Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijacked By Pop-ups. Help Please...


  • Please log in to reply
8 replies to this topic

#1 mmarramm

mmarramm

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:51 AM

Posted 30 April 2006 - 01:22 PM

Greetings. My stepsons PC has been hijacked. I have managed pretty well in the past to clean it up myself but this one is giving me fits. Any assistance would be much appreciated. Thanks!

Logfile of HijackThis v1.99.1
Scan saved at 2:18:50 PM, on 4/30/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\NavNT\vptray.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Spybot - Search & Destroy\ZipDll.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\System32\svchost.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R3 - URLSearchHook: (no name) - _{B1FF7D15-ED88-B102-A0A0-E2CB2D955ACF} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\ncbmd.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,yxiqnrb.exe
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\enl0l13m1.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe

BC AdBot (Login to Remove)

 


#2 Skate_Punk_21

Skate_Punk_21

    Crapware Killing Canuck!


  • Members
  • 185 posts
  • OFFLINE
  •  
  • Local time:03:51 AM

Posted 30 April 2006 - 01:54 PM

Please download Brute Force Uninstaller to your desktop. (rightclick on this link and choose save as, if using IE save target as)
  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk" (C:) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
  • Download qoofix.bat (rightclick on this link and choose save as, if using IE save target as)
  • Place qoofix.bat in your C:\BFU - folder. (Important!)
  • Doubleclick qooFix.bat, Close all browsers and explorer folders.
  • Choose option 1 (Qoolfix autofix) and follow the prompts.
  • Please be patient, it will take about five minutes.
  • After the PC has restarted please post another hijackthis log.

If I've helped you in any way, please consider a donation to help me continue the fight: Posted Image
Posted Image

#3 mmarramm

mmarramm
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:51 AM

Posted 30 April 2006 - 02:12 PM

When I execute qoofix.bat, once it starts to run I get a popup that reads:

c:\windows\system32\regedit.com is not a valid win32 application.

qoofix.bat shows a couple of "Access Denied" errors and then closes leaving a "Systems Settings Change" window open and asking if I want to reboot now.

Is it worth rebooting or do we need to fix the problem with regedit not working (regedit does exist in c:\windows but not c:\windows\system32).

Thanks for the response...

#4 mmarramm

mmarramm
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:51 AM

Posted 30 April 2006 - 03:37 PM

For now I have gotten by the problem of it not being able to find regedit by changing the references of regedit to c:\windows\regedit in qoofix.bat. I rebooted and ran hijackthis and this is the new log...

Logfile of HijackThis v1.99.1
Scan saved at 4:31:37 PM, on 4/30/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\NavNT\vptray.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\ICROSO~1.NET\notepad.exe
C:\Program Files\Common Files\F?nts\r?ndll32.exe
C:\Program Files\AOD\TRAINER.exe
C:\WINDOWS\System32\svchost.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R3 - URLSearchHook: (no name) - _{B1FF7D15-ED88-B102-A0A0-E2CB2D955ACF} - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKCU\..\Run: [Osoo] "C:\WINDOWS\system32\ICROSO~1.NET\notepad.exe" -vt yazr
O4 - HKCU\..\Run: [Exyivp] C:\Program Files\Common Files\F?nts\r?ndll32.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll
O20 - Winlogon Notify: H323TSP - C:\WINDOWS\system32\e0jmla111d.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe

#5 Skate_Punk_21

Skate_Punk_21

    Crapware Killing Canuck!


  • Members
  • 185 posts
  • OFFLINE
  •  
  • Local time:03:51 AM

Posted 01 May 2006 - 02:17 PM

Good work :thumbsup: thats a big chunk of the infection outta the way, now on to the next one...

Please download Look2Me-Destroyer.exe to your desktop.
  • Close all windows before continuing.
  • Double-click Look2Me-Destroyer.exe to run it.
  • Put a check next to Run this program as a task.
  • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
  • When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
  • Once it's done scanning, click the Remove L2M button.
  • You will receive a Done Scanning message, click OK.
  • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
  • Your computer will then shutdown.
  • Turn your computer back on.
  • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32 Directory.
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX
If I've helped you in any way, please consider a donation to help me continue the fight: Posted Image
Posted Image

#6 mmarramm

mmarramm
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:51 AM

Posted 01 May 2006 - 06:02 PM

Thanks for the continued support... It looks like we're there (or almost there).
Logfile of HijackThis v1.99.1
Scan saved at 6:55:44 PM, on 5/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\NavNT\vptray.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\NetMeeting\wcb32.exe
C:\WINDOWS\System32\svchost.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - URLSearchHook: (no name) - _{B1FF7D15-ED88-B102-A0A0-E2CB2D955ACF} - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe


------------------------------------------------------------------------------


Look2Me-Destroyer V1.0.12

Scanning for infected files.....
Scan started at 5/1/2006 6:39:52 PM

Infected! C:\WINDOWS\system32\k6620gjoe6oc0.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP472\A0030582.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP472\A0030586.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP473\A0030626.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP473\A0030628.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030636.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030637.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030643.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030644.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030651.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030652.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030657.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030661.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030749.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030750.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030751.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030761.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030765.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030769.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030778.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030785.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030789.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030790.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030808.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030809.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030818.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030819.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030825.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030826.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030870.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030875.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030877.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030881.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP475\A0030889.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP475\A0030893.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP475\A0030899.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP475\A0030903.dll
Infected! C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP475\A0031902.dll
Infected! C:\WINDOWS\system32\djvmgr.dll
Infected! C:\WINDOWS\system32\k6620gjoe6oc0.dll
Infected! C:\WINDOWS\system32\o8luli3918.dll
Infected! C:\WINDOWS\system32\s0pu0a79ed.dll
Infected! C:\WINDOWS\system32\xnsp1res.dll

Attempting to delete infected files...

Attempting to delete: C:\WINDOWS\system32\k6620gjoe6oc0.dll
C:\WINDOWS\system32\k6620gjoe6oc0.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP472\A0030582.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP472\A0030582.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP472\A0030586.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP472\A0030586.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP473\A0030626.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP473\A0030626.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP473\A0030628.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP473\A0030628.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030636.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030636.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030637.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030637.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030643.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030643.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030644.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030644.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030651.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030651.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030652.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030652.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030657.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030657.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030661.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030661.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030749.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030749.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030750.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030750.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030751.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030751.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030761.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030761.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030765.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030765.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030769.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030769.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030778.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030778.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030785.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030785.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030789.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030789.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030790.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030790.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030808.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030808.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030809.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030809.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030818.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030818.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030819.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030819.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030825.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030825.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030826.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030826.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030870.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030870.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030875.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030875.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030877.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030877.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030881.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP474\A0030881.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP475\A0030889.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP475\A0030889.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP475\A0030893.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP475\A0030893.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP475\A0030899.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP475\A0030899.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP475\A0030903.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP475\A0030903.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP475\A0031902.dll
C:\System Volume Information\_restore{AB86B0B6-3EEC-4164-B94C-1DCE6213AA65}\RP475\A0031902.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\djvmgr.dll
C:\WINDOWS\system32\djvmgr.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\k6620gjoe6oc0.dll
C:\WINDOWS\system32\k6620gjoe6oc0.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\o8luli3918.dll
C:\WINDOWS\system32\o8luli3918.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\s0pu0a79ed.dll
C:\WINDOWS\system32\s0pu0a79ed.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\xnsp1res.dll
C:\WINDOWS\system32\xnsp1res.dll Deleted successfully!

Making registry repairs.

Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SideBySide

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{B3E09AB7-F116-4F9F-8321-A0D0078CAE8F}"
HKCR\Clsid\{B3E09AB7-F116-4F9F-8321-A0D0078CAE8F}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{2C77169D-E492-4D66-BBCB-B206D273BC41}"
HKCR\Clsid\{2C77169D-E492-4D66-BBCB-B206D273BC41}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded

#7 Skate_Punk_21

Skate_Punk_21

    Crapware Killing Canuck!


  • Members
  • 185 posts
  • OFFLINE
  •  
  • Local time:03:51 AM

Posted 01 May 2006 - 08:38 PM

wow your log just got a lot shorter!
Perform an online scan with Internet Explorer with Panda ActiveScan
  • Click Scan your PC & a 'pop up' window shall appear. *ensure that your pop up blocker doesn't block it
  • Click Scan Now
  • Enter your e-mail address & click Scan Now ...begins downloading 8 MB Panda's ActiveX controls
Begin the scan by selecting My Computer
  • If it finds any malware, it will offer you a report.
  • Click on see report. Then click Save report
Post the contents of the report in your next reply along with a new HJT log

*You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
*Turn off the real time scanner of any existing antivirus program while performing the online scan


Please post a fresh HijackThis log & the Log from Panda so that we can check if your system is clean.
If I've helped you in any way, please consider a donation to help me continue the fight: Posted Image
Posted Image

#8 mmarramm

mmarramm
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:51 AM

Posted 06 May 2006 - 03:30 PM

Sorry for the long time in between posts. It's been a busy week. I don't have the log to post now but everything is cleaned off. Thanks skate_punk_21 for all of your help. I sent you something through paypal earlier in the week.

Thanks again.

#9 Skate_Punk_21

Skate_Punk_21

    Crapware Killing Canuck!


  • Members
  • 185 posts
  • OFFLINE
  •  
  • Local time:03:51 AM

Posted 07 May 2006 - 12:24 PM

I received that :thumbsup: thank you for your kindness, and glad i could help.
Skate
If I've helped you in any way, please consider a donation to help me continue the fight: Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users