![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 12
OS: WinXP
|
Help, i think something's wrong (log)
Lately my computer has been acting funny, and my AntiVir (personal edition) has been detecting a few files that i have been deleting. another thing is that whenever i've started up my computer in the past couple days, my C:\WINDOWS\system32 folder opens up by itself.
Here's my HJT log, can anyone help me? Logfile of HijackThis v1.99.1 Scan saved at 1:56:01 PM, on 6/11/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\MSI\Live Update 3\LMonitor.exe C:\WINDOWS\tppaldr.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Xfire\Xfire.exe C:\PROGRA~1\MOZILL~1\firefox.exe C:\WINDOWS\system32\svchost.exe C:\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.qsrch.com/ O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Quick! - {4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} - C:\PROGRA~1\quickbar\quickbar.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Nothing - {686a161d-5bd1-4999-8832-6393f41e564c} - C:\WINDOWS\system32\hp100.tmp O3 - Toolbar: Quick! - {4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} - C:\PROGRA~1\quickbar\quickbar.dll O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing) O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider 'xfire_lsp_10650.dll' missing O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1038091948750 O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{ECEA5359-1D12-49BE-AF94-237BD0376134}: NameServer = 68.87.76.178,68.87.66.196 O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,255
OS: 2000 Pro; XP Pro; XP Home
|
Hello and Welcome. Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.
Before begining the fix, read this post completely. If there's anything that you do not understand, kindly ask your questions before proceeding. Ensure that there aren't any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this webpage would not be available when you're carrying out the fix. It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence. --------------------------------------------------------------------------------------------- Download these programs. Do not run them except as directed. smitRem.exe and save the file to your desktop. Double click on the file to extract it to it's own folder on the desktop. *Note* Alternate download sites for smitrem... http://www.downloads.subratam.org/smitRem.exe http://www.bleepingcomputer.com/file...ar/smitRem.exe DelDomains.inf Right-click and select Save Target As - save it to your desktop. To use: Right-click and select....... Install (no need to restart) **Note** This will remove all entries in the "Trusted Zone" --------------------------------------------------------------------------------------------- Download and install CleanUp! NOTE: CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, make a backup of these before running CleanUp!. Do NOT run this program if you have XP Professional 64 bit edition. If you're unsure please do not run it! If you don't already know, you're probably not using XP64, but you can download & run this tool to find out for sure.....http://www.kellys-korner-xp.com/regs...p_whichcpu.exe Download Ewido Anti-Malware
If you are having problems with the updater, you can use this link to manually update Ewido When you have finished updating, EXIT Ewido. --------------------------------------------------------------------------------------------- Restart your computer and boot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn't work. Login on your usual account. Make sure to close any open browsers. --------------------------------------------------------------------------------------------- Uninstall the following via the Add/Remove Panel (Start->(Settings)->Control Panel->Add/Remove Programs) if they exist: QuickBar NewDotNet --------------------------------------------------------------------------------------------- Open HijackThis and click on 'Do a System Scan Only'. Check the following entries if they exist (make sure you do not miss any) and click Fix Checked O2 - BHO: Quick! - {4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} - C:\PROGRA~1\quickbar\quickbar.dll O3 - Toolbar: Quick! - {4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} - C:\PROGRA~1\quickbar\quickbar.dll --------------------------------------------------------------------------------------------- Go to My Computer->Tools->Folder Options->View tab: * Under the Hidden files and folders heading, select Show hidden files and folders. * Uncheck the Hide protected operating system files (recommended) option. * Also make sure there is no checkmark beside Hide file extensions for known file types * Click Yes to confirm and then click OK. Delete the following if they exist: C:\Program Files\quickbar C:\Program Files\NewDotNet --------------------------------------------------------------------------------------------- Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish. The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply. --------------------------------------------------------------------------------------------- Run Cleanup! using the following configuration: Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows: Click "Options..." Move the arrow down to "Custom CleanUp!" Put a check next to the following (Make sure nothing else is checked!):
Press the CleanUp! button to start the program.. Do NOT Reboot/logoff when prompted. * CleanUp! will not create any backups!! --------------------------------------------------------------------------------------------- Run Ewido with it's updated definitions:(...it's important that all windows must be closed)
** Ewido scan would require at least an hour. --------------------------------------------------------------------------------------------- Next go to Control Panel click Display>Desktop>Customize Desktop>Web> Now, Uncheck Everything and delete if present:
--------------------------------------------------------------------------------------------- Restart in Normal Mode --------------------------------------------------------------------------------------------- Perform an online scan with Internet Explorer with Panda ActiveScan ** click on "Free use ActiveScan" located on the top right hand corner
*You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report. *Turn off the real time scanner of any existing antivirus program while performing the online scan --------------------------------------------------------------------------------------------- Open Hijack This and click on 'Do a System Scan and save a Logfile'. Save the log file and post it here. --------------------------------------------------------------------------------------------- In your next post, please provide results from: Smitfiles.txt Ewido's log Online scan HiJackThis log
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 12
OS: WinXP
|
Thanks for replying. here are all the logs that you asked for, in order. (i shortened some of the gaps in the logs for space)
Smit log smitRem © log file version 3.0 by noahdfear Microsoft Windows XP [Version 5.1.2600] "IE"="6.0000" The current date is: Mon 06/12/2006 The current time is: 9:03:04.42 Running from C:\Documents and Settings\Logan\Desktop\smitRem ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Pre-run SharedTask Export (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler) Copyright(C) 2006 BleepingComputer.com Registry Pseudo-Format Mode (Not a valid reg file): [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" "{5aaf6542-f4ba-4df4-873d-4902ecbe794c}"="acheweed" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{5aaf6542-f4ba-4df4-873d-4902ecbe794c}\InProcServer32] @="C:\WINDOWS\system32\acvgxw.dll" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ checking for ShudderLTD key ShudderLTD key not present! checking for PSGuard.com key PSGuard.com key not present! checking for WinHound.com key WinHound.com key not present! checking for drsmartload2 key drsmartload2 key not present! spyaxe uninstaller NOT present Winhound uninstaller NOT present SpywareStrike uninstaller NOT present AlfaCleaner uninstaller NOT present SpyFalcon uninstaller NOT present SpywareQuake uninstaller NOT present SpywareSheriff uninstaller NOT present ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Existing Pre-run Files ~~~ Program Files ~~~ Security Toolbar ~~~ Shortcuts ~~~ Online Security Guide.url Security Troubleshooting.url ~~~ Favorites ~~~ Antivirus Test Online.url ~~~ system32 folder ~~~ simpole.tlb atmclk.exe dcomcfg.exe amcompat.tlb nscompat.tlb 1024 dir hp***.tmp ~~~ Icons in System32 ~~~ ot.ico ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org Killing PID 760 'explorer.exe' Killing PID 760 'explorer.exe' Starting registry repairs Registry repairs complete ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ SharedTask Export after registry fix (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler) Copyright(C) 2006 BleepingComputer.com Registry Pseudo-Format Mode (Not a valid reg file): [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Deleting files ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Remaining Post-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~ Wininet.dll ~~~ CLEAN! :) Ewido's --------------------------------------------------------- ewido anti-malware - Scan report --------------------------------------------------------- + Created on: 9:49:27 AM, 6/12/2006 + Report-Checksum: 2F3CD198 + Scan result: HKU\S-1-5-21-790525478-2111687655-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} -> Adware.NewDotNet : Cleaned with backup :mozilla.7:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup :mozilla.8:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup :mozilla.9:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup :mozilla.11:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup :mozilla.12:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup :mozilla.15:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup :mozilla.26:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup :mozilla.27:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup :mozilla.32:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.37:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup :mozilla.64:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.65:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.66:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.67:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.68:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.70:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.79:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.80:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.83:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.90:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.94:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.95:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.96:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.98:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.108:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.116:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.120:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup :mozilla.122:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.128:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.129:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.130:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.134:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup :mozilla.135:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.136:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup :mozilla.137:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.138:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.139:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.140:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.141:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.150:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.151:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.169:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.173:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.179:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\kevw7puj.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.16:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup :mozilla.17:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup :mozilla.19:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup :mozilla.20:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.21:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.22:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.23:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.24:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.25:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.32:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.33:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.34:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.35:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.36:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup :mozilla.37:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.38:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.45:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.47:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.48:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.49:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.50:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.51:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.52:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup :mozilla.53:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup :mozilla.54:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.55:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.56:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.57:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.58:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.59:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.61:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.62:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.63:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.65:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.73:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.74:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.75:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.76:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.94:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.97:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup :mozilla.98:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.99:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.100:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.101:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.102:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.103:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.104:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.117:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup :mozilla.118:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup :mozilla.120:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.121:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup :mozilla.122:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\45w0584o.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup :mozilla.15:C:\Documents and Settings\Kristi\Application Data\Mozilla\Firefox\Profiles\smsl7xuf.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup :mozilla.24:C:\Documents and Settings\Kristi\Application Data\Mozilla\Firefox\Profiles\smsl7xuf.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup :mozilla.27:C:\Documents and Settings\Kristi\Application Data\Mozilla\Firefox\Profiles\smsl7xuf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.28:C:\Documents and Settings\Kristi\Application Data\Mozilla\Firefox\Profiles\smsl7xuf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.29:C:\Documents and Settings\Kristi\Application Data\Mozilla\Firefox\Profiles\smsl7xuf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.31:C:\Documents and Settings\Kristi\Application Data\Mozilla\Firefox\Profiles\smsl7xuf.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.32:C:\Documents and Settings\Kristi\Application Data\Mozilla\Firefox\Profiles\smsl7xuf.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.33:C:\Documents and Settings\Kristi\Application Data\Mozilla\Firefox\Profiles\smsl7xuf.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup C:\Program Files\hix\scripts\IPLookup\portscan.exe -> Not-A-Virus.NetTool.Win32.Scan.12 : Cleaned with backup C:\Program Files\Media-Codec -> Trojan.Small : Cleaned with backup C:\Program Files\Media-Codec\uninst.exe -> Trojan.Small : Cleaned with backup ::Report End Online Scan Report Incident Status Location Spyware:spyware/new.net Not disinfected c:\windows\NDNuninstall6_76.exe Adware:adware/quickbar Not disinfected Windows Registry Adware:adware/savenow Not disinfected Windows Registry Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Logan\Cookies\logan@doubleclick[1].txt Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Logan\Cookies\logan@questionmarket[1].txt Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Logan\Cookies\logan@zedo[2].txt Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Logan\Desktop\smitRem\Process.exe Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Logan\Desktop\smitRem.exe[smitRem/Process.exe] Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Logan\Local Settings\Application Data\Mozilla\Firefox\Profiles\u8zsc53l.default\Cache\3EFBEAA3d01[smitRem/Process.exe] Virus:mIRC/Gen Disinfected C:\Program Files\hix\aliases.ini Potentially unwanted tool:Application/MotherboardMonitor.A Not disinfected C:\Program Files\hix\moo.dll Potentially unwanted tool:Application/MotherboardMonitor.A Not disinfected C:\Program Files\hix\scripts\systeminfo\moo.dll Hijackthis Logfile of HijackThis v1.99.1 Scan saved at 10:51:26 AM, on 6/12/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\MSI\Live Update 3\LMonitor.exe C:\WINDOWS\tppaldr.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\iPod\bin\iPodService.exe C:\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.qsrch.com/ O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing) O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider 'xfire_lsp_10650.dll' missing O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1038091948750 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{ECEA5359-1D12-49BE-AF94-237BD0376134}: NameServer = 68.87.76.178,68.87.66.196 O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe The online scan report looks a little hard to read, sorry about that, for some reason the formatting got removed. Thanks for helping |
|
|
|
|
#4 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,255
OS: 2000 Pro; XP Pro; XP Home
|
That's ok....I'm used to reading those logs just like that.
Do you use HIX scripting for mIRC? Before begining the fix, read this post completely. If there's anything that you do not understand, kindly ask your questions before proceeding. Ensure that there aren't any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this webpage would not be available when you're carrying out the fix. --------------------------------------------------------------------------------------------- Open HijackThis and click on 'Do a System Scan Only'. Check the following entries if they exist (make sure you do not miss any) and click Fix Checked R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.qsrch.com/ --------------------------------------------------------------------------------------------- Delete the following files: c:\windows\NDNuninstall6_76.exe If it resists deletion, boot to safe mode and delete from there. --------------------------------------------------------------------------------------------- We need to update your Java as it is out of date. The older version is a security risk, as malware writers exploit the weaknesses in it's code. Updating Java:
--------------------------------------------------------------------------------------------- Open Hijack This and click on 'Do a System Scan and save a Logfile'. Save the log file and post it here. --------------------------------------------------------------------------------------------- Establish an internet connection & perform an online scan with Internet Explorer at Kaspersky Online Scanner Answer Yes, when prompted to install an ActiveX component.
--------------------------------------------------------------------------------------------- Please return with results from: Kaspersky HJT How is your system behaving now, please?
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
#5 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 12
OS: WinXP
|
ok, to answer your question, i did use the HIX scripting for mIRC, but i have not used mIRC in a long time, i'd say about a year ago or longer. also, i think my computer is acting more normal (system32 folder no longer opens itself upon startup). here are the logs from the Kaspersky and the new HJT.
Kaspersky ------------------------------------------------------------------------------- KASPERSKY ON-LINE SCANNER REPORT Monday, June 12, 2006 4:48:19 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky On-line Scanner version: 5.0.78.0 Kaspersky Anti-Virus database last update: 13/06/2006 Kaspersky Anti-Virus database records: 200064 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ E:\ Scan Statistics: Total number of scanned objects: 60257 Number of viruses found: 6 Number of infected objects: 14 Number of suspicious objects: 0 Duration of the scan process: 00:40:02 Infected Object Name / Virus Name / Last Action C:\Program Files\BitTorrent\uninstall.exe/stream/data0002 Infected: not-a-virus:RiskTool.Win32.PsKill.n skipped C:\Program Files\BitTorrent\uninstall.exe/stream Infected: not-a-virus:RiskTool.Win32.PsKill.n skipped C:\Program Files\BitTorrent\uninstall.exe NSIS: infected - 2 skipped C:\RECYCLER\S-1-5-21-790525478-2111687655-725345543-1003\Dc1.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped C:\System Volume Information\_restore{DE631B92-5657-4E1D-9CC1-3033F5EBD144}\RP427\A0090087.exe/stream/data0009 Infected: not-a-virus:RiskTool.Win32.PsKill.n skipped C:\System Volume Information\_restore{DE631B92-5657-4E1D-9CC1-3033F5EBD144}\RP427\A0090087.exe/stream Infected: not-a-virus:RiskTool.Win32.PsKill.n skipped C:\System Volume Information\_restore{DE631B92-5657-4E1D-9CC1-3033F5EBD144}\RP427\A0090087.exe NSIS: infected - 2 skipped C:\System Volume Information\_restore{DE631B92-5657-4E1D-9CC1-3033F5EBD144}\RP449\A0092115.tlb Infected: Trojan-Downloader.Win32.Zlob.jh skipped C:\System Volume Information\_restore{DE631B92-5657-4E1D-9CC1-3033F5EBD144}\RP450\A0092123.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped C:\System Volume Information\_restore{DE631B92-5657-4E1D-9CC1-3033F5EBD144}\RP454\A0092362.exe Infected: Trojan-Downloader.Win32.Zlob.rq skipped C:\System Volume Information\_restore{DE631B92-5657-4E1D-9CC1-3033F5EBD144}\RP454\A0092363.exe Infected: Trojan-Downloader.Win32.Zlob.jh skipped C:\System Volume Information\_restore{DE631B92-5657-4E1D-9CC1-3033F5EBD144}\RP454\A0092366.tlb Infected: Trojan-Downloader.Win32.Zlob.jh skipped C:\System Volume Information\_restore{DE631B92-5657-4E1D-9CC1-3033F5EBD144}\RP454\A0092424.exe Infected: not-a-virus:NetTool.Win32.Scan.12 skipped C:\WINDOWS\system32\o Infected: Trojan-Downloader.BAT.Ftp.ay skipped Scan process completed. HTJ Logfile of HijackThis v1.99.1 Scan saved at 2:47:10 PM, on 6/12/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\savedump.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\MSI\Live Update 3\LMonitor.exe C:\WINDOWS\tppaldr.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\WINDOWS\system32\wuauclt.exe C:\hijackthis\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing) O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider 'xfire_lsp_10650.dll' missing O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1038091948750 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{ECEA5359-1D12-49BE-AF94-237BD0376134}: NameServer = 68.87.76.178,68.87.66.196 O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe Thank you. Last edited by leech21; 06-12-2006 at 06:01 PM. |
|
|
|
|
#6 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,255
OS: 2000 Pro; XP Pro; XP Home
|
Since you no longer use HIX, you can delete these potentially unwanted tools:
Potentially unwanted tool:Application/MotherboardMonitor.A Not disinfected C:\Program Files\hix\moo.dll Potentially unwanted tool:Application/MotherboardMonitor.A Not disinfected C:\Program Files\hix\scripts\systeminfo\moo.dll --------------------------------------------------------------------------------------------- Delete the following if they exist: C:\RECYCLER\S-1-5-21-790525478-2111687655-725345543-1003\Dc1.exe C:\WINDOWS\system32\o If they resist deletion, boot to safe mode, and delete them from there --------------------------------------------------------------------------------------------- The other items found by Kaspersky are in System Restore, which we shall take care of shortly. Well done. Your logs are clean. Any more issues? If not you should be good to go. We still have a few items to address. Reset hidden/system files and folders
Create a new System Restore point
Please ensure that you have already patched your system against the recent WMF exploit. Go to this page to get the KB912919 patch. Enable Windows Auto Update
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programs:
If you do not have a firewall, here are 4 free ones available for personal use: In light of your recent troubles, I'm sure you'll like to avoid any future infections. Please take a look at these well written articles If you want to fight back the Malware Writers that have made your life a misery, please take a look here and read what you can do against it. Please respond to this thread one more time so we can mark this thread as resolved.
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
#7 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 12
OS: WinXP
|
ok great, i'll get those programs you listed. thanks again for helping me out with my computer, i'm not sure what i would have done if you guys didn't have this forum.
Last edited by leech21; 06-12-2006 at 08:04 PM. |
|
|
| Thread Tools | |
|
|