Unsolved

This post is more than 5 years old

11 Posts

1022

March 29th, 2006 03:00

Another Amaena/Blackworm infection

Having the Ameana/blackworm issue on my pc. I ran Vundo but it didn't find anything. Also made sure my java was up-to-date.
 
Logfile of HijackThis v1.99.1
Scan saved at 11:35:22 PM, on 3/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,ihmuqhs.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - blank (file missing)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - blank (file missing)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://usercenter.cox.net/rsuite/sdccommon/asp/cx_tgctlcm.jsp
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/286be158a22555397405/netzip/RdxIE601.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096224395421
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O20 - AppInit_DLLs: repairs303169563.dll
O20 - Winlogon Notify: MS-DOS Emulation - C:\WINDOWS\system32\ktp4l77q1.dll
O20 - Winlogon Notify: pptp32 - C:\WINDOWS\SYSTEM32\pptp32.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing)
 
 
Vundo

VundoFix V4.2.42
Checking Java version...
Java version is 1.5.0.6
Scan started at 1:17:47 PM 3/28/2006
Listing files found while scanning....

No infected files were found.
 
 

1.2K Posts

March 29th, 2006 11:00

Hello oingo and Welcome to Dell,

Yes, I can see problems in the hijackthis log. Let's try a few scans first.



STEP 1.
======
SpySweeper

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless you are instructed to.


Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!

When the sweep has finished, click Remove. Click Select All and then Next

From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.

Exit Spy Sweeper.


STEP 2.
======
Ewido Trojan Scanner
Please download, install, and update the NEW free version of Ewido trojan scanner:

  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".

  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.

  • From the main ewido screen, click on update in the left menu, then click the Start update button.

  • After the update finishes (the status bar at the bottom will display "Update successful")

  • Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.

  • If ewido finds anything, it will pop up a notification. Select "clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.

  • When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.


Empty Recycle Bin

Reboot

Please post the results from SpySweeper, ewido and a new hijackthis log.

11 Posts

March 30th, 2006 03:00

That seemed to work. No more stupid popups asking me to give them money to stop more stupid popups. Really appreciate the help.

1.2K Posts

March 30th, 2006 08:00

Hello oingo,

Glad things have improved but I really wish that you would post the logs I requested. I want to make sure that everything looks ok.

Susan

11 Posts

April 4th, 2006 22:00

Sorry about the delay. Here are the logs.
 
---------------------------------------------------------
 ewido anti-malware - Scan report
---------------------------------------------------------
 + Created on:   12:04:23 AM, 4/1/2006
 + Report-Checksum:  6A4DBD3C
 + Scan result:
 [1788] C:\WINDOWS\system32\ljor813.dll -> Adware.Look2Me : Error during cleaning
 [304] C:\WINDOWS\system32\ljor813.dll -> Adware.Look2Me : Error during cleaning
 C:\WINDOWS\SYSTEM32\uerv42a.dll -> Adware.Look2Me : Cleaned with backup
 C:\WINDOWS\SYSTEM32\pptp32.dll -> Backdoor.Haxdoor.gh : Cleaned with backup
 C:\WINDOWS\SYSTEM32\qz.dll -> Backdoor.Haxdoor.gh : Cleaned with backup
 C:\WINDOWS\SYSTEM32\pptp64.sys -> Backdoor.Haxdoor.ho : Cleaned with backup
 C:\WINDOWS\SYSTEM32\qz.sys -> Backdoor.Haxdoor.ho : Cleaned with backup
 C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\6DGR07GH\l[1].exe -> Downloader.Small.dso : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@ads1.revenue[2].txt -> TrackingCookie.Revenue : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@as1.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@linksynergy[1].txt -> TrackingCookie.Linksynergy : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@c5.zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@anat.tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@as-eu.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@revenue[2].txt -> TrackingCookie.Revenue : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
 C:\WINDOWS\TEMP\Cookies\shane@reduxads.valuead[2].txt -> TrackingCookie.Valuead : Cleaned with backup
 C:\FOUND.007\FILE0069.CHK -> Adware.SurfSide : Cleaned with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@as-eu.falkag[1].txt -> TrackingCookie.Falkag :
Cleaned with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@trafficmp[1].txt -> TrackingCookie.Trafficmp :
Cleaned with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@casalemedia[2].txt -> TrackingCookie.Casalemedia :
Cleaned with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with
backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@fastclick[2].txt -> TrackingCookie.Fastclick :
Cleaned with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@stats1.reliablestats[1].txt ->
TrackingCookie.Reliablestats : Cleaned with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@questionmarket[2].txt ->
TrackingCookie.Questionmarket : Cleaned with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@as-us.falkag[1].txt -> TrackingCookie.Falkag :
Cleaned with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@yieldmanager[1].txt -> TrackingCookie.Yieldmanager
: Cleaned with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@serving-sys[2].txt -> TrackingCookie.Serving-sys :
Cleaned with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@citi.bridgetrack[1].txt ->
TrackingCookie.Bridgetrack : Cleaned with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@z1.adserver[1].txt -> TrackingCookie.Adserver :
Cleaned with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned
with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@statcounter[1].txt -> TrackingCookie.Statcounter :
Cleaned with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@ad.yieldmanager[1].txt ->
TrackingCookie.Yieldmanager : Cleaned with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned
with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@bluestreak[1].txt -> TrackingCookie.Bluestreak :
Cleaned with backup
 C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@ads.pointroll[2].txt -> TrackingCookie.Pointroll :
Cleaned with backup
 C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP433\A0074650.dll -> Adware.Look2Me :
Cleaned with backup
 C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP433\A0074651.dll -> Adware.Look2Me :
Cleaned with backup
 C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP433\A0074662.dll -> Adware.Look2Me :
Cleaned with backup
 C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP433\A0074670.dll -> Adware.Look2Me :
Cleaned with backup
 C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP433\A0074674.dll -> Adware.Look2Me :
Cleaned with backup
 C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP433\A0074680.dll -> Adware.Look2Me :
Cleaned with backup
 C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP434\A0074688.dll -> Adware.Look2Me :
Cleaned with backup
 C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP434\A0074690.dll -> Adware.Look2Me :
Cleaned with backup
 C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP434\A0074695.dll -> Adware.Look2Me :
Cleaned with backup
 C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP434\A0074700.dll -> Adware.Look2Me :
Cleaned with backup
 C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP436\A0074736.dll -> Adware.Look2Me :
Cleaned with backup
 C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP436\A0074741.dll -> Adware.Look2Me :
Cleaned with backup
 C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP437\A0074748.dll -> Adware.Look2Me :
Cleaned with backup
 C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP437\A0074753.dll -> Adware.Look2Me :
Cleaned with backup

::Report End

11 Posts

April 4th, 2006 22:00

Have tried to post the sweeper log but it is too big. Even tried to cut it into 4 pieces and it was too long.
 
Logfile of HijackThis v1.99.1
Scan saved at 6:30:17 PM, on 4/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,ihmuqhs.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} -
%windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
http://usercenter.cox.net/rsuite/sdccommon/asp/cx_tgctlcm.jsp
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/286be158a22555397405/netzip/RdxIE601.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096224395421
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O20 - Winlogon Notify: drivers.desc - C:\WINDOWS\system32\gp88l3lu1.dll
O20 - Winlogon Notify: MS-DOS Emulation - C:\WINDOWS\
O20 - Winlogon Notify: Reinstall - C:\WINDOWS\
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy
Sweeper\WRSSSDK.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe"
"WMP54Gv4.exe (file missing)
 

1.2K Posts

April 5th, 2006 21:00

Please set your system to show all files; please see here if you're unsure how to do this.

STEP 1.
======
Submit File to Jotti
Please click on Jotti
Use the " Browse" button and locate the following file on your computer:
C:\WINDOWS\system32\userinit.exe
Click the " Submit" button.
Please copy and post (reply) with the results

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html

Please also check the properties of those files (right-click and select properties from the popupmenu). Look if you can find some company information, etc.

Do a search for the files ihmuqhs.exe to find where it is located so you can browse to it.

Please click on Jotti
Use the " Browse" button and locate the following file on your computer:
ihmuqhs.exe
Click the " Submit" button.
Please copy and post (reply) with the results

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html

Please also check the properties of those files (right-click and select properties from the popupmenu). Look if you can find some company information, etc.

Now run this online scan using Internet Explorer:
Kaspersky WebScanner from http://www.kaspersky.com/virusscanner

Next Click on Launch Kaspersky Anti-Virus Web Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.

  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
  • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.

Copy and paste that information from Kapersky along with the Jotti information in your next post.

11 Posts

April 5th, 2006 23:00

Service load:0%  100%File:userinit.exeStatus:
OK (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD539b1ffb03c2296323832acbae50d2affPackers detected:
-
Scanner results
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
UNA
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing

11 Posts

April 5th, 2006 23:00

ihmuqhs.exe is not on my pc anywhere.

1.2K Posts

April 5th, 2006 23:00

Hello oingo,

Please do the following:

Disable SpySweeper:
You have SpySweeper installed. While this is a great program, we need to temporarily disable (not uninstall) the program because it might stop our fix.
  • Open it click >Options over to the left then >program options>Uncheck "load at windows startup"
  • Over to the left click "shields" and uncheck all there.
  • Uncheck" home page shield".
  • Uncheck ''automatically restore default without notification".

After all of the fixes are complete it is very important that you enable SpySweeper again.

Please download and run CWShredder
Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX.

Please set your system to show all files; please see here if you're unsure how to do this.

Scan with hijackthis and check the following:.
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,ihmuqhs.exe
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/286be158a22555397405/netzip/RdxIE601.cab
O20 - Winlogon Notify: drivers.desc - C:\WINDOWS\system32\gp88l3lu1.dll
O20 - Winlogon Notify: MS-DOS Emulation - C:\WINDOWS\
O20 - Winlogon Notify: Reinstall - C:\WINDOWS\

After you check these items, close all browsers and windows, except for HijackThis, then click on the Fix Checked button on HijackThis.


Reboot into Safe Mode: please see here if you are not sure how to do this.

Using Windows Explorer, locate the following files/folders, and delete them:
C:\WINDOWS\system32\gp88l3lu1.dll<==file
Exit Explorer, and reboot as normal afterwards.

Post back a fresh HijackThis log and we will take another look.

Please run Kapersky as requested above and post the results.

Message Edited by ALgal on 04-05-2006 08:00 PM

11 Posts

April 6th, 2006 12:00

Interrupted it when it got to my network drives but here is the log:

-------------------------------------------------------------------------------
 KASPERSKY ON-LINE SCANNER REPORT
 Thursday, April 06, 2006 7:57:35 AM
 Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
 Kaspersky On-line Scanner version: 5.0.78.0
 Kaspersky Anti-Virus database last update:  6/04/2006
 Kaspersky Anti-Virus database records: 175182
-------------------------------------------------------------------------------

Scan Settings:
 Scan using the following antivirus database: standard
 Scan Archives: true
 Scan Mail Bases: true

Scan Target - My Computer:
 A:\
 C:\
 D:\
 E:\
 F:\
 G:\
 H:\
 I:\

Scan Statistics:
 Total number of scanned objects: 327545
 Number of viruses found: 7
 Number of infected objects: 34
 Number of suspicious objects: 0
 Duration of the scan process: 12:22:24

Infected Object Name / Virus Name / Last Action
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\6DGR07GH\62.193.224[1].htm Infected: Exploit.JS.CVE-2006-1359.b skipped
C:\WINDOWS\YazzleBundle-1119.exe/data0002 Infected: Trojan.Win32.Scapur.k skipped
C:\WINDOWS\YazzleBundle-1119.exe NSIS: infected - 1 skipped
C:\RECYCLED\Dc8.007\FILE0087.CHK/data0002 Infected: Trojan.Win32.Scapur.k skipped
C:\RECYCLED\Dc8.007\FILE0087.CHK NSIS: infected - 1 skipped
C:\RECYCLED\Dc8.007\FILE0102.CHK Infected: Trojan.Win32.Scapur.k skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/Counter.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/Beyond.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/Worker.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/web.exe Infected: Trojan-Downloader.Win32.Delf.ags skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896 ZIP: infected - 5 skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896 CryptFF.b: infected - 5 skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\drsmartload[1].exe.bac_a02896 Infected: Trojan-Downloader.Win32.VB.zg skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\drsmartload1.exe.bac_a02896 Infected: Trojan-Downloader.Win32.VB.zg skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 04:20:47 +0100]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 04:20:47 +0100]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 06:58:57 +0200]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 06:58:57 +0200]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 04:29:49 -0600]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 04:29:49 -0600]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 13:57:31 +0100]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 13:57:31 +0100]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 17:15:44 +0200]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 17:15:44 +0200]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 09:15:21 -0700]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 09:15:21 -0700]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 22:22:06 +0600]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 22:22:06 +0600]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 22:14:28 -0300]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 22:14:28 -0300]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 21:32:43 -0500]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 21:32:43 -0500]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT Mail: infected - 18 skipped

Scan was interrupted by user!

(Left it running over night and it still hadn't finished but had gone through all my local drives. But that is the reason for the late post)

Message Edited by oingo on 04-06-2006 08:03 AM

1.2K Posts

April 6th, 2006 13:00

Hello oingo,

Yes, those scans do take awhile. But you can see that Kapersky found some things that ewido did not. That is why I like to request two different scans.

You can use the following to delete temporary files.

Please download ATF Cleaner by Atribune.

This program is for XP and Windows 2000 only

  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

If you use Firefox browser

  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.

If you use Opera browser

  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Show Hidden Files
Please show all files for your system.
You will need to reverse this process when all steps are done.


Please delete the following files!

This one is Temporary Internet File but go ahead and try to locate it just to make sure it has been deleted.
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\6DGR07GH\62.193.2241>.htm

C:\WINDOWS\YazzleBundle-1119.exe/data0002
C:\WINDOWS\YazzleBundle-1119.exe

E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 04:20:47 +0100]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 04:20:47 +0100]/UNNAMED
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 06:58:57 +0200]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 06:58:57 +0200]/UNNAMED
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 04:29:49 -0600]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 04:29:49 -0600]/UNNAMED
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 13:57:31 +0100]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 13:57:31 +0100]/UNNAMED
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 17:15:44 +0200]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 17:15:44 +0200]/UNNAMED
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 09:15:21 -0700]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 09:15:21 -0700]/UNNAMED
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 22:22:06 +0600]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 22:22:06 +0600]/UNNAMED
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 22:14:28 -0300]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 22:14:28 -0300]/UNNAMED
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 21:32:43 -0500]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 21:32:43 -0500]/UNNAMED
E:\Entertain\Agent\00000001.DAT Mail: infected - 18 skipped

Empty your Recycle bin.
Reboot.

I would run another Kapersky scan to see if files got deleted. Also please post another hijackthis log.

11 Posts

April 7th, 2006 12:00

I think I still have something. When I turn spy sweeper off, the Amaena screens start coming back.
 
-------------------------------------------------------------------------------
 KASPERSKY ON-LINE SCANNER REPORT
 Friday, April 07, 2006 8:00:28 AM
 Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
 Kaspersky On-line Scanner version: 5.0.78.0
 Kaspersky Anti-Virus database last update:  7/04/2006
 Kaspersky Anti-Virus database records: 175357
-------------------------------------------------------------------------------
Scan Settings:
 Scan using the following antivirus database: standard
 Scan Archives: true
 Scan Mail Bases: true
Scan Target - My Computer:
 A:\
 C:\
 D:\
 E:\
 F:\
 G:\
Scan Statistics:
 Total number of scanned objects: 307201
 Number of viruses found: 5
 Number of infected objects: 11
 Number of suspicious objects: 0
 Duration of the scan process: 01:49:12
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/Counter.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/Beyond.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/Worker.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/web.exe Infected: Trojan-Downloader.Win32.Delf.ags skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896 ZIP: infected - 5 skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896 CryptFF.b: infected - 5 skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\drsmartload[1].exe.bac_a02896 Infected: Trojan-Downloader.Win32.VB.zg skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\drsmartload1.exe.bac_a02896 Infected: Trojan-Downloader.Win32.VB.zg skipped
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP441\A0074993.exe/data0002 Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP441\A0074993.exe NSIS: infected - 1 skipped
Scan process completed.
Logfile of HijackThis v1.99.1
Scan saved at 8:03:05 AM, on 4/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://usercenter.cox.net/rsuite/sdccommon/asp/cx_tgctlcm.jsp
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096224395421
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O20 - Winlogon Notify: Welcome - C:\WINDOWS\system32\i4jqle151h.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing)
 

11 Posts

April 12th, 2006 22:00

Have you had a chance to review this one? With spysweeper's trial gone, I am getting popups again so I guess I still have something.

1.2K Posts

April 12th, 2006 23:00

Hello oingo,

Sorry about that! Please do the following:


STEP 1.
======
Look2Me-Destroyer
Please download Look2Me-Destroyer.exe to your desktop.


  • Close all windows before continuing.
  • Double-click Look2Me-Destroyer.exe to run it.
  • Put a check next to Run this program as a task .
  • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
  • When Look2Me-Destroyer re-opens, click the Scan for L2M button , your desktop icons will disappear, this is normal.
  • Once it's done scanning, click the Remove L2M button .
  • You will receive a Done Scanning message, click OK .
  • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK .
  • Your computer will then shutdown.
  • Turn your computer back on.
  • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.


If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339'. please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32. Directory
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX

11 Posts

April 13th, 2006 00:00


Look2Me-Destroyer V1.0.12
Scanning for infected files.....
Scan started at 4/12/2006 8:31:26 PM
Infected! C:\WINDOWS\system32\mv6ul9j91.dll
Infected! C:\WINDOWS\SYSTEM32\ibwphbk.dll
Infected! C:\WINDOWS\SYSTEM32\kydcz2.dll
Infected! C:\WINDOWS\SYSTEM32\hjd.dll
Infected! C:\WINDOWS\SYSTEM32\mkacm.dll
Infected! C:\WINDOWS\SYSTEM32\rbpdd.dll
Infected! C:\WINDOWS\SYSTEM32\cnlbact.dll
Infected! C:\WINDOWS\SYSTEM32\gcmf32.dll
Infected! C:\WINDOWS\SYSTEM32\mv6ul9j91.dll
Infected! C:\WINDOWS\SYSTEM32\q8nu0i59e8.dll
Infected! C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP446\A0075158.dll
Infected! C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP446\A0075163.dll
Infected! C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP445\A0075135.dll
Attempting to delete infected files...
Attempting to delete: C:\WINDOWS\system32\mv6ul9j91.dll
C:\WINDOWS\system32\mv6ul9j91.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\ibwphbk.dll
C:\WINDOWS\SYSTEM32\ibwphbk.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\kydcz2.dll
C:\WINDOWS\SYSTEM32\kydcz2.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\hjd.dll
C:\WINDOWS\SYSTEM32\hjd.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\mkacm.dll
C:\WINDOWS\SYSTEM32\mkacm.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\rbpdd.dll
C:\WINDOWS\SYSTEM32\rbpdd.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\cnlbact.dll
C:\WINDOWS\SYSTEM32\cnlbact.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\gcmf32.dll
C:\WINDOWS\SYSTEM32\gcmf32.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\mv6ul9j91.dll
C:\WINDOWS\SYSTEM32\mv6ul9j91.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\q8nu0i59e8.dll
C:\WINDOWS\SYSTEM32\q8nu0i59e8.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP446\A0075158.dll
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP446\A0075158.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP446\A0075163.dll
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP446\A0075163.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP445\A0075135.dll
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP445\A0075135.dll Deleted successfully!
Making registry repairs.
Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RunOnceEx
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{5555F535-623E-452F-BA6F-85679056A650}"
HKCR\Clsid\{5555F535-623E-452F-BA6F-85679056A650}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{AA5D0715-F61C-451F-9FDB-1A45C57CFAB1}"
HKCR\Clsid\{AA5D0715-F61C-451F-9FDB-1A45C57CFAB1}
Restoring Windows certificates.
Replaced hosts file with default windows hosts file

Restoring SeDebugPrivilege for Administrators - Succeeded
 
Logfile of HijackThis v1.99.1
Scan saved at 8:36:07 PM, on 4/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://usercenter.cox.net/rsuite/sdccommon/asp/cx_tgctlcm.jsp
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096224395421
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing)
 
No Events found!

Top