Have recently obtained a few trojan viruses (which have also popped up weird sites on my favorites & hijacked my home page with w-find.com)... Can someone please help with my HJT log? I have scanned & disinfected with CA EZ Armor & also Panda Free Online...I have also attached an HJT scan from March for comparison...
Thanks so much in advance...
Logfile of HijackThis v1.99.1 Scan saved at 11:08:46 PM, on 4/13/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\hkcmd.exe C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\System32\DSentry.exe C:\Program Files\Dell\Media Experience\PCMService.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\Program Files\Common Files\Dell\EUSW\Support.exe C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe C:\Program Files\QuickTime\qttask.exe C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe C:\Program Files\DIGStream\digstream.exe C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe C:\WINDOWS\System32\lexpps.exe C:\Program Files\Dell AIO Printer A940\dlbabmon.exe C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\System32\svqxjaaa.exe C:\WINDOWS\System32\rundll32.exe C:\HJT\HijackThis.exe
Logfile of HijackThis v1.99.1 Scan saved at 12:47:15 AM, on 3/4/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Please print out or copy this page to notepad for easy reference when carrying out the instructions. Make sure to work through the fixes in the exact order they are listed. If you have any questions feel free to ask before carrying out the fixes.
Turn off System Restore by doing the following: Click Start > Right Click My Computer > Properties. Click the System Restore tab and Check"Turn off System Restore" or "Turn off System Restore on all drives". Click Apply. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this then Click OK.
Show Hidden and System files: Go to My Computer >Tools >Folder Options >View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing / visible. Uncheck the Hide protected operating system files option.
For the options that you have checked/enabled, you may uncheck them after your log is clean. If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad, but you want to keep).
Please download all of the following programs before trying any of the fixes: Please download Ad-aware SE and install it if you don't have it already. Make sure it's the newest version and check for any updates before running it. Also go here to get the plug-in for fixing VX2 variants. To run this tool, go into Ad-aware->Add-ons and select VX2 Cleaner. Then click Run Tool and OK to start it. If it's clean, it will say Status System Clean. Otherwise, you will have to click on the Clean button to remove the VX2 infection. Also make sure to customize the settings in Ad-aware for better scan results. Run the scan and fix everything that it finds.
Download CWShredder and click on 'Fix' (it will automatically fix anything it finds for you). If it asks if you want to delete a certain random file, choose No and post that filename here.
If you have a fast internet connection (broadband), run an online scan at Trend Micro or RAV Antivirus. Please select the autoclean option when using Trend Micro.
==========================
Reboot into Safe Mode (hit F8 key until menu shows up).
End Running Processes: Make sure to close any open browsers. Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click Kill process for each one if they are still listed (they shouldn't be - but double check it):
C:\WINDOWS\System32\svqxjaaa.exe
Open Hijack This and click on Scan. Check the following entries, if they are still there.(make sure you do not miss any)
Reboot into Normal Mode and run new HijackThis scan. If there were some entries that didn't show up in Safe Mode, you may check and fix those that appear now in normal mode (if you do that, make sure to run a new scan again). Save the log file and post it up in the forum.
150!! intresting, did the virus scans catch anything? Sometimes once you remove part of an infection it bites back and new things will show up, but 150 is worrying.
The two services Loading Outpost Connections (KDE) is Win32.Bagz.i email virus Trace network connections (ACCRA) is Trojan.Mochi (http://securityresponse.symantec.com/avcenter/venc/data/trojan.mochi.html)
Lets see if we can't get rid of them.
Go to Start->Run and type in services.msc and hit OK. Then look for Trace network connections (ACCRA) Double click on it. Click on the Stop button and under Startup type, choose Disabled. Then look for Loading Outpost Connections (KDE) Double click on it. Click on the Stop button and under Startup type, choose Disabled.
Reboot into Safe Mode (hit F8 key until menu shows up).
Open Hijack This and click on Scan. Check the following entries, if they are still there.(make sure you do not miss any)
Reboot into Normal Mode and run new HijackThis scan. If there were some entries that didn't show up in Safe Mode, you may check and fix those that appear now in normal mode (if you do that, make sure to run a new scan again). Save the log file and put it up in the forum.
I did not have much luck in Safe Mode, as once I performed things (I did everything you recommended but CW Shredder) in safe mode, I went back in "normal restart" & ran HJT and everything was still in my HJT log. In fact there were many more O4's (about 150 total), but I fix checked them nonetheless....Any idea why there became so many O4's after safe mode? The fix check took care of my browser hijack & I have been able to delete those annoying porn references in my favorites...The only thing that I am now noticing is that the two O23's that you recommended to fix check will not fix check. I have tried several times and it does not go away...Any other ideas, and do you have any idea what exactly these programs are?
Logfile of HijackThis v1.99.1 Scan saved at 11:10:04 AM, on 4/14/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\hkcmd.exe C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\System32\DSentry.exe C:\Program Files\Dell\Media Experience\PCMService.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe C:\Program Files\QuickTime\qttask.exe C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe C:\Program Files\DIGStream\digstream.exe C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe C:\Program Files\Dell AIO Printer A940\dlbabmon.exe C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe C:\HJT\HijackThis.exe
Thanks so much Bob...The two O23's are no longer appearing in my HJT log...I had run EZ Armor, TrendMicro & Panda & none of them find viruses any longer as well...Spybot & AdAware are now clean... Check out the latest HJT...Does it look clean to you?
When I go back into Run services.msc...the two items in question are still listed although they are "disabled". Is there any way to get rid of them all together, or would that foul something else up?
A couple of other HJT questions...I do not use dell4me.com as my home page so is there any reason not to fix check these :
Logfile of HijackThis v1.99.1 Scan saved at 12:29:08 PM, on 4/14/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\hkcmd.exe C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\System32\DSentry.exe C:\Program Files\Dell\Media Experience\PCMService.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\Program Files\Common Files\Dell\EUSW\Support.exe C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe C:\Program Files\QuickTime\qttask.exe C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe C:\Program Files\DIGStream\digstream.exe C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe C:\Program Files\Dell AIO Printer A940\dlbabmon.exe C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\HijackThis.exe
When I go back into Run services.msc...the two items in question are still listed although they are "disabled". Is there any way to get rid of them all together, or would that foul something else up?
There is but it is not really necessary as long as they are disabled and the file is removed.
If you wish to remove them:
Open HijackThis->config->misc tools->delete an NT service and put in the box the name of the service
Loading Outpost Connections (KDE) and then ok, do the same for
Trace network connections (ACCRA)
A couple of other HJT questions...I do not use dell4me.com as my home page so is there any reason not to fix check these :
You can fix those 3 if you do not use them as your homepage.
Also if I am not using AOL Spyware, would it hurt to fix check these two items?:
I'm not sure if this is required for AOL or not, I don't think it should be and it should have an enrty in Add/Remove programs that will remove it for you.
Other than those your log is clean. If you disabled System Restore, make sure to enable it now.
To help prevent future spyware installations/infections, please read the Anti-Spyware Tutorial http://www.greyknight17.com/spyware.htm#prevent and use the tools provided.
bobmartino
40 Posts
531
0
Posted April 14th, 2005 10:00
Please print out or copy this page to notepad for easy reference when carrying out the instructions. Make sure to work through the fixes in the exact order they are listed. If you have any questions feel free to ask before carrying out the fixes.
Turn off System Restore by doing the following:
Click Start > Right Click My Computer > Properties. Click the System Restore tab and Check "Turn off System Restore" or "Turn off System Restore on all drives". Click Apply. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this then Click OK.
Show Hidden and System files:
Go to My Computer >Tools >Folder Options >View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing / visible. Uncheck the Hide protected operating system files option.
For the options that you have checked/enabled, you may uncheck them after your log is clean.
If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad, but you want to keep).
Please download all of the following programs before trying any of the fixes:
Please download Ad-aware SE and install it if you don't have it already. Make sure it's the newest version and check for any updates before running it. Also go here to get the plug-in for fixing VX2 variants. To run this tool, go into Ad-aware->Add-ons and select VX2 Cleaner. Then click Run Tool and OK to start it. If it's clean, it will say Status System Clean. Otherwise, you will have to click on the Clean button to remove the VX2 infection. Also make sure to customize the settings in Ad-aware for better scan results. Run the scan and fix everything that it finds.
Download CWShredder and click on 'Fix' (it will automatically fix anything it finds for you). If it asks if you want to delete a certain random file, choose No and post that filename here.
If you have a fast internet connection (broadband), run an online scan at Trend Micro or RAV Antivirus.
Please select the autoclean option when using Trend Micro.
==========================
Reboot into Safe Mode (hit F8 key until menu shows up).
End Running Processes:
Make sure to close any open browsers. Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click Kill process for each one if they are still listed (they shouldn't be - but double check it):
C:\WINDOWS\System32\svqxjaaa.exe
Open Hijack This and click on Scan. Check the following entries, if they are still there.(make sure you do not miss any)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://w-find.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://w-find.com/index.htm
O4 - HKCU\..\Run: [yhkcdma] c:\windows\pnjdlum.exe
O4 - HKCU\..\Run: [thmppna] c:\windows\pnjdlum.exe
O4 - HKCU\..\Run: [cnxxgjy] c:\windows\pnjdlum.exe
O4 - HKCU\..\Run: [fbgoinj] c:\windows\pnjdlum.exe
O4 - HKCU\..\Run: [jxqvddc] c:\windows\pnjdlum.exe
O4 - HKCU\..\Run: [jfoyumj] c:\windows\pnjdlum.exe
O4 - HKCU\..\Run: [ltubfqc] c:\windows\pnjdlum.exe
O4 - HKCU\..\Run: [proraiw] c:\windows\pnjdlum.exe
O4 - HKCU\..\Run: [rkqirxp] c:\windows\pnjdlum.exe
O4 - HKCU\..\Run: [hdigpre] c:\windows\pnjdlum.exe
O4 - HKCU\..\Run: [ccakhmt] c:\windows\pnjdlum.exe
O4 - HKCU\..\Run: [nopoqlt] c:\windows\pnjdlum.exe
O4 - HKCU\..\Run: [txbexyt] c:\windows\pnjdlum.exe
O4 - HKCU\..\Run: [hcnyobp] c:\windows\pnjdlum.exe
O4 - HKCU\..\Run: [vbfloan] c:\windows\pnjdlum.exe
O23 - Service: Trace network connections (ACCRA) - Unknown owner - C:\WINDOWS\System32\mocih.exe (file missing)
O23 - Service: Loading Outpost Connections (KDE) - Unknown owner - C:\WINDOWS\System32\cmdtel.exe (file missing)
Please remember to close all other windows, including browsers then click Fix checked.
Delete the following Files indicated in RED and Folders indicated in BLUE if they still exist.
C:\WINDOWS\System32\svqxjaaa.exe
c:\windows\pnjdlum.exe
C:\WINDOWS\System32\mocih.exe
C:\WINDOWS\System32\cmdtel.exe
Reboot into Normal Mode and run new HijackThis scan. If there were some entries that didn't show up in Safe Mode, you may check and fix those that appear now in normal mode (if you do that, make sure to run a new scan again). Save the log file and post it up in the forum.