Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Trojan in system file Removal not easy  (Read 13165 times)

0 Members and 1 Guest are viewing this topic.

Twylla

    Topic Starter


    Beginner
  • I love YaBB 1G - SP1!
    Trojan in system file Removal not easy
    « on: December 29, 2005, 10:48:19 PM »
    I have a real pickel and need some expert advise.

    I know the rules not to open emails I dont know and all the  safety rules but..........

    I have Norton System Works and it detected a trojan named
    PWSTEAL.trojan.  I have researched it all over but the instruction given do not apply it seems.

    This nasty little bugger has set up house in my system files
    C;\\windows\system    in a file called dvd4free.dll

    Norton can not quaranteen it or delete it.

    Also I beleive that this thing is sending out spam through my computer which I cant seem to stop.

    Any help to remove this little bugger would be such a help.  Thank you in advance. I try not to stay online long because it continues to send emails out.

    I should mention I have Windows XP Pro
    « Last Edit: December 29, 2005, 10:51:27 PM by Twylla »

    GX1_Man

    • Guest
    Re: Trojan in system file Removal not easy
    « Reply #1 on: December 29, 2005, 11:02:05 PM »

    dl65

    • R.I.P.


    • Prodigy

      Thanked: 18
      Re: Trojan in system file Removal not easy
      « Reply #2 on: December 29, 2005, 11:05:02 PM »
      Twylla....ok ......the first thing to do is to turn off your system restore feature in XP pro .........  then d/l Ewido ....  http://www.download.com/Ewido-Security-Suite/3000-8022_4-10326287.html     its a 14 day fully functional trial version which should find and remove your pest. Once you have downloaded the app ...open it up and then check for the latest updates ...let it scan your system ....and dont be surprised if it finds a lot of infected files .......

      let us know how you make out .

      dl65  ::)
      If you don't know the answer, it isn't a dumb question.

      Twylla

        Topic Starter


        Beginner
      • I love YaBB 1G - SP1!
        Re: Trojan in system file Removal not easy
        « Reply #3 on: January 02, 2006, 11:42:01 PM »
        I downloaded Ewido and it found the same Trojan as my Norton and it couldnt repair the file either.  I was tired of trying to do anything online with all those messages being scanned and going out while I was trying to do something, so I left it for a bit.  Then all of a sudden the file is gone and no trace of it or outgoing emails.

        Yahhhhhhh

        Are there trojans or whatever on a time limit?  Are they there for a certain amount of time and then automatically delete themselves?  Cause I didnt do anything and now it is gone.  

        Good ridence!!

        I really appreciate your help.  Thank you.  I have bookmarked this awesome site and will share it with friends.  Thanks again

        dl65

        • R.I.P.


        • Prodigy

          Thanked: 18
          Re: Trojan in system file Removal not easy
          « Reply #4 on: January 03, 2006, 01:10:07 AM »
          Twylla..... Lets do one more check to be certain that sucker has departed ......
          D/l hijackthis  .......  http://www.download.com/HijackThis/3000-8022_4-10227353.html     ........save it on your desktop and then run the scan and post the logfile it generates here ...... it should show us if the trojan is gone or has simply changed its name and location .

          dl65  ::)
          « Last Edit: January 03, 2006, 01:10:41 AM by dl65 »
          If you don't know the answer, it isn't a dumb question.

          Twylla

            Topic Starter


            Beginner
          • I love YaBB 1G - SP1!
            Re: Trojan in system file Removal not easy
            « Reply #5 on: January 04, 2006, 11:04:51 PM »
            I can't beleive it the emails still keep going out.  They stopped for a day and now they are back.  I did the down load and here is the log

            Logfile of HijackThis v1.99.1
            Scan saved at 9:40:23 PM, on 04/01/2006
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
            C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
            C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
            C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\ewido\security suite\ewidoctrl.exe
            C:\WINDOWS\System32\GEARSec.exe
            C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
            C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
            C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
            C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
            C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
            C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
            C:\Program Files\Java\jre1.5.0\bin\jusched.exe
            C:\Program Files\Common Files\Symantec Shared\ccApp.exe
            C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\WinZip\WZQKPICK.EXE
            C:\Program Files\Norton SystemWorks\Norton AntiVirus\OPScan.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\PROGRA~1\NORTON~1\NORTON~3\navw32.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\Documents and Settings\henrietta\My Documents\Unzipped\hijackthis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.ca/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by TELUS Internet Services
            O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
            O4 - HKLM\..\Run: [Norton Ghost 9.0] C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
            O4 - HKCU\..\Run: [oimr] C:\PROGRA~1\COMMON~1\oimr\oimrm.exe
            O4 - Startup: PowerReg Scheduler V3.exe
            O4 - Startup: PowerReg Scheduler.exe
            O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
            O14 - IERESET.INF: START_PAGE_URL=http://www.telus.net/homepage
            O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
            O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
            O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
            O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1116734391647
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1130015153638
            O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
            O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
            O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
            O20

            Twylla

              Topic Starter


              Beginner
            • I love YaBB 1G - SP1!
              Re: Trojan in system file Removal not easy
              « Reply #6 on: January 04, 2006, 11:07:23 PM »
              I also have one more problem.  I cant change the picture on my desktop.  It is blocked.  When I try to choose from the picture options the browse button and the slider with my choices is disabled,.  This too happened about the same time as this bad little bug.

              Fed

              • Moderator


              • Sage
              • Thanked: 35
                • Experience: Experienced
                • OS: Windows XP
                Re: Trojan in system file Removal not easy
                « Reply #7 on: January 04, 2006, 11:18:42 PM »
                Use HJT and mark for deletion...

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
                [highlight]O4 - HKCU\..\Run: [oimr] C:\PROGRA~1\COMMON~1\oimr\oimrm.exe
                O4 - Startup: PowerReg Scheduler V3.exe
                O4 - Startup: PowerReg Scheduler.exe [/highlight]

                Don't delete the last three if you know what they are & you want to keep them.
                If unsure Google them.


                Delete them all.
                Do you have a firewall?
                What protection are you running?
                Everything real time?
                « Last Edit: January 04, 2006, 11:26:47 PM by Fed »

                Fed

                • Moderator


                • Sage
                • Thanked: 35
                  • Experience: Experienced
                  • OS: Windows XP
                  Re: Trojan in system file Removal not easy
                  « Reply #8 on: January 04, 2006, 11:28:34 PM »
                  Put up the rest of your HJT log.

                  Twylla

                    Topic Starter


                    Beginner
                  • I love YaBB 1G - SP1!
                    Re: Trojan in system file Removal not easy
                    « Reply #9 on: January 04, 2006, 11:32:32 PM »
                    Logfile of HijackThis v1.99.1
                    Scan saved at 10:31:55 PM, on 04/01/2006
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\ewido\security suite\ewidoctrl.exe
                    C:\WINDOWS\System32\GEARSec.exe
                    C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
                    C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
                    C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
                    C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
                    C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
                    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                    C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                    C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\WinZip\WZQKPICK.EXE
                    C:\Program Files\MSN Messenger\msnmsgr.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\WINDOWS\explorer.exe
                    C:\Program Files\Norton SystemWorks\Norton AntiVirus\OPScan.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\Documents and Settings\henrietta\My Documents\Unzipped\hijackthis\HijackThis.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.ca/
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by TELUS Internet Services
                    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                    O4 - HKLM\..\Run: [Norton Ghost 9.0] C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                    O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
                    O4 - HKCU\..\Run: [oimr] C:\PROGRA~1\COMMON~1\oimr\oimrm.exe
                    O4 - Startup: PowerReg Scheduler V3.exe
                    O4 - Startup: PowerReg Scheduler.exe
                    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
                    O14 - IERESET.INF: START_PAGE_URL=http://www.telus.net/homepage
                    O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
                    O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
                    O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
                    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
                    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1116734391647
                    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1130015153638
                    O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
                    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{9DC9C98F-BCF2-4424-BA6A-58E8C8926384}: NameServer = 204.174.64.1 204.174.65.1
                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                    O20 - Winlogon Notify:

                    Twylla

                      Topic Starter


                      Beginner
                    • I love YaBB 1G - SP1!
                      Re: Trojan in system file Removal not easy
                      « Reply #10 on: January 04, 2006, 11:35:39 PM »
                      BTW Thanks for this supper fast help.
                       I just did this scan and that is the whole thing.

                      Before I do the fix should I have restore turned off?

                      Fed

                      • Moderator


                      • Sage
                      • Thanked: 35
                        • Experience: Experienced
                        • OS: Windows XP
                        Re: Trojan in system file Removal not easy
                        « Reply #11 on: January 04, 2006, 11:37:00 PM »
                        Use HJT to fix all the ones I said.
                        Re-boot & come back with a fresh Log.

                        Twylla

                          Topic Starter


                          Beginner
                        • I love YaBB 1G - SP1!
                          Re: Trojan in system file Removal not easy
                          « Reply #12 on: January 05, 2006, 12:29:27 AM »

                          Here is the fresh log.  The emails are still going out.  What kind of Malware does this?  I need to get this fixed ASAP.  I dont want someone using me to send the rotten spam to others. Grrrrr how I hate spam

                          Logfile of HijackThis v1.99.1
                          Scan saved at 11:25:02 PM, on 04/01/2006
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                          C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                          C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                          C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\ewido\security suite\ewidoctrl.exe
                          C:\Program Files\ewido\security suite\ewidoguard.exe
                          C:\WINDOWS\System32\GEARSec.exe
                          C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
                          C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
                          C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
                          C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
                          C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
                          C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                          C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                          C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                          C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
                          C:\Program Files\MSN Messenger\MsnMsgr.Exe
                          C:\Program Files\Webroot\Washer\wwDisp.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\WinZip\WZQKPICK.EXE
                          C:\WINDOWS\system32\wuauclt.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Documents and Settings\henrietta\My Documents\Unzipped\hijackthis\HijackThis.exe
                          C:\Program Files\Messenger\msmsgs.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.ca/
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by TELUS Internet Services
                          O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                          O4 - HKLM\..\Run: [Norton Ghost 9.0] C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
                          O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
                          O14 - IERESET.INF: START_PAGE_URL=http://www.telus.net/homepage
                          O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
                          O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
                          O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
                          O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
                          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1116734391647
                          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1130015153638
                          O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
                          O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                          O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
                          O17 - HKLM\System\CCS\Services\Tcpip\..\{9DC9C98F-BCF2-4424-BA6A-58E8C8926384}: NameServer = 204.174.64.1 204.174.65.1
                          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                          O20 - Winlogon Notify: dvd4free - dvd4free.dll (file missing)
                          O20 - Winlogon Notify: msupdate - msupdate32.dll (file missing)
                          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                          O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
                          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                          O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
                          O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
                          O23 - Service: GEARSecurity - GEAR Software - C:\WIND

                          dl65

                          • R.I.P.


                          • Prodigy

                            Thanked: 18
                            Re: Trojan in system file Removal not easy
                            « Reply #13 on: January 05, 2006, 12:51:27 AM »
                            Twylla........ Finally its showed itself.....
                            Make sure you have system restore turned off...
                            Mark for removal :

                             O20 - Winlogon Notify: dvd4free - dvd4free.dll (file missing)    
                             
                              O20 - Winlogon Notify: msupdate - msupdate32.dll (file missing)

                            click FIX MARKED .......

                            reboot and then run another scan with hijackthis to confirm its gone .

                            For some reason those entries didnt show up in your earlier logs.

                            dl65  ::)
                            « Last Edit: January 05, 2006, 01:06:57 AM by dl65 »
                            If you don't know the answer, it isn't a dumb question.

                            Twylla

                              Topic Starter


                              Beginner
                            • I love YaBB 1G - SP1!
                              Re: Trojan in system file Removal not easy
                              « Reply #14 on: January 05, 2006, 10:01:20 AM »
                              Okay. I did all the removals you guys have suggested and rebooted it and I am still being used to send out those rotten spam crap.

                              This is this mornings log after everything was done

                              Logfile of HijackThis v1.99.1
                              Scan saved at 8:57:03 AM, on 05/01/2006
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                              C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                              C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\ewido\security suite\ewidoctrl.exe
                              C:\Program Files\ewido\security suite\ewidoguard.exe
                              C:\WINDOWS\System32\GEARSec.exe
                              C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
                              C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
                              C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
                              C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
                              C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
                              C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                              C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                              C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                              C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
                              C:\Program Files\Webroot\Washer\wwDisp.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\WinZip\WZQKPICK.EXE
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              C:\Program Files\ewido\security suite\securitysuite.exe
                              C:\Program Files\Norton SystemWorks\Norton AntiVirus\OPScan.exe
                              C:\Program Files\MSN\MSNCoreFiles\msn6.exe
                              C:\PROGRA~1\MSNMES~1\msnmsgr.exe
                              C:\Program Files\Messenger\msmsgs.exe
                              C:\Documents and Settings\henrietta\My Documents\Unzipped\hijackthis\HijackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.ca/
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by TELUS Internet Services
                              O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                              O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                              O4 - HKLM\..\Run: [Norton Ghost 9.0] C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                              O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
                              O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
                              O14 - IERESET.INF: START_PAGE_URL=http://www.telus.net/homepage
                              O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
                              O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
                              O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
                              O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
                              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1116734391647
                              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1130015153638
                              O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
                              O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                              O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
                              O17 - HKLM\System\CCS\Services\Tcpip\..\{9DC9C98F-BCF2-4424-BA6A-58E8C8926384}: NameServer = 204.174.64.1 204.174.65.1
                              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                              O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                              O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
                              O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                              O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
                              O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
                              O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
                              O23 - Service: Norton AntiVirus Auto-Protect Service (n