![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| HijackThis Log Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help. |
![]() |
|
|
Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Feb 2007
Posts: 4
OS: XP
|
Hwlo. Help with my HJT log needed.
I've done full sweeps with the usual programs but keep getting bugs re-installing themselves.
I've switched this machine off after taking the log and have no intention of switching it back on until I have an idea of how to combat the bugs therein. Many thanks in advance. Logfile of HijackThis v1.99.1 Scan saved at 17:52:58, on 05/02/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe C:\Program Files\Eset\nod32krn.exe C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wbem\wmiapsrv.exe C:\WINDOWS\System32\dmadmin.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe C:\Program Files\Lexmark 2400 Series\lxcrmon.exe C:\Program Files\Lexmark 2400 Series\ezprint.exe C:\Program Files\Multimedia keyboard utility\1.3\KbdAp32A.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\TomTom HOME\TomTomHOME.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\lxcrcoms.exe C:\PROGRA~1\INCRED~1\bin\IMApp.exe C:\Documents and Settings\User\Desktop\HijackThis.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by blueyonder R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing) O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll (file missing) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing) O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Multimedia keyboard utility\1.3\MMKEYBD.EXE O4 - HKLM\..\Run: [EasyMessage] "C:\PROGRA~1\ZANGOA~1\ZANGOM~1\em2.exe" -wait O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe" O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .xml: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\ O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe |
|
|
|
|
|
#2 (permalink) |
|
Moderator/ Rangemaster TSF Academy; Analyst, Security Team; Oor Wullie; TSF Surgeon and Resident Comic
|
Hi and welcome to TSF.
My name is Iain and I will be helping you clean your system. You may wish to Subscribe to this thread (Thread Tools > Subscribe to this thread) so that you are notified when you receive a reply. Please read these instructions carefully and then print out or copy this page to Notepad in order to assist you when carrying out the fix. You should not have any open browsers or live internet connections when you are following the procedures below. Note that the fix may take several posts. Please continue to respond to my instructions until I confirm that your system is clean. Remember that although your symptoms may vanish, this does NOT mean that your system is clean. If there is anything you don't understand, please ask BEFORE proceeding with the fixes. Please ensure that you follow the instructions in the order I have them listed. Show Hidden Files Go to My Computer > Tools > Folder Options > View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System files and Folders are showing / visible. Uncheck the Hide protected operating system files option. Downloads Please download Cleanup! or use this Alternate Link if the main link does not work and install it. You will use this later. *NOTE* Cleanup deletes EVERYTHING out of temporary folders and does NOT make backups. If you have any files in any TEMP directory and you need to keep them, then please MOVE THEM NOW! Download AVG Anti Spyware Use the link at the bottom of the page under "AVG Anti-Spyware Free for Windows" ![]()
When you have finished updating, EXIT AVG Anti Spyware. Please download combofix.exe to your desktop. IMPORTANT - You must place combofix on your desktop!! Double click combofix.exe & follow the prompts. When finished, the tool will produce a log for you at c:\combofix.txt. Post that log in your next reply. Note: Do not mouseclick combofix's window while it's running. That may cause it to stall. Reboot Reboot your system in Safe Mode.
Uninstall Programmes Click > Start > Control Panel > Add / Remove Programs and uninstall the following programs (if present): 180Solutions or Easy Messenger or Zango HijackThis Entries Open Hijack This and click on Scan. Check the following entries (if they still exist) (make sure you do not miss any) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = O4 - HKLM\..\Run: [EasyMessage] "C:\PROGRA~1\ZANGOA~1\ZANGOM~1\em2.exe" -wait Please remember to close all other windows, including browsers then click Fix checked. File Deletions Delete the following Folder indicated in BLUE if it still exists. C:\PROGRAM FILES\ZANGOA~1 Run CleanUp! *NOTE* Cleanup deletes EVERYTHING out of temporary folders and does NOT make backups. If you have any files in any TEMP directory and you need to keep them, then please MOVE THEM NOW! Open Cleanup! by double-clicking the icon on your desktop (or from Start > All Programs). Set the program up as follows: Click Options Move the slider button down to Custom CleanUp! Check the following:
Click OK, Press the CleanUp! button to start the program and DO NOT REBOOT when prompted. Note: CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these BEFORE running CleanUp! If you have a 64 bit Operating System do NOT run Cleanup and let me know as we will use another utility. Run AVG Anti Spyware Run AVG with it's updated definitions:(...it's important that all windows must be closed)
NOTE: AVG scan may require an hour. Reboot Reboot your system in Normal Mode. Online Scan Perform an online scan with Internet Explorer with Panda ActiveScan
![]()
* Turn off the real time scanner of any existing antivirus program while performing the online scan Logs required c:\combofix.txt AVG Log Panda Log HijackThis Log Please also let me know how your system is performing now and if you have any specific problems. In order to provide you with the best possible help, please ensure that HijackThis logs are produced only while in Normal Mode.
__________________
Iain - Defender of the Haggis and all things Scottish. I don't help by PM - post in the Forums. ![]() ![]() Ad-Aware::SpywareBlaster::SpyBot::SpywareGuard::SnoopFree::AVG Free::HOSTS File::HijackThis::Donate::5 Steps For Infected PCs |
|
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Feb 2007
Posts: 4
OS: XP
|
His system seems to be performing a lot better now, although it's still a little temperamental. Here are the requested logs. Thanks in advance
"User" - 07-02-13 15:17:36 Service Pack 2 ComboFix 07-02-11.1.1 - Running from: "C:\Documents and Settings\User\Desktop" (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\INSTALL.LOG C:\WINDOWS\secure32.html C:\Documents and Settings\All Users\Documents\Settings ((((((((((((((((((((((((((((((( Files Created from 2007-01-13 to 2007-02-13 )))))))))))))))))))))))))))))))))) 2007-02-13 15:10 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-02-13 15:10 <DIR> d-------- C:\Program Files\Grisoft 2007-02-06 16:57 <DIR> d-------- C:\Program Files\Nero 2007-02-06 16:57 <DIR> d-------- C:\Program Files\Common Files\Ahead 2007-02-06 16:52 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat 2007-02-06 16:51 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs 2007-02-06 16:51 <DIR> d-------- C:\WINDOWS\Internet Logs 2007-02-06 16:28 22,040 --a------ C:\DOCUME~1\User\Application Data\addon.dat 2007-02-06 16:28 <DIR> d-------- C:\Program Files\Bifrost 2007-02-06 16:20 639,224 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-02-05 15:33 <DIR> d-------- C:\DOCUME~1\User\Application Data\Lavasoft 2007-02-05 15:15 <DIR> d-------- C:\Program Files\Lavasoft 2007-02-05 15:13 502,368 --a------ C:\WINDOWS\system32\drivers\amon.sys 2007-02-05 15:13 270,336 --a------ C:\WINDOWS\system32\imon.dll 2007-02-05 14:35 <DIR> d-------- C:\WINDOWS\pss 2007-02-05 14:31 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys 2007-02-01 07:39 <DIR> d--hs---- C:\WINDOWS\CSC 2007-01-31 22:51 262,144 --a------ C:\DOCUME~1\Ben\ntuser.dat 2007-01-22 20:57 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-02-06 17:00 -------- d-------- C:\DOCUME~1\User\Application Data\ahead 2007-02-05 15:24 -------- d--h----- C:\Program Files\installshield installation information 2007-02-05 15:18 -------- d-------- C:\Program Files\Common Files\symantec shared 2007-02-05 15:18 -------- d-------- C:\DOCUME~1\User\Application Data\symantec 2007-02-05 15:02 -------- d-------- C:\Program Files\symantec 2007-01-31 21:56 -------- d-------- C:\Program Files\cyberlink 2007-01-31 21:36 -------- d-------- C:\Program Files\cdtrustee 2006-12-22 11:25 -------- d-------- C:\DOCUME~1\User\Application Data\help 2006-12-22 11:19 -------- d-------- C:\Program Files\steinberg 2006-12-13 21:03 -------- d-------- C:\Program Files\vanbasco's karaoke player 2006-12-07 06:40 2362184 --a------ C:\WINDOWS\system32\wmvcore.dll 2006-11-20 08:42 33280 --a------ C:\WINDOWS\system32\snmp.exe 2006-11-01 23:47 67104 --a------ C:\DOCUME~1\User\Application Data\gdipfontcachev1.dat (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe\" -quiet" "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" "msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background" "IncrediMail"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe /c" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "FLMK08KB"="C:\\Program Files\\Multimedia keyboard utility\\1.3\\MMKEYBD.EXE" "EasyMessage"="\"C:\\PROGRA~1\\ZANGOA~1\\ZANGOM~1\\em2.exe\" -wait" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\"" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "lxcrmon.exe"="\"C:\\Program Files\\Lexmark 2400 Series\\lxcrmon.exe\"" "EzPrint"="\"C:\\Program Files\\Lexmark 2400 Series\\ezprint.exe\"" "FaxCenterServer"="\"C:\\Program Files\\Lexmark Fax Solutions\\fm3032.exe\" /s" "LXCRCATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\LXCRtime.dll,_RunDLLEntry@16" "RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\"" "TomTomHOME.exe"="\"C:\\Program Files\\TomTom HOME\\TomTomHOME.exe\" -s" "WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe" "nod32kui"="\"C:\\Program Files\\Eset\\nod32kui.exe\" /WAITSERVICE" "Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\"" "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe" "!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\WinZip Quick Pick.lnk" "backup"="C:\\WINDOWS\\pss\\WinZip Quick Pick.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\WinZip\\WZQKPICK.EXE " "item"="WinZip Quick Pick" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RunDll32 cmicnfg" "hkey"="HKLM" "command"="RunDll32 cmicnfg.cpl,CMICtrlWnd" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\flaw stupid] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="user mpeg" "hkey"="HKCU" "command"="C:\\DOCUME~1\\LOCALS~1\\APPLIC~1\\GRIMPI~1\\user mpeg.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\intell32.exe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="intell32" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\intell32.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSOffice32] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="msjcf" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\msjcf.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NeroCheck" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\NeroCheck.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="mssysmgr" "hkey"="HKCU" "command"="C:\\PROGRA~1\\Ahead\\NEROPH~2\\data\\Xtras\\mssysmgr.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shell] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ibm00001" "hkey"="HKCU" "command"="\"C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\ibm00001.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SNPSTD2] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="vsnpstd2" "hkey"="HKLM" "command"="C:\\WINDOWS\\vsnpstd2.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Workflow] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Workflow" "hkey"="HKLM" "command"="D:\\Workflow.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{D1A2E7CD-F5C1-21A8-CA2C-13D0AC72D19D}"="Wheel Mouse Optical Driver" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1] Source REG_SZ C:\WINDOWS\warnhp.html [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e4f6821-76f9-11db-870a-000b6aa059e9}] Shell\AutoRun\command H:\InstallTomTomHOME.exe *newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_AVG_ANTI-SPYWARE_DRIVER *newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_AVG_ANTI-SPYWARE_GUARD ******************************************************************** catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006 http://www.gmer.net scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run EasyMessage = "C:\PROGRA~1\ZANGOA~1\ZANGOM~1\em2.exe" -wait?.g?????????????=??????G???????x???????Y???`)???=???????????????????(F??????C??????????????????????????????????R???`)??x???????????????????????????????W???`)??x?????????????????????????????????????????????????????? LXCRCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 07-02-13 15:20:31 --------------------------------------------------------- AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 11:42:53 14/02/2007 + Scan result: HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22} -> Adware.Generic : Cleaned with backup (quarantined). HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22} -> Adware.Generic : Cleaned with backup (quarantined). HKU\S-1-5-21-343818398-287218729-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22} -> Adware.Generic : Cleaned with backup (quarantined). C:\System Volume Information\_restore{036B7185-9F99-43DA-9AB7-BD332E610127}\RP428\A0058454.EXE -> Adware.HelpExpress : Cleaned with backup (quarantined). HKU\S-1-5-21-343818398-287218729-839522115-1003\Software\Classes\CLSID\{D1A2E7CD-F5C1-21A8-CA2C-13D0AC72D19D} -> Adware.SpyFalcon : Cleaned with backup (quarantined). HKU\S-1-5-21-343818398-287218729-839522115-1003_Classes\CLSID\{D1A2E7CD-F5C1-21A8-CA2C-13D0AC72D19D} -> Adware.SpyFalcon : Cleaned with backup (quarantined). C:\Documents and Settings\User\Desktop\Alcohol120% Retail v1.9.6.4719\crack\keygenerator_Alcohol120_retail_1.9.6.4719.exe/server.exe -> Backdoor.Bifrose.adn : Cleaned with backup (quarantined). :mozilla.44:C:\Documents and Settings\Ben\Application Data\Mozilla\Firefox\Profiles\ttyfjwsn.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.24:C:\Documents and Settings\Ben\Application Data\Mozilla\Firefox\Profiles\ttyfjwsn.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.25:C:\Documents and Settings\Ben\Application Data\Mozilla\Firefox\Profiles\ttyfjwsn.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.26:C:\Documents and Settings\Ben\Application Data\Mozilla\Firefox\Profiles\ttyfjwsn.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.27:C:\Documents and Settings\Ben\Application Data\Mozilla\Firefox\Profiles\ttyfjwsn.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.32:C:\Documents and Settings\Ben\Application Data\Mozilla\Firefox\Profiles\ttyfjwsn.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.40:C:\Documents and Settings\Ben\Application Data\Mozilla\Firefox\Profiles\ttyfjwsn.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned. :mozilla.33:C:\Documents and Settings\Ben\Application Data\Mozilla\Firefox\Profiles\ttyfjwsn.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.21:C:\Documents and Settings\Ben\Application Data\Mozilla\Firefox\Profiles\ttyfjwsn.default\cookies.txt -> TrackingCookie.Epilot : Cleaned. :mozilla.34:C:\Documents and Settings\Ben\Application Data\Mozilla\Firefox\Profiles\ttyfjwsn.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.23:C:\Documents and Settings\Ben\Application Data\Mozilla\Firefox\Profiles\ttyfjwsn.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.45:C:\Documents and Settings\Ben\Application Data\Mozilla\Firefox\Profiles\ttyfjwsn.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.46:C:\Documents and Settings\Ben\Application Data\Mozilla\Firefox\Profiles\ttyfjwsn.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.22:C:\Documents and Settings\Ben\Application Data\Mozilla\Firefox\Profiles\ttyfjwsn.default\cookies.txt -> TrackingCookie.Revenue : Cleaned. :mozilla.11:C:\Documents and Settings\Ben\Application Data\Mozilla\Firefox\Profiles\ttyfjwsn.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.12:C:\Documents and Settings\Ben\Application Data\Mozilla\Firefox\Profiles\ttyfjwsn.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. C:\WINDOWS\system32\1024 -> Trojan.Small : Cleaned with backup (quarantined). ::Report end Incident Status Location Adware:adware/securityerror Not disinfected c:\windows\system32\ot.ico Virus:trj/abwiz.a Disinfected Operating system Adware:adware/ncase Not disinfected c:\windows\msbb_gdf.dat Adware:adware/cws.searchmeup Not disinfected c:\windows\toolbar.exe Adware:adware/webattaker Not disinfected c:\windows\uniq Dialer:dialer.dgi Not disinfected hkey_local_machine\software\Mpb Adware:adware/maxifiles Not disinfected Windows Registry Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\User\Cookies\user@ads.pointroll[1].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\User\Cookies\user@atdmt[2].txt Potentially unwanted tool:Application/MotherboardMonitor.A Not disinfected C:\Documents and Settings\User\My Documents\myriad karaoke 4u.zip[Myriad/myriad.dll] Adware:Adware/nCase Not disinfected C:\RECYCLER\S-1-5-21-343818398-287218729-839522115-1004\Dc5\EZ-Emoticons.exe[saap.exe] Adware:Adware/nCase Not disinfected C:\RECYCLER\S-1-5-21-343818398-287218729-839522115-1004\Dc5\Funny-MSN-Display-Pictures\Extract.exe[msbb.exe] Adware:Adware/nCase Not disinfected C:\RECYCLER\S-1-5-21-343818398-287218729-839522115-1004\Dc5\Love-MSN-Pack\Extract.exe[msbb.exe] Adware:Adware/nCase Not disinfected C:\RECYCLER\S-1-5-21-343818398-287218729-839522115-1004\Dc5\MSN.Zangy.Emoticon.Font\Install.exe[msbb.exe] Adware:Adware/nCase Not disinfected C:\RECYCLER\S-1-5-21-343818398-287218729-839522115-1004\Dc5\MSN6.DP.Pack.Simpsons\Extract.exe[msbb.exe] Hacktool:Generic Application Not disinfected C:\RECYCLER\S-1-5-21-343818398-287218729-839522115-1004\Dc5\MSN6.EmoPackV10\EmoPackV1\Extract.exe Adware:Adware/nCase Not disinfected C:\RECYCLER\S-1-5-21-343818398-287218729-839522115-1004\Dc5\MSN6.EmoPackV10\Extract.exe[msbb.exe] Adware:Adware/nCase Not disinfected C:\RECYCLER\S-1-5-21-343818398-287218729-839522115-1004\Dc5\MSN6.EmoPackV14\Extract.exe[msbb.exe] Logfile of HijackThis v1.99.1 Scan saved at 13:13:22, on 14/02/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe C:\Program Files\Lexmark 2400 Series\lxcrmon.exe C:\Program Files\Lexmark 2400 Series\ezprint.exe C:\Program Files\Multimedia keyboard utility\1.3\KbdAp32A.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\TomTom HOME\TomTomHOME.exe C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Eset\nod32krn.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\pctspk.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wbem\wmiapsrv.exe C:\WINDOWS\System32\dmadmin.exe C:\PROGRA~1\INCRED~1\bin\IMApp.exe C:\WINDOWS\system32\lxcrcoms.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe C:\Documents and Settings\User\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by blueyonder R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing) O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll (file missing) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing) O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Multimedia keyboard utility\1.3\MMKEYBD.EXE O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe" O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .xml: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\ O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe Last edited by Technologikal : 02-14-2007 at 06:13 AM. |
|
|
|
|
|
#4 (permalink) |
|
Moderator/ Rangemaster TSF Academy; Analyst, Security Team; Oor Wullie; TSF Surgeon and Resident Comic
|
Hi again
Looking better. Delete the following Files indicated in RED if they still exist. c:\windows\system32\ot.ico c:\windows\msbb_gdf.dat c:\windows\toolbar.exe c:\windows\uniq C:\DOCUMENTS AND SETTINGS\User\Application Data\addon.dat Note: If they resist, you may have to boot to Safe Mode to delete them. Combofix - Second Run Please run combofix again, just as you did previously. Online Scan Establish an internet connection & perform an online scan with Internet Explorer at Kaspersky WebScanner Next Click on Kaspersky Online Scanner ![]() A Welcome screen will appear - click 'Accept' at the bottom. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
Now under select a target to scan: Select My Computer
* Turn off the real time scanner of any existing antivirus program while performing the online scan Please post back with c:\combofix.txt, the Kaspersky Log and a fresh HijackThis Log. Please also let me know how your system is performing now and if you have any specific problems. In order to provide you with the best possible help, please ensure that HijackThis logs are produced only while in Normal Mode.
__________________
Iain - Defender of the Haggis and all things Scottish. I don't help by PM - post in the Forums. ![]() ![]() Ad-Aware::SpywareBlaster::SpyBot::SpywareGuard::SnoopFree::AVG Free::HOSTS File::HijackThis::Donate::5 Steps For Infected PCs |
|
|
|
|
|
#5 (permalink) |
|
Registered User
Join Date: Feb 2007
Posts: 4
OS: XP
|
Re: Hwlo. Help with my HJT log needed.
Sorry to come back to this so late. I've been chasing the guy who's PC this is with the result that he says he's tried the details up to using Kaspersky which scans his computer and then crashes before outputting a log. This is with the online and downloadable versions. I don't know what's going on with his system but unless he gets back to me I think you should consider this thread closed. I'll repost if he finds he's still having considerable problems. Thanks for your attention.
|
|
|
|
|
|
#6 (permalink) |
|
Moderator/ Rangemaster TSF Academy; Analyst, Security Team; Oor Wullie; TSF Surgeon and Resident Comic
|
Re: Hwlo. Help with my HJT log needed.
Thanks for the update.
You could skip Kaspersky and I can suggest other scanners if required. I'll keep an eye out for any further posts.
__________________
Iain - Defender of the Haggis and all things Scottish. I don't help by PM - post in the Forums. ![]() ![]() Ad-Aware::SpywareBlaster::SpyBot::SpywareGuard::SnoopFree::AVG Free::HOSTS File::HijackThis::Donate::5 Steps For Infected PCs |
|
|
|
![]() |
| Thread Tools | |
|
|