Computing.Net > Forums > Windows 95/98 > Trojan SNDSRVC.EXE

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Trojan SNDSRVC.EXE

Reply to Message Icon

Name: andy smithers
Date: December 9, 2003 at 10:33:11 Pacific
OS: duron 800 Mhz
CPU/Ram: 1/2gb
Comment:

I have been getting problems not too dissimilar to the 6825.html forum.
The internet home page is not apparently redirected, but a task manager check does show the dreaded SNDSRVC.exe.

I have tried the Norton Internet Security tools but it did not flag any trojans or other viruses.

I therefore followed the HIJACKTHIS line and attach the log.

Logfile of HijackThis v1.97.5
Scan saved at 18:04:40, on 09/12/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPROXY.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.exe
C:\WINDOWS\SYSTEM\HIDSERV.exe
C:\WINDOWS\EXPLORER.exe
C:\WINDOWS\SYSTEM\RNAAPP.exe
C:\WINDOWS\SYSTEM\TAPISRV.exe
C:\WINDOWS\TASKMON.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.exe
C:\WINDOWS\RunDLL.exe
C:\IOMEGA ZIP\IOWATCH.exe
C:\IOMEGA ZIP\IMGICON.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.exe
C:\DOWNLOADS TEMP\VIRUSCHECK\HIJACKTHIS\HIJACKTHIS.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/my.asp?did=1&t=4*bndTSYlDWX5WydimYF6vTaCCzJeNxoyJwxKbUN91JNmmyb*g7WskUQFRm3hM61D*KS!IysbCFnO5wR1v!Oy!VQ$$&p=48ZFp4MlwDSLOvn*8tsrUZXd0jc5GwXFPKmGdHQHIaFy92ox14UxiBFD6mv3uPb*CoSsh*LCDDbqiRNBontf39SINGmvEO39RTdZn1Kw7ChyKrsag8CcsjY4CiEExR58qthy7eGwjP5UEhOELe8Y*BIt79obmxRHa9giL8q6P0oJpG9KOpM6g1gsqjll3cpSNf&Ath=x
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Utilities\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Utilities\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.exe
O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Utilities\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Hidserv] Hidserv.exe run
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccProxy] C:\PROGRA~1\COMMON~1\SYMANT~1\CCPROXY.exe
O4 - HKLM\..\RunServices: [SndSrvc] C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSRVC.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - Startup: Iomega Watch.lnk = C:\IOMEGA ZIP\IOWATCH.exe
O4 - Startup: Iomega Startup Options.lnk = C:\IOMEGA ZIP\IMGSTART.exe
O4 - Startup: Iomega Disk Icons.lnk = C:\IOMEGA ZIP\IMGICON.exe
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37871.5732060185
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} (loader Class) - http://dload.ipbill.com/del/loader.exe
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll

I am a bit of a novice on the techie stuff, so any advice on how to clear up my PC would be very welcome.

I cannot see any MSxxxx.DLL files of about 13K size as was mentioned in this forum, so is it a new-ish variant? Only started getting it curiously enough once I had installed NIS? Although I suspect it was related to checking the Parental controls for my kids in the various modes.




Sponsored Link
Ads by Google

Response Number 1
Name: winipcfg
Date: December 9, 2003 at 11:00:06 Pacific
Reply:

Hi,
Get Trojan Remover. You can download it from http://www.simplysup.com/tremover/download.html. It is excellent. I haven't found a trojan that it coulsn't remove, just remember to update it. You have a free 30-Day trial period. Then you must either buy or uninstall. The problem with Norton is that yes, it does miss Trojans once in awhile.
Good Luck,
~winipcfg


0

Response Number 2
Name: winipcfg
Date: December 9, 2003 at 11:14:28 Pacific
Reply:

Actually,
After some research, I don't think that is even a trojan. Looks to be a Normal Norton file.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows 95/98 Forum Home


Sponsored links

Ads by Google


Results for: Trojan SNDSRVC.EXE

Question Trojan KERNEL32.exe www.computing.net/answers/windows-95/question-trojan-kernel32exe-/132779.html

Trojan .... openme.exe www.computing.net/answers/windows-95/trojan-openmeexe/116819.html

Trojan Virus belt.exe www.computing.net/answers/windows-95/trojan-virus-beltexe/151651.html