
UNSOLVED
My HijackThis Log, Please Help Me!
I am running Windows XP and I recently got this warning: "A fatal error in IE has occured at 0028:C0011E36 in VXD VMM <01> + 00010E36. Error was caused by Trojan-spy.HTML.Smitfraud.c"
Also it warned me that I was infected with the "Stealth.Hjack" virus
Here is my Log...Please help me, I am very dependent on my computer.
Logfile of HijackThis v1.99.1
Scan saved at 12:36:12 am, on 04-16-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\RoamMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Switching\User\RoamSvc.exe
C:\Program Files\Intel\NCS\Sync\NetSvc.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Belkin F8E825-USB MiniWireless Optical Mouse\cm20.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\winupdt.exe
C:\Documents and Settings\All Users\Application Data\msw\MSW.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
C:\WINDOWS\adiagcmg.exe
C:\WINDOWS\FHVPDLL.EXE
C:\WINDOWS\CITDENC.EXE
C:\WINDOWS\IEXPLOR.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\WinTask.exe
C:\WINDOWS\tempdl\Terp03292005.exe
C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
C:\WINDOWS\System32\picsvr\picsvr.exe
C:\Program Files\Media Access\MediaAccK.exe
C:\WINDOWS\System32\ifsv_32.exe
C:\Program Files\Media Access\MediaAccess.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system\elxwasehgh.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINDOWS\System32\idefx13n.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\wp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\SYSTEM32\kx509_kfwk5.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rdud.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\msw\BMan.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\SYSTEM32\krbcc32s.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotoffers.info/ad0278/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: 69.50.173.4 earthlink.net
O1 - Hosts: 69.50.173.4 www.earthlink.net
O1 - Hosts: 69.50.173.4 go.com
O1 - Hosts: 69.50.173.4 www.go.com
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINDOWS\System32\nsm1EB9.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [Start RF Wireless Mouse] C:\Program Files\Belkin F8E825-USB MiniWireless Optical Mouse\cm20.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe
O4 - HKLM\..\Run: [App32dll] c:\windows\system32\msnavc32.exe lee0105
O4 - HKLM\..\Run: [msw] C:\Documents and Settings\All Users\Application Data\msw\MSW.exe
O4 - HKLM\..\Run: [RSync] C:\WINDOWS\System32\netsync.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
O4 - HKLM\..\Run: [msmc] C:\WINDOWS\System32\msmc.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [ivrakznjpqdwqppvmdndda] C:\WINDOWS\adiagcmg.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\irarik.exe
O4 - HKLM\..\Run: [C:\WINDOWS\IEXPLOR.EXE] C:\WINDOWS\IEXPLOR.EXE
O4 - HKLM\..\Run: [FHVPDLL] C:\WINDOWS\FHVPDLL.EXE
O4 - HKLM\..\Run: [CITDENC] C:\WINDOWS\CITDENC.EXE
O4 - HKLM\..\Run: [AtxBrw] C:\WINDOWS\IEXPLOR.exe
O4 - HKLM\..\Run: [RUNGogoTools] C:\Program Files\GogoTools\Gogoware\LaunchAdware.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Mix Soft Ref Flag] C:\Documents and Settings\All Users\Application Data\Spam Jump Mix Soft\BurnSettings.exe
O4 - HKLM\..\Run: [C:\WINDOWS\WinTask.exe] C:\WINDOWS\WinTask.exe
O4 - HKLM\..\Run: [PopMark] C:\WINDOWS\WinTask.exe
O4 - HKLM\..\Run: [Visual Element FX5] C:\WINDOWS\tempdl\Terp03292005.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\System32\picsvr\picsvr.exe
O4 - HKLM\..\Run: [tzszhp] c:\windows\system32\tzszhp.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [239h3El] ifsv_32.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [sf] C:\Program Files\sf\sf.exe
O4 - HKCU\..\Run: [sfita] C:\WINDOWS\sfita.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [J0qnROJql] idefx13n.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [Downloadelse] C:\DOCUME~1\Stephen\APPLIC~1\THATMP~1\Upload Tons Book.exe
O4 - HKCU\..\Run: [WindowsFY] c:\wp.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: KX509.lnk = C:\WINDOWS\SYSTEM32\kx509_kfwk5.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {7E30A5B6-71CC-46A5-AB64-DB129DA8B100} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7E30A5B6-71CC-46A5-AB64-DB129DA8B100} - (no file) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.1.5.28/blackjack/blackjack-ob-assets.cab
O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.1.5.28/jigsaw/jigsaw-ob-assets.cab
O16 - DPF: Perfect Passer by pogo - http://game1.pogo.com/applet-6.1.5.28/perfectpasser/perfectpasser-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.1.5.28/worldclass/worldclass-ob-assets.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099015700595
O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.101.3/g_bin/eng/poker_2_0_0_36.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Adapter Switching (IntelRoam) - Intel Corporation - C:\Program Files\Intel\Switching\User\RoamSvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PsShutdown (PsShutdownSvc) - Unknown owner - C:\WINDOWS\System32\PSSDNSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: RoamMgr - Intel Corporation - C:\WINDOWS\System32\RoamMgr.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
Responses (17)
Solutions (0)
- I ran Ad-aware, CWShredder, Spybot and everything else you recommended...I hope this new log is more helpful.Logfile of HijackThis v1.99.1
Scan saved at 06:57:04 pm, on 04-18-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Belkin F8E825-USB MiniWireless Optical Mouse\cm20.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\winupdt.exe
C:\Documents and Settings\All Users\Application Data\msw\MSW.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
C:\WINDOWS\adiagcmg.exe
C:\WINDOWS\IEXPLOR.EXE
C:\WINDOWS\FHVPDLL.EXE
C:\WINDOWS\CITDENC.EXE
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\WinTask.exe
C:\WINDOWS\tempdl\Terp03292005.exe
C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
C:\WINDOWS\System32\picsvr\picsvr.exe
C:\Program Files\Media Access\MediaAccK.exe
C:\WINDOWS\System32\ifsv_32.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system\elxwasehgh.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINDOWS\System32\idefx13n.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Media Access\MediaAccess.exe
C:\wp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\msw\BMan.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\SYSTEM32\kx509_kfwk5.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rdud.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\WINDOWS\SYSTEM32\krbcc32s.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\RoamMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Switching\User\RoamSvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Intel\NCS\Sync\NetSvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\HijackThis.exe
c:\progra~1\intern~1\iexplore.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotoffers.info/ad0278/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: 69.50.173.4 earthlink.net
O1 - Hosts: 69.50.173.4 www.earthlink.net
O1 - Hosts: 69.50.173.4 go.com
O1 - Hosts: 69.50.173.4 www.go.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINDOWS\System32\nsm1EB9.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [Start RF Wireless Mouse] C:\Program Files\Belkin F8E825-USB MiniWireless Optical Mouse\cm20.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe
O4 - HKLM\..\Run: [App32dll] c:\windows\system32\msnavc32.exe lee0105
O4 - HKLM\..\Run: [msw] C:\Documents and Settings\All Users\Application Data\msw\MSW.exe
O4 - HKLM\..\Run: [RSync] C:\WINDOWS\System32\netsync.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
O4 - HKLM\..\Run: [msmc] C:\WINDOWS\System32\msmc.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [ivrakznjpqdwqppvmdndda] C:\WINDOWS\adiagcmg.exe
O4 - HKLM\..\Run: [C:\WINDOWS\IEXPLOR.EXE] C:\WINDOWS\IEXPLOR.EXE
O4 - HKLM\..\Run: [FHVPDLL] C:\WINDOWS\FHVPDLL.EXE
O4 - HKLM\..\Run: [CITDENC] C:\WINDOWS\CITDENC.EXE
O4 - HKLM\..\Run: [AtxBrw] C:\WINDOWS\IEXPLOR.exe
O4 - HKLM\..\Run: [RUNGogoTools] C:\Program Files\GogoTools\Gogoware\LaunchAdware.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Mix Soft Ref Flag] C:\Documents and Settings\All Users\Application Data\Spam Jump Mix Soft\BurnSettings.exe
O4 - HKLM\..\Run: [C:\WINDOWS\WinTask.exe] C:\WINDOWS\WinTask.exe
O4 - HKLM\..\Run: [PopMark] C:\WINDOWS\WinTask.exe
O4 - HKLM\..\Run: [Visual Element FX5] C:\WINDOWS\tempdl\Terp03292005.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\System32\picsvr\picsvr.exe
O4 - HKLM\..\Run: [tzszhp] c:\windows\system32\tzszhp.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [239h3El] ifsv_32.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [sf] C:\Program Files\sf\sf.exe
O4 - HKCU\..\Run: [sfita] C:\WINDOWS\sfita.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [J0qnROJql] idefx13n.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [Downloadelse] C:\DOCUME~1\Stephen\APPLIC~1\THATMP~1\Upload Tons Book.exe
O4 - HKCU\..\Run: [WindowsFY] c:\wp.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: KX509.lnk = C:\WINDOWS\SYSTEM32\kx509_kfwk5.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {7E30A5B6-71CC-46A5-AB64-DB129DA8B100} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7E30A5B6-71CC-46A5-AB64-DB129DA8B100} - (no file) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.1.5.28/blackjack/blackjack-ob-assets.cab
O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.1.5.28/jigsaw/jigsaw-ob-assets.cab
O16 - DPF: Perfect Passer by pogo - http://game1.pogo.com/applet-6.1.5.28/perfectpasser/perfectpasser-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.1.5.28/worldclass/worldclass-ob-assets.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099015700595
O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.101.3/g_bin/eng/poker_2_0_0_36.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Adapter Switching (IntelRoam) - Intel Corporation - C:\Program Files\Intel\Switching\User\RoamSvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PsShutdown (PsShutdownSvc) - Unknown owner - C:\WINDOWS\System32\PSSDNSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: RoamMgr - Intel Corporation - C:\WINDOWS\System32\RoamMgr.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exeReply bobmartino
40 Posts
502
0
Posted April 19th, 2005 12:00
Hello and Welcome, Still a whole lot of stuff there, but lets give this a try. There is a lot here is you see something you don't want to remove move on and let me know at the end. There was a major infection that disappeared between log 1 and 2, it will probably return sometime soon.
Please print out or copy this page to notepad for easy reference when carrying out the instructions. Make sure to work through the fixes in the exact order they are listed. If you have any questions feel free to ask before carrying out the fixes.
Show Hidden and System files:
Go to My Computer >Tools >Folder Options >View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing / visible. Uncheck the Hide protected operating system files option.
For the options that you have checked/enabled, you may uncheck them after your log is clean.
If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad, but you want to keep).
Please download all of the following programs before trying any of the fixes:
Right click Del015Domains and choose Save As. Save it to your desktop. Right click on that file and choose Install. You may delete it afterwards.
Download Hoster http://www.greyknight17.com/spy/Hoster.exe and run it. Choose the 'Restore Original Hosts' button and press OK.
The Temp folders should be cleaned out periodically as installation programs and hijack programs leave a lot of junk there. Download CleanUp! ( Alternate Link if main link don't work) and install it. Don't run it yet.
==========================
Reboot into Safe Mode (hit F8 key until menu shows up).
End Running Processes:
Make sure to close any open browsers. Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click Kill process for each one if they are still listed (they shouldn't be - but double check it):
C:\WINDOWS\System32\winupdt.exe
C:\Documents and Settings\All Users\Application Data\msw\MSW.exe
C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
C:\WINDOWS\adiagcmg.exe
C:\WINDOWS\IEXPLOR.EXE
C:\WINDOWS\FHVPDLL.EXE
C:\WINDOWS\CITDENC.EXE
C:\WINDOWS\WinTask.exe
C:\WINDOWS\tempdl\Terp03292005.exe
C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
C:\WINDOWS\System32\picsvr\picsvr.exe
C:\Program Files\Media Access\MediaAccK.exe
C:\WINDOWS\System32\ifsv_32.exe
C:\WINDOWS\system\elxwasehgh.exe
C:\WINDOWS\System32\idefx13n.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\Program Files\Media Access\MediaAccess.exe
C:\wp.exe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\msw\BMan.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rdud.exe
Add / Remove Programs
Click > Start > Control Panel > Add / Remove Programs and uninstall the following programs:
Weatherbug
Security iGuard
MediaAccess
GogoTools
Open Hijack This and click on Scan. Check the following entries, if they are still there. (make sure you do not miss any)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotoffers.info/ad0278/ -- if you didn't set this fix it aswell
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: 69.50.173.4 earthlink.net
O1 - Hosts: 69.50.173.4 www.earthlink.net
O1 - Hosts: 69.50.173.4 go.com
O1 - Hosts: 69.50.173.4 www.go.com
O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINDOWS\System32\nsm1EB9.dll
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe
O4 - HKLM\..\Run: [App32dll] c:\windows\system32\msnavc32.exe lee0105
O4 - HKLM\..\Run: [msw] C:\Documents and Settings\All Users\Application Data\msw\MSW.exe
O4 - HKLM\..\Run: [RSync] C:\WINDOWS\System32\netsync.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
O4 - HKLM\..\Run: [msmc] C:\WINDOWS\System32\msmc.exe
O4 - HKLM\..\Run: [ivrakznjpqdwqppvmdndda] C:\WINDOWS\adiagcmg.exe
O4 - HKLM\..\Run: [C:\WINDOWS\IEXPLOR.EXE] C:\WINDOWS\IEXPLOR.EXE
O4 - HKLM\..\Run: [FHVPDLL] C:\WINDOWS\FHVPDLL.EXE
O4 - HKLM\..\Run: [CITDENC] C:\WINDOWS\CITDENC.EXE
O4 - HKLM\..\Run: [AtxBrw] C:\WINDOWS\IEXPLOR.exe
O4 - HKLM\..\Run: [RUNGogoTools] C:\Program Files\GogoTools\Gogoware\LaunchAdware.exe
O4 - HKLM\..\Run: [Mix Soft Ref Flag] C:\Documents and Settings\All Users\Application Data\Spam Jump Mix Soft\BurnSettings.exe
O4 - HKLM\..\Run: [C:\WINDOWS\WinTask.exe] C:\WINDOWS\WinTask.exe
O4 - HKLM\..\Run: [PopMark] C:\WINDOWS\WinTask.exe
O4 - HKLM\..\Run: [Visual Element FX5] C:\WINDOWS\tempdl\Terp03292005.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\System32\picsvr\picsvr.exe
O4 - HKLM\..\Run: [tzszhp] c:\windows\system32\tzszhp.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [239h3El] ifsv_32.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKCU\..\Run: [sf] C:\Program Files\sf\sf.exe
O4 - HKCU\..\Run: [sfita] C:\WINDOWS\sfita.exe
O4 - HKCU\..\Run: [J0qnROJql] idefx13n.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [Downloadelse] C:\DOCUME~1\Stephen\APPLIC~1\THATMP~1\Upload Tons Book.exe
O4 - HKCU\..\Run: [WindowsFY] c:\wp.exe
O9 - Extra button: Microsoft AntiSpyware helper - {7E30A5B6-71CC-46A5-AB64-DB129DA8B100} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7E30A5B6-71CC-46A5-AB64-DB129DA8B100} - (no file) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
Please remember to close all other windows, including browsers then click Fix checked.
Delete the following Files indicated in RED and Folders indicated in BLUE if they still exist.
C:\WINDOWS\System32\winupdt.exe
C:\Documents and Settings\All Users\Application Data\msw\
C:\WINDOWS\adiagcmg.exe
C:\WINDOWS\IEXPLOR.EXE -- note the spelling
C:\WINDOWS\FHVPDLL.EXE
C:\WINDOWS\CITDENC.EXE
C:\WINDOWS\WinTask.exe
C:\WINDOWS\tempdl\Terp03292005.exe
C:\WINDOWS\System32\nsvsvc\
C:\WINDOWS\System32\picsvr\
C:\Program Files\Media Access\
C:\WINDOWS\System32\ifsv_32.exe
C:\WINDOWS\system\elxwasehgh.exe
C:\WINDOWS\System32\idefx13n.exe
C:\PROGRA~1\AWS\
C:\wp.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rdud.exe
C:\WINDOWS\System32\nsm1EB9.dll
c:\windows\system32\msnavc32.exe
C:\WINDOWS\System32\netsync.exe
AUNPS2.DLL
C:\WINDOWS\System32\msmc.exe
C:\Program Files\GogoTools\
C:\Documents and Settings\All Users\Application Data\Spam Jump Mix Soft\BurnSettings.exe
c:\windows\system32\tzszhp.exe
C:\Program Files\Security iGuard\
C:\Program Files\sf\
C:\WINDOWS\sfita.exe
C:\DOCUME~1\Stephen\APPLIC~1\THATMP~1\Upload Tons Book.exe
Run CleanUp! and click on CleanUp! button. When it asks you if you want to logoff, click on Yes.
Reboot into Normal Mode and run new HijackThis scan. If there were some entries that didn't show up in Safe Mode, you may check and fix those that appear now in normal mode (if you do that, make sure to run a new scan again). Save the log file and post it up here.Reply - That seemed to help a bit, especially on reboot. However, I still have the "fatal error in IE" message in the middle of my desktop. I am also still being warned that my "system is attacked by stealth.Hjack virus!" I am also getting a message "Error #317-Mircosoft Windows Security Warning" Finally I keep getting unwanted icons (shortcuts) added to my desktop, even after I delete them. I ran everything you instructed, and here is my lastest log....Also, I'd like to thank you for your help so far, it's very much appreciated.Logfile of HijackThis v1.99.1
Scan saved at 09:35:48 pm, on 04-19-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Belkin F8E825-USB MiniWireless Optical Mouse\cm20.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\System32\gah95on6.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\SYSTEM32\kx509_kfwk5.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\SYSTEM32\krbcc32s.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\RoamMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Switching\User\RoamSvc.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Intel\NCS\Sync\NetSvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\program files\internet explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\HijackThis.exe
C:\PROGRA~1\MUSICM~1\Common\COMPON~1\MMCOMP~1.EXER0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotoffers.info/ad0278/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [Start RF Wireless Mouse] C:\Program Files\Belkin F8E825-USB MiniWireless Optical Mouse\cm20.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: KX509.lnk = C:\WINDOWS\SYSTEM32\kx509_kfwk5.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.1.5.28/blackjack/blackjack-ob-assets.cab
O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.1.5.28/jigsaw/jigsaw-ob-assets.cab
O16 - DPF: Perfect Passer by pogo - http://game1.pogo.com/applet-6.1.5.28/perfectpasser/perfectpasser-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.1.5.28/worldclass/worldclass-ob-assets.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099015700595
O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.101.3/g_bin/eng/poker_2_0_0_36.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Adapter Switching (IntelRoam) - Intel Corporation - C:\Program Files\Intel\Switching\User\RoamSvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PsShutdown (PsShutdownSvc) - Unknown owner - C:\WINDOWS\System32\PSSDNSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: RoamMgr - Intel Corporation - C:\WINDOWS\System32\RoamMgr.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exeReply bobmartino
40 Posts
502
0
Posted April 20th, 2005 10:00
Make sure to disable Spybot's Tea Timer for now, as it can interfere with the fixing of problems.
Open Spybot and and make sure you are in Advanced mode (check it in the 'Mode' menu). Go to the Tools section and click resident and then uncheck the box for Tea Timer.
Reboot into Safe Mode (hit F8 key until menu shows up). Make sure to close any open browsers. Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click Kill process for each one if they are still listed (they shouldn't be - but double check it):
C:\WINDOWS\System32\gah95on6.exe
Open Hijack This and click on Scan. Check the following entries, if they are still there.(make sure you do not miss any)
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe
Please remember to close all other windows, including browsers then click Fix checked.
Delete the following Files indicated in RED and Folders indicated in BLUE if they still exist.
C:\WINDOWS\System32\gah95on6.exe
Reboot into Normal Mode and run new HijackThis scan. If there were some entries that didn't show up in Safe Mode, you may check and fix those that appear now in normal mode (if you do that, make sure to run a new scan again). Save the log file and post it up here.
Let's use a program to scan for any trojans that may exist. Download TDS-3. Learn how to use it here. Make sure to update it after you installed it. You can get the manual updates here. When you launch the program, it will scan your memory for running processes. This will take less than 30 seconds. Next go to System Testing on the menu and choose Full System Scan. After that's finished, post the log file by selecting everything on the top pane (select from bottom to top). If any alarms are found, it will be listed in the bottom window. Please copy and paste that here also if it applies.I still have the "fatal error in IE" message in the middle of my desktop.
As a background picture or an error box on the screen?
Reply - First off, it appears that the "Error in IE" message is a background, and not an error box. Also the warning message comes from a red circle with an X in the middle, in my system tray. It advises me to download certain software to correct the problem, but I have not. I'm only downloading things you instruct me to. (this post contains 3 sections, the hijack log, the TDS3 log, and the Alarms from the TDS3 scan)The lastest HijackThis log:Logfile of HijackThis v1.99.1
Scan saved at 03:52:47 pm, on 04-20-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Belkin F8E825-USB MiniWireless Optical Mouse\cm20.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\SYSTEM32\kx509_kfwk5.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\SYSTEM32\krbcc32s.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\RoamMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Switching\User\RoamSvc.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Intel\NCS\Sync\NetSvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\HijackThis.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\PROGRA~1\MUSICM~1\Common\COMPON~1\MMCOMP~1.EXER0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.umich.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [Start RF Wireless Mouse] C:\Program Files\Belkin F8E825-USB MiniWireless Optical Mouse\cm20.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: KX509.lnk = C:\WINDOWS\SYSTEM32\kx509_kfwk5.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.1.5.28/blackjack/blackjack-ob-assets.cab
O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.1.5.28/jigsaw/jigsaw-ob-assets.cab
O16 - DPF: Perfect Passer by pogo - http://game1.pogo.com/applet-6.1.5.28/perfectpasser/perfectpasser-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.1.5.28/worldclass/worldclass-ob-assets.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099015700595
O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.101.3/g_bin/eng/poker_2_0_0_36.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Adapter Switching (IntelRoam) - Intel Corporation - C:\Program Files\Intel\Switching\User\RoamSvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PsShutdown (PsShutdownSvc) - Unknown owner - C:\WINDOWS\System32\PSSDNSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: RoamMgr - Intel Corporation - C:\WINDOWS\System32\RoamMgr.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exeReply - Sorry about 2 posts, it wouldn't let me put every thing on 1 post, as it was too many charactersThe TDS3 scan:16:25:22 [Init] Trojan Defence Suite v3.2.0 (UNLICENSED)
16:25:22 [Init] Started 20-04-05 16:25:22 Eastern Standard Time (UTC: 5), Internet Time @892.62
16:25:22 [Init] Loading TDS-3 Systems ...
16:25:22 [Init] Token successfully adjusted.
16:25:22 [Init] • TDS Privileges : OK. Adjusted TDS-3 token privileges to maximum
16:25:22 [Init] • Plugins : OK. Loaded 13
16:25:22 [Init] • Exec Protection : Not Installed
16:25:22 [Init] WARNING: Your Radius.TD3 database needs to be updated!
16:25:22 [Init] Please download the latest from http://tds.diamondcs.com.au/radius.td3
16:25:22 [Init] Licensed users can use the Update facility from the TDS menu
16:25:23 [Init] Loading Radius Advanced Scanning Systems ...
16:25:28 [Init] • Radius Advanced Specialist Extensions on standby for 13 trojan families
16:25:28 [Init] • Systems Initialised [39471 references - 16560 primaries/10873 traces/12038 variants/other]
16:25:28 [Init] Radius Systems loaded.
16:25:29 [Init] TDS-3 Ready. < Stephen@127.0.0.1 - United States>
16:25:29 [Tip Of The Day] For freeware applications also released by Diamond Computer Systems, go to http://www.diamondcs.com.au
16:25:29 [TDS] Good afternoon Stephen.
16:25:42 [Mutex Memory Scan] Started...
16:25:44 [Mutex Memory Scan] Finished (no trojan mutexes found).
16:25:44 [TDS-3] This is an EVALUATION demo of TDS-3. Please see the help file for help on registering.
16:25:59 [CRC32] Started - verifying 29 files ...
16:26:00 [CRC32] File doesn't exist: C:\autoexec.bat
16:26:08 [CRC32] Test finished.
16:28:55 [Memory Scan] Memory scan started, please wait a moment ...
16:28:59 [Memory Scan] Memory scan complete.
16:28:59 [Mutex Memory Scan] Started...
16:29:01 [Mutex Memory Scan] Finished (no trojan mutexes found).
16:29:01 [Trace Scan] Started...
16:29:07 [Trace Scan] Finished.
16:29:07 [ServiceScan] Scanning for services and drivers ...
16:29:15 [ServiceScan] Scanned 354 services and drivers.
16:29:15 [File Scan] Scanning in C:\ ...
17:32:04 [File Scan] Scanned 54782 files: 31 alarms in 3768.879 seconds (Avg 15.54 files/sec)
17:32:04 [File Scan] Scanning in D:\ ...
17:32:04 [File Scan] Scanned 0 files: 31 alarms in 5.859375E-02 seconds (Avg 1. files/sec)
17:32:04 [File Scan] Scanning in E:\ ...
17:32:19 [File Scan] Scanned 26 files: 31 alarms in 15.125 seconds (Avg 2.72 files/sec)
17:32:20 [Scan] Finished.The TDS3 scan alarm log:Scan Control Dumped @ 17:33:53 20-04-05
Positive identification: Adware.EZula.g2
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp436\a0065379.exePositive identification: Adware.EZula.g
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp436\a0065382.exePositive identification: Adware.EZula.g2
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp436\a0066434.exePositive identification: Adware.EZula.g1
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp436\a0066561.exePositive identification: Adware.EZula.g2
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp437\a0069282.exePositive identification: Adware.EZula.g1
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp437\a0069298.exePositive identification: Adware.EZula.g1
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp437\a0069301.exePositive identification: Adware.EZula.g2
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp441\a0072398.exePositive identification: Adware.EZula.g
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp441\a0072401.exePositive identification: Adware.EZula.g2
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp441\a0072426.exePositive identification: Adware.EZula.g
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp441\a0072431.exePositive identification: Adware.EZula.g2
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp441\a0073639.exePositive identification: Adware.EZula.g
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp441\a0073642.exePositive identification: Adware.EZula.g1
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp442\a0075063.exePositive identification (DLL): Adware.Toolbar.Mirar (dll)
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp442\a0075064.dllPositive identification : Possible WebDownloader
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp445\a0078306.exePositive identification : Possible WebDownloader
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp445\a0078335.exePositive identification : Possible WebDownloader
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp445\a0078336.exePositive identification : Possible WebDownloader
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp445\a0078338.exePositive identification (DLL): Adware.DelfinMediaViewer (dll)
File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp445\a0078345.ocxPositive identification: TrojanDropper.Win32.Small.fl
File: c:\windows\system32\setup66.exePositive identification (embedded in file): Adware.Toolbar.Mirar (dll)
File: c:\windows\system32\cache\876003.exePositive identification (embedded in file): Adware.Toolbar.Mirar.a (dll)
File: c:\windows\system32\cache\876003.exePositive identification: Adware.EZula.g1
File: c:\windows\system32\cache\ezstub.exePositive identification : Suspicious: Microsoft-tagged exe built with Borland compiler
File: c:\windows\system32\cache\helperinstall.exePositive identification (embedded in file): Trojan.Win32.Small.i
File: c:\windows\system32\cache\omi-ic-setup.exePositive identification (embedded in file): Trojan.Win32.Small.i
File: c:\windows\system32\cache\omi.exePositive identification : Possible WebDownloader
File: c:\windows\system32\cache\pop.exePositive identification: TrojanDropper.Win32.Small.fl
File: c:\windows\system32\cache\setup66.exePositive identification (embedded in file): TrojanDropper.Win32.Small.fl
File: c:\windows\system32\cache\setupwrapper.exeSuspicious Filename: Dual extensions
File: c:\windows\system32\cache\us4.0-2.exeReply bobmartino
40 Posts
502
0
Posted April 20th, 2005 21:00
Ok, now for some more log fun.
Can you run a scan at http://www.pandasoftware.com/activescan/com/activescan_principal.htm and post up the output here.
cheers
Reply - The log you requestedIncident Location
Adware:Adware/Hotoffers C:\WINDOWS\System32\param32.dll
Virus:Trj/Clicker.CY Operating system
Adware:Adware/Ucmore C:\Program Files\thesearchaccelerator
Adware:Adware/SaveNow Windows Registry
Adware:Adware/MyWay C:\Program Files\MySearch
Adware:Adware/nCase C:\WINDOWS\System32\FLEOK
Spyware:Spyware/ISTbar C:\Program Files\Common Files\Totem Shared
Spyware:Spyware/BetterInet Windows Registry
Adware:Adware/SAHAgent C:\WINDOWS\a95kfrhe.exe
Adware:Adware/Apropos C:\Program Files\cxtpls
Adware:Adware/WinTools Windows Registry
Adware:Adware/ISearch C:\WINDOWS\deskbar.ini
Adware:Adware/WUpd C:\WINDOWS\System32\a95kfrhe.ini
Adware:Adware/Beginto C:\WINDOWS\System32\rtneg?.dll
Adware:Adware/MyWebSearch Windows Registry
Adware:Adware/Kingporn C:\WINDOWS\System32\commcoss.dll
Spyware:Spyware/Spyblocs C:\Documents and Settings\Stephen\Desktop\Remove Spyware.url
Spyware:Spyware/Search3 C:\Program Files\Search3 Toolbar
Adware:Adware/BTGrab Windows Registry
Adware:Adware/InstaFinder C:\Program Files\INSTAFINK
Adware:Adware/Pacimedia C:\Documents and Settings\Stephen\Favorites\1111\1111.url
Adware:Adware/IGuard C:\WINDOWS\System32\wldr.dll
Adware:Adware/Hotoffers Windows Registry
Adware:Adware/SearchTheWeb C:\WINDOWS\System32\Cache\mswinstall.exe
Virus:Exploit/ByteVerify C:\Documents and Settings\Stephen\.jpi_cache\jar\1.0\arc.zip-53b42299-7a4efbaa.zip[VerifierBug.class]
Virus:Exploit/ByteVerify C:\Documents and Settings\Stephen\.jpi_cache\jar\1.0\arc.zip-53b42299-7a4efbaa.zip[Counter.class]
Virus:Exploit/ByteVerify C:\Documents and Settings\Stephen\.jpi_cache\jar\1.0\arc.zip-53b42299-7a4efbaa.zip[Gummy.class]
Virus:Exploit/ByteVerify C:\Documents and Settings\Stephen\.jpi_cache\jar\1.0\arc.zip-53b42299-7a4efbaa.zip[Beyond.class]
Virus:Exploit/ByteVerify C:\Documents and Settings\Stephen\.jpi_cache\jar\1.0\arc.zip-53b42299-7a4efbaa.zip[Worker.class]
Spyware:Spyware/AdClicker C:\Documents and Settings\Stephen\.jpi_cache\jar\1.0\arc.zip-53b42299-7a4efbaa.zip[web.exe]
Adware:Adware/PurityScan C:\Documents and Settings\Stephen\Application Data\osoa.exe
Adware:Adware/Lop C:\Documents and Settings\Stephen\Application Data\That mp3 five\comp cdrom mags rdr.exe
Adware:Adware/Lop C:\Documents and Settings\Stephen\Application Data\That mp3 five\Date Info Once.exe
Adware:Adware/Lop C:\Documents and Settings\Stephen\Application Data\That mp3 five\llhakhtp.exe
Virus:W32/Spybot.QV.worm C:\Documents and Settings\Stephen\Local Settings\Temp\tp7543.exe
Adware:Adware/Minibug C:\Program Files\AIM\Sysfiles\WxBug.EXE
Adware:Adware/DelFinMedia C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe
Adware:Adware/Apropos C:\Program Files\CxtPls\ace.dll
Adware:Adware/Apropos C:\Program Files\CxtPls\CxtPls.dll
Adware:Adware/Apropos C:\Program Files\CxtPls\CxtPls.exe
Adware:Adware/Apropos C:\Program Files\CxtPls\ProxyStub.dll
Adware:Adware/Apropos C:\Program Files\CxtPls\uninstaller.exe
Adware:Adware/Apropos C:\Program Files\CxtPls\WinGenerics.dll
Spyware:Spyware/ClearSearch C:\Program Files\oft8m045\3p07f56f.DLL
Spyware:Spyware/ClearSearch C:\Program Files\oft8m045\7s442bhq.DLL
Adware:Adware Program C:\Program Files\oft8m045\87672918.exe
Spyware:Spyware/ClearSearch C:\Program Files\oft8m045\dpcq38eb.DLL
Virus:Trj/Small.GO C:\temporary\aun_0018.exe
Adware:Adware/PortalScan C:\temporary\aun_0029.exe
Adware:Adware/SAHAgent C:\WINDOWS\70tovmto.exe
Adware:Adware/SAHAgent C:\WINDOWS\a95kfrhe.exe
Virus:Trj/SCBop.B C:\WINDOWS\ms05595670-10022005.exe
Virus:Trj/SCBop.B C:\WINDOWS\ms075670-1002592005.exe
Virus:Trj/SCBop.B C:\WINDOWS\SysCheckBop32.exe
Adware:Adware/SAHAgent C:\WINDOWS\SYSTEM32\2b3fsk0h.dll
Adware:Adware/SAHAgent C:\WINDOWS\SYSTEM32\a95kfrhe.ini
Virus:Trj/Downloader.BOV C:\WINDOWS\SYSTEM32\AUNPS.dll
Adware:Adware/SAHAgent C:\WINDOWS\SYSTEM32\bln02nqv.exe
Virus:Trj/Downloader.AWZ C:\WINDOWS\SYSTEM32\Cache\20001.exe
Virus:Trj/TSUpdate.A C:\WINDOWS\SYSTEM32\Cache\AMEX_54.exe
Virus:Trj/Downloader.BOD C:\WINDOWS\SYSTEM32\Cache\AUNIcons.exe
Adware:Adware/Beginto C:\WINDOWS\SYSTEM32\Cache\b2s-537466.exe
Virus:Trj/Downloader.BJG C:\WINDOWS\SYSTEM32\Cache\EDow_AS2.exe
Spyware:Spyware/ISTbar C:\WINDOWS\SYSTEM32\Cache\em_d.exe
Adware:Adware/eZula C:\WINDOWS\SYSTEM32\Cache\ezstub.exe
Adware:Adware/Gogotools C:\WINDOWS\SYSTEM32\Cache\gogotoolssilawo18pi.exe
Virus:Trj/Delf.EB C:\WINDOWS\SYSTEM32\Cache\HelperInstall.exe
Adware:Adware/ISearch C:\WINDOWS\SYSTEM32\Cache\HLInstaller.exe
Spyware:Spyware/ISTbar C:\WINDOWS\SYSTEM32\Cache\ic_d.exe
Adware:Adware/PortalScan C:\WINDOWS\SYSTEM32\Cache\InstallAPS.exe
Virus:Trj/Multidropper.XI C:\WINDOWS\SYSTEM32\Cache\installer_282r2_189.exe
Spyware:Spyware/BargainBuddy C:\WINDOWS\SYSTEM32\Cache\installer_MARKETING17.exe
Virus:Trj/Multidropper.UO C:\WINDOWS\SYSTEM32\Cache\Kyongju.exe
Adware:Adware/ISearch C:\WINDOWS\SYSTEM32\Cache\MTE0MzA6ODoxMg.exe
Virus:Trj/Downloader.BBA C:\WINDOWS\SYSTEM32\Cache\MTE1NDE6ODoxMg.exe
Adware:Adware/ISearch C:\WINDOWS\SYSTEM32\Cache\MTE1NjE6ODoxMg.exe
Adware:Adware/ISearch C:\WINDOWS\SYSTEM32\Cache\MTE1NTA6ODoxMg.exe
Virus:Trj/Small.GZ C:\WINDOWS\SYSTEM32\Cache\omi-ic-setup.exe
Virus:Trj/Small.GZ C:\WINDOWS\SYSTEM32\Cache\omi.exe
Adware:Adware/nCase C:\WINDOWS\SYSTEM32\Cache\pop.exe
Virus:Trj/Downloader.BJG C:\WINDOWS\SYSTEM32\Cache\Pop1.exe
Spyware:Spyware/ShhhToolbar C:\WINDOWS\SYSTEM32\Cache\runsearch.exe
Virus:Trj/SCBop.B C:\WINDOWS\SYSTEM32\Cache\Setup.exe
Spyware:Spyware/UrlSpy C:\WINDOWS\SYSTEM32\Cache\setup1015.exe
Virus:Trj/Downloader.BJG C:\WINDOWS\SYSTEM32\Cache\setup1015a.exe
Virus:Trj/Dropper.DB C:\WINDOWS\SYSTEM32\Cache\SetupWrapper.exe
Virus:Trj/Downloader.BJF C:\WINDOWS\SYSTEM32\Cache\skh2.exe
Spyware:Spyware/SurfSideKick C:\WINDOWS\SYSTEM32\Cache\SSK_B5 Seedcorn 2.EXE
Spyware:Spyware/SurfSideKick C:\WINDOWS\SYSTEM32\Cache\SSK_B5 Ventura Marketing 3.EXE
Virus:Trj/Downloader.BYZ C:\WINDOWS\SYSTEM32\Cache\stubinstaller5592.exe
Spyware:Spyware/BetterInet C:\WINDOWS\SYSTEM32\Cache\thin-8-3-x-x.exe
Adware:Adware/ILookup C:\WINDOWS\SYSTEM32\Cache\trafficgeneration-fran.exeAdware:Adware/ILookup C:\WINDOWS\SYSTEM32\Cache\trgen-fran-default.exeAdware:Adware/ILookup C:\WINDOWS\SYSTEM32\Cache\trgen_fran-162813.exeAdware:Adware/Ucmore C:\WINDOWS\SYSTEM32\Cache\ucmoreiex.exeAdware:Adware/QoolAid C:\WINDOWS\SYSTEM32\Cache\VCM QOOL_3.exeVirus:Trj/Multidropper.XI C:\WINDOWS\SYSTEM32\Cache\VCM2 Qinstaller 282_190.exeVirus:Trj/Downloader.BJI C:\WINDOWS\SYSTEM32\Cache\VCMnet7 updated 030905.exeAdware:Adware/Apropos C:\WINDOWS\SYSTEM32\fmihu.exeAdware:Adware/Apropos C:\WINDOWS\SYSTEM32\gpunw.exeAdware:Adware/Hotoffers C:\WINDOWS\SYSTEM32\guninst.exeVirus:W32/Spybot.QV.worm C:\WINDOWS\SYSTEM32\irarik.exeAdware:Adware/Apropos C:\WINDOWS\SYSTEM32\mipman32.exeSpyware:Spyware/SafeSurf C:\WINDOWS\SYSTEM32\netsync.exeAdware:Adware/Beginto C:\WINDOWS\SYSTEM32\nsa2A16.dllAdware:Adware/Beginto C:\WINDOWS\SYSTEM32\nsy2495.dllAdware:Adware/Hotoffers C:\WINDOWS\SYSTEM32\param32.dllAdware:Adware/ILookup C:\WINDOWS\SYSTEM32\rtneg.dllAdware:Adware/Beginto C:\WINDOWS\SYSTEM32\rtneg2.dllVirus:Trj/Clicker.CY C:\WINDOWS\SYSTEM32\winup2date.dllAdware:Adware/IGuard C:\WINDOWS\SYSTEM32\wldr.dllVirus:Trj/Clicker.CX C:\WINDOWS\SYSTEM32\wmconfig.cplVirus:W32/Spybot.QV.worm C:\WINDOWS\SYSTEM32\wqgqw.datAdware:Adware/AdLogix C:\WINDOWS\SYSTEM32\xscjl.dllVirus:Trj/Clicker.CZ C:\WINDOWS\unadbeh.exeReply bobmartino
40 Posts
276
0
Posted April 21st, 2005 11:00
Hmmm, the panda log should look like this
Adware:Adware/nCase No disinfected C:\WINDOWS\system32\Cache\pop.exe
Anyway, lets try get rid of some stuff
Goto Control Panel -> add/remove programs and remove these if they are there
cxtpls
Go to Start->Run and type in regedit and hit OK. Go to File->Export and save the registry somewhere as a backup. While in the Registry Editor, navigate to, some may not exist:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and delete the entry on the right called "WindowsFY"
HKEY_CLASSES_ROOT\CLSID\ and delete the subkey on the left "{145E6FB1-1256-44ed-A336-8BBA43373BE6}"
HKEY_CURRENT_USER\Software\Micorsoft\Windows\CurrentVersion\Policies\Explorer and delete the entry on the right called "NoActiveDesktopChanges"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System and delete the entry on the right called "NoDispBackgroundPage" AND "NoDispAppearancePage"
If any of the above registry keys are giving you problems deleting, right click on them and click on Permissions. Then click on the Advanced button. Make sure the first box (Inherit from parent...) is checked. Click OK and OK. Then try deleting the entry again. Once you're done, close the Registry Editor.
There is too many files to go after at one go, and I also don't know what panda disenfected, so we will take a few runs at it.
Download KillBox http://www.greyknight17.com/spy/KillBox.exe. Run KillBox and check the box that says 'End Explorer Shell While Killing File'. Next click on 'Delete on Reboot'. For each of the following files below, check the box that says 'Unregister .dll Before Deleting' if it's not grayed out. Copy and paste each of the following into KillBox (hitting the X button for each file - choose NO when it asks if you want to reboot):
C:\wp.bmp
c:\windows\system32\setup66.exe
c:\windows\system32\cache\876003.exe
c:\windows\system32\cache\setup66.exe
c:\windows\system32\cache\pop.exe
c:\windows\system32\cache\setupwrapper.exe
C:\WINDOWS\System32\Cache\mswinstall.exe
C:\WINDOWS\System32\wldr.dll
C:\WINDOWS\System32\param32.dll
C:\Program Files\Common Files\Totem Shared
C:\WINDOWS\a95kfrhe.exe
C:\Program Files\cxtpls
C:\WINDOWS\deskbar.ini
C:\Documents and Settings\Stephen\Application Data\osoa.exe
C:\Documents and Settings\Stephen\Application Data\That mp3 five\comp cdrom mags rdr.exe
C:\Documents and Settings\Stephen\Application Data\That mp3 five\Date Info Once.exe
C:\Documents and Settings\Stephen\Application Data\That mp3 five\llhakhtp.exe
C:\Documents and Settings\Stephen\Application Data\That mp3 five\
C:\Documents and Settings\Stephen\Local Settings\Temp\tp7543.exe
C:\Program Files\oft8m045\3p07f56f.DLL
C:\Program Files\oft8m045\7s442bhq.DLL
C:\Program Files\oft8m045\87672918.exe
C:\Program Files\oft8m045\dpcq38eb.DLL
C:\Program Files\oft8m045\
C:\temporary\aun_0018.exe
C:\temporary\aun_0029.exe
C:\WINDOWS\70tovmto.exe
C:\WINDOWS\ms05595670-10022005.exe
C:\WINDOWS\ms075670-1002592005.exe
C:\WINDOWS\SysCheckBop32.exe
C:\WINDOWS\SYSTEM32\2b3fsk0h.dll
C:\WINDOWS\SYSTEM32\a95kfrhe.ini
C:\WINDOWS\SYSTEM32\Cache\HelperInstall.exe
C:\WINDOWS\SYSTEM32\Cache\HLInstaller.exe
C:\WINDOWS\SYSTEM32\Cache\installer_282r2_189.exe
C:\WINDOWS\SYSTEM32\Cache\installer_MARKETING17.exe
C:\WINDOWS\SYSTEM32\Cache\Kyongju.exe
C:\WINDOWS\SYSTEM32\Cache\pop.exe
C:\WINDOWS\SYSTEM32\Cache\Pop1.exe
Restart.
You should hopefully now be able to change your desktop back to normal by usual methods
Right click on desktop
Select Properties
In the Desktop tab, set the following properties:
Background
Position
Color
Click OK
Run a new panda scan and post up the results, we shall try go after the rest of these files.
Reply

bobmartino
40 Posts
502
0
Posted April 18th, 2005 13:00
There is just to much here to start with a complete fix. Lets try get rid of some stuff first.
Download and run these tools
Please download Ad-aware SE and install it if you don't have it already. Make sure it's the newest version and check for any updates before running it. Also go here to get the plug-in for fixing VX2 variants. To run this tool, go into Ad-aware->Add-ons and select VX2 Cleaner. Then click Run Tool and OK to start it. If it's clean, it will say Status System Clean. Otherwise, you will have to click on the Clean button to remove the VX2 infection. Also make sure to customize the settings in Ad-aware for better scan results. Run the scan and fix everything that it finds.
Please download Spybot S&D and install it if you don't have it already. Run Spybot and click on the 'Search for Updates' button. Install any updates that are available. Next click on the 'Check for Problems' button. Let it run the scan. If it finds something, check all those in RED and hit the Fix Selected Problems button. Exit Spybot. If you keep getting the DSO Exploit entries, even after you updated Windows and fixed them, then download the Spybot DSO Exploit Fix and install it over the current Spybot installation.
Download CWShredder and click on 'Fix' (it will automatically fix anything it finds for you). If it asks if you want to delete a certain random file, choose No and post that filename here.
The Temp folders should be cleaned out periodically as installation programs and hijack programs leave a lot of junk there. Download CleanUp! ( Alternate Link if main link don't work) and install it. Run CleanUp! and click on CleanUp! button. When it asks you if you want to logoff, click on Yes.
If you have a fast internet connection (broadband), run an online scan at Trend Micro and RAV Antivirus.
Please select the autoclean option when using Trend Micro.
Then run a new scan and post up the log, please try not to double space it as it makes it alot harder to read.