Unsolved

This post is more than 5 years old

5 Posts

616

June 29th, 2005 00:00

DT neeeds more help

In a previous log you had asked me to uninstall new.net and paste another log.  I have downloaded the uninstall program.  Here you go.
 
Logfile of HijackThis v1.99.1
Scan saved at 10:28:15 PM, on 6/17/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\neten32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\popuper.exe
C:\WINNT\system32\intmonp.exe
C:\WINNT\system32\msole32.exe
C:\WINNT\system32\shnlog.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-ca\msnappau.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\intmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\winfw.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Warez P2P Client\warez.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\taskmgr.exe
C:\WINNT\system32\CMD.exe
C:\WINNT\system32\drwtsn32.exe
C:\WINNT\system32\drwtsn32.exe
C:\WINNT\system32\drwtsn32.exe
C:\hjt\HijackThis.exe
C:\WINNT\explorer.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.updatesearches.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.updatesearches.com/bar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.updatesearches.com/search.php?qq=%1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\system32\uwzna.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\uwzna.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\uwzna.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.updatesearches.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.updatesearches.com/search.php?qq=%1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\uwzna.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.updatesearches.com/search.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.updatesearches.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Rogers Hi-Speed Internet
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe, msmsgs.exe
O2 - BHO: (no name) - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINNT\system32\hpB852.tmp
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-ca\msntb.dll (file missing)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-ca\msnappau.exe"
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [winfw.exe] C:\WINNT\winfw.exe
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [RegSvr32] C:\WINNT\system32\msmsgs.exe
O4 - HKCU\..\Run: [RHSI SHS] "C:\Program Files\Rogers Hi-Speed Internet\RHSI SelfHealing\SHS.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [warez] "C:\Program Files\Warez P2P Client\warez.exe" -h
O4 - Global Startup: Microsoft Broadband Networking.lnk = C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: U.S. Robotics 802.11g Wireless Network Utility.lnk = C:\Program Files\U.S. Robotics 802.11g WLAN\USRWLANG.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O14 - IERESET.INF: START_PAGE_URL=http://www.hispeed.rogers.com
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\zpkobtnm.exe
O16 - DPF: {1B7FF0F2-20A8-4419-B0E0-A9A9B4DCA14C} (VPlayer Control) - http://www.blindreaper.com/sneak/vivid_ocx.jpeg
O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} (InstallX Class) - http://www.20x2p.com/5258303d/enter.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple.com/iTunes4/WW/win/019-0312.20050111.MmVrT/iTunesSetup.exe
O20 - Winlogon Notify: style2 - C:\WINNT\q5338756_disk.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\system32\neten32.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 

302 Posts

June 29th, 2005 04:00

You still have problems in this log. Please post your reply back in your original thread whereever it is. That will alert your original remover responder and they can continue to help you in an orderly and systematic manner.

Thanks for helping them to help you.

REgards.

cg

 

302 Posts

June 29th, 2005 12:00

Ok, I see your problem. Let me see if I can think this one out or get you some other help.

Regards.

cg

302 Posts

June 29th, 2005 13:00

Interesting assortment of stuff.
 
Here is a post I found by a security expert named Calmity Jane:

~~~~~~~~~~~~~~~~~~~~~~~~~~
Use either of of these free online file scanner sites which use a dozen or more well-known Antivirus Scanners simulaneously to let you know if the file is infected.
Jotti Malware Scan
http://virusscan.jotti.org/
Browse to and upload the file in question. It will give you a report at the end. If you have any questions, feel free to post that scan log here for advice
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Please scan both of these files at one of those sites and let me know the results.
C:\WINNT\winfw.exe
C:\WINNT\system32\msmsgs.exe
 
Thanks.
cg

Message Edited by cghost on 06-29-2005 09:57 AM

302 Posts

June 29th, 2005 13:00

Here is a tutorial for new.net.
 
You can go through those steps:
 
 
You also have a coolwebsearch issue and maybe some other stuff. I am not "top of my head" familiar with all the xp files so it is going to take me awhile to research your log but I will get you another post with a next step.
 
Regards.
cg

4.8K Posts

June 29th, 2005 14:00

cghost,

Didn't mean to step in here on you...

DTHunter,

You have a smitfraud infection, A/B, NewDotNet and a few toolbars and trojans - and it's very fixable. However, you need to stay in the original thread where you started, so they can help you get your system cleaned. Starting multiple threads with multiple posts, makes it extremely difficult for them to know when you've posted back to their instructions so they can track the progression of the cleanup, since they will no longer be getting any notifications from the original thread.

==========

Mike.

302 Posts

June 29th, 2005 15:00

Mike,

His post history and something I saw at malwareremoval is why I changed from my original post. I am going to continue responding on this one - in this thread only.

Regards.

cg

302 Posts

June 29th, 2005 15:00

Hi,
 
To combine this with the previous posts,
 
1) Please follow the new.net uninstall procedure.
 
2) Please check the two files that I mentioned.
 
3)
Please download Intermute's CWShredder from here:
http://cwshredder.net/bin/CWShredder.exe
Save it to the desktop and run it, and click "Fix" to remove the CWS infection.
Then please download About:Buster from here:
http://www.malwarebytes.biz/AboutBuster5.zip
Unzip the files to a convenient location such as C:\AboutBuster, and run AboutBuster.exe.  Read the instructions then click OK to proceed.  Click "Check for Updates", and then "Download Updates" to update About:Buster to the newest version.  Then click Start to begin the scan.  If prompted to end the Explorer.exe process, click Yes.  Your desktop may disappear --- this is normal.  Allow the program to scan twice, and when complete click "Save Log".  This will create a text file called "AB Logfile.txt" in the folder where About:Buster is saved.
 
4) go to http://www.ravantivirus.com/scan/ and run RAV on your system.
When finished, save the RAV report.
 
5) Reboot the system.
 
Run a new hijackthis log.
Let me know what the virus scans showed about the 2 files I asked about.
Post the aboutbuster log.
Post the RAV report.
Post the new hijackthis log.
 
We'll see where we go from there.

Sorry about the delay you had in getting a response. Most of us replying to posts in this forum are volunteer folks with an interest in helping others. Our personal and work lives will sometimes interfere with our ability to provide prompt answers to people seeking help.

Regards.
cg

711 Posts

June 30th, 2005 07:00

Hi DT,

Sorry for the wait have been away from the baords for a while.

Please follow the above fix and post back a new HJT Log

Bertha2

5 Posts

August 23rd, 2005 02:00

Hi,

It has been a while, however, I have finally had the chance to get back to this problem.

 

Here are the 3 logs

AboutBuster, RAV and HiJackThis

AboutBuster 5.0 reference file 28
Scan started on [8/21/2005] at [9:31:13 PM]
------------------------------------------------
No Ads Found!
------------------------------------------------
No Files Found!
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 9:31:29 PM

Scan started at 8/22/2005 9:36:14 PM
 
Scanning memory...
Scanning boot sectors...
Scanning files...
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6ZIV69QL\input[1].php->(SCRIPT0004) - JS/DragDrop.A* -> Infected
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SLUJODY3\input[1].php->(GZip)->(SCRIPT0004) - JS/DragDrop.A* -> Infected
C:\WINNT\addjj32.exe - TrojanDownloader:Win32/Agent.GZ -> Infected
C:\WINNT\appco32.dll - TrojanDownloader:Win32/Agent.HT -> Infected
C:\WINNT\COM+.log->ADS:qfnexf - TrojanDownloader:Win32/Agent.GZ -> Infected
C:\WINNT\crvs32.dll - TrojanDownloader:Win32/Agent.HT -> Infected
C:\WINNT\sdkim32.exe - TrojanDownloader:Win32/Agent.GZ -> Infected
C:\WINNT\winfw.exe - TrojanDownloader:Win32/Agent.GZ -> Infected
C:\WINNT\_default.pif->ADS:xddbid - TrojanDownloader:Win32/Agent.GZ -> Infected
C:\WINNT\_default.pif->ADS:agwoa - TrojanDownloader:Win32/Agent.GZ -> Infected
C:\WINNT\system32\crle32.exe - TrojanDownloader:Win32/Agent.GZ -> Infected
C:\WINNT\system32\neten32.exe - Trojan:Win32/Agent.BI -> Infected
C:\WINNT\system32\ntkp.exe - TrojanDownloader:Win32/Agent.GZ -> Infected
C:\WINNT\system32\pbopg.dll - TrojanDownloader:Win32/WinShow.AK -> Suspicious
C:\WINNT\system32\sysli32.dll - TrojanDownloader:Win32/Agent.HT -> Infected

Scanned
============================
 Objects: 10744
 Directories: 595
 Archives: 341
 Size(Kb): 1601529
 Infected files: 14

Found
============================
 Viruses found: 4
 Suspicious files: 1
 Disinfected files: 0
 Mail files: 53

C:\WINNT\system32\intmonp.exe
C:\WINNT\system32\msole32.exe
C:\WINNT\system32\shnlog.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\intmon.exe
C:\WINNT\system32\taskmgr.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\system32\cmd.exe
C:\hjt\HijackThis.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\drwtsn32.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.updatesearches.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.updatesearches.com/bar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.updatesearches.com/search.php?qq=%1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.updatesearches.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.updatesearches.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.updatesearches.com/search.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.updatesearches.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Rogers Hi-Speed Internet
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe, msmsgs.exe
O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINNT\system32\hpA364.tmp
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-ca\msntb.dll (file missing)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [RegSvr32] C:\WINNT\system32\msmsgs.exe
O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKCU\..\Run: [RHSI SHS] "C:\Program Files\Rogers Hi-Speed Internet\RHSI SelfHealing\SHS.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [warez] "C:\Program Files\Warez P2P Client\warez.exe" -h
O4 - Global Startup: Microsoft Broadband Networking.lnk = C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: U.S. Robotics 802.11g Wireless Network Utility.lnk = C:\Program Files\U.S. Robotics 802.11g WLAN\USRWLANG.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O14 - IERESET.INF: START_PAGE_URL=http://www.hispeed.rogers.com
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\zpkobtnm.exe
O16 - DPF: {1B7FF0F2-20A8-4419-B0E0-A9A9B4DCA14C} (VPlayer Control) - http://www.blindreaper.com/sneak/vivid_ocx.jpeg
O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} (InstallX Class) - http://www.20x2p.com/5258303d/enter.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple.com/iTunes4/WW/win/019-0312.20050111.MmVrT/iTunesSetup.exe
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O20 - Winlogon Notify: style2 - C:\WINNT\q5338756_disk.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

No Events found!

Top