Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Some sort of Hijacker, plus ???
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Some sort of Hijacker, plus ???  
Forum Quick Jump
 
New Topic Post reply to : Some sort of Hijacker, plus ??? Printable version of : Some sort of Hijacker, plus ???
[ << Previous Thread | Next Thread >> ]

Susie1
New Member


Date Joined Nov 2006
Total Posts : 5
 
   Posted 11-21-2006 2:07 (GMT +2)    Quote: Some sort of Hijacker, plus ???Alert an admin about: Some sort of Hijacker, plus ???
I'm having troubles with browsers (AOL, IE, Firefox) working fine and after awhile, certain sites won't load act as if they're trying and time out, or I get what looks like a search engine return when I wasn't using a search enging.

Current versions Ad-aware & Spybot S&D (which for awhile I had troubles downloading current updates), found nothing. Symantec online scan acted as if it was downloading Active X controls but would never finish and progress. Housecall has worked fine a couple of times, found a few things, and then last night wouldn't run correctly. :-( After the first housecall run and fix, I ran ad-aware and spybot again -- one of them, I don't remember which, said it found and fixed both fizzlebar and softomate. After that, housecall didn't find anything but a few vulnerabilities -- I installed windows XP SP2 to fix part of that, and am working on getting office SP3 installed. But now even housecall won't run, acts like its trying, but never gets anywhere. I can't help but suspect that something is blocking each of these either from running or from finding anything even if they seem to have run properly.

Tonight, I had a URL unexpected show: http://aolsearch.aol.com/aol/webhome and don't know if this is legitimate or hijack....

I ran Hijack this and could really use some help and would be most grateful!!!

Logfile of HijackThis v1.99.1
Scan saved at 12:15:36 AM, on 11/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\shicoxp.exe
C:\WINDOWS\caxchg.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\America Online 9.0a\waol.exe
C:\PROGRA~1\COMMON~1\AOL\116339~1\EE\AOLHOS~1.EXE
C:\Program Files\Mightyfax\MFNTCTL.EXE
C:\PROGRA~1\COMMON~1\AOL\116339~1\EE\AOLServiceHost.exe
C:\Program Files\America Online 9.0a\shellmon.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\ACEhtml\AceHTML Freeware\acehtmlfree.exe
C:\Program Files\Virus n Spyware\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://a.tribalfusion.com/p.media/GLNTJLPMHKLGILGMNWMCJHNROVRREYTQFGMQGQPOLIWIKJGINTELIBKKJSWRLOMQUCWKGCIGLOBDMIJ/518736/pop.html
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [shicoxp] C:\WINDOWS\shicoxp.exe
O4 - HKLM\..\Run: [caxchg] C:\WINDOWS\caxchg.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [RealTray] "C:\Program Files\Real\RealPlayer\RealPlay.exe" SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1163390790\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: MightyFAX Controller.lnk = C:\Program Files\Mightyfax\MFNTCTL.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1163199936890
O17 - HKLM\System\CCS\Services\Tcpip\..\{B9984892-D86B-4F4F-BAC5-12054EAE3BEA}: NameServer = 205.188.146.145
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Back to Top
 

Tron
Trusted Member




Date Joined Oct 2006
Total Posts : 290
 
   Posted 11-21-2006 1:10 (GMT +2)    Quote: Some sort of Hijacker, plus ???Alert an admin about: Some sort of Hijacker, plus ???
Hi Susie1.
 
Please press Ctrl/Alt/Del at the same time to open Windows Task Manager.
Click the Process tab (located at the top of task window).
Highlight shicoxp.exe & caxchg.exe and click End Process (located at the bottom right of the task window).
Close Task Window.
 
 
Click Killbox.exe.
Select the option "Delete on reboot" and "unregister dll's before deleting".
Click the button: All Files (Important!)
Now it should flash green.
Now copy the next bold part:
 
C:\WINDOWS\shicoxp.exe
C:\WINDOWS\caxchg.exe
 
Open 'file' in the killboxmenu on top and choose "Paste from clipboard"
Then press the button that looks like a red circle with a white X in it.
Killbox will tell you that all listed files will be removed on next reboot and asks if you would like to Reboot now, click YES.
 
Boot into safe mode (you can do this by switching off your machine, and continually tap the F8 key at first blank screen).
 
Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these files (if present):
 
C:\WINDOWS\shicoxp.exe
C:\WINDOWS\caxchg.exe
 
Boot to normal windows.
 
Re-open HiJackThis and scan. Check the boxes next to all the entries listed below.
 
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://a.tribalfusion.com/p.media/GLNTJLPMHKLGILGMNWMCJHNROVRREYTQFGMQGQPOLIWIKJGINTELIBKKJSWRLOMQUCWKGCIGLOBDMIJ/518736/pop.html
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O4 - HKLM\..\Run: [shicoxp] C:\WINDOWS\shicoxp.exe
O4 - HKLM\..\Run: [caxchg] C:\WINDOWS\caxchg.exe
 
NOTE: O4 - HKLM\..\Run: [shicoxp] / O4 - HKLM\..\Run: [caxchg] may not exist after you run Killbox, this is normal.
 
Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.
 
Please download Ewido Anti-Spyware and save that file to your desktop.
This is a 30 day trial of the program
 
1. Once you have downloaded ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
2. Once the setup is complete you will need run ewido and update the definition files.
3. On the main screen select the icon " Update " then select the " Update now " link.
4. Next select the " Start update " button, the update will start and a progress bar will show the updates being installed.
5. Once the update has completed select the " Scanner " icon at the top of the screen, then select the " Settings " tab.
6. Once in the Settings screen click on " Recommended actions " and then select " Quarantine ".
7. Under " Reports "
8. Select " Automatically generate report after every scan "
9. UnSelect " Only if threats were found "
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
10. Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
 
IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess:
 
1. Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
2. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
 
Ewido will now begin the scanning process, be patient this may take a little time.
Once the scan is complete do the following:
 
* If you have any infections you will prompted, then select "Apply all actions"
* Next select the "Reports" icon at the top.
* Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
* Close ewido and reboot your system back into Normal Mode.
 
Post the result of the Ewido Scan, and a fresh HJT Logfile.
 
Kind Regards.
Tron.


NOTE: You may be asked to download various tools to aid with system repair.
          These tools are essential in the clean up of your machine,
          and can be removed after cleaning has transpired (Optional).

Back to Top
 

Susie1
New Member


Date Joined Nov 2006
Total Posts : 5
 
   Posted 11-22-2006 6:44 (GMT +2)    Quote: Some sort of Hijacker, plus ???Alert an admin about: Some sort of Hijacker, plus ???
In Killbox, the checkbox for unregistering the dll was grayed out and I couldn't figure out any way to activate it.

When I rebooted, I missed safe mode and did a regular boot -- so then I rebooted again to get to safe mode. Then I wasn't able to find or delete either:
C:\WINDOWS\shicoxp.exe
C:\WINDOWS\caxchg.exe

In Hijack this, this BHO wasn't there to check off:
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)

Updating Ewido, the first time it aborted for some reason. Then update took a quite some time, hopefully that's expected/normal? Once finished it did say update successful.

Ran Ewido, took just short of 1 1/2 hours, and it said I'm clean.... probably too good to be true!!!

So, here is Ewido report and new HJT log.... what ARE the shicoxp & caxchg bugs?

Thank you so very much, and while I'll be amazed if true, I hope you tell me I'm clean and don't have more to do, but REALLY appreciate the help!!!

================= Ewido =================================

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 5:20:09 PM 11/21/2006

+ Scan result:



Nothing found.


::Report end

================= HijackThisLog =============================

Logfile of HijackThis v1.99.1
Scan saved at 7:50:51 PM, on 11/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\COMMON~1\AOL\116339~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\PROGRA~1\COMMON~1\AOL\116339~1\EE\AOLServiceHost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Mightyfax\MFNTCTL.EXE
C:\Program Files\America Online 9.0a\waol.exe
C:\Program Files\America Online 9.0a\shellmon.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Virus n Spyware\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [RealTray] "C:\Program Files\Real\RealPlayer\RealPlay.exe" SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1163390790\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: MightyFAX Controller.lnk = C:\Program Files\Mightyfax\MFNTCTL.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1163199936890
O17 - HKLM\System\CCS\Services\Tcpip\..\{B9984892-D86B-4F4F-BAC5-12054EAE3BEA}: NameServer = 205.188.146.145
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

======================Spyware Doctor Scan ======================

For whatever it mgiht be worth, and I hope you folks don't mind that I've added this, after first posting to the forum but before getting a reply, I'd downloaded & tried the spyware doctor trial version too, and it'd said that I had one indication of a bad site, & 7 other infections, all that it showed as, I think, registry keys (can post log if it'll help at all!), all for virtumonde/kaspersky.... just ran it again and got:

Spyware Doctor Activity Report
Generated on 11/21/2006 5:27:01 PM Spyware Doctor Homepage PC Tools Homepage Technical Support


Scans (basic information only):

Scan Results:
scan start: 11/21/2006 7:00:01 PM
scan stop: 11/21/2006 7:10:44 PM
scanned items: 80744
found items: 7
found and ignored: 0
tools used: General Scanner, Process Scanner, LSP Scanner, Startup Scanner, Registry Scanner, Browser Scanner, Browser Activity Scanner, Disk Scanner, ActiveX Scanner



Infection Name Location Risk
Virtumonde HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3} Elevated
Virtumonde HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3}## Elevated
Virtumonde HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3}\iexplore Elevated
Virtumonde HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3}\iexplore## Elevated
Virtumonde HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3}\iexplore##Count Elevated
Virtumonde HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3}\iexplore##Time Elevated
Virtumonde HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3}\iexplore##Type Elevated

Scan Results:
scan start: 11/21/2006 7:53:26 PM
scan stop: 11/21/2006 8:20:54 PM
scanned items: 121330
found items: 8
found and ignored: 0
tools used: General Scanner, Process Scanner, LSP Scanner, Startup Scanner, Registry Scanner, Hosts Scanner, Browser Scanner, Browser Activity Scanner, Disk Scanner, ActiveX Scanner



Infection Name Location Risk
Known Bad Sites C:\Documents and Settings\Robin Siskel\Local Settings\Temporary Internet Files\Content.IE5\6SY3HCE9\10446799-1.jpg High
Virtumonde HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3} Elevated
Virtumonde HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3}## Elevated
Virtumonde HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3}\iexplore Elevated
Virtumonde HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3}\iexplore## Elevated
Virtumonde HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3}\iexplore##Count Elevated
Virtumonde HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3}\iexplore##Time Elevated
Virtumonde HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3}\iexplore##Type Elevated


Other Sections:
Back to Top
 

Susie1
New Member


Date Joined Nov 2006
Total Posts : 5
 
   Posted 11-22-2006 10:14 (GMT +2)    Quote: Some sort of Hijacker, plus ???Alert an admin about: Some sort of Hijacker, plus ???
Hi all,

VERY odd -- I just noticed, and am pretty certain this was NOT there before, that now if I click on the start button, where normally there would be ONE shortcut/link to mozilla firefox, there are now two, and two links/shortcuts to outlook email also (which I don't use and while I think its been in the list all along, I'm honestly not sure). Then, when I launched firefox, it launched TWO windows simultaneously. None of the other items under the start button are duplicated this way, just those two, which are in the top lefthand area of the start button window....

In the past, I have occassionally had the computer paste whatever I was pasting in twice, without space between the first and the duplicate copy. That made me wonder if something was logging my commands or keystrokes, but regardless, its just weird and I thought I should mention this.

I also just updated and ran adaware, and it didnt' find anything. I'll probably give spybot a try too.
Back to Top
 

Tron
Trusted Member




Date Joined Oct 2006
Total Posts : 290
 
   Posted 11-22-2006 12:49 (GMT +2)    Quote: Some sort of Hijacker, plus ???Alert an admin about: Some sort of Hijacker, plus ???
Hi Susie1.


Please click here and download Virtumonde cleaner to your desktop.


Click the FxVMonde icon, and click start. Let it delete whatever it finds.


Next, we need to disable and re-enable your system restore, this will clear ALL your system restore points.
We need to do this as Virus's/Spyware are mostly backed up by system restore,
making the likelyhood of them returning a definite possibility.
 
Disable System Restore
 
Click Start, right click My Computer, select Properties.
At the top of the System Restore window, click the System Restore Tab.
Tick the box Turn off System Restore, click Apply then Ok.
 
Re-enable System Restore
 
Click Start, right click My Computer, select Properties.
At the top of the System Restore window, click the System Restore Tab.
Untick the box Turn off System Restore, click Apply then Ok.
 
clear out all your temp files.
The easy way to do thit is by downloading CCleaner from here:-
 
Before running CCleaner you should configure it by clicking 'Options'/'Advanced'
and unticking the box 'Only delete files in Windows Temp folders older than 48 hours'.
 
Download ATF Cleaner by Atribune to your desktop.
http://www.atribune.org/ccount/click.php?id=1
 
Run ATF Cleaner
Under Main choose: Select All
Click the Empty Selected button.
 
If you use Firefox browser
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
 
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
 
If you use Opera browser
Click Opera at the top and choose: Select All
Click the Empty Selected button.
 
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
 
Click Exit on the Main menu to close the program.
 
The HijackThis logfile appears to be clean, so there's nothing to do there.
shicoxp.exe & caxchg.exe are Trojan/Backdoor, but they also appear to have been cleaned, this is excellent.
Now, to the duplicate icons. I have not come accross duplicate icons in the Start Menu before.
I have come accross them on the desktop, and there's a simple fix for this, but the fix does not apply to the Start Menu.
This seems like a silly question, but have you right clicked the unwanted icons, and remove from list?
I shall do more research into this and will get back to you with a fix shortly.
 
In the meantime, the following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.
  1. Spybot Search & Destroy - Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.
  2. AdAware - Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.
  3. SpywareBlaster - Great prevention tool to keep nasties from installing on your system.
  4. SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place.
  5. IE-SpyAd - puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
  6. CleanUP! - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  7. Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  8. Google Toolbar - Free google toolbar that allows you to use the powerful Google search engine from the bar, but also blocks pop up windows.
  9. Trillian or Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
Kind Regards.
Tron.


NOTE: You may be asked to download various tools to aid with system repair.
          These tools are essential in the clean up of your machine,
          and can be removed after cleaning has transpired (Optional).

Back to Top
 

Susie1
New Member


Date Joined Nov 2006
Total Posts : 5
 
   Posted 11-22-2006 10:00 (GMT +2)    Quote: Some sort of Hijacker, plus ???Alert an admin about: Some sort of Hijacker, plus ???
I think I may have stubled onto something -- when I first ran spyware doc & it found virtumonde, I'd clicked thru to every bit of info they had on it.  Their online page noted that its called other things by other anti-spyware organizations -- then in searching symantec for a removal tool,  I'd found they seemed to have several that might be the right one, including the one you just recommended.  So I'd downloaded two of them, and ran the adware-virtumondo one you suggested last night.  It didn't find anything.  Today, I was about to run the other, and now driving myself buggy trying to figure out just which one it was and where/how I'd gotten to the symantec page that listed several possibilities -- they tag kaspersky into the name.  Anyhow, before running it, in searching around, I ran across yet another possible, and this one mentioned that it corrupts the hosts files, thus keeping you from being able to find it using spybot s&d, ad-aware, symantec's online tool, etc -- and I've sure encountered that!!! 
 
So, I did a "start" search on host to see where & what all came up that way on my drive.  That returned a TON of files -- is that typical?  Only a few were the info files I'd copied that just tell me about hosts files.  So, I wasn't sure how to or if I can somehow copy a search page directory to you here?  But I tried a "select all" and "copy" (sorry if that's really stupid!!!) and when I pasted into a new email -- it was huge -- AND includes some entries like:
 
127.0.0.1  casalemedia.com #[McAfee.Cookie-Casalemedia]
127.0.0.1  as.casalemedia.com #[Ewido.TrackingCookie.Casalemedia]
127.0.0.1  b.casalemedia.com #[McAfee.Adware-SrchExplorer]
127.0.0.1  c.casalemedia.com #[Ad-Aware.Tracking Cookie]
127.0.0.1  i.casalemedia.com #[Tenebril.Tracking Cookie]
127.0.0.1  img.casalemedia.com #[SunBelt.casalemedia.com]
127.0.0.1  lb01.casalemedia.com #[SpySweeper.Spy.Cookie]
127.0.0.1  r.casalemedia.com #[Symantec.SpywareStormer]
127.0.0.1  www.casalemedia.com
127.0.0.1  www.errorguard.com #[PcTools.ErrorGuard][McAfee.ErrorGuard]
127.0.0.1  spywarestormer.com #[Rogue/Suspect]
127.0.0.1  www.spywarestormer.com #[Symantec.SpywareStormer][Adware-SpyStormer]
 
Now, I totally realize that I may be completely misunderstanding this -- maybe its real hosts entries that just block tracking cookies & adware from otherwise legitimate sites?  I haven't picked these out from the page, just did a find in top window for symantec and then copied and pasted some adjacent entries all in a block.....
 
Anyhow, I'm wondering if my host file has been taken over, and if this may be what symantec calls trojan.spamthru?
 
 
Anyhow, I'll save that odd long file I got when I tried to copy off the directory, so I can post or attach it later if that would be of any help -- maybe when I did the copy & paste it actually pasted all the files appended to each other or something???  Let me know if that file or some way of copying the directory listing for a search on host would be of any use.
 
If I don't hear back from you in a little while telling me to do something different or in a different order, I'll probably try running both this one, the trojan.spamthru tool, and the other I'd found, FixVundo. 
 
Here's the fixVMonde log:
 
Symantec Adware.VirtuMonde Removal Tool 1.0.3
Adware.VirtuMonde has not been found on your computer.

and I guess then move on to ccleaner, etc?  Unless I hear otherwise from you first. 
 
Thanks again!!!
 
I can't help but wonder how the heck the blasted thing(s) got on my computer to begin with, blast it. :-(
 
Back to Top
 

Tron
Trusted Member




Date Joined Oct 2006
Total Posts : 290
 
   Posted 11-23-2006 3:32 (GMT +2)    Quote: Some sort of Hijacker, plus ???Alert an admin about: Some sort of Hijacker, plus ???
Hi Susie1.
 
I did some research into this, and the problems you were having downloading Active X controls, Housecall not working correctly, and given the previous infections you had, this also led me to the possibility of host file corruption. When the Host Files get corrupted, it can block access to legitimate sites by redirecting any connection attempts back to the local machine. All these tie in with the problems you were/are experiencing. The infections that we relinquished from your machine were Spyware/Trojan, some had the capability to caused the problems experienced, but once removed the problems usually resolve. Host File corruption seems like a valid probable cause. Having many Host Files is typical, but when you say many, does this run into 100s 1000s?? I think that  running the trojan.spamthru tool would be an excellent option, you can also run FixVundo, but the Vundo Trojan was not present in your logfile. To be absolutely certain this is not Host File corruption, please Download the Hoster:
 
 
 
This will restore all your original Microsoft Hosts files.
Download and extract to desktop, double click Hoster folder, click Hoster icon.
Press "Restore Original Hosts" and press "OK"
 
NOTE: I suggest running the Trojan.spamthru tool first, then restore original files using the Hoster, as the files may show signs of corruption even if the Trojan was illiminated.
 
There are so many ways you could have got infected. It may have been something you downloaded-installed, something picked up inadvertently from a website visited, there are so many ways for an exploiter to hijack a system or to infect one. The only disapointment is Firewalls and such like software cannot block them all, some do get through, this is why these Forums exist.
Please let me know if the hoster does it's job, and your browser issues improve.
 
Kind Regards.
Tron.
 
Oh yes, 10/10 for doing your research into this smile
It's very refreshing to see that you searched the net looking for probable causes to fix your problems,
I think that's excellent work.
80% of all Pc problems can be solved through Google search.
 
hmmm You after my job? ;-)


NOTE: You may be asked to download various tools to aid with system repair.
          These tools are essential in the clean up of your machine,
          and can be removed after cleaning has transpired (Optional).

Back to Top
 

Susie1
New Member


Date Joined Nov 2006
Total Posts : 5
 
   Posted 11-23-2006 9:50 (GMT +2)    Quote: Some sort of Hijacker, plus ???Alert an admin about: Some sort of Hijacker, plus ???
Hi Tron,

Well, I sorta goofed -- that trojan.spamthru from symantec isn't a tool, its instructions for manual removal and is to be done to EVERY host file you find on a search.... Yikes!!! And no, its not 100's or 1000's, but is full screen plus maybe 1/4 to 1/3rd more of 15 inch maximized window at high resolution (small text etc) -- some of those not applicable, liked ones that are "gHOST" files, tho I'm not sure if any of the ones like svchost are of issue or not.... plus, embarrassing, but one of the information type files I'd copied was to Kim Komando's recommended Hosts files/file thingy, and in reading it, it appears that it doesn't use the typical file names:

"Now includes most major parasites, hijackers and unwanted Search Engines!
Proudly now the #1 rated HOSTS file on the Internet! - Google | MSN | Yahoo | AltaVista
Now featured on the Kim Komando Radio Show
The MVPS HOSTS file has been selected by Pricelessware as "the best of the best in Freeware"

and...

"This download includes a simple batch file (mvps.bat) that will rename the existing HOSTS file (HOSTS.MVP) then copy the included HOSTS file to the proper location. For more information please see the readme.txt included in the download." (read me link: http://www.mvps.org/winhelp2002/readme.txt)

but I'm not even certain if that's what I did or didn't do!!! Plus, the info mentions that hosts files like this can sometimes cause timeout errors on XP machines -- I wonder if that might be some of my problem?

Plus, I have to wonder if the "hoster" program will work on these if its what I did? Shoot, for that matter, can I just delete them all and start over??

So, it all rather complicates things a bit, unfortunately.

as to your ps -- THANK YOU and heck NO, I'm not tryin' to snitch your job, tho if you got any extra, I can always use a bit extra from a bit of moonlighting!! <VBG> Ah well, anyhow, yes, I am trying to help and get it figured out as best I can. :0)

My best to you and yours!!

(and may you enjoy some really good Turkey tomorrow, no matter what nationality or nation you may happen to be or believe in -- its a good excuse for a really good meal and some great company no matter what!! <VBG>)
Back to Top
 
New Topic Post reply to : Some sort of Hijacker, plus ??? Printable version of : Some sort of Hijacker, plus ???
 
Forum Information
Currently it is Monday, May 21, 2012 10:37 PM (GMT +2)
There are a total of 82.921 posts in 18.688 threads.
In the last 3 days there were 2 new threads and 3 reply posts. View Active Threads
Who's Online
This forum has 33970 registered members. Please welcome our newest member, JohnKWagner.
34 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
BullGuard Support Hijacked :) (0)21-05-2012 19:36:34 (Andreea-Luciana Ostache)
Empty tmp folders (14)21-05-2012 19:31:13 (Andreea-Luciana Ostache)
Bogus BullGuard Websites (0)21-05-2012 14:37:08 (Robert Mateescu)
Multiple Virus Issues (7)19-05-2012 15:44:59 (Touch)