Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rating: Thread Rating: 1 votes, 1.00 average. Display Modes
Old 08-10-2005, 05:55 PM   #1
Mechanical Guru
 
PardeGT's Avatar
 
Join Date: Jul 2000
Location: Husker Country
Posts: 1,482
Unhappy Hijack log critique

I have a friend who is having some difficulties with trojans and the like. I helped him clear some of it out but some keeps coming back and was hoping for some input.

Sometimes he get popups including these:
clean-xp.com, fixregerror.com, e-regclean.com as well as
this - error:reg-3328

Here's his log file:

Logfile of HijackThis v1.99.1
Scan saved at 3:55:20 PM, on 8/10/2005
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\Explorer.exe
C:\WINNT\javakl32.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINNT\System32\intell32.exe
C:\WINNT\systy.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Evanne\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\program files\adobe\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Class - {ED094E2D-10B1-7DB1-84CC-C1B055BABB7C} - C:\WINNT\system32\mshc32.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [intell32.exe] C:\WINNT\System32\intell32.exe
O4 - HKLM\..\Run: [ipxo.exe] C:\WINNT\ipxo.exe
O4 - HKLM\..\Run: [ipzd32.exe] C:\WINNT\ipzd32.exe
O4 - HKLM\..\Run: [systy.exe] C:\WINNT\systy.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Office\OSA9.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.activation.rr.com/install...ad/tgctlcm.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1122757531221
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\ipdo32.exe" /s (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe


Thanks for the help.
__________________
If you really want to understand - try changing it.

Sys specs:
NZXT Lexa_Asus P5E_E6750 2.66Ghz_GSkill 2GB PC6400_Mushkin 2GB PC6400_WD SE16 250GB_Pioneer 16x slot dvd_Pioneer 16x dvdrw
ATI x1600pro 512mb
PardeGT is offline   Reply With Quote
Old 08-11-2005, 01:45 AM   #2
Member (10 bit)
 
Join Date: Mar 2004
Location: California
Posts: 936
hello Parde

Please read through the instructions before you start (you may want to print this out or copy it into a word program).

Please download and install these programs - don't run them yet!!

Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/
1. When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
2. When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
3. From the main ewido screen, click on update in the left menu, then click the Start update button.
4. After the update finishes (the status bar at the bottom will display "Update successful")
5. Exit Ewido. DO NOT scan yet.
Tutorial if needed


Please download and unzip
AboutBuster to a folder.
AboutBuster MUST be updated before you use it.
Check the AboutBuster Tutorial for instructions.
Don't run it yet.

Download and unzip HSfix to your desktop. use link below:
DownloadItHere

The above Registry file was written specifically for this infection and is not to be used on any other infection as it could damage a person's PC


Download CW-Shredder at the link below:
http://www.trendmicro.com/ftp/produc...cwshredder.exe

Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked.
Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

Reboot into SafeMode. <---MAKE SURE YOU KNOW HOW TO DO THIS!!

+++++++++++++++++++++++++++++++++++++++++++++++++

Here's the fix:


1. Reboot into safe mode

Important Step
2. Go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called:
Remote Procedure Call (RPC) Helper

When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.

3.Run HiJackThis then:

1. Click "Config..."
2. Click "Misc Tools"
3. Click "Open Process manager"

-

Next, while holding down the CTRL key, locate (if present) and click on (highlight) each of the following:

C:\WINNT\javakl32.exe
C:\WINNT\System32\intell32.exe
C:\WINNT\systy.exe

Now double-check and make sure that only those item(s) above are highlighted, then click "Kill process". Now, click "Refresh", check again, and repeat this step if any remain.




4. CLOSE ALL WINDOWS AND BROWSERS Scan with Hijack This and put checks next to all the following, then click "Fix Checked"


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\rqxdz.dll/sp.html#12047

R3 - Default URLSearchHook is missing

O2 - BHO: Class - {ED094E2D-10B1-7DB1-84CC-C1B055BABB7C} - C:\WINNT\system32\mshc32.dll

O4 - HKLM\..\Run: [intell32.exe] C:\WINNT\System32\intell32.exe
O4 - HKLM\..\Run: [ipxo.exe] C:\WINNT\ipxo.exe
O4 - HKLM\..\Run: [ipzd32.exe] C:\WINNT\ipzd32.exe
O4 - HKLM\..\Run: [systy.exe] C:\WINNT\systy.exe

O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\ipdo32.exe" /s (file missing)

Click on Fix Checked and exit HijackThis.

5. Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:

files...

C:\WINNT\javakl32.exe
C:\WINNT\System32\intell32.exe
C:\WINNT\systy.exe
C:\WINNT\system32\rqxdz.dll
C:\WINNT\system32\mshc32.dll
C:\WINNT\ipxo.exe
C:\WINNT\ipzd32.exe


(and any other files with the same name that end in .dll, .exe or .dat, you may find them right next to each other, example - javakl32.exe, javakl32.dll, javakl32.dat)

If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.

6. Double click on the HSfix and when asked to merge say yes.

7. Run CW-Shredder - Hit the FIX button - let it run and fix what it finds.

8. Run AboutBuster . This will scan your computer for the bad files and delete them. It will ask to scan the system again, let it. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

9. Run Ewido Security Suite
Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
If ewido finds anything, it will pop up a notification. We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, pcAnywhere and the game "Risk" have been flagged), select "none" as the action. DO NOT check "Perform action with all infections". If you are unsure of an entry, select "none" for the time being. I'll see that in the log you will post later and let you know if ewido needs to be run again.
When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.


10. Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin

11. Reboot into normal mode and open up Internet Explorer

12. Download and run this online virus scan if you can:<---Important
http://housecall.trendmicro.com/hous...start_corp.asp
Make sure you check "AutoClean"

13. Reboot and post a fresh HJT log back here by using the add reply button below, and lets see how we did.



Lobos
Lobos is offline   Reply With Quote
Old 08-13-2005, 01:16 PM   #3
Mechanical Guru
 
PardeGT's Avatar
 
Join Date: Jul 2000
Location: Husker Country
Posts: 1,482
I had him follow the instructions. The about blank is now gone but he is still having pop ups asking to visit sites to remove ad/spyware. Here are the Hijack and Ewido logs. He didn't know where the Aboutbuster log went but I told him to look for it in the Aboutbuster folder it would have created.

Logfile of HijackThis v1.99.1
Scan saved at 3:50:20 PM, on 8/12/2005
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\Explorer.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\Evanne\Desktop\Cheeser's Stuff\HijackThis.exe

O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [netip.exe] C:\WINNT\system32\netip.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Office\OSA9.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.activation.rr.com/install...ad/tgctlcm.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1122757531221
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe


---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 3:37:33 PM, 8/12/2005
+ Report-Checksum: D3B0F3D8

+ Scan result:

C:\WINNT\system32\winyc.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\javapa32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\sysyp.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\apixl32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\winxx.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\winbk32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\javaas.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\apijz.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\msga.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\addwl32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\mfcmt.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\d3hc32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\javaae.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\appfx.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\netjz.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\syswo.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\winov.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\javadt.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\atlqi.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\apinq32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\winva.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\ietl.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\atljg32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\ipir32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\ipeg32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\ntkd.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\mfclx32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\atlfd32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\apizm32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\mswf.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\mfccw32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\nteq.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\apikh.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\javabu32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\syskh32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\ntjp.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\sdkmc32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\d3en32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\d3ep.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\addvd32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\netxe32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\adddg.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\d3nv.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\system32\ipmm32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\ajcygl.dat -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\tbyudo.dat -> Trojan.Agent.bi : Ignored
C:\WINNT\jmkncs.log -> Trojan.Agent.bi : Ignored
C:\WINNT\ygztnh.dat -> Trojan.Agent.bi : Ignored
C:\WINNT\xdcsyb.txt -> Trojan.Agent.bi : Ignored
C:\WINNT\kdxttk.log -> Trojan.Agent.bi : Ignored
C:\WINNT\wwxudt.dat -> Trojan.Agent.bi : Ignored
C:\WINNT\qynhqq.log -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\vomolk.dat -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\kvrboe.txt -> Trojan.Agent.bi : Ignored
C:\WINNT\jlmnlx.dat -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\qauvrt.txt -> Trojan.Agent.bi : Ignored
C:\WINNT\apiew32.dll -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\uoxmro.txt -> Trojan.Agent.bi : Ignored
C:\WINNT\netjx32.dll -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\gxyxmk.dat -> Trojan.Agent.bi : Ignored
C:\WINNT\wraukb.txt -> Trojan.Agent.bi : Ignored
C:\WINNT\akofno.txt -> Trojan.Agent.bi : Ignored
C:\WINNT\zlifme.txt -> Trojan.Agent.bi : Ignored
C:\WINNT\appzu.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\crkz.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\apiad.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\mszh.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\ntle.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\appbi.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\netfm32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\iedi32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\apptx.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\mfcps32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\ipnz.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\crjb.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\sysoy32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\sdknf32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\mfczc32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\ipmy.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\addpr32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\apijb32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\winxl.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\addfp32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\atldr.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\applm32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\crwz32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\sysfm32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\javaif.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\ntlg32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\atluv32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\ntpv.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\netjb.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\d3bg32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\mspu.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\sysnw32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\sysmy32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\xvpbzs.dat -> Trojan.Agent.bi : Ignored
C:\WINNT\d3ts32.dll -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\gtpvqg.dat -> Trojan.Agent.bi : Ignored
C:\WINNT\ipma.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\qwrpvd.dat -> Trojan.Agent.bi : Ignored
C:\WINNT\qxshxs.dat -> Trojan.Agent.bi : Ignored
C:\WINNT\atlwx32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\apicz32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\xchsjs.dat -> Trojan.Agent.bi : Ignored
C:\WINNT\crqi32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\ixciyv.dat -> Trojan.Agent.bi : Ignored
C:\WINNT\fvyggy.dat -> Trojan.Agent.bi : Ignored
C:\WINNT\netyg.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\ntsi32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\apiuz.exe -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\ipdi32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\iejf.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\appim32.exe -> Trojan.Agent.bi : Ignored
C:\WINNT\apivn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\ieqb32.exe -> Trojan.Agent.bi : Cleaned with backup


::Report End
PardeGT is offline   Reply With Quote
Old 08-14-2005, 12:11 AM   #4
Member (10 bit)
 
Join Date: Mar 2004
Location: California
Posts: 936
Download Pocket Killbox version 2.0.0.175
http://www.atribune.org/downloads/KillBox.exe
If you already have Killbox first ensure it is this version !.

Then double-click on the killbox.exe program.

When the program is open, select the option labeled Delete on reboot.

Do not close killbox, and open notepad, by clicking on Start, then Run, and typing notepad.exe and pressing the OK button.


When notepad is open, copy and paste the following bolded text into the notepad screen. You do this by highlighting each of the below bolded filenames and then pressing Control-C on your keyboard. Then click on the open notepad windows and press Control-V to paste the contents into the notepad.




C:\WINNT\system32\winyc.exe
C:\WINNT\system32\javapa32.exe
C:\WINNT\system32\sysyp.exe
C:\WINNT\system32\apixl32.exe
C:\WINNT\system32\winxx.exe
C:\WINNT\system32\winbk32.exe
C:\WINNT\system32\javaas.exe
C:\WINNT\system32\apijz.exe
C:\WINNT\system32\msga.exe
C:\WINNT\system32\addwl32.exe
C:\WINNT\system32\mfcmt.exe
C:\WINNT\system32\d3hc32.exe
C:\WINNT\system32\javaae.exe
C:\WINNT\system32\appfx.exe
C:\WINNT\system32\netjz.exe
C:\WINNT\system32\syswo.exe
C:\WINNT\system32\winov.exe
C:\WINNT\system32\javadt.exe
C:\WINNT\system32\atlqi.exe
C:\WINNT\system32\apinq32.exe
C:\WINNT\system32\winva.exe
C:\WINNT\system32\ietl.exe
C:\WINNT\system32\atljg32.exe
C:\WINNT\system32\ipir32.exe
C:\WINNT\system32\ipeg32.exe
C:\WINNT\system32\ntkd.exe
C:\WINNT\system32\mfclx32.exe
C:\WINNT\system32\atlfd32.exe
C:\WINNT\system32\apizm32.exe
C:\WINNT\system32\mswf.exe
C:\WINNT\system32\mfccw32.exe
C:\WINNT\system32\nteq.exe
C:\WINNT\system32\apikh.exe
C:\WINNT\system32\javabu32.exe
C:\WINNT\system32\syskh32.exe
C:\WINNT\system32\ntjp.exe
C:\WINNT\system32\sdkmc32.exe
C:\WINNT\system32\d3en32.exe
C:\WINNT\system32\d3ep.exe
C:\WINNT\system32\addvd32.exe
C:\WINNT\system32\netxe32.exe
C:\WINNT\system32\adddg.exe
C:\WINNT\system32\d3nv.exe
C:\WINNT\system32\ipmm32.exe
C:\WINNT\system32\netip.exe
C:\WINNT\ajcygl.dat
C:\WINNT\tbyudo.dat
C:\WINNT\jmkncs.log
C:\WINNT\ygztnh.dat
C:\WINNT\xdcsyb.txt
C:\WINNT\kdxttk.log
C:\WINNT\wwxudt.dat
C:\WINNT\qynhqq.log
C:\WINNT\vomolk.dat
C:\WINNT\kvrboe.txt
C:\WINNT\jlmnlx.dat
C:\WINNT\qauvrt.txt
C:\WINNT\apiew32.dll
C:\WINNT\uoxmro.txt
C:\WINNT\netjx32.dll
C:\WINNT\gxyxmk.dat
C:\WINNT\wraukb.txt
C:\WINNT\akofno.txt
C:\WINNT\zlifme.txt
C:\WINNT\appzu.exe
C:\WINNT\crkz.exe
C:\WINNT\apiad.exe
C:\WINNT\mszh.exe
C:\WINNT\ntle.exe
C:\WINNT\appbi.exe
C:\WINNT\netfm32.exe
C:\WINNT\iedi32.exe
C:\WINNT\apptx.exe
C:\WINNT\mfcps32.exe
C:\WINNT\ipnz.exe
C:\WINNT\crjb.exe
C:\WINNT\sysoy32.exe
C:\WINNT\sdknf32.exe
C:\WINNT\mfczc32.exe
C:\WINNT\ipmy.exe
C:\WINNT\addpr32.exe
C:\WINNT\apijb32.exe
C:\WINNT\winxl.exe
C:\WINNT\addfp32.exe
C:\WINNT\atldr.exe
C:\WINNT\applm32.exe
C:\WINNT\crwz32.exe
C:\WINNT\sysfm32.exe
C:\WINNT\javaif.exe
C:\WINNT\ntlg32.exe
C:\WINNT\atluv32.exe
C:\WINNT\ntpv.exe
C:\WINNT\netjb.exe
C:\WINNT\d3bg32.exe
C:\WINNT\mspu.exe
C:\WINNT\sysnw32.exe
C:\WINNT\sysmy32.exe
C:\WINNT\xvpbzs.dat
C:\WINNT\d3ts32.dll
C:\WINNT\gtpvqg.dat
C:\WINNT\ipma.exe
C:\WINNT\qwrpvd.dat
C:\WINNT\qxshxs.dat
C:\WINNT\atlwx32.exe
C:\WINNT\apicz32.exe
C:\WINNT\xchsjs.dat
C:\WINNT\crqi32.exe
C:\WINNT\ixciyv.dat
C:\WINNT\fvyggy.dat
C:\WINNT\netyg.exe
C:\WINNT\ntsi32.exe
C:\WINNT\apiuz.exe
C:\WINNT\ipdi32.exe
C:\WINNT\iejf.exe
C:\WINNT\appim32.exe
C:\WINNT\apivn32.exe
C:\WINNT\ieqb32.exe




Return to Killbox, go to the File menu and select Paste from Clipboard.


Still in Killbox, click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click No at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually

Post another hijack this log


Lobos
Lobos is offline   Reply With Quote
Old 08-14-2005, 11:12 PM   #5
Mechanical Guru
 
PardeGT's Avatar
 
Join Date: Jul 2000
Location: Husker Country
Posts: 1,482
Unhappy

Had friend download and run killbox.
Here's what he emailed me:

"Still have pop ups on system messenger, have developed a new wall paper that tells me of errors in my computer and that I should buy Razespyware to fix it."

Here's his hijack log after running killbox:

Logfile of HijackThis v1.99.1
Scan saved at 9:01:20 PM, on 8/14/2005
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\Explorer.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Documents and Settings\Evanne\Desktop\Cheeser's Stuff\HijackThis.exe

O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - Startup: Internet Cleaning Tool.lnk = C:\Program Files\Internet Cleaning Tool\InternetCleaningTool.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.activation.rr.com/install...ad/tgctlcm.cab
O16 - DPF: {11010101-1001-1111-1000-110112345678} - mk:@mSItSTORE:Mhtml:FiLE://C:\html.mHT!http://205.177.122.27/docs/xxx/html.chm::/html.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1122757531221
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1124031360636
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
PardeGT is offline   Reply With Quote
Old 08-16-2005, 05:49 PM   #6
Member (10 bit)
 
Join Date: Mar 2004
Location: California
Posts: 936
Run HiJackThis and click "Scan", then check(tick) the following, if present:


O16 - DPF: {11010101-1001-1111-1000-110112345678} - mk:@mSItSTORE:Mhtml:FiLE://C:\html.mHT!http://205.177.122.27/docs/xxx/html.chm::/html.exe


Now, with all windows closed except HiJackThis, click "Fix checked".

===============

To turn messenger off In Windows 2000:

1. Select "Start"
2. Choose "Settings"
3. Choose "Control Panel"
4. Choose "Administrative Tools"
5. Choose "Services"
6. Right-click "Messenger"
7. Select "Properties"
8. Click "Stop" To permanently disable Messenger:
9. Change "Startup Type" to "Disabled" and click "OK"

messenger is off

download this
Right click here and go to Save As (in IE it's Save Target As) in order to download the smitfraud reg to your desktop.
Double-click smitfraud.reg on your desktop. When asked if you want to merge with the registry click YES.
After the merged successfully prompt, using Windows Explorer, navigate to the following folder:

C:\WINNT\Prefetch

If there are any files inside the Prefetch folder, delete ALL of them. (Do NOT delete the folder. Just delete the files inside.)
Reboot your computer.

now you should be able to change your desktop to what ever you want

Post back a new log, and let me know how everything goes.

-

Lobos.

Last edited by Lobos; 08-16-2005 at 05:56 PM.
Lobos is offline   Reply With Quote
Old 08-17-2005, 08:41 PM   #7
Mechanical Guru
 
PardeGT's Avatar
 
Join Date: Jul 2000
Location: Husker Country
Posts: 1,482
Lobos - thank you for the help so far.

Here's the latest log file after following the instructions. He also emailed this info:
"The good news is the warnings have stopped - I suppose that's because the messenger might still be disabled. The leftover is the Razespyware crap as it is still in charge of the screen. Right click does not respond when activated on the screen while the razecrap is on. When I tried to find the Prefetch folder I could not find it in WINNT I searched the computer with no luck."


Logfile of HijackThis v1.99.1
Scan saved at 5:19:59 PM, on 8/17/2005
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\Explorer.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Documents and Settings\Evanne\Desktop\New Briefcase\Cheeser's Stuff\HijackThis.exe

O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Office\OSA9.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.activation.rr.com/install...ad/tgctlcm.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1122757531221
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1124031360636
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
PardeGT is offline   Reply With Quote
Old 08-18-2005, 03:00 PM   #8
Member (10 bit)
 
Join Date: Mar 2004
Location: California
Posts: 936
can you uninstall it

if you cant find it

Open hijack this

Click config
click Misc tools
click open uninstall manager
click save list

post the list here


Lobos
Lobos is offline   Reply With Quote
Old 08-18-2005, 03:04 PM   #9
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 41,180
Now it's time to put SP4, the rollup package, and all critical updates on.

I'd be a bit suspicious of regsvc.exe - this is the remote registry service. It's only used on Win2K Server and workstations administered over a network. On a standalone machine it can be disabled.

Something to look at - set the folder options to show hidden and system files and unhide known extensions. Go into documents and settings - his username - desktop - and if there's a desktop.ini file in there delete it.
glc is online now   Reply With Quote
Old 08-22-2005, 10:32 PM   #10
Mechanical Guru
 
PardeGT's Avatar
 
Join Date: Jul 2000
Location: Husker Country
Posts: 1,482
Friend followed the above suggestions. With his limited memory/space had trouble getting the SP4 but finally did. Also, had trouble with regsvc.exe and could not get rid of it.

Here is what he has now:

"I'm getting this "Run Time Error 5 at 004047C5" [0=zero] just before Razespyware takes over the wallpaper."
PardeGT is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are Off
Pingbacks are Off
Refbacks are On



All times are GMT -5. The time now is 03:00 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.1