Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Win32.Actux.A virus [RESOLVED]


  • This topic is locked This topic is locked

#1
roacham

roacham

    Member

  • Member
  • PipPipPip
  • 245 posts
Hello again great people. My children have once again got a virus on the computer. I keep getting pop-ups and when I log on it says I have 3 infections. When I run my antivirus it does not find any infections. Please help again.


Logfile of HijackThis v1.99.1
Scan saved at 11:03:49 AM, on 12/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\COMPAQ\Compaq Advisor\bin\compaq-rba.exe
C:\WINDOWS\system32\msCMTSrvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\zkacfqe.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\2D2C2A2932332.exe
C:\WINDOWS\SYS99.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\WINDOWS\win3207136-856199.exe
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\WINDOWS\zkacfqeA.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CMMan\CMMan.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\SynCor.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\Program Files\Microsoft Money\System\urlmap.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presari...&c=2c02&lc=0409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/.../search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {6001CDF7-6F45-471b-A203-0225615E35A7} - C:\WINDOWS\DH.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {B5505C04-F46D-DE57-60D1-596639556AD9} - C:\WINDOWS\zdfmnfyz.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Search - {CD2DE76E-9A8E-A0F7-97C3-0C74AD82CB84} - C:\WINDOWS\zdfmnfyz.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [363533323B3C353] 2D2C2A2932332.exe
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\pwinssaw.exe CORN001
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYS99.exe
O4 - HKLM\..\Run: [win3207136-856199] C:\WINDOWS\win3207136-856199.exe
O4 - HKLM\..\Run: [zkacfqeA] C:\WINDOWS\zkacfqeA.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [CMMan] "C:\Program Files\CMMan\CMMan.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\pwinssaw.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O18 - Filter: text/html - {6793D547-38DD-4325-B35A-F1817EDFA567} - (no file)
O21 - SSODL: Monansys - {301108F3-2871-476D-8251-E9137AF8FB85} - C:\WINDOWS\system32\mp4alipv.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\COMPAQ\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\zkacfqe.exe
  • 0

Advertisements


#2
sari

sari

    GeekU Admin

  • Community Leader
  • 21,806 posts
  • MVP
Hi, roacham, and welcome to Geeks to Go. I'm analyzing your log now, and will be posting a fix shortly.

sari
  • 0

#3
roacham

roacham

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 245 posts
Thank you so much. I will be waiting.
  • 0

#4
sari

sari

    GeekU Admin

  • Community Leader
  • 21,806 posts
  • MVP
roacham,

OK, let's start cleaning you up. You may want to print these instructions for reference.

Step 1:

First, we need to temporarily disable your SpywareGuard program, as it could interfere with the fixes.

Double-click the red SG in your system try to Open Spywareguard
  • Click Option on the left
  • Uncheck the following
    • Enable Real-Time Scanning
    • Enable Download Protection
    • Enable Browser HiJack Protection
  • Click Save Settings
  • We will re-enable it when we're done.
Step 2:
Go to Start > Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the below services:

Windows Overlay Components

When you find it, double-click on it. In the next window that opens, under the General tab click the Stop button, then click the drop-down box to change the Startup Type to Disabled. Now hit Apply and then Ok.

Open HiJackThis, click on "None of the above, just start the program". Now, click on the "Config" button (bottom right), then click on "Misc Tools", then click on "Delete an NT Service" a window will pop up. Enter the below item into that field (make sure there are NO spaces before or after the name):

Windows Overlay Components

Click OK.

It should pull up information about the service, then ask if you want to reboot. Click YES.

Step 3:
Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O2 - BHO: (no name) - {6001CDF7-6F45-471b-A203-0225615E35A7} - C:\WINDOWS\DH.dll
O2 - BHO: (no name) - {B5505C04-F46D-DE57-60D1-596639556AD9} - C:\WINDOWS\zdfmnfyz.dll
O3 - Toolbar: Search - {CD2DE76E-9A8E-A0F7-97C3-0C74AD82CB84} - C:\WINDOWS\zdfmnfyz.dll
O4 - HKLM\..\Run: [363533323B3C353] 2D2C2A2932332.exe
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\pwinssaw.exe CORN001
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYS99.exe
O4 - HKLM\..\Run: [win3207136-856199] C:\WINDOWS\win3207136-856199.exe
O4 - HKLM\..\Run: [zkacfqeA] C:\WINDOWS\zkacfqeA.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\pwinssaw.exe
O18 - Filter: text/html - {6793D547-38DD-4325-B35A-F1817EDFA567} - (no file)
O21 - SSODL: Monansys - {301108F3-2871-476D-8251-E9137AF8FB85} - C:\WINDOWS\system32\mp4alipv.dll
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\zkacfqe.exe

Now close all windows other than HiJackThis, then click Fix Checked. Reboot into safe mode.

Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Make sure hidden files and folders are showing:

* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.

[/b]Please delete these files using Windows Explorer(if present):

C:\WINDOWS\DH.dll
C:\WINDOWS\zdfmnfyz.dll
C:\WINDOWS\system32\pwinssaw.exe
C:\WINDOWS\SYS99.exe
C:\WINDOWS\win3207136-856199.exe
C:\WINDOWS\zkacfqeA.exe
C:\WINDOWS\system32\mp4alipv.dll

After that, Reboot.

Step 4:
Please run an on-line virus scan at Kaspersky OnLine Scan or if that doesnt work, you can use TrendMicro or BitDefender. (Please post the results of the scan(s) in your next reply)

+++++

If you are unable to run the activeX Antivirus Scanners, lets try this Java based solution from Trend Micro.

Please post a new hijackthis log and the results of the online virus scan.

Thanks,

sari
  • 0

#5
roacham

roacham

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 245 posts
Here is the Hijack logfile

Logfile of HijackThis v1.99.1
Scan saved at 8:37:48 PM, on 1/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CMMan\CMMan.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\COMPAQ\Compaq Advisor\bin\compaq-rba.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\system32\msCMTSrvc.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
c:\Program Files\Microsoft Money\System\urlmap.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presari...&c=2c02&lc=0409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/.../search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Alexa - {3CEFF6CD-6F08-4E4D-BCCD-FF7415288C3B} - C:\WINDOWS\system32\SHDOCVW.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [Compaq_RBA] C:\Program Files\COMPAQ\Compaq Advisor\bin\compaq-rba.exe -z
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [CMMan] "C:\Program Files\CMMan\CMMan.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Alexa - {9D74677A-E227-40fb-9511-F7E92EA4083A} - C:\WINDOWS\system32\SHDOCVW.DLL
O9 - Extra 'Tools' menuitem: Alexa Toolbar - {9D74677A-E227-40fb-9511-F7E92EA4083A} - C:\WINDOWS\system32\SHDOCVW.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\COMPAQ\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Here is the virus scan
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Tuesday, January 03, 2006 20:35:30
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 3/01/2006
Kaspersky Anti-Virus database records: 158591
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
G:\

Scan Statistics:
Total number of scanned objects: 55162
Number of viruses found: 15
Number of infected objects: 47
Number of suspicious objects: 0
Duration of the scan process: 4597 sec

Infected Object Name - Virus Name
C:\Documents and Settings\Heather\Local Settings\Temporary Internet Files\Content.IE5\JFSQJTFM\opmrket[1].exe Infected: Trojan.Win32.Favadd.o
C:\n.exe Infected: Trojan-Downloader.Win32.Small.cdo
C:\Program Files\backups\backup-20051231-102629-208.dll Infected: Trojan.Win32.VB.aft
C:\Program Files\backups\backup-20051231-173443-255.dll Infected: Trojan.Win32.VB.aft
C:\Program Files\backups\backup-20060103-184257-633.dll Infected: Trojan-Clicker.Win32.Small.jf
C:\Program Files\Common Files\VCClient\Setup88.exe/data0002 Infected: Trojan-Downloader.Win32.VB.tw
C:\Program Files\Common Files\VCClient\Setup88.exe/data0003 Infected: Trojan.Win32.VB.tg
C:\Program Files\Common Files\VCClient\Setup88.exe/data0004 Infected: Trojan-Clicker.Win32.VB.jz
C:\Program Files\Common Files\VCClient\Setup88.exe/data0007 Infected: Trojan.Win32.VB.tg
C:\Program Files\Common Files\VCClient\Setup88.exe/data0008 Infected: Trojan.Win32.VB.tg
C:\Program Files\Common Files\VCClient\Setup88.exe Infected: Trojan.Win32.VB.tg
C:\Program Files\Common Files\VCClient\Setup8823.exe/data0010/data0002 Infected: Trojan-Downloader.Win32.VB.tw
C:\Program Files\Common Files\VCClient\Setup8823.exe/data0010/data0003 Infected: Trojan.Win32.VB.tg
C:\Program Files\Common Files\VCClient\Setup8823.exe/data0010/data0004 Infected: Trojan-Clicker.Win32.VB.jz
C:\Program Files\Common Files\VCClient\Setup8823.exe/data0010/data0007 Infected: Trojan.Win32.VB.tg
C:\Program Files\Common Files\VCClient\Setup8823.exe/data0010/data0008 Infected: Trojan.Win32.VB.tg
C:\Program Files\Common Files\VCClient\Setup8823.exe/data0010 Infected: Trojan.Win32.VB.tg
C:\Program Files\Common Files\VCClient\Setup8823.exe Infected: Trojan.Win32.VB.tg
C:\RECYCLER\S-1-5-21-2322712386-2745678790-3725260815-1007\Dc4.exe Infected: Trojan-Downloader.Win32.Adload.k
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP149\A0112238.dll Infected: Trojan.Win32.VB.aft
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP151\A0115330.dll Infected: Trojan-Clicker.Win32.Small.jf
C:\WINDOWS\linun.exe Infected: Trojan.Win32.VB.tg
C:\WINDOWS\offun.exe Infected: Trojan-Downloader.Win32.VB.nw
C:\WINDOWS\opmrket.exe Infected: Trojan.Win32.Favadd.o
C:\WINDOWS\SearchB.exe Infected: Trojan-Clicker.Win32.VB.jz
C:\WINDOWS\SYS99.exe Infected: Trojan.Win32.VB.tg
C:\WINDOWS\system32\2D2C2A2932332.exe Infected: Trojan.Win32.VB.aft
C:\WINDOWS\system32\399.exe Infected: Trojan-Dropper.Win32.Agent.xw
C:\WINDOWS\system32\app_b.exe Infected: Trojan-Dropper.Win32.Agent.afl
C:\WINDOWS\system32\GS2.exe/data0002/data0006 Infected: Trojan-Dropper.Win32.VB.kk
C:\WINDOWS\system32\GS2.exe/data0002 Infected: Trojan-Dropper.Win32.VB.kk
C:\WINDOWS\system32\GS2.exe Infected: Trojan-Dropper.Win32.VB.kk
C:\WINDOWS\system32\msCMTsrvc.exe Infected: Trojan-Downloader.Win32.Presario
C:\WINDOWS\system32\sate.exe Infected: Trojan-Downloader.Win32.IstBar.gen
C:\WINDOWS\system32\Setup8823.exe/data0010/data0010/data0002 Infected: Trojan-Downloader.Win32.VB.tw
C:\WINDOWS\system32\Setup8823.exe/data0010/data0010/data0003 Infected: Trojan.Win32.VB.tg
C:\WINDOWS\system32\Setup8823.exe/data0010/data0010/data0004 Infected: Trojan-Clicker.Win32.VB.jz
C:\WINDOWS\system32\Setup8823.exe/data0010/data0010/data0007 Infected: Trojan.Win32.VB.tg
C:\WINDOWS\system32\Setup8823.exe/data0010/data0010/data0008 Infected: Trojan.Win32.VB.tg
C:\WINDOWS\system32\Setup8823.exe/data0010/data0010 Infected: Trojan.Win32.VB.tg
C:\WINDOWS\system32\Setup8823.exe/data0010 Infected: Trojan.Win32.VB.tg
C:\WINDOWS\system32\Setup8823.exe Infected: Trojan.Win32.VB.tg
C:\WINDOWS\system32\{FBD2EBD0-E6DF-456E-B300-A4D10A90C683}.dll Infected: Trojan.Win32.VB.aft
C:\WINDOWS\uninstall_wh.exe Infected: Trojan.Win32.VB.tg
C:\WINDOWS\win3207136-856199.exe Infected: Trojan-Downloader.Win32.VB.tw
C:\WINDOWS\zkacfqe.exe Infected: Trojan-Clicker.Win32.VB.ij
C:\WINDOWS\zkacfqeA.exe Infected: Trojan-Clicker.Win32.VB.ij

Scan process completed.
  • 0

#6
sari

sari

    GeekU Admin

  • Community Leader
  • 21,806 posts
  • MVP
roacham,

Good job so far. We have a few things left to do.

Step 1:

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O3 - Toolbar: Alexa - {3CEFF6CD-6F08-4E4D-BCCD-FF7415288C3B} - C:\WINDOWS\system32\SHDOCVW.DLL
O4 - HKCU\..\Run: [CMMan] "C:\Program Files\CMMan\CMMan.exe"
O9 - Extra button: Alexa - {9D74677A-E227-40fb-9511-F7E92EA4083A} - C:\WINDOWS\system32\SHDOCVW.DLL
O9 - Extra 'Tools' menuitem: Alexa Toolbar - {9D74677A-E227-40fb-9511-F7E92EA4083A} - C:\WINDOWS\system32\SHDOCVW.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)

Now close all windows other than HiJackThis, then click Fix Checked. Reboot into safe mode.

Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Please remove these entries from Add/Remove Programs in the Control Panel(if present):

Alexa Toolbar

Please note any other programs that you dont recognize in that list in your next response

Please delete these files or folders using Windows Explorer(if present):

C:\Program Files\CMMan <=== folder
C:\WINDOWS\web\related.htm <==== file

After that, Reboot.

Step 2:

Please download the Killbox by Option^Explicit.

Note: In the event you already have Killbox, this is a new version that I need you to download.
  • Save it to your desktop.
  • Please double-click Killbox.exe to run it.
  • Select:
    • Delete on Reboot
    • then Click on the All Files button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\n.exe
    C:\Program Files\backups
    C:\Program Files\Common Files\VCClient
    C:\WINDOWS\linun.exe
    C:\WINDOWS\offun.exe
    C:\WINDOWS\opmrket.exe
    C:\WINDOWS\SearchB.exe
    C:\WINDOWS\system32\399.exe
    C:\WINDOWS\system32\app_b.exe
    C:\WINDOWS\system32\GS2.exe
    C:\WINDOWS\system32\sate.exe
    C:\WINDOWS\system32\Setup8823.exe
    C:\WINDOWS\system32\{FBD2EBD0-E6DF-456E-B300-A4D10A90C683}.dll

  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
  • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

Step 3:

Download and install CleanUp!
NOTE: Do NOT run this program if you have XP Professional 64 bit edition. If you're unsure please do not run it!

Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:
Click "Options..."
Move the arrow down to "Custom CleanUp!"
Put a check next to the following (Make sure nothing else is checked!):
  • Empty Recycle Bins
  • Delete Cookies
  • Delete Prefetch files (if present)
  • Cleanup! All Users
Click OK
Press the CleanUp! button to start the program.

It may ask you to log-off/reboot at the end, if it does please do so.

Please post another hijackthis log for review.

Thanks,

sari
  • 0

#7
roacham

roacham

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 245 posts
When I went to safe mode and tried to remove the Alexa toolbar it asked if I was sure I wanted to unistall and I said yes, Then it said installation failed. The only other thing that did not look familiar was Compaq Setrefresh. It may have always been there and I just did not recognize it, I'm not sure so just thought I would let you know.

O.K. Here is my new log file

Logfile of HijackThis v1.99.1
Scan saved at 11:07:11 AM, on 1/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\COMPAQ\Compaq Advisor\bin\compaq-rba.exe
C:\WINDOWS\system32\msCMTSrvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presari...&c=2c02&lc=0409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/.../search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\COMPAQ\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
  • 0

#8
sari

sari

    GeekU Admin

  • Community Leader
  • 21,806 posts
  • MVP
roacham,

Congratulations! Your log is clean - please let me know if you're still experiencing problems. The Compaq Setrefresh is a Compaq utility - you don't need to worry about it. Let's reset your SpywareGuard program:

Double-click the red SG in your system try to Open Spywareguard
  • Click Option on the left
  • Uncheck the following
    • Enable Real-Time Scanning
    • Enable Download Protection
    • Enable Browser HiJack Protection
  • Click Save Settings
We also have to hide your hidden files again:

Make sure hidden files and folders are showing:

* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Do Not show hidden files and folders.
* Check the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.

While you're already protecting your computer to a certain extent with SpywareGuard and your anti-virus program, I'm going to list some other tools you might want to consider to further protect yourself. I would definitely suggest running Spybot on a regular basis, along with Ad-aware, and SpywareBlaster can prevent malicious programs from even being installed. I would also recommend the IE/Spyads program.

Here are some tips to reduce the potential for spyware infection in the future. I strongly recommend installing the following applications:

Detect and Remove Programs:
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
Prevention Programs:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
Other necessary Programs:
  • AntiVirus Program<= An AntiVirus program is a must! Whether it is a free version like AVG or Anti-Vir, or a shareware version like Norton or Kapersky, this is a must have.
  • Firewall<= A firewall is definitely a must have. Two good free versions are Sygate and ZoneLabs.
  • More Secure Browser<= Internet Explorer is not the most secure and best browser. There are safer and better alternatives available. I recommend Firefox, however Opera and SlimBrowsers are good as well.
And also see TonyKlein's good advice
So how did I get infected in the first place? and Spyware Aid's spyware article: Spyware, Adware, Malware: What it is, how it got on my computer, how to get rid of it, and how to prevent it.

Thanks,

sari
  • 0

#9
roacham

roacham

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 245 posts
Thank you so much for your help. I do still have the Alexa toolbar in my Add/Remove programs. It will not let me uninstall it. It asks me if I am sure I want to uninstall I said yes, then it says installation failed. How do I get rid of it? Also, my internet explorer just closed for no reason. I am going to try firefox after I get everything straightened out on my computer. It is working much better but I think it needs a little bit more help.
Thank you,
Angie

Edited by roacham, 05 January 2006 - 10:35 AM.

  • 0

#10
roacham

roacham

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 245 posts
Now my antivirus just popped up and said I have 4 infections Win32.SillyDI.AAV
  • 0

Advertisements


#11
roacham

roacham

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 245 posts
O.K., I ran ad-aware and I think it got rid of the Alexa toolbar. I have ran my EZ Trust ant-virus and it did not find any viruses. I went ahead and did another hijack this scan and kapersky scan. I am posting the log files of them. Maybe everything is cleaned up now (hopefully). I will let you check it out.

Logfile of HijackThis v1.99.1
Scan saved at 1:34:31 PM, on 1/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\COMPAQ\Compaq Advisor\bin\compaq-rba.exe
C:\WINDOWS\system32\msCMTSrvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presari...&c=2c02&lc=0409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/.../search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\pwinssaw.exe CORN001
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\pwinssaw.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\COMPAQ\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Thursday, January 05, 2006 13:33:01
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 5/01/2006
Kaspersky Anti-Virus database records: 158982
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
G:\

Scan Statistics:
Total number of scanned objects: 45087
Number of viruses found: 14
Number of infected objects: 64
Number of suspicious objects: 0
Duration of the scan process: 4412 sec

Infected Object Name - Virus Name
C:\!KillBox\399.exe Infected: Trojan-Dropper.Win32.Agent.xw
C:\!KillBox\app_b.exe Infected: Trojan-Dropper.Win32.Agent.afl
C:\!KillBox\GS2.exe/data0002/data0006 Infected: Trojan-Dropper.Win32.VB.kk
C:\!KillBox\GS2.exe/data0002 Infected: Trojan-Dropper.Win32.VB.kk
C:\!KillBox\GS2.exe Infected: Trojan-Dropper.Win32.VB.kk
C:\!KillBox\linun.exe Infected: Trojan.Win32.VB.tg
C:\!KillBox\offun.exe Infected: Trojan-Downloader.Win32.VB.nw
C:\!KillBox\opmrket.exe Infected: Trojan.Win32.Favadd.o
C:\!KillBox\sate.exe Infected: Trojan-Downloader.Win32.IstBar.gen
C:\!KillBox\SearchB.exe Infected: Trojan-Clicker.Win32.VB.jz
C:\!KillBox\Setup8823.exe/data0010/data0010/data0002 Infected: Trojan-Downloader.Win32.VB.tw
C:\!KillBox\Setup8823.exe/data0010/data0010/data0003 Infected: Trojan.Win32.VB.tg
C:\!KillBox\Setup8823.exe/data0010/data0010/data0004 Infected: Trojan-Clicker.Win32.VB.jz
C:\!KillBox\Setup8823.exe/data0010/data0010/data0007 Infected: Trojan.Win32.VB.tg
C:\!KillBox\Setup8823.exe/data0010/data0010/data0008 Infected: Trojan.Win32.VB.tg
C:\!KillBox\Setup8823.exe/data0010/data0010 Infected: Trojan.Win32.VB.tg
C:\!KillBox\Setup8823.exe/data0010 Infected: Trojan.Win32.VB.tg
C:\!KillBox\Setup8823.exe Infected: Trojan.Win32.VB.tg
C:\!KillBox\{FBD2EBD0-E6DF-456E-B300-A4D10A90C683}.dll Infected: Trojan.Win32.VB.aft
C:\Program Files\backups\backup-20051231-102629-208.dll Infected: Trojan.Win32.VB.aft
C:\Program Files\backups\backup-20051231-173443-255.dll Infected: Trojan.Win32.VB.aft
C:\Program Files\backups\backup-20060103-184257-633.dll Infected: Trojan-Clicker.Win32.Small.jf
C:\Program Files\Common Files\VCClient\Setup88.exe/data0002 Infected: Trojan-Downloader.Win32.VB.tw
C:\Program Files\Common Files\VCClient\Setup88.exe/data0003 Infected: Trojan.Win32.VB.tg
C:\Program Files\Common Files\VCClient\Setup88.exe/data0004 Infected: Trojan-Clicker.Win32.VB.jz
C:\Program Files\Common Files\VCClient\Setup88.exe/data0007 Infected: Trojan.Win32.VB.tg
C:\Program Files\Common Files\VCClient\Setup88.exe/data0008 Infected: Trojan.Win32.VB.tg
C:\Program Files\Common Files\VCClient\Setup88.exe Infected: Trojan.Win32.VB.tg
C:\Program Files\Common Files\VCClient\Setup8823.exe/data0010/data0002 Infected: Trojan-Downloader.Win32.VB.tw
C:\Program Files\Common Files\VCClient\Setup8823.exe/data0010/data0003 Infected: Trojan.Win32.VB.tg
C:\Program Files\Common Files\VCClient\Setup8823.exe/data0010/data0004 Infected: Trojan-Clicker.Win32.VB.jz
C:\Program Files\Common Files\VCClient\Setup8823.exe/data0010/data0007 Infected: Trojan.Win32.VB.tg
C:\Program Files\Common Files\VCClient\Setup8823.exe/data0010/data0008 Infected: Trojan.Win32.VB.tg
C:\Program Files\Common Files\VCClient\Setup8823.exe/data0010 Infected: Trojan.Win32.VB.tg
C:\Program Files\Common Files\VCClient\Setup8823.exe Infected: Trojan.Win32.VB.tg
C:\RECYCLER\S-1-5-21-2322712386-2745678790-3725260815-1007\Dc4.exe Infected: Trojan-Downloader.Win32.Adload.k
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP149\A0112238.dll Infected: Trojan.Win32.VB.aft
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP151\A0115330.dll Infected: Trojan-Clicker.Win32.Small.jf
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116371.exe Infected: Trojan.Win32.VB.tg
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116372.exe Infected: Trojan-Downloader.Win32.VB.nw
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116373.exe Infected: Trojan.Win32.Favadd.o
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116374.exe Infected: Trojan-Clicker.Win32.VB.jz
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116375.exe Infected: Trojan-Dropper.Win32.Agent.xw
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116376.exe Infected: Trojan-Dropper.Win32.Agent.afl
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116377.exe/data0002/data0006 Infected: Trojan-Dropper.Win32.VB.kk
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116377.exe/data0002 Infected: Trojan-Dropper.Win32.VB.kk
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116377.exe Infected: Trojan-Dropper.Win32.VB.kk
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116378.exe Infected: Trojan-Downloader.Win32.IstBar.gen
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116379.exe/data0010/data0010/data0002 Infected: Trojan-Downloader.Win32.VB.tw
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116379.exe/data0010/data0010/data0003 Infected: Trojan.Win32.VB.tg
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116379.exe/data0010/data0010/data0004 Infected: Trojan-Clicker.Win32.VB.jz
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116379.exe/data0010/data0010/data0007 Infected: Trojan.Win32.VB.tg
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116379.exe/data0010/data0010/data0008 Infected: Trojan.Win32.VB.tg
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116379.exe/data0010/data0010 Infected: Trojan.Win32.VB.tg
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116379.exe/data0010 Infected: Trojan.Win32.VB.tg
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116379.exe Infected: Trojan.Win32.VB.tg
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP152\A0116380.dll Infected: Trojan.Win32.VB.aft
C:\WINDOWS\SYS99.exe Infected: Trojan.Win32.VB.tg
C:\WINDOWS\system32\2D2C2A2932332.exe Infected: Trojan.Win32.VB.aft
C:\WINDOWS\system32\msCMTsrvc.exe Infected: Trojan-Downloader.Win32.Presario
C:\WINDOWS\uninstall_wh.exe Infected: Trojan.Win32.VB.tg
C:\WINDOWS\win3207136-856199.exe Infected: Trojan-Downloader.Win32.VB.tw
C:\WINDOWS\zkacfqe.exe Infected: Trojan-Clicker.Win32.VB.ij
C:\WINDOWS\zkacfqeA.exe Infected: Trojan-Clicker.Win32.VB.ij

Scan process completed.


Thanks,
Angie
  • 0

#12
sari

sari

    GeekU Admin

  • Community Leader
  • 21,806 posts
  • MVP
roacham,

I see from the Kaspersky scan that not all the files I had you delete previously were successfully deleted, so we're going to use the killbox on those as well, and I'm going to have you delete them and some other folders in safe mode. Please print these instructions, as you won't be able to access them whild in safe mode.

Step 1:
*Open Notepad - Start, All Programs, Accessories, Notepad
*Copy all of the files listed below and paste them into Notepad:

C:\Program Files\backups\backup-20051231-102629-208.dll
C:\Program Files\backups\backup-20051231-173443-255.dll
C:\Program Files\backups\backup-20060103-184257-633.dll
C:\WINDOWS\SYS99.exe
C:\WINDOWS\system32\2D2C2A2932332.exe
C:\WINDOWS\uninstall_wh.exe
C:\WINDOWS\win3207136-856199.exe
C:\WINDOWS\zkacfqe.exe
C:\WINDOWS\zkacfqeA.exe


*Save it as Killboxfiles.txt to your desktop.
Step 2:

Reboot into safe mode.

Step 3:

Delete the following folder:

C:\Program Files\Common Files\VCClient

Step 4:

[*] Open the Killboxfiles.txt you placed on your desktop.
[*] Please double-click Killbox.exe to run it.
[*] Select:
  • Delete on Reboot
  • then Click on the All Files button.
[*]Please copy the file paths from Killboxfiles.txt to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

[*] Return to Killbox, go to the File menu, and choose Paste from Clipboard.

[*]Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).[/list]
If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

Step 5:

Now that you're back in normal mode, we're going to reset your system restore. This will erase your system restore points, but there are viruses residing in there anyway, so it will give you a clean restore point to work from.

To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.

(Windows XP)
1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

How to Turn On and Turn Off System Restore in Windows XP
http://support.micro...kb;en-us;310405

Run the Kaspersky scan again, and post the results back here.

Thanks,

sari
  • 0

#13
roacham

roacham

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 245 posts
here is the kaspersky results

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Thursday, January 05, 2006 17:37:33
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 5/01/2006
Kaspersky Anti-Virus database records: 158982
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
G:\

Scan Statistics:
Total number of scanned objects: 44707
Number of viruses found: 14
Number of infected objects: 43
Number of suspicious objects: 0
Duration of the scan process: 3997 sec

Infected Object Name - Virus Name
C:\!KillBox\2D2C2A2932332.exe Infected: Trojan.Win32.VB.aft
C:\!KillBox\399.exe Infected: Trojan-Dropper.Win32.Agent.xw
C:\!KillBox\app_b.exe Infected: Trojan-Dropper.Win32.Agent.afl
C:\!KillBox\backup-20051231-102629-208.dll Infected: Trojan.Win32.VB.aft
C:\!KillBox\backup-20051231-173443-255.dll Infected: Trojan.Win32.VB.aft
C:\!KillBox\backup-20060103-184257-633.dll Infected: Trojan-Clicker.Win32.Small.jf
C:\!KillBox\GS2.exe/data0002/data0006 Infected: Trojan-Dropper.Win32.VB.kk
C:\!KillBox\GS2.exe/data0002 Infected: Trojan-Dropper.Win32.VB.kk
C:\!KillBox\GS2.exe Infected: Trojan-Dropper.Win32.VB.kk
C:\!KillBox\linun.exe Infected: Trojan.Win32.VB.tg
C:\!KillBox\offun.exe Infected: Trojan-Downloader.Win32.VB.nw
C:\!KillBox\opmrket.exe Infected: Trojan.Win32.Favadd.o
C:\!KillBox\sate.exe Infected: Trojan-Downloader.Win32.IstBar.gen
C:\!KillBox\SearchB.exe Infected: Trojan-Clicker.Win32.VB.jz
C:\!KillBox\Setup8823.exe/data0010/data0010/data0002 Infected: Trojan-Downloader.Win32.VB.tw
C:\!KillBox\Setup8823.exe/data0010/data0010/data0003 Infected: Trojan.Win32.VB.tg
C:\!KillBox\Setup8823.exe/data0010/data0010/data0004 Infected: Trojan-Clicker.Win32.VB.jz
C:\!KillBox\Setup8823.exe/data0010/data0010/data0007 Infected: Trojan.Win32.VB.tg
C:\!KillBox\Setup8823.exe/data0010/data0010/data0008 Infected: Trojan.Win32.VB.tg
C:\!KillBox\Setup8823.exe/data0010/data0010 Infected: Trojan.Win32.VB.tg
C:\!KillBox\Setup8823.exe/data0010 Infected: Trojan.Win32.VB.tg
C:\!KillBox\Setup8823.exe Infected: Trojan.Win32.VB.tg
C:\!KillBox\SYS99.exe Infected: Trojan.Win32.VB.tg
C:\!KillBox\uninstall_wh.exe Infected: Trojan.Win32.VB.tg
C:\!KillBox\win3207136-856199.exe Infected: Trojan-Downloader.Win32.VB.tw
C:\!KillBox\zkacfqe.exe Infected: Trojan-Clicker.Win32.VB.ij
C:\!KillBox\zkacfqeA.exe Infected: Trojan-Clicker.Win32.VB.ij
C:\!KillBox\{FBD2EBD0-E6DF-456E-B300-A4D10A90C683}.dll Infected: Trojan.Win32.VB.aft
C:\RECYCLER\S-1-5-21-2322712386-2745678790-3725260815-1005\Dc1\Setup88.exe/data0002 Infected: Trojan-Downloader.Win32.VB.tw
C:\RECYCLER\S-1-5-21-2322712386-2745678790-3725260815-1005\Dc1\Setup88.exe/data0003 Infected: Trojan.Win32.VB.tg
C:\RECYCLER\S-1-5-21-2322712386-2745678790-3725260815-1005\Dc1\Setup88.exe/data0004 Infected: Trojan-Clicker.Win32.VB.jz
C:\RECYCLER\S-1-5-21-2322712386-2745678790-3725260815-1005\Dc1\Setup88.exe/data0007 Infected: Trojan.Win32.VB.tg
C:\RECYCLER\S-1-5-21-2322712386-2745678790-3725260815-1005\Dc1\Setup88.exe/data0008 Infected: Trojan.Win32.VB.tg
C:\RECYCLER\S-1-5-21-2322712386-2745678790-3725260815-1005\Dc1\Setup88.exe Infected: Trojan.Win32.VB.tg
C:\RECYCLER\S-1-5-21-2322712386-2745678790-3725260815-1005\Dc1\Setup8823.exe/data0010/data0002 Infected: Trojan-Downloader.Win32.VB.tw
C:\RECYCLER\S-1-5-21-2322712386-2745678790-3725260815-1005\Dc1\Setup8823.exe/data0010/data0003 Infected: Trojan.Win32.VB.tg
C:\RECYCLER\S-1-5-21-2322712386-2745678790-3725260815-1005\Dc1\Setup8823.exe/data0010/data0004 Infected: Trojan-Clicker.Win32.VB.jz
C:\RECYCLER\S-1-5-21-2322712386-2745678790-3725260815-1005\Dc1\Setup8823.exe/data0010/data0007 Infected: Trojan.Win32.VB.tg
C:\RECYCLER\S-1-5-21-2322712386-2745678790-3725260815-1005\Dc1\Setup8823.exe/data0010/data0008 Infected: Trojan.Win32.VB.tg
C:\RECYCLER\S-1-5-21-2322712386-2745678790-3725260815-1005\Dc1\Setup8823.exe/data0010 Infected: Trojan.Win32.VB.tg
C:\RECYCLER\S-1-5-21-2322712386-2745678790-3725260815-1005\Dc1\Setup8823.exe Infected: Trojan.Win32.VB.tg
C:\RECYCLER\S-1-5-21-2322712386-2745678790-3725260815-1007\Dc4.exe Infected: Trojan-Downloader.Win32.Adload.k
C:\WINDOWS\system32\msCMTsrvc.exe Infected: Trojan-Downloader.Win32.Presario

Scan process completed.


I am wondering if I should uninstall killbox when we are done. I know it is helping but it is also showing alot of viruses. I guess it is supposed to though. I hope this is better.
Angie
  • 0

#14
sari

sari

    GeekU Admin

  • Community Leader
  • 21,806 posts
  • MVP
roacham,

What is showing in Killbox is the backup of what was deleted - those viruses aren't present on your system in a way that could harm you. It appears that all the viruses have now been deleted - how is your system running? Have you had any more issues with Internet Explorer closing?

Let's delete the backups in Killbox now:

Open Killbox, and select File > Cleanup > Delete All Backups.

Please post back and let me know how things are.

Thanks,

sari
  • 0

#15
roacham

roacham

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 245 posts
So far so good. I have not had more IE closing. I am not getting any more pop-ups. I am now using firefox also. How do I know if my anti-virus has a firewall? I am using eTrust EZ. Thank you so much for your help. I was going to send a small donation but I am not seeing a link for you. Do you have one? Again, thank you very much.
Angie

Edited by roacham, 06 January 2006 - 11:25 AM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP