Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

please help me i have a nasty virus :'(


  • This topic is locked This topic is locked

#1
ricardo

ricardo

    New Member

  • Member
  • Pip
  • 1 posts
pleae help me i got some nat trojans and virus and i;m going crazy !! i want to get rit of it please help me!!

hijack logLogfile
of HijackThis v1.99.1
Scan saved at 15:50:00, on 6-3-05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
D:\NORMAN\BIN\ZANDA.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
D:\NORMAN\NVC\BIN\CCLAW.EXE
D:\NORMAN\NVC\BIN\NVCSCHED.EXE
D:\NORMAN\NVC\BIN\NIP.EXE
D:\NORMAN\BIN\NJEEVES.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\RUNDLL32.EXE
D:\CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
D:\NORMAN\BIN\ZLH.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\RUNDLL32.EXE
D:\NORMAN\NPFMSG.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
F:\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {A8F37EB5-8E53-11D9-9EEC-005065F42F0F} - C:\WINDOWS\SYSTEM\KNLLIIA.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [Taakcontrole] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AdaptecDirectCD] "D:\CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [Norman ZANDA] D:\NORMAN\BIN\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKLM\..\RunServices: [Norman ZANDA] D:\NORMAN\BIN\ZANDA.EXE /LOAD
O4 - Startup: NPF Messenger.lnk = D:\Norman\NPFMSG.EXE
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O18 - Filter: text/html - {A8F37EB4-8E53-11D9-9EEC-00500AB88A94} - C:\WINDOWS\SYSTEM\KNLLIIA.DLL
O18 - Filter: text/plain - {A8F37EB4-8E53-11D9-9EEC-00500AB88A94} - C:\WINDOWS\SYSTEM\KNLLIIA.DLL

startdeck logfile
StartDreck (build 2.1.7 public stable) - 2005-03-04 @ 15:50:49 (GMT +01:00)
Platform: Windows 98 SE (Win 4.10.2222 A)
Internet Explorer: 5.00.2614.3500
Logged in as Ricardo at ACHTER

舞egistry
舞un Keys
翟urrent User
舞un
舞unOnce
聞efault User
舞un
舞unOnce
腿ocal Machine
舞un
*ScanRegistry=C:\WINDOWS\scanregw.exe /autorun
*Taakcontrole=C:\WINDOWS\taskmon.exe
*SystemTray=SysTray.Exe
*LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
*Cmaudio=RunDll32 cmicnfg.cpl,CMICtrlWnd
*NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
*nwiz=nwiz.exe /install
*NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvMcTray.dll,NvTaskbarInit
*AdaptecDirectCD="D:\CD Creator 5\DirectCD\DirectCD.exe"
*LoadQM=loadqm.exe
*StillImageMonitor=C:\WINDOWS\SYSTEM\STIMON.EXE
*Norman ZANDA=D:\NORMAN\BIN\ZLH.EXE /LOAD /SPLASH
*sp=rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
+OptionalComponents
+IMAIL
*Installed=1
+MAPI
*NoChange=1
*Installed=1
+MAPI
*NoChange=1
*Installed=1
舞unOnce
舞unServices
*LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
*SchedulingAgent=C:\WINDOWS\SYSTEM\mstask.exe
*Machine Debug Manager=C:\WINDOWS\SYSTEM\MDM.EXE
*Norman ZANDA=D:\NORMAN\BIN\ZANDA.EXE /LOAD
舞unServicesOnce
**tp=rundll32 C:\WINDOWS\FSI.CPE,DllGetClassObject
舞unOnceEx
舞unServicesOnceEx
肇iles
艋ystem/Drivers
舞unning Processes
+FFEFF39D=C:\WINDOWS\SYSTEM\KERNEL32.DLL
+FFFE3041=C:\WINDOWS\SYSTEM\MSGSRV32.EXE
+FFFE3D31=C:\WINDOWS\SYSTEM\MPREXE.EXE
+FFFEB8AD=C:\WINDOWS\SYSTEM\MSTASK.EXE
+FFFE846D=C:\WINDOWS\SYSTEM\MDM.EXE
+FFFE9B89=D:\NORMAN\BIN\ZANDA.EXE
+FFFEE0F1=C:\WINDOWS\SYSTEM\mmtask.tsk
+FFFD3089=C:\WINDOWS\RUNDLL32.EXE
+FFFD08D9=D:\NORMAN\NVC\BIN\CCLAW.EXE
+FFFD1E91=D:\NORMAN\NVC\BIN\NVCSCHED.EXE
+FFFD40C9=D:\NORMAN\NVC\BIN\NIP.EXE
+FFFD7BD5=D:\NORMAN\BIN\NJEEVES.EXE
+FFFED3D9=C:\WINDOWS\EXPLORER.EXE
+FFFCD699=C:\WINDOWS\TASKMON.EXE
+FFFB2431=C:\WINDOWS\SYSTEM\SYSTRAY.EXE
+FFFB6901=C:\WINDOWS\RUNDLL32.EXE
+FFFBB1E5=C:\WINDOWS\RUNDLL32.EXE
+FFFB8A59=D:\CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
+FFFA6FC1=C:\WINDOWS\LOADQM.EXE
+FFFA8CAD=C:\WINDOWS\SYSTEM\STIMON.EXE
+FFFCDD85=C:\WINDOWS\SYSTEM\DDHELP.EXE
+FFFA8E05=D:\NORMAN\BIN\ZLH.EXE
+FFFB6815=C:\WINDOWS\RUNDLL32.EXE
+FFF908BD=D:\NORMAN\NPFMSG.EXE
+FFF98431=C:\WINDOWS\SYSTEM\WMIEXE.EXE
+FFFC3551=C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
+FFF7DDA1=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
+FFF61425=C:\WINDOWS\SYSTEM\PSTORES.EXE
+FFF51531=F:\PACIFICPOKER\UTILS\POKER.EXE
+FFF526FD=F:\STARTDRECK\STARTDRECK.EXE
翠pplication specific


please help me !!!

thank you , ricardo from holland
  • 0

Advertisements


#2
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Hello Ricardo,

Good thing you already used Startdreck in here, because we really need that log.
You have to boot in DOS too, to get rid of it, but that's for later.
Maybe it's better to print this out or save this in notepad.

* Download and install CCleaner
Do not use it yet.

* Download the latest version of CWShredder

* Open notepad and copy and paste next in the white field in it
(don't copy the word code in it):

REGEDIT4

[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\New Windows]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchAssistant Uninstall]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce] 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

Save this as fix.reg , choose for save as *all files and save it on your desktop

* Reboot into Safe Mode`:
To get into safe mode as the computer is booting you press and hold your "F8 key" on the top of your keyboard or press and hold the left or right Ctrl key as the computer is booting. In this menu choose option 3 by pressing the 3 key and press enter.

* Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {A8F37EB5-8E53-11D9-9EEC-005065F42F0F} - C:\WINDOWS\SYSTEM\KNLLIIA.DLL
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O18 - Filter: text/html - {A8F37EB4-8E53-11D9-9EEC-00500AB88A94} - C:\WINDOWS\SYSTEM\KNLLIIA.DLL
O18 - Filter: text/plain - {A8F37EB4-8E53-11D9-9EEC-00500AB88A94} - C:\WINDOWS\SYSTEM\KNLLIIA.DLL


* Start CWShredder and click FIX

* Start Ccleaner and click Run Cleaner.

* Now we are going to boot in DOS,
* Click the Start button
* Select Shut Down
* Select Restart the computer in MS-DOS mode
* Click the Yes button

When in DOS...

Type:

del C:\WINDOWS\FSI.CPE <enter>

Reboot your system and ignore the errors you will get.

Doubleclick fix.reg
*Answer Yes when prompted to add the contents to the registry..

Reboot again..
Make a new hijackthislog and startdrecklog and post it in your next reply

If you had any problems during this fix, please tell me afterwards.
  • 0

#3
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Due to inactivity, this thread will now be closed.
If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you.
Include the address of this thread in your request. If you should have a new issue, please start a new topic.
This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP