![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 10
OS: Win2kPro
|
Win2kPro restarts automaticly after log in
I can log in to the computer I'm using currently (I'm an administrator and the OS is Win2kPro) on any of the 3 admin accounts on the computer and once I do the computer hangs and reboots in about a minute or so (the wallpaper comes up and the cursor is the full "busy" hourglass, then presto, restarted on it's own.) I've been able to get desktop icons to apear by ctrl-alt-del>log off and then logging back in, but the computer still restarts and does so about 5 seconds max after logging back in.
I'm able to get into the system through safe mode although after a while the computer restarts again. No specific ammount of time with safe mode though. I hope you all can help me out with this... here's my Hijack This log from safemode. I'll keep trying to get a regular login one in the meantime. Logfile of HijackThis v1.99.1 Scan saved at 3:37:16 AM, on 6/8/2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\savedump.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINNT\explorer.exe C:\Documents and Settings\gomer\Desktop\HijackThis.exe F2 - REG:system.ini: Shell=explorer.exe C:\WINNT\svchost.exe F3 - REG:win.ini: load=C:\WINNT\svchost.exe F3 - REG:win.ini: run=C:\WINNT\svchost.exe O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [CTSysVol] D:\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [CTDVDDET] D:\DVDAudio\CTDVDDet.EXE O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [IW Controlcenter] d:\INSTAN~1\IWCTRL.EXE O4 - HKLM\..\Run: [RemoteControl] C:\WINNT\system32\rmctrl.exe O4 - HKLM\..\Run: [wnddrv] C:\WINNT\svchost.exe O4 - HKLM\..\Run: [nvchost] C:\WINNT\winlogon.exe O4 - HKLM\..\Run: [jssvc23] jsssvc.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Manager 006] C:\WINNT\svchost.exe O4 - HKLM\..\Run: [icsc] C:\WINNT\system32\icsc.exe O4 - HKLM\..\Run: [icsc] C:\WINNT\system32\icsc.exe O4 - HKLM\..\Run: [skcs] C:\WINNT\system32\skcs.exe O4 - HKLM\..\Run: [desman] C:\WINNT\system32\desman.exe O4 - HKLM\..\Run: [comms] C:\WINNT\system32\comms.exe O4 - HKLM\..\Run: [mgrds] C:\WINNT\system32\mgrds.exe O4 - HKLM\..\Run: [monmc] C:\WINNT\system32\monmc.exe O4 - HKLM\..\Run: [wiznt] C:\WINNT\system32\wiznt.exe O4 - HKLM\..\Run: [foks] C:\WINNT\system32\foks.exe O4 - HKLM\..\Run: [fowi] C:\WINNT\system32\fowi.exe O4 - HKLM\..\Run: [idapi] C:\WINNT\system32\idapi.exe O4 - HKLM\..\Run: [dsut] C:\WINNT\system32\dsut.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [icmsg] C:\WINNT\system32\icmsg.exe O4 - HKLM\..\Run: [32hlp] C:\WINNT\system32\32hlp.exe O4 - HKLM\..\Run: [wmid] C:\WINNT\system32\wmid.exe O4 - HKLM\..\RunServices: [0mcamcap] C:\WINNT\system32\0mcamcap.exe O4 - HKLM\..\RunServices: [jssvc23] jsssvc.exe O4 - HKCU\..\Run: [0mcamcap] C:\WINNT\system32\0mcamcap.exe O4 - HKCU\..\Run: [Manager 006] C:\WINNT\svchost.exe O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/game...ts/y/ct2_x.cab O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/game...s/y/pote_x.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...38&clcid=0x409 O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/04c5c40f...p/RdxIE601.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemp...ogin-devel.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {9BFC2253-B9D9-477E-9488-CA450232620D} (BinAg1 Class) - https://fastconnectkitsetup.cox.net/...lowActiveX.CAB O16 - DPF: {B9A296D4-38AC-4566-8168-F7ACAF7D35E6} (Eyeball Video Session Control) - http://imlive.com/ChatSource/gVideoContol.cab O20 - AppInit_DLLs: srrs44855981.dll nwwk44855981.dll O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All Users\Documents\Settings\artm_new.dll O20 - Winlogon Notify: cfgmngr32 - C:\WINNT\system32\cfgmngr32.dll O20 - Winlogon Notify: directpt - directpt.dll (file missing) O20 - Winlogon Notify: hnup - C:\WINNT\system32\hnup.dll O20 - Winlogon Notify: polymorphreg - C:\Documents and Settings\All Users\Documents\Settings\polymorph.dll O20 - Winlogon Notify: SensSrv - C:\WINNT\ O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe -=edit=- Sorry if this seems rushed but I'm in safe mode and I'm not sure how much time I've got before the next restart. *^_^* Last edited by gomer1075; 06-08-2006 at 04:59 AM. |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#3 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 10
OS: Win2kPro
|
I was just informed by my roommate that the last time anyone was able to log on normally there was a system tray icon (A red circle with a white X) that when moused over it said the computer is infected. I have yet to see it but I figure the more info I can give the better the chances of getting this cleared up.
|
|
|
|
|
#4 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 10
OS: Win2kPro
|
Something else I just found... I'm unable to end processes via task manager.
I'm getting... ============================ = Unable to Terminate Process==X== ============================ ============================ ===X=The operation could not be=== =====completed =============== ============================ =====Access is denied.========== ============================ =============[OK] =========== ============================ when trying to end process. I'm trying to end process on IEXPLORE.EXE because I've two of them in the taskmanager when I don't even have an Internet explorer window open. |
|
|
|
|
#6 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 10
OS: Win2kPro
|
Ok... I've gone and weeded down my HJT log some on my own... god bless google... and this is my current log.
Logfile of HijackThis v1.99.1 Scan saved at 3:52:45 AM, on 6/10/2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\savedump.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\userinit.exe C:\WINNT\explorer.exe C:\Documents and Settings\gomer\Desktop\HijackThis.exe F2 - REG:system.ini: Shell=explorer.exe C:\WINNT\svchost.exe F3 - REG:win.ini: load=C:\WINNT\svchost.exe F3 - REG:win.ini: run=C:\WINNT\svchost.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [CTSysVol] D:\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...38&clcid=0x409 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe The F2 and two F3 entries keep returning and the restarting problem persists. Also now and then I'll get a few new 04's that are all labeled [Manager 006] or something along those lines, but I'll keep trying and post another log if I see them again. At this point I'm in safe mode with networking still and am using HJT, Ad-Aware SE personal, Avira AntiVir PE classic, and the most updated Spybot Search and Destroy. At this point I'm quite stumped... I've tried what I can and have weeded down to what I think is either mandatory or harmless, or just won't go away. |
|
|
|
|
#7 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 10
OS: Win2kPro
|
Ok. I'm back again and I've got a hijackthis log from this mornings boot up into safe mode.
Logfile of HijackThis v1.99.1 Scan saved at 9:00:44 AM, on 6/10/2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\Explorer.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\gomer\Desktop\HijackThis.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [CTSysVol] D:\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [Manager 006] C:\WINNT\svchost.exe O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\RunServices: [Manager 006] C:\WINNT\svchost.exe O4 - HKLM\..\RunOnce: [Manager 006] C:\WINNT\svchost.exe O4 - HKLM\..\RunServicesOnce: [Manager 006] C:\WINNT\svchost.exe O4 - HKCU\..\Run: [Manager 006] C:\WINNT\svchost.exe O4 - HKCU\..\RunOnce: [Manager 006] C:\WINNT\svchost.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...38&clcid=0x409 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe As you can see the items in dark green are the ones that popped up since the last logfile. Also, the F2 and F3 entires, F2 - REG:system.ini: Shell=explorer.exe C:\WINNT\svchost.exe F3 - REG:win.ini: load=C:\WINNT\svchost.exe F3 - REG:win.ini: run=C:\WINNT\svchost.exe aren't here on this boot up and probably will be on the next one. Thanks in advance. |
|
|
|
|
#8 (permalink) |
|
Analyst, Security Team
|
No constant bumping....
Get Ewido either in Safe Mode with Networking or from another computer and burn it to a CD. Print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below. Download smitRem at http://noahdfear.geekstogo.com/click...click.php?id=1 and save the file to your desktop. NOTE: If you have Windows 9x/ME, you don't need to use Ewido (skip this step). Download Ewido Security Suite at http://www.ewido.net/en/download/ 1. Install Ewido Security Suite. 2. When installing, under 'Additional Options' uncheck: * Install background guard * Install scan via context menu 3. Launch Ewido, there should be an icon on your desktop, double click it. 4. The program will now open to the main screen. 5. When you run Ewido for the first time, you might get a warning 'Database could not be found!'. Click OK. We will fix this in a moment. 6. You will need to update Ewido to the latest definition files. * On the left hand side of the main screen click update. * Then click on start update. 7. The update will start and a progress bar will show the updates being installed. The status bar at the bottom will display 'Update successful'. 8. Exit Ewido. DO NOT scan yet. If you are having problems with the updater, you can go to http://www.ewido.net/en/download/updates/ to update manually. If you have not already installed Ad-Aware SE 1.06, follow the download and setup instructions at http://rstones12.geekstogo.com/adawareSE_setup.htm. Otherwise, check for updates. Don't run it yet! Download CleanUp! http://cleanup.stevengould.org/ (Alternate Link if main link don't work - http://www.greyknight17.com/spy/CleanUp.exe ) and install it. Don't run it yet. Restart your computer and boot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn't work. CleanUp! deletes EVERYTHING out of your temp/temporary folders. It does not make backups. If you have any documents or programs that are saved in any Temporary Folders, make a backup of these before running CleanUp!. Run CleanUp! and click on the CleanUp! button. Let it run. After it's done, click the Close button and choose Yes to logoff. Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any): O4 - HKLM\..\Run: [Manager 006] C:\WINNT\svchost.exe O4 - HKLM\..\RunServices: [Manager 006] C:\WINNT\svchost.exe O4 - HKLM\..\RunOnce: [Manager 006] C:\WINNT\svchost.exe O4 - HKLM\..\RunServicesOnce: [Manager 006] C:\WINNT\svchost.exe O4 - HKCU\..\Run: [Manager 006] C:\WINNT\svchost.exe O4 - HKCU\..\RunOnce: [Manager 006] C:\WINNT\svchost.exe Delete this: C:\WINNT\svchost.exe - only delete it in this folder Run the smitRem.exe tool you downloaded earlier. There should be a folder called smitrem created on your desktop. Open it and double click on the RunThis file. Follow the prompts on the screen. Wait for the tool to complete and disk cleanup to finish. The tool will create a log named smitfiles.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Post that log along with all others requested in your next reply. Open Ad-aware and do a full scan. Remove all it finds. Run Ewido now: * Click on scanner and then Settings. Under 'What to scan' select 'Scan every file' and hit OK. * Click on 'Complete System Scan' and the scan will begin. * While the scan is in progress you will be prompted to clean the first infected file it finds. Choose 'Remove', then put a check next to 'Perform action with all infections' in the left corner of the box so you don't have to sit and watch Ewido the whole time. Click OK. * Once the scan has completed, there will be a button located on the bottom of the screen named 'Save report'. * Click 'Save report'. Save it to your desktop. Right click on your desktop and go to Properties. Then go to the Desktop tab and click on Customize Desktop. Go to the Web tab and delete everything there except My Current Home Page (which should be unchecked). Click OK. Restart your computer to get back to Normal Mode. Perform an online scan with Internet Explorer at Panda ActiveScan http://www.pandasoftware.com/products/activescan.htm * Click on 'Scan your PC' button. There should be a popup - if you have a pop-up blocker, make sure it's not blocking it. * Click 'Check Now' & a pop-up window will appear. * Enter your Country, State and E-mail Address & click 'Scan Now' - begin downloading Panda's ActiveX controls (8 MB size). * Begin the scan by selecting My Computer. * If it finds any malware, it will offer you a report. Ignore any entry it finds (since it wants you to buy the program for removal) as we will address this later. * Click on see report. Then click Save report. * Post that log in your next reply. Then post the Panda log here along with the logs for smitfiles.txt, Ewido and a new HijackThis log.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it. |
|
|
|
|
#9 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 10
OS: Win2kPro
|
Thank you very much for your help. Here's the logs that you requested after perfoming the steps.
Panda log Incident Status Location Adware:adware/adsmart Not disinfected c:\winnt\system32\dlh9jkdq8.exe Potentially unwanted tool:application/bestoffer Not disinfected c:\winnt\smdat32m.sys Adware:adware/keenvalue Not disinfected c:\winnt\browserxtras\pn\remove.exe Adware:adware/cydoor Not disinfected c:\winnt\cdmxtras Spyware:spyware/apropos Not disinfected Windows Registry Potentially unwanted tool:application/altnet Not disinfected hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\AltnetDM Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt[.apmebf.com/] smitfiles.txt smitRem © log file version 3.0 by noahdfear Microsoft Windows 2000 [Version 5.00.2195] "IE"="6.0000" The current date is: Sun 06/11/2006 The current time is: 4:53:04.32 Running from C:\Documents and Settings\gomer\Desktop\smitRem ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Pre-run SharedTask Export (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler) Copyright(C) 2006 BleepingComputer.com Registry Pseudo-Format Mode (Not a valid reg file): [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" "{B29BE267-3A64-4F7E-8A57-75FB5E900503}"="Windows Updater" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B29BE267-3A64-4F7E-8A57-75FB5E900503}\InProcServer32] @="C:\WINNT\system32\cfgmngr32.dll" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ checking for ShudderLTD key ShudderLTD key not present! checking for PSGuard.com key PSGuard.com key not present! checking for WinHound.com key WinHound.com key not present! checking for drsmartload2 key drsmartload2 key not present! spyaxe uninstaller NOT present Winhound uninstaller NOT present SpywareStrike uninstaller NOT present AlfaCleaner uninstaller NOT present SpyFalcon uninstaller NOT present SpywareQuake uninstaller NOT present SpywareSheriff uninstaller NOT present ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Existing Pre-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org Killing PID 684 'explorer.exe' Starting registry repairs Registry repairs complete ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ SharedTask Export after registry fix (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler) Copyright(C) 2006 BleepingComputer.com Registry Pseudo-Format Mode (Not a valid reg file): [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" "{B29BE267-3A64-4F7E-8A57-75FB5E900503}"="Windows Updater" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B29BE267-3A64-4F7E-8A57-75FB5E900503}\InProcServer32] @="C:\WINNT\system32\cfgmngr32.dll" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Deleting files ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Remaining Post-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~ Wininet.dll ~~~ CLEAN! :) Ewido --------------------------------------------------------- ewido anti-malware - Scan report --------------------------------------------------------- + Created on: 5:10:11 AM, 6/11/2006 + Report-Checksum: 4A72C5A2 + Scan result: HKLM\SOFTWARE\Classes\CLSID\{00000000-15D9-4736-AB29-131578A45F2B} -> Adware.Wordsonweb : Cleaned with backup :mozilla.6:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.8:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.9:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.10:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.11:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.12:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup :mozilla.13:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.14:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.15:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.16:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.17:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.18:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.19:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.20:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.21:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.22:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.23:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.24:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.25:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.28:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.29:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.30:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.31:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup :mozilla.32:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup :mozilla.33:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.34:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.35:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.36:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.37:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.38:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.47:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup :mozilla.48:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.49:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.50:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.54:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.55:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.56:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.61:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.62:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.63:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.71:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.75:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.82:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup :mozilla.83:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup :mozilla.84:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup :mozilla.85:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup :mozilla.86:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup :mozilla.94:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.95:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.96:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.97:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.98:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.99:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.100:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.102:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup :mozilla.116:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.118:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.119:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.120:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.121:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.122:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup :mozilla.153:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.162:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup :mozilla.163:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup :mozilla.165:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup :mozilla.166:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Comclick : Cleaned with backup :mozilla.167:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Comclick : Cleaned with backup :mozilla.168:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ocajjum8.default\cookies.txt -> TrackingCookie.Comclick : Cleaned with backup C:\Documents and Settings\Administrator\Start Menu\Programs\Power Scan -> Adware.PowerScan : Cleaned with backup C:\Documents and Settings\Administrator\Start Menu\Programs\Power Scan\Power Scan.lnk -> Adware.PowerScan : Cleaned with backup C:\Program Files\Aprps -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\ace.dll -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\AI_01-06-2006.log -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\AI_02-06-2006.log -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\AI_03-06-2006.log -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\AI_04-06-2006.log -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\AI_05-06-2006.log -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\AI_06-06-2006.log -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\AI_07-06-2006.log -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\atl.dll -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\CxtPls.dll -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\CxtPls.exe -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\libexpat.dll -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\plg0 -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\plg0\cxtpls.dll -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\ProxyStub.dll -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\pstub0 -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\pstub0\proxystub.dll -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\uninstaller.exe -> Adware.Apropos : Cleaned with backup C:\Program Files\Aprps\WinGenerics.dll -> Adware.Apropos : Cleaned with backup C:\WINNT\file1.exe -> Backdoor.Small : Cleaned with backup C:\WINNT\OEM.exe -> Proxy.Agent.jw : Cleaned with backup C:\WINNT\OEM.exe.bak -> Proxy.Agent.jw : Cleaned with backup C:\WINNT\system32\directprt.sys -> Backdoor.Haxdoor.io : Cleaned with backup C:\WINNT\system32\dlh9jkdq2.exe -> Trojan.Small : Cleaned with backup C:\WINNT\system32\dlh9jkdq6.exe -> Trojan.Small : Cleaned with backup C:\WINNT\system32\dlh9jkdq7.exe -> Trojan.Small : Cleaned with backup C:\WINNT\system32\HLInstaller1.exe -> Adware.MDH : Cleaned with backup C:\WINNT\system32\HyperLinker1.exe -> Adware.MDH : Cleaned with backup C:\WINNT\system32\ib14.dll -> Logger.Bancos : Cleaned with backup C:\WINNT\system32\ipod.raw.exe -> Proxy.Lager.bi : Cleaned with backup C:\WINNT\system32\jsssvc.exe -> Backdoor.Rbot.aeu : Cleaned with backup C:\WINNT\system32\mpcsvc.exe -> Proxy.Small.du : Cleaned with backup C:\WINNT\system32\vxgame6.exe3072.exe -> Downloader.Tiny.cp : Cleaned with backup D:\TopSearch.dll -> Adware.Altnet : Cleaned with backup ::Report End New HijackThis log Logfile of HijackThis v1.99.1 Scan saved at 5:19:49 AM, on 6/11/2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\explorer.exe C:\Documents and Settings\gomer\Desktop\HijackThis.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [CTSysVol] D:\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...38&clcid=0x409 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe There you go, and thank you so very much for your help. -=small edit=- Ok. After doing all of that in Safemode with networking and posting all the logs I tried to log in normally. No restart!! Here's a Hijack this log from a normal login (not safemode) Logfile of HijackThis v1.99.1 Scan saved at 5:33:23 AM, on 6/11/2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\WINNT\System32\CTsvcCDA.exe C:\WINNT\System32\svchost.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\WINNT\System32\nvsvc32.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\tcpsvcs.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\WINNT\Explorer.EXE D:\Surround Mixer\CTSysVol.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\WINNT\system32\wuauclt.exe C:\Documents and Settings\gomer\Desktop\HijackThis.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [CTSysVol] D:\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...38&clcid=0x409 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe Last edited by gomer1075; 06-11-2006 at 06:38 AM. |
|
|
|
|
#10 (permalink) |
|
Analyst, Security Team
|
Getting better right?
![]() 1. Download The Avenger (http://swandog46.geekstogo.com/avenger.zip) to your Desktop and unzip/extract it. 2. Copy all the below text in bold contained in the codebox below to a blank notepad file: Code:
Registry keys to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B29BE267-3A64-4F7E-8A57-75FB5E900503}
hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\AltnetDM
registry values to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler | {B29BE267-3A64-4F7E-8A57-75FB5E900503}
Files to delete:
c:\winnt\system32\dlh9jkdq8.exe
c:\winnt\smdat32m.sys
Folders to delete:
c:\winnt\browserxtras
c:\winnt\cdmxtras
3. Start The Avenger program from your desktop. - Under 'Script file to execute', choose 'Input Script Manually'. - Click on the Magnifying Glass icon which will open a new window titled 'View/edit script'. - Paste the text you copied to the notepad earlier into this window. - Click Done. - Now click on the Green Light to begin execution of the script. - Answer 'Yes' twice when prompted. 4. The Avenger will automatically do the following: - Restart your computer. In cases where the code to execute contains 'Drivers to Unload', The Avenger will actually restart your system twice. - On reboot, it briefly opens a black command window on your desktop. This is normal. - After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt - The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip. 5. Copy and paste all the contents of avenger.txt into your reply along with a new HijackThis log.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it. Last edited by greyknight17; 06-11-2006 at 12:53 PM. |
|
|
|
|
#11 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 10
OS: Win2kPro
|
Much better indeed! My roommate is quite impresed with the loading time of the computer now. I really appreciate your help. Here's my logs.
Logfile of The Avenger version 1, by Swandog46 Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\ftxvdpdm ******************* Script file located at: \??\C:\WINNT\system32\mlkdwopx.txt Script file opened successfully. Script file read successfully Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: File c:\winnt\system32\dlh9jkdq8.exe deleted successfully. File c:\winnt\smdat32m.sys deleted successfully. Folder c:\winnt\browserxtras deleted successfully. Folder c:\winnt\cdmxtras deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B29BE267-3A64-4F7E-8A57-75FB5E900503} deleted successfully. Registry key hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\AltnetDM deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler|{B29BE267-3A64-4F7E-8A57-75FB5E900503} deleted successfully. Completed script processing. ******************* Finished! Terminate. HJT Logfile of HijackThis v1.99.1 Scan saved at 11:49:50 AM, on 6/12/2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\WINNT\System32\CTsvcCDA.exe C:\WINNT\System32\svchost.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\WINNT\System32\nvsvc32.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\tcpsvcs.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\Explorer.EXE D:\Surround Mixer\CTSysVol.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\WINNT\system32\wuauclt.exe C:\Documents and Settings\gomer\Desktop\security\HijackThis.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [CTSysVol] D:\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...38&clcid=0x409 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe |
|
|
|
|
#12 (permalink) |
|
Analyst, Security Team
|
Good job. Your log is clean.
To help prevent future spyware infections, read the Anti-Spyware Tutorial and use the tools provided. Are there any problems now? If not, you should be set to go. Post back once more to confirm everything is ok.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it. |
|
|
| Thread Tools | |
|
|