My computer is freezing up when I try to get on the net. In fact, after I try to get on I cannot access my start menu and when I hit ctrl/alt/delete I any programs that are running show as not responding and the CPU says usage is around 80%. I have run PCPitstops extermintate and it says I have a trojan named Pripi. Went to the site for info but none of the items are turning up in a file search (ie. .dll file %system%\ipripsvc.dll). The search did turn up an iprip.dll and msiprip2.mib both of which were in the windows\system32 folder. I didn't see it when I ran HJT but then I am not sure what I am looking at. Each time I restore to an earlier point I get to use the internet a short time and so I used it to see if anyone can see anything that is nuts with my computer. Can't use exterminate to get rid of it at this time because my subscription ran out. Thank you for anyone who can help.
A final note: Upon startup I get an error report that says WUSB54GC.exe has encountered a problem and needs to close. It lists the following from the data: szAppname: WUSB54GC.exe szAppVer: 1.1.0.2 szModName:msvcrt.dll szModVer: 7.0.2600.2180 offset: 00036fa3.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:20:49 PM, on 1/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Thank you for your patience. I will be helping you deal with the issues raised in your log from this point onwards
Before we start jumping into things, here is a quick basic note which I mention to
everyone. The fix which I have provided for you is for this computer only, it should not be used on any other computer. Each fix is tailor made for the specific task in hand. If for some reason you have system restore disabled, then please re-enable it before proceeding, an infected restore is better than none. Please read through the fix first and set enough time aside to complete the task in one session. If there is anything you feel needs clarification then please ask - do not guess! Thanks.
If this is a business machine then please make sure that you have both the authority and full administration rights to the computer system.
To aid clarity all external links are in bold, blue and underlined where possible as follows ->
www.example-link.com
On with the fix.....
Important! - Please follow these directions in the order they are set out for you.
Open up HJT and select the second entry - Do a system scan only
Place a checkmark next to these entries:
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
Make sure all browser and open windows/programs are closed and select "Fix checked"
1. Double click on combo.exe and follow the prompts.
2. When finished, it will produce a logfile located at C:\ComboFix.txt.
3. Post the contents of that log in your next reply with a new HijackThis log.
Note: Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang. Do not proceed with the rest of the fix if you fail to run combofix
If your computer did not restart then please restart it now.
Once it has restarted please generate a fresh HJT log
Post this along with the results from combofix in your next reply
Here ya go sjb07 HJT log first then the combofix log
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:01:09 PM, on 2/1/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal
ComboFix 08-02.01.6 - Us 2008-02-01 17:53:45.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1103 [GMT -5:00] Running from: C:\Documents and Settings\Us\Desktop\ComboFix.exe * Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Possible infected sites -----
hxxp://au.download.windowsupdate.com . ((((((((((((((((((((((((( Files Created from 2008-01-01 to 2008-02-01 ))))))))))))))))))))))))))))))) .
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup
I am not seeing anything obvious in your log that suggest a trojan is present
In this next post I want to do a little bit of clearing up regarding temporary files, also, I want you to run an online scan - Please note that this scan may take more than an hour depending on the amount of data on your drive that it has to scan through. Please set enough free time for this scan to complete.
Download and scan with
CCleaner lite 1.Double click the file and install ccleaner
2. Before first use, select Options >
Advanced and UNCHECK
"Only delete files in Windows Temp folder older than 48 hours"
3. Then select the items you wish to clean up.
In the Windows Tab:
Clean all entries in the "Internet Explorer" section.
Clean all the entries in the "Windows Explorer" section.
Clean all entries in the "System" section.
Clean all entries in the "Advanced" section.
Clean any others that you choose.
In the Applications Tab:
Clean all in the Firefox/Mozilla section if you use it.
Clean all in the Opera section if you use it.
Clean Sun Java in the Internet Section.
Clean any others that you choose.
4. Click the "
Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click
"OK" and it will scan and clean your system.
7. Click "
exit" when done.
1. Click the "
Kaspersky Online Scanner" button (
NOT "Kaspersky File Scanner").
2. Read the Requirements and Privacy statement, then select "
Accept".
3. A new window will appear promting you to install an ActiveX component from Kaspersky - "
Do you want to install this software?".
4. Click "
Yes" or select "
Install" to download the ActiveX controls that allows ActiveScan to run.
5. When the download is complete it will say ready, click "
Next".
6. Click "
Scan Settings" and check the option to use the
Extended Database if available otherwise Standard).
7. Click "
Scan Options" and select both "
Scan Archives" and "
Scan Mail Bases".
8. Click "
OK".
9. Under "
Select a target to scan", click on "
My Computer".
10. When the scan is complete choose to save the results as "
Save as Text" named kaspersky.txt to your desktop and post them in your next reply.
Kaspersky does not remove anything but will provide a log of anything it finds. On August 8th, 2006 Kaspersky updated the software used for
Free Online Virus Scanner. In order to continue using the online scanner you will need to uninstall the old version (if previously used) from your Add/Remove Programs list and then install the latest version. To do this, follow the steps
here and reboot afterwards if your system does not reboot automatically or it will show '
Kaspersky Online Scanner license key was not found!
Please post back with the results from Kaspersky in your next reply
------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT Saturday, February 09, 2008 10:06:46 AM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 9/02/2008 Kaspersky Anti-Virus database records: 555731 -------------------------------------------------------------------------------
Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true
Scan Target - My Computer: A:\ C:\ D:\
Scan Statistics: Total number of scanned objects: 53353 Number of viruses found: 0 Number of infected objects: 0 Number of suspicious objects: 0 Duration of the scan process: 01:24:57
Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Us\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Us\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped C:\Documents and Settings\Us\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Us\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Us\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Us\Local Settings\History\History.IE5\MSHist012008020820080209\index.dat Object is locked skipped C:\Documents and Settings\Us\Local Settings\Temp\~DFDBA5.tmp Object is locked skipped C:\Documents and Settings\Us\Local Settings\Temp\~DFDBB0.tmp Object is locked skipped C:\Documents and Settings\Us\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Us\ntuser.dat Object is locked skipped C:\Documents and Settings\Us\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Us\UserData\index.dat Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{9E23F733-9CF1-4128-9E87-E22604051986}\RP99\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_6c.dat Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped
All is looking clear, no infection is showing, lets try a different scan tool
I want you to download and run
Silentrunners Please note: If you are using Internet Explorer, the download link will work as normal If you are using firefox browser then right click on the link and choose "save link as" Once downloaded, double click on the script to start it, you may get a warning from your virus checker suggesting it may be malicious, make sure you allow it.
Once it is running it will take a couple of mins to complete. once it has done its job a pop up window will appear (please make sure this window appears!)
Save the results to safe locaton and post them as a reply to this post
Please download
ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button.
If you use Firefox browser
Click Firefox at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
Click Opera at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click
Exit on the Main menu to close the program. For
Technical Support, double-click the e-mail address located at the bottom of each menu.
Double-click SUPERAntiSpyware.exe and use the default settings for installation.
An icon will be created on your desktop. Double-click that icon to launch the program.
If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
Under "Configuration and Preferences", click the Preferences button.
Click the Scanning Control tab.
Under Scanner Options make sure the following are checked (leave all others unchecked):
Close browsers before scanning.
Scan for tracking cookies.
Terminate memory threats before quarantining.
Click the "Close" button to leave the control center screen.
Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
On the left, make sure you check C:\Fixed Drive.
On the right, under "Complete Scan", choose Perform Complete Scan.
Click "Next" to start the scan. Please be patient while it scans your computer.
After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
Make sure everything has a checkmark next to it and click "Next".
A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
If asked if you want to reboot, click "Yes".
To retrieve the removal information after reboot, launch SUPERAntispyware again.
Click Preferences, then click the Statistics/Logs tab.
Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
Please copy and paste the Scan Log results in your next reply.
Click Close to exit the program.
Please post back with: SUPERAntiSpyware Scan Log
Silentrunners Log
A fresh HJT log
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:24:41 PM, on 2/9/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal
"Silent Runners.vbs", revision 55, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry: ---------------------------------
"shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001 {Shutdown: Allow system to be shut down without having to log on}
"undockwithoutlogon" = (REG_DWORD) dword:0x00000001 {Devices: Allow undock without having to log on}
Active Desktop and Wallpaper: -----------------------------
Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"
Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ "Wallpaper" = "C:\Documents and Settings\Us\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"
---------- (launch time: 2008-02-09 18:58:48) < >: Suspicious data at a malware launch point.
+ This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + To search all directories of local fixed drives for DESKTOP.INI DLL launch points, use the -supp parameter or answer "No" at the first message box and "Yes" at the second message box. ---------- (total run time: 66 seconds, including 28 seconds for message boxes)
HiJackThis log in next reply. Otherwise 20,000 characters allowed in posts is exceeded.
We have run some extensive scans here and nothng has shown up suggesting anything malicious, everything appears to be in order here. Im not sure what the tool at PCPitstop was showing but nothing is showing in the scans which suggest a
possible false positive somewhere. I would suggest posting in the Windows XP section of the forum to see of they can throw any light on the Explorer crashes/freezes that you are experiencing here.
When I am on my computer (Fujistu Siemens - Windows XP Home Edition) I get a message from my spyware centre saying that Pripi cannot be deleted. It then gives me the option to visit the spyware centre. When I click on that I get a message saying No information available for [pripi]. After reading the messages above, I wonder if there is anything you can do for me - but you will have to start at the very beginning as I do not know where all of the jargon logs can be found
sjb07
106 Posts
694
0
Posted February 1st, 2008 15:00
Thank you for your patience. I will be helping you deal with the issues raised in your log from this point onwards
Before we start jumping into things, here is a quick basic note which I mention to everyone. The fix which I have provided for you is for this computer only, it should not be used on any other computer. Each fix is tailor made for the specific task in hand. If for some reason you have system restore disabled, then please re-enable it before proceeding, an infected restore is better than none. Please read through the fix first and set enough time aside to complete the task in one session. If there is anything you feel needs clarification then please ask - do not guess! Thanks.
If this is a business machine then please make sure that you have both the authority and full administration rights to the computer system.
To aid clarity all external links are in bold, blue and underlined where possible as follows -> www.example-link.com
On with the fix.....
Important! - Please follow these directions in the order they are set out for you.
Open up HJT and select the second entry - Do a system scan only
Place a checkmark next to these entries:
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
Make sure all browser and open windows/programs are closed and select "Fix checked"
Please download ComboFix.exe
Save ComboFix to the desktop.
1. Double click on combo.exe and follow the prompts.
2. When finished, it will produce a logfile located at C:\ComboFix.txt.
3. Post the contents of that log in your next reply with a new HijackThis log.
Note: Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang. Do not proceed with the rest of the fix if you fail to run combofix
If your computer did not restart then please restart it now.
Once it has restarted please generate a fresh HJT log
Post this along with the results from combofix in your next reply