Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Explorer being assaulted by trojan  (Read 22602 times)

0 Members and 1 Guest are viewing this topic.

CBMatt

  • Mod & Malware Specialist


  • Prodigy

  • Sad and lonely...and loving every minute of it.
  • Thanked: 167
    • Yes
  • Experience: Experienced
  • OS: Windows 7
Re: Explorer being raped by trojan
« Reply #30 on: July 21, 2007, 12:02:32 AM »
I'm not even  downloading warez  and everybody knows I love my warez.
Which is bound to be the cause of 90% of your problems.
Quote
An undefined problem has an infinite number of solutions.
—Robert A. Humphrey

mycompisbroke

  • Guest
Re: Explorer being raped by trojan
« Reply #31 on: July 22, 2007, 12:53:36 PM »
Well thats commen sense. I know its probably the cause of most of my problems.

Fed

  • Moderator


  • Sage
  • Thanked: 35
    • Experience: Experienced
    • OS: Windows XP
    Re: Explorer being raped by trojan
    « Reply #32 on: July 22, 2007, 05:45:34 PM »
    Don't forget to keep a Firewall, AV and AS uptodate and running in realtime.

    mycompisbroke

    • Guest
    Re: Explorer being raped by trojan
    « Reply #33 on: July 24, 2007, 07:11:30 PM »
    Someone post a link to a hijackthis that works please.

    Richenstony

    • Guest
    Re: Explorer being raped by trojan
    « Reply #34 on: July 24, 2007, 08:30:21 PM »

    mycompisbroke

    • Guest
    Re: Explorer being assaulted by trojan
    « Reply #35 on: July 25, 2007, 11:51:00 AM »
    hijackthislog

    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 12:58:37 PM, on 7/25/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    C:\WINDOWS\Explorer.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
    C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\lich.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AIM2.exe
    C:\WINDOWS\wanmpsvc.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
    C:\Program Files\Verizon Online\bin\mpbtn.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
    c:\progra~1\mcafee.com\vso\mcvsftsn.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\EarthLink TotalAccess\FastLane\IPClient.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Travis\My Documents\My

    mycompisbroke

    • Guest
    Re: Explorer being assaulted by trojan
    « Reply #36 on: July 25, 2007, 11:51:40 AM »
    Videos\hideme\HiJackThis_v2.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginia.edu/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\msiexec.exe
    O2 - BHO: SuperAdBlockerBHO Class - {00000000-6C30-11D8-9363-000AE6309654} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABBHO.DLL (file missing)
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
    O2 - BHO: PnIEBrowserHelperObj Class - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: (no name) - {6064348C-FF1E-42B3-A90A-4B35AF0AB67E} - C:\WINDOWS\system32\jkklj.dll
    O2 - BHO: Toolbar Helper - {D44BBB61-E17F-4AE6-A502-8D7E0B29E616} - C:\WINDOWS\system32\s1940.dll
    O2 - BHO: (no name) - {D80C4E21-C346-4E21-8E64-20746AA20AEB} - (no file)
    O2 - BHO: (no name) - {F4002052-AB29-4B33-8C8D-0E99084564EC} - C:\WINDOWS\system32\cbxyaax.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
    O3 - Toolbar: Stumble&Upon - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\WINDOWS\system32\s1940.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
    O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
    O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
    O4 - HKLM\..\Run: [lich] lich.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [pas_check] C:\Program Files\SystemDoctor 2006 Free\pasmon.exe
    O4 - HKLM\..\Run: [NI.UWA7P_0001_N91M0809] "C:\Documents and Settings\Travis\My Documents\My Videos\WinAntiVirusPro2007FreeInstall.exe" -nag

    mycompisbroke

    • Guest
    Re: Explorer being assaulted by trojan
    « Reply #37 on: July 25, 2007, 11:52:13 AM »
    O4 - HKLM\..\Run: [MemoryManager] rundll32.exe "C:\WINDOWS\system32\ihhpwfge.dll",forkonce
    O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: AIM2.exe
    O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
    O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
    O8 - Extra context menu item: StumbleUpon: &Blog This - res://C:\WINDOWS\system32\s1940.dll/blogimage
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: *.stumbleupon.com
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/CursorManiaFWBInitialSetup1.0.0.15.cab
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX28.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{EBE3764D-FAD0-4AC0-9E4D-0B10C70E8BE1}: NameServer = 207.69.188.187 207.69.188.186
    O20 - Winlogon Notify: cbxyaax - C:\WINDOWS\SYSTEM32\cbxyaax.dll
    O20 - Winlogon Notify: jkklj - C:\WINDOWS\system32\jkklj.dll
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    --
    End of file - 10811 bytes

    Richenstony

    • Guest
    Re: Explorer being assaulted by trojan
    « Reply #38 on: July 25, 2007, 11:59:20 AM »
    O4 - HKLM\..\Run: [pas_check] C:\Program Files\SystemDoctor 2006 Free\pasmon.exe  -fix that


    More information on what it is i have just asked you to fix.... http://www.symantec.com/security_response/writeup.jsp?docid=2006-062015-2622-99&tabid=2


    I also think i see a few Trojan down loaders , im still learning how to read the log correctly.... i think i should let unlovedwarrior and cbmatt help you out here ....... unloved is this a Trojan down loader.

    C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe

        * Backup any important data first!!
        * Re-configure Windows Explorer to Show Hidden Files & Folders.
        * Ensure you're familiar with restarting in Safe Mode.
        * Perform all actions in the order given.
        * If you're unsure of anything, stop and ask! Don't keep on going!
        * Please reply to this thread. Do not start a new topic.
        * Stick with it till you're given the all clear.
        * REMEMBER, ABSENCE OF SYMPTOMS DOES NOT ALWAYS MEAN A CLEAN  COMPUTER!!


    « Last Edit: July 25, 2007, 12:09:46 PM by Richenstony »

    mycompisbroke

    • Guest
    Re: Explorer being assaulted by trojan
    « Reply #39 on: July 25, 2007, 12:50:24 PM »
    Im gona wait for cbmatt to come on because hes the smartest of yall (no offense to richenstony ) . Also I already knew system doctor was ad ware when i saw it so i got rid of that  but thats all.

    Richenstony

    • Guest
    Re: Explorer being assaulted by trojan
    « Reply #40 on: July 25, 2007, 12:55:17 PM »
    lol none taken i will remember that

    unlovedwarrior



      Guru

    • someday this name will be known
    • Thanked: 13
      Re: Explorer being assaulted by trojan
      « Reply #41 on: July 25, 2007, 03:35:39 PM »
      hi  mycomp. you might want to get superantispyware install reboot into safe mode and do a full scan then start run and enter chkdsk /f ( notice the space between the k and the /f ) press ok

      a box will pop up and ask to run on next reboot enter y and press enter, then restart and let it run.

      when you get back into normal mode try this online scanner

      remove anything found and right down any vulnerabilities it finds.

      report back on the vulnerabilities and any infection it finds.


      these don't look friendly i can't find anything on them.
      O4 - HKLM\..\Run: [MemoryManager] rundll32.exe "C:\WINDOWS\system32\ihhpwfge.dll",forkonce

      O4 - HKLM\..\Run: [lich] lich.exe

      MemoryManager do you know what program this is?


      thoses are just some things i picked out, lets wait for fed dl65 or cbmatt to reply on the hjt log, but try my other suggestions and see oh they work out.

      mycompisbroke

      • Guest
      Re: Explorer being assaulted by trojan
      « Reply #42 on: July 25, 2007, 04:20:09 PM »
      The buffer overload thing is back. <_< And the patch i downloaded is still working so i guess it found a way around it. Also I think a trojan somehow deleted hijackthis because i saw it magicly disapear before my eyes. <_<

      mycompisbroke

      • Guest
      Re: Explorer being assaulted by trojan
      « Reply #43 on: July 25, 2007, 04:21:23 PM »
      Great. It disabled my pop up blockers.

      unlovedwarrior



        Guru

      • someday this name will be known
      • Thanked: 13
        Re: Explorer being assaulted by trojan
        « Reply #44 on: July 25, 2007, 04:23:29 PM »
        hi  mycomp. you might want to get superantispyware install reboot into safe mode and do a full scan then start run and enter chkdsk /f ( notice the space between the k and the /f ) press ok

        a box will pop up and ask to run on next reboot enter y and press enter, then restart and let it run.

        when you get back into normal mode try this online scanner

        remove anything found and right down any vulnerabilities it finds.

        report back on the vulnerabilities and any infection it finds.


        these don't look friendly i can't find anything on them.
        O4 - HKLM\..\Run: [MemoryManager] rundll32.exe "C:\WINDOWS\system32\ihhpwfge.dll",forkonce

        O4 - HKLM\..\Run: [lich] lich.exe

        MemoryManager do you know what program this is?


        thoses are just some things i picked out, lets wait for fed dl65 or cbmatt to reply on the hjt log, but try my other suggestions and see oh they work out.
        try this stuff yet