UNSOLVED

JustAnotherLost

updated

19 years ago

0

1218

August 14th, 2007 16:00

HJT Help Request

Would anybody be willing to help me with my HJT log and anything else you see wrong.  I would really appreciate your assistance.
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:11:40 PM, on 8/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\xagmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinPop\winpop.exe
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Encore\Hoyle Card Games 2005\HoyleCardGames2005.exe
C:\Program Files\Rhapsody\rhaphlpr.exe
C:\Program Files\WinTouch\WinTouch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fark.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1BD9FDC5-600F-1FFF-7A71-3CB6094EF2EF} - C:\WINDOWS\system32\lwwdp.dll
O2 - BHO: (no name) - {4D8FAB9F-675C-4BAE-7C71-3CB6094EF0BB} - C:\WINDOWS\system32\yyuuvttd.dll
O2 - BHO: (no name) - {4DDCFCC4-665A-1EF2-7A71-3CB6094EF3B8} - C:\WINDOWS\system32\jba.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WinTouch] C:\Program Files\WinTouch\WinTouch.exe
O4 - HKLM\..\Run: [SfKg6w] C:\WINDOWS\xagmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WinPop] C:\Program Files\WinPop\winpop.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/amun/default/mjolauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab53083.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/bingame/hsol/default/SCEWebLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWljaGFlbCBDYXJ0ZXI\command.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 5555 bytes
  • Bugbatter

    4 Apprentice

    20487 Posts

    483

    0

    Posted August 14th, 2007 16:00

    Welcome :)
    Yes, you have a few instances of malware in there.

    Please download DrWeb-CureIt & save it to your desktop. DO NOT perform a scan yet.

    Reboot your computer in SAFE MODE using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

    Scan with DrWeb-CureIt as follows:
    • Double-click on cureit.exe to start the program. An "Express Scan of your PC" notice will appear.
    • Under "Start the Express Scan Now", Click "OK" to start. This is a short scan that will scan the files currently running in memory and when something is found, click the Yes button when it asks you if you want to cure it.
    • Once the short scan has finished, Click Options > Change settings
    • Choose the "Scan tab" and UNcheck "Heuristic analysis"
    • Back at the main window, click "Select drives" (a red dot will show which drives have been chosen)
    • Then click the "Start/Stop Scanning" button (green arrow on the right) and the scan will start.
    • When done, a message will be displayed at the bottom advising if any viruses were found.
    • Click "Yes to all" if it asks if you want to cure/move the file.
    • When the scan has finished, look if you can see the icon next to the files found. If so, click it, then click the next icon right below and select "Move incurable".
    • ( This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
    • Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
    • Save the DrWeb.csv report to your desktop.
    • Exit Dr.Web Cureit when done.
    • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
    • After reboot, post the contents of the log from Dr.Web in your next reply along with a fresh HijackThis log. (You can use Notepad to open the DrWeb.cvs report)
  • 483

    0

    Posted August 15th, 2007 00:00

    Bugbatter,

     

    Thanks so much for your help so far.  Here's the two files you requested.  The Dr Web Cureit finished and another family member started playing Hoyle.  She didn't know what was going on.  I closed Hoyle and when I was closing Dr Web I got a message "No Operations Performed With Some Objects in List.  Exit Program?"  I clicked yes and rebooted.  Also, I have no idea how but the Dr Web file was saved in Excel.  I cut and pasted it into a Notepad. 

     

    Here's the HJT Log

     

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:11:52 PM, on 8/14/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\userinit.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\WinTouch\WinTouch.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fark.com/
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {1BD9FDC5-600F-1FFF-7A71-3CB6094EF2EF} - C:\WINDOWS\system32\lwwdp.dll (file missing)
    O2 - BHO: (no name) - {4D8FAB9F-675C-4BAE-7C71-3CB6094EF0BB} - C:\WINDOWS\system32\yyuuvttd.dll (file missing)
    O2 - BHO: (no name) - {4DDCFCC4-665A-1EF2-7A71-3CB6094EF3B8} - C:\WINDOWS\system32\jba.dll (file missing)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [WinTouch] C:\Program Files\WinTouch\WinTouch.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [WinPop] C:\Program Files\WinPop\winpop.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/amun/default/mjolauncher.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab53083.cab
    O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/bingame/hsol/default/SCEWebLauncher.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
    O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWljaGFlbCBDYXJ0ZXI\command.exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    --
    End of file - 5266 bytes

     

    Here's the Dr Web Log

     

    winpop.exe;c:\program files\winpop;Trojan.LowZones.267;Deleted.;
    core.sys;c:\windows\system32\drivers;Trojan.NtRootKit.239;Deleted.;
    jba.dll;c:\windows\system32;Trojan.DownLoader.29746;Deleted.;
    lwwdp.dll;c:\windows\system32;Trojan.DownLoader.29746;Deleted.;
    yyuuvttd.dll;c:\windows\system32;Trojan.DownLoader.29746;Deleted.;
    xagmon.exe;c:\windows;Trojan.DownLoader.26460;Deleted.;
    10.tmp;C:\;Trojan.DownLoader.26881;Deleted.;
    101.tmp;C:\;Trojan.DownLoader.26881;Deleted.;
    120.tmp;C:\;Trojan.DownLoader.26881;Deleted.;
    6E.tmp;C:\;Trojan.DownLoader.26881;Deleted.;
    E5.tmp;C:\;Trojan.DownLoader.24028;Deleted.;
    E8.tmp;C:\;Trojan.DownLoader.24028;Deleted.;
    !update.exe;C:\Documents and Settings\Trom da Bone\Local Settings\Temp;Trojan.DownLoader.22753;Deleted.;
    !update.exe;C:\Documents and Settings\WoW Queen\Local Settings\Temp;Trojan.DownLoader.22753;Deleted.;
    !update-4395[1].0000;C:\Documents and Settings\WoW Queen\Local Settings\Temporary Internet Files\Content.IE5\WDQB6BWD;Trojan.DownLoader.22753;Deleted.;
    Yazzle1552OinAdmin.exe;C:\Program Files\Common Files;Adware.ClickSpring;;
    ibm00034.dll;C:\Program Files\Common Files\Microsoft Shared\Web Folders;Trojan.PWS.Snap;Deleted.;
    slghex.dll;C:\Program Files\Common Files\Sandlot Shared;Adware.SpywareStorm;;
    popinstall.exe;C:\Program Files\InetGet2;Trojan.Winpop;Deleted.;
    BndDrive.dll;C:\Program Files\ISM;Adware.SearchAid.37;;
    ISMModule2.exe;C:\Program Files\ISM;Trojan.Click.3596;Deleted.;
    UnInstall.exe;C:\Program Files\WinPop;Trojan.Winpop;Deleted.;
    A0075742.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP351;Trojan.DownLoader.24772;Deleted.;
    A0075747.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP352;Adware.ClickSpring;;
    A0075750.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP352;Adware.WebHancer;;
    A0075751.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP352;Adware.WebHancer;;
    A0075937.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Trojan.DnsChange;Deleted.;
    A0075938.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Trojan.Proxy.493;Deleted.;
    A0075940.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Trojan.DownLoader.11355;Deleted.;
    A0075941.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Adware.TargetServer;;
    A0075942.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Trojan.DownLoader.11354;Deleted.;
    A0075943.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Adware.TargetServer;;
    A0075944.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Adware.TargetServer;;
    A0075945.exe\data001;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353\A0075945.exe;Adware.ClickSpring;;
    A0075945.exe\data002;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353\A0075945.exe;Adware.MediaTicket;;
    A0075945.exe\data003;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353\A0075945.exe;Adware.ClickSpring;;
    A0075945.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Archive contains infected objects;Moved.;
    A0075950.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Adware.WebHancer;;
    A0075952.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Adware.WebHancer;;
    A0075953.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Adware.WebHancer;;
    A0075957.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Trojan.Proxy.493;Deleted.;
    MFEX-1.DAT;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353\snapshot;Adware.WebHancer;;
    MFEX-2.DAT;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353\snapshot;Adware.WebHancer;;
    MFEX-3.DAT;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353\snapshot;Adware.WebHancer;;
    MFEX-6.DAT;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353\snapshot;Adware.WebHancer;;
    MFEX-7.DAT;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353\snapshot;Adware.WebHancer;;
    MFEX-8.DAT;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353\snapshot;Adware.WebHancer;;
    A0077067.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP356;Adware.ClickSpring;;
    A0077068.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP356;Adware.ClickSpring;;
    A0077152.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP356;Adware.ClickSpring;;
    A0077153.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP356;Adware.ClickSpring;;
    A0079172.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP358;Trojan.DownLoader.24772;Deleted.;
    A0081164.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP359;Adware.ClickSpring;;
    A0081165.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP359;Adware.ClickSpring;;
    A0081200.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP360;Adware.ClickSpring;;
    A0081201.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP360;Adware.ClickSpring;;
    A0083216.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP361;Adware.ClickSpring;;
    A0083217.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP361;Adware.ClickSpring;;
    A0084413.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP365;Trojan.DownLoader.24772;Deleted.;
    A0084450.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP366;Trojan.DownLoader.24772;Deleted.;
    A0084455.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP366;Trojan.Rond;Deleted.;
    A0084572.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP368;Adware.ClickSpring;;
    A0084573.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP368;Adware.ClickSpring;;
    A0084583.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP368;Trojan.DownLoader.24772;Deleted.;
    A0085721.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP371;Adware.ClickSpring;;
    A0085722.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP371;Adware.ClickSpring;;
    A0085742.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP371;Trojan.DownLoader.24772;Deleted.;
    A0087043.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP377;Trojan.DownLoader.24772;Deleted.;
    A0087138.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP378;Trojan.Rond;Deleted.;
    A0087203.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP380;Trojan.DownLoader.24772;Deleted.;
    A0087247.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP381;Adware.ClickSpring;;
    A0088258.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP381;Adware.ClickSpring;;
    A0088346.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP383;Adware.ClickSpring;;
    A0088347.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP383;Adware.ClickSpring;;
    A0088394.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP384;Adware.ClickSpring;;
    A0088395.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP384;Adware.ClickSpring;;
    A0088419.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP384;Adware.ClickSpring;;
    A0088420.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP384;Adware.ClickSpring;;
    A0088460.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP385;Adware.ClickSpring;;
    A0088467.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP385;Adware.ClickSpring;;
    A0088471.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP385;Adware.ClickSpring;;
    A0089516.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP386;Adware.ClickSpring;;
    A0089580.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP386;Adware.ClickSpring;;
    A0089581.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP386;Adware.ClickSpring;;
    A0089598.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP387;Adware.ClickSpring;;
    A0089616.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP387;Adware.ClickSpring;;
    A0089663.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP387;Adware.ClickSpring;;
    A0089671.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP387;Adware.ClickSpring;;
    A0089672.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP387;Adware.ClickSpring;;
    A0089926.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP389;Adware.ClickSpring;;
    A0089970.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP389;Trojan.DownLoader.24772;Deleted.;
    A0091061.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP390;Adware.ClickSpring;;
    A0091109.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP391;Adware.ClickSpring;;
    A0091110.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP391;Adware.ClickSpring;;
    A0091115.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP391;Adware.ClickSpring;;
    A0091241.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP391;Adware.ClickSpring;;
    A0091242.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP391;Adware.ClickSpring;;
    A0091245.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP391;Trojan.DownLoader.29746;Deleted.;
    A0091271.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP392;Trojan.Click.3573;Deleted.;
    A0091276.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP392;Trojan.DownLoader.29746;Deleted.;
    A0093707.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP399;Trojan.LowZones.267;Deleted.;
    A0093708.sys;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP399;Trojan.NtRootKit.239;Deleted.;
    A0093709.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP399;Trojan.DownLoader.29746;Deleted.;
    A0093710.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP399;Trojan.DownLoader.29746;Deleted.;
    A0093711.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP399;Trojan.DownLoader.29746;Deleted.;
    A0093712.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP399;Trojan.DownLoader.26460;Deleted.;
    A0093713.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP399;Trojan.PWS.Snap;Deleted.;
    A0093714.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP399;Trojan.Winpop;Deleted.;
    A0093715.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP399;Trojan.Click.3596;Deleted.;
    A0093716.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP399;Trojan.Winpop;Deleted.;
    b122.exe;C:\WINDOWS;Trojan.MulDrop.8200;Deleted.;
    retadpu72.exe;C:\WINDOWS;Trojan.DownLoader.24772;Deleted.;
    retadpu72.exe.tmp;C:\WINDOWS;Trojan.DownLoader.24772;Deleted.;
    popcaploader.dll;C:\WINDOWS\Downloaded Program Files;Program.PopcapLoader;;


    Message Edited by JustAnotherLostSoul on 08-15-2007 01:15 PM
  • Bugbatter

    4 Apprentice

    20487 Posts

    483

    0

    Posted August 15th, 2007 10:00

    It would be best if the ONLY thing you or anyone else does on that computer is run these fixes in the sequence that they are given. Interfering with a scan could undesirable consequences.

    You have Viewpoint installed. Viewpoint developed a behavioral targeting product in 2006. Viewpoint is associated with a program called viewmgr.exe and the ViewPoint Media Player.
    Viewpoint is bundled with AOL, AOL Instant Messenger, Adobe Atmosphere, Netscape 7, etc and sometimes not mentioned in the license agreement. Hardware manufacturers pre-install some of these applications.
    ViewPoint Toolbar will redirect your search queries and also transmits non personally identifiable information back to their servers. The Viewpoint Toolbar is listed is also classified as a threat in the CounterSpy Threat Library because it hijacks your search queries and also transmits non personally identifiable information back to their servers.
    Viewpoint Manager is a media player often bundled with AIM software. Viewpoint Manager is a useless add on.

    Because Viewpoint's software will track your web surfing and tailor advertisements based on the web pages you are visiting, I suggest you remove the program.
    ** Note: Removing Viewpoint Media Player may cause the program that bundled it to not function as intended. For AOL and AIM it is needed to use their 3D icons known as Super Buddies and for customized themes, etc.
    If you wish to remove Viewpoint, end process on ViewManager in Task Manager.
    Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.

    • Viewpoint
    • Viewpoint Manager
    • Viewpoint Media Player
    • Viewpoint Toolbar
    • Viewpoint Experience Technology
    Then remove the Viewpoint folder in your Program Files.


    Please end process in Task Manager (Ctrl+Alt+Del) on WinTouch if listed. Go to Add/Remove Programs and remove it if listed. Also remove Winpop. If not listed, please continue anyway.

    Please launch Hijackthis and place a checkmark next to these:

    O2 - BHO: (no name) - {1BD9FDC5-600F-1FFF-7A71-3CB6094EF2EF} - C:\WINDOWS\system32\lwwdp.dll (file missing)
    O2 - BHO: (no name) - {4D8FAB9F-675C-4BAE-7C71-3CB6094EF0BB} - C:\WINDOWS\system32\yyuuvttd.dll (file missing)
    O2 - BHO: (no name) - {4DDCFCC4-665A-1EF2-7A71-3CB6094EF3B8} - C:\WINDOWS\system32\jba.dll (file missing)
    O4 - HKLM\..\Run: [WinTouch] C:\Program Files\WinTouch\WinTouch.exe
    O4 - HKCU\..\Run: [WinPop] C:\Program Files\WinPop\winpop.exe
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWljaGFlbCBDYXJ0ZXI\command.exe (file missing)


    Fix these if you, and administrator, or Spybot did not set these restrictions:
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present


    If you removed Viewpoint, please fix this one as well:
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    This is optional to fix because it uses resources as it loads Office components at Startup even if you are not using Office. Fixing it here will not prevent you from opening Office manually as needed.
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE


    Please close all windows except HijackThis and click "Fix Checked". Close HijackThis and reboot.

    Please delete the specified folders if they still exist:

    C:\Program Files\ WinTouch
    C:\Program Files\ WinPop

    Please run another scan with Dr. Web and post that log along with a fresh Hijackthis log. Thanks.
  • 483

    0

    Posted August 15th, 2007 20:00

    Bugbatter,

     

    Here's the new HJT log and Dr Web log...

     

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:08:23 PM, on 8/15/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\userinit.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\Program Files\iPod\bin\iPodService.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fark.com/
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: (no name) - {EC70706F-EEAD-CF58-8FDB-E6ABA87450B6} - C:\WINDOWS\system32\gbnnkv.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/amun/default/mjolauncher.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab53083.cab
    O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/bingame/hsol/default/SCEWebLauncher.cab
    O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWljaGFlbCBDYXJ0ZXI\command.exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

    --
    End of file - 4305 bytes

     

    23100247.exe;C:\;Probably DLOADER.Trojan;;
    Yazzle1552OinAdmin.exe;C:\Program Files\Common Files;Adware.ClickSpring;;
    slghex.dll;C:\Program Files\Common Files\Sandlot Shared;Adware.SpywareStorm;;
    BndDrive.dll;C:\Program Files\ISM;Adware.SearchAid.37;;
    backup-20070815-130642-650.dll;C:\Program Files\Trend Micro\HijackThis\backups;Program.PopcapLoader;;
    A0075747.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP352;Adware.ClickSpring;;
    A0075750.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP352;Adware.WebHancer;;
    A0075751.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP352;Adware.WebHancer;;
    A0075941.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Adware.TargetServer;;
    A0075943.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Adware.TargetServer;;
    A0075944.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Adware.TargetServer;;
    A0075950.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Adware.WebHancer;;
    A0075952.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Adware.WebHancer;;
    A0075953.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353;Adware.WebHancer;;
    MFEX-1.DAT;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353\snapshot;Adware.WebHancer;;
    MFEX-2.DAT;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353\snapshot;Adware.WebHancer;;
    MFEX-3.DAT;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353\snapshot;Adware.WebHancer;;
    MFEX-6.DAT;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353\snapshot;Adware.WebHancer;;
    MFEX-7.DAT;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353\snapshot;Adware.WebHancer;;
    MFEX-8.DAT;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP353\snapshot;Adware.WebHancer;;
    A0077067.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP356;Adware.ClickSpring;;
    A0077068.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP356;Adware.ClickSpring;;
    A0077152.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP356;Adware.ClickSpring;;
    A0077153.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP356;Adware.ClickSpring;;
    A0081164.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP359;Adware.ClickSpring;;
    A0081165.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP359;Adware.ClickSpring;;
    A0081200.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP360;Adware.ClickSpring;;
    A0081201.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP360;Adware.ClickSpring;;
    A0083216.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP361;Adware.ClickSpring;;
    A0083217.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP361;Adware.ClickSpring;;
    A0084572.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP368;Adware.ClickSpring;;
    A0084573.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP368;Adware.ClickSpring;;
    A0085721.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP371;Adware.ClickSpring;;
    A0085722.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP371;Adware.ClickSpring;;
    A0087247.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP381;Adware.ClickSpring;;
    A0088258.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP381;Adware.ClickSpring;;
    A0088346.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP383;Adware.ClickSpring;;
    A0088347.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP383;Adware.ClickSpring;;
    A0088394.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP384;Adware.ClickSpring;;
    A0088395.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP384;Adware.ClickSpring;;
    A0088419.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP384;Adware.ClickSpring;;
    A0088420.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP384;Adware.ClickSpring;;
    A0088460.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP385;Adware.ClickSpring;;
    A0088467.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP385;Adware.ClickSpring;;
    A0088471.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP385;Adware.ClickSpring;;
    A0089516.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP386;Adware.ClickSpring;;
    A0089580.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP386;Adware.ClickSpring;;
    A0089581.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP386;Adware.ClickSpring;;
    A0089598.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP387;Adware.ClickSpring;;
    A0089616.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP387;Adware.ClickSpring;;
    A0089663.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP387;Adware.ClickSpring;;
    A0089671.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP387;Adware.ClickSpring;;
    A0089672.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP387;Adware.ClickSpring;;
    A0089926.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP389;Adware.ClickSpring;;
    A0091061.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP390;Adware.ClickSpring;;
    A0091109.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP391;Adware.ClickSpring;;
    A0091110.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP391;Adware.ClickSpring;;
    A0091115.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP391;Adware.ClickSpring;;
    A0091241.dll;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP391;Adware.ClickSpring;;
    A0091242.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP391;Adware.ClickSpring;;
    A0093717.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP399;Trojan.MulDrop.8200;Deleted.;
    A0093718.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP399;Trojan.DownLoader.24772;Deleted.;
    A0093748.exe;C:\System Volume Information\_restore{A8C62D27-0396-425C-8C0A-EC66DBD13B95}\RP399;Trojan.DownLoader.29746;Deleted.;
  • Bugbatter

    4 Apprentice

    20487 Posts

    483

    0

    Posted August 15th, 2007 22:00

    Thank you for posting those. I've been busy on other forums and did not have a chance to reply to your messages earlier. You had a fair amount of infection in there when we started, a new critter has been added, and I do not see a resident anti-virus running in realtime.
    Please consider installing one of the free anti-virus programs, but only after all remnants of any previous anti-virus software have been removed.
    I suggest that you install one of these:

    1. Grisoft’s AVG Free:
    http://free.grisoft.com/freeweb.php/doc/2/
    If you need support for AVG, their forum is located here: http://forum.grisoft.cz/freeforum/

    2. Avast also has a free version for home users:
    http://www.avast.com/eng/programs.html
    Their support forums are here: http://forum.avast.com/

    After you have installed an anti-virus, please do a scan in safemode:
    Turn on the computer.
    Immediately begin tapping the F8 key.
    Use the arrow keys to highlight Safe Mode and press the Enter key.

    Let your anti-virus quarantine/clean anything that it finds.

    Following that, please launch HijackThis and place a checkmark next to the following:

    O2 - BHO: (no name) - {EC70706F-EEAD-CF58-8FDB-E6ABA87450B6} - C:\WINDOWS\system32\gbnnkv.dll
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWljaGFlbCBDYXJ0ZXI\command.exe (file missing)


    Close all windows except HijackThis and click "Fix Checked". Close HijackThis.

    Configure to show all files/folders:
    Go to Start>Search and at the top select Tools>Folder Options
    Select the View tab
    Display the contents of system folders
    Show hidden files and folders
    Uncheck: Hide protected operating system files
    Click on Apply.
    Next go to the side of the Search box and select All files and folders. Go down to More advanced options.
    Be sure the first three boxes are selected:
    Search System folders
    Search Hidden Files and folders
    Search SubFolders

    This file should be gone, but please delete it if it remains.
    C:\WINDOWS\system32\ gbnnkv.dll

    Reboot normally.

    Go back and rehide files:
    Start>Search and at the top select Tools>Folder Options
    Select the View tab
    Display the contents of system folders
    Show hidden files and folders
    Check: Hide protected operating system files
    Click on Apply.

    Please post a fresh HijackThis log and let me know how things are running. Thanks :)
  • 483

    0

    Posted August 20th, 2007 11:00

    Bugbatter,

     

    I'm sorry for not getting back sooner but I've been very busy.  So far it's working great.  I installed the Avast program and read the documentation as you suggested.  Right now it's working great.  I'm keeping track of what's going on and I will just start a new thread if needed.

     

    I really do appreciate what you've done.  You were a great help. 

     

    Thanks so much....
  • Bugbatter

    4 Apprentice

    20487 Posts

    483

    0

    Posted August 20th, 2007 15:00

    You're welcome. I'm glad your're happy with it. It would have been good to see a follow-up log, but I'll take your word for it. If you have not done so already, please delete Dr. Web CureIt. You may want to keep HJT so you can post a log in the future if you ever have another problem -- assuming the tool does not have a newer version at that time.

    Also make sure that computer is using the latest version of Java. Older versions have vulnerabilities that malware can use to infect your system. It is possible that you may be running Java code in your applications that absolutely require a specific version of the JRE to run. Please follow these steps to remove older version Java components and update.

    Updating Java:
    • Download the latest version of Java Runtime Environment (JRE) 6.
    • Scroll down to where it says "Java Runtime Environment (JRE) 6u2 allows end-users to run Java applications".
    • Click the "Download" button to the right.
    • Check the box that says: "Accept License Agreement".
    • The page will refresh.
    • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each Java versions.

    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.

    Official JAVA Installation Instructions if needed.


    If you feel that your issue has been resolved, I'll leave you with my standard list of Prevention Tips.

    You may have already taken some of these steps:
    1. Visit Windows Update:
    Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly patched OS.
    Windows Update: http://v4.windowsupdate.microsoft.com/en/default.asp

    2. Adjust your security settings for ActiveX:
    Go to Internet Options/Security/Internet, press 'default level', then OK.
    Now press "Custom Level."
    In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to 'prompt', and 'Initialize and Script ActiveX controls not marked as safe" to 'disable'.

    3. Download and install the following free programs:
    a. SpywareBlaster:
    http://www.javacoolsoftware.com/spywareblaster.html
    Tutorial here: http://www.bleepingcomputer.com/forums/tutorial49.html
    b. SpywareGuard:
    http://www.javacoolsoftware.com/spywareguard.html
    Tutorial here: http://www.bleepingcomputer.com/tutorials/tutorial50.html
    Periodically check for updates in both programs.

    4. Please use a firewall and realtime anti-virus. Keep the anti-virus software and firewall software up to date.
    Note: Zone Alarm Firewall (Zone Labs) http://www.zonelabs.com/store/content/company/products/trial_zaFamily/trial_zaFamily.jsp?lid=home_freedownloads
    Sunbelt Kerio has a free version: http://www.kerio.com/kpf_download.html

    5. You might consider installing Mozilla / Firefox.
    http://www.mozilla.org/

    6. Install spyware detection and removal programs:
    You may also want to consider installing either or both of AdAware (free version) and Spybot S&D (freeware). Use these programs to regularly scan your system for and remove many forms of spyware/malware.

    a. Ad-aware: http://www.lavasoft.de/software/adaware/

    b. SpyBot S&D: http://safer-networking.org/en/news/2005-05-31.html

    I would check for updates in SpyBot once a week or so.
    Check for updates in Ad-aware frequently.

    7. Before using or purchasing any Spyware/Malware protection/removal program, always check the Rogue/Suspect Spyware List.
    Here is the link:
    http://www.spywarewarrior.com/rogue_anti-spyware.htm

    8. If you have not already done so, you might want to install CCleaner and run it in each user's profile: http://www.ccleaner.com/
    ** UNcheck the option to install the Yahoo toolbar that is checked by default for the Standard version, or download the toolbar-free versions (Slim or Basic) when given the option for those.

    9. If you use Adobe Reader it may need to be updated to be sure that you have a more secure version. If you are using a version prior to v. 6.05, you should update to 6.05, preferably version 8.1.0.
    It would be best to remove prior versions before updating to a new version.
    If you need additional assistance, the Adobe forums are here: http://www.adobe.com/support/forums/main.html

    10. Make sure you are using the most updated version of Java.
    The current version is Java Runtime Environment (JRE) 6u2

    You can go here to download the latest version of Java Runtime Environment (JRE) 6.
    Scroll down to where it says " Java Runtime Environment (JRE) 6u2 allows end-users to run Java applications".

    Click the link to download the Windows (Offline Installation) package: Save it, do not run it. When the download is complete, close the browser.

    Remove all prior versions using Add/Remove Programs, and delete the Java folder in Program Files.
    Reboot your computer once all Java components are removed.
    Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.
    Official JAVA Installation Instructions if needed.
    Reboot.

    11. Practice Safe Surfing with with TrendProtect by Trendmicro.
    TrendProtect is a browser plugin that assigns a safety rating to domains listed in your search engine. TrendProtect also adds a new button to your browser's toolbar area. The icon and color of the button changes to indicate whether the page currently open is safe, unsafe, trusted, or unrated, or whether it contains unwanted content.

    The following color codes are used by TrendProtect to indicate the safety of each site.

    Red for Warning
    Yellow for Use Caution
    Green for Safe
    Grey for Unknown


    12. Here are some helpful articles:
    "So how did I get infected in the first place?"
    by TonyKlein
    http://computercops.biz/postlite7736-.html

    "I'm not pulling your leg, honest"
    by Sandi Hardmeier
    http://www.microsoft.com/windows/IE/community/columns/pulling.mspx

    13. This is an excellent resource for users of all levels. General computer maintenance as well as internet security is covered.
    Rootkits for Dummies
    (Paperback)
    by Larry Stevenson (Author), Nancy Altholz (Author)

    It has been a pleasure working with you.
    Let us know if we have not resolved your problem. Otherwise, you are good to go.
    Happy and Safe Surfing!
  • Bugbatter

    4 Apprentice

    20487 Posts

    483

    0

    Posted August 22nd, 2007 20:00

    Thank you for letting me know.
  • 483

    0

    Posted August 22nd, 2007 20:00

    Bugbatter, I'm going to be busy for the next several weeks and I won't be able to devote much time to this problem. I didn't want to leave you hanging, waiting for a response. As soon as I have some free time I'll get back and post the most current reports. Thanks again!!!