first time posting a hijack this log (RESOLVED)

  1. #1
    jlew is offline Newbie

    first time posting a hijack this log (RESOLVED)

    so my girlfriends computer was performing very slow and not connecting to the internet, there was norton antivirus installed but it wasn't working correctly. I deleted some new .net crap and fixed the winsocks so it could connect to the internet. then i downloaded and installed AVG and download the updates and it found and deleted 200+ infections. I'm unsure if the computer is up and running well or still infected with junk. adaware and spybot don't turn anything up but its running awfully slow. I have been unable to use windows update either, although i have yet to try since I have cleaned those infections. here is a hijack this log, any help is appreciated.

    Logfile of HijackThis v1.99.1
    Scan saved at 3:59:52 PM, on 10/31/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Iomega\System32\AppServices.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Iomega HotBurn\Autolaunch.exe
    C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    C:\QUICKENW\QWDLLS.EXE
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Microsoft Money\System\urlmap.exe
    C:\Program Files\Hijack This\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/start.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com/start.html
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Drag'n'Drop_Autolaunch] "C:\Program Files\Iomega HotBurn\Autolaunch.exe"
    O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 4200 Series\Fax\fm3032.exe" /s
    O4 - HKLM\..\Run: [Lexmark 4200 Series] "C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe"
    O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
    O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
    O4 - Global Startup: ScanPanel.lnk = C:\ScanPanel\ScnPanel.exe
    O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com/start.html
    O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/game...ts/y/tt3_x.cab
    O16 - DPF: Yahoo! Spelldown - http://download.games.yahoo.com/game...s/y/sdt1_x.cab
    O16 - DPF: Yahoo! Towers 2.0 - http://download.games.yahoo.com/game...s/y/ywt0_x.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
    O16 - DPF: {4E7BD74F-2B8D-469E-DAEE-FE7EB39ABD7D} - http://toolbar.gograph.com/toolbar/install/gograph.cab
    O16 - DPF: {528C14CD-CF9E-489C-A365-5999F17B69B9} (LightSurfUploadCtl Class) - http://pictures.sprintpcs.com/active...oadControl.cab
    O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
    O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1097629948906
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.g...tl_0_0_0_1.ocx
    O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
    O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10...o.cab27513.cab
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yaho...tocomplete.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...a/SymAData.dll
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab
    O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/tech...ActiveData.cab
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
    Last edited by jlew; 31-10-2005 at 11:12 PM.


  2. #2
    Neal is offline Dedicated Member
    Welcome to DAL,

    If you are not going to use Norton please uninstall, it is not a good idea to use two anti-virus programs together even if it is not working correctly.


    Lets see what some virus scans can uncover and we will go from there.

    Get the stinger here:
    http://vil.nai.com/vil/stinger/

    Download it to another computer if need be, and bring it to the affected computer on floppy disk.

    It will kill the top 53 virus files if any are found there

    then,

    Internet Explorer required
    Run these two online virus scanners (Panda Activescan) following these instructions below:
    http://www.pandasoftware.com/product..._principal.htm


    Internet Explorer required
    Also this excellent(BitDefender) scanner:http://www.bitdefender.com/scan8/ie.html

    These scans are going to take a couple of hours to do, Panda and BitDefender both make logs of what is found please post those for me to take a look at please. Thanks

    also post a new HJT log as well.

  3. #3
    jlew is offline Newbie
    sorry I should have clarified that I did uninstall norton. do I need to uninstall AVG before using any of these?

  4. #4
    Neal is offline Dedicated Member
    No, go ahead and do those scans these are not installed scanners

  5. #5
    AlkS14 is offline Valued Member
    no- i used the same scans, as Neal helped me out earlier (thanks again ) AVG is a really good AV program, and can remain installed when you run any of those scans.

  6. #6
    jlew is offline Newbie
    Stinger didn't find anything. I tried both of those online scans and the links weren't working in IE. I think it was a javascript error.

    the address bar read

    javascript:pp(1,2,63)

    anywho, windows update came back to life and auto downloaded service pack 2. should I install it now or try to fix this first?

  7. #7
    Neal is offline Dedicated Member
    Do not install service pack 2 on an infected machine.


    Go here and install Sun Java then try the scans


    Sun Java

  8. #8
    jlew is offline Newbie
    Quote Originally Posted by Neal
    Do not install service pack 2 on an infected machine.


    Go here and install Sun Java then try the scans


    Sun Java
    I installed the java 1.5 and the pages still didn't work. windows automatically updated to service pack 2 I guess. It says "sp2" when I boot in safe mode now. the computer seems to be moving a little faster but the online scanners still aren't working and the actual windows update page doesn't display anything. for fun I tried to go to us.mcafee.com and got nothing either. perhaps the hosts file is corrupted?

    I looked into it also possibly being a trojan, so i tried a full system scan with ewido in safe mode and it found 7 infections. I removed them and saved the log and can post it later tonight when I have access to that machine again if needed.

    after the ewido scan the pages still aren't loading with IE. They do load and display with firefox but of course the IE is required for them to function.

    thanks for all your help so far. anymore suggestions would be appreciated.

  9. #9
    Neal is offline Dedicated Member
    Hmmmm, not sure what that is about, but there is a version of Housecall online scanner that will work with firefox if you have the java runtime enviroment.

    Upgrade to this version of sunjava: This is 5.0, if I gave you the wrong link my apologies


    sunjava


    Then try the scans

  10. #10
    jlew is offline Newbie
    Save 20% on AVG Internet Security 2012 Suite!
    Quote Originally Posted by Neal
    Hmmmm, not sure what that is about, but there is a version of Housecall online scanner that will work with firefox if you have the java runtime enviroment.

    Upgrade to this version of sunjava: This is 5.0, if I gave you the wrong link my apologies


    sunjava


    Then try the scans
    sorry I made a typo. you gave me the right link before. I did install java 5.0 and the links still weren't working in IE.

    here are the results of all the fun stuff ewido found.

    ---------------------------------------------------------
    ewido security suite - Scan report
    ---------------------------------------------------------

    + Created on: 2:02:16 AM, 11/1/2005
    + Report-Checksum: 2F3F56E9

    + Scan result:

    HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
    HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTr ansporterX\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
    HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTr ansporterX.1\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Mod uleUsage\C:/WINDOWS/Downloaded Program Files/btiein.dll\\.Owner -> Spyware.HuntBar : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Mod uleUsage\C:/WINDOWS/Downloaded Program Files/btiein.dll\\{26E8361F-BCE7-4F75-A347-98C88B418322} -> Spyware.HuntBar : Cleaned with backup
    C:\Documents and Settings\amy riddle\Local Settings\Application Data\Wildtangent\Cdacache\00\00\0F.dat/files\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
    C:\Documents and Settings\patricia riddle\Cookies\patricia riddle@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
    C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.PornWare.PopCap.b : Cleaned with backup
    C:\WINDOWS\NDNuninstall5_20.exe -> Spyware.NewDotNet : Cleaned with backup
    C:\WINDOWS\NDNuninstall5_40.exe -> Spyware.NewDotNet : Cleaned with backup
    C:\WINDOWS\NDNuninstall5_64.exe -> Spyware.NewDotNet : Cleaned with backup
    C:\WINDOWS\NDNuninstall6_10.exe -> Spyware.NewDotNet : Cleaned with backup
    C:\WINDOWS\NDNuninstall6_22.exe -> Spyware.NewDotNet : Cleaned with backup
    C:\WINDOWS\NDNuninstall6_38.exe -> Spyware.NewDotNet : Cleaned with backup
    C:\WINDOWS\system32\drivers\etc\hosts.20050721-235353.backup -> Trojan.Qhost.bs : Cleaned with backup


    ::Report End

    I'm running the trend micro scan through firefox and I can post those results if you'd like.
    Last edited by jlew; 04-11-2005 at 09:13 AM.

Closed Thread
Page 1 of 3 1 2 3 LastLast