Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Bloodhound.packed.8


  • This topic is locked This topic is locked
4 replies to this topic

#1 BostiPB

BostiPB

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:43 AM

Posted 17 December 2006 - 10:19 PM

Hey,
I recently got a Bloodhound.Packed.8 infection on one of my computer. I can seem to get rid of it. Please help me. Thanks In Advanced

Here is my Log:




Logfile of HijackThis v1.99.1
Scan saved at 10:00:06 PM, on 12/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\Skip\LOCALS~1\Temp\spoolsvv.exe
C:\Program Files\Saitek\Software\Profiler.exe
C:\Program Files\Saitek\Software\SaiSmart.exe
C:\WINDOWS\TEMP\spoolsvv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Skip\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\system32\spoolsvv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Profiler] C:\Program Files\Saitek\Software\Profiler.exe
O4 - HKLM\..\Run: [SaiSmart] C:\Program Files\Saitek\Software\SaiSmart.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [WinMedia] C:\WINDOWS\system32\vxgame6.exe3072.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.0.97.cab
O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All Users\Documents\Settings\artm_new.dll
O20 - Winlogon Notify: s_reg - notifysb.dll (file missing)
O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

BC AdBot (Login to Remove)

 


m

#2 Daemon

Daemon

    Security Expert


  • Members
  • 1,446 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:10:43 AM

Posted 18 December 2006 - 12:18 AM

Please download SUPERAntiSpyware Home Edition (free version)
  • Install it and double-click the icon on your desktop to run it.
  • It will ask if you want to update the program definitions, click Yes.
  • Under Configuration and Preferences, click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked:
    • Close browsers before scanning
    • Scan for tracking cookies
    • Terminate memory threats before quarantining.
    • Please leave the others unchecked.
    • Click the Close button to leave the control center screen.
  • On the main screen, under Scan for Harmful Software click Scan your computer.
  • On the left check C:\Fixed Drive.
  • On the right, under Complete Scan, choose Perform Complete Scan.
  • Click Next to start the scan. Please be patient while it scans your computer.
  • After the scan is complete a summary box will appear. Click OK.
  • Make sure everything in the white box has a check next to it, then click Next.
  • It will quarantine what it found and if it asks if you want to reboot, click Yes.
  • To retrieve the removal information for me please do the following:
    • After reboot, double-click the SUPERAntispyware icon on your desktop.
    • Click Preferences. Click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • It will open in your default text editor (such as Notepad/Wordpad).
    • Please highlight everything in the notepad, then right-click and choose copy.
  • Click close and close again to exit the program.
  • Please paste that information here for me with a new HijackThis log.

Posted Image

Have I helped you? Please consider donating to help me continue with the fight against malware. Click here

#3 BostiPB

BostiPB
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:43 AM

Posted 18 December 2006 - 08:50 PM

Here is the SuperAntiSpyware Log:

SUPERAntiSpyware Scan Log
Generated 12/18/2006 at 07:41 PM

Application Version : 3.4.1000

Core Rules Database Version : 3149
Trace Rules Database Version: 1165

Scan type : Complete Scan
Total Scan Time : 01:11:26

Memory items scanned : 351
Memory threats detected : 2
Registry items scanned : 4967
Registry threats detected : 25
File items scanned : 95302
File threats detected : 201

Trojan.ARTM/Polymorph
C:\DOCUMENTS AND SETTINGS\ALL USERS\DOCUMENTS\SETTINGS\ARTM_NEW.DLL
C:\DOCUMENTS AND SETTINGS\ALL USERS\DOCUMENTS\SETTINGS\ARTM_NEW.DLL
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\artm_newreg
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\artm_newreg
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\artm_newreg#DllName
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\artm_newreg#Startup
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\artm_newreg#Impersonate
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\artm_newreg#Asynchronous

Trojan.SpoolSVV/32
C:\DOCUME~1\SKIP\LOCALS~1\TEMP\SPOOLSVV.EXE
C:\DOCUME~1\SKIP\LOCALS~1\TEMP\SPOOLSVV.EXE
[spoolsvv] C:\WINDOWS\SYSTEM32\SPOOLSVV.EXE
C:\WINDOWS\SYSTEM32\SPOOLSVV.EXE
C:\DOCUMENTS AND SETTINGS\SKIP\LOCAL SETTINGS\TEMP\SPOOLSVV.EXE
C:\WINDOWS\TEMP\SPOOLSVV.EXE
C:\WINDOWS\Prefetch\SPOOLSVV.EXE-1404A6D1.pf
C:\WINDOWS\Prefetch\SPOOLSVV.EXE-2C253AC2.pf

Adware.Tracking Cookie
C:\Documents and Settings\Skip\Cookies\skip@www.macromedia[1].txt
C:\Documents and Settings\Skip\Cookies\skip@sales.liveperson[1].txt
C:\Documents and Settings\Skip\Cookies\skip@campaign.indieclick[1].txt
C:\Documents and Settings\Skip\Cookies\skip@ad[1].txt
C:\Documents and Settings\Skip\Cookies\skip@cz9.clickzs[2].txt
C:\Documents and Settings\Skip\Cookies\skip@entrepreneur[2].txt
C:\Documents and Settings\Skip\Cookies\skip@24290[1].txt
C:\Documents and Settings\Skip\Cookies\skip@cgi-bin[6].txt
C:\Documents and Settings\Skip\Cookies\skip@49044919[1].txt
C:\Documents and Settings\Skip\Cookies\skip@adbrite[2].txt
C:\Documents and Settings\Skip\Cookies\skip@atdmt[1].txt
C:\Documents and Settings\Skip\Cookies\skip@bannerspace[1].txt
C:\Documents and Settings\Skip\Cookies\skip@try.starware[1].txt
C:\Documents and Settings\Skip\Cookies\skip@www.clickxchange[1].txt
C:\Documents and Settings\Skip\Cookies\skip@cgi-bin[11].txt
C:\Documents and Settings\Skip\Cookies\skip@roiservice[2].txt
C:\Documents and Settings\Skip\Cookies\skip@90079178[1].txt
C:\Documents and Settings\Skip\Cookies\skip@cz4.clickzs[2].txt
C:\Documents and Settings\Skip\Cookies\skip@burstnet[2].txt
C:\Documents and Settings\Skip\Cookies\skip@pamedia.com[2].txt
C:\Documents and Settings\Skip\Cookies\skip@data3.perf.overture[2].txt
C:\Documents and Settings\Skip\Cookies\skip@jokes[2].txt
C:\Documents and Settings\Skip\Cookies\skip@tdstats[1].txt
C:\Documents and Settings\Skip\Cookies\skip@hitbox[2].txt
C:\Documents and Settings\Skip\Cookies\skip@cgi-bin[2].txt
C:\Documents and Settings\Skip\Cookies\skip@13954[1].txt
C:\Documents and Settings\Skip\Cookies\skip@dcsi583rp10000oevcqz9y4us_6l6d[1].txt
C:\Documents and Settings\Skip\Cookies\skip@admarketplace[2].txt
C:\Documents and Settings\Skip\Cookies\skip@www.adultsefeed[2].txt
C:\Documents and Settings\Skip\Cookies\skip@ad.yieldmanager[1].txt
C:\Documents and Settings\Skip\Cookies\skip@sexsearchcom[1].txt
C:\Documents and Settings\Skip\Cookies\skip@24215[1].txt
C:\Documents and Settings\Skip\Cookies\skip@ad2.pamedia.com[1].txt
C:\Documents and Settings\Skip\Cookies\skip@partypoker[2].txt
C:\Documents and Settings\Skip\Cookies\skip@metacafe.122.2o7[1].txt
C:\Documents and Settings\Skip\Cookies\skip@mb[5].txt
C:\Documents and Settings\Skip\Cookies\skip@24296[2].txt
C:\Documents and Settings\Skip\Cookies\skip@www.ticketsnow[1].txt
C:\Documents and Settings\Skip\Cookies\skip@ad.yieldmanager[2].txt
C:\Documents and Settings\Skip\Cookies\skip@86992609[2].txt
C:\Documents and Settings\Skip\Cookies\skip@rotator.adjuggler[1].txt
C:\Documents and Settings\Skip\Cookies\skip@dist.belnk[2].txt
C:\Documents and Settings\Skip\Cookies\skip@ads.as4x.tmcs[1].txt
C:\Documents and Settings\Skip\Cookies\skip@clickability[1].txt
C:\Documents and Settings\Skip\Cookies\skip@13956[1].txt
C:\Documents and Settings\Skip\Cookies\skip@www.ticketsnow1[1].txt
C:\Documents and Settings\Skip\Cookies\skip@adopt.euroclick[2].txt
C:\Documents and Settings\Skip\Cookies\skip@data1.perf.overture[1].txt
C:\Documents and Settings\Skip\Cookies\skip@drivecleaner[1].txt
C:\Documents and Settings\Skip\Cookies\skip@a.websponsors[1].txt
C:\Documents and Settings\Skip\Cookies\skip@S006-00-6-10-146607-13491[2].txt
C:\Documents and Settings\Skip\Cookies\skip@ads.realtechnetwork[2].txt
C:\Documents and Settings\Skip\Cookies\skip@stats1.reliablestats[2].txt
C:\Documents and Settings\Skip\Cookies\skip@interclick[1].txt
C:\Documents and Settings\Skip\Cookies\skip@anad.tacoda[1].txt
C:\Documents and Settings\Skip\Cookies\skip@bizrate[1].txt
C:\Documents and Settings\Skip\Cookies\skip@1035908[1].txt
C:\Documents and Settings\Skip\Cookies\skip@partner2profit[2].txt
C:\Documents and Settings\Skip\Cookies\skip@image.masterstats[1].txt
C:\Documents and Settings\Skip\Cookies\skip@atwola[1].txt
C:\Documents and Settings\Skip\Cookies\skip@edge.ru4[2].txt
C:\Documents and Settings\Skip\Cookies\skip@cgi-bin[5].txt
C:\Documents and Settings\Skip\Cookies\skip@keywordmax[1].txt
C:\Documents and Settings\Skip\Cookies\skip@adopt.specificclick[1].txt
C:\Documents and Settings\Skip\Cookies\skip@76588168[1].txt
C:\Documents and Settings\Skip\Cookies\skip@casalemedia[1].txt
C:\Documents and Settings\Skip\Cookies\skip@login.tracking101[1].txt
C:\Documents and Settings\Skip\Cookies\skip@cz7.clickzs[2].txt
C:\Documents and Settings\Skip\Cookies\skip@44153975[1].txt
C:\Documents and Settings\Skip\Cookies\skip@adknowledge[1].txt
C:\Documents and Settings\Skip\Cookies\skip@yieldmanager[1].txt
C:\Documents and Settings\Skip\Cookies\skip@xiti[1].txt
C:\Documents and Settings\Skip\Cookies\skip@adultfriendfinder[2].txt
C:\Documents and Settings\Skip\Cookies\skip@Models[1].txt
C:\Documents and Settings\Skip\Cookies\skip@icc.intellisrv[2].txt
C:\Documents and Settings\Skip\Cookies\skip@tacoda[2].txt
C:\Documents and Settings\Skip\Cookies\skip@statcounter[2].txt
C:\Documents and Settings\Skip\Cookies\skip@data2.perf.overture[2].txt
C:\Documents and Settings\Skip\Cookies\skip@nextag[2].txt
C:\Documents and Settings\Skip\Cookies\skip@ticketsnow[1].txt
C:\Documents and Settings\Skip\Cookies\skip@cgi-bin[4].txt
C:\Documents and Settings\Skip\Cookies\skip@anat.tacoda[2].txt
C:\Documents and Settings\Skip\Cookies\skip@ehg-digg.hitbox[1].txt
C:\Documents and Settings\Skip\Cookies\skip@50255095[2].txt
C:\Documents and Settings\Skip\Cookies\skip@cz11.clickzs[2].txt
C:\Documents and Settings\Skip\Cookies\skip@ex=1_[2].txt
C:\Documents and Settings\Skip\Cookies\skip@cpvfeed[2].txt
C:\Documents and Settings\Skip\Cookies\skip@gostats[2].txt
C:\Documents and Settings\Skip\Cookies\skip@eonsex[2].txt
C:\Documents and Settings\Skip\Cookies\skip@yadro[1].txt
C:\Documents and Settings\Skip\Cookies\skip@cgi-bin[3].txt
C:\Documents and Settings\Skip\Cookies\skip@winfixer[2].txt
C:\Documents and Settings\Skip\Cookies\skip@24218[1].txt
C:\Documents and Settings\Skip\Cookies\skip@38270[1].txt
C:\Documents and Settings\Skip\Cookies\skip@ad.sensismediasmart.com[1].txt
C:\Documents and Settings\Skip\Cookies\skip@38262[1].txt
C:\Documents and Settings\Skip\Cookies\skip@belnk[1].txt
C:\Documents and Settings\Skip\Cookies\skip@ads.primeinteractive[2].txt
C:\Documents and Settings\Skip\Cookies\skip@13947[1].txt
C:\Documents and Settings\Skip\Cookies\skip@www.drivecleaner[2].txt
C:\Documents and Settings\Skip\Cookies\skip@ad1.clickhype[2].txt
C:\Documents and Settings\Skip\Cookies\skip@adinterax[2].txt
C:\Documents and Settings\Skip\Cookies\skip@stats.wildties[2].txt
C:\Documents and Settings\Skip\Cookies\skip@click.revsharecash[1].txt
C:\Documents and Settings\Skip\Cookies\skip@mb[4].txt
C:\Documents and Settings\Skip\Cookies\skip@toplist[1].txt
C:\Documents and Settings\Skip\Cookies\skip@advertpro.ya[1].txt
C:\Documents and Settings\Skip\Cookies\skip@mb[6].txt
C:\Documents and Settings\Skip\Cookies\skip@josiemaran.sexybabesx[1].txt
C:\Documents and Settings\Skip\Cookies\skip@mb[3].txt
C:\Documents and Settings\Skip\Cookies\skip@[1].txt
C:\Documents and Settings\Skip\Cookies\skip@34591768[1].txt
C:\Documents and Settings\Skip\Cookies\skip@www.antivermins[1].txt
C:\Documents and Settings\Skip\Cookies\skip@sexycamteens[1].txt
C:\Documents and Settings\Skip\Cookies\skip@banner[1].txt
C:\Documents and Settings\Skip\Cookies\skip@i[1].txt
C:\Documents and Settings\Skip\Cookies\skip@go.drivecleaner[2].txt
C:\Documents and Settings\Skip\Cookies\skip@1070344717[1].txt
C:\Documents and Settings\Skip\Cookies\skip@kanoodle[2].txt
C:\Documents and Settings\Skip\Cookies\skip@indextools[2].txt
C:\Documents and Settings\Skip\Cookies\skip@24297[1].txt
C:\Documents and Settings\Skip\Cookies\skip@qnsr[1].txt
C:\Documents and Settings\Skip\Cookies\skip@cz6.clickzs[2].txt
C:\Documents and Settings\Skip\Cookies\skip@cz5.clickzs[2].txt
C:\Documents and Settings\Skip\Cookies\skip@38286[1].txt
C:\Documents and Settings\Skip\Cookies\skip@entertainment[1].txt
C:\Documents and Settings\Skip\Cookies\skip@wt.sexsearchcom[1].txt
C:\Documents and Settings\Skip\Cookies\skip@gamerking[2].txt
C:\Documents and Settings\Skip\Cookies\skip@38291[1].txt
C:\Documents and Settings\Skip\Cookies\skip@adverts.loadedinc[2].txt
C:\Documents and Settings\Skip\Cookies\skip@38266[2].txt
C:\Documents and Settings\Skip\Cookies\skip@www.redorbit[2].txt
C:\Documents and Settings\Skip\Cookies\skip@cgi-bin[1].txt
C:\Documents and Settings\Skip\Cookies\skip@www.clickmanage[2].txt
C:\Documents and Settings\Skip\Cookies\skip@38274[2].txt
C:\Documents and Settings\Skip\Cookies\skip@t2[1].txt
C:\Documents and Settings\Skip\Cookies\skip@redorbit[2].txt
C:\Documents and Settings\Skip\Cookies\skip@mb[1].txt
C:\Documents and Settings\Skip\Cookies\skip@38283[1].txt
C:\Documents and Settings\Skip\Cookies\skip@tracker.myspacemaps[1].txt
C:\Documents and Settings\Skip\Cookies\skip@ads1.revenue[1].txt
C:\Documents and Settings\Skip\Cookies\skip@www.burstnet[1].txt
C:\Documents and Settings\Skip\Cookies\skip@sexybabesx[1].txt
C:\Documents and Settings\Skip\Cookies\skip@offeroptimizer[2].txt
C:\Documents and Settings\Skip\Cookies\skip@www2.mystats[1].txt
C:\Documents and Settings\Skip\Cookies\skip@www.magicxxxvideos[1].txt
C:\Documents and Settings\Skip\Cookies\skip@stats.drivecleaner[2].txt
C:\Documents and Settings\Skip\Cookies\skip@adopt.hbmediapro[2].txt
C:\Documents and Settings\Skip\Cookies\skip@zedo[2].txt
C:\Documents and Settings\Skip\Cookies\skip@data4.perf.overture[1].txt
C:\Documents and Settings\Skip\Cookies\skip@www.belstat[2].txt
C:\Documents and Settings\Skip\Cookies\skip@mb[7].txt
C:\Documents and Settings\Skip\Cookies\skip@www.serials[1].txt
C:\Documents and Settings\Skip\Cookies\skip@h.starware[1].txt
C:\Documents and Settings\Skip\Cookies\skip@m1.webstats4u[2].txt
C:\Documents and Settings\Skip\Cookies\skip@azjmp[2].txt
C:\Documents and Settings\Skip\Cookies\skip@ads.incgamers[1].txt
C:\Documents and Settings\Skip\Cookies\skip@www.adultfreevideos[2].txt
C:\Documents and Settings\Skip\Cookies\skip@adlegend[1].txt
C:\Documents and Settings\Skip\Cookies\skip@coolsavings[1].txt
C:\Documents and Settings\Skip\Cookies\skip@www.adultdream[1].txt
C:\Documents and Settings\Skip\Cookies\skip@ex=1[2].txt
C:\Documents and Settings\Skip\Cookies\skip@voyeur[1].txt
C:\Documents and Settings\Skip\Cookies\skip@www.sexkey[1].txt
C:\Documents and Settings\Skip\Cookies\skip@www.burstbeacon[1].txt
C:\Documents and Settings\Skip\Cookies\skip@sensismediasmart.com[2].txt
C:\Documents and Settings\Skip\Cookies\skip@adultdream[1].txt
C:\Documents and Settings\Skip\Cookies\skip@publishers.clickbooth[1].txt
C:\Documents and Settings\Skip\Cookies\skip@nextstat[1].txt

Trojan.Media-Codec
HKCR\CLSID\{5D4831E0-5A7C-4A46-AFD5-A79AB8CE36C2}
HKCR\CLSID\{5D4831E0-5A7C-4A46-AFD5-A79AB8CE36C2}\Implemented Categories
HKCR\CLSID\{5D4831E0-5A7C-4A46-AFD5-A79AB8CE36C2}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
HKCR\CLSID\{5D4831E0-5A7C-4A46-AFD5-A79AB8CE36C2}\InprocServer32
HKCR\CLSID\{5D4831E0-5A7C-4A46-AFD5-A79AB8CE36C2}\InprocServer32#ThreadingModel
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03#UninstallString
HKCR\VideoAXObject.Chl
HKCR\VideoAXObject.Chl\CLSID
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#isamonitor.exe [ C:\Program Files\Video ActiveX Object\isamonitor.exe ]
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{5d4831e0-5a7c-4a46-afd5-a79ab8ce36c2}
C:\DOCUMENTS AND SETTINGS\SKIP\LOCAL SETTINGS\TEMP\TEMP.FREF02\ISAUNINST.EXE
C:\DOCUMENTS AND SETTINGS\SKIP\LOCAL SETTINGS\TEMP\TEMP.FREF02\PMUNINST.EXE

Malware.VirusBurst
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#pmsngr.exe [ C:\Program Files\Video ActiveX Object\pmsngr.exe ]

Malware.AntiVermins
C:\Program Files\AntiVermins\av.ini
C:\Program Files\AntiVermins
C:\DOCUMENTS AND SETTINGS\SKIP\LOCAL SETTINGS\TEMP\~NSU.TMP\AU_.EXE
C:\RECYCLER\NPROTECT\00120155.EXE
C:\RECYCLER\NPROTECT\00120168.EXE

Trojan.Downloader-WS2F
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\winsys2freg
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\winsys2freg#DllName
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\winsys2freg#Startup
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\winsys2freg#Impersonate
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\winsys2freg#Asynchronous
C:\DOCUMENTS AND SETTINGS\SKIP\LOCAL SETTINGS\TEMP\TEMP.FR32A0

Trojan.VXGame-Gen
C:\DOCUMENTS AND SETTINGS\SKIP\LOCAL SETTINGS\TEMP\1.DLB
C:\RECYCLER\NPROTECT\00120230.EXE

Dialer.Dial/Gen Variant
C:\DOCUMENTS AND SETTINGS\SKIP\LOCAL SETTINGS\TEMP\MAXDD1.GAME
C:\RECYCLER\NPROTECT\00120227.EXE

Trojan.Unknown Origin
C:\DOCUMENTS AND SETTINGS\SKIP\LOCAL SETTINGS\TEMP\TEMP.FREF02\OT.ICO
C:\DOCUMENTS AND SETTINGS\SKIP\LOCAL SETTINGS\TEMP\TEMP.FREF02\TS.ICO
C:\RECYCLER\NPROTECT\00120228.TLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{FC41458E-A437-447E-8311-69DC31AA87A7}\RP103\A0009856.ICO
C:\SYSTEM VOLUME INFORMATION\_RESTORE{FC41458E-A437-447E-8311-69DC31AA87A7}\RP103\A0009860.ICO

Trojan.VXGame/32
C:\DOCUMENTS AND SETTINGS\SKIP\LOCAL SETTINGS\TEMP\VX3.GAME
C:\DOCUMENTS AND SETTINGS\SKIP\LOCAL SETTINGS\TEMP\VXT3.GAME
C:\WINDOWS\SYSTEM32\VXGAME3.EXE
C:\WINDOWS\SYSTEM32\VXGAMET3.EXE
C:\WINDOWS\TEMP\ART5AA5.TMP
C:\WINDOWS\TEMP\ART770D.TMP

Adware.WhenU
C:\PROGRAM FILES\DAEMON TOOLS\SETUPDTSB.EXE

Trojan.ClbBt
C:\WINDOWS\COMDLJ32.DLL

Here is my new HijackThis Log:

Logfile of HijackThis v1.99.1
Scan saved at 8:46:40 PM, on 12/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Saitek\Software\Profiler.exe
C:\Program Files\Saitek\Software\SaiSmart.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Skip\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Profiler] C:\Program Files\Saitek\Software\Profiler.exe
O4 - HKLM\..\Run: [SaiSmart] C:\Program Files\Saitek\Software\SaiSmart.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.0.97.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: s_reg - notifysb.dll (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Thanks For the help

#4 Daemon

Daemon

    Security Expert


  • Members
  • 1,446 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:10:43 AM

Posted 19 December 2006 - 03:41 AM

Looks better - how is it running now?
Posted Image

Have I helped you? Please consider donating to help me continue with the fight against malware. Click here

#5 Daemon

Daemon

    Security Expert


  • Members
  • 1,446 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:10:43 AM

Posted 22 December 2006 - 10:08 AM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
Posted Image

Have I helped you? Please consider donating to help me continue with the fight against malware. Click here




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users