Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Ebay Laptop


  • Please log in to reply
3 replies to this topic

#1 Steamhead

Steamhead

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:11:09 AM

Posted 06 August 2005 - 07:56 PM

My dad decided to get a laptop off ebay...bad idea...the thing was riddled with malware..I ran ad-aware, spybot, AVG, and installed ZoneAlarm free version, and if you guys dont mind telling me if they missed anything before I give it back to my dad..

HJT Log

--------------------------------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 5:38:02 PM, on 08/07/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINNT\system32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\Explorer.EXE
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S0BIC1.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\msw\BMan.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINNT\system32\??oolsv.exe
C:\Program Files\saom\cnpa.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Belkin\Belkin 802.11g Wireless Card Configuration Utility\utility.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\abc\Desktop\Malware Removal\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: {B5AB638F-D76C-415B-A8F2-F3CEAC502212} - - (no file)
O2 - BHO: (no name) - {00000000-0000-44A3-8741-4BC1A556C6CF} - C:\Program Files\y5zm3uzf\y5zm3uzf.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {63678683-466F-4095-695D-4331B4C2A2C0} - C:\WINNT\system32\rcgria.dll (file missing)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {8E74EF78-20B8-2C4C-B858-7A22811348E5} - C:\WINNT\system32\sqhgbm.dll
O2 - BHO: (no name) - {A42DB544-73DB-7E7F-8F9A-73A2D9A16FB5} - C:\WINNT\system32\bket.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AOLToolBand Class - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S0BIC1.EXE /P23 "EPSON Stylus C62 Series" /O5 "LPT1:" /M "Stylus C62"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [fqCu4x] C:\winnt\system32\fqCu4x.exe
O4 - HKLM\..\Run: [NLLaOoE.exe] c:\winnt\system32\NLLaOoE.exe
O4 - HKLM\..\Run: [r3ni3pQ] sfcn50.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
O4 - HKLM\..\Run: [103] "C:\Program Files\Defender Pro Anti Spam\admin" "-hide"
O4 - HKLM\..\Run: [exp.exe] C:\WINNT\system32\exp.exe
O4 - HKLM\..\Run: [spgvgjgz] C:\WINNT\spgvgjgz.exe
O4 - HKLM\..\Run: [SpySpotter] C:\PROGRA~1\SPYSPO~1\SpySpotter.exe -onreboot
O4 - HKLM\..\Run: [XoftSpy] C:\Program Files\XoftSpy\XoftSpy.exe -s
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [a04sRfc7O] sdpne.exe
O4 - HKCU\..\Run: [Gjzn] C:\WINNT\system32\??oolsv.exe
O4 - HKCU\..\Run: [Pere] C:\Program Files\saom\cnpa.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Belkin 802.11g Wireless Card Utility.lnk = C:\Program Files\Belkin\Belkin 802.11g Wireless Card Configuration Utility\utility.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\system32\Shdocvw.dll
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1091764151031
O16 - DPF: {B4831DED-3A57-4CC6-9E4B-0E7C5B08DBF4} - http://www.alwaysupdatednews.com/install/aun_0032.exe
O16 - DPF: {BAB3E70B-A847-4A88-ACFC-778FCCC00287} (CActSetupObj Object) - http://www.odysseusmarketing.com/actsetup.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe

BC AdBot (Login to Remove)

 


#2 mikeyrn06

mikeyrn06

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:11:09 AM

Posted 06 August 2005 - 09:38 PM

*DISCLAIMER - Any modifications made to your computer based upon this information is at your own risk.*

I have analyzed your log and the following entries are alleged malware. I have listed what alleged malware they represent:

1.C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe | Adware.SearchTheWeb

2.C:\DOCUME~1\ALLUSE~1\APPLIC~1\msw\BMan.exe |Adware.SearchTheWeb

3.C:\WINNT\system32\??oolsv.exe - Unidentified, mimics the Print Spooler Service Manager

3(sorry can't count tonight).C:\Program Files\saom\cnpa.exe |Unidentified..MOST LIKELY Malware

4.R3 - URLSearchHook: {B5AB638F-D76C-415B-A8F2-F3CEAC502212} - - (no file) |Unidentified..MOST LIKELY Malware

5.O2 - BHO: (no name) - {00000000-0000-44A3-8741-4BC1A556C6CF} - C:\Program Files\y5zm3uzf\y5zm3uzf.dll (file missing)|Unidentified..MOST LIKELY Malware

6.O2 - BHO: (no name) - {63678683-466F-4095-695D-4331B4C2A2C0} - C:\WINNT\system32\rcgria.dll (file missing)|Unidentified..MOST LIKELY Malware

7.O2 - BHO: (no name) - {8E74EF78-20B8-2C4C-B858-7A22811348E5} - C:\WINNT\system32\sqhgbm.dll|Unidentified..MOST LIKELY Malware

8.O2 - BHO: (no name) - {A42DB544-73DB-7E7F-8F9A-73A2D9A16FB5} - C:\WINNT\system32\bket.dll (file missing)|Unidentified..MOST LIKELY Malware

9.O4 - HKLM\..\Run: [fqCu4x] C:\winnt\system32\fqCu4x.exe|Unidentified..MOST LIKELY Malware

10.O4 - HKLM\..\Run: [NLLaOoE.exe] c:\winnt\system32\NLLaOoE.exe|Unidentified..MOST LIKELY Malware

11.O4 - HKLM\..\Run: [r3ni3pQ] sfcn50.exe|Unidentified..MOST LIKELY Malware

12.O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16 |Adware.AUNPS

13.O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe|Adware.SearchTheWeb

14.O4 - HKLM\..\Run: [103] "C:\Program Files\Defender Pro Anti Spam\admin" "-hide"|While this may not TECHNICALLY be malware, there are CERTAINLY far better and less intrusive anti spam programs.

15.O4 - HKLM\..\Run: [exp.exe] C:\WINNT\system32\exp.exe | TROJAN

16.O4 - HKLM\..\Run: [spgvgjgz] C:\WINNT\spgvgjgz.exe Unidentified..MOST LIKELY Malware

17.O4 - HKLM\..\Run: [SpySpotter] C:\PROGRA~1\SPYSPO~1\SpySpotter.exe -onreboot |Useless Spyware Search, Most likely malware itself

18.O4 - HKLM\..\Run: [XoftSpy] C:\Program Files\XoftSpy\XoftSpy.exe -s |Useless Spyware Search, Most likely malware itself

19.O4 - HKCU\..\Run: [a04sRfc7O] sdpne.exe |Unidentified..MOST LIKELY Malware

20.O4 - HKCU\..\Run: [Gjzn] C:\WINNT\system32\??oolsv.exe | MALWARE, designed to mimic the name of the Print Spooler Service Manager

21.O4 - HKCU\..\Run: [Pere] C:\Program Files\saom\cnpa.exe Unidentified..MOST LIKELY Malware

22.O16 - DPF: {B4831DED-3A57-4CC6-9E4B-0E7C5B08DBF4} - http://www.alwaysupdatednews.com/install/aun_0032.exe | Adware.AUNPS

23.O16 - DPF: {BAB3E70B-A847-4A88-ACFC-778FCCC00287} (CActSetupObj Object) - http://www.odysseusmarketing.com/actsetup.cab Unidentified..MOST LIKELY Malware

#3 CrankeBoy

CrankeBoy

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:10:09 AM

Posted 07 August 2005 - 01:45 AM

Deleted content of the post because you are not allowed to post here

Edited by Bobbi Flekman, 10 August 2005 - 06:37 AM.


#4 Bobbi Flekman

Bobbi Flekman

    The computer whisperer


  • Malware Response Team
  • 4,423 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:09 PM

Posted 10 August 2005 - 06:49 AM

Hi Steamhead,

Launch Notepad, and copy/paste the box below into a new text file. Save it as FindFile.bat and save it on your Desktop.

dir C:\WINNT\system32\??oolsv.exe /a h > files.txt
notepad files.txt

Locate FindFile.bat on your Desktop and double-click on it. It will open Notepad with some text in it. Please post the text here.

You might want to save this page on your favorites, so you can find it again when you return. You can also click on your name and click on "Find All Posts" to find your thread.

Run HijackThis, click on "Scan" and check the boxes next to all these items.

R3 - URLSearchHook: {B5AB638F-D76C-415B-A8F2-F3CEAC502212} - - (no file)

O2 - BHO: (no name) - {00000000-0000-44A3-8741-4BC1A556C6CF} - C:
\Program Files\y5zm3uzf\y5zm3uzf.dll (file missing)
O2 - BHO: (no name) - {63678683-466F-4095-695D-4331B4C2A2C0} - C:\WINNT\system32\rcgria.dll (file missing)
O2 - BHO: (no name) - {8E74EF78-20B8-2C4C-B858-7A22811348E5} - C:\WINNT\system32\sqhgbm.dll
O2 - BHO: (no name) - {A42DB544-73DB-7E7F-8F9A-73A2D9A16FB5} - C:\WINNT\system32\bket.dll (file missing)

O4 - HKLM\..\Run: [fqCu4x] C:\winnt\system32\fqCu4x.exe
O4 - HKLM\..\Run: [NLLaOoE.exe] c:\winnt\system32\NLLaOoE.exe
O4 - HKLM\..\Run: [r3ni3pQ] sfcn50.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINNT\system32\exp.exe
O4 - HKLM\..\Run: [spgvgjgz] C:\WINNT\spgvgjgz.exe

SpySpotter is on Spyware Warrior's Rogue List. Uninstall this program!

O4 - HKLM\..\Run: [SpySpotter] C:\PROGRA~1\SPYSPO~1\SpySpotter.exe -onreboot

And even though XoftSpy is not on the list, we don't recommend that one
O4 - HKLM\..\Run: [XoftSpy] C:\Program Files\XoftSpy\XoftSpy.exe -s

O4 - HKCU\..\Run: [a04sRfc7O] sdpne.exe
O4 - HKCU\..\Run: [Gjzn] C:\WINNT\system32\??oolsv.exe
O4 - HKCU\..\Run: [Pere] C:\Program Files\saom\cnpa.exe

O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)

O16 - DPF: {B4831DED-3A57-4CC6-9E4B-0E7C5B08DBF4} - http://www.alwaysupdatednews.com/install/aun_0032.exe
O16 - DPF: {BAB3E70B-A847-4A88-ACFC-778FCCC00287} (CActSetupObj Object) - http://www.odysseusmarketing.com/actsetup.cab


Then close all windows, and browsers, except HijackThis. Tell HijackThis to "Fix checked".

Restart your computer in Safe Mode. How do I Safe Boot my computer?

Show hidden files. How do I show hidden files?
At the end if the fix you can return the files to hidden status if you want.

Delete the following files in red (it could be that they are deleted already):

C:\WINNT\system32\rcgria.dll
C:\WINNT\system32\sqhgbm.dll
C:\WINNT\system32\bket.dll
C:\winnt\system32\fqCu4x.exe
c:\winnt\system32\NLLaOoE.exe
C:\WINNT\system32\sfcn50.exe
C:\WINNT\system32\AUNPS2.DLL
C:\WINNT\system32\exp.exe
C:\WINNT\spgvgjgz.exe
C:\WINNT\system32\sdpne.exe

Delete the following folders in red (it could be that they are deleted already):

C:\Program Files\y5zm3uzf
C:\Documents and Settings\All Users\Application Data\msw
C:\Program Files\SpySpotter
C:\Program Files\XoftSpy
C:\Program Files\saom

Restart your computer and post a new log in this thread.
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users