Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: MSN Virus [RESOLVED]  (Read 15714 times)

0 Members and 1 Guest are viewing this topic.

Gliff

    Topic Starter


    Beginner

    MSN Virus [RESOLVED]
    « on: April 26, 2007, 03:38:48 PM »
    My sister clicked on a link the other day whilst on MSN, and it installed some kind of virus. I looked it up and it seems like it's a virus a few people have happened to get. The link my sister clicked on was to a website known as "yourdreampartner.net" ~ i'm not sure beyond that. Here's my latest "Hijackthis" log

    ---

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wanadoo.co.uk
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer Provided By Wanadoo
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {99FF4998-A2E0-4424-9ABC-4F9EB941D2BE} - C:\WINDOWS\system32\ddcyx.dll
    O2 - BHO: (no name) - {A2E49E61-7F19-4337-8620-60FF0538866B} - C:\WINDOWS\system32\tuvurss.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
    O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\sgqrbobq.dll
    O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\WINDOWS\system32\WSBar.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [AOL_Demo] C:\Applications\Tool\AOL Demo\DSGDemo.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [SiSRaid] C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
    O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
    O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\taeybfxb.dll",realset
    O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Search with Wanadoo - res://C:\WINDOWS\system32\WSBar.dll/VSearch.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.pcservicecall.co.uk
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {15AC034D-14DF-4AF8-9D02-29E1F56A8235} (Virgin Digital MusicNet Class) - http://www.virgindigital.co.uk/activeX/VirginWMA.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://games.king.com/ctl/kingcomie.cab
    O16 - DPF: {47CEF84E-92D8-4C4A-86D7-CB982889DCC0} (Oberon Media Network Optimizer) - http://mp1.mplay.oberon-media.com/client/flashnet.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game11.zylom.com/activex/zylomgamesplayer.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{42674042-8611-4CE1-B2CB-6CA1A71C299A}: NameServer = 195.92.195.95 195.92.195.94
    O17 - HKLM\System\CS1\Services\Tcpip\..\{42674042-8611-4CE1-B2CB-6CA1A71C299A}: NameServer = 195.92.195.95 195.92.195.94
    O20 - Winlogon Notify: ddcyx - C:\WINDOWS\system32\ddcyx.dll
    O20 - Winlogon Notify: tuvurss - C:\WINDOWS\SYSTEM32\tuvurss.dll
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: AlProSoft Support Service (AlProSoftSupSvc) - TODO: <Company name> - C:\WINDOWS\system32\alpsfsvc.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe


    - Does anybody have any idea what isn't adding up here? There's a .dll file that i can't seem to find, ddcyx.dll ~ which is apparently not advised to keep. Any help would be much appreciated, thanks.
    « Last Edit: June 02, 2007, 06:56:57 PM by CBMatt »

    dl65

    • R.I.P.


    • Prodigy

      Thanked: 18
      Re: MSN Virus
      « Reply #1 on: April 26, 2007, 03:55:47 PM »
      Gliff ...... Would you please repost your logfile ...only this time please post the top header and the running processes as well as the log ......... in other words , the whole thing .


      thank you .

      dl65  ::)
      If you don't know the answer, it isn't a dumb question.

      Gliff

        Topic Starter


        Beginner

        Re: MSN Virus
        « Reply #2 on: April 26, 2007, 04:02:58 PM »
        Message is exceeding the character length, so i'll split the two parts into two replies. Thanks.

        Logfile of Trend Micro HijackThis v2.0.0 (BETA)
        Scan saved at 23:01:29, on 26/04/2007
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\LEXBCES.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\LEXPPS.EXE
        C:\WINDOWS\system32\alpsfsvc.exe
        C:\WINDOWS\system32\CTsvcCDA.exe
        C:\WINDOWS\runservice.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
        C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
        C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
        C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\WINDOWS\system32\sistray.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktopOE.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Documents and Settings\Sandra\Desktop\HiJackThis_v2.exe

        --> next reply
        « Last Edit: April 26, 2007, 04:15:46 PM by Gliff »

        Gliff

          Topic Starter


          Beginner

          Re: MSN Virus
          « Reply #3 on: April 26, 2007, 04:03:23 PM »
          --->

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.co.uk/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wanadoo.co.uk
          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
          O2 - BHO: (no name) - {61A6BD5B-642C-4840-A3E0-4268930D165C} - C:\WINDOWS\system32\ddcyx.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O2 - BHO: (no name) - {99FF4998-A2E0-4424-9ABC-4F9EB941D2BE} - C:\WINDOWS\system32\ddcyx.dll
          O2 - BHO: (no name) - {A2E49E61-7F19-4337-8620-60FF0538866B} - C:\WINDOWS\system32\tuvurss.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
          O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\sgqrbobq.dll
          O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\WINDOWS\system32\WSBar.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O4 - HKLM\..\Run: [AOL_Demo] C:\Applications\Tool\AOL Demo\DSGDemo.exe
          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
          O4 - HKLM\..\Run: [SiSRaid] C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
          O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
          O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
          O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
          O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\taeybfxb.dll",realset
          O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
          O4 - HKUS\S-1-5-21-869101610-620706971-2619405480-1007\..\Run: [Power2GoExpress]  (User 'Dan')
          O4 - HKUS\S-1-5-21-869101610-620706971-2619405480-1007\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray (User 'Dan')
          O4 - HKUS\S-1-5-21-869101610-620706971-2619405480-1007\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl (User 'Dan')
          O4 - HKUS\S-1-5-21-869101610-620706971-2619405480-1007\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (User 'Dan')
          O4 - HKUS\S-1-5-21-869101610-620706971-2619405480-1007\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" (User 'Dan')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O14 - IERESET.INF: START_PAGE_URL=http://www.pcservicecall.co.uk
          O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
          O16 - DPF: {15AC034D-14DF-4AF8-9D02-29E1F56A8235} (Virgin Digital MusicNet Class) - http://www.virgindigital.co.uk/activeX/VirginWMA.cab
          O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://games.king.com/ctl/kingcomie.cab
          O16 - DPF: {47CEF84E-92D8-4C4A-86D7-CB982889DCC0} (Oberon Media Network Optimizer) - http://mp1.mplay.oberon-media.com/client/flashnet.cab
          O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
          O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game11.zylom.com/activex/zylomgamesplayer.cab
          O17 - HKLM\System\CCS\Services\Tcpip\..\{42674042-8611-4CE1-B2CB-6CA1A71C299A}: NameServer = 195.92.195.95 195.92.195.94
          O17 - HKLM\System\CS1\Services\Tcpip\..\{42674042-8611-4CE1-B2CB-6CA1A71C299A}: NameServer = 195.92.195.95 195.92.195.94
          O20 - Winlogon Notify: ddcyx - C:\WINDOWS\system32\ddcyx.dll
          O20 - Winlogon Notify: tuvurss - C:\WINDOWS\SYSTEM32\tuvurss.dll
          O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
          O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
          O23 - Service: AlProSoft Support Service (AlProSoftSupSvc) - TODO: <Company name> - C:\WINDOWS\system32\alpsfsvc.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
          O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe

          --
          End of file - 9785 bytes

          oddjob



            Hopeful

            Thanked: 4
            • Experience: Beginner
            • OS: Windows 7
            Re: MSN Virus
            « Reply #4 on: April 27, 2007, 02:50:10 AM »
            Hi Gliff

            This may take a few passes to fix completely. After each stage please reply and let us know how your compter is operating. That way we can get a feel for how the fix is progressing.

            Your log shows evidence of Vundo, Conhook and Startpage Trojan infections. Also your java is well out of date.

            I suggest you print this out to help you follow my advice.
             
            ***********************
             
            Make sure you have exposed all Hidden Files & Folders.
             
            To enable the viewing of Hidden files follow these steps:
             
               1. Close all programs so that you are at your desktop.
               2. Double-click on the My Computer icon.
               3. Select the Tools menu and click Folder Options.
               4. After the new window appears select the View tab.
               5. Put a checkmark in the checkbox labeled Display the contents of system folders.
               6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
               7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
               8. Remove the checkmark from the checkbox labeled Hide protected operating system files.
               9. Press the Apply button and then the OK button and close My Computer.
             
            ***********************

            Download VundoFix.exe to your desktop from here ……

            http://www.atribune.org/ccount/click.php?id=4

            >Double-click VundoFix.exe to run it.
            >Click the Scan for Vundo button.
            >Once it's done scanning, click the Remove Vundo button.
            >You will receive a prompt asking if you want to remove the files, click YES
            >Once you click yes, your desktop will go blank as it starts removing Vundo.
            >When completed, it will prompt that it will reboot your computer, click OK.
            >Please post the contents of C:\vundofix.txt and a new HijackThis log in a reply to this thread.
            Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

            ***********************

            Next download AVG Anti Spyware from here ....

            http://www.ewido.net/en/

            It has a fully working 30 day trial period.

            Install it and update it to the latest definitions.

            Do NOT use it yet.

            ***********************

            Now boot to safe mode. Here’s a “how to” if you’re not sure ..

            http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406


            When in safe mode run a full system scan with AVGAS and let it fix what it wants to.

            REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it.

            Reboot to normal mode and use the computer as you would usually do.

            [FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].

            *******************

            Open HJT ... click on scan ... put tick/check marks next to these entries IF they are still present ...

            O2 - BHO: (no name) - {61A6BD5B-642C-4840-A3E0-4268930D165C} - C:\WINDOWS\system32\ddcyx.dll

            O2 - BHO: (no name) - {99FF4998-A2E0-4424-9ABC-4F9EB941D2BE} - C:\WINDOWS\system32\ddcyx.dll

            O2 - BHO: (no name) - {A2E49E61-7F19-4337-8620-60FF0538866B} - C:\WINDOWS\system32\tuvurss.dll

            O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\sgqrbobq.dll

            O20 - Winlogon Notify: ddcyx - C:\WINDOWS\system32\ddcyx.dll

            O20 - Winlogon Notify: tuvurss - C:\WINDOWS\SYSTEM32\tuvurss.dll


            Remember to close ALL open browser windows – including this one – before clicking on “Fix Checked” at the foot of the HijackThis window.

            *******************

            Go to these files in BOLD and delete them IF they are present ....

            C:\WINDOWS\system32\ddcyx.dll
            C:\WINDOWS\system32\tuvurss.dll
            C:\WINDOWS\system32\sgqrbobq.dll

            *******************

            Rehide "Hidden" files & folders by carrying out the reverse procedure to that advised at the start of this post.

            *******************

            Reboot your system into normal mode and use it as you would usually do.

            Post a fresh HJT log and let us know how things are working now. Any improvement? We can then move on and update java.



            OJ







            Gliff

              Topic Starter


              Beginner

              Re: MSN Virus
              « Reply #5 on: April 27, 2007, 03:30:50 AM »
              OK, i've completed the Vundo section. Here's the content of vundofix.txt.


              VundoFix V6.3.20

              Checking Java version...

              Java version is 1.5.0.6
              Old versions of java are exploitable and should be removed.

              Scan started at 10:03:23 27/04/2007

              Listing files found while scanning....

              C:\WINDOWS\system32\ddcyx.dll
              C:\WINDOWS\system32\jkkjjkh.dll
              C:\WINDOWS\system32\tuvurss.dll
              C:\WINDOWS\system32\xycdd.bak1
              C:\WINDOWS\system32\xycdd.bak2
              C:\WINDOWS\system32\xycdd.ini
              C:\WINDOWS\system32\xycdd.ini2
              C:\WINDOWS\system32\yaywvuu.dll

              Beginning removal...

               Attempting to delete C:\WINDOWS\system32\ddcyx.dll
              C:\WINDOWS\system32\ddcyx.dll Has been deleted!

               Attempting to delete C:\WINDOWS\system32\jkkjjkh.dll
              C:\WINDOWS\system32\jkkjjkh.dll Has been deleted!

               Attempting to delete C:\WINDOWS\system32\tuvurss.dll
              C:\WINDOWS\system32\tuvurss.dll Has been deleted!

               Attempting to delete C:\WINDOWS\system32\xycdd.bak1
              C:\WINDOWS\system32\xycdd.bak1 Has been deleted!

               Attempting to delete C:\WINDOWS\system32\xycdd.bak2
              C:\WINDOWS\system32\xycdd.bak2 Has been deleted!

               Attempting to delete C:\WINDOWS\system32\xycdd.ini
              C:\WINDOWS\system32\xycdd.ini Has been deleted!

               Attempting to delete C:\WINDOWS\system32\xycdd.ini2
              C:\WINDOWS\system32\xycdd.ini2 Has been deleted!

               Attempting to delete C:\WINDOWS\system32\yaywvuu.dll
              C:\WINDOWS\system32\yaywvuu.dll Has been deleted!

              Performing Repairs to the registry.
              Done!

              Here's the first part of the latest HJT log;

              Logfile of Trend Micro HijackThis v2.0.0 (BETA)
              Scan saved at 10:29:40, on 27/04/2007
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
              C:\WINDOWS\SOUNDMAN.EXE
              C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
              C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
              C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\Program Files\Common Files\Real\Update_OB\realsched.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\Shareaza\Shareaza.exe
              C:\WINDOWS\system32\LEXBCES.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\LEXPPS.EXE
              C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              C:\WINDOWS\system32\alpsfsvc.exe
              C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
              C:\WINDOWS\system32\CTsvcCDA.exe
              C:\WINDOWS\runservice.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\sistray.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Documents and Settings\Dan\My Documents\Downloads\HiJackThis_v2.exe

              ---> Next Reply

              Gliff

                Topic Starter


                Beginner

                Re: MSN Virus
                « Reply #6 on: April 27, 2007, 03:31:34 AM »
                ---> Here's the second part.

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wanadoo.co.uk
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer Provided By Wanadoo
                R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                O2 - BHO: (no name) - {A2E49E61-7F19-4337-8620-60FF0538866B} - C:\WINDOWS\system32\tuvurss.dll (file missing)
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
                O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\sgqrbobq.dll
                O2 - BHO: (no name) - {F800F741-3B09-4623-B15E-16C9039ABAA1} - C:\WINDOWS\system32\ddcyx.dll (file missing)
                O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\WINDOWS\system32\WSBar.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
                O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O4 - HKLM\..\Run: [AOL_Demo] C:\Applications\Tool\AOL Demo\DSGDemo.exe
                O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                O4 - HKLM\..\Run: [SiSRaid] C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
                O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
                O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
                O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
                O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\taeybfxb.dll",realset
                O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
                O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                O8 - Extra context menu item: Search with Wanadoo - res://C:\WINDOWS\system32\WSBar.dll/VSearch.htm
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O14 - IERESET.INF: START_PAGE_URL=http://www.pcservicecall.co.uk
                O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
                O16 - DPF: {15AC034D-14DF-4AF8-9D02-29E1F56A8235} (Virgin Digital MusicNet Class) - http://www.virgindigital.co.uk/activeX/VirginWMA.cab
                O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
                O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://games.king.com/ctl/kingcomie.cab
                O16 - DPF: {47CEF84E-92D8-4C4A-86D7-CB982889DCC0} (Oberon Media Network Optimizer) - http://mp1.mplay.oberon-media.com/client/flashnet.cab
                O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game11.zylom.com/activex/zylomgamesplayer.cab
                O17 - HKLM\System\CCS\Services\Tcpip\..\{42674042-8611-4CE1-B2CB-6CA1A71C299A}: NameServer = 195.92.195.95 195.92.195.94
                O17 - HKLM\System\CS1\Services\Tcpip\..\{42674042-8611-4CE1-B2CB-6CA1A71C299A}: NameServer = 195.92.195.95 195.92.195.94
                O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                O23 - Service: AlProSoft Support Service (AlProSoftSupSvc) - TODO: <Company name> - C:\WINDOWS\system32\alpsfsvc.exe
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe

                --
                End of file - 9186 bytes

                Gliff

                  Topic Starter


                  Beginner

                  Re: MSN Virus
                  « Reply #7 on: April 27, 2007, 04:24:47 AM »
                  Right, i'm in safe mode on my comp (writing this on a laptop) ~ it's taking a while for AVGAS to work its magic but it's getting there. Unfortuately i'm not gonna have access to the computer over the weeked; so i'm gonna leave it to my Brother to have a go at finishig the advice you gave oddjob. When i'm back on Monday, i'll post a HJT file myself to make sure everything has worked smoothly. Once again, thankyou for your help, it's really appreciated. Thanks.

                  oddjob



                    Hopeful

                    Thanked: 4
                    • Experience: Beginner
                    • OS: Windows 7
                    Re: MSN Virus
                    « Reply #8 on: April 27, 2007, 04:38:34 AM »
                    Open HJT ... click on scan ... put tick/check marks next to these entries IF they are still present ...

                    O2 - BHO: (no name) - {A2E49E61-7F19-4337-8620-60FF0538866B} - C:\WINDOWS\system32\tuvurss.dll (file missing)

                    O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\sgqrbobq.dll

                    O2 - BHO: (no name) - {F800F741-3B09-4623-B15E-16C9039ABAA1} - C:\WINDOWS\system32\ddcyx.dll (file missing)


                    Remember to close ALL open browser windows – including this one – before clicking on “Fix Checked” at the foot of the HijackThis window.

                    ****************

                    Go to these files and delete them IF they are still present ...

                    C:\WINDOWS\system32\tuvurss.dll

                    C:\WINDOWS\system32\sgqrbobq.dll

                    C:\WINDOWS\system32\ddcyx.dll

                    ****************

                    Empty your recycle bin.

                    ****************

                    Make sure your brother completes the part of my earlier instructions on using AVG Anti Spyware. It's a valuable free tool.

                    ****************

                    I see you are using P2P file sharing on this computer. The program itself may not be loaded with malware but the download files may well be. If I were you I would delete all P2P file sharing programs on the computer and not us it again but it's your call.

                    Here are a couple of articles on the subject ....


                    http://p2p.malwareremoval.com/

                    http://www.spywareinfo.com/articles/p2p/


                    Please post a fresh HJT log when all this is done AND an update on how it's behaving now.

                    Thanks.


                    OJ

                    Gliff

                      Topic Starter


                      Beginner

                      Re: MSN Virus
                      « Reply #9 on: April 30, 2007, 04:51:24 AM »
                      Right, i'm back, and all the advice has been followed.

                      Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                      Scan saved at 11:47:33, on 30/04/2007
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
                      C:\WINDOWS\SOUNDMAN.EXE
                      C:\WINDOWS\system32\LEXBCES.EXE
                      C:\WINDOWS\system32\LEXPPS.EXE
                      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
                      C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
                      C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                      C:\WINDOWS\system32\alpsfsvc.exe
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                      C:\WINDOWS\system32\CTsvcCDA.exe
                      C:\WINDOWS\runservice.exe
                      C:\Program Files\QuickTime\qttask.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                      C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
                      C:\WINDOWS\system32\sistray.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\iPod\bin\iPodService.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Documents and Settings\Dan\My Documents\Downloads\HiJackThis_v2.exe

                      ----> Next Post

                      Gliff

                        Topic Starter


                        Beginner

                        Re: MSN Virus
                        « Reply #10 on: April 30, 2007, 04:53:50 AM »
                        --- >

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wanadoo.co.uk
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer Provided By Wanadoo
                        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
                        O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\WINDOWS\system32\WSBar.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
                        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O4 - HKLM\..\Run: [AOL_Demo] C:\Applications\Tool\AOL Demo\DSGDemo.exe
                        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                        O4 - HKLM\..\Run: [SiSRaid] C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
                        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                        O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                        O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                        O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
                        O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
                        O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
                        O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\taeybfxb.dll",realset
                        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                        O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                        O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                        O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                        O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
                        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                        O8 - Extra context menu item: Search with Wanadoo - res://C:\WINDOWS\system32\WSBar.dll/VSearch.htm
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                        O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O14 - IERESET.INF: START_PAGE_URL=http://www.pcservicecall.co.uk
                        O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
                        O16 - DPF: {15AC034D-14DF-4AF8-9D02-29E1F56A8235} (Virgin Digital MusicNet Class) - http://www.virgindigital.co.uk/activeX/VirginWMA.cab
                        O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
                        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                        O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://games.king.com/ctl/kingcomie.cab
                        O16 - DPF: {47CEF84E-92D8-4C4A-86D7-CB982889DCC0} (Oberon Media Network Optimizer) - http://mp1.mplay.oberon-media.com/client/flashnet.cab
                        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                        O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game11.zylom.com/activex/zylomgamesplayer.cab
                        O17 - HKLM\System\CCS\Services\Tcpip\..\{42674042-8611-4CE1-B2CB-6CA1A71C299A}: NameServer = 195.92.195.94 195.92.195.95
                        O17 - HKLM\System\CS1\Services\Tcpip\..\{42674042-8611-4CE1-B2CB-6CA1A71C299A}: NameServer = 195.92.195.94 195.92.195.95
                        O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                        O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                        O23 - Service: AlProSoft Support Service (AlProSoftSupSvc) - TODO: <Company name> - C:\WINDOWS\system32\alpsfsvc.exe
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                        O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe

                        --
                        End of file - 9127 bytes

                        ////// I have to say that the PC is generally less slow, fewer pop-ups and so far no symptoms that existed when this virus-thing got onto the computer. I've uninstalled the P2P i thought you were referring to, i never use it anyway. Thanks, *Very* much for helping.

                        oddjob



                          Hopeful

                          Thanked: 4
                          • Experience: Beginner
                          • OS: Windows 7
                          Re: MSN Virus
                          « Reply #11 on: April 30, 2007, 10:13:46 AM »
                          fewer pop-ups
                          Hmm .... really you should not be getting ANY pop ups at all.

                          Please let us know what pop ups you see (i.e. what sites they are referring you to).

                          We'll now address the java issues.

                          Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

                          Updating Java:
                          • Download the latest version of  Java Runtime Environment (JRE) 6.
                          • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..

                          • Click the "Download" button to the right.
                          • Check the box that says: "Accept License Agreement".
                          • The page will refresh.
                          • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
                          • Close any programs you may have running - especially your web browser.
                          • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
                          • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
                          • Click the Remove or Change/Remove button.
                          • Repeat as many times as necessary to remove each Java versions.
                          • Reboot your computer once all Java components are removed.
                          • Then from your desktop double-click on jre-6u1-windows-i586-p.exe to install the newest version.
                          Update your AVG Anti Spyware to the latest definitions and rescan your computer. Again, let it fix what it wants to.

                          After this please post a fresh HJT log and another update on how things are going.


                          OJ

                          Gliff

                            Topic Starter


                            Beginner

                            Re: MSN Virus
                            « Reply #12 on: April 30, 2007, 01:31:54 PM »
                            Before i download Java; i was going to say that the pop-ups i no longer get are the general ones that tend to come up on websites that perhaps aren't as sensible (www.prowrestling.com is an example of an awful website for pop-ups).

                            What i am beginning to get is pop-ups from a different web browser. Whilst using Firefox, Windows IE comes up with a pop-up occasionally. One was Winantivus (Which i've heard is not good); and a 'your debt' style advert.

                            oddjob



                              Hopeful

                              Thanked: 4
                              • Experience: Beginner
                              • OS: Windows 7
                              Re: MSN Virus
                              « Reply #13 on: May 01, 2007, 01:56:15 AM »
                              You are correct ... Winantivirus is not a genuine "fixing" program. It's malware.

                              Go to this file in your HJT folder .....

                              C:\Documents and Settings\Dan\My Documents\Downloads\HiJackThis_v2.exe

                              ....right click the file and and rename it to newHiJackThis_v2.exe.

                              Run a fresh HJT scan and post the log here with more updates on performance if anything has changed.


                              OJ

                              Gliff

                                Topic Starter


                                Beginner

                                Re: MSN Virus
                                « Reply #14 on: May 05, 2007, 10:06:11 AM »
                                Right, sorry that it's taken a while to respond. Everything seems to be working quite well. There are still a few strange pop-ups, with links that resemble IP addresses, but they very very rarely appear. But *Sighs*, i just got a HJT log and i noticed some new dll files that don't look right.

                                Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                                Scan saved at 17:05:20, on 05/05/2007
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\WINDOWS\system32\LEXBCES.EXE
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\WINDOWS\system32\LEXPPS.EXE
                                C:\WINDOWS\system32\alpsfsvc.exe
                                C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
                                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                C:\WINDOWS\SOUNDMAN.EXE
                                C:\WINDOWS\system32\CTsvcCDA.exe
                                C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                                C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
                                C:\WINDOWS\runservice.exe
                                C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                C:\Program Files\QuickTime\qttask.exe
                                C:\Program Files\iTunes\iTunesHelper.exe
                                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
                                C:\Program Files\AIM\aim.exe
                                C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
                                C:\WINDOWS\system32\sistray.exe
                                C:\WINDOWS\system32\wuauclt.exe
                                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                C:\Program Files\Mozilla Firefox\firefox.exe
                                C:\Program Files\iPod\bin\iPodService.exe
                                C:\WINDOWS\system32\wuauclt.exe
                                C:\Documents and Settings\Dan\My Documents\Downloads\NewHiJackThis_v2.exe

                                ----> Next Post