Unsolved

This post is more than 5 years old

6 Posts

1407

April 5th, 2007 13:00

Help: internet explorer default homepage changes unexpectedly (hijackthis.log file attached)

Logfile of HijackThis v1.99.1
Scan saved at 10:39:21 AM, on 4/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\iPass\iPassConnect\iPCAgent.exe
C:\WINDOWS\system32\ncsvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Funk Software\Odyssey Client\OdTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\SysDayN6\svchost.exe
C:\SysWsj7\svchost.exe
C:\SysAd5D\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\474115BE.exe
C:\WINDOWS\system32\8A37EDF2.exe
C:\WINDOWS\system32\474115BE.exe
C:\WINDOWS\system32\8A37EDF2.exe
C:\Program Files\iPass\iPassConnect\downloader\ipccheck.exe
C:\WINDOWS\system32\474115BE.exe
C:\WINDOWS\system32\8A37EDF2.exe
C:\WINDOWS\system32\474115BE.exe
C:\WINDOWS\system32\8A37EDF2.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\474115BE.exe
C:\WINDOWS\system32\8A37EDF2.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\HJT\HJT.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.new114.com.cn:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [OdTray.exe] "C:\Program Files\Funk Software\Odyssey Client\OdTray.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [winform] C:\WINDOWS\winform.exe
O4 - HKLM\..\Run: [nortons] C:\WINDOWS\nortons.exe
O4 - HKLM\..\Run: [cmdbcs] C:\WINDOWS\cmdbcs.exe
O4 - HKLM\..\Run: [yupxdnd] C:\DOCUME~1\yit\LOCALS~1\Temp\yupxdnd.exe
O4 - HKLM\..\Run: [mppds] C:\WINDOWS\mppds.exe
O4 - HKLM\..\Run: [upxdnd] C:\DOCUME~1\yit\LOCALS~1\Temp\upxdnd.exe
O4 - HKLM\..\Run: [nortone] C:\WINDOWS\nortone.exe
O4 - HKLM\..\Run: [norton] C:\WINDOWS\norton.exe
O4 - HKLM\..\Run: [msccrt] C:\WINDOWS\msccrt.exe
O4 - HKLM\..\Run: [nortonq] C:\WINDOWS\nortonq.exe
O4 - HKLM\..\Run: [dcoh] C:\WINDOWS\dcoh.exe
O4 - HKLM\..\Run: [cmdbcsg] C:\WINDOWS\cmdbcsg.exe
O4 - HKLM\..\Run: [upxdwnd] C:\DOCUME~1\yit\LOCALS~1\Temp\upxdwnd.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://home
O15 - Trusted Zone: http://home.medimmune.com
O15 - Trusted Zone: http://home.medimmune.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://remote.medimmune.com/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {6AE02E1C-8859-4F57-9097-5A55A56A4CAF} - http://images.5460.net/toolbar/webinstall/5460.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = medimmune.com
O17 - HKLM\Software\..\Telephony: DomainName = medimmune.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = medimmune.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = medimmune.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: OdysseyClient - C:\WINDOWS\SYSTEM32\odyEvent.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPCAgent.exe
O23 - Service: Virtual Com Port Service (neoNcSvc) - Unknown owner - C:\WINDOWS\system32\ncsvc.exe
O23 - Service: Odyssey Client (odClientService) - Funk Software, Inc. - C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
O23 - Service: OracleOra920ClientCache - Unknown owner - C:\ora920\BIN\ONRSD.EXE (file missing)
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
 

10.4K Posts

April 5th, 2007 15:00

july_yi

That's quite an infection you have there. It will take a couple of runs at this before we can fix it so please be patient

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
 
bamajim   Graduate of MRU
CastleCops  Instructor

6 Posts

April 5th, 2007 16:00

Thank you, bamajim!   the log is attached below.
 
"YiT" - 07-04-05 13:37:33    Service Pack 2
ComboFix 07-04-05 - Running from: "C:\Documents and Settings\yit\Desktop"

((((((((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

C:\WINDOWS\system32\jdsfdutj.dat
C:\SysAd5C\Ghook.dll
C:\SysAd5C\svchost.exe
C:\SysAd5D\Ghook.dll
C:\SysAd5D\svchost.exe
C:\SysDayN5\Ghook.dll
C:\SysDayN5\svchost.exe
C:\SysDayN6\Ghook.dll
C:\SysDayN6\svchost.exe
C:\Syswm1f\Ghook.dll
C:\Syswm1f\svchost.exe
C:\Syswm1h\Ghook.dll
C:\Syswm1h\svchost.exe
C:\SysWsj4\Ghook.dll
C:\SysWsj4\svchost.exe
C:\SysWsj5\Ghook.dll
C:\SysWsj5\svchost.exe
C:\SysWsj6\Ghook.dll
C:\SysWsj6\svchost.exe
C:\SysWsj7\Ghook.dll
C:\SysWsj7\svchost.exe
C:\SysAd5C
C:\SysAd5D
C:\SysDayN5
C:\SysDayN6
C:\Syswm1f
C:\Syswm1h
C:\SysWsj4
C:\SysWsj5
C:\SysWsj6
C:\SysWsj7

(((((((((((((((((((((((((((((((   Files Created from 2007-03-05 to 2007-04-05  ))))))))))))))))))))))))))))))))))

2007-04-05 13:23 540 --a------ C:\WINDOWS\system32\index.dat
2007-04-05 13:23   d-------- C:\WINDOWS\network diagnostic
2007-04-05 11:08   d-------- C:\Program Files\Windows Live Safety Center
2007-04-05 10:38   d-------- C:\Program Files\HJT
2007-04-05 10:30   d-------- C:\HJT
2007-04-05 09:33   d-------- C:\Program Files\Windows Defender
2007-04-05 09:31   d-------- C:\Program Files\CCleaner
2007-04-04 19:08   d-------- C:\WINDOWS\pss
2007-04-04 18:58 43,767 --a------ C:\WINDOWS\system32\D943C8B2T.EXE
2007-04-04 18:58 43,767 --a------ C:\WINDOWS\system32\D943C8B2.EXE
2007-04-04 16:14 9,401 --a------ C:\WINDOWS\system32\7AA263EE.DLL
2007-04-04 16:14 15,364 --a------ C:\WINDOWS\system32\7AA263EE.EXE
2007-04-04 16:14 15,364 ---h----- C:\rising.exe
2007-03-30 10:41 37,195 --a------ C:\WINDOWS\system32\D943C8B2.DLL
2007-03-30 10:41 26,134 --a------ C:\WINDOWS\system32\474115BE.exe
2007-03-28 15:48   d--hs---- C:\Syswm1i
2007-03-22 09:30 13,862 --a------ C:\WINDOWS\nortons.exe
2007-03-21 15:56 43,762 --a------ C:\WINDOWS\system32\2FC3F5DAT.EXE
2007-03-21 15:56 43,762 --a------ C:\WINDOWS\system32\2FC3F5DA.EXE
2007-03-21 15:56 37,190 --a------ C:\WINDOWS\system32\2FC3F5DA.DLL
2007-03-21 15:56 26,126 --a------ C:\WINDOWS\system32\8A37EDF2.exe
 
 
((((((((((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-04-05 13:31 -------- d-------- C:\Program Files\symantec antivirus
2007-03-08 11:36 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 11:36 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 11:36 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 09:47 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-05 15:29 -------- d-------- C:\Program Files\nquery advisor 6.01
2007-02-09 10:13 -------- d-------- C:\Program Files\google
 
 
((((((((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_9 -reboot 1"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
@=""
"OdTray.exe"="\"C:\\Program Files\\Funk Software\\Odyssey Client\\OdTray.exe\""
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"UpdateManager"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"vptray"="C:\\PROGRA~1\\SYMANT~1\\VPTray.exe"
"Acrobat Assistant 7.0"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"IMEKRMIG6.1"="C:\\WINDOWS\\ime\\imkr6_1\\IMEKRMIG.EXE"
"MSPY2002"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
"PHIME2002ASync"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"nortons"="C:\\WINDOWS\\nortons.exe"
"nortone"="C:\\WINDOWS\\nortone.exe"
"norton"="C:\\WINDOWS\\norton.exe"
"nortonq"="C:\\WINDOWS\\nortonq.exe"
"dcoh"="C:\\WINDOWS\\dcoh.exe"
"cmdbcsg"="C:\\WINDOWS\\cmdbcsg.exe"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDisconnect"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"66"="C:\\SysDayN6\\svchost.exe"
"50"="C:\\SysAd5D\\svchost.exe"
"333"="C:\\Syswm1i\\svchost.exe"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OdysseyClient
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
   Authentication Packages REG_MULTI_SZ    msv1_0\0\0
   Security Packages REG_MULTI_SZ    kerberos\0msv1_0\0schannel\0wdigest\0\0
   Notification Packages REG_MULTI_SZ    scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ    HTTPFilter\0\0
LocalService REG_MULTI_SZ    Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ    DnsCache\0\0
DcomLaunch REG_MULTI_SZ    DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ    RpcSs\0\0
imgsvc REG_MULTI_SZ    StiSvc\0\0
termsvcs REG_MULTI_SZ    TermService\0\0
 
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job

********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-05 13:40:06
C:\ComboFix-quarantined-files.txt ... 07-04-05 13:40

10.4K Posts

April 5th, 2007 18:00

july_yi

Your welcome

You may want to print out these instructions for reference

1. We need to make sure we can see hidden files and folders

To enable the viewing of Hidden and System files follow these steps:
  • Right click on Start and select Explore.
    Select the Tools menu and click Folder Options.
    After the new window appears select the View tab.
    Put a checkmark in the checkbox labeled Display the contents of system folders.
    Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
    Remove the checkmark from the checkbox labeled Hide protected operating system files.
    Click Yes To confirm
    Press the Apply button and then the OK button.

2. Open Notepad (Not Wordpad)
Select Edit and uncheck Wordwrap
Copy and paste the following into Notepad
(Making sure there is no space between the top of the window and the first line)

REGEDIT4

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"nortons"=-
"nortone"=-
"norton"=-
"nortonq"=-
"dcoh"=-
"cmdbcsg"=-

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDisconnect"=-

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"66"=-
"50"=-
"333"=-


After you copy and paste it your cursor should be at the end of the first line
Hit Enter so your cursor is under the last line
  • Click File->> Save as->>type in fix.reg->>
    Under " Save as type" Select " All Files"->> save it to your Desktop
    Close Notepad

The fix.reg file should now appear on your Desktop

Rt Click and Select merge->>If prompted to Merge this Select Yes (it will appear that nothing has happened but that's o.k.)

3. Using Windows Explorer
  • (Right click on "Start," select "Explore," and you will see the "tree' of file folders in the left side of the window. Click on the "+" next to any folder name to expand its contents)

Locate and Delete (To delete, Rt Click->>Select Delete) the following folders
  • C:\Syswm1i
    C:\SysDayN6
    C:\SysAd5D


Close Windows explorer

4. Please download the Killbox.
  • 1)Save it to the desktop and run it.
    2) Select " Delete on Reboot", and then select "All files".
    3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:

    • C:\WINDOWS\system32\D943C8B2T.EXE
      C:\WINDOWS\system32\D943C8B2.EXE
      C:\WINDOWS\system32\7AA263EE.DLL
      C:\WINDOWS\system32\7AA263EE.EXE
      C:\rising.exe
      C:\WINDOWS\system32\D943C8B2.DLL
      C:\WINDOWS\system32\474115BE.exe
      C:\WINDOWS\nortons.exe
      C:\WINDOWS\system32\2FC3F5DAT.EXE
      C:\WINDOWS\system32\2FC3F5DA.EXE
      C:\WINDOWS\system32\2FC3F5DA.DLL
      C:\WINDOWS\system32\8A37EDF2.exe
      C:\WINDOWS\nortons.exe
      C:\WINDOWS\nortone.exe
      C:\WINDOWS\norton.exe
      C:\WINDOWS\nortonq.exe
      C:\WINDOWS\dcoh.exe
      C:\WINDOWS\cmdbcsg.exe


    4) Return to Killbox, go to the File menu, and choose " Paste from Clipboard".
    5) Click the red-and-white " Delete File" button.  Click " Yes" at the Delete on Reboot prompt.  Click " No" at the Pending Operations prompt.
5. Reboot your PC->>Rerun Hijackthis and post a frresh Hijackthis log
 
bamajim   Graduate of MRU
CastleCops  Instructor






Message Edited by bamajim on 04-05-2007 03:30 PM

6 Posts

April 5th, 2007 19:00

bamajim,

   Thank you again!  I followed your instructions. Howerver, these files couldn't be deleted by killbox.

 C:\WINDOWS\nortons.exe
C:\WINDOWS\nortone.exe
C:\WINDOWS\norton.exe
C:\WINDOWS\nortonq.exe
C:\WINDOWS\dcoh.exe
C:\WINDOWS\cmdbcsg.exe

   So I deleted them via hijackthis. Hope it will be okay.  I attached the new hjt.log below:

 

Logfile of HijackThis v1.99.1
Scan saved at 16:23, on 07-04-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\iPass\iPassConnect\iPCAgent.exe
C:\WINDOWS\system32\ncsvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Funk Software\Odyssey Client\OdTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPass\iPassConnect\downloader\ipccheck.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HJT\HJT.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.new114.com.cn:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [OdTray.exe] "C:\Program Files\Funk Software\Odyssey Client\OdTray.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://home
O15 - Trusted Zone: http://home.medimmune.com
O15 - Trusted Zone: http://home.medimmune.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://remote.medimmune.com/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {6AE02E1C-8859-4F57-9097-5A55A56A4CAF} - http://images.5460.net/toolbar/webinstall/5460.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1175786905448
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = medimmune.com
O17 - HKLM\Software\..\Telephony: DomainName = medimmune.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = medimmune.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = medimmune.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: OdysseyClient - C:\WINDOWS\SYSTEM32\odyEvent.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: 2FC3F5DA - Unknown owner - C:\WINDOWS\system32\2FC3F5DA.EXE (file missing)
O23 - Service: 7AA263EE - Unknown owner - C:\WINDOWS\system32\7AA263EE.EXE (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: D943C8B2 - Unknown owner - C:\WINDOWS\system32\D943C8B2.EXE (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPCAgent.exe
O23 - Service: Virtual Com Port Service (neoNcSvc) - Unknown owner - C:\WINDOWS\system32\ncsvc.exe
O23 - Service: Odyssey Client (odClientService) - Funk Software, Inc. - C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
O23 - Service: OracleOra920ClientCache - Unknown owner - C:\ora920\BIN\ONRSD.EXE (file missing)
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

 

 

10.4K Posts

April 5th, 2007 23:00

july_yi

That's o.k good job.

1. Rerun Hiackthis (scan only) and place checks beside the following entries
  • O23 - Service: 2FC3F5DA - Unknown owner - C:\WINDOWS\system32\2FC3F5DA.EXE (file missing)
    O23 - Service: 7AA263EE - Unknown owner - C:\WINDOWS\system32\7AA263EE.EXE (file missing)
    O23 - Service: D943C8B2 - Unknown owner - C:\WINDOWS\system32\D943C8B2.EXE (file missing)
Close all other open windows except Hijackthis and Select " Fix checked"

Close Hijackthis and reboot your PC

2. Go here and Download AVG Anti-Spyware
( 30 day free trial version) Save it to Your Desktop
 
Double Click AVG Anti-Spyware-setup
(It will create its own folder)
Once the program starts You will be at the Status menu
  • Under "Your computers Security"
    Click Update now (next to last update)
    After the update loads
    Under Automatic updates Uncheck download and install updates automatically(recommended)
    (you can always select maual updates the next day)

At the top toolbar Click Scanner Then the settings tab
  • Under How to act? Set default action for detected malwareTo Quarantine
    Under how to scan All boxes should be checked
    Under Possibly unwanted software All boxes should be checked
    Under reports Select Automatically generate report after every scan
    Uncheck Only if threats were found
    Under what to scan Scan every file should be highlited
Exit AVG(But do not run it yet)
 
Reboot into Safe Mode
This can be done by
  • Restart your PC, and after it starts, but before you see the Windows Splash screen
    Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
    Use your arrow keys and select Safe Mode and then Enter

Run AVG Anti-Spyware
  • Click scanner
    Select Complete system scan
Once the scan finishes
  • Select Apply all actions (The items found will be quarantined)
    Click save report as (Another window will open)
    Save it to your desktop
    (By default It will be saved in the AVG folder as)
    C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports
Exit AVG
 
Reboot your PC in Normal Mode->>Re run Hijackthis and post a fresh Hijackthis log.
  • Double click the report-scan txt. you saved to your desktop
    It will open in Notepad
    Copy and paste that report as a reply to this thread
Your reply should include
  • a fresh Hijackthis log
    your report_scan.txt log from AVG
      bamajim   Graduate of MRU
      CastleCops Instructor


      6 Posts

      April 6th, 2007 02:00

      bamajim,
       
          I don't have the right to log into my computer in the safe mode. I am wondering if I can run AVG Anti-Spyware in the normal mode?  Thanks again!

      10.4K Posts

      April 6th, 2007 11:00

      july_yi
       
      If thats all you can use. Then do it in Normal Mode
       
      bamajim   Graduate of MRU
      CastleCops  Instructor

      10.4K Posts

      April 6th, 2007 14:00

       
      You are most welcome.
      How's your PC running Now?
       
      bamajim   Graduate of MRU
      CastleCops  Instructor

      6 Posts

      April 6th, 2007 14:00

      bamajim,
       
           I attached the HJT.log and AVG scan report below.  Thank you very much for your help!
       
      july_yi
       
       
      Logfile of HijackThis v1.99.1
      Scan saved at 10:59, on 07-04-06
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16414)
      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
      C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\Symantec AntiVirus\DefWatch.exe
      C:\Program Files\iPass\iPassConnect\iPCAgent.exe
      C:\WINDOWS\system32\ncsvc.exe
      C:\Program Files\Symantec AntiVirus\SavRoam.exe
      C:\Program Files\Symantec AntiVirus\Rtvscan.exe
      C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
      C:\WINDOWS\system32\CCM\CcmExec.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\msiexec.exe
      C:\Program Files\Funk Software\Odyssey Client\OdTray.exe
      C:\WINDOWS\system32\dla\tfswctrl.exe
      C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\Program Files\iPass\iPassConnect\downloader\ipccheck.exe
      C:\PROGRA~1\SYMANT~1\VPTray.exe
      C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\MSN Messenger\MsnMsgr.Exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\HJT\HJT.exe
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
      O4 - HKLM\..\Run: [OdTray.exe] "C:\Program Files\Funk Software\Odyssey Client\OdTray.exe"
      O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
      O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
      O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
      O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
      O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
      O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKLM\..\Run: [Google IME Autoupdater] "C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe"
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O11 - Options group: [INTERNATIONAL] International*
      O14 - IERESET.INF: START_PAGE_URL=http://home
      O15 - Trusted Zone: http://home.medimmune.com
      O15 - Trusted Zone: http://home.medimmune.com (HKLM)
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://remote.medimmune.com/dana-cached/setup/NeoterisSetup.cab
      O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1175786905448
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = medimmune.com
      O17 - HKLM\Software\..\Telephony: DomainName = medimmune.com
      O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = medimmune.com
      O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = medimmune.com
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
      O20 - Winlogon Notify: OdysseyClient - C:\WINDOWS\SYSTEM32\odyEvent.dll
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
      O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPCAgent.exe
      O23 - Service: Virtual Com Port Service (neoNcSvc) - Unknown owner - C:\WINDOWS\system32\ncsvc.exe
      O23 - Service: Odyssey Client (odClientService) - Funk Software, Inc. - C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
      O23 - Service: OracleOra920ClientCache - Unknown owner - C:\ora920\BIN\ONRSD.EXE (file missing)
      O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
      O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
       
       
       
      ---------------------------------------------------------
      AVG Anti-Spyware - Scan Report
      ---------------------------------------------------------
       + Created at: 10:47 07-04-06
       + Scan result: 
       
      HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6AE02E1C-8859-4F57-9097-5A55A56A4CAF} -> Adware.MyTool : Cleaned with backup (quarantined).
      C:\Documents and Settings\All Users\Application Data\webex\ieatgpc.dll -> Adware.WebEx : Cleaned with backup (quarantined).
      C:\!KillBox\2FC3F5DA.DLL -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
      C:\!KillBox\2FC3F5DA.DLL( 3) -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
      C:\!KillBox\2FC3F5DA.EXE -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
      C:\!KillBox\2FC3F5DA.EXE( 4) -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
      C:\!KillBox\2FC3F5DAT.EXE -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
      C:\!KillBox\2FC3F5DAT.EXE( 5) -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
      C:\!KillBox\474115BE.exe -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
      C:\!KillBox\474115BE.exe( 7) -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
      C:\!KillBox\8A37EDF2.exe -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
      C:\!KillBox\8A37EDF2.exe( 2) -> Backdoor.Agent.ahj : Cleaned with backup (quarantined).
      C:\Documents and Settings\yit\Cookies\yit@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
      C:\Documents and Settings\yit\Cookies\yit@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
      C:\Documents and Settings\yit\Cookies\yit@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
      C:\Documents and Settings\Administrator\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\Default User\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\JankowskiJ\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\corothersn\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\frenchgw\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\lious\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\mcguinc\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\murphymf.MEDIMMUNE\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\owensk\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\santiagoj\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\ullaha\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\wa_imagebuilder\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\yit\Cookies\yit@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\yit\Cookies\yit@atdmt[3].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\zhouy\Cookies\wa_imagebuilder@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\yit\Cookies\yit@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
      C:\Documents and Settings\yit\Cookies\yit@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
      C:\Documents and Settings\yit\Cookies\yit@media.fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
      C:\Documents and Settings\yit\Cookies\yit@ehg-morningstar.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\yit\Cookies\yit@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\yit\Cookies\yit@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
      C:\Documents and Settings\yit\Cookies\yit@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
      C:\Documents and Settings\yit\Cookies\yit@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
      C:\Documents and Settings\yit\Cookies\yit@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
      C:\Documents and Settings\yit\Cookies\yit@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
      C:\Documents and Settings\yit\Cookies\yit@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
      C:\Documents and Settings\yit\Cookies\yit@ad.yieldmanager[3].txt -> TrackingCookie.Yieldmanager : Cleaned.
      C:\QooBox\Quarantine\SysAd5C\Ghook.dll.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\SysDayN5\svchost.exe.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\SysWsj4\Ghook.dll.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\SysWsj5\Ghook.dll.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\SysWsj5\svchost.exe.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\SysWsj6\Ghook.dll.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\SysWsj7\Ghook.dll.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\Syswm1f\Ghook.dll.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\Syswm1f\svchost.exe.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\Syswm1h\Ghook.dll.vir -> Trojan.OnLineGames.jj : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\SysAd5C\svchost.exe.vir -> Trojan.OnLineGames.kt : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\SysAd5D\svchost.exe.vir -> Trojan.OnLineGames.kt : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\SysDayN5\Ghook.dll.vir -> Trojan.OnLineGames.kt : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\SysDayN6\Ghook.dll.vir -> Trojan.OnLineGames.kt : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\SysDayN6\svchost.exe.vir -> Trojan.OnLineGames.kt : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\SysWsj4\svchost.exe.vir -> Trojan.OnLineGames.kt : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\SysWsj6\svchost.exe.vir -> Trojan.OnLineGames.kt : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\Syswm1h\svchost.exe.vir -> Trojan.OnLineGames.kt : Cleaned with backup (quarantined).
      C:\!KillBox\nortons.exe -> Trojan.OnLineGames.ld : Cleaned with backup (quarantined).
      C:\!KillBox\nortons.exe( 6) -> Trojan.OnLineGames.ld : Cleaned with backup (quarantined).
      C:\QooBox\Quarantine\SysWsj7\svchost.exe.vir -> Trojan.OnLineGames.mf : Cleaned with backup (quarantined).

      ::Report end
       
       
       

      6 Posts

      April 6th, 2007 15:00

      bamajim,
       
         It runs well now.  Thank you!
       
      july_yi

      10.4K Posts

      April 6th, 2007 15:00

      july_yi

      You may now remove/delete/uninstall the tools we used to clean your PC

      Now that your log is clean

      There are some final notes:
      Disable and Enable System Restore
      • Lets create a clean System Restore point
        the instructions are here
      Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
      Please follow these steps to remove older version Java components and update.

      Updating Java:
      • Download the latest version of
        Java Runtime Environment (JRE) 6.1.
        Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
        Click the " Download" button to the right.
        Check the box that says: " Accept License Agreement".
        The page will refresh.
        Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
        Close any programs you may have running - especially your web browser.
        Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
        Check any item with Java Runtime Environment (JRE or J2SE) in the name.
        Click the Remove or Change/Remove button.
        Repeat as many times as necessary to remove each Java versions.
        Reboot your computer once all Java components are removed.
        Then from your desktop double-click on jre-6-windowsi586-p.exe to install the newest version.
      Make your Internet Explorer more secure
      This can be done by following these simple instructions:
      • Open Internet Explorer click Tools->> Options.
        Click Security tab
        Click once on the Internet icon so it becomes highlighted.
        Click Custom Level.
        Change the Download signed ActiveX controls to Prompt
        Change the Download unsigned ActiveX controls to Disable
        Change the Initialise and script ActiveX controls not marked as safe to Disable
        Change the Installation of desktop items to Prompt
        Change the Launching programs and files in an IFRAME to Prompt
        Change the Navigate sub-frames across different domains to Prompt
        When all these settings have been made, click OK.
        If it prompts you to save the settings, press Yes.
        Next press Apply and then OK to exit the Internet Properties page
      Update your Anti Virus Software

      Use and maintain a Firewall such as ZoneAlarm
      • The Windows Firewall is good at blocking incoming threats, but not outgoing threats such as "Backdoor Trojans"
        Some others are
        Sygate
        And
        Sunbelt personal
        All of which are free
      Install IE SPYAD for protection against innocent looking websites that are not innocent

      Visit Microsoft's Windows Update Site Frequently for critical updates

      Backup your Important Documents and Files on a regular basis
      • To a disc or a USB key, not your Hardrive
      You may want to read this article" So how did I get infected in the first place" by Tony Klein

      surf safe
       
      bamajim   Graduate of MRU
      CastleCops  Instructor

      No Events found!

      Top