Unsolved
This post is more than 5 years old
11 Posts
0
1022
March 29th, 2006 03:00
Another Amaena/Blackworm infection
Having the Ameana/blackworm issue on my pc. I ran Vundo but it didn't find anything. Also made sure my java was up-to-date.
Logfile of HijackThis v1.99.1
Scan saved at 11:35:22 PM, on 3/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Scan saved at 11:35:22 PM, on 3/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,ihmuqhs.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - blank (file missing)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - blank (file missing)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://usercenter.cox.net/rsuite/sdccommon/asp/cx_tgctlcm.jsp
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/286be158a22555397405/netzip/RdxIE601.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096224395421
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O20 - AppInit_DLLs: repairs303169563.dll
O20 - Winlogon Notify: MS-DOS Emulation - C:\WINDOWS\system32\ktp4l77q1.dll
O20 - Winlogon Notify: pptp32 - C:\WINDOWS\SYSTEM32\pptp32.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,ihmuqhs.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - blank (file missing)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - blank (file missing)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://usercenter.cox.net/rsuite/sdccommon/asp/cx_tgctlcm.jsp
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/286be158a22555397405/netzip/RdxIE601.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096224395421
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O20 - AppInit_DLLs: repairs303169563.dll
O20 - Winlogon Notify: MS-DOS Emulation - C:\WINDOWS\system32\ktp4l77q1.dll
O20 - Winlogon Notify: pptp32 - C:\WINDOWS\SYSTEM32\pptp32.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing)
Vundo
VundoFix V4.2.42
Checking Java version...
Java version is 1.5.0.6
Scan started at 1:17:47 PM 3/28/2006
Listing files found while scanning....
No infected files were found.
No Events found!


ALgal
1.2K Posts
0
March 29th, 2006 11:00
Yes, I can see problems in the hijackthis log. Let's try a few scans first.
STEP 1.
======
SpySweeper
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.
Please do not delete anything unless you are instructed to.
Download the trial version of Spy Sweeper from Here
Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)
You will be prompted to check for updated definitions, please do so.
(This may take several minutes)
Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.
Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!
When the sweep has finished, click Remove. Click Select All and then Next
From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.
Exit Spy Sweeper.
STEP 2.
======
Ewido Trojan Scanner
Please download, install, and update the NEW free version of Ewido trojan scanner:
Empty Recycle Bin
Reboot
Please post the results from SpySweeper, ewido and a new hijackthis log.
oingo
11 Posts
0
March 30th, 2006 03:00
ALgal
1.2K Posts
0
March 30th, 2006 08:00
Glad things have improved but I really wish that you would post the logs I requested. I want to make sure that everything looks ok.
Susan
oingo
11 Posts
0
April 4th, 2006 22:00
ewido anti-malware - Scan report
---------------------------------------------------------
+ Report-Checksum: 6A4DBD3C
[304] C:\WINDOWS\system32\ljor813.dll -> Adware.Look2Me : Error during cleaning
C:\WINDOWS\SYSTEM32\uerv42a.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\SYSTEM32\pptp32.dll -> Backdoor.Haxdoor.gh : Cleaned with backup
C:\WINDOWS\SYSTEM32\qz.dll -> Backdoor.Haxdoor.gh : Cleaned with backup
C:\WINDOWS\SYSTEM32\pptp64.sys -> Backdoor.Haxdoor.ho : Cleaned with backup
C:\WINDOWS\SYSTEM32\qz.sys -> Backdoor.Haxdoor.ho : Cleaned with backup
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\6DGR07GH\l[1].exe -> Downloader.Small.dso : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@ads1.revenue[2].txt -> TrackingCookie.Revenue : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@as1.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@linksynergy[1].txt -> TrackingCookie.Linksynergy : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@c5.zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@anat.tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@as-eu.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@revenue[2].txt -> TrackingCookie.Revenue : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\shane@reduxads.valuead[2].txt -> TrackingCookie.Valuead : Cleaned with backup
C:\FOUND.007\FILE0069.CHK -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@as-eu.falkag[1].txt -> TrackingCookie.Falkag :
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@trafficmp[1].txt -> TrackingCookie.Trafficmp :
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@casalemedia[2].txt -> TrackingCookie.Casalemedia :
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@fastclick[2].txt -> TrackingCookie.Fastclick :
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@stats1.reliablestats[1].txt ->
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@questionmarket[2].txt ->
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@as-us.falkag[1].txt -> TrackingCookie.Falkag :
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@yieldmanager[1].txt -> TrackingCookie.Yieldmanager
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@serving-sys[2].txt -> TrackingCookie.Serving-sys :
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@citi.bridgetrack[1].txt ->
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@z1.adserver[1].txt -> TrackingCookie.Adserver :
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@statcounter[1].txt -> TrackingCookie.Statcounter :
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@ad.yieldmanager[1].txt ->
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@bluestreak[1].txt -> TrackingCookie.Bluestreak :
C:\Documents and Settings\Shane\Local Settings\Temp\Cookies\shane@ads.pointroll[2].txt -> TrackingCookie.Pointroll :
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP433\A0074650.dll -> Adware.Look2Me :
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP433\A0074651.dll -> Adware.Look2Me :
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP433\A0074662.dll -> Adware.Look2Me :
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP433\A0074670.dll -> Adware.Look2Me :
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP433\A0074674.dll -> Adware.Look2Me :
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP433\A0074680.dll -> Adware.Look2Me :
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP434\A0074688.dll -> Adware.Look2Me :
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP434\A0074690.dll -> Adware.Look2Me :
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP434\A0074695.dll -> Adware.Look2Me :
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP434\A0074700.dll -> Adware.Look2Me :
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP436\A0074736.dll -> Adware.Look2Me :
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP436\A0074741.dll -> Adware.Look2Me :
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP437\A0074748.dll -> Adware.Look2Me :
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP437\A0074753.dll -> Adware.Look2Me :
::Report End
oingo
11 Posts
0
April 4th, 2006 22:00
Scan saved at 6:30:17 PM, on 4/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,ihmuqhs.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} -
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/286be158a22555397405/netzip/RdxIE601.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O20 - Winlogon Notify: drivers.desc - C:\WINDOWS\system32\gp88l3lu1.dll
O20 - Winlogon Notify: MS-DOS Emulation - C:\WINDOWS\
O20 - Winlogon Notify: Reinstall - C:\WINDOWS\
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe"
ALgal
1.2K Posts
0
April 5th, 2006 21:00
STEP 1.
======
Submit File to Jotti
Please click on Jotti
Use the " Browse" button and locate the following file on your computer:
C:\WINDOWS\system32\userinit.exe
Click the " Submit" button.
Please copy and post (reply) with the results
If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html
Please also check the properties of those files (right-click and select properties from the popupmenu). Look if you can find some company information, etc.
Do a search for the files ihmuqhs.exe to find where it is located so you can browse to it.
Please click on Jotti
Use the " Browse" button and locate the following file on your computer:
ihmuqhs.exe
Click the " Submit" button.
Please copy and post (reply) with the results
If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html
Please also check the properties of those files (right-click and select properties from the popupmenu). Look if you can find some company information, etc.
Now run this online scan using Internet Explorer:
Kaspersky WebScanner from http://www.kaspersky.com/virusscanner
Next Click on Launch Kaspersky Anti-Virus Web Scanner
You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
Copy and paste that information from Kapersky along with the Jotti information in your next post.
oingo
11 Posts
0
April 5th, 2006 23:00
oingo
11 Posts
0
April 5th, 2006 23:00
ALgal
1.2K Posts
0
April 5th, 2006 23:00
Please do the following:
Disable SpySweeper:
You have SpySweeper installed. While this is a great program, we need to temporarily disable (not uninstall) the program because it might stop our fix.
After all of the fixes are complete it is very important that you enable SpySweeper again.
Please download and run CWShredder
Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX.
Please set your system to show all files; please see here if you're unsure how to do this.
Scan with hijackthis and check the following:.
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,ihmuqhs.exe
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/286be158a22555397405/netzip/RdxIE601.cab
O20 - Winlogon Notify: drivers.desc - C:\WINDOWS\system32\gp88l3lu1.dll
O20 - Winlogon Notify: MS-DOS Emulation - C:\WINDOWS\
O20 - Winlogon Notify: Reinstall - C:\WINDOWS\
After you check these items, close all browsers and windows, except for HijackThis, then click on the Fix Checked button on HijackThis.
Reboot into Safe Mode: please see here if you are not sure how to do this.
Using Windows Explorer, locate the following files/folders, and delete them:
C:\WINDOWS\system32\gp88l3lu1.dll<==file
Exit Explorer, and reboot as normal afterwards.
Post back a fresh HijackThis log and we will take another look.
Please run Kapersky as requested above and post the results.
Message Edited by ALgal on 04-05-2006 08:00 PM
oingo
11 Posts
0
April 6th, 2006 12:00
Interrupted it when it got to my network drives but here is the log:
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Thursday, April 06, 2006 7:57:35 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.78.0
Kaspersky Anti-Virus database last update: 6/04/2006
Kaspersky Anti-Virus database records: 175182
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 327545
Number of viruses found: 7
Number of infected objects: 34
Number of suspicious objects: 0
Duration of the scan process: 12:22:24
Infected Object Name / Virus Name / Last Action
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\6DGR07GH\62.193.224[1].htm Infected: Exploit.JS.CVE-2006-1359.b skipped
C:\WINDOWS\YazzleBundle-1119.exe/data0002 Infected: Trojan.Win32.Scapur.k skipped
C:\WINDOWS\YazzleBundle-1119.exe NSIS: infected - 1 skipped
C:\RECYCLED\Dc8.007\FILE0087.CHK/data0002 Infected: Trojan.Win32.Scapur.k skipped
C:\RECYCLED\Dc8.007\FILE0087.CHK NSIS: infected - 1 skipped
C:\RECYCLED\Dc8.007\FILE0102.CHK Infected: Trojan.Win32.Scapur.k skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/Counter.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/Beyond.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/Worker.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/web.exe Infected: Trojan-Downloader.Win32.Delf.ags skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896 ZIP: infected - 5 skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896 CryptFF.b: infected - 5 skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\drsmartload[1].exe.bac_a02896 Infected: Trojan-Downloader.Win32.VB.zg skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\drsmartload1.exe.bac_a02896 Infected: Trojan-Downloader.Win32.VB.zg skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 04:20:47 +0100]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 04:20:47 +0100]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 06:58:57 +0200]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 06:58:57 +0200]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 04:29:49 -0600]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 04:29:49 -0600]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 13:57:31 +0100]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 13:57:31 +0100]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 17:15:44 +0200]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 17:15:44 +0200]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 09:15:21 -0700]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 09:15:21 -0700]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 22:22:06 +0600]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 22:22:06 +0600]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 22:14:28 -0300]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 22:14:28 -0300]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 21:32:43 -0500]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" <support@charterone.com>][Date Sun, 24 Apr 2005 21:32:43 -0500]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.dh skipped
E:\Entertain\Agent\00000001.DAT Mail: infected - 18 skipped
Scan was interrupted by user!
Message Edited by oingo on 04-06-2006 08:03 AM
ALgal
1.2K Posts
0
April 6th, 2006 13:00
Yes, those scans do take awhile. But you can see that Kapersky found some things that ewido did not. That is why I like to request two different scans.
You can use the following to delete temporary files.
Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only
If you use Firefox browser
If you use Opera browser
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.
Show Hidden Files
Please show all files for your system.
You will need to reverse this process when all steps are done.
Please delete the following files!
This one is Temporary Internet File but go ahead and try to locate it just to make sure it has been deleted.
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\6DGR07GH\62.193.2241>.htm
C:\WINDOWS\YazzleBundle-1119.exe/data0002
C:\WINDOWS\YazzleBundle-1119.exe
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 04:20:47 +0100]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 04:20:47 +0100]/UNNAMED
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 06:58:57 +0200]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 06:58:57 +0200]/UNNAMED
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 04:29:49 -0600]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 04:29:49 -0600]/UNNAMED
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 13:57:31 +0100]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 13:57:31 +0100]/UNNAMED
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 17:15:44 +0200]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 17:15:44 +0200]/UNNAMED
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 09:15:21 -0700]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 09:15:21 -0700]/UNNAMED
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 22:22:06 +0600]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 22:22:06 +0600]/UNNAMED
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 22:14:28 -0300]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 22:14:28 -0300]/UNNAMED
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 21:32:43 -0500]/UNNAMED/html
E:\Entertain\Agent\00000001.DAT/[From "Charter One Bank" ][Date Sun, 24 Apr 2005 21:32:43 -0500]/UNNAMED
E:\Entertain\Agent\00000001.DAT Mail: infected - 18 skipped
Empty your Recycle bin.
Reboot.
I would run another Kapersky scan to see if files got deleted. Also please post another hijackthis log.
oingo
11 Posts
0
April 7th, 2006 12:00
KASPERSKY ON-LINE SCANNER REPORT
Friday, April 07, 2006 8:00:28 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.78.0
Kaspersky Anti-Virus database last update: 7/04/2006
Kaspersky Anti-Virus database records: 175357
-------------------------------------------------------------------------------
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
A:\
C:\
D:\
E:\
F:\
G:\
Total number of scanned objects: 307201
Number of viruses found: 5
Number of infected objects: 11
Number of suspicious objects: 0
Duration of the scan process: 01:49:12
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/Counter.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/Beyond.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/Worker.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896/web.exe Infected: Trojan-Downloader.Win32.Delf.ags skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896 ZIP: infected - 5 skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\arc.zip-68f7ffc7-31128c6d.zip.bac_a02896 CryptFF.b: infected - 5 skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\drsmartload[1].exe.bac_a02896 Infected: Trojan-Downloader.Win32.VB.zg skipped
C:\Documents and Settings\Shane\.housecall\Quarantine\drsmartload1.exe.bac_a02896 Infected: Trojan-Downloader.Win32.VB.zg skipped
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP441\A0074993.exe/data0002 Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP441\A0074993.exe NSIS: infected - 1 skipped
Scan saved at 8:03:05 AM, on 4/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://usercenter.cox.net/rsuite/sdccommon/asp/cx_tgctlcm.jsp
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096224395421
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O20 - Winlogon Notify: Welcome - C:\WINDOWS\system32\i4jqle151h.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing)
oingo
11 Posts
0
April 12th, 2006 22:00
ALgal
1.2K Posts
0
April 12th, 2006 23:00
Sorry about that! Please do the following:
STEP 1.
======
Look2Me-Destroyer
Please download Look2Me-Destroyer.exe to your desktop.
If you receive a message from your firewall about this program accessing the internet please allow it.
If you receive a runtime error '339'. please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32. Directory
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX
oingo
11 Posts
0
April 13th, 2006 00:00
Look2Me-Destroyer V1.0.12
Scan started at 4/12/2006 8:31:26 PM
Infected! C:\WINDOWS\SYSTEM32\ibwphbk.dll
Infected! C:\WINDOWS\SYSTEM32\kydcz2.dll
Infected! C:\WINDOWS\SYSTEM32\hjd.dll
Infected! C:\WINDOWS\SYSTEM32\mkacm.dll
Infected! C:\WINDOWS\SYSTEM32\rbpdd.dll
Infected! C:\WINDOWS\SYSTEM32\cnlbact.dll
Infected! C:\WINDOWS\SYSTEM32\gcmf32.dll
Infected! C:\WINDOWS\SYSTEM32\mv6ul9j91.dll
Infected! C:\WINDOWS\SYSTEM32\q8nu0i59e8.dll
Infected! C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP446\A0075158.dll
Infected! C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP446\A0075163.dll
Infected! C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP445\A0075135.dll
C:\WINDOWS\system32\mv6ul9j91.dll Deleted successfully!
C:\WINDOWS\SYSTEM32\ibwphbk.dll Deleted successfully!
C:\WINDOWS\SYSTEM32\kydcz2.dll Deleted successfully!
C:\WINDOWS\SYSTEM32\hjd.dll Deleted successfully!
C:\WINDOWS\SYSTEM32\mkacm.dll Deleted successfully!
C:\WINDOWS\SYSTEM32\rbpdd.dll Deleted successfully!
C:\WINDOWS\SYSTEM32\cnlbact.dll Deleted successfully!
C:\WINDOWS\SYSTEM32\gcmf32.dll Deleted successfully!
C:\WINDOWS\SYSTEM32\mv6ul9j91.dll Deleted successfully!
C:\WINDOWS\SYSTEM32\q8nu0i59e8.dll Deleted successfully!
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP446\A0075158.dll Deleted successfully!
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP446\A0075163.dll Deleted successfully!
C:\System Volume Information\_restore{AFD46788-6A0B-4F67-BA96-08F219E0F8A1}\RP445\A0075135.dll Deleted successfully!
HKCR\Clsid\{5555F535-623E-452F-BA6F-85679056A650}
HKCR\Clsid\{AA5D0715-F61C-451F-9FDB-1A45C57CFAB1}
Restoring SeDebugPrivilege for Administrators - Succeeded
Scan saved at 8:36:07 PM, on 4/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://usercenter.cox.net/rsuite/sdccommon/asp/cx_tgctlcm.jsp
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096224395421
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing)