This is a wonderful service. I don't think I'd be going too far if I said it is a noble endeavor, helping many, many people who are struggling with the criminals who want to cripple our computing power.
Ive performed all of the recommended steps before posting here, and thanks to those steps, have removed all or most of Trojan.Rootkit.h, Generic Rootkit (aka Backdoor, HaxDrv, sdbot), CoolWebSearch, Aurora and mouse.hs.
Are they really gone? Is there any other malware lurking about? My HJT log is below.
-----------------
Logfile of HijackThis v1.99.1
Scan saved at 11:08:29 PM, on 8/11/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kavmm.exe
C:\WINDOWS\System32\Tablet.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Wacom\TabUserW.exe
C:\Hijack\HijackThis.exe
R1 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net/
R1 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink...ton/search.html
R1 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.earthlink...ton/search.html
R0 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net/
R0 HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.earthlink...ton/search.html
R1 HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://start.earthlink.net
R0 HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
02 BHO: (no name) {53707962-6F74-2D53-2644-206D7942484F} C:\PROGRA~1\SPYBOT~1\SDHelper.dll
03 Toolbar: McAfee VirusScan {BA52B914-B692-46c4-B683-905236F6F655} c:\progra~1\mcafee.com\vso\mcvsshl.dll
03 Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} C:\WINDOWS\System32\msdxm.ocx
04 = HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
04 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /Sync
04 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
04 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
04 - HKLM\..\Run: [THGuard] C:\Trojan Hunter 4.2\THGuard.exe
04 - HKLM\..\Run: [KAV50] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kav.exe run n PersonalPro v 5.0.0.0 -chkss
04 - HKLM\..\Run: [VSOCheckTask] c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe /checktask
04 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
04 - HKLM\..\Run: [NeroCheck] C:\WINDOWS|system32\NeroCheck.exe
04 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
04 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\mcafee.com\agent\mcagent.exe
04 - HKLM\..\RunServices: [MediaXPServicePack] mxpsp.exe
04 - HKCU\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
04 - HKCU\..\RunServices: [MediaXPServicePack] mxpsp.exe
04 Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
04 Global Startup: TabUserW.lnk = C:\Program Files\wacom\TabUserW.exe
06 HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
09 Extra button: (no name) {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} (no file}
09 Extra button: (no name) {CD67F990-D8E9-11D2-98FE-00C0F0318AFE} (no file)
016 DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) http://download.mcaf...90/mcinsctl.cab
016 DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) http://download.mcaf...,23/mcgdmgr.cab
023 Service: ewido security suite control ewido networks C:\Program Files\ewido\security suite\ewidoctrl.exe
023 Service: Hardware Clock Driver (hwclock) Unknown owner C:\WINDOWS\System32\hwclock.exe (file missing)
023 Service: Kaspersky Anti-Virus Service (KLBLMain) Kaspersky Lab C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kavmm.exe
023 Service: McAfee.com McShield (McShield) Unknown owner C:\PROGRA~1\mcafee.com\vso\mcshield.exe (file missing)
023 Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) Unknown owner - C:\PROGRA~1\mcafee.com\vso\mcvsrte.exe (file missing)
023 Service: TabletService Wacom Technology, Corp. C:\WINDOWS\System32\Tablet.exe
023 Service: AntiVir Update Temp (TmpUpSrv) Unknown owner C:\DOCUME~1\OWNER~1.DOT\LOCALS~1\TEMP\_VWUPSRV.EXE (file missing)
Thanks for your help,
moxie47
Edited by moxie47, 15 August 2005 - 10:05 AM.