Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 06-28-2005, 09:32 AM   #1 (permalink)
I helped the forums.
 
Join Date: Jun 2005
Posts: 9
OS: XP


HJT help...cannot get rid of Narrator KAVSVC and maybe others

I have the KavSvc Narrator problem and cannot seem to get rid of it...I'm sure I have a couple others as well. I have followed the instructions of some of the other posts but cannot seem to completely eliminate all files. Below is the HJT log...thanks for any help.

Logfile of HijackThis v1.99.1
Scan saved at 10:28:53 AM, on 6/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ndnu.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Kary Nulisch\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\vrvlmm.exe reg_run
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4101542B-4071-4B52-9F3A-7BCA44C1E791} (MarketTrader - ETrade v3.2a) - http://etrade.bridge.com/etgmt_prd/j...a_etrade_i.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-24.cab
O16 - DPF: {712D42CD-3513-473E-96E8-019C9AD78F1A} (MSN Money QuickList) - http://moneycentral.msn.com/cabs/webinst.exe
O16 - DPF: {963BE66B-121D-4E6C-BF9F-1A774D9A2E41} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupdate.exe
O16 - DPF: {D8A14CC1-B68A-11D6-B8FA-00C04F5E375A} (MarketTrader - Reuters v3.2a) - http://etrade.bridge.com/etgmt_prd/j..._reuters_i.cab
O20 - Winlogon Notify: Explorer - C:\WINDOWS\system32\eps.dll
O23 - Service: Aluria Security Center Spyware Eliminator Service (ASCService) - Unknown owner - C:\PROGRA~1\ALURIA~1\ascserv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe
lastbird is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 06-28-2005, 12:46 PM   #2 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,480
OS: N/A


Hi and Welcome to TSF!

Here's what you can do....

Please subscribe to this thread so you'll be notified as soon as we post your fix. To do this, please click here. On the proceeding page, make sure Instant notification by email is selected, then click Add subscription.

I see no anti-virus application installed on this machine. An anti-virus application is your first line of defense against infections from the internet and email. Without one you leave your computer completely vulnerable to every virus, spyware program, trojan and piece of malware tht is floating around out there today.

I strongly recommend that you install an anti-virus program as quickly as possible. Here are 3 free programs that are available for home use:
In the meanwhile, I suggest that you stop using Interent Explorer until we've fully disinfected your machine. Please download & use an alternative browser like Firefox.


Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are following the procedures below.

During the course of disinfection, I may ask you to fix a program that you wish to retain. Please post back to inform me.


+++ WARNING +++

You are running HijackThis from an inappropriate location. It should be run from a permanent folder. This program creates backup files which we may need to use later. If the program is in a temporary folder, important backups may be accidentally deleted.
  1. Please go into Windows Explorer
  2. Click on C:\
  3. Click on File > New > Folder
  4. Call it HJT, or another name of your choice.
  5. Move all files to the newly created folder.


Enable the viewing of Hidden files

Windows XP/2000

Go to My Computer > Tools > Folder Options > View tab & ensure that the following are enabled;
  • Show hidden files and folders.
  • Display the contents of system folders
  • Uncheck the Hide protected operating system files option.

===============

Download & install CleanUp!. We'll run it later

Download KillBox v2.0.0.175 & save to desktop

Download rkfiles.zip and unzip the contents to a new folder on your desktop.

Download the remv3.zip at http://forums.skads.org/index.php?showtopic=80 (look for the attachment to download). Make a new folder on the root drive C:\ and unzip remv3.zip files into it.

L2mfix - Download & Save to Desktop

This is a self extracting file. By double clicking on it, it will automatically extract it's contents to a new folder on Desktop.
  1. Close ALL other programs
  2. Double click L2mfix.exe.
  3. When prompted, answer "Accept"
  4. Then click the "Install" button to extract the files to a newly created folder named - L2mfix
  5. Open the L2mfix folder & double click L2mfix.bat
  6. Select option #2 for Run Fix by typing "2" and then press enter
  7. Press any key to reboot your computer.
After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, you will be presented with a log. Copy the contents of that log and paste it here, along with a new HJT log.

Please Do NOT run any other files in the l2mfix folder until you are told to


===============

Using KillBox

Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard.

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ndnu.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\vrvlmm.exe reg_run
  • Start KillBox.
  • Go to the File menu, and choose "Paste from Clipboard".
    Verify that you've done this properly by clicking the dropdown-arrow next to the "Full Path of File to Delete" field. The filenames you pasted will be found in there.
  • Select "Delete on Reboot", "End Explorer Shell While Killing File" & "Unregister.dll Before Deleting" if it's not grayed out.
  • Click the RED-and-white "Delete File" button.
  • Click "Yes" at the 'Delete on Reboot' prompt. Click "Yes" at the Pending Operations prompt.

* If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again.


===============

Reboot to Safe Mode
  1. Shut Windows down, and then turn off the computer.
  2. Restart the computer. The computer begins processing a set of instructions known as the Basic Input/Output System (BIOS). What is displayed depends on the BIOS manufacturer. Some computers display a progress bar that refers to the word BIOS, while others may not display any indication that this process is happening.
  3. As soon as the BIOS has finished loading, begin tapping the F8 key on your keyboard. Continue to do so until the
    Windows Advanced Options menu appears.
  4. Using the arrow keys on the keyboard, scroll to and select the Safe mode menu item, and then press Enter.

===============

Close all other windows & Run HiJackThis and click "Scan", then check(tick) the following, if present:

O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\vrvlmm.exe reg_run
O20 - Winlogon Notify: Explorer - C:\WINDOWS\system32\eps.dll


Click "Fix checked" for HJT to fix them

===============

Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
  1. Click "Options..."
  2. Move the arrow down to Custom CleanUp!
  3. Put a check next to the following:
    • Empty Recycle Bins
    • Delete Cookies
    • Delete Prefetch files
    • [X]Scan local drives for temporary files (Please uncheck this option)
    • Cleanup! All Users
  4. Click "OK"
  5. Press the "CleanUp!" button to start the program. Reboot/logoff when prompted.
* CleanUp! will delete all the files in your temp folders

Double click rkfiles.bat file to run it. It will scan for a while, so please be patient. Wait until the DOS window closes. Open the C:\log.txt it created and rename it log1.txt.

Now open the folder where you saved remv3.zip files and double click the rem.bat file and let it run. It will delete the files and remove the infection and then make a log of the files it finds. The log file will be C:\log.txt and bad1.txt

**Note** Each tool uses log.txt as it’s output file so make sure you save the entries from one tools log before running the other as it will overwrite the file if you don’t.


Post the contents of both the log.txt and log1.txt in your next post


===============

Reboot to Normal Mode.

Run a new HijackThis scan. Save the log file and run KRC HijackThis Analyzer in the same folder to get the result.txt log. Just post the contents of the result.txt file in your next reply.

In your next post, please include:
  • Copy of KRC HijackThis Analyzer log
  • L2MFix's log
  • Remv3 & rkfiles logs
__________________

Question - what have you done for the community today?
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-28-2005, 03:05 PM   #3 (permalink)
I helped the forums.
 
Join Date: Jun 2005
Posts: 9
OS: XP


Ok, thanks for your help! Using AVG now and firefox and moved hjt to its own folder......



Here is the Hijackthis Analyzer log:
====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 6/3/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 3:54:58 PM, on 6/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\system32\rkrlnn.exe
C:\Documents and Settings\Kary Nulisch\My Documents\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\rkrlnn.exe reg_run
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4101542B-4071-4B52-9F3A-7BCA44C1E791} (MarketTrader - ETrade v3.2a) - http://etrade.bridge.com/etgmt_prd/j...a_etrade_i.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-24.cab
O16 - DPF: {712D42CD-3513-473E-96E8-019C9AD78F1A} (MSN Money QuickList) - http://moneycentral.msn.com/cabs/webinst.exe
O16 - DPF: {963BE66B-121D-4E6C-BF9F-1A774D9A2E41} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupdate.exe
O16 - DPF: {D8A14CC1-B68A-11D6-B8FA-00C04F5E375A} (MarketTrader - Reuters v3.2a) - http://etrade.bridge.com/etgmt_prd/j..._reuters_i.cab
O23 - Service: Aluria Security Center Spyware Eliminator Service (ASCService) - Unknown owner - C:\PROGRA~1\ALURIA~1\ascserv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe


End of KRC HijackThis Analyzer Log.
====================================================================




Here is the L2MFix log:
L2Mfix 1.03

Running From:
C:\Documents and Settings\Kary Nulisch\Desktop\l2mfix



RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting registry permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Denying C(CI) access for predefined group "Administrators"
- adding new ACCESS DENY entry


Registry Permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting up for Reboot


Starting Reboot!

C:\Documents and Settings\Kary Nulisch\Desktop\l2mfix
System Rebooted!

Running From:
C:\Documents and Settings\Kary Nulisch\Desktop\l2mfix

killing explorer and rundll32.exe

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1796 'explorer.exe'
Killing PID 1796 'explorer.exe'
Killing PID 1796 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1872 'rundll32.exe'

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!
Backing Up: C:\WINDOWS\system32\APLEDIT.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\APLEDIT.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\bdpanui.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\bdpanui.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CDL3D32.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CDL3D32.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dqrgui.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dqrgui.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\eps.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\eps.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\jSvart.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\jSvart.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\msqm.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\msqm.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\guard.tmp
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\guard.tmp
1 file(s) copied.
deleting: C:\WINDOWS\system32\APLEDIT.DLL
Successfully Deleted: C:\WINDOWS\system32\APLEDIT.DLL
deleting: C:\WINDOWS\system32\APLEDIT.DLL
Successfully Deleted: C:\WINDOWS\system32\APLEDIT.DLL
deleting: C:\WINDOWS\system32\bdpanui.dll
Successfully Deleted: C:\WINDOWS\system32\bdpanui.dll
deleting: C:\WINDOWS\system32\bdpanui.dll
Successfully Deleted: C:\WINDOWS\system32\bdpanui.dll
deleting: C:\WINDOWS\system32\CDL3D32.DLL
Successfully Deleted: C:\WINDOWS\system32\CDL3D32.DLL
deleting: C:\WINDOWS\system32\CDL3D32.DLL
Successfully Deleted: C:\WINDOWS\system32\CDL3D32.DLL
deleting: C:\WINDOWS\system32\dqrgui.dll
Successfully Deleted: C:\WINDOWS\system32\dqrgui.dll
deleting: C:\WINDOWS\system32\dqrgui.dll
Successfully Deleted: C:\WINDOWS\system32\dqrgui.dll
deleting: C:\WINDOWS\system32\eps.dll
Successfully Deleted: C:\WINDOWS\system32\eps.dll
deleting: C:\WINDOWS\system32\eps.dll
Successfully Deleted: C:\WINDOWS\system32\eps.dll
deleting: C:\WINDOWS\system32\jSvart.dll
Successfully Deleted: C:\WINDOWS\system32\jSvart.dll
deleting: C:\WINDOWS\system32\jSvart.dll
Successfully Deleted: C:\WINDOWS\system32\jSvart.dll
deleting: C:\WINDOWS\system32\msqm.dll
Successfully Deleted: C:\WINDOWS\system32\msqm.dll
deleting: C:\WINDOWS\system32\msqm.dll
Successfully Deleted: C:\WINDOWS\system32\msqm.dll
deleting: C:\WINDOWS\system32\guard.tmp
Successfully Deleted: C:\WINDOWS\system32\guard.tmp
deleting: C:\WINDOWS\system32\guard.tmp
Successfully Deleted: C:\WINDOWS\system32\guard.tmp


Zipping up files for submission:
adding: APLEDIT.DLL (164 bytes security) (deflated 48%)
adding: bdpanui.dll (164 bytes security) (deflated 48%)
adding: CDL3D32.DLL (164 bytes security) (deflated 48%)
adding: dqrgui.dll (164 bytes security) (deflated 48%)
adding: eps.dll (164 bytes security) (deflated 48%)
adding: jSvart.dll (164 bytes security) (deflated 48%)
adding: msqm.dll (164 bytes security) (deflated 48%)
adding: guard.tmp (164 bytes security) (deflated 48%)
adding: clear.reg (164 bytes security) (deflated 22%)
adding: echo.reg (164 bytes security) (deflated 9%)
adding: direct.txt (164 bytes security) (stored 0%)
adding: lo2.txt (164 bytes security) (deflated 83%)
adding: readme.txt (164 bytes security) (deflated 49%)
adding: test.txt (164 bytes security) (deflated 84%)
adding: test2.txt (164 bytes security) (stored 0%)
adding: test3.txt (164 bytes security) (stored 0%)
adding: test5.txt (164 bytes security) (stored 0%)
adding: xfind.txt (164 bytes security) (deflated 80%)
adding: backregs/C68BF954-5C67-460A-BF56-6704F35E91A7.reg (164 bytes security) (deflated 70%)
adding: backregs/shell.reg (164 bytes security) (deflated 74%)

Restoring Registry Permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Revoking access for predefined group "Administrators"
Inherited ACE can not be revoked here!
Inherited ACE can not be revoked here!


Registry permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


Restoring Sedebugprivilege:

Granting SeDebugPrivilege to Administrators ... successful

deleting local copy: APLEDIT.DLL
deleting local copy: APLEDIT.DLL
deleting local copy: bdpanui.dll
deleting local copy: bdpanui.dll
deleting local copy: CDL3D32.DLL
deleting local copy: CDL3D32.DLL
deleting local copy: dqrgui.dll
deleting local copy: dqrgui.dll
deleting local copy: eps.dll
deleting local copy: eps.dll
deleting local copy: jSvart.dll
deleting local copy: jSvart.dll
deleting local copy: msqm.dll
deleting local copy: msqm.dll
deleting local copy: guard.tmp
deleting local copy: guard.tmp

The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]


The following are the files found:
****************************************************************************
C:\WINDOWS\system32\APLEDIT.DLL
C:\WINDOWS\system32\APLEDIT.DLL
C:\WINDOWS\system32\bdpanui.dll
C:\WINDOWS\system32\bdpanui.dll
C:\WINDOWS\system32\CDL3D32.DLL
C:\WINDOWS\system32\CDL3D32.DLL
C:\WINDOWS\system32\dqrgui.dll
C:\WINDOWS\system32\dqrgui.dll
C:\WINDOWS\system32\eps.dll
C:\WINDOWS\system32\eps.dll
C:\WINDOWS\system32\jSvart.dll
C:\WINDOWS\system32\jSvart.dll
C:\WINDOWS\system32\msqm.dll
C:\WINDOWS\system32\msqm.dll
C:\WINDOWS\system32\guard.tmp
C:\WINDOWS\system32\guard.tmp

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{C68BF954-5C67-460A-BF56-6704F35E91A7}"=-
[-HKEY_CLASSES_ROOT\CLSID\{C68BF954-5C67-460A-BF56-6704F35E91A7}]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************
****************************************************************************




Here is the RKFILE log:
C:\rkf

PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Files Found in system Folder............
------------------------
C:\WINDOWS\SYSTEM32\AUNPS2.dll: UPX!
C:\WINDOWS\SYSTEM32\supdate.dll: UPX!

Files Found in all users startup Folder............
------------------------
Files Found in all users windows Folder............
------------------------
Finished
bye



Here is the REMV3 log:The batch is run from -- C:\remv3

Files Found.................
----------------------------------------

Files Not deleted.................
----------------------------------------

Merging registry entries
-----------------------------------------------------------------
The Registry Entries Found...
-----------------------------------------------------------------


Other bad files to be Manually deleted.. Please note that this might also list legit Files, be careful while deleting
-----------------------------------------------------------------
Volume in drive C has no label.
Volume Serial Number is 48B0-ECB2

Directory of C:\WINDOWS\SYSTEM32

msi.dll
Finished
lastbird is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-28-2005, 03:22 PM   #4 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,480
OS: N/A


Run a scan with HiJackThis & select(tick) the following & click "Fix checked" :

O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\rkrlnn.exe reg_run

~~~~~~~~~~~~~~~

Using KillBox

Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard.
  • C:\WINDOWS\system32\rkrlnn.exe
    C:\WINDOWS\SYSTEM32\AUNPS2.dll
    C:\WINDOWS\SYSTEM32\supdate.dll

Start KillBox.
  1. Go to the File menu, and choose "Paste from Clipboard".
    Verify that you've done this properly by clicking the dropdown-arrow next to the "Full Path of File to Delete" field. The filenames you pasted will be found in there.
  2. Select/tick the following:
    • "Delete on Reboot"
    • "End Explorer Shell While Killing File"
    • "Unregister.dll Before Deleting" if it's not grayed out.
  3. Click the RED X button.
  4. Click "Yes" at the 'Delete on Reboot' prompt. Click "Yes" at the Pending Operations prompt.

* If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try Killbox again.


~~~~~~~~~~~~~~~

After the reboot, do another scan with HiJackThis & check if this entry exist..
O4 - HKLM\..\Run: [KavSvc]
If it's gone, post that HJT log in your next reply.
Otherwise, we need to use a different program to scan for any trojans that may exist.

Download TDS-3 - & Install.
Close it after you have finished installation.
Download & overwrite the existing file - "radius.td3", located in folder >> C:\Program Files\TDS-3\ with this file
  • Launch TDS-3 & it will scan your memory for running processes. This will take less than 30 seconds.
  • Go to "System Testing" on the menu bar & select "Full System Scan".
  • After it has finished scanning, Select & Copy everything on the top pane into your next post.
  • If present, right click on any entry listed in the lower pane & select "Save as text".. This will create a logfile named scandump.txt in TDS-3's folder - post that in your next reply.
__________________

Question - what have you done for the community today?
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-28-2005, 05:18 PM   #5 (permalink)
I helped the forums.
 
Join Date: Jun 2005
Posts: 9
OS: XP


The KavSvc was still there after deleting those files....here is the result from the top pane of the TD3 run....

17:21:14 [Init] Trojan Defence Suite v3.2.0 (UNLICENSED)
17:21:14 [Init] Started 28-06-05 17:21:14 Central Standard Time (UTC: 6), Internet Time @973.08
17:21:14 [Init] Loading TDS-3 Systems ...
17:21:14 [Init] Token successfully adjusted.
17:21:14 [Init] • TDS Privileges : OK. Adjusted TDS-3 token privileges to maximum
17:21:15 [Init] • Plugins : OK. Loaded 13
17:21:15 [Init] • Exec Protection : Not Installed
17:21:15 [Init] WARNING: Your Radius.TD3 database needs to be updated!
17:21:15 [Init] Please download the latest from http://tds.diamondcs.com.au/radius.td3
17:21:15 [Init] Licensed users can use the Update facility from the TDS menu
17:21:15 [Init] Loading Radius Advanced Scanning Systems ... <R3 Engine, DCS Labs>
17:21:25 [Init] • Radius Advanced Specialist Extensions on standby for 13 trojan families
17:21:25 [Init] • Systems Initialised [59325 references - 31553 primaries/15456 traces/12316 variants/other]
17:21:25 [Init] Radius Systems loaded. <Databases updated 28-06-2005>
17:21:25 [Init] TDS-3 Ready. <Kary nulisch@192.168.2.2, 127.0.0.1 - United States>
17:21:25 [Tip Of The Day] If your machine has minimal resources, run minimal sockets! Sockets can be relatively expensive in terms of resources.
17:21:25 [TDS] Good evening Kary nulisch. Time to stop working!
17:21:30 [Mutex Memory Scan] Started...
17:21:32 [Mutex Memory Scan] Finished (no trojan mutexes found).
17:21:32 [TDS-3] This is an EVALUATION demo of TDS-3. Please see the help file for help on registering.
17:21:51 [CRC32] Started - verifying 29 files ...
17:21:52 [CRC32] File doesn't exist: C:\autoexec.bat
17:22:09 [CRC32] Test finished.
17:23:10 [Memory Scan] Memory scan started, please wait a moment ...
17:23:11 [Memory Scan] Memory scan complete.
17:23:11 [Mutex Memory Scan] Started...
17:23:12 [Mutex Memory Scan] Finished (no trojan mutexes found).
17:23:12 [Trace Scan] Started...
17:23:18 [Trace Scan] Finished.
17:23:18 [ServiceScan] Scanning for services and drivers ...
17:23:27 [ServiceScan] Scanned 355 services and drivers.
17:23:27 [File Scan] Scanning in C:\ ...
17:24:43 [Locked File] Couldn't open c:\documents and settings\kary nulisch\desktop\backups\backup-20050627-101324-131-ndnu.exe for read access, file is locked
17:25:03 [Locked File] Couldn't open c:\documents and settings\kary nulisch\my documents\hjt\backups\backup-20050628-143658-276-ndnu.exe for read access, file is locked
17:52:41 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp647\a0028231.exe for read access, file is locked
17:52:44 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp648\a0028260.exe for read access, file is locked
17:52:44 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp648\a0028263.exe for read access, file is locked
17:52:45 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp648\a0028275.exe for read access, file is locked
17:52:53 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp648\a0028348.exe for read access, file is locked
17:53:01 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp648\a0028444.exe for read access, file is locked
17:53:02 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp648\a0028459.exe for read access, file is locked
17:53:06 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp649\a0028484.exe for read access, file is locked
17:53:21 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp649\a0028651.exe for read access, file is locked
17:53:26 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp650\a0028733.exe for read access, file is locked
17:53:31 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp650\a0028950.exe for read access, file is locked
17:53:32 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp650\a0028989.exe for read access, file is locked
17:53:34 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp650\a0028993.exe for read access, file is locked
17:53:34 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp650\a0028994.exe for read access, file is locked
17:53:35 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp650\a0029021.exe for read access, file is locked
17:53:36 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp650\a0029034.exe for read access, file is locked
17:53:42 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0029209.exe for read access, file is locked
17:53:42 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0029210.exe for read access, file is locked
17:53:42 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0029211.exe for read access, file is locked
17:53:46 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0030283.exe for read access, file is locked
17:53:47 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0030290.exe for read access, file is locked
17:53:47 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0030291.exe for read access, file is locked
17:53:48 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0030316.exe for read access, file is locked
17:53:50 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0030336.exe for read access, file is locked
17:53:50 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0030345.exe for read access, file is locked
17:53:54 [Locked File] Couldn't open c:\windows\appbs.exe for read access, file is locked
17:53:54 [Locked File] Couldn't open c:\windows\atlhr32.exe for read access, file is locked
17:53:55 [Locked File] Couldn't open c:\windows\crdk32.exe for read access, file is locked
17:53:58 [Locked File] Couldn't open c:\windows\mfcpk32.exe for read access, file is locked
17:53:58 [Locked File] Couldn't open c:\windows\netrc.exe for read access, file is locked
17:54:01 [Locked File] Couldn't open c:\windows\ntoy.exe for read access, file is locked
17:54:01 [Locked File] Couldn't open c:\windows\ntyr.exe for read access, file is locked
17:54:05 [Locked File] Couldn't open c:\windows\winii.exe for read access, file is locked
18:08:24 [Locked File] Couldn't open c:\windows\system32\crqh32.exe for read access, file is locked
18:08:30 [Locked File] Couldn't open c:\windows\system32\d3qt32.exe for read access, file is locked
18:11:29 [Locked File] Couldn't open c:\windows\system32\wingu32.exe for read access, file is locked
18:14:10 [File Scan] Scanned 60793 files: 43 alarms in 3043.449 seconds (Avg 20.98 files/sec)
18:14:10 [File Scan] Scanning in D:\ ...
18:14:10 [File Scan] Scanned 0 files: 43 alarms in 0 seconds (Avg -1.#IND files/sec)
18:14:10 [Scan] Finished.





Here is the scandump.txt text....
Scan Control Dumped @ 18:16:59 28-06-05
RegVal Trace: Suspicious: HKEY_LOCAL_MACHINE
File: Software\Microsoft\Windows\CurrentVersion\Run [KavSvc=C:\WINDOWS\system32\rkrlnn.exe reg_run]

Suspicious Filename: Dual extensions
File: c:\documents and settings\kary nulisch\desktop\firefox setup 1.0.4.exe

Positive identification (DLL): Adware.SmartPops.d (dll)
File: c:\documents and settings\kary nulisch\desktop\backups\backup-20050623-204119-997.dll

Suspicious Filename: Dual extensions
File: c:\documents and settings\kary nulisch\desktop\downloads\dcplusplus-0.304.exe

Positive identification: TrojanDownloader.Win32.Small.abd
File: c:\program files\aluria security center\backup\qfle06252005150323563232.pwn

Positive identification (DLL): TrojanClicker.Win32.Agent.dh (dll)
File: c:\program files\aluria security center\backup\qfle06262005205250092899.pwn

Positive identification: Adware.VirtualBouncer.i
File: c:\program files\aluria security center\backup\qmem06252005065854215337.pwn

Positive identification (DLL): TrojanClicker.Win32.Small.ez (dll)
File: c:\program files\aluria security center\backup\qmem0626200506562055585.pwn

Positive identification (DLL): TrojanClicker.Win32.Agent.dh (dll)
File: c:\program files\aluria security center\backup\qmem06262005205250092749.pwn

Positive identification (DLL): Adware.WinAD.aj (dll)
File: c:\program files\yahoo!\ypsr\quarantine\ppqf3.tmp\mediaaccc.dll

Positive identification <Adv>: Possible WebDownloader
File: c:\program files\yahoo!\ypsr\quarantine\ppqf3.tmp\mediaaccess.exe

Positive identification (embedded in file): Adware.BetterInternet.d1
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp646\a0028141.dll

Positive identification (DLL): Adware.BetterInternet.d (dll)
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp646\a0028141.dll

Positive identification (embedded in file): Adware.BetterInternet.d1
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp647\a0028194.dll

Positive identification (DLL): Adware.BetterInternet.d (dll)
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp647\a0028194.dll

Positive identification: Adware.BetterInternet.d1
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp647\a0028207.exe

Positive identification (embedded in file): Adware.BetterInternet.d1
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp647\a0028208.dll

Positive identification (DLL): Adware.BetterInternet.d (dll)
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp647\a0028208.dll

Positive identification: Adware.BookedSpace.e Dropper
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028262.exe

Positive identification (embedded in file): Adware.BetterInternet.d1
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028284.dll

Positive identification (DLL): Adware.BetterInternet.d (dll)
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028284.dll

Positive identification (DLL): Adware.Exact.d (dll)
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028288.dll

Positive identification: Adware.VirtualBouncer.i
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028354.exe

Positive identification: Adware.VirtualBouncer.j Dropper.a
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028435.exe

Positive identification: Adware.VirtualBouncer.j Dropper.b
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028436.exe

Positive identification: Adware.VirtualBouncer Dropper
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028438.exe

Positive identification: TrojanDownloader.Win32.Wintool.e1
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028445.exe

Positive identification: Adware.DelphinMedia.Viewer.f
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028451.exe

Positive identification (DLL): Adware.DelphinMedia.Viewer.f (dll)
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028452.dll

Suspicious Filename: HTA file in suspicious location
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp649\a0028610.hta

Positive identification: Adware.BargainBuddy.w
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp651\a0029201.exe

Positive identification: Adware.BargainBuddy.p
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp651\a0029202.exe

Positive identification: Adware.CashBack.b
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp651\a0029203.exe

Positive identification: Adware.CashBack.d
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp651\a0029204.exe

Positive identification (DLL): Adware.Exact.d (dll)
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp651\a0029207.dll

Positive identification (DLL): TrojanDownloader.Win32.Agent.bc12 (dll)
File: c:\windows\javalb32.dll2

Positive identification: Trojan.Win32.Zapchast.b
File: c:\windows\launchurl.exe

Positive identification: Adware.MediaMotor
File: c:\windows\unstall.exe

Positive identification (embedded in file): Adware.SmartPops.d (dll)
File: c:\windows\cdmweb\vpambelutv.exe

Positive identification (DLL): TrojanClicker.Win32.Agent.dh (dll)
File: c:\windows\system32\d0ce0c16b1.dll

Positive identification (DLL): TrojanDownloader.Win32.Agent.bc12 (dll)
File: c:\windows\system32\syslq.dll2

Suspicious Filename: Dual extensions
File: c:\windows\system32\shellext\rs.exe.exe

Positive identification: Adware.DelphinMediaViewer.f
File: c:\windows\system32\vidctrl\vidctrl.exe
lastbird is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-28-2005, 10:28 PM   #6 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,480
OS: N/A


Using KillBox

Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard.
  • C:\windows\javalb32.dll2
    C:\windows\launchurl.exe
    C:\windows\unstall.exe
    C:\windows\cdmweb\vpambelutv.exe
    C:\windows\system32\d0ce0c16b1.dll
    C:\windows\system32\syslq.dll2
    C:\windows\system32\shellext\rs.exe.exe
    C:\windows\system32\vidctrl\vidctrl.exe
    c:\windows\appbs.exe
    c:\windows\atlhr32.exe
    c:\windows\crdk32.exe
    c:\windows\mfcpk32.exe
    c:\windows\netrc.exe
    c:\windows\ntoy.exe
    c:\windows\ntyr.exe
    c:\windows\winii.exe
    c:\windows\system32\crqh32.exe
    c:\windows\system32\d3qt32.exe
    c:\windows\system32\wingu32.exe
    C:\WINDOWS\system32\rkrlnn.exe

Start KillBox.
  1. Go to the File menu, and choose "Paste from Clipboard".
    Verify that you've done this properly by clicking the dropdown-arrow next to the "Full Path of File to Delete" field. The filenames you pasted will be found in there.
  2. Select/tick the following:
    • "Delete on Reboot"
    • "End Explorer Shell While Killing File"
    • "Unregister.dll Before Deleting" if it's not grayed out.
  3. Click the RED X button.
  4. Click "Yes" at the 'Delete on Reboot' prompt. Click "Yes" at the Pending Operations prompt.

* If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

~~~~~~~~~~~~~~~

Reboot & Do an online scan at one of the following sites:Take note the names and locations of any file it detects but fails to clean.

* Turn off the real time scanner of any existing antivirus program while performing the online scan


Reboot Again & Run a new scan with HiJackThis. Save the log file and run KRC HiJackThis Analyzer in the same folder to get the result.txt log. Just post the contents of the result.txt file in your next reply.

In your next post, please include:
  • Copy of KRC HiJackThis Analyzer log
  • List of files that online scans failed to disinfect

Tell me how your computer is behaving now
__________________

Question - what have you done for the community today?

Last edited by sUBs; 06-28-2005 at 10:29 PM.
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-29-2005, 07:19 AM   #7 (permalink)
I helped the forums.
 
Join Date: Jun 2005
Posts: 9
OS: XP


Here is the KVC result.txt and the results of the TrendMicro scan/clean....TrendMicro found 76 viruses and a trojan...it could only clean one or two so I chose the delete option. Prior to the TrendMicro run the mouse would barely work...it is working better now. Also, I had to open up IE to run TrendMicro.

====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 6/3/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 8:15:14 AM, on 6/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\system32\rkrlnn.exe
C:\Documents and Settings\Kary Nulisch\My Documents\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\rkrlnn.exe reg_run
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4101542B-4071-4B52-9F3A-7BCA44C1E791} (MarketTrader - ETrade v3.2a) - http://etrade.bridge.com/etgmt_prd/j...a_etrade_i.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-24.cab
O16 - DPF: {712D42CD-3513-473E-96E8-019C9AD78F1A} (MSN Money QuickList) - http://moneycentral.msn.com/cabs/webinst.exe
O16 - DPF: {963BE66B-121D-4E6C-BF9F-1A774D9A2E41} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupdate.exe
O16 - DPF: {D8A14CC1-B68A-11D6-B8FA-00C04F5E375A} (MarketTrader - Reuters v3.2a) - http://etrade.bridge.com/etgmt_prd/j..._reuters_i.cab
O23 - Service: Aluria Security Center Spyware Eliminator Service (ASCService) - Unknown owner - C:\PROGRA~1\ALURIA~1\ascserv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe


End of KRC HijackThis Analyzer Log.
====================================================================





Results:
We have detected 27 infected file(s) with 76 virus(es) on your computer. Only 0 out of 0 infected files are displayed.

Delete files if clean action is not successful
Detected File Associated Virus Name Action
C:\Documents and Settings\Kary Nulisch\.jpi_cache\file\1.0\SecurityClassLoader.class-52260159-1a6514f0.classUncleanable HTML_COOLWEB.A DeletePass
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\a.jar-6bb41746-59b25523.zip DeletePass
- a.classUncleanable JAVA_BYTEVER.A
- Dummy.classUncleanable JAVA_BYTEVER.A
- VerifierBug.classUncleanable JAVA_BYTEVER.A
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\ar2.jar-741bd86b-29a3b00a.zip DeletePass
- B.classUncleanable JAVA_CLOADER.E
- V.classUncleanable JAVA_BYTEVER.A
- Dummy.classUncleanable JAVA_BYTEVER.A
- A.classUncleanable JAVA_CLOADER.E
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\ar3.jar-3ae82c1c-6701e022.zip DeletePass
- Counter.classUncleanable JAVA_FEMAD.B
- VerifierBug.classUncleanable JAVA_BYTEVER.A-1
- Gummy.classUncleanable JAVA_BYTEVER.A-1
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\ar3.jar-51b26348-1e457a03.zip DeletePass
- Gummy.classUncleanable JAVA_BYTEVER.A-1
- Counter.classUncleanable JAVA_BYTEVER.A-1
- VerifierBug.classUncleanable JAVA_BYTEVER.A-1
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\ar3.jar-5ef20017-26a74551.zip DeletePass
- Gummy.classUncleanable JAVA_BYTEVER.A-1
- Counter.classUncleanable JAVA_BYTEVER.A-1
- VerifierBug.classUncleanable JAVA_BYTEVER.A-1
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\ar3.jar-7429efec-7e7ab5be.zip DeletePass
- Gummy.classUncleanable JAVA_BYTEVER.A-1
- Counter.classUncleanable JAVA_BYTEVER.A-1
- VerifierBug.classUncleanable JAVA_BYTEVER.A-1
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\archive.jar-487b52a0-180053cd.zip DeletePass
- rundll32.exeUncleanable TROJ_STARTPGE.BG
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\classload.jar-11faa9ed-278f4239.zip DeletePass
- GetAccess.classUncleanable JAVA_BYTEVER.A
- InsecureClassLoader.classUncleanable JAVA_BYTEVER.A
- Dummy.classUncleanable JAVA_BYTEVER.A
- Installer.classUncleanable JAVA_BYTEVER.A
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\classload.jar-1f5b6b54-35e6d148.zip DeletePass
- GetAccess.classUncleanable JAVA_BYTEVER.A
- InsecureClassLoader.classUncleanable JAVA_BYTEVER.A
- Dummy.classUncleanable JAVA_BYTEVER.A
- Installer.classUncleanable JAVA_BYTEVER.A
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\clsld.jar-455f8b8a-51e4e624.zip DeletePass
- GetAccess.classUncleanable JAVA_BYTEVER.A
- InsecureClassLoader.classUncleanable JAVA_BYTEVER.A
- Dummy.classUncleanable JAVA_BYTEVER.A
- Installer.classUncleanable JAVA_BYTEVER.A
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\count.jar-314758c1-3f1e4a79.zip DeletePass
- BlackBox.classUncleanable JAVA_BYTEVER.A
- Dummy.classUncleanable JAVA_BYTEVER.A
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\count.jar-4d094f47-3c51652d.zip DeletePass
- BlackBox.classUncleanable JAVA_BYTEVER.A
- Dummy.classUncleanable JAVA_BYTEVER.A
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\count1.jar-4888e0ab-43297f3e.zip DeletePass
- BlackBox.classUncleanable JAVA_BYTEVER.A
- Dummy.classUncleanable JAVA_BYTEVER.A
- VerifierBug.classUncleanable JAVA_BYTEVER.A
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\counter.jar-4b1d7eab-22580f5f.zip DeletePass
- BB.classUncleanable JAVA_BYTEVER.A
- VerifierBug.classUncleanable JAVA_BYTEVER.A
- Dummy.classUncleanable JAVA_BYTEVER.A
- BeyondInterface.classUncleanable JAVA_BYTEVER.A
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\counter.jar-5b38b92d-5e736831.zip DeletePass
- Beyond.classUncleanable JAVA_BYTEVER.A
- counter.classUncleanable JAVA_BYTEVER.A
- Dummy.classUncleanable JAVA_BYTEVER.A
- VerifierBug.classUncleanable JAVA_BYTEVER.A
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\counter.jar-7271642a-69dc6e66.zip DeletePass
- counter.classUncleanable JAVA_BYTEVER.A
- Dummy.classUncleanable JAVA_BYTEVER.A
- VerifierBug.classUncleanable JAVA_BYTEVER.A
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\loader.jar-288a6362-22141f3d.zip DeletePass
- Counter.classUncleanable JAVA_BYTEVER.C
- Dummy.classUncleanable JAVA_BYTEVER.A
- Parser.classUncleanable JAVA_BYTEVER.A
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\loaderadv74.jar-170b188f-6fffaf4d.zip DeletePass
- Counter.classUncleanable JAVA_BYTEVER.C
- Dummy.classUncleanable JAVA_BYTEVER.A
- Parser.classUncleanable JAVA_BYTEVER.A
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\loaderdmitriy.jar-798e87d9-7b110fc5.zip DeletePass
- Counter.classUncleanable JAVA_BYTEVER.C
- Dummy.classUncleanable JAVA_BYTEVER.A
- Parser.classUncleanable JAVA_BYTEVER.A
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\nude.jar-30e3d4e0-1dfc8d34.zip DeletePass
- NudeBox.classUncleanable JAVA_BYTEVER.A
- VerifierBug.classUncleanable JAVA_BYTEVER.A
- Dummy.classUncleanable JAVA_BYTEVER.A
- Beyond.classUncleanable JAVA_BYTEVER.A
- Worker.classUncleanable JAVA_BYTEVER.A
- msdos.exeUncleanable BKDR_RSBOT.A
- explorer.exeUncleanable TROJ_SHELEX.A
C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\WebCounter.jar-12a49c8f-75e498fd.zip DeletePass
- Dummy.classUncleanable JAVA_BYTEVER.A
- VerifierBug.classUncleanable JAVA_BYTEVER.A
- WebCounter.classUncleanable JAVA_BYTEVER.A
- a.classUncleanable JAVA_BYTEVER.A
C:\Program Files\Aluria Security Center\Backup\QFle0624200515531215718.pwnUncleanable TROJ_HARNIG.Z DeletePass
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP648\A0028298.exeUncleanable TROJ_HARNIG.Z DeletePass
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP652\A0030441.exeUncleanable TROJ_DLOADER.OT DeletePass
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP652\A0030443.exeUncleanable TROJ_ZAPCHAST.J DeletePass
C:\WINDOWS\SYSTEM32\secure32.txt JS_STARTPAG.AD CleanDeletePass




Trojan/Worm Check 1 worm/Trojan horse detected

What we checked:
Malicious activity by a Trojan horse program. Although a Trojan seems like a harmless program, it contains malicious code and once installed can cause damage to your computer.
Results:
We have detected 1 Trojan horse program(s) and worm(s) on your computer. Only 0 out of 0 Trojan horse programs and worms are displayed.
Trojan/Worm Name Trojan/Worm Type Action
TROJ_SMALL-1 Trojan DeletePass
lastbird is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-29-2005, 11:34 AM   #8 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,480
OS: N/A


It's still there. Something is still holding it in place. Let's take another whack at it & then do another round of online scans.
  1. Run KillBox. Paste the following locations into KillBox one at a time :
    • C:\WINDOWS\system32\rkrlnn.exe
  2. Checkmark the following boxes :
    • Delete on Reboot
    • End Explorer Shell While Killing File
    • Unregister DLL (If available)
  3. Click the RED X button and
    • Answer "YES" when asked to confirm file deletion
    • Answer "YES" when prompted to reboot now


Upon reboot, Do an online scan at Panda
Take note the names and locations of any file it detects but fails to clean.

Post that with a fresh copy of HJT log in your next reply
__________________

Question - what have you done for the community today?
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-29-2005, 12:29 PM   #9 (permalink)
I helped the forums.
 
Join Date: Jun 2005
Posts: 9
OS: XP


Yep, Killbox couldn't get it again. Here is the log from Panda:


Adware:Adware/AdBehavior No disinfected C:\WINDOWS\system32\reryoou.dll
Adware:Adware/AdBehavior No disinfected C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ndnu.exe
Adware:Adware/AdBehavior No disinfected C:\WINDOWS\system32\rkrlnn.exe
Adware:Adware/AdBehavior No disinfected C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ndnu.exe
Spyware:Spyware/AdClicker No disinfected C:\WINDOWS\usta32.ini
Spyware:Spyware/Dyfuca No disinfected Windows Registry
Adware:Adware/BookedSpace No disinfected C:\WINDOWS\cfgmgr52.dll
Adware:Adware/WinTools No disinfected Windows Registry
Spyware:Spyware/TVMedia No disinfected C:\Documents and Settings\Kary Nulisch\Application Data\tvm*.dll
Adware:Adware/MediaTickets No disinfected Windows Registry
Adware:Adware/IPInsight No disinfected C:\WINDOWS\inf\polall1r.inf
Adware:Adware/DealHelper No disinfected Windows Registry
Adware:Adware/PowerSearch No disinfected C:\WINDOWS\system32\stlb2.xml
Adware:Adware/Novo No disinfected Windows Registry
Adware:Adware/AdBehavior No disinfected C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ndnu.exe
Spyware:Spyware/TVMedia No disinfected C:\Documents and Settings\Kary Nulisch\Application Data\tvmcwrd.dll
Adware:Adware/nCase No disinfected C:\Documents and Settings\Kary Nulisch\Desktop\backups\backup-20050623-204119-787.inf
Adware:Adware/Novo No disinfected C:\Documents and Settings\Kary Nulisch\Desktop\backups\backup-20050623-204119-997.dll
Adware:Adware/AdBehavior No disinfected C:\Documents and Settings\Kary Nulisch\Desktop\backups\backup-20050626-193800-357-ndnu.exe
Adware:Adware/BrowserAid No disinfected C:\Program Files\Aluria Security Center\Backup\QFle06262005205250092899.pwn
Adware:Adware/VirtualBouncer No disinfected C:\Program Files\Aluria Security Center\Backup\QMem06252005065854215337.pwn
Adware:Adware/BrowserAid No disinfected C:\Program Files\Aluria Security Center\Backup\QMem06262005205250092749.pwn
Adware:Adware/Startpage.CEH No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\20041124153815.zip[hosts]
Adware:Adware/DelFinMedia No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\20050627090816.zip[RemoveDisplayUtility.exe]
Adware:Adware/WinAD No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppqF3.tmp\MediaAccC.dll
Adware:Adware/WinAD No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppqF3.tmp\MediaAccess.exe
Adware:Adware/WinAD No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppqF3.tmp\MediaAccK.exe
Adware:Adware/BookedSpace No disinfected C:\WINDOWS\cfgmgr52.dll
Adware:Adware/Transponder No disinfected C:\WINDOWS\INF\polall1r.inf
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\UpdInst.exe
Adware:Adware/AdBehavior No disinfected C:\WINDOWS\SYSTEM32\pqpgb.dat
Adware:Adware/AdBehavior No disinfected C:\WINDOWS\SYSTEM32\reryoou.dll
Adware:Adware/AdBehavior No disinfected C:\WINDOWS\SYSTEM32\rkrlnn.exe
Virus:Trj/Harnig.M Disinfected C:\WINDOWS\SYSTEM32\secure32.RB0
Adware:Adware/Startpage.CBL No disinfected C:\WINDOWS\SYSTEM32\secure33.txt
Adware:Adware/PowerSearch No disinfected C:\WINDOWS\SYSTEM32\stlb2.xml
Adware:Adware/AdBehavior No disinfected C:\WINDOWS\SYSTEM32\urugq.dll
Spyware:Spyware/AdClicker No disinfected C:\WINDOWS\usta32.ini
lastbird is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-29-2005, 01:20 PM   #10 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,480
OS: N/A


The Panda scan manage to uncover some interesting results..

We should be a bit more lucky this time round..

~~~~~~~~~~~~~~~~~~~

KillBox these..
C:\WINDOWS\system32\reryoou.dll
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ndnu.exe
C:\WINDOWS\system32\rkrlnn.exe
C:\WINDOWS\cfgmgr52.dll
C:\Documents and Settings\Kary Nulisch\Application Data\tvm*.dll
C:\WINDOWS\inf\polall1r.inf
C:\WINDOWS\system32\stlb2.xml
C:\Documents and Settings\Kary Nulisch\Application Data\tvmcwrd.dll
C:\WINDOWS\cfgmgr52.dll
C:\WINDOWS\SYSTEM\UpdInst.exe
C:\WINDOWS\SYSTEM32\pqpgb.dat
C:\WINDOWS\SYSTEM32\secure32.RB0
C:\WINDOWS\SYSTEM32\secure33.txt
C:\WINDOWS\SYSTEM32\urugq.dll
C:\WINDOWS\usta32.ini
~~~~~~~~~~~~~~~~~~

After you have rebooted, we need to download an additional tool for another infection which Panda uncovered.

L2mfix - Download & Save to Desktop

This is a self extracting file. By double clicking on it, it will automatically extract it's contents to a new folder on Desktop.
  1. Close ALL other programs
  2. Double click L2mfix.exe.
  3. When prompted, answer "Accept"
  4. Then click the "Install" button to extract the files to a newly created folder named - L2mfix
  5. Open the L2mfix folder & double click L2mfix.bat
  6. Select option #2 for Run Fix by typing "2" and then press enter
  7. Press any key to reboot your computer.
After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, you will be presented with a log. Copy the contents of that log and paste it here, along with a new HJT log.

Please Do NOT run any other files in the l2mfix folder until you are told to

Note: Please do a search of this folder - C:\Documents and Settings\Kary Nulisch\Application Data\. Try locating files with names similar to this - tvm*.dll. Post your findings in the next reply
__________________

Question - what have you done for the community today?

Last edited by sUBs; 06-29-2005 at 01:23 PM.
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-29-2005, 01:46 PM   #11 (permalink)
I helped the forums.
 
Join Date: Jun 2005
Posts: 9
OS: XP


Looks like it's still there, below is the KRC log followed by the L2Mfix log.

I am cut/pasting one at a time in killbox and then rebooting after the last one is entered....

I cannot see any tvm*.dll files on my computer anywhere. Also, I tried to find that ndnu.exe file (thinking that is what it was attached to) and cannot find it in the directory specified either.





====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 6/3/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 2:42:35 PM, on 6/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Documents and Settings\Kary Nulisch\My Documents\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\rkrlnn.exe reg_run
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4101542B-4071-4B52-9F3A-7BCA44C1E791} (MarketTrader - ETrade v3.2a) - http://etrade.bridge.com/etgmt_prd/j...a_etrade_i.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-24.cab
O16 - DPF: {712D42CD-3513-473E-96E8-019C9AD78F1A} (MSN Money QuickList) - http://moneycentral.msn.com/cabs/webinst.exe
O16 - DPF: {963BE66B-121D-4E6C-BF9F-1A774D9A2E41} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupdate.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D8A14CC1-B68A-11D6-B8FA-00C04F5E375A} (MarketTrader - Reuters v3.2a) - http://etrade.bridge.com/etgmt_prd/j..._reuters_i.cab
O23 - Service: Aluria Security Center Spyware Eliminator Service (ASCService) - Unknown owner - C:\PROGRA~1\ALURIA~1\ascserv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe


End of KRC HijackThis Analyzer Log.
====================================================================





L2Mfix 1.03

Running From:
C:\Documents and Settings\Kary Nulisch\Desktop\l2mfix



RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting registry permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Denying C(CI) access for predefined group "Administrators"
- adding new ACCESS DENY entry


Registry Permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting up for Reboot


Starting Reboot!

C:\Documents and Settings\Kary Nulisch\Desktop\l2mfix
System Rebooted!

Running From:
C:\Documents and Settings\Kary Nulisch\Desktop\l2mfix

killing explorer and rundll32.exe

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1772 'explorer.exe'
Killing PID 1772 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Error, Cannot find a process with an image name of rundll32.exe

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!

Zipping up files for submission:
updating: clear.reg (164 bytes security) (deflated 2%)
updating: echo.reg (164 bytes security) (deflated 9%)
updating: direct.txt (164 bytes security) (stored 0%)
updating: lo2.txt (164 bytes security) (deflated 74%)
updating: readme.txt (164 bytes security) (deflated 49%)
updating: test.txt (164 bytes security) (stored 0%)
updating: test2.txt (164 bytes security) (stored 0%)
updating: test3.txt (164 bytes security) (stored 0%)
updating: test5.txt (164 bytes security) (stored 0%)
adding: log.txt (164 bytes security) (deflated 84%)
updating: backregs/C68BF954-5C67-460A-BF56-6704F35E91A7.reg (164 bytes security) (deflated 70%)
updating: backregs/shell.reg (164 bytes security) (deflated 74%)

Restoring Registry Permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Revoking access for predefined group "Administrators"
Inherited ACE can not be revoked here!
Inherited ACE can not be revoked here!


Registry permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


Restoring Sedebugprivilege:

Granting SeDebugPrivilege to Administrators ... successful


The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]


The following are the files found:
****************************************************************************

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************
****************************************************************************

lastbird is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-29-2005, 02:27 PM   #12 (permalink)
I helped the forums.
 
Join Date: Jun 2005
Posts: 9
OS: XP


Also, here is a qoologic log if that helps....

PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
some examples are MRT.EXE NTDLL.DLL.
»»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

»»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

»»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»»

(fstarts by IMM - test ver. 0.001) NOT using address check -- 0x7c90df5e

Global Startup:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
.
..
DESKTOP.INI

User Startup:
C:\Documents and Settings\Kary Nulisch\Start Menu\Programs\Startup
.
..
DESKTOP.INI

»»»»»»»»»»»»»»»»»»»»»»»» Registry Entries Found »»»»»»»»»»»»»»»»»»»»»»»

! REG.EXE VERSION 3.0

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\AVG7 Shell Extension
<NO NAME> REG_SZ {9F97547E-4609-42C5-AE0C-81C61FFAEBC3}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\fgfsttqq
<NO NAME> REG_SZ {f4af3096-87f8-4228-9ecc-da63c860e85c}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
<NO NAME> REG_SZ {750fdf0e-2a26-11d1-a3ea-080036587f03}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
<NO NAME> REG_SZ {09799AFB-AD67-11d1-ABCD-00C04FC30936}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
<NO NAME> REG_SZ {A470F8CF-A1E8-4f65-8335-227475AA5C46}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\TDS-3
<NO NAME> REG_SZ {E8ADA3E1-CE9B-44A0-A165-997304EF4E18}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip
<NO NAME> REG_SZ {E0D79304-84BE-11CE-9641-444553540000}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Yahoo! Mail
<NO NAME> REG_SZ {5464D816-CF16-4784-B9F3-75C0DB52B499}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
<NO NAME> REG_SZ Start Menu Pin
lastbird is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-29-2005, 02:28 PM   #13 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,480
OS: N/A


It doesn't seem to be there anymore. It's not in the list of running processes

Run a scan with HiJackThis & select(tick) the following & click "Fix checked" :

O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\rkrlnn.exe reg_run

Reboot & give me a new log
__________________

Question - what have you done for the community today?
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-29-2005, 02:40 PM   #14 (permalink)
I helped the forums.
 
Join Date: Jun 2005
Posts: 9
OS: XP


It looks like it is gone, awesome job....here is the krc log...did we get them all?


====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 6/3/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 3:38:28 PM, on 6/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Documents and Settings\Kary Nulisch\My Documents\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4101542B-4071-4B52-9F3A-7BCA44C1E791} (MarketTrader - ETrade v3.2a) - http://etrade.bridge.com/etgmt_prd/j...a_etrade_i.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-24.cab
O16 - DPF: {712D42CD-3513-473E-96E8-019C9AD78F1A} (MSN Money QuickList) - http://moneycentral.msn.com/cabs/webinst.exe
O16 - DPF: {963BE66B-121D-4E6C-BF9F-1A774D9A2E41} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupdate.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D8A14CC1-B68A-11D6-B8FA-00C04F5E375A} (MarketTrader - Reuters v3.2a) - http://etrade.bridge.com/etgmt_prd/j..._reuters_i.cab
O23 - Service: Aluria Security Center Spyware Eliminator Service (ASCService) - Unknown owner - C:\PROGRA~1\ALURIA~1\ascserv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe


End of KRC HijackThis Analyzer Log.
====================================================================
lastbird is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-29-2005, 02:44 PM   #15 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,480
OS: N/A


Looks like I can issue you the Death Certificate for KavSvc now.

Your log is clean. Well done
Do you have any more problems with your computer? If not, you should be set to go.

However, there still remains a few bits of housekeeping ...

Go to the L2MFix folder & double click L2mfix.bat
  • Select option #4 to "Merge Winlogon Notify Defaults" by typing "4" and then press Enter
  • Type "E" to exit the program.
You may delete the L2MFix folder after that.


Reset hidden/system files and folders
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Deselect the Show hidden files and folders option.
  • Select the Hide file extensions for known types option.
  • Select the Hide protected operating system files option.
  • Click Yes to confirm.
  • Click OK.

Create a new System Restore point
  • click Start >> Run - type SYSDM.CPL & press Enter
  • select the System Restore Tab
  • tick on the checkbox - "Turn off System Restore on all drives"
  • click Apply
  • then untick the same checkbox & click OK

Enable Windows Auto Update
  • Go to Start > Settings > Control Panel > System > Automatic Updates
  • tick on the checkbox - "Keep my computer up to date"
  • Under settings, choose "Automatically download the updates, and install them on the schedule that I specify".
  • Click on "OK".

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programs:
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SpywareGuard to catch and block spyware before it can execute.
  • IESpy-Ad to block access to malicious websites so you cannot be redirected to them from an infected site or email.

If you do not have a firewall, here are 3 free ones available for personal use:and a good antivirus like the one you are currently using. It is critical to have both a firewall and an anti-virus application and to keep them updated.


In light of your recent hiccup, I'm sure you'll like to avoid any future infections. Please take a look at these well written articles
Have a safe & happy computing day.

Please respond to this thread one more time so we can mark this thread as resolved.
__________________

Question - what have you done for the community today?
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-29-2005, 03:18 PM   #16 (permalink)
I helped the forums.
 
Join Date: Jun 2005
Posts: 9
OS: XP


Awesome, I'm not going to miss it....thanks for all of your help, a donation is on the way!

Thanks again
lastbird is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 04:32 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85