I have attempted to clean these trojans using Malware Bytes but it keeps coming right back. I have run the scanner both full and quick and it shows up after reboot even after stating "quarantined and deleted succesfully" in the logs.
the files it shows as infected are jgsh40032.dll in windows\system32
4 numbered .manifest files (0200000007d4bc5e1270c, 1270o, 1270p, 1270s)in system 32 and in documents&settings\localservice\application data
as well a key called .fsharproj that MBAM calls (Trojan.BHO) and 3 other registry keys.
.
DDS (Ver_2011-06-12.02) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
Run by Christopher at 15:59:03 on 2011-06-13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3069.2117 [GMT -4:00]
.
AV: PC-cillin Internet Security - Virus Protection *Enabled/Updated* {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: PC-cillin Internet Security - Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\ctfmon.exe
svchost.exe
C:\WINDOWS\System32\svchost.exe -k Akamai
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\untfs32.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\system32\comuid32.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdnserv.exe
C:\WINDOWS\system32\lxdncoms.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Mozilla Firefox 4.0 Beta 8\firefox.exe
C:\Program Files\Mozilla Firefox 4.0 Beta 8\plugin-container.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.ask.com?o=14196&l=dis
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=k8n8wAEb1F_ueJgmVJzQ0Y_uAv8
uInternet Settings,ProxyOverride = *.local
BHO: {0429c23e-ee50-4e44-8b1a-2754cd1c5913} - c:\windows\system32\atmfd32.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.3.7.16.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: 80decf0e: {b9d56cea-68df-c18f-6832-46a4e96ba1bc} - c:\windows\system32\jgsh40032.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
uRun: [OE_OEM] "c:\program files\trend micro\internet security 14\tmas_oe\TMAS_OEMon.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanel.exe" /r
mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [pccguide.exe] "c:\program files\trend micro\internet security 14\pccguide.exe"
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.3.7.16.dll/206
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://zone.msn.com/bingame/popcaploader_v10.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{3CA47A3B-A6D2-45A0-8CB7-915768E73FD1} : DhcpNameServer = 192.168.0.1
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
AppInit_DLLs: c:\windows\system32\jgsh40032.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\christopher\application data\mozilla\firefox\profiles\ttgcozgi.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
============= SERVICES / DRIVERS ===============
.
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2005-8-16 14336]
R2 clr_optimization_v2.0.50727_3232;.NET Runtime Optimization Service v2.0.50727_X86 ;c:\windows\system32\untfs32.exe [2011-5-29 776704]
R2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service --> c:\windows\system32\lxdncoms.exe -service [?]
R2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdnserv.exe [2009-9-19 98984]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\trendm~1\intern~1\Tmntsrv.exe [2007-11-8 345696]
R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\trendm~1\intern~1\TmPfw.exe [2007-11-8 923216]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2007-11-8 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\trendm~1\intern~1\tmproxy.exe [2007-11-8 566872]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2008-2-25 280392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-5-10 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-5-10 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-4-17 39984]
S3 P1171VID;Creative WebCam Notebook #2;c:\windows\system32\drivers\P1171Vid.sys [2009-4-6 91392]
S3 PCDSRVC{E9D79540-57D5953E-06020101}_0;PCDSRVC{E9D79540-57D5953E-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc.pkms [2011-5-12 21744]
S3 physX32;physX32;c:\windows\system32\drivers\physX32.sys [2008-2-25 120960]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-06-13 00:24:55 -------- d-----w- c:\program files\Cobian Backup 8
2011-06-13 00:02:35 167936 ------w- c:\windows\system32\jgsh40032.dll
2011-06-11 09:25:44 190032 ------w- c:\windows\system32\drivers\tmcomm.sys
2011-06-11 09:25:44 -------- d-----w- c:\documents and settings\christopher\log
2011-06-11 03:25:53 -------- d-sha-r- C:\cmdcons
2011-06-11 03:24:26 98816 ------w- c:\windows\sed.exe
2011-06-11 03:24:26 518144 ------w- c:\windows\SWREG.exe
2011-06-11 03:24:26 256512 ------w- c:\windows\PEV.exe
2011-06-11 03:24:26 208896 ------w- c:\windows\MBR.exe
2011-06-05 02:28:25 -------- d-----w- C:\AeriaGames
2011-06-05 02:01:34 -------- d-----w- c:\program files\common files\Akamai
2011-06-03 05:43:11 -------- d-----w- c:\program files\CCleaner
2011-05-30 17:00:18 -------- d-----w- c:\program files\Hi-Rez Studios
2011-05-29 23:30:33 0 ------w- c:\documents and settings\christopher\hyryualhgr.tmp
2011-05-29 22:05:57 776704 ------w- c:\windows\system32\comuid32.exe
2011-05-29 22:05:56 776704 ------w- c:\windows\system32\untfs32.exe
2011-05-29 22:05:56 365568 ------w- c:\windows\system32\atmfd32.dll
2011-05-29 20:21:45 -------- d-----w- c:\documents and settings\christopher\application data\Dwarfs
2011-05-29 20:19:42 -------- d-----w- c:\program files\Microsoft XNA
2011-05-29 03:49:48 -------- d-----w- c:\documents and settings\christopher\application data\SUPERAntiSpyware.com
2011-05-29 03:49:48 -------- d-----w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com
2011-05-29 03:49:44 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-05-29 02:15:20 -------- d-----w- c:\documents and settings\christopher\application data\Dell
2011-05-20 20:49:30 -------- d-----w- C:\Program Files (x86)
2011-05-16 21:37:53 404640 ------w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
==================== Find3M ====================
.
2011-05-29 13:11:30 39984 ------w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-14 17:01:08 260224 ------w- c:\windows\system32\nvdrsdb1.bin
2011-05-14 17:01:08 1 ------w- c:\windows\system32\nvdrssel.bin
2011-05-14 17:00:57 260220 ------w- c:\windows\system32\nvdrsdb0.bin
2011-04-08 05:14:00 944232 ------w- c:\windows\system32\nvdispco3220140.dll
2011-04-08 05:14:00 855656 ------w- c:\windows\system32\nvgenco322060.dll
2011-04-08 05:14:00 61440 ------w- c:\windows\system32\OpenCL.dll
2011-04-08 05:14:00 5210112 ------w- c:\windows\system32\nvcuda.dll
2011-04-08 05:14:00 4111232 ------w- c:\windows\system32\nv4_disp.dll
2011-04-08 05:14:00 2770536 ------w- c:\windows\system32\nvcuvid.dll
2011-04-08 05:14:00 2116894 ------w- c:\windows\system32\nvdata.bin
2011-04-08 05:14:00 2074216 ------w- c:\windows\system32\nvcuvenc.dll
2011-04-08 05:14:00 2027008 ------w- c:\windows\system32\nvapi.dll
2011-04-08 05:14:00 14856192 ------w- c:\windows\system32\nvoglnt.dll
2011-04-08 05:14:00 13000704 ------w- c:\windows\system32\nvcompiler.dll
2011-04-08 05:14:00 12501600 ------w- c:\windows\system32\drivers\nv4_mini.sys
2011-04-08 02:15:38 81920 ------w- c:\windows\system32\nvwddi.dll
2011-04-08 02:15:38 580200 ------w- c:\windows\system32\easyUpdatusAPIU.dll
2011-04-08 02:15:34 277608 ------w- c:\windows\system32\nvmccs.dll
2011-04-08 02:15:34 13891176 ------w- c:\windows\system32\nvcpl.dll
2011-04-08 02:15:34 111208 ------w- c:\windows\system32\nvmctray.dll
2011-04-08 02:15:32 155752 ------w- c:\windows\system32\nvsvc32.exe
2011-04-08 02:15:32 145000 ------w- c:\windows\system32\nvcolor.exe
2011-04-06 20:20:16 91424 ------w- c:\windows\system32\dnssd.dll
2011-04-06 20:20:16 75040 ------w- c:\windows\system32\jdns_sd.dll
2011-04-06 20:20:16 197920 ------w- c:\windows\system32\dnssdX.dll
2011-04-06 20:20:16 107808 ------w- c:\windows\system32\dns-sd.exe
.
============= FINISH: 15:59:51.10 ===============
Attached File(s)
-
attach.txt (23.19K)
Number of downloads: 0 -
ark.log (5.23K)
Number of downloads: 1

Help
This topic is locked

Back to top
button.









