Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Trojan -
   
BullGuard Antivirus Forum > General Security > Spyware > Trojan -  
Forum Quick Jump
 
New Topic Locked Topic Printable version of : Trojan -
[ << Previous Thread | Next Thread >> ]

Josheh
New Member


Date Joined Nov 2007
Total Posts : 14
 
   Posted 11-25-2007 10:48 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
Hey guys, went away for the week with my cousins and other family members used my Desktop while i was away, No idea what they did or what happened but i come back with a barely working computer.

I've tried to get as much info as possible on what it / they are. One that comes up is a fake MS looking thing called System Defender, Theres another one that comes up with a balloon or something saying your system is only running 40% of what it should be,

Theres also a trojanspm/lx, and another balloon thing pops up saying Security Alert and a System performance monitor warning with the % of how slow the comps running Theres just so many things right now that are having problems with this, i have absalutely no idea how somebody could allow my comp to get so bad without knowing. Could you please help me?

Here is my Hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:11:10 PM, on 25/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\regsvr32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SecCenter\scprot4.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\VideoMate\ComproRemote.exe
C:\Program Files\Common Files\VideoMate\ComproSchedulerDTV.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\Josh\Desktop\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://au.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://au.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://au.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://au.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\skmnxahn.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [CM108Sound] RunDll32 CM108.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [hglwpwrw] rundll32.exe "C:\Program Files\hglwpwrw\lehkjwbe.dll",Init
O4 - HKLM\..\Run: [obsdmrgl] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\obsdmrgl.dll"
O4 - HKLM\..\Run: [SC2] C:\Program Files\SecCenter\scprot4.exe
O4 - HKLM\..\Run: [509619c8] rundll32.exe "C:\WINDOWS\system32\lvlikbft.dll",b
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: ComproRemote.lnk = ?
O4 - Global Startup: ComproSchedulerDTV.lnk = ?
O4 - Global Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Joshuas Folder\Junk\Stuff\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 7785 bytes
Back to Top
 

Josheh
New Member


Date Joined Nov 2007
Total Posts : 14
 
   Posted 11-25-2007 10:53 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
Oh sorry forgot to add, I'm pretty sure i saw a cyberlog-x trojan / virus in one of the popups too, and a malware threats and stuff. and a networm-i.virus@fp... they just keep coming !!!!

Post Edited (Josheh) : 25-11-2007 09:55:05 GMT

Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 11-25-2007 11:18 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
Hi Josheh 


This is probably what they have done -
 
How to get Infected without trying

A little bit of humour but also based on fact. ;-)
Look for cracks, subdivided in illegal software and .....
Look for spyware removers, concentrate on the kind that makes you pay before it removes anything
--------------------------------------------
 
Therefore -
Click here - ->>  Before posting a log 
 
 
 After You have run the scan tools -
 
Reboot normally
 
Post Hijackthis log along with AVG Anti-Spyware log, C: Rootlog TXT, C: combofix txt in this topic
 
 
 
 


 


Do NOT post your problem in someone elses thread.

Back to Top
 

Josheh
New Member


Date Joined Nov 2007
Total Posts : 14
 
   Posted 11-25-2007 11:29 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
Do i really need to download AVG? I have never got along with that mate.

Or do you need it to see what needs to be fixed? I'm barely able to even write messages let alone download tons of stuff mate.

I wonder if i find what ever they downloaded / did it will remove it, or if its spread to my other files.

While looking on the net about these trojans they say AVG doesn't pick it up?

I'm downloading it now anyway mate, will get back to you ASAP

EDIT: The site url for AVG AntiSpyware doesn't work mate

Alright i have everuthing now and scanning while i get bllions of pop ups and messages "Even in safe mode / disconnected from the net'

Post Edited (Josheh) : 25-11-2007 10:44:45 GMT

Back to Top
 

Josheh
New Member


Date Joined Nov 2007
Total Posts : 14
 
   Posted 11-25-2007 11:50 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
So far only got root log done:

********************************* ROOTCHK-(21-09-07)-LOG, by ejvindh
Sun 25/11/2007 21:17:59.42

The rootkits that are detected by this tool were not found.

********************************* ROOTCHK-LOG-end


catchme 0.3.1160 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-25 21:18:01
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...

scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40]
"khjeh"=hex:20,02,00,00,b3,b8,7f,fc,df,f1,32,02,df,e9,7f,04,90,3e,d6,ee,5b,..
"hj34z0"=hex:64,b6,3e,b8,70,b4,69,70,be,73,c1,9a,cf,fc,71,05,0d,5c,bb,51,b9,..
"hj34z1"=hex:a1,b6,3e,b8,08,b4,69,70,bf,73,c0,9a,ce,fc,71,05,0d,5c,bb,51,04,..
"hj34z2"=hex:a1,b6,3e,b8,08,b4,69,70,bf,73,c0,9a,ce,fc,71,05,0d,5c,bb,51,04,..
"hj34z3"=hex:a1,b6,3e,b8,08,b4,69,70,bf,73,c0,9a,ce,fc,71,05,0d,5c,bb,51,04,..
"hj34z4"=hex:a1,b6,3e,b8,08,b4,69,70,bf,73,c0,9a,ce,fc,71,05,0d,5c,bb,51,04,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf41]
"khjeh"=hex:20,02,00,00,b3,b8,7f,fc,07,81,69,02,df,e9,7f,04,40,3f,d6,ee,5b,..
"hj34z0"=hex:54,b6,3e,b8,70,b4,69,70,be,73,c1,9a,cf,fc,71,05,0d,5c,bb,51,27,..
"hj34z1"=hex:a1,b6,3e,b8,08,b4,69,70,bf,73,c0,9a,ce,fc,71,05,0d,5c,bb,51,04,..
"hj34z2"=hex:a1,b6,3e,b8,08,b4,69,70,bf,73,c0,9a,ce,fc,71,05,0d,5c,bb,51,04,..
"hj34z3"=hex:a1,b6,3e,b8,08,b4,69,70,bf,73,c0,9a,ce,fc,71,05,0d,5c,bb,51,04,..
"hj34z4"=hex:a1,b6,3e,b8,08,b4,69,70,bf,73,c0,9a,ce,fc,71,05,0d,5c,bb,51,04,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf42]
"khjeh"=hex:20,02,00,00,b3,b8,7f,fc,b9,76,5b,ee,df,e9,7f,04,9d,3e,d6,ee,5b,..
"hj34z0"=hex:61,b6,3e,b8,70,b4,69,70,be,73,c1,9a,cf,fc,71,05,0d,5c,bb,51,c9,..
"hj34z1"=hex:a1,b6,3e,b8,08,b4,69,70,bf,73,c0,9a,ce,fc,71,05,0d,5c,bb,51,04,..
"hj34z2"=hex:a1,b6,3e,b8,08,b4,69,70,bf,73,c0,9a,ce,fc,71,05,0d,5c,bb,51,04,..
"hj34z3"=hex:a1,b6,3e,b8,08,b4,69,70,bf,73,c0,9a,ce,fc,71,05,0d,5c,bb,51,04,..
"hj34z4"=hex:a1,b6,3e,b8,08,b4,69,70,bf,73,c0,9a,ce,fc,71,05,0d,5c,bb,51,04,..

scanning hidden registry entries ...

scanning hidden files ...

hidden processes: 0
hidden services: 0
hidden files: 0
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 11-25-2007 12:45 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
Post combofix log along with new hijackthis log


Do NOT post your problem in someone elses thread.

Back to Top
 

Josheh
New Member


Date Joined Nov 2007
Total Posts : 14
 
   Posted 11-26-2007 6:55 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
Sorry had comp problems last night, and combofix locked up this morning when t was turning on so i have to redo that, and the virus hasn't changed 1 bit so far, I'll post up when i've got it done mate.

At the moment I'm doing an AVG Scan, and then I'll do that other one and post up the logs of the new Hijack this log.

Should i be doing all of this with the ethernet cable unplugged?

Post Edited (Josheh) : 26-11-2007 06:16:38 GMT

Back to Top
 

Josheh
New Member


Date Joined Nov 2007
Total Posts : 14
 
   Posted 11-26-2007 9:09 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
I couldn't get you the Combofix log mate, for some reason that just doesn't work like it should on my comp, i haven't had any hickups after the AVG Scan / Reboot though and the comp seems faster already, Although the clock is missing and for some reason it auto set my default browser back to IE and it also asked if i want to unblock internet access to MSN? Did this do a system restore of some sort? the "Combfix"?

Anyway, here is the Hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 06:37, on 2007-11-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Common Files\VideoMate\ComproRemote.exe
C:\Program Files\Common Files\VideoMate\ComproSchedulerDTV.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\Documents and Settings\Josh\Desktop\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://au.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://au.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://au.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://au.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {158A95B4-1F79-3B06-78BF-0424CDB17C2E} - C:\Program Files\Zksvcaym\rzetjkmi.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\skmnxahn.dll
O2 - BHO: {a2f3b3ac-4cb7-645a-fe04-ae0bd78e017c} - {c710e87d-b0ea-40ef-a546-7bc4ca3b3f2a} - C:\WINDOWS\system32\tfthjboq.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\skmnxahn.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [CM108Sound] RunDll32 CM108.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [509619c8] rundll32.exe "C:\WINDOWS\system32\naathtad.dll",b
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: ComproRemote.lnk = ?
O4 - Global Startup: ComproSchedulerDTV.lnk = ?
O4 - Global Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Joshuas Folder\Junk\Stuff\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: skmnxahn - C:\WINDOWS\SYSTEM32\skmnxahn.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 8674 bytes
Back to Top
 

Josheh
New Member


Date Joined Nov 2007
Total Posts : 14
 
   Posted 11-26-2007 9:57 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
ok 15 mins of being online and it's all back again the comp wa running fine for around 15 mins, I'm working out the back while it does it all and just come back to see the same thing is back.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 11-26-2007 10:11 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
There are still some infections in hijackthis log We have to fix -
 
 
Please download Free  Version of Superantispyware
 
Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it.
close the program
 
 
 
Download and install DrWebCureit:
 
to your desktop.
 
 
 
Run Hijackthis and place a check beside each of the following. Close all other browser windows except HJT.
Click fix checked.
O2 - BHO: (no name) - {158A95B4-1F79-3B06-78BF-0424CDB17C2E} - C:\Program Files\Zksvcaym\rzetjkmi.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\skmnxahn.dll
O2 - BHO: {a2f3b3ac-4cb7-645a-fe04-ae0bd78e017c} - {c710e87d-b0ea-40ef-a546-7bc4ca3b3f2a} - C:\WINDOWS\system32\tfthjboq.dll
O4 - HKLM\..\Run: [509619c8] rundll32.exe "C:\WINDOWS\system32\naathtad.dll",b
O20 - Winlogon Notify: skmnxahn - C:\WINDOWS\SYSTEM32\skmnxahn.dll
 
 
Please print out or copy this page to Notepad as you will be in Safe Mode and unable to refer to this page.
 
 
 
 
 
Delete the following files or folders (delete item in bold). Please do not be concerned if
any of the items are not found as they may have been automatically removed by actions I had
you take earlier in the cleaning process.
 
 
Open Folder Options in Controlpanel >view and check your settings:
Select
Show hidden files and folders
Display the contents of system folders
Uncheck: Hide protected operating system files
Delete:
Files:
C:\WINDOWS\system32\skmnxahn.dll
C:\WINDOWS\system32\naathtad.dll
 
 
Folders:
C:\Program Files\Zksvcaym
 
 
 
 
 
 
 
Doubleclick the "drweb-cureit.exe" and click "Start" in the prompt window that will open , asking "start the express scan now".
It will first make a quick scan of your system, let it clean what it find, and when it says "done"
Click on the Options->Change settings.
 
Actions Tab- Adware-Dialers-Riskware-Hacktools, use dropdown menu and select –Rename
Click – Apply - OK
Click on Scan Tab.  Move  dot from Express scan to Complete Scan.  Click on The Green arrow to the right.  It will now scan your  drive(s), say yes to all
 
After the scan, in the Dr.Web CureIt menu on top, click file and choose save report list
Save the report to your desktop. The report will be called DrWeb.csv
Close Dr.Web Cureit.
 
Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
 
 
 
 
 
Start Superantispyware.
Hit - Scan Your Computer - button
Click on the drive(s) you want to scan. Put a check in - Perform Complete Scan, then next,
it will scan now. When scan have finished, put a checkmark with  all items it found. Next, after cleaning, allow it to Reboot
 
 
 
Start Superantispyware again –
Click Preferences and then click the statistics/logs tab.
Click the dated log and press view log and a text file will appear.
 
 
 
Post this log along with fresh hijackthis log, Dr.Web log and tell how things are running  ?
 
 
 
 
 
 
 
 
 
 
 


Do NOT post your problem in someone elses thread.

Back to Top
 

Josheh
New Member


Date Joined Nov 2007
Total Posts : 14
 
   Posted 11-26-2007 12:49 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
Thanks mate, I have been VERY busy out the back, "Heh 70 IE windows"

Anyway i will do this right now and report back ASAP, it's pretty late here and i will probably leave this go and get back to you in the morning.

The URL for the doctor web said it was majorly outdated, I'll manually go to their site and try download it then.

Oh also, you say reboot your computer so it can finish removing the virus and then run the spyware program? I presume you mean in normal mode now not safe mode? I'll probably be done before you reply though so i hope i get it right by doing it in normal mode.

downloading drweb at only 10kbps i have to wait for that

Post Edited (Josheh) : 26-11-2007 11:57:55 GMT

Back to Top
 

Josheh
New Member


Date Joined Nov 2007
Total Posts : 14
 
   Posted 11-26-2007 1:38 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
Mkay, problems problems and more problems now.

Did what you said, got up to removing C:\WINDOWS\system32\skmnxahn.dll and it said access denied "Even in safe mode

Then i get to the Doubleclick the "drweb-cureit.exe" and click "Start" the new one i downloaded demanded i buy it, so i open the one i got from you and the "Code" is inactive so i cannot do that.

Now i turn the comp back on to say this and it looks like nothings changed if anything its quicker than before.

What Can we do now? Oh also, this virus it looks like doesn't come up with popups, but the balloons down the bottom still show up saying i could be infected. Even in !!!! Safe mode!

Best regards, Josh

Post Edited (Josheh) : 26-11-2007 12:44:30 GMT

Back to Top
 

Josheh
New Member


Date Joined Nov 2007
Total Posts : 14
 
   Posted 11-28-2007 12:30 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
jeez what happened to the site yesterday??? I couldn't come on at all and get any help! hah

Anyway, the latest problems are 1 post above this one Touch and this is starting to really nick me off.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 11-28-2007 12:40 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
When Yo click - "Start" the new one i downloaded demanded i buy it" - It don´t demand You to buy it.  Just close the - buy- popup


Do NOT post your problem in someone elses thread.

Back to Top
 

Josheh
New Member


Date Joined Nov 2007
Total Posts : 14
 
   Posted 11-29-2007 12:35 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
huh? The program won't do anything because the license on the program is broken now, So what else am i suppose to do apart from use that program? because it's not working
Back to Top
 

Josheh
New Member


Date Joined Nov 2007
Total Posts : 14
 
   Posted 11-29-2007 12:36 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
huh? The program won't do anything because the license on the program is broken now, So what else am i suppose to do apart from use that program? because it's not working

I decided to use the "Demo" in the new one i downloaded mate, I hope it still works.
Back to Top
 

Josheh
New Member


Date Joined Nov 2007
Total Posts : 14
 
   Posted 11-29-2007 3:54 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
Okay done it all, Here is

DR WEB LOG:

backup-20071126-104453-287.dll;C:\Documents and Settings\Josh\Desktop\backups;Trojan.Fakealert.372;;
Starmaker trainer SE.exe.exe;C:\Program Files\Lionhead Studios Ltd\The Movies;Tool.GameCrack;Renamed.;
Process.exe;C:\SDFix\apps;Tool.Prockill;Renamed.;
A0005118.dll;C:\System Volume Information\_restore{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP6;Trojan.Virtumod.232;;
A0005231.dll;C:\System Volume Information\_restore{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP6;Trojan.Fakealert.372;;
A0005237.exe;C:\System Volume Information\_restore{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP6;Tool.GameCrack;Renamed.;
A0005238.exe;C:\System Volume Information\_restore{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP6;Tool.Prockill;Renamed.;
armxsumg.dll;C:\WINDOWS\system32;Trojan.Juan.25;;
drvgiz.dll;C:\WINDOWS\system32;Trojan.Fakealert.341;;
ljjiige.dll;C:\WINDOWS\system32;Trojan.Virtumod.211;;
ohanhhrh.exe;C:\WINDOWS\system32;Trojan.EzulaAd;;
tuvvtus.dll;C:\WINDOWS\system32;Trojan.Virtumod.211;;
wtcdeyun.dll;C:\WINDOWS\system32;Trojan.Fakealert.372;;
Movies.exe;E:\Setup\Data;Win95.SK;;




SUPER ANTI SPYWARE WHAT EVER:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/29/2007 at 01:18 PM

Application Version : 3.9.1008

Core Rules Database Version : 3350
Trace Rules Database Version: 1349

Scan type : Complete Scan
Total Scan Time : 00:35:34

Memory items scanned : 479
Memory threats detected : 0
Registry items scanned : 5882
Registry threats detected : 16
File items scanned : 46886
File threats detected : 35

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}

Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}

Trojan.WinFixer
HKLM\Software\Classes\CLSID\{AB1FC0D4-D8FB-4609-AD15-8C6B6E7DD64C}
HKCR\CLSID\{AB1FC0D4-D8FB-4609-AD15-8C6B6E7DD64C}
HKCR\CLSID\{AB1FC0D4-D8FB-4609-AD15-8C6B6E7DD64C}\InprocServer32
HKCR\CLSID\{AB1FC0D4-D8FB-4609-AD15-8C6B6E7DD64C}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\JKKJI.DLL
HKLM\Software\Classes\CLSID\{AD86A0DC-6E69-4104-AECF-FEC9B030B0BC}
HKCR\CLSID\{AD86A0DC-6E69-4104-AECF-FEC9B030B0BC}
HKCR\CLSID\{AD86A0DC-6E69-4104-AECF-FEC9B030B0BC}\InprocServer32
HKCR\CLSID\{AD86A0DC-6E69-4104-AECF-FEC9B030B0BC}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\JKKLI.DLL
HKLM\Software\Classes\CLSID\{F90CC3C1-5F11-48CC-9502-B307A63EE79B}
HKCR\CLSID\{F90CC3C1-5F11-48CC-9502-B307A63EE79B}
HKCR\CLSID\{F90CC3C1-5F11-48CC-9502-B307A63EE79B}\InprocServer32
HKCR\CLSID\{F90CC3C1-5F11-48CC-9502-B307A63EE79B}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\DDCCB.DLL

Adware.Tracking Cookie
C:\Documents and Settings\Josh\Cookies\josh@serving-sys.txt
C:\Documents and Settings\Josh\Cookies\josh@doubleclick.txt
C:\Documents and Settings\Josh\Cookies\josh@atdmt.txt
C:\Documents and Settings\Josh\Cookies\josh@adopt.euroclick.txt
C:\Documents and Settings\Josh\Cookies\josh@overture.txt
C:\Documents and Settings\Josh\Cookies\josh@mediaplex.txt
C:\Documents and Settings\Josh\Cookies\josh@cgi-bin.txt
C:\Documents and Settings\Josh\Cookies\josh@bs.serving-sys.txt
C:\Documents and Settings\Josh\Cookies\josh@msnportal.112.2o7.txt
C:\Documents and Settings\Josh\Cookies\josh@247realmedia.txt

Adware.Vundo-Variant
C:\DOCUMENTS AND SETTINGS\JOSH\DESKTOP\BACKUPS\BACKUP-20071126-104453-287.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP6\A0005231.DLL
C:\WINDOWS\SYSTEM32\WTCDEYUN.DLL

Trojan.Downloader-Gen/MobRules
C:\DOCUMENTS AND SETTINGS\JOSH\DESKTOP\BACKUPS\BACKUP-20071126-104453-591.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP2\A0000012.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP6\A0005120.DLL

Adware.Vundo-Variant/Small-A
C:\DOCUMENTS AND SETTINGS\JOSH\DESKTOP\BACKUPS\BACKUP-20071126-104453-620.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP6\A0005118.DLL
C:\WINDOWS\SYSTEM32\ARMXSUMG.DLL
C:\WINDOWS\SYSTEM32\TFTHJBOQ.DLL

Trojan.Downloader-Gen/JLove
C:\PROGRAM FILES\HGLWPWRW\LEHKJWBE.DLL

Trojan.Downloader-Gen/BigTkt
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\DRVGIZR.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP2\A0000016.DLL

Malware.Ultimate Defender
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\TNRTMWUK\TNRTMWUK1.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\TNRTMWUK\TNRTMWUK2.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\TNRTMWUK\TNRTMWUK3.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP2\A0000013.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP2\A0000014.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP2\A0000015.EXE

Adware.Vundo-Variant/Small
C:\WINDOWS\SYSTEM32\LJJIIGE.DLL
C:\WINDOWS\SYSTEM32\TUVVTUS.DLL

Trojan.Downloader-Gen/DDC
C:\WINDOWS\SYSTEM32\OHANHHRH.EXE





HIJACK THIS LOG





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:23, on 2007-11-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\DrWeb\spiderui.exe
C:\Program Files\DrWeb\DRWEBSCD.EXE
C:\Program Files\DrWeb\spiderml.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\PROGRA~1\DrWeb\spidernt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\VideoMate\ComproRemote.exe
C:\Program Files\Common Files\VideoMate\ComproSchedulerDTV.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Josh\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://au.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://au.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://au.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://au.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [CM108Sound] RunDll32 CM108.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpIDerNT] C:\PROGRA~1\DrWeb\spiderui.exe /agent
O4 - HKLM\..\Run: [DrWebScheduler] "C:\Program Files\DrWeb\DRWEBSCD.EXE"
O4 - HKLM\..\Run: [SpIDerMail] "C:\Program Files\DrWeb\spiderml.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: ComproRemote.lnk = ?
O4 - Global Startup: ComproSchedulerDTV.lnk = ?
O4 - Global Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Joshuas Folder\Junk\Stuff\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SpIDer Guard for Windows (SPIDERNT) - Doctor Web, Ltd. - C:\PROGRA~1\DrWeb\spidernt.exe

--
End of file - 8882 bytes





Seems to be running better now, but this did happen before for like an hour then it came back. what do you think?
Back to Top
 

Josheh
New Member


Date Joined Nov 2007
Total Posts : 14
 
   Posted 11-29-2007 3:55 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
Okay done it all, Here is

DR WEB LOG:

backup-20071126-104453-287.dll;C:\Documents and Settings\Josh\Desktop\backups;Trojan.Fakealert.372;;
Starmaker trainer SE.exe.exe;C:\Program Files\Lionhead Studios Ltd\The Movies;Tool.GameCrack;Renamed.;
Process.exe;C:\SDFix\apps;Tool.Prockill;Renamed.;
A0005118.dll;C:\System Volume Information\_restore{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP6;Trojan.Virtumod.232;;
A0005231.dll;C:\System Volume Information\_restore{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP6;Trojan.Fakealert.372;;
A0005237.exe;C:\System Volume Information\_restore{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP6;Tool.GameCrack;Renamed.;
A0005238.exe;C:\System Volume Information\_restore{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP6;Tool.Prockill;Renamed.;
armxsumg.dll;C:\WINDOWS\system32;Trojan.Juan.25;;
drvgiz.dll;C:\WINDOWS\system32;Trojan.Fakealert.341;;
ljjiige.dll;C:\WINDOWS\system32;Trojan.Virtumod.211;;
ohanhhrh.exe;C:\WINDOWS\system32;Trojan.EzulaAd;;
tuvvtus.dll;C:\WINDOWS\system32;Trojan.Virtumod.211;;
wtcdeyun.dll;C:\WINDOWS\system32;Trojan.Fakealert.372;;
Movies.exe;E:\Setup\Data;Win95.SK;;




SUPER ANTI SPYWARE WHAT EVER:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/29/2007 at 01:18 PM

Application Version : 3.9.1008

Core Rules Database Version : 3350
Trace Rules Database Version: 1349

Scan type : Complete Scan
Total Scan Time : 00:35:34

Memory items scanned : 479
Memory threats detected : 0
Registry items scanned : 5882
Registry threats detected : 16
File items scanned : 46886
File threats detected : 35

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}

Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}

Trojan.WinFixer
HKLM\Software\Classes\CLSID\{AB1FC0D4-D8FB-4609-AD15-8C6B6E7DD64C}
HKCR\CLSID\{AB1FC0D4-D8FB-4609-AD15-8C6B6E7DD64C}
HKCR\CLSID\{AB1FC0D4-D8FB-4609-AD15-8C6B6E7DD64C}\InprocServer32
HKCR\CLSID\{AB1FC0D4-D8FB-4609-AD15-8C6B6E7DD64C}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\JKKJI.DLL
HKLM\Software\Classes\CLSID\{AD86A0DC-6E69-4104-AECF-FEC9B030B0BC}
HKCR\CLSID\{AD86A0DC-6E69-4104-AECF-FEC9B030B0BC}
HKCR\CLSID\{AD86A0DC-6E69-4104-AECF-FEC9B030B0BC}\InprocServer32
HKCR\CLSID\{AD86A0DC-6E69-4104-AECF-FEC9B030B0BC}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\JKKLI.DLL
HKLM\Software\Classes\CLSID\{F90CC3C1-5F11-48CC-9502-B307A63EE79B}
HKCR\CLSID\{F90CC3C1-5F11-48CC-9502-B307A63EE79B}
HKCR\CLSID\{F90CC3C1-5F11-48CC-9502-B307A63EE79B}\InprocServer32
HKCR\CLSID\{F90CC3C1-5F11-48CC-9502-B307A63EE79B}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\DDCCB.DLL

Adware.Tracking Cookie
C:\Documents and Settings\Josh\Cookies\josh@serving-sys.txt
C:\Documents and Settings\Josh\Cookies\josh@doubleclick.txt
C:\Documents and Settings\Josh\Cookies\josh@atdmt.txt
C:\Documents and Settings\Josh\Cookies\josh@adopt.euroclick.txt
C:\Documents and Settings\Josh\Cookies\josh@overture.txt
C:\Documents and Settings\Josh\Cookies\josh@mediaplex.txt
C:\Documents and Settings\Josh\Cookies\josh@cgi-bin.txt
C:\Documents and Settings\Josh\Cookies\josh@bs.serving-sys.txt
C:\Documents and Settings\Josh\Cookies\josh@msnportal.112.2o7.txt
C:\Documents and Settings\Josh\Cookies\josh@247realmedia.txt

Adware.Vundo-Variant
C:\DOCUMENTS AND SETTINGS\JOSH\DESKTOP\BACKUPS\BACKUP-20071126-104453-287.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP6\A0005231.DLL
C:\WINDOWS\SYSTEM32\WTCDEYUN.DLL

Trojan.Downloader-Gen/MobRules
C:\DOCUMENTS AND SETTINGS\JOSH\DESKTOP\BACKUPS\BACKUP-20071126-104453-591.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP2\A0000012.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP6\A0005120.DLL

Adware.Vundo-Variant/Small-A
C:\DOCUMENTS AND SETTINGS\JOSH\DESKTOP\BACKUPS\BACKUP-20071126-104453-620.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP6\A0005118.DLL
C:\WINDOWS\SYSTEM32\ARMXSUMG.DLL
C:\WINDOWS\SYSTEM32\TFTHJBOQ.DLL

Trojan.Downloader-Gen/JLove
C:\PROGRAM FILES\HGLWPWRW\LEHKJWBE.DLL

Trojan.Downloader-Gen/BigTkt
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\DRVGIZR.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP2\A0000016.DLL

Malware.Ultimate Defender
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\TNRTMWUK\TNRTMWUK1.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\TNRTMWUK\TNRTMWUK2.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\TNRTMWUK\TNRTMWUK3.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP2\A0000013.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP2\A0000014.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1412C0D0-1CFA-438B-9D2A-BB11E037FFF7}\RP2\A0000015.EXE

Adware.Vundo-Variant/Small
C:\WINDOWS\SYSTEM32\LJJIIGE.DLL
C:\WINDOWS\SYSTEM32\TUVVTUS.DLL

Trojan.Downloader-Gen/DDC
C:\WINDOWS\SYSTEM32\OHANHHRH.EXE





HIJACK THIS LOG





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:23, on 2007-11-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\DrWeb\spiderui.exe
C:\Program Files\DrWeb\DRWEBSCD.EXE
C:\Program Files\DrWeb\spiderml.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\PROGRA~1\DrWeb\spidernt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\VideoMate\ComproRemote.exe
C:\Program Files\Common Files\VideoMate\ComproSchedulerDTV.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Josh\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://au.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://au.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://au.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://au.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [CM108Sound] RunDll32 CM108.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpIDerNT] C:\PROGRA~1\DrWeb\spiderui.exe /agent
O4 - HKLM\..\Run: [DrWebScheduler] "C:\Program Files\DrWeb\DRWEBSCD.EXE"
O4 - HKLM\..\Run: [SpIDerMail] "C:\Program Files\DrWeb\spiderml.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: ComproRemote.lnk = ?
O4 - Global Startup: ComproSchedulerDTV.lnk = ?
O4 - Global Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Joshuas Folder\Junk\Stuff\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SpIDer Guard for Windows (SPIDERNT) - Doctor Web, Ltd. - C:\PROGRA~1\DrWeb\spidernt.exe

--
End of file - 8882 bytes





Seems to be running better now, but this did happen before for like an hour then it came back. what do you think?
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 11-29-2007 7:12 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
Looks clean smile


Delete: C:\QOOBOX < - Folder


Hide systemfiles again
From Windows Explorer, go to Tools>Folder Options> View tab.
Untick - Show hidden files and folder
Tick - Hide file extensions for known types
Tick - Hide protected operating system files
Click Yes to confirm & then click OK


 
To completely and immediately remove any infected file or files in the data store, turn off and then turn on System Restore. To do so, follow these steps:
System Restore
 
Important  -->>>   Now that You are clean:
 
Here are some additional software you may wish to consider using, to prevent malicious software installing in your PC  - >

 

SpywareBlaster  This is not a scanner, it blocks malicious objects and code from being downloaded, in addition to blocking access to sites known to download malware. Spyware Blaster runs silently in the background and does not need to be open to protect your PC.  
Freeware
 
Boclean  BOClean is designed to run quietly without intrusion if no malware "attack" exists and will scan through any suspicious files with signature analysis to preclude false alarms or possible damage to valid configurations.
Think of your antivirus as a burglar alarm. BOClean is a motion detector.
Freeware
 
Make sure to keep these programs up-to-date
 



Do NOT post your problem in someone elses thread.

Back to Top
 

Josheh
New Member


Date Joined Nov 2007
Total Posts : 14
 
   Posted 11-30-2007 12:39 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
Thanks Touch, Funny thing is all those hide extensions and all that had already changed back to how they where before.

Thanks for the advice on the other programs and thanks for all your help
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 11-30-2007 8:06 (GMT +1)    Quote: Trojan -Alert an admin about: Trojan -
My pleasure smile
 
 
 
 
Now that your problem appears to be resolved, this thread will be closed
 to prevent others with similar issues posting in it.
 


Do NOT post your problem in someone elses thread.

Back to Top
 
New Topic Locked Topic Printable version of : Trojan -
 
Forum Information
Currently it is Saturday, November 21, 2009 3:04 PM (GMT +1)
There are a total of 73.032 posts in 17.116 threads.
In the last 3 days there were 14 new threads and 69 reply posts. View Active Threads
Who's Online
This forum has 30334 registered members. Please welcome our newest member, sushil.
38 Guest(s), 1 Registered Member(s) are currently online.  Details
prolife
5 Latest Threads
Cannot install anti-virus softeware or do window updates... need help (17)21-11-2009 13:46:11 (superjesse)
Constant scanning andskipped files? (1)21-11-2009 10:08:33 (Dickens)
Michael Vick jerseys (1)21-11-2009 09:42:37 (Dickens)
Arizona Cardinals Jerseys (1)21-11-2009 09:37:23 (Dickens)
How to remove this Malware/Virus (0)21-11-2009 06:54:16 (bozzack)