Start a Conversation

Unsolved

This post is more than 5 years old

327

May 27th, 2006 16:00

Help with virus

​ I have a virus where i cant change my homepage. ​
​ ​
​Logfile of HijackThis v1.99.1 ​
​Scan saved at 12:04:07 PM, on 5/27/2006 ​
​Platform: Windows XP SP2 (WinNT 5.01.2600) ​
​MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) ​
​ ​
​Running processes: ​
​C:\WINDOWS\System32\smss.exe ​
​C:\WINDOWS\system32\winlogon.exe ​
​C:\WINDOWS\system32\services.exe ​
​C:\WINDOWS\system32\lsass.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\Program Files\Windows Defender\MsMpEng.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\WINDOWS\Explorer.EXE ​
​C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe ​
​C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe ​
​C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe ​
​C:\WINDOWS\system32\LEXBCES.EXE ​
​C:\WINDOWS\system32\spoolsv.exe ​
​C:\WINDOWS\system32\LEXPPS.EXE ​
​C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe ​
​C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe ​
​C:\Program Files\Alwil Software\Avast4\ashServ.exe ​
​C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe ​
​C:\Program Files\Norton AntiVirus\navapsvc.exe ​
​C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe ​
​C:\WINDOWS\System32\nvsvc32.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ​
​C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe ​
​C:\Program Files\Alwil Software\Avast4\ashWebSv.exe ​
​C:\WINDOWS\system32\dcomcfg.exe ​
​C:\Program Files\Common Files\Symantec Shared\ccApp.exe ​
​C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe ​
​C:\Program Files\MSN Messenger\msnmsgr.exe ​
​C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe ​
​C:\Program Files\Internet Explorer\iexplore.exe ​
​C:\Program Files\Internet Explorer\iexplore.exe ​
​C:\Program Files\Messenger\msmsgs.exe ​
​C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX00.859\Hijac kThis.exe ​
​C:\Program Files\Internet Explorer\iexplore.exe ​
​ ​
​R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = ​
​ ​
​ ​​http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com​​ ​
​O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program ​
​ ​
​Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ​
​O2 - BHO: (no name) - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - (no file) ​
​O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - ​
​ ​
​C:\PROGRA~1\SPYBOT~1\SDHelper.dll ​
​O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program ​
​ ​
​Files\Norton AntiVirus\NavShExt.dll ​
​O2 - BHO: Nothing - {f79fd28e-36ee-4989-aa61-9dd8e30a82fa} - ​
​ ​
​C:\WINDOWS\system32\hp100.tmp ​
​O3 - Toolbar: 3DNA Toolbar - {2ECB7FB2-0333-416F-92FD-4904AD49252B} - ​
​ ​
​C:\WINDOWS\system32\3DNATO~1.DLL ​
​O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program ​
​ ​
​Files\Norton AntiVirus\NavShExt.dll ​
​O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program ​
​ ​
​Files\Yahoo!\Companion\Installs\cpn1\yt.dll ​
​O3 - Toolbar: SecurityToolbar - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - C:\Program ​
​ ​
​Files\Security Toolbar\Security Toolbar.dll ​
​O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" ​
​O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe ​
​O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE ​
​ ​
​C:\WINDOWS\system32\NvCpl.dll,NvStartup ​
​O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe ​
​ ​
​/Consumer ​
​O4 - HKLM\..\Run: [Ad-watch] C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe ​
​O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h ​
​O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background ​
​O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" ​
​ ​
​-quiet ​
​O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe ​
​O4 - Global Startup: m-trip Launcher.lnk = ? ​
​O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present ​
​O8 - Extra context menu item: &Search - ​
​ ​
​ ​​http://ka.bar.need2find.com/KA/menusearch.html?p=KA​ ​
​O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program ​
​ ​
​Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll ​
​O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} ​
​ ​
​- C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll ​
​O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and ​
​ ​
​Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing) ​
​O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - ​
​ ​
​C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe ​
​O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - ​
​ ​
​C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe ​
​O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program ​
​ ​
​Files\Messenger\msmsgs.exe ​
​O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - ​
​ ​
​C:\Program Files\Messenger\msmsgs.exe ​
​O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll ​
​O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - ​
​ ​
​ ​​http://messenger.zone.msn.com/binary...r.cab31267.cab​​ ​
​O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - ​
​ ​
​ ​​http://housecall60.trendmicro.com/housecall/xscan60.cab​​ ​
​O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - ​
​ ​
​ ​​http://www.kaspersky.com/kos/english...an_unicode.cab​​ ​
​O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - ​
​ ​
​ ​​http://messenger.zone.msn.com/binary...t.cab31267.cab​​ ​
​O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage ​
​ ​
​Validation Tool) - ​​http://go.microsoft.com/fwlink/?linkid=39204​​ ​
​O16 - DPF: {18871EA7-1B30-46DE-9283-E96E707492BA} (Playcom_ATL_Object Class) - ​
​ ​
​ ​​http://www.netbabyworld.com/media/playcom/Playcom.cab​​ ​
​O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} - ​
​ ​
​ ​​http://www.miniclip.com/platypus/miniclipGameLoader.dll​​ ​
​O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - ​
​ ​
​ ​​http://us.chat1.yimg.com/us.yimg.com...45/yacscom.cab​​ ​
​O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - ​
​ ​
​ ​​http://us.dl1.yimg.com/download.yaho...st_current.cab​​ ​
​O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - ​
​ ​
​ ​​http://spaces.msn.com//PhotoUpload/MsnPUpld.cab​​ ​
​O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - ​
​ ​
​ ​​http://security.symantec.com/sscv6/S.../bin/cabsa.cab​​ ​
​O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - ​
​ ​
​ ​​http://update.microsoft.com/microsof...site.cab?11415​​ ​
​ ​
​90994171 ​
​O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - ​
​ ​
​ ​​http://housecall65.trendmicro.com/ho...vex/hcImpl.cab​​ ​
​O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - ​
​ ​
​ ​​https://www.gamespyid.com/alaunch.cab​​ ​
​O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - ​
​ ​
​ ​​http://a840.g.akamai.net/7/840/537/2...all/xscan53.ca​​ ​
​ ​
​b ​
​O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - ​
​ ​
​ ​​http://chat.yahoo.com/cab/yacsui.cab​​ ​
​O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - ​
​ ​
​ ​​http://www.worldwinner.com/games/shared/wwlaunch.cab​​ ​
​O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - ​
​ ​
​ ​​http://messenger.zone.msn.com/binary...t.cab31267.cab​​ ​
​O16 - DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} (WebCam Control) - ​
​ ​
​ ​​http://www.webcamnow.com/broadcast/ActiveXWebCam.cab​​ ​
​O16 - DPF: {AC120B1D-9411-4111-AF52-118052D85D45} (GameDesire Darts Games) - ​
​ ​
​ ​​http://67.15.101.3/g_bin/eng/darts_2_0_0_29.cab​​ ​
​O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl ​
​ ​
​Class) - ​​http://messenger.msn.com/download/Ms...Downloader.cab​​ ​
​O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - ​
​ ​
​ ​​http://zone.msn.com/binFramework/v10...o.cab34246.cab​​ ​
​O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) ​
​ ​
​- ​​http://download.toontown.com/sv1.0.15.22/ttinst.cab​​ ​
​O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - ​

8 Posts

May 27th, 2006 16:00

Continued...


http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -

http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) -

http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) -

http://www.worldwinner.com/games/v51...ol/h2hpool.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} -

"C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} -

"C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program

Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program

Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil

Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil

Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil

Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program

Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. -

C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation -

C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates

Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: MrobeService - OLYMPUS IMAGING CORP. -

C:\WINDOWS\system32\MRobeService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. -

C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation -

C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation -

C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner -

%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton

AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -

C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common

Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common

Files\Symantec Shared\Security Center\SymWSC.exe

8 Posts

May 27th, 2006 19:00

Wow dell seems to always be a big help.....

20.5K Posts

May 28th, 2006 01:00

You seem to be running more than one anti-virus program. That is not advisable because it can cause conflicts and slowdowns. I suggest that you use the vendor's instructions to uninstall one of those completely and leave only one running in realtime.

Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
or from here: http://siri.geekstogo.com/SmitfraudFix.zip
Extract all the files to your Desktop. A folder named SmitfraudFix will be created on your Desktop.
______________________________

Please download the trial version of Ewido Anti-malware 3.5 from here:
http://www.ewido.net/en/download/
  • Install Ewido Anti-malware.
  • When installing, under Additional Options uncheck Install background guard and Install scan via context menu.
  • When you run Ewido for the first time, you could get a warning "Database could not be found!". Click Ok.
  • The program will prompt you to update. Click the Ok button.
  • The program will now go to the main screen.
You will need to update Ewido to the latest definition files.
  • On the left-hand side of the main screen click the Update Button.
  • Click on Start.
The update will start and a progress bar will show the updates being installed.If you are having problems with the updater, you can use this link to manually update Ewido.
http://download.ewido.net/ewido-signatures-full-current.exe

Once finished updating, close Ewido.
Make sure to close Ewido before installing the update.
______________________________

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter
This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool";. It is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.


IMPORTANT: Do NOT run any other options until you are asked to do so!

The spacing in your HJT log makes it difficult to read and makes the posts really long. Please open Notepad. Go to Format>Uncheck Wordwrap.
Delete your copy of Hijackthis. We need one that is located in its own folder. Yours has not been extracted from the .zip. Please delete your copy and download a self-extractable version.
Click HERE to download a self-extractable version of HijackThis.
  • Double click on hijackthis.exe to extract hijackthis to folder c:\hijackthis.
  • It will extract it to that folder and open the folder for you.
  • It will also create a shortcut on your desktop to HijackThis.

  • It will scan and the log should open in notepad.Click on "Edit > Select
  • All" then click on "Edit > Copy" to copy the entire contents of the
  • log.
Come back here to this thread and Paste the log in your next reply.
DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.

Please post the report from SmitfraudFix (rapport.txt) and a fresh HijackThis log. Thanks.
No Events found!

Top