Hello Crunchie
Thanks for the quick reply, I really appreciate the help.
It has taken a while and I have had to work through this
a few times, and it looks like all has been fixed.
=====================================================
CME II, GMT, GAIN / GATOR, GMT.exe, CMESys.exe, Gator.exe
All appear to be related to Gator and I left them alone for now.
Found empty folder:
C:\WINDOWS\system32\WinSxS = C:\WINDOWS\System32\WNSXS~1
Folder and contents previously removed:
C:\Program Files\Common Files\mwrk
= C:\PROGRA~1\COMMON~1\mwrk
C:\Program Files\Common Files\mwrk\mwrka.exe
C:\Program Files\Common Files\mwrk\mwrkl.exe
C:\Program Files\Common Files\mwrk\mwrkm.exe
C:\Program Files\Common Files\mwrk\mwrkp.exe ... and other files
=====================================================
Ran PurityScan uninstaller (again)
===============
Found:
C:\WINDOWS\Prefetch\GMT.EXE-00C623D4.pf
C:\WINDOWS\Prefetch\MWRKA.EXE-38DEA512.pf
C:\WINDOWS\Prefetch\MWRKL.EXE-2D78DA05.pf
C:\WINDOWS\Prefetch\UPDATE.EXE-276CF44C.pf
Deleted:
C:\WINDOWS\Prefetch\MWRKA.EXE-38DEA512.pf
===============
Ran: services.msc
Found entry with Display name=[COM+ Messages]
Service command="C:\WINDOWS\System32\svchosts.exe" -e te-110-12-0000213
Service was already Stopped.
Service Startup type was set=Automatic
Set service Startup type=Disabled
===============
Ran HiJackThis-process manager:
I found this process, highlighted it and clicked [Kill process]:
C:\Program Files\Common Files\{CC4978D5-0327-1033-0226-010507990001}\Update.exe
The process: C:\...\Update.exe closed successfully.
===============
Not Found:
C:\WINDOWS\System32\WNSXS~1\services.exe [folder was empty]
C:\PROGRA~1\COMMON~1\mwrk\mwrkm.exe [folder/contents previously removed]
C:\PROGRA~1\COMMON~1\mwrk\mwrka.exe [folder/contents previously removed]
C:\Program Files\??crosoft\?xplorer.exe [folder/file not present]
Found but left running:
C:\Program Files\Common Files\CMEII\CMESys.exe
C:\Program Files\Gator.com\Gator\Gator.exe
C:\Program Files\Common Files\GMT\GMT.exe
===============
Ran HijackThis-Scan:
Found and checked only these four items:
O2 - BHO: IEWatchObj Class - {9527D42F-D666-11D3-B8DD-00600838CD5F} - C:\WINDOWS\System32\IETie.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links -
{c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O23 - Service: COM+ Messages - Unknown owner - C:\WINDOWS\System32\svchosts.exe" -e te-110-12-0000213 (file missing)
Clicked to Fix these
===============
Also removed entry:
HKCU\..\Run: "C:\Program Files\Common
Files\{CC4978D5-0327-1033-0226-010507990001}\Update.exe"
===============
Deleted folder and contents:
C:\Program Files\Common Files\{CC4978D5-0327-1033-0226-010507990001}
Deleted empty folder:
C:\Program Files\Common Files\{3C4978D5-0327-1033-0226-010507990001}
===============
Removed empty folder:
C:\WINDOWS\System32\WNSXS~1 = C:\WINDOWS\system32\WinSxS
Folder and contents previously renoved:
C:\PROGRA~1\COMMON~1\mwrk
===============
Removed files:
C:\WINDOWS\System32\svchosts.exe
C:\WINDOWS\System32\IETie.dll
=====================================================
Rebooted and repeated some steps to remove some items
that re-appeared. Then rebooted again. So far, all
reboots are normal, not safe-mode.
=====================================================
After 2nd and further Reboots:
===============
Found these files --- should they be deleted ?:
C:\WINDOWS\Prefetch\MWRKL.EXE-2D78DA05.pf 58.5 KB (59,938 bytes)
C:\WINDOWS\Prefetch\OIUNINSTALLER.EXE-11C837B6.pf 13.5 KB (13,868 bytes)
C:\WINDOWS\Prefetch\OIUNINSTALLER[1].EXE-11C837B6.pf 13.4 KB (13,748 bytes)
C:\WINDOWS\Prefetch\UPDATE.EXE-276CF44C.pf 8.86 KB (9,078 bytes)
===============
These folders/files are no longer present:-)
C:\Program Files\Common Files\{3C4978D5-0327-1033-0226-010507990001}
C:\Program Files\Common Files\{CC4978D5-0327-1033-0226-010507990001}\Update.exe
C:\WINDOWS\System32\IETie.dll
===============
This file is still present:
C:\WINDOWS\Web\RELATED.HTM
File RELATED.HTM contains referance to Msn.com only:
http://related.msn.com/related.asp?url=
===============
HijackThis no longer shows O23 - Service: COM+ Messages
For HKLM\SYSTEM\ControlSet001\Services\COM+ Messages
These key/values still exist in registry in
three places:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\COM+ Messages
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\COM+ Messages
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\COM+ Messages
DisplayName=COM+ Messages
ImagePath="C:\WINDOWS\System32\svchosts.exe" -e te-110-12-0000213
File: C:\WINDOWS\System32\svchosts.exe is no longer present.
When I run services.msc, the entry for 'COM+ Messages' is still
present.
=====================================================
I still have a folder/files:
C:\Program Files\Cowabanga
C:\Program Files\Cowabanga\License.txt
C:\Program Files\Cowabanga\uninstaller.exe
License.txt refers to
http://www.outerinfo.com/OiUninstaller.exe
This is the same file/location given at
http://www.purityscan.com/uninstall.html
I will manually remove the folder and contents.
=====================================================
What does the presence of mwrka.exe (and mwrk[almp].exe) indicate ?
=====================================================
Do you know What this is --- I always find files in trash from here:
C:\Program Files\Common Files\onudfbuu\mpaqrmcs
C:\Program Files\Common Files\onudfbuu\oufqaqmosn
=====================================================
Here is my latest HJT log ... thanks again ...
Logfile of HijackThis v1.99.1
Scan saved at 4:43:17 AM, on 1/12/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
F:\Program Files\WS_FTP Pro\ftpsched.exe
F:\Program Files\Norton\SystemWorks2003\Norton AntiVirus\navapsvc.exe
F:\Program Files\Norton\SystemWorks2003\Norton Utilities\NPROTECT.EXE
F:\PROGRA~1\Norton\SYSTEM~2\SPEEDD~1\nopdb.exe
F:\PROGRA~1\ALLUME~1\StuffIt\MXTask.exe
F:\PROGRA~1\VCOM\SYSTEM~1\MXTask.exe
F:\PROGRA~1\VCOM\SYSTEM~1\mxtask.exe
F:\PROGRA~1\ALLUME~1\StuffIt\mxtask.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\WINDOWS\System32\LMSXXD.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
F:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Program Files\Gator.com\Gator\Gator.exe
F:\Program Files\Creative Element Power Tools\Startup.exe
F:\Program Files\Qualcomm\Eudora\Eudora.exe
F:\Program Files\Microsoft Office\Office\FINDFAST.EXE
F:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Common Files\GMT\GMT.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HijackThis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - F:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - F:\Program Files\Norton\SystemWorks2003\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - F:\Program Files\Save Flash\SaveFlash.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - F:\Program Files\Norton\SystemWorks2003\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [LMSXXD] LMSXXD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [ftpqueue] F:\Program Files\WS_FTP Pro\ftpqueue.exe -tray
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Creative Element Power Tools Startup.lnk = F:\Program Files\Creative Element Power Tools\Startup.exe
O4 - Startup: Eudora 6-GMspam.lnk = F:\Program Files\Qualcomm\Eudora\Eudora.exe
O4 - Startup: Microsoft Find Fast.lnk = F:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Office Startup.lnk = F:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: A-Acrobat Assistant.lnk = F:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: A-Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: A-Gator eWallet.lnk = C:\Program Files\Gator.com\Gator\Gator.exe
O8 - Extra context menu item: &StealthBid -
http://www.stealthbid.com/Toolbar/ContextMenu.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: StealthBid - {DA430631-621F-411c-A883-A4850D1928EC} - C:\WINDOWS\Downloaded Program Files\IQStealthBid.dll (HKCU)
O9 - Extra 'Tools' menuitem: StealthBid - {DA430631-621F-411c-A883-A4850D1928EC} - C:\WINDOWS\Downloaded Program Files\IQStealthBid.dll (HKCU)
O15 - Trusted Zone: *.netmagazines.com
O16 - DPF: {271BEE78-FBBE-43D7-980B-58B5F53E34A7} (StealthBid Class) -
http://www.stealthbid.com/Toolbar/IQStealthBid.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) -
http://mvnet.xlontech.net/qm/fox/061...ie06101001.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Ipswitch WS_FTP Queue (ftpqueue) - Ipswitch, Inc., 81 Hartwell Ave, Lexington MA 02421 - F:\Program Files\WS_FTP Pro\ftpsched.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lexar SG20 (LxrSG20s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSG20s.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - F:\Program Files\Norton\SystemWorks2003\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - F:\Program Files\Norton\SystemWorks2003\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - F:\PROGRA~1\Norton\SYSTEM~2\SPEEDD~1\nopdb.exe
O23 - Service: StuffIt Task Manager - Allume Systems, Inc. - F:\PROGRA~1\ALLUME~1\StuffIt\MXTask.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: SystemSuite Task Manager - V Communications, Inc. - F:\PROGRA~1\VCOM\SYSTEM~1\MXTask.exe