Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: hit hard by trojan, can't even perform "pre-scans" for forum  (Read 8405 times)

0 Members and 1 Guest are viewing this topic.

stxbones

    Topic Starter


    Greenhorn

    hit hard by trojan, can't even perform "pre-scans" for forum
    « on: December 17, 2008, 04:12:19 PM »
    I'm running legal system:
     Microsoft Windows XP
    Home Edition
    Version 2002
    Service Pack 3


    Computer was acting strange.
    Did scans that i always do using avg and ccleaner and malwarebytes stuff, but nothin is working for me.

    avg came up with some trojan entries:

    1. Infection
        Virus name: - Trojan Horse Downloader.Delf.Dum
        Path: C:\Documents and settings\Application Data\googleklnxv.19819115.exe
        Found:  12/16/08 12:35:50AM

    2. Infection
        Virus name: - Trojan Horse SHeur2.FJD
        Path - C:\WINDOWS\system32\prunnet.exe
        Found - 12/16/08 2:53:47 PM

    3. Infection
        Virus name: Trojan Horse Downloader. Agent. AQCU
        Path: C:\Documents and settings\Local Settings\Temporary Internet Files\Content.IE5\TU5FDA7E\winsinstall[1].exe
        Found - 12/16/08 2:54:36 PM

    4. Infection
        Virus name: Trojan Horse Agent. AQCU
        Path: C:\Documents and settings\Application Data\gadcom\gadcom.exe
        Found:  12/16/08 2:55:50

    5. Infection
        Virus name: Found registry key with reference to infected file C:\Documents and settings\Application Data\gadcom\gadcom.exe
        Path: HKU\s-1-5-21-3087560337-971410402-1518621887-1011\Software\Microsoft\Windows\CurrentVersion\Run\\gadcom
        Found: 12/16/08 2:55:50

    6. Infection
        Virus Name: Trojan Horse Agent.AOQG
        Path: C:\Documents and settings\Application Data\gadcom\gadcom.exe
        Found: 12/16/08 3:08:22PM

    7. Infection
        Virus Name: Trojan Horse Sheur2.FJD
        Path: C:\Documents and Settings\Local Setting\temp\smxacweonr.tmp
        Found: 12/17/08 12:51:23 AM

    8. Infection
        Virus Name: Trojan Horse Sheur2.FJD
        Path: C:\WINDOWS\systems32\prunnet.exe
        FoundL 12/17/08 3:20:13 AM



    and thats it. sorry thats all I have.  I'm not able to do the necessary scans that are needed before you're able to post here in the forum.

    in trying to run AVG after reinstalling it I get this:
    avgwdsvc.exe has encountered a problem and needs to close.
     We are sorry for the inconvenience.

    It tells me theses are the files that were sent with the error report:
    C:\DOCUME~1\sandra!\LOCALS~1\Temp\WERb255.dir00\avgwdsvc.exe.mdmp
    C:\DOCUME~1\sandra!\LOCALS~1\Temp\WERb255.dir00\appcompat.txt

    Then out of nowhere all the components become inactive or outdated then become active again except for  Anti-virus, Anti-Spyware and update manager. I'm not able to update software it will not connect.

    With the rest of the programs CCleaner is not a problem it runs fine, but Malwarebytes Anti Malware will not work at all, when i try to open it nothing happends, same with SUPERAntiSpyware and HIJackthis.

    Even when i try to download software my computer will not connect to any page.
    It seems pages that will help me out my computer doesn't connect to, and the rest it just connects fine.
    I was gonna paste a screen cap or the viruses AVG found, but even paint won't open, when i click on it it says it's unable to prepare a blank document.

    Other symptoms: I can google search but cannot click on results, if i do it will send me to a bogus link, so i have to copy and paste url in address bar.  When I do that, i get 1 firefox popup and 1 IE popup that starts opening just a bunch of tabs, all which are blank.
    Also automatic updates from microsoft, trying turning them on, but nothing happends.
    Will post more later.

    Can anybody help?
    I can't even run the necessary tools that are needed to fix this, and yes i have run them in safemode too.

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: hit hard by trojan, can't even perform "pre-scans" for forum
    « Reply #1 on: December 17, 2008, 05:07:25 PM »
    Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.
    • Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.
    • Then search for TDSSserv.sys
    • Let me know if you find this or not.
    • If you do find it, right click on it, and select “Disable”. Do not try to uninstall it.
    • Also if this is found and you disable it, then reboot and see if you can run the other scans that would not run.

    stxbones

      Topic Starter


      Greenhorn

      Re: hit hard by trojan, can't even perform "pre-scans" for forum
      « Reply #2 on: December 17, 2008, 09:38:19 PM »
      alright found it.
      disabled it.
      had to reboot twice.

      on rebooting avg's resident shield found a bunch of infections. I just removed threats.

      opened firefox to access this forum and resident shield alert came up again.
      39 threats, all some sort of trojan horse virus.
      All detected on open.
      I can't log the file, i can open paint so here are all the screen caps.
      then i'll remove threats and then scan the computer.
       

      heres the list: http://img361.imageshack.us/img361/1894/logir6.jpg


      stxbones

        Topic Starter


        Greenhorn

        Re: hit hard by trojan, can't even perform "pre-scans" for forum
        « Reply #3 on: December 17, 2008, 09:39:48 PM »
        removed threats and avg came back and said specific file not found for each of them.

        now i'm about to begin scanning.

        stxbones

          Topic Starter


          Greenhorn

          Re: hit hard by trojan, can't even perform "pre-scans" for forum
          « Reply #4 on: December 17, 2008, 09:53:22 PM »
          opened avg to do initial scan, got 8 threats.
          all trojan horses
          they're either
          BHO.GQR
          or
          Vundo.CQ
          Vundo.CM
          Vundo.CS

          all specific files not found.

          stxbones

            Topic Starter


            Greenhorn

            Re: hit hard by trojan, can't even perform "pre-scans" for forum
            « Reply #5 on: December 18, 2008, 11:16:20 AM »
            logs so far.

            [attachment deleted by admin]

            stxbones

              Topic Starter


              Greenhorn

              Re: hit hard by trojan, can't even perform "pre-scans" for forum
              « Reply #6 on: December 18, 2008, 01:13:18 PM »
              more logs.

              Malwarebytes' Anti-Malware 1.31
              Database version: 1515
              Windows 5.1.2600 Service Pack 3

              12/18/2008 12:46:37 PM
              mbam-log-2008-12-18 (12-46-37).txt

              Scan type: Quick Scan
              Objects scanned: 77919
              Time elapsed: 25 minute(s), 55 second(s)

              Memory Processes Infected: 0
              Memory Modules Infected: 0
              Registry Keys Infected: 4
              Registry Values Infected: 18
              Registry Data Items Infected: 0
              Folders Infected: 0
              Files Infected: 3

              Memory Processes Infected:
              (No malicious items detected)

              Memory Modules Infected:
              (No malicious items detected)

              Registry Keys Infected:
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e63efb46-c46f-46dc-8cdc-7ecf358f610f} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{e63efb46-c46f-46dc-8cdc-7ecf358f610f} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Delete on reboot.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.

              Registry Values Infected:
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_id (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_options (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_server1 (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_reserv (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_forms (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_certs (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_options (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_ss (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_pstorage (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_command (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_file (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_idproject (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_pauseopt (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_pausecert (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_deletecookie (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_deletesol (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_patch (Backdoor.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_control_crc (Backdoor.Agent) -> Quarantined and deleted successfully.

              Registry Data Items Infected:
              (No malicious items detected)

              Folders Infected:
              (No malicious items detected)

              Files Infected:
              C:\WINDOWS\system32\spdvnc.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              C:\WINDOWS\kernel32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\TDSSixgp.dll (Rootkit.Agent) -> Quarantined and deleted successfully.






              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 2:09:43 PM, on 12/18/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16762)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\LEXBCES.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
              C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              C:\PROGRA~1\AVG\AVG8\avgrsx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Viewpoint\Common\ViewpointService.exe
              C:\WINDOWS\system32\ZuneBusEnum.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
              C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
              C:\Program Files\Real\RealPlayer\RealPlay.exe
              C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
              C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
              C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
              C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
              C:\Program Files\Zune\ZuneLauncher.exe
              C:\Program Files\HPQ\SHARED\HPQWMI.exe
              C:\PROGRA~1\AVG\AVG8\avgtray.exe
              C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
              C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Documents and Settings\sandra!\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
              C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
              C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\WINDOWS\system32\rundll32.exe
              C:\Program Files\Trend Micro\HijackThis\sniper.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = ¸?Ô
              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
              O2 - BHO: (no name) - {4046A27F-B156-4312-8A1B-790EDEF1067D} - C:\WINDOWS\system32\wvUkHYsp.dll (file missing)
              O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
              O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
              O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
              O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
              O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
              O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
              O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
              O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
              O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
              O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
              O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
              O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
              O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
              O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
              O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
              O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
              O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
              O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
              O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
              O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
              O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\sandra!\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
              O4 - S-1-5-18 Startup: AutoTBar.exe (User 'SYSTEM')
              O4 - .DEFAULT Startup: AutoTBar.exe (User 'Default user')
              O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
              O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
              O4 - Global Startup: HotSync Manager.lnk = ?
              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
              O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
              O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
              O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
              O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
              O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
              O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
              O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
              O9 - Extra button: StumbleUpon - {75C9223A-409A-4795-A3CA-08DE6B075B4B} - C:\WINDOWS\system32\shdocvw.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
              O15 - Trusted Zone: *.avsystemcare.com
              O15 - Trusted Zone: *.onerateld.com
              O15 - Trusted Zone: *.safetydownload.com
              O15 - Trusted Zone: *.stumbleupon.com
              O15 - Trusted Zone: *.trustedantivirus.com
              O15 - Trusted Zone: *.virusschlacht.com
              O15 - Trusted Zone: *.avsystemcare.com (HKLM)
              O15 - Trusted Zone: *.onerateld.com (HKLM)
              O15 - Trusted Zone: *.safetydownload.com (HKLM)
              O15 - Trusted Zone: *.trustedantivirus.com (HKLM)
              O15 - Trusted Zone: *.virusschlacht.com (HKLM)
              O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
              O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://download.games.yahoo.com/games/web_games/playfirst/trijinx/TriJinx.1.0.0.55.cab
              O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
              O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
              O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
              O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/luxr/default/mjolauncher.cab
              O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
              O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
              O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/games/web_games/tikgames/cinematycoon/cinematycoon.cab
              O16 - DPF: {DBA8E419-0D5F-439B-A3CC-D01C768D9B51} (DVCDownloaderControl Object) - http://aolsvc.aol.com/onlinegames/sonydavincicode/DVCDownloaderControl.cab
              O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,4946/mcfscan.cab
              O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
              O20 - AppInit_DLLs: avgrsstx.dll spdvnc.dll
              O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
              O20 - Winlogon Notify: hgGyxWMG - hgGyxWMG.dll (file missing)
              O23 - Service: afisicx  Manages  messages (afisicx) - Unknown owner - C:\WINDOWS\system32\afisicx.exe (file missing)
              O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe (file missing)
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
              O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              O23 - Service: mabidwe  Service (mabidwe) - Unknown owner - C:\WINDOWS\system32\mabidwe.exe (file missing)
              O23 - Service: MBackMonitor - Unknown owner - C:\Program Files\McAfee\MBK\MBackMonitor.exe (file missing)
              O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
              O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
              O23 - Service: noxtcyr  Event propagation service (noxtcyr) - Unknown owner - C:\WINDOWS\system32\noxtcyr.exe (file missing)
              O23 - Service: noytcyr  Service (noytcyr) - Unknown owner - C:\WINDOWS\system32\noytcyr.exe (file missing)
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              O23 - Service: roxtctm  pass-through (roxtctm) - Unknown owner - C:\WINDOWS\system32\roxtctm.exe (file missing)
              O23 - Service: roytctm  Service (roytctm) - Unknown owner - C:\WINDOWS\system32\roytctm.exe (file missing)
              O23 - Service: sotpeca  Manages  messages (sotpeca) - Unknown owner - C:\WINDOWS\system32\sotpeca.exe (file missing)
              O23 - Service: soxpeca  Service (soxpeca) - Unknown owner - C:\WINDOWS\system32\soxpeca.exe (file missing)
              O23 - Service: tdydowkc  Service (tdydowkc) - Unknown owner - C:\WINDOWS\system32\tdydowkc.exe (file missing)
              O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
              O23 - Service: wsldoekd  Corporation inc. (wsldoekd) - Unknown owner - C:\WINDOWS\system32\wsldoekd.exe (file missing)

              --
              End of file - 14879 bytes


              stxbones

                Topic Starter


                Greenhorn

                Re: hit hard by trojan, can't even perform "pre-scans" for forum
                « Reply #7 on: December 18, 2008, 01:14:18 PM »
                thats it.

                am i forgetting any logs?

                evilfantasy

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Calm like a bomb
                • Thanked: 493
                • Experience: Experienced
                • OS: Windows 11
                Re: hit hard by trojan, can't even perform "pre-scans" for forum
                « Reply #8 on: December 18, 2008, 07:07:14 PM »
                Open HijackThis and select Do a system scan only.

                Place a check mark next to the following entries: (if there)

                - R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = ¸?Ô
                - O2 - BHO: (no name) - {4046A27F-B156-4312-8A1B-790EDEF1067D} - C:\WINDOWS\system32\wvUkHYsp.dll (file missing)
                - O20 - AppInit_DLLs: avgrsstx.dll spdvnc.dll
                - O20 - Winlogon Notify: hgGyxWMG - hgGyxWMG.dll (file missing)


                Important: Close all windows except for HijackThis and then click Fix checked.

                Exit HijackThis.

                ----------

                Before you begin the SDFix instructions you should copy these instructions in a Notepad file and save them to your desktop or print them for easy reference. Much of SDFix will be done in Safe mode and you will be unable to access this web page after booting into Safe mode.

                Download SDFix by AndyManchesta and save it to your desktop.

                When using this tool, you must use the Administrator's account or an account with Administrative rights

                • Double click SDFix.exe and it will extract the files to %systemdrive%
                • (this is the drive that contains the Windows Directory, typically C:\SDFix).
                • DO NOT use it just yet.
                Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

                Open the SDFix folder and double click RunThis.bat to start the script.
                • Type Y to begin the cleanup process.
                • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
                • Press any Key and it will restart the PC.
                • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
                • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
                • Copy and paste the contents of the results file Report.txt in your next reply along with a new HijackThis log (from normal boot mode).