Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I can't stop this virus!


  • This topic is locked This topic is locked
6 replies to this topic

#1 MyBoss is going to kill me

MyBoss is going to kill me

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:21 PM

Posted 04 February 2005 - 03:19 PM

I have try the shredder, Ad-Aware SE, and like three diffrent programs.
Ad-Aare detected it but that is about it. I can't stop this at all... not even hurt it!

I now have to you MSN explorer to use the internet because E.I. dose not change from the homepage (which has bee hijacked).

Please help me!

Here is mine:

Logfile of HijackThis v1.98.2
Scan saved at 3:13:48 PM, on 2/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\System32\aniServ.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\NavNT\vptray.exe
C:\WINDOWS\system32\ap9h4qmo.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\explorer.exe
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\DOCUME~1\Hermes\LOCALS~1\Temp\Temporary Directory 1 for HijackThis1982[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ovjtz.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ovjtz.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ovjtz.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ovjtz.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ovjtz.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ovjtz.dll/sp.html#28129
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {849D904A-DC93-D77C-39BA-5AEC4315B49B} - C:\WINDOWS\system32\sdkzm32.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [iewd32.exe] C:\WINDOWS\iewd32.exe
O4 - HKLM\..\Run: [7.tmp] C:\DOCUME~1\Hermes\LOCALS~1\Temp\7.tmp.exe 1 28129
O4 - HKLM\..\Run: [Windows AdStatus] C:\Program Files\Windows AdStatus\WinStat.exe
O4 - HKLM\..\Run: [9.tmp] C:\DOCUME~1\Hermes\LOCALS~1\Temp\9.tmp.exe 0 28129
O4 - HKLM\..\Run: [tibs5] C:\WINDOWS\system32\tibs5.exe
O4 - HKLM\..\Run: [ap9h4qmo] C:\WINDOWS\system32\ap9h4qmo.exe
O4 - HKLM\..\Run: [23B.tmp] C:\DOCUME~1\Hermes\LOCALS~1\Temp\23B.tmp.exe 1 28129
O4 - HKLM\..\Run: [MSNSysRestore] C:\WINDOWS\system32\pc32.exe bg
O4 - HKLM\..\Run: [23B.tmp.exe] C:\DOCUME~1\Hermes\LOCALS~1\Temp\23B.tmp.exe 2 28129
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [emsw.exe] C:\WINNT\emsw.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Rebate Nation - file://C:\Program Files\Rebate_Nation\Sy5300\Tp5300\scri5300a.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.static.topconverting.com
O15 - Trusted Zone: *.xxxtoolbar.com
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/CDTInc/ie/bridge-c46.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_adult.cab
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://sef.mlxchange.com/Control/MultiSelectComboBox.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1105427568460
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLXchange Client Utils) - http://sef.mlxchange.com/Control/MLXClientUtils.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://sef.mlxchange.com/Control/IRCSharc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = millenniumrealtor.com
O17 - HKLM\Software\..\Telephony: DomainName = millenniumrealtor.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3F02F1D-ABFA-4698-B01F-9B6917A57B13}: NameServer = 192.168.2.50,205.152.144.23,205.152.132.23
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = millenniumrealtor.com

BC AdBot (Login to Remove)

 


m

#2 MyBoss is going to kill me

MyBoss is going to kill me
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:21 PM

Posted 04 February 2005 - 03:20 PM

I work for a mortgage/real state compnay... don't know if that info might help. Im also ona server.

#3 MyBoss is going to kill me

MyBoss is going to kill me
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:21 PM

Posted 07 February 2005 - 12:18 PM

Bump...

Any help? Please

#4 MyBoss is going to kill me

MyBoss is going to kill me
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:21 PM

Posted 09 February 2005 - 04:47 PM

Bump..

I really need help.

#5 MyBoss is going to kill me

MyBoss is going to kill me
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:21 PM

Posted 16 February 2005 - 11:03 AM

those anyone actually read this.. I still can't fix it.

#6 ddeerrff

ddeerrff

    Retired


  • Malware Response Team
  • 2,717 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Upper Midwest, US
  • Local time:12:21 PM

Posted 16 February 2005 - 02:53 PM

Sorry for the delay. The HJT Team looks for posts with no replies, and when you replied to yourself you took yourself 'out of the queue'.

Let's see what we can do...

Open Control Panel then Add/Remove Programs. Look for the following and uninstall them if found:

Windows AdStatus


Download the following file and save it to your desktop:
http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click on the deldomains.inf file and select 'Install'.


A new version of HijackThis has just been released, and it will give us much more info about this infection. Please download and install the newest version, v1.99.1, from this HijackThis download site.

To preserve backup data, HijackThis should be run from it's own folder.

Create a folder on the C: drive called C:\HJT. You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT. Unzip HijackThis into this folder (right click on HijackThis.exe, select 'Extract to' and point to the newly created folder). If required a tutorial is here.

Run HijackThis by opening the C:\HJT folder and double clicking on the Hijackthis.exe file. Select the option 'None of the above, just start the program'. Then click on the Scan button and then on the Save Log button. After specifying the save path (keeping the logs in C:\HJT is a good idea) NotePad will open. Right click and Select All, then right click again and select Copy.

Paste the new HJT log into your next reply.
Derfram
~~~~~~

#7 ddeerrff

ddeerrff

    Retired


  • Malware Response Team
  • 2,717 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Upper Midwest, US
  • Local time:12:21 PM

Posted 28 February 2005 - 04:00 PM

Due to inactivity, this thread will now be closed. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
Derfram
~~~~~~




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users