Unsolved
This post is more than 5 years old
6 Posts
0
1407
April 5th, 2007 13:00
Help: internet explorer default homepage changes unexpectedly (hijackthis.log file attached)
Logfile of HijackThis v1.99.1
Scan saved at 10:39:21 AM, on 4/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Scan saved at 10:39:21 AM, on 4/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\iPass\iPassConnect\iPCAgent.exe
C:\WINDOWS\system32\ncsvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Funk Software\Odyssey Client\OdTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\SysDayN6\svchost.exe
C:\SysWsj7\svchost.exe
C:\SysAd5D\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\474115BE.exe
C:\WINDOWS\system32\8A37EDF2.exe
C:\WINDOWS\system32\474115BE.exe
C:\WINDOWS\system32\8A37EDF2.exe
C:\Program Files\iPass\iPassConnect\downloader\ipccheck.exe
C:\WINDOWS\system32\474115BE.exe
C:\WINDOWS\system32\8A37EDF2.exe
C:\WINDOWS\system32\474115BE.exe
C:\WINDOWS\system32\8A37EDF2.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\474115BE.exe
C:\WINDOWS\system32\8A37EDF2.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\HJT\HJT.exe
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\iPass\iPassConnect\iPCAgent.exe
C:\WINDOWS\system32\ncsvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Funk Software\Odyssey Client\OdTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\SysDayN6\svchost.exe
C:\SysWsj7\svchost.exe
C:\SysAd5D\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\474115BE.exe
C:\WINDOWS\system32\8A37EDF2.exe
C:\WINDOWS\system32\474115BE.exe
C:\WINDOWS\system32\8A37EDF2.exe
C:\Program Files\iPass\iPassConnect\downloader\ipccheck.exe
C:\WINDOWS\system32\474115BE.exe
C:\WINDOWS\system32\8A37EDF2.exe
C:\WINDOWS\system32\474115BE.exe
C:\WINDOWS\system32\8A37EDF2.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\474115BE.exe
C:\WINDOWS\system32\8A37EDF2.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\HJT\HJT.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://home
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.new114.com.cn:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [OdTray.exe] "C:\Program Files\Funk Software\Odyssey Client\OdTray.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [winform] C:\WINDOWS\winform.exe
O4 - HKLM\..\Run: [nortons] C:\WINDOWS\nortons.exe
O4 - HKLM\..\Run: [cmdbcs] C:\WINDOWS\cmdbcs.exe
O4 - HKLM\..\Run: [yupxdnd] C:\DOCUME~1\yit\LOCALS~1\Temp\yupxdnd.exe
O4 - HKLM\..\Run: [mppds] C:\WINDOWS\mppds.exe
O4 - HKLM\..\Run: [upxdnd] C:\DOCUME~1\yit\LOCALS~1\Temp\upxdnd.exe
O4 - HKLM\..\Run: [nortone] C:\WINDOWS\nortone.exe
O4 - HKLM\..\Run: [norton] C:\WINDOWS\norton.exe
O4 - HKLM\..\Run: [msccrt] C:\WINDOWS\msccrt.exe
O4 - HKLM\..\Run: [nortonq] C:\WINDOWS\nortonq.exe
O4 - HKLM\..\Run: [dcoh] C:\WINDOWS\dcoh.exe
O4 - HKLM\..\Run: [cmdbcsg] C:\WINDOWS\cmdbcsg.exe
O4 - HKLM\..\Run: [upxdwnd] C:\DOCUME~1\yit\LOCALS~1\Temp\upxdwnd.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://home
O15 - Trusted Zone: http://home.medimmune.com
O15 - Trusted Zone: http://home.medimmune.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://remote.medimmune.com/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {6AE02E1C-8859-4F57-9097-5A55A56A4CAF} - http://images.5460.net/toolbar/webinstall/5460.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = medimmune.com
O17 - HKLM\Software\..\Telephony: DomainName = medimmune.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = medimmune.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = medimmune.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: OdysseyClient - C:\WINDOWS\SYSTEM32\odyEvent.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPCAgent.exe
O23 - Service: Virtual Com Port Service (neoNcSvc) - Unknown owner - C:\WINDOWS\system32\ncsvc.exe
O23 - Service: Odyssey Client (odClientService) - Funk Software, Inc. - C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
O23 - Service: OracleOra920ClientCache - Unknown owner - C:\ora920\BIN\ONRSD.EXE (file missing)
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.new114.com.cn:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [OdTray.exe] "C:\Program Files\Funk Software\Odyssey Client\OdTray.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [winform] C:\WINDOWS\winform.exe
O4 - HKLM\..\Run: [nortons] C:\WINDOWS\nortons.exe
O4 - HKLM\..\Run: [cmdbcs] C:\WINDOWS\cmdbcs.exe
O4 - HKLM\..\Run: [yupxdnd] C:\DOCUME~1\yit\LOCALS~1\Temp\yupxdnd.exe
O4 - HKLM\..\Run: [mppds] C:\WINDOWS\mppds.exe
O4 - HKLM\..\Run: [upxdnd] C:\DOCUME~1\yit\LOCALS~1\Temp\upxdnd.exe
O4 - HKLM\..\Run: [nortone] C:\WINDOWS\nortone.exe
O4 - HKLM\..\Run: [norton] C:\WINDOWS\norton.exe
O4 - HKLM\..\Run: [msccrt] C:\WINDOWS\msccrt.exe
O4 - HKLM\..\Run: [nortonq] C:\WINDOWS\nortonq.exe
O4 - HKLM\..\Run: [dcoh] C:\WINDOWS\dcoh.exe
O4 - HKLM\..\Run: [cmdbcsg] C:\WINDOWS\cmdbcsg.exe
O4 - HKLM\..\Run: [upxdwnd] C:\DOCUME~1\yit\LOCALS~1\Temp\upxdwnd.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://home
O15 - Trusted Zone: http://home.medimmune.com
O15 - Trusted Zone: http://home.medimmune.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://remote.medimmune.com/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {6AE02E1C-8859-4F57-9097-5A55A56A4CAF} - http://images.5460.net/toolbar/webinstall/5460.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = medimmune.com
O17 - HKLM\Software\..\Telephony: DomainName = medimmune.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = medimmune.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = medimmune.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: OdysseyClient - C:\WINDOWS\SYSTEM32\odyEvent.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPCAgent.exe
O23 - Service: Virtual Com Port Service (neoNcSvc) - Unknown owner - C:\WINDOWS\system32\ncsvc.exe
O23 - Service: Odyssey Client (odClientService) - Funk Software, Inc. - C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
O23 - Service: OracleOra920ClientCache - Unknown owner - C:\ora920\BIN\ONRSD.EXE (file missing)
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
No Events found!


bamajim
10.4K Posts
0
April 5th, 2007 15:00
That's quite an infection you have there. It will take a couple of runs at this before we can fix it so please be patient
1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
july_yi
6 Posts
0
April 5th, 2007 16:00
ComboFix 07-04-05 - Running from: "C:\Documents and Settings\yit\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\jdsfdutj.dat
C:\SysAd5C\Ghook.dll
C:\SysAd5C\svchost.exe
C:\SysAd5D\Ghook.dll
C:\SysAd5D\svchost.exe
C:\SysDayN5\Ghook.dll
C:\SysDayN5\svchost.exe
C:\SysDayN6\Ghook.dll
C:\SysDayN6\svchost.exe
C:\Syswm1f\Ghook.dll
C:\Syswm1f\svchost.exe
C:\Syswm1h\Ghook.dll
C:\Syswm1h\svchost.exe
C:\SysWsj4\Ghook.dll
C:\SysWsj4\svchost.exe
C:\SysWsj5\Ghook.dll
C:\SysWsj5\svchost.exe
C:\SysWsj6\Ghook.dll
C:\SysWsj6\svchost.exe
C:\SysWsj7\Ghook.dll
C:\SysWsj7\svchost.exe
C:\SysAd5C
C:\SysAd5D
C:\SysDayN5
C:\SysDayN6
C:\Syswm1f
C:\Syswm1h
C:\SysWsj4
C:\SysWsj5
C:\SysWsj6
C:\SysWsj7
((((((((((((((((((((((((((((((( Files Created from 2007-03-05 to 2007-04-05 ))))))))))))))))))))))))))))))))))
2007-04-05 13:23 540 --a------ C:\WINDOWS\system32\index.dat
2007-04-05 13:23
2007-04-05 11:08
2007-04-05 10:38
2007-04-05 10:30
2007-04-05 09:33
2007-04-05 09:31
2007-04-04 19:08
2007-04-04 18:58 43,767 --a------ C:\WINDOWS\system32\D943C8B2T.EXE
2007-04-04 18:58 43,767 --a------ C:\WINDOWS\system32\D943C8B2.EXE
2007-04-04 16:14 9,401 --a------ C:\WINDOWS\system32\7AA263EE.DLL
2007-04-04 16:14 15,364 --a------ C:\WINDOWS\system32\7AA263EE.EXE
2007-04-04 16:14 15,364 ---h----- C:\rising.exe
2007-03-30 10:41 37,195 --a------ C:\WINDOWS\system32\D943C8B2.DLL
2007-03-30 10:41 26,134 --a------ C:\WINDOWS\system32\474115BE.exe
2007-03-28 15:48
2007-03-22 09:30 13,862 --a------ C:\WINDOWS\nortons.exe
2007-03-21 15:56 43,762 --a------ C:\WINDOWS\system32\2FC3F5DAT.EXE
2007-03-21 15:56 43,762 --a------ C:\WINDOWS\system32\2FC3F5DA.EXE
2007-03-21 15:56 37,190 --a------ C:\WINDOWS\system32\2FC3F5DA.DLL
2007-03-21 15:56 26,126 --a------ C:\WINDOWS\system32\8A37EDF2.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-05 13:31 -------- d-------- C:\Program Files\symantec antivirus
2007-03-08 11:36 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 11:36 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 11:36 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 09:47 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-05 15:29 -------- d-------- C:\Program Files\nquery advisor 6.01
2007-02-09 10:13 -------- d-------- C:\Program Files\google
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_9 -reboot 1"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
@=""
"OdTray.exe"="\"C:\\Program Files\\Funk Software\\Odyssey Client\\OdTray.exe\""
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"UpdateManager"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"vptray"="C:\\PROGRA~1\\SYMANT~1\\VPTray.exe"
"Acrobat Assistant 7.0"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"IMEKRMIG6.1"="C:\\WINDOWS\\ime\\imkr6_1\\IMEKRMIG.EXE"
"MSPY2002"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
"PHIME2002ASync"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"nortons"="C:\\WINDOWS\\nortons.exe"
"nortone"="C:\\WINDOWS\\nortone.exe"
"norton"="C:\\WINDOWS\\norton.exe"
"nortonq"="C:\\WINDOWS\\nortonq.exe"
"dcoh"="C:\\WINDOWS\\dcoh.exe"
"cmdbcsg"="C:\\WINDOWS\\cmdbcsg.exe"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"Installed"="1"
"NoChange"="1"
"Installed"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
"NoDisconnect"=dword:00000001
"66"="C:\\SysDayN6\\svchost.exe"
"50"="C:\\SysAd5D\\svchost.exe"
"333"="C:\\Syswm1i\\svchost.exe"
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
C:\WINDOWS\tasks\MP Scheduled Scan.job
********************************************************************
http://www.gmer.net
hidden processes: 0
hidden services: 0
hidden files: 0
C:\ComboFix-quarantined-files.txt ... 07-04-05 13:40
bamajim
10.4K Posts
0
April 5th, 2007 18:00
Your welcome
You may want to print out these instructions for reference
1. We need to make sure we can see hidden files and folders
To enable the viewing of Hidden and System files follow these steps:
Select the Tools menu and click Folder Options.
After the new window appears select the View tab.
Put a checkmark in the checkbox labeled Display the contents of system folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.
Click Yes To confirm
Press the Apply button and then the OK button.
2. Open Notepad (Not Wordpad)
Select Edit and uncheck Wordwrap
Copy and paste the following into Notepad
(Making sure there is no space between the top of the window and the first line)
REGEDIT4
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"nortons"=-
"nortone"=-
"norton"=-
"nortonq"=-
"dcoh"=-
"cmdbcsg"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDisconnect"=-
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"66"=-
"50"=-
"333"=-
After you copy and paste it your cursor should be at the end of the first line
Hit Enter so your cursor is under the last line
Under " Save as type" Select " All Files"->> save it to your Desktop
Close Notepad
The fix.reg file should now appear on your Desktop
Rt Click and Select merge->>If prompted to Merge this Select Yes (it will appear that nothing has happened but that's o.k.)
3. Using Windows Explorer
Locate and Delete (To delete, Rt Click->>Select Delete) the following folders
C:\SysDayN6
C:\SysAd5D
Close Windows explorer
4. Please download the Killbox.
2) Select " Delete on Reboot", and then select "All files".
3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:
C:\WINDOWS\system32\D943C8B2.EXE
C:\WINDOWS\system32\7AA263EE.DLL
C:\WINDOWS\system32\7AA263EE.EXE
C:\rising.exe
C:\WINDOWS\system32\D943C8B2.DLL
C:\WINDOWS\system32\474115BE.exe
C:\WINDOWS\nortons.exe
C:\WINDOWS\system32\2FC3F5DAT.EXE
C:\WINDOWS\system32\2FC3F5DA.EXE
C:\WINDOWS\system32\2FC3F5DA.DLL
C:\WINDOWS\system32\8A37EDF2.exe
C:\WINDOWS\nortons.exe
C:\WINDOWS\nortone.exe
C:\WINDOWS\norton.exe
C:\WINDOWS\nortonq.exe
C:\WINDOWS\dcoh.exe
C:\WINDOWS\cmdbcsg.exe
4) Return to Killbox, go to the File menu, and choose " Paste from Clipboard".
5) Click the red-and-white " Delete File" button. Click " Yes" at the Delete on Reboot prompt. Click " No" at the Pending Operations prompt.
Message Edited by bamajim on 04-05-2007 03:30 PM
july_yi
6 Posts
0
April 5th, 2007 19:00
bamajim,
Thank you again! I followed your instructions. Howerver, these files couldn't be deleted by killbox.
C:\WINDOWS\nortons.exe
C:\WINDOWS\nortone.exe
C:\WINDOWS\norton.exe
C:\WINDOWS\nortonq.exe
C:\WINDOWS\dcoh.exe
C:\WINDOWS\cmdbcsg.exe
So I deleted them via hijackthis. Hope it will be okay. I attached the new hjt.log below:
Logfile of HijackThis v1.99.1
Scan saved at 16:23, on 07-04-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\iPass\iPassConnect\iPCAgent.exe
C:\WINDOWS\system32\ncsvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Funk Software\Odyssey Client\OdTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPass\iPassConnect\downloader\ipccheck.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HJT\HJT.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.new114.com.cn:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [OdTray.exe] "C:\Program Files\Funk Software\Odyssey Client\OdTray.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://home
O15 - Trusted Zone: http://home.medimmune.com
O15 - Trusted Zone: http://home.medimmune.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://remote.medimmune.com/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {6AE02E1C-8859-4F57-9097-5A55A56A4CAF} - http://images.5460.net/toolbar/webinstall/5460.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1175786905448
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = medimmune.com
O17 - HKLM\Software\..\Telephony: DomainName = medimmune.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = medimmune.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = medimmune.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: OdysseyClient - C:\WINDOWS\SYSTEM32\odyEvent.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: 2FC3F5DA - Unknown owner - C:\WINDOWS\system32\2FC3F5DA.EXE (file missing)
O23 - Service: 7AA263EE - Unknown owner - C:\WINDOWS\system32\7AA263EE.EXE (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: D943C8B2 - Unknown owner - C:\WINDOWS\system32\D943C8B2.EXE (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPCAgent.exe
O23 - Service: Virtual Com Port Service (neoNcSvc) - Unknown owner - C:\WINDOWS\system32\ncsvc.exe
O23 - Service: Odyssey Client (odClientService) - Funk Software, Inc. - C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
O23 - Service: OracleOra920ClientCache - Unknown owner - C:\ora920\BIN\ONRSD.EXE (file missing)
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
bamajim
10.4K Posts
0
April 5th, 2007 23:00
That's o.k good job.
1. Rerun Hiackthis (scan only) and place checks beside the following entries
- O23 - Service: 2FC3F5DA - Unknown owner - C:\WINDOWS\system32\2FC3F5DA.EXE (file missing)
Close all other open windows except Hijackthis and Select " Fix checked"O23 - Service: 7AA263EE - Unknown owner - C:\WINDOWS\system32\7AA263EE.EXE (file missing)
O23 - Service: D943C8B2 - Unknown owner - C:\WINDOWS\system32\D943C8B2.EXE (file missing)
Close Hijackthis and reboot your PC
2. Go here and Download AVG Anti-Spyware
( 30 day free trial version) Save it to Your Desktop
Double Click AVG Anti-Spyware-setup
(It will create its own folder)
Once the program starts You will be at the Status menu
Click Update now (next to last update)
After the update loads
Under Automatic updates Uncheck download and install updates automatically(recommended)
(you can always select maual updates the next day)
At the top toolbar Click Scanner Then the settings tab
- Under How to act? Set default action for detected malwareTo Quarantine
Exit AVG(But do not run it yet)Under how to scan All boxes should be checked
Under Possibly unwanted software All boxes should be checked
Under reports Select Automatically generate report after every scan
Uncheck Only if threats were found
Under what to scan Scan every file should be highlited
Reboot into Safe Mode
This can be done by
Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
Use your arrow keys and select Safe Mode and then Enter
Run AVG Anti-Spyware
- Click scanner
Once the scan finishesSelect Complete system scan
- Select Apply all actions (The items found will be quarantined)
Exit AVGClick save report as (Another window will open)
Save it to your desktop
(By default It will be saved in the AVG folder as)
C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports
Reboot your PC in Normal Mode->>Re run Hijackthis and post a fresh Hijackthis log.
- Double click the report-scan txt. you saved to your desktop
Your reply should includeIt will open in Notepad
Copy and paste that report as a reply to this thread
your report_scan.txt log from AVG
july_yi
6 Posts
0
April 6th, 2007 02:00
bamajim
10.4K Posts
0
April 6th, 2007 11:00
bamajim
10.4K Posts
0
April 6th, 2007 14:00
july_yi
6 Posts
0
April 6th, 2007 14:00
Scan saved at 10:59, on 07-04-06
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\iPass\iPassConnect\iPCAgent.exe
C:\WINDOWS\system32\ncsvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Funk Software\Odyssey Client\OdTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iPass\iPassConnect\downloader\ipccheck.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HJT\HJT.exe
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [OdTray.exe] "C:\Program Files\Funk Software\Odyssey Client\OdTray.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Google IME Autoupdater] "C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://home
O15 - Trusted Zone: http://home.medimmune.com
O15 - Trusted Zone: http://home.medimmune.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://remote.medimmune.com/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1175786905448
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = medimmune.com
O17 - HKLM\Software\..\Telephony: DomainName = medimmune.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = medimmune.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = medimmune.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: OdysseyClient - C:\WINDOWS\SYSTEM32\odyEvent.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPCAgent.exe
O23 - Service: Virtual Com Port Service (neoNcSvc) - Unknown owner - C:\WINDOWS\system32\ncsvc.exe
O23 - Service: Odyssey Client (odClientService) - Funk Software, Inc. - C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
O23 - Service: OracleOra920ClientCache - Unknown owner - C:\ora920\BIN\ONRSD.EXE (file missing)
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
C:\Documents and Settings\All Users\Application Data\webex\ieatgpc.dll -> Adware.WebEx : Cleaned with backup (quarantined).
C:\!KillBox\2FC3F5DA.DLL -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
C:\!KillBox\2FC3F5DA.DLL( 3) -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
C:\!KillBox\2FC3F5DA.EXE -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
C:\!KillBox\2FC3F5DA.EXE( 4) -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
C:\!KillBox\2FC3F5DAT.EXE -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
C:\!KillBox\2FC3F5DAT.EXE( 5) -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
C:\!KillBox\474115BE.exe -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
C:\!KillBox\474115BE.exe( 7) -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
C:\!KillBox\8A37EDF2.exe -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
C:\!KillBox\8A37EDF2.exe( 2) -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
C:\Documents and Settings\yit\Cookies\yit@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\yit\Cookies\yit@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\yit\Cookies\yit@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Administrator\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Default User\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\JankowskiJ\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\corothersn\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\frenchgw\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\lious\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\mcguinc\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\murphymf.MEDIMMUNE\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\owensk\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\santiagoj\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\ullaha\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\wa_imagebuilder\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\yit\Cookies\yit@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\yit\Cookies\yit@atdmt[3].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\zhouy\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\yit\Cookies\yit@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\yit\Cookies\yit@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\yit\Cookies\yit@media.fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\yit\Cookies\yit@ehg-morningstar.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\yit\Cookies\yit@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\yit\Cookies\yit@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\yit\Cookies\yit@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\yit\Cookies\yit@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\yit\Cookies\yit@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\yit\Cookies\yit@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\yit\Cookies\yit@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\yit\Cookies\yit@ad.yieldmanager[3].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\QooBox\Quarantine\SysAd5C\Ghook.dll.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\SysDayN5\svchost.exe.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\SysWsj4\Ghook.dll.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\SysWsj5\Ghook.dll.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\SysWsj5\svchost.exe.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\SysWsj6\Ghook.dll.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\SysWsj7\Ghook.dll.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\Syswm1f\Ghook.dll.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\Syswm1f\svchost.exe.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\Syswm1h\Ghook.dll.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\SysAd5C\svchost.exe.vir -> Trojan.OnLineGames.kt : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\SysAd5D\svchost.exe.vir -> Trojan.OnLineGames.kt : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\SysDayN5\Ghook.dll.vir -> Trojan.OnLineGames.kt : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\SysDayN6\Ghook.dll.vir -> Trojan.OnLineGames.kt : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\SysDayN6\svchost.exe.vir -> Trojan.OnLineGames.kt : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\SysWsj4\svchost.exe.vir -> Trojan.OnLineGames.kt : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\SysWsj6\svchost.exe.vir -> Trojan.OnLineGames.kt : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\Syswm1h\svchost.exe.vir -> Trojan.OnLineGames.kt : Cleaned with backup (quarantined).
C:\!KillBox\nortons.exe -> Trojan.OnLineGames.ld : Cleaned with backup (quarantined).
C:\!KillBox\nortons.exe( 6) -> Trojan.OnLineGames.ld : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\SysWsj7\svchost.exe.vir -> Trojan.OnLineGames.mf : Cleaned with backup (quarantined).
::Report end
july_yi
6 Posts
0
April 6th, 2007 15:00
bamajim
10.4K Posts
0
April 6th, 2007 15:00
You may now remove/delete/uninstall the tools we used to clean your PC
Now that your log is clean
There are some final notes:
Disable and Enable System Restore
- Lets create a clean System Restore point
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.the instructions are here
Please follow these steps to remove older version Java components and update.
Updating Java:
- Download the latest version of
Make your Internet Explorer more secureJava Runtime Environment (JRE) 6.1.
Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
Click the " Download" button to the right.
Check the box that says: " Accept License Agreement".
The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6-windowsi586-p.exe to install the newest version.
This can be done by following these simple instructions:
- Open Internet Explorer click Tools->> Options.
Update your Anti Virus SoftwareClick Security tab
Click once on the Internet icon so it becomes highlighted.
Click Custom Level.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click OK.
If it prompts you to save the settings, press Yes.
Next press Apply and then OK to exit the Internet Properties page
Use and maintain a Firewall such as ZoneAlarm
- The Windows Firewall is good at blocking incoming threats, but not outgoing threats such as "Backdoor Trojans"
Install IE SPYAD for protection against innocent looking websites that are not innocentSome others are
Sygate
And
Sunbelt personal
All of which are free
Visit Microsoft's Windows Update Site Frequently for critical updates
Backup your Important Documents and Files on a regular basis
- To a disc or a USB key, not your Hardrive
You may want to read this article" So how did I get infected in the first place" by Tony Kleinsurf safe