Hello,
Need more expertise to get rid of pretty resistant one(s) !
I'm using Win2k with Firefox (AV is Norman, firewall is ZoneLabs) and each time I reboot the PC / connect to the web things like wacky32.exe appear on C:. Also on the Windows Control panel Winantivirus 2006 icon can not be removed (!).
Ran ad-aware and AVG, also smitfraud (found nothing after a successful run) and VundoFix.exe until lists have been cleared, but still spybot is finding the same list of elements.
Thanks for the help and I hope the thread is fine
----
Here's the spybot report :
--- Search result list ---
Command Service: Réglages Autorun (Valeur du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\newname
Smitfraud-C.: Réglages Autorun (wma34987) (Valeur du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wma34987
Smitfraud-C.: Fichier de programme (Fichier, fixed)
C:\WINNT\system32\RUNDLL32.EXE
Smitfraud-C.: Réglages Autorun (defender) (Valeur du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\defender
Microsoft.WindowsSecurityCenter.AntiVirusDisableNotify: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify!=dword:0
Microsoft.WindowsSecurityCenter.AntiVirusOverride: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride!=dword:0
Microsoft.WindowsSecurityCenter.FirewallDisabled: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\windowsfirewall\domainprofile\enablefirewall!=dword:1
Microsoft.WindowsSecurityCenter.FirewallDisabled: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\windowsfirewall\standardprofile\enablefirewall!=dword:1
Microsoft.WindowsSecurityCenter.FirewallDisableNotify: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify!=dword:0
Microsoft.WindowsSecurityCenter.FirewallOverride: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride!=dword:0
Microsoft.WindowsSecurityCenter.SP2Update: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\DoNotAllowXPSP2!=dword:0
Microsoft.WindowsSecurityCenter.UpdateDisableNotify: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify!=dword:0
Microsoft.WindowsSecurityCenter_disabled: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Start!=W=2
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-05-31 Update.exe (1.4.0.0)
2006-10-08 unins000.exe (51.41.0.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-02-20 Tools.dll (2.0.0.2)
2006-02-06 advcheck.dll (1.0.2.0)
2006-10-13 Includes\Spybots.sbi (*)
2006-10-13 Includes\Trojans.sbi (*)
2006-10-13 Includes\Dialer.sbi (*)
2006-10-13 Includes\Security.sbi (*)
2006-10-13 Includes\Malware.sbi (*)
2006-10-13 Includes\Hijackers.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2006-10-20 Includes\PUPS.sbi (*)
2006-10-27 Includes\Cookies.sbi (*)
2006-10-27 Includes\Revision.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-10-27 Includes\TrojansC.sbi (*)
2006-10-27 Includes\SpybotsC.sbi (*)
2006-10-27 Includes\SecurityC.sbi (*)
2006-10-27 Includes\PUPSC.sbi (*)
2006-10-27 Includes\MalwareC.sbi (*)
2006-10-27 Includes\KeyloggersC.sbi (*)
2006-10-27 Includes\HijackersC.sbi (*)
2006-10-27 Includes\DialerC.sbi (*)
--- System information ---
Windows 2000 (Build: 2195) Service Pack 4
/ DataAccess: Microsoft Data Access Components KB870669
/ DataAccess: Security Update for Microsoft Data Access Components
/ DirectX / DX8.1 / SP1: Correctif pour DirectX 8.1 - KB839643
/ DirectX: DirectX Update 819696
... (cut as too lon)
--- Startup entries list ---
Located: HK_LM:Run, !AVG Anti-Spyware
command: "C:\Program Files\Finders\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
file: C:\Program Files\Finders\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
size: 6266880
MD5: 01d90ae5dccbce0c7b52874fec35a608
Located: HK_LM:Run, Anti-Virus Update Scheduler V1.39.12R
command: C:\WINNT\sysdat.exe
file:
Located: HK_LM:Run, defender
command: C:\\dfndrff_e26.exe
file:
Located: HK_LM:Run, HPDJ Taskbar Utility
command: C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
file: C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
size: 196608
MD5: 7c6b5065e7326e3c91a62800df3a31fa
Located: HK_LM:Run, NeroCheck
command: C:\WINNT\system32\NeroCheck.exe
file: C:\WINNT\system32\NeroCheck.exe
size: 155648
MD5: 3e4c03cefad8de135263236b61a49c90
Located: HK_LM:Run, newname
command: C:\\nwnmff_e26.exe
file:
Located: HK_LM:Run, Norman ZANDA
command: C:\Program Files\Norman\bin\ZLH.EXE /LOAD /SPLASH
file:
Located: HK_LM:Run, NvCplDaemon
command: RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
file: C:\WINNT\system32\RUNDLL32.EXE
size: 10000
MD5: 61cf5b74a4b5fe430f87e9259b7e4f60
Located: HK_LM:Run, nwiz
command: nwiz.exe /install
file: C:\WINNT\system32\nwiz.exe
size: 741376
MD5: a4ae9ba1e10cb9f6c0949c4db91a1f72
Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 98304
MD5: 76a3a30b58405c2c6d833895253a51a9
Located: HK_LM:Run, Share-to-Web Namespace Daemon
command: C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
file: C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
size: 69632
MD5: 2f2bc80803f0638f6738e37f769e4bd0
Located: HK_LM:Run, Synchronization Manager
command: mobsync.exe /logon
file: C:\WINNT\system32\mobsync.exe
size: 111888
MD5: 25927f36c86159f0d55288f4fed12d93
Located: HK_LM:Run, wma34987
command: RUNDLL32.EXE w0181c50.dll,n 005349820000000a0181c50
file: C:\WINNT\system32\RUNDLL32.EXE
size: 10000
MD5: 61cf5b74a4b5fe430f87e9259b7e4f60
Located: HK_LM:Run, Zone Labs Client
command: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
file: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
size: 755480
MD5: b4e843ded6daf99aec3fbfe395e643c7
Located: HK_LM:RunServices, tetriz3
command: C:\WINNT\system32\tetriz3.exe
file:
Located: HK_CU:Run, internat.exe
command: internat.exe
file: C:\WINNT\system32\internat.exe
size: 20752
MD5: 406b12788886496bd299c3f9e5e310d0
Located: HK_CU:Run, Shell
command: "C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00005.exe"
file:
Located: HK_CU:Run, SpybotSD TeaTimer
command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 1415824
MD5: 70496eee0ddbe485f658693826f44d38
Located: HK_CU:Run, tetriz3
command: C:\WINNT\system32\tetriz3.exe
file:
Located: Démarrage (tous utilisateurs), Acrobat Assistant.lnk
command: C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
file: C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
size: 49254
MD5: 0e6e43d31ac16bcf682eb5f63178c492
Located: Démarrage (tous utilisateurs), hp psc 2000 Series.lnk
command: C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
file: C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
size: 323646
MD5: 1fd676dceec0288701445bc9acc61329
Located: Démarrage (tous utilisateurs), Nielsen NetRatings.lnk
command: C:\Program Files\NielsenNetratings\bin\insight.exe
file: C:\Program Files\NielsenNetratings\bin\insight.exe
size: 20480
MD5: b613f98929f988c8103463742272b72e
Located: System.ini, crypt32chain
command: crypt32.dll
file: crypt32.dll
Located: System.ini, cryptnet
command: cryptnet.dll
file: cryptnet.dll
Located: System.ini, cscdll
command: cscdll.dll
file: cscdll.dll
Located: System.ini, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
Located: System.ini, SensLogn
command: WlNotify.dll
file: WlNotify.dll
Located: System.ini, wzcnotif
command: wzcdlg.dll
file: wzcdlg.dll
Need more expertise to get rid of pretty resistant one(s) !
I'm using Win2k with Firefox (AV is Norman, firewall is ZoneLabs) and each time I reboot the PC / connect to the web things like wacky32.exe appear on C:. Also on the Windows Control panel Winantivirus 2006 icon can not be removed (!).
Ran ad-aware and AVG, also smitfraud (found nothing after a successful run) and VundoFix.exe until lists have been cleared, but still spybot is finding the same list of elements.

----
Here's the spybot report :
--- Search result list ---
Command Service: Réglages Autorun (Valeur du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\newname
Smitfraud-C.: Réglages Autorun (wma34987) (Valeur du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wma34987
Smitfraud-C.: Fichier de programme (Fichier, fixed)
C:\WINNT\system32\RUNDLL32.EXE
Smitfraud-C.: Réglages Autorun (defender) (Valeur du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\defender
Microsoft.WindowsSecurityCenter.AntiVirusDisableNotify: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify!=dword:0
Microsoft.WindowsSecurityCenter.AntiVirusOverride: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride!=dword:0
Microsoft.WindowsSecurityCenter.FirewallDisabled: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\windowsfirewall\domainprofile\enablefirewall!=dword:1
Microsoft.WindowsSecurityCenter.FirewallDisabled: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\windowsfirewall\standardprofile\enablefirewall!=dword:1
Microsoft.WindowsSecurityCenter.FirewallDisableNotify: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify!=dword:0
Microsoft.WindowsSecurityCenter.FirewallOverride: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride!=dword:0
Microsoft.WindowsSecurityCenter.SP2Update: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\DoNotAllowXPSP2!=dword:0
Microsoft.WindowsSecurityCenter.UpdateDisableNotify: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify!=dword:0
Microsoft.WindowsSecurityCenter_disabled: Réglages (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Start!=W=2
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-05-31 Update.exe (1.4.0.0)
2006-10-08 unins000.exe (51.41.0.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-02-20 Tools.dll (2.0.0.2)
2006-02-06 advcheck.dll (1.0.2.0)
2006-10-13 Includes\Spybots.sbi (*)
2006-10-13 Includes\Trojans.sbi (*)
2006-10-13 Includes\Dialer.sbi (*)
2006-10-13 Includes\Security.sbi (*)
2006-10-13 Includes\Malware.sbi (*)
2006-10-13 Includes\Hijackers.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2006-10-20 Includes\PUPS.sbi (*)
2006-10-27 Includes\Cookies.sbi (*)
2006-10-27 Includes\Revision.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-10-27 Includes\TrojansC.sbi (*)
2006-10-27 Includes\SpybotsC.sbi (*)
2006-10-27 Includes\SecurityC.sbi (*)
2006-10-27 Includes\PUPSC.sbi (*)
2006-10-27 Includes\MalwareC.sbi (*)
2006-10-27 Includes\KeyloggersC.sbi (*)
2006-10-27 Includes\HijackersC.sbi (*)
2006-10-27 Includes\DialerC.sbi (*)
--- System information ---
Windows 2000 (Build: 2195) Service Pack 4
/ DataAccess: Microsoft Data Access Components KB870669
/ DataAccess: Security Update for Microsoft Data Access Components
/ DirectX / DX8.1 / SP1: Correctif pour DirectX 8.1 - KB839643
/ DirectX: DirectX Update 819696
... (cut as too lon)
--- Startup entries list ---
Located: HK_LM:Run, !AVG Anti-Spyware
command: "C:\Program Files\Finders\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
file: C:\Program Files\Finders\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
size: 6266880
MD5: 01d90ae5dccbce0c7b52874fec35a608
Located: HK_LM:Run, Anti-Virus Update Scheduler V1.39.12R
command: C:\WINNT\sysdat.exe
file:
Located: HK_LM:Run, defender
command: C:\\dfndrff_e26.exe
file:
Located: HK_LM:Run, HPDJ Taskbar Utility
command: C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
file: C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
size: 196608
MD5: 7c6b5065e7326e3c91a62800df3a31fa
Located: HK_LM:Run, NeroCheck
command: C:\WINNT\system32\NeroCheck.exe
file: C:\WINNT\system32\NeroCheck.exe
size: 155648
MD5: 3e4c03cefad8de135263236b61a49c90
Located: HK_LM:Run, newname
command: C:\\nwnmff_e26.exe
file:
Located: HK_LM:Run, Norman ZANDA
command: C:\Program Files\Norman\bin\ZLH.EXE /LOAD /SPLASH
file:
Located: HK_LM:Run, NvCplDaemon
command: RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
file: C:\WINNT\system32\RUNDLL32.EXE
size: 10000
MD5: 61cf5b74a4b5fe430f87e9259b7e4f60
Located: HK_LM:Run, nwiz
command: nwiz.exe /install
file: C:\WINNT\system32\nwiz.exe
size: 741376
MD5: a4ae9ba1e10cb9f6c0949c4db91a1f72
Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 98304
MD5: 76a3a30b58405c2c6d833895253a51a9
Located: HK_LM:Run, Share-to-Web Namespace Daemon
command: C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
file: C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
size: 69632
MD5: 2f2bc80803f0638f6738e37f769e4bd0
Located: HK_LM:Run, Synchronization Manager
command: mobsync.exe /logon
file: C:\WINNT\system32\mobsync.exe
size: 111888
MD5: 25927f36c86159f0d55288f4fed12d93
Located: HK_LM:Run, wma34987
command: RUNDLL32.EXE w0181c50.dll,n 005349820000000a0181c50
file: C:\WINNT\system32\RUNDLL32.EXE
size: 10000
MD5: 61cf5b74a4b5fe430f87e9259b7e4f60
Located: HK_LM:Run, Zone Labs Client
command: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
file: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
size: 755480
MD5: b4e843ded6daf99aec3fbfe395e643c7
Located: HK_LM:RunServices, tetriz3
command: C:\WINNT\system32\tetriz3.exe
file:
Located: HK_CU:Run, internat.exe
command: internat.exe
file: C:\WINNT\system32\internat.exe
size: 20752
MD5: 406b12788886496bd299c3f9e5e310d0
Located: HK_CU:Run, Shell
command: "C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00005.exe"
file:
Located: HK_CU:Run, SpybotSD TeaTimer
command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 1415824
MD5: 70496eee0ddbe485f658693826f44d38
Located: HK_CU:Run, tetriz3
command: C:\WINNT\system32\tetriz3.exe
file:
Located: Démarrage (tous utilisateurs), Acrobat Assistant.lnk
command: C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
file: C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
size: 49254
MD5: 0e6e43d31ac16bcf682eb5f63178c492
Located: Démarrage (tous utilisateurs), hp psc 2000 Series.lnk
command: C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
file: C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
size: 323646
MD5: 1fd676dceec0288701445bc9acc61329
Located: Démarrage (tous utilisateurs), Nielsen NetRatings.lnk
command: C:\Program Files\NielsenNetratings\bin\insight.exe
file: C:\Program Files\NielsenNetratings\bin\insight.exe
size: 20480
MD5: b613f98929f988c8103463742272b72e
Located: System.ini, crypt32chain
command: crypt32.dll
file: crypt32.dll
Located: System.ini, cryptnet
command: cryptnet.dll
file: cryptnet.dll
Located: System.ini, cscdll
command: cscdll.dll
file: cscdll.dll
Located: System.ini, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
Located: System.ini, SensLogn
command: WlNotify.dll
file: WlNotify.dll
Located: System.ini, wzcnotif
command: wzcdlg.dll
file: wzcdlg.dll