1.2K Posts

August 26th, 2005 12:00

Hello and Welcome Peterbell,
 

Please download Ewido Security Suite.

Run the installer.
When installing uncheck:
Install background guard
Install scan via context menu
Now open Ewido.
Update the definitons for Ewido.
Now close Ewido for right now.

Please download Ad-Aware SE Personal from this page.

Now download the VX2 Cleaner from this page.

Run Ad-Aware SE Personal.
Click Add-Ons.
Double-click VX2 Cleaner.
Click Ok to Excute this tool.
If nothing is found click Ok and exit the program.

or

If malware is found click Clean System.
When it's done click Start in Ad-Aware SE Personal.
Make sure Perform smart system scan is checked.
Click Next.
Let it clean anything it finds.


Run HiJackThis and click "Scan", then check(tick) the following, if present:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

O2 - BHO: PicShow Class - {4487598C-2EC7-43A2-870E-6D8D720FDD9F} - C:\WINDOWS\system32\pkshdecv.dll

O4 - HKLM\..\Run: [mlmzuh] C:\WINDOWS\system32\evdewop.exe r

O4 - HKCU\..\Run: [pshower] C:\WINDOWS\system32\pshwr.exe

 

Now, with all windows closed except HiJackThis, click "Fix checked".

 


How to see hidden files in Windows.

Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:

 

files...

   C:\WINDOWS\system32\evdewop.exe

   C:\WINDOWS\Nail.exe

   C:\WINDOWS\system32\pkshdecv.dll

   C:\WINDOWS\system32\pshwr.exe

 

-

Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them from "Safe Mode".


Now reboot.

Run Ewido.
Click on scanner. (Don't do anything on the computer while Ewido is running.)
Click Complete System Scan.
If you get a prompt asking to clean files then click OK.
When it cleans the first file put a check by Perform action on all infections and then choose clean and click OK.
Once the scan is done choose Save Report and save it your desktop.
Close Ewido.

Run Ad-Aware SE Personal.
Click Start in Ad-Aware SE Personal.
Make sure Perform smart system scan is checked.
Click Next.
Let it clean anything it finds.

Now reboot and post a new HijackThis log along with the Ewido log.

1.2K Posts

August 26th, 2005 14:00

Congratulations! Your log looks clean - good work!


Reboot your computer, and try using different programs and make sure everything is running ok. If your still experiencing problems, post back any concerns or problems you may be having and wait for any advice before continuing with the cleanup.


Download, install and run Cleanup! from Steven Gould, then:
1. Click " Cleanup!"
  ( wait for the program to finish scanning your system, and selecting files to be removed.)
2. Exit the program and reboot the computer, if necessary.
-
For more information about using Cleanup! see here.


If everything is running ok, let's do the final cleanup...


1.  Run " Disk Cleanup" and allow it to remove everything it finds. Click Start ==>Run ==> Enter "cleanmgr" without the quotes.
2.  If you've downloaded MicroWorld AV ( MWAV), run it again - but don't scan, just click " Clear Log" and exit the program.
3.  Go to www.trendmicro.com and click " Free Online Scan", then " Scan now, it's free!". When it's downloaded, select all available drives, then check(tick) " Auto clean", then click " Scan".
4.  Run AdAware SE Personal and " perform a full system scan", then Spybot S&D, and " Check for Problems". Let them both remove the residual 'problems' left that HiJackThis couldn't fix.
5.  Disable, then re-enable system restore; with a reboot in-between. Then immediately create a new system point manually. This clears out infected files that you may have in your restore/archive files.  This clears out your restore/archive files which may contain infected files.


If you have some extra time, let's review ways to help avoid an 'infected' system both now, and in the future.
-
Change your passwords now and on a regular basis.
-
Make your Internet Explorer more secure - This can be done by following these simple instructions:
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click once on the Security tab
3. Click once on the Internet icon so it becomes highlighted.
4. Click once on the Custom Level button.
a. Change the Download signed ActiveX controls to Prompt
b. Change the Download unsigned ActiveX controls to Disable
c. Change the Initialise and script ActiveX controls not marked as safe to Disable
d. Change the Installation of desktop items to Prompt
e. Change the Launching programs and files in an IFRAME to Prompt
f. Change the Navigate sub-frames across different domains to Prompt
g. When all these settings have been made, click on the OK button.
h. If it prompts you as to whether or not you want to save the settings, press the Yes button.
5. Next press the Apply button and then the OK to exit the Internet Properties page.
-
Use an Anti Virus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti-virus programs:
Computer Safety On line - Anti-Virus - http://forum.malwareremoval.com/viewtopic.php?p=53#53
-
Update your Anti Virus Software - It is imperative that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out
-
Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For an article on Firewalls and a listing of some available ones see the link below:
Computer Safety On line - Software Firewalls http://forum.malwareremoval.com/viewtopic.php?p=56#56
-
Test your firewall
You can visit the following website and test to see if your firewall is working
http://hackerwatch.org/probe
This can be useful to AOL users who do not use the AOL provided firewall and the AOL 9.0 startup screen does not detect your firewall and you wonder if your firewall is working!
-
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
-
Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:
Instructions for - Spybot S & D and Ad-aware http://forum.malwareremoval.com/viewtopic.php?t=13
-
Install Ad-Aware - Install and download Ad-Aware. You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot. A tutorial on installing & using this product can be found here:
Instructions for - Spybot S & D and Ad-aware http://forum.malwareremoval.com/viewtopic.php?t=13
-
Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. A article on anti-malware products with links for this program and others can be found here:
Computer Safety on line - Anti-Malware http://forum.malwareremoval.com/viewtopic.php?p=54#54
-
Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.



If your having any more problems, post back.
-
Have safe and happy surfing.
Thank you for letting me assist you!
Susan
 

Message Edited by ALgal on 08-26-200510:42 AM

Message Edited by ALgal on 08-26-2005 10:42 AM

August 26th, 2005 14:00

Thanks again for your help and great advice!!

Pete

August 26th, 2005 14:00

Hi.

Thanks a lot for the quick reply.

I've done as you suggested. Here's the Ewido and HijackThis log files ....

(I didn't get a pop-up ad when I opened this browser window so hopefully things are back to normal!!!)

 

Logfile of HijackThis v1.99.1
Scan saved at 16:14:29, on 26/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Documents and Settings\Hijack This\HijackThis[1].exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.compaq.com/1Q00CDT/0409/bl8.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.compaq.com/1Q00CDT/0409/bl7.asp
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

 

---------------------------------------------------------
 ewido security suite - Scan report
---------------------------------------------------------

 + Created on:   16:09:49, 26/08/2005
 + Report-Checksum:  9B76554E

 + Scan result:

 HKLM\SOFTWARE\Classes\CLSID\{9F95F736-0F62-4214-A4B4-CAA6738D4C07} -> Spyware.SaveNow : Cleaned with backup
 HKLM\SOFTWARE\Classes\Interface\{C285D18D-43A2-4AEF-83FB-BF280E660A97} -> Spyware.SaveNow : Cleaned with backup
 HKU\S-1-5-21-2828789760-2048353829-2582235506-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{36A59337-6EEF-40AE-94B1-ED443A0C4740} -> Spyware.BetterInternet : Cleaned with backup
 HKU\S-1-5-21-2828789760-2048353829-2582235506-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4D568F0F-8AC9-40AB-88B7-415134C78777} -> Spyware.Begin2Search : Cleaned with backup
 HKU\S-1-5-21-2828789760-2048353829-2582235506-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{52FE5233-367C-4EFB-BDD7-0BE4D212C107} -> Spyware.Begin2Search : Cleaned with backup
 HKU\S-1-5-21-2828789760-2048353829-2582235506-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E0CE16CB-741C-4B24-8D04-A817856E07F4} -> Spyware.Roimoi : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@adopt.euroclick[1].txt -> Spyware.Cookie.Euroclick : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wfkyghdzeho.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wfliahdpsgq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wflikid5wdq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wfmiolajghq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wfmyuoczacp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wgkicgd5sbq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjkoahdzkdo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjkoaoc5cdp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjkoejd5oco.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjkoopdzohp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjkoqjcpadp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjkyejczaep.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjkyupcpehp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjloagdpwdq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjlyuidzicp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjmiumdzado.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjmyolcjmap.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjmysjc5afp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@rotator.adjuggler[1].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
 C:\Documents and Settings\Administrator\Cookies\administrator@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
 C:\Program Files\BearShare\Installer\saveinstwm.exe -> Adware.SaveNow : Cleaned with backup
 C:\quarantine\svcproc.exe.Vir -> Trojan.Stervis.d : Error during cleaning
 C:\quarantine\svcproc.exe.Vir.0 -> Trojan.Stervis.d : Error during cleaning
 C:\quarantine\svcproc.exe.Vir.1 -> Trojan.Stervis.d : Error during cleaning
 C:\quarantine\svcproc.exe.Vir.2 -> Trojan.Stervis.d : Error during cleaning
 C:\quarantine\svcproc.exe.Vir.3 -> Trojan.Stervis.d : Error during cleaning
 C:\quarantine\svcproc.exe.Vir.4 -> Trojan.Stervis.d : Error during cleaning
 C:\quarantine\svcproc.exe.Vir.5 -> Trojan.Stervis.d : Error during cleaning
 C:\quarantine\svcproc.exe.Vir.6 -> Trojan.Stervis.d : Error during cleaning
 C:\WINDOWS\viyuijqop.exe -> Adware.BetterInternet : Cleaned with backup


::Report End

No Events found!

Top