UNSOLVED

ALgal

updated

21 years ago

A

ALgal

1188 Posts

0

1383

April 29th, 2005 02:00

Hijackthis Analysis Please

My brother is having problems with his laptop again.  He states that it runs slower than usual.  The previous post was:
 
This is the current log and it looks like that WINUP2DATE.dll is back!  
 
Please tell me what to do! 
 
Thanks,
Susan
 
Logfile of HijackThis v1.99.1
Scan saved at 8:52:55 PM, on 4/28/05
Platform: Windows 98 SE (Win9x 4.10.2222B)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATI2PLAB.EXE
C:\WINDOWS\SYSTEM\ATIPTAAB.EXE
C:\WINDOWS\SYSTEM\ATI2CWXX.EXE
C:\WINDOWS\SYSTEM\ESSAPM.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\AOL SPYWARE PROTECTION\AOLSP SCHEDULER.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLDIAL.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\VZNKAA.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAM FILES\AMERICA ONLINE 8.0\AOLTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HJT\HIJACKTHIS.EXE
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ATIPOLAB] ati2plab.exe
O4 - HKLM\..\Run: [AtiPTA] Atiptaab.exe
O4 - HKLM\..\Run: [Ati2cwxx] Ati2cwxx.exe
O4 - HKLM\..\Run: [essapm] essapm.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\SYGATE\SPF\SMC.EXE -startgui
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [OEMCleanup] C:\WINDOWS\OPTIONS\OEMRESET.EXE
O4 - HKLM\..\Run: [AtiGart] c:\Ati\Gart\AtiGart.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [autoupdate] rundll32 C:\WINDOWS\SYSTEM\WINUP2DATE.DLL,SHStart
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\vznkaa.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [AolAcsDaemon1] "C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE"
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [SmcService] C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Startup: nati.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
O9 - Extra button: Microsoft AntiSpyware helper - {D7875740-9796-11D9-B72A-444553540000} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D7875740-9796-11D9-B72A-444553540000} - (no file) (HKCU)
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/22f74e0339045b8b2b05/netzip/RdxIE601.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net
 
 
 
  • ALgal

    1188 Posts

    369

    0

    Posted April 29th, 2005 11:00

    I have tried to run a virus scan (Trend Micro, eTrust) but it just hung. System resources were at 100% load so now I am looking at the start-up to see if I can disable/uncheck unnecessary items to be able to run virus scan.  I noticed a nati.exe that is in the start-up. My brother's laptop only has 128 MB RAM. Previously I had deleted it in safe mode from advice given in Microsoft Windows 98 forum but it is back. It did not show on the hjt log.
     
  • Midnight Star

    4791 Posts

    369

    0

    Posted April 29th, 2005 12:00

    ALGal,

    Be sure to look this solution over before beginning the fix; there are few items here i'm not familar with. If you know what any are, just omit them from the fix. I'm also wondering about another running process that GOOGLES out to be good, so when we're done, let's try running MWAV just to see if something else is lurking about.



    If you haven't ran HouseCall lately, let's go back to www.trendmicro.com, download the latest definitions, and run it.



    Run HiJackThis then:

    1. Click " Config..."
    2. Click " Misc Tools"
    3. Click " Open Process manager"

    -

    Next, while holding down the CTRL key, locate ( if present) and click on ( highlight) each of the following:

    C:\WINDOWS\VZNKAA.EXE

    Now double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.



    Run HiJackThis and click " Scan", then check(tick) the following, if present:


    O4 - HKLM\..\Run: [autoupdate] rundll32 C:\WINDOWS\SYSTEM\WINUP2DATE.DLL,SHStart
    O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\vznkaa.exe
    O4 - Startup: Microsoft Works Calendar Reminders.lnk = ?
    O4 - Startup: nati.exe

    O9 - Extra button: Microsoft AntiSpyware helper - {D7875740-9796-11D9-B72A-444553540000} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D7875740-9796-11D9-B72A-444553540000} - (no file) (HKCU)

    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/22f74e0339045b8b2b05/netzip/RdxIE601.cab


    Now, with all windows closed except HiJackThis, click " Fix checked".



    Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:

    files...

    C:\WINDOWS\VZNKAA.EXE
    C:\WINDOWS\SYSTEM\WINUP2DATE.DLL

    Search for...

    nati.exe

    ...using " Start | Search...".

    -

    Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".



    Post back a new log, and let me know how everything goes.

    -

    Mike.

    Message Edited by Midnight Star on 04-29-2005 08:02 AM

  • Midnight Star

    4791 Posts

    369

    0

    Posted April 29th, 2005 13:00

    ALgal,

    Your welcome - but it's Mike ... :D

    You might also try deleting those files in safe mode (check and make sure none are OS files), then clear the java cache by starting Java from the Control Panel (2nd page).

    ==========

    Mike.
  • Midnight Star

    4791 Posts

    369

    0

    Posted April 29th, 2005 13:00

    Susan,

    That's ok, i'm not too far behind you ... :D

    -

    "Start -> Control Panel" -> other control panel options (box on the left hand side) -> Java -> Then look to either clear the cache, or delete temporary java files.

    That's a good list, but requires knowing the startup name, since the folder aren't included in the list, which unfortunately can't be listed in the virus scan's log since it resides in the registry, and a 'bad' program on the harddrive doesn't always need a registry entry to start.

    I'd just GOOGLE the programs name to see what comes up. I took a quick glance, and from what I saw, they all look like pure virus/trojans to me.

    ==========

    Mike.
  • ALgal

    1188 Posts

    369

    0

    Posted April 29th, 2005 13:00

    Thank you Steve,
     
    My brother told me he ran a virus scan! I managed to get virus scan done after disabling enough items at start-up  You can see that many could not be cured.  Is my best bet to format the hard drive and reinstall Windows 98?
     
    Susan
     
     
     
    Scan Results: 31577 files scanned. 44 viruses were detected.

    File Infection Status Path
    OHA.DLL Win32.Startpage.FZ cannot cure C:\WINDOWS\SYSTEM\
    kaeece.dll Win32.Startpage.FZ cannot cure C:\WINDOWS\SYSTEM\
    beigfda.dll Win32.Startpage.FZ cannot cure C:\WINDOWS\SYSTEM\
    124529.exe Win32.Tibser.H cannot cure C:\WINDOWS\SYSTEM\
    OutLook.exe Win32.Sneet.B cannot cure C:\WINDOWS\SYSTEM\
    twink64.exe Win32.SillyDl.KF cannot cure C:\WINDOWS\SYSTEM\
    kkmldg.dll Win32.Startpage.FZ cannot cure C:\WINDOWS\SYSTEM\
    lpt.exe Win32.Tibser.P cannot cure C:\WINDOWS\SYSTEM\
    MSXMIDI.EXE Win32.Chopenoz.H cannot cure C:\WINDOWS\SYSTEM\services\
    dktibs.exe Win32.Tibser.P cannot cure C:\WINDOWS\SYSTEM\
    systime.exe Win32.Startpage.JE cannot cure C:\WINDOWS\SYSTEM\
    sysprinter.exe Win32.Secdrop.ED cannot cure C:\WINDOWS\SYSTEM\
    dload.exe Win32.Tibser.P cannot cure C:\WINDOWS\SYSTEM\
    wldr.dll Win32.Angourd.B cannot cure C:\WINDOWS\SYSTEM\
    classload.jar-a2d72dc-315ac833.zip>GetAccess.class Java.ByteVerify!exploit cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
    classload.jar-a2d72dc-315ac833.zip>InsecureClassLoader.class Java.ByteVerify!exploit cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
    classload.jar-a2d72dc-315ac833.zip>Dummy.class Java.ByteVerify!exploit cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
    classload.jar-a2d72dc-315ac833.zip>Installer.class Java.Shinwow.Q cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
    msxmidi.exe Win32.Chopenoz.H cannot cure C:\WINDOWS\
    loadclean.exe Win32.SillyDl.KF cannot cure C:\WINDOWS\
    toolbar.exe Win32.Secdrop.AP cannot cure C:\WINDOWS\
    bstart.exe Win32.Secdrop.ED cannot cure C:\WINDOWS\
    dstart1.exe Win32.Tibser.G cannot cure C:\WINDOWS\
    helpsys.exe Win32.Secdrop.ED cannot cure C:\WINDOWS\
    ef.exe Win32.Chopemail.C cannot cure C:\WINDOWS\
    dstart5.exe Win32.Lospad.C cannot cure C:\WINDOWS\
    dstart2.exe Win32.Secdrop.ED cannot cure C:\WINDOWS\
    dstart4.exe Win32.SillyDl cannot cure C:\WINDOWS\
    dstart6.exe Win32.Lospad.C cannot cure C:\WINDOWS\
    dstart7.exe Win32.Lospad.C cannot cure C:\WINDOWS\
    wldr.dll Win32.Angourd.B cannot cure C:\WINDOWS\
    43219171.asw Win32.SillyDl.CM cannot cure C:\Program Files\Common Files\AOL\AOL Spyware Protection\Backup\
    dtpdibhv.exe Win32.SillyDl.AL cannot cure C:\Program Files\Internet Explorer\
    ihzhvejr.exe Win32.SillyDl.AL cannot cure C:\Program Files\Internet Explorer\
    woqtiwpy.exe Win32.SillyDl.AL cannot cure C:\Program Files\Internet Explorer\
    ndcnpuyt.exe Win32.SillyDl.AL cannot cure C:\Program Files\Internet Explorer\
    wxhqykbd.exe Win32.SillyDl.AL cannot cure C:\Program Files\Internet Explorer\
    optimize.exe Win32.Dyfuca.J cannot cure C:\Program Files\Internet Optimizer\
    optimize.exe Win32.Dyfuca.J cannot cure C:\Program Files\Internet Optimizer\update\
    load_mas2_java.exe Win32.SillyDl.AL cannot cure C:\
    124459.exe Win32.Tibser.G cannot cure C:\
    4.dat Win32.DlMersting.BO cannot cure C:\AOL Downloads\America Online 8.0\
    3.dat Win32.Secdrop.M cannot cure C:\AOL Downloads\America Online 8.0\
    2.dat Win32.Tibser.P cannot cure C:\AOL Downloads\America Online 8.0\

     

      Search

    CA Security Advisor Virus Encyclopedia Vulnerability Encyclopedia Spyware Encyclopedia News and Information 


  • ALgal

    1188 Posts

    369

    0

    Posted April 29th, 2005 13:00

    Sorry Mike,
     
    Steve helped me the last time.  My mind is going as I approach the big 50!
     
    Please explain what you meant by (2nd page).  How do you check and make sure none are OS files? Do you mean those files listed at Pac-man?
     
    Susan  
  • ALgal

    1188 Posts

    369

    0

    Posted April 29th, 2005 20:00

    Hi Mike,
     
    This is the latest hijackthis log. I did run one and it had many things in the trusted zones which surprised me so I checked thoses before I ran and posted this one.
     
    I ran the eTrust virus scan this morning and you saw that it found 44 viruses.  I manually deleted some files and got it down to 11.  Hey, I thought I was doing better and then I ran the Trend Micro Housecalls and it found 39.  The files were non-cleanable and so I clicked delete but there were some cabinet files and it asked if I wanted to delete the whole file.  I thought I had better get your input. But it got down to 3 files. One file that was deleted was Outlook.exe and if Outlook is messed up, I think that means reinstalling Internet Explorer. But then since he uses AOL maybe he wouldn't care.
     
    Now which is better? Trend Micros HouseCall or Computer Associates e-Trust?
     
    The I.P. address is appearing in the Trusted Zone again!
     
    Logfile of HijackThis v1.99.1
    Scan saved at 3:15:38 PM, on 4/29/05
    Platform: Windows 98 SE (Win9x 4.10.2222B)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    c:\windows\SYSTEM\KB891711\KB891711.EXE
    C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\ATI2PLAB.EXE
    C:\WINDOWS\SYSTEM\ATIPTAAB.EXE
    C:\WINDOWS\SYSTEM\ATI2CWXX.EXE
    C:\WINDOWS\SYSTEM\ESSAPM.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\AOL SPYWARE PROTECTION\AOLSP SCHEDULER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLDIAL.EXE
    C:\WINDOWS\SYSTEM\QTTASK.EXE
    C:\WINDOWS\SYSTEM\SYSTIME.EXE
    C:\WINDOWS\RunDLL.exe
    C:\WINDOWS\SYSTEM\SYSTIME.EXE
    C:\PROGRAM FILES\AMERICA ONLINE 8.0\AOLTRAY.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\HJT\HIJACKTHIS.EXE
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://213.159.117.134/index.php
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://213.159.117.134/index.php
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
    O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [ATIPOLAB] ati2plab.exe
    O4 - HKLM\..\Run: [AtiPTA] Atiptaab.exe
    O4 - HKLM\..\Run: [Ati2cwxx] Ati2cwxx.exe
    O4 - HKLM\..\Run: [essapm] essapm.exe
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\SYGATE\SPF\SMC.EXE -startgui
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
    O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [SysTime] C:\WINDOWS\SYSTEM\systime.exe
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [AolAcsDaemon1] "C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE"
    O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
    O4 - HKLM\..\RunServices: [SmcService] C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
    O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
    O4 - HKCU\..\Run: [SysTime] C:\WINDOWS\SYSTEM\systime.exe
    O4 - Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
    O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
    O15 - Trusted IP range: 213.159.117.133
    O15 - Trusted IP range: 213.159.117.133 (HKLM)
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/22f74e0339045b8b2b05/netzip/RdxIE601.cab
    O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
     
  • ALgal

    1188 Posts

    369

    0

    Posted April 29th, 2005 23:00

    Hi Mike,
    I still have problems with the hjackthis log but now the Trend Micro only shows 2 infected files which are
    C:\ied_s7m.cab *ied.exe* with TROJ_DOWNLOAD.O
    C:\ied_s7.cab*ied_s7_c_7.exe* with TROJ RE.A
     
     
  • Midnight Star

    4791 Posts

    369

    0

    Posted April 29th, 2005 23:00

    Hi Susan,

    Great work! Just delete those two CAB files manually. There's one other program that concerns me, but it's coming up as good: "HKLM\..\Run: [essapm] essapm.exe" - do you know what this is?


    -

    Let's continue on with the fix...



    Download, unzip to your desktop CWShredder and run it, then:

    1. Click " Check For Update"

    ( If an update isn't available, skip to step #4.)

    2. Click " Click here to Download the upate".
    3. When the new version has been downloaded, click " Save".
    4. Click " Fix ->"




    Run HiJackThis then:

    1. Click " Config..."
    2. Click " Misc Tools"
    3. Click " Open Process manager"

    -

    Next, while holding down the CTRL key, locate ( if present) and click on ( highlight) each of the following:

    C:\WINDOWS\SYSTEM\SYSTIME.EXE

    Now double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.



    Run HiJackThis and click " Scan", then check(tick) the following, if present:


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://213.159.117.134/index.php
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://213.159.117.134/index.php
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php

    O4 - HKLM\..\Run: [SysTime] C:\WINDOWS\SYSTEM\systime.exe
    O4 - HKCU\..\Run: [SysTime] C:\WINDOWS\SYSTEM\systime.exe

    O15 - Trusted IP range: 213.159.117.133
    O15 - Trusted IP range: 213.159.117.133 (HKLM)

    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/22f74e0339045b8b2b05/netzip/RdxIE601.cab


    Now, with all windows closed except HiJackThis, click " Fix checked".



    Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:

    files...

    C:\WINDOWS\SYSTEM\SYSTIME.EXE

    -

    Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".



    Post back a new log, and let me know how everything goes.

    -

    Mike.
  • ALgal

    1188 Posts

    241

    0

    Posted April 30th, 2005 01:00

    Hi Mike,
    I ran CWShredder and it got rid of the Sys Time.
    Essapm essapm.exe- ESS Solo soundcard driver
     
    I still have a problem with the I.P. in the Trusted Zone.  I even went to the zone in IE and removed it but it is still there. 
    Here is the log:
    Logfile of HijackThis v1.99.1
    Scan saved at 9:02:55 PM, on 4/29/05
    Platform: Windows 98 SE (Win9x 4.10.2222B)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    c:\windows\SYSTEM\KB891711\KB891711.EXE
    C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\ATI2PLAB.EXE
    C:\WINDOWS\SYSTEM\ATIPTAAB.EXE
    C:\WINDOWS\SYSTEM\ATI2CWXX.EXE
    C:\WINDOWS\SYSTEM\ESSAPM.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\AOL SPYWARE PROTECTION\AOLSP SCHEDULER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLDIAL.EXE
    C:\WINDOWS\SYSTEM\QTTASK.EXE
    C:\WINDOWS\RunDLL.exe
    C:\PROGRAM FILES\AMERICA ONLINE 8.0\AOLTRAY.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\HJT\HIJACKTHIS.EXE
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
    O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [ATIPOLAB] ati2plab.exe
    O4 - HKLM\..\Run: [AtiPTA] Atiptaab.exe
    O4 - HKLM\..\Run: [Ati2cwxx] Ati2cwxx.exe
    O4 - HKLM\..\Run: [essapm] essapm.exe
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\SYGATE\SPF\SMC.EXE -startgui
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
    O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [AolAcsDaemon1] "C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE"
    O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
    O4 - HKLM\..\RunServices: [SmcService] C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
    O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
    O4 - Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
    O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
    O15 - Trusted IP range: 213.159.117.133 (HKLM)
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
    O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab