UNSOLVED

ACSP

updated

20 years ago

A

ACSP

12 Posts

0

1037

May 11th, 2006 21:00

Strange Behavior 2

My computer has been doing strange things- the start menu duplicates itself, windows explorer shuts down and removes some of the tray icons.  Active x and .dill files are missing from Internet Explorer.
 
Logfile of HijackThis v1.99.1
Scan saved at 4:25:52 PM, on 5/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\cisvc.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Dell\AccessDirect\DadTray.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\cidaemon.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\AOL\1145773832\ee\AOLSoftware.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\AOL Companion\companion.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\Common Files\Aol\aoltpspd.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1145773832\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Update Page Content - C:\Program Files\MSN\MSNIA\CC\MSNCC\WA\refreshpage.htm
O8 - Extra context menu item: View All Originals On Page - C:\Program Files\MSN\MSNIA\CC\MSNCC\WA\getoriginal.htm
O8 - Extra context menu item: View Original Image - C:\Program Files\MSN\MSNIA\CC\MSNCC\WA\getoriginal.htm
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/1365f1b8be0c48b9a500/netzip/RdxIE601.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1131153223349
O16 - DPF: {776706AE-CACA-4EA3-93DF-BB83D9259DA9} (MailConfigure Class) - http://supportservices.msn.com/us/oeconfig/MailCfg.cab
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.mcafee.com/products/protected/mvt/mvt.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB4C01E2-3E29-4A7F-A4A0-FD05965765E3}: NameServer = 205.188.146.145
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
 
  • RKinner

    2 Intern

    •

    5851 Posts

    281

    0

    Posted May 11th, 2006 21:00

    Don't see anything in your log.

    Have you checked the C:\ drive for errors?

    Start, My Computer, then rightclick on Local Drive C: and select Properties then Tools, (Error Checking) Check Now.  Check the two options then Start.  It almost always complains that it can't do it now but would like to schedule it for your next boot.  Let it do that then reboot.  It will take a while so be patient.

    You may just be running too many antispyware apps.  Sometimes they fight each other.

    Never hurts to do one of the free on-line scans from Panda or Trend.  They take a while but are pretty good.
    www.pandasoftware.com/activescan/activescan.asp?


    http://uk.trendmicro-europe.com/consumer/housecall/housecall_launch.php (works with both java and activeX browsers)
    or
    http://housecall60.trendmicro.com/en/start_corp.asp?id=scan (activeX only, but with some extra useful option

    Check the Event log for clues:

    Start, Run, eventvwr,msc, OK then select System.  Look for red marked events near the time of your last problem.  Doubleclick on one to open it then copy the text by clicking on the bottom of the three buttons then move to a reply to this post and Edit. Paste (or Ctrl + v).  Repeat for each different error.  (If you have multiple copies of the same error just post one copy and tell me you have 10 of these or whatever.)  Also look under Applications.

     

    Ron

  • ACSP

    12 Posts

    281

    0

    Posted May 11th, 2006 21:00

    Thanks so much for the quick response.  I will get started working on the things you suggested.  One thing I forgot to mention - the organize favorites box no longer lists my favorites-now it has a red x.  When I clicked on it, I got www.doubleclick.net.  I have deleted this from the cookies file, but I can't remove this.  Also, how may spyware programs do you think are sufficient? 

    Message Edited by ACSP on 05-11-200605:33 PM

  • RKinner

    2 Intern

    •

    5851 Posts

    281

    0

    Posted May 12th, 2006 01:00

    Start, Run, cmd.exe, OK to bring up a new black cmd window and type:
     
    cd \windows\system32
    regsvr32 /s jscript.dll
    regsvr32 /s msxml.dll
    regsvr32 /s vbscript.dll
     
    Don't know if that will help but it won't hurt.  The Organize Favorites window is apparently created by JavaScript and I have seen a few cases where somehow the jscript.dll and his friends got unregistered.  Usually when someone removed Norton/Symantec programs.  Their uninstaller seems to have some major problems.
     
    Ron
  • ACSP

    12 Posts

    281

    0

    Posted May 13th, 2006 07:00

    I've completed all of the items that you outlined.  The check disk was good and I have no errors in the event log for apps, security or system.  One of the scans found a Trojan - exploit.  It was deleted.  The other scan found a potential rootkit which it deleted on reboot.  Also found was a doubleclick cookie in the systemroot that could not be deleted.  I am having the same problems, plus I keep hearing a clicking noise while viewing several different sites.  In addition, the Microsoft Removal Tool is no longer on my computer.  It was replaced with 2 files that I deleted. 

    I hope this is not as bad as it feels!  Please let me know what I should do next.

    Thanks again. 

  • RKinner

    2 Intern

    •

    5851 Posts

    281

    0

    Posted May 15th, 2006 17:00

    Do you have the exact name and location of any of the files that were found by the scans?

     

    Ron

     

  • ACSP

    12 Posts

    281

    0

    Posted May 17th, 2006 06:00

    This is the Trojan:  JS/Exploit-BO.gen  It was found in the Windows Temp Directory

    This is the Rootkit Information: Found System Monitor: potentially rootkit-masked files.  Warning: Unhandled Archive Type.  Traces Found: 4

    These were files that I saved from WebMD.

    Also, I followed your instructions and I was able to view the organize favorites box, however, the next day they were gone again.

     

    Message Edited by ACSP on 05-17-200602:31 AM

  • RKinner

    2 Intern

    •

    5851 Posts

    281

    0

    Posted May 17th, 2006 16:00

    We have two fairly good tools for rootkits:
     
    try RootKitRevealer from SysInternals and see if it finds anything:
    http://www.sysinternals.com/Utilities/RootkitRevealer.html
    It likes to find registry entries but ignore them.  Just look for files that end in .exe, .sys or .dll.
     
     
    Also download and run blacklight
    F-Secure Blacklight: http://www.f-secure.com/blacklight/try.shtml
     
    click > scan then > next,
    If any items show have blacklight rename them except for wbemtest.exe"
    Do not rename "wbemtest.exe" it's a windows file
    The tool will ask if you want to reboot (restart) choose yes.
     
     
    Also download and install Windows Script 5.6
     
     
     
     
    Ron
  • ACSP

    12 Posts

    281

    0

    Posted May 18th, 2006 06:00

    I followed all of your instructions ---

    Rootkit Revealer - No .dill, .exe. or .sys files.  Only 1 registry item (Data Mismatch).

    F-Secure Blacklight - No hidden files.

    I also installed Script 5.6 - I haven't noticed anything different.  I am still unable to view the organize favorites box.

    I don't know if this is important, but I noticed an entry in my hijack this log, 017 for host file 205.188.136.145.

    Let me know what's next - I'm perplexed!

  • RKinner

    2 Intern

    •

    5851 Posts

    281

    0

    Posted May 18th, 2006 13:00

    205.188.136.145 is AOL's DNS server.  Not a problem.
     
    Start, Run, services.msc, OK and when the services list comes up find:
     
    Symantec Network Drivers Service (SNDSrvc)  and doubleclick on it.  Then change the Startup Type: to Disabled.  Apply.
     
    Probably won't help any but at least it shouldn't try to start any more.  Also it would probably be a good idea to follow the instructions here to make sure Symantec is completely uninstalled.
     
     
    Then repeat the regsvr32 commands.
     
    Also turn off Spybot's teatimer (or just uninstall Spybot) then
    run HJT, scan only and check these (if still there) then Fix Checked:
     
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
     
    Now Start, Run, cmd.exe, OK
     
    cd \
    dir /a /s wmplayer.exe
     
    Then highlight the result of the last command and hit Enter.  That should copy the text.  Move to a reply and Edit, Paste.
     
    Probably wouldn't hurt to run another scan and see if it finds anything.  Try kaspersky
     
     
     
     
    Ron
     

     
     
     
  • ACSP

    12 Posts

    112

    0

    Posted May 19th, 2006 06:00

    Hi,

    Here is the info you requested --


     Volume in drive C is Main Drive
     Volume Serial Number is 80CC-4D6F

     Directory of C:\I386

    08/28/2002  04:00 PM           520,192 WMPLAYER.EXE
                  1 File(s)        520,192 bytes

     Directory of C:\Program Files\Windows Media Player

    09/22/2004  07:46 PM            73,728 wmplayer.exe
                  1 File(s)         73,728 bytes

     Directory of C:\WINDOWS\RegisteredPackages\{B3C1B200-8F14-4C49-96D3-67425AD5991
    4}

    04/11/2003  03:11 PM           520,192 wmplayer.exe
                  1 File(s)        520,192 bytes

     Directory of C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF0879
    9}

    09/22/2004  07:46 PM            73,728 wmplayer.exe
                  1 File(s)         73,728 bytes

     Directory of C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF0879
    9}$BACKUP$\System

    12/11/2002  05:27 PM            73,728 wmplayer.exe
                  1 File(s)         73,728 bytes

     Directory of C:\WINDOWS\ServicePackFiles\i386

    08/04/2004  12:56 AM            73,728 wmplayer.exe
                  1 File(s)         73,728 bytes

     Directory of C:\WINDOWS\SoftwareDistribution\Download\9ded4ee34a35fced0033d3e15
    2a36e0e

    08/04/2004  02:56 AM            73,728 wmplayer.exe
                  1 File(s)         73,728 bytes

     Directory of C:\WINDOWS\SYSTEM32\DLLCACHE

    09/22/2004  07:46 PM            73,728 wmplayer.exe
                  1 File(s)         73,728 bytes

        Total Files Listed:
                  8 File(s)      1,482,752 bytes
                  0 Dir(s)  20,420,993,024 bytes free

    C:\>

    Also used Symantec tool - now totally uninstalled, removed Spybot, did HJT scan and fixed the items that you had specified and ran Kaspersky virus scan - no malware detected-clean.

    FYI --- While online earlier my virus program, McAfee, cleaned and deleted the VBS/Psyme Trojan. Also, the organize favorities box is still blank, but everything else appears normal.