Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

FINDIT NT-2000-XP Log


  • This topic is locked This topic is locked

#1
Portnoy

Portnoy

    Member

  • Member
  • PipPip
  • 18 posts
Greetings,
I am trying to save an XP home box.

I have run and installed HJT, NAV2005, Ad-Aware, Spy Bot S&D, FindIt Nt-2000-XP
as well as LSPfix.
In my tool kit I have TDS3, l2mfix (I have the look2me crap in the machine) and killbox.
So i am ready to KILL KILL KILL.

I have run FindIt and I don't quite know what to do next.
It is currently 645PM PST February 25, 2005.
I will on- and off-line all night.

Here is the log file from FindIt
*********************************************
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

Find.bat is running from: C:\temp\Find It NT-2K-XP

------- System Files in System32 Directory -------

Volume in drive C has no label.
Volume Serial Number is 2853-88F8

Directory of C:\WINDOWS\System32

02/25/2005 06:12 PM 229,715 lvn4095qe.dll
02/25/2005 05:18 PM 231,243 kt8ul7l91.dll
02/25/2005 04:13 PM 229,256 oaesvr.dll
02/25/2005 04:13 PM 230,971 irjsl5171.dll
02/25/2005 04:13 PM <DIR> dllcache
02/25/2005 02:20 PM 229,256 wispdmod.dll
02/25/2005 02:20 PM 229,655 lvro0993e.dll
02/25/2005 12:51 PM 229,256 nfrsptb.dll
02/25/2005 12:51 PM 230,393 ktlml7311.dll
02/25/2005 08:31 AM 229,256 sotupdll.dll
02/25/2005 08:31 AM 230,749 gpr4l39q1.dll
02/25/2005 07:44 AM 229,256 n66q0gj5e6o.dll
02/24/2005 09:02 PM 228,714 e4200efmeh2a0.dll
02/24/2005 07:00 PM 229,750 i060lajm1doa.dll
02/24/2005 06:23 PM 232,078 bfowselc.dll
02/24/2005 06:21 PM 228,502 k2pm0c71ef.dll
02/24/2005 04:16 PM 229,021 m246lchs1f46.dll
02/24/2005 04:02 PM 232,078 drband.dll
02/24/2005 04:02 PM 228,405 h0j40a1qed.dll
02/24/2005 08:19 AM 228,600 k0080adued080.dll
02/24/2005 07:50 AM 231,473 hr6605jse.dll
02/23/2005 08:38 PM 231,003 iz41_qcx.dll
02/23/2005 08:38 PM 228,925 enn4l15q1.dll
02/23/2005 04:18 PM 231,003 dpcprop2.dll
02/23/2005 02:21 PM 229,148 cqfview.dll
02/23/2005 02:12 PM 231,003 mhscp.dll
02/23/2005 01:01 PM 229,148 lvcalsec.dll
02/23/2005 12:39 PM 231,003 SLP32.DLL
02/23/2005 12:09 PM 231,191 crrsrv.dll
02/23/2005 11:59 AM 231,003 mpvcp60.dll
02/23/2005 10:30 AM 231,003 uupnpmgr.dll
02/23/2005 10:30 AM 232,248 ir42l5ho1.dll
02/23/2005 10:10 AM 230,836 sclwid.dll
02/22/2005 03:32 PM 231,003 cml3d32.dll
02/22/2005 03:13 PM 230,836 ctrpol.dll
02/22/2005 02:46 PM 230,836 sarmdll.dll
02/22/2005 02:46 PM 231,379 fp4q03h5e.dll
02/19/2005 01:41 PM 229,434 ceiconfg.dll
02/19/2005 01:29 PM 229,434 cNpesnpn.dll
02/19/2005 01:27 PM 229,434 lvr2099oe.dll
02/19/2005 01:21 PM 229,434 vua.dll
02/19/2005 01:21 PM 231,065 enl6l13s1.dll
02/19/2005 01:17 PM 229,434 dvofile.dll
02/19/2005 01:17 PM 229,568 g4lm0e31eh.dll
02/18/2005 05:03 PM 228,975 dnlayx.dll
02/18/2005 04:46 PM 229,434 mdrapi.dll
02/18/2005 04:26 PM 228,975 ikwdial.dll
02/16/2005 12:00 PM 229,088 lv0s09d7e.dll
02/16/2005 11:49 AM 229,088 mbgsvc.dll
02/16/2005 11:29 AM 229,088 iornonce.dll
02/16/2005 11:05 AM 229,088 lkasrv.dll
02/15/2005 09:52 AM 229,088 ixakeng.dll
02/15/2005 09:35 AM 228,975 mfrclr40.dll
01/25/2005 09:29 AM <DIR> Microsoft
08/18/2001 04:00 AM 84,112 wsmct.exe
53 File(s) 12,042,909 bytes
2 Dir(s) 14,964,109,312 bytes free

------- Hidden Files in System32 Directory -------

Volume in drive C has no label.
Volume Serial Number is 2853-88F8

Directory of C:\WINDOWS\System32

02/25/2005 04:13 PM <DIR> dllcache
05/14/2002 05:18 PM 488 WindowsLogon.manifest
05/14/2002 05:18 PM 488 logonui.exe.manifest
05/14/2002 05:18 PM 749 cdplayer.exe.manifest
05/14/2002 05:18 PM 749 wuaucpl.cpl.manifest
05/14/2002 05:18 PM 749 sapi.cpl.manifest
05/14/2002 05:18 PM 749 nwc.cpl.manifest
05/14/2002 05:18 PM 749 ncpa.cpl.manifest
08/18/2001 04:00 AM 84,112 wsmct.exe
8 File(s) 88,833 bytes
1 Dir(s) 14,964,105,216 bytes free

------------ Files Named "Guard" ---------------

Volume in drive C has no label.
Volume Serial Number is 2853-88F8

Directory of C:\WINDOWS\System32


------ Temp Files in System32 Directory ------

Volume in drive C has no label.
Volume Serial Number is 2853-88F8

Directory of C:\WINDOWS\System32

08/18/2001 04:00 AM 2,577 CONFIG.TMP
1 File(s) 2,577 bytes
0 Dir(s) 14,964,105,216 bytes free

------------------ User Agent ----------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{47064461-9804-4E7F-8A40-D554621FCF9A}"=""


------------- Keys Under Notify -------------

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Setup]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\sotupdll.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"


------------- Locate.com Results -------------

-------- Strings.exe Qoologic Results --------


--------- Strings.exe Aspack Results ---------

C:\WINDOWS\system32\ntdll.dll: .aspack

-------------- HKLM Run Key ----------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe /install"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

Any, and All help is very much appreciated

Portnoy

:tazz:
  • 0

Advertisements


#2
Portnoy

Portnoy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
*Bump :tazz:
  • 0

#3
Dragon

Dragon

    All Around Computer Nut

  • Retired Staff
  • 2,678 posts
Welcome to Geeks to Go,

Did you follow the recomendations here?
  • 0

#4
Portnoy

Portnoy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Thanks for responding.

Yup I tried everything except CWShredder. I will download that now.
The PC is in a lot of trouble.
On top of the obvious mal-ware, the machine will inadvertantly freeze.
No real time frame for it. On re-boot it works fine for an hour or many hours.
The cpu doesn't feel hot to the touch neither does the Vpu.

I will try the shredder and see if it helps.

In the meantime with the findit log file: How do I know which are real dll's and which are phoney-baloney's?

Portnoy
  • 0

#5
Portnoy

Portnoy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Weirdness is still happening after following all the instruction in the "read this b4 posting any HJT Log"
For instance the web page on geeks to go just refreshed itself and I lost my post??


Logfile of HijackThis v1.98.2
Scan saved at 9:46:34 AM, on 2/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\hijackthis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R3 - URLSearchHook: (no name) - _{CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - (no file)
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: (no name) - {17B66827-9B64-BCDF-4DB2-A4AFDEBA0CDB} - (no file)
O2 - BHO: (no name) - {3CCFF652-33C6-EC88-BC36-50435974539C} - (no file)
O2 - BHO: (no name) - {A4320AC3-C590-D886-ACA9-BD8564A3A813} - (no file)
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [aos8RPipO] itsrseng.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
  • 0

#6
Dragon

Dragon

    All Around Computer Nut

  • Retired Staff
  • 2,678 posts
Click Here download the latest version of Hijack This (1.98.2). It's better able to catch the latest threats.

next, You may want to print these out as you have to disconnect from the internet
Please Download LSPFix from http://www.cexx.org/lspfix.htm and Run the Program. Disconnect from the Internet and close all Internet Explorer Windows. Check the "I know what I'm doing" Button and remove all traces of dolsp.dll. Reboot.

note a lot of those .dll files maybe legit, thats why we ask for a Hijack This log and not a findnfix log.

Edited by Efwis, 26 February 2005 - 12:56 PM.

  • 0

#7
Portnoy

Portnoy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Thank you very much Efwis.
The system appears to be running more stable.

Here is the last HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 11:11:31 AM, on 2/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\shch.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\hijackthis\HijackThis.exe

R3 - URLSearchHook: (no name) - _{CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - (no file)
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: (no name) - {17B66827-9B64-BCDF-4DB2-A4AFDEBA0CDB} - (no file)
O2 - BHO: (no name) - {3CCFF652-33C6-EC88-BC36-50435974539C} - (no file)
O2 - BHO: (no name) - {A4320AC3-C590-D886-ACA9-BD8564A3A813} - (no file)
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\Jghfun.exe
O4 - HKLM\..\Run: [SheduIer] C:\WINDOWS\shch.exe /i
O4 - HKLM\..\Run: [secure] C:\WINDOWS\System32\Wagovh.exe
O4 - HKLM\..\Run: [rF3U3FO] labew.exe
O4 - HKLM\..\Run: [Hooyqx] C:\Program Files\Kgbc\Ularfc.exe
O4 - HKLM\..\Run: [FOeb8W] C:\WINDOWS\qiofiq.exe
O4 - HKLM\..\Run: [antiware] C:\windows\system32\elitepxv32.exe
O4 - HKLM\..\Run: [AdTools Service] C:\Program Files\AdTools Service\AdTools.exe
O4 - HKLM\..\Run: [AdStatus Service] C:\Program Files\AdStatus Service\AdStatServ.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [aos8RPipO] itsrseng.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: btrhpkdrlrfy (pygkmcmd5) - Unknown owner - C:\WINDOWS\System32\nfbqpuco5.exe (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#8
Dragon

Dragon

    All Around Computer Nut

  • Retired Staff
  • 2,678 posts
Please look over the Following Entries I have listed, run Hijack This again and check them and then, making sure you have No Internet Explorer Windows open, including this one, Press the "Fix Checked" Button with HijackThis.

Reboot If I have specified below, and Post a Fresh HijackThis log.

R3 - URLSearchHook: (no name) - _{CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - (no file)
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: (no name) - {17B66827-9B64-BCDF-4DB2-A4AFDEBA0CDB} - (no file)
O2 - BHO: (no name) - {3CCFF652-33C6-EC88-BC36-50435974539C} - (no file)
O2 - BHO: (no name) - {A4320AC3-C590-D886-ACA9-BD8564A3A813} - (no file)
O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\Jghfun.exe
O4 - HKLM\..\Run: [SheduIer] C:\WINDOWS\shch.exe /i
O4 - HKLM\..\Run: [secure] C:\WINDOWS\System32\Wagovh.exe
O4 - HKLM\..\Run: [rF3U3FO] labew.exe
O4 - HKLM\..\Run: [Hooyqx] C:\Program Files\Kgbc\Ularfc.exe
O4 - HKLM\..\Run: [FOeb8W] C:\WINDOWS\qiofiq.exe
O4 - HKLM\..\Run: [antiware] C:\windows\system32\elitepxv32.exe
O4 - HKLM\..\Run: [AdTools Service] C:\Program Files\AdTools Service\AdTools.exe
O4 - HKLM\..\Run: [AdStatus Service] C:\Program Files\AdStatus Service\AdStatServ.exe
O4 - HKCU\..\Run: [aos8RPipO] itsrseng.exe


After this, Reboot and Delete the following files:

C:\WINDOWS\shch.exe
C:\WINDOWS\System32\Jghfun.exe
C:\WINDOWS\System32\Wagovh.exe
C:\labew.exe
<-this may be in C:\windows\system32, C:\windows, or C:\program files
C:\Program Files\Kgbc\Ularfc.exe
C:\WINDOWS\qiofiq.exe
C:\windows\system32\elitepxv32.exe
C:\Program Files\AdTools Service
C:\Program Files\AdStatus Service
C:\itsrseng.exe
<-this may be in C:\windows\system32, C:\windows, or C:\program files


Note: Make sure you have Set Windows to show Hidden Files & Folders before you Start Sending Them to us For Analysis, or you're deleting them. This can be done by looking at the instructions at This Webpage http://www.xtra.co.n...1916458,00.html

To Delete These Files/Folders, You Will need to Boot into Safe Mode. This can be done by tapping F8 while your machine restarts.

post a fresh Hijack This log

Edited by Efwis, 26 February 2005 - 01:25 PM.

  • 0

#9
Portnoy

Portnoy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Some of the files were not present on the PC.
Here is my latest HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 11:40:45 AM, on 2/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

O2 - BHO: (no name) - {17B66827-9B64-BCDF-4DB2-A4AFDEBA0CDB} - (no file)
O2 - BHO: (no name) - {3CCFF652-33C6-EC88-BC36-50435974539C} - (no file)
O2 - BHO: (no name) - {A4320AC3-C590-D886-ACA9-BD8564A3A813} - (no file)
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: btrhpkdrlrfy (pygkmcmd5) - Unknown owner - C:\WINDOWS\System32\nfbqpuco5.exe (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#10
Dragon

Dragon

    All Around Computer Nut

  • Retired Staff
  • 2,678 posts
you may wnt to print this out as you won't be able to go online.
Reboot into Sfae Mode then look over the Following Entries I have listed, run Hijack This again and check them and then, making sure you have No Windows open, Press the "Fix Checked" Button with HijackThis.

Reboot If I have specified below, and Post a Fresh HijackThis log.

O2 - BHO: (no name) - {17B66827-9B64-BCDF-4DB2-A4AFDEBA0CDB} - (no file)
O2 - BHO: (no name) - {3CCFF652-33C6-EC88-BC36-50435974539C} - (no file)
O2 - BHO: (no name) - {A4320AC3-C590-D886-ACA9-BD8564A3A813} - (no file)


After this, Reboot and post a fresh log

Edited by Efwis, 26 February 2005 - 01:50 PM.

  • 0

Advertisements


#11
Portnoy

Portnoy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Thanks for your help Efwis.

I booted into safe mode.
Made sure IE and Explorer were closed.
Ran HJT.
"fixed" the three HBO's
Rebooted into normal mode
Ran HJT and...they were BACK!?!? (I did the whole procedure 3 times. Same results)
BTW: I have 4 PC's in my lab so i always have at leats one online.

Here is the log :

Logfile of HijackThis v1.99.1
Scan saved at 12:10:54 PM, on 2/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\hijackthis\HijackThis.exe

O2 - BHO: (no name) - {17B66827-9B64-BCDF-4DB2-A4AFDEBA0CDB} - (no file)
O2 - BHO: (no name) - {3CCFF652-33C6-EC88-BC36-50435974539C} - (no file)
O2 - BHO: (no name) - {A4320AC3-C590-D886-ACA9-BD8564A3A813} - (no file)
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: btrhpkdrlrfy (pygkmcmd5) - Unknown owner - C:\WINDOWS\System32\nfbqpuco5.exe (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#12
Dragon

Dragon

    All Around Computer Nut

  • Retired Staff
  • 2,678 posts
Using windows explorer, navigate to C:\windows\system32\nfbqpuco5.exe
if you find this file, right click on it.
then click properties
click the security tab. if it doesn't let you see the permissions or you can't find it, let me know...

Edited by Efwis, 26 February 2005 - 02:41 PM.

  • 0

#13
Portnoy

Portnoy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
I did a full search on C:\windows and it came up empty
  • 0

#14
Dragon

Dragon

    All Around Computer Nut

  • Retired Staff
  • 2,678 posts
with Hijack this remove these entries, hopefully those 3 BHO files will go away.

O2 - BHO: (no name) - {17B66827-9B64-BCDF-4DB2-A4AFDEBA0CDB} - (no file)
O2 - BHO: (no name) - {3CCFF652-33C6-EC88-BC36-50435974539C} - (no file)
O2 - BHO: (no name) - {A4320AC3-C590-D886-ACA9-BD8564A3A813} - (no file)
O23 - Service: btrhpkdrlrfy (pygkmcmd5) - Unknown owner - C:\WINDOWS\System32\nfbqpuco5.exe (file missing)


and post a fresh Hijack this log
  • 0

#15
Portnoy

Portnoy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
No dice.
I ran HJT in safe mode.
Did a complete system search for the file.
Hidden files are seen as well as OS files.
Same log on reboot:

Logfile of HijackThis v1.99.1
Scan saved at 1:23:50 PM, on 2/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

O2 - BHO: (no name) - {17B66827-9B64-BCDF-4DB2-A4AFDEBA0CDB} - (no file)
O2 - BHO: (no name) - {3CCFF652-33C6-EC88-BC36-50435974539C} - (no file)
O2 - BHO: (no name) - {A4320AC3-C590-D886-ACA9-BD8564A3A813} - (no file)

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: btrhpkdrlrfy (pygkmcmd5) - Unknown owner - C:\WINDOWS\System32\nfbqpuco5.exe (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP