NOT AGAIN!? [CLOSED], 3rd time lucky... |
![]() ![]() |
NOT AGAIN!? [CLOSED], 3rd time lucky... |
Jul 19 2005, 07:20 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 46 OS: 2k |
Perhaps the best way to avoid these problems is to avoid the intermet. This is the HJT log after my pc was cleaned last week from thatman... Logfile of HijackThis v1.99.1 Scan saved at 12:05:08 PM, on 13/07/2005 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\csrss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\svchost.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\ewido\security suite\ewidoguard.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\spoolsv.exe C:\WINNT\System32\svchost.exe C:\WINNT\Explorer.EXE C:\PROGRA~1\NORTON~1\navapw32.exe C:\WINNT\system32\internat.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe C:\Program Files\Microsoft Office\Office\1033\msoffice.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Outlook Express\msimn.exe C:\Program Files\Microsoft Office\Office\WINWORD.EXE C:\Antivirus Files\Hijack This\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe O4 - HKCU\..\Run: [internat.exe] internat.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0 O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O15 - Trusted Zone: http://www.anz.com.au O15 - Trusted Zone: http://www.commbank.com.au O15 - Trusted Zone: http://www.emailcash.com.au O15 - Trusted Zone: http://www.footytips.com.au O15 - Trusted Zone: http://www.ewido.net O15 - Trusted Zone: http://www.hotmail.com O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe Here is the HJT log since being infected again... Logfile of HijackThis v1.99.1 Scan saved at 12:10:47 PM, on 19/07/2005 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\csrss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\WINNT\System32\svchost.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\WINNT\Explorer.EXE C:\PROGRA~1\NORTON~1\navapw32.exe C:\WINNT\system32\svcnt.exe C:\WINNT\system32\internat.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe C:\Program Files\Microsoft Office\Office\1033\msoffice.exe C:\Program Files\Microsoft Office\Office\EXCEL.EXE C:\Antivirus Files\Hijack This\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdocsv.dll/blank.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://shdocsv.dll/asst.htm O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" O4 - HKLM\..\Run: [Fast Start] C:\WINNT\system32\svcnt.exe home O4 - HKCU\..\Run: [internat.exe] internat.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0 O4 - HKCU\..\Run: [Intel system tool] C:\WINNT\system32\hookdump.exe O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O15 - Trusted Zone: http://www.anz.com.au O15 - Trusted Zone: http://www.commbank.com.au O15 - Trusted Zone: http://www.emailcash.com.au O15 - Trusted Zone: http://www.footytips.com.au O15 - Trusted Zone: http://www.ewido.net O15 - Trusted Zone: http://www.hotmail.com O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe I ran a scan using Ewido and here is the log... --------------------------------------------------------- ewido security suite - Scan report --------------------------------------------------------- + Created on: 3:04:43 PM, 19/07/2005 + Report-Checksum: 867AEE3F + Scan result: C:\WINNT\system32\abirvalg32.dll -> TrojanProxy.Small.cn : Cleaned with backup ::Report End Adaware Scan... Ad-Aware SE Build 1.05 Logfile Created on:Tuesday, 19 July 2005 3:10:06 PM Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R54 14.07.2005 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» MRU List(TAC index:0):14 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Ad-Aware SE Settings =========================== Set : Search for negligible risk entries Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Play sound at scan completion if scan locates critical objects 19-07-2005 3:10:06 PM - Scan started. (Full System Scan) MRU List Object Recognized! Location: : C:\Documents and Settings\Administrator\Application Data\microsoft\office\recent Description : list of recently opened documents using microsoft office MRU List Object Recognized! Location: : C:\Documents and Settings\Administrator\recent Description : list of recently opened documents MRU List Object Recognized! Location: : S-1-5-21-1078081533-1682526488-1708537768-500\software\adobe\adobe acrobat\6.0\avgeneral\crecentfiles Description : list of recently used files in adobe acrobat MRU List Object Recognized! Location: : software\microsoft\directdraw\mostrecentapplication Description : most recent application to use microsoft directdraw MRU List Object Recognized! Location: : S-1-5-21-1078081533-1682526488-1708537768-500\software\microsoft\internet explorer Description : last download directory used in microsoft internet explorer MRU List Object Recognized! Location: : S-1-5-21-1078081533-1682526488-1708537768-500\software\microsoft\microsoft management console\recent file list Description : list of recent snap-ins used in the microsoft management console MRU List Object Recognized! Location: : S-1-5-21-1078081533-1682526488-1708537768-500\software\microsoft\office\9.0\common\open find\microsoft word\settings\open\file name mru Description : list of recent documents opened by microsoft word MRU List Object Recognized! Location: : S-1-5-21-1078081533-1682526488-1708537768-500\software\microsoft\office\9.0\common\open find\microsoft word\settings\save as\file name mru Description : list of recent documents saved by microsoft word MRU List Object Recognized! Location: : S-1-5-21-1078081533-1682526488-1708537768-500\software\microsoft\office\9.0\excel\recent files Description : list of recent files used by microsoft excel MRU List Object Recognized! Location: : S-1-5-21-1078081533-1682526488-1708537768-500\software\microsoft\windows\currentversion\applets\regedit Description : last key accessed using the microsoft registry editor MRU List Object Recognized! Location: : S-1-5-21-1078081533-1682526488-1708537768-500\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru Description : list of recent programs opened MRU List Object Recognized! Location: : S-1-5-21-1078081533-1682526488-1708537768-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru Description : list of recently saved files, stored according to file extension MRU List Object Recognized! Location: : S-1-5-21-1078081533-1682526488-1708537768-500\software\microsoft\windows\currentversion\explorer\recentdocs Description : list of recent documents opened MRU List Object Recognized! Location: : S-1-5-21-1078081533-1682526488-1708537768-500\software\microsoft\windows media\wmsdk\general Description : windows media sdk Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [smss.exe] FilePath : \SystemRoot\System32\ ProcessID : 136 ThreadCreationTime : 19-07-2005 3:41:37 AM BasePriority : Normal #:2 [csrss.exe] FilePath : \??\C:\WINNT\system32\ ProcessID : 164 ThreadCreationTime : 19-07-2005 3:42:00 AM BasePriority : Normal #:3 [winlogon.exe] FilePath : \??\C:\WINNT\system32\ ProcessID : 160 ThreadCreationTime : 19-07-2005 3:42:02 AM BasePriority : High #:4 [services.exe] FilePath : C:\WINNT\system32\ ProcessID : 212 ThreadCreationTime : 19-07-2005 3:42:05 AM BasePriority : Normal FileVersion : 5.00.2195.6700 ProductVersion : 5.00.2195.6700 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : services.exe #:5 [lsass.exe] FilePath : C:\WINNT\system32\ ProcessID : 224 ThreadCreationTime : 19-07-2005 3:42:05 AM BasePriority : Normal FileVersion : 5.00.2195.6695 ProductVersion : 5.00.2195.6695 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : LSA Executable and Server DLL (Export Version) InternalName : lsasrv.dll and lsass.exe LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : lsasrv.dll and lsass.exe #:6 [svchost.exe] FilePath : C:\WINNT\system32\ ProcessID : 408 ThreadCreationTime : 19-07-2005 3:42:13 AM BasePriority : Normal FileVersion : 5.00.2134.1 ProductVersion : 5.00.2134.1 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : svchost.exe #:7 [spoolsv.exe] FilePath : C:\WINNT\system32\ ProcessID : 436 ThreadCreationTime : 19-07-2005 3:42:13 AM BasePriority : Normal FileVersion : 5.00.2195.6659 ProductVersion : 5.00.2195.6659 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolss.exe LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : spoolss.exe #:8 [svchost.exe] FilePath : C:\WINNT\System32\ ProcessID : 468 ThreadCreationTime : 19-07-2005 3:42:14 AM BasePriority : Normal FileVersion : 5.00.2134.1 ProductVersion : 5.00.2134.1 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : svchost.exe #:9 [ewidoctrl.exe] FilePath : C:\Program Files\ewido\security suite\ ProcessID : 484 ThreadCreationTime : 19-07-2005 3:42:14 AM BasePriority : Normal FileVersion : 3, 0, 0, 1 ProductVersion : 3, 0, 0, 1 ProductName : ewido control CompanyName : ewido networks FileDescription : ewido control InternalName : ewido control LegalCopyright : Copyright © 2004 OriginalFilename : ewidoctrl.exe #:10 [ewidoguard.exe] FilePath : C:\Program Files\ewido\security suite\ ProcessID : 524 ThreadCreationTime : 19-07-2005 3:42:17 AM BasePriority : Normal FileVersion : 3, 0, 0, 1 ProductVersion : 3, 0, 0, 1 ProductName : guard CompanyName : ewido networks FileDescription : guard InternalName : guard LegalCopyright : Copyright © 2004 OriginalFilename : guard.exe #:11 [navapsvc.exe] FilePath : C:\Program Files\Norton AntiVirus\ ProcessID : 596 ThreadCreationTime : 19-07-2005 3:42:22 AM BasePriority : Normal FileVersion : 8.00.58 ProductVersion : 8.00.58 ProductName : Norton AntiVirus CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Auto-Protect Service InternalName : NAVAPSVC LegalCopyright : Copyright © 2000-2001 Symantec Corporation. All rights reserved. OriginalFilename : NAVAPSVC.EXE #:12 [regsvc.exe] FilePath : C:\WINNT\system32\ ProcessID : 668 ThreadCreationTime : 19-07-2005 3:42:27 AM BasePriority : Normal FileVersion : 5.00.2195.6701 ProductVersion : 5.00.2195.6701 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Remote Registry Service InternalName : regsvc LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : REGSVC.EXE #:13 [mstask.exe] FilePath : C:\WINNT\system32\ ProcessID : 704 ThreadCreationTime : 19-07-2005 3:42:28 AM BasePriority : Normal FileVersion : 4.71.2195.6704 ProductVersion : 4.71.2195.6704 ProductName : Microsoft® Windows® Task Scheduler CompanyName : Microsoft Corporation FileDescription : Task Scheduler Engine InternalName : TaskScheduler LegalCopyright : Copyright © Microsoft Corp. 1997 OriginalFilename : mstask.exe #:14 [winmgmt.exe] FilePath : C:\WINNT\System32\WBEM\ ProcessID : 776 ThreadCreationTime : 19-07-2005 3:42:31 AM BasePriority : Normal FileVersion : 1.50.1085.0100 ProductVersion : 1.50.1085.0100 ProductName : Windows Management Instrumentation CompanyName : Microsoft Corporation FileDescription : Windows Management Instrumentation InternalName : WINMGMT LegalCopyright : Copyright © Microsoft Corp. 1995-1999 #:15 [svchost.exe] FilePath : C:\WINNT\system32\ ProcessID : 808 ThreadCreationTime : 19-07-2005 3:42:33 AM BasePriority : Normal FileVersion : 5.00.2134.1 ProductVersion : 5.00.2134.1 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : svchost.exe #:16 [explorer.exe] FilePath : C:\WINNT\ ProcessID : 908 ThreadCreationTime : 19-07-2005 3:42:50 AM BasePriority : Normal FileVersion : 5.00.3700.6690 ProductVersion : 5.00.3700.6690 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : EXPLORER.EXE #:17 [navapw32.exe] FilePath : C:\PROGRA~1\NORTON~1\ ProcessID : 992 ThreadCreationTime : 19-07-2005 3:43:07 AM BasePriority : Normal FileVersion : 8.00.58 ProductVersion : 8.00.58 ProductName : Norton AntiVirus CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Agent InternalName : NAVAPW32 LegalCopyright : Copyright © 2000-2001 Symantec Corporation. All rights reserved. OriginalFilename : NAVAPW32.EXE #:18 [svcnt.exe] FilePath : C:\WINNT\system32\ ProcessID : 1096 ThreadCreationTime : 19-07-2005 3:43:19 AM BasePriority : Normal #:19 [internat.exe] FilePath : C:\WINNT\system32\ ProcessID : 1104 ThreadCreationTime : 19-07-2005 3:43:19 AM BasePriority : Normal FileVersion : 5.00.2920.0000 ProductVersion : 5.00.2920.0000 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Keyboard Language Indicator Applet InternalName : INTERNAT LegalCopyright : Copyright © Microsoft Corp. 1994-1999 OriginalFilename : INTERNAT.EXE #:20 [spysweeper.exe] FilePath : C:\Program Files\Webroot\Spy Sweeper\ ProcessID : 1208 ThreadCreationTime : 19-07-2005 3:43:33 AM BasePriority : Normal FileVersion : 3.2.0.147 ProductVersion : 3.2 ProductName : Spy Sweeper CompanyName : Webroot Software, Inc. FileDescription : Spy Sweeper LegalCopyright : Copyright © 2001-2004 Webroot Software, Inc. LegalTrademarks : Spy Sweeper is a trademark of Webroot Software, Inc. #:21 [acrotray.exe] FilePath : C:\Program Files\Adobe\Acrobat 6.0\Distillr\ ProcessID : 1200 ThreadCreationTime : 19-07-2005 3:43:36 AM BasePriority : Normal FileVersion : 6.0.0.2003051500 ProductVersion : 6.0.0.0 ProductName : AcroTray - Adobe Acrobat Distiller helper application. CompanyName : Adobe Systems Inc. FileDescription : AcroTray InternalName : AcroTray LegalCopyright : Copyright 1984-2003 Adobe Systems Incorporated and its licensors. All rights reserved. OriginalFilename : AcroTray.exe #:22 [msoffice.exe] FilePath : C:\Program Files\Microsoft Office\Office\1033\ ProcessID : 1260 ThreadCreationTime : 19-07-2005 3:43:43 AM BasePriority : Normal FileVersion : 9.0.2601 ProductVersion : 9.0.2601 ProductName : Microsoft Office 2000 CompanyName : Microsoft Corporation FileDescription : Microsoft Office 2000 component InternalName : MSOFFICE LegalCopyright : Copyright© Microsoft Corporation 1994-1999. All rights reserved. OriginalFilename : MSOFFICE.EXE #:23 [iexplore.exe] FilePath : C:\Program Files\Internet Explorer\ ProcessID : 1128 ThreadCreationTime : 19-07-2005 5:02:53 AM BasePriority : Normal FileVersion : 6.00.2800.1106 ProductVersion : 6.00.2800.1106 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : IEXPLORE.EXE #:24 [ad-aware.exe] FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\ ProcessID : 948 ThreadCreationTime : 19-07-2005 5:03:36 AM BasePriority : Normal FileVersion : 6.2.0.206 ProductVersion : VI.Second Edition ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 14 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 14 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 14 Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 14 Deep scanning and examining files (C:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 14 Scanning Hosts file...... Hosts file location:"C:\WINNT\system32\drivers\etc\hosts". »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 698 entries scanned. New critical objects:0 Objects found so far: 14 Performing conditional scans... »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 14 3:51:35 PM Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:41:29.520 Objects scanned:50262 Objects identified:0 Objects ignored:0 New critical objects:0 And finally, Active Scan... Incident Status Location Spyware:Spyware/Smitfraud No disinfected C:\WINNT\system32\svcnt.exe Adware:adware/psguard No disinfected C:\WINNT\SYSTEM32\intel32.exe Adware:adware/cws No disinfected C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\FAVORITES\Insurance Adware:adware/navhelper No disinfected HKEY_CLASSES_ROOT\CLSID\{BDF3E430-B101-42AD-A544-FADC6B084872} Adware:Adware/PsGuard No disinfected C:\WINNT\system32\intel32.exe Spyware:Spyware/Smitfraud No disinfected C:\WINNT\system32\svcnt.exe Can somebody help....again, please? Thanks, BV |
|
|
| Guest_thatman_* |
Jul 22 2005, 03:19 AM
Post
#2
|
|
|
Hi BlackVinyl
Please read through the instructions before you start (you may want to print this out). Please download the trial version of Ewido Security Suite here: http://www.ewido.net/en/download/ Install it, and update the definitions to the newest files. Do NOT run a scan yet. Download Pocket Killbox and unzip it; save it to your Desktop. Download smitRem.zip and save the file to your desktop. Right click on the file and extract it to it's own folder on the desktop. Don't run it yet! Please download and install AD-Aware se. Click Here on how setup and use it - please make sure you update it first. Don't run yet. Please set your system to show all files; please see here if you're unsure how to do this. Download CWShredder (there is a link in my signature), unzip it, and save it on the Desktop. Please do not run it yet, Reboot into Safe Mode: please see here if you are not sure how to do this. Then please run Ewido, and run a full scan. Save the logfile from the scan. Clear out the files in the Prefetch folder. Go to start> run> type into the box Prefetch and delete all the files in that folder. (XP Only) Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish. Please go offline, close all browsers and any open Windows, making sure that only HijackThis is open. Scan and when it finishes, put an X in the boxes, only next to these following items: R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdocsv.dll/blank.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://shdocsv.dll/asst.htm O4 - HKLM\..\Run: [Fast Start] C:\WINNT\system32\svcnt.exe home O4 - HKCU\..\Run: [Intel system tool] C:\WINNT\system32\hookdump.exe Click on Fix Checked when finished and exit HijackThis. Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure all are checked and then press *ok* to remove: Run CWShredder to fix your CWS problem. Run AD-Aware se Run killbox and click the radio button that says Delete a file on reboot. For each of the files you could not delete, paste them one at a time into the full path of file to delete box and click the red circle with a white cross in it. The program will ask you if you want to reboot; say No each time until the last one has been pasted in whereupon you should answer Yes. C:\WINNT\system32\svcnt.exe C:\WINNT\SYSTEM32\intel32.exe C:\WINNT\system32\hookdump.exe Let the system reboot as normal. Please run the following free, online virus scans. http://www.pandasoftware.com/activescan/co...n_principal.htm Please post the logs From Panda, Ewido HJT.log We will need them to remove previous infections that have left files on your system. Kc |
|
|
| Guest_thatman_* |
Jul 30 2005, 09:02 AM
Post
#3
|
|
|
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
2 / 292 | 15th August 2005 - 08:35 PM kchristine7 started - last by greyknight17 |
|||||
![]() |
6 / 247 | 14th June 2006 - 03:11 AM Ray Harvey started - last by Crustyoldbloke |
|||||
![]() |
2 / 362 | 30th March 2008 - 10:07 AM out of my league started - last by Rorschach112 |
|||||
![]() |
2 / 406 | 21st June 2008 - 06:50 AM Ben_3_Death started - last by miekiemoes |
|||||
|
Time is now: 2nd December 2008 - 02:17 PM |
| Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. |