UNSOLVED

ALgal

updated

21 years ago

A

ALgal

1188 Posts

0

2143

March 29th, 2005 20:00

Hijackthis Analysis Please!

Please analyze this hijackthis log.  I ran CWShredder and deleted things, but I think there is still malware on this computer.  
 
Thanks,
Susan
***************************************************************************************************************
Logfile of HijackThis v1.99.1
Scan saved at 4:11:45 PM, on 3/29/05
Platform: Windows 98 SE (Win9x 4.10.2222B)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\INETDATA\SERVICES.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATI2PLAB.EXE
C:\WINDOWS\SYSTEM\ATIPTAAB.EXE
C:\WINDOWS\SYSTEM\ESSAPM.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\WINDOWS\SYSTEM\UEEOR.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\AOL SPYWARE PROTECTION\AOLSP SCHEDULER.EXE
C:\WINDOWS\VZNKAA.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\PROGRAM FILES\AMERICA ONLINE 9.0A\AOLTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\WINDOWS\SYSTEM\UEEOR.EXE
C:\PROGRAM FILES\ANTI-SPY\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search-paga.com/10039/
F1 - win.ini: run=C:\WINDOWS\INETDATA\SERVICES.EXE
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\PROGRAM FILES\SEP\SEP.DLL
O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\PROGRAM FILES\ESYNDICATE\ESYN.DLL
O2 - BHO: HBO Class - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - C:\WINDOWS\inetdata\3.00.00.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\PROGRAM FILES\SEP\SEP.DLL
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [OEMCleanup] C:\WINDOWS\OPTIONS\OEMRESET.EXE
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [ATIPOLAB] ati2plab.exe
O4 - HKLM\..\Run: [AtiPTA] Atiptaab.exe
O4 - HKLM\..\Run: [Ati2cwxx] Ati2cwxx.exe
O4 - HKLM\..\Run: [AtiGart] c:\Ati\Gart\AtiGart.exe
O4 - HKLM\..\Run: [essapm] essapm.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\INETDATA\SERVICES.EXE
O4 - HKLM\..\Run: [USB controller] "C:\WINDOWS\TEMP\ICD1.TMP\SVCMM32.EXE" /startup
O4 - HKLM\..\Run: [autoupdate] rundll32 C:\WINDOWS\SYSTEM\WINUP2DATE.DLL,SHStart
O4 - HKLM\..\Run: [AutoUpdater] "c:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [Ueeor.exe] C:\WINDOWS\SYSTEM\UEEOR.EXE
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\vznkaa.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [AolAcsDaemon1] "C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE"
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\INETDATA\SERVICES.EXE
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0a\aoltray.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: nati.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
O9 - Extra button: Microsoft AntiSpyware helper - {D7875740-9796-11D9-B72A-444553540000} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D7875740-9796-11D9-B72A-444553540000} - (no file) (HKCU)
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\ied_s7m.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net
 
  • ky331

    5 Journeyman

    15621 Posts

    45046 Points

    909

    0

    Posted March 29th, 2005 20:00

    I'm rather certain you have Look2Me infection;

    (there's also a chance, though I'm NOT sure about this one, that you have the W32.Netsky.B worm)

    Please be patient, and hopefully one of the HJT experts will get to you soon.

  • ALgal

    1188 Posts

    909

    0

    Posted March 29th, 2005 21:00

    Thanks, I am patient. I have run Spybot and Adaware.
  • zbestwun2001

    4 Apprentice

    8831 Posts

    909

    0

    Posted March 29th, 2005 21:00

    Please run AdAwareSE and Spybot if you haven't yet and post a new log.

    Steve
  • zbestwun2001

    4 Apprentice

    8831 Posts

    909

    0

    Posted March 29th, 2005 22:00

    pkeyrich,
    Since you seem to have a better handle on what is going on is this thread then I do at the present time, please continue with this victim and help her out with the rest of her log when posted.

    I am working so many logs right now, that I really appreciate the fact that you can handle this problem.

    Thanks Phil, I appreciate it.

    Steve
  • pkeyrich

    81 Posts

    909

    0

    Posted March 29th, 2005 22:00

    The WinUp2Date and other lines in your list seem to match that found in the discussion at the following page:

    http://forums.spywareinfo.com/lofiversion/index.php/t43602.html

    I think you may have an entry called Software Update in your Add/Remove Programs list.  It is commonly found to be spyware and needs to be uninstalled before removing WinTools from your system, if present.

  • pkeyrich

    81 Posts

    909

    0

    Posted March 29th, 2005 23:00

    I have not claimed ownership, and will not assume ownership.  I was only trying to help.  Sorry.
  • ALgal

    1188 Posts

    909

    0

    Posted March 30th, 2005 01:00

     
    Guess this Phil is a popular guy.  Meanwhile back at the ranch I am looking at the registry entries
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrenntVersion\Run-
    with names like:
    180ax
    Dvx
    KavSvc
    p59f36g
    Security iGuard
    Ueeor.exe - google never heard of that one
    Uiydww.exe - google never heard of that one either
    VBundleOuterDL
    vmss
    Windows Service - sounds legit until you notice the pd7.exe in the data part. 
     
  • ALgal

    1188 Posts

    909

    0

    Posted March 30th, 2005 10:00

    Guess I am on my own.  At least I have a name Look2me to put with this.  I need to unregister some DLLs and delete them. My brother's laptop only has 128MB Ram so I encountered problems with enough memory to try to download and run the Symantec virus scan.  More recent post gives good information on hijacthis analysis

    http://castlecops.com/HijackThis.html .

     
  • zbestwun2001

    4 Apprentice

    8831 Posts

    909

    0

    Posted March 30th, 2005 13:00

    Algal,
    I am not going to ignore you! Unlike others.

    So here we go, put your seatbelts on!!!!


    Run HiJackThis then:

    1. Click "Config..."
    2. Click "Misc Tools"
    3. Click "Open Process manager"

    -
    Next, while holding down the CTRL key, locate (if present) and click on (highlight) each of the following

    C:\WINDOWS\SYSTEM\UEEOR.EXE
    C:\WINDOWS\VZNKAA.EXE
    C:\WINDOWS\SYSTEM\UEEOR.EXE


    Now double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.


    Open HJT this and tick these entries if present:
    C:\WINDOWS\SYSTEM\UEEOR.EXE
    C:\WINDOWS\VZNKAA.EXE
    C:\WINDOWS\SYSTEM\UEEOR.EXE
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O2 - BHO: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\PROGRAM FILES\SEP\SEP.DLL
    O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\PROGRAM FILES\ESYNDICATE\ESYN.DLL
    O2 - BHO: HBO Class - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - C:\WINDOWS\inetdata\3.00.00.dll
    O4 - HKLM\..\Run: [USB controller] "C:\WINDOWS\TEMP\ICD1.TMP\SVCMM32.EXE" /startup
    O4 - HKLM\..\Run: [autoupdate] rundll32 C:\WINDOWS\SYSTEM\WINUP2DATE.DLL,SHStart
    O4 - HKLM\..\Run: [Ueeor.exe] C:\WINDOWS\SYSTEM\UEEOR.EXE


    With all applicatiions closed except the HJT program hit the FIX button




    Reboot and post a new log.

    Steve

    Message Edited by zbestwun2001 on 03-30-2005 07:34 AM

  • ALgal

    1188 Posts

    202

    0

    Posted March 30th, 2005 14:00

    I followed your instructions but that ueeor.exe will not be deleted even after I kill the process and check it. I have noticed that It is an entry in the registry under
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
     
    I have tried to delete the entry in the registry but when system is rebooted, it appears. I cannot go to the ueeor.exe and delete because I get message that "The specified file is being used by Windows." I also cannot rename it.