|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread |
Rating:
|
Display Modes |
|
|
#1 |
|
Mechanical Guru
Join Date: Jul 2000
Location: Husker Country
Posts: 1,482
|
I have a friend who is having some difficulties with trojans and the like. I helped him clear some of it out but some keeps coming back and was hoping for some input.
Sometimes he get popups including these: clean-xp.com, fixregerror.com, e-regclean.com as well as this - error:reg-3328 Here's his log file: Logfile of HijackThis v1.99.1 Scan saved at 3:55:20 PM, on 8/10/2005 Platform: Windows 2000 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\System32\mspmspsv.exe C:\WINNT\Explorer.exe C:\WINNT\javakl32.exe C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINNT\System32\intell32.exe C:\WINNT\systy.exe C:\PROGRA~1\WINZIP\winzip32.exe C:\Documents and Settings\Evanne\Local Settings\Temp\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047 R3 - Default URLSearchHook is missing O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\program files\adobe\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: Class - {ED094E2D-10B1-7DB1-84CC-C1B055BABB7C} - C:\WINNT\system32\mshc32.dll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKLM\..\Run: [intell32.exe] C:\WINNT\System32\intell32.exe O4 - HKLM\..\Run: [ipxo.exe] C:\WINNT\ipxo.exe O4 - HKLM\..\Run: [ipzd32.exe] C:\WINNT\ipzd32.exe O4 - HKLM\..\Run: [systy.exe] C:\WINNT\systy.exe O4 - Global Startup: Microsoft Office.lnk = D:\Office\OSA9.EXE O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.activation.rr.com/install...ad/tgctlcm.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1122757531221 O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\ipdo32.exe" /s (file missing) O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe Thanks for the help.
__________________
If you really want to understand - try changing it. Sys specs: NZXT Lexa_Asus P5E_E6750 2.66Ghz_GSkill 2GB PC6400_Mushkin 2GB PC6400_WD SE16 250GB_Pioneer 16x slot dvd_Pioneer 16x dvdrw ATI x1600pro 512mb |
|
|
|
|
|
#2 |
|
Member (10 bit)
Join Date: Mar 2004
Location: California
Posts: 936
|
hello Parde
Please read through the instructions before you start (you may want to print this out or copy it into a word program). Please download and install these programs - don't run them yet!! Please download the trial version of Ewido Security Suite here: http://www.ewido.net/en/download/ 1. When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu". 2. When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment. 3. From the main ewido screen, click on update in the left menu, then click the Start update button. 4. After the update finishes (the status bar at the bottom will display "Update successful") 5. Exit Ewido. DO NOT scan yet. Tutorial if needed Please download and unzip AboutBuster to a folder. AboutBuster MUST be updated before you use it. Check the AboutBuster Tutorial for instructions. Don't run it yet. Download and unzip HSfix to your desktop. use link below: DownloadItHere The above Registry file was written specifically for this infection and is not to be used on any other infection as it could damage a person's PC Download CW-Shredder at the link below: http://www.trendmicro.com/ftp/produc...cwshredder.exe Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders" Click "Apply" then "OK" Reboot into SafeMode. <---MAKE SURE YOU KNOW HOW TO DO THIS!! +++++++++++++++++++++++++++++++++++++++++++++++++ Here's the fix: 1. Reboot into safe mode Important Step 2. Go to Start->Run and type "Services.msc" (without quotes) then hit Ok Scroll down and find the service called: Remote Procedure Call (RPC) Helper When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps. 3.Run HiJackThis then: 1. Click "Config..." 2. Click "Misc Tools" 3. Click "Open Process manager" - Next, while holding down the CTRL key, locate (if present) and click on (highlight) each of the following: C:\WINNT\javakl32.exe C:\WINNT\System32\intell32.exe C:\WINNT\systy.exe Now double-check and make sure that only those item(s) above are highlighted, then click "Kill process". Now, click "Refresh", check again, and repeat this step if any remain. 4. CLOSE ALL WINDOWS AND BROWSERS Scan with Hijack This and put checks next to all the following, then click "Fix Checked" R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047 R3 - Default URLSearchHook is missing O2 - BHO: Class - {ED094E2D-10B1-7DB1-84CC-C1B055BABB7C} - C:\WINNT\system32\mshc32.dll O4 - HKLM\..\Run: [intell32.exe] C:\WINNT\System32\intell32.exe O4 - HKLM\..\Run: [ipxo.exe] C:\WINNT\ipxo.exe O4 - HKLM\..\Run: [ipzd32.exe] C:\WINNT\ipzd32.exe O4 - HKLM\..\Run: [systy.exe] C:\WINNT\systy.exe O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\ipdo32.exe" /s (file missing) Click on Fix Checked and exit HijackThis. 5. Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders: files... C:\WINNT\javakl32.exe C:\WINNT\System32\intell32.exe C:\WINNT\systy.exe C:\WINNT\system32\rqxdz.dll C:\WINNT\system32\mshc32.dll C:\WINNT\ipxo.exe C:\WINNT\ipzd32.exe (and any other files with the same name that end in .dll, .exe or .dat, you may find them right next to each other, example - javakl32.exe, javakl32.dll, javakl32.dat) If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again. 6. Double click on the HSfix and when asked to merge say yes. 7. Run CW-Shredder - Hit the FIX button - let it run and fix what it finds. 8. Run AboutBuster . This will scan your computer for the bad files and delete them. It will ask to scan the system again, let it. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps. 9. Run Ewido Security Suite Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run. If ewido finds anything, it will pop up a notification. We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, pcAnywhere and the game "Risk" have been flagged), select "none" as the action. DO NOT check "Perform action with all infections". If you are unsure of an entry, select "none" for the time being. I'll see that in the log you will post later and let you know if ewido needs to be run again. When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again. 10. Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove: Temporary Files Temporary Internet Files Recycle Bin 11. Reboot into normal mode and open up Internet Explorer 12. Download and run this online virus scan if you can:<---Important http://housecall.trendmicro.com/hous...start_corp.asp Make sure you check "AutoClean" 13. Reboot and post a fresh HJT log back here by using the add reply button below, and lets see how we did. Lobos |
|
|
|
|
|
#3 |
|
Mechanical Guru
Join Date: Jul 2000
Location: Husker Country
Posts: 1,482
|
I had him follow the instructions. The about blank is now gone but he is still having pop ups asking to visit sites to remove ad/spyware. Here are the Hijack and Ewido logs. He didn't know where the Aboutbuster log went but I told him to look for it in the Aboutbuster folder it would have created.
Logfile of HijackThis v1.99.1 Scan saved at 3:50:20 PM, on 8/12/2005 Platform: Windows 2000 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINNT\System32\svchost.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\System32\mspmspsv.exe C:\WINNT\Explorer.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINNT\explorer.exe C:\Documents and Settings\Evanne\Desktop\Cheeser's Stuff\HijackThis.exe O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKLM\..\Run: [netip.exe] C:\WINNT\system32\netip.exe O4 - Global Startup: Microsoft Office.lnk = D:\Office\OSA9.EXE O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.activation.rr.com/install...ad/tgctlcm.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1122757531221 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe --------------------------------------------------------- ewido security suite - Scan report --------------------------------------------------------- + Created on: 3:37:33 PM, 8/12/2005 + Report-Checksum: D3B0F3D8 + Scan result: C:\WINNT\system32\winyc.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\javapa32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\sysyp.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\apixl32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\winxx.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\winbk32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\javaas.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\apijz.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\msga.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\addwl32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\mfcmt.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\d3hc32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\javaae.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\appfx.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\netjz.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\syswo.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\winov.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\javadt.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\atlqi.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\apinq32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\winva.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\ietl.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\atljg32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\ipir32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\ipeg32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\ntkd.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\mfclx32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\atlfd32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\apizm32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\mswf.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\mfccw32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\nteq.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\apikh.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\javabu32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\syskh32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\ntjp.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\sdkmc32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\d3en32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\d3ep.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\addvd32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\netxe32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\adddg.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\d3nv.exe -> Trojan.Agent.bi : Ignored C:\WINNT\system32\ipmm32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\ajcygl.dat -> TrojanDownloader.Agent.bq : Ignored C:\WINNT\tbyudo.dat -> Trojan.Agent.bi : Ignored C:\WINNT\jmkncs.log -> Trojan.Agent.bi : Ignored C:\WINNT\ygztnh.dat -> Trojan.Agent.bi : Ignored C:\WINNT\xdcsyb.txt -> Trojan.Agent.bi : Ignored C:\WINNT\kdxttk.log -> Trojan.Agent.bi : Ignored C:\WINNT\wwxudt.dat -> Trojan.Agent.bi : Ignored C:\WINNT\qynhqq.log -> TrojanDownloader.Agent.bq : Ignored C:\WINNT\vomolk.dat -> TrojanDownloader.Agent.bc : Ignored C:\WINNT\kvrboe.txt -> Trojan.Agent.bi : Ignored C:\WINNT\jlmnlx.dat -> TrojanDownloader.Agent.bc : Ignored C:\WINNT\qauvrt.txt -> Trojan.Agent.bi : Ignored C:\WINNT\apiew32.dll -> TrojanDownloader.Agent.bc : Ignored C:\WINNT\uoxmro.txt -> Trojan.Agent.bi : Ignored C:\WINNT\netjx32.dll -> TrojanDownloader.Agent.bc : Ignored C:\WINNT\gxyxmk.dat -> Trojan.Agent.bi : Ignored C:\WINNT\wraukb.txt -> Trojan.Agent.bi : Ignored C:\WINNT\akofno.txt -> Trojan.Agent.bi : Ignored C:\WINNT\zlifme.txt -> Trojan.Agent.bi : Ignored C:\WINNT\appzu.exe -> Trojan.Agent.bi : Ignored C:\WINNT\crkz.exe -> Trojan.Agent.bi : Ignored C:\WINNT\apiad.exe -> Trojan.Agent.bi : Ignored C:\WINNT\mszh.exe -> Trojan.Agent.bi : Ignored C:\WINNT\ntle.exe -> Trojan.Agent.bi : Ignored C:\WINNT\appbi.exe -> Trojan.Agent.bi : Ignored C:\WINNT\netfm32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\iedi32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\apptx.exe -> Trojan.Agent.bi : Ignored C:\WINNT\mfcps32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\ipnz.exe -> Trojan.Agent.bi : Ignored C:\WINNT\crjb.exe -> Trojan.Agent.bi : Ignored C:\WINNT\sysoy32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\sdknf32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\mfczc32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\ipmy.exe -> Trojan.Agent.bi : Ignored C:\WINNT\addpr32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\apijb32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\winxl.exe -> Trojan.Agent.bi : Ignored C:\WINNT\addfp32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\atldr.exe -> Trojan.Agent.bi : Ignored C:\WINNT\applm32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\crwz32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\sysfm32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\javaif.exe -> Trojan.Agent.bi : Ignored C:\WINNT\ntlg32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\atluv32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\ntpv.exe -> Trojan.Agent.bi : Ignored C:\WINNT\netjb.exe -> Trojan.Agent.bi : Ignored C:\WINNT\d3bg32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\mspu.exe -> Trojan.Agent.bi : Ignored C:\WINNT\sysnw32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\sysmy32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\xvpbzs.dat -> Trojan.Agent.bi : Ignored C:\WINNT\d3ts32.dll -> TrojanDownloader.Agent.bc : Ignored C:\WINNT\gtpvqg.dat -> Trojan.Agent.bi : Ignored C:\WINNT\ipma.exe -> Trojan.Agent.bi : Ignored C:\WINNT\qwrpvd.dat -> Trojan.Agent.bi : Ignored C:\WINNT\qxshxs.dat -> Trojan.Agent.bi : Ignored C:\WINNT\atlwx32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\apicz32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\xchsjs.dat -> Trojan.Agent.bi : Ignored C:\WINNT\crqi32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\ixciyv.dat -> Trojan.Agent.bi : Ignored C:\WINNT\fvyggy.dat -> Trojan.Agent.bi : Ignored C:\WINNT\netyg.exe -> Trojan.Agent.bi : Ignored C:\WINNT\ntsi32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\apiuz.exe -> TrojanDownloader.Agent.bq : Ignored C:\WINNT\ipdi32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\iejf.exe -> Trojan.Agent.bi : Ignored C:\WINNT\appim32.exe -> Trojan.Agent.bi : Ignored C:\WINNT\apivn32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINNT\ieqb32.exe -> Trojan.Agent.bi : Cleaned with backup ::Report End |
|
|
|
|
|
#4 |
|
Member (10 bit)
Join Date: Mar 2004
Location: California
Posts: 936
|
Download Pocket Killbox version 2.0.0.175
http://www.atribune.org/downloads/KillBox.exe If you already have Killbox first ensure it is this version !. Then double-click on the killbox.exe program. When the program is open, select the option labeled Delete on reboot. Do not close killbox, and open notepad, by clicking on Start, then Run, and typing notepad.exe and pressing the OK button. When notepad is open, copy and paste the following bolded text into the notepad screen. You do this by highlighting each of the below bolded filenames and then pressing Control-C on your keyboard. Then click on the open notepad windows and press Control-V to paste the contents into the notepad. C:\WINNT\system32\winyc.exe C:\WINNT\system32\javapa32.exe C:\WINNT\system32\sysyp.exe C:\WINNT\system32\apixl32.exe C:\WINNT\system32\winxx.exe C:\WINNT\system32\winbk32.exe C:\WINNT\system32\javaas.exe C:\WINNT\system32\apijz.exe C:\WINNT\system32\msga.exe C:\WINNT\system32\addwl32.exe C:\WINNT\system32\mfcmt.exe C:\WINNT\system32\d3hc32.exe C:\WINNT\system32\javaae.exe C:\WINNT\system32\appfx.exe C:\WINNT\system32\netjz.exe C:\WINNT\system32\syswo.exe C:\WINNT\system32\winov.exe C:\WINNT\system32\javadt.exe C:\WINNT\system32\atlqi.exe C:\WINNT\system32\apinq32.exe C:\WINNT\system32\winva.exe C:\WINNT\system32\ietl.exe C:\WINNT\system32\atljg32.exe C:\WINNT\system32\ipir32.exe C:\WINNT\system32\ipeg32.exe C:\WINNT\system32\ntkd.exe C:\WINNT\system32\mfclx32.exe C:\WINNT\system32\atlfd32.exe C:\WINNT\system32\apizm32.exe C:\WINNT\system32\mswf.exe C:\WINNT\system32\mfccw32.exe C:\WINNT\system32\nteq.exe C:\WINNT\system32\apikh.exe C:\WINNT\system32\javabu32.exe C:\WINNT\system32\syskh32.exe C:\WINNT\system32\ntjp.exe C:\WINNT\system32\sdkmc32.exe C:\WINNT\system32\d3en32.exe C:\WINNT\system32\d3ep.exe C:\WINNT\system32\addvd32.exe C:\WINNT\system32\netxe32.exe C:\WINNT\system32\adddg.exe C:\WINNT\system32\d3nv.exe C:\WINNT\system32\ipmm32.exe C:\WINNT\system32\netip.exe C:\WINNT\ajcygl.dat C:\WINNT\tbyudo.dat C:\WINNT\jmkncs.log C:\WINNT\ygztnh.dat C:\WINNT\xdcsyb.txt C:\WINNT\kdxttk.log C:\WINNT\wwxudt.dat C:\WINNT\qynhqq.log C:\WINNT\vomolk.dat C:\WINNT\kvrboe.txt C:\WINNT\jlmnlx.dat C:\WINNT\qauvrt.txt C:\WINNT\apiew32.dll C:\WINNT\uoxmro.txt C:\WINNT\netjx32.dll C:\WINNT\gxyxmk.dat C:\WINNT\wraukb.txt C:\WINNT\akofno.txt C:\WINNT\zlifme.txt C:\WINNT\appzu.exe C:\WINNT\crkz.exe C:\WINNT\apiad.exe C:\WINNT\mszh.exe C:\WINNT\ntle.exe C:\WINNT\appbi.exe C:\WINNT\netfm32.exe C:\WINNT\iedi32.exe C:\WINNT\apptx.exe C:\WINNT\mfcps32.exe C:\WINNT\ipnz.exe C:\WINNT\crjb.exe C:\WINNT\sysoy32.exe C:\WINNT\sdknf32.exe C:\WINNT\mfczc32.exe C:\WINNT\ipmy.exe C:\WINNT\addpr32.exe C:\WINNT\apijb32.exe C:\WINNT\winxl.exe C:\WINNT\addfp32.exe C:\WINNT\atldr.exe C:\WINNT\applm32.exe C:\WINNT\crwz32.exe C:\WINNT\sysfm32.exe C:\WINNT\javaif.exe C:\WINNT\ntlg32.exe C:\WINNT\atluv32.exe C:\WINNT\ntpv.exe C:\WINNT\netjb.exe C:\WINNT\d3bg32.exe C:\WINNT\mspu.exe C:\WINNT\sysnw32.exe C:\WINNT\sysmy32.exe C:\WINNT\xvpbzs.dat C:\WINNT\d3ts32.dll C:\WINNT\gtpvqg.dat C:\WINNT\ipma.exe C:\WINNT\qwrpvd.dat C:\WINNT\qxshxs.dat C:\WINNT\atlwx32.exe C:\WINNT\apicz32.exe C:\WINNT\xchsjs.dat C:\WINNT\crqi32.exe C:\WINNT\ixciyv.dat C:\WINNT\fvyggy.dat C:\WINNT\netyg.exe C:\WINNT\ntsi32.exe C:\WINNT\apiuz.exe C:\WINNT\ipdi32.exe C:\WINNT\iejf.exe C:\WINNT\appim32.exe C:\WINNT\apivn32.exe C:\WINNT\ieqb32.exe Return to Killbox, go to the File menu and select Paste from Clipboard. Still in Killbox, click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click No at the Pending Operations prompt. If your computer does not restart automatically, please restart it manually Post another hijack this log Lobos |
|
|
|
|
|
#5 |
|
Mechanical Guru
Join Date: Jul 2000
Location: Husker Country
Posts: 1,482
|
Had friend download and run killbox.
Here's what he emailed me: "Still have pop ups on system messenger, have developed a new wall paper that tells me of errors in my computer and that I should buy Razespyware to fix it." Here's his hijack log after running killbox: Logfile of HijackThis v1.99.1 Scan saved at 9:01:20 PM, on 8/14/2005 Platform: Windows 2000 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINNT\System32\svchost.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\System32\mspmspsv.exe C:\WINNT\Explorer.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\Documents and Settings\Evanne\Desktop\Cheeser's Stuff\HijackThis.exe O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - Startup: Internet Cleaning Tool.lnk = C:\Program Files\Internet Cleaning Tool\InternetCleaningTool.exe O4 - Global Startup: Microsoft Office.lnk = D:\Office\OSA9.EXE O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.activation.rr.com/install...ad/tgctlcm.cab O16 - DPF: {11010101-1001-1111-1000-110112345678} - mk:@mSItSTORE:Mhtml:FiLE://C:\html.mHT!http://205.177.122.27/docs/xxx/html.chm::/html.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1122757531221 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1124031360636 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe |
|
|
|
|
|
#6 |
|
Member (10 bit)
Join Date: Mar 2004
Location: California
Posts: 936
|
Run HiJackThis and click "Scan", then check(tick) the following, if present:
O16 - DPF: {11010101-1001-1111-1000-110112345678} - mk:@mSItSTORE:Mhtml:FiLE://C:\html.mHT!http://205.177.122.27/docs/xxx/html.chm::/html.exe Now, with all windows closed except HiJackThis, click "Fix checked". =============== To turn messenger off In Windows 2000: 1. Select "Start" 2. Choose "Settings" 3. Choose "Control Panel" 4. Choose "Administrative Tools" 5. Choose "Services" 6. Right-click "Messenger" 7. Select "Properties" 8. Click "Stop" To permanently disable Messenger: 9. Change "Startup Type" to "Disabled" and click "OK" messenger is off download this Right click here and go to Save As (in IE it's Save Target As) in order to download the smitfraud reg to your desktop. Double-click smitfraud.reg on your desktop. When asked if you want to merge with the registry click YES. After the merged successfully prompt, using Windows Explorer, navigate to the following folder: C:\WINNT\Prefetch If there are any files inside the Prefetch folder, delete ALL of them. (Do NOT delete the folder. Just delete the files inside.) Reboot your computer. now you should be able to change your desktop to what ever you want Post back a new log, and let me know how everything goes. - Lobos. Last edited by Lobos; 08-16-2005 at 05:56 PM. |
|
|
|
|
|
#7 |
|
Mechanical Guru
Join Date: Jul 2000
Location: Husker Country
Posts: 1,482
|
Lobos - thank you for the help so far.
Here's the latest log file after following the instructions. He also emailed this info: "The good news is the warnings have stopped - I suppose that's because the messenger might still be disabled. The leftover is the Razespyware crap as it is still in charge of the screen. Right click does not respond when activated on the screen while the razecrap is on. When I tried to find the Prefetch folder I could not find it in WINNT I searched the computer with no luck." Logfile of HijackThis v1.99.1 Scan saved at 5:19:59 PM, on 8/17/2005 Platform: Windows 2000 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINNT\System32\svchost.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\System32\mspmspsv.exe C:\WINNT\Explorer.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\Documents and Settings\Evanne\Desktop\New Briefcase\Cheeser's Stuff\HijackThis.exe O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - Global Startup: Microsoft Office.lnk = D:\Office\OSA9.EXE O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.activation.rr.com/install...ad/tgctlcm.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1122757531221 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1124031360636 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe |
|
|
|
|
|
#8 |
|
Member (10 bit)
Join Date: Mar 2004
Location: California
Posts: 936
|
can you uninstall it
if you cant find it Open hijack this Click config click Misc tools click open uninstall manager click save list post the list here Lobos |
|
|
|
|
|
#9 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 41,180
|
Now it's time to put SP4, the rollup package, and all critical updates on.
I'd be a bit suspicious of regsvc.exe - this is the remote registry service. It's only used on Win2K Server and workstations administered over a network. On a standalone machine it can be disabled. Something to look at - set the folder options to show hidden and system files and unhide known extensions. Go into documents and settings - his username - desktop - and if there's a desktop.ini file in there delete it. |
|
|
|
|
|
#10 |
|
Mechanical Guru
Join Date: Jul 2000
Location: Husker Country
Posts: 1,482
|
Friend followed the above suggestions. With his limited memory/space had trouble getting the SP4 but finally did. Also, had trouble with regsvc.exe and could not get rid of it.
Here is what he has now: "I'm getting this "Run Time Error 5 at 004047C5" [0=zero] just before Razespyware takes over the wallpaper." |
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|