Unsolved

This post is more than 5 years old

54 Posts

1572

March 14th, 2004 03:00

58 file ~ HijackThis log #2

I have done exactly as you said and now I am posting my copied HijackThis log for you. I did want to tell you that I used the removal tool for the GHOSTS-1 file, rebooting then running it again, and both times it told me that trojan Ghosts has not been found on my computer.

My screen saver did start working again though! We have definately done something to improve my computer! Thank You one million times over!!!!

Here you go:
Logfile of HijackThis v1.97.7
Scan saved at 10:42:43 PM, on 3/13/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.iwon.com/
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.iwon.com"); (C:\Program Files\Netscape\Users\User1\prefs.js)
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1078621097375
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37870.6513310185
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

54 Posts

March 14th, 2004 04:00

I should add that when I ran AVG again after this was all said and done it still showed that I had one virus still on my computer that it could not remove. It said it was called, Downloader. Turnown .A

2 Intern

 • 

3.9K Posts

March 14th, 2004 11:00

Continued from this thread :-

http://forums.us.dell.com/supportforums/board/message?board.id=si_virus&message.id=6612

Please add any future replies to here as a reply, not start a new message.
------------------------------------
Check these in hijackthis, AND WITH ALL OTHER WINDOWS CLOSED, fix checked.

O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab

Then Reboot and post a fresh log for me to check.

That should leave you clear of infection, please let me know of any problems.

You may need to remove any system restore point and restart system restore, to stop your AV conplaining about things in that.
Instructions on Bay Wolfs site http://www.bay-wolf.com/dk.htm#4a
Turn it off, reboot and turn it back on. Then rescan with your Anti-virus program.


 

54 Posts

March 14th, 2004 15:00

Here you go, I have not checked with the AV just yet, but I will let you know if the pesky thing is still showing up there. Thank you for all your help! What do you suggest for a firewall? We have only one computer but do have DSL. By the way, this is just a side note, I had a gateway for 5 years and just got my dell last year, I Love it!

Logfile of HijackThis v1.97.7
Scan saved at 10:15:29 AM, on 3/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.iwon.com/
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.iwon.com"); (C:\Program Files\Netscape\Users\User1\prefs.js)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1078621097375
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37870.6513310185
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

54 Posts

March 14th, 2004 15:00

I had already turned of the System Restore before beginning the HijackThis process but I went ahead and turned it on, reboot, turned it off, reboot, turned it back on, ran my AV and it still found the download trojan. It finds it in the first 2 seconds of searching. Do you think the backup files created by the HijackThis could be causing it? Should I remove the backup files, and if yes, how? {I already tried to remove the oldest ones and they just copy themselves.}

54 Posts

March 14th, 2004 19:00

It is finding it here: c:/Documents and settings/ragland/LocalSettings/temp/ckzd06955/files/td.exe

The AV is calling it: Downloader. Turown.A

2 Intern

 • 

3.9K Posts

March 14th, 2004 19:00

Then in safe mode, windows explorer, and delete the contents of the folder (not the folder itself)

c:/Documents and settings/ragland/LocalSettings/temp/

You may need to set folder properties do that you can see hidden and system files/folder and you should then be able to delete it.

2 Intern

 • 

3.9K Posts

March 14th, 2004 19:00

That log is showing clean, where is the virus being found, if in your email folders, delete the items in your deleted folder, if in the recycle bin, empty it, if in the temp internet files area, IE, tool, internet options, and delete all off line content, and all history.

Let me know if that solves it or where the AV is finding the virus.

54 Posts

March 14th, 2004 21:00

I can do that. Can you tell me how to change the properties of the folder and how to use safe mode? I really have become a pain haven't I?

2 Intern

 • 

3.9K Posts

March 15th, 2004 12:00

No you are not a pain, those that I find a pain are those who don't know and don't ask. Always ask if you don't know or understand.

Use windows explorer, find the file in question, right click, properties. It should have tick boxes to change the attributes, such as hidden etc.

54 Posts

March 15th, 2004 21:00

I have some more information for you. First of all, I have not managed to do any of what you said yet. I am not sure how to get into safe mode, I do have a book but it tells me how to do it with Windows 98. Is it the same process? Next, I tryed to change the properties, or at least look into changing them. While I was exploring C drive (right clicked my computer, picked explore) got to c:\Documents and Settings/Ragland... I right clicked on Ragland (in the left portion of the window) and the file number when from apx. 400 to over 19,000 in just over a few seconds.

I also made a mistake as to where the virus was found. It was in C:\ SETUP_TD.EXE: Files\td.exe

There also is ALWAYS a Purity Scan thing that shows up after I delete it when I am looking through files. It is a black "P" symble with a yellow halo over the "P". Do know what that is? I think it is bad.

2 Intern

 • 

3.9K Posts

March 15th, 2004 22:00

Can you post another hijackthis log for me, just in case you have been re infected.

54 Posts

March 16th, 2004 00:00

Here is the new HijackThis log. I also wanted to tell you that the folder that has the HijackThis program has 2507 files in it. Some are as high as copy 32. What is with that? Should I remove them? Should I delete the folder and re-download the HijackThis program?

Logfile of HijackThis v1.97.7
Scan saved at 7:29:05 PM, on 3/15/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.iwon.com/
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.iwon.com"); (C:\Program Files\Netscape\Users\User1\prefs.js)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\RunOnce: [SpyBotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1078621097375
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37870.6513310185
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

2 Intern

 • 

3.9K Posts

March 16th, 2004 11:00

Well it has not reinfected you.

You need to start your computer in safe mode - press the F8 key while the machine starts up from cold.

Then in windows explorer find and delete this whole folder

C:\ SETUP_TD.EXE: Files\

Empty the recycle bin as well, after the delete.

Then reboot your machine.

If the delete has worked, the scan by AVg will be clean, and you can delete the hijackthis folder.
------------------------
Here is some advise for the future.
------------------------
How on earth did I get infected with all that spyware in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051
Also available from here :- http://www.computercops.biz/postlite7736-.html or http://boards.cexx.org/viewtopic.php?t=957
--------------
Look at the info on my website regarding malware (Link below). Some things you can do to stop getting infected again:-

Spybot s&d, Ad-aware Run weekly - or after a heavy internet session.

Spywareblaster & Spywareguard, first sets kill bits to stop known bad activeX controls installing, second acts like your AV to stop browser hijacks and installing of known badies.

Also ie-spyad, puts 4000 bad sites in your restricted (banned) sites list, to stop you accidentaly getting sent to a bad site, it has optional list of "bad" adult sites to install as well.

All those with links from my site. Do remember just like AV they need to be updated regularly, I do mine weekly, AV daily.

With these and a firewall in place I have to try various bad sites when checking peoples hijackthis logs looking to sort bad from good, and I have not yet been infected. Still time for it to happen LOL.

 

54 Posts

March 16th, 2004 12:00

Wooo Hoooo! I think we killed that little bug! Thank you so much! I am going to use your advice, I am also not going to let neighborhood kids use the internet on my computer anymore! 5 years no problem, one kid, Bam!

There is a good side to this though, I found this wonderful site offered by dell and I again learned a little more about my computer. I love that.

Why do you thing that when I right clicked to get to the properties of "Ragland" yesterday the file count went up so much and so fast?

2 Intern

 • 

3.9K Posts

March 16th, 2004 13:00

To be honest, I have no idea.

When fixing others computers like this you have to rely on the observations of the user and then understanding third hand what they saw. All sorts of things get in the way of that understanding, even little things like the difference in launguage between us. I assume you are in the US, well I am in the UK. I often gave the instruction to users to 'tick' those items to fix. and I now understand the the word 'tick' is more better understood as 'check' in the US.

Regards (and thanks for being a good user to work with).

No Events found!

Top