Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijackthis Log: Please Help Diagnose


  • This topic is locked This topic is locked
7 replies to this topic

#1 berisjuan7

berisjuan7

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:07:31 AM

Posted 27 June 2006 - 09:58 AM

Logfile of HijackThis v1.99.1
Scan saved at 09:51:06 a.m., on 27/06/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\System32\SCardSvr.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
D:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
D:\WINNT\System32\llssrv.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
D:\WINNT\system32\nvsvc32.exe
D:\oracle\ora92\bin\omtsreco.exe
D:\oracle\ora92\bin\agntsrvc.exe
D:\oracle\ora92\BIN\TNSLSNR.exe
D:\WINNT\system32\cmd.exe
D:\oracle\ora92\bin\dbsnmp.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\System32\tcpsvcs.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\wins.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
D:\WINNT\system32\CCM\CcmExec.exe
D:\WINNT\system32\Dfssvc.exe
D:\WINNT\System32\inetsrv\inetinfo.exe
D:\WINNT\System32\msdtc.exe
D:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
D:\WINNT\system32\mqsvc.exe
D:\WINNT\system32\rundll32.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\Explorer.EXE
D:\WINNT\system32\wuauclt.exe
D:\WINNT\system32\PRPCUI.exe
D:\Program Files\Apoint\Apoint.exe
D:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
D:\WINNT\system32\internat.exe
D:\Program Files\MSN Messenger\MsnMsgr.Exe
D:\Program Files\Apoint\Apntex.exe
F:\Program Files\Ares Lite Edition\AresLite.exe
D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
D:\Program Files\Dell\Bluetooth Software\BTTray.exe
D:\PROGRA~1\Dell\BLUETO~1\BTSTAC~1.EXE
D:\WINNT\system32\svchost.exe
D:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
D:\WINNT\system32\cmd.exe
D:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
D:\WINNT\system32\mshta.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Quest Software\TOAD\TOAD.exe
D:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.search.msn.com/en-us/srchasst/srchasst.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.microsoft.com/search/lobby/search.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/en-us/srchasst/srchasst.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.gdmex.com:8002
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <local>
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [Apoint] D:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [NT Services] ntsvc.exe
O4 - HKLM\..\Run: [vptray] D:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdwareAlert] D:\Program Files\AdwareAlert\AdwareAlert.Exe -boot
O4 - HKLM\..\RunServices: [NT Services] ntsvc.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [areslite] "F:\Program Files\Ares Lite Edition\AresLite.exe" -h
O4 - HKCU\..\Run: [ntdll.dll] "F:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [updateMgr] "D:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - Global Startup: Administrador de servicios.lnk = D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = D:\Program Files\Dell\Bluetooth Software\BTTray.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://D:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy - D:\Program Files\Altova\XMLSpy2006\spy.htm
O8 - Extra context menu item: Send To &Bluetooth - D:\Program Files\Dell\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINNT\system32\msjava.dll
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - D:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - D:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\WINNT\system32\shdocvw.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\Dell\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\Dell\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstall...oupe/index.html
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = smnyl.com.mx
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = smnyl.com.mx
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = smnyl.com.mx
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - D:\WINNT\system32\btxppanel.dll
O20 - Winlogon Notify: NavLogon - D:\WINNT\system32\NavLogon.dll
O20 - Winlogon Notify: Uninstall - D:\WINNT\system32\gp86l3ls1.dll
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - D:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
O23 - Service: Command Service (cmdService) - Unknown owner - D:\WINNT\SnVhbiBCZXJpc3RhaW4\command.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - D:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - D:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NT Services - Unknown owner - D:\WINNT\system32\ntsvc.exe" -service (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINNT\system32\nvsvc32.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - D:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92Agent - Oracle Corporation - D:\oracle\ora92\bin\agntsrvc.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - D:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: OracleOraHome92HTTPServer - Unknown owner - D:\oracle\ora92\Apache\Apache\apache.exe" --ntservice (file missing)
O23 - Service: OracleOraHome92PagingServer - Unknown owner - D:\oracle\ora92/bin/pagntsrv.exe
O23 - Service: OracleOraHome92SNMPPeerEncapsulator - Unknown owner - D:\oracle\ora92\BIN\ENCSVC.EXE
O23 - Service: OracleOraHome92SNMPPeerMasterAgent - Unknown owner - D:\oracle\ora92\BIN\AGNTSVC.EXE
O23 - Service: OracleOraHome92TNSListener - Unknown owner - D:\oracle\ora92\BIN\TNSLSNR.exe
O23 - Service: OracleServiceBIMBO - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceCDF - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceGIS - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceHEWITT - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServicePRUEBA - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceSEGMTY - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceSFP - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceSTDKSYS - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: Pml Driver HPZ12 - HP - D:\WINNT\system32\HPZipm12.exe
O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - D:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe

BC AdBot (Login to Remove)

 


#2 berisjuan7

berisjuan7
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:07:31 AM

Posted 28 June 2006 - 11:48 AM

More details on the case:

Here are some of th popups i get.

//www.redemption-slip.com/t112851063.html
//www.announceme-nt.com/t122851063.html
//www.zestyfind.com/cgi-bin/search.cgi?keywords=investing+online
//www.broadcast-ing.com/t112851063.html
//www.savi-ngs.com/t112851063.html

I also had my etc/hosts modified, but i used hijackthis to fix it, but the popups are still appearing.

Sometimes i get an error, something like, the winlogon process has failed, and que i click on accept, an blue screen appears with the same message, and i have to reboot.

thanks

//Mod edit to modify URLs above.

Edited by KoanYorel, 28 June 2006 - 12:03 PM.


#3 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:02:31 PM

Posted 05 July 2006 - 08:39 AM

Hi,

The forums are really busy, that explains why logs get behind. If you still need some help, please start with posting a new hijackthislog in this thread. Don't start with a new thread.
Then I'll take a look. :thumbsup:
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#4 berisjuan7

berisjuan7
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:07:31 AM

Posted 07 July 2006 - 10:23 AM

thanks for your help, heres the log:

Logfile of HijackThis v1.99.1
Scan saved at 09:43:55 a.m., on 07/07/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\System32\SCardSvr.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
D:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
D:\WINNT\System32\llssrv.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
D:\WINNT\system32\nvsvc32.exe
D:\oracle\ora92\bin\omtsreco.exe
D:\oracle\ora92\bin\agntsrvc.exe
D:\oracle\ora92\BIN\TNSLSNR.exe
D:\WINNT\system32\cmd.exe
D:\oracle\ora92\bin\dbsnmp.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\System32\tcpsvcs.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\wins.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
D:\WINNT\system32\CCM\CcmExec.exe
D:\WINNT\system32\Dfssvc.exe
D:\WINNT\System32\inetsrv\inetinfo.exe
D:\WINNT\System32\msdtc.exe
D:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
D:\WINNT\system32\mqsvc.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\rundll32.exe
D:\WINNT\Explorer.EXE
D:\WINNT\system32\PRPCUI.exe
D:\Program Files\Apoint\Apoint.exe
D:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
D:\WINNT\system32\internat.exe
D:\Program Files\Apoint\Apntex.exe
D:\Program Files\MSN Messenger\MsnMsgr.Exe
D:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
D:\Program Files\Dell\Bluetooth Software\BTTray.exe
D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
D:\PROGRA~1\Dell\BLUETO~1\BTSTAC~1.EXE
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\meta4\M4DevClient\Bin\M4Mind.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.gdmex.com:8002
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [Apoint] D:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [NT Services] ntsvc.exe
O4 - HKLM\..\Run: [vptray] D:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdwareAlert] D:\Program Files\AdwareAlert\AdwareAlert.Exe -boot
O4 - HKLM\..\RunServices: [NT Services] ntsvc.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [areslite] "F:\Program Files\Ares Lite Edition\AresLite.exe" -h
O4 - HKCU\..\Run: [ntdll.dll] "F:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [updateMgr] "D:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: Administrador de servicios.lnk = D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = D:\Program Files\Dell\Bluetooth Software\BTTray.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://D:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy - D:\Program Files\Altova\XMLSpy2006\spy.htm
O8 - Extra context menu item: Send To &Bluetooth - D:\Program Files\Dell\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINNT\system32\msjava.dll
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - D:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - D:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\WINNT\system32\shdocvw.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\Dell\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\Dell\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstall...oupe/index.html
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = smnyl.com.mx
O17 - HKLM\System\CCS\Services\Tcpip\..\{A2E69A05-565F-47C0-BF9C-6BB7CFF83C6D}: NameServer = 172.29.150.220
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = smnyl.com.mx
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = smnyl.com.mx
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - D:\WINNT\system32\btxppanel.dll
O20 - Winlogon Notify: NavLogon - D:\WINNT\system32\NavLogon.dll
O20 - Winlogon Notify: Reliability - D:\WINNT\system32\dnrq0195e.dll
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - D:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
O23 - Service: Command Service (cmdService) - Unknown owner - D:\WINNT\SnVhbiBCZXJpc3RhaW4\command.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - D:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - D:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NT Services - Unknown owner - D:\WINNT\system32\ntsvc.exe" -service (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINNT\system32\nvsvc32.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - D:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92Agent - Oracle Corporation - D:\oracle\ora92\bin\agntsrvc.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - D:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: OracleOraHome92HTTPServer - Unknown owner - D:\oracle\ora92\Apache\Apache\apache.exe" --ntservice (file missing)
O23 - Service: OracleOraHome92PagingServer - Unknown owner - D:\oracle\ora92/bin/pagntsrv.exe
O23 - Service: OracleOraHome92SNMPPeerEncapsulator - Unknown owner - D:\oracle\ora92\BIN\ENCSVC.EXE
O23 - Service: OracleOraHome92SNMPPeerMasterAgent - Unknown owner - D:\oracle\ora92\BIN\AGNTSVC.EXE
O23 - Service: OracleOraHome92TNSListener - Unknown owner - D:\oracle\ora92\BIN\TNSLSNR.exe
O23 - Service: OracleServiceBIMBO - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceCDF - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceGIS - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceHEWITT - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServicePRUEBA - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceSEGMTY - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceSFP - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceSTDKSYS - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: Pml Driver HPZ12 - HP - D:\WINNT\system32\HPZipm12.exe
O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - D:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe

Some of th popups:

http://www.zestyfind.com/cgi-bin/search.cg...=+ge+appliances
http://www.goodrumor.com/t11691115.html
http://www.cheappress.com/m11691115.html

#5 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:02:31 PM

Posted 07 July 2006 - 10:38 AM

Hello,

Please download Look2Me-Destroyer.exe to your desktop.
  • Close all windows before continuing.
  • Double-click Look2Me-Destroyer.exe to run it.
  • Put a check next to Run this program as a task.
  • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 1 minute. Click OK
    (If Look2Me-Destroyer does not reopen automatically, reboot and try again.)
  • When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
  • Once it's done scanning, click the Remove L2M button.
  • You will receive a Done Scanning message, click OK.
  • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
  • Your computer will then shutdown.
  • Turn your computer back on.
  • Please post the contents of Look2Me-Destroyer.txt present on your desktop and a new HiJackThis log.
If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your D:\Winnt\System32 Directory.
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#6 berisjuan7

berisjuan7
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:07:31 AM

Posted 09 July 2006 - 09:36 AM

I followed the steps, I didn'd receive the runtime error '339'

Thanks, here's the logs

Look2Me-Destroyer V1.0.12

Scanning for infected files.....
Scan started at 09/07/2006 09:14:28 a.m.

Infected! D:\WINNT\system32\en8ul1l91.dll
Infected! D:\WINNT\system32\ahsiis.dll
Infected! D:\WINNT\system32\bcsendto_office.dll
Infected! D:\WINNT\system32\bFtmeter.dll
Infected! D:\WINNT\system32\CBFtp.dll
Infected! D:\WINNT\system32\cEbview.dll
Infected! D:\WINNT\system32\cFbview.dll
Infected! D:\WINNT\system32\ckosys.dll
Infected! D:\WINNT\system32\curtc.dll
Infected! D:\WINNT\system32\cVbview.dll
Infected! D:\WINNT\system32\dgnput.dll
Infected! D:\WINNT\system32\dmcprop.dll
Infected! D:\WINNT\system32\dn0001dme.dll
Infected! D:\WINNT\system32\dn0801due.dll
Infected! D:\WINNT\system32\dn2q01f5e.dll
Infected! D:\WINNT\system32\dn6401jqe.dll
Infected! D:\WINNT\system32\dn6s01j7e.dll
Infected! D:\WINNT\system32\dodmoprp.dll
Infected! D:\WINNT\system32\dWd9.dll
Infected! D:\WINNT\system32\e8200ifme82a0.dll
Infected! D:\WINNT\system32\en8ul1l91.dll
Infected! D:\WINNT\system32\fGxadmin.dll
Infected! D:\WINNT\system32\fp2u03f9e.dll
Infected! D:\WINNT\system32\fp6803jue.dll
Infected! D:\WINNT\system32\fpj8031ue.dll
Infected! D:\WINNT\system32\fpl8033ue.dll
Infected! D:\WINNT\system32\fpnq0355e.dll
Infected! D:\WINNT\system32\g8040idqe80e0.dll
Infected! D:\WINNT\system32\gpnml3511.dll
Infected! D:\WINNT\system32\h40qled51h0.dll
Infected! D:\WINNT\system32\hr4u05h9e.dll
Infected! D:\WINNT\system32\i2060cdsef060.dll
Infected! D:\WINNT\system32\i2420choef4c0.dll
Infected! D:\WINNT\system32\idsrstap.dll
Infected! D:\WINNT\system32\iimsmtp.dll
Infected! D:\WINNT\system32\ir0ul5d91.dll
Infected! D:\WINNT\system32\irj2l51o1.dll
Infected! D:\WINNT\system32\j22q0cf5ef2.dll
Infected! D:\WINNT\system32\j8p0li7m18.dll
Infected! D:\WINNT\system32\jtl4073qe.dll
Infected! D:\WINNT\system32\jtps0777e.dll
Infected! D:\WINNT\system32\kcdne.dll
Infected! D:\WINNT\system32\kkdfc.dll
Infected! D:\WINNT\system32\kt24l7fq1.dll
Infected! D:\WINNT\system32\kt2ml7f11.dll
Infected! D:\WINNT\system32\ktcsvc.dll
Infected! D:\WINNT\system32\l2p20c7oef.dll
Infected! D:\WINNT\system32\lt2027fmg.dll
Infected! D:\WINNT\system32\m2po0c73ef.dll
Infected! D:\WINNT\system32\m446lehs1h46.dll
Infected! D:\WINNT\system32\m8rmli9118.dll
Infected! D:\WINNT\system32\marddm.dll
Infected! D:\WINNT\system32\marperf.dll
Infected! D:\WINNT\system32\mavbvm60.dll
Infected! D:\WINNT\system32\mbastmib.dll
Infected! D:\WINNT\system32\mkvbvm50.dll
Infected! D:\WINNT\system32\mlrclr40.dll
Infected! D:\WINNT\system32\mrcories.dll
Infected! D:\WINNT\system32\mSpo0c73ef.dll
Infected! D:\WINNT\system32\mtrapi.dll
Infected! D:\WINNT\system32\mv4ul9h91.dll
Infected! D:\WINNT\system32\mv82l9lo1.dll
Infected! D:\WINNT\system32\mxrapi.dll
Infected! D:\WINNT\system32\myvcp71.dll
Infected! D:\WINNT\system32\n2p4lc7q1f.dll
Infected! D:\WINNT\system32\ndtrap.dll
Infected! D:\WINNT\system32\ngshrui.dll
Infected! D:\WINNT\system32\nhvdmd.dll
Infected! D:\WINNT\system32\notshell.dll
Infected! D:\WINNT\system32\nrcod.dll
Infected! D:\WINNT\system32\nroglnt.dll
Infected! D:\WINNT\system32\nrtfxperf.dll
Infected! D:\WINNT\system32\ovpf.dll
Infected! D:\WINNT\system32\p46slej71ho.dll
Infected! D:\WINNT\system32\p8r40i9qe8.dll
Infected! D:\WINNT\system32\pfailext.dll
Infected! D:\WINNT\system32\pL6slej71ho.dll
Infected! D:\WINNT\system32\q2ps0c77ef.dll
Infected! D:\WINNT\system32\q8680ijue8o80.dll
Infected! D:\WINNT\system32\qksname.dll
Infected! D:\WINNT\system32\qvvd.dll
Infected! D:\WINNT\system32\qwgr.dll
Infected! D:\WINNT\system32\r4r6le9s1h.dll
Infected! D:\WINNT\system32\rem.dll
Infected! D:\WINNT\system32\rGsppp.dll
Infected! D:\WINNT\system32\ricrt4.dll
Infected! D:\WINNT\system32\rkvpsp.dll
Infected! D:\WINNT\system32\rMsser.dll
Infected! D:\WINNT\system32\rWsmontr.dll
Infected! D:\WINNT\system32\s2rslc971f.dll
Infected! D:\WINNT\system32\s4rsle971h.dll
Infected! D:\WINNT\system32\s6880glue6q80.dll
Infected! D:\WINNT\system32\seorage.dll
Infected! D:\WINNT\system32\sFrslc971f.dll
Infected! D:\WINNT\system32\ssbapiu.dll
Infected! D:\WINNT\system32\t0r8la9u1d.dll
Infected! D:\WINNT\system32\tiec.dll
Infected! D:\WINNT\system32\tnec.dll
Infected! D:\WINNT\system32\wccsapi.dll
Infected! D:\WINNT\system32\wdpdinfo.dll
Infected! D:\WINNT\system32\wipasf.dll
Infected! D:\WINNT\system32\wqdmlog.dll
Infected! D:\WINNT\system32\wrnotify.dll
Infected! D:\WINNT\system32\wsbcheck.dll
Infected! D:\WINNT\system32\wspasf.dll
Infected! D:\WINNT\system32\wvdmlog.dll
Infected! D:\WINNT\system32\wvnssnap.dll
Infected! D:\WINNT\system32\WYASF.dll
Infected! D:\WINNT\system32\wzdmps.dll

Attempting to delete infected files...

Attempting to delete: D:\WINNT\system32\en8ul1l91.dll
D:\WINNT\system32\en8ul1l91.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\ahsiis.dll
D:\WINNT\system32\ahsiis.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\bcsendto_office.dll
D:\WINNT\system32\bcsendto_office.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\bFtmeter.dll
D:\WINNT\system32\bFtmeter.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\CBFtp.dll
D:\WINNT\system32\CBFtp.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\cEbview.dll
D:\WINNT\system32\cEbview.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\cFbview.dll
D:\WINNT\system32\cFbview.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\ckosys.dll
D:\WINNT\system32\ckosys.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\curtc.dll
D:\WINNT\system32\curtc.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\cVbview.dll
D:\WINNT\system32\cVbview.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\dgnput.dll
D:\WINNT\system32\dgnput.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\dmcprop.dll
D:\WINNT\system32\dmcprop.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\dn0001dme.dll
D:\WINNT\system32\dn0001dme.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\dn0801due.dll
D:\WINNT\system32\dn0801due.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\dn2q01f5e.dll
D:\WINNT\system32\dn2q01f5e.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\dn6401jqe.dll
D:\WINNT\system32\dn6401jqe.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\dn6s01j7e.dll
D:\WINNT\system32\dn6s01j7e.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\dodmoprp.dll
D:\WINNT\system32\dodmoprp.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\dWd9.dll
D:\WINNT\system32\dWd9.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\e8200ifme82a0.dll
D:\WINNT\system32\e8200ifme82a0.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\en8ul1l91.dll
D:\WINNT\system32\en8ul1l91.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\fGxadmin.dll
D:\WINNT\system32\fGxadmin.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\fp2u03f9e.dll
D:\WINNT\system32\fp2u03f9e.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\fp6803jue.dll
D:\WINNT\system32\fp6803jue.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\fpj8031ue.dll
D:\WINNT\system32\fpj8031ue.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\fpl8033ue.dll
D:\WINNT\system32\fpl8033ue.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\fpnq0355e.dll
D:\WINNT\system32\fpnq0355e.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\g8040idqe80e0.dll
D:\WINNT\system32\g8040idqe80e0.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\gpnml3511.dll
D:\WINNT\system32\gpnml3511.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\h40qled51h0.dll
D:\WINNT\system32\h40qled51h0.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\hr4u05h9e.dll
D:\WINNT\system32\hr4u05h9e.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\i2060cdsef060.dll
D:\WINNT\system32\i2060cdsef060.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\i2420choef4c0.dll
D:\WINNT\system32\i2420choef4c0.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\idsrstap.dll
D:\WINNT\system32\idsrstap.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\iimsmtp.dll
D:\WINNT\system32\iimsmtp.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\ir0ul5d91.dll
D:\WINNT\system32\ir0ul5d91.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\irj2l51o1.dll
D:\WINNT\system32\irj2l51o1.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\j22q0cf5ef2.dll
D:\WINNT\system32\j22q0cf5ef2.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\j8p0li7m18.dll
D:\WINNT\system32\j8p0li7m18.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\jtl4073qe.dll
D:\WINNT\system32\jtl4073qe.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\jtps0777e.dll
D:\WINNT\system32\jtps0777e.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\kcdne.dll
D:\WINNT\system32\kcdne.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\kkdfc.dll
D:\WINNT\system32\kkdfc.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\kt24l7fq1.dll
D:\WINNT\system32\kt24l7fq1.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\kt2ml7f11.dll
D:\WINNT\system32\kt2ml7f11.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\ktcsvc.dll
D:\WINNT\system32\ktcsvc.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\l2p20c7oef.dll
D:\WINNT\system32\l2p20c7oef.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\lt2027fmg.dll
D:\WINNT\system32\lt2027fmg.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\m2po0c73ef.dll
D:\WINNT\system32\m2po0c73ef.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\m446lehs1h46.dll
D:\WINNT\system32\m446lehs1h46.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\m8rmli9118.dll
D:\WINNT\system32\m8rmli9118.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\marddm.dll
D:\WINNT\system32\marddm.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\marperf.dll
D:\WINNT\system32\marperf.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\mavbvm60.dll
D:\WINNT\system32\mavbvm60.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\mbastmib.dll
D:\WINNT\system32\mbastmib.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\mkvbvm50.dll
D:\WINNT\system32\mkvbvm50.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\mlrclr40.dll
D:\WINNT\system32\mlrclr40.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\mrcories.dll
D:\WINNT\system32\mrcories.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\mSpo0c73ef.dll
D:\WINNT\system32\mSpo0c73ef.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\mtrapi.dll
D:\WINNT\system32\mtrapi.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\mv4ul9h91.dll
D:\WINNT\system32\mv4ul9h91.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\mv82l9lo1.dll
D:\WINNT\system32\mv82l9lo1.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\mxrapi.dll
D:\WINNT\system32\mxrapi.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\myvcp71.dll
D:\WINNT\system32\myvcp71.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\n2p4lc7q1f.dll
D:\WINNT\system32\n2p4lc7q1f.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\ndtrap.dll
D:\WINNT\system32\ndtrap.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\ngshrui.dll
D:\WINNT\system32\ngshrui.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\nhvdmd.dll
D:\WINNT\system32\nhvdmd.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\notshell.dll
D:\WINNT\system32\notshell.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\nrcod.dll
D:\WINNT\system32\nrcod.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\nroglnt.dll
D:\WINNT\system32\nroglnt.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\nrtfxperf.dll
D:\WINNT\system32\nrtfxperf.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\ovpf.dll
D:\WINNT\system32\ovpf.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\p46slej71ho.dll
D:\WINNT\system32\p46slej71ho.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\p8r40i9qe8.dll
D:\WINNT\system32\p8r40i9qe8.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\pfailext.dll
D:\WINNT\system32\pfailext.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\pL6slej71ho.dll
D:\WINNT\system32\pL6slej71ho.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\q2ps0c77ef.dll
D:\WINNT\system32\q2ps0c77ef.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\q8680ijue8o80.dll
D:\WINNT\system32\q8680ijue8o80.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\qksname.dll
D:\WINNT\system32\qksname.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\qvvd.dll
D:\WINNT\system32\qvvd.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\qwgr.dll
D:\WINNT\system32\qwgr.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\r4r6le9s1h.dll
D:\WINNT\system32\r4r6le9s1h.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\rem.dll
D:\WINNT\system32\rem.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\rGsppp.dll
D:\WINNT\system32\rGsppp.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\ricrt4.dll
D:\WINNT\system32\ricrt4.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\rkvpsp.dll
D:\WINNT\system32\rkvpsp.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\rMsser.dll
D:\WINNT\system32\rMsser.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\rWsmontr.dll
D:\WINNT\system32\rWsmontr.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\s2rslc971f.dll
D:\WINNT\system32\s2rslc971f.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\s4rsle971h.dll
D:\WINNT\system32\s4rsle971h.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\s6880glue6q80.dll
D:\WINNT\system32\s6880glue6q80.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\seorage.dll
D:\WINNT\system32\seorage.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\sFrslc971f.dll
D:\WINNT\system32\sFrslc971f.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\ssbapiu.dll
D:\WINNT\system32\ssbapiu.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\t0r8la9u1d.dll
D:\WINNT\system32\t0r8la9u1d.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\tiec.dll
D:\WINNT\system32\tiec.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\tnec.dll
D:\WINNT\system32\tnec.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\wccsapi.dll
D:\WINNT\system32\wccsapi.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\wdpdinfo.dll
D:\WINNT\system32\wdpdinfo.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\wipasf.dll
D:\WINNT\system32\wipasf.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\wqdmlog.dll
D:\WINNT\system32\wqdmlog.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\wrnotify.dll
D:\WINNT\system32\wrnotify.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\wsbcheck.dll
D:\WINNT\system32\wsbcheck.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\wspasf.dll
D:\WINNT\system32\wspasf.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\wvdmlog.dll
D:\WINNT\system32\wvdmlog.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\wvnssnap.dll
D:\WINNT\system32\wvnssnap.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\WYASF.dll
D:\WINNT\system32\WYASF.dll Deleted successfully!

Attempting to delete: D:\WINNT\system32\wzdmps.dll
D:\WINNT\system32\wzdmps.dll Deleted successfully!

Making registry repairs.

Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\URL

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{22604021-CDE2-43E3-8BE9-B35E1E44839E}"
HKCR\Clsid\{22604021-CDE2-43E3-8BE9-B35E1E44839E}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{0F49E6AE-8A59-40F2-B40D-3DF97A59928C}"
HKCR\Clsid\{0F49E6AE-8A59-40F2-B40D-3DF97A59928C}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{D055A2BD-542C-4A5E-894A-9DD053B0F8E4}"
HKCR\Clsid\{D055A2BD-542C-4A5E-894A-9DD053B0F8E4}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded


----------------------------------------------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 09:32:53 a.m., on 09/07/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\System32\SCardSvr.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
D:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
D:\WINNT\System32\llssrv.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
D:\WINNT\system32\nvsvc32.exe
D:\oracle\ora92\bin\omtsreco.exe
D:\oracle\ora92\bin\agntsrvc.exe
D:\oracle\ora92\BIN\TNSLSNR.exe
D:\WINNT\system32\cmd.exe
D:\oracle\ora92\bin\dbsnmp.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\System32\tcpsvcs.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\wins.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
D:\WINNT\system32\CCM\CcmExec.exe
D:\WINNT\system32\Dfssvc.exe
D:\WINNT\System32\inetsrv\inetinfo.exe
D:\WINNT\System32\msdtc.exe
D:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
D:\WINNT\system32\mqsvc.exe
D:\WINNT\system32\msiexec.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\Explorer.EXE
D:\WINNT\system32\PRPCUI.exe
D:\Program Files\Apoint\Apoint.exe
D:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
D:\Program Files\QuickTime\qttask.exe
D:\WINNT\system32\internat.exe
D:\Program Files\Yahoo!\Messenger\ypager.exe
D:\Program Files\Apoint\Apntex.exe
D:\Program Files\MSN Messenger\MsnMsgr.Exe
F:\Program Files\Ares Lite Edition\AresLite.exe
D:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
D:\Program Files\Dell\Bluetooth Software\BTTray.exe
D:\PROGRA~1\Dell\BLUETO~1\BTSTAC~1.EXE
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINNT\system32\NOTEPAD.EXE
D:\WINNT\system32\NOTEPAD.EXE
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.gdmex.com:8002
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [Apoint] D:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [NT Services] ntsvc.exe
O4 - HKLM\..\Run: [vptray] D:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdwareAlert] D:\Program Files\AdwareAlert\AdwareAlert.Exe -boot
O4 - HKLM\..\RunServices: [NT Services] ntsvc.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [areslite] "F:\Program Files\Ares Lite Edition\AresLite.exe" -h
O4 - HKCU\..\Run: [ntdll.dll] "F:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [updateMgr] "D:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: Administrador de servicios.lnk = D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = D:\Program Files\Dell\Bluetooth Software\BTTray.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://D:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy - D:\Program Files\Altova\XMLSpy2006\spy.htm
O8 - Extra context menu item: Send To &Bluetooth - D:\Program Files\Dell\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINNT\system32\msjava.dll
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - D:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - D:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\WINNT\system32\shdocvw.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\Dell\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\Dell\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstall...oupe/index.html
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = smnyl.com.mx
O17 - HKLM\System\CCS\Services\Tcpip\..\{A2E69A05-565F-47C0-BF9C-6BB7CFF83C6D}: NameServer = 172.29.150.220
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = smnyl.com.mx
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = smnyl.com.mx
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - D:\WINNT\system32\btxppanel.dll
O20 - Winlogon Notify: NavLogon - D:\WINNT\system32\NavLogon.dll
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - D:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
O23 - Service: Command Service (cmdService) - Unknown owner - D:\WINNT\SnVhbiBCZXJpc3RhaW4\command.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - D:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - D:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NT Services - Unknown owner - D:\WINNT\system32\ntsvc.exe" -service (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINNT\system32\nvsvc32.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - D:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92Agent - Oracle Corporation - D:\oracle\ora92\bin\agntsrvc.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - D:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: OracleOraHome92HTTPServer - Unknown owner - D:\oracle\ora92\Apache\Apache\apache.exe" --ntservice (file missing)
O23 - Service: OracleOraHome92PagingServer - Unknown owner - D:\oracle\ora92/bin/pagntsrv.exe
O23 - Service: OracleOraHome92SNMPPeerEncapsulator - Unknown owner - D:\oracle\ora92\BIN\ENCSVC.EXE
O23 - Service: OracleOraHome92SNMPPeerMasterAgent - Unknown owner - D:\oracle\ora92\BIN\AGNTSVC.EXE
O23 - Service: OracleOraHome92TNSListener - Unknown owner - D:\oracle\ora92\BIN\TNSLSNR.exe
O23 - Service: OracleServiceBIMBO - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceCDF - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceGIS - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceHEWITT - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServicePRUEBA - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceSEGMTY - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceSFP - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: OracleServiceSTDKSYS - Oracle Corporation - d:\oracle\ora92\bin\ORACLE.EXE
O23 - Service: Pml Driver HPZ12 - HP - D:\WINNT\system32\HPZipm12.exe
O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - D:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe

#7 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:02:31 PM

Posted 09 July 2006 - 09:49 AM

Hello,

* Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following:

O4 - HKLM\..\Run: [NT Services] ntsvc.exe
O4 - HKLM\..\RunServices: [NT Services] ntsvc.exe
O4 - HKCU\..\Run: [ntdll.dll] "F:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
<== this is not the default displayname, the default, right O4 - HKCU is already present.
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstall...oupe/index.html
O23 - Service: Command Service (cmdService) - Unknown owner - D:\WINNT\SnVhbiBCZXJpc3RhaW4\command.exe (file missing)
O23 - Service: NT Services - Unknown owner - D:\WINNT\system32\ntsvc.exe" -service (file missing)


* Click on Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer is closed when you click Fix Checked!

Open notepad and copy and paste next present in the quotebox below in it:
(don't forget to copy and paste REGEDIT4)

REGEDIT4

[-HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NT Services]

[-HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cmdService]

Save this as fix.reg Choose to save as *all files and place it on your desktop.
It should look like this: Posted Image
Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.
In case you still are unsure how to create a reg file, take a look here with screenshots.

Update your Sun Java:
Updating Java:
  • Go to Start > Control Panel double-click on the Software icon > add/remove programs.
  • Search in the list for all previous installed versions of Java. (J2SE Runtime Environment.... )
    It should have next icon next to it: Posted Image
    Select it and click Remove.
  • Then Download and install the newest version from here:http://www.java.com/en/download/manual.jsp
Post a new hijackthislog in your next reply and let me know how things are running now.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#8 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:02:31 PM

Posted 15 July 2006 - 06:08 PM

Due to the lack of feedback, this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users