View Full Version : Spybot not finding threats

2007-07-26, 03:54
Am using Spybot 1.4, with Firefox Prob's: address bar no longer highlights when clicked, unable to get addresses from Bookmarks, I was taken to Netscape for Men including titles like Babes in Bikinis, my download icon/symbol never stops rotating, unable to download pictures using "save image as". AVG found SHeur.BID virus on 7/20 and deleted it. It's the 1st virus I've ever had since 9/04 when comp. was purchsd. Spybot has not been finding any spyware, which is highly unusual. I've downloaded everything I can find and it all seems to be OK?
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 6:51:58 PM, on 7/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Netscape Internet Service\NSClient.exe
C:\Program Files\Common Files\ISPCOMP\InstallService.exe
C:\Program Files\Common Files\ISPCOMP\SystemTrayIcon.exe
C:\Program Files\Netscape Internet Service\_NSWatchman.exe
C:\Program Files\Netscape Internet Service\Netscape Web Accelerator\nsaccel.exe
C:\Program Files\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\Program Files\Netscape Internet Service\Netscape Web Accelerator\pbhelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Netscape] C:\Program Files\Common Files\ISPCOMP\InstallService.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [PCPitstop Disk MD Registration Reminder] C:\Program Files\PCPitstop\Disk MD\Reminder.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Creating Keepsakes Scrapbook Designer Event Reminder.lnk = C:\Program Files\Scrapbook Designer\scrapremind.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Show All Original Images - res://C:\Program Files\Netscape Internet Service\Netscape Web Accelerator\nsaccel.exe/250
O8 - Extra context menu item: Show Original Image - res://C:\Program Files\Netscape Internet Service\Netscape Web Accelerator\nsaccel.exe/227
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1177803226984
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1179097562921
O17 - HKLM\System\CCS\Services\Tcpip\..\{4BFF89F6-71BC-48BB-9949-80B3A385C44D}: NameServer =
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

End of file - 6920 bytes
Do you need any further info, and can you help me? Mouse

2007-07-26, 13:44
Go to Start > My Computer
Go to Tools > Folder Options
Click on the View tab
Untick the following:

Hide extensions for known file types
Hide protected operating system files (Recommended)

You will get a message warning you about showing protected operating system files, click Yes
Make sure this option is selected:

Show hidden files and folders

Click Apply and then click OK

To assist diagnosis I would like a list of installed programs.

Open HijackThis and select Open the Misc Tools section
Click on the Open Uninstall Manager…
Select the Save List button
I suggest that you accept the default name of uninstall_list.txt and save the file to your desktop
Close HijackThis

Then please upload this file:

C:\Program Files\Common Files\ISPCOMP\InstallService.exe

To either jotti (http://virusscan.jotti.org/) or virustotal (http://www.virustotal.com/en/indexf.html)

Post back with the uninstall list, the jotti/virustotal results and a new HijackThis log

2007-07-27, 01:31
I don't know how to upload, unless you mean via File, Send to, Mail Recip., which I can't do because I put the wrong info in the set up (incoming, outgoing) and it won't let me fix it, it just keeps telling me: the host smtp can not be found, error 11004, err. code0x800CCC0D.

Thank you so much for you help! Mouse

2007-07-27, 05:57
Something has changed. My address list highlights, the download icon has stopped spinning, my Bookmarks list comes down. I haven't checked out everything, but it looks like my browser is back. It must have been something you had me do, but what was it, and do I have to change back any of the things that were changed in My Computer?
Thanks, Mouse

2007-07-27, 14:50
It must have been something you had me do, but what was it, and do I have to change back any of the things that were changed in My Computer?

Nothing I had you should have had that effect, I was trying to get information about what was causing your problem

To upload that file to virustotal:

Please visit this link VIRUSTOTAL UPLOAD LINK (http://www.virustotal.com/en/indexf.html)
* Click the Browse... button
* Navigate to the file C:\Program Files\Common Files\ISPCOMP\InstallService.exe
* Click the Open button
* Click the Send button
* Copy and paste the results back here please.

2007-07-28, 03:11
File InstallService.exe received on 07.28.2007 02:50:49 (CET)

The info about the scan being expired etc. did not show on the test results that were shown to me, so I don't know why they are in the info I've pasted. I did not highlight and copy that part.

2007-07-28, 03:14
I am still getting "no threats found" in Spybot. Mouse

2007-07-28, 11:45
Are you still experiencing any pother problems?

2007-07-28, 18:13
No, is everything OK now? Spybot is still not finding any problems. That is worrisome. Mouse

2007-07-28, 18:26
If spybot's not finding any threats it means that you have no threats present on your system that spybot detects -which is surely a good thing

There's a couple of orphaned HijackThis entries which can be removed:

Run HijackThis
Click on do a system scan only
Place a checkmark next to these lines(if still present)

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

Then close all windows except HijackThis and click Fix Checked

2007-07-28, 19:08
Thanks for your help. I don't see the "no threats" as a good thing, because I run it every time I'm on the computer, and there is almost always at least 1 problem found. Now, all of a sudden, no threat has been found for a week or more. Something is not right. I also have seen, on the bottom download info bar, doubleclick downloading , twice. I tried to look it up, but I'm still not sure whether it's a virus or malware, and I don't know why I would have seen it there. If you think I'm OK, I'll go with that, but I wish 'spybot was finding things. The last time this happened was in 06, and I was advised to update to the latest version, but I believe that I have the latest version, 1.4. Thanks, Mouse

2007-07-28, 22:00
As I'm not that familiar with attempting to troubleshoot spybot, I suggest that you ask in this section of the forum:


2007-07-29, 23:31
Random/Random-----Thank you so much for all of your help! Do I need to undo any of the things that you had me change, like the folder options? Mouse

2007-07-30, 14:35
The change to the folder options mean that you can see hidden and system files, and you will see the file extensions on the end of files

You can reverse them if you like, but it is not necessary to do so

2007-07-30, 20:23
Thanks! Mouse

2007-07-30, 20:25
Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.