View Single Post
Old 02-22-2006, 12:44 AM   #5 (permalink)
Jag11
Analyst, Security Team
 
Jag11's Avatar
 
Join Date: Nov 2005
Location: 127.0.0.1
Posts: 806
OS: Windows XP


Thanks for the logs, before we proceed, just want to inform you that you have no Anti-Virus installed. You really need to have one because this will serve as your shield to the bad guys over the internet. The one I use is AVG, it's free. Once you've downloaded it, install it as soon as possible, because this is important.

==========================================================

Please follow the instructions provided, you may want to print out these instructions and use them as a reference. If you have any questions regarding the fix, please ask us before proceeding.

==========================================================

Download ATF Cleaner by Atribune, save it to your Desktop. We will use this later.

==========================================================

Run HijackThis

Please open HJT, click Do a system scan only, and then place a checkmark beside each of these entries:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} - http://www.azebar.com/install/azesearch.cab
O20 - Winlogon Notify: H323TSP - C:\WINDOWS\system32\fp2403fqe.dll (file missing)
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/14...3/cpbrkpie.cab
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -


After placing all the checkmarks, close all windows (except HJT), and then hit Fix Checked. When it finishes, exit HJT.

==========================================================

Show Hidden Files and Folders. Click Start » My Computer » Tools » Folder Options. Select the View tab. Check Show hidden files and folders. Uncheck the Hide protected operating system files (recommended) option. Click Yes to confirm, then OK to exit.

==========================================================

Boot into Safe Mode. Please restart your computer and as soon as it starts to boot, tap F8 repeatedly. A menu should appear, select Safe Mode from the menu and then hit Enter on your keyboard. (this will take a while, so don't worry, just wait)

==========================================================

Delete Files and Folders

Find and delete this file:
  • C:\WINDOWS\SYSC00.exe
NOTE: Please let us know if there were any files or folders that you couldn't delete or find.

==========================================================

Run ATF Cleaner
  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
Click Exit on the Main menu to close the program.

==========================================================

Run an online scan at Panda's ActiveScan

Perform an online scan with Internet Explorer at Panda ActiveScan
  • Click on Free use ActiveScan located on the top right hand corner.
  • Click Scan your PC & a 'pop up' window shall appear. (ensure that your pop up blocker doesn't block it)
  • Click Scan Now.
  • Enter your e-mail address & click Scan Now. (begins downloading 8 MB Panda's ActiveX controls)
Begin the scan by selecting My Computer
  • If it finds any malware, it will offer you a report.
  • Click on see report. Then click Save report.
Please post that log in your next reply.

==========================================================

Please post this log(s) on your next reply:
  • HijackThis (new)
  • Panda
Please also provide details of any problems you encountered while performing the above steps and update us on how the computer behaves now.
__________________

If you think that we helped you in any way, please consider donating to the site.
.
Jag11 is offline