Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Virus Disabling My Ad-aware


  • Please log in to reply
34 replies to this topic

#1 ksaama

ksaama

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:08:17 AM

Posted 05 April 2007 - 03:56 PM

Hello. I am unable to run Ad-Aware or any other anti-malware softwares. Ad-Awaqre open up then gets terminated before it's started. It seems I have some malicious program that's terminating it. Can anyone help please.

Below is my Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 11:41:25 PM, on 4/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
d:\Program Files\Remote Desktop Control\apc_host.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uspoliticsonline.com/indexf.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 203.99.204.14:1080
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: VIPTToolbarManager Class - {1A2641AE-2C42-4C51-A05F-8ECEC3FDC94D} - d:\Program Files\Visual IP Trace\VisualIPTraceIE.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Visual IP Trace - {E70C26AE-DFF1-40A8-8D37-19180F56F0AA} - d:\Program Files\Visual IP Trace\VisualIPTraceIE.dll
O4 - HKLM\..\Run: [Video Driver] D:\Program Files\Common Files\Microsoft Shared\DAO\OWNER\svchost.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Anonymizer] D:\Program Files\Anonymizer\Anonymizer Software\Anonymizer.exe -nogui
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.p0rt2.com
O16 - DPF: ANB Direct - http://www.anb.com.sa/onlinebanking/classes.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {630F2610-7654-11D1-83E3-0080C71A8794} (ANB Direct) - http://www.anb.com.sa/onlinebanking/anb.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: RDC-Host - AQUATRA, Inc. - d:\Program Files\Remote Desktop Control\apc_host.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

BC AdBot (Login to Remove)

 


#2 jurgenv

jurgenv

  • Members
  • 1,093 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:06:17 AM

Posted 05 April 2007 - 04:04 PM

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Greets Jürgenv

Donation: Click me.

#3 ksaama

ksaama
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:08:17 AM

Posted 05 April 2007 - 06:31 PM

While waiting for your response, I happened to have ran Spybot Search and destroy. It ran and cleaned a few things. I then tried Ad-Aware and to my surprise it ran ok.

However, I have the same problem on my other PC but I can't run Spybot because it's not installed. When I tried installing it, it gets terminated every time I try to install it.

I will attempt to download and run combofix.exe on my other PC and thenI will post log.

Thanks

#4 ksaama

ksaama
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:08:17 AM

Posted 05 April 2007 - 08:23 PM

Here's the log:

"Administrator" - 07-04-06 2:41:13 Service Pack 2
ComboFix 07-04-05 - Running from: "D:\DOWNLOADS"


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\system32\drivers\npf.sys


((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\NPF
-------\LEGACY_NPF


((((((((((((((((((((((((((((((( Files Created from 2007-03-06 to 2007-04-06 ))))))))))))))))))))))))))))))))))


2007-04-04 10:53 1 --ah----- C:\DOCUME~1\ALLUSE~1\APPLIC~1\uni.dat
2007-04-04 08:23 49,822 --a------ C:\WINDOWS\rspoolv.exe
2007-04-04 07:53 77,824 --a------ C:\WINDOWS\winsrvc.exe
2007-04-04 07:53 49,782 --a------ C:\WINDOWS\rscc.dll
2007-04-04 07:53 39,572 --a------ C:\WINDOWS\rsnti.dll
2007-04-04 05:58 104,490 ---h----- C:\Program Files\services.exe
2007-04-02 12:42 30,615 --a------ C:\DOCUME~1\ADMINI~1\x.exe
2007-04-02 11:42 722,176 --a------ C:\DOCUME~1\ADMINI~1\gotomypc_428.exe
2007-03-31 07:16 <DIR> d-------- C:\Program Files\WinConfig
2007-03-31 06:55 277,282 --a------ C:\WINDOWS\drsetup.exe
2007-03-31 06:25 25,609 --a------ C:\WINDOWS\rskl.dll
2007-03-31 06:25 21 --a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\emopts.dat
2007-03-31 06:25 <DIR> d--h----- C:\DOCUME~1\ALLUSE~1\APPLIC~1\sacache
2007-03-31 06:24 270,336 --a------ C:\WINDOWS\rsscap.dll
2007-03-29 01:46 <DIR> d-------- C:\WINDOWS\pss
2007-03-28 20:40 3,820,104 --a------ C:\DOCUME~1\ADMINI~1\gosetup.exe
2007-03-28 03:06 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-03-26 21:16 2,368 --a------ C:\WINDOWS\system32\SVKP.sys
2007-03-20 02:33 14,568 --a------ C:\WINDOWS\system32\drivers\wg3n.sys
2007-03-20 02:32 83,096 --a------ C:\WINDOWS\system32\SSSensor.dll
2007-03-20 02:32 60,496 --a------ C:\WINDOWS\system32\drivers\Teefer.sys
2007-03-20 02:32 21,075 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2007-03-20 02:32 <DIR> d-------- C:\Program Files\Sygate
2007-03-18 17:08 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2007-03-18 14:54 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-03-18 14:44 <DIR> d-------- C:\DOCUME~1\ADMINI~1\.housecall6.6
2007-03-15 01:10 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2007-03-14 14:37 <DIR> d-------- C:\WINDOWS\system32\bak
2007-03-14 01:15 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Contacts
2007-03-14 01:14 <DIR> d-------- C:\Program Files\Real
2007-03-14 01:13 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-03-14 01:12 <DIR> d-------- C:\Program Files\MSN Messenger


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-04-03 17:04 -------- d--h----- C:\Program Files\installshield installation information
2007-04-02 12:43 -------- d-------- C:\Program Files\visualware security suite
2007-04-02 12:26 -------- d-------- C:\Program Files\ulead systems
2007-01-19 12:53 51056 --a------ C:\WINDOWS\system32\sirenacm.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"PopUpStopperFreeEdition"="D:\\PROGRA~1\\PANICW~1\\POP-UP~1\\PSFree.exe"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"S3hotkey"="S3hotkey.exe"
"VTTimer"="VTTimer.exe"
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
"SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui"
"Video Driver"="D:\\Program Files\\Common Files\\Microsoft Shared\\DAO\\HOME\\svchost.exe"
"Srv32Win"="C:\\Program Files\\services.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0



********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-04-06 3:42:21
C:\ComboFix-quarantined-files.txt ... 07-04-06 03:42

#5 ksaama

ksaama
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:08:17 AM

Posted 05 April 2007 - 10:12 PM

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall


Combofix.exe deleted wpcap.dll which I need for the running of a legitimate module that I installed. Now I can't reinstall the module because that file is gone. Please help me restore the wpcap.dll file.

#6 jurgenv

jurgenv

  • Members
  • 1,093 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:06:17 AM

Posted 06 April 2007 - 05:54 AM

Combofix creates backups, so that's good news for you. :thumbsup: Please post the content of the following textfile here.
C:\Combofix_quarantined_files.txt

Please install WinPCap from this official site: http://www.winpcap.org/install/default.htm
Combofix doesn't touch this verison.

Edited by jurgenv, 06 April 2007 - 06:18 AM.

Greets Jürgenv

Donation: Click me.

#7 ksaama

ksaama
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:08:17 AM

Posted 06 April 2007 - 11:41 AM

C:\Combofix_quarantined_files.txt:


03-06-13 12:52	  212992	--a------	C:\Qoobox\Quarantine\WINDOWS\system32\wpcap.dll.vir 
03-06-13 12:55	  57344	--a------	C:\Qoobox\Quarantine\WINDOWS\system32\packet.dll.vir 
03-06-13 13:06	  30336	--a------	C:\Qoobox\Quarantine\WINDOWS\system32\drivers\npf.sys.vir 
07-04-06 03:03	  1220	--a------	C:\Qoobox\Quarantine\Registry_backups\LEGACY_NPF.reg.cf 
07-04-06 03:03	  2362	--a------	C:\Qoobox\Quarantine\Registry_backups\services_NPF.reg.cf 
C:Combofix_quarantined_files.txt:



Folder PATH listing
Volume serial number is 00F3-C168
C:\QOOBOX
\---Quarantine
	+---Registry_backups
	|	   LEGACY_NPF.reg.cf
	|	   services_NPF.reg.cf
	|	   
	\---WINDOWS
		\---system32
			|   packet.dll.vir
			|   wpcap.dll.vir
			|   
			\---drivers
					npf.sys.vir


I will install WinPCap from the link you indicated.

#8 jurgenv

jurgenv

  • Members
  • 1,093 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:06:17 AM

Posted 06 April 2007 - 11:53 AM

Ok, let me know if it helps.
Greets Jürgenv

Donation: Click me.

#9 ksaama

ksaama
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:08:17 AM

Posted 06 April 2007 - 12:08 PM

I installed WinPCap then installed the monitoring module that was disabled by Combofix.exe. I didn't get any error reinstalling the monitoring module. It will be at least another half hour to see if the module is back to task or not. Will let you know once I find out.

So what does that quarantined text file tell you?

#10 ksaama

ksaama
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:08:17 AM

Posted 06 April 2007 - 12:14 PM

I got this warning message from my firewall: "Rpf.sys[nt5/6 x86] Kernel driver [npf.sys] is being contacted from a remote machine www.bleepingcomputer.com [216.213.19.27] using local port 1101 [pt2-discover-pt2-discover] Do you want to allow this program to access the network?"

That's strange!!! :thumbsup:

#11 ksaama

ksaama
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:08:17 AM

Posted 06 April 2007 - 01:56 PM

Combofix creates backups, so that's good news for you. :thumbsup: Please post the content of the following textfile here.
C:\Combofix_quarantined_files.txt

Please install WinPCap from this official site: http://www.winpcap.org/install/default.htm
Combofix doesn't touch this verison.


When i clicked on the link you gave to install WinPCap it seemed to have hung up so I tried ALT+CTRL+Delete to see what's going on. My pc froze so I had to restart. That somwhow messed up my task manager program. It eliminated the top portion of the tak manager so now I can't switch back and forth between Resources, performance and other funtions. How can I get my tak manager back in shape?

This thread seems to have caused more problems with my PC than it did any help.

Can I get some help please?

#12 jurgenv

jurgenv

  • Members
  • 1,093 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:06:17 AM

Posted 06 April 2007 - 02:33 PM

Can I see a new hijackthis log? :thumbsup:
EDIT: You may allow acces with your firewall

These are the backups:

C:\Qoobox\Quarantine\WINDOWS\system32\wpcap.dll.vir
C:\Qoobox\Quarantine\WINDOWS\system32\packet.dll.vir
C:\Qoobox\Quarantine\WINDOWS\system32\drivers\npf.sys.vir

remove the .vir extension and place the first two in your C:\WINDOWS\system32 folder
npf.sys must be replaced in the C:\WINDOWS\system32\drivers folder

Next:

C:\Qoobox\Quarantine\Registry_backups\LEGACY_NPF.reg.cf
C:\Qoobox\Quarantine\Registry_backups\services_NPF.reg.cf

Please remove the .cf extensions and double click in the two .reg files and let them both merge with the registry.

Edited by jurgenv, 06 April 2007 - 02:37 PM.

Greets Jürgenv

Donation: Click me.

#13 ksaama

ksaama
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:08:17 AM

Posted 06 April 2007 - 04:39 PM

my hijacklog:

Logfile of HijackThis v1.99.1
Scan saved at 12:34:02 AM, on 4/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
d:\Program Files\Network LookOut Administrator Pro\bin\NLAgentProSvc.exe
C:\WINDOWS\system32\wuauclt.exe
d:\Program Files\Network LookOut Administrator Pro\bin\NLAgentPro.exe
C:\WINDOWS\system32\S3hotkey.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\csrss.exe
D:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\winsrvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [S3hotkey] S3hotkey.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [Video Driver] D:\Program Files\Common Files\Microsoft Shared\DAO\HOME\svchost.exe
O4 - HKLM\..\Run: [Srv32Win] C:\Program Files\csrss.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] D:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Network LookOut Agent (NetworkLookOutAgent) - Unknown owner - d:\Program Files\Network LookOut Administrator Pro\bin\NLAgentProSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

#14 jurgenv

jurgenv

  • Members
  • 1,093 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:06:17 AM

Posted 06 April 2007 - 04:43 PM

Your Java Runtime Environment is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6u1.
  • Scroll down to where it says "Java Runtime Enviroinment (JRE) 6u1, The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation, Multi-language and save it to your desktop (13.16 MB).
  • Close any programs you may have running - especially any web browsers.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u1-windows-i586-p.exe to install the newest version.
* Please open hijackthis and put a check next to the following:

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [Video Driver] D:\Program Files\Common Files\Microsoft Shared\DAO\HOME\svchost.exe
O4 - HKLM\..\Run: [Srv32Win] C:\Program Files\csrss.exe


* After you check the items you want to fix, close all browsers and windows, except for HijackThis, then click on the Fix Checked button on HijackThis.

Please download the Killbox by Option^Explicit.

Note: In the event you already have Killbox, this is a new version that I need you to download.
  • Save it to your desktop.
  • Please double-click Killbox.exe to run it.
  • Select:
    • Delete on Reboot
    • then Click on the All Files button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    D:\Program Files\Common Files\Microsoft Shared\DAO\HOME\svchost.exe
    C:\Program Files\csrss.exe



  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
  • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

* After that, post a new hijackthis log here.
Greets Jürgenv

Donation: Click me.

#15 ksaama

ksaama
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:08:17 AM

Posted 06 April 2007 - 05:23 PM

Ok I am downloading Java and will follow the instructions you specified but please take note that I think that C:\Program Files\csrss.exe is the legit monitoring module that I want to keep. Should I skip the instructions reg C:\Program Files\csrss.exe?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users