Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Cannot Go Into Safe Mode.


  • This topic is locked This topic is locked
4 replies to this topic

#1 R. Danner III

R. Danner III

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:05:18 AM

Posted 02 December 2006 - 05:11 PM

Can't get to safe mode. Shows that hal.dll needs to be replaced (i.e.: is missing). Well, I did that (thank God for the Recovery Console) and regained proper shutdown, but so far, still can't get into Safe Mode. (which makes things a bit difficult for the scans you lot recommend. :thumbsup:)

Odd fact:
TrendMicro's Housecall dies in the late part of the scan, but shows both Virtumundo and another threat.

Machine: eMachines T6420 (AMD Athlon-64/3400+, 1Gb RAM, 200Gb HDD)
OS ver.: WinXP MCE 2005 with all current updates

---- Ewido Anti-Spyware 4.0 Report ----
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 16:53 CT 12/2/2006

+ Scan result:



C:\Maintenance\PerfectDisk\Crack.exe -> Not-A-Virus.VirTool.Win32.AvSpoffer.a : No action taken.
C:\My Backup -- 06-08-31 0216PM\Documents and Settings\Owner\My Documents\Downloads\PerfectDisk.7.0.Build.xx.GENERiC_CRK-FFF.zip/Crack.exe -> Not-A-Virus.VirTool.Win32.AvSpoffer.a : No action taken.
:mozilla.56:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.57:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.61:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Bfast : No action taken.
:mozilla.65:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Coremetrics : No action taken.
:mozilla.48:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Hitslink : No action taken.
:mozilla.67:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Hotlog : No action taken.
:mozilla.62:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.25:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.70:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Spylog : No action taken.
:mozilla.32:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Trafic : No action taken.
:mozilla.33:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.34:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.35:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.36:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.37:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.38:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.68:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Yadro : No action taken.
:mozilla.69:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Yadro : No action taken.
:mozilla.28:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.29:C:\Documents and Settings\Owner.A64-3400\Application Data\Mozilla\Firefox\Profiles\dc1etay0.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Program Files\thriXXX\3D SexVilla\Binaries\3DSexVilla-017-001-start.exe -> Trojan.QQPass.ly : No action taken.
C:\Program Files\thriXXX\HentaII 3D\Binaries\HentaII3D-017.004-start.exe -> Trojan.QQPass.ly : No action taken.
C:\Documents and Settings\Raymond Danner\Desktop\SanDisk unit backup 20061124.rar/hexedfull.exe -> Trojan.SrvAdmin.A : No action taken.


::Report end
---- Ewido Anti-Spyware 4.0 Report ----

---- HijackThis report ----
Logfile of HijackThis v1.99.1
Scan saved at 16:57 CT, on 12/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\MAINTE~1\AVGFRE~1\avgamsvr.exe
C:\MAINTE~1\AVGFRE~1\avgupsvc.exe
C:\MAINTE~1\AVGFRE~1\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Maintenance\Shavlik Technologies\NetChk\5.6.0.446\HfNetChkProService.exe
C:\Maintenance\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Maintenance\PerfectDisk\PDAgent.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\ProPatches\Scheduler\stSchedEx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Streamload\AMD LIVE! Media Vault\StreamloadService.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\Program Files\DynDNS Updater\DynDNS.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Internet\ZoneAlarm\zlclient.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\CrossHair\CrossHair.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Launchy\Launchy.exe
C:\WINDOWS\system32\LVComS.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Multimedia\Winamp\winamp.exe
C:\Documents and Settings\Owner.A64-3400\Desktop\hijackthis_sfx.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Internet\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [VirtualDrive] C:\Program Files\VDPPro\VDP\vdtask.exe /AutoRestore
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [AVG7_CC] C:\MAINTE~1\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKCU\..\Run: [hidedale] C:\DOCUME~1\OWNER~1.A64\APPLIC~1\REGSRE~1\error copy comp.exe
O4 - HKCU\..\Run: [CrossHair] C:\Program Files\CrossHair\CrossHair.exe
O4 - Global Startup: DNet Client.lnk = C:\Program Files\Distributed.net\dnetc.exe
O4 - Global Startup: Gomez PEER.lnk = C:\Internet\Gomez\bin\GomezPEER.exe
O4 - Global Startup: Launchy.lnk = C:\Program Files\Launchy\Launchy.exe
O4 - Global Startup: SocketWatch.lnk = C:\Maintenance\SocketWatch\swatch.exe
O4 - Global Startup: WordWeb.lnk = C:\Internet\WordWeb\wweb32.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab
O16 - DPF: {93EFDAB8-8800-4896-B428-76F943140E1B} - http://www.consumerinput.com.edgesuite.net...ple/dcainst.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\MAINTE~1\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\MAINTE~1\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\MAINTE~1\AVGFRE~1\avgemc.exe
O23 - Service: DynDNS Updater Service (DynDNS_Updater_Service) - Kana Solution - C:\Program Files\DynDNS Updater\DynDNS.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Maintenance\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NetChk Patch Service (NetChkPatch) - Unknown owner - C:\Maintenance\Shavlik Technologies\NetChk\5.6.0.446\HfNetChkProService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Maintenance\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Maintenance\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Maintenance\PerfectDisk\PDEngine.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Shavlik Remote Scheduler Service (Shavlik Scheduler) - Shavlik Technologies - C:\WINDOWS\ProPatches\Scheduler\stSchedEx.exe
O23 - Service: Streamload Service (StreamloadService) - Streamload - C:\Program Files\Streamload\AMD LIVE! Media Vault\StreamloadService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)
---- HijackThis report ----

Edited by R. Danner III, 02 December 2006 - 06:14 PM.


BC AdBot (Login to Remove)

 


#2 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:04:18 AM

Posted 06 December 2006 - 03:06 PM

Hello R. Danner III,

I am SifuMike and I will be helping you. :thumbsup:


Please Download NoLop to your desktop from one of the links below...
http://www.spywareedge.net/nolop/NoLop.exe
http://www.thespykiller.co.uk/forum/index....tpmod;dl=item16

First close any other programs you have running as this will require a reboot
Double click NoLop.exe to run it
Now click the button labelled "Search and Destroy"
<<your computer will now be scanned for infected files>>
When scanning is finished you will be prompted to reboot only if infected, Click OK
Now click the "REBOOT" Button.
A Message should popup from NoLop.
If not, double click the program again and it will finish Please Post the contents of C:\NoLop.log along with a fresh HijackThis log

--If you receive an error, "mscomctl.ocx or one of its dependencies are not correctly registered," please download mscomctl.ocx to your system32 folder then rerun the program.-- http://www.boletrice.com/downloads/mscomctl.ocx

Edited by SifuMike, 06 December 2006 - 03:06 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 R. Danner III

R. Danner III
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:05:18 AM

Posted 07 December 2006 - 12:00 PM

---- HijackThis! log ----

Logfile of HijackThis v1.99.1

Scan saved at 10:32 ct, on 12/7/2006

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)



Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\SYSTEM32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\WINDOWS\system32\spoolsv.exe

C:\MAINTE~1\AVGFRE~1\avgamsvr.exe

C:\MAINTE~1\AVGFRE~1\avgupsvc.exe

C:\MAINTE~1\AVGFRE~1\avgemc.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\Maintenance\ewido anti-spyware 4.0\guard.exe

C:\Maintenance\Shavlik Technologies\NetChk\5.6.0.446\HfNetChkProService.exe

C:\Maintenance\Eset\nod32krn.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Maintenance\PerfectDisk\PDAgent.exe

C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

C:\WINDOWS\ProPatches\Scheduler\stSchedEx.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Streamload\AMD LIVE! Media Vault\StreamloadService.exe

C:\Program Files\TightVNC\WinVNC.exe

C:\Program Files\DynDNS Updater\DynDNS.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\Explorer.EXE

C:\Internet\ZoneAlarm\zlclient.exe

C:\Program Files\VDPPro\VDP\vdtask.exe

C:\Program Files\Digital Media Reader\shwiconem.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

C:\MAINTE~1\AVGFRE~1\avgcc.exe

C:\WINDOWS\StartupMonitor.exe

C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe

C:\Program Files\Logitech\Video\LogiTray.exe

C:\Program Files\CrossHair\CrossHair.exe

c:\progra~1\intern~1\iexplore.exe

C:\Program Files\AceLogix\Free Ram Optimizer\fro.exe

C:\Program Files\Launchy\Launchy.exe

C:\Maintenance\SocketWatch\swatch.exe

C:\WINDOWS\system32\LVComS.exe

C:\Internet\WordWeb\wweb32.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe

C:\Program Files\HijackThis\HijackThis.exe



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = 

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\MAINTE~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll

O4 - HKLM\..\Run: [Zone Labs Client] "C:\Internet\ZoneAlarm\zlclient.exe"

O4 - HKLM\..\Run: [VirtualDrive] C:\Program Files\VDPPro\VDP\vdtask.exe /AutoRestore

O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

O4 - HKLM\..\Run: [AVG7_CC] C:\MAINTE~1\AVGFRE~1\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe

O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe

O4 - HKCU\..\Run: [hidedale] C:\DOCUME~1\OWNER~1.A64\APPLIC~1\REGSRE~1\error copy comp.exe

O4 - HKCU\..\Run: [CrossHair] C:\Program Files\CrossHair\CrossHair.exe

O4 - HKCU\..\Run: [Free Ram Optimizer] C:\Program Files\AceLogix\Free Ram Optimizer\fro.exe

O4 - Global Startup: DNet Client.lnk = C:\Program Files\Distributed.net\dnetc.exe

O4 - Global Startup: Gomez PEER.lnk = C:\Internet\Gomez\bin\GomezPEER.exe

O4 - Global Startup: Launchy.lnk = C:\Program Files\Launchy\Launchy.exe

O4 - Global Startup: SocketWatch.lnk = C:\Maintenance\SocketWatch\swatch.exe

O4 - Global Startup: WordWeb.lnk = C:\Internet\WordWeb\wweb32.exe

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html

O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html

O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html

O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html

O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab

O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab

O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab

O16 - DPF: {93EFDAB8-8800-4896-B428-76F943140E1B} - http://www.consumerinput.com.edgesuite.net/panel/maple/dcainst.cab

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\MAINTE~1\AVGFRE~1\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\MAINTE~1\AVGFRE~1\avgupsvc.exe

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\MAINTE~1\AVGFRE~1\avgemc.exe

O23 - Service: DynDNS Updater Service (DynDNS_Updater_Service) - Kana Solution - C:\Program Files\DynDNS Updater\DynDNS.exe

O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Maintenance\ewido anti-spyware 4.0\guard.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NetChk Patch Service (NetChkPatch) - Unknown owner - C:\Maintenance\Shavlik Technologies\NetChk\5.6.0.446\HfNetChkProService.exe

O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Maintenance\Eset\nod32krn.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: PDAgent - Raxco Software, Inc. - C:\Maintenance\PerfectDisk\PDAgent.exe

O23 - Service: PDEngine - Raxco Software, Inc. - C:\Maintenance\PerfectDisk\PDEngine.exe

O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

O23 - Service: Shavlik Remote Scheduler Service (Shavlik Scheduler) - Shavlik Technologies - C:\WINDOWS\ProPatches\Scheduler\stSchedEx.exe

O23 - Service: Streamload Service (StreamloadService) - Streamload - C:\Program Files\Streamload\AMD LIVE! Media Vault\StreamloadService.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)

---- HijackThis! log ----



---- NoLop! Log ----

NoLop! Log by Skate_Punk_21



Fix running from: C:\Documents and Settings\Raymond Danner\My Documents\Downloads

[12/7/2006]

[10:26:20 CT]



---Infection Files Found/Removed---

C:\WINDOWS\tasks\B4E206259821BBED.job



Beginning Removal...

Rebooting...

Removing Lop's Leftover Files/Folders...

Editing Registry...

**Fix Complete!**



---Listing AppData sub directories---



C:\Documents and Settings\Administrator\Application Data\Aol  -- EMPTY Directory

C:\Documents and Settings\Administrator\Application Data\Avg7  -- EMPTY Directory

C:\Documents and Settings\Administrator\Application Data\Farstone

C:\Documents and Settings\Administrator\Application Data\Google  -- EMPTY Directory

C:\Documents and Settings\Administrator\Application Data\Identities

C:\Documents and Settings\Administrator\Application Data\Kana Solution

C:\Documents and Settings\Administrator\Application Data\Leadertech

C:\Documents and Settings\Administrator\Application Data\Macromedia

C:\Documents and Settings\Administrator\Application Data\Microsoft

C:\Documents and Settings\Administrator\Application Data\Mozilla

C:\Documents and Settings\Administrator\Application Data\Sun

C:\Documents and Settings\Administrator\Application Data\Talkback

C:\Documents and Settings\Administrator\Application Data\You've Got Pictures Screensaver

C:\Documents and Settings\All Users\Application Data\Aol  -- EMPTY Directory

C:\Documents and Settings\All Users\Application Data\Apple Computer

C:\Documents and Settings\All Users\Application Data\Avg7

C:\Documents and Settings\All Users\Application Data\Cyberlink

C:\Documents and Settings\All Users\Application Data\Google

C:\Documents and Settings\All Users\Application Data\Grisoft

C:\Documents and Settings\All Users\Application Data\Installshield

C:\Documents and Settings\All Users\Application Data\Mcafee

C:\Documents and Settings\All Users\Application Data\Mcafee.com

C:\Documents and Settings\All Users\Application Data\Mcafee.com Personal Firewall

C:\Documents and Settings\All Users\Application Data\Microsoft

C:\Documents and Settings\All Users\Application Data\Napster

C:\Documents and Settings\All Users\Application Data\Nview_profiles  -- EMPTY Directory

C:\Documents and Settings\All Users\Application Data\Prism Deploy

C:\Documents and Settings\All Users\Application Data\Pure Networks

C:\Documents and Settings\All Users\Application Data\Quicktime

C:\Documents and Settings\All Users\Application Data\Raxco

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

C:\Documents and Settings\All Users\Application Data\Trymedia

C:\Documents and Settings\All Users\Application Data\Viewpoint

C:\Documents and Settings\All Users\Application Data\Wayfindspampure

C:\Documents and Settings\All Users\Application Data\Yahoo!

C:\Documents and Settings\Default User\Application Data\Aol  -- EMPTY Directory

C:\Documents and Settings\Default User\Application Data\Identities

C:\Documents and Settings\Default User\Application Data\Microsoft

C:\Documents and Settings\Default User\Application Data\You've Got Pictures Screensaver

C:\Documents and Settings\Localservice\Application Data\Avg7

C:\Documents and Settings\Localservice\Application Data\Macromedia

C:\Documents and Settings\Localservice\Application Data\Mcafee.com Personal Firewall

C:\Documents and Settings\Localservice\Application Data\Microsoft

C:\Documents and Settings\Localservice\Application Data\Mozilla

C:\Documents and Settings\Localservice\Application Data\Talkback

C:\Documents and Settings\Networkservice\Application Data\Avg7  -- EMPTY Directory

C:\Documents and Settings\Networkservice\Application Data\Microsoft

C:\Documents and Settings\Owner.a64-3400\Application Data\Aol  -- EMPTY Directory

C:\Documents and Settings\Owner.a64-3400\Application Data\Avg7  -- EMPTY Directory

C:\Documents and Settings\Owner.a64-3400\Application Data\Cyberlink

C:\Documents and Settings\Owner.a64-3400\Application Data\Farstone

C:\Documents and Settings\Owner.a64-3400\Application Data\Feedreader

C:\Documents and Settings\Owner.a64-3400\Application Data\Google  -- EMPTY Directory

C:\Documents and Settings\Owner.a64-3400\Application Data\Help  -- EMPTY Directory

C:\Documents and Settings\Owner.a64-3400\Application Data\Identities

C:\Documents and Settings\Owner.a64-3400\Application Data\Kaboom Studios

C:\Documents and Settings\Owner.a64-3400\Application Data\Lavasoft

C:\Documents and Settings\Owner.a64-3400\Application Data\Macromedia

C:\Documents and Settings\Owner.a64-3400\Application Data\Mcafee.com Personal Firewall

C:\Documents and Settings\Owner.a64-3400\Application Data\Microsoft

C:\Documents and Settings\Owner.a64-3400\Application Data\Microsoft Web Folders  -- EMPTY Directory

C:\Documents and Settings\Owner.a64-3400\Application Data\Mozilla

C:\Documents and Settings\Owner.a64-3400\Application Data\Netpumper  -- EMPTY Directory

C:\Documents and Settings\Owner.a64-3400\Application Data\Real

C:\Documents and Settings\Owner.a64-3400\Application Data\Regs Remote Title

C:\Documents and Settings\Owner.a64-3400\Application Data\Sampleview  -- EMPTY Directory

C:\Documents and Settings\Owner.a64-3400\Application Data\Sereniti

C:\Documents and Settings\Owner.a64-3400\Application Data\Smart Pc Solutions  -- EMPTY Directory

C:\Documents and Settings\Owner.a64-3400\Application Data\Sun

C:\Documents and Settings\Owner.a64-3400\Application Data\Talkback

C:\Documents and Settings\Owner.a64-3400\Application Data\Thunderbird

C:\Documents and Settings\Owner.a64-3400\Application Data\You've Got Pictures Screensaver

C:\Documents and Settings\Raymond Danner\Application Data\Aol  -- EMPTY Directory

C:\Documents and Settings\Raymond Danner\Application Data\Apple Computer

C:\Documents and Settings\Raymond Danner\Application Data\Avg7

C:\Documents and Settings\Raymond Danner\Application Data\Cyberlink

C:\Documents and Settings\Raymond Danner\Application Data\Divx

C:\Documents and Settings\Raymond Danner\Application Data\Farstone

C:\Documents and Settings\Raymond Danner\Application Data\Gnupg

C:\Documents and Settings\Raymond Danner\Application Data\Google

C:\Documents and Settings\Raymond Danner\Application Data\Help  -- EMPTY Directory

C:\Documents and Settings\Raymond Danner\Application Data\Identities

C:\Documents and Settings\Raymond Danner\Application Data\Installshield

C:\Documents and Settings\Raymond Danner\Application Data\Jasc Software Inc

C:\Documents and Settings\Raymond Danner\Application Data\Kaboom Studios

C:\Documents and Settings\Raymond Danner\Application Data\Macromedia

C:\Documents and Settings\Raymond Danner\Application Data\Microsoft

C:\Documents and Settings\Raymond Danner\Application Data\Microsoft Web Folders  -- EMPTY Directory

C:\Documents and Settings\Raymond Danner\Application Data\Mozilla

C:\Documents and Settings\Raymond Danner\Application Data\Mozillacontrol

C:\Documents and Settings\Raymond Danner\Application Data\Netpumper

C:\Documents and Settings\Raymond Danner\Application Data\Openoffice.org

C:\Documents and Settings\Raymond Danner\Application Data\Openoffice.org2

C:\Documents and Settings\Raymond Danner\Application Data\Real

C:\Documents and Settings\Raymond Danner\Application Data\Sampleview  -- EMPTY Directory

C:\Documents and Settings\Raymond Danner\Application Data\Sereniti

C:\Documents and Settings\Raymond Danner\Application Data\Shareaza

C:\Documents and Settings\Raymond Danner\Application Data\Smartftp

C:\Documents and Settings\Raymond Danner\Application Data\Sun

C:\Documents and Settings\Raymond Danner\Application Data\Talkback

C:\Documents and Settings\Raymond Danner\Application Data\Tgtsoft

C:\Documents and Settings\Raymond Danner\Application Data\Thunderbird

C:\Documents and Settings\Raymond Danner\Application Data\Utorrent

C:\Documents and Settings\Raymond Danner\Application Data\Weatherbug

C:\Documents and Settings\Raymond Danner\Application Data\Winamp

C:\Documents and Settings\Raymond Danner\Application Data\You've Got Pictures Screensaver

---- NoLop! Log ----


#4 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:04:18 AM

Posted 07 December 2006 - 12:52 PM

Hi R. Danner III,

Download CCleaner and install it. (default location is best). Do not run it yet!

CCleaner Tutorial


*******************************************

How to Reboot into Safe Mode
tap F8 key during reboot, until the boot menu appears...use the arrow keys to choose "Safe Mode" from the menu......,then press the "Enter" key. If that does not work this go to this site: http://www.bleepingcomputer.com/tutorials/how-to-start-windows-in-safe-mode/



Please boot into Safe Mode and select the following with HijackThis.
With all windows (including this one!) closed (close browser/explorer windows), please select "fix.

O4 - HKCU\..\Run: [hidedale] C:\DOCUME~1\OWNER~1.A64\APPLIC~1\REGSRE~1\error copy comp.exe

The following are not necessarily spyware/malware, but I suggest you place a check mark next to the following entries, as these programs may be taking up system resources.

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
(Description: Sun Java update scheduler. Checks for updates. Not necessary. Removing this entry will free up a small amount of system resources.)

O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
(Description: Logitech Image Studio system tray applet. Not necessary. Removing this entry will free up a small amount of system resources.)

*******************************************

Next, we're going on a file hunt.
Go to My Computer and double-click C.
Go to the Tools menu and select 'Folder Options'.
On the 'View' tab select 'show hidden files and folders',
deselect (uncheck) 'hide protected operating system files (recommended)', and
deselect (uncheck) "Hide extensions for known file types.'

Don't use the windows start\search feature
Using Windows Explorer, find and delete each of the following. If you can't delete an item, right-click it and click properties. Make sure 'read-only' is unchecked.
If you still can't delete something, right-click it and rename it to a random word. Then drag the item to a different location. Try deleting it now. If you still can't, be sure to let me know.
Folders and files with a tilde (~), means that there is a file/folder that starts with the six characters in front of the tilde, note that there may be spaces in the name.

Using Windows Explorer, delete the following files/folders in bold (Do not be concerned if they do not exist)

C:\DOCUME~1\OWNER~1.A64\APPLIC~1\REGSRE~1\error copy comp.exe <==file

*******************************************

*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders and does not make backups.

Let's empty the temp files:

Run CCleaner.

1. Starting with v1.27.260, CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation.
IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbarfree Basic version instead of the Standard Build.


2. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"

3. Then select the items you wish to clean up.

In the Windows Tab:
Clean all entries in the "Internet Explorer" section except Cookies.
Clean all the entries in the "Windows Explorer" section.
Clean all entries in the "System" section.
Clean all entries in the "Advanced" section.
Clean any others that you choose.

In the Applications Tab:
Clean all except cookies in the Firefox/Mozilla section if you use it.
Clean all in the Opera section if you use it.
Clean Sun Java in the Internet Section.
Clean any others that you choose.

4. Click the "Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click "OK" and it will scan and clean your system.
7. Click "exit" when done.

If it asks you to reboot at the end, click NO.

CCleaner should be run with the above settings for each User Account!

*******************************************


Reboot to the Normal Mode.

Disable your antivirus program and go here http://www.bitdefender.com/scan8/ie.html and run an online scan with BitDefender (you will need to use Internet Explorer for this scan). When the ActiveX Control has loaded, click on "Click here to scan" and grab a coffee. :thumbsup:
Be patient, as the run time depends on the number of files in your computer.

When BitDefender completes the scan, select the "Detected Problems" tab.
Click on "Click here to export scan".
Save the file as an HTML to your Desktop.
Then click on the saved file and allow it to open with your browser.
Go to Edit - Select All then copy/paste that log back here.
Post the BitDefender log.

Please do not put your Hijackthis log or other logs in quotes as they are harder to read that way.
Post a new Hijackthis log, the BitDepender log and tell me how your computer is running.

Edited by SifuMike, 07 December 2006 - 12:55 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:04:18 AM

Posted 23 December 2006 - 06:36 PM

Due to inactivity, this thread will now be closed. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users