![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
I helped the forums.
Join Date: Jun 2005
Posts: 9
OS: XP
|
HJT help...cannot get rid of Narrator KAVSVC and maybe others
I have the KavSvc Narrator problem and cannot seem to get rid of it...I'm sure I have a couple others as well. I have followed the instructions of some of the other posts but cannot seem to completely eliminate all files. Below is the HJT log...thanks for any help.
Logfile of HijackThis v1.99.1 Scan saved at 10:28:53 AM, on 6/28/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Dell\EUSW\Support.exe C:\WINDOWS\system32\ctfmon.exe C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ndnu.exe C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe C:\WINDOWS\System32\wbem\wmiapsrv.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Kary Nulisch\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\vrvlmm.exe reg_run O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab O16 - DPF: {4101542B-4071-4B52-9F3A-7BCA44C1E791} (MarketTrader - ETrade v3.2a) - http://etrade.bridge.com/etgmt_prd/j...a_etrade_i.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-24.cab O16 - DPF: {712D42CD-3513-473E-96E8-019C9AD78F1A} (MSN Money QuickList) - http://moneycentral.msn.com/cabs/webinst.exe O16 - DPF: {963BE66B-121D-4E6C-BF9F-1A774D9A2E41} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupdate.exe O16 - DPF: {D8A14CC1-B68A-11D6-B8FA-00C04F5E375A} (MarketTrader - Reuters v3.2a) - http://etrade.bridge.com/etgmt_prd/j..._reuters_i.cab O20 - Winlogon Notify: Explorer - C:\WINDOWS\system32\eps.dll O23 - Service: Aluria Security Center Spyware Eliminator Service (ASCService) - Unknown owner - C:\PROGRA~1\ALURIA~1\ascserv.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing) O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,480
OS: N/A
|
Hi and Welcome to TSF!
Here's what you can do.... Please subscribe to this thread so you'll be notified as soon as we post your fix. To do this, please click here. On the proceeding page, make sure Instant notification by email is selected, then click Add subscription. I see no anti-virus application installed on this machine. An anti-virus application is your first line of defense against infections from the internet and email. Without one you leave your computer completely vulnerable to every virus, spyware program, trojan and piece of malware tht is floating around out there today. I strongly recommend that you install an anti-virus program as quickly as possible. Here are 3 free programs that are available for home use: In the meanwhile, I suggest that you stop using Interent Explorer until we've fully disinfected your machine. Please download & use an alternative browser like Firefox. Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are following the procedures below. During the course of disinfection, I may ask you to fix a program that you wish to retain. Please post back to inform me. +++ WARNING +++ You are running HijackThis from an inappropriate location. It should be run from a permanent folder. This program creates backup files which we may need to use later. If the program is in a temporary folder, important backups may be accidentally deleted.
Enable the viewing of Hidden files Windows XP/2000 Go to My Computer > Tools > Folder Options > View tab & ensure that the following are enabled;
=============== Download & install CleanUp!. We'll run it later Download KillBox v2.0.0.175 & save to desktop Download rkfiles.zip and unzip the contents to a new folder on your desktop. Download the remv3.zip at http://forums.skads.org/index.php?showtopic=80 (look for the attachment to download). Make a new folder on the root drive C:\ and unzip remv3.zip files into it. L2mfix - Download & Save to Desktop This is a self extracting file. By double clicking on it, it will automatically extract it's contents to a new folder on Desktop.
Please Do NOT run any other files in the l2mfix folder until you are told to =============== Using KillBox Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard. C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ndnu.exe O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\vrvlmm.exe reg_run
* If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again. =============== Reboot to Safe Mode
=============== Close all other windows & Run HiJackThis and click "Scan", then check(tick) the following, if present: O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\vrvlmm.exe reg_run O20 - Winlogon Notify: Explorer - C:\WINDOWS\system32\eps.dll Click "Fix checked" for HJT to fix them =============== Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
Double click rkfiles.bat file to run it. It will scan for a while, so please be patient. Wait until the DOS window closes. Open the C:\log.txt it created and rename it log1.txt. Now open the folder where you saved remv3.zip files and double click the rem.bat file and let it run. It will delete the files and remove the infection and then make a log of the files it finds. The log file will be C:\log.txt and bad1.txt **Note** Each tool uses log.txt as it’s output file so make sure you save the entries from one tools log before running the other as it will overwrite the file if you don’t. Post the contents of both the log.txt and log1.txt in your next post =============== Reboot to Normal Mode. Run a new HijackThis scan. Save the log file and run KRC HijackThis Analyzer in the same folder to get the result.txt log. Just post the contents of the result.txt file in your next reply. In your next post, please include:
__________________
Question - what have you done for the community today? |
|
|
|
|
#3 (permalink) |
|
I helped the forums.
Join Date: Jun 2005
Posts: 9
OS: XP
|
Ok, thanks for your help! Using AVG now and firefox and moved hjt to its own folder......
Here is the Hijackthis Analyzer log: ==================================================================== Log was analyzed using KRC HijackThis Analyzer - Updated on 6/3/05 Get updates at http://www.greyknight17.com/download.htm#programs ***Security Programs Detected*** C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Logfile of HijackThis v1.99.1 Scan saved at 3:54:58 PM, on 6/28/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\system32\rkrlnn.exe C:\Documents and Settings\Kary Nulisch\My Documents\hjt\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com O1 - Hosts: 64.91.255.87 www.dcsresearch.com O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\rkrlnn.exe reg_run O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab O16 - DPF: {4101542B-4071-4B52-9F3A-7BCA44C1E791} (MarketTrader - ETrade v3.2a) - http://etrade.bridge.com/etgmt_prd/j...a_etrade_i.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-24.cab O16 - DPF: {712D42CD-3513-473E-96E8-019C9AD78F1A} (MSN Money QuickList) - http://moneycentral.msn.com/cabs/webinst.exe O16 - DPF: {963BE66B-121D-4E6C-BF9F-1A774D9A2E41} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupdate.exe O16 - DPF: {D8A14CC1-B68A-11D6-B8FA-00C04F5E375A} (MarketTrader - Reuters v3.2a) - http://etrade.bridge.com/etgmt_prd/j..._reuters_i.cab O23 - Service: Aluria Security Center Spyware Eliminator Service (ASCService) - Unknown owner - C:\PROGRA~1\ALURIA~1\ascserv.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing) O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe End of KRC HijackThis Analyzer Log. ==================================================================== Here is the L2MFix log: L2Mfix 1.03 Running From: C:\Documents and Settings\Kary Nulisch\Desktop\l2mfix RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify: (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Read BUILTIN\Power Users (ID-IO) ALLOW Read BUILTIN\Power Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access CREATOR OWNER Setting registry permissions: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Denying C(CI) access for predefined group "Administrators" - adding new ACCESS DENY entry Registry Permissions set too: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify: (CI) DENY --C------- BUILTIN\Administrators (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Read BUILTIN\Power Users (ID-IO) ALLOW Read BUILTIN\Power Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access CREATOR OWNER Setting up for Reboot Starting Reboot! C:\Documents and Settings\Kary Nulisch\Desktop\l2mfix System Rebooted! Running From: C:\Documents and Settings\Kary Nulisch\Desktop\l2mfix killing explorer and rundll32.exe Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org Killing PID 1796 'explorer.exe' Killing PID 1796 'explorer.exe' Killing PID 1796 'explorer.exe' Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org Killing PID 1872 'rundll32.exe' Scanning First Pass. Please Wait! First Pass Completed Second Pass Scanning Second pass Completed! Backing Up: C:\WINDOWS\system32\APLEDIT.DLL 1 file(s) copied. Backing Up: C:\WINDOWS\system32\APLEDIT.DLL 1 file(s) copied. Backing Up: C:\WINDOWS\system32\bdpanui.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\bdpanui.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\CDL3D32.DLL 1 file(s) copied. Backing Up: C:\WINDOWS\system32\CDL3D32.DLL 1 file(s) copied. Backing Up: C:\WINDOWS\system32\dqrgui.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\dqrgui.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\eps.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\eps.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\jSvart.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\jSvart.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\msqm.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\msqm.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\guard.tmp 1 file(s) copied. Backing Up: C:\WINDOWS\system32\guard.tmp 1 file(s) copied. deleting: C:\WINDOWS\system32\APLEDIT.DLL Successfully Deleted: C:\WINDOWS\system32\APLEDIT.DLL deleting: C:\WINDOWS\system32\APLEDIT.DLL Successfully Deleted: C:\WINDOWS\system32\APLEDIT.DLL deleting: C:\WINDOWS\system32\bdpanui.dll Successfully Deleted: C:\WINDOWS\system32\bdpanui.dll deleting: C:\WINDOWS\system32\bdpanui.dll Successfully Deleted: C:\WINDOWS\system32\bdpanui.dll deleting: C:\WINDOWS\system32\CDL3D32.DLL Successfully Deleted: C:\WINDOWS\system32\CDL3D32.DLL deleting: C:\WINDOWS\system32\CDL3D32.DLL Successfully Deleted: C:\WINDOWS\system32\CDL3D32.DLL deleting: C:\WINDOWS\system32\dqrgui.dll Successfully Deleted: C:\WINDOWS\system32\dqrgui.dll deleting: C:\WINDOWS\system32\dqrgui.dll Successfully Deleted: C:\WINDOWS\system32\dqrgui.dll deleting: C:\WINDOWS\system32\eps.dll Successfully Deleted: C:\WINDOWS\system32\eps.dll deleting: C:\WINDOWS\system32\eps.dll Successfully Deleted: C:\WINDOWS\system32\eps.dll deleting: C:\WINDOWS\system32\jSvart.dll Successfully Deleted: C:\WINDOWS\system32\jSvart.dll deleting: C:\WINDOWS\system32\jSvart.dll Successfully Deleted: C:\WINDOWS\system32\jSvart.dll deleting: C:\WINDOWS\system32\msqm.dll Successfully Deleted: C:\WINDOWS\system32\msqm.dll deleting: C:\WINDOWS\system32\msqm.dll Successfully Deleted: C:\WINDOWS\system32\msqm.dll deleting: C:\WINDOWS\system32\guard.tmp Successfully Deleted: C:\WINDOWS\system32\guard.tmp deleting: C:\WINDOWS\system32\guard.tmp Successfully Deleted: C:\WINDOWS\system32\guard.tmp Zipping up files for submission: adding: APLEDIT.DLL (164 bytes security) (deflated 48%) adding: bdpanui.dll (164 bytes security) (deflated 48%) adding: CDL3D32.DLL (164 bytes security) (deflated 48%) adding: dqrgui.dll (164 bytes security) (deflated 48%) adding: eps.dll (164 bytes security) (deflated 48%) adding: jSvart.dll (164 bytes security) (deflated 48%) adding: msqm.dll (164 bytes security) (deflated 48%) adding: guard.tmp (164 bytes security) (deflated 48%) adding: clear.reg (164 bytes security) (deflated 22%) adding: echo.reg (164 bytes security) (deflated 9%) adding: direct.txt (164 bytes security) (stored 0%) adding: lo2.txt (164 bytes security) (deflated 83%) adding: readme.txt (164 bytes security) (deflated 49%) adding: test.txt (164 bytes security) (deflated 84%) adding: test2.txt (164 bytes security) (stored 0%) adding: test3.txt (164 bytes security) (stored 0%) adding: test5.txt (164 bytes security) (stored 0%) adding: xfind.txt (164 bytes security) (deflated 80%) adding: backregs/C68BF954-5C67-460A-BF56-6704F35E91A7.reg (164 bytes security) (deflated 70%) adding: backregs/shell.reg (164 bytes security) (deflated 74%) Restoring Registry Permissions: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Revoking access for predefined group "Administrators" Inherited ACE can not be revoked here! Inherited ACE can not be revoked here! Registry permissions set too: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify: (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Read BUILTIN\Power Users (ID-IO) ALLOW Read BUILTIN\Power Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access CREATOR OWNER Restoring Sedebugprivilege: Granting SeDebugPrivilege to Administrators ... successful deleting local copy: APLEDIT.DLL deleting local copy: APLEDIT.DLL deleting local copy: bdpanui.dll deleting local copy: bdpanui.dll deleting local copy: CDL3D32.DLL deleting local copy: CDL3D32.DLL deleting local copy: dqrgui.dll deleting local copy: dqrgui.dll deleting local copy: eps.dll deleting local copy: eps.dll deleting local copy: jSvart.dll deleting local copy: jSvart.dll deleting local copy: msqm.dll deleting local copy: msqm.dll deleting local copy: guard.tmp deleting local copy: guard.tmp The following Is the Current Export of the Winlogon notify key: **************************************************************************** Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] The following are the files found: **************************************************************************** C:\WINDOWS\system32\APLEDIT.DLL C:\WINDOWS\system32\APLEDIT.DLL C:\WINDOWS\system32\bdpanui.dll C:\WINDOWS\system32\bdpanui.dll C:\WINDOWS\system32\CDL3D32.DLL C:\WINDOWS\system32\CDL3D32.DLL C:\WINDOWS\system32\dqrgui.dll C:\WINDOWS\system32\dqrgui.dll C:\WINDOWS\system32\eps.dll C:\WINDOWS\system32\eps.dll C:\WINDOWS\system32\jSvart.dll C:\WINDOWS\system32\jSvart.dll C:\WINDOWS\system32\msqm.dll C:\WINDOWS\system32\msqm.dll C:\WINDOWS\system32\guard.tmp C:\WINDOWS\system32\guard.tmp Registry Entries that were Deleted: Please verify that the listing looks ok. If there was something deleted wrongly there are backups in the backreg folder. **************************************************************************** REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved] "{C68BF954-5C67-460A-BF56-6704F35E91A7}"=- [-HKEY_CLASSES_ROOT\CLSID\{C68BF954-5C67-460A-BF56-6704F35E91A7}] REGEDIT4 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "SV1"="" **************************************************************************** Desktop.ini Contents: **************************************************************************** **************************************************************************** Here is the RKFILE log: C:\rkf PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. Files Found in system Folder............ ------------------------ C:\WINDOWS\SYSTEM32\AUNPS2.dll: UPX! C:\WINDOWS\SYSTEM32\supdate.dll: UPX! Files Found in all users startup Folder............ ------------------------ Files Found in all users windows Folder............ ------------------------ Finished bye Here is the REMV3 log:The batch is run from -- C:\remv3 Files Found................. ---------------------------------------- Files Not deleted................. ---------------------------------------- Merging registry entries ----------------------------------------------------------------- The Registry Entries Found... ----------------------------------------------------------------- Other bad files to be Manually deleted.. Please note that this might also list legit Files, be careful while deleting ----------------------------------------------------------------- Volume in drive C has no label. Volume Serial Number is 48B0-ECB2 Directory of C:\WINDOWS\SYSTEM32 msi.dll Finished |
|
|
|
|
#4 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,480
OS: N/A
|
Run a scan with HiJackThis & select(tick) the following & click "Fix checked" :
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\rkrlnn.exe reg_run ~~~~~~~~~~~~~~~ Using KillBox Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard.
Start KillBox.
* If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try Killbox again. ~~~~~~~~~~~~~~~ After the reboot, do another scan with HiJackThis & check if this entry exist.. O4 - HKLM\..\Run: [KavSvc]If it's gone, post that HJT log in your next reply. Otherwise, we need to use a different program to scan for any trojans that may exist. Download TDS-3 - & Install. Close it after you have finished installation. Download & overwrite the existing file - "radius.td3", located in folder >> C:\Program Files\TDS-3\ with this file
__________________
Question - what have you done for the community today? |
|
|
|
|
#5 (permalink) |
|
I helped the forums.
Join Date: Jun 2005
Posts: 9
OS: XP
|
The KavSvc was still there after deleting those files....here is the result from the top pane of the TD3 run....
17:21:14 [Init] Trojan Defence Suite v3.2.0 (UNLICENSED) 17:21:14 [Init] Started 28-06-05 17:21:14 Central Standard Time (UTC: 6), Internet Time @973.08 17:21:14 [Init] Loading TDS-3 Systems ... 17:21:14 [Init] Token successfully adjusted. 17:21:14 [Init] • TDS Privileges : OK. Adjusted TDS-3 token privileges to maximum 17:21:15 [Init] • Plugins : OK. Loaded 13 17:21:15 [Init] • Exec Protection : Not Installed 17:21:15 [Init] WARNING: Your Radius.TD3 database needs to be updated! 17:21:15 [Init] Please download the latest from http://tds.diamondcs.com.au/radius.td3 17:21:15 [Init] Licensed users can use the Update facility from the TDS menu 17:21:15 [Init] Loading Radius Advanced Scanning Systems ... <R3 Engine, DCS Labs> 17:21:25 [Init] • Radius Advanced Specialist Extensions on standby for 13 trojan families 17:21:25 [Init] • Systems Initialised [59325 references - 31553 primaries/15456 traces/12316 variants/other] 17:21:25 [Init] Radius Systems loaded. <Databases updated 28-06-2005> 17:21:25 [Init] TDS-3 Ready. <Kary nulisch@192.168.2.2, 127.0.0.1 - United States> 17:21:25 [Tip Of The Day] If your machine has minimal resources, run minimal sockets! Sockets can be relatively expensive in terms of resources. 17:21:25 [TDS] Good evening Kary nulisch. Time to stop working! 17:21:30 [Mutex Memory Scan] Started... 17:21:32 [Mutex Memory Scan] Finished (no trojan mutexes found). 17:21:32 [TDS-3] This is an EVALUATION demo of TDS-3. Please see the help file for help on registering. 17:21:51 [CRC32] Started - verifying 29 files ... 17:21:52 [CRC32] File doesn't exist: C:\autoexec.bat 17:22:09 [CRC32] Test finished. 17:23:10 [Memory Scan] Memory scan started, please wait a moment ... 17:23:11 [Memory Scan] Memory scan complete. 17:23:11 [Mutex Memory Scan] Started... 17:23:12 [Mutex Memory Scan] Finished (no trojan mutexes found). 17:23:12 [Trace Scan] Started... 17:23:18 [Trace Scan] Finished. 17:23:18 [ServiceScan] Scanning for services and drivers ... 17:23:27 [ServiceScan] Scanned 355 services and drivers. 17:23:27 [File Scan] Scanning in C:\ ... 17:24:43 [Locked File] Couldn't open c:\documents and settings\kary nulisch\desktop\backups\backup-20050627-101324-131-ndnu.exe for read access, file is locked 17:25:03 [Locked File] Couldn't open c:\documents and settings\kary nulisch\my documents\hjt\backups\backup-20050628-143658-276-ndnu.exe for read access, file is locked 17:52:41 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp647\a0028231.exe for read access, file is locked 17:52:44 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp648\a0028260.exe for read access, file is locked 17:52:44 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp648\a0028263.exe for read access, file is locked 17:52:45 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp648\a0028275.exe for read access, file is locked 17:52:53 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp648\a0028348.exe for read access, file is locked 17:53:01 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp648\a0028444.exe for read access, file is locked 17:53:02 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp648\a0028459.exe for read access, file is locked 17:53:06 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp649\a0028484.exe for read access, file is locked 17:53:21 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp649\a0028651.exe for read access, file is locked 17:53:26 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp650\a0028733.exe for read access, file is locked 17:53:31 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp650\a0028950.exe for read access, file is locked 17:53:32 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp650\a0028989.exe for read access, file is locked 17:53:34 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp650\a0028993.exe for read access, file is locked 17:53:34 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp650\a0028994.exe for read access, file is locked 17:53:35 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp650\a0029021.exe for read access, file is locked 17:53:36 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp650\a0029034.exe for read access, file is locked 17:53:42 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0029209.exe for read access, file is locked 17:53:42 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0029210.exe for read access, file is locked 17:53:42 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0029211.exe for read access, file is locked 17:53:46 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0030283.exe for read access, file is locked 17:53:47 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0030290.exe for read access, file is locked 17:53:47 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0030291.exe for read access, file is locked 17:53:48 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0030316.exe for read access, file is locked 17:53:50 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0030336.exe for read access, file is locked 17:53:50 [Locked File] Couldn't open c:\system volume information\_restore(987e0331-0f01-427c-a58a-7a2e4aabf84d)\rp651\a0030345.exe for read access, file is locked 17:53:54 [Locked File] Couldn't open c:\windows\appbs.exe for read access, file is locked 17:53:54 [Locked File] Couldn't open c:\windows\atlhr32.exe for read access, file is locked 17:53:55 [Locked File] Couldn't open c:\windows\crdk32.exe for read access, file is locked 17:53:58 [Locked File] Couldn't open c:\windows\mfcpk32.exe for read access, file is locked 17:53:58 [Locked File] Couldn't open c:\windows\netrc.exe for read access, file is locked 17:54:01 [Locked File] Couldn't open c:\windows\ntoy.exe for read access, file is locked 17:54:01 [Locked File] Couldn't open c:\windows\ntyr.exe for read access, file is locked 17:54:05 [Locked File] Couldn't open c:\windows\winii.exe for read access, file is locked 18:08:24 [Locked File] Couldn't open c:\windows\system32\crqh32.exe for read access, file is locked 18:08:30 [Locked File] Couldn't open c:\windows\system32\d3qt32.exe for read access, file is locked 18:11:29 [Locked File] Couldn't open c:\windows\system32\wingu32.exe for read access, file is locked 18:14:10 [File Scan] Scanned 60793 files: 43 alarms in 3043.449 seconds (Avg 20.98 files/sec) 18:14:10 [File Scan] Scanning in D:\ ... 18:14:10 [File Scan] Scanned 0 files: 43 alarms in 0 seconds (Avg -1.#IND files/sec) 18:14:10 [Scan] Finished. Here is the scandump.txt text.... Scan Control Dumped @ 18:16:59 28-06-05 RegVal Trace: Suspicious: HKEY_LOCAL_MACHINE File: Software\Microsoft\Windows\CurrentVersion\Run [KavSvc=C:\WINDOWS\system32\rkrlnn.exe reg_run] Suspicious Filename: Dual extensions File: c:\documents and settings\kary nulisch\desktop\firefox setup 1.0.4.exe Positive identification (DLL): Adware.SmartPops.d (dll) File: c:\documents and settings\kary nulisch\desktop\backups\backup-20050623-204119-997.dll Suspicious Filename: Dual extensions File: c:\documents and settings\kary nulisch\desktop\downloads\dcplusplus-0.304.exe Positive identification: TrojanDownloader.Win32.Small.abd File: c:\program files\aluria security center\backup\qfle06252005150323563232.pwn Positive identification (DLL): TrojanClicker.Win32.Agent.dh (dll) File: c:\program files\aluria security center\backup\qfle06262005205250092899.pwn Positive identification: Adware.VirtualBouncer.i File: c:\program files\aluria security center\backup\qmem06252005065854215337.pwn Positive identification (DLL): TrojanClicker.Win32.Small.ez (dll) File: c:\program files\aluria security center\backup\qmem0626200506562055585.pwn Positive identification (DLL): TrojanClicker.Win32.Agent.dh (dll) File: c:\program files\aluria security center\backup\qmem06262005205250092749.pwn Positive identification (DLL): Adware.WinAD.aj (dll) File: c:\program files\yahoo!\ypsr\quarantine\ppqf3.tmp\mediaaccc.dll Positive identification <Adv>: Possible WebDownloader File: c:\program files\yahoo!\ypsr\quarantine\ppqf3.tmp\mediaaccess.exe Positive identification (embedded in file): Adware.BetterInternet.d1 File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp646\a0028141.dll Positive identification (DLL): Adware.BetterInternet.d (dll) File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp646\a0028141.dll Positive identification (embedded in file): Adware.BetterInternet.d1 File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp647\a0028194.dll Positive identification (DLL): Adware.BetterInternet.d (dll) File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp647\a0028194.dll Positive identification: Adware.BetterInternet.d1 File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp647\a0028207.exe Positive identification (embedded in file): Adware.BetterInternet.d1 File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp647\a0028208.dll Positive identification (DLL): Adware.BetterInternet.d (dll) File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp647\a0028208.dll Positive identification: Adware.BookedSpace.e Dropper File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028262.exe Positive identification (embedded in file): Adware.BetterInternet.d1 File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028284.dll Positive identification (DLL): Adware.BetterInternet.d (dll) File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028284.dll Positive identification (DLL): Adware.Exact.d (dll) File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028288.dll Positive identification: Adware.VirtualBouncer.i File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028354.exe Positive identification: Adware.VirtualBouncer.j Dropper.a File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028435.exe Positive identification: Adware.VirtualBouncer.j Dropper.b File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028436.exe Positive identification: Adware.VirtualBouncer Dropper File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028438.exe Positive identification: TrojanDownloader.Win32.Wintool.e1 File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028445.exe Positive identification: Adware.DelphinMedia.Viewer.f File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028451.exe Positive identification (DLL): Adware.DelphinMedia.Viewer.f (dll) File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp648\a0028452.dll Suspicious Filename: HTA file in suspicious location File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp649\a0028610.hta Positive identification: Adware.BargainBuddy.w File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp651\a0029201.exe Positive identification: Adware.BargainBuddy.p File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp651\a0029202.exe Positive identification: Adware.CashBack.b File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp651\a0029203.exe Positive identification: Adware.CashBack.d File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp651\a0029204.exe Positive identification (DLL): Adware.Exact.d (dll) File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp651\a0029207.dll Positive identification (DLL): TrojanDownloader.Win32.Agent.bc12 (dll) File: c:\windows\javalb32.dll2 Positive identification: Trojan.Win32.Zapchast.b File: c:\windows\launchurl.exe Positive identification: Adware.MediaMotor File: c:\windows\unstall.exe Positive identification (embedded in file): Adware.SmartPops.d (dll) File: c:\windows\cdmweb\vpambelutv.exe Positive identification (DLL): TrojanClicker.Win32.Agent.dh (dll) File: c:\windows\system32\d0ce0c16b1.dll Positive identification (DLL): TrojanDownloader.Win32.Agent.bc12 (dll) File: c:\windows\system32\syslq.dll2 Suspicious Filename: Dual extensions File: c:\windows\system32\shellext\rs.exe.exe Positive identification: Adware.DelphinMediaViewer.f File: c:\windows\system32\vidctrl\vidctrl.exe |
|
|
|
|
#6 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,480
OS: N/A
|
Using KillBox
Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard.
Start KillBox.
* If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try Killbox again. ~~~~~~~~~~~~~~~ Reboot & Do an online scan at one of the following sites:Take note the names and locations of any file it detects but fails to clean. * Turn off the real time scanner of any existing antivirus program while performing the online scan Reboot Again & Run a new scan with HiJackThis. Save the log file and run KRC HiJackThis Analyzer in the same folder to get the result.txt log. Just post the contents of the result.txt file in your next reply. In your next post, please include:
Tell me how your computer is behaving now
__________________
Question - what have you done for the community today? Last edited by sUBs; 06-28-2005 at 10:29 PM. |
|
|
|
|
#7 (permalink) |
|
I helped the forums.
Join Date: Jun 2005
Posts: 9
OS: XP
|
Here is the KVC result.txt and the results of the TrendMicro scan/clean....TrendMicro found 76 viruses and a trojan...it could only clean one or two so I chose the delete option. Prior to the TrendMicro run the mouse would barely work...it is working better now. Also, I had to open up IE to run TrendMicro.
==================================================================== Log was analyzed using KRC HijackThis Analyzer - Updated on 6/3/05 Get updates at http://www.greyknight17.com/download.htm#programs ***Security Programs Detected*** C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Logfile of HijackThis v1.99.1 Scan saved at 8:15:14 AM, on 6/29/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\system32\rkrlnn.exe C:\Documents and Settings\Kary Nulisch\My Documents\hjt\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com O1 - Hosts: 64.91.255.87 www.dcsresearch.com O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\rkrlnn.exe reg_run O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab O16 - DPF: {4101542B-4071-4B52-9F3A-7BCA44C1E791} (MarketTrader - ETrade v3.2a) - http://etrade.bridge.com/etgmt_prd/j...a_etrade_i.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-24.cab O16 - DPF: {712D42CD-3513-473E-96E8-019C9AD78F1A} (MSN Money QuickList) - http://moneycentral.msn.com/cabs/webinst.exe O16 - DPF: {963BE66B-121D-4E6C-BF9F-1A774D9A2E41} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupdate.exe O16 - DPF: {D8A14CC1-B68A-11D6-B8FA-00C04F5E375A} (MarketTrader - Reuters v3.2a) - http://etrade.bridge.com/etgmt_prd/j..._reuters_i.cab O23 - Service: Aluria Security Center Spyware Eliminator Service (ASCService) - Unknown owner - C:\PROGRA~1\ALURIA~1\ascserv.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing) O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe End of KRC HijackThis Analyzer Log. ==================================================================== Results: We have detected 27 infected file(s) with 76 virus(es) on your computer. Only 0 out of 0 infected files are displayed. Delete files if clean action is not successful Detected File Associated Virus Name Action C:\Documents and Settings\Kary Nulisch\.jpi_cache\file\1.0\SecurityClassLoader.class-52260159-1a6514f0.classUncleanable HTML_COOLWEB.A DeletePass C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\a.jar-6bb41746-59b25523.zip DeletePass - a.classUncleanable JAVA_BYTEVER.A - Dummy.classUncleanable JAVA_BYTEVER.A - VerifierBug.classUncleanable JAVA_BYTEVER.A C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\ar2.jar-741bd86b-29a3b00a.zip DeletePass - B.classUncleanable JAVA_CLOADER.E - V.classUncleanable JAVA_BYTEVER.A - Dummy.classUncleanable JAVA_BYTEVER.A - A.classUncleanable JAVA_CLOADER.E C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\ar3.jar-3ae82c1c-6701e022.zip DeletePass - Counter.classUncleanable JAVA_FEMAD.B - VerifierBug.classUncleanable JAVA_BYTEVER.A-1 - Gummy.classUncleanable JAVA_BYTEVER.A-1 C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\ar3.jar-51b26348-1e457a03.zip DeletePass - Gummy.classUncleanable JAVA_BYTEVER.A-1 - Counter.classUncleanable JAVA_BYTEVER.A-1 - VerifierBug.classUncleanable JAVA_BYTEVER.A-1 C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\ar3.jar-5ef20017-26a74551.zip DeletePass - Gummy.classUncleanable JAVA_BYTEVER.A-1 - Counter.classUncleanable JAVA_BYTEVER.A-1 - VerifierBug.classUncleanable JAVA_BYTEVER.A-1 C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\ar3.jar-7429efec-7e7ab5be.zip DeletePass - Gummy.classUncleanable JAVA_BYTEVER.A-1 - Counter.classUncleanable JAVA_BYTEVER.A-1 - VerifierBug.classUncleanable JAVA_BYTEVER.A-1 C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\archive.jar-487b52a0-180053cd.zip DeletePass - rundll32.exeUncleanable TROJ_STARTPGE.BG C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\classload.jar-11faa9ed-278f4239.zip DeletePass - GetAccess.classUncleanable JAVA_BYTEVER.A - InsecureClassLoader.classUncleanable JAVA_BYTEVER.A - Dummy.classUncleanable JAVA_BYTEVER.A - Installer.classUncleanable JAVA_BYTEVER.A C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\classload.jar-1f5b6b54-35e6d148.zip DeletePass - GetAccess.classUncleanable JAVA_BYTEVER.A - InsecureClassLoader.classUncleanable JAVA_BYTEVER.A - Dummy.classUncleanable JAVA_BYTEVER.A - Installer.classUncleanable JAVA_BYTEVER.A C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\clsld.jar-455f8b8a-51e4e624.zip DeletePass - GetAccess.classUncleanable JAVA_BYTEVER.A - InsecureClassLoader.classUncleanable JAVA_BYTEVER.A - Dummy.classUncleanable JAVA_BYTEVER.A - Installer.classUncleanable JAVA_BYTEVER.A C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\count.jar-314758c1-3f1e4a79.zip DeletePass - BlackBox.classUncleanable JAVA_BYTEVER.A - Dummy.classUncleanable JAVA_BYTEVER.A C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\count.jar-4d094f47-3c51652d.zip DeletePass - BlackBox.classUncleanable JAVA_BYTEVER.A - Dummy.classUncleanable JAVA_BYTEVER.A C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\count1.jar-4888e0ab-43297f3e.zip DeletePass - BlackBox.classUncleanable JAVA_BYTEVER.A - Dummy.classUncleanable JAVA_BYTEVER.A - VerifierBug.classUncleanable JAVA_BYTEVER.A C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\counter.jar-4b1d7eab-22580f5f.zip DeletePass - BB.classUncleanable JAVA_BYTEVER.A - VerifierBug.classUncleanable JAVA_BYTEVER.A - Dummy.classUncleanable JAVA_BYTEVER.A - BeyondInterface.classUncleanable JAVA_BYTEVER.A C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\counter.jar-5b38b92d-5e736831.zip DeletePass - Beyond.classUncleanable JAVA_BYTEVER.A - counter.classUncleanable JAVA_BYTEVER.A - Dummy.classUncleanable JAVA_BYTEVER.A - VerifierBug.classUncleanable JAVA_BYTEVER.A C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\counter.jar-7271642a-69dc6e66.zip DeletePass - counter.classUncleanable JAVA_BYTEVER.A - Dummy.classUncleanable JAVA_BYTEVER.A - VerifierBug.classUncleanable JAVA_BYTEVER.A C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\loader.jar-288a6362-22141f3d.zip DeletePass - Counter.classUncleanable JAVA_BYTEVER.C - Dummy.classUncleanable JAVA_BYTEVER.A - Parser.classUncleanable JAVA_BYTEVER.A C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\loaderadv74.jar-170b188f-6fffaf4d.zip DeletePass - Counter.classUncleanable JAVA_BYTEVER.C - Dummy.classUncleanable JAVA_BYTEVER.A - Parser.classUncleanable JAVA_BYTEVER.A C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\loaderdmitriy.jar-798e87d9-7b110fc5.zip DeletePass - Counter.classUncleanable JAVA_BYTEVER.C - Dummy.classUncleanable JAVA_BYTEVER.A - Parser.classUncleanable JAVA_BYTEVER.A C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\nude.jar-30e3d4e0-1dfc8d34.zip DeletePass - NudeBox.classUncleanable JAVA_BYTEVER.A - VerifierBug.classUncleanable JAVA_BYTEVER.A - Dummy.classUncleanable JAVA_BYTEVER.A - Beyond.classUncleanable JAVA_BYTEVER.A - Worker.classUncleanable JAVA_BYTEVER.A - msdos.exeUncleanable BKDR_RSBOT.A - explorer.exeUncleanable TROJ_SHELEX.A C:\Documents and Settings\Kary Nulisch\.jpi_cache\jar\1.0\WebCounter.jar-12a49c8f-75e498fd.zip DeletePass - Dummy.classUncleanable JAVA_BYTEVER.A - VerifierBug.classUncleanable JAVA_BYTEVER.A - WebCounter.classUncleanable JAVA_BYTEVER.A - a.classUncleanable JAVA_BYTEVER.A C:\Program Files\Aluria Security Center\Backup\QFle0624200515531215718.pwnUncleanable TROJ_HARNIG.Z DeletePass C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP648\A0028298.exeUncleanable TROJ_HARNIG.Z DeletePass C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP652\A0030441.exeUncleanable TROJ_DLOADER.OT DeletePass C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP652\A0030443.exeUncleanable TROJ_ZAPCHAST.J DeletePass C:\WINDOWS\SYSTEM32\secure32.txt JS_STARTPAG.AD CleanDeletePass Trojan/Worm Check 1 worm/Trojan horse detected What we checked: Malicious activity by a Trojan horse program. Although a Trojan seems like a harmless program, it contains malicious code and once installed can cause damage to your computer. Results: We have detected 1 Trojan horse program(s) and worm(s) on your computer. Only 0 out of 0 Trojan horse programs and worms are displayed. Trojan/Worm Name Trojan/Worm Type Action TROJ_SMALL-1 Trojan DeletePass |
|
|
|
|
#8 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,480
OS: N/A
|
It's still there. Something is still holding it in place. Let's take another whack at it & then do another round of online scans.
Upon reboot, Do an online scan at Panda Take note the names and locations of any file it detects but fails to clean. Post that with a fresh copy of HJT log in your next reply
__________________
Question - what have you done for the community today? |
|
|
|
|
#9 (permalink) |
|
I helped the forums.
Join Date: Jun 2005
Posts: 9
OS: XP
|
Yep, Killbox couldn't get it again. Here is the log from Panda:
Adware:Adware/AdBehavior No disinfected C:\WINDOWS\system32\reryoou.dll Adware:Adware/AdBehavior No disinfected C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ndnu.exe Adware:Adware/AdBehavior No disinfected C:\WINDOWS\system32\rkrlnn.exe Adware:Adware/AdBehavior No disinfected C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ndnu.exe Spyware:Spyware/AdClicker No disinfected C:\WINDOWS\usta32.ini Spyware:Spyware/Dyfuca No disinfected Windows Registry Adware:Adware/BookedSpace No disinfected C:\WINDOWS\cfgmgr52.dll Adware:Adware/WinTools No disinfected Windows Registry Spyware:Spyware/TVMedia No disinfected C:\Documents and Settings\Kary Nulisch\Application Data\tvm*.dll Adware:Adware/MediaTickets No disinfected Windows Registry Adware:Adware/IPInsight No disinfected C:\WINDOWS\inf\polall1r.inf Adware:Adware/DealHelper No disinfected Windows Registry Adware:Adware/PowerSearch No disinfected C:\WINDOWS\system32\stlb2.xml Adware:Adware/Novo No disinfected Windows Registry Adware:Adware/AdBehavior No disinfected C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ndnu.exe Spyware:Spyware/TVMedia No disinfected C:\Documents and Settings\Kary Nulisch\Application Data\tvmcwrd.dll Adware:Adware/nCase No disinfected C:\Documents and Settings\Kary Nulisch\Desktop\backups\backup-20050623-204119-787.inf Adware:Adware/Novo No disinfected C:\Documents and Settings\Kary Nulisch\Desktop\backups\backup-20050623-204119-997.dll Adware:Adware/AdBehavior No disinfected C:\Documents and Settings\Kary Nulisch\Desktop\backups\backup-20050626-193800-357-ndnu.exe Adware:Adware/BrowserAid No disinfected C:\Program Files\Aluria Security Center\Backup\QFle06262005205250092899.pwn Adware:Adware/VirtualBouncer No disinfected C:\Program Files\Aluria Security Center\Backup\QMem06252005065854215337.pwn Adware:Adware/BrowserAid No disinfected C:\Program Files\Aluria Security Center\Backup\QMem06262005205250092749.pwn Adware:Adware/Startpage.CEH No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\20041124153815.zip[hosts] Adware:Adware/DelFinMedia No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\20050627090816.zip[RemoveDisplayUtility.exe] Adware:Adware/WinAD No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppqF3.tmp\MediaAccC.dll Adware:Adware/WinAD No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppqF3.tmp\MediaAccess.exe Adware:Adware/WinAD No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppqF3.tmp\MediaAccK.exe Adware:Adware/BookedSpace No disinfected C:\WINDOWS\cfgmgr52.dll Adware:Adware/Transponder No disinfected C:\WINDOWS\INF\polall1r.inf Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\UpdInst.exe Adware:Adware/AdBehavior No disinfected C:\WINDOWS\SYSTEM32\pqpgb.dat Adware:Adware/AdBehavior No disinfected C:\WINDOWS\SYSTEM32\reryoou.dll Adware:Adware/AdBehavior No disinfected C:\WINDOWS\SYSTEM32\rkrlnn.exe Virus:Trj/Harnig.M Disinfected C:\WINDOWS\SYSTEM32\secure32.RB0 Adware:Adware/Startpage.CBL No disinfected C:\WINDOWS\SYSTEM32\secure33.txt Adware:Adware/PowerSearch No disinfected C:\WINDOWS\SYSTEM32\stlb2.xml Adware:Adware/AdBehavior No disinfected C:\WINDOWS\SYSTEM32\urugq.dll Spyware:Spyware/AdClicker No disinfected C:\WINDOWS\usta32.ini |
|
|
|
|
#10 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,480
OS: N/A
|
The Panda scan manage to uncover some interesting results..
We should be a bit more lucky this time round.. ~~~~~~~~~~~~~~~~~~~ KillBox these.. C:\WINDOWS\system32\reryoou.dll~~~~~~~~~~~~~~~~~~ After you have rebooted, we need to download an additional tool for another infection which Panda uncovered. L2mfix - Download & Save to Desktop This is a self extracting file. By double clicking on it, it will automatically extract it's contents to a new folder on Desktop.
Please Do NOT run any other files in the l2mfix folder until you are told to Note: Please do a search of this folder - C:\Documents and Settings\Kary Nulisch\Application Data\. Try locating files with names similar to this - tvm*.dll. Post your findings in the next reply
__________________
Question - what have you done for the community today? Last edited by sUBs; 06-29-2005 at 01:23 PM. |
|
|
|
|
#11 (permalink) |
|
I helped the forums.
Join Date: Jun 2005
Posts: 9
OS: XP
|
Looks like it's still there, below is the KRC log followed by the L2Mfix log.
I am cut/pasting one at a time in killbox and then rebooting after the last one is entered.... I cannot see any tvm*.dll files on my computer anywhere. Also, I tried to find that ndnu.exe file (thinking that is what it was attached to) and cannot find it in the directory specified either. ==================================================================== Log was analyzed using KRC HijackThis Analyzer - Updated on 6/3/05 Get updates at http://www.greyknight17.com/download.htm#programs ***Security Programs Detected*** C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Logfile of HijackThis v1.99.1 Scan saved at 2:42:35 PM, on 6/29/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\Documents and Settings\Kary Nulisch\My Documents\hjt\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com O1 - Hosts: 64.91.255.87 www.dcsresearch.com O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\rkrlnn.exe reg_run O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab O16 - DPF: {4101542B-4071-4B52-9F3A-7BCA44C1E791} (MarketTrader - ETrade v3.2a) - http://etrade.bridge.com/etgmt_prd/j...a_etrade_i.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-24.cab O16 - DPF: {712D42CD-3513-473E-96E8-019C9AD78F1A} (MSN Money QuickList) - http://moneycentral.msn.com/cabs/webinst.exe O16 - DPF: {963BE66B-121D-4E6C-BF9F-1A774D9A2E41} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupdate.exe O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O16 - DPF: {D8A14CC1-B68A-11D6-B8FA-00C04F5E375A} (MarketTrader - Reuters v3.2a) - http://etrade.bridge.com/etgmt_prd/j..._reuters_i.cab O23 - Service: Aluria Security Center Spyware Eliminator Service (ASCService) - Unknown owner - C:\PROGRA~1\ALURIA~1\ascserv.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing) O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe End of KRC HijackThis Analyzer Log. ==================================================================== L2Mfix 1.03 Running From: C:\Documents and Settings\Kary Nulisch\Desktop\l2mfix RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify: (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Read BUILTIN\Power Users (ID-IO) ALLOW Read BUILTIN\Power Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access CREATOR OWNER Setting registry permissions: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Denying C(CI) access for predefined group "Administrators" - adding new ACCESS DENY entry Registry Permissions set too: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify: (CI) DENY --C------- BUILTIN\Administrators (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Read BUILTIN\Power Users (ID-IO) ALLOW Read BUILTIN\Power Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access CREATOR OWNER Setting up for Reboot Starting Reboot! C:\Documents and Settings\Kary Nulisch\Desktop\l2mfix System Rebooted! Running From: C:\Documents and Settings\Kary Nulisch\Desktop\l2mfix killing explorer and rundll32.exe Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org Killing PID 1772 'explorer.exe' Killing PID 1772 'explorer.exe' Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org Error, Cannot find a process with an image name of rundll32.exe Scanning First Pass. Please Wait! First Pass Completed Second Pass Scanning Second pass Completed! Zipping up files for submission: updating: clear.reg (164 bytes security) (deflated 2%) updating: echo.reg (164 bytes security) (deflated 9%) updating: direct.txt (164 bytes security) (stored 0%) updating: lo2.txt (164 bytes security) (deflated 74%) updating: readme.txt (164 bytes security) (deflated 49%) updating: test.txt (164 bytes security) (stored 0%) updating: test2.txt (164 bytes security) (stored 0%) updating: test3.txt (164 bytes security) (stored 0%) updating: test5.txt (164 bytes security) (stored 0%) adding: log.txt (164 bytes security) (deflated 84%) updating: backregs/C68BF954-5C67-460A-BF56-6704F35E91A7.reg (164 bytes security) (deflated 70%) updating: backregs/shell.reg (164 bytes security) (deflated 74%) Restoring Registry Permissions: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Revoking access for predefined group "Administrators" Inherited ACE can not be revoked here! Inherited ACE can not be revoked here! Registry permissions set too: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify: (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Read BUILTIN\Power Users (ID-IO) ALLOW Read BUILTIN\Power Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access CREATOR OWNER Restoring Sedebugprivilege: Granting SeDebugPrivilege to Administrators ... successful The following Is the Current Export of the Winlogon notify key: **************************************************************************** Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] The following are the files found: **************************************************************************** Registry Entries that were Deleted: Please verify that the listing looks ok. If there was something deleted wrongly there are backups in the backreg folder. **************************************************************************** REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved] REGEDIT4 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "SV1"="" **************************************************************************** Desktop.ini Contents: **************************************************************************** **************************************************************************** |
|
|
|
|
#12 (permalink) |
|
I helped the forums.
Join Date: Jun 2005
Posts: 9
OS: XP
|
Also, here is a qoologic log if that helps....
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. some examples are MRT.EXE NTDLL.DLL. »»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»» (fstarts by IMM - test ver. 0.001) NOT using address check -- 0x7c90df5e Global Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup . .. DESKTOP.INI User Startup: C:\Documents and Settings\Kary Nulisch\Start Menu\Programs\Startup . .. DESKTOP.INI »»»»»»»»»»»»»»»»»»»»»»»» Registry Entries Found »»»»»»»»»»»»»»»»»»»»»»» ! REG.EXE VERSION 3.0 HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\AVG7 Shell Extension <NO NAME> REG_SZ {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\fgfsttqq <NO NAME> REG_SZ {f4af3096-87f8-4228-9ecc-da63c860e85c} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files <NO NAME> REG_SZ {750fdf0e-2a26-11d1-a3ea-080036587f03} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With <NO NAME> REG_SZ {09799AFB-AD67-11d1-ABCD-00C04FC30936} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu <NO NAME> REG_SZ {A470F8CF-A1E8-4f65-8335-227475AA5C46} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\TDS-3 <NO NAME> REG_SZ {E8ADA3E1-CE9B-44A0-A165-997304EF4E18} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip <NO NAME> REG_SZ {E0D79304-84BE-11CE-9641-444553540000} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Yahoo! Mail <NO NAME> REG_SZ {5464D816-CF16-4784-B9F3-75C0DB52B499} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} <NO NAME> REG_SZ Start Menu Pin |
|
|
|
|
#13 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,480
OS: N/A
|
It doesn't seem to be there anymore. It's not in the list of running processes
Run a scan with HiJackThis & select(tick) the following & click "Fix checked" : O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\rkrlnn.exe reg_run Reboot & give me a new log
__________________
Question - what have you done for the community today? |
|
|
|
|
#14 (permalink) |
|
I helped the forums.
Join Date: Jun 2005
Posts: 9
OS: XP
|
It looks like it is gone, awesome job....here is the krc log...did we get them all?
==================================================================== Log was analyzed using KRC HijackThis Analyzer - Updated on 6/3/05 Get updates at http://www.greyknight17.com/download.htm#programs ***Security Programs Detected*** C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Logfile of HijackThis v1.99.1 Scan saved at 3:38:28 PM, on 6/29/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\Documents and Settings\Kary Nulisch\My Documents\hjt\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com O1 - Hosts: 64.91.255.87 www.dcsresearch.com O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab O16 - DPF: {4101542B-4071-4B52-9F3A-7BCA44C1E791} (MarketTrader - ETrade v3.2a) - http://etrade.bridge.com/etgmt_prd/j...a_etrade_i.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-24.cab O16 - DPF: {712D42CD-3513-473E-96E8-019C9AD78F1A} (MSN Money QuickList) - http://moneycentral.msn.com/cabs/webinst.exe O16 - DPF: {963BE66B-121D-4E6C-BF9F-1A774D9A2E41} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupdate.exe O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O16 - DPF: {D8A14CC1-B68A-11D6-B8FA-00C04F5E375A} (MarketTrader - Reuters v3.2a) - http://etrade.bridge.com/etgmt_prd/j..._reuters_i.cab O23 - Service: Aluria Security Center Spyware Eliminator Service (ASCService) - Unknown owner - C:\PROGRA~1\ALURIA~1\ascserv.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing) O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe End of KRC HijackThis Analyzer Log. ==================================================================== |
|
|
|
|
#15 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,480
OS: N/A
|
Looks like I can issue you the Death Certificate for KavSvc now.
Your log is clean. Well done Do you have any more problems with your computer? If not, you should be set to go. However, there still remains a few bits of housekeeping ... Go to the L2MFix folder & double click L2mfix.bat
Reset hidden/system files and folders
Create a new System Restore point
Enable Windows Auto Update
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programs:
If you do not have a firewall, here are 3 free ones available for personal use:and a good antivirus like the one you are currently using. It is critical to have both a firewall and an anti-virus application and to keep them updated. In light of your recent hiccup, I'm sure you'll like to avoid any future infections. Please take a look at these well written articles Have a safe & happy computing day. Please respond to this thread one more time so we can mark this thread as resolved.
__________________
Question - what have you done for the community today? |
|
|
| Thread Tools | |
|
|