UNSOLVED

smc0827

updated

21 years ago

S

smc0827

14 Posts

0

2299

March 19th, 2005 23:00

Help! Have virus.

Hi - my son apparently opened a file through MSN Messenger and I now have a formatsys virus.  I have McAfee online anti-virus and firewall, but am unable to access McAfee or other virus removal sites online.  Also cannot use system restore - it says that "it has been turned off by group policy, and to contact my domain administrator".  Please tell me how to remove this virus when I am unable to go to a website to run a scan.  thanks!
 
Logfile of HijackThis v1.99.1
Scan saved at 7:21:09 PM, on 3/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Net Nanny\nnsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\sysmtor.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Net Nanny\nntray.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
c:\windows\system32\ctmn.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Aluria Software\ASE\ASE Scheduler.exe
C:\WINDOWS\system32\dlbtcoms.exe
C:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.netnanny.com/p/search?pi=nnh5&qt=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.netnanny.com/p/search?pi=nnh5&qt=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.netnanny.com/p/search?pi=nnh5&qt=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O1 - Hosts: 64.233.167.104 www.symantec.com
O1 - Hosts: 64.233.167.104 www.sophos.com
O1 - Hosts: 64.233.167.104 www.mcafee.com
O1 - Hosts: 64.233.167.104 www.viruslist.com
O1 - Hosts: 64.233.167.104 www.f-secure.com
O1 - Hosts: 64.233.167.104 www.avp.com
O1 - Hosts: 64.233.167.104 www.kaspersky.com
O1 - Hosts: 64.233.167.104 www.networkassociates.com
O1 - Hosts: 64.233.167.104 www.ca.com
O1 - Hosts: 64.233.167.104 www.my-etrust.com
O1 - Hosts: 64.233.167.104 www.nai.com
O1 - Hosts: 64.233.167.104 www.trendmicro.com
O1 - Hosts: 64.233.167.104 securityresponse.symantec.com
O1 - Hosts: 64.233.167.104 sophos.com
O1 - Hosts: 64.233.167.104 mcafee.com
O1 - Hosts: 64.233.167.104 liveupdate.symantecliveupdate.com
O1 - Hosts: 64.233.167.104 viruslist.com
O1 - Hosts: 64.233.167.104 f-secure.com
O1 - Hosts: 64.233.167.104 kaspersky.com
O1 - Hosts: 64.233.167.104 kaspersky-labs.com
O1 - Hosts: 64.233.167.104 avp.com
O1 - Hosts: 64.233.167.104 networkassociates.com
O1 - Hosts: 64.233.167.104 ca.com
O1 - Hosts: 64.233.167.104 mast.mcafee.com
O1 - Hosts: 64.233.167.104 my-etrust.com
O1 - Hosts: 64.233.167.104 download.mcafee.com
O1 - Hosts: 64.233.167.104 dispatch.mcafee.com
O1 - Hosts: 64.233.167.104 secure.nai.com
O1 - Hosts: 64.233.167.104 nai.com
O1 - Hosts: 64.233.167.104 update.symantec.com
O1 - Hosts: 64.233.167.104 updates.symantec.com
O1 - Hosts: 64.233.167.104 us.mcafee.com
O1 - Hosts: 64.233.167.104 liveupdate.symantec.com
O1 - Hosts: 64.233.167.104 customer.symantec.com
O1 - Hosts: 64.233.167.104 rads.mcafee.com
O1 - Hosts: 64.233.167.104 trendmicro.com
O1 - Hosts: 64.233.167.104 sandbox.norman.no
O1 - Hosts: 64.233.167.104 www.pandasoftware.com
O1 - Hosts: 64.233.167.104 uk.trendmicro-europe.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [NNTray] C:\Program Files\Net Nanny\nnstart.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [serpe] C:\WINDOWS\system32\serbw.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [ltwob] C:\WINDOWS\system32\formatsys.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [CMSETTINGS] C:\WINDOWS\system32\ctbeg.exe
O4 - HKLM\..\Run: [avnort] C:\WINDOWS\msmbw.exe
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKLM\..\RunServices: [avnort] C:\WINDOWS\msmbw.exe
O4 - HKLM\..\RunServices: [ltwob] C:\WINDOWS\system32\formatsys.exe
O4 - HKLM\..\RunServices: [serpe] C:\WINDOWS\system32\serbw.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Startup: ASE Scheduler.lnk = C:\Program Files\Aluria Software\ASE\ASE Scheduler.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Aluria Spyware Eliminator Service (ASEService) - Unknown owner - C:\PROGRA~1\ALURIA~1\ASE\ASEServ.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NNSvc - Looksmart, Ltd. - C:\Program Files\Net Nanny\nnsvc.exe
O23 - Service: sysmtor - BioNet Systems, LLC - C:\WINDOWS\system32\sysmtor.exe
 
  • Bertha2

    711 Posts

    553

    0

    Posted March 20th, 2005 10:00

    Hey smc,

    I am currently looking at your Hijackthis Log now and will get back to you shortly

    Bertha2

  • ky331

    5 Journeyman

    15622 Posts

    45048 Points

    553

    0

    Posted March 20th, 2005 12:00

    Under the rule that no specific hijacklog assistance has been offered yet, I am replying here:
     
    Your computer has more than one problem.  What I have to say will help only the specific problem of the FORMATSYS worm/virus you obtained via MSN Messenger.   After you follow these directions, you should come back to this forum with a revised HiJack Log for additional assistance, and other people will help you.
     
    Your computer has been infected by the  W32.Serflog.A worm (also known as W32/Sumom-A ), and you should do the following:
     
    I've located a removal tool for the virus, from Symantec. However, one of the "quirks" of the virus is that it will not let you access the Symantec site :-(  Fortunately, upon searching further, I found out that the Symantec tool is also available from MajorGeeks:

    http://majorgeeks.com/download4523.html

    which, hopefully, has not been blocked.  Go there, download the

    Symantec W32.Serflog.A Free Removal Tool 1.02 :  FixSflog.exe

    and then follow these directions.  You may want to print these out before continuing.

    1. Download the FixSflog.exe file from http://majorgeeks.com/download4523.html

    Note:  This is a very 'resistant' worm.  If, for any reason, you cannot perform/complete the download from this site, then you'll have to go to another "clean" PC (a friend's, at work, etc.), download it there, copy it to a floppy (it's a very small file), and then, bring it back to your infected P.C.

    2. Save the file to a convenient location, such as your Windows desktop.

    3. Close all the running programs.

    4. If you are on a network or if you have a full-time connection to the Internet, disconnect the computer from the network and the Internet.

    5. Locate the file that you just downloaded.

    6. Double-click the FixSflog.exe file to start the removal tool.

    7. Click Start to begin the process, and then allow the tool to run.

    8. Restart the computer.

    9. After rebooting, run the removal tool again to ensure that the system is clean.  (Do not be surprised if it finds some entries again.)

    10. If you are on a network or if you have a full-time connection to the Internet, reconnect the computer to the network or to the Internet connection.

    11. Update your anti-virus definitions, and run a complete virus scan.

     

    Message Edited by ky331 on 03-20-2005 09:18 AM

  • Bertha2

    711 Posts

    553

    0

    Posted March 20th, 2005 16:00

    Firstly ky331 I am providing Hijackthis assistance here as I said "I was looking at their HJT Log and will get back to them shortly!!!!!!!!

    Also you have messed up this fix becuase their hosts files need resetting before they run any Online Scans

    So smc,

    Print the following instructions off as you will need to be offline

    Download Hoster here - http://members.aol.com/toadbee/hoster.zip
    Unzip it

    Run it and click
    "Restore original Microsft Hosts"

    Reboot

    Run some Online scans:

    Panda -
    http://www.pandasoftware.com/activescan/com/activescan_principal.htm

    Housecall -
    http://housecall.trendmicro.com/housecall/start_corp.asp

    eTrust -
    http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

    Allow them to remove anything they find and note down anything they find but cannot remove and its location and post back here in your reply
     
    Please download and run AdAware and Spybot S&D

    AdAware -
    http://www.lavasoftusa.com/software/adaware/

    Spybot S&D -
    http://www.safer-networking.org/en/download/index.html

    See here for how to set them up
    http://forum.malwareremoval.com/viewtopic.php?t=13

    Post a New Hijackthis Log Back Here and Ill take another look

    Bertha

  • Bertha2

    711 Posts

    553

    0

    Posted March 20th, 2005 17:00

    Hey smc

    Firstly I am sorry about this "SMC"

    (Midnight yes Ky331's tool would work but it needs to be run after the hosts files have been reset which is part of the fix I advised)

    SMC please follow my fix and only use Ky331's tool after you have completed the resetting of the hosts files!!

    Bertha2

  • Midnight Star

    4791 Posts

    553

    0

    Posted March 20th, 2005 17:00

    smc,

    I apologize for any confusion this might be causing you. I'll check with the forum where Bertha is working as see if his steps will sufficently resolve the problem since there can sometimes be multiple ways of cleaning the same infections.


    ky331,

    I'd also seen indications of the infection you've mentioned in at least three files in that log, but i'm not sure in which order i'd begin the 'disinfecting' process. Bertha is in training at www.malwareremoval.com, and is following the guidelines they use to help him learn the proper procedures to 'disinfect' a user's system, and ensure that nothing gets hosed in the process.


    Bertha,

    Would the 'tool' that ky331 mentioned work on part of this infection? Can it be run at anypoint during the cleanup process?

    -----

    Here's the example I like to provide:

    Let's say that I go into a garage to have someone look at my car. One technician steps up and says "Mr. Mike", i'll be working on your vehicle today (implying taking responsibility to solve my car's troubles come what may). Now while he starts looking, just about every technician in the garage approaches me and says "I think it's this...", and "I think we need to do this..." - which they may or may not be correct. Now, not only does the technician helping me out have to use his own analysis techinques, but answer all the other possibilities that were brought up by everyone else, in requards to my vehicle. Now, I might be apt to beleive that if he doesn't follow everyones advice, or is taking a different approach than those proposed by others, he really doesn't need to be working on my car - and might not take it back to that garage again (not because what I thought of him, but because I might feel that others are working to make the garage fail at the expense of my vehicle) - the team wins, or the team fails.



    Mike.
  • smc0827

    14 Posts

    553

    0

    Posted March 20th, 2005 17:00

    Perhaps I should have waited longer, due to the responses I know see - but I went ahead and followed ky331's removal instructions, so hopefully it isn't more messed up now.  I ran the Serflog removal tool twice, and the 2nd didn't find anything.  I also have run adaware se and also spybot search & destroy and cw shredder.  Did a McAfee update and a virus scan which removed further viruses.  Here is an updated logfile.  Please take a look and tell me what you find.  thanks very much!  smc0827

    Logfile of HijackThis v1.99.1
    Scan saved at 1:34:14 PM, on 3/20/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\drivers\dcfssvc.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
    C:\Program Files\Net Nanny\nnsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\sysmtor.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\Program Files\Net Nanny\nntray.exe
    C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
    C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Dell Support\DSAgnt.exe
    c:\windows\system32\ctmn.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    C:\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.netnanny.com/p/search?pi=nnh5&qt=%s
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.netnanny.com/p/search?pi=nnh5&qt=%s
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.netnanny.com/p/search?pi=nnh5&qt=%s
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
    O4 - HKLM\..\Run: [NNTray] C:\Program Files\Net Nanny\nnstart.exe
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
    O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
    O4 - HKLM\..\Run: [CMSETTINGS] C:\WINDOWS\system32\ctbeg.exe
    O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
    O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - Startup: ASE Scheduler.lnk = C:\Program Files\Aluria Software\ASE\ASE Scheduler.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
    O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O23 - Service: Aluria Spyware Eliminator Service (ASEService) - Unknown owner - C:\PROGRA~1\ALURIA~1\ASE\ASEServ.exe
    O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
    O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: NNSvc - Looksmart, Ltd. - C:\Program Files\Net Nanny\nnsvc.exe
    O23 - Service: sysmtor - BioNet Systems, LLC - C:\WINDOWS\system32\sysmtor.exe

     

  • Bertha2

    711 Posts

    553

    0

    Posted March 20th, 2005 18:00

    Hey smc,

    As Ky331 does not fix HJT Logs completely (as I was told) then I will get back to you shortly

    Bertha2

    Message Edited by Bertha2 on 03-20-2005 02:37 PM

  • Bertha2

    711 Posts

    552

    0

    Posted March 20th, 2005 19:00

    Hey smc,

    Print the following instructions off as you will need to be offline

    Run Hijackthis and with all windows closed put a check mark next to the following

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    O4 - HKLM\..\Run: [CMSETTINGS] C:\WINDOWS\system32\ctbeg.exe


    Now click "FIX"

    Reboot into Safe Mode

    Start-Logoff-Restart

    · Immediately begin tapping the F8 key continually
    · Select the option for Safe Mode using the arrow keys
    · Press enter on your keyboard to begin Safe Mode
    · A black screen will appear then Windows will load

    Showing Hidden Files and Folders·

    Click Start

    · Open My Computer
    · Select the Tools Menu and click Folder Options
    · Select the View Tab
    · Under the hidden files and folders heading, Select Show · Uncheck: Hide File extensions for known file types
    · Uncheck: Hide protected operating system files
    · Click Yes to Confirm
    · Click Ok


    Use the search otion on the start menu (bottom left hand corner of the screen) to search for and find the following files and folders:

    Files

    C:\WINDOWS\system32\ctbeg.exe

    If found delete the offending file (they may not be there this is fine)

    Reverse the above to hide your files and folders again

    Run Cleanup to empty all your
    Temporary Internet Folders as Hijackthis and other programs
    leave a lot of junk behind:
    http://cleanup.stevengould.org

     
    Hows things running now

    Post a New Log back here

    Bertha
  • smc0827

    14 Posts

    552

    0

    Posted March 20th, 2005 21:00

    Hi Bertha,

    Thanks for the advice.  Here is my latest logfile after following instructions.  Everything seems to  be running much better.  I do get one error message upon reboot, but I'm able to get to websites that I previously couldn't, etc.  The error message is:

    RUN DLL

    "Error loading c:\ProgramFiles\WildTangent\Apps\CDA\cdaEngine0400.dll"

    Wild Tangent is deleted but there is still this error showing up.  If you click on okay it just goes away.  Please advise after checking the logfile.  thanks very much!  smc0827

    Logfile of HijackThis v1.99.1
    Scan saved at 5:09:50 PM, on 3/20/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\drivers\dcfssvc.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
    C:\Program Files\Net Nanny\nnsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\sysmtor.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    C:\Program Files\Net Nanny\nntray.exe
    C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    C:\PROGRA~1\mcafee.com\agent\McAgent.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
    C:\Program Files\Dell Support\DSAgnt.exe
    C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Aluria Software\ASE\ASE Scheduler.exe
    C:\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.netnanny.com/p/search?pi=nnh5&qt=%s
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.netnanny.com/p/search?pi=nnh5&qt=%s
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.netnanny.com/p/search?pi=nnh5&qt=%s
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O4 - HKLM\..\Run: [NNTray] C:\Program Files\Net Nanny\nnstart.exe
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
    O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
    O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - Startup: ASE Scheduler.lnk = C:\Program Files\Aluria Software\ASE\ASE Scheduler.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\bns shared\eng\ossysprv.dll
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
    O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O23 - Service: Aluria Spyware Eliminator Service (ASEService) - Unknown owner - C:\PROGRA~1\ALURIA~1\ASE\ASEServ.exe
    O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
    O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: NNSvc - Looksmart, Ltd. - C:\Program Files\Net Nanny\nnsvc.exe
    O23 - Service: sysmtor - BioNet Systems, LLC - C:\WINDOWS\system32\sysmtor.exe

     

     

  • ky331

    5 Journeyman

    15622 Posts

    45048 Points

    258

    0

    Posted March 21st, 2005 00:00

    To SMC:
     
    First off, let me apologize for any confusion (and anguish) this posting may have caused you.  My goal in helping-out in the Dell forum(s) is to assist others.... quickly/simply, if possible... if i believe i can correctly diagnose a problem.... and without causing any damage in the process.  I can assure you that the tool I had you run did not in any way do any damage to your computer... your system did NOT get any "more messed up" by following my directions.  I have used this tool with several people now, and the results have been superlative.  The fact that, before running the tool, you were  "unable to access McAfee or other virus removal sites online", but that after running it, you "did a McAfee update and a virus scan which removed further viruses", and still later, that "Everything seems to  be running much better...   I'm able to get to websites that I previously couldn't", vindicates what I was advocating: The tool removed all the 'bad' O1 Browser Redirections in the Hosts file, as well as the 3 critical files (formatsys.exe, msmbw.exe, & serbw.exe) containing/generating the W32.Serflog.A worm.
     
    (For your information, I actually went through a "learning curve" in the beginning, initially playing it extra-safe in diagnosing this problem, specifically because I did not want to inflict any damage.  As a result, I've already been "questioned" by another forum member, claiming that I was holding back information which could be of vital assistance to many people here.   Since I now feel 100% safe with the results I've experienced, I can confidently recommend this tool, when it's called for, without having any reservations about it.  The official directions from Symantec call for running the Serflog tool twice, rebooting in-between, and at least one person I assisted DID find some entries on the second run.  So, on that point, better safe than sorry.)
     
    Also, please note that I clearly pointed out to you, at the very outset, that " Your computer has more than one problem.  What I have to say will help only the specific problem of the FORMATSYS worm/virus you obtained via MSN Messenger.   After you follow these directions, you should come back to this forum with a revised HiJack Log for additional assistance, and other people will help you."   For, as Bertha correctly noted, "Ky331 does not fix HJT Logs completely" --- I only fixed the parts I was capable of fixing, and left the rest for others.  (For example, I am 'concerned' about all the O10 Winsock file entries... but I freely admit *not* knowing enough about them --- except that, allegedly, one must handle/delete these with extreme caution, since if they are removed without properly fixing the "gap" in the Winsock "chain", it can result in the loss of internet access.  But since I really don't know FOR SURE.... meaning, I could be wrong, and maybe this particular O10 is okay??? ---  I offered you no assistance on this point, nor on any of the other problems that (may) remain in your HJT Log.
     
                                                                              **********
     
    To Bertha:
     
    I hope you do not view this as a personal attack.  I was only trying to help.  And, as you can plainly see from the results, the tool I advocated does *NOT* have to be run (only) after fixing the Hosts file first... rather, the tool itself is capable of  removing  the bad O1 entries from the Hosts file  (that is to say, at least all those entries which are related to Serflog.A).  If you weren't aware of this previously, then I would hope you consider this as a source of enlightenment.   I have witnessed too many cases of people suffering/struggling to remove W32.Serflog.A in this forum... threads that went on, unnecessarily, for several pages... when this tool offers a very simple fix. Please feel free to add it to your "tool bag" for the next time you come across this worm.
     
    Also, to say    to me that "you have messed up this fix because their hosts files need resetting before they run any Online Scans"...
    1) at the point you wrote that, you hadn't even offered any specific "fix" yet...
    yes, perhaps you were contemplating one at the time.   but we're not mind-readers.  
    Is it possible that something I suggested here might have interfered with something you intended to be done at some later point?  --- as Mike asked, is there one specific sequence of events that must be followed? --- theoretically, yes... but it is my experience with this particular removal tool that it cleaned up precisely what I was trying to do, W32.Serflog.A ---- no more, and no less ---- without interfering with anything else.   in fact, I strongly believe that the resulting log, after running the Serflog tool, was much simpler for you (or anyone else) to further analyze --- after all, it was FORTY-EIGHT (48) entries shorter!!
    On the other hand, since you posted your advice after I posted mine, I certainly hope you double-checked your advice to make sure what you were suggesting was still fully applicable and appropriate after my (partial) "fix" was already implemented.
    2) I was not advocating running any online scans, because I am well aware that W32.Serflog.A prevents a person from doing so!
     
                                                                   *******************
     
    To Bertha (and forum moderator ChrisM):
     
    Chris's instructions, as he clarified them, currently read:
     
    " Once User B posts a specific HJT repair assistance to User A, User B should be allowed to proceed as far as he can without another person "breaking in" to also offer specific HJT repair assistance.  * exception - a simple posting of the generic direction to "Please post your HJT log here", should not be viewed as actually having offered specific HJT repair assistance. Only the posting of specific details/advice (i.e., Please tick on the following entries to remove them) should be deemed as "taking ownership" of a thread)."
     
    Now, I see that you also work at www.malwareremoval.com, and perhaps they have different rules there.  But, it seems to me that simply saying " I am currently looking at your Hijackthis Log now and will get back to you shortly" does NOT constitute specific HJT repair assistance as defined above.  So I have every confidence that I was working within the current rules.  
    To Chris:  If this was not your intent, then I think you must go back to an "absolute" rule... that once there is a single reply, absolutely no one else may join in.  If that's what you decide, I'll (reluctantly) comply.

    Message Edited by ky331 on 03-21-2005 06:30 AM