Hi,
I'm a new boy just starting to learn at your online university. Please could you help with the problem below. I hope I have followed the right process and posted the right information.
My friend's laptop has been suffering from Lop and other problems for some time and I have not been able to fix it. (Trying to fix it is what led me to find yourselves and inspired me to try to learn more about this subject).
Symptoms include Casinos online, find a date, my antivirus software and cellphone ringtones appearing as desktop icons. A search bar covering the start menu when using IE (he got around this by using firefox instead).
I've spent quite some time using your recommenced tools today with the following effect. At first Ad-aware was finding a Lop process running each time after a reboot even though it removed Lop. Each process had a different name. I had 5 goes at this with Ad-aware and gave up. After having run most of the online scanners that you recommend Ad-aware did ot find Lop when run the last time. However, the synaptics scanner still shows quite a lot of infection. Here is the last output from the scanner:
C:\WINDOWS\XxxAccess.exe is infected with Dialer.OneOnOne
C:\Program Files\Microsoft AntiSpyware\Quarantine\6BF2736F-2232-45BF-8CCC-6D5624\4A718C56-7D09-445B-8513-84DF3F is infected with Adware.GAIN
C:\Program Files\Microsoft AntiSpyware\Quarantine\6BF2736F-2232-45BF-8CCC-6D5624\D2886BC8-7065-41C2-93F3-48A8ED is infected with Adware.GAIN
C:\Documents and Settings\alsly\Local Settings\Temp\31286.exe is infected with Download.Adware.Lop
C:\Documents and Settings\alsly\Local Settings\Temp\Inside Program.exe is infected with Download.Adware.Lop
C:\Documents and Settings\alsly\Local Settings\Temp\ynircgwj.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Local Settings\Temp\~310358.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~311182.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~312494.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~313207.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~313913.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~314593.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~315277.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~316626.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~317279.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~318094.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~318956.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~320065.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~321014.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~321978.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~322812.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~323567.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~324274.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~325032.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~325608.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~326508.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~327264.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~327946.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~328599.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~329316.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~330068.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~330886.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~331672.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~332411.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~333116.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~334440.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~352773.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~376847.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~418014.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~432220.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~473721.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~707605.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~835694.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~879700.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~892397.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Application Data\Error Owns\aachdrpo.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\aastwdly.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\adjbnijq.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\bhzsstlr.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\bmfsbuxl.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\crorrdqz.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\dcukrpdl.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\dkzobizw.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\ejpvwqtx.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\equfjigp.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\ezydtoic.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\fktpajki.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\gecxsjmz.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\iybqzbid.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\jhhdwfnw.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\jvffyclf.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\kgwflumr.exe is infected with Download.Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\kiybeoau.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\kltzxphb.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\kugxacfp.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\mdqmcyhg.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\memo wipe third bend.exe is infected with Download.Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\mvmyduvl.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\nygdfxdj.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\ouuxlawz.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\oyeqjtpe.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\rajfanhb.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\rdxtdoeu.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\rxhrttau.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\ryigmexh.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\snkjvmpj.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\snushrjh.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\uadsnght.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\vbqysbcs.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\wboqyedq.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\xwuxedkk.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\zhcpgrvt.exe is infected with Adware.Lop
Here is the latest Hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 17:19:36, on 01/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SonicWALL\SonicWALL VPN Client\IreIKE.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\SonicWALL\SonicWALL VPN Client\IPSecMon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\HPQ\One-Touch\OneTouch.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\Program Files\SonicWALL\SonicWALL VPN Client\SafeCfg.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [EnigmaPopupStop] C:\Program Files\Enigma Software Group\SpyHunter\PopupBlocker\EnigmaPopupStop.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [AdaptecDirectCD] "c:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SureCleanProfessional] "C:\PROGRA~1\PANICW~1\SURECL~1\SRClean.exe"
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe
O4 - HKCU\..\Run: [MailChacker.exe] C:\MailChk\MailChecker.exe -r
O4 - HKCU\..\Run: [SPSTEALT] "C:\Program Files\Smart Protector Pro\SmartProtector-Pro.exe" /stealt
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Eq copy] C:\DOCUME~1\alsly\APPLIC~1\ERRORO~1\Info Bib Manager.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O4 - Global Startup: SonicWALL VPN Client.lnk = C:\Program Files\SonicWALL\SonicWALL VPN Client\SafeCfg.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsup ... SupCtl.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/bestfriends/miniclipGameLoader.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: SafeNet Monitor Service (IPSECMON) - SafeNet - C:\Program Files\SonicWALL\SonicWALL VPN Client\IPSecMon.exe
O23 - Service: SafeNet IKE Service (IreIKE) - SafeNet - C:\Program Files\SonicWALL\SonicWALL VPN Client\IreIKE.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Any help gratefully received.
Thanks in advance.
I'm a new boy just starting to learn at your online university. Please could you help with the problem below. I hope I have followed the right process and posted the right information.
My friend's laptop has been suffering from Lop and other problems for some time and I have not been able to fix it. (Trying to fix it is what led me to find yourselves and inspired me to try to learn more about this subject).
Symptoms include Casinos online, find a date, my antivirus software and cellphone ringtones appearing as desktop icons. A search bar covering the start menu when using IE (he got around this by using firefox instead).
I've spent quite some time using your recommenced tools today with the following effect. At first Ad-aware was finding a Lop process running each time after a reboot even though it removed Lop. Each process had a different name. I had 5 goes at this with Ad-aware and gave up. After having run most of the online scanners that you recommend Ad-aware did ot find Lop when run the last time. However, the synaptics scanner still shows quite a lot of infection. Here is the last output from the scanner:
C:\WINDOWS\XxxAccess.exe is infected with Dialer.OneOnOne
C:\Program Files\Microsoft AntiSpyware\Quarantine\6BF2736F-2232-45BF-8CCC-6D5624\4A718C56-7D09-445B-8513-84DF3F is infected with Adware.GAIN
C:\Program Files\Microsoft AntiSpyware\Quarantine\6BF2736F-2232-45BF-8CCC-6D5624\D2886BC8-7065-41C2-93F3-48A8ED is infected with Adware.GAIN
C:\Documents and Settings\alsly\Local Settings\Temp\31286.exe is infected with Download.Adware.Lop
C:\Documents and Settings\alsly\Local Settings\Temp\Inside Program.exe is infected with Download.Adware.Lop
C:\Documents and Settings\alsly\Local Settings\Temp\ynircgwj.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Local Settings\Temp\~310358.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~311182.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~312494.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~313207.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~313913.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~314593.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~315277.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~316626.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~317279.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~318094.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~318956.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~320065.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~321014.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~321978.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~322812.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~323567.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~324274.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~325032.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~325608.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~326508.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~327264.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~327946.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~328599.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~329316.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~330068.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~330886.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~331672.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~332411.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~333116.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~334440.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~352773.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~376847.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~418014.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~432220.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~473721.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~707605.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~835694.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~879700.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Local Settings\Temp\~892397.tmp is infected with Adware.Websearch
C:\Documents and Settings\alsly\Application Data\Error Owns\aachdrpo.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\aastwdly.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\adjbnijq.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\bhzsstlr.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\bmfsbuxl.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\crorrdqz.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\dcukrpdl.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\dkzobizw.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\ejpvwqtx.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\equfjigp.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\ezydtoic.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\fktpajki.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\gecxsjmz.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\iybqzbid.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\jhhdwfnw.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\jvffyclf.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\kgwflumr.exe is infected with Download.Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\kiybeoau.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\kltzxphb.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\kugxacfp.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\mdqmcyhg.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\memo wipe third bend.exe is infected with Download.Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\mvmyduvl.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\nygdfxdj.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\ouuxlawz.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\oyeqjtpe.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\rajfanhb.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\rdxtdoeu.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\rxhrttau.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\ryigmexh.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\snkjvmpj.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\snushrjh.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\uadsnght.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\vbqysbcs.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\wboqyedq.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\xwuxedkk.exe is infected with Adware.Lop
C:\Documents and Settings\alsly\Application Data\Error Owns\zhcpgrvt.exe is infected with Adware.Lop
Here is the latest Hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 17:19:36, on 01/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SonicWALL\SonicWALL VPN Client\IreIKE.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\SonicWALL\SonicWALL VPN Client\IPSecMon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\HPQ\One-Touch\OneTouch.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\Program Files\SonicWALL\SonicWALL VPN Client\SafeCfg.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [EnigmaPopupStop] C:\Program Files\Enigma Software Group\SpyHunter\PopupBlocker\EnigmaPopupStop.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [AdaptecDirectCD] "c:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SureCleanProfessional] "C:\PROGRA~1\PANICW~1\SURECL~1\SRClean.exe"
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe
O4 - HKCU\..\Run: [MailChacker.exe] C:\MailChk\MailChecker.exe -r
O4 - HKCU\..\Run: [SPSTEALT] "C:\Program Files\Smart Protector Pro\SmartProtector-Pro.exe" /stealt
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Eq copy] C:\DOCUME~1\alsly\APPLIC~1\ERRORO~1\Info Bib Manager.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O4 - Global Startup: SonicWALL VPN Client.lnk = C:\Program Files\SonicWALL\SonicWALL VPN Client\SafeCfg.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsup ... SupCtl.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/bestfriends/miniclipGameLoader.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: SafeNet Monitor Service (IPSECMON) - SafeNet - C:\Program Files\SonicWALL\SonicWALL VPN Client\IPSecMon.exe
O23 - Service: SafeNet IKE Service (IreIKE) - SafeNet - C:\Program Files\SonicWALL\SonicWALL VPN Client\IreIKE.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Any help gratefully received.
Thanks in advance.