Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Bad pop ups


  • This topic is locked This topic is locked
18 replies to this topic

#1 Pandy

Pandy

    Bleepin'


  • Members
  • 9,559 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:10:32 AM

Posted 21 May 2005 - 08:26 PM

Hallo All :thumbsup: I am posting this for my best friend. Right now in IE I am having trouble staying logged in here at BC. Pop ups are slaying me here and some are adult ones too. Well my friend has run Ad-aware and Spybot but spybot is getting some sort of error that I have not seen yet. Anyhow I thought I would post a log for her. I have tried to log her in. Her member name is SueB.. just in case she manages to post to the thread here. LOL This is a mess!!!

Logfile of HijackThis v1.99.1
Scan saved at 9:24:31 PM, on 5/21/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\PROGRA~1\Toolbar\TBPSSvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\Common Files\WinTools\WToolsS.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\system32\ltmsg.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\program files\zangoclient\zanu.exe
C:\WINNT\system32\Qkivtq.exe
C:\PROGRA~1\Toolbar\TBPS.exe
C:\PROGRA~1\Toolbar\PIB.exe
C:\WINNT\system32\rpcda.exe
c:\PROGRA~1\Toolbar\radio.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINNT\system32\ukunpp.exe
C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
C:\Program Files\Common Files\WinTools\WSup.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\system32\rasatmsg.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\CxtPls\CxtPls.exe
C:\Program Files\NaviSearch\bin\nls.exe
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\drvi\fbralitsay.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\my hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50245
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINNT\system32\Userinit.exe
O2 - BHO: PynixObj Class - {00000000-DD60-0064-6EC2-6E0100000000} - C:\WINNT\Pynix.dll
O2 - BHO: (no name) - {00000049-8F91-4D9C-9573-F016E7626484} - (no file)
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINNT\cfgmgr52.dll
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINNT\systb.dll
O2 - BHO: (no name) - {4622EA50-2992-FC3C-930F-865170E4EE96} - C:\WINNT\drvi\fbralitsay.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O2 - BHO: Fizzlebar.clsFwBar - {9056A11F-5EA6-4A67-BDE9-8D3C7C453DAC} - c:\sysfwb\1532661468\iefwbar.dll
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINNT\system32\nvms.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINNT\system32\msbe.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [¢ª¸ï0ÓÈÜÅè]wø*8@ýžáC:\Program Files\ISTsvc\istsvc.exe] C:\WINNT\fkwdsodi.exe
O4 - HKLM\..\Run: [Zhtvdwk] C:\Program Files\Ujxskr\Uamiok.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [zanu] c:\program files\zangoclient\zanu.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nvjgye] c:\winnt\system32\nvjgye.exe
O4 - HKLM\..\Run: [farmmext] C:\WINNT\farmmext.exe
O4 - HKLM\..\Run: [PSoft1] C:\WINNT\system32\psoft1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINNT\system32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINNT\system32\wintask.exe
O4 - HKLM\..\Run: [secure] C:\WINNT\system32\Qkivtq.exe
O4 - HKLM\..\Run: [checkrun] C:\winnt\system32\eliterhw32.exe
O4 - HKLM\..\Run: [webscan] C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe -k
O4 - HKLM\..\Run: [GMedia2] C:\WINNT\system32\GSMedia3.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINNT\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [5FrR38h] rpcda.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINNT\system32\ukunpp.exe reg_run
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINNT\wupdt.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [Ko05RUNsi] rasatmsg.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZRxdm069YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\system32\Shdocvw.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: World Class Solitaire by pogo - http://game4.pogo.com/applet-6.1.1.21/worl...s-ob-assets.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab34120.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Download...e/bridge-c9.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAcc...e/bridge-c6.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...up1.0.0.8-2.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com/files2/Install.cab
O16 - DPF: {2F5B39C5-C6F5-447A-A946-48B382C53985} - http://www.pacimedia.com/install/pcs_0015.exe
O16 - DPF: {31DDC1FD-CEA3-4837-A6DC-87E67015ADC9} - http://akamai.downloadv3.com/binaries/IA/svcsysnet32_EN.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {41D1977F-4161-4720-800F-EA4903983A38} (Jigsaw Genius Control) - http://www.worldwinner.com/games/v42/jigsaw/jigsaw.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP...l_v1-0-3-24.cab
O16 - DPF: {4E7BD74F-2B8D-469E-DEFA-EB76B1D5FA7D} - http://grouplotto.aavalue.com/PrizeMachine/GL_live.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v49/bjattack/bjattack.cab
O16 - DPF: {5E8FD788-C323-4357-AB76-7CBCEFBA573C} (SpyBouncer.SBDownloader) - http://www.spybouncer.com/downloader.ocx
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y...ctl_0_0_0_2.ocx
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} (ZPA_WheelOfFortune Object) - http://zone.msn.com/bingame/zpagames/zpa_wof.cab34501.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinner.com/games/v44/sol/sol.cab
O16 - DPF: {99410CDE-6F16-42ce-9D49-3807F78F0287} (ClientInstaller Class) - http://www.zango.com/GetZango/Download/zangoax.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v61/swapit/swapit.cab
O16 - DPF: {B2F0618A-7C27-4900-B8D6-61D39B91FD81} (gc Class) - http://www.gamecolony.com/gcatl.cab
O16 - DPF: {B4831DED-3A57-4CC6-9E4B-0E7C5B08DBF4} - http://www.alwaysupdatednews.com/install/aun_0019.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BA14D944-0D8C-4F16-A950-6E53EEBB558F} - http://akamai.downloadv3.com/binaries/P2EC..._1040_EN_XP.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d.../ITDetector.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/shpo/default/shapo.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab34035.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/bingame/hsol/default/SCEWebLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: ptssvc - KODAK - C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
O23 - Service: WebSeach Toolbar support NT service (TBPSSvc) - Unknown owner - C:\PROGRA~1\Toolbar\TBPSSvc.exe
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe
O23 - Service: ZESOFT - Unknown owner - C:\WINNT\zeta.exe

Ok I have got her Firefox and I am able to post properly now. Not a single pop up now and I can stay logged in here!!! lol She will be happy. I am afraid to look in her ad remove programs for fear what is in there. LOL

Edited by Pandy, 21 May 2005 - 08:51 PM.

Do not anticipate trouble, or worry about what may never happen. Keep in the sunlight.

Hide not your talents. They for use were made. What's a sundial in the shade?

~ Benjamin Franklin

I am a Bleeping Computer fan! Are you?

Facebook

Follow us on Twitter


BC AdBot (Login to Remove)

 


m

#2 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:32 AM

Posted 21 May 2005 - 10:26 PM

Hi Pandy. Well, we certainly have our work cut out for us here so let's get started. Please print these directions and then proceed with the following steps in order.

Step #1

Download CCleaner and install it but do not run it yet.

Download and install ewido security suite. Update the program and then close it. Do not run it yet.

Now we need to remove a service.

Part 1
  • Click Start>Run, type services.msc into the Open editbox and click the Ok button.
  • Locate the WebSeach Toolbar support NT service service and click the Stop button.
  • In the Startup type dropdown select Disabled.
  • Click the Apply button and then the Ok button.
  • Repeat the above steps for the following services:
    • WinTools for IE service
      ZESOFT
  • Close the Services window
Part 2
  • Click Start>Run, type cmd into the Open editbox and click the Ok button.
  • Copy/paste each line below into the Command Prompt window and press the Enter key after each one:
    • sc delete TBPSSvc
      sc delete WinToolsSvc
      sc delete ZESOFT
  • Close the Command Prompt window
Step #2

Start in Safe Mode Using the F8 method:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until the boot menu appears.
  • Use the arrow keys to select the Safe Mode menu item.
  • Press the Enter key.
Step #3

Start HijackThis and click the Scan button to perform a scan. Look for the following items and click in the checkbox in front of each item to select it:R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50245
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINNT\system32\Userinit.exe
O2 - BHO: PynixObj Class - {00000000-DD60-0064-6EC2-6E0100000000} - C:\WINNT\Pynix.dll
O2 - BHO: (no name) - {00000049-8F91-4D9C-9573-F016E7626484} - (no file)
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINNT\cfgmgr52.dll
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINNT\systb.dll
O2 - BHO: (no name) - {4622EA50-2992-FC3C-930F-865170E4EE96} - C:\WINNT\drvi\fbralitsay.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O2 - BHO: Fizzlebar.clsFwBar - {9056A11F-5EA6-4A67-BDE9-8D3C7C453DAC} - c:\sysfwb\1532661468\iefwbar.dll
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINNT\system32\nvms.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINNT\system32\msbe.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [¢ª¸ï0ÓÈÜÅè]wø*8@ýžáC:\Program Files\ISTsvc\istsvc.exe] C:\WINNT\fkwdsodi.exe
O4 - HKLM\..\Run: [Zhtvdwk] C:\Program Files\Ujxskr\Uamiok.exe
O4 - HKLM\..\Run: [zanu] c:\program files\zangoclient\zanu.exe
O4 - HKLM\..\Run: [nvjgye] c:\winnt\system32\nvjgye.exe
O4 - HKLM\..\Run: [farmmext] C:\WINNT\farmmext.exe
O4 - HKLM\..\Run: [PSoft1] C:\WINNT\system32\psoft1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINNT\system32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINNT\system32\wintask.exe
O4 - HKLM\..\Run: [secure] C:\WINNT\system32\Qkivtq.exe
O4 - HKLM\..\Run: [checkrun] C:\winnt\system32\eliterhw32.exe
O4 - HKLM\..\Run: [GMedia2] C:\WINNT\system32\GSMedia3.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINNT\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [5FrR38h] rpcda.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [KavSvc] C:\WINNT\system32\ukunpp.exe reg_run
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINNT\wupdt.exe
O4 - HKCU\..\Run: [Ko05RUNsi] rasatmsg.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZRxdm069YYUS
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Download...e/bridge-c9.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAcc...e/bridge-c6.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...up1.0.0.8-2.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {99410CDE-6F16-42ce-9D49-3807F78F0287} (ClientInstaller Class) - http://www.zango.com/GetZango/Download/zangoax.cab
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll

Now close ALL open windows except HijackThis and click the Fix Checked button to finish the repair.

Step #4

We need to make sure all hidden files are showing so please:
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide file extensions for known types option.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Find the following files/folders and delete them (don't worry if they are already gone):C:\PROGRAM FILES\Toolbar\ <--folder
C:\Program Files\CxtPls\ <--folder
C:\Program Files\Ujxskr\ <--folder
c:\program files\zangoclient\ <--folder
C:\Program Files\AutoUpdate\ <--folder
C:\Program Files\NaviSearch <--folder
C:\Program Files\BullsEye Network\ <--folder
C:\PROGRAM FILES\COMMON FILES\WinTools\ <--folder
c:\sysfwb\ <--folder
C:\WINNT\Pynix.dll
C:\WINNT\cfgmgr52.dll
C:\WINNT\systb.dll
C:\WINNT\fkwdsodi.exe
C:\WINNT\farmmext.exe
C:\WINNT\wupdt.exe
C:\WINNT\zeta.exe
C:\WINNT\drvi\fbralitsay.dll
C:\WINNT\drvi\fbralitsay.exe
C:\WINNT\system32\nvms.dll
C:\WINNT\system32\msbe.dll
c:\winnt\system32\nvjgye.exe
C:\WINNT\system32\psoft1.exe
C:\WINNT\system32\exp.exe
C:\WINNT\system32\wintask.exe
C:\WINNT\system32\Qkivtq.exe
C:\winnt\system32\eliterhw32.exe (and any other file with a name like elite***32.exe)
C:\WINNT\system32\GSMedia3.exe
C:\WINNT\system32\ukunpp.exe
C:\WINNT\system32\rasatmsg.exe
C:\WINNT\system32\rpcda.exe

Step #5

Start CCleaner and click on the Run Cleaner button in the lower right-hand corner. When it is finished close CCleaner.

Step #6

Start ewido and click on the Scanner button. On the Scanner page click on My Computer and then click the Start button to begin the scan. Let it run to completion and fix anything that it finds.

Step #7

Reboot normally and run at least 2 of the following on-line virus scans:Trend Micro Housecall
BitDefender On-Line Virus Scan
Panda ActiveScan
eTrust Antivirus Web Scanner
Make sure that you choose "fix" or "clean".

Step #8

AdAware SE

Download, install, update, configure and run a scan with Ad-aware SE:
  • Download and Install AdAware SE Personal, keeping the default options. However, some of the settings will need to be changed before your first scan.
  • Close ALL windows except Ad-Aware SE.
  • Click on the‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.
  • Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window:
    • In the ‘General’ window make sure the following are selected in green:
      • Under Safety:
        • Automatically save log-file
      • Automatically quarantine objects prior to removal
      • Safe Mode (always request confirmation)
    • Under Definitions:
      • Prompt to update outdated definitions - set the number of days
  • Click on the ‘Scanning’ button on the left and select in green:
    • Under Driver, Folders & Files:
      • Scan Within Archives
    • Under Select drives & folders to scan:
      • choose all hard drives
    • Under Memory & Registry: all green
      • Scan Active Processes
      • Scan Registry
      • Deep Scan Registry
      • Scan my IE favorites for banned URL’s
      • Scan my Hosts file
  • Click on the ‘Advanced’ button on the left and select in green:
    • Under Shell Integration:
      • Move deleted files to recycle bin
    • Under Logfile Detail Level: all green
      • include addtional object information
      • DESELECT - include negligible objects information
      • include environment information
    • Under Alternate Data Streams:
      • Don't log streams smaller than 0 bytes
      • Don't log ADS with the following names: CA_INOCULATEIT
  • Click the ‘Tweak’ button and select in green:
    • Under ‘Scanning Engine’:
      • Unload recognized processes during scanning
      • Scan registry for all users instead of current user only
    • Under ‘Cleaning Engine’:
      • Let Windows remove files in use at next reboot
    • Under Log Files:
      • Include basic Ad-aware SE settings in logfile
      • Include additional Ad-aware SE settings in logfile
      • Please do not check: Include Module list in logfile
  • Click on ‘Proceed’ to save the settings.
  • Click ‘Start’
  • Choose 'Perform Full System Scan'
  • DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.
  • Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.
  • If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window
  • Save the log file when it asks and then click ‘Finish’
  • REBOOT to complete the removal of what Ad-Aware SE found.
Step #9

OK. Reboot your computer normally, start HijackThis and perform a new scan. Use the Add Reply button to post your new log file back here along with details of any problems you encountered performing the above steps and I will review it when it comes in.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#3 SueB

SueB

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Location:Hannibal, NY USA
  • Local time:09:32 AM

Posted 22 May 2005 - 11:39 PM

Hi Old Timer, I am Pandy's friend SueB. I really want to give you a big THANK YOU for your help with the mess I'v made with my computer. I did all the steps without to many problems, any that I did run into I spoke with Pandy over the phone and she pretty much talked me through them. She is a real sweetie. Anyway I will try and copy and paste the Hijack this log from my final scan so you can check it out. Thanks again :java script:emoticon(':)')
smilie) Let me know if you actually receive the log, Pandy is trying to teach me to copy and paste.Logfile of HijackThis v1.99.1
Scan saved at 12:32:46 AM, on 5/23/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\system32\ltmsg.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\WINNT\system32\ukunpp.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\unzipped\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [webscan] C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe -k
O4 - HKLM\..\Run: [vfiarkbz] c:\winnt\system32\vfiarkbz.exe -start
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINNT\system32\ukunpp.exe reg_run
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\system32\Shdocvw.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: World Class Solitaire by pogo - http://game4.pogo.com/applet-6.1.1.21/worl...s-ob-assets.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab34120.cab
O16 - DPF: {2F5B39C5-C6F5-447A-A946-48B382C53985} - http://www.pacimedia.com/install/pcs_0015.exe
O16 - DPF: {31DDC1FD-CEA3-4837-A6DC-87E67015ADC9} - http://akamai.downloadv3.com/binaries/IA/svcsysnet32_EN.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {41D1977F-4161-4720-800F-EA4903983A38} (Jigsaw Genius Control) - http://www.worldwinner.com/games/v42/jigsaw/jigsaw.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP...l_v1-0-3-24.cab
O16 - DPF: {4E7BD74F-2B8D-469E-DEFA-EB76B1D5FA7D} - http://grouplotto.aavalue.com/PrizeMachine/GL_live.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v49/bjattack/bjattack.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {5E8FD788-C323-4357-AB76-7CBCEFBA573C} (SpyBouncer.SBDownloader) - http://www.spybouncer.com/downloader.ocx
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y...ctl_0_0_0_2.ocx
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} (ZPA_WheelOfFortune Object) - http://zone.msn.com/bingame/zpagames/zpa_wof.cab34501.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinner.com/games/v44/sol/sol.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v61/swapit/swapit.cab
O16 - DPF: {B2F0618A-7C27-4900-B8D6-61D39B91FD81} (gc Class) - http://www.gamecolony.com/gcatl.cab
O16 - DPF: {B4831DED-3A57-4CC6-9E4B-0E7C5B08DBF4} - http://www.alwaysupdatednews.com/install/aun_0019.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BA14D944-0D8C-4F16-A950-6E53EEBB558F} - http://akamai.downloadv3.com/binaries/P2EC..._1040_EN_XP.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d.../ITDetector.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/shpo/default/shapo.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab34035.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/bingame/hsol/default/SCEWebLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: ptssvc - KODAK - C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
Is it daiquiri o'clock yet?

#4 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:32 AM

Posted 23 May 2005 - 02:07 AM

Hi SueB. You did a really good job on that log. I told Pandy that you had every infection known to man!

We still have one of the infected files hanging in there which usually means that there is something hiding that does not show up in the HijackThis log. I would like to do a different scan to check for those hidden files.

Download PFind.zip and unzip the contents to its own permanent folder.

Important! Reboot in SAFE MODE !!

Start in Safe Mode Using the F8 method:
  • Restart the computer in Safe Mode.
  • As soon as the BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
  • Use the arrow keys to select the Safe Mode menu item.
  • Press the Enter key.
Locate the pfind.bat file and double-click it to run it. It will start scanning your computer and could take a little while so be patient. When the DOS window closes, reboot back to normal mode.

Post the contents of C:\pfind.txt back here and I will review it when it comes in.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#5 SueB

SueB

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Location:Hannibal, NY USA
  • Local time:09:32 AM

Posted 23 May 2005 - 10:24 AM

:thumbsup: OldTimer

I hope I did the scan right. I recieved an error while it was running..

C:\\WINNT\System32\cmd.exe
C:\\WINNT\SYSTEM32\AUTOEXEC.NT

The system file is not suitable for running MS-DOS and Microsoft applications. Choose close to terminate.

[b]Pandy is here helping me.. here is the scan that we did get.

Files found with this application may be legitimate.
Only remove files that you know are malware related.


Checking the C: folder

C:\pfinda.txt: C:\WINNT\momkz.dll: excl_urls=stech.web-nexus.net,zone.msn.com,z1.adserver.com,yimg.com,yahoo.com,
xlime.offeroptimizer.com,xanga.com,xadsq.offeroptimizer.com,xadso.offeroptimizer.
com,www4.yesadvertising.com,wwp.icq.com,ww2.weatherbug.com,wisapidata.
weatherbug.com,windowsupdate.microsoft.com,whenusearch.com,websearch.com,
webpdp.gator.com,web.tickle.com,web.icq.com,weatherbug.com,view.atdmt.com,v8.
alwaysupdatednews.com,v4.windowsupdate.microsoft.com,us.yimg.com,us.update.
companion.yahoo.com,us.js1.yimg.com,us.i1.yimg.com,us.a1.yimg.com,updates.
qoologic.com,update32.searchmiracle.com,u.clkoptimizer.com,tv.180solutions.
com,trk.pcsecurityshield.com,trk.bestmagsdirect.com,trafficmp.com,toprebates.com,
topmoxie.com,topicks.com,top-banners.com,target.com,t.trafficmp.com,switch.
atdmt.com,stopzilla.com,stats.eblocs.com,sr.websearch.com,sr.adwave.com,
smileycentral.com,server.iad.liveperson.net,servedby.advertising.com,servedby.
valuead.com,servedby.adscpm.com,searchprogress.com,sc.musicmatch.com,
searcheffect.com,search200.com,sandboxer.com,rightmedia.net,radio.launch.yahoo.
com,qksrv.net,popuptraffic.com,popupsearches.com,popups.ad-logics.com,
popuppers.com,popup.msn.com,pops.browseraid.com,pgq.yahoo.com,photobucket.
com,paypopup.com,passportimages.com,pan-advert.com,pagead2.
googlesyndication.com,onemoresearch.net,oz.valueclick.com,odysseusmarketing.
com,newupdates.lzio.com,mydailyhoroscope.net,msads.net,mmm.media-motor.net,
mm.delfinproject.com,microsoft.com,messenger.zango.com,messenger.msn.com,
mediaplex.com,media76.fastclick.net,media.fastclick.net,media.deskwizz.com,
maxserving.com,master.mx-targeting.com,mail.yahoo.com,m3.doubleclick.net,
m2.doubleclick.net,look2me.com,loginnet.passport.com,login.passport.net,
loadingwebsite.com,license.hotbar.com,kill-pop-ups.com,js1.yimg.com,join1.
winhundred.com,jnictech.cjt1.net,jmnad1.com,jicmedia.cjt1.net,jcontent.bns1.
net,jbns2.cydoor.com,jbigpops.cjt1.net,j.2004cms.com,isg05.casalemedia.
com,isapi60.weatherbug.com,img2.mailpostdirect.com,insider.msg.yahoo.com,
images.trafficmp.com,i.emarketresearchgroup.com,hotmail.msn.com,hotmail.com,
host239.ipowerweb.com,hop.clickbank.net,hits.clickandtrack.net,heavy.com,global.
msads.net,focusin.ads.targetnet.com,goldenpalace.com,games.yahoo.com,fxfeeds.
mozilla.org,filter.belkin.com,falkag.net,ezula.com,ekmas.com,e.rn11.com,dw.
dailywinner.net,download.websearch.com,download.smileycentral.com,download.
abetterinternet.com,delfinproject.com,ctl.twain-tech.com,creativeby.viewpoint.com,
couponage.com,counters.honesty.com,count.exitexchange.com,comcast.net,clicktrk.
com,clickspring.net,clickserve.cc-dt.com,clickit.go2net.com,click2.containsitall.com,
cfg.mywebsearch.com,cdn.icq.com,cdn.aim.com,cdn.comcast.net,cdn-cf.aol.com,
cdn-aimtoday.aol.com,c5.zedo.com,c4.maxserving.com,c1.zedo.com,by.optimost.
com,bv.channel.aol.com,bannerserver.gator.com,banners.searchingbooth.com,
banners.pennyweb.com,atdmt.com,ayb.lop.com,bannerfarm.ace.advertising.com,as.
casalemedia.com,as.adwave.com,as-us.falkag.net,aol.com,ar.atwola.com,anrdoezrs.
net,amch.questionmarket.com,alwaysupdatednews.com,altfarm.mediaplex.com,
allaboutsearching.com,akapp.whenu.com,aim-charts.pf.aol.com,affiliates.4lowrates.
com,adverts.lzio.com,advert.runescape.com,adv.eblocs.com,adsv2.delfinproject.com,
adsrv.qoologic.com,adserv1.gruvmedia.com,adserv.internetfuel.com,ads234.com,
ads2.revenue.net,ads.mydailyhoroscope.net,ads1.revenue.net,ads.inet1.com,
ads.exitexchange.com,ads.delfinproject.com,ads.clickagents.com,ads.bidclix.com,
ads.addynamix.com,ad.trafficmp.com,adfarm.mediaplex.com,adlog2.lzio.com,
ad.firstadsolution.com,ad.doubleclick.net,actualdeals.com,aaabesthomepage.com,
a1.yimg.com,a.websponsors.com,a.as-us.falkag.net,0dp.com
C:\pfinda.txt: C:\WINNT\ss3unstl.exe: UPX!
C:\pfinda.txt: C:\WINNT\vsapi32.dll: UPX!t4
C:\pfinda.txt: C:\WINNT\SYSTEM32\dndommd.exe: .aspack
C:\pfinda.txt: C:\WINNT\SYSTEM32\msclock32.dll: UPX!
C:\pfinda.txt: C:\WINNT\SYSTEM32\msplock32.dll: UPX!
C:\pfinda.txt: C:\WINNT\SYSTEM32\oiogrro.dll: .aspack
C:\pfinda.txt: C:\WINNT\SYSTEM32\okodu.dll: .aspack
C:\pfinda.txt: C:\WINNT\SYSTEM32\svcsysnet32.dll: UPX!
C:\pfinda.txt: C:\WINNT\SYSTEM32\Tropical Screensaver.scr: UPX!
C:\pfinda.txt: C:\WINNT\SYSTEM32\Tropical Screensaver.scr: UPX!
C:\pfinda.txt: C:\WINNT\SYSTEM32\ukunpp.exe: .aspack
C:\pfinda.txt: C:\WINNT\SYSTEM32\wawvk.dat: .aspack
C:\pfinda.txt: C:\WINNT\SYSTEM32\ysbinstall_1003032.exe: UPX!
C:\pfinda.txt: C:\WINNT\SYSTEM32\Drivers\avg7core.sys: =FSG!u*h
C:\pfinda.txt: C:\WINNT\SYSTEM32\Drivers\avg7core.sys: error finding UPX! header
C:\pfinda.txt: C:\WINNT\SYSTEM32\Drivers\avg7core.sys: UPX!
C:\pfinda.txt: C:\Documents and Settings\All Users\Start Menu\programs\Startup\rkrt.exe: .aspack


Checking the C:\Program Files folder



Checking the C:\WINNT folder

C:\WINNT\momkz.dll: excl_urls=stech.web-nexus.net,zone.msn.com,z1.adserver.com,yimg.com,
yahoo.com,xlime.offeroptimizer.com,xanga.com,xadsq.offeroptimizer.com,
xadso.offeroptimizer.com,www4.yesadvertising.com,wwp.icq.com
,ww2.weatherbug.com,wisapidata.weatherbug.com,windowsupdate.microsoft.com,
whenusearch.com,websearch.com,webpdp.gator.com,web.tickle.com,web.icq.com,
weatherbug.com,view.atdmt.com,v8.alwaysupdatednews.com,
v4.windowsupdate.microsoft.com,us.yimg.com,
us.update.companion.yahoo.com,us.js1.yimg.com,us.i1.yimg.com,us.a1.yimg.com,
updates.qoologic.com,update32.searchmiracle.com,u.clkoptimizer.com,
tv.180solutions.com,trk.pcsecurityshield.com,trk.bestmagsdirect.com,trafficmp.com,
toprebates.com,topmoxie.com,topicks.com,top-banners.com,target.com,
t.trafficmp.com,switch.atdmt.com,stopzilla.com,stats.eblocs.com,sr.websearch.com,
sr.adwave.com,smileycentral.com,server.iad.liveperson.net,
servedby.advertising.com,servedby.valuead.com,servedby.adscpm.com,
searchprogress.com,sc.musicmatch.com,searcheffect.com,search200.com,
sandboxer.com,rightmedia.net,radio.launch.yahoo.com,qksrv.net,popuptraffic.com,
popupsearches.com,popups.ad-logics.com,popuppers.com,popup.msn.com,
pops.browseraid.com,pgq.yahoo.com,photobucket.com,paypopup.com,
passportimages.com,pan-advert.com,pagead2.googlesyndication.com,
onemoresearch.net,oz.valueclick.com,odysseusmarketing.com,newupdates.lzio.com,
mydailyhoroscope.net,msads.net,mmm.media-motor.net,mm.delfinproject.com,
microsoft.com,messenger.zango.com,messenger.msn.com,mediaplex.com,
media76.fastclick.net,media.fastclick.net,media.deskwizz.com,maxserving.com,
master.mx-targeting.com,mail.yahoo.com,m3.doubleclick.net,m2.doubleclick.net,
look2me.com,loginnet.passport.com,login.passport.net,loadingwebsite.com,
license.hotbar.com,kill-pop-ups.com,js1.yimg.com,join1.winhundred.com,
jnictech.cjt1.net,jmnad1.com,jicmedia.cjt1.net,jcontent.bns1.net,jbns2.cydoor.com,
jbigpops.cjt1.net,j.2004cms.com,isg05.casalemedia.com,isapi60.weatherbug.com,
img2.mailpostdirect.com,insider.msg.yahoo.com,images.trafficmp.com,
i.emarketresearchgroup.com,hotmail.msn.com,hotmail.com,host239.ipowerweb.com,
hop.clickbank.net,hits.clickandtrack.net,heavy.com,global.msads.net,
focusin.ads.targetnet.com,goldenpalace.com,games.yahoo.com,fxfeeds.mozilla.org,
filter.belkin.com,falkag.net,ezula.com,ekmas.com,e.rn11.com,dw.dailywinner.net,
download.websearch.com,download.smileycentral.com,download.abetterinternet.com
,delfinproject.com,ctl.twain-tech.com,creativeby.viewpoint.com,couponage.com,
counters.honesty.com,count.exitexchange.com,comcast.net,clicktrk.com,
clickspring.net,clickserve.cc-dt.com,clickit.go2net.com,click2.containsitall.com,
cfg.mywebsearch.com,cdn.icq.com,cdn.aim.com,cdn.comcast.net,cdn-cf.aol.com,
cdn-aimtoday.aol.com,c5.zedo.com,c4.maxserving.com,c1.zedo.com,
by.optimost.com,bv.channel.aol.com,bannerserver.gator.com,
banners.searchingbooth.com,banners.pennyweb.com,atdmt.com,ayb.lop.com,
bannerfarm.ace.advertising.com,as.casalemedia.com,as.adwave.com,
as-us.falkag.net,aol.com,ar.atwola.com,anrdoezrs.net,amch.questionmarket.com,
alwaysupdatednews.com,altfarm.mediaplex.com,allaboutsearching.com,
akapp.whenu.com,aim-charts.pf.aol.com,affiliates.4lowrates.com,adverts.lzio.com,
advert.runescape.com,adv.eblocs.com,adsv2.delfinproject.com,adsrv.qoologic.com,
adserv1.gruvmedia.com,adserv.internetfuel.com,ads234.com,ads2.revenue.net,
ads.mydailyhoroscope.net,ads1.revenue.net,ads.inet1.com,ads.exitexchange.com,
ads.delfinproject.com,ads.clickagents.com,ads.bidclix.com,ads.addynamix.com,
ad.trafficmp.com,adfarm.mediaplex.com,adlog2.lzio.com,ad.firstadsolution.com,
ad.doubleclick.net,actualdeals.com,aaabesthomepage.com,a1.yimg.com,
a.websponsors.com,a.as-us.falkag.net,0dp.com
C:\WINNT\ss3unstl.exe: UPX!
C:\WINNT\vsapi32.dll: UPX!t4


Checking the C:\WINNT\SYSTEM32 folder

C:\WINNT\SYSTEM32\dndommd.exe: .aspack
C:\WINNT\SYSTEM32\msclock32.dll: UPX!
C:\WINNT\SYSTEM32\msplock32.dll: UPX!
C:\WINNT\SYSTEM32\oiogrro.dll: .aspack
C:\WINNT\SYSTEM32\okodu.dll: .aspack
C:\WINNT\SYSTEM32\svcsysnet32.dll: UPX!
C:\WINNT\SYSTEM32\Tropical Screensaver.scr: UPX!
C:\WINNT\SYSTEM32\Tropical Screensaver.scr: UPX!
C:\WINNT\SYSTEM32\ukunpp.exe: .aspack
C:\WINNT\SYSTEM32\wawvk.dat: .aspack
C:\WINNT\SYSTEM32\ysbinstall_1003032.exe: UPX!


Checking all directories under the C:\WINNT\SYSTEM32\drivers folder

C:\WINNT\SYSTEM32\Drivers\avg7core.sys: =FSG!u*h
C:\WINNT\SYSTEM32\Drivers\avg7core.sys: error finding UPX! header
C:\WINNT\SYSTEM32\Drivers\avg7core.sys: UPX!


Checking the C:\Documents and Settings\All Users\Start Menu\programs\Startup\ folder


C:\Documents and Settings\All Users\Start Menu\programs\Startup\rkrt.exe: .aspack


Checking the C:\Documents and Settings\All Users\Application Data folder




Checking the C:\Documents and Settings\Administrator\Start Menu\programs\Startup\ folder




Checking the C:\Documents and Settings\Administrator\Application Data folder




Checking the Windows folder for system and hidden files within the last 60 days

Edited by Pandy, 23 May 2005 - 11:33 AM.

Is it daiquiri o'clock yet?

#6 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:32 AM

Posted 23 May 2005 - 04:36 PM

Hi SueB. Yes, we need to fix the command system. Please do the following.

Download xp_fix.exe and run it. Reboot your computer into Safe Mode when finished.

Re-run the pfind scan by doing the following:

Important! Reboot in SAFE MODE !!

Start in Safe Mode Using the F8 method:
  • Restart the computer in Safe Mode.
  • As soon as the BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
  • Use the arrow keys to select the Safe Mode menu item.
  • Press the Enter key.
Locate the pfind.bat file and double-click it to run it. It will start scanning your computer and could take a little while so be patient. When the DOS window closes, reboot back to normal mode.

Post the contents of C:\pfind.txt back here and I will review it when it comes in.

OT

Edited by OldTimer, 23 May 2005 - 04:37 PM.

I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#7 SueB

SueB

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Location:Hannibal, NY USA
  • Local time:09:32 AM

Posted 24 May 2005 - 11:42 AM

Good afternoon OT! Thanks again for your help. I did the scan and here is the scan results, I hope I copy and paste right.Files found with this application may be legitimate.
Only remove files that you know are malware related.


Checking the C: folder

C:\pfinda.txt: C:\WINNT\momkz.dll: excl_urls=stech.web-nexus.net,zone.msn.com,z1.adserver.com,yimg.com,
yahoo.com,xlime.offeroptimizer.com,xanga.com,xadsq.offeroptimizer.com,
xadso.offeroptimizer.com,www4.yesadvertising.com,wwp.icq.com,
ww2.weatherbug.com,wisapidata.weatherbug.com,windowsupdate.microsoft.com,
whenusearch.com,websearch.com,webpdp.gator.com,web.tickle.com,
web.icq.com,weatherbug.com,view.atdmt.com,v8.alwaysupdatednews.com,
v4.windowsupdate.microsoft.com,us.yimg.com,us.update.companion.yahoo.com,
us.js1.yimg.com,us.i1.yimg.com,us.a1.yimg.com,updates.qoologic.com,
update32.searchmiracle.com,u.clkoptimizer.com,tv.180solutions.com,
trk.pcsecurityshield.com,trk.bestmagsdirect.com,trafficmp.com,toprebates.com,
topmoxie.com,topicks.com,top-banners.com,target.com,t.trafficmp.com,
switch.atdmt.com,stopzilla.com,stats.eblocs.com,sr.websearch.com,sr.adwave.com,
smileycentral.com,server.iad.liveperson.net,servedby.advertising.com,
servedby.valuead.com,servedby.adscpm.com,searchprogress.com,
sc.musicmatch.com,searcheffect.com,search200.com,sandboxer.com,rightmedia.net,
radio.launch.yahoo.com,qksrv.net,popuptraffic.com,popupsearches.com,
popups.ad-logics.com,popuppers.com,popup.msn.com,pops.browseraid.com,
pgq.yahoo.com,photobucket.com,paypopup.com,passportimages.com,
pan-advert.com,pagead2.googlesyndication.com,onemoresearch.net,
oz.valueclick.com,odysseusmarketing.com,newupdates.lzio.com,
mydailyhoroscope.net,msads.net,mmm.media-motor.net,mm.delfinproject.com,
microsoft.com,messenger.zango.com,messenger.msn.com,mediaplex.com,
media76.fastclick.net,media.fastclick.net,media.deskwizz.com,maxserving.com,
master.mx-targeting.com,mail.yahoo.com,m3.doubleclick.net,m2.doubleclick.net,
look2me.com,loginnet.passport.com,login.passport.net,loadingwebsite.com,
license.hotbar.com,kill-pop-ups.com,js1.yimg.com,join1.winhundred.com,
jnictech.cjt1.net,jmnad1.com,jicmedia.cjt1.net,jcontent.bns1.net,jbns2.cydoor.com,
jbigpops.cjt1.net,j.2004cms.com,isg05.casalemedia.com,isapi60.weatherbug.com,
img2.mailpostdirect.com,insider.msg.yahoo.com,images.trafficmp.com,
i.emarketresearchgroup.com,hotmail.msn.com,hotmail.com,host239.ipowerweb.com,
hop.clickbank.net,hits.clickandtrack.net,heavy.com,global.msads.net,
focusin.ads.targetnet.com,goldenpalace.com,games.yahoo.com,fxfeeds.mozilla.org,
filter.belkin.com,falkag.net,ezula.com,ekmas.com,e.rn11.com,dw.dailywinner.net,
download.websearch.com,download.smileycentral.com,download.abetterinternet.com,
delfinproject.com,ctl.twain-tech.com,creativeby.viewpoint.com,couponage.com,
counters.honesty.com,count.exitexchange.com,comcast.net,clicktrk.com,
clickspring.net,clickserve.cc-dt.com,clickit.go2net.com,click2.containsitall.com,
cfg.mywebsearch.com,cdn.icq.com,cdn.aim.com,cdn.comcast.net,cdn-cf.aol.com,
cdn-aimtoday.aol.com,c5.zedo.com,c4.maxserving.com,c1.zedo.com,
by.optimost.com,bv.channel.aol.com,bannerserver.gator.com,
banners.searchingbooth.com,banners.pennyweb.com,atdmt.com,ayb.lop.com,
bannerfarm.ace.advertising.com,as.casalemedia.com,as.adwave.com,
as-us.falkag.net,aol.com,ar.atwola.com,anrdoezrs.net,amch.questionmarket.com,
alwaysupdatednews.com,altfarm.mediaplex.com,allaboutsearching.com,
akapp.whenu.com,aim-charts.pf.aol.com,affiliates.4lowrates.com,adverts.lzio.com,
advert.runescape.com,adv.eblocs.com,adsv2.delfinproject.com,adsrv.qoologic.com,
adserv1.gruvmedia.com,adserv.internetfuel.com,ads234.com,ads2.revenue.net,
ads.mydailyhoroscope.net,ads1.revenue.net,ads.inet1.com,ads.exitexchange.com,
ads.delfinproject.com,ads.clickagents.com,ads.bidclix.com,ads.addynamix.com,
ad.trafficmp.com,adfarm.mediaplex.com,adlog2.lzio.com,ad.firstadsolution.com,
ad.doubleclick.net,actualdeals.com,aaabesthomepage.com,a1.yimg.com,
a.websponsors.com,a.as-us.falkag.net,0dp.com
C:\pfinda.txt: C:\WINNT\ss3unstl.exe: UPX!
C:\pfinda.txt: C:\WINNT\vsapi32.dll: UPX!t4
C:\pfinda.txt: C:\WINNT\SYSTEM32\dndommd.exe: .aspack
C:\pfinda.txt: C:\WINNT\SYSTEM32\msclock32.dll: UPX!
C:\pfinda.txt: C:\WINNT\SYSTEM32\msplock32.dll: UPX!
C:\pfinda.txt: C:\WINNT\SYSTEM32\oiogrro.dll: .aspack
C:\pfinda.txt: C:\WINNT\SYSTEM32\okodu.dll: .aspack
C:\pfinda.txt: C:\WINNT\SYSTEM32\svcsysnet32.dll: UPX!
C:\pfinda.txt: C:\WINNT\SYSTEM32\Tropical Screensaver.scr: UPX!
C:\pfinda.txt: C:\WINNT\SYSTEM32\Tropical Screensaver.scr: UPX!
C:\pfinda.txt: C:\WINNT\SYSTEM32\ukunpp.exe: .aspack
C:\pfinda.txt: C:\WINNT\SYSTEM32\wawvk.dat: .aspack
C:\pfinda.txt: C:\WINNT\SYSTEM32\ysbinstall_1003032.exe: UPX!
C:\pfinda.txt: C:\WINNT\SYSTEM32\Drivers\avg7core.sys: =FSG!u*h
C:\pfinda.txt: C:\WINNT\SYSTEM32\Drivers\avg7core.sys: error finding UPX! header
C:\pfinda.txt: C:\WINNT\SYSTEM32\Drivers\avg7core.sys: UPX!
C:\pfinda.txt: C:\Documents and Settings\All Users\Start Menu\programs\Startup\rkrt.exe: .aspack
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\momkz.dll: excl_urls=stech.web-nexus.net,zone.msn.com,z1.adserver.com,yimg.com,
yahoo.com,xlime.offeroptimizer.com,xanga.com,xadsq.offeroptimizer.com,
xadso.offeroptimizer.com,www4.yesadvertising.com,wwp.icq.com,
ww2.weatherbug.com,wisapidata.weatherbug.com,windowsupdate.microsoft.com,
whenusearch.com,websearch.com,webpdp.gator.com,web.tickle.com,web.icq.com,
weatherbug.com,view.atdmt.com,v8.alwaysupdatednews.com,
v4.windowsupdate.microsoft.com,us.yimg.com,us.update.companion.yahoo.com,
us.js1.yimg.com,us.i1.yimg.com,us.a1.yimg.com,updates.qoologic.com,
update32.searchmiracle.com,u.clkoptimizer.com,tv.180solutions.com,
trk.pcsecurityshield.com,trk.bestmagsdirect.com,trafficmp.com,toprebates.com,
topmoxie.com,topicks.com,top-banners.com,target.com,t.trafficmp.com,
switch.atdmt.com,stopzilla.com,stats.eblocs.com,sr.websearch.com,sr.adwave.com,
smileycentral.com,server.iad.liveperson.net,servedby.advertising.com,
servedby.valuead.com,servedby.adscpm.com,searchprogress.com,
sc.musicmatch.com,searcheffect.com,search200.com,sandboxer.com,rightmedia.net,
radio.launch.yahoo.com,qksrv.net,popuptraffic.com,popupsearches.com,
popups.ad-logics.com,popuppers.com,popup.msn.com,pops.browseraid.com,
pgq.yahoo.com,photobucket.com,paypopup.com,
passportimages.com,pan-advert.com,pagead2.googlesyndication.com,
onemoresearch.net,oz.valueclick.com,odysseusmarketing.com,newupdates.lzio.com,
mydailyhoroscope.net,msads.net,mmm.media-motor.net,mm.delfinproject.com,
microsoft.com,messenger.zango.com,messenger.msn.com,mediaplex.com,
media76.fastclick.net,media.fastclick.net,media.deskwizz.com,maxserving.com,
master.mx-targeting.com,mail.yahoo.com,m3.doubleclick.net,m2.doubleclick.net,
look2me.com,loginnet.passport.com,login.passport.net,loadingwebsite.com,
license.hotbar.com,kill-pop-ups.com,js1.yimg.com,join1.winhundred.com,
jnictech.cjt1.net,jmnad1.com,jicmedia.cjt1.net,jcontent.bns1.net,jbns2.cydoor.com,
jbigpops.cjt1.net,j.2004cms.com,isg05.casalemedia.com,isapi60.weatherbug.com
,img2.mailpostdirect.com,insider.msg.yahoo.com,images.trafficmp.com,
i.emarketresearchgroup.com,hotmail.msn.com,hotmail.com,
host239.ipowerweb.com,hop.clickbank.net,hits.clickandtrack.net,heavy.com,
global.msads.net,focusin.ads.targetnet.com,goldenpalace.com,games.yahoo.com,
fxfeeds.mozilla.org,filter.belkin.com,falkag.net,ezula.com,ekmas.com,e.rn11.com,
dw.dailywinner.net,download.websearch.com,download.smileycentral.com,
download.abetterinternet.com,delfinproject.com,ctl.twain-tech.com,
creativeby.viewpoint.com,couponage.com,counters.honesty.com,
count.exitexchange.com,comcast.net,clicktrk.com,clickspring.net,
clickserve.cc-dt.com,clickit.go2net.com,click2.containsitall.com,
cfg.mywebsearch.com,cdn.icq.com,cdn.aim.com,cdn.comcast.net,cdn-cf.aol.com,
cdn-aimtoday.aol.com,c5.zedo.com,c4.maxserving.com,c1.zedo.com,
by.optimost.com,bv.channel.aol.com,bannerserver.gator.com,
banners.searchingbooth.com,banners.pennyweb.com,atdmt.com,ayb.lop.com,
bannerfarm.ace.advertising.com,as.casalemedia.com,as.adwave.com,
as-us.falkag.net,aol.com,ar.atwola.com,anrdoezrs.net,amch.questionmarket.com,
alwaysupdatednews.com,altfarm.mediaplex.com,allaboutsearching.com,
akapp.whenu.com,aim-charts.pf.aol.com,affiliates.4lowrates.com,adverts.lzio.com,
advert.runescape.com,adv.eblocs.com,adsv2.delfinproject.com,adsrv.qoologic.com,
adserv1.gruvmedia.com,adserv.internetfuel.com,ads234.com,ads2.revenue.net,
ads.mydailyhoroscope.net,ads1.revenue.net,ads.inet1.com,ads.exitexchange.com,
ads.delfinproject.com,ads.clickagents.com,ads.bidclix.com,ads.addynamix.com,
ad.trafficmp.com,adfarm.mediaplex.com,adlog2.lzio.com,ad.firstadsolution.com,
ad.doubleclick.net,actualdeals.com,aaabesthomepage.com,a1.yimg.com,
a.websponsors.com,a.as-us.falkag.net,0dp.com
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\ss3unstl.exe: UPX!
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\vsapi32.dll: UPX!t4
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\SYSTEM32\dndommd.exe: .aspack
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\SYSTEM32\msclock32.dll: UPX!
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\SYSTEM32\msplock32.dll: UPX!
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\SYSTEM32\oiogrro.dll: .aspack
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\SYSTEM32\okodu.dll: .aspack
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\SYSTEM32\svcsysnet32.dll: UPX!
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\SYSTEM32\Tropical Screensaver.scr: UPX!
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\SYSTEM32\Tropical Screensaver.scr: UPX!
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\SYSTEM32\ukunpp.exe: .aspack
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\SYSTEM32\wawvk.dat: .aspack
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\SYSTEM32\ysbinstall_1003032.exe: UPX!
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\SYSTEM32\Drivers\avg7core.sys: =FSG!u*h
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\SYSTEM32\Drivers\avg7core.sys: error finding UPX! header
C:\pfindb.txt: C:\pfinda.txt: C:\WINNT\SYSTEM32\Drivers\avg7core.sys: UPX!
C:\pfindb.txt: C:\pfinda.txt: C:\Documents and Settings\All Users\Start Menu\programs\Startup\rkrt.exe: .aspack
C:\pfindb.txt: C:\WINNT\momkz.dll: excl_urls=stech.web-nexus.net,zone.msn.com,z1.adserver.com,yimg.com,yahoo.com,xlime.offeroptimizer.com,xanga.com,xadsq.offeroptimizer.com,xadso.offeroptimizer.com,www4.yesadvertising.com,wwp.icq.com,ww2.weatherbug.com,wisapidata.weatherbug.com,windowsupdate.microsoft.com,whenusearch.com,websearch.com,webpdp.gator.com,web.tickle.com,web.icq.com,weatherbug.com,view.atdmt.com,v8.alwaysupdatednews.com,v4.windowsupdate.microsoft.com,us.yimg.com,us.update.companion.yahoo.com,us.js1.yimg.com,us.i1.yimg.com,us.a1.yimg.com,updates.qoologic.com,update32.searchmiracle.com,u.clkoptimizer.com,tv.180solutions.com,trk.pcsecurityshield.com,trk.bestmagsdirect.com,trafficmp.com,toprebates.com,topmoxie.com,topicks.com,top-banners.com,target.com,t.trafficmp.com,switch.atdmt.com,stopzilla.com,stats.eblocs.com,sr.websearch.com,sr.adwave.com,smileycentral.com,server.iad.liveperson.net,servedby.advertising.com,servedby.valuead.com,servedby.adscpm.com,searchprogress.com,sc.musicmatch.com,searcheffect.com,search200.com,sandboxer.com,rightmedia.net,radio.launch.yahoo.com,qksrv.net,popuptraffic.com,popupsearches.com,popups.ad-logics.com,popuppers.com,popup.msn.com,pops.browseraid.com,pgq.yahoo.com,photobucket.com,paypopup.com,passportimages.com,pan-advert.com,pagead2.googlesyndication.com,onemoresearch.net,oz.valueclick.com,odysseusmarketing.com,newupdates.lzio.com,mydailyhoroscope.net,msads.net,mmm.media-motor.net,mm.delfinproject.com,microsoft.com,messenger.zango.com,messenger.msn.com,mediaplex.com,media76.fastclick.net,media.fastclick.net,media.deskwizz.com,maxserving.com,master.mx-targeting.com,mail.yahoo.com,m3.doubleclick.net,m2.doubleclick.net,look2me.com,loginnet.passport.com,login.passport.net,loadingwebsite.com,license.hotbar.com,kill-pop-ups.com,js1.yimg.com,join1.winhundred.com,jnictech.cjt1.net,jmnad1.com,jicmedia.cjt1.net,jcontent.bns1.net,jbns2.cydoor.com,jbigpops.cjt1.net,j.2004cms.com,isg05.casalemedia.com,isapi60.weatherbug.com,img2.mailpostdirect.com,insider.msg.yahoo.com,images.trafficmp.com,i.emarketresearchgroup.com,hotmail.msn.com,hotmail.com,host239.ipowerweb.com,hop.clickbank.net,hits.clickandtrack.net,heavy.com,global.msads.net,focusin.ads.targetnet.com,goldenpalace.com,games.yahoo.com,fxfeeds.mozilla.org,filter.belkin.com,falkag.net,ezula.com,ekmas.com,e.rn11.com,dw.dailywinner.net,download.websearch.com,download.smileycentral.com,download.abetterinternet.com,delfinproject.com,ctl.twain-tech.com,creativeby.viewpoint.com,couponage.com,counters.honesty.com,count.exitexchange.com,comcast.net,clicktrk.com,clickspring.net,clickserve.cc-dt.com,clickit.go2net.com,click2.containsitall.com,cfg.mywebsearch.com,cdn.icq.com,cdn.aim.com,cdn.comcast.net,cdn-cf.aol.com,cdn-aimtoday.aol.com,c5.zedo.com,c4.maxserving.com,c1.zedo.com,by.optimost.com,bv.channel.aol.com,bannerserver.gator.com,banners.searchingbooth.com,banners.pennyweb.com,atdmt.com,ayb.lop.com,bannerfarm.ace.advertising.com,as.casalemedia.com,as.adwave.com,as-us.falkag.net,aol.com,ar.atwola.com,anrdoezrs.net,amch.questionmarket.com,alwaysupdatednews.com,altfarm.mediaplex.com,allaboutsearching.com,akapp.whenu.com,aim-charts.pf.aol.com,affiliates.4lowrates.com,adverts.lzio.com,advert.runescape.com,adv.eblocs.com,adsv2.delfinproject.com,adsrv.qoologic.com,adserv1.gruvmedia.com,adserv.internetfuel.com,ads234.com,ads2.revenue.net,ads.mydailyhoroscope.net,ads1.revenue.net,ads.inet1.com,ads.exitexchange.com,ads.delfinproject.com,ads.clickagents.com,ads.bidclix.com,ads.addynamix.com,ad.trafficmp.com,adfarm.mediaplex.com,adlog2.lzio.com,ad.firstadsolution.com,ad.doubleclick.net,actualdeals.com,aaabesthomepage.com,a1.yimg.com,a.websponsors.com,a.as-us.falkag.net,0dp.com
C:\pfindb.txt: C:\WINNT\ss3unstl.exe: UPX!
C:\pfindb.txt: C:\WINNT\vsapi32.dll: UPX!t4
C:\pfindb.txt: C:\WINNT\SYSTEM32\dndommd.exe: .aspack
C:\pfindb.txt: C:\WINNT\SYSTEM32\msclock32.dll: UPX!
C:\pfindb.txt: C:\WINNT\SYSTEM32\msplock32.dll: UPX!
C:\pfindb.txt: C:\WINNT\SYSTEM32\oiogrro.dll: .aspack
C:\pfindb.txt: C:\WINNT\SYSTEM32\okodu.dll: .aspack
C:\pfindb.txt: C:\WINNT\SYSTEM32\svcsysnet32.dll: UPX!
C:\pfindb.txt: C:\WINNT\SYSTEM32\Tropical Screensaver.scr: UPX!
C:\pfindb.txt: C:\WINNT\SYSTEM32\Tropical Screensaver.scr: UPX!
C:\pfindb.txt: C:\WINNT\SYSTEM32\ukunpp.exe: .aspack
C:\pfindb.txt: C:\WINNT\SYSTEM32\wawvk.dat: .aspack
C:\pfindb.txt: C:\WINNT\SYSTEM32\ysbinstall_1003032.exe: UPX!
C:\pfindb.txt: C:\WINNT\SYSTEM32\Drivers\avg7core.sys: =FSG!u*h
C:\pfindb.txt: C:\WINNT\SYSTEM32\Drivers\avg7core.sys: error finding UPX! header
C:\pfindb.txt: C:\WINNT\SYSTEM32\Drivers\avg7core.sys: UPX!
C:\pfindb.txt: C:\Documents and Settings\All Users\Start Menu\programs\Startup\rkrt.exe: .aspack


Checking the C:\Program Files folder



Checking the C:\WINNT folder

C:\WINNT\momkz.dll: excl_urls=stech.web-nexus.net,zone.msn.com,z1.adserver.com,yimg.com,yahoo.com,xlime.offeroptimizer.com,xanga.com,xadsq.offeroptimizer.com,xadso.offeroptimizer.com,www4.yesadvertising.com,wwp.icq.com,ww2.weatherbug.com,wisapidata.weatherbug.com,windowsupdate.microsoft.com,whenusearch.com,websearch.com,webpdp.gator.com,web.tickle.com,web.icq.com,weatherbug.com,view.atdmt.com,v8.alwaysupdatednews.com,v4.windowsupdate.microsoft.com,us.yimg.com,us.update.companion.yahoo.com,us.js1.yimg.com,us.i1.yimg.com,us.a1.yimg.com,updates.qoologic.com,update32.searchmiracle.com,u.clkoptimizer.com,tv.180solutions.com,trk.pcsecurityshield.com,trk.bestmagsdirect.com,trafficmp.com,toprebates.com,topmoxie.com,topicks.com,top-banners.com,target.com,t.trafficmp.com,switch.atdmt.com,stopzilla.com,stats.eblocs.com,sr.websearch.com,sr.adwave.com,smileycentral.com,server.iad.liveperson.net,servedby.advertising.com,servedby.valuead.com,servedby.adscpm.com,searchprogress.com,sc.musicmatch.com,searcheffect.com,search200.com,sandboxer.com,rightmedia.net,radio.launch.yahoo.com,qksrv.net,popuptraffic.com,popupsearches.com,popups.ad-logics.com,popuppers.com,popup.msn.com,pops.browseraid.com,pgq.yahoo.com,photobucket.com,paypopup.com,passportimages.com,pan-advert.com,pagead2.googlesyndication.com,onemoresearch.net,oz.valueclick.com,odysseusmarketing.com,newupdates.lzio.com,mydailyhoroscope.net,msads.net,mmm.media-motor.net,mm.delfinproject.com,microsoft.com,messenger.zango.com,messenger.msn.com,mediaplex.com,media76.fastclick.net,media.fastclick.net,media.deskwizz.com,maxserving.com,master.mx-targeting.com,mail.yahoo.com,m3.doubleclick.net,m2.doubleclick.net,look2me.com,loginnet.passport.com,login.passport.net,loadingwebsite.com,license.hotbar.com,kill-pop-ups.com,js1.yimg.com,join1.winhundred.com,jnictech.cjt1.net,jmnad1.com,jicmedia.cjt1.net,jcontent.bns1.net,jbns2.cydoor.com,jbigpops.cjt1.net,j.2004cms.com,isg05.casalemedia.com,isapi60.weatherbug.com,img2.mailpostdirect.com,insider.msg.yahoo.com,images.trafficmp.com,i.emarketresearchgroup.com,hotmail.msn.com,hotmail.com,host239.ipowerweb.com,hop.clickbank.net,hits.clickandtrack.net,heavy.com,global.msads.net,focusin.ads.targetnet.com,goldenpalace.com,games.yahoo.com,fxfeeds.mozilla.org,filter.belkin.com,falkag.net,ezula.com,ekmas.com,e.rn11.com,dw.dailywinner.net,download.websearch.com,download.smileycentral.com,download.abetterinternet.com,delfinproject.com,ctl.twain-tech.com,creativeby.viewpoint.com,couponage.com,counters.honesty.com,count.exitexchange.com,comcast.net,clicktrk.com,clickspring.net,clickserve.cc-dt.com,clickit.go2net.com,click2.containsitall.com,cfg.mywebsearch.com,cdn.icq.com,cdn.aim.com,cdn.comcast.net,cdn-cf.aol.com,cdn-aimtoday.aol.com,c5.zedo.com,c4.maxserving.com,c1.zedo.com,by.optimost.com,bv.channel.aol.com,bannerserver.gator.com,banners.searchingbooth.com,banners.pennyweb.com,atdmt.com,ayb.lop.com,bannerfarm.ace.advertising.com,as.casalemedia.com,as.adwave.com,as-us.falkag.net,aol.com,ar.atwola.com,anrdoezrs.net,amch.questionmarket.com,alwaysupdatednews.com,altfarm.mediaplex.com,allaboutsearching.com,akapp.whenu.com,aim-charts.pf.aol.com,affiliates.4lowrates.com,adverts.lzio.com,advert.runescape.com,adv.eblocs.com,adsv2.delfinproject.com,adsrv.qoologic.com,adserv1.gruvmedia.com,adserv.internetfuel.com,ads234.com,ads2.revenue.net,ads.mydailyhoroscope.net,ads1.revenue.net,ads.inet1.com,ads.exitexchange.com,ads.delfinproject.com,ads.clickagents.com,ads.bidclix.com,ads.addynamix.com,ad.trafficmp.com,adfarm.mediaplex.com,adlog2.lzio.com,ad.firstadsolution.com,ad.doubleclick.net,actualdeals.com,aaabesthomepage.com,a1.yimg.com,a.websponsors.com,a.as-us.falkag.net,0dp.com
C:\WINNT\ss3unstl.exe: UPX!
C:\WINNT\vsapi32.dll: UPX!t4


Checking the C:\WINNT\SYSTEM32 folder

C:\WINNT\SYSTEM32\dndommd.exe: .aspack
C:\WINNT\SYSTEM32\msclock32.dll: UPX!
C:\WINNT\SYSTEM32\msplock32.dll: UPX!
C:\WINNT\SYSTEM32\oiogrro.dll: .aspack
C:\WINNT\SYSTEM32\okodu.dll: .aspack
C:\WINNT\SYSTEM32\svcsysnet32.dll: UPX!
C:\WINNT\SYSTEM32\Tropical Screensaver.scr: UPX!
C:\WINNT\SYSTEM32\Tropical Screensaver.scr: UPX!
C:\WINNT\SYSTEM32\ukunpp.exe: .aspack
C:\WINNT\SYSTEM32\wawvk.dat: .aspack
C:\WINNT\SYSTEM32\ysbinstall_1003032.exe: UPX!


Checking all directories under the C:\WINNT\SYSTEM32\drivers folder

C:\WINNT\SYSTEM32\Drivers\avg7core.sys: =FSG!u*h
C:\WINNT\SYSTEM32\Drivers\avg7core.sys: error finding UPX! header
C:\WINNT\SYSTEM32\Drivers\avg7core.sys: UPX!


Checking the C:\Documents and Settings\All Users\Start Menu\programs\Startup\ folder


C:\Documents and Settings\All Users\Start Menu\programs\Startup\rkrt.exe: .aspack


Checking the C:\Documents and Settings\All Users\Application Data folder




Checking the C:\Documents and Settings\Administrator\Start Menu\programs\Startup\ folder




Checking the C:\Documents and Settings\Administrator\Application Data folder




Checking the Windows folder for system and hidden files within the last 60 days


C:\WINNT\
qtfont.qfn Tue May 3 2005 4:45:30p A..H. 54,156 52.89 K
shelli~1 Tue May 24 2005 12:16:58p ...H. 923,086 901.45 K

C:\WINNT\ASSEMBLY\
desktop.ini Wed Apr 27 2005 5:48:48p ..SHR 227 0.22 K

C:\WINNT\CSC\
00000001 Tue May 24 2005 12:17:18p A.S.. 64 0.06 K
00000002 Mon May 23 2005 11:28:54a A.S.. 64 0.06 K
csc1.tmp Mon May 23 2005 11:12:06a A.S.. 64 0.06 K

C:\WINNT\HELP\
update.gid Tue Mar 29 2005 6:42:08p A..H. 10,820 10.57 K

C:\WINNT\TASKS\
sa.dat Tue May 24 2005 12:17:18p A..H. 6 0.00 K

C:\WINNT\SYSTEM32\CONFIG\
default.log Tue May 24 2005 6:50:52a A..H. 1,024 1.00 K
sam.log Tue May 24 2005 12:23:04p A..H. 1,024 1.00 K
security.log Tue May 24 2005 12:21:12p A..H. 1,024 1.00 K
software.log Tue May 24 2005 12:25:52p A..H. 1,024 1.00 K

C:\WINNT\SYSTEM32\MICROS~1\PROTECT\S-1-5-18\USER\
75db62~1 Thu Apr 28 2005 4:54:20p A.SH. 336 0.33 K
prefer~1 Thu Apr 28 2005 4:54:20p A.SH. 24 0.02 K

14 items found: 14 files, 0 directories.
Total of file sizes: 992,943 bytes 969.67 K

Edited by Pandy, 24 May 2005 - 12:13 PM.

Is it daiquiri o'clock yet?

#8 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:32 AM

Posted 24 May 2005 - 07:49 PM

Hi SueB. There's still something not working properly with that scan. Let's try a different one and see if that one will work.

Download Find_It_s.zip and unzip the contents to its own folder.

Important! Reboot in SAFE MODE !!

Start in Safe Mode Using the F8 method:
  • Restart the computer in Safe Mode.
  • As soon as the BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
  • Use the arrow keys to select the Safe Mode menu item.
  • Press the Enter key.
Locate the FindIt's.bat file and double-click it to run it. It will start scanning your computer and could take a little while so be patient. When the DOS window closes, reboot back to normal mode.

Post the contents of C:\log.txt back here and I will review it when it comes in.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#9 SueB

SueB

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Location:Hannibal, NY USA
  • Local time:09:32 AM

Posted 26 May 2005 - 08:36 AM

Good morning OT, sorry I didn't reply yesterday but I didn't make it to the computer. Here is the scan of the findit hopefully this will show what the problem is, we must have really picked up junk, I'm so thankful to you, Pandy and this site.Microsoft Windows 2000 [Version 5.00.2195]
The current date is: Thu 05/26/2005
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
»»»»»»»»»»»»»»»»»»»»»»»» Todo Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»


»»»»»»»»»»»»»»»»»»»»»»»» aurora Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»


»»»»»»»»»»»»»»»»»»»»»»»» Suspect's »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Dont delete file's in the section without guidance
If any doubt back them up first

* UPX! C:\WINNT\System32\YSBINS~1.EXE
* UPX! C:\WINNT\SS3UNSTL.EXE

»»»»» lagitamate file's can/will show in this section.

* UPX! C:\WINNT\System32\MSCLOC~1.DLL
* UPX! C:\WINNT\System32\MSPLOC~1.DLL
* UPX! C:\WINNT\System32\SVCSYS~1.DLL
* UPX! C:\WINNT\VSAPI32.DLL
»»»»»»»»»»»»»»»»»»»»»»»» Buddy file's »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

»»»»»»»»»»»»»»»»»»»»»»»» SAHAgent Files found »»»»»»»»»»»»»»»»»»»»»»»»»

»»»»»»»»»»»»»»»»»»»»»»»» Misc checks »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


»»»»» Check for Windows\SYSTEM32\cache32_rtneg* folder.

Volume in drive C has no label.
Volume Serial Number is D8A6-3ECB

Directory of C:\WINNT\SYSTEM32

»»»»» Checking for SAHAgent ico files.
Volume in drive C has no label.
Volume Serial Number is D8A6-3ECB

Directory of C:\WINNT\system32

04/28/2005 04:43p 3,262 creditcard32123123123asdsa.ico
04/28/2005 04:43p 4,286 greenmovie2313asaadsasfad112341231adsfa.ico
04/28/2005 04:43p 3,262 kill popups.ico
04/28/2005 04:43p 3,262 kill spyware1.ico
04/28/2005 04:43p 4,286 mp3red51aads.ico
5 File(s) 18,358 bytes
0 Dir(s) 11,391,537,152 bytes free

»»»»»»»»»»»»»»»»»»»»»»»».
Is it daiquiri o'clock yet?

#10 SueB

SueB

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Location:Hannibal, NY USA
  • Local time:09:32 AM

Posted 26 May 2005 - 09:09 AM

Hey there again OT. ran into a little problem after I sent that last log. I closed out of bleeping comp. and restarted my computer and ewido notified me that it found 2 viruses. I copied all info down to show you and then I let ewido clean them, I believe that worked. Here is what it found:


File - ukunpp.exe
Path - c:\WINNT\system32
Infection - Trojan Downloader.Qoologic.n


File - rkrt.exe
Path - c:\AllUsers\Startmenu\Program\Startup
Infection - Trojan Downloader.Qoologic.n
Is it daiquiri o'clock yet?

#11 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:32 AM

Posted 26 May 2005 - 09:43 AM

Hi SueB. Let's get to work.

Download Pocket Killbox and unzip it to your desktop.

Double-click on KillBox.exe to launch the program.
  • Highlight the lines below and press the Ctrl key and the C key at the same time to copy them to the clipboard:
    • C:\WINNT\momkz.dll
      C:\WINNT\SYSTEM32\dndommd.exe
      C:\WINNT\SYSTEM32\msclock32.dll
      C:\WINNT\SYSTEM32\msplock32.dll
      C:\WINNT\SYSTEM32\oiogrro.dll
      C:\WINNT\SYSTEM32\okodu.dll
      C:\WINNT\SYSTEM32\svcsysnet32.dll
      C:\WINNT\SYSTEM32\Tropical Screensaver.scr
      C:\WINNT\SYSTEM32\Tropical Screensaver.scr
      C:\WINNT\SYSTEM32\ukunpp.exe
      C:\WINNT\SYSTEM32\wawvk.dat
      C:\WINNT\SYSTEM32\ysbinstall_1003032.exe
      C:\Documents and Settings\All Users\Start Menu\programs\Startup\rkrt.exe
  • Now go to the Killbox application and click on the File menu and then the Paste from Clipboard menu item. In the Full Path of File to Delete box you should see the first file. If you dropdown that box you should see the rest of them. Make sure that they are all there.
  • Click on the Replace on Reboot option and check the checkbox for Use dummy. Now click on the red circle with a white 'X' in to to delete the files. Killbox will tell you that all listed files will be deleted on next reboot, click YES. When it asks if you would like to Reboot now, click YES. If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.
Your system will reboot now.

Start HijackThis and perform a new scan. Use the Add Reply button to post your new log file back here along with details of any problems you encountered performing the above steps and I will review it when it comes in.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#12 SueB

SueB

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Location:Hannibal, NY USA
  • Local time:09:32 AM

Posted 26 May 2005 - 10:38 AM

ok, i did the scan without any problems. Here's what I got,Logfile of HijackThis v1.99.1
Scan saved at 11:45:39 AM, on 5/26/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\system32\ltmsg.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\unzipped\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [webscan] C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe -k
O4 - HKLM\..\Run: [vfiarkbz] c:\winnt\system32\vfiarkbz.exe -start
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\system32\Shdocvw.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\avgfwafu.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: World Class Solitaire by pogo - http://game4.pogo.com/applet-6.1.1.21/worl...s-ob-assets.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab34120.cab
O16 - DPF: {2F5B39C5-C6F5-447A-A946-48B382C53985} - http://www.pacimedia.com/install/pcs_0015.exe
O16 - DPF: {31DDC1FD-CEA3-4837-A6DC-87E67015ADC9} - http://akamai.downloadv3.com/binaries/IA/svcsysnet32_EN.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {41D1977F-4161-4720-800F-EA4903983A38} (Jigsaw Genius Control) - http://www.worldwinner.com/games/v42/jigsaw/jigsaw.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP...l_v1-0-3-24.cab
O16 - DPF: {4E7BD74F-2B8D-469E-DEFA-EB76B1D5FA7D} - http://grouplotto.aavalue.com/PrizeMachine/GL_live.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v49/bjattack/bjattack.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {5E8FD788-C323-4357-AB76-7CBCEFBA573C} (SpyBouncer.SBDownloader) - http://www.spybouncer.com/downloader.ocx
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y...ctl_0_0_0_2.ocx
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} (ZPA_WheelOfFortune Object) - http://zone.msn.com/bingame/zpagames/zpa_wof.cab34501.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinner.com/games/v44/sol/sol.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v61/swapit/swapit.cab
O16 - DPF: {B2F0618A-7C27-4900-B8D6-61D39B91FD81} (gc Class) - http://www.gamecolony.com/gcatl.cab
O16 - DPF: {B4831DED-3A57-4CC6-9E4B-0E7C5B08DBF4} - http://www.alwaysupdatednews.com/install/aun_0019.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BA14D944-0D8C-4F16-A950-6E53EEBB558F} - http://akamai.downloadv3.com/binaries/P2EC..._1040_EN_XP.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d.../ITDetector.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/shpo/default/shapo.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab34035.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/bingame/hsol/default/SCEWebLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: ptssvc - KODAK - C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
Is it daiquiri o'clock yet?

#13 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:32 AM

Posted 26 May 2005 - 10:53 AM

Hi SueB. I am curious about 1 file that I see.

Go to the Jotti's malware scan page and use the buttons at the top of the page to browse to this file(s) on your hard drive to submit for a scan:c:\winnt\system32\vfiarkbz.exe
Several scanning engines will be used to check the file for any threats. Please post the results of the scans back here.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#14 SueB

SueB

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Location:Hannibal, NY USA
  • Local time:09:32 AM

Posted 26 May 2005 - 11:12 AM

OT here is that scan, Virus

Service
Service load:
0% 100%
File: vfiarkbz.exe
Status:
INFECTED/MALWARE (Note: only non-destructive malware has been found. Considering the non-destructive nature of samples like these - although they can be a pain -, results will not be stored in the database.)
MD5 28bc0f1a6a036b40ef41d17bc57527f2
Packers detected:
YODAPROTECT
Scanner results
AntiVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found not-a-virus:AdWare.NaviPromo.c
mks_vir
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
VBA32
Found nothing
Is it daiquiri o'clock yet?

#15 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:32 AM

Posted 26 May 2005 - 11:25 AM

Hi Sue. Let's use Killbox again and get rid of that file.
  • Double-click on KillBox.exe.
  • Click "Delete on Reboot".
  • Paste the line below into the top "Full Path of File to Delete" box.
    • c:\winnt\system32\vfiarkbz.exe
  • Click the "Delete File" button which looks like a stop sign.
  • Click "Yes" at the Delete on Reboot prompt.
  • Click "Yes" at the Delete next Reboot prompt.
  • If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.
After the reboot, start HijackThis and click the Scan button to perform a scan. Look for the following items and click in the checkbox in front of each item to select it:O4 - HKLM\..\Run: [vfiarkbz] c:\winnt\system32\vfiarkbz.exe -start
Now close ALL open windows except HijackThis and click the Fix Checked button to finish the repair.

OK. Reboot your computer normally, start HijackThis and perform a new scan. Use the Add Reply button to post your new log file back here along with details of any problems you encountered performing the above steps and I will review it when it comes in.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users