Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 07-11-2005, 05:23 PM   #1 (permalink)
Registered User
 
Join Date: Sep 2004
Posts: 11
OS: XP Professional


HJT log....a few things still hanging on :(

I'm getting frazzled... I had the AV GOLD problem, and tried a couple fixes from other sites. I seem to be rid of that but have some leftover problems (popups, added favorites, etc.). I have run spy sweeper, adaware, CWS shredder, spybot search and destroy among others, but problems keep getting loaded (I've tried running all these in safe mode). Any help would be greatly appreciated.

Here's my HJT log.

Logfile of HijackThis v1.98.2
Scan saved at 12:11:36 PM, on 7/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\d3ey32.exe
C:\WINDOWS\System32\sistray.EXE
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\dpmw32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DLink\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hjt\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.charlotte.com/mld/charlotte
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {2B4B5589-B4B7-A432-BCE4-C96F8E7DB2A0} - C:\WINDOWS\crax.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Class - {FBA819B5-BECF-B27B-6F9B-963F513D8D14} - C:\WINDOWS\apifz.dll
O2 - BHO: Class - {FE7AA604-D603-D018-CCF2-941EB9FDFB36} - C:\WINDOWS\msqz.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [d3ey32.exe] C:\WINDOWS\system32\d3ey32.exe
O4 - HKLM\..\RunOnce: [winzd.exe] C:\WINDOWS\system32\winzd.exe
O4 - HKLM\..\RunOnce: [apifz.exe] C:\WINDOWS\apifz.exe
O4 - HKLM\..\RunOnce: [addek32.exe] C:\WINDOWS\system32\addek32.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\DLink\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://mirror.worldwinner.com/games/v44/pool/pool.cab
O16 - DPF: {6BB594E2-6E4D-4CC9-98B0-931C323F9165} (DepHlp Control) - http://mirror.worldwinner.com/games/shared/dephlp.cab
O16 - DPF: {6F6DBC29-7A0C-4AC0-A42D-10EC70678526} (Word Cubes Control) - http://mirror.worldwinner.com/games/...e/wordcube.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8BDF4BDB-7C40-4DC8-B2DD-138D8059698C} (Focus Control) - http://mirror.worldwinner.com/games/v41/focus/focus.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://mirror.worldwinner.com/games/...o/wordmojo.cab
O16 - DPF: {957BDEC2-50EA-4B01-ABF5-22F86364A914} (Trivia Control) - http://mirror.worldwinner.com//games...via/trivia.cab
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - http://mirror.worldwinner.com/games/...an/hangman.cab
O16 - DPF: {C5142630-9BC9-4236-BAC9-2E3C24566EC8} (XWord Control) - http://mirror.worldwinner.com/games/v40/xword/xword.cab
O16 - DPF: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} (JInitiator 1.3.1.13) - https://esis.ncwise.org/jinitiator/jinit.exe
O16 - DPF: {D27FFC5F-D7B9-4349-9F41-F7458B585374} (SoloTriv Control) - http://mirror.worldwinner.com/games/...v/solotriv.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
bigjohn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 07-12-2005, 03:13 AM   #2 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,409
OS: N/A


Hi and Welcome to TSF!

Please subscribe to this thread to be notified of fixes as soon as they are posted by our Team. To do this, please click the "Thread Tools" button located in the original thread line and selecting "Subscribe to this Thread".

It's better to print out the next instructions or save them in notepad, because you also have to work in safe mode without networking support, so this page wouldn't be available then.
It is also important you don't miss a step and perform everything in the right order!!.
If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are carrying out the procedures below.

Please disable Webroot SpySweeper, as it may hinder the removal of some entries. You can re-enable it after you're clean.
To disable Webroot SpySweeper:
  • Go to the Options>Program Options
  • Uncheck Load at Windows Startup
  • Click Shields & uncheck all items there
  • Uncheck Home page shield.
  • Automaticly restore default without notifiction

~~~~~~~~~~~~~~

Please download these additional files/programs :- (Do not run them unless instructed to do so)
Unplug your computer from the Internet when you have finished downloading

CleanUp! - Install

KillBox v2.0.0.175 - Save to Desktop.


~~~~~~~~~~~~~~

Start HiJackThis & go to Config>Misc Tools>Open process manager
Select the following and click [Kill process] one at a time. Some entries may no longer exist.
C:\WINDOWS\system32\d3ey32.exe

~~~~~~~~~~~~~~

Run a scan with HiJackThis & select(tick) the following & click [Fix checked] :

R3 - Default URLSearchHook is missing
O2 - BHO: Class - {2B4B5589-B4B7-A432-BCE4-C96F8E7DB2A0} - C:\WINDOWS\crax.dll
O2 - BHO: Class - {FBA819B5-BECF-B27B-6F9B-963F513D8D14} - C:\WINDOWS\apifz.dll
O2 - BHO: Class - {FE7AA604-D603-D018-CCF2-941EB9FDFB36} - C:\WINDOWS\msqz.dll
O4 - HKLM\..\Run: [d3ey32.exe] C:\WINDOWS\system32\d3ey32.exe
O4 - HKLM\..\RunOnce: [winzd.exe] C:\WINDOWS\system32\winzd.exe
O4 - HKLM\..\RunOnce: [apifz.exe] C:\WINDOWS\apifz.exe
O4 - HKLM\..\RunOnce: [addek32.exe] C:\WINDOWS\system32\addek32.exe
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://mirror.worldwinner.com/games/v44/pool/pool.cab
O16 - DPF: {6BB594E2-6E4D-4CC9-98B0-931C323F9165} (DepHlp Control) - http://mirror.worldwinner.com/games/shared/dephlp.cab
O16 - DPF: {6F6DBC29-7A0C-4AC0-A42D-10EC70678526} (Word Cubes Control) - http://mirror.worldwinner.com/games...be/wordcube.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8BDF4BDB-7C40-4DC8-B2DD-138D8059698C} (Focus Control) - http://mirror.worldwinner.com/games/v41/focus/focus.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://mirror.worldwinner.com/games...jo/wordmojo.cab
O16 - DPF: {957BDEC2-50EA-4B01-ABF5-22F86364A914} (Trivia Control) - http://mirror.worldwinner.com//game...ivia/trivia.cab
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - http://mirror.worldwinner.com/games...man/hangman.cab
O16 - DPF: {C5142630-9BC9-4236-BAC9-2E3C24566EC8} (XWord Control) - http://mirror.worldwinner.com/games/v40/xword/xword.cab
O16 - DPF: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} (JInitiator 1.3.1.13) - https://esis.ncwise.org/jinitiator/jinit.exe
O16 - DPF: {D27FFC5F-D7B9-4349-9F41-F7458B585374} (SoloTriv Control) - http://mirror.worldwinner.com/games...iv/solotriv.cab



~~~~~~~~~~~~~~

Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard.
C:\WINDOWS\crax.dll
C:\WINDOWS\apifz.dll
C:\WINDOWS\msqz.dll
C:\WINDOWS\system32\d3ey32.exe
C:\WINDOWS\system32\winzd.exe
C:\WINDOWS\apifz.exe
C:\WINDOWS\system32\addek32.exe
Start KillBox.
  1. Go to the File menu, and choose Paste from Clipboard.
    Verify that you've done this properly by clicking the dropdown-arrow next to the Full Path of File to Delete field. The filenames you pasted will be found in there.
  2. Select/tick the following:
    * Delete on Reboot
    * End Explorer Shell While Killing File
    * Unregister.dll Before Deleting" if it's not grayed out.
  3. Click the RED X button.
  4. Click [Yes] at the 'Delete on Reboot' prompt. Click [Yes] at the Pending Operations prompt.

* If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try Killbox again.


~~~~~~~~~~~~~~

Upon reboot, Run Cleanup! & configure the program up as follows:
  1. Click Options...
  2. Move the arrow down to Custom CleanUp!
  3. Put a check next to the following:
    • Empty Recycle Bins
    • Delete Cookies
    • Delete Prefetch files
    • [X]Scan local drives for temporary files (Please uncheck this option)
    • Cleanup! All Users
  4. Click OK
  5. Press the CleanUp! button to start the program. Reboot/logoff when prompted.
* CleanUp! will delete all the files in your temp folders without making a backup


~~~~~~~~~~~~~~

Do an online scan at one of the following sites:Take note the names and locations of any file it detects but fails to clean.
* Turn off the real time scanner of any existing antivirus program while performing the online scan



Reboot Again & Run a new scan with HiJackThis. Save the log file and post the contents in your next reply.

In your next post, please include fresh copies of:

1. Copy of HiJackThis log
2. List of files that online scans failed to disinfect

Please provide details of any problems you encountered whilst performing the above steps.
Update us on how your computer behaves now
__________________

Question - what have you done for the community today?
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 07-12-2005, 12:13 PM   #3 (permalink)
Registered User
 
Join Date: Sep 2004
Posts: 11
OS: XP Professional


Ok... I've done that...

Done... Still slow on startup, still getting a pop-up here and there, and also getting these messages on startup:


The application or DLL C:\WINDOWS\javato.dll is not a valid Windows image.

The application or DLL C:\WINDOWS\system32\crrn.dll is not a valid Windows image.

Updated HJT Log:


Logfile of HijackThis v1.98.2
Scan saved at 2:05:35 PM, on 7/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\crbk32.exe
C:\WINDOWS\system32\crff32.exe
C:\WINDOWS\System32\sistray.EXE
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\dpmw32.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DLink\Bluetooth Software\BTTray.exe
C:\hjt\HijackThis.exe
C:\WINDOWS\system32\MsiExec.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {003156AA-B2AD-54C8-CF6D-1C992B937149} - C:\WINDOWS\system32\apidt.dll
O2 - BHO: Class - {146A4A8B-66F9-80FA-6E14-51A6991BAC7D} - C:\WINDOWS\system32\apibs32.dll
O2 - BHO: Class - {4ABB5929-6D33-1BD3-5889-307B70AC94D2} - C:\WINDOWS\system32\crxz.dll
O2 - BHO: Class - {5CE5B985-51B1-3958-E5DB-92DD9091CFBB} - C:\WINDOWS\javavq.dll
O2 - BHO: Class - {63C3B90C-CAE8-913A-DBA5-AC8E0D0896D0} - C:\WINDOWS\system32\crbk32.dll
O2 - BHO: Class - {6827E44A-FCD1-5704-0FF9-EE64FBCBD77F} - C:\WINDOWS\system32\wingm32.dll
O2 - BHO: Class - {7D52FC72-76A8-77EF-270D-8A1A8EA30F96} - C:\WINDOWS\system32\winsx32.dll
O2 - BHO: Class - {91D042E7-25DF-B6F2-5C0C-B0963EF3EA01} - C:\WINDOWS\winqv32.dll
O2 - BHO: Class - {A4913EBE-69AB-7C2E-EA16-13F6C5E79E14} - C:\WINDOWS\system32\ipvh32.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Class - {C1A7352F-7207-2C2F-6A41-8C46196F8284} - C:\WINDOWS\system32\winug32.dll
O2 - BHO: Class - {C2EFCA32-D3CF-3801-B32F-6A7589AA0A8A} - C:\WINDOWS\netfd.dll
O2 - BHO: Class - {FEF289B2-6015-9A71-D02D-8394ED825678} - C:\WINDOWS\system32\javany.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [iesn.exe] C:\WINDOWS\system32\iesn.exe
O4 - HKLM\..\Run: [crbk32.exe] C:\WINDOWS\system32\crbk32.exe
O4 - HKLM\..\RunOnce: [apiua.exe] C:\WINDOWS\apiua.exe
O4 - HKLM\..\RunOnce: [crnf.exe] C:\WINDOWS\crnf.exe
O4 - HKLM\..\RunOnce: [appxr32.exe] C:\WINDOWS\system32\appxr32.exe
O4 - HKLM\..\RunOnce: [mfcpj32.exe] C:\WINDOWS\system32\mfcpj32.exe
O4 - HKLM\..\RunOnce: [mfcsy32.exe] C:\WINDOWS\mfcsy32.exe
O4 - HKLM\..\RunOnce: [javaad32.exe] C:\WINDOWS\system32\javaad32.exe
O4 - HKLM\..\RunOnce: [iexj.exe] C:\WINDOWS\system32\iexj.exe
O4 - HKLM\..\RunOnce: [ipfp.exe] C:\WINDOWS\system32\ipfp.exe
O4 - HKLM\..\RunOnce: [addvf.exe] C:\WINDOWS\system32\addvf.exe
O4 - HKLM\..\RunOnce: [appkj32.exe] C:\WINDOWS\appkj32.exe
O4 - HKLM\..\RunOnce: [addyu.exe] C:\WINDOWS\system32\addyu.exe
O4 - HKLM\..\RunOnce: [netkc32.exe] C:\WINDOWS\netkc32.exe
O4 - HKLM\..\RunOnce: [crcy.exe] C:\WINDOWS\system32\crcy.exe
O4 - HKLM\..\RunOnce: [sysxo.exe] C:\WINDOWS\sysxo.exe
O4 - HKLM\..\RunOnce: [msvh32.exe] C:\WINDOWS\msvh32.exe
O4 - HKLM\..\RunOnce: [addua.exe] C:\WINDOWS\addua.exe
O4 - HKLM\..\RunOnce: [addyp.exe] C:\WINDOWS\addyp.exe
O4 - HKLM\..\RunOnce: [crzj32.exe] C:\WINDOWS\crzj32.exe
O4 - HKLM\..\RunOnce: [msul32.exe] C:\WINDOWS\msul32.exe
O4 - HKLM\..\RunOnce: [crnn.exe] C:\WINDOWS\crnn.exe
O4 - HKLM\..\RunOnce: [winsx.exe] C:\WINDOWS\winsx.exe
O4 - HKLM\..\RunOnce: [crff32.exe] C:\WINDOWS\system32\crff32.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\DLink\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} (JInitiator 1.3.1.13) - https://esis.ncwise.org/jinitiator/jinit.exe
O16 - DPF: {D27FFC5F-D7B9-4349-9F41-F7458B585374} (SoloTriv Control) - http://mirror.worldwinner.com/games/...v/solotriv.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab


********
And here's the results from Panda's online scan:


Incident Status Location

Adware:Adware/nCase No disinfected C:\WINDOWS\180solutions
Adware:Adware/SearchAid No disinfected C:\Documents and Settings\jthomps\Favorites\Only sex website.url
Adware:Adware/SideStep No disinfected C:\WINDOWS\Downloaded Program Files\SbCIe???.???
Adware:Adware/Midaddle No disinfected Windows Registry
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Ab scissor.url
Adware:Adware/CWS.Aboutblank No disinfected Windows Registry
Adware:Adware/CWS.008k No disinfected C:\WINDOWS\appaz32.exe
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected Windows Registry
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-228d5c98-4ce0ce54.zip[a.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-228d5c98-4ce0ce54.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-228d5c98-4ce0ce54.zip[VerifierBug.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6fd1d987-4758c273.zip[BlackBox.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6fd1d987-4758c273.zip[VB.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6fd1d987-4758c273.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6fd1d987-4758c273.zip[Beyond.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-6699b1e6-6a0ae450.zip[BlackBox.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-6699b1e6-6a0ae450.zip[VerifierBug.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-6699b1e6-6a0ae450.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-6699b1e6-6a0ae450.zip[Beyond.class]
Adware:Adware/SearchAid No disinfected C:\Documents and Settings\jthomps\Favorites\Only sex website.url
Adware:Adware/SearchAid No disinfected C:\Documents and Settings\jthomps\Favorites\Search the web.url
Adware:Adware/SearchAid No disinfected C:\Documents and Settings\jthomps\Favorites\Seven days of free porn.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Ab scissor.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Broadband comparison.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Credit counseling.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Credit report.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Crm software.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Debt credit card.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Escorts.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Fha.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Health insurance.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Help desk software.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Insurance home.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Loan for debt consolidation.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Loan for people with bad credit.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Marketing email.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Mortgage insurance.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Mortgage life insurance.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Nevada corporations.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Online Betting Site.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Online gambling casino.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Online instant loan.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Order phentermine.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Payroll advance.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Personal loans online.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Personal loans with bad credit.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Prescription Drugs Rx Online.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Refinancing my mortgage.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Tahoe vacation rental.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Unsecured bad credit loans.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\Videos.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\jthomps\Favorites\Sites about\What is hydrocodone.url
Adware:Adware/nCase No disinfected C:\WINDOWS\180loader.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\addvn32.exe
Adware:Adware/CWS.008k No disinfected C:\WINDOWS\appaz32.exe
Adware:Adware/SideStep No disinfected C:\WINDOWS\Downloaded Program Files\SbCIe026.dll
Virus:Trj/Downloader.DKJ Disinfected C:\WINDOWS\sdkqu32.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\system32\netgk32.exe

****

Thanks so much for the help... what next?
bigjohn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 07-12-2005, 01:01 PM   #4 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,409
OS: N/A


Looks like we opened Pandora's Box & all the worms came crawling out.

First thing on the agenda (something which I failed to notice earlier)
You are currently running an outdated version of HiJackThis. Please click on the link below to download the most current version:Delete your current HiJackThis.exe file and double-click on the file you just downloaded and then click on the Unzip button to install the newer version. It will be installed to the C:\Program Files\HiJackThis\ directory by default. I would require your next HJT log to be from this newer version


~~~~~~~~~~~~~~

Please download these additional files/programs :- (Do not run them unless instructed to do so)
Unplug your computer from the Internet when you have finished downloading

CWShredder - Save on Desktop. Run CWShredder & click on the [Check for update] button. Exit the program after it has updated itself.

SpSeHjfix - Save to a new folder on desktop


~~~~~~~~~~~~~~

Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard.
C:\WINDOWS\system32\auapd.dll
C:\WINDOWS\system32\apidt.dll
C:\WINDOWS\system32\apibs32.dll
C:\WINDOWS\system32\crxz.dll
C:\WINDOWS\javavq.dll
C:\WINDOWS\system32\crbk32.dll
C:\WINDOWS\system32\wingm32.dll
C:\WINDOWS\system32\winsx32.dll
C:\WINDOWS\winqv32.dll
C:\WINDOWS\system32\ipvh32.dll
C:\WINDOWS\system32\winug32.dll
C:\WINDOWS\netfd.dll
C:\WINDOWS\system32\javany.dll
C:\WINDOWS\system32\iesn.exe
C:\WINDOWS\system32\crbk32.exe
C:\WINDOWS\apiua.exe
C:\WINDOWS\crnf.exe
C:\WINDOWS\system32\appxr32.exe
C:\WINDOWS\system32\mfcpj32.exe
C:\WINDOWS\mfcsy32.exe
C:\WINDOWS\system32\javaad32.exe
C:\WINDOWS\system32\iexj.exe
C:\WINDOWS\system32\ipfp.exe
C:\WINDOWS\system32\addvf.exe
C:\WINDOWS\appkj32.exe
C:\WINDOWS\system32\addyu.exe
C:\WINDOWS\netkc32.exe
C:\WINDOWS\system32\crcy.exe
C:\WINDOWS\sysxo.exe
C:\WINDOWS\msvh32.exe
C:\WINDOWS\addua.exe
C:\WINDOWS\addyp.exe
C:\WINDOWS\crzj32.exe
C:\WINDOWS\msul32.exe
C:\WINDOWS\crnn.exe
C:\WINDOWS\winsx.exe
C:\WINDOWS\system32\crff32.exe
C:\Documents and Settings\jthomps\Favorites\Only sex website.url
C:\WINDOWS\Downloaded Program Files\SbCIe???.???
C:\WINDOWS\appaz32.exe
CWS.HomeSearchAsisstantNo disinfected Windows Registry
C:\Documents and Settings\jthomps\Favorites\Only sex website.url
C:\Documents and Settings\jthomps\Favorites\Search the web.url
C:\Documents and Settings\jthomps\Favorites\Seven days of free porn.url
C:\WINDOWS\180loader.exe
C:\WINDOWS\addvn32.exe
C:\WINDOWS\appaz32.exe
C:\WINDOWS\Downloaded Program Files\SbCIe026.dll
C:\WINDOWS\sdkqu32.exe
C:\WINDOWS\system32\netgk32.exe
Start KillBox.
  1. Go to the File menu, and choose Paste from Clipboard.
    Verify that you've done this properly by clicking the dropdown-arrow next to the Full Path of File to Delete field. The filenames you pasted will be found in there.
  2. Select/tick the following:
    * Delete on Reboot
    * End Explorer Shell While Killing File
    * Unregister.dll Before Deleting" if it's not grayed out.
  3. Click the RED X button.
  4. Click [Yes] at the 'Delete on Reboot' prompt. Click [Yes] at the Pending Operations prompt.

* If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try Killbox again.


~~~~~~~~~~~~~~

Reboot to SafeMode
  1. Shut Windows down, and then turn off the computer.
  2. Restart the computer. The computer begins processing a set of instructions known as the Basic Input/Output System (BIOS). What is displayed depends on the BIOS manufacturer. Some computers display a progress bar that refers to the word BIOS, while others may not display any indication that this process is happening.
  3. As soon as the BIOS has finished loading, begin tapping the F8 key on your keyboard. Continue to do so until the
    [Windows Advanced Options] menu appears.
  4. Using the arrow keys on the keyboard, scroll to and select the Safe mode menu item, and then press Enter.

~~~~~~~~~~~~~~

Run a scan with HiJackThis & select(tick) the following & click [Fix checked] :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\auapd.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {003156AA-B2AD-54C8-CF6D-1C992B937149} - C:\WINDOWS\system32\apidt.dll
O2 - BHO: Class - {146A4A8B-66F9-80FA-6E14-51A6991BAC7D} - C:\WINDOWS\system32\apibs32.dll
O2 - BHO: Class - {4ABB5929-6D33-1BD3-5889-307B70AC94D2} - C:\WINDOWS\system32\crxz.dll
O2 - BHO: Class - {5CE5B985-51B1-3958-E5DB-92DD9091CFBB} - C:\WINDOWS\javavq.dll
O2 - BHO: Class - {63C3B90C-CAE8-913A-DBA5-AC8E0D0896D0} - C:\WINDOWS\system32\crbk32.dll
O2 - BHO: Class - {6827E44A-FCD1-5704-0FF9-EE64FBCBD77F} - C:\WINDOWS\system32\wingm32.dll
O2 - BHO: Class - {7D52FC72-76A8-77EF-270D-8A1A8EA30F96} - C:\WINDOWS\system32\winsx32.dll
O2 - BHO: Class - {91D042E7-25DF-B6F2-5C0C-B0963EF3EA01} - C:\WINDOWS\winqv32.dll
O2 - BHO: Class - {A4913EBE-69AB-7C2E-EA16-13F6C5E79E14} - C:\WINDOWS\system32\ipvh32.dll
O2 - BHO: Class - {C1A7352F-7207-2C2F-6A41-8C46196F8284} - C:\WINDOWS\system32\winug32.dll
O2 - BHO: Class - {C2EFCA32-D3CF-3801-B32F-6A7589AA0A8A} - C:\WINDOWS\netfd.dll
O2 - BHO: Class - {FEF289B2-6015-9A71-D02D-8394ED825678} - C:\WINDOWS\system32\javany.dll
O4 - HKLM\..\Run: [iesn.exe] C:\WINDOWS\system32\iesn.exe
O4 - HKLM\..\Run: [crbk32.exe] C:\WINDOWS\system32\crbk32.exe
O4 - HKLM\..\RunOnce: [apiua.exe] C:\WINDOWS\apiua.exe
O4 - HKLM\..\RunOnce: [crnf.exe] C:\WINDOWS\crnf.exe
O4 - HKLM\..\RunOnce: [appxr32.exe] C:\WINDOWS\system32\appxr32.exe
O4 - HKLM\..\RunOnce: [mfcpj32.exe] C:\WINDOWS\system32\mfcpj32.exe
O4 - HKLM\..\RunOnce: [mfcsy32.exe] C:\WINDOWS\mfcsy32.exe
O4 - HKLM\..\RunOnce: [javaad32.exe] C:\WINDOWS\system32\javaad32.exe
O4 - HKLM\..\RunOnce: [iexj.exe] C:\WINDOWS\system32\iexj.exe
O4 - HKLM\..\RunOnce: [ipfp.exe] C:\WINDOWS\system32\ipfp.exe
O4 - HKLM\..\RunOnce: [addvf.exe] C:\WINDOWS\system32\addvf.exe
O4 - HKLM\..\RunOnce: [appkj32.exe] C:\WINDOWS\appkj32.exe
O4 - HKLM\..\RunOnce: [addyu.exe] C:\WINDOWS\system32\addyu.exe
O4 - HKLM\..\RunOnce: [netkc32.exe] C:\WINDOWS\netkc32.exe
O4 - HKLM\..\RunOnce: [crcy.exe] C:\WINDOWS\system32\crcy.exe
O4 - HKLM\..\RunOnce: [sysxo.exe] C:\WINDOWS\sysxo.exe
O4 - HKLM\..\RunOnce: [msvh32.exe] C:\WINDOWS\msvh32.exe
O4 - HKLM\..\RunOnce: [addua.exe] C:\WINDOWS\addua.exe
O4 - HKLM\..\RunOnce: [addyp.exe] C:\WINDOWS\addyp.exe
O4 - HKLM\..\RunOnce: [crzj32.exe] C:\WINDOWS\crzj32.exe
O4 - HKLM\..\RunOnce: [msul32.exe] C:\WINDOWS\msul32.exe
O4 - HKLM\..\RunOnce: [crnn.exe] C:\WINDOWS\crnn.exe
O4 - HKLM\..\RunOnce: [winsx.exe] C:\WINDOWS\winsx.exe
O4 - HKLM\..\RunOnce: [crff32.exe] C:\WINDOWS\system32\crff32.exe
O16 - DPF: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} (JInitiator 1.3.1.13) - https://esis.ncwise.org/jinitiator/jinit.exe
O16 - DPF: {D27FFC5F-D7B9-4349-9F41-F7458B585374} (SoloTriv Control) - http://mirror.worldwinner.com/games...iv/solotriv.cab



~~~~~~~~~~~~~~

Enable the viewing of Hidden files
  1. Open Windows Explorer
  2. Go to Tools>Folder Options>View tab.
  3. enable the option for `Show hidden files and folder´
  4. disable the option for `Hide file extensions for known types´
  5. disable the option for `Hide protected operating system files´
  6. click "Yes" to confirm & then click "OK"

Locate and delete the following folder(s), if present:
  • C:\WINDOWS\180solutions
    C:\Documents and Settings\jthomps\Favorites\Sites about\
Locate and delete the following file(s), if present:
  • C:\WINDOWS\Downloaded Program Files\SbCIe???.???

~~~~~~~~~~~~~~

Run Cleanup! & configure the program up as follows:
  1. Click Options...
  2. Move the arrow down to Custom CleanUp!
  3. Put a check next to the following:
    • Empty Recycle Bins
    • Delete Cookies
    • Delete Prefetch files
    • [X]Scan local drives for temporary files (Please uncheck this option)
    • Cleanup! All Users
  4. Click OK
  5. Press the CleanUp! button to start the program. Reboot/logoff when prompted.
* CleanUp! will delete all the files in your temp folders without making a backup


~~~~~~~~~~~~~~

Run SpSeHjfix and click on [Start Disinfection].
If SpSeHjfix finds the "system clean", it will not proceed with the next stage. Otherwise, it may reboot your machine to finish the cleaning process. A log of the fix will be created in the containing folder.

Run CWShredder & Click the [Fix] button.

~~~~~~~~~~~~~~

Reboot and download Trend Micro™ Anti-Spyware for the Web Utility (by clicking the "Scan and Clean your PC" button).
  • Save it to your desktop.
  • Double-click the new icon on your desktop (tmas-web-scan.exe)
  • It will say "Loading TrendMicro definitions".
  • Once the definitions are loaded, the program will appear to close then re-open.
  • Click "Start Scan"
  • After it's done scanning, click "Scan Results"
  • Make sure all items found have a check next to them, then click "Clean Threats Now".
  • Click Exit.
Reboot your computer. In place of the TrendMicro icon will be a text file called "Antispyware.log", please double-click that log and copy the entire contents and paste them here.


In your next post, please include fresh copies of:

1. HiJackThis log
2. Antispyware.log
3. SpSeHjfix's log

Please provide details of any problems you encountered whilst performing the above steps.
Update us on how your computer behaves now
__________________

Question - what have you done for the community today?
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 07-12-2005, 07:03 PM   #5 (permalink)
Registered User
 
Join Date: Sep 2004
Posts: 11
OS: XP Professional


thanks....next?

HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 8:57:25 PM, on 7/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\MsiExec.exe
C:\WINDOWS\iegn32.exe
C:\WINDOWS\System32\sistray.EXE
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\dpmw32.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DLink\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {710D83F2-D312-9683-955D-E46F3DC64541} - C:\WINDOWS\ipyk32.dll
O2 - BHO: Class - {A512FB1C-927A-CC1E-86A8-0057B192600A} - C:\WINDOWS\msde.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Class - {C9AAF6C6-1AF0-F61B-55AB-4198770AA549} - C:\WINDOWS\system32\ipwa.dll
O2 - BHO: Class - {DA692D53-0117-E647-4FC9-E8D29D3E7D5F} - C:\WINDOWS\system32\ntog32.dll
O2 - BHO: Class - {E2CF3F20-7B47-7FDF-0B4B-317598789569} - C:\WINDOWS\system32\appnn.dll
O2 - BHO: Class - {F00ADCBD-1759-E8D3-3EB9-1B8318EAC367} - C:\WINDOWS\mssh32.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [ntal32.exe] C:\WINDOWS\system32\ntal32.exe
O4 - HKLM\..\Run: [iegn32.exe] C:\WINDOWS\iegn32.exe
O4 - HKLM\..\RunOnce: [addok32.exe] C:\WINDOWS\system32\addok32.exe
O4 - HKLM\..\RunOnce: [mfcso32.exe] C:\WINDOWS\mfcso32.exe
O4 - HKLM\..\RunOnce: [sysgi.exe] C:\WINDOWS\sysgi.exe
O4 - HKLM\..\RunOnce: [ntml.exe] C:\WINDOWS\ntml.exe
O4 - HKLM\..\RunOnce: [apinx.exe] C:\WINDOWS\apinx.exe
O4 - HKLM\..\RunOnce: [wingp32.exe] C:\WINDOWS\system32\wingp32.exe
O4 - HKLM\..\RunOnce: [atlls.exe] C:\WINDOWS\atlls.exe
O4 - HKLM\..\RunOnce: [apiop32.exe] C:\WINDOWS\system32\apiop32.exe
O4 - HKLM\..\RunOnce: [netpc32.exe] C:\WINDOWS\system32\netpc32.exe
O4 - HKLM\..\RunOnce: [appfq32.exe] C:\WINDOWS\appfq32.exe
O4 - HKLM\..\RunOnce: [ipju32.exe] C:\WINDOWS\system32\ipju32.exe
O4 - HKLM\..\RunOnce: [ipaq.exe] C:\WINDOWS\system32\ipaq.exe
O4 - HKLM\..\RunOnce: [d3qv.exe] C:\WINDOWS\d3qv.exe
O4 - HKLM\..\RunOnce: [crzb.exe] C:\WINDOWS\system32\crzb.exe
O4 - HKLM\..\RunOnce: [winel.exe] C:\WINDOWS\winel.exe
O4 - HKLM\..\RunOnce: [mfcxk.exe] C:\WINDOWS\system32\mfcxk.exe
O4 - HKLM\..\RunOnce: [msde.exe] C:\WINDOWS\msde.exe
O4 - HKLM\..\RunOnce: [mfcuk32.exe] C:\WINDOWS\mfcuk32.exe
O4 - HKLM\..\RunOnce: [javajh.exe] C:\WINDOWS\system32\javajh.exe
O4 - HKLM\..\RunOnce: [javanh32.exe] C:\WINDOWS\system32\javanh32.exe
O4 - HKLM\..\RunOnce: [netde.exe] C:\WINDOWS\netde.exe
O4 - HKLM\..\RunOnce: [addca32.exe] C:\WINDOWS\addca32.exe
O4 - HKLM\..\RunOnce: [sdkfr.exe] C:\WINDOWS\sdkfr.exe
O4 - HKLM\..\RunOnce: [d3jv32.exe] C:\WINDOWS\system32\d3jv32.exe
O4 - HKLM\..\RunOnce: [atlnf32.exe] C:\WINDOWS\system32\atlnf32.exe
O4 - HKLM\..\RunOnce: [netdm.exe] C:\WINDOWS\system32\netdm.exe
O4 - HKLM\..\RunOnce: [d3bh32.exe] C:\WINDOWS\d3bh32.exe
O4 - HKLM\..\RunOnce: [winxl32.exe] C:\WINDOWS\winxl32.exe
O4 - HKLM\..\RunOnce: [addqq32.exe] C:\WINDOWS\system32\addqq32.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\DLink\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addok32.exe" /s (file missing)
O23 - Service: avinitnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: schscnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\schscnt.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe



Antispyware


Started Scanning
Internet Cookies
Programs in Memory
Windows Registry
Found '' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA'
Found '' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE'
Found '' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW'
Found 'DisplayName' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA'
Found 'UninstallString' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA'
Found 'DisplayName' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE'
Found 'UninstallString' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE'
Found 'DisplayName' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW'
Found 'UninstallString' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW'
Found '' in 'CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5}'
Found '' in 'SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5}'
Internet URL Shortcuts
Files and Directories
Finished Scanning
Started Backup
Finished Backup
Started Cleaning
Finished Cleaning


SpSeHjfix's log



(7/12/05 5:30:22 PM) SPSeHjFix started v1.1.2
(7/12/05 5:30:22 PM) OS: WinXP Service Pack 2 (5.1.2600)
(7/12/05 5:30:22 PM) Language: english
(7/12/05 5:30:22 PM) Win-Path: C:\WINDOWS
(7/12/05 5:30:22 PM) System-Path: C:\WINDOWS\system32
(7/12/05 5:30:22 PM) Temp-Path: C:\DOCUME~1\jthomps\LOCALS~1\Temp\
(7/12/05 5:30:28 PM) Disinfection started
(7/12/05 5:30:28 PM) Bad-Dll(IEP): (not found)
(7/12/05 5:30:28 PM) Bad-Dll(IEP) in BHO: (not found)
(7/12/05 5:30:28 PM) UBF: 4 - UBB: 1 - UBR: 94
(7/12/05 5:30:28 PM) UBF: 4 - UBB: 1 - UBR: 94
(7/12/05 5:30:28 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
(7/12/05 5:30:28 PM) Stealth-String not found
(7/12/05 5:30:28 PM) Not infected->END


(7/12/05 5:31:21 PM) SPSeHjFix started v1.1.2
(7/12/05 5:31:21 PM) OS: WinXP Service Pack 2 (5.1.2600)
(7/12/05 5:31:21 PM) Language: english
(7/12/05 5:31:21 PM) Win-Path: C:\WINDOWS
(7/12/05 5:31:21 PM) System-Path: C:\WINDOWS\system32
(7/12/05 5:31:21 PM) Temp-Path: C:\DOCUME~1\jthomps\LOCALS~1\Temp\
(7/12/05 5:31:23 PM) Disinfection started
(7/12/05 5:31:23 PM) Bad-Dll(IEP): (not found)
(7/12/05 5:31:23 PM) Bad-Dll(IEP) in BHO: (not found)
(7/12/05 5:31:23 PM) UBF: 4 - UBB: 1 - UBR: 94
(7/12/05 5:31:23 PM) UBF: 4 - UBB: 1 - UBR: 94
(7/12/05 5:31:23 PM) Bad IE-pages: (none)
(7/12/05 5:31:23 PM) Stealth-String not found
(7/12/05 5:31:23 PM) Not infected->END


Thanks for your continued help....
bigjohn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 07-12-2005, 09:33 PM   #6 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,409
OS: N/A


Looks so much cleaner. We're getting close to home. The log done by the updated HJT has shown a new entry.

Please disable Webroot SpySweeper, as it may hinder the removal of some entries. You can re-enable it after you're clean.
To disable Webroot SpySweeper:
  • Go to the Options>Program Options
  • Uncheck Load at Windows Startup
  • Click Shields & uncheck all items there
  • Uncheck Home page shield.
  • Automaticly restore default without notifiction

~~~~~~~~~~~~~~

Remove a Malware Service
  1. Click Start>Run - type services.msc.
  2. Locate the Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) service and double-click on it to open the Properties dialog.
  3. Click the Stop button.
  4. In the Startup type dropdown select Disabled.
  5. Click the Apply button and then the Ok button.
  6. Close the Services window
  7. Then start HiJackThis & go to Config>Misc.Tools...>Delete an NT service...
    In the popup box that appears, type in " 11Fßä#·ºÄÖ`I" (without the quotes) & click the OK button.

~~~~~~~~~~~~~~

Start HiJackThis & go to Config>Misc Tools>Open process manager
Select the following and click [Kill process] one at a time. Some entries may no longer exist.
C:\WINDOWS\iegn32.exe
~~~~~~~~~~~~~~

Run a scan with HiJackThis & select(tick) the following & click [Fix checked] :

R3 - Default URLSearchHook is missing
O2 - BHO: Class - {710D83F2-D312-9683-955D-E46F3DC64541} - C:\WINDOWS\ipyk32.dll
O2 - BHO: Class - {A512FB1C-927A-CC1E-86A8-0057B192600A} - C:\WINDOWS\msde.dll
O2 - BHO: Class - {C9AAF6C6-1AF0-F61B-55AB-4198770AA549} - C:\WINDOWS\system32\ipwa.dll
O2 - BHO: Class - {DA692D53-0117-E647-4FC9-E8D29D3E7D5F} - C:\WINDOWS\system32\ntog32.dll
O2 - BHO: Class - {E2CF3F20-7B47-7FDF-0B4B-317598789569} - C:\WINDOWS\system32\appnn.dll
O2 - BHO: Class - {F00ADCBD-1759-E8D3-3EB9-1B8318EAC367} - C:\WINDOWS\mssh32.dll
O4 - HKLM\..\Run: [ntal32.exe] C:\WINDOWS\system32\ntal32.exe
O4 - HKLM\..\Run: [iegn32.exe] C:\WINDOWS\iegn32.exe
O4 - HKLM\..\RunOnce: [addok32.exe] C:\WINDOWS\system32\addok32.exe
O4 - HKLM\..\RunOnce: [mfcso32.exe] C:\WINDOWS\mfcso32.exe
O4 - HKLM\..\RunOnce: [sysgi.exe] C:\WINDOWS\sysgi.exe
O4 - HKLM\..\RunOnce: [ntml.exe] C:\WINDOWS\ntml.exe
O4 - HKLM\..\RunOnce: [apinx.exe] C:\WINDOWS\apinx.exe
O4 - HKLM\..\RunOnce: [wingp32.exe] C:\WINDOWS\system32\wingp32.exe
O4 - HKLM\..\RunOnce: [atlls.exe] C:\WINDOWS\atlls.exe
O4 - HKLM\..\RunOnce: [apiop32.exe] C:\WINDOWS\system32\apiop32.exe
O4 - HKLM\..\RunOnce: [netpc32.exe] C:\WINDOWS\system32\netpc32.exe
O4 - HKLM\..\RunOnce: [appfq32.exe] C:\WINDOWS\appfq32.exe
O4 - HKLM\..\RunOnce: [ipju32.exe] C:\WINDOWS\system32\ipju32.exe
O4 - HKLM\..\RunOnce: [ipaq.exe] C:\WINDOWS\system32\ipaq.exe
O4 - HKLM\..\RunOnce: [d3qv.exe] C:\WINDOWS\d3qv.exe
O4 - HKLM\..\RunOnce: [crzb.exe] C:\WINDOWS\system32\crzb.exe
O4 - HKLM\..\RunOnce: [winel.exe] C:\WINDOWS\winel.exe
O4 - HKLM\..\RunOnce: [mfcxk.exe] C:\WINDOWS\system32\mfcxk.exe
O4 - HKLM\..\RunOnce: [msde.exe] C:\WINDOWS\msde.exe
O4 - HKLM\..\RunOnce: [mfcuk32.exe] C:\WINDOWS\mfcuk32.exe
O4 - HKLM\..\RunOnce: [javajh.exe] C:\WINDOWS\system32\javajh.exe
O4 - HKLM\..\RunOnce: [javanh32.exe] C:\WINDOWS\system32\javanh32.exe
O4 - HKLM\..\RunOnce: [netde.exe] C:\WINDOWS\netde.exe
O4 - HKLM\..\RunOnce: [addca32.exe] C:\WINDOWS\addca32.exe
O4 - HKLM\..\RunOnce: [sdkfr.exe] C:\WINDOWS\sdkfr.exe
O4 - HKLM\..\RunOnce: [d3jv32.exe] C:\WINDOWS\system32\d3jv32.exe
O4 - HKLM\..\RunOnce: [atlnf32.exe] C:\WINDOWS\system32\atlnf32.exe
O4 - HKLM\..\RunOnce: [netdm.exe] C:\WINDOWS\system32\netdm.exe
O4 - HKLM\..\RunOnce: [d3bh32.exe] C:\WINDOWS\d3bh32.exe
O4 - HKLM\..\RunOnce: [winxl32.exe] C:\WINDOWS\winxl32.exe
O4 - HKLM\..\RunOnce: [addqq32.exe] C:\WINDOWS\system32\addqq32.exe
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addok32.exe" /s (file missing)



~~~~~~~~~~~~~~

Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard.
C:\WINDOWS\ipyk32.dll
C:\WINDOWS\msde.dll
C:\WINDOWS\system32\ipwa.dll
C:\WINDOWS\system32\ntog32.dll
C:\WINDOWS\system32\appnn.dll
C:\WINDOWS\mssh32.dll
C:\WINDOWS\system32\ntal32.exe
C:\WINDOWS\iegn32.exe
C:\WINDOWS\system32\addok32.exe
C:\WINDOWS\mfcso32.exe
C:\WINDOWS\sysgi.exe
C:\WINDOWS\ntml.exe
C:\WINDOWS\apinx.exe
C:\WINDOWS\system32\wingp32.exe
C:\WINDOWS\atlls.exe
C:\WINDOWS\system32\apiop32.exe
C:\WINDOWS\system32\netpc32.exe
C:\WINDOWS\appfq32.exe
C:\WINDOWS\system32\ipju32.exe
C:\WINDOWS\system32\ipaq.exe
C:\WINDOWS\d3qv.exe
C:\WINDOWS\system32\crzb.exe
C:\WINDOWS\winel.exe
C:\WINDOWS\system32\mfcxk.exe
C:\WINDOWS\msde.exe
C:\WINDOWS\mfcuk32.exe
C:\WINDOWS\system32\javajh.exe
C:\WINDOWS\system32\javanh32.exe
C:\WINDOWS\netde.exe
C:\WINDOWS\addca32.exe
C:\WINDOWS\sdkfr.exe
C:\WINDOWS\system32\d3jv32.exe
C:\WINDOWS\system32\atlnf32.exe
C:\WINDOWS\system32\netdm.exe
C:\WINDOWS\d3bh32.exe
C:\WINDOWS\winxl32.exe
C:\WINDOWS\system32\addqq32.exe
C:\WINDOWS\system32\addok32.exe
Start KillBox.
  1. Go to the File menu, and choose Paste from Clipboard.
    Verify that you've done this properly by clicking the dropdown-arrow next to the "Full Path of File to Delete" field. The filenames you pasted will be found in there. Do not be alarmed if several of these entries do not appear. Let me know which one appeared.
  2. Select/tick the following:
    * Delete on Reboot
    * End Explorer Shell While Killing File
    * "Unregister.dll Before Deleting" if it's not grayed out.
  3. Click the RED X button.
  4. Click [Yes] at the 'Delete on Reboot' prompt.
  5. Click [Yes] at the Pending Operations prompt.

~~~~~~~~~~~~~~

Upon reboot, post a fresh HJT log
__________________

Question - what have you done for the community today?

Last edited by sUBs; 07-12-2005 at 09:35 PM.
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 07-13-2005, 07:45 PM   #7 (permalink)
Registered User
 
Join Date: Sep 2004
Posts: 11
OS: XP Professional


getting there...

Still a bit slow on startup....But again thanks for the help, big time.

Verify that you've done this properly by clicking the dropdown-arrow next to the "Full Path of File to Delete" field. The filenames you pasted will be found in there. Do not be alarmed if several of these entries do not appear. Let me know which one appeared.

These didn't appear in Killbox:
c:\windows\ipyk32.dll
c:\windows\mssh32.dll

Here's the HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 9:40:54 PM, on 7/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\ntol32.exe
C:\WINDOWS\system32\MsiExec.exe
C:\WINDOWS\System32\sistray.EXE
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\dpmw32.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DLink\Bluetooth Software\BTTray.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\txvun.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\txvun.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\txvun.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\txvun.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\txvun.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\txvun.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\txvun.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {095933F6-AE92-4230-E373-22A96F9C0C5F} - C:\WINDOWS\msnu32.dll
O2 - BHO: Class - {0B1EC0AC-4B60-2E3C-6008-EA958BCC19DD} - C:\WINDOWS\ieto32.dll
O2 - BHO: Class - {116B5897-9869-1B77-3DC7-646F9CB58D2B} - C:\WINDOWS\system32\msrn32.dll
O2 - BHO: Class - {14763206-F6A7-4D6F-D4D5-2E72E367ABB1} - C:\WINDOWS\system32\apiqa32.dll
O2 - BHO: Class - {33EC6E43-4826-94FA-3A03-B94290B62B85} - C:\WINDOWS\ieij.dll
O2 - BHO: Class - {378AE8EE-0426-C141-F3C8-F6BD25766BFA} - C:\WINDOWS\iegh.dll
O2 - BHO: Class - {4EC161EA-4FC8-150B-C21E-5378B07ABE5D} - C:\WINDOWS\system32\javafq.dll
O2 - BHO: Class - {4F9E4629-7EAF-1FF6-F770-E08CAFC44CC5} - C:\WINDOWS\atlou.dll
O2 - BHO: Class - {544B7F26-ABCC-6632-0DB7-C12341FA8D26} - C:\WINDOWS\mfcco32.dll
O2 - BHO: Class - {5650AA43-7586-D4A3-49D9-D9FB154279D6} - C:\WINDOWS\system32\apilk.dll
O2 - BHO: Class - {56791174-6E86-7AEF-B404-ED9E42ABFF73} - C:\WINDOWS\winvc.dll
O2 - BHO: Class - {64E5E8FA-69A1-48F4-8963-F00907CAAF17} - C:\WINDOWS\system32\ntvx.dll
O2 - BHO: Class - {686EDB70-FD7A-B9A7-77C0-4C7E44057CFF} - C:\WINDOWS\nthq32.dll
O2 - BHO: Class - {72B3B578-A76A-7C0A-70B4-F15E624D8319} - C:\WINDOWS\system32\ntjs32.dll
O2 - BHO: Class - {73C994D2-169A-3A21-18CA-289B70E63DA3} - C:\WINDOWS\sdklb32.dll
O2 - BHO: Class - {77CD9B7C-6604-FD84-83FE-47AE9E1477C2} - C:\WINDOWS\system32\mspd32.dll
O2 - BHO: Class - {793213B8-A74C-2C0F-94D1-DD4AC65FBE45} - C:\WINDOWS\system32\mfceq32.dll
O2 - BHO: Class - {7AEF1698-E8CD-4535-C196-EAEADE211A17} - C:\WINDOWS\system32\appaa.dll
O2 - BHO: Class - {7E895675-8786-0AE8-F4FB-E7CDC57A70B8} - C:\WINDOWS\appwp32.dll
O2 - BHO: Class - {80C01395-9FF4-13F4-EE8C-750CC0B764CF} - C:\WINDOWS\javazw.dll
O2 - BHO: Class - {90706F45-D241-085D-C3F4-2CA0366EF00C} - C:\WINDOWS\system32\iprm.dll
O2 - BHO: Class - {964D3DD2-09FB-6B41-D4A8-3F2010E2B8A5} - C:\WINDOWS\iptw.dll
O2 - BHO: Class - {979130FE-70C0-35E6-DFA3-4D4D55876849} - C:\WINDOWS\atlqw.dll
O2 - BHO: Class - {97C211C9-3E29-A7D3-5DB7-A9B8789A8C69} - C:\WINDOWS\system32\sdknl32.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Class - {AC8C8EF2-B1DB-E428-AE33-869E38C4F846} - C:\WINDOWS\d3bj.dll
O2 - BHO: Class - {AD057E36-3E90-9C24-A714-A8ADE460FBF9} - C:\WINDOWS\ntxh.dll
O2 - BHO: Class - {B3205B60-1D3F-AADD-01D0-77FF30CC211B} - C:\WINDOWS\system32\atlml.dll
O2 - BHO: Class - {B4CF1A3D-BFA2-5C15-720D-3E33706227F0} - C:\WINDOWS\winyn32.dll
O2 - BHO: Class - {C70A9850-BFBE-FA80-AEBC-F027897A9AC5} - C:\WINDOWS\sdkpm32.dll
O2 - BHO: Class - {C7F1A546-4FA4-2F1E-B74E-2A722FED05AC} - C:\WINDOWS\system32\appyq32.dll
O2 - BHO: Class - {C8B127F3-B154-FA38-4A64-BAAF01543DCD} - C:\WINDOWS\system32\sysks.dll
O2 - BHO: Class - {D34815E7-66F7-C465-A083-5BABECE896F5} - C:\WINDOWS\system32\mfcsf32.dll
O2 - BHO: Class - {D59AC151-F00C-3509-5093-1C3589B36680} - C:\WINDOWS\appkj.dll
O2 - BHO: Class - {E0E5A173-0CF3-BCA9-8543-4B6252CD9DA6} - C:\WINDOWS\winao32.dll
O2 - BHO: Class - {E22C1991-1181-9BEB-C171-E0B7E631A3AF} - C:\WINDOWS\sysmu.dll
O2 - BHO: Class - {E931541A-F610-204D-5340-6A7598B41F6B} - C:\WINDOWS\system32\ieey.dll
O2 - BHO: Class - {EAF521EB-5513-475B-B2B3-4D4B1195A1B0} - C:\WINDOWS\mfcgz32.dll
O2 - BHO: Class - {FC99EFF4-58A4-239B-1E0E-184CC2DCD960} - C:\WINDOWS\system32\msls32.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [ipur.exe] C:\WINDOWS\ipur.exe
O4 - HKLM\..\Run: [ntol32.exe] C:\WINDOWS\ntol32.exe
O4 - HKLM\..\RunOnce: [ieqz32.exe] C:\WINDOWS\system32\ieqz32.exe
O4 - HKLM\..\RunOnce: [appxl32.exe] C:\WINDOWS\system32\appxl32.exe
O4 - HKLM\..\RunOnce: [atlqj.exe] C:\WINDOWS\atlqj.exe
O4 - HKLM\..\RunOnce: [sdkaf.exe] C:\WINDOWS\sdkaf.exe
O4 - HKLM\..\RunOnce: [appyo.exe] C:\WINDOWS\system32\appyo.exe
O4 - HKLM\..\RunOnce: [crmq.exe] C:\WINDOWS\system32\crmq.exe
O4 - HKLM\..\RunOnce: [d3gi.exe] C:\WINDOWS\d3gi.exe
O4 - HKLM\..\RunOnce: [iegn32.exe] C:\WINDOWS\system32\iegn32.exe
O4 - HKLM\..\RunOnce: [atlqm.exe] C:\WINDOWS\atlqm.exe
O4 - HKLM\..\RunOnce: [addoh.exe] C:\WINDOWS\addoh.exe
O4 - HKLM\..\RunOnce: [d3hx32.exe] C:\WINDOWS\system32\d3hx32.exe
O4 - HKLM\..\RunOnce: [addar.exe] C:\WINDOWS\system32\addar.exe
O4 - HKLM\..\RunOnce: [apinr32.exe] C:\WINDOWS\apinr32.exe
O4 - HKLM\..\RunOnce: [atlri.exe] C:\WINDOWS\system32\atlri.exe
O4 - HKLM\..\RunOnce: [crap32.exe] C:\WINDOWS\crap32.exe
O4 - HKLM\..\RunOnce: [ntsn.exe] C:\WINDOWS\ntsn.exe
O4 - HKLM\..\RunOnce: [ntne.exe] C:\WINDOWS\ntne.exe
O4 - HKLM\..\RunOnce: [d3ms32.exe] C:\WINDOWS\system32\d3ms32.exe
O4 - HKLM\..\RunOnce: [d3ee.exe] C:\WINDOWS\system32\d3ee.exe
O4 - HKLM\..\RunOnce: [ippv32.exe] C:\WINDOWS\ippv32.exe
O4 - HKLM\..\RunOnce: [msww.exe] C:\WINDOWS\msww.exe
O4 - HKLM\..\RunOnce: [d3mc.exe] C:\WINDOWS\d3mc.exe
O4 - HKLM\..\RunOnce: [iexy32.exe] C:\WINDOWS\iexy32.exe
O4 - HKLM\..\RunOnce: [ieuy.exe] C:\WINDOWS\system32\ieuy.exe
O4 - HKLM\..\RunOnce: [d3st32.exe] C:\WINDOWS\system32\d3st32.exe
O4 - HKLM\..\RunOnce: [appvi32.exe] C:\WINDOWS\system32\appvi32.exe
O4 - HKLM\..\RunOnce: [sdkqa32.exe] C:\WINDOWS\sdkqa32.exe
O4 - HKLM\..\RunOnce: [crhk.exe] C:\WINDOWS\system32\crhk.exe
O4 - HKLM\..\RunOnce: [ipab.exe] C:\WINDOWS\ipab.exe
O4 - HKLM\..\RunOnce: [iejh32.exe] C:\WINDOWS\iejh32.exe
O4 - HKLM\..\RunOnce: [mfcyw.exe] C:\WINDOWS\system32\mfcyw.exe
O4 - HKLM\..\RunOnce: [netyk32.exe] C:\WINDOWS\netyk32.exe
O4 - HKLM\..\RunOnce: [mfcbl.exe] C:\WINDOWS\mfcbl.exe
O4 - HKLM\..\RunOnce: [winay.exe] C:\WINDOWS\system32\winay.exe
O4 - HKLM\..\RunOnce: [netql.exe] C:\WINDOWS\netql.exe
O4 - HKLM\..\RunOnce: [msyw32.exe] C:\WINDOWS\msyw32.exe
O4 - HKLM\..\RunOnce: [ntlw32.exe] C:\WINDOWS\ntlw32.exe
O4 - HKLM\..\RunOnce: [cryy.exe] C:\WINDOWS\system32\cryy.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\DLink\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addok32.exe" /s (file missing)
O23 - Service: avinitnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: schscnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\schscnt.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
bigjohn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 07-13-2005, 11:31 PM   #8 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,409
OS: N/A


Please download these additional files/programs :- (Do not run them unless instructed to do so)
Unplug your computer from the Internet when you have finished downloading

TDS-3 - & Install.
Close it after you have finished installation.
Download & overwrite the existing file - "radius.td3", located in folder >> C:\Program Files\TDS-3\ with this file

About Buster - Unzip to a new folder on Desktop.
Update About Buster & exit the program once that is completed.

Ewido Security Suite - Install & Update it's database but do not run it yet.

cwsserviceremove.zip - Unzip the contents of cwsserviceremove.zip (cwsserviceremove.reg) to your desktop.

Backdoor.Agent.B Removal Tool from Symantec.
  1. Follow Symantec's instructions for how to run it.
  2. Be sure to save the log file. I will need to see it later.
  3. Restart your computer.

~~~~~~~~~~~~~~

Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard.
C:\WINDOWS\msnu32.dll
C:\WINDOWS\ieto32.dll
C:\WINDOWS\system32\msrn32.dll
C:\WINDOWS\system32\apiqa32.dll
C:\WINDOWS\ieij.dll
C:\WINDOWS\iegh.dll
C:\WINDOWS\system32\javafq.dll
C:\WINDOWS\atlou.dll
C:\WINDOWS\mfcco32.dll
C:\WINDOWS\system32\apilk.dll
C:\WINDOWS\winvc.dll
C:\WINDOWS\system32\ntvx.dll
C:\WINDOWS\nthq32.dll
C:\WINDOWS\system32\ntjs32.dll
C:\WINDOWS\sdklb32.dll
C:\WINDOWS\system32\mspd32.dll
C:\WINDOWS\system32\mfceq32.dll
C:\WINDOWS\system32\appaa.dll
C:\WINDOWS\appwp32.dll
C:\WINDOWS\javazw.dll
C:\WINDOWS\system32\iprm.dll
C:\WINDOWS\iptw.dll
C:\WINDOWS\atlqw.dll
C:\WINDOWS\system32\sdknl32.dll
C:\WINDOWS\d3bj.dll
C:\WINDOWS\ntxh.dll
C:\WINDOWS\system32\atlml.dll
C:\WINDOWS\winyn32.dll
C:\WINDOWS\sdkpm32.dll
C:\WINDOWS\system32\appyq32.dll
C:\WINDOWS\system32\sysks.dll
C:\WINDOWS\system32\mfcsf32.dll
C:\WINDOWS\appkj.dll
C:\WINDOWS\winao32.dll
C:\WINDOWS\sysmu.dll
C:\WINDOWS\system32\ieey.dll
C:\WINDOWS\mfcgz32.dll
C:\WINDOWS\system32\msls32.dll
C:\WINDOWS\ipur.exe
C:\WINDOWS\ntol32.exe
C:\WINDOWS\system32\ieqz32.exe
C:\WINDOWS\system32\appxl32.exe
C:\WINDOWS\atlqj.exe
C:\WINDOWS\sdkaf.exe
C:\WINDOWS\system32\appyo.exe
C:\WINDOWS\system32\crmq.exe
C:\WINDOWS\d3gi.exe
C:\WINDOWS\system32\iegn32.exe
C:\WINDOWS\atlqm.exe
C:\WINDOWS\addoh.exe
C:\WINDOWS\system32\d3hx32.exe
C:\WINDOWS\system32\addar.exe
C:\WINDOWS\apinr32.exe
C:\WINDOWS\system32\atlri.exe
C:\WINDOWS\crap32.exe
C:\WINDOWS\ntsn.exe
C:\WINDOWS\ntne.exe
C:\WINDOWS\system32\d3ms32.exe
C:\WINDOWS\system32\d3ee.exe
C:\WINDOWS\ippv32.exe
C:\WINDOWS\msww.exe
C:\WINDOWS\d3mc.exe
C:\WINDOWS\iexy32.exe
C:\WINDOWS\system32\ieuy.exe
C:\WINDOWS\system32\d3st32.exe
C:\WINDOWS\system32\appvi32.exe
C:\WINDOWS\sdkqa32.exe
C:\WINDOWS\system32\crhk.exe
C:\WINDOWS\ipab.exe
C:\WINDOWS\iejh32.exe
C:\WINDOWS\system32\mfcyw.exe
C:\WINDOWS\netyk32.exe
C:\WINDOWS\mfcbl.exe
C:\WINDOWS\system32\winay.exe
C:\WINDOWS\netql.exe
C:\WINDOWS\msyw32.exe
C:\WINDOWS\ntlw32.exe
C:\WINDOWS\system32\cryy.exe
Start KillBox.
  1. Go to the File menu, and choose Paste from Clipboard.
    Verify that you've done this properly by clicking the dropdown-arrow next to the "Full Path of File to Delete" field. The filenames you pasted will be found in there.
  2. Select/tick the following:
    * Replace on Reboot
    * Use Dummy
  3. Click the RED X button.
  4. Click [Yes] at the 'Delete on Reboot' prompt.
  5. Click [Yes] at the Pending Operations prompt.


~~~~~~~~~~~~~~

Reboot to SafeMode

Run CWShredder:
  • Double-click on CWShredder.exe.
  • Click "Fix ->" and click "OK" at the prompt.
  • CWShredder will scan and clean your system of CWS files.
  • Click "Next->" and then "Exit".

Remove the offending service:
  • Double-click on cwsserviceremove.reg you downloaded earlier.
  • When it asks you to merge the information to the registry click "Yes".

~~~~~~~~~~~~~~

Run a scan with HiJackThis & select(tick) the following & click [Fix checked] :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\txvun.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\txvun.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\txvun.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\txvun.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\txvun.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\txvun.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\txvun.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {095933F6-AE92-4230-E373-22A96F9C0C5F} - C:\WINDOWS\msnu32.dll
O2 - BHO: Class - {0B1EC0AC-4B60-2E3C-6008-EA958BCC19DD} - C:\WINDOWS\ieto32.dll
O2 - BHO: Class - {116B5897-9869-1B77-3DC7-646F9CB58D2B} - C:\WINDOWS\system32\msrn32.dll
O2 - BHO: Class - {14763206-F6A7-4D6F-D4D5-2E72E367ABB1} - C:\WINDOWS\system32\apiqa32.dll
O2 - BHO: Class - {33EC6E43-4826-94FA-3A03-B94290B62B85} - C:\WINDOWS\ieij.dll
O2 - BHO: Class - {378AE8EE-0426-C141-F3C8-F6BD25766BFA} - C:\WINDOWS\iegh.dll
O2 - BHO: Class - {4EC161EA-4FC8-150B-C21E-5378B07ABE5D} - C:\WINDOWS\system32\javafq.dll
O2 - BHO: Class - {4F9E4629-7EAF-1FF6-F770-E08CAFC44CC5} - C:\WINDOWS\atlou.dll
O2 - BHO: Class - {544B7F26-ABCC-6632-0DB7-C12341FA8D26} - C:\WINDOWS\mfcco32.dll
O2 - BHO: Class - {5650AA43-7586-D4A3-49D9-D9FB154279D6} - C:\WINDOWS\system32\apilk.dll
O2 - BHO: Class - {56791174-6E86-7AEF-B404-ED9E42ABFF73} - C:\WINDOWS\winvc.dll
O2 - BHO: Class - {64E5E8FA-69A1-48F4-8963-F00907CAAF17} - C:\WINDOWS\system32\ntvx.dll
O2 - BHO: Class - {686EDB70-FD7A-B9A7-77C0-4C7E44057CFF} - C:\WINDOWS\nthq32.dll
O2 - BHO: Class - {72B3B578-A76A-7C0A-70B4-F15E624D8319} - C:\WINDOWS\system32\ntjs32.dll
O2 - BHO: Class - {73C994D2-169A-3A21-18CA-289B70E63DA3} - C:\WINDOWS\sdklb32.dll
O2 - BHO: Class - {77CD9B7C-6604-FD84-83FE-47AE9E1477C2} - C:\WINDOWS\system32\mspd32.dll
O2 - BHO: Class - {793213B8-A74C-2C0F-94D1-DD4AC65FBE45} - C:\WINDOWS\system32\mfceq32.dll
O2 - BHO: Class - {7AEF1698-E8CD-4535-C196-EAEADE211A17} - C:\WINDOWS\system32\appaa.dll
O2 - BHO: Class - {7E895675-8786-0AE8-F4FB-E7CDC57A70B8} - C:\WINDOWS\appwp32.dll
O2 - BHO: Class - {80C01395-9FF4-13F4-EE8C-750CC0B764CF} - C:\WINDOWS\javazw.dll
O2 - BHO: Class - {90706F45-D241-085D-C3F4-2CA0366EF00C} - C:\WINDOWS\system32\iprm.dll
O2 - BHO: Class - {964D3DD2-09FB-6B41-D4A8-3F2010E2B8A5} - C:\WINDOWS\iptw.dll
O2 - BHO: Class - {979130FE-70C0-35E6-DFA3-4D4D55876849} - C:\WINDOWS\atlqw.dll
O2 - BHO: Class - {97C211C9-3E29-A7D3-5DB7-A9B8789A8C69} - C:\WINDOWS\system32\sdknl32.dll
O2 - BHO: Class - {AC8C8EF2-B1DB-E428-AE33-869E38C4F846} - C:\WINDOWS\d3bj.dll
O2 - BHO: Class - {AD057E36-3E90-9C24-A714-A8ADE460FBF9} - C:\WINDOWS\ntxh.dll
O2 - BHO: Class - {B3205B60-1D3F-AADD-01D0-77FF30CC211B} - C:\WINDOWS\system32\atlml.dll
O2 - BHO: Class - {B4CF1A3D-BFA2-5C15-720D-3E33706227F0} - C:\WINDOWS\winyn32.dll
O2 - BHO: Class - {C70A9850-BFBE-FA80-AEBC-F027897A9AC5} - C:\WINDOWS\sdkpm32.dll
O2 - BHO: Class - {C7F1A546-4FA4-2F1E-B74E-2A722FED05AC} - C:\WINDOWS\system32\appyq32.dll
O2 - BHO: Class - {C8B127F3-B154-FA38-4A64-BAAF01543DCD} - C:\WINDOWS\system32\sysks.dll
O2 - BHO: Class - {D34815E7-66F7-C465-A083-5BABECE896F5} - C:\WINDOWS\system32\mfcsf32.dll
O2 - BHO: Class - {D59AC151-F00C-3509-5093-1C3589B36680} - C:\WINDOWS\appkj.dll
O2 - BHO: Class - {E0E5A173-0CF3-BCA9-8543-4B6252CD9DA6} - C:\WINDOWS\winao32.dll
O2 - BHO: Class - {E22C1991-1181-9BEB-C171-E0B7E631A3AF} - C:\WINDOWS\sysmu.dll
O2 - BHO: Class - {E931541A-F610-204D-5340-6A7598B41F6B} - C:\WINDOWS\system32\ieey.dll
O2 - BHO: Class - {EAF521EB-5513-475B-B2B3-4D4B1195A1B0} - C:\WINDOWS\mfcgz32.dll
O2 - BHO: Class - {FC99EFF4-58A4-239B-1E0E-184CC2DCD960} - C:\WINDOWS\system32\msls32.dll
O4 - HKLM\..\Run: [ipur.exe] C:\WINDOWS\ipur.exe
O4 - HKLM\..\Run: [ntol32.exe] C:\WINDOWS\ntol32.exe
O4 - HKLM\..\RunOnce: [ieqz32.exe] C:\WINDOWS\system32\ieqz32.exe
O4 - HKLM\..\RunOnce: [appxl32.exe] C:\WINDOWS\system32\appxl32.exe
O4 - HKLM\..\RunOnce: [atlqj.exe] C:\WINDOWS\atlqj.exe
O4 - HKLM\..\RunOnce: [sdkaf.exe] C:\WINDOWS\sdkaf.exe
O4 - HKLM\..\RunOnce: [appyo.exe] C:\WINDOWS\system32\appyo.exe
O4 - HKLM\..\RunOnce: [crmq.exe] C:\WINDOWS\system32\crmq.exe
O4 - HKLM\..\RunOnce: [d3gi.exe] C:\WINDOWS\d3gi.exe
O4 - HKLM\..\RunOnce: [iegn32.exe] C:\WINDOWS\system32\iegn32.exe
O4 - HKLM\..\RunOnce: [atlqm.exe] C:\WINDOWS\atlqm.exe
O4 - HKLM\..\RunOnce: [addoh.exe] C:\WINDOWS\addoh.exe
O4 - HKLM\..\RunOnce: [d3hx32.exe] C:\WINDOWS\system32\d3hx32.exe
O4 - HKLM\..\RunOnce: [addar.exe] C:\WINDOWS\system32\addar.exe
O4 - HKLM\..\RunOnce: [apinr32.exe] C:\WINDOWS\apinr32.exe
O4 - HKLM\..\RunOnce: [atlri.exe] C:\WINDOWS\system32\atlri.exe
O4 - HKLM\..\RunOnce: [crap32.exe] C:\WINDOWS\crap32.exe
O4 - HKLM\..\RunOnce: [ntsn.exe] C:\WINDOWS\ntsn.exe
O4 - HKLM\..\RunOnce: [ntne.exe] C:\WINDOWS\ntne.exe
O4 - HKLM\..\RunOnce: [d3ms32.exe] C:\WINDOWS\system32\d3ms32.exe
O4 - HKLM\..\RunOnce: [d3ee.exe] C:\WINDOWS\system32\d3ee.exe
O4 - HKLM\..\RunOnce: [ippv32.exe] C:\WINDOWS\ippv32.exe
O4 - HKLM\..\RunOnce: [msww.exe] C:\WINDOWS\msww.exe
O4 - HKLM\..\RunOnce: [d3mc.exe] C:\WINDOWS\d3mc.exe
O4 - HKLM\..\RunOnce: [iexy32.exe] C:\WINDOWS\iexy32.exe
O4 - HKLM\..\RunOnce: [ieuy.exe] C:\WINDOWS\system32\ieuy.exe
O4 - HKLM\..\RunOnce: [d3st32.exe] C:\WINDOWS\system32\d3st32.exe
O4 - HKLM\..\RunOnce: [appvi32.exe] C:\WINDOWS\system32\appvi32.exe
O4 - HKLM\..\RunOnce: [sdkqa32.exe] C:\WINDOWS\sdkqa32.exe
O4 - HKLM\..\RunOnce: [crhk.exe] C:\WINDOWS\system32\crhk.exe
O4 - HKLM\..\RunOnce: [ipab.exe] C:\WINDOWS\ipab.exe
O4 - HKLM\..\RunOnce: [iejh32.exe] C:\WINDOWS\iejh32.exe
O4 - HKLM\..\RunOnce: [mfcyw.exe] C:\WINDOWS\system32\mfcyw.exe
O4 - HKLM\..\RunOnce: [netyk32.exe] C:\WINDOWS\netyk32.exe
O4 - HKLM\..\RunOnce: [mfcbl.exe] C:\WINDOWS\mfcbl.exe
O4 - HKLM\..\RunOnce: [winay.exe] C:\WINDOWS\system32\winay.exe
O4 - HKLM\..\RunOnce: [netql.exe] C:\WINDOWS\netql.exe
O4 - HKLM\..\RunOnce: [msyw32.exe] C:\WINDOWS\msyw32.exe
O4 - HKLM\..\RunOnce: [ntlw32.exe] C:\WINDOWS\ntlw32.exe
O4 - HKLM\..\RunOnce: [cryy.exe] C:\WINDOWS\system32\cryy.exe
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addok32.exe" /s (file missing)



~~~~~~~~~~~~~~

Run Cleanup! & configure the program up as follows:
  1. Click Options...
  2. Move the arrow down to Custom CleanUp!
  3. Put a check next to the following:
    • Empty Recycle Bins
    • Delete Cookies
    • Delete Prefetch files
    • [X]Scan local drives for temporary files (Please uncheck this option)
    • Cleanup! All Users
  4. Click OK
  5. Press the CleanUp! button to start the program. Reboot/logoff when prompted.
* CleanUp! will delete all the files in your temp folders without making a backup


~~~~~~~~~~~~~~

Run AboutBuster and save the logs:
  • Browse to where you saved AboutBuster and run AboutBuster.exe.
  • Click OK at the directions prompt.
  • Click Start and then OK to allow AboutBuster to scan for Alternate Data Streams.
  • Click Yes to allow it to shutdown explorer.exe.
  • It will begin to your computer for malicious files. If it asks if you would like to do a second pass, allow it to do so.
  • When it has finished, click Save Log. Make sure you save it as I need a copy of it.

~~~~~~~~~~~~~~

** Please disable all other antivirus programs before proceeding.**

Run Ewido:
  • Click Scanner
  • Click Complete System Scan to begin scanning.
  • Click OK when prompted to clean files
  • With the first file it prompts to clean, select the option - "Perform action on all infections" - & choose clean and click OK
  • Once finished, click the Save report button
  • Save the report to your desktop
Close Ewido

~~~~~~~~~~~~~~

Launch TDS-3 & it will scan your memory for running processes. This will take less than 30 seconds.
  • Go to System Testing on the menu bar & select Full System Scan.
  • After it has finished scanning, Delete ALL of those files found in the bottom window that shows as positives.
  • Rescan again
  • Select & Copy everything on the top pane into your next post.
  • If present, right click on any entry listed in the lower pane & select Save as text. This will create a logfile named scandump.txt in TDS-3's folder - post that in your next reply.

~~~~~~~~~~~~~~

Reboot to NormalMode.

Do an online scan at Kaspersky

Take note the names and locations of any file it detects but fails to clean.
* Turn off the real time scanner of any existing antivirus program while performing the online scan


Reboot Again & Run a new scan with HiJackThis. Save the log file and post the contents in your next reply.

In your next post, please include fresh copies of:

1. HiJackThis log
2. List of files that online scans failed to disinfect
3. About Buster's log
4. TDS-3's log
5. Backdoor.Agent.B Removal Tool's log
6. Ewido's log


Please provide details of any problems you encountered whilst performing the above steps.
Update us on how your computer behaves now
__________________

Question - what have you done for the community today?
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 07-15-2005, 11:59 AM   #9 (permalink)
Registered User
 
Join Date: Sep 2004
Posts: 11
OS: XP Professional


getting there...i think

Booting up a lot faster now...again, thanks so far.

1. HJT Log

Logfile of HijackThis v1.99.1
Scan saved at 1:47:15 PM, on 7/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\System32\sistray.EXE
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\dpmw32.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DLink\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\system32\MsiExec.exe

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [appac.exe] C:\WINDOWS\system32\appac.exe
O4 - HKLM\..\Run: [sysok.exe] C:\WINDOWS\sysok.exe
O4 - HKLM\..\Run: [apprt.exe] C:\WINDOWS\apprt.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\DLink\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/k...an_unicode.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O23 - Service: avinitnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: schscnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\schscnt.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe



2. Online scans:

Not sure if the Kaspersky scan deleted disinfected anything or not. The log file is huge-- here is a portion of it (if I need to post the whole thing let me know).


Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\

Scan Statistics:
Total number of scanned objects: 112384
Number of viruses found: 9
Number of infected objects: 14485
Number of suspicious objects: 2
Duration of the scan process: 4444 sec

Infected Object Name - Virus Name
C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-50757294-51d84901.zip/GetAccess.class Infected: Trojan.Java.ClassLoader.c
C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-50757294-51d84901.zip/InsecureClassLoader.class Infected: Exploit.Java.Bytverify
C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-50757294-51d84901.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a
C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-50757294-51d84901.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v
C:\Documents and Settings\jthomps\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-50757294-51d84901.zip Infected: Trojan-Downloader.Java.OpenConnection.v
C:\Documents and Settings\jthomps\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Deleted Items/10 May 2005 21:01 from Mail Delivery System:Mail delivery failed.eml/[From Webmaster@johnthompsonjr.com][Date Tue, 10 May 2005 16:59:56 -0400]/UNNAMED/email-doc.pif Infected: Net-Worm.Win32.Mytob.au
C:\Documents and Settings\jthomps\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Deleted Items/10 May 2005 21:01 from Mail Delivery System:Mail delivery failed.eml/[From Webmaster@johnthompsonjr.com][Date Tue, 10 May 2005 16:59:56 -0400]/UNNAMED Infected: Net-Worm.Win32.Mytob.au
C:\Documents and Settings\jthomps\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Deleted Items/10 May 2005 21:01 from Mail Delivery System:Mail delivery failed.eml Infected: Net-Worm.Win32.Mytob.au
C:\Documents and Settings\jthomps\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Sent Items/19 Apr 2004 12:44 to 'Old North State Apiaries':RE: Mail Deliver.rtf Suspicious: Exploit.HTML.Iframe.FileDownload
C:\Documents and Settings\jthomps\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Sent Items/20 Apr 2004 13:10 to 'Old North State Apiaries':RE: Mail Deliver.rtf Suspicious: Exploit.HTML.Iframe.FileDownload
C:\Documents and Settings\jthomps\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Infected: Exploit.HTML.Iframe.FileDownload
C:\System Volume Information\_restore{8BE5DB73-D7BE-4265-BEE7-58A995099902}\RP1\A0000001.pif:aafyu:$DATA Infected: Trojan-Downloader.Win32.Agent.bq
C:\System Volume Information\_restore{8BE5DB73-D7BE-4265-BEE7-58A995099902}\RP1\A0000001.pif:aaocu:$DATA Infected: Trojan-Downloader.Win32.Agent.bq
C:\System Volume Information\_restore{8BE5DB73-D7BE-4265-BEE7-58A995099902}\RP1\A0000001.pif:achpe:$DATA Infected: Trojan-Downloader.Win32.Agent.bq
C:\System Volume Information\_restore{8BE5DB73-D7BE-4265-BEE7-58A995099902}\RP1\A0000001.pif:acqgo:$DATA Infected: Trojan-Downloader.Win32.Agent.bq
C:\System Volume Information\_restore{8BE5DB73-D7BE-4265-BEE7-58A995099902}\RP1\A0000001.pif:actik:$DATA Infected: Trojan-Downloader.Win32.Agent.bq
C:\System Volume Information\_restore{8BE5DB73-D7BE-4265-BEE7-58A995099902}\RP1\A0000001.pif:adbeb:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{8BE5DB73-D7BE-4265-BEE7-58A995099902}\RP1\A0000001.pif:adebb:$DATA Infected: Trojan-Downloader.Win32.Agent.bq
C:\System Volume Information\_restore{8BE5DB73-D7BE-4265-BEE7-58A995099902}\RP1\A0000001.pif:aduaq:$DATA Infected: Trojan-Downloader.Win32.Agent.bq

3. About Buster's Log

AboutBuster 5.0 reference file 28
Scan started on [7/14/2005] at [9:50:32 PM]
------------------------------------------------
Removed Stream! C:\WINDOWS\_default.pif:bztdhe
------------------------------------------------
Removed File! : C:\Windows\duehu.dat
Removed File! : C:\Windows\idzmc.dat
Removed File! : C:\Windows\ijmii.dll
Removed File! : C:\Windows\iultz.dll
Removed File! : C:\Windows\jyqxt.dat
Removed File! : C:\Windows\kgdkx.dll
Removed File! : C:\Windows\oqtqd.dat
Removed File! : C:\Windows\pomfj.dat
Removed File! : C:\Windows\tbijr.dat
Removed File! : C:\Windows\txvun.dll
Removed File! : C:\Windows\udeqa.dll
Removed File! : C:\Windows\wustj.dat
Removed File! : C:\Windows\System32\esrxi.dll
Removed File! : C:\Windows\System32\hhnfg.dat
Removed File! : C:\Windows\System32\ixysh.dat
Removed File! : C:\Windows\System32\ketmc.dat
Removed File! : C:\Windows\System32\odnpw.dat
Removed File! : C:\Windows\System32\olsne.dat
Removed File! : C:\Windows\System32\peslc.dll
Removed File! : C:\Windows\System32\rldfc.dll
Removed File! : C:\Windows\System32\rwxif.dat
Removed File! : C:\Windows\System32\tjrrg.dat
Removed File! : C:\Windows\System32\yjscf.dll
Removed File! : C:\Windows\System32\ztips.dll
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 9:55:11 PM

4. TDS-3 Log

23:18:54 [Init] Trojan Defence Suite v3.2.0 (UNLICENSED)
23:18:54 [Init] Started 14-07-05 23:18:54 Eastern Standard Time (UTC: 5), Internet Time @1179.79
23:18:54 [Init] Loading TDS-3 Systems ...
23:18:54 [Init] Token successfully adjusted.
23:18:54 [Init] • TDS Privileges : OK. Adjusted TDS-3 token privileges to maximum
23:18:54 [Init] • Plugins : OK. Loaded 13
23:18:54 [Init] • Exec Protection : Not Installed
23:18:54 [Init] WARNING: Your Radius.TD3 database needs to be updated!
23:18:54 [Init] Please download the latest from http://tds.diamondcs.com.au/radius.td3
23:18:54 [Init] Licensed users can use the Update facility from the TDS menu
23:18:54 [Init] Loading Radius Advanced Scanning Systems ... <R3 Engine, DCS Labs>
23:19:09 [Init] • Radius Advanced Specialist Extensions on standby for 13 trojan families
23:19:09 [Init] • Systems Initialised [60540 references - 32393 primaries/15825 traces/12322 variants/other]
23:19:09 [Init] Radius Systems loaded. <Databases updated 14-07-2005>
23:19:09 [Init] TDS-3 Ready. <Jthomps@127.0.0.1 - United States>
23:19:09 [Tip Of The Day] Shopping for DiamondCS services and software is easy! Simply visit http://www.diamondcs.com.au/shop.php
23:19:09 [TDS] Good evening Jthomps.
23:19:13 [Mutex Memory Scan] Started...
23:19:15 [Mutex Memory Scan] Finished (no trojan mutexes found).
23:19:15 [TDS-3] This is an EVALUATION demo of TDS-3. Please see the help file for help on registering.
23:19:28 [CRC32] Started - verifying 29 files ...
23:19:42 [CRC32] Test finished.
23:20:01 [Memory Scan] Memory scan started, please wait a moment ...
23:20:02 [Memory Scan] Memory scan complete.
23:20:02 [Mutex Memory Scan] Started...
23:20:03 [Mutex Memory Scan] Finished (no trojan mutexes found).
23:20:03 [Trace Scan] Started...
23:20:11 [Trace Scan] Finished.
23:20:11 [ServiceScan] Scanning for services and drivers ...
23:20:17 [ServiceScan] Scanned 329 services and drivers.
23:20:17 [File Scan] Scanning in A:\ ...
23:20:18 [File Scan] Scanned 0 files: 0 alarms in 1.054688 seconds (Avg 1. files/sec)
23:20:18 [File Scan] Scanning in C:\ ...
00:52:10 [File Scan] Scanned 107705 files: 2 alarms in -80888.63 seconds (Avg -.33 files/sec)
00:52:10 [File Scan] Scanning in D:\ ...
00:58:20 [File Scan] Scanned 1859 files: 2 alarms in 370.4531 seconds (Avg 6.02 files/sec)
00:58:20 [File Scan] Scanning in E:\ ...
00:58:20 [File Scan] Scanned 0 files: 2 alarms in 0 seconds (Avg -1.#IND files/sec)
00:58:20 [File Scan] Scanning in F:\ ...
00:58:20 [File Scan] Scanned 0 files: 2 alarms in 1.000977E-02 seconds (Avg 1. files/sec)
00:58:20 [File Scan] Scanning in G:\ ...
00:58:20 [File Scan] Scanned 0 files: 2 alarms in 0 seconds (Avg -1.#IND files/sec)
00:58:20 [Scan] Finished.
08:59:34 [CRC32] Started - verifying 29 files ...
08:59:48 [CRC32] Test finished.
09:00:07 [Memory Scan] Memory scan started, please wait a moment ...
09:00:07 [Memory Scan] Memory scan complete.
09:00:07 [Mutex Memory Scan] Started...
09:00:09 [Mutex Memory Scan] Finished (no trojan mutexes found).
09:00:09 [Trace Scan] Started...
09:00:17 [Trace Scan] Finished.
09:00:17 [ServiceScan] Scanning for services and drivers ...
09:00:23 [ServiceScan] Scanned 329 services and drivers.
09:00:23 [File Scan] Scanning in A:\ ...
09:00:24 [File Scan] Scanned 0 files: 0 alarms in 1.041016 seconds (Avg 1. files/sec)
09:00:24 [File Scan] Scanning in C:\ ...
10:31:30 [File Scan] Scanned 107704 files: 0 alarms in 5465.379 seconds (Avg 20.71 files/sec)
10:31:30 [File Scan] Scanning in D:\ ...
10:37:39 [File Scan] Scanned 1859 files: 0 alarms in 368.832 seconds (Avg 6.04 files/sec)
10:37:39 [File Scan] Scanning in E:\ ...
10:37:39 [File Scan] Scanned 0 files: 0 alarms in 1.171875E-02 seconds (Avg 1. files/sec)
10:37:39 [File Scan] Scanning in F:\ ...
10:37:39 [File Scan] Scanned 0 files: 0 alarms in 0.0078125 seconds (Avg 1. files/sec)
10:37:39 [File Scan] Scanning in G:\ ...
10:37:39 [File Scan] Scanned 0 files: 0 alarms in 0 seconds (Avg -1.#IND files/sec)
10:37:39 [Scan] Finished.

5. Backdoor.Agent.B Removal Tool

No infection found

6. Ewido Log (see next post)

Thanks so much for the help.
bigjohn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 07-15-2005, 12:01 PM   #10 (permalink)
Registered User
 
Join Date: Sep 2004
Posts: 11
OS: XP Professional


Ewido's log

6. Ewido's Log


The log was too long to include.... I just cut and pasted a portion- I can send the entire log if needed.

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 11:17:33 PM, 7/14/2005
+ Report-Checksum: 78446C7A

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{04256906-BECE-83AC-2058-27ABA38B11A3} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{05CFF62B-F8EF-A6A3-C2D8-0649EE07F197} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{07FF232E-41D0-38A2-6073-6847AD3E6453} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{09248DC7-285D-A208-7675-8D1BAC7208C9} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0FBFA147-FFB4-19A8-49F8-D1A17B80E32D} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{208BD4D8-3DA2-3736-A8E6-F3AF3479FA31} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{26F5CDB0-3ADD-70F3-F30F-8DD2B92D52FF} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3A044FBA-5DEF-1ECF-55E6-8A9DE3722CEC} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3F15B481-32E2-FE85-96FA-A8976289B4FD} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{4A210C09-C3AE-D36C-3EC5-0D7723985463} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{4C1CBC17-3C15-343F-1E7C-D8F447935C05} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5345A51F-E5D0-5A0D-1418-A1C95C417E3C} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5BCC3EE7-9153-E89F-6D4E-9B02B02B4E2E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{72071605-48F5-CC68-B374-2CDDF451F27F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{735DDAC7-F8F1-47DD-D87A-6AF0100B6A48} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7658C68E-7ED4-8476-AC96-729091012307} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{77CD9B7C-6604-FD84-83FE-47AE9E1477C2} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7868EC16-8C67-1DBD-6D5A-EBB325881BD9} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8CD1D4D3-8260-44A7-67DD-A71E995AB77F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{929F8E8D-2C15-4240-E685-FA3C645381C5} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A4405AD1-A13C-E10B-4B57-D5092B102F2B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B78A202C-9FF5-481D-3E8C-0877C167707F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B7C06F7A-7E5B-8248-7CE7-E61C97F1037E} -> Spyware.MidAddle : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BAA4A995-E881-38F6-1E95-AF9F2785FBB3} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BB35FD19-38F4-89DC-FA76-BA6507A5C6D7} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BC0DC8BD-646D-FA46-8739-116B4F8B8228} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BC0FE7F5-AD1D-A795-C683-F3EB54072EFE} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BD00AB82-F105-58F8-2B31-B600383177E6} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BEB133E5-FD72-43b7-8AFF-681831CC72D9} -> Spyware.Hijacker.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C0E27572-BE10-BE39-5F1B-F26255B8F141} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D02510A9-69A7-24D5-85DA-D3EC8E911C73} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D775F18B-70E6-FBB1-C13D-52CE71E899B3} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{E4564D6D-4921-87B7-0C6A-2097D907B4A5} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F573A15E-4E08-2CE8-1F75-3F0D794E2E42} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FA6A8ADC-5ACF-A739-A8BF-5E4D7B5991C1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FA6A9E8D-BFF9-8822-80F2-D1B507D9FF99} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FBD21FB3-D80F-1A9B-2038-2D60684CDEE0} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1935655697-813497703-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{77CD9B7C-6604-FD84-83FE-47AE9E1477C2} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1935655697-813497703-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B78A202C-9FF5-481D-3E8C-0877C167707F} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1935655697-813497703-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BB35FD19-38F4-89DC-FA76-BA6507A5C6D7} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1935655697-813497703-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E0E5A173-0CF3-BCA9-8543-4B6252CD9DA6} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1935655697-813497703-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F573A15E-4E08-2CE8-1F75-3F0D794E2E42} -> Spyware.CoolWebSearch : Cleaned with backup
C:\Program Files\HijackThis\backups\backup-20050713-211723-796.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Active Setup Log.txt:kzdtub -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Active Setup Log.txt:lpkli -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Active Setup Log.txt:zpjij -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\addaa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addaj.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\addau32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\adday.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addbz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addcf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\adddj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\adddr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\adddu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addfb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addfz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addge32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addgv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addhq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addih.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\addjt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addkb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addke32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addkp.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\addkp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addkq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addky32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\addky32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\addlc.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\addle.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addmi.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\addns32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addoe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addog32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addoi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addoo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addoq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\addqb.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\addqh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addqq32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\addqt.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\addqt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addqx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addro32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addrt32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\addsq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addtl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addtr32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\addty32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\addva.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addvi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addvk32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\addvp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addvv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addvy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addwi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addwz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addxo.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\addxo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addxu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addya.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addyh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addyj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addyr32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\addyr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addyz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addzn32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\addzq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addzv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ahdqj.txt:bxllp -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ahdqj.txt:hnhvn -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ahdqj.txt:jaanj -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apiav.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apick32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apicu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apicw.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apidf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apief.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apieh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apifl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apifn32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apifw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apifx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apigl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apigs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apigv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apigz32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apihc.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apihn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiii32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apija32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apijg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apijs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apikh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiks.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apila.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apily32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apilz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apimr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apimy.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apioh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apioh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apipf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apipz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiqn.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apiqn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiqr.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apiqr32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apisa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apise.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apisn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiso32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apisq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apisr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apisu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apisz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apitr32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apiuc.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apiuj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiuk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiux.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiuy.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apiuy.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apiuy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apivv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiwg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiwi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apixt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apixx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiyb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiyt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apizd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appab32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\appad32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appaj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appbx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appcx32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\appdd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appde.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\appdp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appef.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appeu.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
bigjohn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 07-15-2005, 04:09 PM   #11 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,409
OS: N/A


It certainly looks cleaner than before.
Please include Kaspersky's log in your next post as an attchment.

= = = = = = = = = = =

Run a HiJackThis scan. Select the following entries & click Fix checked :

O4 - HKLM\..\Run: [appac.exe] C:\WINDOWS\system32\appac.exe
O4 - HKLM\..\Run: [sysok.exe] C:\WINDOWS\sysok.exe
O4 - HKLM\..\Run: [apprt.exe] C:\WINDOWS\apprt.exe



= = = = = = = = = = =

Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard.
  • C:\WINDOWS\system32\appac.exe
    C:\WINDOWS\sysok.exe
    C:\WINDOWS\apprt.exe
Start KillBox.
Go to the File menu, and choose Paste from Clipboard * this feature does not work on older versons of Killbox
Click the dropdown-arrow next to the "Full Path of File to Delete" field.
Verify that the filenames you pasted are found in there.
Select/tick the following:
* Replace on Reboot
* Use Dummy
* End Explorer Shell While Killing File
* "Unregister.dll Before Deleting" * if it's not grayed out
Click the RED X button.
Click "Yes" at the 'Delete on Reboot' prompt.
Click "Yes" at the 'Pending Operations' prompt.

* If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try Killbox again.


= = = = = = = = = = =

Then download SilentRunners.vbs - Right click & choose Save As... Save it as SilentRunners.vbs to Desktop.

Before proceeding, disable any anti-virus or anti-spyware programs that may block/disable scripts
Double-click SilentRunners.vbs to run it. This will take a few minutes.
When it's done, you'll receive the prompt "All Done!". It will create a file called "Startup Programs". Post ALL its contents here in your next reply.

Also include a fresh copy of HJT log
__________________

Question - what have you done for the community today?
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 07-15-2005, 06:54 PM   #12 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,409
OS: N/A


John,

Another thing I need you to do. Download this file & unzip it to a folder on Desktop.
Within that folder, double click on activesetup.vbs.
When it has finished running, it will pop up a 'Finish" message. A log will be created within that folder.
Post the contents of that log in your next reply
__________________

Question - what have you done for the community today?
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 07-16-2005, 07:33 AM   #13 (permalink)
Registered User
 
Join Date: Sep 2004
Posts: 11
OS: XP Professional


alrighty...

Startup Problems

"Silent Runners.vbs", revision 39, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"SiS Tray" = "C:\WINDOWS\System32\sistray.EXE" ["Silicon Integrated Systems Corporation"]
"PCTVOICE" = "pctspk.exe" [empty string]
"NDPS" = "C:\WINDOWS\System32\dpmw32.exe" [null data]
"CSAV_CheckViruses" = "C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe" ["Command Software Systems, Inc."]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"NWTRAY" = "NWTRAY.EXE" ["Novell, Inc."]

HKLM\Software\Microsoft\Active Setup\Installed Components\
>{26923b43-4d38-484f-9b9e-de460746276c}\(Default) = "Internet Explorer"
\StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigIE" [MS]
>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}\(Default) = "Outlook Express"
\StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigOE" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = "Google Toolbar Helper" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" [file not found]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
"{AF8DE18D-9065-4102-BC40-EB294A95BB07}" = "Novell Connections"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nwshlxnt.dll" ["Novell, Inc."]
"{04c23aa0-3d34-11d2-b788-008029605ac7}" = "NDPS Shell Extension"
-> {CLSID}\InProcServer32\(Default) = "ndpsprop.dll" [empty string]
"{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{6af09ec9-b429-11d4-a1fb-0090960218cb}" = "My Bluetooth Places"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\BTNEIG~1.DLL" ["WIDCOMM, Inc."]
"{9DED7A30-D572-4D21-8D82-6945EA697400}" = "Macromedia FlashPaper Context Menu"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Macromedia\FlashPaper 2\FlashPaperContextMenu.dll" [null data]
"{7C9D5882-CB4A-4090-96C8-430BFE8B795B}" = "Webroot Spy Sweeper Context Menu Integration"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll" ["Webroot Software, Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
INFECTION WARNING! "{54D9498B-CF93-414F-8984-8CE7FDE0D391}" = "ewido shell guard"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\shellhook.dll" ["TODO: <Firmenname>"]

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
INFECTION WARNING! "GinaDLL" = "NWGINA.DLL" ["Novell, Inc."]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\context.dll" ["ewido networks"]
FProtMenu\(Default) = "{4a479be0-3333-11d0-b519-00400519153f}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Command Software\Command AntiVirus\avshext.dll" ["Command Software Systems, Inc."]
Macromedia.FlashPaper.ContextMenu\(Default) = "{9DED7A30-D572-4D21-8D82-6945EA697400}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Macromedia\FlashPaper 2\FlashPaperContextMenu.dll" [null data]
NetWareMenuItems\(Default) = "{e3bbbfc0-f61f-11cf-bb16-00c04fd371f4}"
-> {CLSID}\InProcServer32\(Default) = "novnpnt.dll" ["Novell, Inc."]
TDS-3\(Default) = "{E8ADA3E1-CE9B-44A0-A165-997304EF4E18}"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\tds3shl.dll" [empty string]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\context.dll" ["ewido networks"]
TDS-3\(Default) = "{E8ADA3E1-CE9B-44A0-A165-997304EF4E18}"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\tds3shl.dll" [empty string]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
FProtMenu\(Default) = "{4A479BE0-3333-11D0-B519-00400519153F}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Command Software\Command AntiVirus\avshext.dll" ["Command Software Systems, Inc."]
NetWareMenuItems\(Default) = "{e3bbbfc0-f61f-11cf-bb16-00c04fd371f4}"
-> {CLSID}\InProcServer32\(Default) = "novnpnt.dll" ["Novell, Inc."]
NetWareServerMenu\(Default) = "{9b173360-732b-11ce-aa22-00805f9834b0}"
-> {CLSID}\InProcServer32\(Default) = "novnpnt.dll" ["Novell, Inc."]
SpySweeper\(Default) = "{7C9D5882-CB4A-4090-96C8-430BFE8B795B}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll" ["Webroot Software, Inc."]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]


Group Policies [Description] {enabled Group Policy setting}:
------------------------------------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
"NoActiveDesktop"=dword:00000001
[disables Active Desktop; removes Web tab from Display Properties|
Desktop (tab)|Customize Desktop... (button)|Desktop Items (window)]
{User Configuration|Administrative Templates|Desktop|Active Desktop|
Disable Active Desktop}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop disabled via Group Policy.

HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\jthomps\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"


Startup items in "jthomps" & "All Users" startup folders:
---------------------------------------------------------

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"Adobe Gamma Loader" -> shortcut to: "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]
"BTTray" -> shortcut to: "C:\Program Files\DLink\Bluetooth Software\BTTray.exe" ["WIDCOMM, Inc."]


Enabled Scheduled Tasks:
------------------------

"AE468DD091893E48" -> launches: "c:\progra~1\deadba~1\that blue spam.exe" [file not found]
"Enterprise update for Command AntiVirus" -> launches: "C:\Program Files\Command Software\Command AntiVirus\cuagent.exe" ["Command Software Systems, Inc."]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000004\LibraryPath = "%SystemRoot%\system32\netware\NWWS2NDS.DLL" ["Novell, Inc."]
000000000005\LibraryPath = "%SystemRoot%\system32\netware\NWWS2SAP.DLL" ["Novell, Inc."]
000000000006\LibraryPath = "%SystemRoot%\system32\netware\NWWS2SLP.DLL" ["Novell, Inc."]
000000000007\LibraryPath = "%SystemRoot%\system32\wshbth.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 28
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = "&Google" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = "&Google" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = "&Google" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll" ["Sun Microsystems, Inc."]

{CCA281CA-C863-46EF-9331-5C8D4460577F}\
"ButtonText" = "@btrez.dll,-4015"
"MenuText" = "@btrez.dll,-4017"
"Script" = "C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm" [null data]

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

avinitnt, avinitnt, ""C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe"" ["Command Software Systems, Inc."]
Bluetooth Service, btwdins, "C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe" ["WIDCOMM, Inc."]
Bluetooth Support Service, BthServ, "C:\WINDOWS\system32\svchost.exe -k bthsvcs" {"C:\WINDOWS\System32\bthserv.dll" [MS]}
DvpApi, dvpapi, ""C:\Program Files\Common Files\Command Software\dvpapi.exe"" ["Command Software Systems, Inc."]
ewido security suite control, ewido security suite control, "C:\Program Files\ewido\security suite\ewidoctrl.exe" ["ewido networks"]
ewido security suite guard, ewido security suite guard, "C:\Program Files\ewido\security suite\ewidoguard.exe" ["ewido networks"]
Machine Debug Manager, MDM, ""C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"" [MS]
Webroot Spy Sweeper Engine, svcWRSSSDK, "C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe" ["Webroot Software, Inc."]


----------
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 255 seconds.
+ The search for all Registry CLSIDs containing dormant Explorer Bars
took 28 seconds.
---------- (total run time: 314 seconds)


Activesetup

"Find activesetup", version1, launched at: 09:30
Operating System: Windows XP SP2


HKLM\Software\Microsoft\Active Setup\Installed Components\
">{26923b43-4d38-484f-9b9e-de460746276c}\(Default)" = "Internet Explorer"
\StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigIE" [MS]
">{881dd1c5-3dcf-431b-b061-f3f88e8be88a}\(Default)" = "Outlook Express"
\StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigOE" [MS]


HJT log

Logfile of HijackThis v1.99.1
Scan saved at 9:28:36 AM, on 7/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\sistray.EXE
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\dpmw32.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DLink\Bluetooth Software\BTTray.exe
C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.charlotte.com/
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\DLink\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/k...an_unicode.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O23 - Service: avinitnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: schscnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\schscnt.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe



Are we pretty much clean? Machine seems to be running much faster. Thanks a ton.
bigjohn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 07-16-2005, 09:38 AM   #14 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,409
OS: N/A


John,

Apparently, it's all gone. It was tough but you're finally clean.

Do you have any more problems with your computer? If not, you should be set to go.

Just a few bits of housekeeping left to do ...

Reset hidden/system files and folders
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Deselect the Show hidden files and folders option.
  • Select the Hide file extensions for known types option.
  • Select the Hide protected operating system files option.
  • Click Yes to confirm.
  • Click OK.

Clear Java Cache
  1. Click Start >Settings>Control Panel
  2. Click the Java Plugin Icon
  3. Click the Cache tab
  4. Click the Clear button and click OK to confirm
Note: Please repeat this procedure for each "Java Plugin" button in your Control Panel

Follow the instructions outlined here to clear Sun Java's cache.


Create a new System Restore point
  • click Start >> Run - type SYSDM.CPL & press Enter
  • select the System Restore Tab
  • tick on the checkbox - "Turn off System Restore on all drives"
  • click Apply
  • then untick the same checkbox & click OK

Enable Windows Auto Update
  • Go to Start>Run - type wuaucpl.cpl
  • tick on the checkbox - "Keep my computer up to date"
  • Under settings, choose "Automatically download the updates, and install them on the schedule that I specify".
  • Click on "OK".

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programs:
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SpywareGuard to catch and block spyware before it can execute.
  • IESpy-Ad to block access to malicious websites so you cannot be redirected to them from an infected site or email.

If you do not have a firewall, here are 3 free ones available for personal use:
In light of your recent hiccup, I'm sure you'll like to avoid any future infections. Please take a look at these well written articles
Have a safe & happy computing day.

Please respond to this thread one more time so we can mark this thread as resolved.
__________________

Question - what have you done for the community today?
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 07-17-2005, 03:33 PM   #15 (permalink)
Registered User
 
Join Date: Sep 2004
Posts: 11
OS: XP Professional


Thank you!

Downloaded everything and it's looking good. Thanks so much for your help.

I'll be making a donation shortly!
bigjohn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 05:54 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85