Home / Software / Computer viruses and spyware / Please help! HijackThis log
0 Members and 2 Guests are viewing this topic. « previous next »
Pages: 1 2 [All] - (Bottom) Print
Author Topic: Please help! HijackThis log  (Read 1744 times)
GAC76
Guest
« on: November 28, 2007, 04:32:59 PM »

Please tell me which files I need to fix and delete with HijackThis.  Thanks in advance.

Logfile of HijackThis v1.99.1
Scan saved at 5:23:14 PM, on 11/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\tp4serv.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Documents and Settings\Greg Coons\Desktop\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [b0b952d1] rundll32.exe "C:\WINDOWS\system32\losygkkw.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HPAiODevice(hp officejet 7100 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
O8 - Extra context menu item: &Search - ?p=ZUxdm082YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O11 - Options group: [JAVA_IBM] Java (IBM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: www.espn.go.com
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1162846184513
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe

IP logged
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #1 on: November 28, 2007, 04:41:16 PM »

delete/uninstall your copy of HijackThis and reinstall the new version from the below link.

Please see this thread http://www.computerhope.com/forum/index.php/topic,46313.0.html

Post the logs as attachments.
IP logged

GAC76
Guest
« Reply #2 on: November 29, 2007, 07:20:14 AM »


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:18:29 AM, on 11/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\tp4serv.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [b0b952d1] rundll32.exe "C:\WINDOWS\system32\losygkkw.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HPAiODevice(hp officejet 7100 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
O8 - Extra context menu item: &Search - ?p=ZUxdm082YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: www.espn.go.com
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1162846184513
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe

--
End of file - 8312 bytes
IP logged
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #3 on: November 29, 2007, 08:13:48 AM »

We need all of the logs from the thread.

Add them as attachments please.
IP logged

GAC76
Guest
« Reply #4 on: November 29, 2007, 11:27:30 AM »

As requested please see the attached files.  Thank you.


[saving disk space - old attachment deleted by admin]
IP logged
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #5 on: November 29, 2007, 11:40:06 AM »

Please download Vundofix.exe to your desktop.

* Double-click VundoFix.exe to run it.
* Put a check next to Run VundoFix as a task.
* You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
* When VundoFix re-opens, click the Scan for Vundo button.
* Once it's done scanning, click the Remove Vundo button.
* You will receive a prompt asking if you want to remove the files, click YES
* Once you click yes, your desktop will go blank as it starts removing Vundo.
* When completed, it will prompt that it will shutdown your computer, click OK.
* Turn your computer back on.
* Please post the contents of C:\vundofix.txt and a new HiJackThis log.

Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears at reboot.

Please let Vundo finish, sometimes it can take multiple passes

===

Next post please attach
vundofix.txt log
A New HijackThis log
IP logged

GAC76
Guest
« Reply #6 on: November 29, 2007, 01:29:26 PM »

Ran: VundoFix (3 passes), VirtumundoBeGone, ComboFix, FixVundo (Symantec), and FxVundoB (Symantec)

Then ran another hijackthis per your request.

Please see the attached in this and the next post.

[saving disk space - old attachment deleted by admin]
IP logged
GAC76
Guest
« Reply #7 on: November 29, 2007, 01:32:30 PM »

more attached.

[saving disk space - old attachment deleted by admin]
IP logged
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #8 on: November 29, 2007, 01:59:52 PM »

Please download FindAWF:
http://noahdfear.net/downloads/FindAWF.exe

Save the file to the Desktop
Double-click the FindAWF icon.

If a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 1 then Enter to scan for bak folders
The scan may take a while, please be patient.

When done, a text file, Find AWF report is produced.
Please attach the Find AWF report in your reply.
IP logged

GAC76
Guest
« Reply #9 on: November 29, 2007, 02:24:06 PM »

As requested, see the attached.

[saving disk space - old attachment deleted by admin]
IP logged
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #10 on: November 29, 2007, 02:41:20 PM »

Double-click the FindAWF icon once again

If a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 2 then Enter to restore files from bak folders

A text file opens called: files.txt
Click below the line and paste the following list of files to be restored:


C:\IBMTOOLS\utils\bak\ibmprc.exe
C:\Program Files\QuickTime\bak\qttask.exe
C:\WINDOWS\system32\bak\ctfmon.exe
C:\WINDOWS\system32\bak\hkcmd.exe
C:\WINDOWS\system32\bak\igfxtray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\bak\hpgs2wnd.exe
C:\Program Files\IBM\Updater\bak\ucstartup.exe
C:\Program Files\ThinkPad\ConnectUtilities\bak\QCWLICON.EXE
C:\Program Files\ThinkPad\Utilities\bak\BMMLREF.EXE
C:\Program Files\ThinkPad\Utilities\bak\EzEjMnAp.Exe
C:\Program Files\ThinkPad\Utilities\bak\TpKmapAp.exe
C:\WINDOWS\system32\dla\bak\tfswctrl.exe
C:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe
C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe
C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe
C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\bak\TPHKMGR.exe

Next, close and click Yes to save the changes.

Once files.txt is saved, FindAWF does the following:
-It attempts to terminate the process represented by each filename on the list, if running
-Deletes the rogue file from the parent folder, if present
-Copies the original file to the parent folder

When done with the above, it automatically runs a new scan and opens a new log.
Please attach the new FindAWF log in your reply.
« Last Edit: December 01, 2007, 01:55:04 PM by evilfantasy » IP logged

GAC76
Guest
« Reply #11 on: November 29, 2007, 03:22:01 PM »

attached

[saving disk space - old attachment deleted by admin]
IP logged
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #12 on: November 29, 2007, 03:45:23 PM »

Double-click the FindAWF icon once again

If a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 3 then Enter to remove bak folders

A text file opens called: folders.txt
Click below the line and paste the following list of folders to be removed:


C:\IBMTOOLS\UTILS\BAK
C:\PROGRA~1\QUICKT~1\BAK
C:\WINDOWS\SYSTEM32\BAK
C:\PROGRA~1\HEWLET~1\HPSHAR~1\BAK
C:\PROGRA~1\IBM\UPDATER\BAK
C:\PROGRA~1\THINKPAD\CONNEC~1\BAK
C:\PROGRA~1\THINKPAD\UTILIT~1\BAK
C:\WINDOWS\SYSTEM32\DLA\BAK
C:\PROGRA~1\ADOBE\READER~1.0\READER\BAK
C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK
C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK
C:\PROGRA~1\JAVA\JRE16~2.0_0\BIN\BAK
C:\PROGRA~1\THINKPAD\PKGMGR\HOTKEY\BAK


Next, close and click Yes to save the changes.

Once folders.txt is saved, FindAWF does the following:
-It deletes the contents of the bak folders
-Removes the bak folders

When done with the above, it automatically runs a new scan and opens a new log.
Please attach the new FindAWF log in your reply.

We are getting there, still another step after this one but they have to be done one by one unfortunately.


« Last Edit: December 01, 2007, 01:56:41 PM by evilfantasy » IP logged

GAC76
Guest
« Reply #13 on: November 29, 2007, 03:52:42 PM »

No problem, I appreciate the help!

[saving disk space - old attachment deleted by admin]
IP logged
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #14 on: November 29, 2007, 04:33:41 PM »

Double-click the FindAWF icon once again

If a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 4 then Enter to reset domain zones

This removes all entries from the domain zones.
When the program returns to the main menu, use the following option:
Press E then Enter to EXIT

Run combofix again and attach the new log.
Also please attach a new HiJackThis log.

IP logged

GAC76
Guest
« Reply #15 on: November 29, 2007, 04:46:37 PM »

attached

[saving disk space - old attachment deleted by admin]
IP logged
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #16 on: November 29, 2007, 05:39:42 PM »

Delete these files/folders, as follows:

* Open notepad and copy/paste the text in the quote box below into it (all except the word QUOTE):

Quote
File::
ujedltxb.ini
gfeoebci.ini
mpckddxl.ini
ftjjovke.ini
gjxqajdm.ini
jrpptech.ini
ggujimly.ini
lqsvtnpa.ini
sgrvgoaf.ini
ddijkixx.ini
kubtafxc.ini
fabcvped.ini
itweqqvc.ini
fujcvtwn.ini
nivowbpr.dll
craatwsk.dll
aglndpln.dll
ntmfgwqk.dll
jquqrcou.dll
mddqfaxi.dll
mcrh.tmp
fuxfdyna.dll
lcsypdjo.dll
mvyqmkya.dll
kjrwdqts.dll
ulmbjbab.dll
tbkeuymt.dll
mmafbdvu.dll
cpaonoqi.dll
ngyqnuen.ini
kxuiigaj.ini
thertnnu.ini
hjjxqjnv.ini
gckkqkxx.ini
muwquhfd.ini
losygkkw.dll

Folder::
C:\VundoFix Backups

* Save this as CFScript on the desktop.
* Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



* ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it shall produce a log for you. Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick combofix's window while it is running. That may cause your system to hang

Next post please attach
combofix.txt log
New HijackThis log
IP logged

GAC76
Guest
« Reply #17 on: November 29, 2007, 05:52:09 PM »

as requested

[saving disk space - old attachment deleted by admin]
IP logged
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #18 on: November 29, 2007, 06:19:08 PM »

Well combofix didn't delete all that I wanted it to.

Enable Viewing Of Hidden System Files & Folders

1. Right Click Start.
2. Select Control Panel.
3. Select the Tools menu and click Folder Options.
4. Select the View Tab.
5. Under the Hidden files and folders heading select Show hidden files and folders.
6. Uncheck the Hide extensions for known file types option.
7. Uncheck the Hide protected operating system files (recommended) option.
8. Click Apply.
9. Click OK.

===

Open HijackThis and select "Do a system scan only"

Place a check mark next to:

O4 - HKLM\..\Run: [b0b952d1] rundll32.exe "C:\WINDOWS\system32\losygkkw.dll",b
O8 - Extra context menu item: &Search - ?p=ZUxdm082YYUS

Next click "Fix checked"

On the desktop right click "My Computer" and "Open"

Locate and delete the following file/folder (in bold):

C:\WINDOWS\system32\losygkkw.dll (if there)

I am going to look into the combofix entries and will post back when I know more.

We are almost there.

Also how is the computer now?
IP logged

GAC76
Guest
« Reply #19 on: November 29, 2007, 07:09:50 PM »

My Computer seems fine. 

No more automatic resets to "accept all cookies", no more automatic redirects to an unknown webpage, no more annoying popups, and now I know why I kept getting the "error" at startup stating that the file C:\WINDOWS\system32\losygkkw.dll could not be found.  It was deleted at some point as a virus file.

You didn't ask for a logfile last post, so I will await your next for further instructions.

Thanks for your continued assistance. 
IP logged
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #20 on: November 29, 2007, 07:28:23 PM »

I'm awaiting a second opinion on the combofix log. Probably won't until later but I will post back and let you know.

Glad things are working better.
IP logged

evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #21 on: November 30, 2007, 08:43:49 AM »

OK we are rolling again.


Delete these files/folders, as follows:

* Open notepad and copy/paste the text in the quote box below into it (all except the word QUOTE):

Quote
File::
C:\WINDOWS\system32\ujedltxb.ini
C:\WINDOWS\system32\gfeoebci.ini
C:\WINDOWS\system32\mpckddxl.ini
C:\WINDOWS\system32\ftjjovke.ini
C:\WINDOWS\system32\gjxqajdm.ini
C:\WINDOWS\system32\jrpptech.ini
C:\WINDOWS\system32\ggujimly.ini
C:\WINDOWS\system32\lqsvtnpa.ini
C:\WINDOWS\system32\sgrvgoaf.ini
C:\WINDOWS\system32\ddijkixx.ini
C:\WINDOWS\system32\kubtafxc.ini
C:\WINDOWS\system32\fabcvped.ini
C:\WINDOWS\system32\itweqqvc.ini
C:\WINDOWS\system32\fujcvtwn.ini
C:\WINDOWS\system32\nivowbpr.dll
C:\WINDOWS\system32\craatwsk.dll
C:\WINDOWS\system32\aglndpln.dll
C:\WINDOWS\system32\ntmfgwqk.dll
C:\WINDOWS\system32\jquqrcou.dll
C:\WINDOWS\system32\mddqfaxi.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\fuxfdyna.dll
C:\WINDOWS\system32\lcsypdjo.dll
C:\WINDOWS\system32\mvyqmkya.dll
C:\WINDOWS\system32\kjrwdqts.dll
C:\WINDOWS\system32\ulmbjbab.dll
C:\WINDOWS\system32\tbkeuymt.dll
C:\WINDOWS\system32\mmafbdvu.dll
C:\WINDOWS\system32\cpaonoqi.dll
C:\WINDOWS\system32\ngyqnuen.ini
C:\WINDOWS\system32\kxuiigaj.ini
C:\WINDOWS\system32\thertnnu.ini
C:\WINDOWS\system32\hjjxqjnv.ini
C:\WINDOWS\system32\gckkqkxx.ini
C:\WINDOWS\system32\muwquhfd.ini
C:\WINDOWS\system32\losygkkw.dll

* Save this as CFScript on the desktop.
* Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



* ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it shall produce a log for you. Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick combofix's window while it is running. That may cause your system to hang


Next post please add:
combofix log
New HijackThis log
IP logged

GAC76
Guest
« Reply #22 on: November 30, 2007, 09:23:07 AM »

as requested, please see the attached

[saving disk space - old attachment deleted by admin]
IP logged
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #23 on: November 30, 2007, 09:35:05 AM »

That did it.

The logs look fine now.

Delete Find AWF and all of its logs.
Delete any vundo programs used.

Go to Start > Run and copy and paste next command in the field:

ComboFix /u



Make sure there's a space between Combofix and /
Then hit Enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again

To learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place?

Are you having any problems now?

If anything else comes back let us know.
IP logged

GAC76
Guest
« Reply #24 on: November 30, 2007, 10:23:59 AM »

Great job! Thanks for all your help!

If anything else comes up I know where to post.
IP logged
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #25 on: November 30, 2007, 10:38:42 AM »

No problem.

Safe surfing.......
IP logged

Pages: 1 2 [All] - (Top) Print 
Home / Software / Computer viruses and spyware / Please help! HijackThis log « previous next »
 


Login with username, password and session length

Old Forum Search | Forum Rules
Copyright © 2010 Computer Hope ® All rights reserved.
Powered by SMF 2.0 RC3 | SMF © 2006–2010, Simple Machines LLC
Page created in 0.214 seconds with 20 queries.