Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HTJ Log - jjankowsk (for RLOWE PC)


  • This topic is locked This topic is locked
5 replies to this topic

#1 jjankowsk

jjankowsk

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:37 AM

Posted 15 July 2004 - 09:28 AM

The PC (Win XP Pro in network environment) on bootup - Norton Corp Edition popup says file C:\windows\tgbcdelibrary32.dll is infected with PWStealTrojan and has quarantined it. I also get a windows popup saying "modeule32.exe" is also infected and is also quarantined. I also note that IE has been hijacked (Blank start page) and the "WhenUScan" toolbar is active. Lot of pop-up activity. Loss of access to some network drives.
==
The log is below.
===
Logfile of HijackThis v1.98.0
Scan saved at 9:51:40 AM, on 7/15/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: ohb - {4D568F0F-8AC9-40AB-88B7-415134C78777} - C:\WINDOWS\System32\winb2s32.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: Begin2Search.com Bar - {52FE5233-367C-4EFB-BDD7-0BE4D212C107} - C:\WINDOWS\System32\winb2s32.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [intdctrr] C:\WINDOWS\System32\idctup20.exe
O4 - HKLM\..\Run: [WhenUSearch] C:\Program Files\WhenUSearch\Search.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKCU\..\Run: [tgbcde] C:\WINDOWS\tgbcde\module32.exe arg1
O4 - Startup: Download Plus.lnk = C:\Documents and Settings\rlowe\Application Data\DownloadPlus.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Instant Update Reminder.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\iupkjpcj.exe
O16 - DPF: {11111111-1111-1111-1111-111111111113} - mhtml:C:\\NO_SUCH_MHTML.MHT!http://66.79.166.152/go.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = DOMAIN.BIZ
O17 - HKLM\Software\..\Telephony: DomainName = DOMAIN.BIZ
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = DOMAIN.BIZ
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = DOMAIN.BIZ

BC AdBot (Login to Remove)

 


#2 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:37 AM

Posted 15 July 2004 - 11:13 AM

First,

Click on start, settings, control panel and double-click on add/remove programs. From with add/remove program uninstall the following if they exist:

WhenU
WhenUSearch
Web Rebates
Begin2Search

Then,

I want you to fix some of those entries. Please do the following:

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Run Hijackthis again, click scan, and Put a checkmark next to each of these. Then click the Fix button
R3 - Default URLSearchHook is missing
O2 - BHO: ohb - {4D568F0F-8AC9-40AB-88B7-415134C78777} - C:\WINDOWS\System32\winb2s32.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: Begin2Search.com Bar - {52FE5233-367C-4EFB-BDD7-0BE4D212C107} - C:\WINDOWS\System32\winb2s32.dll
O4 - HKLM\..\Run: [intdctrr] C:\WINDOWS\System32\idctup20.exe
O4 - HKLM\..\Run: [WhenUSearch] C:\Program Files\WhenUSearch\Search.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKCU\..\Run: [tgbcde] C:\WINDOWS\tgbcde\module32.exe arg1
O4 - Startup: Download Plus.lnk = C:\Documents and Settings\rlowe\Application Data\DownloadPlus.exe
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\iupkjpcj.exe
O16 - DPF: {11111111-1111-1111-1111-111111111113} - mhtml:C:\\NO_SUCH_MHTML.MHT!http://66.79.166.152/go.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = DOMAIN.BIZ
O17 - HKLM\Software\..\Telephony: DomainName = DOMAIN.BIZ
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = DOMAIN.BIZ
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = DOMAIN.BIZ


Reboot your computer into Safe Mode and delete the following files:

Then delete these files or directories (Do not be concerned if they do not exist)
C:\WINDOWS\System32\winb2s32.dll
C:\Program Files\WhenUSearch\
C:\Program Files\Web_Rebates\
C:\WINDOWS\tgbcde

Disable System Restore. You can find instructions on how to enable and reenable system restore here:

Managing Windows Millenium System Restore
or

Windows XP System Restore Guide

Renable system restore with instructions from tutorial above

Reboot your computer to go back to normal mode and post a new log.

#3 jjankowsk

jjankowsk
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:37 AM

Posted 15 July 2004 - 12:02 PM

Thanks Grinler - much appreciated. Here is the new log:
==
Logfile of HijackThis v1.98.0
Scan saved at 12:56:04 PM, on 7/15/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\U.S. Robotics\ControlCenter\Reminder.exe
C:\WINDOWS\system32\userinit.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Instant Update Reminder.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = DOMAIN.BIZ
O17 - HKLM\Software\..\Telephony: DomainName = DOMAIN.BIZ
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = DOMAIN.BIZ
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = DOMAIN.BIZ

#4 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:37 AM

Posted 15 July 2004 - 07:51 PM

Did you purposely add domain.biz as your domain on your computer?

If not you can remove these if you wish :

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = DOMAIN.BIZ
O17 - HKLM\Software\..\Telephony: DomainName = DOMAIN.BIZ
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = DOMAIN.BIZ
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = DOMAIN.BIZ

Reboot and post a last log, but you are already looking clean

#5 jjankowsk

jjankowsk
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:37 AM

Posted 16 July 2004 - 05:04 AM

Yes, DOMAIN.BIZ is our server's domain name.

Thanks again, Grinler.

#6 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:37 AM

Posted 16 July 2004 - 11:35 AM

Ok great. Then you are clean :thumbsup:

Now that you are clean, please follow this simple step and use the following programs:

Visit http://www.windowsupdate.com regularly. This will ensure that you have the latest patches for your operating system installed. If there are new updates to install, install all the critical updates, reboot and revisit the site until there are no more critical updates.

I would strongly advise you download and install SpywareBlaster and Spybot (With TeaTimer)

Tutorials and download locations for each programs can be found below. They will help to prevent a lot of future reinfections.

Using SpywareBlaster to protect your web browser

Using Spybot - Search & Destroy to remove Spyware from Your Computer

Glad i was able to help.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users