task manager wont open

  1. #1
    levi18 is offline Newbie

    task manager wont open

    programs were getting removed and renamed mysteriously i followed a few guides think i got rid of that also msconfig, regedit and task manager werent working now msconfig and regedit are but task manager isnt. Any help will be appreciated! hijack this log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:53:38 PM, on 2/10/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\fxssvc.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = ;localhost;<local>
    R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {4390F437-1081-1D2E-F24A-1BE33691AAE7} - (no file)
    O2 - BHO: (no name) - {52706EF7-D7A2-49AD-A615-E903858CF284} - (no file)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Easy Gif Animator Toolbar Helper - {96372AB6-15EB-4316-B497-71C741BC548C} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.0\EasyGifAnimator_Toolbar.dll (file missing)
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: (no name) - {E09962E7-A39E-4F60-8003-66D57BED27B7} - (no file)
    O3 - Toolbar: (no name) - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - (no file)
    O3 - Toolbar: (no name) - {53E0B6E8-A51D-448B-B692-40B67B285543} - (no file)
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Easy Gif Animator Toolbar - {35065594-9169-4A34-B167-FC4865038E53} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.0\EasyGifAnimator_Toolbar.dll (file missing)
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
    O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: Display All Images with Full Quality - "res://C:\Program Files\NetZero\qsacc\appres.dll/228"
    O8 - Extra context menu item: Display Image with Full Quality - "res://C:\Program Files\NetZero\qsacc\appres.dll/227"
    O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?f4671f139c3343c7895834c19ffd91f3
    O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?f4671f139c3343c7895834c19ffd91f3
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: worsock.dll
    O10 - Unknown file in Winsock LSP: worsock.dll
    O10 - Unknown file in Winsock LSP: worsock.dll
    O10 - Unknown file in Winsock LSP: worsock.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.pathwaynet.com
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
    O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Application Layer Gateway Service ALGTermService (ALGTermService) - Unknown owner - C:\WINDOWS\system32\12520437y.exe (file missing)
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

    --
    End of file - 7470 bytes


  2. #2
    levi18 is offline Newbie
    spybot s&d failed to removed Hotbar, MeMedia advantage and zlob something.. and computer acts like its at 100% cpu all the time

  3. #3
    Neal is offline Dedicated Member
    Go here to learn how to show hidden files/folders:

    http://www.xtra.co.nz/help/0,,4155-1916458,00.html#5

    Re-hide after we are done



    Find this file:

    C:\WINDOWS\System32\worsock.dll

    And...



    Go to next site:
    http://www.virustotal.com/en/indexf.html
    On top you'll find 'Browse'
    Click the browse button and browse to next file:


    C:\WINDOWS\system32\worsock.dll


    Click open.
    Then click the 'Send' button next to it.
    This will scan the file. Please be patient.
    Once scanned, copy and paste the results as well in your next reply.


    If that one is to busy here is another option:


    http://virusscan.jotti.org

    And

    http://www.kaspersky.com/scanforvirus.html

  4. #4
    levi18 is offline Newbie
    File has already been analysed:
    MD5: 6c7726cd91afc08bb44f98ab7dd41ff9
    Date: 02.13.2008 05:25:40 (CET) [+1D]
    Results: 8/32
    Permalink: analisis/896c054cbb2baa8e1128af5ff2e5d48a


    Antivirus Version Last Update Result
    AhnLab-V3 2008.2.13.11 2008.02.13 -
    AntiVir 7.6.0.65 2008.02.12 -
    Authentium 4.93.8 2008.02.13 -
    Avast 4.7.1098.0 2008.02.12 -
    AVG 7.5.0.516 2008.02.12 Agent.2.BL
    BitDefender 7.2 2008.02.13 -
    CAT-QuickHeal None 2008.02.12 -
    ClamAV 0.92 2008.02.12 -
    DrWeb 4.44.0.09170 2008.02.12 -
    eSafe 7.0.15.0 2008.02.11 -
    eTrust-Vet 31.3.5532 2008.02.12 Win32/Charaho.CB
    Ewido 4.0 2008.02.12 -
    FileAdvisor 1 2008.02.13 -
    Fortinet 3.14.0.0 2008.02.13 -
    F-Prot 4.4.2.54 2008.02.12 -
    F-Secure 6.70.13260.0 2008.02.13 Trojan-PSW.Win32.Agent.yt
    Ikarus T3.1.1.20 2008.02.13 Trojan-Spy.Finanz.J
    Kaspersky 7.0.0.125 2008.02.13 Trojan-PSW.Win32.Agent.yt
    McAfee 5228 2008.02.12 -
    Microsoft 1.3204 2008.02.12 TrojanSpy:Win32/Glaze.B
    NOD32v2 2870 2008.02.12 -
    Norman 5.80.02 2008.02.12 -
    Panda 9.0.0.4 2008.02.13 -
    Prevx1 V2 2008.02.13 Heuristic: Suspicious File With Bad Parent Associations
    Rising 20.29.22.00 2008.01.30 -
    Sophos 4.26.0 2008.02.13 -
    Sunbelt 2.2.907.0 2008.02.13 Trojan.Nethell.B
    Symantec 10 2008.02.13 -
    TheHacker 6.2.9.218 2008.02.12 -
    VBA32 3.12.6.0 2008.02.11 -
    VirusBuster 4.3.26:9 2008.02.12 -
    Webwasher-Gateway 6.6.2 2008.02.12 -
    Additional information
    File size: 10752 bytes
    MD5: 6c7726cd91afc08bb44f98ab7dd41ff9
    SHA1: 6501de01a205174f95ba93f1902a6d4107d2b3f5
    PEiD: -
    packers: UPX
    packers: UPX
    packers: UPX
    Prevx info: http://info.prevx.com/aboutprogramte...80020024BB2A11

  5. #5
    Neal is offline Dedicated Member
    Download LSPfix here:
    http://www.cexx.org/lspfix.htm
    Or here:
    http://www.snapfiles.com/get/lspfix.html
    or here:
    http://majorgeeks.com/download625.html

    To run it be sure you are NOT connected to the Internet.

    Launch the application, and click the "I know what I'm doing" checkbox.

    Check all instances of worsock.dll (and nothing else), and move them to the "Remove" pane.
    Then click Finish.
    Go to c:\windows\system32\worsock.dll and delete worsock.dll< file
    Reboot your computer. A full power down reboot.


    to find and delete worsock.dll:

    Navigate to this file using Windows Explorer (OR Start -> Search) and delete (if present):


    Post a new hijackthis log please.

  6. #6
    levi18 is offline Newbie
    wont let me delete the file

  7. #7
    Neal is offline Dedicated Member
    Save 20% on AVG Internet Security 2012 Suite!
    If you have previously downloaded ComboFix,please delete that version now.

    Now download ComboFix and save to your desktop:

    Note:

    It is IMPORTANT that it is saved directly to your desktop

    Close any open browsers.

    Disconnect from the Internet.

    Please do not re-connect your machine back to the Internet until Combofix has completely finished.

    Disable your antivirus program and any realtime malware scanners now

    Double click on combofix.exe and follow the prompts.

    When it's finished it will produce a log.
    Post the entire contents of C:\ComboFix.txt into your next reply.

    Note:
    Do not mouseclick combofix's window while it's running.

    That may cause the program to freeze/hang.

    Do NOT post the ComboFix-quarantined-files.txt unless I ask.

    Re-enable your anti-virus and re-connect back to the internet and post the combofix log.



    *Note*
    In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.
    Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.



    New hijackthis log also please.

+ Reply to Thread