Wallpaper and Spysheriff won't go away! [CLOSED], Problems with wallpaper/Spysheriff. |
![]() ![]() |
Wallpaper and Spysheriff won't go away! [CLOSED], Problems with wallpaper/Spysheriff. |
Jul 10 2005, 01:15 AM
Post
#1
|
|
|
New Member ![]() Posts: 5 OS: Windows XP |
"CRITICAL WARNING!" System has been stopped due to a serious malfunction. Spyware activity has been detected. It is recommended to use a spyware removal tool to prevent data loss. Do not use the computer before all spyware removed". And when I turn on my computer, a program called "Spysheriff" installs itself. No matter what I do, it will not be permanently deleted. The following is a scan from HijackThis. Logfile of HijackThis v1.99.1 Scan saved at 11:37:53 PM, on 7/9/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINDOWS\Explorer.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\ewido\security suite\ewidoguard.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\Program Files\eMachines Bay Reader\shwiconem.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\WINDOWS\system32\paytime.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\m?dtc.exe C:\Program Files\AIM\aim.exe C:\Program Files\sswp\cruu.exe C:\WINDOWS\system32\paytime.exe C:\Program Files\BigFix\BigFix.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Owner\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://195.95.218.172/index.php R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://195.95.218.172/index.php R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.172/index.php R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.172/index.php R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing) O2 - BHO: (no name) - {0701E4CC-7E2E-23D4-56BF-0532D76CB6CD} - C:\WINDOWS\system32\ishhmv.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {6A903147-A1F4-FA05-8F57-DB7F136ED5C4} - C:\WINDOWS\system32\judgbme.dll (file missing) O2 - BHO: (no name) - {B01CC521-5BB3-5735-E4D9-20C0CA9457B4} - C:\WINDOWS\system32\psuh.dll (file missing) O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file) O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe O4 - HKLM\..\Run: [firlnin] C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\UP0T03UP\delf061225[1].exe O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE O4 - HKLM\..\Run: [Porijnr] C:\Program Files\Avjbs\Bpymxmt.exe O4 - HKLM\..\Run: [MsConfigs] C:\Program Files\MsConfigs\MsConfigs.exe O4 - HKLM\..\Run: [p2pnetwork] p2pnetwork.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [brojvrp] c:\windows\system32\wgrfggh.exe O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe O4 - HKLM\..\Run: [Service Process] C:\WINDOWS\system32\config\service.exe O4 - HKLM\..\Run: [wcadime] c:\windows\system32\oiaftda.exe r O4 - HKLM\..\RunServices: [p2pnetwork] p2pnetwork.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Fbtcsslh] C:\WINDOWS\system32\m?dtc.exe O4 - HKCU\..\Run: [p2pnetwork] p2pnetwork.exe O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [Cpue] C:\Program Files\sswp\cruu.exe O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe O4 - HKCU\..\RunServices: [p2pnetwork] p2pnetwork.exe O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O15 - Trusted Zone: *.windupdates.com O15 - Trusted IP range: 81.222.131.59 O15 - Trusted IP range: 81.222.131.59 (HKLM) O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing) O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe Please, if you can, help me. I have done all in my power, now I need help from a professional. |
|
|
Jul 14 2005, 08:10 PM
Post
#2
|
|
|
Malware Expert Posts: 10,017 OS: XP |
Hi and welcome to GeeksToGo! My name is Sam and I will be helping you.
I apologize for the delay getting to your log, the helpers here are very busy. I see several infections in your log that I can help you with. If you still need help, please post a fresh Hijack log, in this thread, so I can help you with your Malware Problems. If you have resolved this issue please let us know. |
|
|
Jul 14 2005, 10:57 PM
Post
#3
|
|
|
New Member ![]() Posts: 5 OS: Windows XP |
Of course. It's here. I wouldn't be surprised if anything changed, it continues to install things on my computer.
Logfile of HijackThis v1.99.1 Scan saved at 9:53:02 PM, on 7/14/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\ewido\security suite\ewidoguard.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\Program Files\eMachines Bay Reader\shwiconem.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\WINDOWS\system32\paytime.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\m?dtc.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\AIM\aim.exe C:\Program Files\sswp\cruu.exe C:\WINDOWS\system32\paytime.exe C:\Program Files\BigFix\BigFix.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\LimeWire\LimeWire.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Owner\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://195.95.218.172/index.php R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://195.95.218.172/index.php R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.172/index.php R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.172/index.php R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing) O2 - BHO: (no name) - {0701E4CC-7E2E-23D4-56BF-0532D76CB6CD} - C:\WINDOWS\system32\ishhmv.dll (file missing) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {6A903147-A1F4-FA05-8F57-DB7F136ED5C4} - C:\WINDOWS\system32\judgbme.dll (file missing) O2 - BHO: (no name) - {B01CC521-5BB3-5735-E4D9-20C0CA9457B4} - C:\WINDOWS\system32\psuh.dll (file missing) O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file) O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe O4 - HKLM\..\Run: [firlnin] C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\UP0T03UP\delf061225[1].exe O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE O4 - HKLM\..\Run: [Porijnr] C:\Program Files\Avjbs\Bpymxmt.exe O4 - HKLM\..\Run: [MsConfigs] C:\Program Files\MsConfigs\MsConfigs.exe O4 - HKLM\..\Run: [p2pnetwork] p2pnetwork.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [brojvrp] c:\windows\system32\wgrfggh.exe O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe O4 - HKLM\..\Run: [Service Process] C:\WINDOWS\system32\config\service.exe O4 - HKLM\..\Run: [wcadime] c:\windows\system32\oiaftda.exe r O4 - HKLM\..\RunServices: [p2pnetwork] p2pnetwork.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Fbtcsslh] C:\WINDOWS\system32\m?dtc.exe O4 - HKCU\..\Run: [p2pnetwork] p2pnetwork.exe O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [Cpue] C:\Program Files\sswp\cruu.exe O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe O4 - HKCU\..\Run: [SpySheriff] C:\Program Files\SpySheriff\SpySheriff.exe O4 - HKCU\..\RunServices: [p2pnetwork] p2pnetwork.exe O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O15 - Trusted Zone: *.windupdates.com O15 - Trusted IP range: 81.222.131.59 O15 - Trusted IP range: 81.222.131.59 (HKLM) O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing) O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe |
|
|
Jul 15 2005, 02:57 PM
Post
#4
|
|
|
Malware Expert Posts: 10,017 OS: XP |
Download smitRem.zip and save the file to your desktop.
Right click on the file and extract it to it's own folder on the desktop. Place a shortcut to Panda ActiveScan on your desktop. Please download the trial version of Ewido Security Suite here: http://www.ewido.net/en/download/ Please read Ewido Setup Instructions Install it, and update the definitions to the newest files. Do NOT run a scan yet. If you have not already installed Ad-Aware SE 1.06, follow these download and setup instructions, otherwise, check for updates: Ad-Aware SE Setup Don't run it yet! Next, please reboot your computer in SafeMode by doing the following:
=================================================== R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://195.95.218.172/index.php R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://195.95.218.172/index.php R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.172/index.php R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.172/index.php R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe O15 - Trusted Zone: *.windupdates.com O15 - Trusted IP range: 81.222.131.59 O15 - Trusted IP range: 81.222.131.59 (HKLM) =================================================== Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish. The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply. Open Ad-aware and do a full scan. Remove all it finds. Run Ewido:
Next go to Control Panel click Display > Desktop > Customize Desktop > Website > Uncheck "Security Info" if present. Reboot back into Windows and click the Panda ActiveScan shortcut, then do a full system scan. Make sure the autoclean box is checked! Save the scan log and post it along with a new HijackThis Log, the contents of the smitfiles.txt log and the Ewido Log by using Add Reply. Let us know if any problems persist. |
|
|
Jul 15 2005, 07:49 PM
Post
#5
|
|
|
New Member ![]() Posts: 5 OS: Windows XP |
Logfile of HijackThis v1.99.1
Scan saved at 6:43:42 PM, on 7/15/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\ewido\security suite\ewidoguard.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\Program Files\eMachines Bay Reader\shwiconem.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\m?dtc.exe C:\Program Files\AIM\aim.exe C:\Program Files\BigFix\BigFix.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Owner\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://195.95.218.172/index.php R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://195.95.218.172/index.php R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.172/index.php R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.172/index.php O2 - BHO: (no name) - {0701E4CC-7E2E-23D4-56BF-0532D76CB6CD} - C:\WINDOWS\system32\ishhmv.dll (file missing) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {6A903147-A1F4-FA05-8F57-DB7F136ED5C4} - C:\WINDOWS\system32\judgbme.dll (file missing) O2 - BHO: (no name) - {B01CC521-5BB3-5735-E4D9-20C0CA9457B4} - C:\WINDOWS\system32\psuh.dll (file missing) O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe O4 - HKLM\..\Run: [firlnin] C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\UP0T03UP\delf061225[1].exe O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE O4 - HKLM\..\Run: [Porijnr] C:\Program Files\Avjbs\Bpymxmt.exe O4 - HKLM\..\Run: [MsConfigs] C:\Program Files\MsConfigs\MsConfigs.exe O4 - HKLM\..\Run: [p2pnetwork] p2pnetwork.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [brojvrp] c:\windows\system32\wgrfggh.exe O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe O4 - HKLM\..\Run: [Service Process] C:\WINDOWS\system32\config\service.exe O4 - HKLM\..\Run: [wcadime] c:\windows\system32\oiaftda.exe r O4 - HKLM\..\RunServices: [p2pnetwork] p2pnetwork.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Fbtcsslh] C:\WINDOWS\system32\m?dtc.exe O4 - HKCU\..\Run: [p2pnetwork] p2pnetwork.exe O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [Cpue] C:\Program Files\sswp\cruu.exe O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe O4 - HKCU\..\RunServices: [p2pnetwork] p2pnetwork.exe O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O15 - Trusted IP range: 81.222.131.59 O15 - Trusted IP range: 81.222.131.59 (HKLM) O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing) O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe Pre-run Files Present ~~~ Program Files ~~~ SpySheriff ~~~ Shortcuts ~~~ Install.dat ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Windows directory ~~~ desktop.html ~~~ Drive root ~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Post-run Files Present ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Wininet.dll ~~~ CLEAN! --------------------------------------------------------- ewido security suite - Scan report --------------------------------------------------------- + Created on: 6:35:18 PM, 7/15/2005 + Report-Checksum: ADE53CAE + Scan result: HKLM\SOFTWARE\Classes\ImgConv.clsImgConv -> Spyware.WebRebates : Cleaned with backup HKLM\SOFTWARE\Classes\ImgConv.clsImgConv\Clsid -> Spyware.WebRebates : Cleaned with backup HKLM\SOFTWARE\Classes\Interface\{2DDD90D6-F153-4EA7-A324-4B2D83D1027E} -> Spyware.HotBar : Cleaned with backup HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Spyware.WebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\TypeLib\{15E7D23B-736E-46FA-BFFD-CBEC4126BEFD} -> Spyware.WebRebates : Cleaned with backup HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DisplayUtility -> Spyware.Delfin : Cleaned with backup HKLM\SOFTWARE\Mvu -> Spyware.Delfin : Cleaned with backup HKU\S-1-5-21-4166258374-2193716384-4240240725-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup HKU\S-1-5-21-4166258374-2193716384-4240240725-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D60FF48-95BE-4956-B4C6-6BB168A70310} -> Spyware.KeenValue : Cleaned with backup HKU\S-1-5-21-4166258374-2193716384-4240240725-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} -> Spyware.MoneyTree : Cleaned with backup HKU\S-1-5-21-4166258374-2193716384-4240240725-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A0269420-A638-4509-889C-8FC3CC85DA7E} -> Dialer.Generic : Cleaned with backup HKU\S-1-5-21-4166258374-2193716384-4240240725-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA2325ED-F9EB-4830-8FCE-0BC35B16969B} -> Spyware.SaveNow : Cleaned with backup HKU\S-1-5-21-4166258374-2193716384-4240240725-1003\Software\Mvu -> Spyware.Delfin : Cleaned with backup :mozilla.23:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.24:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.25:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.43:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.44:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.45:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.46:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.50:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.51:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.52:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.57:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.58:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.66:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.67:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.86:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.87:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.88:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.89:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.90:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.91:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8g7yhap3.Default User\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.29:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.42:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.44:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.45:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.46:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.47:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.56:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.57:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.58:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.60:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.61:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.62:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.69:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.70:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.71:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.74:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.76:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.77:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.78:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.80:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.81:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.82:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.83:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.84:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.85:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.86:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.87:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.88:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.89:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.90:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.91:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.92:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.93:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.127:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.128:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qbsrgia0.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\WINDOWS\sys944.exe -> TrojanDownloader.Small.bct : Cleaned with backup C:\WINDOWS\system32\Ojqgqc32.exe -> Backdoor.Padodor.az : Cleaned with backup C:\WINDOWS\system32\paytime.exe -> Heuristic.Win32.Hijacker1 : Cleaned with backup ::Report End Well, those are the scans. The wallpaper remains the same, though. It doesn't have the option to "Uncheck" the security info, though. However, there are alot less infections, so that was a help. |
|
|
Jul 15 2005, 08:28 PM
Post
#6
|
|
|
Malware Expert Posts: 10,017 OS: XP |
Let's clean up your log and then we'll come back to your desktop once we get rid all of the underlying infection.
*Click Here to download Killbox by Option^Explicit. *Extract the program to your desktop and double-click on its folder, then double-click on Killbox.exe to start the program. *In the killbox program, select the Delete on Reboot option. *Copy the file names below to the clipboard by highlighting them and pressing Control-C: C:\Program Files\MsConfigs\MsConfigs.exe C:\WINDOWS\system32\p2pnetwork.exe C:\WINDOWS\system32\CMD.COM C:\WINDOWS\system32\netstat.com C:\WINDOWS\system32\ping.com C:\WINDOWS\system32\regedit.com C:\WINDOWS\system32\tasklist.com C:\WINDOWS\system32\taskkill.com C:\WINDOWS\system32\taskmgr.com C:\WINDOWS\system32\tracert.com C:\WINDOWS\SM1BG.EXE c:\windows\system32\wgrfggh.exe C:\WINDOWS\system32\paytime.exe C:\WINDOWS\system32\config\service.exe c:\windows\system32\oiaftda.exe C:\Program Files\sswp\cruu.exe C:\WINDOWS\system32\m?dtc.exe C:\winstall.exe *Return to Killbox, go to the File menu, and choose "Paste from Clipboard". *Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt. After the reboot run HijackThis again. Check the following items in HijackThis. Close all windows except HijackThis and click Fix checked: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://195.95.218.172/index.php R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://195.95.218.172/index.php R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.172/index.php R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.172/index.php O2 - BHO: (no name) - {0701E4CC-7E2E-23D4-56BF-0532D76CB6CD} - C:\WINDOWS\system32\ishhmv.dll (file missing) O2 - BHO: (no name) - {6A903147-A1F4-FA05-8F57-DB7F136ED5C4} - C:\WINDOWS\system32\judgbme.dll (file missing) O2 - BHO: (no name) - {B01CC521-5BB3-5735-E4D9-20C0CA9457B4} - C:\WINDOWS\system32\psuh.dll (file missing) O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [firlnin] C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\UP0T03UP\delf061225[1].exe O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE O4 - HKLM\..\Run: [Porijnr] C:\Program Files\Avjbs\Bpymxmt.exe O4 - HKLM\..\Run: [MsConfigs] C:\Program Files\MsConfigs\MsConfigs.exe O4 - HKLM\..\Run: [p2pnetwork] p2pnetwork.exe O4 - HKLM\..\Run: [brojvrp] c:\windows\system32\wgrfggh.exe O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe O4 - HKLM\..\Run: [Service Process] C:\WINDOWS\system32\config\service.exe O4 - HKLM\..\Run: [wcadime] c:\windows\system32\oiaftda.exe r O4 - HKLM\..\RunServices: [p2pnetwork] p2pnetwork.exe O4 - HKCU\..\Run: [Fbtcsslh] C:\WINDOWS\system32\m?dtc.exe O4 - HKCU\..\Run: [p2pnetwork] p2pnetwork.exe O4 - HKCU\..\Run: [Cpue] C:\Program Files\sswp\cruu.exe O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe O4 - HKCU\..\RunServices: [p2pnetwork] p2pnetwork.exe O15 - Trusted IP range: 81.222.131.59 O15 - Trusted IP range: 81.222.131.59 (HKLM) O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing) ========== Please download, install, and run Cleanup 4.0 This will remove all of your temp files. http://cleanup.stevengould.org/ ========== Please run at least two of these online scans. Make sure they are set to clean automatically Panda Virus Scan Bit Defender TrendMicro Housecall There will be files that these scans will not remove. Please include that information in your next post. Reboot and post a new hijackthis log and the info from your virus scans. |
|
|
Jul 16 2005, 01:20 AM
Post
#7
|
|
|
New Member ![]() Posts: 5 OS: Windows XP |
Logfile of HijackThis v1.99.1 Scan saved at 12:16:10 AM, on 7/16/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\ewido\security suite\ewidoguard.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\Program Files\eMachines Bay Reader\shwiconem.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\AIM\aim.exe C:\Program Files\BigFix\BigFix.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\LimeWire\LimeWire.exe C:\Documents and Settings\Owner\Desktop\HijackThis.exe O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe O4 - HKLM\..\Run: [firlnin] C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\UP0T03UP\delf061225[1].exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing) O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Fi |