UNSOLVED

prospicience

updated

21 years ago

P

prospicience

1 Message

0

542

November 25th, 2005 22:00

command.exe/webhancer

Cannot get rid of these virus' they don't allow me to install anyprograms. I just reformatted my computer and they were back on my HD before I could even install Norton again. here's my HJT log thanks in advance.

Logfile of HijackThis v1.99.1
Scan saved at 6:29:34 AM, on 11/26/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\TGVlIFN0b25laG91c2U\command.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\HJT\HijackThis.exe

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\System32\WinNB57.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [shmapp] C:\WINDOWS\System32\shmapp.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://promo.dollarrevenue.com/webmasterexe/drsmartload114a.exe
O16 - DPF: {7149E79C-DC19-4C5E-A53C-A54DDF75EEE9} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/joysaver.cab
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} (MediaGatewayX) - http://static.zangocash.com/cab/Zango/ie/bridge-c18.cab
O20 - Winlogon Notify: WebCheck - C:\WINDOWS\system32\e802lido180c.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TGVlIFN0b25laG91c2U\command.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
  • mat2

    139 Posts

    249

    0

    Posted November 26th, 2005 09:00



    Welcome to the forum

    I am checking your log now and will return as soon as I have researched all the items.
    While we are working together, please ....

    • Reply to this thread. Do not start a new topic.
    • If you are unsure of what to do, stop and ask! Don't keep going on.
    • Be patient. HijackThis logs take some time to research
    • .


      Please note the following:
    • I will be working on your Malware issues: This may or may not, solve other issues you may have with your machine.
    • The fixes are specific to your problem and should only be used for this issue on this machine.
    • Please continue to review my answers until I tell you your machine is clear. (Absence of symptoms does not mean that everything is clear.)
    • The process may take considerable time.
  • mat2

    139 Posts

    249

    0

    Posted November 26th, 2005 11:00

    Hi

    You may want to print out these instructions or save them as a text file with Notepad to your desktop because we will be restarting into Safe Mode later on in the fix and you might not be able to access the Internet. Read this instructions carefully and feel free to ask if you're unsure about something

    A malicious .DLL file is disrupting the LSP chain on your computer. We need to get rid of it.

    • Please download LSPFix from here

    • Disconnect from the internet and run the LSPFix.exe that you have just finished downloading.

    • Check the I know what I'm doing box.

    • In the Keep box you should see one or more instances of webhdll.dll.

    • Select every instance of webhdll.dll and move each one to the Remove box by clicking the >> button.

    • When you are done click Finish >>.


    • ===============

      Go to Add/Remove programs and remove(uninstall) the following, if present:

        Web Related
        The above could appear anywhere within the entry. Be careful not to remove any personal or system software.

        ===============

        Next, Open a command prompt by:
        1. Clicking "Start", then "Run...".
        2. Enter "cmd" (without the quotes).
        3. Enter "services.msc" (without the quotes).

        Now, locate and 'stop' the following services, if present:

        Command Service (cmdService) owner ... (C:\WINDOWS\TGVlIFN0b25laG91c2U\command.exe)

        Look carefully, since the name of the service (above) can be anywhere in the entry; also be careful not to 'stop' any required system services

        ===============

        Run HiJackThis then:

        1. Click "Config..."
        2. Click "Misc Tools"
        3. Click "Open Process manager"

        Next, while holding down the CTRL key, locate (if present) and click on (highlight) each of the following:

        C:\WINDOWS\TGVlIFN0b25laG91c2U\command.exe

        Now double-check and make sure that only those item(s) above are highlighted, then click "Kill process". Now, click "Refresh", check again, and repeat this step if any remain..

        ===============

        Run HiJackThis and click "Scan", then check(tick) the following, if present:

        R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
        O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\System32\WinNB57.dll
        O4 - HKCU\..\Run: [shmapp] C:\WINDOWS\System32\shmapp.exe
        O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
        O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
        O15 - Trusted Zone: *.media-motor.net
        O15 - Trusted Zone: *.popuppers.com
        O15 - Trusted Zone: http://awbeta.net-nucleus.com
        O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://promo.dollarrevenue.com/webmasterexe/drsmartload114a.exe

        O16 - DPF: {7149E79C-DC19-4C5E-A53C-A54DDF75EEE9} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/joysaver.cab
        O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} (MediaGatewayX) - http://static.zangocash.com/cab/Zango/ie/bridge-c18.cab

        O20 - Winlogon Notify: WebCheck - C:\WINDOWS\system32\e802lido180c.dll
        O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TGVlIFN0b25laG91c2U\command.exe

        Now, with all windows closed except HiJackThis, click "Fix checked".

        ============

        1. Restart your computer. As your computer restarts, repeatedly press the F8 key on your keyboard until the Windows Advanced Options menu appears.
        2. Use the arrow key to select Safe Mode, and then press ENTER.
        3. Use an arrow key to select an operating system and press ENTER.
        4. When prompted whether you want your Windows to run in safe mode, click Yes.

        Make sure your able to view system and hidden files/ folders, as follows

        * Click Start
        * Open My Computer
        * Select the Tools menu and click Folder Options
        * Select the View Tab
        * Under the Hidden files and folders heading select Show hidden files and folders
        * Uncheck the Hide protected operating system files (recommended) option
        * Click Yes to confirm
        * Click OK
        Now use Windows Explorer to locate and delete the following item(s), if present.

        folders...

        C:\WINDOWS\TGVlIFN0b25laG91c2U

        files...

        C:\WINDOWS\System32\WinNB57.dll
        C:\WINDOWS\System32\shmapp.exe
        C:\WINDOWS\system32\e802lido180c.dll

        =============

        Restart Windows back into normal mode.Post back a new log, and let me know how everything goes.

         

        Message Edited by mat2 on 11-26-2005 08:00 PM

    • mat2

      139 Posts

      249

      0

      Posted December 20th, 2005 13:00

      Since there as been no reponse from the client for over 1 week, this thread is now considered closed.