Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

smitfraud/huntbar/tbps


  • This topic is locked This topic is locked

#1
mtbxcrider

mtbxcrider

    New Member

  • Member
  • Pip
  • 2 posts
By using tips on your various pages regarding the smitfraud trojan, i tried to remove it myself. this seemed to work ok and everything ran fine for about 24 hrs. but now i have the reoccuring problems with TBPS and Huntbbar reappearing. Are these related to the smitfraud or is this a seperate virus/adware? I've run Spysweeper/Spybot/Adaware, but they cant seem to remove these completely. Here is my HJT log;

Logfile of HijackThis v1.99.1
Scan saved at 4:58:03 PM, on 6/20/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Webroot\Desktop Firewall\WDFLogService.exe
C:\Program Files\Webroot\Desktop Firewall\FirewallNTService.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Toolbar\TBPS.exe
C:\PROGRA~1\Toolbar\PIB.exe
C:\Program Files\Common Files\WinTools\WToolsA.exe
C:\PROGRA~1\COMMON~1\WinTools\WSup.exe
C:\WINDOWS\System32\khooker.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Gearbox Connection Kit\bin\confsvr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Webroot\Desktop Firewall\WebrootDesktopFirewall.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Gearbox Connection Kit\bin\gbConMon.exe
C:\Program Files\Gearbox Connection Kit\bin\gbTask.exe
C:\Remover\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.updatesea...earch.php?qq=%1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch....aspx?tb_id=128
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
F2 - REG:system.ini: Shell=explorer.exe, msmsgs.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O2 - BHO: (no name) - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINDOWS\System32\hpC06C.tmp (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [Gearbox] "C:\Program Files\Gearbox Connection Kit\bin\confsvr.exe"
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WebrootDesktopFirewall] C:\Program Files\Webroot\Desktop Firewall\WebrootDesktopFirewall.exe -t
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\RunServices: [Gearbox Deferal Check] C:\Program Files\Gearbox Connection Kit\bin\gbdefer.exe
O4 - Global Startup: MiniMavis.lnk.disabled
O9 - Extra button: (no name) - {BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B} - C:\WINDOWS\crtv2_32.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B} - C:\WINDOWS\crtv2_32.dll (HKCU)
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.co...clean_micro.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{8F1028C7-D7AB-40AE-869C-6B90D5A5E0AD}: NameServer = 66.81.0.251 66.81.0.252
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WebSeach Toolbar support NT service (TBPSSvc) - Unknown owner - C:\PROGRA~1\Toolbar\TBPSSvc.exe (file missing)
O23 - Service: Webroot Desktop Firewall Log Server (WebrootDesktopFirewallLogServer) - Webroot Software, Inc. - C:\Program Files\Webroot\Desktop Firewall\WDFLogService.exe
O23 - Service: Webroot Desktop Firewall (WebrootFirewall) - Unknown owner - C:\Program Files\Webroot\Desktop Firewall\FirewallNTService.exe
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe (file missing)


Any help is greatly appreciated.
Thank You
  • 0

Advertisements


#2
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Hi mtbxcrider and welcome to the Geeks to Go Forums.

My name is Trevuren and I will be helping you with your log.

1. Go to Geeks to Go
. Click on My Controls at the top right hand corner of the window. (make sure you have signed in first)
. In the left hand column, click "View Topics"
. If you click on the title of your post, you will be taken there

2. Also, while at the My Controls page, check the box to the right of your post and then scroll down.
.Where it says "unsubscribe" click the pull-down menu and select "immediate email notification"
------------------------------------------------------------
3. Please follow the instructions provided, you may want to print out these instructions and use them as a reference.


1. Please download ewido security suite it is a trial version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will prompt you to update click the OK button
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Click on Start
The update will start and a progress bar will show the updates being installed.
Once the updates are installed do the following:
  • Click on scanner
  • Make sure the following boxes are checked before scanning:
  • Binder
  • Crypter
  • Archives
2. REBOOT into SAFE MODE

3. Click on Start Scan, let the program scan the machine.

While the scan is in progress you will be prompted to clean files, click OK

4. Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report
  • Save the report to your desktop
5. REBOOT into Normal Mode

6. Repeat Steps 2,3, 4 and 5.

7. Postback a new HJT log and the ewido .txt log files you saved by using Add Reply

Regards,

Trevuren

  • 0

#3
mtbxcrider

mtbxcrider

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
Ok ... downloaded and ran ewido ...here are the logs;

1st run of ewido:

ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 11:22:07 AM, 6/21/2005
+ Report-Checksum: D60FCA0A

+ Date of database: 6/21/2005
+ Version of scan engine: v3.0

+ Duration: 40 min
+ Scanned Files: 35179
+ Speed: 14.38 Files/Second
+ Infected files: 81
+ Removed files: 81
+ Files put in quarantine: 81
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0

+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes

+ Scanned items:
C:\

+ Scan result:
C:\WINDOWS\system32\oleadm.dll -> Trojan.Agent.eq -> Cleaned with backup
C:\WINDOWS\system32\AWM226.exe -> Dialer.Generic -> Cleaned with backup
C:\WINDOWS\system32\kernel32.exe -> TrojanDownloader.Small.yo -> Cleaned with backup
C:\WINDOWS\system32\wins32t.dll -> TrojanDownloader.Small.yo -> Cleaned with backup
C:\WINDOWS\system32\crt32_v2.dll -> TrojanDownloader.Small.hr -> Cleaned with backup
C:\WINDOWS\system32\jjczo.dll -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\112063.exe -> Dialer.Generic -> Cleaned with backup
C:\WINDOWS\sCache32\Unreal2 (2.8) crack.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\WinZip 8.3b (crack).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\FlashFXP (keygen).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\TitJiggle (flash game).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Patch Creator 3.5a.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\RemoteSpy 1.5.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Auction Sentry (new).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\iSnipeIt 5.0c.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\PhotoShow 3.1.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\AC3-MP3 converter.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\DivX edit (new).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\MP3 cut pro 3.0.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Half-Life keygen (+ogc hack).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Hacker Tutorial (by ph3Akz).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\HL keys (working).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\mIRC 6.x addon patch.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\mIRC s3th war-script.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\UniversalFlood (4.8b).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\AudioLabel CD Labeler 3.0 (+crack).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Complete UK Music Database 4.2.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\All Editor 3.0b.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Genie Stream 3.2.4.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\FreeRip 4.30.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\DvD Rip guide (+tools) st0rm.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Wippit 2.1 (beta).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Kazaa Skins 1.8.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\2 Find MP3 8.2.0.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\NeoNapster 3.92.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\BearShare 5.1.1.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Easy CD Creator Software Update.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\New Nvidia (geForce) drivers (beta).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\ACDSee 5.5b.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\DirectDVD 4.9.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\ACDSee Classic 2.79.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Find 1.0.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Dynamite Downloads.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\ICQ Lite beta (b2253).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\WinZip 9.0 SR-1.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\AOL Instant Messenger 6.1.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\ICQ Pro 2003a beta (b4600).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\iMesh 4.1 beta.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Ad-aware 6.5 (new).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Download Accelerator Plus 6.3.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Trillian 0.8 + plugins.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Kazaa Media Desktop 2.5.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\WinRAR 3.8.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Grokster 2.0.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Morpheus 2.6.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Nero Burning ROM 5.8.2.4.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\KaZooM MP3 Kazaa Accelerator 2.5.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Window Washer 4.8.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\WS_FTP LE 6.0.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Global DiVX Player 2.0.1.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\RealOne Free Player 2.8.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\MSN Messenger 5.5.10.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\DivX Video Bundle 5.5.1.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Pop-Up Stopper 4.0 (beta).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\QuickTime 7.2 (new).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Network Cable + ADSL Speed 2.0 (beta).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\GetRight 5.5 + crack.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\WinMX 3.5.1.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\RealJukebox Basic 2.8.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\XViD bundle (codec+tutorial).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\DivX Bundle 6.2.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Microangelo 6.0b.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Nimo Codec Pack 9.0 (stable).exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\sCache32\Adobe Acrobat Reader 5.6.exe -> Worm.Sddrop.C -> Cleaned with backup
C:\WINDOWS\crt32_v2.dll -> TrojanDownloader.Small.hr -> Cleaned with backup
C:\WINDOWS\uninstIU.exe -> Trojan.Agent.eo -> Cleaned with backup
C:\WINDOWS\dsykws.dat -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\Program Files\Common Files\WinTools\WToolsB.dll -> Spyware.Wintol.y -> Cleaned with backup
C:\Program Files\Internet Explorer\smdkjcxe.exe -> TrojanDownloader.Petrolin.a -> Cleaned with backup
C:\Program Files\Toolbar\common.dll -> Spyware.WebSearch.aj -> Cleaned with backup
C:\Program Files\Toolbar\xlmurin.wzg -> Spyware.IBISToolbar -> Cleaned with backup


::Report End

2nd run of ewido:

ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 12:07:01 PM, 6/21/2005
+ Report-Checksum: 4C09FD8E

+ Date of database: 6/21/2005
+ Version of scan engine: v3.0

+ Duration: 36 min
+ Scanned Files: 35183
+ Speed: 16.02 Files/Second
+ Infected files: 0
+ Removed files: 0
+ Files put in quarantine: 0
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0

+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes

+ Scanned items:
C:\

+ Scan result:
No infected files found!


::Report End

New HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 12:10:19 PM, on 6/21/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\khooker.exe
C:\WINDOWS\System32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Gearbox Connection Kit\bin\confsvr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Webroot\Desktop Firewall\WebrootDesktopFirewall.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Gearbox Connection Kit\bin\gbConMon.exe
C:\Program Files\Gearbox Connection Kit\bin\gbTask.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Webroot\Desktop Firewall\WDFLogService.exe
C:\Program Files\Webroot\Desktop Firewall\FirewallNTService.exe
C:\PROGRA~1\Toolbar\TBPS.exe
C:\PROGRA~1\Toolbar\PIB.exe
C:\Remover\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.updatesea...earch.php?qq=%1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch....aspx?tb_id=128
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
F2 - REG:system.ini: Shell=explorer.exe, msmsgs.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll (file missing)
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O2 - BHO: (no name) - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINDOWS\System32\hpC06C.tmp (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [Gearbox] "C:\Program Files\Gearbox Connection Kit\bin\confsvr.exe"
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WebrootDesktopFirewall] C:\Program Files\Webroot\Desktop Firewall\WebrootDesktopFirewall.exe -t
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\RunServices: [Gearbox Deferal Check] C:\Program Files\Gearbox Connection Kit\bin\gbdefer.exe
O4 - Global Startup: MiniMavis.lnk.disabled
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B} - C:\WINDOWS\crtv2_32.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B} - C:\WINDOWS\crtv2_32.dll (HKCU)
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.co...clean_micro.exe
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WebSeach Toolbar support NT service (TBPSSvc) - Unknown owner - C:\PROGRA~1\Toolbar\TBPSSvc.exe (file missing)
O23 - Service: Webroot Desktop Firewall Log Server (WebrootDesktopFirewallLogServer) - Webroot Software, Inc. - C:\Program Files\Webroot\Desktop Firewall\WDFLogService.exe
O23 - Service: Webroot Desktop Firewall (WebrootFirewall) - Unknown owner - C:\Program Files\Webroot\Desktop Firewall\FirewallNTService.exe
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe (file missing)

Again ... Thank you for your help.
  • 0

#4
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
What a cleanup. Good job

Now we must get rid of 2 malicious Added Services

We must stop, disable and delete an added service (023)

A. To stop a service and set to 'disabled'

Go to Start > Run and type in Services.msc then click OK

Click the Extended tab.

Scroll down until you find the services.

O23 - Service: WebSeach Toolbar support NT service (TBPSSvc) - Unknown owner - C:\PROGRA~1\Toolbar\TBPSSvc.exe (file missing)
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe (file missing)


Perform the following tasks on one servive at a time

Click once on the service to highlight it.

Click Stop

Right-Click on the service.

Click on 'Properties'

Select the 'General' tab

Click the Arrow-down tab on the right-hand side on the 'Start-up Type' box

From the drop-down menu, click on 'Disabled'

Click the 'Apply' tab, then click 'OK'

The services are now stopped and disabled.


B. We will now delete the services:

Now,

1. Open HJT
2. Click on Config>>Misc Tools>>Delete an NT Service
3. Type TBPSSvc in the space provided and click OK
4. The program will ask you to REBOOT --- Accept

5. REBOOT

6. Now repeat the above steps 1 through 4 inclusively but using WinToolsSvc as the Service Name.

7. When asked to REBOOT do so but into SAFE MODE

C. Using the Add/Remove feature in your Control Panel, UNINSTALL WINTOOLS.

D. Using Windows Explorer, locate and DELETE the following file/folder (if it still is present):

C:\WINDOWS\svcproc.exe
C:\Program Files\Common Files\WinTools,- Folder and all its content

E. REBOOT back into Normal Mode

F. Finally, run HijackThis, click SCAN, produce a LOG and POST it in this thread for review.

Regards,

Trevuren

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP