Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


shvhost.exe infection (MSN Messenger started all)

  • This topic is locked This topic is locked
2 replies to this topic

#1 .Ax.


  • Members
  • 1 posts
  • Gender:Male
  • Location:Mex
  • Local time:09:14 PM

Posted 13 March 2009 - 12:15 PM

Hello everyone!

Okay, here's the thing: A couple days ago, my MSN Messenger account started sending messages of this kind to my contacts:

[quote]Are Thease Your photo ? {hxxp://www.shqip.com.es/images/Google.exe?=<myContact'sEmail>}
I've tried running my Antivirus (ESET Smart Security), and nothing happened, also tried with Spybot but it didn't find a problem.

Doing some research I found that this strange service shvhost.exe is malware, and tried to fix it by myself (I downloaded SDfix and made a scan), but it didn't help, I probably did something wrong. dry.gif

A little help would be greatly appreciated,

Here is the DDS.txt:

DDS (Ver_09-02-01.01) - NTFSx86
Run by Mar¡a at 10:57:59.57 on 13/03/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.52.3082.18.502.130 [GMT -6:00]

AV: ESET Smart Security 3.0 *On-access scanning enabled* (Updated)
FW: Cortafuegos personal de ESET *enabled*

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Archivos de programa\Apache Software Foundation\Apache2.2\bin\httpd.exe
C:\Archivos de programa\Archivos comunes\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Archivos de programa\Bonjour\mDNSResponder.exe
C:\Archivos de programa\ESET\ESET Smart Security\ekrn.exe
C:\Archivos de programa\Java\jre6\bin\jqs.exe
C:\Archivos de programa\Archivos comunes\LightScribe\LSSrvc.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Archivos de programa\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Archivos de programa\Archivos comunes\Ulead Systems\DVD\ULCDRSvr.exe
C:\Archivos de programa\Apache Software Foundation\Apache2.2\bin\httpd.exe
C:\Archivos de programa\Java\jre6\bin\jusched.exe
C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe
C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
C:\Archivos de programa\HPQ\Quick Launch Buttons\EabServr.exe
C:\Archivos de programa\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Archivos de programa\Hp\HP Software Update\HPWuSchd2.exe
C:\Archivos de programa\ESET\ESET Smart Security\egui.exe
C:\Archivos de programa\pdfforge Toolbar\SearchSettings.exe
C:\Archivos de programa\iTunes\iTunesHelper.exe
C:\Archivos de programa\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\Archivos de programa\CursorXP\CursorXP.exe
C:\Archivos de programa\RocketDock\RocketDock.exe
C:\Archivos de programa\iPod\bin\iPodService.exe
C:\Archivos de programa\Mozilla Firefox\firefox.exe
C:\Documents and Settings\María\Escritorio\dds.scr

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyServer = 55402496@prodigy.com.mx:80
uInternet Settings,ProxyOverride = *.local;<local>
uURLSearchHooks: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - c:\archivos de programa\pdfforge toolbar\SearchSettings.dll
mWinlogon: UIHost=c:\windows\system32\logonuiX.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\archivos de programa\archivos comunes\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\archivos de programa\java\jre6\bin\ssv.dll
BHO: Windows Live Aplicación auxiliar de inicio de sesión: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\archivos de programa\archivos comunes\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\archivos de programa\pdfforge toolbar\WidgiToolbarIE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\archivos de programa\java\jre6\bin\jp2ssv.dll
BHO: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - c:\archivos de programa\pdfforge toolbar\SearchSettings.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\archivos de programa\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\archivos de programa\pdfforge toolbar\WidgiToolbarIE.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - No File
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [MsnMsgr] "c:\archivos de programa\windows live\messenger\msnmsgr.exe" /background
uRun: [LClock] c:\archivos de programa\lclock\lclock.exe
uRun: [CursorXP] c:\archivos de programa\cursorxp\CursorXP.exe
uRun: [RocketDock] "c:\archivos de programa\rocketdock\RocketDock.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [SunJavaUpdateSched] "c:\archivos de programa\java\jre6\bin\jusched.exe"
mRun: [SynTPLpr] c:\archivos de programa\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\archivos de programa\synaptics\syntp\SynTPEnh.exe
mRun: [eabconfg.cpl] c:\archivos de programa\hpq\quick launch buttons\EabServr.exe /Start
mRun: [Cpqset] c:\archivos de programa\hpq\default settings\cpqset.exe
mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
mRun: [StatusClient] c:\archivos de programa\hewlett-packard\toolbox2.0\apache tomcat 4.0\webapps\toolbox\statusclient\StatusClient.exe /auto
mRun: [TomcatStartup] c:\archivos de programa\hewlett-packard\toolbox2.0\hpbpsttp.exe
mRun: [HPLJ Config] c:\archivos de programa\hewlett-packard\hp laserjet 1150_1300\SetConfig.exe -c Network -p hpLaserJet1300n -pn "hp LaserJet 1300n PCL 6" -n 0 -l 1034 -sl 120000
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [HP Software Update] c:\archivos de programa\hp\hp software update\HPWuSchd2.exe
mRun: [hpfsched] c:\windows\hpfsched.exe
mRun: [egui] "c:\archivos de programa\eset\eset smart security\egui.exe" /hide /waitservice
mRun: [Adobe Reader Speed Launcher] "c:\archivos de programa\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [LogonStudio] "c:\archivos de programa\wincustomize\logonstudio\logonstudio.exe" /RANDOM
mRun: [SearchSettings] c:\archivos de programa\pdfforge toolbar\SearchSettings.exe
mRun: [QuickTime Task] "c:\archivos de programa\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\archivos de programa\itunes\iTunesHelper.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\mara~1\menini~1\progra~1\inicio\stardo~1.lnk - c:\archivos de programa\stardock\objectdock\ObjectDock.exe
StartupFolder: c:\docume~1\alluse~1\menini~1\progra~1\inicio\monito~1.lnk - c:\archivos de programa\apache software foundation\apache2.2\bin\ApacheMonitor.exe
IE: &Windows Live Search - c:\archivos de programa\windows live toolbar\msntb.dll/search.htm
IE: E&xportar a Microsoft Excel - c:\archiv~1\micros~3\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\archivos de programa\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\archiv~1\micros~3\office11\REFIEBAR.DLL
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - hxxp://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: igfxcui - igfxsrvc.dll
SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - No File

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\mara~1\datosd~1\mozilla\firefox\profiles\gaqbp1ke.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - chrome://fastdial/content/fastdial.html
FF - prefs.js: keyword.URL - hxxp://mx.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=971163&p=
FF - component: c:\archivos de programa\mozilla firefox\extensions\{b922d405-6d13-4a2b-ae89-08a030da4402}\components\pdfforgeToolbarFF.dll
FF - component: c:\archivos de programa\mozilla firefox\extensions\search@searchsettings.com\components\SearchSettingsFF.dll
FF - plugin: c:\archivos de programa\mozilla firefox\plugins\npqtplugin8.dll
FF - plugin: c:\archivos de programa\quicktime\plugins\npqtplugin8.dll

============= SERVICES / DRIVERS ===============

R2 Apache2.2;Apache2.2;c:\archivos de programa\apache software foundation\apache2.2\bin\httpd.exe [2008-12-10 24636]
R2 ekrn;Eset Service;c:\archivos de programa\eset\eset smart security\ekrn.exe [2008-3-13 472320]

=============== Created Last 30 ================

2009-03-13 08:25 579,584 a------- c:\windows\system32\dllcache\user32.dll
2009-03-13 08:24 <DIR> --d----- c:\windows\ERUNT
2009-03-13 08:23 <DIR> --d----- C:\SDFix
2009-03-12 12:45 <DIR> --d-hr-- c:\documents and settings\maría\Recent
2009-03-12 12:37 <DIR> --d----- c:\archivos de programa\CCleaner
2009-03-12 11:10 <DIR> --d----- C:\MSNCleaner
2009-03-11 16:26 198,918 a------- C:\real.exe
2009-03-07 21:16 <DIR> --d----- C:\Ceci
2009-03-07 21:01 49,714 ---shr-- c:\windows\shvhost.exe
2009-02-21 20:28 <DIR> --d----- c:\docume~1\alluse~1\datosd~1\Spybot - Search & Destroy
2009-02-21 20:28 <DIR> --d----- c:\archivos de programa\Spybot - Search & Destroy
2009-02-20 10:59 25 a------- c:\windows\.prj
2009-02-19 19:45 <DIR> --d----- c:\archivos de programa\iPod
2009-02-19 19:44 <DIR> --d----- c:\docume~1\alluse~1\datosd~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-02-19 19:44 <DIR> --d----- c:\archivos de programa\iTunes
2009-02-18 22:46 <DIR> --d----- c:\docume~1\mara~1\datosd~1\Search Settings
2009-02-18 22:46 <DIR> --d----- c:\docume~1\mara~1\datosd~1\pdfforge
2009-02-18 22:35 <DIR> --d----- c:\archivos de programa\pdfforge Toolbar
2009-02-18 22:34 137,000 a------- c:\windows\system32\MSMAPI32.OCX
2009-02-18 22:34 116,224 a------- c:\windows\system32\pdfcmnnt.dll
2009-02-18 22:34 23,552 a------- c:\windows\system32\MSMPIDE.DLL
2009-02-18 22:34 <DIR> --d----- c:\archivos de programa\PDFCreator
2009-02-18 10:30 <DIR> --d----- C:\Program Files
2009-02-17 17:50 335 a------- c:\windows\pagebreeze.ini
2009-02-17 17:50 44 a------- c:\windows\formbreeze.ini
2009-02-17 17:50 203,576 a------- c:\windows\system32\RICHTX32.OCX
2009-02-17 17:50 97,280 a------- c:\windows\system32\vspell32.ocx
2009-02-17 17:50 102,912 a------- c:\windows\system32\Vb6stkit.dll
2009-02-17 17:50 70,656 a------- c:\windows\system32\vspell32.dll
2009-02-17 17:50 89,600 a------- c:\windows\system32\Leocx32.ocx
2009-02-17 17:50 84,992 a------- c:\windows\system32\Ledit32.dll
2009-02-17 17:50 503,808 a------- c:\windows\system32\ChilkatFTPx.dll
2009-02-17 17:50 <DIR> --d----- c:\archivos de programa\PageBreeze
2009-02-17 15:08 <DIR> --d----- c:\docume~1\alluse~1\datosd~1\SWiSHMax2WorkFolder
2009-02-15 21:15 <DIR> --d----- c:\archivos de programa\TrueLaunchBar
2009-02-14 23:04 <DIR> --d----- c:\archivos de programa\MySQL
2009-02-14 22:58 <DIR> --d----- c:\archivos de programa\PHP
2009-02-14 22:44 <DIR> --d----- c:\archivos de programa\Apache Software Foundation

==================== Find3M ====================

2009-03-13 10:17 5,242,880 a---h--- c:\documents and settings\maría\NTUSER.DAT
2009-02-10 23:41 7,710,720 a------- c:\windows\system32\logonuiX.exe
2009-02-09 11:51 410,984 a------- c:\windows\system32\deploytk.dll
2009-02-09 08:06 1,846,912 a------- c:\windows\system32\win32k.sys
2009-02-09 08:06 1,846,912 -------- c:\windows\system32\dllcache\win32k.sys
2009-02-06 18:52 49,504 a------- c:\windows\system32\sirenacm.dll
2009-01-20 23:44 443,846 a------- c:\windows\system32\perfh00A.dat
2009-01-20 23:44 70,266 a------- c:\windows\system32\perfc00A.dat
2009-01-20 23:27 83,187 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-01-20 15:55 441 a------- C:\bootbak.bat
2009-01-16 21:05 3,594,752 a------- c:\windows\system32\dllcache\mshtml.dll
2008-12-31 17:04 691,560 a------- c:\windows\system32\OGACheckControl.dll
2008-12-31 17:04 528,744 a------- c:\windows\system32\OGAVerify.exe
2008-12-31 17:04 502,120 a------- c:\windows\system32\OGAAddin.dll
2008-12-20 16:47 826,368 a------- c:\windows\system32\wininet.dll
2008-12-20 16:47 826,368 a------- c:\windows\system32\dllcache\wininet.dll
2008-12-20 16:47 1,160,192 a------- c:\windows\system32\dllcache\urlmon.dll
2008-12-20 16:47 233,472 -------- c:\windows\system32\dllcache\webcheck.dll
2008-12-20 16:47 44,544 a------- c:\windows\system32\dllcache\pngfilt.dll
2008-12-20 16:47 105,984 -------- c:\windows\system32\dllcache\url.dll
2008-12-20 16:47 671,232 a------- c:\windows\system32\dllcache\mstime.dll
2008-12-20 16:47 102,912 -------- c:\windows\system32\dllcache\occache.dll
2008-12-20 16:47 477,696 a------- c:\windows\system32\dllcache\mshtmled.dll
2008-12-20 16:47 193,024 a------- c:\windows\system32\dllcache\msrating.dll
2008-12-19 03:11 70,656 -------- c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 03:10 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2008-12-18 23:25 634,024 -------- c:\windows\system32\dllcache\iexplore.exe
2008-12-18 23:23 161,792 -------- c:\windows\system32\dllcache\ieakui.dll
2005-11-03 17:29 72,832 a----r-- c:\windows\inf\CamAvb.sys
2007-10-08 13:00 16,384 a--sh--- c:\windows\temp\temporary internet files\content.ie5\index.dat

============= FINISH: 10:58:50.40 ===============

Attached Files

Edited by Orange Blossom, 11 February 2013 - 04:19 AM.
Deactivate link. ~ OB

BC AdBot (Login to Remove)


#2 suebaby41


    W.A.M. (Women Against Malware)

  • Malware Response Team
  • 6,248 posts
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:10:14 PM

Posted 24 March 2009 - 07:16 PM

Welcome to the BleepingComputer Forums.

Since it has been a few days since you scanned your computer with HijackThis, we will need a new HijackThis log. Please download Trend Micro - HijackThis. Do a new scan with Trend Micro - HijackThis and post it in your next reply. Thank you for your patience.

Please see Preparation Guide for use before posting about your potential Malware problem.

If you have already posted this log at another forum or if you decide to seek help at another forum, please let us know. There is a shortage of helpers and taking the time of two volunteer helpers means that someone else may not be helped.

Please post your HijackThis log as a reply to this thread and not as an attachment. I am always leery of opening attachments so I always request that HijackThis logs are to be posted as a reply to the thread. I do not think that you are attaching anything scary but others may do so.

While we are working on your HijackThis log, please:
  • Reply to this thread; do not start another!
  • Do not make any changes on your computer during the cleaning process or download/add programs on your computer unless instructed to do so.
  • Do not run any other tool until instructed to do so!
  • Let me know if any of the links do not work or if any of the tools do not work.
  • Tell me about problems or symptoms that occur during the fix.
  • Do not run any other programs or open any other windows while doing a fix.
  • Ask any questions that you have regarding the fix(es), the infection(s), the performance of your computer, etc.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#3 suebaby41


    W.A.M. (Women Against Malware)

  • Malware Response Team
  • 6,248 posts
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:10:14 PM

Posted 03 April 2009 - 06:07 AM

This subject is now closed. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users