Unsolved
This post is more than 5 years old
40 Posts
0
1731
February 25th, 2005 00:00
Trojans!!! Someone Please Help Me!
I just keep having problems. Could someone help me or should I just give up and reformat? I would hate that. I have already reinstalled windows to see if it would help with other problems in my e-mail. No such luck! I have a Dem 2400 Desktop running Windows XP. I did have SP2 from an upgrade but after the reinstall I again have SP1. Now I have Trojans. 12 cases according to Trend Micro HouseCall. McAfee did not find these. The Trojans are Troj Agent.KX, Troj Agent.AAD and Troj Agent. IV. I couldn't delete all of these with Trend Micro. I have run Microsoft AntiSpyware and Ad-Aware. I don't know how to do the HijackThis and wouldn't know what to delete etc. Is there anyone that can help!
No Events found!


100mph
1.2K Posts
0
February 25th, 2005 06:00
Infected file names.
Infected file location.
Type of infection (virus name, etc.)
---
While waiting for response, clean your Temp files:
http://www.fixyourwindows.com/optimizewindowstempfiles.htm
Alter and lock your HOSTS file:
http://www.mvps.org/winhelp2002/hosts.htm
and install and use Spybot S&D.
Thank you.
danamike
40 Posts
0
February 25th, 2005 18:00
Here you go. Some of these I deleted last night but they are back. The ones that says I can't access them I cannot delete.
Troj Agent.KX Location: C:Windows /System32Drivers
Troj Agent. KX Location: Volume Information (There are 5 of these that say the same thing)
Troj Agent ADD Location: Windows/System32/krzjkrur
Troj Agent ADD Location: Windows/System32/flngjqd
Troj Agent KX Location: Windows/System32/ zrzmtc
The last 4 say that I cannot access them.
100mph
1.2K Posts
0
February 25th, 2005 20:00
http://support.microsoft.com/kb/264887
But do NOT do it now - clean the rest of the infection first.
----------------------------------------------------------------------------
TROJ_AGENT.KX Removal Instructions:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FAGENT%2EKX&VSect=Sn
This will take care of the items related to TROJ_AGENT.KX.
----------------------------------------------------------------------------
And you'll have to deal with:
Troj Agent ADD Location: Windows/System32/krzjkrur
Troj Agent ADD Location: Windows/System32/flngjqd
Try deleting files with KillBox:
http://www.bleepingcomputer.com/files/spyware/KillBox.zip
And then do "While waiting for response ... " part from my previos post (above).
If still having problems, download and unzip HiJackThis, and post your log:
http://www.spywareinfo.com/~merijn/files/hijackthis.zip
Good Luck!
danamike
40 Posts
0
February 26th, 2005 20:00
Scan saved at 5:22:04 PM, on 2/26/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\xxqfeocv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Kodak\KODAK Picture Transfer Software\pts.exe
C:\Program Files\Greetings Workshop\GWREMIND.EXE
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {21DBE1CB-17F3-D2FD-EE26-FCE96158CF24} - C:\WINDOWS\System32\xdxecwbi.dll
O2 - BHO: (no name) - {320B90E7-A9D1-89AE-82FD-A630CCB91228} - C:\WINDOWS\system32\krzjkrur.dll
O2 - BHO: (no name) - {75EC7631-C61C-7360-1262-15C9CB8F2727} - C:\WINDOWS\system32\otjytrqf.dll (file missing)
O2 - BHO: (no name) - {77F3F041-662B-A012-393C-463795F85D2E} - C:\WINDOWS\System32\flngjqde.dll
O2 - BHO: (no name) - {96E5C0DF-8CDE-3397-4475-B5D5E7E2214C} - C:\WINDOWS\system32\aiqkfojl.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {82315A18-6CFB-44a7-BDFD-90E36537C252} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\Internet Accelerator\trayctl.exe" /STARTUPLAUNCH
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [xxqfeocv] C:\WINDOWS\system32\xxqfeocv.exe
O4 - HKLM\..\Run: [snlcrtlm] C:\WINDOWS\System32\snlcrtlm.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: Greetings Workshop Reminders.lnk = C:\Program Files\Greetings Workshop\GWREMIND.EXE
O4 - Startup: Mopy Points Collector.lnk = C:\MOPYFISH\GETPOINT.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O4 - Global Startup: KODAK Picture Transfer Software.lnk = ?
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\Internet Accelerator\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\Internet Accelerator\pac-image.html
O9 - Extra button: TREND MICRO HouseCall - {2B5EA4F8-620A-4A8B-B003-4C8C5EBEA826} - http://uk.trendmicro-europe.com/enterprise/products/housecall_pre.php (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.jetsetpoker.com/setup.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinstall/includes/vzWebIns.CAB
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/zuma/popcaploader_v5.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0D64B7C4-17DE-4246-9026-7F0153821291}: NameServer = 151.199.0.39 151.199.0.38
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: mhbswyudvjwg (acixgdqf6) - Unknown owner - C:\WINDOWS\system32\nlcsulpv6.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
100mph
1.2K Posts
0
February 27th, 2005 01:00
http://www.cexx.org/lspfix.htm
Download LSPfix.zip or LSPfix.exe from the same page. Use this program ONLY if you can not connect to the Internet after removing the infection.
--------------------------------------------------------------
Save this information to a Notepad file and keep Internet Explorer closed.
Disconnect from the Internet.
--------------------------------------------------------------
Uninstall Programs (if present):
Open the Control Panel’s Add/Remove Programs list and use the entries for ‘New.net domains’ (B variant), ‘FirstLook’ (FirstLook variant) and ‘QuickSearch Toolbar’ (QuickSearch variant).
If these options are unavailable, try looking in the Windows folder and the Program Files\NewDotNet folder for an uninstaller. NewDotNet/B typically leaves uninstaller files here. There may be more than one; if so, try the installer with the highest version number in its name.
--------------------------------------------------------------
Stop the mhbswyudvjwg (acixgdqf6) service:
Right-click My Computer -> Manage -> Services and Applications -> Services -> find and double-click mhbswyudvjwg (or mhbswyudvjwg (acixgdqf6)) service -> Stop the service and switch the Startup Type to Disabled -> OK.
Close the Computer Management window.
--------------------------------------------------------------
Start -> Settings -> Control Panel -> Folder Options -> View tab
Check the following options:
Display contents of system folder
Display the full path in the address bar
Display the full pathin the title bar
Show hidden files and folders
Uncheck the following option:
Hide protected Operating systems files (Recommended)
Click OK. Close everything.
--------------------------------------------------------------
Open Task Manager (ALT + CTRL + DEL), Processes tab, and end the following (if running):
xxqfeocv.exe
snlcrtlm.exe
Close Task Manager.
--------------------------------------------------------------
Open Command Prompt (Start -> Run -> cmd -> OK), and unregister DLLs by entering the following and pushing ENTER key after each line (if get an error, don’t worry about it – just close the window):
cd "%SystemRoot%"
regsvr32 /u xdxecwbi.dll
regsvr32 /u krzjkrur.dll
regsvr32 /u otjytrqf.dll
regsvr32 /u flngjqde.dll
regsvr32 /u aiqkfojl.dll
exit
--------------------------------------------------------------
Now run HiJackThis, and fix the following (if present):
C:\WINDOWS\system32\xxqfeocv.exe
O2 - BHO: (no name) - {21DBE1CB-17F3-D2FD-EE26-FCE96158CF24} - C:\WINDOWS\System32\xdxecwbi.dll
O2 - BHO: (no name) - {320B90E7-A9D1-89AE-82FD-A630CCB91228} - C:\WINDOWS\system32\krzjkrur.dll
O2 - BHO: (no name) - {75EC7631-C61C-7360-1262-15C9CB8F2727} - C:\WINDOWS\system32\otjytrqf.dll (file missing)
O2 - BHO: (no name) - {77F3F041-662B-A012-393C-463795F85D2E} - C:\WINDOWS\System32\flngjqde.dll
O2 - BHO: (no name) - {96E5C0DF-8CDE-3397-4475-B5D5E7E2214C} - C:\WINDOWS\system32\aiqkfojl.dll
O3 - Toolbar: (no name) - {82315A18-6CFB-44a7-BDFD-90E36537C252} - (no file)
O4 - HKLM\..\Run: [xxqfeocv] C:\WINDOWS\system32\xxqfeocv.exe
O4 - HKLM\..\Run: [snlcrtlm] C:\WINDOWS\System32\snlcrtlm.exe
O4 - Global Startup: KODAK Picture Transfer Software.lnk = ?
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O9 - Extra button: TREND MICRO HouseCall - {2B5EA4F8-620A-4A8B-B003-4C8C5EBEA826} - http://uk.trendmicro-europe.com/enterprise/products/housecall_pre.php (file missing)
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.jetsetpoker.com/setup.exe
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinstall/includes/vzWebIns.CAB
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/zuma/popcaploader_v5.cab
O23 - Service: mhbswyudvjwg (acixgdqf6) - Unknown owner - C:\WINDOWS\system32\nlcsulpv6.exe (file missing)
--------------------------------------------------------------
Reboot into safe mode:
Restart the computer, and immediately begin tapping the F8 key.
Use the arrow keys to highlight Safe Mode and press the Enter key.
--------------------------------------------------------------
Look for the following files and delete them (if present):
C:\WINDOWS\System32\xdxecwbi.dll
C:\WINDOWS\system32\krzjkrur.dll
C:\WINDOWS\system32\otjytrqf.dll
C:\WINDOWS\System32\flngjqde.dll
C:\WINDOWS\system32\aiqkfojl.dll
C:\WINDOWS\system32\xxqfeocv.exe
C:\WINDOWS\System32\snlcrtlm.exe
C:\WINDOWS\system32\nlcsulpv6.exe
--------------------------------------------------------------
Clean temporary files:
Browse to the following folders, and delete everything inside (DO NOT delete folders themselves):
C:\WINDOWS\Temp
C:\Documents and Settings\{COMPUTER USER NAME}\Local Settings\Temp - repeat for each user.
--------------------------------------------------------------
Restart computer in Normal Mode.
--------------------------------------------------------------
If you skipped any steps from my previous posts, do them now.
--------------------------------------------------------------
Run this scan:
http://www.windowsecurity.com/trojanscan/
--------------------------------------------------------------
Run HiJackThis, and post your fresh log.
Message Edited by 100mph on 02-27-2005 03:30 AM