![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
I helped the forums.
Join Date: Mar 2005
Location: Long Island, NY
Posts: 21
OS: XP
|
help with HiJackThis please
My daughter is home from college for the year with a mess on her computer.
Would very much appreciate help with the below mess. - thanks, Ken ==================================================================== Log was analyzed using KRC HijackThis Analyzer - Updated on 4/1/05 Get updates at http://www.greyknight17.com/download.htm#programs ***Security Programs Detected*** C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Logfile of HijackThis v1.99.1 Scan saved at 9:29:36 PM, on 5/13/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\Botnet.exe C:\WINDOWS\System32\Tnqxjr.exe C:\WINDOWS\System32\vmss\vmss.exe C:\WINDOWS\System32\winupdt.exe C:\WINDOWS\System32\wintask.exe C:\WINDOWS\System32\wowpbrd.exe C:\WINDOWS\a65d.exe C:\WINDOWS\system\lxqpuodw.exe C:\WINDOWS\System32\msxsma.exe C:\WINDOWS\System32\sysmonnt.exe C:\WINDOWS\System32\msxsma.exe c:\windows\system32\vdxregvu.exe C:\Program Files\Microsoft AntiSpyware\gcasServAlert.exe C:\WINDOWS\System32\ammzzr.exe C:\Program Files\Microsoft AntiSpyware\gcasServAlert.exe C:\Program Files\Microsoft AntiSpyware\gcasServAlert.exe C:\DOCUME~1\ALLUSE~1\APPLIC~1\msw\BMan1.exe C:\WINDOWS\System32\qmgrt4.exe C:\WINDOWS\System32\qwienh.exe C:\Program Files\AutoUpdate\AutoUpdate.exe C:\Program Files\CxtPls\CxtPls.exe C:\WINDOWS\System32\ffgsysi6.exe C:\Security\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file) F2 - REG:system.ini: Shell=Explorer.exe C:\logon.exe O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing) O4 - HKLM\..\Run: [Microsoft Updates] Botnet.exe O4 - HKLM\..\Run: [Shell Logon] C:\logon.exe O4 - HKLM\..\Run: [WebSpecials] rundll32 "C:\Program Files\WebSpecials\webspec.dll",run O4 - HKLM\..\Run: [secure] C:\WINDOWS\System32\Tnqxjr.exe O4 - HKLM\..\Run: [vmss] C:\WINDOWS\System32\vmss\vmss.exe O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe O4 - HKLM\..\Run: [hkadkzoy] c:\windows\system32\hkadkzoy.exe O4 - HKLM\..\Run: [r5a57j7b] C:\Program Files\r5a57j7b\r5a57j7b.exe O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1 O4 - HKLM\..\Run: [popuppers65] C:\WINDOWS\a65d.exe O4 - HKLM\..\Run: [NPKC17] C:\WINDOWS\wpasqow.exe O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitefpm32.exe O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16 O4 - HKLM\..\Run: [C:\WINDOWS\VCMnet11.exe] C:\WINDOWS\VCMnet11.exe O4 - HKLM\..\Run: [ZStart] c:\windows\system32\vdxregvu.exe lee0105 O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\ammzzr.exe O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe" O4 - HKLM\..\Run: [qFni39e] wowpbrd.exe O4 - HKLM\..\Run: [SysStart] C:\WINDOWS\System32\ffgsysi6.exe lee0105 O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun O4 - HKLM\..\RunServices: [Microsoft Updates] Botnet.exe O4 - HKCU\..\Run: [sysmonnt] C:\WINDOWS\System32\sysmonnt O4 - HKCU\..\Run: [Ttmmumi] C:\WINDOWS\System32\m?dtc.exe O4 - HKCU\..\Run: [bo4sRVK9U] qmgrt4.exe O4 - HKCU\..\Run: [msxsma] C:\WINDOWS\System32\msxsma.exe O4 - HKCU\..\RunOnce: [msxsma] C:\WINDOWS\System32\msxsma.exe O4 - Startup: Paint.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O10 - Unknown file in Winsock LSP: c:\windows\system32\winlspak.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\winlspak.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\winlspak.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\winlspak.dll O15 - Trusted Zone: *.media-motor.net O15 - Trusted Zone: *.popuppers.com O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll O20 - Winlogon Notify: OptimalLayout - C:\WINDOWS\system32\m4460ehseh460.dll O21 - SSODL: mtklef - {633915D7-EB88-4300-6DA2-E7241C69F36B} - C:\WINDOWS\System32\oktc32.dll (file missing) End of KRC HijackThis Analyzer Log. ==================================================================== |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Manager Emeritus - Security Center, Expert Analyst, Moderator - Security Team; Rangemaster, TSF Academy & Supporter
|
Hi and Welcome to TSF
You are severly infected!! Lets start by pointing out why your infected. You have no security on this PC.. Both XP and IE6 are out of date. Please visit microsofts update page and install the lastest service packs and security updates for both XP and IE6. Failing to to this...will waste both are times..in cleaning this PC. You have several MAJOR infections..and I will attack each one in a step. Please print these instructions out..and following them closely. STEP1............. Before attacking an adware/spyware problem with hijackthis make sure you have already run ad-aware SE with VX2 add-on cleaner, Spybot Search & Destroy (with updated database) and CWShredder as these programs will clean a lot of the crap out first. All links to programs are in my signature. Ok..on to the log….. If you have a highspeed connection please Run an online virus scan from TrendMicro Please select the “autoclean” option when prompted to do so. Download and install CleanUp http://cleanup.stevengould.org/ Download DelDomains.inf Right-click and select..... Save Target As To use: Right-click and select....... Install (no need to restart) **Note** This will remove all entries in the "Trusted Zone" Download Winsock2Fix and unzip it. Then double-click on it to run it. Go to My Computer->Tools->Folder Options->View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing/visible also. Please make sure system restore is enabled by right clicking on My Computer and go to Properties->System Restore and check the box for Turn OFF System Restore and make sure it’s NOT checked. We want system restore ON and monitoring your current hard drive. Once your clean we will turn this off and then create a new restore point. Reboot into Safe Mode (hit F8 key until menu shows up). Make sure to close any open browsers. Open add/remove programs and remove the following if listed. E2Give WebSpecials Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click Kill process for each one if they are still listed (they shouldn't be but make sure) C:\WINDOWS\System32\Botnet.exe C:\WINDOWS\System32\Tnqxjr.exe C:\WINDOWS\System32\vmss\vmss.exe C:\WINDOWS\System32\winupdt.exe C:\WINDOWS\System32\wintask.exe C:\WINDOWS\System32\wowpbrd.exe C:\WINDOWS\a65d.exe C:\WINDOWS\system\lxqpuodw.exe C:\WINDOWS\System32\msxsma.exe C:\WINDOWS\System32\sysmonnt.exe C:\WINDOWS\System32\msxsma.exe c:\windows\system32\vdxregvu.exe C:\WINDOWS\System32\ammzzr.exe C:\DOCUME~1\ALLUSE~1\APPLIC~1\msw\BMan1.exe C:\WINDOWS\System32\qmgrt4.exe C:\WINDOWS\System32\qwienh.exe C:\Program Files\AutoUpdate\AutoUpdate.exe C:\Program Files\CxtPls\CxtPls.exe C:\WINDOWS\System32\ffgsysi6.exe Check and fix the following in HijackThis if they still exist (make sure you do not miss an entry) R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file) F2 - REG:system.ini: Shell=Explorer.exe C:\logon.exe O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing) O4 - HKLM\..\Run: [Microsoft Updates] Botnet.exe O4 - HKLM\..\Run: [Shell Logon] C:\logon.exe O4 - HKLM\..\Run: [WebSpecials] rundll32 "C:\Program Files\WebSpecials\webspec.dll",run O4 - HKLM\..\Run: [secure] C:\WINDOWS\System32\Tnqxjr.exe O4 - HKLM\..\Run: [vmss] C:\WINDOWS\System32\vmss\vmss.exe O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe O4 - HKLM\..\Run: [hkadkzoy] c:\windows\system32\hkadkzoy.exe O4 - HKLM\..\Run: [r5a57j7b] C:\Program Files\r5a57j7b\r5a57j7b.exe O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1 O4 - HKLM\..\Run: [popuppers65] C:\WINDOWS\a65d.exe O4 - HKLM\..\Run: [NPKC17] C:\WINDOWS\wpasqow.exe O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitefpm32.exe O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16 O4 - HKLM\..\Run: [C:\WINDOWS\VCMnet11.exe] C:\WINDOWS\VCMnet11.exe O4 - HKLM\..\Run: [ZStart] c:\windows\system32\vdxregvu.exe lee0105 O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\ammzzr.exe O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe" O4 - HKLM\..\Run: [qFni39e] wowpbrd.exe O4 - HKLM\..\Run: [SysStart] C:\WINDOWS\System32\ffgsysi6.exe lee0105 O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun O4 - HKLM\..\RunServices: [Microsoft Updates] Botnet.exe O4 - HKCU\..\Run: [sysmonnt] C:\WINDOWS\System32\sysmonnt O4 - HKCU\..\Run: [Ttmmumi] C:\WINDOWS\System32\m?dtc.exe O4 - HKCU\..\Run: [bo4sRVK9U] qmgrt4.exe O4 - HKCU\..\Run: [msxsma] C:\WINDOWS\System32\msxsma.exe O4 - HKCU\..\RunOnce: [msxsma] C:\WINDOWS\System32\msxsma.exe O4 - Startup: Paint.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O10 - Unknown file in Winsock LSP: c:\windows\system32\winlspak.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\winlspak.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\winlspak.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\winlspak.dll O15 - Trusted Zone: *.media-motor.net O15 - Trusted Zone: *.popuppers.com O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll O20 - Winlogon Notify: OptimalLayout - C:\WINDOWS\system32\m4460ehseh460.dll O21 - SSODL: mtklef - {633915D7-EB88-4300-6DA2-E7241C69F36B} - C:\WINDOWS\System32\oktc32.dll (file missing) Delete the following Files/Folders in RED (delete folders if no filename is specified or if they are highlighted in RED) according to their directory (If you can't find them...do a search for them…make sure you have search hidden files, folders, sub directorys..ect enabled if it applys to your OS) C:\WINDOWS\System32\Botnet.exe C:\WINDOWS\System32\Tnqxjr.exe C:\WINDOWS\System32\vmss\vmss.exe C:\WINDOWS\System32\winupdt.exe C:\WINDOWS\System32\wintask.exe C:\WINDOWS\System32\wowpbrd.exe C:\WINDOWS\a65d.exe C:\WINDOWS\system\lxqpuodw.exe C:\WINDOWS\System32\msxsma.exe C:\WINDOWS\System32\sysmonnt.exe C:\WINDOWS\System32\msxsma.exe c:\windows\system32\vdxregvu.exe C:\WINDOWS\System32\ammzzr.exe C:\DOCUME~1\ALLUSE~1\APPLIC~1\msw\BMan1.exe C:\WINDOWS\System32\qmgrt4.exe C:\WINDOWS\System32\qwienh.exe C:\Program Files\AutoUpdate\AutoUpdate.exe C:\Program Files\CxtPls\CxtPls.exe C:\WINDOWS\System32\ffgsysi6.exe C:\logon.exe C:\Program Files\WebSpecials\webspec.dll C:\Program Files\r5a57j7b\r5a57j7b.exe C:\WINDOWS\System32\exp.exe C:\WINDOWS\wpasqow.exe C:\windows\system32\elitefpm32.exe C:\WINDOWS\VCMnet11.exe c:\windows\system32\vdxregvu.exe C:\WINDOWS\System32\ammzzr.exe C:\WINDOWS\cfgmgr52.dll C:\WINDOWS\System32\m?dtc.exe c:\windows\system32\winlspak.dll c:\windows\system32\dolsp.dll C:\WINDOWS\isrvs\mfiltis.dll C:\WINDOWS\system32\m4460ehseh460.dll C:\WINDOWS\System32\oktc32.dll AUNPS2.DLL D0CE0C16B1.dll <--locate and dlete these 2. Run the cleanup utility and reboot/logoff when prompted. Then proceed with the next step.. ================================================ STEP2. Download L2mfix from one of these two locations: http://www.atribune.org/downloads/l2mfix.exe http://www.downloads.subratam.org/l2mfix.exe Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Close any programs you have open since this step requires a reboot. From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log. IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so! ============================================ STEP3 Download Rkfiles.zip http://skads.org/special/rkfiles.zip UNZIP the contents to a permanent folder on your desktop. Download the following attachment remv3.zip http://forums.skads.org/index.php?showtopic=80 Make a folder on the root drive C:\ and unzip the files into it. Now run the Cleanup utility and reboot/logoff when prompted. REBOOT TO SAFE MODE… These tools MUST be run in safe mode!! Once in safe mode… Double click rkfiles.bat It will scan for a while, so please be patient. Wait till the dos window closes. Open the C:\log.txt it created and rename it log1.txt. Now Open the folder were you saved remv3.zip files and click the rem.bat file and let it run. It will delete the files and remove the infection and then make a log of the files it finds. The log file will be C:\log.txt and bad1.txt **Note** Each tool uses log.txt as it’s output file so make sure you save the entry’s from one tool before running the other as it will overwrite the file if you don’t. Reboot back to normal mode and post the contents of both the log.txt and log1.txt in your next post. So..in your next post...I need the following logs.. Hijackthis log l2mfix log rkfiles log (log1.txt) remv3 log (log.txt)
__________________
We Are The BORG Spyware KILLER and Adware Destroyer!
![]() ![]() ![]() Spyware/Adware Removal Tools Hijackthis Ad-aware SE Spybot Search&Destroy SpywareBlaster CWShredder Last edited by MicroBell; 05-15-2005 at 12:38 AM. |
|
|
|
|
#3 (permalink) |
|
I helped the forums.
Join Date: Mar 2005
Location: Long Island, NY
Posts: 21
OS: XP
|
follow on logs
Here are logs.
==================================================================== Log was analyzed using KRC HijackThis Analyzer - Updated on 4/1/05 Get updates at http://www.greyknight17.com/download.htm#programs ***Security Programs Detected*** C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Logfile of HijackThis v1.99.1 Scan saved at 11:33:46 PM, on 5/16/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\Dsdgno.exe C:\WINDOWS\System32\ammzzr.exe C:\WINDOWS\System32\nsvsvc\nsvsvc.exe C:\WINDOWS\System32\picsvr\picsvr.exe C:\WINDOWS\System32\8pr3kkhh.exe C:\DOCUME~1\liz\LOCALS~1\Temp\ICD3.tmp\svcmm32.exe C:\WINDOWS\seeve.exe C:\Program Files\ISTsvc\istsvc.exe C:\WINDOWS\System32\actit142.exe C:\Program Files\AutoUpdate\AutoUpdate.exe C:\WINDOWS\System32\mcidcz.exe C:\WINDOWS\System32\mcidcz.exe C:\WINDOWS\System32\8prsl.exe c:\windows\system32\jrwhfa.exe C:\WINDOWS\System32\ole32.exe C:\Security\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchmiracle.com/sp.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmiracle.com/sp.php R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchmiracle.com/sp.php F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll O4 - HKLM\..\Run: [secure] C:\WINDOWS\System32\Dsdgno.exe O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\ammzzr.exe O4 - HKLM\..\Run: [saap] c:\program files\180search assistant\saap.exe O4 - HKLM\..\Run: [zgtipyb] C:\WINDOWS\zgtipyb.exe O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\System32\picsvr\picsvr.exe O4 - HKLM\..\Run: [8pr3kkhh] C:\WINDOWS\System32\8pr3kkhh.exe O4 - HKLM\..\Run: [PS1] C:\WINDOWS\System32\ps1.exe O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\Pbzclk.exe O4 - HKLM\..\Run: [USB controller] "C:\DOCUME~1\liz\LOCALS~1\Temp\ICD3.tmp\svcmm32.exe" /startup O4 - HKLM\..\Run: [seeve] C:\WINDOWS\seeve.exe O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe O4 - HKLM\..\Run: [cfgmgr51] RunDLL32.EXE C:\WINDOWS\cfgmgr51.dll,DllRun O4 - HKLM\..\Run: [qFni39e] actit142.exe O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe" O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitetph32.exe O4 - HKLM\..\Run: [wuzdlt] c:\windows\system32\jrwhfa.exe O4 - HKCU\..\Run: [ole32] C:\WINDOWS\System32\ole32.exe O4 - HKCU\..\Run: [mcidcz] C:\WINDOWS\System32\mcidcz.exe O4 - HKCU\..\Run: [bo4sRVK9U] 8prsl.exe O4 - HKCU\..\RunOnce: [mcidcz] C:\WINDOWS\System32\mcidcz.exe O15 - Trusted Zone: *.media-motor.net O15 - Trusted Zone: *.popuppers.com O16 - DPF: {7149E79C-DC19-4C5E-A53C-A54DDF75EEE9} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/joysaver.cab O16 - DPF: {99410CDE-6F16-42ce-9D49-3807F78F0287} (ClientInstaller Class) - http://www.180searchassistant.com/180saax.cab O16 - DPF: {EC51659D-721F-4CBF-9CEA-5E776D89CEA9} - http://www.pacimedia.com/install/pcs_0002.exe O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll O21 - SSODL: mtklef - {633915D7-EB88-4300-6DA2-E7241C69F36B} - C:\WINDOWS\System32\oktc32.dll (file missing) O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe End of KRC HijackThis Analyzer Log. ==================================================================== L2Mfix 1.03 Running From: C:\Security\l2mfix RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify: (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Read BUILTIN\Power Users (ID-IO) ALLOW Read BUILTIN\Power Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access CREATOR OWNER Setting registry permissions: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Denying C(CI) access for predefined group "Administrators" - adding new ACCESS DENY entry Registry Permissions set too: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify: (CI) DENY --C------- BUILTIN\Administrators (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Read BUILTIN\Power Users (ID-IO) ALLOW Read BUILTIN\Power Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access CREATOR OWNER Setting up for Reboot Starting Reboot! C:\Security\l2mfix System Rebooted! Running From: C:\Security\l2mfix killing explorer and rundll32.exe Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org Killing PID 972 'explorer.exe' Killing PID 972 'explorer.exe' Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org Error, Cannot find a process with an image name of rundll32.exe Scanning First Pass. Please Wait! First Pass Completed Second Pass Scanning Second pass Completed! Backing Up: C:\WINDOWS\system32\aalui.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\azaolgd3160.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\ctmaddin.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\cxyptnet.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\dccprop2.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\decprop.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\dLtime.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\dudlgs.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\dwdmoprp.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\e002lado1d0c.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\e4020edoeh0c0.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\e4200efmeh2a0.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\en8ol1l31.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\en8ql1l51.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\enj8l11u1.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\enl6l13s1.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\ennsl1571.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\enrsl1971.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\f60olgd3160.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\h40q0ed5eh0.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\h60qlgd5160.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\hpps0577e.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\hr2s05f7e.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\hr8605lse.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\hrps0577e.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\iaxwan.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\ib2_win.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\ir8ol5l31.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\irjml5111.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\j4l40e3qeh.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\k4620ejoehoc0.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\kcdne.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\kgdest.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\kldro.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\kwrnel32.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\lv2o09f3e.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\lv8409lqe.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\lvj2091oe.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\lvlm0931e.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\lvlq0935e.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\lvp0097me.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\lvp4097qe.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\lvr2099oe.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\m4640ejqehoe0.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\m4820eloehqc0.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\m6nqlg5516.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\mcdvdopt.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\mghtmled.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\MJCTFP.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\mjencode.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\mmvidc32.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\mnv1_0.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\mriwave.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\n0n60a5sed.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\n4r20e9oeh.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\n6r2lg9o16.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\nfcfg.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\nGrrhook.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\p64ulgh9164.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\palstore.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\pfrfos.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\potorsvc.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\qygr.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\s0880aluedq80.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\sgns.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\skrwvdrv.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\sktupdll.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\stns.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\tukwks.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\ufrvoica.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\ukrdtea.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\vqscript.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\vtipxspx.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\wI2time.dll 1 file(s) copied. deleting: C:\WINDOWS\system32\aalui.dll Successfully Deleted: C:\WINDOWS\system32\aalui.dll deleting: C:\WINDOWS\system32\azaolgd3160.dll Successfully Deleted: C:\WINDOWS\system32\azaolgd3160.dll deleting: C:\WINDOWS\system32\ctmaddin.dll Successfully Deleted: C:\WINDOWS\system32\ctmaddin.dll deleting: C:\WINDOWS\system32\cxyptnet.dll Successfully Deleted: C:\WINDOWS\system32\cxyptnet.dll deleting: C:\WINDOWS\system32\dccprop2.dll Successfully Deleted: C:\WINDOWS\system32\dccprop2.dll deleting: C:\WINDOWS\system32\decprop.dll Successfully Deleted: C:\WINDOWS\system32\decprop.dll deleting: C:\WINDOWS\system32\dLtime.dll Successfully Deleted: C:\WINDOWS\system32\dLtime.dll deleting: C:\WINDOWS\system32\dudlgs.dll Successfully Deleted: C:\WINDOWS\system32\dudlgs.dll deleting: C:\WINDOWS\system32\dwdmoprp.dll Successfully Deleted: C:\WINDOWS\system32\dwdmoprp.dll deleting: C:\WINDOWS\system32\e002lado1d0c.dll Successfully Deleted: C:\WINDOWS\system32\e002lado1d0c.dll deleting: C:\WINDOWS\system32\e4020edoeh0c0.dll Successfully Deleted: C:\WINDOWS\system32\e4020edoeh0c0.dll deleting: C:\WINDOWS\system32\e4200efmeh2a0.dll Successfully Deleted: C:\WINDOWS\system32\e4200efmeh2a0.dll deleting: C:\WINDOWS\system32\en8ol1l31.dll Successfully Deleted: C:\WINDOWS\system32\en8ol1l31.dll deleting: C:\WINDOWS\system32\en8ql1l51.dll Successfully Deleted: C:\WINDOWS\system32\en8ql1l51.dll deleting: C:\WINDOWS\system32\enj8l11u1.dll Successfully Deleted: C:\WINDOWS\system32\enj8l11u1.dll deleting: C:\WINDOWS\system32\enl6l13s1.dll Successfully Deleted: C:\WINDOWS\system32\enl6l13s1.dll deleting: C:\WINDOWS\system32\ennsl1571.dll Successfully Deleted: C:\WINDOWS\system32\ennsl1571.dll deleting: C:\WINDOWS\system32\enrsl1971.dll Successfully Deleted: C:\WINDOWS\system32\enrsl1971.dll deleting: C:\WINDOWS\system32\f60olgd3160.dll Successfully Deleted: C:\WINDOWS\system32\f60olgd3160.dll deleting: C:\WINDOWS\system32\h40q0ed5eh0.dll Successfully Deleted: C:\WINDOWS\system32\h40q0ed5eh0.dll deleting: C:\WINDOWS\system32\h60qlgd5160.dll Successfully Deleted: C:\WINDOWS\system32\h60qlgd5160.dll deleting: C:\WINDOWS\system32\hpps0577e.dll Successfully Deleted: C:\WINDOWS\system32\hpps0577e.dll deleting: C:\WINDOWS\system32\hr2s05f7e.dll Successfully Deleted: C:\WINDOWS\system32\hr2s05f7e.dll deleting: C:\WINDOWS\system32\hr8605lse.dll Successfully Deleted: C:\WINDOWS\system32\hr8605lse.dll deleting: C:\WINDOWS\system32\hrps0577e.dll Successfully Deleted: C:\WINDOWS\system32\hrps0577e.dll deleting: C:\WINDOWS\system32\iaxwan.dll Successfully Deleted: C:\WINDOWS\system32\iaxwan.dll deleting: C:\WINDOWS\system32\ib2_win.dll Successfully Deleted: C:\WINDOWS\system32\ib2_win.dll deleting: C:\WINDOWS\system32\ir8ol5l31.dll Successfully Deleted: C:\WINDOWS\system32\ir8ol5l31.dll deleting: C:\WINDOWS\system32\irjml5111.dll Successfully Deleted: C:\WINDOWS\system32\irjml5111.dll deleting: C:\WINDOWS\system32\j4l40e3qeh.dll Successfully Deleted: C:\WINDOWS\system32\j4l40e3qeh.dll deleting: C:\WINDOWS\system32\k4620ejoehoc0.dll Successfully Deleted: C:\WINDOWS\system32\k4620ejoehoc0.dll deleting: C:\WINDOWS\system32\kcdne.dll Successfully Deleted: C:\WINDOWS\system32\kcdne.dll deleting: C:\WINDOWS\system32\kgdest.dll Successfully Deleted: C:\WINDOWS\system32\kgdest.dll deleting: C:\WINDOWS\system32\kldro.dll Successfully Deleted: C:\WINDOWS\system32\kldro.dll deleting: C:\WINDOWS\system32\kwrnel32.dll Successfully Deleted: C:\WINDOWS\system32\kwrnel32.dll deleting: C:\WINDOWS\system32\lv2o09f3e.dll Successfully Deleted: C:\WINDOWS\system32\lv2o09f3e.dll deleting: C:\WINDOWS\system32\lv8409lqe.dll Successfully Deleted: C:\WINDOWS\system32\lv8409lqe.dll deleting: C:\WINDOWS\system32\lvj2091oe.dll Successfully Deleted: C:\WINDOWS\system32\lvj2091oe.dll deleting: C:\WINDOWS\system32\lvlm0931e.dll Successfully Deleted: C:\WINDOWS\system32\lvlm0931e.dll deleting: C:\WINDOWS\system32\lvlq0935e.dll Successfully Deleted: C:\WINDOWS\system32\lvlq0935e.dll deleting: C:\WINDOWS\system32\lvp0097me.dll Successfully Deleted: C:\WINDOWS\system32\lvp0097me.dll deleting: C:\WINDOWS\system32\lvp4097qe.dll Successfully Deleted: C:\WINDOWS\system32\lvp4097qe.dll deleting: C:\WINDOWS\system32\lvr2099oe.dll Successfully Deleted: C:\WINDOWS\system32\lvr2099oe.dll deleting: C:\WINDOWS\system32\m4640ejqehoe0.dll Successfully Deleted: C:\WINDOWS\system32\m4640ejqehoe0.dll deleting: C:\WINDOWS\system32\m4820eloehqc0.dll Successfully Deleted: C:\WINDOWS\system32\m4820eloehqc0.dll deleting: C:\WINDOWS\system32\m6nqlg5516.dll Successfully Deleted: C:\WINDOWS\system32\m6nqlg5516.dll deleting: C:\WINDOWS\system32\mcdvdopt.dll Successfully Deleted: C:\WINDOWS\system32\mcdvdopt.dll deleting: C:\WINDOWS\system32\mghtmled.dll Successfully Deleted: C:\WINDOWS\system32\mghtmled.dll deleting: C:\WINDOWS\system32\MJCTFP.dll Successfully Deleted: C:\WINDOWS\system32\MJCTFP.dll deleting: C:\WINDOWS\system32\mjencode.dll Successfully Deleted: C:\WINDOWS\system32\mjencode.dll deleting: C:\WINDOWS\system32\mmvidc32.dll Successfully Deleted: C:\WINDOWS\system32\mmvidc32.dll deleting: C:\WINDOWS\system32\mnv1_0.dll Successfully Deleted: C:\WINDOWS\system32\mnv1_0.dll deleting: C:\WINDOWS\system32\mriwave.dll Successfully Deleted: C:\WINDOWS\system32\mriwave.dll deleting: C:\WINDOWS\system32\n0n60a5sed.dll Successfully Deleted: C:\WINDOWS\system32\n0n60a5sed.dll deleting: C:\WINDOWS\system32\n4r20e9oeh.dll Successfully Deleted: C:\WINDOWS\system32\n4r20e9oeh.dll deleting: C:\WINDOWS\system32\n6r2lg9o16.dll Successfully Deleted: C:\WINDOWS\system32\n6r2lg9o16.dll deleting: C:\WINDOWS\system32\nfcfg.dll Successfully Deleted: C:\WINDOWS\system32\nfcfg.dll deleting: C:\WINDOWS\system32\nGrrhook.dll Successfully Deleted: C:\WINDOWS\system32\nGrrhook.dll deleting: C:\WINDOWS\system32\p64ulgh9164.dll Successfully Deleted: C:\WINDOWS\system32\p64ulgh9164.dll deleting: C:\WINDOWS\system32\palstore.dll Successfully Deleted: C:\WINDOWS\system32\palstore.dll deleting: C:\WINDOWS\system32\pfrfos.dll Successfully Deleted: C:\WINDOWS\system32\pfrfos.dll deleting: C:\WINDOWS\system32\potorsvc.dll Successfully Deleted: C:\WINDOWS\system32\potorsvc.dll deleting: C:\WINDOWS\system32\qygr.dll Successfully Deleted: C:\WINDOWS\system32\qygr.dll deleting: C:\WINDOWS\system32\s0880aluedq80.dll Successfully Deleted: C:\WINDOWS\system32\s0880aluedq80.dll deleting: C:\WINDOWS\system32\sgns.dll Successfully Deleted: C:\WINDOWS\system32\sgns.dll deleting: C:\WINDOWS\system32\skrwvdrv.dll Successfully Deleted: C:\WINDOWS\system32\skrwvdrv.dll deleting: C:\WINDOWS\system32\sktupdll.dll Successfully Deleted: C:\WINDOWS\system32\sktupdll.dll deleting: C:\WINDOWS\system32\stns.dll Successfully Deleted: C:\WINDOWS\system32\stns.dll deleting: C:\WINDOWS\system32\tukwks.dll Successfully Deleted: C:\WINDOWS\system32\tukwks.dll deleting: C:\WINDOWS\system32\ufrvoica.dll Successfully Deleted: C:\WINDOWS\system32\ufrvoica.dll deleting: C:\WINDOWS\system32\ukrdtea.dll Successfully Deleted: C:\WINDOWS\system32\ukrdtea.dll deleting: C:\WINDOWS\system32\vqscript.dll Successfully Deleted: C:\WINDOWS\system32\vqscript.dll deleting: C:\WINDOWS\system32\vtipxspx.dll Successfully Deleted: C:\WINDOWS\system32\vtipxspx.dll deleting: C:\WINDOWS\system32\wI2time.dll Successfully Deleted: C:\WINDOWS\system32\wI2time.dll Desktop.ini sucessfully removed Zipping up files for submission: adding: aalui.dll (188 bytes security) (deflated 5%) adding: azaolgd3160.dll (188 bytes security) (deflated 5%) adding: ctmaddin.dll (188 bytes security) (deflated 6%) adding: cxyptnet.dll (188 bytes security) (deflated 6%) adding: dccprop2.dll (188 bytes security) (deflated 5%) adding: decprop.dll (188 bytes security) (deflated 4%) adding: dLtime.dll (188 bytes security) (deflated 4%) adding: dudlgs.dll (188 bytes security) (deflated 5%) adding: dwdmoprp.dll (188 bytes security) (deflated 5%) adding: e002lado1d0c.dll (188 bytes security) (deflated 5%) adding: e4020edoeh0c0.dll (188 bytes security) (deflated 4%) adding: e4200efmeh2a0.dll (188 bytes security) (deflated 5%) adding: en8ol1l31.dll (188 bytes security) (deflated 5%) adding: en8ql1l51.dll (188 bytes security) (deflated 5%) adding: enj8l11u1.dll (188 bytes security) (deflated 4%) adding: enl6l13s1.dll (188 bytes security) (deflated 5%) adding: ennsl1571.dll (188 bytes security) (deflated 5%) adding: enrsl1971.dll (188 bytes security) (deflated 5%) adding: f60olgd3160.dll (188 bytes security) (deflated 4%) adding: h40q0ed5eh0.dll (188 bytes security) (deflated 6%) adding: h60qlgd5160.dll (188 bytes security) (deflated 5%) adding: hpps0577e.dll (188 bytes security) (deflated 5%) adding: hr2s05f7e.dll (188 bytes security) (deflated 5%) adding: hr8605lse.dll (188 bytes security) (deflated 4%) adding: hrps0577e.dll (188 bytes security) (deflated 5%) adding: iaxwan.dll (188 bytes security) (deflated 6%) adding: ib2_win.dll (188 bytes security) (deflated 4%) adding: ir8ol5l31.dll (188 bytes security) (deflated 5%) adding: irjml5111.dll (188 bytes security) (deflated 5%) adding: j4l40e3qeh.dll (188 bytes security) (deflated 5%) adding: k4620ejoehoc0.dll (188 bytes security) (deflated 5%) adding: kcdne.dll (188 bytes security) (deflated 5%) adding: kgdest.dll (188 bytes security) (deflated 6%) adding: kldro.dll (188 bytes security) (deflated 4%) adding: kwrnel32.dll (188 bytes security) (deflated 5%) adding: lv2o09f3e.dll (188 bytes security) (deflated 5%) adding: lv8409lqe.dll (188 bytes security) (deflated 5%) adding: lvj2091oe.dll (188 bytes security) (deflated 5%) adding: lvlm0931e.dll (188 bytes security) (deflated 5%) adding: lvlq0935e.dll (188 bytes security) (deflated 5%) adding: lvp0097me.dll (188 bytes security) (deflated 5%) adding: lvp4097qe.dll (188 bytes security) (deflated 4%) adding: lvr2099oe.dll (188 bytes security) (deflated 6%) adding: m4640ejqehoe0.dll (188 bytes security) (deflated 4%) adding: m4820eloehqc0.dll (188 bytes security) (deflated 5%) adding: m6nqlg5516.dll (188 bytes security) (deflated 5%) adding: mcdvdopt.dll (188 bytes security) (deflated 4%) adding: mghtmled.dll (188 bytes security) (deflated 4%) adding: MJCTFP.dll (188 bytes security) (deflated 6%) adding: mjencode.dll (188 bytes security) (deflated 5%) adding: mmvidc32.dll (188 bytes security) (deflated 5%) adding: mnv1_0.dll (188 bytes security) (deflated 5%) adding: mriwave.dll (188 bytes security) (deflated 4%) adding: n0n60a5sed.dll (188 bytes security) (deflated 5%) adding: n4r20e9oeh.dll (188 bytes security) (deflated 5%) adding: n6r2lg9o16.dll (188 bytes security) (deflated 5%) adding: nfcfg.dll (188 bytes security) (deflated 4%) adding: nGrrhook.dll (188 bytes security) (deflated 4%) adding: p64ulgh9164.dll (188 bytes security) (deflated 4%) adding: palstore.dll (188 bytes security) (deflated 5%) adding: pfrfos.dll (188 bytes security) (deflated 6%) adding: potorsvc.dll (188 bytes security) (deflated 4%) adding: qygr.dll (188 bytes security) (deflated 6%) adding: s0880aluedq80.dll (188 bytes security) (deflated 6%) adding: sgns.dll (188 bytes security) (deflated 4%) adding: skrwvdrv.dll (188 bytes security) (deflated 5%) adding: sktupdll.dll (188 bytes security) (deflated 5%) adding: stns.dll (188 bytes security) (deflated 6%) adding: tukwks.dll (188 bytes security) (deflated 5%) adding: ufrvoica.dll (188 bytes security) (deflated 5%) adding: ukrdtea.dll (188 bytes security) (deflated 5%) adding: vqscript.dll (188 bytes security) (deflated 5%) adding: vtipxspx.dll (188 bytes security) (deflated 5%) adding: wI2time.dll (188 bytes security) (deflated 5%) adding: clear.reg (188 bytes security) (deflated 22%) adding: echo.reg (188 bytes security) (deflated 5%) adding: desktop.ini (188 bytes security) (deflated 14%) adding: direct.txt (188 bytes security) (stored 0%) adding: lo2.txt (188 bytes security) (deflated 88%) adding: readme.txt (188 bytes security) (deflated 49%) adding: test.txt (188 bytes security) (deflated 84%) adding: test2.txt (188 bytes security) (stored 0%) adding: test3.txt (188 bytes security) (stored 0%) adding: test5.txt (188 bytes security) (stored 0%) adding: xfind.txt (188 bytes security) (deflated 79%) adding: backregs/6BFB6F7D-E430-4FD0-848F-2ECFA3868629.reg (188 bytes security) (deflated 69%) adding: backregs/shell.reg (188 bytes security) (deflated 74%) Restoring Registry Permissions: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Revoking access for predefined group "Administrators" Inherited ACE can not be revoked here! Inherited ACE can not be revoked here! Registry permissions set too: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify: (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Read BUILTIN\Power Users (ID-IO) ALLOW Read BUILTIN\Power Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access CREATOR OWNER Restoring Sedebugprivilege: Granting SeDebugPrivilege to Administrators ... successful deleting local copy: aalui.dll deleting local copy: azaolgd3160.dll deleting local copy: ctmaddin.dll deleting local copy: cxyptnet.dll deleting local copy: dccprop2.dll deleting local copy: decprop.dll deleting local copy: dLtime.dll deleting local copy: dudlgs.dll deleting local copy: dwdmoprp.dll deleting local copy: e002lado1d0c.dll deleting local copy: e4020edoeh0c0.dll deleting local copy: e4200efmeh2a0.dll deleting local copy: en8ol1l31.dll deleting local copy: en8ql1l51.dll deleting local copy: enj8l11u1.dll deleting local copy: enl6l13s1.dll deleting local copy: ennsl1571.dll deleting local copy: enrsl1971.dll deleting local copy: f60olgd3160.dll deleting local copy: h40q0ed5eh0.dll deleting local copy: h60qlgd5160.dll deleting local copy: hpps0577e.dll deleting local copy: hr2s05f7e.dll deleting local copy: hr8605lse.dll deleting local copy: hrps0577e.dll deleting local copy: iaxwan.dll deleting local copy: ib2_win.dll deleting local copy: ir8ol5l31.dll deleting local copy: irjml5111.dll deleting local copy: j4l40e3qeh.dll deleting local copy: k4620ejoehoc0.dll deleting local copy: kcdne.dll deleting local copy: kgdest.dll deleting local copy: kldro.dll deleting local copy: kwrnel32.dll deleting local copy: lv2o09f3e.dll deleting local copy: lv8409lqe.dll deleting local copy: lvj2091oe.dll deleting local copy: lvlm0931e.dll deleting local copy: lvlq0935e.dll deleting local copy: lvp0097me.dll deleting local copy: lvp4097qe.dll deleting local copy: lvr2099oe.dll deleting local copy: m4640ejqehoe0.dll deleting local copy: m4820eloehqc0.dll deleting local copy: m6nqlg5516.dll deleting local copy: mcdvdopt.dll deleting local copy: mghtmled.dll deleting local copy: MJCTFP.dll deleting local copy: mjencode.dll deleting local copy: mmvidc32.dll deleting local copy: mnv1_0.dll deleting local copy: mriwave.dll deleting local copy: n0n60a5sed.dll deleting local copy: n4r20e9oeh.dll deleting local copy: n6r2lg9o16.dll deleting local copy: nfcfg.dll deleting local copy: nGrrhook.dll deleting local copy: p64ulgh9164.dll deleting local copy: palstore.dll deleting local copy: pfrfos.dll deleting local copy: potorsvc.dll deleting local copy: qygr.dll deleting local copy: s0880aluedq80.dll deleting local copy: sgns.dll deleting local copy: skrwvdrv.dll deleting local copy: sktupdll.dll deleting local copy: stns.dll deleting local copy: tukwks.dll deleting local copy: ufrvoica.dll deleting local copy: ukrdtea.dll deleting local copy: vqscript.dll deleting local copy: vtipxspx.dll deleting local copy: wI2time.dll The following Is the Current Export of the Winlogon notify key: **************************************************************************** Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon] "Logoff"="NavLogoffEvent" "DllName"="C:\\WINDOWS\\System32\\NavLogon.dll" "StartShell"="NavStartShellEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEvent" "Logoff"="UnregisterTicketExpiredNotificationEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 The following are the files found: **************************************************************************** C:\WINDOWS\system32\aalui.dll C:\WINDOWS\system32\azaolgd3160.dll C:\WINDOWS\system32\ctmaddin.dll C:\WINDOWS\system32\cxyptnet.dll C:\WINDOWS\system32\dccprop2.dll C:\WINDOWS\system32\decprop.dll C:\WINDOWS\system32\dLtime.dll C:\WINDOWS\system32\dudlgs.dll C:\WINDOWS\system32\dwdmoprp.dll C:\WINDOWS\system32\e002lado1d0c.dll C:\WINDOWS\system32\e4020edoeh0c0.dll C:\WINDOWS\system32\e4200efmeh2a0.dll C:\WINDOWS\system32\en8ol1l31.dll C:\WINDOWS\system32\en8ql1l51.dll C:\WINDOWS\system32\enj8l11u1.dll C:\WINDOWS\system32\enl6l13s1.dll C:\WINDOWS\system32\ennsl1571.dll C:\WINDOWS\system32\enrsl1971.dll C:\WINDOWS\system32\f60olgd3160.dll C:\WINDOWS\system32\h40q0ed5eh0.dll C:\WINDOWS\system32\h60qlgd5160.dll C:\WINDOWS\system32\hpps0577e.dll C:\WINDOWS\system32\hr2s05f7e.dll C:\WINDOWS\system32\hr8605lse.dll C:\WINDOWS\system32\hrps0577e.dll C:\WINDOWS\system32\iaxwan.dll C:\WINDOWS\system32\ib2_win.dll C:\WINDOWS\system32\ir8ol5l31.dll C:\WINDOWS\system32\irjml5111.dll C:\WINDOWS\system32\j4l40e3qeh.dll C:\WINDOWS\system32\k4620ejoehoc0.dll C:\WINDOWS\system32\kcdne.dll C:\WINDOWS\system32\kgdest.dll C:\WINDOWS\system32\kldro.dll C:\WINDOWS\system32\kwrnel32.dll C:\WINDOWS\system32\lv2o09f3e.dll C:\WINDOWS\system32\lv8409lqe.dll C:\WINDOWS\system32\lvj2091oe.dll C:\WINDOWS\system32\lvlm0931e.dll C:\WINDOWS\system32\lvlq0935e.dll C:\WINDOWS\system32\lvp0097me.dll C:\WINDOWS\system32\lvp4097qe.dll C:\WINDOWS\system32\lvr2099oe.dll C:\WINDOWS\system32\m4640ejqehoe0.dll C:\WINDOWS\system32\m4820eloehqc0.dll C:\WINDOWS\system32\m6nqlg5516.dll C:\WINDOWS\system32\mcdvdopt.dll C:\WINDOWS\system32\mghtmled.dll C:\WINDOWS\system32\MJCTFP.dll C:\WINDOWS\system32\mjencode.dll C:\WINDOWS\system32\mmvidc32.dll C:\WINDOWS\system32\mnv1_0.dll C:\WINDOWS\system32\mriwave.dll C:\WINDOWS\system32\n0n60a5sed.dll C:\WINDOWS\system32\n4r20e9oeh.dll C:\WINDOWS\system32\n6r2lg9o16.dll C:\WINDOWS\system32\nfcfg.dll C:\WINDOWS\system32\nGrrhook.dll C:\WINDOWS\system32\p64ulgh9164.dll C:\WINDOWS\system32\palstore.dll C:\WINDOWS\system32\pfrfos.dll C:\WINDOWS\system32\potorsvc.dll C:\WINDOWS\system32\qygr.dll C:\WINDOWS\system32\s0880aluedq80.dll C:\WINDOWS\system32\sgns.dll C:\WINDOWS\system32\skrwvdrv.dll C:\WINDOWS\system32\sktupdll.dll C:\WINDOWS\system32\stns.dll C:\WINDOWS\system32\tukwks.dll C:\WINDOWS\system32\ufrvoica.dll C:\WINDOWS\system32\ukrdtea.dll C:\WINDOWS\system32\vqscript.dll C:\WINDOWS\system32\vtipxspx.dll C:\WINDOWS\system32\wI2time.dll Registry Entries that were Deleted: Please verify that the listing looks ok. If there was something deleted wrongly there are backups in the backreg folder. **************************************************************************** REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved] "{6BFB6F7D-E430-4FD0-848F-2ECFA3868629}"=- [-HKEY_CLASSES_ROOT\CLSID\{6BFB6F7D-E430-4FD0-848F-2ECFA3868629}] REGEDIT4 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] **************************************************************************** Desktop.ini Contents: **************************************************************************** [.ShellClassInfo] CLSID={645FF040-5081-101B-9F08-00AA002F954E} <IDone>{111A9A76-2AAD-4B19-9B44-D3662897D61D}</IDone> <IDtwo>VT00</IDtwo> <VERSION>200</VERSION> **************************************************************************** The batch is run from -- C:\Security\remv3 Files Found................. ---------------------------------------- Files Not deleted................. ---------------------------------------- Merging registry entries ----------------------------------------------------------------- The Registry Entries Found... ----------------------------------------------------------------- Other bad files to be Manually deleted.. Please note that this might also list legit Files, be careful while deleting ----------------------------------------------------------------- Volume in drive C has no label. Volume Serial Number is 38EC-2F22 Directory of C:\WINDOWS\system32 msi.dll Finished ************************** C:\Security\rkfiles\rkfiles PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. Files Found in system Folder............ ------------------------ C:\WINDOWS\system32\1800414.dll: UPX! C:\WINDOWS\system32\1802.dll: UPX! C:\WINDOWS\system32\ammzzr.exe: UPX! C:\WINDOWS\system32\AUNBHO.dll: UPX! C:\WINDOWS\system32\AUNPS.dll: UPX! C:\WINDOWS\system32\better0503.dll: UPX! C:\WINDOWS\system32\blizzard.dll: UPX! C:\WINDOWS\system32\delfin0414.dll: UPX! C:\WINDOWS\system32\ehhyypi.dll: UPX! C:\WINDOWS\system32\expypt.exe: UPX! C:\WINDOWS\system32\gbbuu.dat: UPX! C:\WINDOWS\system32\golden513.dll: UPX! C:\WINDOWS\system32\HyperLinker2.exe: UPX! C:\WINDOWS\system32\ixpowme.exe: UPX! C:\WINDOWS\system32\mcidcz.exe: UPX! C:\WINDOWS\system32\ps1.exe: UPX! C:\WINDOWS\system32\skytown.exe: UPX! C:\WINDOWS\system32\winup2date.dll: UPX! C:\WINDOWS\system32\wmconfig.cpl: UPX! C:\WINDOWS\system32\elitebjd32.exe: FSG! C:\WINDOWS\system32\eliteoke32.exe: FSG! C:\WINDOWS\system32\eliteozi32.exe: FSG! C:\WINDOWS\system32\elitetph32.exe: FSG! C:\WINDOWS\system32\dfrg.msc: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213 C:\WINDOWS\system32\elitebrp32.exe: PEC2 C:\WINDOWS\system32\elitedpb32.exe: PEC2 C:\WINDOWS\system32\elitetzn32.exe: PEC2 C:\WINDOWS\gx9fzj83m9.exe: PEC2 C:\WINDOWS\MEMORY.DMP: PEC2 C:\WINDOWS\MEMORY.DMP: PEC2 Files Found in all users startup Folder............ ------------------------ C:\Documents and Settings\All Users\Start Menu\Programs\Startup\uppa.exe: UPX! Files Found in all users windows Folder............ ------------------------ C:\WINDOWS\del.tmp: UPX! C:\WINDOWS\icont.exe: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX!- C:\WINDOWS\MEMORY.DMP: UPX!- C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX!- C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\Nail.exe: UPX! C:\WINDOWS\sskb5.exe: UPX! C:\WINDOWS\svcproc.exe: UPX! C:\WINDOWS\wpasqow.exe: UPX! C:\WINDOWS\MEMORY.DMP: efsg!>!#ztuf# C:\WINDOWS\MEMORY.DMP: FSG!- C:\WINDOWS\MEMORY.DMP: efsg!>!#ztuf# C:\WINDOWS\MEMORY.DMP: FSG!- C:\WINDOWS\MEMORY.DMP: efsg!>!#ztuf# C:\WINDOWS\MEMORY.DMP: FSG!- Finished bye ***************** thanks again for your help - Ken |
|
|
|
|
#4 (permalink) |
|
Manager Emeritus - Security Center, Expert Analyst, Moderator - Security Team; Rangemaster, TSF Academy & Supporter
|
Ok Ken.
Since all those entrys came back..it looks like you have the Bube.d (aka Win32.Beavis) virus. Please follow the instructions on this site...http://www.dslreports.com/forum/rema...8162~mode=flat Once you complete that...post another set of the following logs... Hijackthis log rkfiles log (log1.txt) remv3 log (log.txt) Remember..you still need to update XP and IE6 with the latest service packs.
__________________
We Are The BORG Spyware KILLER and Adware Destroyer!
![]() ![]() ![]() Spyware/Adware Removal Tools Hijackthis Ad-aware SE Spybot Search&Destroy SpywareBlaster CWShredder |
|
|
|
|
#5 (permalink) |
|
I helped the forums.
Join Date: Mar 2005
Location: Long Island, NY
Posts: 21
OS: XP
|
more logs
Here are more logs.
I was able to update XP to SP1 and then SP2. Windows update gave me problems but I was able to manually download them and install them. Thanks again......Ken ******************************************** ==================================================================== Log was analyzed using KRC HijackThis Analyzer - Updated on 4/1/05 Get updates at http://www.greyknight17.com/download.htm#programs ***Security Programs Detected*** C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Logfile of HijackThis v1.99.1 Scan saved at 11:46:40 PM, on 5/18/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\8pr3kkhh.exe C:\WINDOWS\system32\actit142.exe C:\WINDOWS\system32\8prsl.exe C:\Security\HiJackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchmiracle.com/sp.php R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id= R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q= F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfgmgr51.dll (file missing) O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing) O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll (file missing) O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing) O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll (file missing) O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file) O4 - HKLM\..\Run: [8pr3kkhh] C:\WINDOWS\System32\8pr3kkhh.exe O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe O4 - HKLM\..\Run: [cfgmgr51] RunDLL32.EXE C:\WINDOWS\cfgmgr51.dll,DllRun O4 - HKLM\..\Run: [qFni39e] actit142.exe O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe" O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize O4 - HKCU\..\Run: [bo4sRVK9U] 8prsl.exe O15 - Trusted Zone: *.media-motor.net O15 - Trusted Zone: *.popuppers.com O16 - DPF: {7149E79C-DC19-4C5E-A53C-A54DDF75EEE9} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/joysaver.cab O16 - DPF: {99410CDE-6F16-42ce-9D49-3807F78F0287} (ClientInstaller Class) - http://www.180searchassistant.com/180saax.cab O16 - DPF: {EC51659D-721F-4CBF-9CEA-5E776D89CEA9} - http://www.pacimedia.com/install/pcs_0002.exe O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll O21 - SSODL: mtklef - {633915D7-EB88-4300-6DA2-E7241C69F36B} - C:\WINDOWS\System32\oktc32.dll (file missing) O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe End of KRC HijackThis Analyzer Log. ==================================================================== L2Mfix 1.03 Running From: C:\Security\l2mfix RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify: (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Read BUILTIN\Power Users (ID-IO) ALLOW Read BUILTIN\Power Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access CREATOR OWNER Setting registry permissions: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Denying C(CI) access for predefined group "Administrators" - adding new ACCESS DENY entry Registry Permissions set too: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify: (CI) DENY --C------- BUILTIN\Administrators (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Read BUILTIN\Power Users (ID-IO) ALLOW Read BUILTIN\Power Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access CREATOR OWNER Setting up for Reboot Starting Reboot! C:\Security\l2mfix System Rebooted! Running From: C:\Security\l2mfix killing explorer and rundll32.exe Scanning First Pass. Please Wait! First Pass Completed Second Pass Scanning Second pass Completed! Zipping up files for submission: updating: clear.reg (188 bytes security) (deflated 2%) updating: echo.reg (188 bytes security) (deflated 5%) updating: direct.txt (188 bytes security) (stored 0%) updating: lo2.txt (188 bytes security) (deflated 75%) updating: readme.txt (188 bytes security) (deflated 49%) updating: test.txt (188 bytes security) (stored 0%) updating: test2.txt (188 bytes security) (stored 0%) updating: test3.txt (188 bytes security) (stored 0%) updating: test5.txt (188 bytes security) (stored 0%) adding: log.txt (188 bytes security) (deflated 86%) updating: backregs/6BFB6F7D-E430-4FD0-848F-2ECFA3868629.reg (188 bytes security) (deflated 69%) updating: backregs/shell.reg (188 bytes security) (deflated 74%) Restoring Registry Permissions: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Revoking access for predefined group "Administrators" Inherited ACE can not be revoked here! Inherited ACE can not be revoked here! Registry permissions set too: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify: (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Read BUILTIN\Power Users (ID-IO) ALLOW Read BUILTIN\Power Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access CREATOR OWNER Restoring Sedebugprivilege: Granting SeDebugPrivilege to Administrators ... successful The following Is the Current Export of the Winlogon notify key: **************************************************************************** Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon] "Logoff"="NavLogoffEvent" "DllName"="C:\\WINDOWS\\System32\\NavLogon.dll" "StartShell"="NavStartShellEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEvent" "Logoff"="UnregisterTicketExpiredNotificationEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 The following are the files found: **************************************************************************** Registry Entries that were Deleted: Please verify that the listing looks ok. If there was something deleted wrongly there are backups in the backreg folder. **************************************************************************** REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved] REGEDIT4 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "SV1"="" **************************************************************************** Desktop.ini Contents: **************************************************************************** **************************************************************************** C:\Security\rkfiles\rkfiles PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. Files Found in system Folder............ ------------------------ C:\WINDOWS\system32\dfrg.msc: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213 C:\WINDOWS\MEMORY.DMP: PEC2 C:\WINDOWS\MEMORY.DMP: PEC2 Files Found in all users startup Folder............ ------------------------ Files Found in all users windows Folder............ ------------------------ C:\WINDOWS\del.tmp: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX!- C:\WINDOWS\MEMORY.DMP: UPX!- C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX!- C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\MEMORY.DMP: UPX! C:\WINDOWS\tdtb.exe: UPX! C:\WINDOWS\MEMORY.DMP: efsg!>!#ztuf# C:\WINDOWS\MEMORY.DMP: FSG!- C:\WINDOWS\MEMORY.DMP: efsg!>!#ztuf# C:\WINDOWS\MEMORY.DMP: FSG!- C:\WINDOWS\MEMORY.DMP: efsg!>!#ztuf# C:\WINDOWS\MEMORY.DMP: FSG!- Finished bye ************************ The batch is run from -- C:\Security\remv3 Files Found................. ---------------------------------------- Files Not deleted................. ---------------------------------------- Merging registry entries ----------------------------------------------------------------- The Registry Entries Found... ----------------------------------------------------------------- Other bad files to be Manually deleted.. Please note that this might also list legit Files, be careful while deleting ----------------------------------------------------------------- Volume in drive C has no label. Volume Serial Number is 38EC-2F22 Directory of C:\WINDOWS\system32 msi.dll Finished |
|
|
|
|
#6 (permalink) |
|
Analyst, Security Team
|
Please download nailfix at http://users.pandora.be/bluepatchy/nailfix.zip (for Windows XP) or http://users.pandora.be/bluepatchy/nailfix2k.zip (for Windows 2000) Unzip it to the desktop but do NOT run it yet.
Right click on this link http://www.greyknight17.com/spy/DelO15Domains.inf and choose Save As. Save it to your desktop. Right click on that file and choose Install. It will run immediately (you won't be able to see anything happen). You may delete it afterwards. Reboot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn't work. Download KillBox http://www.greyknight17.com/spy/KillBox.exe. Don't run it yet. Once in Safe Mode, please double-click on nailfix.bat (or nailfix2k.bat if you have Windows 2000). Your desktop and icons will disappear and reappear, and a window should open and close very quickly --- this is normal. Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any): R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchmiracle.com/sp.php R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id= R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q= F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfgmgr51.dll (file missing) O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing) O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll (file missing) O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing) O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll (file missing) O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file) O4 - HKLM\..\Run: [8pr3kkhh] C:\WINDOWS\System32\8pr3kkhh.exe O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe O4 - HKLM\..\Run: [cfgmgr51] RunDLL32.EXE C:\WINDOWS\cfgmgr51.dll,DllRun O4 - HKLM\..\Run: [qFni39e] actit142.exe O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe" O4 - HKCU\..\Run: [bo4sRVK9U] 8prsl.exe O15 - Trusted Zone: *.media-motor.net O15 - Trusted Zone: *.popuppers.com O16 - DPF: {7149E79C-DC19-4C5E-A53C-A54DDF75EEE9} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/joysaver.cab O16 - DPF: {99410CDE-6F16-42ce-9D49-3807F78F0287} (ClientInstaller Class) - http://www.180searchassistant.com/180saax.cab O16 - DPF: {EC51659D-721F-4CBF-9CEA-5E776D89CEA9} - http://www.pacimedia.com/install/pcs_0002.exe O21 - SSODL: mtklef - {633915D7-EB88-4300-6DA2-E7241C69F36B} - C:\WINDOWS\System32\oktc32.dll (file missing) Close all open windows except for HijackThis and click Fix Checked. Run KillBox and check the box that says 'End Explorer Shell While Killing File'. Next click on 'Delete on Reboot'. For each of the following files below, check the box that says 'Unregister .dll Before Deleting' if it's not grayed out. Copy and paste each of the following into KillBox (hitting the X button for each file - choose NO when it asks if you want to reboot): C:\WINDOWS\tdtb.exe C:\WINDOWS\del.tmp C:\WINDOWS\System32\8pr3kkhh.exe C:\WINDOWS\system32\actit142.exe C:\WINDOWS\system32\8prsl.exe C:\WINDOWS\Nail.exe C:\WINDOWS\cfgmgr51.dll C:\WINDOWS\systb.dll C:\Program Files\E2G\ C:\WINDOWS\EliteToolBar\ C:\WINDOWS\System32\exp.exe C:\Program Files\AutoUpdate\ Restart your computer in normal mode and post a new HijackThis log.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it. |
|
|
|
|
#7 (permalink) |
|
I helped the forums.
Join Date: Mar 2005
Location: Long Island, NY
Posts: 21
OS: XP
|
another log
Here is the latest log, this one looks alot cleaner.
Thanks very much for all your help.....Ken *********************************** ==================================================================== Log was analyzed using KRC HijackThis Analyzer - Updated on 4/1/05 Get updates at http://www.greyknight17.com/download.htm#programs ***Security Programs Detected*** C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Logfile of HijackThis v1.99.1 Scan saved at 8:37:34 PM, on 5/19/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\Security\HiJackThis\HijackThis.exe O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll End of KRC HijackThis Analyzer Log. ==================================================================== |
|
|
|
|
#8 (permalink) |
|
Analyst, Security Team
|
Wow, did that do the job or what?
![]() Your log is clean. Turn off system restore by right clicking on My Computer and go to Properties->System Restore and check the box for Turn off System Restore. Click Apply and then OK. Restart your computer and uncheck the same box to enable System Restore. Make sure to get the latest updates for Windows and Internet Explorer at http://v5.windowsupdate.microsoft.co....aspx?ln=en-us. To help prevent future spyware installations/infections, please read the Anti-Spyware Tutorial and use the tools provided. Are there any problems now? If not, you should be set to go.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it. |
|
|
| Thread Tools | |
|
|