Unsolved

This post is more than 5 years old

13 Posts

1094

September 10th, 2005 14:00

IM's HijackThis Log - Help: which files to delete?

Hello experts!

 

Is someone able to help? what files can i delete from my comp?

In my computer the screensaver still displays "Warning... etc etc... click here to download spyware removal software". Previous Spybot scans show Smitfraud-C (43 problems) can't be deleted because it is still running.

 

 

Prob: i cannot go online with the infected comp: it gets immediately bombarded. So i cant update spywarre removers' definitons!!

I hv installed (besides HJT) Spysweeper, SmitfraudC-Fix, AdAware (but definitions r 19 days old); Bazooka (176 days old definitions); Spyware Doctor CWShredder.

 

Thank you for your help!!

IM

 

\\Logfile of HijackThis v1.99.1

Scan saved at 9:05:20 PM, on 9/10/2005

Platform: Windows XP  (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

C:\Program Files\Norton Internet Security\ISSVC.exe

C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\System32\shnlog.exe

C:\WINDOWS\System32\msole32.exe

C:\Program Files\MessengerPlus! 3\MsgPlus.exe

C:\WINDOWS\System32\intell32.exe

C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\Spyware Doctor\spydoctor.exe

C:\WINDOWS\System32\intmon.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\WINDOWS\System32\wuauclt.exe

C:\WINDOWS\Explorer.EXE

C:\HJT\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oneclicksearches.com/search.php?qq=%1

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.oneclicksearches.com/bar.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.oneclicksearches.com/search.php?qq=%1

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.oneclicksearches.com/search.php?qq=%1

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.oneclicksearches.com/search.php?qq=%1

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.oneclicksearches.com/search.php?qq=%1

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.oneclicksearches.com/

F2 - REG:system.ini: Shell=Explorer.exe, msmsgs.exe

O2 - BHO: HP Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINDOWS\System32\hp7946.tmp

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll (file missing)

O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (file missing)

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll (file missing)

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe

O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe

O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"

O4 - HKLM\..\Run: [RegSvr32] C:\WINDOWS\System32\msmsgs.exe

O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\System32\intell32.exe

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe

O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\spydoctor.exe" /Q

O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab

O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by17fd.bay17.hotmail.msn.com/resources/MsnPUpld.cab

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab30149.cab

O16 - DPF: {97AFC0D9-660E-4ACE-B025-46FD64AE335A} (EmailImport.EmailImportControl) - http://www.friendster.com/emailimport/ms/emailimport.cab

O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) - http://blackbass.multiply.com/photos/uploader.cab

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab

O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab

O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - http://lg.home.microsoft.com/search/lobby/searchsettings.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab30149.cab

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe

O23 - Service: License Management Service ESD - element5 - C:\Program Files\Common Files\element5 Shared\Service\Licence Manager ESD.exe

O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

4 Apprentice

 • 

8.8K Posts

September 10th, 2005 17:00

Hi
Before anyone can help you, your need to update your OS to Security Pack 1a. This can be done at the M$ homepage.

If we even try to fix it now, it will get infected again immediately without a Security Pack running.

Don't install SP2.

Steve

4 Apprentice

 • 

8.8K Posts

September 11th, 2005 01:00

Are you sure that SP2 is installed in the system? I would double check on that as it is not reflected in the header of your HJT log as it should be.

Do not install SP1a now, but we have to find out if SP2 is really installed.

Do this, click on Start/ControlPanel/System. In the front tab it will give you your processor and the amount of RAM that is installed. It will also show you what SP is installed on that first tab.

Let me know

Steve

13 Posts

September 11th, 2005 01:00

Hi Steve

The 'General' panel of System properties jus states, under "Computer:" --> Intel(R) Pentium(R) 4 CPU 2.40GHz 2.39GHz 512MB of RAM .

I think i hv SP2 because under Add/Remove Programs i hv Windows XP Hotfix (SP2) [See Q329115 for more information]. Above this item are 25 items that states Hotfix (SP1)

Yup thats that... so i wonder if i hv SP2
 
IM

13 Posts

September 11th, 2005 01:00

Hi zbestwun

Thanx for your reply. I hv just downloaded SP1a.

But i am not installing it yet in the infected PC because...

I hv installed SP2 before... you metioned DO NOT install SP2. Does this mean i shld uninstall SP2 before i install SP1a?

And after installing SP1a, do i need to run HJTscan again and post the new log on this forum?

Thank you!

IM

4 Apprentice

 • 

8.8K Posts

September 11th, 2005 01:00

This is strange.

A hotfix isn't SP2.

Let me research this.

Steve

4 Apprentice

 • 

8.8K Posts

September 11th, 2005 02:00

IM

OK I have a fix for SmitFraud, that's not what concerns me. The fact that you think you have SP2 installed and all signs point to it not being installed.

We can try to remove SF using this fix. If you have no SP installed you will get slammed again with something.

Here is the fix we use for removeing SmitFraud.

Please read these instructions carefully and print them out! Be sure to follow ALL instructions!

Please right-click: HERE and go to Save As (in Internet Explorer it's "Save Target As") in order to download Grinler's reg file. Save it to your desktop.

Locate " smitfraud.reg" on your desktop and double-click it. When asked if you want to merge with the registry, click YES. Wait for the "merged successfully" prompt then follow the rest of the instructions below.

Go to Start > Control Panel > Add or Remove Programs and remove the following programs, if found:

Security IGuard
Virtual Maid
Search Maid


Exit Add/Remove Programs.

*IMPORTANT* CLICK THIS LINK TO LEARN HOW TO VIEW HIDDEN FILES

I need you to copy all of the Killbox file paths below and paste them into Notepad.

* Please download the Killbox by Option^Explicit. *In the event you already have Killbox, this is a new version that I need you to download.

* Unzip to your desktop.

* Please double-click Killbox.exe to run it.

* Select " Delete on Reboot".

* Open the Notepad file where you saved the file paths earlier and copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C

C:\wp.exe
C:\wp.bmp
C:\bsw.exe
C:\Windows\sites.ini
C:\Windows\popuper.exe
C:\Windows\system32\hhk.dll
C:\Windows\System32\wldr.dll
C:\Windows\System32\helper.exe
C:\Windows\System32\intmon.exe
C:\Windows\System32\shnlog.exe
C:\Windows\System32\intmonp.exe
C:\Windows\System32\msmsgs.exe
C:\Windows\system32\msole32.exe
C:\Windows\System32\ole32vbs.exe


* Return to Killbox, go to the File menu, and choose " Paste from Clipboard".

* Click the red-and-white " Delete File" button. Click " Yes" at the Delete on Reboot prompt. Click " No" at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually.

While your computer is restarting, tap the F8 key continually until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.

Make sure you can view hidden files.

Using Windows Explorer, delete the following, if found, ( please do NOT try to find them by "search" because they will not show up that way)

FOLDERS to delete (in bold) if found:

C:\Program Files\ Search Maid
C:\Program Files\ Virtual Maid
C:\Windows\System32\ Log Files
C:\Program Files\ Security IGuard

While still in Safe Mode, do the following:

Make sure all programs and windows are closed. Run HiJackThis and place a check next to the following items, if found, then click FIX CHECKED

items to fix

Close HiJackThis.

Reboot into normal mode.

1.) Download The Hoster Press "Restore Original Hosts" and press "OK". Exit Program.

2.) Right-Click HERE and Save As to download DelDomains.inf to your desktop.
To use: RIGHT-CLICK DelDomains.inf on your desktop and select: Install (no need to restart)
Note: This will remove all entries in the "Trusted Zone" and "Ranges" also.

3.) Download, install, and run CleanUp!

4.) Run this online virus scan: ActiveScan - Save the results from the scan!

Post a new HiJackThis log along with the results from ActiveScan.

Steve

13 Posts

September 11th, 2005 02:00

Thanx Steve.

i hope this will prove to be the root  of the problem. Smitfraud-C appears impossible to remove from my comp so far. This despite having done the following:

1) Installing the Smithfraud-C fix from http://support.winantivirus.com/files/smitfraudC_Fix.zip that is supposed to remove the registry keys associated with Smithfraud-C

2) and the Smitfraud-C reg file that has been merged with my comp Reg (advice in http://www.short-media.com/forum/showthread.php?t=32218, the reg file fr http://www.bleepingcomputer.com/files/reg/smitfraud.reg)

IM

4 Apprentice

 • 

8.8K Posts

September 11th, 2005 03:00

Don't worry I just want to be sure of what's going on, I don't want to complicate things.

Here is a link where you can find ActiveScan. http://www.pandasoftware.com/products/activescan.htm

Don't install any Security Packs untill I tell you to pleases.

By tomorrow morning I will have an answer on this problem.

I'd just wait untill tomorrow when I get back to you before continuing. Don't worry...this is fixable.

Steve

13 Posts

September 11th, 2005 03:00

Hi Steve
ok i have finished downloading all files and saved them onto my external hard disk to plug into my infected PC later (i am using a borrowed laptop to speak with u)
 
all files, save activescan because the link in your message directs me to this URL but there is an error message : "The page cannpt be found"
 
could you resend the link?
 
Also must I install SP1a first before following all the steps u  listed for SF removal?
But is this ok considering the SP2 puzzle?
 
worried, and apologetic
IM

13 Posts

September 11th, 2005 03:00

oh ok i will wait for confirmation of the exact problem of course... i assumed from the instructions u gave that it was for immediate action. sorry abt that

thank u and till Mon then.. hv a gd weekend!

IM

13 Posts

September 11th, 2005 03:00

Thanx Steve... the steps are v long!!

I hv started downloading and keeping in notepad some of the files and instructions.

Do i do this only AFTER i install SP1a?

 

IM 

4 Apprentice

 • 

8.8K Posts

September 11th, 2005 05:00

If you did that SmitFraud fix, that's fine, just post a new HJT log and tell me if that warning went away?

Also go ahead and install SP1a now and then post a fresh log.

Stevev

Message Edited by zbestwun2001 on 09-10-2005 11:20 PM

13 Posts

September 12th, 2005 05:00

Thanx Steve

I can only install SP1a and do the SF fix tomorrow morning, as I will be working till very late tonight.

Is it alright if i do the SF fix without running ActiveScan? I may have problems going online with my affected PC and ActiveScan requires going online to run it. Will running HJT scan be enough?

 

Imran

4 Apprentice

 • 

8.8K Posts

September 12th, 2005 13:00

We can try that and see if it works, but you should be able to run ActiveScan.

Steve

Message Edited by zbestwun2001 on 09-12-2005 08:48 AM

13 Posts

September 13th, 2005 05:00

Hi Steve
 
I started on the steps you gave me this morning. This was what happened:
 
1) after merging smitfraud.reg to my regustry and searching "Add/Remove Programs" none of the three programs were found. But i just read that i must uncheck "Hide protected operating system files" so i will try this step again later when i get home
 
2) Using Killbox.exe: I tried cutting and pasting from clipboard the full list of filepaths for Killbox to "Delete on Reboot", but somehow it could not be pasted all at once.
 
2a. I tried pasting one filepath at a time and rebooting but during rebooting with F8 pressed, a message came out on DOS screen "Keyboard failure" and my keyboard and mouse refused to work
 
2b. So i shut down and reboot again in normal mode and tried the Killbox direct deletion option without rebooting. Several times this error window came up: "Pending File Rename Operations Registry Data has been Removed by External Process!"
 
Nevertheless i pasted every single filepath into Killbox and pressed delete, and every time a window pops up to say filepath does not exist
 
3) After i finished trying to delete each filepath separately using Killbox, in Windows Explorer i chanced upon this new folder in my C:\ called " !Submit" and looked in it. I found the following application files and one DLL file:
 
intmon.exe
intmonp.exe
msmsgs.exe
shnlog.exe
ole32vbs.exe
popuper.exe
hhk.dll
 
Needless to say i deleted the whole folder and reboot the comp
 
4) To my delight, my comp desktop was back to its normal blue - the Warning page with "Click here to download anti-spyware" was gone!
 
5) In the instruction set u gave me, I am to run HJT in Safe Mode and place a check next to certain items if found and to click "Fix Checked". But the instruction set u gave me seems to have omitted the list of items.
 
Could you send me the list of items to fix using HJT while in safe mode?
 
6) I reboot my comp twice to run spyware, spysweeper and Ad-Aware to see what other viruses or trojans remained. This is the result:
 
1st reboot:
Spybot: found 51 problems related to Smitfraud-C - deleted 8, but cld not delete 43
 
Spysweeper: found and deleted 1 adware Virtualmaid toolbar & 11 traces
 
2nd reboot:
Spybot: found 49 problems related to Smitfraud-C - deleted 6, but cld not delete 43
 
Spysweeper: no problems found
 
Ad-Aware (112 days old definitions): no problems found
 
So it seems only Smitfraud-C remains
 
 
IM
 
 
 
 
No Events found!

Top