Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Iworm_attck_v122.02a (?)


  • Please log in to reply
1 reply to this topic

#1 jhawke

jhawke

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:03:43 AM

Posted 08 June 2006 - 11:25 AM

i have no idea what my mother has installed on her PC, but she is getting topsecuritysite.net as her default IE page. other symptoms include:

- blank pages popping up
- system32 folder opens on reboot
- can't access the internet (ironically, i can't even get topsecuritysite.net to load right now)
- recently removed spyguard ware (sp?) and a ton of other crap with the tools on your "preparation guide for use before posting a hijackthis log"

due to the lack of internet acces (or a burner - damn), i am typing this log file onto my mac from her computer screen... i will try to keep the errors to a minimum (the upper/lower case S(s)ystem 32 are not errors), but i apologize in advance for anything else.

and yes, i did go through all of the steps in your lovely "preparation guide" - thank you. :thumbsup:

please let me know what other information you may need. thanks very VERY much in advance.

`jennifer

Logfile of HijackThis v1.99.1
Scan saved at 7:47:28 AM, on 08/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\System32\services.exe
C:\WINDOWS\System32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Defender\MSMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\SNDSrvc.exe
C:\Program Files\Common Files\SPGGC\SPBBCSvc.exe
C:\Program Files\Common Files\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system\hpsysdrv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE
C:\WINDOWS\System32\RunDLL32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Creative\Shared Files\CamTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Documents and Settings\Compaq_Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main, Default_Search_URL = prosearching.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main, Start Page = http://www.learmedia.ca/learadmin
R1 - HKCU\Software\Microsoft\Internet Explorer\Main, SearchURL = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = http://go.microsoft.com/fwlink/?LinkId=566...rosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main, SearchURL = prosearching.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main, Local Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main, Start Page_back = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main, Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page_bak = prosearching.com
02 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adibe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
02 - BHO: (no name) - {53707962-6F742D532644206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
02 - BHO: Nothing - {686a161d-5bd1-4999-8832-6393f41e564c} - C:\WINDOWS\system32\hp100.tmp
02 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
02 - BHO: CNavExtBho Class - {BDF3E30-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
03 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
04 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
04 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
04 - HKLM\..\Run: [nwiz] nwiz.exe /install
04 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
04 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
04 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
04 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
04 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
04 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFace 4.0\SetHook.exe
04 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
04 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"
04 - HKLM\..\Run: [PD0630 STISvc] RunDLL32.exe P0630Pin.dll,RunDLL32EP 513
04 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
04 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
04 - HKLM\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
04 - HKLM\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative Shared Files\CamTray.exe"
04 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\blah
04 - Global Startup: Kodak Easy Share Software.lnk - C:\Program Files\Kodak\blah
04 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\blah
08 - Extra context menu item: &Search - http://ka.bar.need2find.com/KA/menusearch.html?p=KA
09 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
09 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
016 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid39204
016 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg.com/us.yimg.com/i/cha...v45/yacscom.cab
016 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) C:\Program Files\Yahoo!\Common\yinsthelper.dll
016 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1138246853656
016 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
016 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
016 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab
018 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
020 - Winlogon Notify: wineak32 - C:\WINDOWS\SYSTEM32\wineak32.dll
023 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\blah
023 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
023 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Symantec\blah
023 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Symantec\blah
023 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Symantec\blah
023 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Symantec\blah
023 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
023 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Symantec\blah
023 - Service: Norton AntiVirus Firewall Monitor Servic (NPFMntor) - Symantec Corporation - C:\Program Files\Symantec\blah
023 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
023 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
023 - Service: SAVScan - Symantec Corporation - C:\Program Files\blah
023 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\blah
023 - Service: Symantec SPBBCSvc (SPBBCSvc) - - Symantec Corporation - C:\Program Files\blah
023 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\blah
023 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

BC AdBot (Login to Remove)

 


m

#2 Guest_Cretemonster_*

Guest_Cretemonster_*

  • Guests
  • OFFLINE
  •  

Posted 08 June 2006 - 07:33 PM

Hi jhawke and Welcome to the Bleeping Computer!

Download smitRem.exe ©noahdfear, and save the file to your desktop.
Double click on the file to extract it to it's own folder on the desktop.

Place a shortcut to Panda ActiveScan on your desktop (in Internet Explorer, right click on Panda ActiveScan link select "Copy Shortcut" then right click on your desktop and select "Paste Shortcut" or in FireFox right-click the link and select "Save Link As" and save it to your desktop).

Please download the trial version of ewido anti-malware here:
http://www.ewido.net/en/download/

Please read Ewido Setup Instructions
Install it, and update the definitions to the newest files. Do NOT run a scan yet.

If you have not already installed Ad-Aware SE 1.06, follow these download and setup instructions, otherwise, check for updates:
Ad-Aware SE Setup
Don't run it yet!

Next, please reboot your computer in SafeMode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.


Open Ad-aware and do a full scan. Remove all it finds.


Run Ewido:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • While the scan is in progress you will be prompted to clean files, click OK
  • When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Close ewido anti-malware.

Next go to Control Panel click Display > Desktop > Customize Desktop > Web > Uncheck "Security Info" if present.

Reboot back into Windows and click the Panda ActiveScan shortcut.
  • Once you are on the Panda site click the Scan your PC button.
  • A new window will open...click the Check Now button.
    • Enter your Country
    • Enter your State/Province
    • Enter your e-mail address and click send
    • Select either Home User or Company
    • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When the download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log, the contents of smitfiles.txt and the Ewido Log by using Add Reply.
Let us know if any problems persist.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users