UNSOLVED

steveoUM

updated

21 years ago

S

steveoUM

10 Posts

0

1701

April 16th, 2005 03:00

My HijackThis Log, Please Help Me!

I am running Windows XP and I recently got this warning:  "A fatal error in IE has occured at 0028:C0011E36 in VXD VMM <01> + 00010E36. Error was caused by Trojan-spy.HTML.Smitfraud.c"
Also it warned me that I was infected with the "Stealth.Hjack" virus
Here is my Log...Please help me, I am very dependent on my computer.
 
 

Logfile of HijackThis v1.99.1

Scan saved at 12:36:12 am, on 04-16-2005

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\S24EvMon.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\cisvc.exe

C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

C:\Program Files\Network Associates\Common Framework\FrameworkService.exe

C:\Program Files\Network Associates\VirusScan\mcshield.exe

C:\Program Files\Network Associates\VirusScan\vstskmgr.exe

C:\WINDOWS\System32\RegSrvc.exe

C:\WINDOWS\System32\RoamMgr.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Intel\Switching\User\RoamSvc.exe

C:\Program Files\Intel\NCS\Sync\NetSvc.exe

C:\WINDOWS\system32\ZCfgSvc.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\hkcmd.exe

C:\Program Files\Apoint\Apoint.exe

C:\WINDOWS\System32\pctspk.exe

C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe

C:\WINDOWS\System32\DSentry.exe

C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe

C:\Program Files\Common Files\Dell\EUSW\Support.exe

C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE

C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe

C:\Program Files\Belkin F8E825-USB MiniWireless Optical Mouse\cm20.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\System32\winupdt.exe

C:\Documents and Settings\All Users\Application Data\msw\MSW.exe

C:\WINDOWS\System32\RUNDLL32.exe

C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe

C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe

C:\WINDOWS\adiagcmg.exe

C:\WINDOWS\FHVPDLL.EXE

C:\WINDOWS\CITDENC.EXE

C:\WINDOWS\IEXPLOR.exe

C:\Program Files\MessengerPlus! 3\MsgPlus.exe

C:\WINDOWS\WinTask.exe

C:\WINDOWS\tempdl\Terp03292005.exe

C:\WINDOWS\System32\nsvsvc\nsvsvc.exe

C:\WINDOWS\System32\picsvr\picsvr.exe

C:\Program Files\Media Access\MediaAccK.exe

C:\WINDOWS\System32\ifsv_32.exe

C:\Program Files\Media Access\MediaAccess.exe

C:\Program Files\Microsoft AntiSpyware\gcasServ.exe

C:\WINDOWS\system\elxwasehgh.exe

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\Spyware Doctor\swdoctor.exe

C:\WINDOWS\System32\idefx13n.exe

C:\PROGRA~1\AWS\WEATHE~1\Weather.exe

C:\wp.exe

C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe

C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

C:\WINDOWS\SYSTEM32\kx509_kfwk5.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rdud.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\DOCUME~1\ALLUSE~1\APPLIC~1\msw\BMan.exe

C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe

C:\WINDOWS\SYSTEM32\krbcc32s.exe

C:\Program Files\Apoint\Apntex.exe

C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe

C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe

C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe

C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe

C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe

C:\WINDOWS\System32\wbem\wmiapsrv.exe

C:\WINDOWS\System32\wuauclt.exe

C:\WINDOWS\system32\cidaemon.exe

C:\WINDOWS\system32\cidaemon.exe

C:\Program Files\HijackThis.exe

C:\Program Files\Internet Explorer\iexplore.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotoffers.info/ad0278/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - Default URLSearchHook is missing

O1 - Hosts: 69.50.173.4 earthlink.net

O1 - Hosts: 69.50.173.4 www.earthlink.net

O1 - Hosts: 69.50.173.4 go.com

O1 - Hosts: 69.50.173.4 www.go.com

O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll

O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll

O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINDOWS\System32\nsm1EB9.dll

O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll

O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll

O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe

O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe

O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe

O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"

O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"

O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe

O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE

O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"

O4 - HKLM\..\Run: [Start RF Wireless Mouse] C:\Program Files\Belkin F8E825-USB MiniWireless Optical Mouse\cm20.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe

O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe

O4 - HKLM\..\Run: [App32dll] c:\windows\system32\msnavc32.exe lee0105

O4 - HKLM\..\Run: [msw] C:\Documents and Settings\All Users\Application Data\msw\MSW.exe

O4 - HKLM\..\Run: [RSync] C:\WINDOWS\System32\netsync.exe

O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16

O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe

O4 - HKLM\..\Run: [msmc] C:\WINDOWS\System32\msmc.exe

O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"

O4 - HKLM\..\Run: [ivrakznjpqdwqppvmdndda] C:\WINDOWS\adiagcmg.exe

O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\irarik.exe

O4 - HKLM\..\Run: [C:\WINDOWS\IEXPLOR.EXE] C:\WINDOWS\IEXPLOR.EXE

O4 - HKLM\..\Run: [FHVPDLL] C:\WINDOWS\FHVPDLL.EXE

O4 - HKLM\..\Run: [CITDENC] C:\WINDOWS\CITDENC.EXE

O4 - HKLM\..\Run: [AtxBrw] C:\WINDOWS\IEXPLOR.exe

O4 - HKLM\..\Run: [RUNGogoTools] C:\Program Files\GogoTools\Gogoware\LaunchAdware.exe

O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"

O4 - HKLM\..\Run: [Mix Soft Ref Flag] C:\Documents and Settings\All Users\Application Data\Spam Jump Mix Soft\BurnSettings.exe

O4 - HKLM\..\Run: [C:\WINDOWS\WinTask.exe] C:\WINDOWS\WinTask.exe

O4 - HKLM\..\Run: [PopMark] C:\WINDOWS\WinTask.exe

O4 - HKLM\..\Run: [Visual Element FX5] C:\WINDOWS\tempdl\Terp03292005.exe

O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe

O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\System32\picsvr\picsvr.exe

O4 - HKLM\..\Run: [tzszhp] c:\windows\system32\tzszhp.exe

O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe

O4 - HKLM\..\Run: [239h3El] ifsv_32.exe

O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe

O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"

O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [sf] C:\Program Files\sf\sf.exe

O4 - HKCU\..\Run: [sfita] C:\WINDOWS\sfita.exe

O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q

O4 - HKCU\..\Run: [J0qnROJql] idefx13n.exe

O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1

O4 - HKCU\..\Run: [Downloadelse] C:\DOCUME~1\Stephen\APPLIC~1\THATMP~1\Upload Tons Book.exe

O4 - HKCU\..\Run: [WindowsFY] c:\wp.exe

O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe

O4 - Global Startup: hp psc 1000 series.lnk = ?

O4 - Global Startup: hpoddt01.exe.lnk = ?

O4 - Global Startup: KX509.lnk = C:\WINDOWS\SYSTEM32\kx509_kfwk5.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll

O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe

O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll

O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

O9 - Extra button: Microsoft AntiSpyware helper - {7E30A5B6-71CC-46A5-AB64-DB129DA8B100} - (no file) (HKCU)

O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7E30A5B6-71CC-46A5-AB64-DB129DA8B100} - (no file) (HKCU)

O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)

O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)

O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.1.5.28/blackjack/blackjack-ob-assets.cab

O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.1.5.28/jigsaw/jigsaw-ob-assets.cab

O16 - DPF: Perfect Passer by pogo - http://game1.pogo.com/applet-6.1.5.28/perfectpasser/perfectpasser-ob-assets.cab

O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.1.5.28/worldclass/worldclass-ob-assets.cab

O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab

O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab

O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099015700595

O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.101.3/g_bin/eng/poker_2_0_0_36.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab

O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll

O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

O23 - Service: Adapter Switching (IntelRoam) - Intel Corporation - C:\Program Files\Intel\Switching\User\RoamSvc.exe

O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe

O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe

O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe

O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

O23 - Service: PsShutdown (PsShutdownSvc) - Unknown owner - C:\WINDOWS\System32\PSSDNSVC.EXE

O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe

O23 - Service: RoamMgr - Intel Corporation - C:\WINDOWS\System32\RoamMgr.exe

O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\System32\S24EvMon.exe

  • bobmartino

    40 Posts

    502

    0

    Posted April 18th, 2005 13:00

    (Not taking ownership)

    There is just to much here to start with a complete fix. Lets try get rid of some stuff first.

    Download and run these tools
    Please download Ad-aware SE and install it if you don't have it already. Make sure it's the newest version and check for any updates before running it. Also go here to get the plug-in for fixing VX2 variants. To run this tool, go into Ad-aware->Add-ons and select VX2 Cleaner. Then click Run Tool and OK to start it. If it's clean, it will say Status System Clean. Otherwise, you will have to click on the Clean button to remove the VX2 infection. Also make sure to customize the settings in Ad-aware for better scan results. Run the scan and fix everything that it finds.

    Please download Spybot S&D and install it if you don't have it already. Run Spybot and click on the 'Search for Updates' button. Install any updates that are available. Next click on the 'Check for Problems' button. Let it run the scan. If it finds something, check all those in RED and hit the Fix Selected Problems button. Exit Spybot. If you keep getting the DSO Exploit entries, even after you updated Windows and fixed them, then download the Spybot DSO Exploit Fix and install it over the current Spybot installation.

    Download CWShredder and click on 'Fix' (it will automatically fix anything it finds for you). If it asks if you want to delete a certain random file, choose No and post that filename here.

    The Temp folders should be cleaned out periodically as installation programs and hijack programs leave a lot of junk there. Download CleanUp! ( Alternate Link if main link don't work) and install it. Run CleanUp! and click on CleanUp! button. When it asks you if you want to logoff, click on Yes.

    If you have a fast internet connection (broadband), run an online scan at Trend Micro and RAV Antivirus.
    Please select the autoclean option when using Trend Micro.

    Then run a new scan and post up the log, please try not to double space it as it makes it alot harder to read.
  • steveoUM

    10 Posts

    502

    0

    Posted April 18th, 2005 22:00

    I ran Ad-aware, CWShredder, Spybot and everything else you recommended...I hope this new log is more helpful.
     
    Logfile of HijackThis v1.99.1
    Scan saved at 06:57:04 pm, on 04-18-2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\ZCfgSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\WINDOWS\System32\pctspk.exe
    C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Common Files\Dell\EUSW\Support.exe
    C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
    C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
    C:\Program Files\Belkin F8E825-USB MiniWireless Optical Mouse\cm20.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\System32\winupdt.exe
    C:\Documents and Settings\All Users\Application Data\msw\MSW.exe
    C:\WINDOWS\System32\RUNDLL32.exe
    C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
    C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
    C:\WINDOWS\adiagcmg.exe
    C:\WINDOWS\IEXPLOR.EXE
    C:\WINDOWS\FHVPDLL.EXE
    C:\WINDOWS\CITDENC.EXE
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\WINDOWS\WinTask.exe
    C:\WINDOWS\tempdl\Terp03292005.exe
    C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
    C:\WINDOWS\System32\picsvr\picsvr.exe
    C:\Program Files\Media Access\MediaAccK.exe
    C:\WINDOWS\System32\ifsv_32.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\WINDOWS\system\elxwasehgh.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Spyware Doctor\swdoctor.exe
    C:\WINDOWS\System32\idefx13n.exe
    C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
    C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
    C:\Program Files\Media Access\MediaAccess.exe
    C:\wp.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\msw\BMan.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\WINDOWS\SYSTEM32\kx509_kfwk5.exe
    C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rdud.exe
    C:\Program Files\Network Associates\VirusScan\mcshield.exe
    C:\WINDOWS\SYSTEM32\krbcc32s.exe
    C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
    C:\WINDOWS\System32\RegSrvc.exe
    C:\WINDOWS\System32\RoamMgr.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Switching\User\RoamSvc.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\System32\wbem\wmiapsrv.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
    C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\HijackThis.exe
    c:\progra~1\intern~1\iexplore.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotoffers.info/ad0278/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O1 - Hosts: 69.50.173.4 earthlink.net
    O1 - Hosts: 69.50.173.4 www.earthlink.net
    O1 - Hosts: 69.50.173.4 go.com
    O1 - Hosts: 69.50.173.4 www.go.com
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
    O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINDOWS\System32\nsm1EB9.dll
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
    O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
    O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
    O4 - HKLM\..\Run: [Start RF Wireless Mouse] C:\Program Files\Belkin F8E825-USB MiniWireless Optical Mouse\cm20.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
    O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe
    O4 - HKLM\..\Run: [App32dll] c:\windows\system32\msnavc32.exe lee0105
    O4 - HKLM\..\Run: [msw] C:\Documents and Settings\All Users\Application Data\msw\MSW.exe
    O4 - HKLM\..\Run: [RSync] C:\WINDOWS\System32\netsync.exe
    O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
    O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
    O4 - HKLM\..\Run: [msmc] C:\WINDOWS\System32\msmc.exe
    O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
    O4 - HKLM\..\Run: [ivrakznjpqdwqppvmdndda] C:\WINDOWS\adiagcmg.exe
    O4 - HKLM\..\Run: [C:\WINDOWS\IEXPLOR.EXE] C:\WINDOWS\IEXPLOR.EXE
    O4 - HKLM\..\Run: [FHVPDLL] C:\WINDOWS\FHVPDLL.EXE
    O4 - HKLM\..\Run: [CITDENC] C:\WINDOWS\CITDENC.EXE
    O4 - HKLM\..\Run: [AtxBrw] C:\WINDOWS\IEXPLOR.exe
    O4 - HKLM\..\Run: [RUNGogoTools] C:\Program Files\GogoTools\Gogoware\LaunchAdware.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [Mix Soft Ref Flag] C:\Documents and Settings\All Users\Application Data\Spam Jump Mix Soft\BurnSettings.exe
    O4 - HKLM\..\Run: [C:\WINDOWS\WinTask.exe] C:\WINDOWS\WinTask.exe
    O4 - HKLM\..\Run: [PopMark] C:\WINDOWS\WinTask.exe
    O4 - HKLM\..\Run: [Visual Element FX5] C:\WINDOWS\tempdl\Terp03292005.exe
    O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
    O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\System32\picsvr\picsvr.exe
    O4 - HKLM\..\Run: [tzszhp] c:\windows\system32\tzszhp.exe
    O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
    O4 - HKLM\..\Run: [239h3El] ifsv_32.exe
    O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [sf] C:\Program Files\sf\sf.exe
    O4 - HKCU\..\Run: [sfita] C:\WINDOWS\sfita.exe
    O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
    O4 - HKCU\..\Run: [J0qnROJql] idefx13n.exe
    O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
    O4 - HKCU\..\Run: [Downloadelse] C:\DOCUME~1\Stephen\APPLIC~1\THATMP~1\Upload Tons Book.exe
    O4 - HKCU\..\Run: [WindowsFY] c:\wp.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
    O4 - Global Startup: hp psc 1000 series.lnk = ?
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O4 - Global Startup: KX509.lnk = C:\WINDOWS\SYSTEM32\kx509_kfwk5.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra button: Microsoft AntiSpyware helper - {7E30A5B6-71CC-46A5-AB64-DB129DA8B100} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7E30A5B6-71CC-46A5-AB64-DB129DA8B100} - (no file) (HKCU)
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
    O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
    O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.1.5.28/blackjack/blackjack-ob-assets.cab
    O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.1.5.28/jigsaw/jigsaw-ob-assets.cab
    O16 - DPF: Perfect Passer by pogo - http://game1.pogo.com/applet-6.1.5.28/perfectpasser/perfectpasser-ob-assets.cab
    O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.1.5.28/worldclass/worldclass-ob-assets.cab
    O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099015700595
    O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.101.3/g_bin/eng/poker_2_0_0_36.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: Adapter Switching (IntelRoam) - Intel Corporation - C:\Program Files\Intel\Switching\User\RoamSvc.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
    O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
    O23 - Service: PsShutdown (PsShutdownSvc) - Unknown owner - C:\WINDOWS\System32\PSSDNSVC.EXE
    O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
    O23 - Service: RoamMgr - Intel Corporation - C:\WINDOWS\System32\RoamMgr.exe
    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\System32\S24EvMon.exe
     
  • bobmartino

    40 Posts

    502

    0

    Posted April 19th, 2005 12:00

    Hello and Welcome, Still a whole lot of stuff there, but lets give this a try.  There is a lot here is you see something you don't want to remove move on and let me know at the end.  There was a major infection that disappeared between log 1 and 2, it will probably return sometime soon.

    Please print out or copy this page to notepad for easy reference when carrying out the instructions. Make sure to work through the fixes in the exact order they are listed. If you have any questions feel free to ask before carrying out the fixes.

    Show Hidden and System files:
    Go to My Computer >Tools >Folder Options >View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing / visible. Uncheck the Hide protected operating system files option.

    For the options that you have checked/enabled, you may uncheck them after your log is clean.
    If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad, but you want to keep).


    Please download all of the following programs before trying any of the fixes:
    Right click Del015Domains and choose Save As. Save it to your desktop. Right click on that file and choose Install. You may delete it afterwards.

    Download Hoster http://www.greyknight17.com/spy/Hoster.exe and run it. Choose the 'Restore Original Hosts' button and press OK.

    The Temp folders should be cleaned out periodically as installation programs and hijack programs leave a lot of junk there. Download CleanUp! ( Alternate Link if main link don't work) and install it. Don't run it yet.

    ==========================

    Reboot into Safe Mode (hit F8 key until menu shows up).

    End Running Processes:
    Make sure to close any open browsers. Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click Kill process for each one if they are still listed (they shouldn't be - but double check it):

    C:\WINDOWS\System32\winupdt.exe
    C:\Documents and Settings\All Users\Application Data\msw\MSW.exe
    C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
    C:\WINDOWS\adiagcmg.exe
    C:\WINDOWS\IEXPLOR.EXE
    C:\WINDOWS\FHVPDLL.EXE
    C:\WINDOWS\CITDENC.EXE
    C:\WINDOWS\WinTask.exe
    C:\WINDOWS\tempdl\Terp03292005.exe
    C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
    C:\WINDOWS\System32\picsvr\picsvr.exe
    C:\Program Files\Media Access\MediaAccK.exe
    C:\WINDOWS\System32\ifsv_32.exe
    C:\WINDOWS\system\elxwasehgh.exe
    C:\WINDOWS\System32\idefx13n.exe
    C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
    C:\Program Files\Media Access\MediaAccess.exe
    C:\wp.exe
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\msw\BMan.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rdud.exe

    Add / Remove Programs
    Click > Start > Control Panel > Add / Remove Programs and uninstall the following programs:

    Weatherbug
    Security iGuard
    MediaAccess
    GogoTools

    Open Hijack This and click on Scan. Check the following entries, if they are still there. (make sure you do not miss any)

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotoffers.info/ad0278/ -- if you didn't set this fix it aswell
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O1 - Hosts: 69.50.173.4 earthlink.net
    O1 - Hosts: 69.50.173.4 www.earthlink.net
    O1 - Hosts: 69.50.173.4 go.com
    O1 - Hosts: 69.50.173.4 www.go.com
    O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINDOWS\System32\nsm1EB9.dll
    O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe
    O4 - HKLM\..\Run: [App32dll] c:\windows\system32\msnavc32.exe lee0105
    O4 - HKLM\..\Run: [msw] C:\Documents and Settings\All Users\Application Data\msw\MSW.exe
    O4 - HKLM\..\Run: [RSync] C:\WINDOWS\System32\netsync.exe
    O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
    O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
    O4 - HKLM\..\Run: [msmc] C:\WINDOWS\System32\msmc.exe
    O4 - HKLM\..\Run: [ivrakznjpqdwqppvmdndda] C:\WINDOWS\adiagcmg.exe
    O4 - HKLM\..\Run: [C:\WINDOWS\IEXPLOR.EXE] C:\WINDOWS\IEXPLOR.EXE
    O4 - HKLM\..\Run: [FHVPDLL] C:\WINDOWS\FHVPDLL.EXE
    O4 - HKLM\..\Run: [CITDENC] C:\WINDOWS\CITDENC.EXE
    O4 - HKLM\..\Run: [AtxBrw] C:\WINDOWS\IEXPLOR.exe
    O4 - HKLM\..\Run: [RUNGogoTools] C:\Program Files\GogoTools\Gogoware\LaunchAdware.exe
    O4 - HKLM\..\Run: [Mix Soft Ref Flag] C:\Documents and Settings\All Users\Application Data\Spam Jump Mix Soft\BurnSettings.exe
    O4 - HKLM\..\Run: [C:\WINDOWS\WinTask.exe] C:\WINDOWS\WinTask.exe
    O4 - HKLM\..\Run: [PopMark] C:\WINDOWS\WinTask.exe
    O4 - HKLM\..\Run: [Visual Element FX5] C:\WINDOWS\tempdl\Terp03292005.exe
    O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
    O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\System32\picsvr\picsvr.exe
    O4 - HKLM\..\Run: [tzszhp] c:\windows\system32\tzszhp.exe
    O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
    O4 - HKLM\..\Run: [239h3El] ifsv_32.exe
    O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
    O4 - HKCU\..\Run: [sf] C:\Program Files\sf\sf.exe
    O4 - HKCU\..\Run: [sfita] C:\WINDOWS\sfita.exe
    O4 - HKCU\..\Run: [J0qnROJql] idefx13n.exe
    O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
    O4 - HKCU\..\Run: [Downloadelse] C:\DOCUME~1\Stephen\APPLIC~1\THATMP~1\Upload Tons Book.exe
    O4 - HKCU\..\Run: [WindowsFY] c:\wp.exe
    O9 - Extra button: Microsoft AntiSpyware helper - {7E30A5B6-71CC-46A5-AB64-DB129DA8B100} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7E30A5B6-71CC-46A5-AB64-DB129DA8B100} - (no file) (HKCU)
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
    O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?

    Please remember to close all other windows, including browsers then click Fix checked.

    Delete the following Files indicated in RED and Folders indicated in BLUE if they still exist.

    C:\WINDOWS\System32\winupdt.exe
    C:\Documents and Settings\All Users\Application Data\msw\
    C:\WINDOWS\adiagcmg.exe
    C:\WINDOWS\IEXPLOR.EXE -- note the spelling
    C:\WINDOWS\FHVPDLL.EXE
    C:\WINDOWS\CITDENC.EXE
    C:\WINDOWS\WinTask.exe
    C:\WINDOWS\tempdl\Terp03292005.exe
    C:\WINDOWS\System32\nsvsvc\
    C:\WINDOWS\System32\picsvr\
    C:\Program Files\Media Access\
    C:\WINDOWS\System32\ifsv_32.exe
    C:\WINDOWS\system\elxwasehgh.exe
    C:\WINDOWS\System32\idefx13n.exe
    C:\PROGRA~1\AWS\
    C:\wp.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rdud.exe
    C:\WINDOWS\System32\nsm1EB9.dll
    c:\windows\system32\msnavc32.exe
    C:\WINDOWS\System32\netsync.exe
    AUNPS2.DLL
    C:\WINDOWS\System32\msmc.exe
    C:\Program Files\GogoTools\
    C:\Documents and Settings\All Users\Application Data\Spam Jump Mix Soft\BurnSettings.exe
    c:\windows\system32\tzszhp.exe
    C:\Program Files\Security iGuard\
    C:\Program Files\sf\
    C:\WINDOWS\sfita.exe
    C:\DOCUME~1\Stephen\APPLIC~1\THATMP~1\Upload Tons Book.exe

    Run CleanUp! and click on CleanUp! button. When it asks you if you want to logoff, click on Yes.

    Reboot into Normal Mode and run new HijackThis scan. If there were some entries that didn't show up in Safe Mode, you may check and fix those that appear now in normal mode (if you do that, make sure to run a new scan again). Save the log file and post it up here.
  • steveoUM

    10 Posts

    502

    0

    Posted April 20th, 2005 00:00

    That seemed to help a bit, especially on reboot. However, I still have the "fatal error in IE" message in the middle of my desktop. I am also still being warned that my "system is attacked by stealth.Hjack virus!" I am also getting a message "Error #317-Mircosoft Windows Security Warning" Finally I keep getting unwanted icons (shortcuts) added to my desktop, even after I delete them. I ran everything you instructed, and here is my lastest log.
    ...Also, I'd like to thank you for your help so far, it's very much appreciated.
     
    Logfile of HijackThis v1.99.1
    Scan saved at 09:35:48 pm, on 04-19-2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\ZCfgSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\WINDOWS\System32\pctspk.exe
    C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
    C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
    C:\Program Files\Belkin F8E825-USB MiniWireless Optical Mouse\cm20.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\Program Files\Common Files\Dell\EUSW\Support.exe
    C:\WINDOWS\System32\gah95on6.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
    C:\Program Files\Spyware Doctor\swdoctor.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\WINDOWS\SYSTEM32\kx509_kfwk5.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\WINDOWS\SYSTEM32\krbcc32s.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    C:\Program Files\Network Associates\VirusScan\mcshield.exe
    C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
    C:\WINDOWS\System32\RegSrvc.exe
    C:\WINDOWS\System32\RoamMgr.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Switching\User\RoamSvc.exe
    C:\WINDOWS\System32\wbem\wmiapsrv.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
    C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\program files\internet explorer\iexplore.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\HijackThis.exe
    C:\PROGRA~1\MUSICM~1\Common\COMPON~1\MMCOMP~1.EXE
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotoffers.info/ad0278/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
    O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
    O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
    O4 - HKLM\..\Run: [Start RF Wireless Mouse] C:\Program Files\Belkin F8E825-USB MiniWireless Optical Mouse\cm20.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
    O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
    O4 - Global Startup: hp psc 1000 series.lnk = ?
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O4 - Global Startup: KX509.lnk = C:\WINDOWS\SYSTEM32\kx509_kfwk5.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.1.5.28/blackjack/blackjack-ob-assets.cab
    O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.1.5.28/jigsaw/jigsaw-ob-assets.cab
    O16 - DPF: Perfect Passer by pogo - http://game1.pogo.com/applet-6.1.5.28/perfectpasser/perfectpasser-ob-assets.cab
    O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.1.5.28/worldclass/worldclass-ob-assets.cab
    O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099015700595
    O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.101.3/g_bin/eng/poker_2_0_0_36.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: Adapter Switching (IntelRoam) - Intel Corporation - C:\Program Files\Intel\Switching\User\RoamSvc.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
    O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
    O23 - Service: PsShutdown (PsShutdownSvc) - Unknown owner - C:\WINDOWS\System32\PSSDNSVC.EXE
    O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
    O23 - Service: RoamMgr - Intel Corporation - C:\WINDOWS\System32\RoamMgr.exe
    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\System32\S24EvMon.exe
     
  • bobmartino

    40 Posts

    502

    0

    Posted April 20th, 2005 10:00

    Make sure to disable Spybot's Tea Timer for now, as it can interfere with the fixing of problems.

    Open Spybot and and make sure you are in Advanced mode (check it in the 'Mode' menu). Go to the Tools section and click resident and then uncheck the box for Tea Timer.

    Reboot into Safe Mode (hit F8 key until menu shows up). Make sure to close any open browsers. Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click Kill process for each one if they are still listed (they shouldn't be - but double check it):

    C:\WINDOWS\System32\gah95on6.exe

    Open Hijack This and click on Scan. Check the following entries, if they are still there.(make sure you do not miss any)

    O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe

    Please remember to close all other windows, including browsers then click Fix checked.

    Delete the following Files indicated in RED and Folders indicated in BLUE if they still exist.

    C:\WINDOWS\System32\gah95on6.exe

    Reboot into Normal Mode and run new HijackThis scan. If there were some entries that didn't show up in Safe Mode, you may check and fix those that appear now in normal mode (if you do that, make sure to run a new scan again). Save the log file and post it up here.

    Let's use a program to scan for any trojans that may exist. Download TDS-3. Learn how to use it here. Make sure to update it after you installed it. You can get the manual updates here. When you launch the program, it will scan your memory for running processes. This will take less than 30 seconds. Next go to System Testing on the menu and choose Full System Scan. After that's finished, post the log file by selecting everything on the top pane (select from bottom to top). If any alarms are found, it will be listed in the bottom window. Please copy and paste that here also if it applies.

     

    I still have the "fatal error in IE" message in the middle of my desktop.

    As a background picture or an error box on the screen?

  • steveoUM

    10 Posts

    502

    0

    Posted April 20th, 2005 20:00

    First off, it appears that the "Error in IE" message is a background, and not an error box. Also the warning message comes from a red circle with an X in the middle, in my system tray. It advises me to download certain software to correct the problem, but I have not. I'm only downloading things you instruct me to. (this post contains 3 sections, the hijack log, the TDS3 log, and the Alarms from the TDS3 scan)
     
    The lastest HijackThis log:
    Logfile of HijackThis v1.99.1
    Scan saved at 03:52:47 pm, on 04-20-2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\ZCfgSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\WINDOWS\System32\pctspk.exe
    C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
    C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
    C:\Program Files\Belkin F8E825-USB MiniWireless Optical Mouse\cm20.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\Program Files\Common Files\Dell\EUSW\Support.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Spyware Doctor\swdoctor.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\WINDOWS\SYSTEM32\kx509_kfwk5.exe
    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
    C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\WINDOWS\SYSTEM32\krbcc32s.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    C:\Program Files\Network Associates\VirusScan\mcshield.exe
    C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
    C:\WINDOWS\System32\RegSrvc.exe
    C:\WINDOWS\System32\RoamMgr.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Switching\User\RoamSvc.exe
    C:\WINDOWS\System32\wbem\wmiapsrv.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
    C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\HijackThis.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\PROGRA~1\MUSICM~1\Common\COMPON~1\MMCOMP~1.EXE
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.umich.edu/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
    O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
    O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
    O4 - HKLM\..\Run: [Start RF Wireless Mouse] C:\Program Files\Belkin F8E825-USB MiniWireless Optical Mouse\cm20.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
    O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
    O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
    O4 - Global Startup: hp psc 1000 series.lnk = ?
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O4 - Global Startup: KX509.lnk = C:\WINDOWS\SYSTEM32\kx509_kfwk5.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.1.5.28/blackjack/blackjack-ob-assets.cab
    O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.1.5.28/jigsaw/jigsaw-ob-assets.cab
    O16 - DPF: Perfect Passer by pogo - http://game1.pogo.com/applet-6.1.5.28/perfectpasser/perfectpasser-ob-assets.cab
    O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.1.5.28/worldclass/worldclass-ob-assets.cab
    O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099015700595
    O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.101.3/g_bin/eng/poker_2_0_0_36.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: Adapter Switching (IntelRoam) - Intel Corporation - C:\Program Files\Intel\Switching\User\RoamSvc.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
    O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
    O23 - Service: PsShutdown (PsShutdownSvc) - Unknown owner - C:\WINDOWS\System32\PSSDNSVC.EXE
    O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
    O23 - Service: RoamMgr - Intel Corporation - C:\WINDOWS\System32\RoamMgr.exe
    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\System32\S24EvMon.exe
     
  • steveoUM

    10 Posts

    502

    0

    Posted April 20th, 2005 20:00

    Sorry about 2 posts, it wouldn't let me put every thing on 1 post, as it was too many characters
     
    The TDS3 scan:
    16:25:22 [Init] Trojan Defence Suite v3.2.0  (UNLICENSED)
    16:25:22 [Init] Started 20-04-05 16:25:22 Eastern Standard Time (UTC: 5), Internet Time @892.62
    16:25:22 [Init] Loading TDS-3 Systems ...
    16:25:22 [Init] Token successfully adjusted.
    16:25:22 [Init] • TDS Privileges   :   OK.      Adjusted TDS-3 token privileges to maximum
    16:25:22 [Init] • Plugins          :   OK.      Loaded 13
    16:25:22 [Init] • Exec Protection  :   Not Installed
    16:25:22 [Init] WARNING: Your Radius.TD3 database needs to be updated!
    16:25:22 [Init] Please download the latest from http://tds.diamondcs.com.au/radius.td3
    16:25:22 [Init] Licensed users can use the Update facility from the TDS menu
    16:25:23 [Init] Loading Radius Advanced Scanning Systems ...
    16:25:28 [Init] • Radius Advanced Specialist Extensions on standby for 13 trojan families
    16:25:28 [Init] • Systems Initialised [39471 references - 16560 primaries/10873 traces/12038 variants/other]
    16:25:28 [Init] Radius Systems loaded.
    16:25:29 [Init] TDS-3 Ready. < Stephen@127.0.0.1 - United States>
    16:25:29 [Tip Of The Day] For freeware applications also released by Diamond Computer Systems, go to http://www.diamondcs.com.au
    16:25:29 [TDS] Good afternoon Stephen.
    16:25:42 [Mutex Memory Scan] Started...
    16:25:44 [Mutex Memory Scan] Finished (no trojan mutexes found).
    16:25:44 [TDS-3] This is an EVALUATION demo of TDS-3. Please see the help file for help on registering.
    16:25:59 [CRC32] Started - verifying 29 files ...
    16:26:00 [CRC32] File doesn't exist: C:\autoexec.bat
    16:26:08 [CRC32] Test finished.
    16:28:55 [Memory Scan] Memory scan started, please wait a moment ...
    16:28:59 [Memory Scan] Memory scan complete.
    16:28:59 [Mutex Memory Scan] Started...
    16:29:01 [Mutex Memory Scan] Finished (no trojan mutexes found).
    16:29:01 [Trace Scan] Started...
    16:29:07 [Trace Scan] Finished.
    16:29:07 [ServiceScan] Scanning for services and drivers ...
    16:29:15 [ServiceScan] Scanned 354 services and drivers.
    16:29:15 [File Scan] Scanning in C:\ ...
    17:32:04 [File Scan] Scanned 54782 files: 31 alarms in 3768.879 seconds (Avg 15.54 files/sec)
    17:32:04 [File Scan] Scanning in D:\ ...
    17:32:04 [File Scan] Scanned 0 files: 31 alarms in 5.859375E-02 seconds (Avg 1. files/sec)
    17:32:04 [File Scan] Scanning in E:\ ...
    17:32:19 [File Scan] Scanned 26 files: 31 alarms in 15.125 seconds (Avg 2.72 files/sec)
    17:32:20 [Scan] Finished.
     
    The TDS3 scan alarm log:
    Scan Control Dumped @ 17:33:53 20-04-05
    Positive identification: Adware.EZula.g2
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp436\a0065379.exe
    Positive identification: Adware.EZula.g
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp436\a0065382.exe
    Positive identification: Adware.EZula.g2
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp436\a0066434.exe
    Positive identification: Adware.EZula.g1
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp436\a0066561.exe
    Positive identification: Adware.EZula.g2
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp437\a0069282.exe
    Positive identification: Adware.EZula.g1
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp437\a0069298.exe
    Positive identification: Adware.EZula.g1
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp437\a0069301.exe
    Positive identification: Adware.EZula.g2
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp441\a0072398.exe
    Positive identification: Adware.EZula.g
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp441\a0072401.exe
    Positive identification: Adware.EZula.g2
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp441\a0072426.exe
    Positive identification: Adware.EZula.g
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp441\a0072431.exe
    Positive identification: Adware.EZula.g2
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp441\a0073639.exe
    Positive identification: Adware.EZula.g
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp441\a0073642.exe
    Positive identification: Adware.EZula.g1
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp442\a0075063.exe
    Positive identification (DLL): Adware.Toolbar.Mirar (dll)
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp442\a0075064.dll
    Positive identification : Possible WebDownloader
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp445\a0078306.exe
    Positive identification : Possible WebDownloader
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp445\a0078335.exe
    Positive identification : Possible WebDownloader
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp445\a0078336.exe
    Positive identification : Possible WebDownloader
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp445\a0078338.exe
    Positive identification (DLL): Adware.DelfinMediaViewer (dll)
      File: c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\rp445\a0078345.ocx
    Positive identification: TrojanDropper.Win32.Small.fl
      File: c:\windows\system32\setup66.exe
    Positive identification (embedded in file): Adware.Toolbar.Mirar (dll)
      File: c:\windows\system32\cache\876003.exe
    Positive identification (embedded in file): Adware.Toolbar.Mirar.a (dll)
      File: c:\windows\system32\cache\876003.exe
    Positive identification: Adware.EZula.g1
      File: c:\windows\system32\cache\ezstub.exe
    Positive identification : Suspicious: Microsoft-tagged exe built with Borland compiler
      File: c:\windows\system32\cache\helperinstall.exe
    Positive identification (embedded in file): Trojan.Win32.Small.i
      File: c:\windows\system32\cache\omi-ic-setup.exe
    Positive identification (embedded in file): Trojan.Win32.Small.i
      File: c:\windows\system32\cache\omi.exe
    Positive identification : Possible WebDownloader
      File: c:\windows\system32\cache\pop.exe
    Positive identification: TrojanDropper.Win32.Small.fl
      File: c:\windows\system32\cache\setup66.exe
    Positive identification (embedded in file): TrojanDropper.Win32.Small.fl
      File: c:\windows\system32\cache\setupwrapper.exe
    Suspicious Filename: Dual extensions
      File: c:\windows\system32\cache\us4.0-2.exe
  • bobmartino

    40 Posts

    502

    0

    Posted April 20th, 2005 21:00

    Ok, now for some more log fun.

    Can you run a scan at http://www.pandasoftware.com/activescan/com/activescan_principal.htm and post up the output here.

    cheers

  • steveoUM

    10 Posts

    502

    0

    Posted April 21st, 2005 07:00

    The log you requested
    Incident                      Location                                                                          
    Adware:Adware/Hotoffers       C:\WINDOWS\System32\param32.dll
    Virus:Trj/Clicker.CY          Operating system
    Adware:Adware/Ucmore          C:\Program Files\thesearchaccelerator
    Adware:Adware/SaveNow         Windows Registry
    Adware:Adware/MyWay           C:\Program Files\MySearch
    Adware:Adware/nCase           C:\WINDOWS\System32\FLEOK
    Spyware:Spyware/ISTbar        C:\Program Files\Common Files\Totem Shared
    Spyware:Spyware/BetterInet    Windows Registry
    Adware:Adware/SAHAgent        C:\WINDOWS\a95kfrhe.exe
    Adware:Adware/Apropos         C:\Program Files\cxtpls
    Adware:Adware/WinTools        Windows Registry
    Adware:Adware/ISearch         C:\WINDOWS\deskbar.ini
    Adware:Adware/WUpd            C:\WINDOWS\System32\a95kfrhe.ini
    Adware:Adware/Beginto         C:\WINDOWS\System32\rtneg?.dll                                
    Adware:Adware/MyWebSearch     Windows Registry                                                   
    Adware:Adware/Kingporn        C:\WINDOWS\System32\commcoss.dll                       
    Spyware:Spyware/Spyblocs      C:\Documents and Settings\Stephen\Desktop\Remove Spyware.url                  
    Spyware:Spyware/Search3       C:\Program Files\Search3 Toolbar                                 
    Adware:Adware/BTGrab          Windows Registry
    Adware:Adware/InstaFinder     C:\Program Files\INSTAFINK
    Adware:Adware/Pacimedia       C:\Documents and Settings\Stephen\Favorites\1111\1111.url                          
    Adware:Adware/IGuard          C:\WINDOWS\System32\wldr.dll                     
    Adware:Adware/Hotoffers       Windows Registry                                   
    Adware:Adware/SearchTheWeb    C:\WINDOWS\System32\Cache\mswinstall.exe          
    Virus:Exploit/ByteVerify      C:\Documents and Settings\Stephen\.jpi_cache\jar\1.0\arc.zip-53b42299-7a4efbaa.zip[VerifierBug.class] 
    Virus:Exploit/ByteVerify      C:\Documents and Settings\Stephen\.jpi_cache\jar\1.0\arc.zip-53b42299-7a4efbaa.zip[Counter.class]      
    Virus:Exploit/ByteVerify      C:\Documents and Settings\Stephen\.jpi_cache\jar\1.0\arc.zip-53b42299-7a4efbaa.zip[Gummy.class]         
    Virus:Exploit/ByteVerify      C:\Documents and Settings\Stephen\.jpi_cache\jar\1.0\arc.zip-53b42299-7a4efbaa.zip[Beyond.class]       
    Virus:Exploit/ByteVerify      C:\Documents and Settings\Stephen\.jpi_cache\jar\1.0\arc.zip-53b42299-7a4efbaa.zip[Worker.class]  
    Spyware:Spyware/AdClicker     C:\Documents and Settings\Stephen\.jpi_cache\jar\1.0\arc.zip-53b42299-7a4efbaa.zip[web.exe]       
    Adware:Adware/PurityScan      C:\Documents and Settings\Stephen\Application Data\osoa.exe           
    Adware:Adware/Lop             C:\Documents and Settings\Stephen\Application Data\That mp3 five\comp cdrom mags rdr.exe    
    Adware:Adware/Lop             C:\Documents and Settings\Stephen\Application Data\That mp3 five\Date Info Once.exe             
    Adware:Adware/Lop             C:\Documents and Settings\Stephen\Application Data\That mp3 five\llhakhtp.exe          
    Virus:W32/Spybot.QV.worm      C:\Documents and Settings\Stephen\Local Settings\Temp\tp7543.exe                  
    Adware:Adware/Minibug         C:\Program Files\AIM\Sysfiles\WxBug.EXE                                                           
    Adware:Adware/DelFinMedia     C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe   
    Adware:Adware/Apropos         C:\Program Files\CxtPls\ace.dll                                         
    Adware:Adware/Apropos         C:\Program Files\CxtPls\CxtPls.dll                                   
    Adware:Adware/Apropos         C:\Program Files\CxtPls\CxtPls.exe                    
    Adware:Adware/Apropos         C:\Program Files\CxtPls\ProxyStub.dll               
    Adware:Adware/Apropos         C:\Program Files\CxtPls\uninstaller.exe              
    Adware:Adware/Apropos         C:\Program Files\CxtPls\WinGenerics.dll    
    Spyware:Spyware/ClearSearch   C:\Program Files\oft8m045\3p07f56f.DLL  
    Spyware:Spyware/ClearSearch   C:\Program Files\oft8m045\7s442bhq.DLL     
    Adware:Adware Program         C:\Program Files\oft8m045\87672918.exe         
    Spyware:Spyware/ClearSearch   C:\Program Files\oft8m045\dpcq38eb.DLL     
    Virus:Trj/Small.GO            C:\temporary\aun_0018.exe                                     
    Adware:Adware/PortalScan      C:\temporary\aun_0029.exe                             
    Adware:Adware/SAHAgent        C:\WINDOWS\70tovmto.exe            
    Adware:Adware/SAHAgent        C:\WINDOWS\a95kfrhe.exe          
    Virus:Trj/SCBop.B             C:\WINDOWS\ms05595670-10022005.exe  
    Virus:Trj/SCBop.B             C:\WINDOWS\ms075670-1002592005.exe  
    Virus:Trj/SCBop.B             C:\WINDOWS\SysCheckBop32.exe              
    Adware:Adware/SAHAgent        C:\WINDOWS\SYSTEM32\2b3fsk0h.dll         
    Adware:Adware/SAHAgent        C:\WINDOWS\SYSTEM32\a95kfrhe.ini         
    Virus:Trj/Downloader.BOV      C:\WINDOWS\SYSTEM32\AUNPS.dll            
    Adware:Adware/SAHAgent        C:\WINDOWS\SYSTEM32\bln02nqv.exe     
    Virus:Trj/Downloader.AWZ      C:\WINDOWS\SYSTEM32\Cache\20001.exe
    Virus:Trj/TSUpdate.A          C:\WINDOWS\SYSTEM32\Cache\AMEX_54.exe  
    Virus:Trj/Downloader.BOD      C:\WINDOWS\SYSTEM32\Cache\AUNIcons.exe                       
    Adware:Adware/Beginto         C:\WINDOWS\SYSTEM32\Cache\b2s-537466.exe                     
    Virus:Trj/Downloader.BJG      C:\WINDOWS\SYSTEM32\Cache\EDow_AS2.exe                    
    Spyware:Spyware/ISTbar        C:\WINDOWS\SYSTEM32\Cache\em_d.exe                             
    Adware:Adware/eZula           C:\WINDOWS\SYSTEM32\Cache\ezstub.exe                              
    Adware:Adware/Gogotools       C:\WINDOWS\SYSTEM32\Cache\gogotoolssilawo18pi.exe    
    Virus:Trj/Delf.EB             C:\WINDOWS\SYSTEM32\Cache\HelperInstall.exe                         
    Adware:Adware/ISearch         C:\WINDOWS\SYSTEM32\Cache\HLInstaller.exe       
    Spyware:Spyware/ISTbar        C:\WINDOWS\SYSTEM32\Cache\ic_d.exe            
    Adware:Adware/PortalScan      C:\WINDOWS\SYSTEM32\Cache\InstallAPS.exe 
    Virus:Trj/Multidropper.XI     C:\WINDOWS\SYSTEM32\Cache\installer_282r2_189.exe       
    Spyware:Spyware/BargainBuddy  C:\WINDOWS\SYSTEM32\Cache\installer_MARKETING17.exe  
    Virus:Trj/Multidropper.UO     C:\WINDOWS\SYSTEM32\Cache\Kyongju.exe                                  
    Adware:Adware/ISearch         C:\WINDOWS\SYSTEM32\Cache\MTE0MzA6ODoxMg.exe           
    Virus:Trj/Downloader.BBA      C:\WINDOWS\SYSTEM32\Cache\MTE1NDE6ODoxMg.exe       
    Adware:Adware/ISearch         C:\WINDOWS\SYSTEM32\Cache\MTE1NjE6ODoxMg.exe         
    Adware:Adware/ISearch         C:\WINDOWS\SYSTEM32\Cache\MTE1NTA6ODoxMg.exe    
    Virus:Trj/Small.GZ            C:\WINDOWS\SYSTEM32\Cache\omi-ic-setup.exe                        
    Virus:Trj/Small.GZ            C:\WINDOWS\SYSTEM32\Cache\omi.exe                                  
    Adware:Adware/nCase           C:\WINDOWS\SYSTEM32\Cache\pop.exe                     
    Virus:Trj/Downloader.BJG      C:\WINDOWS\SYSTEM32\Cache\Pop1.exe    
    Spyware:Spyware/ShhhToolbar   C:\WINDOWS\SYSTEM32\Cache\runsearch.exe  
    Virus:Trj/SCBop.B             C:\WINDOWS\SYSTEM32\Cache\Setup.exe          
    Spyware:Spyware/UrlSpy        C:\WINDOWS\SYSTEM32\Cache\setup1015.exe    
    Virus:Trj/Downloader.BJG      C:\WINDOWS\SYSTEM32\Cache\setup1015a.exe    
    Virus:Trj/Dropper.DB          C:\WINDOWS\SYSTEM32\Cache\SetupWrapper.exe    
    Virus:Trj/Downloader.BJF      C:\WINDOWS\SYSTEM32\Cache\skh2.exe              
    Spyware:Spyware/SurfSideKick  C:\WINDOWS\SYSTEM32\Cache\SSK_B5 Seedcorn 2.EXE  
    Spyware:Spyware/SurfSideKick  C:\WINDOWS\SYSTEM32\Cache\SSK_B5 Ventura Marketing 3.EXE 
    Virus:Trj/Downloader.BYZ      C:\WINDOWS\SYSTEM32\Cache\stubinstaller5592.exe    
    Spyware:Spyware/BetterInet    C:\WINDOWS\SYSTEM32\Cache\thin-8-3-x-x.exe    
    Adware:Adware/ILookup         C:\WINDOWS\SYSTEM32\Cache\trafficgeneration-fran.exe 
    Adware:Adware/ILookup         C:\WINDOWS\SYSTEM32\Cache\trgen-fran-default.exe 
    Adware:Adware/ILookup         C:\WINDOWS\SYSTEM32\Cache\trgen_fran-162813.exe 
    Adware:Adware/Ucmore          C:\WINDOWS\SYSTEM32\Cache\ucmoreiex.exe 
    Adware:Adware/QoolAid         C:\WINDOWS\SYSTEM32\Cache\VCM QOOL_3.exe
    Virus:Trj/Multidropper.XI     C:\WINDOWS\SYSTEM32\Cache\VCM2 Qinstaller 282_190.exe
    Virus:Trj/Downloader.BJI      C:\WINDOWS\SYSTEM32\Cache\VCMnet7 updated 030905.exe
    Adware:Adware/Apropos         C:\WINDOWS\SYSTEM32\fmihu.exe 
    Adware:Adware/Apropos         C:\WINDOWS\SYSTEM32\gpunw.exe
    Adware:Adware/Hotoffers       C:\WINDOWS\SYSTEM32\guninst.exe 
    Virus:W32/Spybot.QV.worm      C:\WINDOWS\SYSTEM32\irarik.exe
    Adware:Adware/Apropos         C:\WINDOWS\SYSTEM32\mipman32.exe
    Spyware:Spyware/SafeSurf      C:\WINDOWS\SYSTEM32\netsync.exe
    Adware:Adware/Beginto         C:\WINDOWS\SYSTEM32\nsa2A16.dll
    Adware:Adware/Beginto         C:\WINDOWS\SYSTEM32\nsy2495.dll 
    Adware:Adware/Hotoffers       C:\WINDOWS\SYSTEM32\param32.dll
    Adware:Adware/ILookup         C:\WINDOWS\SYSTEM32\rtneg.dll 
    Adware:Adware/Beginto         C:\WINDOWS\SYSTEM32\rtneg2.dll
    Virus:Trj/Clicker.CY          C:\WINDOWS\SYSTEM32\winup2date.dll 
    Adware:Adware/IGuard          C:\WINDOWS\SYSTEM32\wldr.dll 
    Virus:Trj/Clicker.CX          C:\WINDOWS\SYSTEM32\wmconfig.cpl 
    Virus:W32/Spybot.QV.worm      C:\WINDOWS\SYSTEM32\wqgqw.dat 
    Adware:Adware/AdLogix         C:\WINDOWS\SYSTEM32\xscjl.dll
    Virus:Trj/Clicker.CZ          C:\WINDOWS\unadbeh.exe
  • bobmartino

    40 Posts

    276

    0

    Posted April 21st, 2005 11:00

    Hmmm, the panda log should look like this
    Adware:Adware/nCase No disinfected C:\WINDOWS\system32\Cache\pop.exe

    Anyway, lets try get rid of some stuff

    Goto Control Panel -> add/remove programs and remove these if they are there

    cxtpls

    Go to Start->Run and type in regedit and hit OK. Go to File->Export and save the registry somewhere as a backup. While in the Registry Editor, navigate to, some may not exist:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and delete the entry on the right called "WindowsFY"
    HKEY_CLASSES_ROOT\CLSID\ and delete the subkey on the left "{145E6FB1-1256-44ed-A336-8BBA43373BE6}"
    HKEY_CURRENT_USER\Software\Micorsoft\Windows\CurrentVersion\Policies\Explorer and delete the entry on the right called "NoActiveDesktopChanges"
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System and delete the entry on the right called "NoDispBackgroundPage" AND "NoDispAppearancePage"

    If any of the above registry keys are giving you problems deleting, right click on them and click on Permissions. Then click on the Advanced button. Make sure the first box (Inherit from parent...) is checked. Click OK and OK. Then try deleting the entry again. Once you're done, close the Registry Editor.

    There is too many files to go after at one go, and I also don't know what panda disenfected, so we will take a few runs at it.

    Download KillBox http://www.greyknight17.com/spy/KillBox.exe. Run KillBox and check the box that says 'End Explorer Shell While Killing File'. Next click on 'Delete on Reboot'. For each of the following files below, check the box that says 'Unregister .dll Before Deleting' if it's not grayed out. Copy and paste each of the following into KillBox (hitting the X button for each file - choose NO when it asks if you want to reboot):

    C:\wp.bmp
    c:\windows\system32\setup66.exe
    c:\windows\system32\cache\876003.exe
    c:\windows\system32\cache\setup66.exe
    c:\windows\system32\cache\pop.exe
    c:\windows\system32\cache\setupwrapper.exe
    C:\WINDOWS\System32\Cache\mswinstall.exe
    C:\WINDOWS\System32\wldr.dll
    C:\WINDOWS\System32\param32.dll
    C:\Program Files\Common Files\Totem Shared
    C:\WINDOWS\a95kfrhe.exe
    C:\Program Files\cxtpls
    C:\WINDOWS\deskbar.ini
    C:\Documents and Settings\Stephen\Application Data\osoa.exe
    C:\Documents and Settings\Stephen\Application Data\That mp3 five\comp cdrom mags rdr.exe
    C:\Documents and Settings\Stephen\Application Data\That mp3 five\Date Info Once.exe
    C:\Documents and Settings\Stephen\Application Data\That mp3 five\llhakhtp.exe
    C:\Documents and Settings\Stephen\Application Data\That mp3 five\
    C:\Documents and Settings\Stephen\Local Settings\Temp\tp7543.exe
    C:\Program Files\oft8m045\3p07f56f.DLL
    C:\Program Files\oft8m045\7s442bhq.DLL
    C:\Program Files\oft8m045\87672918.exe
    C:\Program Files\oft8m045\dpcq38eb.DLL
    C:\Program Files\oft8m045\
    C:\temporary\aun_0018.exe
    C:\temporary\aun_0029.exe
    C:\WINDOWS\70tovmto.exe
    C:\WINDOWS\ms05595670-10022005.exe
    C:\WINDOWS\ms075670-1002592005.exe
    C:\WINDOWS\SysCheckBop32.exe
    C:\WINDOWS\SYSTEM32\2b3fsk0h.dll
    C:\WINDOWS\SYSTEM32\a95kfrhe.ini
    C:\WINDOWS\SYSTEM32\Cache\HelperInstall.exe
    C:\WINDOWS\SYSTEM32\Cache\HLInstaller.exe
    C:\WINDOWS\SYSTEM32\Cache\installer_282r2_189.exe
    C:\WINDOWS\SYSTEM32\Cache\installer_MARKETING17.exe
    C:\WINDOWS\SYSTEM32\Cache\Kyongju.exe
    C:\WINDOWS\SYSTEM32\Cache\pop.exe
    C:\WINDOWS\SYSTEM32\Cache\Pop1.exe

    Restart.

    You should hopefully now be able to change your desktop back to normal by usual methods
    Right click on desktop
    Select Properties
    In the Desktop tab, set the following properties:

    Background
    Position
    Color

    Click OK

    Run a new panda scan and post up the results, we shall try go after the rest of these files.