![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Sep 2004
Posts: 11
OS: XP Professional
|
HJT log....a few things still hanging on :(
I'm getting frazzled... I had the AV GOLD problem, and tried a couple fixes from other sites. I seem to be rid of that but have some leftover problems (popups, added favorites, etc.). I have run spy sweeper, adaware, CWS shredder, spybot search and destroy among others, but problems keep getting loaded (I've tried running all these in safe mode). Any help would be greatly appreciated.
Here's my HJT log. Logfile of HijackThis v1.98.2 Scan saved at 12:11:36 PM, on 7/11/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\d3ey32.exe C:\WINDOWS\System32\sistray.EXE C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\System32\dpmw32.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\WINDOWS\system32\NWTRAY.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DLink\Bluetooth Software\BTTray.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\hjt\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.charlotte.com/mld/charlotte R3 - Default URLSearchHook is missing O2 - BHO: Class - {2B4B5589-B4B7-A432-BCE4-C96F8E7DB2A0} - C:\WINDOWS\crax.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Class - {FBA819B5-BECF-B27B-6F9B-963F513D8D14} - C:\WINDOWS\apifz.dll O2 - BHO: Class - {FE7AA604-D603-D018-CCF2-941EB9FDFB36} - C:\WINDOWS\msqz.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray O4 - HKLM\..\Run: [d3ey32.exe] C:\WINDOWS\system32\d3ey32.exe O4 - HKLM\..\RunOnce: [winzd.exe] C:\WINDOWS\system32\winzd.exe O4 - HKLM\..\RunOnce: [apifz.exe] C:\WINDOWS\apifz.exe O4 - HKLM\..\RunOnce: [addek32.exe] C:\WINDOWS\system32\addek32.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: BTTray.lnk = ? O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\DLink\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://mirror.worldwinner.com/games/v44/pool/pool.cab O16 - DPF: {6BB594E2-6E4D-4CC9-98B0-931C323F9165} (DepHlp Control) - http://mirror.worldwinner.com/games/shared/dephlp.cab O16 - DPF: {6F6DBC29-7A0C-4AC0-A42D-10EC70678526} (Word Cubes Control) - http://mirror.worldwinner.com/games/...e/wordcube.cab O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab O16 - DPF: {8BDF4BDB-7C40-4DC8-B2DD-138D8059698C} (Focus Control) - http://mirror.worldwinner.com/games/v41/focus/focus.cab O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://mirror.worldwinner.com/games/...o/wordmojo.cab O16 - DPF: {957BDEC2-50EA-4B01-ABF5-22F86364A914} (Trivia Control) - http://mirror.worldwinner.com//games...via/trivia.cab O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - http://mirror.worldwinner.com/games/...an/hangman.cab O16 - DPF: {C5142630-9BC9-4236-BAC9-2E3C24566EC8} (XWord Control) - http://mirror.worldwinner.com/games/v40/xword/xword.cab O16 - DPF: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} (JInitiator 1.3.1.13) - https://esis.ncwise.org/jinitiator/jinit.exe O16 - DPF: {D27FFC5F-D7B9-4349-9F41-F7458B585374} (SoloTriv Control) - http://mirror.worldwinner.com/games/...v/solotriv.cab O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,409
OS: N/A
|
Hi and Welcome to TSF!
Please subscribe to this thread to be notified of fixes as soon as they are posted by our Team. To do this, please click the "Thread Tools" button located in the original thread line and selecting "Subscribe to this Thread". It's better to print out the next instructions or save them in notepad, because you also have to work in safe mode without networking support, so this page wouldn't be available then. It is also important you don't miss a step and perform everything in the right order!!. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are carrying out the procedures below. Please disable Webroot SpySweeper, as it may hinder the removal of some entries. You can re-enable it after you're clean. To disable Webroot SpySweeper:
~~~~~~~~~~~~~~ Please download these additional files/programs :- (Do not run them unless instructed to do so) Unplug your computer from the Internet when you have finished downloading CleanUp! - Install KillBox v2.0.0.175 - Save to Desktop. ~~~~~~~~~~~~~~ Start HiJackThis & go to Config>Misc Tools>Open process manager Select the following and click [Kill process] one at a time. Some entries may no longer exist. C:\WINDOWS\system32\d3ey32.exe ~~~~~~~~~~~~~~ Run a scan with HiJackThis & select(tick) the following & click [Fix checked] : R3 - Default URLSearchHook is missing O2 - BHO: Class - {2B4B5589-B4B7-A432-BCE4-C96F8E7DB2A0} - C:\WINDOWS\crax.dll O2 - BHO: Class - {FBA819B5-BECF-B27B-6F9B-963F513D8D14} - C:\WINDOWS\apifz.dll O2 - BHO: Class - {FE7AA604-D603-D018-CCF2-941EB9FDFB36} - C:\WINDOWS\msqz.dll O4 - HKLM\..\Run: [d3ey32.exe] C:\WINDOWS\system32\d3ey32.exe O4 - HKLM\..\RunOnce: [winzd.exe] C:\WINDOWS\system32\winzd.exe O4 - HKLM\..\RunOnce: [apifz.exe] C:\WINDOWS\apifz.exe O4 - HKLM\..\RunOnce: [addek32.exe] C:\WINDOWS\system32\addek32.exe O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://mirror.worldwinner.com/games/v44/pool/pool.cab O16 - DPF: {6BB594E2-6E4D-4CC9-98B0-931C323F9165} (DepHlp Control) - http://mirror.worldwinner.com/games/shared/dephlp.cab O16 - DPF: {6F6DBC29-7A0C-4AC0-A42D-10EC70678526} (Word Cubes Control) - http://mirror.worldwinner.com/games...be/wordcube.cab O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab O16 - DPF: {8BDF4BDB-7C40-4DC8-B2DD-138D8059698C} (Focus Control) - http://mirror.worldwinner.com/games/v41/focus/focus.cab O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://mirror.worldwinner.com/games...jo/wordmojo.cab O16 - DPF: {957BDEC2-50EA-4B01-ABF5-22F86364A914} (Trivia Control) - http://mirror.worldwinner.com//game...ivia/trivia.cab O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - http://mirror.worldwinner.com/games...man/hangman.cab O16 - DPF: {C5142630-9BC9-4236-BAC9-2E3C24566EC8} (XWord Control) - http://mirror.worldwinner.com/games/v40/xword/xword.cab O16 - DPF: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} (JInitiator 1.3.1.13) - https://esis.ncwise.org/jinitiator/jinit.exe O16 - DPF: {D27FFC5F-D7B9-4349-9F41-F7458B585374} (SoloTriv Control) - http://mirror.worldwinner.com/games...iv/solotriv.cab ~~~~~~~~~~~~~~ Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard. C:\WINDOWS\crax.dllStart KillBox.
* If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try Killbox again. ~~~~~~~~~~~~~~ Upon reboot, Run Cleanup! & configure the program up as follows:
~~~~~~~~~~~~~~ Do an online scan at one of the following sites:Take note the names and locations of any file it detects but fails to clean. * Turn off the real time scanner of any existing antivirus program while performing the online scan Reboot Again & Run a new scan with HiJackThis. Save the log file and post the contents in your next reply. In your next post, please include fresh copies of: 1. Copy of HiJackThis log 2. List of files that online scans failed to disinfect Please provide details of any problems you encountered whilst performing the above steps. Update us on how your computer behaves now
__________________
Question - what have you done for the community today? |
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Sep 2004
Posts: 11
OS: XP Professional
|
Ok... I've done that...
Done... Still slow on startup, still getting a pop-up here and there, and also getting these messages on startup:
The application or DLL C:\WINDOWS\javato.dll is not a valid Windows image. The application or DLL C:\WINDOWS\system32\crrn.dll is not a valid Windows image. Updated HJT Log: Logfile of HijackThis v1.98.2 Scan saved at 2:05:35 PM, on 7/12/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe C:\WINDOWS\system32\msiexec.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\crbk32.exe C:\WINDOWS\system32\crff32.exe C:\WINDOWS\System32\sistray.EXE C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\System32\dpmw32.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\NWTRAY.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DLink\Bluetooth Software\BTTray.exe C:\hjt\HijackThis.exe C:\WINDOWS\system32\MsiExec.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049 R3 - Default URLSearchHook is missing O2 - BHO: Class - {003156AA-B2AD-54C8-CF6D-1C992B937149} - C:\WINDOWS\system32\apidt.dll O2 - BHO: Class - {146A4A8B-66F9-80FA-6E14-51A6991BAC7D} - C:\WINDOWS\system32\apibs32.dll O2 - BHO: Class - {4ABB5929-6D33-1BD3-5889-307B70AC94D2} - C:\WINDOWS\system32\crxz.dll O2 - BHO: Class - {5CE5B985-51B1-3958-E5DB-92DD9091CFBB} - C:\WINDOWS\javavq.dll O2 - BHO: Class - {63C3B90C-CAE8-913A-DBA5-AC8E0D0896D0} - C:\WINDOWS\system32\crbk32.dll O2 - BHO: Class - {6827E44A-FCD1-5704-0FF9-EE64FBCBD77F} - C:\WINDOWS\system32\wingm32.dll O2 - BHO: Class - {7D52FC72-76A8-77EF-270D-8A1A8EA30F96} - C:\WINDOWS\system32\winsx32.dll O2 - BHO: Class - {91D042E7-25DF-B6F2-5C0C-B0963EF3EA01} - C:\WINDOWS\winqv32.dll O2 - BHO: Class - {A4913EBE-69AB-7C2E-EA16-13F6C5E79E14} - C:\WINDOWS\system32\ipvh32.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Class - {C1A7352F-7207-2C2F-6A41-8C46196F8284} - C:\WINDOWS\system32\winug32.dll O2 - BHO: Class - {C2EFCA32-D3CF-3801-B32F-6A7589AA0A8A} - C:\WINDOWS\netfd.dll O2 - BHO: Class - {FEF289B2-6015-9A71-D02D-8394ED825678} - C:\WINDOWS\system32\javany.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE O4 - HKLM\..\Run: [iesn.exe] C:\WINDOWS\system32\iesn.exe O4 - HKLM\..\Run: [crbk32.exe] C:\WINDOWS\system32\crbk32.exe O4 - HKLM\..\RunOnce: [apiua.exe] C:\WINDOWS\apiua.exe O4 - HKLM\..\RunOnce: [crnf.exe] C:\WINDOWS\crnf.exe O4 - HKLM\..\RunOnce: [appxr32.exe] C:\WINDOWS\system32\appxr32.exe O4 - HKLM\..\RunOnce: [mfcpj32.exe] C:\WINDOWS\system32\mfcpj32.exe O4 - HKLM\..\RunOnce: [mfcsy32.exe] C:\WINDOWS\mfcsy32.exe O4 - HKLM\..\RunOnce: [javaad32.exe] C:\WINDOWS\system32\javaad32.exe O4 - HKLM\..\RunOnce: [iexj.exe] C:\WINDOWS\system32\iexj.exe O4 - HKLM\..\RunOnce: [ipfp.exe] C:\WINDOWS\system32\ipfp.exe O4 - HKLM\..\RunOnce: [addvf.exe] C:\WINDOWS\system32\addvf.exe O4 - HKLM\..\RunOnce: [appkj32.exe] C:\WINDOWS\appkj32.exe O4 - HKLM\..\RunOnce: [addyu.exe] C:\WINDOWS\system32\addyu.exe O4 - HKLM\..\RunOnce: [netkc32.exe] C:\WINDOWS\netkc32.exe O4 - HKLM\..\RunOnce: [crcy.exe] C:\WINDOWS\system32\crcy.exe O4 - HKLM\..\RunOnce: [sysxo.exe] C:\WINDOWS\sysxo.exe O4 - HKLM\..\RunOnce: [msvh32.exe] C:\WINDOWS\msvh32.exe O4 - HKLM\..\RunOnce: [addua.exe] C:\WINDOWS\addua.exe O4 - HKLM\..\RunOnce: [addyp.exe] C:\WINDOWS\addyp.exe O4 - HKLM\..\RunOnce: [crzj32.exe] C:\WINDOWS\crzj32.exe O4 - HKLM\..\RunOnce: [msul32.exe] C:\WINDOWS\msul32.exe O4 - HKLM\..\RunOnce: [crnn.exe] C:\WINDOWS\crnn.exe O4 - HKLM\..\RunOnce: [winsx.exe] C:\WINDOWS\winsx.exe O4 - HKLM\..\RunOnce: [crff32.exe] C:\WINDOWS\system32\crff32.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: BTTray.lnk = ? O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\DLink\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O16 - DPF: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} (JInitiator 1.3.1.13) - https://esis.ncwise.org/jinitiator/jinit.exe O16 - DPF: {D27FFC5F-D7B9-4349-9F41-F7458B585374} (SoloTriv Control) - http://mirror.worldwinner.com/games/...v/solotriv.cab O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab ******** And here's the results from Panda's online scan: Incident Status Location Adware:Adware/nCase No disinfected C:\WINDOWS\180solutions Adware:Adware/SearchAid No disinfected C:\Documents and Settings\jthomps\Favorites\Only sex website.url Adware:Adware/SideStep No disinfected C:\WINDOWS\Downloaded Program Files\SbCIe???.??? Adware:Adware/Midaddle No disinfected Windows Registry Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Ab scissor.url Adware:Adware/CWS.Aboutblank No disinfected Windows Registry Adware:Adware/CWS.008k No disinfected C:\WINDOWS\appaz32.exe Adware:Adware/CWS.HomeSearchAsisstantNo disinfected Windows Registry Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-228d5c98-4ce0ce54.zip[a.class] Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-228d5c98-4ce0ce54.zip[Dummy.class] Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-228d5c98-4ce0ce54.zip[VerifierBug.class] Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6fd1d987-4758c273.zip[BlackBox.class] Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6fd1d987-4758c273.zip[VB.class] Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6fd1d987-4758c273.zip[Dummy.class] Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6fd1d987-4758c273.zip[Beyond.class] Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-6699b1e6-6a0ae450.zip[BlackBox.class] Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-6699b1e6-6a0ae450.zip[VerifierBug.class] Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-6699b1e6-6a0ae450.zip[Dummy.class] Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-6699b1e6-6a0ae450.zip[Beyond.class] Adware:Adware/SearchAid No disinfected C:\Documents and Settings\jthomps\Favorites\Only sex website.url Adware:Adware/SearchAid No disinfected C:\Documents and Settings\jthomps\Favorites\Search the web.url Adware:Adware/SearchAid No disinfected C:\Documents and Settings\jthomps\Favorites\Seven days of free porn.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Ab scissor.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Broadband comparison.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Credit counseling.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Credit report.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Crm software.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Debt credit card.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Escorts.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Fha.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Health insurance.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Help desk software.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Insurance home.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Loan for debt consolidation.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Loan for people with bad credit.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Marketing email.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Mortgage insurance.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Mortgage life insurance.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Nevada corporations.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Online Betting Site.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Online gambling casino.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Online instant loan.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Order phentermine.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Payroll advance.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Personal loans online.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Personal loans with bad credit.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Prescription Drugs Rx Online.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Refinancing my mortgage.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Tahoe vacation rental.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Unsecured bad credit loans.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Videos.url Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\What is hydrocodone.url Adware:Adware/nCase No disinfected C:\WINDOWS\180loader.exe Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\addvn32.exe Adware:Adware/CWS.008k No disinfected C:\WINDOWS\appaz32.exe Adware:Adware/SideStep No disinfected C:\WINDOWS\Downloaded Program Files\SbCIe026.dll Virus:Trj/Downloader.DKJ Disinfected C:\WINDOWS\sdkqu32.exe Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\system32\netgk32.exe **** Thanks so much for the help... what next? |
|
|
|
|
#4 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,409
OS: N/A
|
Looks like we opened Pandora's Box & all the worms came crawling out.
First thing on the agenda (something which I failed to notice earlier) You are currently running an outdated version of HiJackThis. Please click on the link below to download the most current version:Delete your current HiJackThis.exe file and double-click on the file you just downloaded and then click on the Unzip button to install the newer version. It will be installed to the C:\Program Files\HiJackThis\ directory by default. I would require your next HJT log to be from this newer version ~~~~~~~~~~~~~~ Please download these additional files/programs :- (Do not run them unless instructed to do so) Unplug your computer from the Internet when you have finished downloading CWShredder - Save on Desktop. Run CWShredder & click on the [Check for update] button. Exit the program after it has updated itself. SpSeHjfix - Save to a new folder on desktop ~~~~~~~~~~~~~~ Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard. C:\WINDOWS\system32\auapd.dllStart KillBox.
* If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try Killbox again. ~~~~~~~~~~~~~~ Reboot to SafeMode
~~~~~~~~~~~~~~ Run a scan with HiJackThis & select(tick) the following & click [Fix checked] : R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049 R3 - Default URLSearchHook is missing O2 - BHO: Class - {003156AA-B2AD-54C8-CF6D-1C992B937149} - C:\WINDOWS\system32\apidt.dll O2 - BHO: Class - {146A4A8B-66F9-80FA-6E14-51A6991BAC7D} - C:\WINDOWS\system32\apibs32.dll O2 - BHO: Class - {4ABB5929-6D33-1BD3-5889-307B70AC94D2} - C:\WINDOWS\system32\crxz.dll O2 - BHO: Class - {5CE5B985-51B1-3958-E5DB-92DD9091CFBB} - C:\WINDOWS\javavq.dll O2 - BHO: Class - {63C3B90C-CAE8-913A-DBA5-AC8E0D0896D0} - C:\WINDOWS\system32\crbk32.dll O2 - BHO: Class - {6827E44A-FCD1-5704-0FF9-EE64FBCBD77F} - C:\WINDOWS\system32\wingm32.dll O2 - BHO: Class - {7D52FC72-76A8-77EF-270D-8A1A8EA30F96} - C:\WINDOWS\system32\winsx32.dll O2 - BHO: Class - {91D042E7-25DF-B6F2-5C0C-B0963EF3EA01} - C:\WINDOWS\winqv32.dll O2 - BHO: Class - {A4913EBE-69AB-7C2E-EA16-13F6C5E79E14} - C:\WINDOWS\system32\ipvh32.dll O2 - BHO: Class - {C1A7352F-7207-2C2F-6A41-8C46196F8284} - C:\WINDOWS\system32\winug32.dll O2 - BHO: Class - {C2EFCA32-D3CF-3801-B32F-6A7589AA0A8A} - C:\WINDOWS\netfd.dll O2 - BHO: Class - {FEF289B2-6015-9A71-D02D-8394ED825678} - C:\WINDOWS\system32\javany.dll O4 - HKLM\..\Run: [iesn.exe] C:\WINDOWS\system32\iesn.exe O4 - HKLM\..\Run: [crbk32.exe] C:\WINDOWS\system32\crbk32.exe O4 - HKLM\..\RunOnce: [apiua.exe] C:\WINDOWS\apiua.exe O4 - HKLM\..\RunOnce: [crnf.exe] C:\WINDOWS\crnf.exe O4 - HKLM\..\RunOnce: [appxr32.exe] C:\WINDOWS\system32\appxr32.exe O4 - HKLM\..\RunOnce: [mfcpj32.exe] C:\WINDOWS\system32\mfcpj32.exe O4 - HKLM\..\RunOnce: [mfcsy32.exe] C:\WINDOWS\mfcsy32.exe O4 - HKLM\..\RunOnce: [javaad32.exe] C:\WINDOWS\system32\javaad32.exe O4 - HKLM\..\RunOnce: [iexj.exe] C:\WINDOWS\system32\iexj.exe O4 - HKLM\..\RunOnce: [ipfp.exe] C:\WINDOWS\system32\ipfp.exe O4 - HKLM\..\RunOnce: [addvf.exe] C:\WINDOWS\system32\addvf.exe O4 - HKLM\..\RunOnce: [appkj32.exe] C:\WINDOWS\appkj32.exe O4 - HKLM\..\RunOnce: [addyu.exe] C:\WINDOWS\system32\addyu.exe O4 - HKLM\..\RunOnce: [netkc32.exe] C:\WINDOWS\netkc32.exe O4 - HKLM\..\RunOnce: [crcy.exe] C:\WINDOWS\system32\crcy.exe O4 - HKLM\..\RunOnce: [sysxo.exe] C:\WINDOWS\sysxo.exe O4 - HKLM\..\RunOnce: [msvh32.exe] C:\WINDOWS\msvh32.exe O4 - HKLM\..\RunOnce: [addua.exe] C:\WINDOWS\addua.exe O4 - HKLM\..\RunOnce: [addyp.exe] C:\WINDOWS\addyp.exe O4 - HKLM\..\RunOnce: [crzj32.exe] C:\WINDOWS\crzj32.exe O4 - HKLM\..\RunOnce: [msul32.exe] C:\WINDOWS\msul32.exe O4 - HKLM\..\RunOnce: [crnn.exe] C:\WINDOWS\crnn.exe O4 - HKLM\..\RunOnce: [winsx.exe] C:\WINDOWS\winsx.exe O4 - HKLM\..\RunOnce: [crff32.exe] C:\WINDOWS\system32\crff32.exe O16 - DPF: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} (JInitiator 1.3.1.13) - https://esis.ncwise.org/jinitiator/jinit.exe O16 - DPF: {D27FFC5F-D7B9-4349-9F41-F7458B585374} (SoloTriv Control) - http://mirror.worldwinner.com/games...iv/solotriv.cab ~~~~~~~~~~~~~~ Enable the viewing of Hidden files
Locate and delete the following folder(s), if present:
~~~~~~~~~~~~~~ Run Cleanup! & configure the program up as follows:
~~~~~~~~~~~~~~ Run SpSeHjfix and click on [Start Disinfection]. If SpSeHjfix finds the "system clean", it will not proceed with the next stage. Otherwise, it may reboot your machine to finish the cleaning process. A log of the fix will be created in the containing folder. Run CWShredder & Click the [Fix] button. ~~~~~~~~~~~~~~ Reboot and download Trend Micro™ Anti-Spyware for the Web Utility (by clicking the "Scan and Clean your PC" button).
In your next post, please include fresh copies of: 1. HiJackThis log 2. Antispyware.log 3. SpSeHjfix's log Please provide details of any problems you encountered whilst performing the above steps. Update us on how your computer behaves now
__________________
Question - what have you done for the community today? |
|
|
|
|
#5 (permalink) |
|
Registered User
Join Date: Sep 2004
Posts: 11
OS: XP Professional
|
thanks....next?
HJT log:
Logfile of HijackThis v1.99.1 Scan saved at 8:57:25 PM, on 7/12/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\msiexec.exe C:\WINDOWS\system32\MsiExec.exe C:\WINDOWS\iegn32.exe C:\WINDOWS\System32\sistray.EXE C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\System32\dpmw32.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\NWTRAY.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DLink\Bluetooth Software\BTTray.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R3 - Default URLSearchHook is missing O2 - BHO: Class - {710D83F2-D312-9683-955D-E46F3DC64541} - C:\WINDOWS\ipyk32.dll O2 - BHO: Class - {A512FB1C-927A-CC1E-86A8-0057B192600A} - C:\WINDOWS\msde.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Class - {C9AAF6C6-1AF0-F61B-55AB-4198770AA549} - C:\WINDOWS\system32\ipwa.dll O2 - BHO: Class - {DA692D53-0117-E647-4FC9-E8D29D3E7D5F} - C:\WINDOWS\system32\ntog32.dll O2 - BHO: Class - {E2CF3F20-7B47-7FDF-0B4B-317598789569} - C:\WINDOWS\system32\appnn.dll O2 - BHO: Class - {F00ADCBD-1759-E8D3-3EB9-1B8318EAC367} - C:\WINDOWS\mssh32.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE O4 - HKLM\..\Run: [ntal32.exe] C:\WINDOWS\system32\ntal32.exe O4 - HKLM\..\Run: [iegn32.exe] C:\WINDOWS\iegn32.exe O4 - HKLM\..\RunOnce: [addok32.exe] C:\WINDOWS\system32\addok32.exe O4 - HKLM\..\RunOnce: [mfcso32.exe] C:\WINDOWS\mfcso32.exe O4 - HKLM\..\RunOnce: [sysgi.exe] C:\WINDOWS\sysgi.exe O4 - HKLM\..\RunOnce: [ntml.exe] C:\WINDOWS\ntml.exe O4 - HKLM\..\RunOnce: [apinx.exe] C:\WINDOWS\apinx.exe O4 - HKLM\..\RunOnce: [wingp32.exe] C:\WINDOWS\system32\wingp32.exe O4 - HKLM\..\RunOnce: [atlls.exe] C:\WINDOWS\atlls.exe O4 - HKLM\..\RunOnce: [apiop32.exe] C:\WINDOWS\system32\apiop32.exe O4 - HKLM\..\RunOnce: [netpc32.exe] C:\WINDOWS\system32\netpc32.exe O4 - HKLM\..\RunOnce: [appfq32.exe] C:\WINDOWS\appfq32.exe O4 - HKLM\..\RunOnce: [ipju32.exe] C:\WINDOWS\system32\ipju32.exe O4 - HKLM\..\RunOnce: [ipaq.exe] C:\WINDOWS\system32\ipaq.exe O4 - HKLM\..\RunOnce: [d3qv.exe] C:\WINDOWS\d3qv.exe O4 - HKLM\..\RunOnce: [crzb.exe] C:\WINDOWS\system32\crzb.exe O4 - HKLM\..\RunOnce: [winel.exe] C:\WINDOWS\winel.exe O4 - HKLM\..\RunOnce: [mfcxk.exe] C:\WINDOWS\system32\mfcxk.exe O4 - HKLM\..\RunOnce: [msde.exe] C:\WINDOWS\msde.exe O4 - HKLM\..\RunOnce: [mfcuk32.exe] C:\WINDOWS\mfcuk32.exe O4 - HKLM\..\RunOnce: [javajh.exe] C:\WINDOWS\system32\javajh.exe O4 - HKLM\..\RunOnce: [javanh32.exe] C:\WINDOWS\system32\javanh32.exe O4 - HKLM\..\RunOnce: [netde.exe] C:\WINDOWS\netde.exe O4 - HKLM\..\RunOnce: [addca32.exe] C:\WINDOWS\addca32.exe O4 - HKLM\..\RunOnce: [sdkfr.exe] C:\WINDOWS\sdkfr.exe O4 - HKLM\..\RunOnce: [d3jv32.exe] C:\WINDOWS\system32\d3jv32.exe O4 - HKLM\..\RunOnce: [atlnf32.exe] C:\WINDOWS\system32\atlnf32.exe O4 - HKLM\..\RunOnce: [netdm.exe] C:\WINDOWS\system32\netdm.exe O4 - HKLM\..\RunOnce: [d3bh32.exe] C:\WINDOWS\d3bh32.exe O4 - HKLM\..\RunOnce: [winxl32.exe] C:\WINDOWS\winxl32.exe O4 - HKLM\..\RunOnce: [addqq32.exe] C:\WINDOWS\system32\addqq32.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: BTTray.lnk = ? O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\DLink\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addok32.exe" /s (file missing) O23 - Service: avinitnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: schscnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\schscnt.exe O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe Antispyware Started Scanning Internet Cookies Programs in Memory Windows Registry Found '' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA' Found '' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE' Found '' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW' Found 'DisplayName' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA' Found 'UninstallString' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA' Found 'DisplayName' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE' Found 'UninstallString' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE' Found 'DisplayName' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW' Found 'UninstallString' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW' Found '' in 'CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5}' Found '' in 'SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5}' Internet URL Shortcuts Files and Directories Finished Scanning Started Backup Finished Backup Started Cleaning Finished Cleaning SpSeHjfix's log (7/12/05 5:30:22 PM) SPSeHjFix started v1.1.2 (7/12/05 5:30:22 PM) OS: WinXP Service Pack 2 (5.1.2600) (7/12/05 5:30:22 PM) Language: english (7/12/05 5:30:22 PM) Win-Path: C:\WINDOWS (7/12/05 5:30:22 PM) System-Path: C:\WINDOWS\system32 (7/12/05 5:30:22 PM) Temp-Path: C:\DOCUME~1\jthomps\LOCALS~1\Temp\ (7/12/05 5:30:28 PM) Disinfection started (7/12/05 5:30:28 PM) Bad-Dll(IEP): (not found) (7/12/05 5:30:28 PM) Bad-Dll(IEP) in BHO: (not found) (7/12/05 5:30:28 PM) UBF: 4 - UBB: 1 - UBR: 94 (7/12/05 5:30:28 PM) UBF: 4 - UBB: 1 - UBR: 94 (7/12/05 5:30:28 PM) Bad IE-pages: deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank (7/12/05 5:30:28 PM) Stealth-String not found (7/12/05 5:30:28 PM) Not infected->END (7/12/05 5:31:21 PM) SPSeHjFix started v1.1.2 (7/12/05 5:31:21 PM) OS: WinXP Service Pack 2 (5.1.2600) (7/12/05 5:31:21 PM) Language: english (7/12/05 5:31:21 PM) Win-Path: C:\WINDOWS (7/12/05 5:31:21 PM) System-Path: C:\WINDOWS\system32 (7/12/05 5:31:21 PM) Temp-Path: C:\DOCUME~1\jthomps\LOCALS~1\Temp\ (7/12/05 5:31:23 PM) Disinfection started (7/12/05 5:31:23 PM) Bad-Dll(IEP): (not found) (7/12/05 5:31:23 PM) Bad-Dll(IEP) in BHO: (not found) (7/12/05 5:31:23 PM) UBF: 4 - UBB: 1 - UBR: 94 (7/12/05 5:31:23 PM) UBF: 4 - UBB: 1 - UBR: 94 (7/12/05 5:31:23 PM) Bad IE-pages: (none) (7/12/05 5:31:23 PM) Stealth-String not found (7/12/05 5:31:23 PM) Not infected->END Thanks for your continued help.... |
|
|
|
|
#6 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,409
OS: N/A
|
Looks so much cleaner. We're getting close to home. The log done by the updated HJT has shown a new entry.
Please disable Webroot SpySweeper, as it may hinder the removal of some entries. You can re-enable it after you're clean. To disable Webroot SpySweeper:
~~~~~~~~~~~~~~ Remove a Malware Service
~~~~~~~~~~~~~~ Start HiJackThis & go to Config>Misc Tools>Open process manager Select the following and click [Kill process] one at a time. Some entries may no longer exist. C:\WINDOWS\iegn32.exe~~~~~~~~~~~~~~ Run a scan with HiJackThis & select(tick) the following & click [Fix checked] : R3 - Default URLSearchHook is missing O2 - BHO: Class - {710D83F2-D312-9683-955D-E46F3DC64541} - C:\WINDOWS\ipyk32.dll O2 - BHO: Class - {A512FB1C-927A-CC1E-86A8-0057B192600A} - C:\WINDOWS\msde.dll O2 - BHO: Class - {C9AAF6C6-1AF0-F61B-55AB-4198770AA549} - C:\WINDOWS\system32\ipwa.dll O2 - BHO: Class - {DA692D53-0117-E647-4FC9-E8D29D3E7D5F} - C:\WINDOWS\system32\ntog32.dll O2 - BHO: Class - {E2CF3F20-7B47-7FDF-0B4B-317598789569} - C:\WINDOWS\system32\appnn.dll O2 - BHO: Class - {F00ADCBD-1759-E8D3-3EB9-1B8318EAC367} - C:\WINDOWS\mssh32.dll O4 - HKLM\..\Run: [ntal32.exe] C:\WINDOWS\system32\ntal32.exe O4 - HKLM\..\Run: [iegn32.exe] C:\WINDOWS\iegn32.exe O4 - HKLM\..\RunOnce: [addok32.exe] C:\WINDOWS\system32\addok32.exe O4 - HKLM\..\RunOnce: [mfcso32.exe] C:\WINDOWS\mfcso32.exe O4 - HKLM\..\RunOnce: [sysgi.exe] C:\WINDOWS\sysgi.exe O4 - HKLM\..\RunOnce: [ntml.exe] C:\WINDOWS\ntml.exe O4 - HKLM\..\RunOnce: [apinx.exe] C:\WINDOWS\apinx.exe O4 - HKLM\..\RunOnce: [wingp32.exe] C:\WINDOWS\system32\wingp32.exe O4 - HKLM\..\RunOnce: [atlls.exe] C:\WINDOWS\atlls.exe O4 - HKLM\..\RunOnce: [apiop32.exe] C:\WINDOWS\system32\apiop32.exe O4 - HKLM\..\RunOnce: [netpc32.exe] C:\WINDOWS\system32\netpc32.exe O4 - HKLM\..\RunOnce: [appfq32.exe] C:\WINDOWS\appfq32.exe O4 - HKLM\..\RunOnce: [ipju32.exe] C:\WINDOWS\system32\ipju32.exe O4 - HKLM\..\RunOnce: [ipaq.exe] C:\WINDOWS\system32\ipaq.exe O4 - HKLM\..\RunOnce: [d3qv.exe] C:\WINDOWS\d3qv.exe O4 - HKLM\..\RunOnce: [crzb.exe] C:\WINDOWS\system32\crzb.exe O4 - HKLM\..\RunOnce: [winel.exe] C:\WINDOWS\winel.exe O4 - HKLM\..\RunOnce: [mfcxk.exe] C:\WINDOWS\system32\mfcxk.exe O4 - HKLM\..\RunOnce: [msde.exe] C:\WINDOWS\msde.exe O4 - HKLM\..\RunOnce: [mfcuk32.exe] C:\WINDOWS\mfcuk32.exe O4 - HKLM\..\RunOnce: [javajh.exe] C:\WINDOWS\system32\javajh.exe O4 - HKLM\..\RunOnce: [javanh32.exe] C:\WINDOWS\system32\javanh32.exe O4 - HKLM\..\RunOnce: [netde.exe] C:\WINDOWS\netde.exe O4 - HKLM\..\RunOnce: [addca32.exe] C:\WINDOWS\addca32.exe O4 - HKLM\..\RunOnce: [sdkfr.exe] C:\WINDOWS\sdkfr.exe O4 - HKLM\..\RunOnce: [d3jv32.exe] C:\WINDOWS\system32\d3jv32.exe O4 - HKLM\..\RunOnce: [atlnf32.exe] C:\WINDOWS\system32\atlnf32.exe O4 - HKLM\..\RunOnce: [netdm.exe] C:\WINDOWS\system32\netdm.exe O4 - HKLM\..\RunOnce: [d3bh32.exe] C:\WINDOWS\d3bh32.exe O4 - HKLM\..\RunOnce: [winxl32.exe] C:\WINDOWS\winxl32.exe O4 - HKLM\..\RunOnce: [addqq32.exe] C:\WINDOWS\system32\addqq32.exe O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addok32.exe" /s (file missing) ~~~~~~~~~~~~~~ Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard. C:\WINDOWS\ipyk32.dllStart KillBox.
~~~~~~~~~~~~~~ Upon reboot, post a fresh HJT log
__________________
Question - what have you done for the community today? Last edited by sUBs; 07-12-2005 at 09:35 PM. |
|
|
|
|
#7 (permalink) |
|
Registered User
Join Date: Sep 2004
Posts: 11
OS: XP Professional
|
getting there...
Still a bit slow on startup....But again thanks for the help, big time.
Verify that you've done this properly by clicking the dropdown-arrow next to the "Full Path of File to Delete" field. The filenames you pasted will be found in there. Do not be alarmed if several of these entries do not appear. Let me know which one appeared. These didn't appear in Killbox: c:\windows\ipyk32.dll c:\windows\mssh32.dll Here's the HJT log: Logfile of HijackThis v1.99.1 Scan saved at 9:40:54 PM, on 7/13/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe C:\WINDOWS\Explorer.EXE C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\msiexec.exe C:\WINDOWS\ntol32.exe C:\WINDOWS\system32\MsiExec.exe C:\WINDOWS\System32\sistray.EXE C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\System32\dpmw32.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\NWTRAY.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DLink\Bluetooth Software\BTTray.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\txvun.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\txvun.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\txvun.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\txvun.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\txvun.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\txvun.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\txvun.dll/sp.html#37049 R3 - Default URLSearchHook is missing O2 - BHO: Class - {095933F6-AE92-4230-E373-22A96F9C0C5F} - C:\WINDOWS\msnu32.dll O2 - BHO: Class - {0B1EC0AC-4B60-2E3C-6008-EA958BCC19DD} - C:\WINDOWS\ieto32.dll O2 - BHO: Class - {116B5897-9869-1B77-3DC7-646F9CB58D2B} - C:\WINDOWS\system32\msrn32.dll O2 - BHO: Class - {14763206-F6A7-4D6F-D4D5-2E72E367ABB1} - C:\WINDOWS\system32\apiqa32.dll O2 - BHO: Class - {33EC6E43-4826-94FA-3A03-B94290B62B85} - C:\WINDOWS\ieij.dll O2 - BHO: Class - {378AE8EE-0426-C141-F3C8-F6BD25766BFA} - C:\WINDOWS\iegh.dll O2 - BHO: Class - {4EC161EA-4FC8-150B-C21E-5378B07ABE5D} - C:\WINDOWS\system32\javafq.dll O2 - BHO: Class - {4F9E4629-7EAF-1FF6-F770-E08CAFC44CC5} - C:\WINDOWS\atlou.dll O2 - BHO: Class - {544B7F26-ABCC-6632-0DB7-C12341FA8D26} - C:\WINDOWS\mfcco32.dll O2 - BHO: Class - {5650AA43-7586-D4A3-49D9-D9FB154279D6} - C:\WINDOWS\system32\apilk.dll O2 - BHO: Class - {56791174-6E86-7AEF-B404-ED9E42ABFF73} - C:\WINDOWS\winvc.dll O2 - BHO: Class - {64E5E8FA-69A1-48F4-8963-F00907CAAF17} - C:\WINDOWS\system32\ntvx.dll O2 - BHO: Class - {686EDB70-FD7A-B9A7-77C0-4C7E44057CFF} - C:\WINDOWS\nthq32.dll O2 - BHO: Class - {72B3B578-A76A-7C0A-70B4-F15E624D8319} - C:\WINDOWS\system32\ntjs32.dll O2 - BHO: Class - {73C994D2-169A-3A21-18CA-289B70E63DA3} - C:\WINDOWS\sdklb32.dll O2 - BHO: Class - {77CD9B7C-6604-FD84-83FE-47AE9E1477C2} - C:\WINDOWS\system32\mspd32.dll O2 - BHO: Class - {793213B8-A74C-2C0F-94D1-DD4AC65FBE45} - C:\WINDOWS\system32\mfceq32.dll O2 - BHO: Class - {7AEF1698-E8CD-4535-C196-EAEADE211A17} - C:\WINDOWS\system32\appaa.dll O2 - BHO: Class - {7E895675-8786-0AE8-F4FB-E7CDC57A70B8} - C:\WINDOWS\appwp32.dll O2 - BHO: Class - {80C01395-9FF4-13F4-EE8C-750CC0B764CF} - C:\WINDOWS\javazw.dll O2 - BHO: Class - {90706F45-D241-085D-C3F4-2CA0366EF00C} - C:\WINDOWS\system32\iprm.dll O2 - BHO: Class - {964D3DD2-09FB-6B41-D4A8-3F2010E2B8A5} - C:\WINDOWS\iptw.dll O2 - BHO: Class - {979130FE-70C0-35E6-DFA3-4D4D55876849} - C:\WINDOWS\atlqw.dll O2 - BHO: Class - {97C211C9-3E29-A7D3-5DB7-A9B8789A8C69} - C:\WINDOWS\system32\sdknl32.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Class - {AC8C8EF2-B1DB-E428-AE33-869E38C4F846} - C:\WINDOWS\d3bj.dll O2 - BHO: Class - {AD057E36-3E90-9C24-A714-A8ADE460FBF9} - C:\WINDOWS\ntxh.dll O2 - BHO: Class - {B3205B60-1D3F-AADD-01D0-77FF30CC211B} - C:\WINDOWS\system32\atlml.dll O2 - BHO: Class - {B4CF1A3D-BFA2-5C15-720D-3E33706227F0} - C:\WINDOWS\winyn32.dll O2 - BHO: Class - {C70A9850-BFBE-FA80-AEBC-F027897A9AC5} - C:\WINDOWS\sdkpm32.dll O2 - BHO: Class - {C7F1A546-4FA4-2F1E-B74E-2A722FED05AC} - C:\WINDOWS\system32\appyq32.dll O2 - BHO: Class - {C8B127F3-B154-FA38-4A64-BAAF01543DCD} - C:\WINDOWS\system32\sysks.dll O2 - BHO: Class - {D34815E7-66F7-C465-A083-5BABECE896F5} - C:\WINDOWS\system32\mfcsf32.dll O2 - BHO: Class - {D59AC151-F00C-3509-5093-1C3589B36680} - C:\WINDOWS\appkj.dll O2 - BHO: Class - {E0E5A173-0CF3-BCA9-8543-4B6252CD9DA6} - C:\WINDOWS\winao32.dll O2 - BHO: Class - {E22C1991-1181-9BEB-C171-E0B7E631A3AF} - C:\WINDOWS\sysmu.dll O2 - BHO: Class - {E931541A-F610-204D-5340-6A7598B41F6B} - C:\WINDOWS\system32\ieey.dll O2 - BHO: Class - {EAF521EB-5513-475B-B2B3-4D4B1195A1B0} - C:\WINDOWS\mfcgz32.dll O2 - BHO: Class - {FC99EFF4-58A4-239B-1E0E-184CC2DCD960} - C:\WINDOWS\system32\msls32.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE O4 - HKLM\..\Run: [ipur.exe] C:\WINDOWS\ipur.exe O4 - HKLM\..\Run: [ntol32.exe] C:\WINDOWS\ntol32.exe O4 - HKLM\..\RunOnce: [ieqz32.exe] C:\WINDOWS\system32\ieqz32.exe O4 - HKLM\..\RunOnce: [appxl32.exe] C:\WINDOWS\system32\appxl32.exe O4 - HKLM\..\RunOnce: [atlqj.exe] C:\WINDOWS\atlqj.exe O4 - HKLM\..\RunOnce: [sdkaf.exe] C:\WINDOWS\sdkaf.exe O4 - HKLM\..\RunOnce: [appyo.exe] C:\WINDOWS\system32\appyo.exe O4 - HKLM\..\RunOnce: [crmq.exe] C:\WINDOWS\system32\crmq.exe O4 - HKLM\..\RunOnce: [d3gi.exe] C:\WINDOWS\d3gi.exe O4 - HKLM\..\RunOnce: [iegn32.exe] C:\WINDOWS\system32\iegn32.exe O4 - HKLM\..\RunOnce: [atlqm.exe] C:\WINDOWS\atlqm.exe O4 - HKLM\..\RunOnce: [addoh.exe] C:\WINDOWS\addoh.exe O4 - HKLM\..\RunOnce: [d3hx32.exe] C:\WINDOWS\system32\d3hx32.exe O4 - HKLM\..\RunOnce: [addar.exe] C:\WINDOWS\system32\addar.exe O4 - HKLM\..\RunOnce: [apinr32.exe] C:\WINDOWS\apinr32.exe O4 - HKLM\..\RunOnce: [atlri.exe] C:\WINDOWS\system32\atlri.exe O4 - HKLM\..\RunOnce: [crap32.exe] C:\WINDOWS\crap32.exe O4 - HKLM\..\RunOnce: [ntsn.exe] C:\WINDOWS\ntsn.exe O4 - HKLM\..\RunOnce: [ntne.exe] C:\WINDOWS\ntne.exe O4 - HKLM\..\RunOnce: [d3ms32.exe] C:\WINDOWS\system32\d3ms32.exe O4 - HKLM\..\RunOnce: [d3ee.exe] C:\WINDOWS\system32\d3ee.exe O4 - HKLM\..\RunOnce: [ippv32.exe] C:\WINDOWS\ippv32.exe O4 - HKLM\..\RunOnce: [msww.exe] C:\WINDOWS\msww.exe O4 - HKLM\..\RunOnce: [d3mc.exe] C:\WINDOWS\d3mc.exe O4 - HKLM\..\RunOnce: [iexy32.exe] C:\WINDOWS\iexy32.exe O4 - HKLM\..\RunOnce: [ieuy.exe] C:\WINDOWS\system32\ieuy.exe O4 - HKLM\..\RunOnce: [d3st32.exe] C:\WINDOWS\system32\d3st32.exe O4 - HKLM\..\RunOnce: [appvi32.exe] C:\WINDOWS\system32\appvi32.exe O4 - HKLM\..\RunOnce: [sdkqa32.exe] C:\WINDOWS\sdkqa32.exe O4 - HKLM\..\RunOnce: [crhk.exe] C:\WINDOWS\system32\crhk.exe O4 - HKLM\..\RunOnce: [ipab.exe] C:\WINDOWS\ipab.exe O4 - HKLM\..\RunOnce: [iejh32.exe] C:\WINDOWS\iejh32.exe O4 - HKLM\..\RunOnce: [mfcyw.exe] C:\WINDOWS\system32\mfcyw.exe O4 - HKLM\..\RunOnce: [netyk32.exe] C:\WINDOWS\netyk32.exe O4 - HKLM\..\RunOnce: [mfcbl.exe] C:\WINDOWS\mfcbl.exe O4 - HKLM\..\RunOnce: [winay.exe] C:\WINDOWS\system32\winay.exe O4 - HKLM\..\RunOnce: [netql.exe] C:\WINDOWS\netql.exe O4 - HKLM\..\RunOnce: [msyw32.exe] C:\WINDOWS\msyw32.exe O4 - HKLM\..\RunOnce: [ntlw32.exe] C:\WINDOWS\ntlw32.exe O4 - HKLM\..\RunOnce: [cryy.exe] C:\WINDOWS\system32\cryy.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: BTTray.lnk = ? O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\DLink\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addok32.exe" /s (file missing) O23 - Service: avinitnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: schscnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\schscnt.exe O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe |
|
|
|
|
#8 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,409
OS: N/A
|
Please download these additional files/programs :- (Do not run them unless instructed to do so)
Unplug your computer from the Internet when you have finished downloading TDS-3 - & Install. Close it after you have finished installation. Download & overwrite the existing file - "radius.td3", located in folder >> C:\Program Files\TDS-3\ with this file About Buster - Unzip to a new folder on Desktop. Update About Buster & exit the program once that is completed. Ewido Security Suite - Install & Update it's database but do not run it yet. cwsserviceremove.zip - Unzip the contents of cwsserviceremove.zip (cwsserviceremove.reg) to your desktop. Backdoor.Agent.B Removal Tool from Symantec.
~~~~~~~~~~~~~~ Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard. C:\WINDOWS\msnu32.dllStart KillBox.
~~~~~~~~~~~~~~ Reboot to SafeMode Run CWShredder:
Remove the offending service:
~~~~~~~~~~~~~~ Run a scan with HiJackThis & select(tick) the following & click [Fix checked] : R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\txvun.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\txvun.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\txvun.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\txvun.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\txvun.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\txvun.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\txvun.dll/sp.html#37049 R3 - Default URLSearchHook is missing O2 - BHO: Class - {095933F6-AE92-4230-E373-22A96F9C0C5F} - C:\WINDOWS\msnu32.dll O2 - BHO: Class - {0B1EC0AC-4B60-2E3C-6008-EA958BCC19DD} - C:\WINDOWS\ieto32.dll O2 - BHO: Class - {116B5897-9869-1B77-3DC7-646F9CB58D2B} - C:\WINDOWS\system32\msrn32.dll O2 - BHO: Class - {14763206-F6A7-4D6F-D4D5-2E72E367ABB1} - C:\WINDOWS\system32\apiqa32.dll O2 - BHO: Class - {33EC6E43-4826-94FA-3A03-B94290B62B85} - C:\WINDOWS\ieij.dll O2 - BHO: Class - {378AE8EE-0426-C141-F3C8-F6BD25766BFA} - C:\WINDOWS\iegh.dll O2 - BHO: Class - {4EC161EA-4FC8-150B-C21E-5378B07ABE5D} - C:\WINDOWS\system32\javafq.dll O2 - BHO: Class - {4F9E4629-7EAF-1FF6-F770-E08CAFC44CC5} - C:\WINDOWS\atlou.dll O2 - BHO: Class - {544B7F26-ABCC-6632-0DB7-C12341FA8D26} - C:\WINDOWS\mfcco32.dll O2 - BHO: Class - {5650AA43-7586-D4A3-49D9-D9FB154279D6} - C:\WINDOWS\system32\apilk.dll O2 - BHO: Class - {56791174-6E86-7AEF-B404-ED9E42ABFF73} - C:\WINDOWS\winvc.dll O2 - BHO: Class - {64E5E8FA-69A1-48F4-8963-F00907CAAF17} - C:\WINDOWS\system32\ntvx.dll O2 - BHO: Class - {686EDB70-FD7A-B9A7-77C0-4C7E44057CFF} - C:\WINDOWS\nthq32.dll O2 - BHO: Class - {72B3B578-A76A-7C0A-70B4-F15E624D8319} - C:\WINDOWS\system32\ntjs32.dll O2 - BHO: Class - {73C994D2-169A-3A21-18CA-289B70E63DA3} - C:\WINDOWS\sdklb32.dll O2 - BHO: Class - {77CD9B7C-6604-FD84-83FE-47AE9E1477C2} - C:\WINDOWS\system32\mspd32.dll O2 - BHO: Class - {793213B8-A74C-2C0F-94D1-DD4AC65FBE45} - C:\WINDOWS\system32\mfceq32.dll O2 - BHO: Class - {7AEF1698-E8CD-4535-C196-EAEADE211A17} - C:\WINDOWS\system32\appaa.dll O2 - BHO: Class - {7E895675-8786-0AE8-F4FB-E7CDC57A70B8} - C:\WINDOWS\appwp32.dll O2 - BHO: Class - {80C01395-9FF4-13F4-EE8C-750CC0B764CF} - C:\WINDOWS\javazw.dll O2 - BHO: Class - {90706F45-D241-085D-C3F4-2CA0366EF00C} - C:\WINDOWS\system32\iprm.dll O2 - BHO: Class - {964D3DD2-09FB-6B41-D4A8-3F2010E2B8A5} - C:\WINDOWS\iptw.dll O2 - BHO: Class - {979130FE-70C0-35E6-DFA3-4D4D55876849} - C:\WINDOWS\atlqw.dll O2 - BHO: Class - {97C211C9-3E29-A7D3-5DB7-A9B8789A8C69} - C:\WINDOWS\system32\sdknl32.dll O2 - BHO: Class - {AC8C8EF2-B1DB-E428-AE33-869E38C4F846} - C:\WINDOWS\d3bj.dll O2 - BHO: Class - {AD057E36-3E90-9C24-A714-A8ADE460FBF9} - C:\WINDOWS\ntxh.dll O2 - BHO: Class - {B3205B60-1D3F-AADD-01D0-77FF30CC211B} - C:\WINDOWS\system32\atlml.dll O2 - BHO: Class - {B4CF1A3D-BFA2-5C15-720D-3E33706227F0} - C:\WINDOWS\winyn32.dll O2 - BHO: Class - {C70A9850-BFBE-FA80-AEBC-F027897A9AC5} - C:\WINDOWS\sdkpm32.dll O2 - BHO: Class - {C7F1A546-4FA4-2F1E-B74E-2A722FED05AC} - C:\WINDOWS\system32\appyq32.dll O2 - BHO: Class - {C8B127F3-B154-FA38-4A64-BAAF01543DCD} - C:\WINDOWS\system32\sysks.dll O2 - BHO: Class - {D34815E7-66F7-C465-A083-5BABECE896F5} - C:\WINDOWS\system32\mfcsf32.dll O2 - BHO: Class - {D59AC151-F00C-3509-5093-1C3589B36680} - C:\WINDOWS\appkj.dll O2 - BHO: Class - {E0E5A173-0CF3-BCA9-8543-4B6252CD9DA6} - C:\WINDOWS\winao32.dll O2 - BHO: Class - {E22C1991-1181-9BEB-C171-E0B7E631A3AF} - C:\WINDOWS\sysmu.dll O2 - BHO: Class - {E931541A-F610-204D-5340-6A7598B41F6B} - C:\WINDOWS\system32\ieey.dll O2 - BHO: Class - {EAF521EB-5513-475B-B2B3-4D4B1195A1B0} - C:\WINDOWS\mfcgz32.dll O2 - BHO: Class - {FC99EFF4-58A4-239B-1E0E-184CC2DCD960} - C:\WINDOWS\system32\msls32.dll O4 - HKLM\..\Run: [ipur.exe] C:\WINDOWS\ipur.exe O4 - HKLM\..\Run: [ntol32.exe] C:\WINDOWS\ntol32.exe O4 - HKLM\..\RunOnce: [ieqz32.exe] C:\WINDOWS\system32\ieqz32.exe O4 - HKLM\..\RunOnce: [appxl32.exe] C:\WINDOWS\system32\appxl32.exe O4 - HKLM\..\RunOnce: [atlqj.exe] C:\WINDOWS\atlqj.exe O4 - HKLM\..\RunOnce: [sdkaf.exe] C:\WINDOWS\sdkaf.exe O4 - HKLM\..\RunOnce: [appyo.exe] C:\WINDOWS\system32\appyo.exe O4 - HKLM\..\RunOnce: [crmq.exe] C:\WINDOWS\system32\crmq.exe O4 - HKLM\..\RunOnce: [d3gi.exe] C:\WINDOWS\d3gi.exe O4 - HKLM\..\RunOnce: [iegn32.exe] C:\WINDOWS\system32\iegn32.exe O4 - HKLM\..\RunOnce: [atlqm.exe] C:\WINDOWS\atlqm.exe O4 - HKLM\..\RunOnce: [addoh.exe] C:\WINDOWS\addoh.exe O4 - HKLM\..\RunOnce: [d3hx32.exe] C:\WINDOWS\system32\d3hx32.exe O4 - HKLM\..\RunOnce: [addar.exe] C:\WINDOWS\system32\addar.exe O4 - HKLM\..\RunOnce: [apinr32.exe] C:\WINDOWS\apinr32.exe O4 - HKLM\..\RunOnce: [atlri.exe] C:\WINDOWS\system32\atlri.exe O4 - HKLM\..\RunOnce: [crap32.exe] C:\WINDOWS\crap32.exe O4 - HKLM\..\RunOnce: [ntsn.exe] C:\WINDOWS\ntsn.exe O4 - HKLM\..\RunOnce: [ntne.exe] C:\WINDOWS\ntne.exe O4 - HKLM\..\RunOnce: [d3ms32.exe] C:\WINDOWS\system32\d3ms32.exe O4 - HKLM\..\RunOnce: [d3ee.exe] C:\WINDOWS\system32\d3ee.exe O4 - HKLM\..\RunOnce: [ippv32.exe] C:\WINDOWS\ippv32.exe O4 - HKLM\..\RunOnce: [msww.exe] C:\WINDOWS\msww.exe O4 - HKLM\..\RunOnce: [d3mc.exe] C:\WINDOWS\d3mc.exe O4 - HKLM\..\RunOnce: [iexy32.exe] C:\WINDOWS\iexy32.exe O4 - HKLM\..\RunOnce: [ieuy.exe] C:\WINDOWS\system32\ieuy.exe O4 - HKLM\..\RunOnce: [d3st32.exe] C:\WINDOWS\system32\d3st32.exe O4 - HKLM\..\RunOnce: [appvi32.exe] C:\WINDOWS\system32\appvi32.exe O4 - HKLM\..\RunOnce: [sdkqa32.exe] C:\WINDOWS\sdkqa32.exe O4 - HKLM\..\RunOnce: [crhk.exe] C:\WINDOWS\system32\crhk.exe O4 - HKLM\..\RunOnce: [ipab.exe] C:\WINDOWS\ipab.exe O4 - HKLM\..\RunOnce: [iejh32.exe] C:\WINDOWS\iejh32.exe O4 - HKLM\..\RunOnce: [mfcyw.exe] C:\WINDOWS\system32\mfcyw.exe O4 - HKLM\..\RunOnce: [netyk32.exe] C:\WINDOWS\netyk32.exe O4 - HKLM\..\RunOnce: [mfcbl.exe] C:\WINDOWS\mfcbl.exe O4 - HKLM\..\RunOnce: [winay.exe] C:\WINDOWS\system32\winay.exe O4 - HKLM\..\RunOnce: [netql.exe] C:\WINDOWS\netql.exe O4 - HKLM\..\RunOnce: [msyw32.exe] C:\WINDOWS\msyw32.exe O4 - HKLM\..\RunOnce: [ntlw32.exe] C:\WINDOWS\ntlw32.exe O4 - HKLM\..\RunOnce: [cryy.exe] C:\WINDOWS\system32\cryy.exe O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addok32.exe" /s (file missing) ~~~~~~~~~~~~~~ Run Cleanup! & configure the program up as follows:
~~~~~~~~~~~~~~ Run AboutBuster and save the logs:
~~~~~~~~~~~~~~ ** Please disable all other antivirus programs before proceeding.** Run Ewido:
~~~~~~~~~~~~~~ Launch TDS-3 & it will scan your memory for running processes. This will take less than 30 seconds.
~~~~~~~~~~~~~~ Reboot to NormalMode. Do an online scan at Kaspersky Take note the names and locations of any file it detects but fails to clean. * Turn off the real time scanner of any existing antivirus program while performing the online scan Reboot Again & Run a new scan with HiJackThis. Save the log file and post the contents in your next reply. In your next post, please include fresh copies of: 1. HiJackThis log 2. List of files that online scans failed to disinfect 3. About Buster's log 4. TDS-3's log 5. Backdoor.Agent.B Removal Tool's log 6. Ewido's log Please provide details of any problems you encountered whilst performing the above steps. Update us on how your computer behaves now
__________________
Question - what have you done for the community today? |
|
|
|
|
#9 (permalink) |
|
Registered User
Join Date: Sep 2004
Posts: 11
OS: XP Professional
|
getting there...i think
Booting up a lot faster now...again, thanks so far.
1. HJT Log Logfile of HijackThis v1.99.1 Scan saved at 1:47:15 PM, on 7/15/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\ewido\security suite\ewidoguard.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe C:\WINDOWS\System32\sistray.EXE C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\System32\dpmw32.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\NWTRAY.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DLink\Bluetooth Software\BTTray.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\HijackThis\HijackThis.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\WINDOWS\system32\MsiExec.exe O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [appac.exe] C:\WINDOWS\system32\appac.exe O4 - HKLM\..\Run: [sysok.exe] C:\WINDOWS\sysok.exe O4 - HKLM\..\Run: [apprt.exe] C:\WINDOWS\apprt.exe O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: BTTray.lnk = ? O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\DLink\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/k...an_unicode.cab O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab O23 - Service: avinitnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: schscnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\schscnt.exe O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe 2. Online scans: Not sure if the Kaspersky scan deleted disinfected anything or not. The log file is huge-- here is a portion of it (if I need to post the whole thing let me know). Scan Settings: Scan using the following antivirus database: standard Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ Scan Statistics: Total number of scanned objects: 112384 Number of viruses found: 9 Number of infected objects: 14485 Number of suspicious objects: 2 Duration of the scan process: 4444 sec Infected Object Name - Virus Name C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-50757294-51d84901.zip/GetAccess.class Infected: Trojan.Java.ClassLoader.c C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-50757294-51d84901.zip/InsecureClassLoader.class Infected: Exploit.Java.Bytverify C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-50757294-51d84901.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-50757294-51d84901.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-50757294-51d84901.zip Infected: Trojan-Downloader.Java.OpenConnection.v C:\Documents and Settings\jthomps\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Deleted Items/10 May 2005 21:01 from Mail Delivery System:Mail delivery failed.eml/[From Webmaster@johnthompsonjr.com][Date Tue, 10 May 2005 16:59:56 -0400]/UNNAMED/email-doc.pif Infected: Net-Worm.Win32.Mytob.au C:\Documents and Settings\jthomps\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Deleted Items/10 May 2005 21:01 from Mail Delivery System:Mail delivery failed.eml/[From Webmaster@johnthompsonjr.com][Date Tue, 10 May 2005 16:59:56 -0400]/UNNAMED Infected: Net-Worm.Win32.Mytob.au C:\Documents and Settings\jthomps\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Deleted Items/10 May 2005 21:01 from Mail Delivery System:Mail delivery failed.eml Infected: Net-Worm.Win32.Mytob.au C:\Documents and Settings\jthomps\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Sent Items/19 Apr 2004 12:44 to 'Old North State Apiaries':RE: Mail Deliver.rtf Suspicious: Exploit.HTML.Iframe.FileDownload C:\Documents and Settings\jthomps\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Sent Items/20 Apr 2004 13:10 to 'Old North State Apiaries':RE: Mail Deliver.rtf Suspicious: Exploit.HTML.Iframe.FileDownload C:\Documents and Settings\jthomps\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Infected: Exploit.HTML.Iframe.FileDownload C:\System Volume Information\_restore{8BE5DB73-D7BE-4265-BEE7-58A995099902}\RP1\A0000001.pif:aafyu:$DATA Infected: Trojan-Downloader.Win32.Agent.bq C:\System Volume Information\_restore{8BE5DB73-D7BE-4265-BEE7-58A995099902}\RP1\A0000001.pif:aaocu:$DATA Infected: Trojan-Downloader.Win32.Agent.bq C:\System Volume Information\_restore{8BE5DB73-D7BE-4265-BEE7-58A995099902}\RP1\A0000001.pif:achpe:$DATA Infected: Trojan-Downloader.Win32.Agent.bq C:\System Volume Information\_restore{8BE5DB73-D7BE-4265-BEE7-58A995099902}\RP1\A0000001.pif:acqgo:$DATA Infected: Trojan-Downloader.Win32.Agent.bq C:\System Volume Information\_restore{8BE5DB73-D7BE-4265-BEE7-58A995099902}\RP1\A0000001.pif:actik:$DATA Infected: Trojan-Downloader.Win32.Agent.bq C:\System Volume Information\_restore{8BE5DB73-D7BE-4265-BEE7-58A995099902}\RP1\A0000001.pif:adbeb:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{8BE5DB73-D7BE-4265-BEE7-58A995099902}\RP1\A0000001.pif:adebb:$DATA Infected: Trojan-Downloader.Win32.Agent.bq C:\System Volume Information\_restore{8BE5DB73-D7BE-4265-BEE7-58A995099902}\RP1\A0000001.pif:aduaq:$DATA Infected: Trojan-Downloader.Win32.Agent.bq 3. About Buster's Log AboutBuster 5.0 reference file 28 Scan started on [7/14/2005] at [9:50:32 PM] ------------------------------------------------ Removed Stream! C:\WINDOWS\_default.pif:bztdhe ------------------------------------------------ Removed File! : C:\Windows\duehu.dat Removed File! : C:\Windows\idzmc.dat Removed File! : C:\Windows\ijmii.dll Removed File! : C:\Windows\iultz.dll Removed File! : C:\Windows\jyqxt.dat Removed File! : C:\Windows\kgdkx.dll Removed File! : C:\Windows\oqtqd.dat Removed File! : C:\Windows\pomfj.dat Removed File! : C:\Windows\tbijr.dat Removed File! : C:\Windows\txvun.dll Removed File! : C:\Windows\udeqa.dll Removed File! : C:\Windows\wustj.dat Removed File! : C:\Windows\System32\esrxi.dll Removed File! : C:\Windows\System32\hhnfg.dat Removed File! : C:\Windows\System32\ixysh.dat Removed File! : C:\Windows\System32\ketmc.dat Removed File! : C:\Windows\System32\odnpw.dat Removed File! : C:\Windows\System32\olsne.dat Removed File! : C:\Windows\System32\peslc.dll Removed File! : C:\Windows\System32\rldfc.dll Removed File! : C:\Windows\System32\rwxif.dat Removed File! : C:\Windows\System32\tjrrg.dat Removed File! : C:\Windows\System32\yjscf.dll Removed File! : C:\Windows\System32\ztips.dll ------------------------------------------------ Scan was COMPLETED SUCCESSFULLY at 9:55:11 PM 4. TDS-3 Log 23:18:54 [Init] Trojan Defence Suite v3.2.0 (UNLICENSED) 23:18:54 [Init] Started 14-07-05 23:18:54 Eastern Standard Time (UTC: 5), Internet Time @1179.79 23:18:54 [Init] Loading TDS-3 Systems ... 23:18:54 [Init] Token successfully adjusted. 23:18:54 [Init] • TDS Privileges : OK. Adjusted TDS-3 token privileges to maximum 23:18:54 [Init] • Plugins : OK. Loaded 13 23:18:54 [Init] • Exec Protection : Not Installed 23:18:54 [Init] WARNING: Your Radius.TD3 database needs to be updated! 23:18:54 [Init] Please download the latest from http://tds.diamondcs.com.au/radius.td3 23:18:54 [Init] Licensed users can use the Update facility from the TDS menu 23:18:54 [Init] Loading Radius Advanced Scanning Systems ... <R3 Engine, DCS Labs> 23:19:09 [Init] • Radius Advanced Specialist Extensions on standby for 13 trojan families 23:19:09 [Init] • Systems Initialised [60540 references - 32393 primaries/15825 traces/12322 variants/other] 23:19:09 [Init] Radius Systems loaded. <Databases updated 14-07-2005> 23:19:09 [Init] TDS-3 Ready. <Jthomps@127.0.0.1 - United States> 23:19:09 [Tip Of The Day] Shopping for DiamondCS services and software is easy! Simply visit http://www.diamondcs.com.au/shop.php 23:19:09 [TDS] Good evening Jthomps. 23:19:13 [Mutex Memory Scan] Started... 23:19:15 [Mutex Memory Scan] Finished (no trojan mutexes found). 23:19:15 [TDS-3] This is an EVALUATION demo of TDS-3. Please see the help file for help on registering. 23:19:28 [CRC32] Started - verifying 29 files ... 23:19:42 [CRC32] Test finished. 23:20:01 [Memory Scan] Memory scan started, please wait a moment ... 23:20:02 [Memory Scan] Memory scan complete. 23:20:02 [Mutex Memory Scan] Started... 23:20:03 [Mutex Memory Scan] Finished (no trojan mutexes found). 23:20:03 [Trace Scan] Started... 23:20:11 [Trace Scan] Finished. 23:20:11 [ServiceScan] Scanning for services and drivers ... 23:20:17 [ServiceScan] Scanned 329 services and drivers. 23:20:17 [File Scan] Scanning in A:\ ... 23:20:18 [File Scan] Scanned 0 files: 0 alarms in 1.054688 seconds (Avg 1. files/sec) 23:20:18 [File Scan] Scanning in C:\ ... 00:52:10 [File Scan] Scanned 107705 files: 2 alarms in -80888.63 seconds (Avg -.33 files/sec) 00:52:10 [File Scan] Scanning in D:\ ... 00:58:20 [File Scan] Scanned 1859 files: 2 alarms in 370.4531 seconds (Avg 6.02 files/sec) 00:58:20 [File Scan] Scanning in E:\ ... 00:58:20 [File Scan] Scanned 0 files: 2 alarms in 0 seconds (Avg -1.#IND files/sec) 00:58:20 [File Scan] Scanning in F:\ ... 00:58:20 [File Scan] Scanned 0 files: 2 alarms in 1.000977E-02 seconds (Avg 1. files/sec) 00:58:20 [File Scan] Scanning in G:\ ... 00:58:20 [File Scan] Scanned 0 files: 2 alarms in 0 seconds (Avg -1.#IND files/sec) 00:58:20 [Scan] Finished. 08:59:34 [CRC32] Started - verifying 29 files ... 08:59:48 [CRC32] Test finished. 09:00:07 [Memory Scan] Memory scan started, please wait a moment ... 09:00:07 [Memory Scan] Memory scan complete. 09:00:07 [Mutex Memory Scan] Started... 09:00:09 [Mutex Memory Scan] Finished (no trojan mutexes found). 09:00:09 [Trace Scan] Started... 09:00:17 [Trace Scan] Finished. 09:00:17 [ServiceScan] Scanning for services and drivers ... 09:00:23 [ServiceScan] Scanned 329 services and drivers. 09:00:23 [File Scan] Scanning in A:\ ... 09:00:24 [File Scan] Scanned 0 files: 0 alarms in 1.041016 seconds (Avg 1. files/sec) 09:00:24 [File Scan] Scanning in C:\ ... 10:31:30 [File Scan] Scanned 107704 files: 0 alarms in 5465.379 seconds (Avg 20.71 files/sec) 10:31:30 [File Scan] Scanning in D:\ ... 10:37:39 [File Scan] Scanned 1859 files: 0 alarms in 368.832 seconds (Avg 6.04 files/sec) 10:37:39 [File Scan] Scanning in E:\ ... 10:37:39 [File Scan] Scanned 0 files: 0 alarms in 1.171875E-02 seconds (Avg 1. files/sec) 10:37:39 [File Scan] Scanning in F:\ ... 10:37:39 [File Scan] Scanned 0 files: 0 alarms in 0.0078125 seconds (Avg 1. files/sec) 10:37:39 [File Scan] Scanning in G:\ ... 10:37:39 [File Scan] Scanned 0 files: 0 alarms in 0 seconds (Avg -1.#IND files/sec) 10:37:39 [Scan] Finished. 5. Backdoor.Agent.B Removal Tool No infection found 6. Ewido Log (see next post) Thanks so much for the help. |
|
|
|
|
#10 (permalink) |
|
Registered User
Join Date: Sep 2004
Posts: 11
OS: XP Professional
|
Ewido's log
6. Ewido's Log
The log was too long to include.... I just cut and pasted a portion- I can send the entire log if needed. --------------------------------------------------------- ewido security suite - Scan report --------------------------------------------------------- + Created on: 11:17:33 PM, 7/14/2005 + Report-Checksum: 78446C7A + Scan result: HKLM\SOFTWARE\Classes\CLSID\{04256906-BECE-83AC-2058-27ABA38B11A3} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{05CFF62B-F8EF-A6A3-C2D8-0649EE07F197} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{07FF232E-41D0-38A2-6073-6847AD3E6453} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{09248DC7-285D-A208-7675-8D1BAC7208C9} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0FBFA147-FFB4-19A8-49F8-D1A17B80E32D} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{208BD4D8-3DA2-3736-A8E6-F3AF3479FA31} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{26F5CDB0-3ADD-70F3-F30F-8DD2B92D52FF} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3A044FBA-5DEF-1ECF-55E6-8A9DE3722CEC} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3F15B481-32E2-FE85-96FA-A8976289B4FD} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{4A210C09-C3AE-D36C-3EC5-0D7723985463} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{4C1CBC17-3C15-343F-1E7C-D8F447935C05} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5345A51F-E5D0-5A0D-1418-A1C95C417E3C} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5BCC3EE7-9153-E89F-6D4E-9B02B02B4E2E} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{72071605-48F5-CC68-B374-2CDDF451F27F} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{735DDAC7-F8F1-47DD-D87A-6AF0100B6A48} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{7658C68E-7ED4-8476-AC96-729091012307} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{77CD9B7C-6604-FD84-83FE-47AE9E1477C2} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{7868EC16-8C67-1DBD-6D5A-EBB325881BD9} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{8CD1D4D3-8260-44A7-67DD-A71E995AB77F} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{929F8E8D-2C15-4240-E685-FA3C645381C5} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A4405AD1-A13C-E10B-4B57-D5092B102F2B} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B78A202C-9FF5-481D-3E8C-0877C167707F} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B7C06F7A-7E5B-8248-7CE7-E61C97F1037E} -> Spyware.MidAddle : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BAA4A995-E881-38F6-1E95-AF9F2785FBB3} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BB35FD19-38F4-89DC-FA76-BA6507A5C6D7} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BC0DC8BD-646D-FA46-8739-116B4F8B8228} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BC0FE7F5-AD1D-A795-C683-F3EB54072EFE} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BD00AB82-F105-58F8-2B31-B600383177E6} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BEB133E5-FD72-43b7-8AFF-681831CC72D9} -> Spyware.Hijacker.Generic : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C0E27572-BE10-BE39-5F1B-F26255B8F141} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{D02510A9-69A7-24D5-85DA-D3EC8E911C73} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{D775F18B-70E6-FBB1-C13D-52CE71E899B3} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E4564D6D-4921-87B7-0C6A-2097D907B4A5} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F573A15E-4E08-2CE8-1F75-3F0D794E2E42} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{FA6A8ADC-5ACF-A739-A8BF-5E4D7B5991C1} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{FA6A9E8D-BFF9-8822-80F2-D1B507D9FF99} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{FBD21FB3-D80F-1A9B-2038-2D60684CDEE0} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-1935655697-813497703-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{77CD9B7C-6604-FD84-83FE-47AE9E1477C2} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-1935655697-813497703-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B78A202C-9FF5-481D-3E8C-0877C167707F} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-1935655697-813497703-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BB35FD19-38F4-89DC-FA76-BA6507A5C6D7} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-1935655697-813497703-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E0E5A173-0CF3-BCA9-8543-4B6252CD9DA6} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-1935655697-813497703-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F573A15E-4E08-2CE8-1F75-3F0D794E2E42} -> Spyware.CoolWebSearch : Cleaned with backup C:\Program Files\HijackThis\backups\backup-20050713-211723-796.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\Active Setup Log.txt:kzdtub -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\Active Setup Log.txt:lpkli -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\Active Setup Log.txt:zpjij -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addaa32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addaj.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addau32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\adday.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addbz32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addcf32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\adddj.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\adddr.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\adddu32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addfb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addfz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addge32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addgv32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addhq.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addih.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addjt.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addkb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addke32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addkp.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addkp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addkq32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addky32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addky32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addlc.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addle.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addmi.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addns32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addoe32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addog32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addoi32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addoo.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addoq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addqb.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addqh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addqq32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addqt.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addqt.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addqx32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addro32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addrt32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addsq32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addtl.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addtr32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addty32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addva.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addvi.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addvk32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addvp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addvv32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addvy.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addwi.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addwz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addxo.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addxo32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addxu32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addya.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addyh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addyj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addyr32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addyr32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addyz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addzn32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addzq32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addzv32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ahdqj.txt:bxllp -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ahdqj.txt:hnhvn -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ahdqj.txt:jaanj -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apiav.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apick32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apicu.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apicw.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apidf32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apief.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apieh.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apifl32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apifn32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apifw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apifx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apigl32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apigs32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apigv.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apigz32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apihc.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apihn32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiii32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apija32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apijg.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apijs32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apikh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiks.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apila.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apily32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apilz32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apimr32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apimy.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apioh.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apioh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apipf32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apipz32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiqn.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apiqn.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiqr.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apiqr32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apisa32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apise.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apisn.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiso32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apisq.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apisr32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apisu.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apisz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apitr32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apiuc.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apiuj.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiuk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiux.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiuy.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apiuy.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apiuy32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apivv.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiwg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiwi32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apixt.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apixx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiyb.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiyt32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apizd32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appab32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\appad32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appaj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appbx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appcx32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\appdd.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appde.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\appdp32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appef.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appeu.dll -> TrojanDownloader.Agent.bc : Cleaned with backup |
|
|
|
|
#11 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,409
OS: N/A
|
It certainly looks cleaner than before.
Please include Kaspersky's log in your next post as an attchment. = = = = = = = = = = = Run a HiJackThis scan. Select the following entries & click Fix checked : O4 - HKLM\..\Run: [appac.exe] C:\WINDOWS\system32\appac.exe O4 - HKLM\..\Run: [sysok.exe] C:\WINDOWS\sysok.exe O4 - HKLM\..\Run: [apprt.exe] C:\WINDOWS\apprt.exe = = = = = = = = = = = Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard.
Go to the File menu, and choose Paste from Clipboard * this feature does not work on older versons of Killbox Click the dropdown-arrow next to the "Full Path of File to Delete" field. Verify that the filenames you pasted are found in there. Select/tick the following: * Replace on Reboot * Use Dummy * End Explorer Shell While Killing File * "Unregister.dll Before Deleting" * if it's not grayed out Click the RED X button. Click "Yes" at the 'Delete on Reboot' prompt. Click "Yes" at the 'Pending Operations' prompt. * If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try Killbox again. = = = = = = = = = = = Then download SilentRunners.vbs - Right click & choose Save As... Save it as SilentRunners.vbs to Desktop. Before proceeding, disable any anti-virus or anti-spyware programs that may block/disable scripts Double-click SilentRunners.vbs to run it. This will take a few minutes. When it's done, you'll receive the prompt "All Done!". It will create a file called "Startup Programs". Post ALL its contents here in your next reply. Also include a fresh copy of HJT log
__________________
Question - what have you done for the community today? |
|
|
|
|
#12 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,409
OS: N/A
|
John,
Another thing I need you to do. Download this file & unzip it to a folder on Desktop. Within that folder, double click on activesetup.vbs. When it has finished running, it will pop up a 'Finish" message. A log will be created within that folder. Post the contents of that log in your next reply
__________________
Question - what have you done for the community today? |
|
|
|
|
#13 (permalink) |
|
Registered User
Join Date: Sep 2004
Posts: 11
OS: XP Professional
|
alrighty...
Startup Problems
"Silent Runners.vbs", revision 39, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} "SiS Tray" = "C:\WINDOWS\System32\sistray.EXE" ["Silicon Integrated Systems Corporation"] "PCTVOICE" = "pctspk.exe" [empty string] "NDPS" = "C:\WINDOWS\System32\dpmw32.exe" [null data] "CSAV_CheckViruses" = "C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe" ["Command Software Systems, Inc."] "QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."] "NWTRAY" = "NWTRAY.EXE" ["Novell, Inc."] HKLM\Software\Microsoft\Active Setup\Installed Components\ >{26923b43-4d38-484f-9b9e-de460746276c}\(Default) = "Internet Explorer" \StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigIE" [MS] >{881dd1c5-3dcf-431b-b061-f3f88e8be88a}\(Default) = "Outlook Express" \StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigOE" [MS] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = "Google Toolbar Helper" [from CLSID] -> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension" -> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found] "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext" -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" [file not found] "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL" [MS] "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS] "{AF8DE18D-9065-4102-BC40-EB294A95BB07}" = "Novell Connections" -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nwshlxnt.dll" ["Novell, Inc."] "{04c23aa0-3d34-11d2-b788-008029605ac7}" = "NDPS Shell Extension" -> {CLSID}\InProcServer32\(Default) = "ndpsprop.dll" [empty string] "{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip" -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."] "{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip" -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."] "{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip" -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."] "{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip" -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."] "{6af09ec9-b429-11d4-a1fb-0090960218cb}" = "My Bluetooth Places" -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\BTNEIG~1.DLL" ["WIDCOMM, Inc."] "{9DED7A30-D572-4D21-8D82-6945EA697400}" = "Macromedia FlashPaper Context Menu" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Macromedia\FlashPaper 2\FlashPaperContextMenu.dll" [null data] "{7C9D5882-CB4A-4090-96C8-430BFE8B795B}" = "Webroot Spy Sweeper Context Menu Integration" -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll" ["Webroot Software, Inc."] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\ INFECTION WARNING! "{54D9498B-CF93-414F-8984-8CE7FDE0D391}" = "ewido shell guard" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\shellhook.dll" ["TODO: <Firmenname>"] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ INFECTION WARNING! "GinaDLL" = "NWGINA.DLL" ["Novell, Inc."] HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\context.dll" ["ewido networks"] FProtMenu\(Default) = "{4a479be0-3333-11d0-b519-00400519153f}" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Command Software\Command AntiVirus\avshext.dll" ["Command Software Systems, Inc."] Macromedia.FlashPaper.ContextMenu\(Default) = "{9DED7A30-D572-4D21-8D82-6945EA697400}" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Macromedia\FlashPaper 2\FlashPaperContextMenu.dll" [null data] NetWareMenuItems\(Default) = "{e3bbbfc0-f61f-11cf-bb16-00c04fd371f4}" -> {CLSID}\InProcServer32\(Default) = "novnpnt.dll" ["Novell, Inc."] TDS-3\(Default) = "{E8ADA3E1-CE9B-44A0-A165-997304EF4E18}" -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\tds3shl.dll" [empty string] WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}" -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\context.dll" ["ewido networks"] TDS-3\(Default) = "{E8ADA3E1-CE9B-44A0-A165-997304EF4E18}" -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\tds3shl.dll" [empty string] WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}" -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ FProtMenu\(Default) = "{4A479BE0-3333-11D0-B519-00400519153F}" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Command Software\Command AntiVirus\avshext.dll" ["Command Software Systems, Inc."] NetWareMenuItems\(Default) = "{e3bbbfc0-f61f-11cf-bb16-00c04fd371f4}" -> {CLSID}\InProcServer32\(Default) = "novnpnt.dll" ["Novell, Inc."] NetWareServerMenu\(Default) = "{9b173360-732b-11ce-aa22-00805f9834b0}" -> {CLSID}\InProcServer32\(Default) = "novnpnt.dll" ["Novell, Inc."] SpySweeper\(Default) = "{7C9D5882-CB4A-4090-96C8-430BFE8B795B}" -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll" ["Webroot Software, Inc."] WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}" -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."] Group Policies [Description] {enabled Group Policy setting}: ------------------------------------------------------------ HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ "NoActiveDesktop"=dword:00000001 [disables Active Desktop; removes Web tab from Display Properties| Desktop (tab)|Customize Desktop... (button)|Desktop Items (window)] {User Configuration|Administrative Templates|Desktop|Active Desktop| Disable Active Desktop} Active Desktop and Wallpaper: ----------------------------- Active Desktop disabled via Group Policy. HKCU\Control Panel\Desktop\ "Wallpaper" = "C:\Documents and Settings\jthomps\Local Settings\Application Data\Microsoft\Wallpaper1.bmp" Startup items in "jthomps" & "All Users" startup folders: --------------------------------------------------------- C:\Documents and Settings\All Users\Start Menu\Programs\Startup "Adobe Gamma Loader" -> shortcut to: "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."] "BTTray" -> shortcut to: "C:\Program Files\DLink\Bluetooth Software\BTTray.exe" ["WIDCOMM, Inc."] Enabled Scheduled Tasks: ------------------------ "AE468DD091893E48" -> launches: "c:\progra~1\deadba~1\that blue spam.exe" [file not found] "Enterprise update for Command AntiVirus" -> launches: "C:\Program Files\Command Software\Command AntiVirus\cuagent.exe" ["Command Software Systems, Inc."] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS] 000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 000000000004\LibraryPath = "%SystemRoot%\system32\netware\NWWS2NDS.DLL" ["Novell, Inc."] 000000000005\LibraryPath = "%SystemRoot%\system32\netware\NWWS2SAP.DLL" ["Novell, Inc."] 000000000006\LibraryPath = "%SystemRoot%\system32\netware\NWWS2SLP.DLL" ["Novell, Inc."] 000000000007\LibraryPath = "%SystemRoot%\system32\wshbth.dll" [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 28 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 Toolbars, Explorer Bars, Extensions: ------------------------------------ Toolbars HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\ "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = "&Google" [from CLSID] -> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."] HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = "&Google" [from CLSID] -> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."] HKLM\Software\Microsoft\Internet Explorer\Toolbar\ "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = "&Google" [from CLSID] -> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."] Extensions (Tools menu items, main toolbar menu buttons) HKLM\Software\Microsoft\Internet Explorer\Extensions\ {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ "MenuText" = "Sun Java Console" "CLSIDExtension" = "{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll" ["Sun Microsystems, Inc."] {CCA281CA-C863-46EF-9331-5C8D4460577F}\ "ButtonText" = "@btrez.dll,-4015" "MenuText" = "@btrez.dll,-4017" "Script" = "C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm" [null data] {FB5F1910-F110-11D2-BB9E-00C04F795683}\ "ButtonText" = "Messenger" "MenuText" = "Windows Messenger" "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS] Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ avinitnt, avinitnt, ""C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe"" ["Command Software Systems, Inc."] Bluetooth Service, btwdins, "C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe" ["WIDCOMM, Inc."] Bluetooth Support Service, BthServ, "C:\WINDOWS\system32\svchost.exe -k bthsvcs" {"C:\WINDOWS\System32\bthserv.dll" [MS]} DvpApi, dvpapi, ""C:\Program Files\Common Files\Command Software\dvpapi.exe"" ["Command Software Systems, Inc."] ewido security suite control, ewido security suite control, "C:\Program Files\ewido\security suite\ewidoctrl.exe" ["ewido networks"] ewido security suite guard, ewido security suite guard, "C:\Program Files\ewido\security suite\ewidoguard.exe" ["ewido networks"] Machine Debug Manager, MDM, ""C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"" [MS] Webroot Spy Sweeper Engine, svcWRSSSDK, "C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe" ["Webroot Software, Inc."] ---------- + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + The search for DESKTOP.INI DLL launch points on all local fixed drives took 255 seconds. + The search for all Registry CLSIDs containing dormant Explorer Bars took 28 seconds. ---------- (total run time: 314 seconds) Activesetup "Find activesetup", version1, launched at: 09:30 Operating System: Windows XP SP2 HKLM\Software\Microsoft\Active Setup\Installed Components\ ">{26923b43-4d38-484f-9b9e-de460746276c}\(Default)" = "Internet Explorer" \StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigIE" [MS] ">{881dd1c5-3dcf-431b-b061-f3f88e8be88a}\(Default)" = "Outlook Express" \StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigOE" [MS] HJT log Logfile of HijackThis v1.99.1 Scan saved at 9:28:36 AM, on 7/16/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\ewido\security suite\ewidoguard.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\sistray.EXE C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\System32\dpmw32.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\NWTRAY.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DLink\Bluetooth Software\BTTray.exe C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.charlotte.com/ O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: BTTray.lnk = ? O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\DLink\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/k...an_unicode.cab O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab O23 - Service: avinitnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: schscnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\schscnt.exe O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe Are we pretty much clean? Machine seems to be running much faster. Thanks a ton. |
|
|
|
|
#14 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,409
OS: N/A
|
John,
Apparently, it's all gone. It was tough but you're finally clean. Do you have any more problems with your computer? If not, you should be set to go. Just a few bits of housekeeping left to do ... Reset hidden/system files and folders
Clear Java Cache
Follow the instructions outlined here to clear Sun Java's cache. Create a new System Restore point
Enable Windows Auto Update
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programs:
If you do not have a firewall, here are 3 free ones available for personal use: In light of your recent hiccup, I'm sure you'll like to avoid any future infections. Please take a look at these well written articles Have a safe & happy computing day. Please respond to this thread one more time so we can mark this thread as resolved.
__________________
Question - what have you done for the community today? |
|
|
| Thread Tools | |
|
|