UNSOLVED

Velec

updated

21 years ago

V

Velec

1 Rookie

73 Posts

0

1491

May 26th, 2005 18:00

Hijackthis

Hey,
can somebody help me?
I have run Hijackthis and do not no what to delete.
 de reason why I did run Hijackthis is Trojan-spy.
A fatal error occurred at 0028:C0011E36 in VXD VMM (01).
Security:Macafee & Adware SE could not locate the trojan horse.
 
Logfile of HijackThis v1.99.1
Scan saved at 20:17:16, on 26/05/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP4 (6.00.2800.1106)
Running processes:
C:\winnt\System32\smss.exe
C:\winnt\system32\winlogon.exe
C:\winnt\system32\services.exe
C:\winnt\system32\lsass.exe
C:\winnt\system32\svchost.exe
C:\winnt\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\winnt\System32\drivers\CDAC11BA.EXE
C:\WINNT\System32\svchost.exe
C:\winnt\system32\regsvc.exe
C:\winnt\system32\MSTask.exe
C:\winnt\system32\stisvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\winnt\system32\svchost.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\winnt\Explorer.EXE
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\winnt\system32\msole32.exe
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\winnt\system32\rundll32.exe
C:\winnt\system32\internat.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\winnt\system32\wuauclt.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://10.0.0.138/index.htm
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O3 - Toolbar: Virtual Maid - {77B2F8DE-CB3F-4b6b-839B-807DD1ADBA1C} - C:\PROGRA~1\VIRTUA~1\VIRTUA~1.DLL
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MSN Messenger] C:\winnt\System32\msmsgs.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [AME_CSA] rundll32 csa.cpl,RUN_DLL
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [WindowsFY] C:\wp.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\winnt\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\winnt\system32\msjava.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Microsoft AntiSpyware helper - {FE5EF18A-4A25-4D98-853C-E9B22B17451C} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {FE5EF18A-4A25-4D98-853C-E9B22B17451C} - (no file) (HKCU)
O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:tsk.mht!http://69.50.161.126/5/s1//q.chm::/file.exe
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/7/532/6712/6c5b0a1ae398e3/player.virtools.com/downloads/player/Install2.5/Installer.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\winnt\System32\drivers\CDAC11BA.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\winnt\System32\dmadmin.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
 
thank You
  • zbestwun2001

    4 Apprentice

    8831 Posts

    403

    0

    Posted May 26th, 2005 18:00

    Hi and welcome,


    Please read these instructions carefully and print them out! Be sure to follow ALL instructions!

    Please right-click: HEREand go to Save As (in Internet Explorer it's "Save Target As") in order to download Grinler's reg file. Save it to your desktop.

    Locate " smitfraud.reg" on your desktop and double-click it. When asked if you want to merge with the registry, click YES. Wait for the "merged successfully" prompt then follow the rest of the instructions below.

    Go to Start > Control Panel > Add or Remove Programs and remove the following programs, if found:

    Security IGuard
    Virtual Maid
    Search Maid


    Exit Add/Remove Programs.

    *IMPORTANT* CLICK THIS LINK TO LEARN HOW TO VIEW HIDDEN FILES

    I need you to copy all of the Killbox file paths below and paste them into Notepad.

    * Please download the Killbox by Option^Explicit. *In the event you already have Killbox, this is a new version that I need you to download.

    * Save it to your desktop.

    * Please double-click Killbox.exe to run it.

    * Select " Delete on Reboot".

    * Open the Notepad file where you saved the file paths earlier and
    copy the file paths below to the clipboard by highlighting ALL of them
    and pressing CTRL + C

    C: \wp.exe
    C:\ wp.bmp
    C:\ bsw.exe
    C:\Windows\ sites.ini
    C:\Windows\ popuper.exe
    C:\Windows\system32\ hhk.dll
    C:\Windows\System32\ wldr.dll
    C:\Windows\System32\ helper.exe
    C:\Windows\System32\ intmon.exe
    C:\Windows\System32\ shnlog.exe
    C:\Windows\System32\ intmonp.exe
    C:\Windows\System32\ msmsgs.exe
    C:\Windows\system32\ msole32.exe
    C:\Windows\System32\ ole32vbs.exe

    * Return to Killbox, go to the File menu, and choose " Paste from Clipboard".

    * Click the red-and-white " Delete File" button. Click " Yes" at the Delete on Reboot prompt. Click " No" at the Pending Operations prompt.

    If your computer does not restart automatically, please restart it manually.

    While
    your computer is restarting, tap the F8 key continually until a menu
    appears. Use your up arrow key to highlight Safe Mode, then hit enter.

    Make sure you can view hidden files.


    Using Windows Explorer, delete the following, if found, ( please do NOT try to find them by "search" because they will not show up that way

    FOLDERS to delete (in bold) if found:

    C:\Program Files\ Search Maid
    C:\Program Files\ Virtual Maid
    C:\Windows\System32\ Log Files
    C:\Program Files\ Security IGuard


    While still in Safe Mode, do the following:

    Make sure all programs and windows are closed. Run HiJackThis and place
    a check next to the following items, if found, then click FIX CHECKED

    items to fix

    Close HiJackThis.


    Reboot into normal mode.

    1.) Download The Hoster Press "Restore Original Hosts" and press "OK". Exit Program.

    2.) Right-Click HERE and Save As to download DelDomains.inf to your desktop.

    To use: RIGHT-CLICK DelDomains.inf on your desktop and select: Install (no need to restart)

    Note: This will remove all entries in the "Trusted Zone" and "Ranges" also.


    3.) Download, install, and run CleanUp!

    4.) Run this online virus scan: ActiveScan - Save the results from the scan!


    Post a new HiJackThis log along with the results from ActiveScan.

    Steve

    Message Edited by zbestwun2001 on 05-26-2005 01:08 PM

  • Velec

    1 Rookie

    73 Posts

    403

    0

    Posted May 31st, 2005 09:00

    Hi Steve,

    I did follow your instructions and it did work everything is back normal.

    But, I did not understand the next sentence:

    While still in Safe Mode, do the following:

    Make sure all programs and windows are closed. Run HiJackThis and place
    a check next to the following items, if found, then click FIX CHECKED
     
    What do you meen by following items.
    I have run HiJackThis but did not place any check may be that ain't write?
     
    This is the result of the latest Run HiJackThis:
     
    Logfile of HijackThis v1.99.1
    Scan saved at 5:50:32, on 31/05/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)
    Running processes:
    C:\winnt\System32\smss.exe
    C:\winnt\system32\winlogon.exe
    C:\winnt\system32\services.exe
    C:\winnt\system32\lsass.exe
    C:\winnt\system32\svchost.exe
    C:\winnt\system32\spoolsv.exe
    C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
    C:\winnt\System32\drivers\CDAC11BA.EXE
    C:\WINNT\System32\svchost.exe
    C:\winnt\system32\regsvc.exe
    C:\winnt\system32\MSTask.exe
    C:\winnt\system32\stisvc.exe
    C:\WINNT\system32\ZoneLabs\vsmon.exe
    C:\winnt\system32\svchost.exe
    C:\Program Files\Network Associates\VirusScan\VsStat.exe
    C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
    C:\Program Files\Network Associates\VirusScan\Avconsol.exe
    C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
    C:\winnt\Explorer.EXE
    C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
    C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Support.com\bin\tgcmd.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\winnt\system32\rundll32.exe
    C:\winnt\system32\internat.exe
    C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
    C:\PROGRA~1\WinZip\winzip32.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\HijackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://10.0.0.138/index.htm
    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
    O3 - Toolbar: Virtual Maid - {77B2F8DE-CB3F-4b6b-839B-807DD1ADBA1C} - C:\PROGRA~1\VIRTUA~1\VIRTUA~1.DLL (file missing)
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MSN Messenger] C:\winnt\System32\msmsgs.exe
    O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
    O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    O4 - HKLM\..\Run: [AME_CSA] rundll32 csa.cpl,RUN_DLL
    O4 - HKCU\..\Run: [internat.exe] internat.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
    O4 - HKCU\..\Run: [WindowsFY] C:\wp.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\winnt\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\winnt\system32\msjava.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\winnt\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\winnt\web\related.htm
    O9 - Extra button: Microsoft AntiSpyware helper - {FE5EF18A-4A25-4D98-853C-E9B22B17451C} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {FE5EF18A-4A25-4D98-853C-E9B22B17451C} - (no file) (HKCU)
    O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:tsk.mht!http://69.50.161.126/5/s1//q.chm::/file.exe
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/7/532/6712/6c5b0a1ae398e3/player.virtools.com/downloads/player/Install2.5/Installer.exe
    O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\winnt\System32\drivers\CDAC11BA.EXE
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\winnt\System32\dmadmin.exe
    O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
                                                                                                                                                                                                                                
    Please can you tell me if everything is OK now, or is there still something I have to do.
     
    Marc
     
    PS: Sorry for my English I m not used to write in Englisch
  • Velec

    1 Rookie

    73 Posts

    403

    0

    Posted May 31st, 2005 09:00

    Hi Steve,
     
    This is the log of ActiveScan:
     

    Incident                                Status                                Location

     

    Adware:Adware/Iguard                                No disinfected                                Windows Registry
    Adware:Adware/Popuper                                No disinfected                                C:\winnt\system32\intmonp.exe
    Adware:Adware/Virmaid                                No disinfected                                Windows Registry
    Adware:Adware/Popuper                                No disinfected                                C:\Documents and Settings\Administrator\Favorites\Anti Spam.ur
    Adware:Adware/PopuperN                                No disinfected                                C:\Documents and Settings\Administrator\Favorites\Network Security.url
    Adware:Adware/Popuper                                No disinfected                                C:\Documents and Settings\Administrator\Favorites\Spyware Removal.url
    Adware:Adware/Popuper                                No disinfected                                C:\Documents and Settings\Administrator\My Documents\Your Scanner.url
    Adware:Adware/Popuper                                No disinfected                                C:\Online Pharmacy.url
    Virus:Trj/Agent.OP                                Disinfected                                C:\WINNT\system32\helper.exe
    Adware:Adware/Popuper                                No disinfected                                C:\WINNT\system32\intmonp.exe
    Adware:Adware/Popuper                                No disinfected                                C:\WINNT\system32\msole32.exe
    Adware:Adware/Virmaid                                No disinfected                                C:\WINNT\system32\perfcii.ini


                                                                                                                                                             
                                                                                                  
    Please can you tell me if everything is OK now, or is there still something I have to do.
    Marc
    PS: Sorry for my English I m not used to write in Englisch
  • zbestwun2001

    4 Apprentice

    8831 Posts

    403

    0

    Posted May 31st, 2005 12:00

    Let's continue on with the fix...

    -

    Be sure to look this solution over before you begin. There are a some item(s) i'm not familar with. If you recognze any, then just omit them from this fix.



    Before we begin, let's move HiJackThis to it's own folder; like c:\HJT. When we're done ' cleaning' off your system, we're going to ' flush' the temporary folders which, with HiJackThis in it's current location, we'll lose both the program and the backups it creates. These backups are important in case we need to restore any 'fixed' entry(s) later.

    Also move the " Backups" folder, for HiJackThis, if present.



    Run HiJackThis and click " Scan", then check(tick) the following, if present:


    O3 - Toolbar: Virtual Maid - {77B2F8DE-CB3F-4b6b-839B-807DD1ADBA1C} - C:\PROGRA~1\VIRTUA~1\VIRTUA~1.DLL (file missing)

    O4 - HKCU\..\Run: [WindowsFY] C:\wp.exe


    Now, with all windows closed except HiJackThis, click " Fix checked".



    Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:

    files...

    C:\wp.exe

    -

    Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".



    Post back a new log, and let me know how everything goes.

    -

    Steve
  • Velec

    1 Rookie

    73 Posts

    403

    0

    Posted May 31st, 2005 18:00

    Hi Steve,

     

    I did run HJT again and found the following files:

    O3 - Toolbar: Virtual Maid - {77B2F8DE-CB3F-4b6b-839B-807DD1ADBA1C}
    O4 - HKCU\..\Run: [WindowsFY] C:\wp.exe

    Fix checked caused no trouble.

    I could not find
    C:\WP.exe

    Here by the most recent log file from HJT

    Logfile of HijackThis v1.99.1
    Scan saved at 21:13:06, on 31/05/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\winnt\System32\smss.exe
    C:\winnt\system32\winlogon.exe
    C:\winnt\system32\services.exe
    C:\winnt\system32\lsass.exe
    C:\winnt\system32\svchost.exe
    C:\winnt\system32\spoolsv.exe
    C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
    C:\winnt\System32\drivers\CDAC11BA.EXE
    C:\WINNT\System32\svchost.exe
    C:\winnt\system32\regsvc.exe
    C:\winnt\system32\MSTask.exe
    C:\winnt\system32\stisvc.exe
    C:\WINNT\system32\ZoneLabs\vsmon.exe
    C:\winnt\system32\svchost.exe
    C:\Program Files\Network Associates\VirusScan\VsStat.exe
    C:\winnt\Explorer.EXE
    C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
    C:\Program Files\Network Associates\VirusScan\Avconsol.exe
    C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
    C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Support.com\bin\tgcmd.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\winnt\system32\rundll32.exe
    C:\winnt\system32\internat.exe
    C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
    C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
    C:\winnt\system32\wuauclt.exe
    C:\HJT\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://10.0.0.138/index.htm
    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MSN Messenger] C:\winnt\System32\msmsgs.exe
    O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    O4 - HKLM\..\Run: [AME_CSA] rundll32 csa.cpl,RUN_DLL
    O4 - HKCU\..\Run: [internat.exe] internat.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\winnt\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\winnt\system32\msjava.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\winnt\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\winnt\web\related.htm
    O9 - Extra button: Microsoft AntiSpyware helper - {FE5EF18A-4A25-4D98-853C-E9B22B17451C} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {FE5EF18A-4A25-4D98-853C-E9B22B17451C} - (no file) (HKCU)
    O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:tsk.mht!http://69.50.161.126/5/s1//q.chm::/file.exe
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/7/532/6712/6c5b0a1ae398e3/player.virtools.com/downloads/player/Install2.5/Installer.exe
    O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\winnt\System32\drivers\CDAC11BA.EXE
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\winnt\System32\dmadmin.exe
    O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

    Velec

  • zbestwun2001

    4 Apprentice

    8831 Posts

    403

    0

    Posted May 31st, 2005 18:00

    Velec
    The log looks good except this minor entry.

    If you are still experienceing problems let me know.

    Let's continue on with the fix...




    Run HiJackThis and click " Scan", then check(tick) the following, if present:


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://10.0.0.138/index.htm


    Now, with all windows closed except HiJackThis, click " Fix checked".



    Post back a new log, and let me know how everything goes.
    Steve
  • Velec

    1 Rookie

    73 Posts

    403

    0

    Posted June 2nd, 2005 05:00

    Hi Steve,

     

    The file you specified is de log on page of my ADSL modem there for I did not HJT this.

    Is it necessary to run this. Please let me know.

    everything is going well. It seems there is no trace left of the trojan horse.

    Velec

  • zbestwun2001

    4 Apprentice

    8831 Posts

    403

    0

    Posted June 2nd, 2005 14:00

    If I have instructed you do delete a file that you know you should have plesae leave it, point that file out to me in the fresh log that you post.

    Steve
  • Velec

    1 Rookie

    73 Posts

    403

    0

    Posted June 5th, 2005 18:00

    Hi Steve,
     
    Better late than never I think.
    It has been a busy weekend.
     
    So yoy asked for a new log file and to point out the file.
    There it is.
     
    Logfile of HijackThis v1.99.1
    Scan saved at 21:02:55, on 5/06/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)
    Running processes:
    C:\winnt\System32\smss.exe
    C:\winnt\system32\winlogon.exe
    C:\winnt\system32\services.exe
    C:\winnt\system32\lsass.exe
    C:\winnt\system32\svchost.exe
    C:\winnt\system32\spoolsv.exe
    C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
    C:\winnt\System32\drivers\CDAC11BA.EXE
    C:\WINNT\System32\svchost.exe
    C:\winnt\system32\regsvc.exe
    C:\winnt\system32\MSTask.exe
    C:\winnt\system32\stisvc.exe
    C:\WINNT\system32\ZoneLabs\vsmon.exe
    C:\winnt\system32\svchost.exe
    C:\Program Files\Network Associates\VirusScan\VsStat.exe
    C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
    C:\winnt\Explorer.EXE
    C:\Program Files\Network Associates\VirusScan\Avconsol.exe
    C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
    C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Support.com\bin\tgcmd.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\winnt\system32\rundll32.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\winnt\system32\internat.exe
    C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
    C:\winnt\system32\wuauclt.exe
    C:\HJT\HijackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://10.0.0.138/index.htm  Log on for my ADSL-connection
    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor
    O4 - HKLM\..\Run: [MSN Messenger] C:\winnt\System32\msmsgs.exe
    O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    O4 - HKLM\..\Run: [AME_CSA] rundll32 csa.cpl,RUN_DLL
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [internat.exe] internat.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\winnt\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\winnt\system32\msjava.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: Microsoft AntiSpyware helper - {FE5EF18A-4A25-4D98-853C-E9B22B17451C} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {FE5EF18A-4A25-4D98-853C-E9B22B17451C} - (no file) (HKCU)
    O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:tsk.mht!http://69.50.161.126/5/s1//q.chm::/file.exe
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/7/532/6712/6c5b0a1ae398e3/player.virtools.com/downloads/player/Install2.5/Installer.exe
    O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\winnt\System32\drivers\CDAC11BA.EXE
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\winnt\System32\dmadmin.exe
    O23 - Service: iPod-service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
     
     
    For the rest I see anything strange.
     
    Thanks
  • zbestwun2001

    4 Apprentice

    8831 Posts

    245

    0

    Posted June 5th, 2005 19:00

    Good eyes, we would have had to restore that AOL entry.

    Let's see if we can get you fixed, cleaned and on your way today.


    Be sure to look this solution over before you begin. There are a some item(s) i'm not familar with. If you recognze any, then just omit them from this fix.

    a



    Run HiJackThis and click " Scan", then check(tick) the following, if present:


    O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:tsk.mht!http://69.50.161.126/5/s1//q.chm::/file.exe
    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/7/532/6712/6c5b0a1ae398e3/player.virtools.com/downloads/player/Install2.5/Installer.exe


    Now, with all windows closed except HiJackThis, click " Fix checked".



    Post back a new log, and let me know how everything goes.

    Steve