Announcement Banner
UNSOLVED

acerbisfox22

updated

20 years ago

0

432

September 24th, 2006 20:00

Please Help Me With My HijackThis Log

Help me with harmful viruses please.
 
 
 
Logfile of HijackThis v1.99.1
Scan saved at 2:17:05 PM, on 9/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50212
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.ieplugin.com/search.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.ieplugin.com/search.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [*unole] C:\WINDOWS\system\unole.exe
O4 - HKLM\..\Run: [*basip] C:\WINDOWS\security\basip.exe
O4 - HKLM\..\Run: [*abrxml] C:\WINDOWS\Web\PRINTERS\abrxml.exe
O4 - HKLM\..\Run: [*uniis] C:\WINDOWS\uniis.exe
O4 - HKLM\..\Run: [SetupWizard] D:\SetupWizard.exe reboot
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [rA4PHMsO] C:\documents and settings\lance\local settings\temp\rA4PHMsO.exe
O4 - HKLM\..\Run: [wdskctl] C:\WINDOWS\wdskctl.exe
O4 - HKLM\..\Run: [ekwsojt] C:\WINDOWS\System32\aubiuo.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: csrss.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm414
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.2.89.cab
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures06.aim.com/ygp/aol/plugin/upf/AOLUPF.en-US-AIM.9.5.1.8.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} - http://download.toontown.com/sv1.0.15.38/ttinst.cab
O16 - DPF: {C0B285F6-DB2B-4908-9C58-F6D95397D747} - http://www.pacimedia.com/install/pcs_0002.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: infoplay - C:\DOCUME~1\BIG&FR~1\LOCALS~1\Temp\yalpofni.dat (file missing)
O20 - Winlogon Notify: uniis - C:\DOCUME~1\lance\LOCALS~1\Temp\siinu.dat (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: System Startup Service  (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
  • 1972vet

    3305 Posts

    179

    0

    Posted September 26th, 2006 17:00

    Please first read through these instructions entirely before you begin. Since there are some applications you need to download and install, you must do that first. Following through the instructions below, each time you see where you are instructed to download and install an application, please download that application now, and refer back to that software when you reach that step along the way while following these instructions.

    Download the software as instructed below with each step that requires a download, stop there after you install it, and continue to the next step that requires another download and so on. Conintue in that manner until you have finished installing all the software that you will need to complete these instructions.

    ...when finished downloading all the software, then disconnect from the internet and go back to the beginning to start the removal processes outlined below.

    Before we start fixing anything you may want to PRINT and keep all instructions handy. You may also want to save them to WordPad so that they will be accessible. DO NOT use notepad. Some steps will require you to disconnect from the Internet and you will not have access to this page.

    Please uninstall the following software:
    ViewPoint View Manager
    BearShare

    Click start-->control panel-->add/remove programs...scroll down the list to locate the program names and click Remove. Reboot when the uninstall completes.

    Your Java application is out of date and causes a slight security risk as a result.
    Please follow these steps to remove older version Java components

    1. Close any open programs you may have running, especially your web
    browser.

    2. Click Start-->Control Panel-->Add or Remove Programs.
    For those just reading this thread:
    Depending on your OS, you may have to click Start-->Settings-->Control Panel-->Add or Remove Programs.


    3. Click once on any item listing Java Runtime Environment in the name (to highlight it) then click the "Remove" or "Change/Remove" button.
    Not every version of Java will begin with "Java" so be sure to read each entry in the list.
    Repeat step 3 as many times as necessary to remove all versions of Java.
    **If you are asked to reboot at any point during the uninstallations, please do so. Then go back to Add/Remove and continue with the rest of the removals...when finished uninstalling all of them, reboot the computer.

    4. Navigate to and delete:
    • C:\Program Files\ Java =this folder if found
    5. Then go to this page.
    Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"and click the "Download" button to the right.

    6. Check the box that says: "Accept License Agreement" the page will refresh and click on the link to download Windows Offline Installation with or without Multi-language. Save it to your desktop.
    Then from your desktop double-click on jre-1_5_0_08-windowsi586-p.exe to install the newest version.

    Please download Look2Me-Destroyer.exe to your desktop.
    • Close all windows before continuing.
    • Double-click "Look2Me-Destroyer.exe" to run it.
    • Put a check next to "Run this program as a task."
    • You will receive a message saying "Look2Me-Destroyer will close and re-open in approximately 1 minute". Click "OK"
    • When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
    • Once it's done scanning, click the "Remove L2M" button.
    • You will receive a "Done Scanning" message, click "OK".
    • When completed, you will receive this message: "Done removing infected files! Look2Me-Destroyer will now shutdown your computer", click "OK".
    • Your computer will then shutdown.
    • Turn your computer back on.
    • Please remember to post the contents of C:\Look2Me-Destroyer.txt on your next reply. The log can be found wherever the fix is located - if Look2Me-Destroyer is on the desktop thats where the log will be.
    If Look2Me-Destroyer does not reopen automatically, reboot and try again.
    If you receive a message from your firewall about this program accessing the internet please allow it.

    If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32 Directory.
    http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX
    Then you click the Remove L2M button and wait for it to give you a message. When you click OK it should shut itself down.


    Next, please follow these instructions below to continue removing the Nail/Aurora infection that is present on your system:
    Step 1: Download and install Ewido Anti-Spyware v4.0
    1. After download, double click on the file to launch the install process.
    2. Choose a language, click " OK" and then click " Next".
    3. Read the " License Agreement" and click " I Agree".
    4. Accept the default installation path: C:\Program Files\ewido anti-spyware 4.0 and click " Next", then click " Install".
    5. After setup completes, click " Finish" to start the program automatically or launch ewido by double-clicking its icon on your desktop or in the system tray.
    6. The main " Status" menu will appear. You can select " Change state" to inactivate ' Resident Sheild' and ' Automatic Updates'. If you choose to do this, then right click on ewdio in the system tray and uncheck " Start with Windows".
    7. Go to Start > Run and type: services.msc
    • Press "OK".
    • In Services, click the " Extended tab" and scroll down the list to find ewido anti-spyware 4.0 guard.
      When you find the guard service, double-click on it.
      In the Properties Window > General Tab that opens, click the " Stop" button.
      From the drop-down menu next to "Startup Type", click on " Manual".
      Now click " Apply", then " OK" and close the Services window.
      8. Select the " Update" button and click " Start update". If you are having problems with the updater, manually update with the Ewido Full database installer from here.
      9. Exit Ewido when done - DO NOT perform a scan yet.

      Step 2: Download Ad-Aware SE.
      Download Ad-Aware VX2 Cleaner Plugin.
      Install Ad-Aware using the default options, then install vx2cleaner_inst.exe, taking all the defaults there as well.

      Step 3: Run Ad-Aware, update to the latest definitions, then click on " Add-ons" in the lefthand column. Select VX2 Cleaner V2.0 and click " Run Tool". Click " OK", then, if something is found, click " Clean" as in the directions given. Click " Close", and exit Ad-Aware.

      Reboot your PC and run Ad-Aware again. This time, click on the " Start" button in Ad-Aware, select " Perform smart system scan" and click " Next". Once the scan finishes, click " Next" again. Select all objects found (right click anywhere in the list of found objects and click " Select All Objects"). Click " Next" one more time, then "OK" to confirm the removal.

      You will be prompted to set Ad-Aware to run on reboot, click " OK". Exit Ad-Aware and restart your PC once again. When Ad-Aware starts up, click on " Start", then " Next". Follow the steps above if anything is found, or click " Finish", then exit Ad-Aware.

      Step 4: Reboot your computer in "SAFE MODE" using the F8 method so Windows will start with minimal drivers and running processes. To do this restart your computer and after hearing your computer beep once during startup press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode". See How to Boot in " SAFE MODE" tutorial if needed.

      Step 5: Scan with Ewido as follows:
      1. Launch Ewido, click on the " Scanner" button and choose the " Settings" tab.
      • Under "How to act?", click on "Recommended actions" and choose "Quarantine" to set default action for detected malware.
      • Under "How to Scan?" check all (default).
      • Under "Possibly unwanted software" check all (default).
      • Under "What to Scan?" make sure "Scan every file" is selected (default).
      • Under "Reports" select "Automatically generate report after every scan and UNcheck "Only if threats were found".
      2. Click the " Scan" tab to return to scanning options.
      3. Click " Complete System Scan" to start.
      4. When the scan has finished you will be presented with a list of infected objects found. Click " Apply all actions" to place the files in Quarantine.

      IMPORTANT! Don't save the report before you have clicked the Apply all actions button. If you do it will make it more difficult for the helper to interpret the report.

      5. Click on " Save Report" to view all completed scans. Click on the most recent scan you just performed and select " Save report as" - the default file name will be in date/time format as follows: Report-Scan-20060620-142816.txt. Save to your desktop. A copy of each report will also be saved in C:\Program Files\ewido anti-spyware 4.0\Reports\
      6. Exit Ewido when done and submit the log report in your next response.

      Note: Close all open windows, programs, and DO NOT USE the computer while Ewido is scanning. If Explorer or other programs are open during the scan that means certain files will also be in use. Some malware will insert itself and hide in areas that are "protected" by Windows when the files are being used. This can hamper Ewido's ability to clean properly and may result in reinfection.

      Step 6: Reboot and post a new HJT log along with the Ewido log report, and the contents of C:\ Look2Me-Destroyer.txt in your next reply.
      Thanks!


      Please post the