BigRed0926
New member
Hi guys, this is my first time posting here so i hope i get it right
I cant get a log from an online virus scanner because i'm having internet issues on my computer, but i have run trendmicro, spybot and adaware several times this week. each time I clean things out my comuter is full of malicious items again within aday or two.
My computer eventually stopped booting up normally, so i ran both adware and spybot in safe mode, but was unable to remove "Command Service" even when running both immediately after booting up. At this point i ran HJT and will post a log below.
Running these scans did allow me to boot up normally, however my internet stopped working. I then can a winsockxp fix program that was recommended to me in another forum, which got it working again, but it quickly slowed to a crawl.
Here is my HJT log:
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {B6F1A4CB-DADD-4D0C-BDFC-E945647302C1} - c:\wmplayer.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [explorer] C:\Documents and Settings\Fraser\304.exe
O4 - HKLM\..\Run: [{6C8BD4ED-0958-1033-0601-040210040001}] "C:\Program Files\Common Files\{6C8BD4ED-0958-1033-0601-040210040001}\Update.exe" mc-110-12-0000904
O4 - HKLM\..\Run: [Intel system tool] C:\WINDOWS\system32\svehost.exe
O4 - HKLM\..\Run: [clcl3] C:\WINDOWS\system32\clcl3.exe
O4 - HKLM\..\Run: [BootService] rundll32.exe "C:\WINDOWS\wvwxvw.dll",realset
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/installdrivecleanerstart.cab
O16 - DPF: {3299935F-2C5A-499A-9908-95CFFF6EF8C1} (Quicksilver Class) - http://scpwcc.ops.placeware.com/etc/place/CHARLIE/CHApws-c2/5.1.8.511/lib/quicksilver.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs:
O21 - SSODL: DCOM Server 20509 - {2C1CD3D7-86AC-4068-93BC-A02304B20509} - C:\WINDOWS\system32\ecclbah.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ieupdater2 - Unknown - C:\Documents and Settings\ie_updater.exe
I already tried fixing some of teh obviously items with HJT but i can't seem to solve this myself. Hope you can help me.
Sincerely,
Fraser Retallack
I cant get a log from an online virus scanner because i'm having internet issues on my computer, but i have run trendmicro, spybot and adaware several times this week. each time I clean things out my comuter is full of malicious items again within aday or two.
My computer eventually stopped booting up normally, so i ran both adware and spybot in safe mode, but was unable to remove "Command Service" even when running both immediately after booting up. At this point i ran HJT and will post a log below.
Running these scans did allow me to boot up normally, however my internet stopped working. I then can a winsockxp fix program that was recommended to me in another forum, which got it working again, but it quickly slowed to a crawl.
Here is my HJT log:
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {B6F1A4CB-DADD-4D0C-BDFC-E945647302C1} - c:\wmplayer.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [explorer] C:\Documents and Settings\Fraser\304.exe
O4 - HKLM\..\Run: [{6C8BD4ED-0958-1033-0601-040210040001}] "C:\Program Files\Common Files\{6C8BD4ED-0958-1033-0601-040210040001}\Update.exe" mc-110-12-0000904
O4 - HKLM\..\Run: [Intel system tool] C:\WINDOWS\system32\svehost.exe
O4 - HKLM\..\Run: [clcl3] C:\WINDOWS\system32\clcl3.exe
O4 - HKLM\..\Run: [BootService] rundll32.exe "C:\WINDOWS\wvwxvw.dll",realset
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ocmvjhk.dll
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/installdrivecleanerstart.cab
O16 - DPF: {3299935F-2C5A-499A-9908-95CFFF6EF8C1} (Quicksilver Class) - http://scpwcc.ops.placeware.com/etc/place/CHARLIE/CHApws-c2/5.1.8.511/lib/quicksilver.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs:
O21 - SSODL: DCOM Server 20509 - {2C1CD3D7-86AC-4068-93BC-A02304B20509} - C:\WINDOWS\system32\ecclbah.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ieupdater2 - Unknown - C:\Documents and Settings\ie_updater.exe
I already tried fixing some of teh obviously items with HJT but i can't seem to solve this myself. Hope you can help me.
Sincerely,
Fraser Retallack