# PC Infected with universa application

**URL:** https://boards.straightdope.com/t/pc-infected-with-universa-application/360245
**Category:** Factual Questions
**Created:** [June 10, 2006, 11:20pm UTC](https://boards.straightdope.com/t/pc-infected-with-universa-application/360245 "2006-06-10T23:20:12Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![MannyL](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@MannyL](https://boards.straightdope.com/u/MannyL)
#### Post date: [June 10, 2006, 11:20pm UTC](https://boards.straightdope.com/t/pc-infected-with-universa-application/360245/1 "2006-06-10T23:20:12Z")

</div>

I was tricked into going to a site that infected me with Universa Application. Zone Alarms is preventing it from talking to the internet but I can’t get rid of it on the computer.

Here is my Hijack This log file

Logfile of HijackThis v1.99.1  
Scan saved at 6:52:25 PM, on 6/10/2006  
Platform: Windows XP SP2 (WinNT 5.01.2600)  
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:  
C:\WINDOWS\System32\smss.exe  
C:\WINDOWS\system32\winlogon.exe  
C:\WINDOWS\system32\services.exe  
C:\WINDOWS\system32\lsass.exe  
C:\WINDOWS\system32\svchost.exe  
C:\WINDOWS\System32\svchost.exe  
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe  
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe  
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe  
C:\WINDOWS\system32\spoolsv.exe  
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe  
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe  
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe  
C:\Program Files\Norton AntiVirus  
avapsvc.exe  
C:\Program Files\Retrospect\Retrospect Client\RemotSvc.exe  
C:\Program Files\Retrospect\Retrospect Client\retroclient.exe  
C:\WINDOWS\system32\svchost.exe  
C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe  
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe  
C:\WINDOWS\system32\ZoneLabs\vsmon.exe  
C:\Program Files\Raxco\PerfectDisk\PDSched.exe  
C:\WINDOWS\Explorer.EXE  
C:\WINDOWS\ALCXMNTR.EXE  
C:\WINDOWS\system32\VTTimer.exe  
C:\Program Files\Common Files\Symantec Shared\ccApp.exe  
C:\Program Files\Java\jre1.5.0\_06\bin\jusched.exe  
C:\Program Files\Common Files\Real\Update\_OB\realsched.exe  
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe  
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe  
C:\WINDOWS\System32\svchost.exe  
C:\WINDOWS\AGRSMMSG.exe  
C:\Program Files\DAEMON Tools\daemon.exe  
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe  
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe  
C:\Program Files\Google\Google Updater\1.1.514.27546\GoogleUpdater.exe  
C:\WINDOWS\system32\cmd.exe  
C:\Program Files\Mozilla Firefox\firefox.exe  
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcrobatInfo.exe  
C:\Documents and Settings\Emanuel Levy\My Documents\hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll  
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll  
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0\_06\bin\ssv.dll  
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll  
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll  
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll  
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll  
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll  
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll  
O4 - HKLM…\Run: [AlcxMonitor] ALCXMNTR.EXE  
O4 - HKLM…\Run: [VTTimer] VTTimer.exe  
O4 - HKLM…\Run: [ccApp] “C:\Program Files\Common Files\Symantec Shared\ccApp.exe”  
O4 - HKLM…\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer  
O4 - HKLM…\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\_06\bin\jusched.exe  
O4 - HKLM…\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe  
O4 - HKLM…\Run: [TkBellExe] “C:\Program Files\Common Files\Real\Update\_OB\realsched.exe” -osboot  
O4 - HKLM…\Run: [RemoteControl] “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”  
O4 - HKLM…\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe  
O4 - HKLM…\Run: [AGRSMMSG] AGRSMMSG.exe  
O4 - HKLM…\Run: [DAEMON Tools] “C:\Program Files\DAEMON Tools\daemon.exe” -lang 1033  
O4 - HKLM…\Run: [CloneCDTray] “C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe” /s  
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe  
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?  
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe  
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\1.1.514.27546\GoogleUpdater.exe  
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html  
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html  
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html  
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html  
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html  
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html  
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html  
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html  
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000  
O8 - Extra context menu item: Save with Download Manager… - file://C:\Program Files\J River\Media Center 11\DMDownload.htm  
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL  
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS  
pqtplugin4.dll  
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - [http://go.microsoft.com/fwlink/?linkid=39204](http://go.microsoft.com/fwlink/?linkid=39204)  
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - [http://update.microsoft.com/microsoftupdat...b?1149744041454](http://update.microsoft.com/microsoftupdat...b?1149744041454)  
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - [http://ipgweb.cce.hp.com/rdqcpc/downloads/msxml4.cab](http://ipgweb.cce.hp.com/rdqcpc/downloads/msxml4.cab)  
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = levy.lan  
O17 - HKLM\Software…\Telephony: DomainName = levy.lan  
O17 - HKLM\System\CCS\Services\Tcpip…{F75A42E1-B59A-4E31-9FCC-8C54A0E56A70}: NameServer = 192.168.3.3,192.168.3.1  
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = levy.lan  
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = levy.lan  
O20 - Winlogon Notify: winwrb32 - C:\WINDOWS\SYSTEM32\winwrb32.dll  
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe  
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe  
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe  
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe  
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe  
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe  
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe  
O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\system32\IcdSptSv.exe  
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe  
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE  
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus  
avapsvc.exe  
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe  
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe  
O23 - Service: Retrospect Client - EMC - C:\Program Files\Retrospect\Retrospect Client\RemotSvc.exe  
O23 - Service: Retrospect Helper - EMC Corporation - C:\Program Files\Retrospect\Retrospect Client\rthlpsvc.exe  
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe  
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe  
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe  
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe  
O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe  
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe  
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe  
I’ve tried booting into safe mode to delete the file it puts in temp but when I try to remove them I’m told access denied.

---

<div class="post-metadata">

### Author: ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)
#### Post date: [June 10, 2006, 11:58pm UTC](https://boards.straightdope.com/t/pc-infected-with-universa-application/360245/2 "2006-06-10T23:58:22Z")

</div>

Is this the file you tried to delete?

**O20 - Winlogon Notify: winwrb32 - C:\WINDOWS\SYSTEM32\winwrb32.dll**

If not, check that item in HJT, and remove it. Then locate that file and delete it.

---

<div class="post-metadata">

### Author: ![MannyL](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@MannyL](https://boards.straightdope.com/u/MannyL)
#### Post date: [June 11, 2006, 12:08am UTC](https://boards.straightdope.com/t/pc-infected-with-universa-application/360245/3 "2006-06-11T00:08:32Z")

</div>

> [@Fear Itself](#):
>
> Is this the file you tried to delete?
> 
> **O20 - Winlogon Notify: winwrb32 - C:\WINDOWS\SYSTEM32\winwrb32.dll**
> 
> If not, check that item in HJT, and remove it. Then locate that file and delete it.

I get access denied when I try to delete it as well

---

<div class="post-metadata">

### Author: ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)
#### Post date: [June 11, 2006, 12:22am UTC](https://boards.straightdope.com/t/pc-infected-with-universa-application/360245/4 "2006-06-11T00:22:24Z")

</div>

Try downloading [Unlocker 1.8.3](http://ccollomb.free.fr/unlocker/) which should allow you to change the permissions on that file. Then download [Killbox](http://www.bleepingcomputer.com/files/killbox.php) and use it to delete that file. Then go back in with HJT and remove the winwrb32.dll entry.

---

<div class="post-metadata">

### Author: ![MannyL](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@MannyL](https://boards.straightdope.com/u/MannyL)
#### Post date: [June 11, 2006, 12:35am UTC](https://boards.straightdope.com/t/pc-infected-with-universa-application/360245/5 "2006-06-11T00:35:52Z")

</div>

> [@Fear Itself](#):
>
> Try downloading [Unlocker 1.8.3](http://ccollomb.free.fr/unlocker/) which should allow you to change the permissions on that file. Then download [Killbox](http://www.bleepingcomputer.com/files/killbox.php) and use it to delete that file. Then go back in with HJT and remove the winwrb32.dll entry.

I was able to use unlocker to unlock and delete the file. I was also able to unlock and delete the tempfiles it made. My HJT log looks good now. Thanks for the help.  
Mod’s I guess this is asked and answered
