Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

win32 trojan [CLOSED]


  • Please log in to reply

#16
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Looks clean. How are things on your end?
  • 0

Advertisements


#17
kevlar061481

kevlar061481

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
i saw an email saying that you replied but i dont see it here where all the posts are
but anyways i still have avast saying thatm.bin has aversion of win32startpage
so any other ideas??
kevin
  • 0

#18
kevlar061481

kevlar061481

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
silly me i didnt look on page 2

but like i said
its still poping up with the same message
  • 0

#19
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Please run Panda Online Virus Scan
  • Make sure it is set to clean automatically.
  • There may be files that this scan will not remove.
  • Please include that information in your next post.

Reboot and post a new hijackthis log and the info from your virus scan.
  • 0

#20
kevlar061481

kevlar061481

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Incident Status Location

Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Kevin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-69741795-2702e688.zip.mwt[BlackBox.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Kevin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-69741795-2702e688.zip.mwt[VerifierBug.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Kevin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-69741795-2702e688.zip.mwt[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Kevin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-69741795-2702e688.zip.mwt[Beyond.class]
Adware:Adware/CWS.Aboutblank No disinfected C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\BHWI1HT3\m[1].bin

Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\SYSTEM32\fob.dll

Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\SYSTEM32\lkleha.dll

Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\SYSTEM32\pdfeaad.dll



Logfile of HijackThis v1.99.1
Scan saved at 9:00:26 PM, on 9/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\hijackthis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...l_v1-0-3-30.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1123978973437
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com..._1/axofupld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsec...scan/axscan.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

thanks sam
  • 0

#21
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Please reboot into Safe mode for the first part of this fix.
  • Run CWShredder, making sure to click "Fix".

  • Delete these files.

    C:\WINDOWS\SYSTEM32\fob.dll
    C:\WINDOWS\SYSTEM32\lkleha.dll
    C:\WINDOWS\SYSTEM32\pdfeaad.dll


  • Delete your temp files
    • Navigate to the C:\Windows\Temp folder.
      • Open the Temp folder
      • Select Edit -> Select All
      • Select Edit -> Delete(or press the delete button on your keyboard) to delete the entire contents of the Temp folder.
    • Navigate to the C:\Windows\Prefetch folder.
      • Open the Prefetch folder
      • Select Edit -> Select All
      • Select Edit -> Delete(or press the delete button on your keyboard) to delete the entire contents of the Temp folder.
    • Click Start -> Run and type %temp% in the Run box.
      • Select Edit -> Select All
      • Select Edit -> Delete(or press the delete button on your keyboard) to delete the entire contents of the Temp folder.
    • Click Start -> Control Panel -> Internet Options.
      • Select the General tab
      • Under "Temporary Internet Files" Click "Delete Files".
      • Put a check by "Delete Offline Content" and click OK.
      • Click on the Programs tab then click the "Reset Web Settings" button.
      • Click Apply then OK.
    • Empty the Recycle Bin.

  • Run Ewido:
    • Click on scanner
    • Click Complete System Scan and the scan will begin.
    • During the scan it will prompt you to clean files, click OK
    • When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.
    • When the scan is finished, click the Save report button at the bottom of the screen.
    • Save the report to your desktop
    Close Ewido


  • Reboot back to normal mode.

  • Please download the trial version of WebRoot SpySweeper
    • Click the Free Trial link under to "SpySweeper" to download the program.
    • Install it.
    • Once the program is installed, it will open.
    • It will prompt you to update to the latest definitions, click Yes.
    • Once the definitions are installed, click Sweep Now on the left side.
    • Click the Start button.
    • When it's done scanning, click the Next button.
    • Make sure everything has a check next to it, then click the Next button.
    • It will remove all of the items found.
    • Click Session Log in the upper right corner, copy everything in that window.
    • Click the Summary tab and click Finish.
    • Paste the contents of the session log you copied into your next reply.
  • Reboot once more and paste the following reports into your next reply.
    • Hijackthis log
    • Ewido log
    • Spysweeper log

  • 0

#22
kevlar061481

kevlar061481

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Logfile of HijackThis v1.99.1
Scan saved at 6:53:16 PM, on 9/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\hijackthis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...l_v1-0-3-30.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1123978973437
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com..._1/axofupld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsec...scan/axscan.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe



********
6:12 PM: |··· Start of Session, Tuesday, September 13, 2005 ···|
6:12 PM: Spy Sweeper started
6:12 PM: Sweep initiated using definitions version 533
6:12 PM: Starting Memory Sweep
6:14 PM: Memory Sweep Complete, Elapsed Time: 00:02:25
6:14 PM: Starting Registry Sweep
6:14 PM: Found Adware: ace club casino
6:14 PM: HKCR\clsid\{4725d0e2-7d0d-1dd6-8de3-00d0ba893cbb}\ (19 subtraces) (ID = 102486)
6:14 PM: HKCR\clsid\{8ba2fe8e-8506-11d4-bfe2-cb5fed326646}\ (8 subtraces) (ID = 102487)
6:14 PM: HKCR\clsid\{8ba2fe90-8506-11d4-bfe2-cb5fed326646}\ (8 subtraces) (ID = 102488)
6:14 PM: HKCR\clsid\{8ba2fe92-8506-11d4-bfe2-cb5fed326646}\ (8 subtraces) (ID = 102489)
6:14 PM: HKCR\nextgenvp.videopoker\ (5 subtraces) (ID = 102504)
6:14 PM: HKCR\sawzip.archive\ (5 subtraces) (ID = 102506)
6:14 PM: HKCR\sawzip.file\ (5 subtraces) (ID = 102507)
6:14 PM: HKLM\software\classes\clsid\{4725d0e2-7d0d-1dd6-8de3-00d0ba893cbb}\ (19 subtraces) (ID = 102511)
6:14 PM: HKLM\software\classes\clsid\{8ba2fe8e-8506-11d4-bfe2-cb5fed326646}\ (8 subtraces) (ID = 102512)
6:14 PM: HKLM\software\classes\clsid\{8ba2fe90-8506-11d4-bfe2-cb5fed326646}\ (8 subtraces) (ID = 102513)
6:14 PM: HKLM\software\classes\clsid\{8ba2fe92-8506-11d4-bfe2-cb5fed326646}\ (8 subtraces) (ID = 102514)
6:14 PM: HKLM\software\classes\nextgenvp.videopoker\ (5 subtraces) (ID = 102515)
6:14 PM: HKLM\software\classes\sawzip.archive\ (5 subtraces) (ID = 102517)
6:14 PM: HKLM\software\classes\sawzip.file\ (5 subtraces) (ID = 102518)
6:14 PM: Found Adware: cws-aboutblank
6:14 PM: HKU\S-1-5-18\software\microsoft\internet explorer\main\ || homeoldsp (ID = 115923)
6:14 PM: HKU\S-1-5-21-2761484609-3218753515-2555392378-1007\software\microsoft\internet explorer\main\ || search bar_bak (ID = 115924)
6:14 PM: Found Adware: drsnsrch.com hijack
6:14 PM: HKU\S-1-5-21-2761484609-3218753515-2555392378-1007\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
6:14 PM: Found Adware: syncroad
6:14 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/syncroadx.dll\ (2 subtraces) (ID = 143513)
6:14 PM: Registry Sweep Complete, Elapsed Time:00:00:10
6:14 PM: Starting Cookie Sweep
6:14 PM: Found Spy Cookie: adknowledge cookie
6:14 PM: kevin@adknowledge[1].txt (ID = 2072)
6:14 PM: Found Spy Cookie: cc214142 cookie
6:14 PM: kevin@ads.cc214142[2].txt (ID = 2367)
6:14 PM: Found Spy Cookie: apmebf cookie
6:14 PM: kevin@apmebf[1].txt (ID = 2229)
6:14 PM: Found Spy Cookie: azjmp cookie
6:14 PM: kevin@azjmp[1].txt (ID = 2270)
6:14 PM: Found Spy Cookie: bravenet cookie
6:14 PM: kevin@bravenet[1].txt (ID = 2322)
6:14 PM: Found Spy Cookie: maxserving cookie
6:14 PM: kevin@maxserving[2].txt (ID = 2966)
6:14 PM: Found Spy Cookie: clicktracks cookie
6:14 PM: kevin@stats1.clicktracks[2].txt (ID = 2407)
6:14 PM: Found Spy Cookie: zedo cookie
6:14 PM: kevin@zedo[2].txt (ID = 3762)
6:14 PM: Cookie Sweep Complete, Elapsed Time: 00:00:01
6:14 PM: Starting File Sweep
6:19 PM: Warning: Failed to read file "c:\windows\system32\sqlohop.dll". System Error. Code: 2.
The system cannot find the file specified
6:19 PM: Found Adware: cws iesearch
6:19 PM: blackbox.class-1b9d2b16-52ad0510.class (ID = 55971)
6:19 PM: blackbox.class-36b4f52d-6b96abc4.class (ID = 55971)
6:19 PM: blackbox.class-4ef544c3-79a70376.class (ID = 55971)
6:19 PM: Found Adware: twain-tech
6:19 PM: mxtini.inf (ID = 81846)
6:20 PM: File Sweep Complete, Elapsed Time: 00:05:23
6:20 PM: Full Sweep has completed. Elapsed time 00:08:02
6:20 PM: Traces Found: 148
6:36 PM: Removal process initiated
6:36 PM: Quarantining All Traces: ace club casino
6:36 PM: Quarantining All Traces: cws-aboutblank
6:36 PM: Quarantining All Traces: drsnsrch.com hijack
6:36 PM: Quarantining All Traces: syncroad
6:36 PM: Quarantining All Traces: adknowledge cookie
6:36 PM: Quarantining All Traces: cc214142 cookie
6:36 PM: Quarantining All Traces: apmebf cookie
6:36 PM: Quarantining All Traces: azjmp cookie
6:36 PM: Quarantining All Traces: bravenet cookie
6:36 PM: Quarantining All Traces: maxserving cookie
6:36 PM: Quarantining All Traces: clicktracks cookie
6:36 PM: Quarantining All Traces: zedo cookie
6:36 PM: Quarantining All Traces: cws iesearch
6:36 PM: Quarantining All Traces: twain-tech
6:36 PM: Removal process completed. Elapsed time 00:00:30
********
6:11 PM: |··· Start of Session, Tuesday, September 13, 2005 ···|
6:11 PM: Spy Sweeper started
6:12 PM: |··· End of Session, Tuesday, September 13, 2005 ···|


---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 6:07:12 PM, 9/13/2005
+ Report-Checksum: 9354C8C9

+ Scan result:

C:\Documents and Settings\Kevin\Cookies\kevin@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@ads.addynamix[2].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@ads.pointroll[1].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@e-2dj6wgkiqkdzmfq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@internetfuel[1].txt -> Spyware.Cookie.Internetfuel : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@perf.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@statcounter[2].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@www.burstbeacon[2].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@www.burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2D4R23IV\m[2].bin -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Y5CTMRAZ\m[2].bin -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\BHWI1HT3\m[1].bin -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP580\A0052090.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP580\A0052091.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP580\A0052092.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\fdce.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\oph.dll -> Spyware.Hijacker.Generic : Cleaned with backup


::Report End


well that seemed to help
ill keep you posted
thanks sam
  • 0

#23
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Your hijackthis log looks pretty good. I'll keep this thread open for a while. Let me know if your problems start popping back up.

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and reenable system restore to make sure there are no infected files found in a restore point left over from what we have just cleaned.

    You can find instructions on how to enable and reenable system restore here:

    Managing Windows Millenium System Restore

    or

    Windows XP System Restore Guide

    Renable system restore with instructions from tutorial above

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

:tazz: :)
  • 0

#24
kevlar061481

kevlar061481

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
hi sam
i completed that web reset and stuff
i wasnt running the spy sweeper though
only avast
and i just got a pop up exactly the same about m.bin having win32 startpage 080
so i dunno maybe i should try a different antivirus program??
  • 0

#25
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Let's take a look and see if it came back.

Run a scan with Spysweeper and post the log along with a new hijackthis log.
  • 0

Advertisements


#26
kevlar061481

kevlar061481

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
i dunno where all those cookies are coming from
all i basically did was check my email, check my ebay account, check this web site,
and check my bank account
but anyways here is the post for spy sweeper and hjt
thanks agian for looking


********
9:09 PM: |··· Start of Session, Wednesday, September 14, 2005 ···|
9:09 PM: Spy Sweeper started
9:09 PM: Sweep initiated using definitions version 533
9:09 PM: Starting Memory Sweep
9:12 PM: Memory Sweep Complete, Elapsed Time: 00:02:12
9:12 PM: Starting Registry Sweep
9:12 PM: Registry Sweep Complete, Elapsed Time:00:00:16
9:12 PM: Starting Cookie Sweep
9:12 PM: Found Spy Cookie: about cookie
9:12 PM: kevin@about[2].txt (ID = 2037)
9:12 PM: Found Spy Cookie: pointroll cookie
9:12 PM: kevin@ads.pointroll[2].txt (ID = 3148)
9:12 PM: Found Spy Cookie: ask cookie
9:12 PM: kevin@ask[1].txt (ID = 2245)
9:12 PM: kevin@bbq.about[2].txt (ID = 2038)
9:12 PM: Found Spy Cookie: burstnet cookie
9:12 PM: kevin@burstnet[2].txt (ID = 2336)
9:12 PM: Found Spy Cookie: 2o7.net cookie
9:12 PM: kevin@microsofteup.112.2o7[2].txt (ID = 1958)
9:12 PM: Found Spy Cookie: overture cookie
9:12 PM: kevin@perf.overture[1].txt (ID = 3106)
9:12 PM: Found Spy Cookie: questionmarket cookie
9:12 PM: kevin@questionmarket[2].txt (ID = 3217)
9:12 PM: Found Spy Cookie: statcounter cookie
9:12 PM: kevin@statcounter[1].txt (ID = 3447)
9:12 PM: Found Spy Cookie: trafficmp cookie
9:12 PM: kevin@trafficmp[2].txt (ID = 3581)
9:12 PM: Found Spy Cookie: tribalfusion cookie
9:12 PM: kevin@tribalfusion[1].txt (ID = 3589)
9:12 PM: Found Spy Cookie: burstbeacon cookie
9:12 PM: kevin@www.burstbeacon[2].txt (ID = 2335)
9:12 PM: kevin@www.burstnet[1].txt (ID = 2337)
9:12 PM: Found Spy Cookie: zedo cookie
9:12 PM: kevin@zedo[2].txt (ID = 3762)
9:12 PM: Cookie Sweep Complete, Elapsed Time: 00:00:02
9:12 PM: Starting File Sweep
9:17 PM: Warning: Failed to read file "c:\windows\system32\sqlohop.dll". System Error. Code: 2.
The system cannot find the file specified
9:18 PM: File Sweep Complete, Elapsed Time: 00:06:05
9:18 PM: Full Sweep has completed. Elapsed time 00:08:38
9:18 PM: Traces Found: 14
9:18 PM: Removal process initiated
9:18 PM: Quarantining All Traces: about cookie
9:18 PM: Quarantining All Traces: pointroll cookie
9:18 PM: Quarantining All Traces: ask cookie
9:18 PM: Quarantining All Traces: burstnet cookie
9:18 PM: Quarantining All Traces: 2o7.net cookie
9:18 PM: Quarantining All Traces: overture cookie
9:18 PM: Quarantining All Traces: questionmarket cookie
9:18 PM: Quarantining All Traces: statcounter cookie
9:18 PM: Quarantining All Traces: trafficmp cookie
9:18 PM: Quarantining All Traces: tribalfusion cookie
9:18 PM: Quarantining All Traces: burstbeacon cookie
9:18 PM: Quarantining All Traces: zedo cookie
9:18 PM: Removal process completed. Elapsed time 00:00:08
********
6:12 PM: |··· Start of Session, Tuesday, September 13, 2005 ···|
6:12 PM: Spy Sweeper started
6:12 PM: Sweep initiated using definitions version 533
6:12 PM: Starting Memory Sweep
6:14 PM: Memory Sweep Complete, Elapsed Time: 00:02:25
6:14 PM: Starting Registry Sweep
6:14 PM: Found Adware: ace club casino
6:14 PM: HKCR\clsid\{4725d0e2-7d0d-1dd6-8de3-00d0ba893cbb}\ (19 subtraces) (ID = 102486)
6:14 PM: HKCR\clsid\{8ba2fe8e-8506-11d4-bfe2-cb5fed326646}\ (8 subtraces) (ID = 102487)
6:14 PM: HKCR\clsid\{8ba2fe90-8506-11d4-bfe2-cb5fed326646}\ (8 subtraces) (ID = 102488)
6:14 PM: HKCR\clsid\{8ba2fe92-8506-11d4-bfe2-cb5fed326646}\ (8 subtraces) (ID = 102489)
6:14 PM: HKCR\nextgenvp.videopoker\ (5 subtraces) (ID = 102504)
6:14 PM: HKCR\sawzip.archive\ (5 subtraces) (ID = 102506)
6:14 PM: HKCR\sawzip.file\ (5 subtraces) (ID = 102507)
6:14 PM: HKLM\software\classes\clsid\{4725d0e2-7d0d-1dd6-8de3-00d0ba893cbb}\ (19 subtraces) (ID = 102511)
6:14 PM: HKLM\software\classes\clsid\{8ba2fe8e-8506-11d4-bfe2-cb5fed326646}\ (8 subtraces) (ID = 102512)
6:14 PM: HKLM\software\classes\clsid\{8ba2fe90-8506-11d4-bfe2-cb5fed326646}\ (8 subtraces) (ID = 102513)
6:14 PM: HKLM\software\classes\clsid\{8ba2fe92-8506-11d4-bfe2-cb5fed326646}\ (8 subtraces) (ID = 102514)
6:14 PM: HKLM\software\classes\nextgenvp.videopoker\ (5 subtraces) (ID = 102515)
6:14 PM: HKLM\software\classes\sawzip.archive\ (5 subtraces) (ID = 102517)
6:14 PM: HKLM\software\classes\sawzip.file\ (5 subtraces) (ID = 102518)
6:14 PM: Found Adware: cws-aboutblank
6:14 PM: HKU\S-1-5-18\software\microsoft\internet explorer\main\ || homeoldsp (ID = 115923)
6:14 PM: HKU\S-1-5-21-2761484609-3218753515-2555392378-1007\software\microsoft\internet explorer\main\ || search bar_bak (ID = 115924)
6:14 PM: Found Adware: drsnsrch.com hijack
6:14 PM: HKU\S-1-5-21-2761484609-3218753515-2555392378-1007\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
6:14 PM: Found Adware: syncroad
6:14 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/syncroadx.dll\ (2 subtraces) (ID = 143513)
6:14 PM: Registry Sweep Complete, Elapsed Time:00:00:10
6:14 PM: Starting Cookie Sweep
6:14 PM: Found Spy Cookie: adknowledge cookie
6:14 PM: kevin@adknowledge[1].txt (ID = 2072)
6:14 PM: Found Spy Cookie: cc214142 cookie
6:14 PM: kevin@ads.cc214142[2].txt (ID = 2367)
6:14 PM: Found Spy Cookie: apmebf cookie
6:14 PM: kevin@apmebf[1].txt (ID = 2229)
6:14 PM: Found Spy Cookie: azjmp cookie
6:14 PM: kevin@azjmp[1].txt (ID = 2270)
6:14 PM: Found Spy Cookie: bravenet cookie
6:14 PM: kevin@bravenet[1].txt (ID = 2322)
6:14 PM: Found Spy Cookie: maxserving cookie
6:14 PM: kevin@maxserving[2].txt (ID = 2966)
6:14 PM: Found Spy Cookie: clicktracks cookie
6:14 PM: kevin@stats1.clicktracks[2].txt (ID = 2407)
6:14 PM: Found Spy Cookie: zedo cookie
6:14 PM: kevin@zedo[2].txt (ID = 3762)
6:14 PM: Cookie Sweep Complete, Elapsed Time: 00:00:01
6:14 PM: Starting File Sweep
6:19 PM: Warning: Failed to read file "c:\windows\system32\sqlohop.dll". System Error. Code: 2.
The system cannot find the file specified
6:19 PM: Found Adware: cws iesearch
6:19 PM: blackbox.class-1b9d2b16-52ad0510.class (ID = 55971)
6:19 PM: blackbox.class-36b4f52d-6b96abc4.class (ID = 55971)
6:19 PM: blackbox.class-4ef544c3-79a70376.class (ID = 55971)
6:19 PM: Found Adware: twain-tech
6:19 PM: mxtini.inf (ID = 81846)
6:20 PM: File Sweep Complete, Elapsed Time: 00:05:23
6:20 PM: Full Sweep has completed. Elapsed time 00:08:02
6:20 PM: Traces Found: 148
6:36 PM: Removal process initiated
6:36 PM: Quarantining All Traces: ace club casino
6:36 PM: Quarantining All Traces: cws-aboutblank
6:36 PM: Quarantining All Traces: drsnsrch.com hijack
6:36 PM: Quarantining All Traces: syncroad
6:36 PM: Quarantining All Traces: adknowledge cookie
6:36 PM: Quarantining All Traces: cc214142 cookie
6:36 PM: Quarantining All Traces: apmebf cookie
6:36 PM: Quarantining All Traces: azjmp cookie
6:36 PM: Quarantining All Traces: bravenet cookie
6:36 PM: Quarantining All Traces: maxserving cookie
6:36 PM: Quarantining All Traces: clicktracks cookie
6:36 PM: Quarantining All Traces: zedo cookie
6:36 PM: Quarantining All Traces: cws iesearch
6:36 PM: Quarantining All Traces: twain-tech
6:36 PM: Removal process completed. Elapsed time 00:00:30
********
6:11 PM: |··· Start of Session, Tuesday, September 13, 2005 ···|
6:11 PM: Spy Sweeper started
6:12 PM: |··· End of Session, Tuesday, September 13, 2005 ···|




Logfile of HijackThis v1.99.1
Scan saved at 9:20:28 PM, on 9/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\hijackthis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...l_v1-0-3-30.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1123978973437
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com..._1/axofupld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsec...scan/axscan.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
  • 0

#27
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
I don't see any problems there. Run a scan with Panda's online virus scan and post the log here. It picked up a few files last time. Let's see if it finds anything this time.
  • 0

#28
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0

#29
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Please post a new hijackthis log and let's take a look.
  • 0

#30
kevlar061481

kevlar061481

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
well because i had been ignoring my computer for a while, the se.dll installed and my web page had been renamed to about blank, and search assistant was installed
so i ran all those programs agian to get rid of that stuff so ill post everything that i had saved a log with so here it is


---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 5:12:19 PM, 10/2/2005
+ Report-Checksum: A51EBC9F

+ Scan result:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchAssistant Uninstall -> Spyware.CoolWebSearch : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@247realmedia[1].txt -> Spyware.Cookie.247realmedia : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@ads.addynamix[1].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@as-eu.falkag[1].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@as-us.falkag[2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@bluestreak[2].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@cs.sexcounter[2].txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@cz7.clickzs[1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@free.wegcash[2].txt -> Spyware.Cookie.Wegcash : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@hypertracker[1].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@paycounter[1].txt -> Spyware.Cookie.Paycounter : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@paypopup[2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@popunder.paypopup[1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@rotator.dex.adjuggler[2].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@thunderbolt.adjuggler[1].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@vip.clickzs[2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Kevin\Cookies\kevin@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\6J8LGNIP\m[2].bin -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Y5CTMRAZ\m[2].bin -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP590\A0052477.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP590\A0052480.scr -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP590\A0052481.DLL -> Spyware.FunWeb : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP590\A0052482.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP590\A0052485.SCR -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP590\A0052487.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP590\A0052488.EXE -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP590\A0052489.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP590\A0052490.DLL -> Spyware.Wesbar : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP590\A0052492.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP590\A0052493.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP590\A0052495.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP590\A0052538.EXE -> Spyware.Wesbar : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP590\A0052539.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\WINDOWS\SYSTEM32\alhomlc.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\bejpfnd.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\bmeejb.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\eoenb.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\fpo.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\gecljg.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\jbagpp.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\lbfopjg.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\pndf.dll -> Spyware.Hijacker.Generic : Cleaned with backup


::Report End

THIS IS THAT PANDA ONLINE SCAN OF MY C: DIR

Incident Status Location

Adware:adware/block-checker No disinfected Windows Registry
Adware:Adware/CWS.Aboutblank No disinfected C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP601\A0052718.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP601\A0052719.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP601\A0052720.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP601\A0052721.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP601\A0052722.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP601\A0052723.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP601\A0052724.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP601\A0052725.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP601\A0052726.dll



i had also ran cwshredder and that found one issue that it fixed but i didnt save a report

i also ran a boot up scan with avast and that found several files that it removed, i wrote down one string that didnt look familiar that it removed it ended with pagefile.sys -win32: trojano.092


this is the spsehjfix log a


(9/5/05 3:06:18 PM) SPSeHjFix started v1.1.2
(9/5/05 3:06:18 PM) OS: WinXP Service Pack 2 (5.1.2600)
(9/5/05 3:06:18 PM) Language: english
(9/5/05 3:06:18 PM) Win-Path: C:\WINDOWS
(9/5/05 3:06:18 PM) System-Path: C:\WINDOWS\system32
(9/5/05 3:06:18 PM) Temp-Path: C:\DOCUME~1\Kevin\LOCALS~1\Temp\
(9/5/05 3:06:24 PM) Disinfection started
(9/5/05 3:06:24 PM) Bad-Dll(IEP): c:\docume~1\kevin\locals~1\temp\se.dll
(9/5/05 3:06:24 PM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\system32\lknfa.dll
(9/5/05 3:06:24 PM) Searchassistant Uninstaller - Keys Deleted
(9/5/05 3:06:24 PM) UBF: 9 - UBB: 1 - UBR: 9
(9/5/05 3:06:24 PM) FilterKey: HKCR\text/html (deleted)
(9/5/05 3:06:24 PM) FilterKey: HKCR\CLSID\{606B07DF-ECD0-468C-B116-BF0C9BC629CF} (deleted)
(9/5/05 3:06:24 PM) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(9/5/05 3:06:24 PM) FilterKey: HKCR\text/plain (deleted)
(9/5/05 3:06:24 PM) FilterKey: HKCR\CLSID\{606B07DF-ECD0-468C-B116-BF0C9BC629CF} (error while deleting)
(9/5/05 3:06:24 PM) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(9/5/05 3:06:24 PM) UBF: 7 - UBB: 1 - UBR: 9
(9/5/05 3:06:24 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\kevin\locals~1\temp\se.dll/sp.html
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\temp\se.dll/sp.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(9/5/05 3:06:25 PM) Stealth-String not found
(9/5/05 3:06:25 PM) File added to delete: c:\windows\system32\lknfa.dll
(9/5/05 3:06:25 PM) Reboot


(9/5/05 3:07:13 PM) SPSeHjFix started v1.1.2
(9/5/05 3:07:13 PM) OS: WinXP Service Pack 2 (5.1.2600)
(9/5/05 3:07:13 PM) Language: english
(9/5/05 3:07:13 PM) Win-Path: C:\WINDOWS
(9/5/05 3:07:13 PM) System-Path: C:\WINDOWS\system32
(9/5/05 3:07:13 PM) Temp-Path: C:\DOCUME~1\Kevin\LOCALS~1\Temp\
(9/5/05 3:07:49 PM) Disinfection started
(9/5/05 3:07:49 PM) Bad-Dll(IEP): (not found)
(9/5/05 3:07:49 PM) Bad-Dll(IEP) in BHO: (not found)
(9/5/05 3:07:49 PM) UBF: 7 - UBB: 1 - UBR: 9
(9/5/05 3:07:49 PM) UBF: 7 - UBB: 1 - UBR: 9
(9/5/05 3:07:49 PM) Bad IE-pages: (none)
(9/5/05 3:07:49 PM) Stealth-String not found
(9/5/05 3:07:49 PM) Not infected->END


(9/5/05 3:20:07 PM) SPSeHjFix started v1.1.2
(9/5/05 3:20:07 PM) OS: WinXP Service Pack 2 (5.1.2600)
(9/5/05 3:20:07 PM) Language: english
(9/5/05 3:20:07 PM) Win-Path: C:\WINDOWS
(9/5/05 3:20:07 PM) System-Path: C:\WINDOWS\system32
(9/5/05 3:20:07 PM) Temp-Path: C:\DOCUME~1\Kevin\LOCALS~1\Temp\


(9/9/05 5:45:43 PM) SPSeHjFix started v1.1.2
(9/9/05 5:45:43 PM) OS: WinXP Service Pack 2 (5.1.2600)
(9/9/05 5:45:43 PM) Language: english
(9/9/05 5:45:43 PM) Win-Path: C:\WINDOWS
(9/9/05 5:45:43 PM) System-Path: C:\WINDOWS\system32
(9/9/05 5:45:43 PM) Temp-Path: C:\DOCUME~1\Kevin\LOCALS~1\Temp\


(9/9/05 5:45:51 PM) SPSeHjFix started v1.1.2
(9/9/05 5:45:51 PM) OS: WinXP Service Pack 2 (5.1.2600)
(9/9/05 5:45:51 PM) Language: english
(9/9/05 5:45:51 PM) Win-Path: C:\WINDOWS
(9/9/05 5:45:51 PM) System-Path: C:\WINDOWS\system32
(9/9/05 5:45:51 PM) Temp-Path: C:\DOCUME~1\Kevin\LOCALS~1\Temp\
(9/9/05 5:45:53 PM) Disinfection started
(9/9/05 5:45:53 PM) Bad-Dll(IEP): c:\windows\temp\se.dll
(9/9/05 5:45:53 PM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\system32\jhlfba.dll
(9/9/05 5:45:53 PM) Searchassistant Uninstaller - Keys Deleted
(9/9/05 5:45:53 PM) UBF: 9 - UBB: 1 - UBR: 9
(9/9/05 5:45:53 PM) FilterKey: HKCR\text/html (deleted)
(9/9/05 5:45:53 PM) FilterKey: HKCR\CLSID\{1F15131B-6E20-471D-BA4F-7B8206067C5F} (deleted)
(9/9/05 5:45:53 PM) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(9/9/05 5:45:53 PM) FilterKey: HKCR\text/plain (deleted)
(9/9/05 5:45:53 PM) FilterKey: HKCR\CLSID\{1F15131B-6E20-471D-BA4F-7B8206067C5F} (error while deleting)
(9/9/05 5:45:53 PM) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(9/9/05 5:45:53 PM) UBF: 7 - UBB: 1 - UBR: 9
(9/9/05 5:45:53 PM) Bad IE-pages:
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\temp\se.dll/sp.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(9/9/05 5:45:53 PM) Stealth-String not found
(9/9/05 5:45:53 PM) File added to delete: c:\windows\system32\jhlfba.dll
(9/9/05 5:45:53 PM) Reboot


(9/9/05 5:46:51 PM) SPSeHjFix started v1.1.2
(9/9/05 5:46:51 PM) OS: WinXP Service Pack 2 (5.1.2600)
(9/9/05 5:46:51 PM) Language: english
(9/9/05 5:46:51 PM) Win-Path: C:\WINDOWS
(9/9/05 5:46:51 PM) System-Path: C:\WINDOWS\system32
(9/9/05 5:46:51 PM) Temp-Path: C:\DOCUME~1\Kevin\LOCALS~1\Temp\
(9/9/05 5:47:30 PM) Disinfection started
(9/9/05 5:47:30 PM) Bad-Dll(IEP): (not found)
(9/9/05 5:47:30 PM) Bad-Dll(IEP) in BHO: (not found)
(9/9/05 5:47:30 PM) UBF: 7 - UBB: 1 - UBR: 9
(9/9/05 5:47:30 PM) UBF: 7 - UBB: 1 - UBR: 9
(9/9/05 5:47:30 PM) Bad IE-pages: (none)
(9/9/05 5:47:30 PM) Stealth-String not found
(9/9/05 5:47:30 PM) Not infected->END


(9/10/05 1:19:15 PM) SPSeHjFix started v1.1.2
(9/10/05 1:19:15 PM) OS: WinXP Service Pack 2 (5.1.2600)
(9/10/05 1:19:15 PM) Language: english
(9/10/05 1:19:15 PM) Win-Path: C:\WINDOWS
(9/10/05 1:19:15 PM) System-Path: C:\WINDOWS\system32
(9/10/05 1:19:15 PM) Temp-Path: C:\DOCUME~1\Kevin\LOCALS~1\Temp\
(9/10/05 1:19:16 PM) Disinfection started
(9/10/05 1:19:16 PM) Bad-Dll(IEP): (not found)
(9/10/05 1:19:16 PM) Bad-Dll(IEP) in BHO: (not found)
(9/10/05 1:19:16 PM) UBF: 7 - UBB: 1 - UBR: 9
(9/10/05 1:19:16 PM) UBF: 7 - UBB: 1 - UBR: 9
(9/10/05 1:19:16 PM) Bad IE-pages:
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
(9/10/05 1:19:17 PM) Stealth-String not found
(9/10/05 1:19:17 PM) Not infected->END


(9/10/05 6:51:05 PM) SPSeHjFix started v1.1.2
(9/10/05 6:51:05 PM) OS: WinXP Service Pack 2 (5.1.2600)
(9/10/05 6:51:05 PM) Language: english
(9/10/05 6:51:05 PM) Win-Path: C:\WINDOWS
(9/10/05 6:51:05 PM) System-Path: C:\WINDOWS\system32
(9/10/05 6:51:05 PM) Temp-Path: C:\DOCUME~1\Kevin\LOCALS~1\Temp\
(9/10/05 6:51:06 PM) Disinfection started
(9/10/05 6:51:06 PM) Bad-Dll(IEP): (not found)
(9/10/05 6:51:06 PM) Bad-Dll(IEP) in BHO: (not found)
(9/10/05 6:51:06 PM) UBF: 7 - UBB: 1 - UBR: 9
(9/10/05 6:51:06 PM) UBF: 7 - UBB: 1 - UBR: 9
(9/10/05 6:51:06 PM) Bad IE-pages: (none)
(9/10/05 6:51:06 PM) Stealth-String not found
(9/10/05 6:51:06 PM) Not infected->END


(10/2/05 5:13:23 PM) SPSeHjFix started v1.1.2
(10/2/05 5:13:23 PM) OS: WinXP Service Pack 2 (5.1.2600)
(10/2/05 5:13:23 PM) Language: english
(10/2/05 5:13:23 PM) Win-Path: C:\WINDOWS
(10/2/05 5:13:23 PM) System-Path: C:\WINDOWS\system32
(10/2/05 5:13:23 PM) Temp-Path: C:\DOCUME~1\Kevin\LOCALS~1\Temp\
(10/2/05 5:13:24 PM) Disinfection started
(10/2/05 5:13:24 PM) Bad-Dll(IEP): (not found)
(10/2/05 5:13:24 PM) Bad-Dll(IEP) in BHO: (not found)
(10/2/05 5:13:24 PM) UBF: 7 - UBB: 1 - UBR: 11
(10/2/05 5:13:24 PM) UBF: 7 - UBB: 1 - UBR: 11
(10/2/05 5:13:25 PM) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\WINDOWS\TEMP\se.dll,DllInstall (deleted)
(10/2/05 5:13:25 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar:
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(10/2/05 5:13:25 PM) Stealth-String not found
(10/2/05 5:13:25 PM) File added to delete: c:\windows\temp\se.dll
(10/2/05 5:13:25 PM) Reboot


(10/2/05 5:14:47 PM) SPSeHjFix started v1.1.2
(10/2/05 5:14:47 PM) OS: WinXP Service Pack 2 (5.1.2600)
(10/2/05 5:14:47 PM) Language: english
(10/2/05 5:14:47 PM) Win-Path: C:\WINDOWS
(10/2/05 5:14:47 PM) System-Path: C:\WINDOWS\system32
(10/2/05 5:14:47 PM) Temp-Path: C:\DOCUME~1\Kevin\LOCALS~1\Temp\
(10/2/05 5:15:24 PM) Disinfection started
(10/2/05 5:15:24 PM) Bad-Dll(IEP): (not found)
(10/2/05 5:15:24 PM) Bad-Dll(IEP) in BHO: (not found)
(10/2/05 5:15:24 PM) UBF: 7 - UBB: 1 - UBR: 10
(10/2/05 5:15:24 PM) UBF: 7 - UBB: 1 - UBR: 10
(10/2/05 5:15:24 PM) Bad IE-pages: (none)
(10/2/05 5:15:25 PM) Stealth-String not found
(10/2/05 5:15:25 PM) Not infected->END


(10/3/05 7:04:43 PM) SPSeHjFix started v1.1.2
(10/3/05 7:04:43 PM) OS: WinXP Service Pack 2 (5.1.2600)
(10/3/05 7:04:43 PM) Language: english
(10/3/05 7:04:43 PM) Win-Path: C:\WINDOWS
(10/3/05 7:04:43 PM) System-Path: C:\WINDOWS\system32
(10/3/05 7:04:43 PM) Temp-Path: C:\DOCUME~1\Kevin\LOCALS~1\Temp\
(10/3/05 7:04:50 PM) Disinfection started
(10/3/05 7:04:50 PM) Bad-Dll(IEP): (not found)
(10/3/05 7:04:50 PM) Bad-Dll(IEP) in BHO: (not found)
(10/3/05 7:04:50 PM) UBF: 7 - UBB: 1 - UBR: 9
(10/3/05 7:04:50 PM) UBF: 7 - UBB: 1 - UBR: 9
(10/3/05 7:04:50 PM) Bad IE-pages:
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
(10/3/05 7:04:50 PM) Stealth-String not found
(10/3/05 7:04:50 PM) Not infected->END


(10/3/05 7:04:54 PM) SPSeHjFix started v1.1.2
(10/3/05 7:04:54 PM) OS: WinXP Service Pack 2 (5.1.2600)
(10/3/05 7:04:54 PM) Language: english
(10/3/05 7:04:54 PM) Win-Path: C:\WINDOWS
(10/3/05 7:04:54 PM) System-Path: C:\WINDOWS\system32
(10/3/05 7:04:54 PM) Temp-Path: C:\DOCUME~1\Kevin\LOCALS~1\Temp\
(10/3/05 7:04:55 PM) Disinfection started
(10/3/05 7:04:55 PM) Bad-Dll(IEP): (not found)
(10/3/05 7:04:55 PM) Bad-Dll(IEP) in BHO: (not found)
(10/3/05 7:04:55 PM) UBF: 7 - UBB: 1 - UBR: 9
(10/3/05 7:04:55 PM) UBF: 7 - UBB: 1 - UBR: 9
(10/3/05 7:04:55 PM) Bad IE-pages: (none)
(10/3/05 7:04:55 PM) Stealth-String not found
(10/3/05 7:04:55 PM) Not infected->END




and hers the current hijack log
Logfile of HijackThis v1.99.1
Scan saved at 7:07:56 PM, on 10/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\hijackthis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...l_v1-0-3-30.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1123978973437
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com..._1/axofupld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsec...scan/axscan.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

i hope thats not to much to look at at once thanks
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP