I am having trouble removing Update.exe Spyware/Adware.
I don't know how it arrived ... I am very careful where I browse and what I download, but unfortunately, I am not the only one who uses this computer.
I have provided some behavior details because I know there are many different Update.exe infections.
Update.exe runs from registry key HKLM\..\Run:
"C:\Program Files\Common Files\{CC4978D5-0327-1033-0226-010507990001}\Update.exe" te-110-12-0000213
I have used Ad-Aware SE by Lavasoft to remove Update.exe. It deletes the key and the file but they return on reboot.
For a while Update.exe tried to connect to:
http://dr32.mcboo.XXXX (com)
It was prevented by my firewall and I blocked it but somehow, it must have connected somewhere.
Now I am getting popup ads. I assume they are caused by Update.exe but I suppose it is possible that there are multiple problems.
When I open a browser page for most any legitimate site, I get just 1, or sometimes many popups. They are usually content related. If I am on Google or browsing Download.com looking at Anti-Spyware or Anti-Virus items, I get a ton of popups related to Anti-Spyware/Anti-Virus. Sometimes though, I can browse for a long time with no popups.
Sometimes It can seriously effect performance/stability but usually not.
Popup ads are mostly from http://ad.oinadserver.XXXX/... (com).
Here is my hijacklog, I hope it helps.
Thanks to all who reads this.
Kevin Fegan
(P.S. I am aware of Gator/GMT but the ads I am seeing are not from Gator. I've been using Gator for a long time, without problems and I like it, and for now I am willing to put up with its occasional interruptions.)
Logfile of HijackThis v1.99.1
Scan saved at 11:23:09 AM, on 1/5/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\svchosts.exe
F:\Program Files\WS_FTP Pro\ftpsched.exe
F:\Program Files\Norton\SystemWorks2003\Norton AntiVirus\navapsvc.exe
F:\Program Files\Norton\SystemWorks2003\Norton Utilities\NPROTECT.EXE
F:\PROGRA~1\Norton\SYSTEM~2\SPEEDD~1\nopdb.exe
F:\PROGRA~1\ALLUME~1\StuffIt\MXTask.exe
F:\PROGRA~1\ALLUME~1\StuffIt\mxtask.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\LMSXXD.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Common Files\CMEII\CMESys.exe
F:\Program Files\WS_FTP Pro\ftpqueue.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\{CC4978D5-0327-1033-0226-010507990001}\Update.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\WNSXS~1\services.exe
C:\PROGRA~1\COMMON~1\mwrk\mwrkm.exe
C:\Program Files\??crosoft\?xplorer.exe
F:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
F:\Program Files\eFax Messenger 4.0\J2GDllCmd.exe
F:\Program Files\eFax Messenger 4.0\J2GTray.exe
C:\Program Files\Gator.com\Gator\Gator.exe
F:\Program Files\Creative Element Power Tools\Startup.exe
C:\Program Files\Common Files\GMT\GMT.exe
F:\Program Files\Microsoft Office\Office\FINDFAST.EXE
F:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\PROGRA~1\COMMON~1\mwrk\mwrka.exe
J:\IBIN\A-Temp-17\Hijack\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R3 - URLSearchHook: (no name) - {3ADB627F-8EB4-8C4F-C52F-8BCD5F63D7CF} - C:\WINDOWS\System32\rmx.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3ADB627F-8EB4-8C4F-C52F-8BCD5F63D7CF} - C:\WINDOWS\System32\rmx.dll
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - F:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: IEWatchObj Class - {9527D42F-D666-11D3-B8DD-00600838CD5F} - C:\WINDOWS\System32\IETie.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - F:\Program Files\Norton\SystemWorks2003\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - F:\Program Files\Save Flash\SaveFlash.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - F:\Program Files\Norton\SystemWorks2003\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [LMSXXD] LMSXXD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [ftpqueue] F:\Program Files\WS_FTP Pro\ftpqueue.exe -tray
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [{CC4978D5-0327-1033-0226-010507990001}] "C:\Program Files\Common Files\{CC4978D5-0327-1033-0226-010507990001}\Update.exe" te-110-12-0000213
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Asme] "C:\WINDOWS\System32\WNSXS~1\services.exe" -vt yazr
O4 - HKCU\..\Run: [mwrk] C:\PROGRA~1\COMMON~1\mwrk\mwrkm.exe
O4 - HKCU\..\Run: [Vkczkp] C:\Program Files\??crosoft\?xplorer.exe
O4 - Startup: Creative Element Power Tools Startup.lnk = F:\Program Files\Creative Element Power Tools\Startup.exe
O4 - Startup: Eudora 6-GMspam.lnk = F:\Program Files\Qualcomm\Eudora\Eudora.exe
O4 - Startup: Microsoft Find Fast.lnk = F:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Office Startup.lnk = F:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: A-Acrobat Assistant.lnk = F:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: A-eFax DllCmd 4.0.lnk = F:\Program Files\eFax Messenger 4.0\J2GDllCmd.exe
O4 - Global Startup: A-eFax Tray Menu 4.0.lnk = F:\Program Files\eFax Messenger 4.0\J2GTray.exe
O4 - Global Startup: A-Gator eWallet.lnk = C:\Program Files\Gator.com\Gator\Gator.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &StealthBid - http://www.stealthbid.com/Toolbar/ContextMenu.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: StealthBid - {DA430631-621F-411c-A883-A4850D1928EC} - C:\WINDOWS\Downloaded Program Files\IQStealthBid.dll (HKCU)
O9 - Extra 'Tools' menuitem: StealthBid - {DA430631-621F-411c-A883-A4850D1928EC} - C:\WINDOWS\Downloaded Program Files\IQStealthBid.dll (HKCU)
O15 - Trusted Zone: *.netmagazines.com
O16 - DPF: {271BEE78-FBBE-43D7-980B-58B5F53E34A7} (StealthBid Class) - http://www.stealthbid.com/Toolbar/IQStealthBid.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: COM+ Messages - Unknown owner - C:\WINDOWS\System32\svchosts.exe" -e te-110-12-0000213 (file missing)
O23 - Service: Ipswitch WS_FTP Queue (ftpqueue) - Ipswitch, Inc., 81 Hartwell Ave, Lexington MA 02421 - F:\Program Files\WS_FTP Pro\ftpsched.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lexar SG20 (LxrSG20s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSG20s.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - F:\Program Files\Norton\SystemWorks2003\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - F:\Program Files\Norton\SystemWorks2003\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - F:\PROGRA~1\Norton\SYSTEM~2\SPEEDD~1\nopdb.exe
O23 - Service: StuffIt Task Manager - Allume Systems, Inc. - F:\PROGRA~1\ALLUME~1\StuffIt\MXTask.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: SystemSuite Task Manager - V Communications, Inc. - F:\PROGRA~1\VCOM\SYSTEM~1\MXTask.exe