weather updates, etc. What are the nasties associated with this page?<br><br>Thanks again,<br>Harvey]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12426384</guid>
<pubDate>Wed, 19 Jan 2005 11:26:00 EDT</pubDate>
</item>

<item>
<title>Re: Another Virus/Hijack Removal Problem</title>
<link>http://www.dslreports.com/forum/remark,12425027</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Your problem is this:<br><br>Transponder - Ceres Variant<br>&raquo;<A HREF="http://doxdesk.com/parasite/Transponder.html" >doxdesk.com/parasite/Transponder.html</A><br><br>That page contains information on additional components that may have been installed and you should check to see if any of the additional files/registry entries need to be removed as all are not visible on the HijackThis log.<br><br>This particular variant we have seen comes bundled with a fresh install of Morpheus, in which case, you should caution your friend about spyware infested programs and taking care in downloading files from the interenet.<br><br>Adaware SE v. 1.05 with the most recent updates does have detection for this.  Please make sure you have the latest version and updates as of Jan 11 is:  <B>SE1R25 11.01.2005</B><br><br> The Transponder DLL lives in the Windows folder. Before it can be deleted, it must be deregistered. Open a Command Prompt window (from Start->Programs->Accessories; called DOS prompt on Windows 95/98/Me) and enter the following command:<br><br>for the Ceres variant:<br><div class="code"><PRE><span class="codetext">    cd "%WinDir%\System"<br>    regsvr32 /u ..\Ceres.dll </SPAN></PRE></DIV><br>Then, boot the PC into SAFE MODE, scan with HijackThis and checkmark the following entries and press *fix checked*<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = »home.iwon.com/index_gen.html<br><br>O2 - BHO: YBIOCtrl Class - {004A5840-FF59-11d2-B50D-0090271D3FD4} - (no file)<br><br>O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)<br><br>O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)<br><br>O2 - BHO: (no name) - {D714A94F-123A-45CC-8F03-040BCAF82AD6} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\SBCIE028.DLL<br><br>O2 - BHO: CeresObj Class - {00000049-8F91-4D9C-9573-F016E7626484} - C:\WINDOWS\CERES.DLL<br><br>O4 - HKLM\..\Run: [efjorvjqpwms] C:\WINDOWS\SYSTEM\vytlkzc.exe<br><br>O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\SBCIE028.DLL<br><br>O16 - DPF: {0837121A-6472-43BD-8A40-D9221FF1C4CE} - »download.sidestep.com/get/k22675/sb028..<br><br>Remain in safe mode and delete the following files named in bold (if found)<br><br><B>SBCIE028.DLL</B><br><br>C:\WINDOWS\<B>CERES.DLL</B><br><br>C:\WINDOWS\SYSTEM\<B>vytlkzc.exe</B><br><br>Also check your system for a file named:  <B>buddy.exe</B>  If found, delete it too.<br><br>Reboot back into normal mode and scan again with HijackThis and post a fresh log.  <br><br>You should make sure Adaware is updated and scan with it as well, since it may find more entries as well.<br><br>Be sure to visit the doxdesk parasites page linked above to see what other entries you may need to search and destroy on the system related to the Ceres variant.<br><br>Note:<br>System Soap Pro has been reported to come with Foistware and it is generally recommended to avoid using that program<br>See description here:<br>&raquo;<A HREF="http://www.liutilities.com/products/wintaskspro/processlibrary/soap/" >www.liutilities.com/products/win&middot;&middot;&middot;ry/soap/</A><br><br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR><br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</A><BR><br><br>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12425027</guid>
<pubDate>Wed, 19 Jan 2005 08:00:07 EDT</pubDate>
</item>

<item>
<title>Re: Another Virus/Hijack Removal Problem</title>
<link>http://www.dslreports.com/forum/remark,12424500</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : This may help remove iwon<br><br>&raquo;<A HREF="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453079969" >www3.ca.com/securityadvisor/pest&middot;&middot;&middot;53079969</A><br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12424500</guid>
<pubDate>Wed, 19 Jan 2005 04:03:05 EDT</pubDate>
</item>

<item>
<title>Another Virus/Hijack Removal Problem</title>
<link>http://www.dslreports.com/forum/remark,12423314</link>
<description><![CDATA[<A HREF="/useremail/u/911232"><b>hgratt</b></A> : Another friend, this time with win98se. He has serious problems with pop-ups from an object called CERES.<br><br>Have done the following, all in SAFE MODE:<br>1. Ran latest Spybot S&D<br>2. Ran latest Ad-Aware<br>3. Ran HJT<br><br>Main problem is with HJT (even in safe mode) the object/file ceres.dll keeps coming back. I also noticed that the HJT tool for removing a file at boot up was greyed out.<br><br>I could rename the file ceres.dll only in safe mode (afraid to delete it at the present time), but when I booted back up, the ceres pop-ups still came. Maybe other thing have to be removed in conjunction, This is the second time these cleaners have failed to remove stuff.<br><br>Anyway, any insights as to why I can't remove this stuff would be appreciated. Here is his HJT logfile:<br><br>Thanks,<br>Harvey<br><br>Logfile of HijackThis v1.99.0<br>Scan saved at 9:19:55 PM, on 1/18/05<br>Platform: Windows 98 SE (Win9x 4.10.2222A)<br>MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)<br><br>Running processes:<br>C:\WINDOWS\SYSTEM\KERNEL32.DLL<br>C:\WINDOWS\SYSTEM\MSGSRV32.EXE<br>C:\WINDOWS\SYSTEM\MPREXE.EXE<br>C:\WINDOWS\SYSTEM\mmtask.tsk<br>C:\WINDOWS\SYSTEM\ATI2PLXX.EXE<br>C:\PROGRAM FILES\EASY INTERNET\ENCMONTR.EXE<br>C:\WINDOWS\SYSTEM\MSTASK.EXE<br>C:\WINDOWS\TASKMON.EXE<br>C:\WINDOWS\SYSTEM\SYSTRAY.EXE<br>C:\WINDOWS\SYSTEM\ATIPTAXX.EXE<br>C:\WINDOWS\SYSTEM\ATI2CWXX.EXE<br>C:\PROGRAM FILES\TIOGA\CLIENT\BIN\TGCMD.EXE<br>C:\TOSHIBA\IVP\ISM\PINGER.EXE<br>C:\WINDOWS\LOADQM.EXE<br>C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKUFIND.EXE<br>C:\PROGRAM FILES\TECH\WHEEL MOUSE\5.0\MOUSE32A.EXE<br>C:\PROGRAM FILES\SYSTEM SOAP PRO\SOAP.EXE<br>C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE<br>C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE<br>C:\PROGRAM FILES\INTERSIL\PRISM 802.11 WIRELESS LAN\CONFIG.EXE<br>C:\PROGRAM FILES\LINKSYS\WIRELESS-B NOTEBOOK ADAPTER\WPC11CFG.EXE<br>C:\WINDOWS\SYSTEM\WMIEXE.EXE<br>C:\WINDOWS\SYSTEM\PSTORES.EXE<br>C:\WINDOWS\SYSTEM\DDHELP.EXE<br>C:\WINDOWS\SYSTEM\SPOOL32.EXE<br>C:\WINDOWS\EXPLORER.EXE<br>C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE<br>C:\HJT\HIJACKTHIS.EXE<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://home.iwon.com/index_gen.html" >home.iwon.com/index_gen.html</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost<br>F1 - win.ini: run=hpfsched<br>O2 - BHO: YBIOCtrl Class - {004A5840-FF59-11d2-B50D-0090271D3FD4} - (no file)<br>O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)<br>O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL<br>O2 - BHO: (no name) - {D714A94F-123A-45CC-8F03-040BCAF82AD6} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\SBCIE028.DLL<br>O2 - BHO: CeresObj Class - {00000049-8F91-4D9C-9573-F016E7626484} - C:\WINDOWS\CERES.DLL<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br>O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun<br>O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe<br>O4 - HKLM\..\Run: [SystemTray] SysTray.Exe<br>O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe<br>O4 - HKLM\..\Run: [Ati2cwxx] Ati2cwxx.exe<br>O4 - HKLM\..\Run: [TgAddServer] "C:\Program Files\tioga\Client\bin\tgfix.exe" /fds "http://vtsupport.answerteam.com/global"<br>O4 - HKLM\..\Run: [Tgcmd] "C:\Program Files\tioga\Client\bin\tgcmd.exe" /nosystray<br>O4 - HKLM\..\Run: [tgsetsite] "C:\Program Files\tioga\Client\bin\tgfix.exe" /i /f "C:\Program Files\tioga\client\bin\toshibasup.dna"<br>O4 - HKLM\..\Run: [Pinger] C:\TOSHIBA\IVP\ISM\pinger.exe<br>O4 - HKLM\..\Run: [mgavrtclexe] c:\windows\MCBin\AV\Rt\mgavrtcl.exe<br>O4 - HKLM\..\Run: [LoadQM] loadqm.exe<br>O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe<br>O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup<br>O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme<br>O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Tech\Wheel Mouse\5.0\MOUSE32A.EXE<br>O4 - HKLM\..\Run: [Logitech Utility] LOGI_MWX.EXE<br>O4 - HKLM\..\Run: [efjorvjqpwms] C:\WINDOWS\SYSTEM\vytlkzc.exe<br>O4 - HKLM\..\RunServices: [ATIPOLAB] ati2plxx.exe<br>O4 - HKLM\..\RunServices: [Encompass_ENCMONTR] C:\Program Files\Easy Internet\ENCMONTR.EXE<br>O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme<br>O4 - HKLM\..\RunServices: [SchedulingAgent] c:\windows\SYSTEM\mstask.exe<br>O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\mnyexpr.exe"<br>O4 - HKCU\..\Run: [System Soap Pro] C:\PROGRAM FILES\SYSTEM SOAP PRO\SOAP.exe min<br>O4 - HKCU\..\Run: [MsnMsgr] "c:\Program Files\MSN Messenger\MsnMsgr.Exe" /background<br>O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br>O4 - Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Desktop Messenger\8876480\Program\LDMConf.exe<br>O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE<br>O4 - Startup: Configuration Utility.lnk = C:\Program Files\Intersil\PRISM 802.11 Wireless LAN\Config.exe<br>O4 - Startup: Wireless-B Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-B Notebook Adapter\WPC11Cfg.exe<br>O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html<br>O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html<br>O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html<br>O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html<br>O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html<br>O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm<br>O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm<br>O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\SBCIE028.DLL<br>O16 - DPF: {0837121A-6472-43BD-8A40-D9221FF1C4CE} - &raquo;<A HREF="http://download.sidestep.com/get/k22675/sb028.cab" >download.sidestep.com/get/k22675/sb028.cab</A><br>O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - &raquo;<A HREF="http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab" >messenger.msn.com/download/MsnMe&middot;&middot;&middot;ader.cab</A><br>O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - &raquo;<A HREF="http://www2.incredimail.com/contents/setup/downloader_sp1/imloader.cab" >www2.incredimail.com/contents/se&middot;&middot;&middot;ader.cab</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12423314</guid>
<pubDate>Tue, 18 Jan 2005 23:40:18 EDT</pubDate>
</item>

</channel>
</rss>
